On Thu, Jun 12, 2014 at 09:52:59PM +0100, Jeremy Harris wrote:
> >Note also, that S/MIME certificates will often have the wrong
> >keyUsage or extendedKeyUsage for use as a TLS client cert.
>
> I've not decided what to do about those two, either with
> respect to extractors or enforcement in certificate verification.
>
> Are they actually used in practice?
Sorry, a bit out of context here, not sure what "they" means, can
you state your question in a bit more detail?
--
Viktor.