On 12/06/14 21:36, Viktor Dukhovni wrote:
> On Thu, Jun 12, 2014 at 08:53:30PM +0100, Jeremy Harris wrote:
>
>> Status|NEW |RESOLVED
>> Resolution| |WONTFIX
>
> Note also, that S/MIME certificates will often have the wrong
> keyUsage or extendedKeyUsage for use as a TLS client cert.
>
I've not decided what to do about those two, either with
respect to extractors or enforcement in certificate verification.
Are they actually used in practice?
--
Cheers,
Jeremy