On Sat, Apr 04, 2015 at 05:31:37AM +0200, Jakob Bohm wrote: > (top posting like the rest of the thread) > > What makes you think it is incorrect to check the Key > Identifier (where present) before checking a signature > against a key? > > What other reasonable purpose could the Key Identifier > fields serve? Indeed I have code that relies on OpenSSL taking the SKI and AKI into account. -- Viktor.