> > You seem to be very very VERY upset by how OpenSSL implements one particular part of RFC 5280. Viktor has shown that it’s not just us, it’s other code as well. The original poster was able to live with OpenSSL’s implementation. You don’t like that code. So be it. > If that's your survey of the situation then it is wrong. Okay, please post a correction. -- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users