The SCEP specification states:
"If the requester does not have an appropriate existing certificate, then a
locally generated self-signed certificate MUST be used instead. The
self-signed certificate MUST use the same subject name as in the PKCS#10
request."
If the client uses a self-signed certificate, the subject name from the ID
certificate, and the subject name from the CSR should be compared, and an
warning raised if they differ.
Original issue reported on code.google.com by da...@grant.org.uk on 16 Aug 2012 at 11:53
Original issue reported on code.google.com by
da...@grant.org.uk
on 16 Aug 2012 at 11:53