1

I've heard that in the X.509 world, the certificate subject attribute is supposed to be unique... and that if someone has multiple trusted roots with the same subject (but still different in other ways) that it is an unusual use case that needs to be reviewed further.

Is this stance documented somewhere?

Mike B
  • 3,336
  • 4
  • 29
  • 39
  • 1
    Not really. CAs may have duplicate subjects, but they will require to have different public keys. This will allow to differentiate distinct CAs with duplicate subjects. – Crypt32 Sep 13 '17 at 06:51

0 Answers0