On Wed, Aug 16, 2017 at 08:36 Salz, Rich via openssl-users <openssl-users@xxxxxxxxxxx> wrote:
➢ So, in summary, do I need to ensure cert serial numbers are unique for my CA?
Why would you not? The specifications require it, but those specifications are for interoperability. If nobody is ever going to see your certs, then who cares what’s in them?
Well, I do like to abide by specs, and they will be used in various browsers, so I think I will continue the unique serial numbering.
Thanks, Rich.
Best regards,
-Tom
-- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users