PKIX and verification depth.

Rod Widdowson rdw at steadingsoftware.com
Wed Jul 2 10:23:34 EDT 2014


> > However that seems like it might be a pretty dangerous change to make
for
> > people who are not configuring via the V2 legacy trust engines.
> 
> I don't see the danger; don't you end up with a default of 1 either way?

Yup, but what I don't know enough to know is whether that is a sensible
enough default in non-IdP situations to break the current paradigm of
requiring an (application defined) value.



More information about the dev mailing list