Minimum requirements for client certificates

Sean Conner sean at conman.org
Mon Aug 31 21:08:21 BST 2020


It was thus said that the Great Solderpunk once stated:
> I think it goes without saying that at the absolute minimum a Gemini
> client certificate ought to be a valid x509 certificate.  I did look
> into this at some stage and IIRC the Issuer needs to be non-empty but
> the Subject does not.  

  I was unaware of this and (incorrectly) assumed that the issuer and
subject fields would always be present.  Maybe mention somewhere in the
specification that servers could expect non-subject client certificates.

  -spc


More information about the Gemini mailing list