Hacker News new | ask | show | jobs
by agwa 51 days ago
I'll note that while X.509 certificates are deployed widely on the Internet, they are not deployed in the manner the ITU intended. There is no global X.500 directory and Distinguished Names are just opaque identifiers that are used to help find issuers during chain building. That hardly counts as a win for the ITU in my book.
1 comments

And in some usages CN is just doesn't even looked up upon.
Apperantly the AKID and SKID extensions are used instead these days