Lines Matching refs:issuer
189 // make sure issuer is not set
190 // we check the issuer in verifyCRLs method
278 * @param validity the time for which the validity of the CRL issuer's
295 // if crlIssuer is set, verify that it matches the issuer of the
297 // boolean asserted. Otherwise, verify that the CRL issuer matches the
298 // certificate issuer.
321 // we accept the case that a CRL issuer provide status
331 debug.println("crl issuer does not equal cert issuer");
335 // in case of self-issued indirect CRL issuer.
344 // we accept the case that a CRL issuer provide status
351 // we accept the case that a CRL issuer provide status
404 // RFC 3280: there must be only 1 CRL issuer
408 "issuer when relative name present");
546 // CRL issuer (if indirect CRL). If a key usage extension is present
547 // in the CRL issuer's certificate, verify that the cRLSign bit is set.
556 // certificate, instead, it only compares the CRL issuer and
558 // delegated CRL issuer is a self-issued certificate, the
559 // builder is unable to find the proper CRL issuer by issuer
561 // proper issuer. It is of great help to narrow the target
583 // trust it during validating the CRL issuer.
585 // the dead loop while looking for the issuer back and forth
586 // between the delegated self-issued certificate and its issuer.
664 * Append relative name to the issuer name and return a new
667 private static GeneralNames getFullNames(X500Name issuer, RDN rdn)
669 List<RDN> rdns = new ArrayList<RDN>(issuer.rdns());