Confirmed users, Administrators
5,526
edits
m (link to examples of CP/CPS reviews) |
(Replaced text with current recommendation and Firefox behavior) |
||
| Line 337: | Line 337: | ||
==== Root certificates with the same subject and different keys ==== | ==== Root certificates with the same subject and different keys ==== | ||
The standards allow for two | The standards allow for two CA certificates to have the same subject names but different subject public keys. Please try to avoid this, because it often leads to confusion and compatibility issues. When verifying an end-entity certificate chaining up to a root certificate with the same subject name as another root certificate, if Firefox is aware of the existence of both root certificates, it will try all possible orderings of (subject, issuer) pairs until it finds the right one. If there are many certificates all with the same subject and issuer names, the number of orderings grows exponentially, so it can take a long time to evaluate the certificate chains. Therefore, it is better to avoid these kinds of situations. | ||
Note that for root certificates, Firefox ignores the authority key identifier and subject key identifier extensions. | |||
==== Root certificates with the same subject and same key ==== | ==== Root certificates with the same subject and same key ==== | ||