11 Oct
2005
11 Oct
'05
6:10 p.m.
David Chadwick writes:
Now if you are telling me that most commercial CAs do not support name constraints, that would be a powerful argument to support reverting name constraints back to their original semantics.
As interesting as the name constraints tangent is, did it actually address your question? I assumed when you said "commercial CA" you meant something like Verisign or Global sign &c. But you could have meant a PKI environment like Entrust or Windows....