AW: [iaik-jce] International Step-Up Encryption Certificate

> I want to generate a certificate, which allows a Step-Up from an Export
> RC4 - 40 bit secret to a true 128 bit RC-4. I read om the netscape
> devloper site:
I strongly doubt that this will work. If it would, 40-bit export suites
wouldn't make sense at all. A certain key will most likely be required to
sign such a certificate or to verify correctly resp.

> So the question is, is there anywhere (link to doco) where I can find
> the meaning of these codes? or can anyone explain the meaning of these 2
> extensions. The extensions were the same for all 3 sites I checked:
The best thing to go to is http://www.alvestrand.no/objectid/top.html


OID description:
An arc under joint-ISO-CCITT(2) countries(16) USA(840) that indexes company
No additional info. I assume 113730 is Verisign.

> [Ext 2 - (class iaik.x509.UnknownExtension)]
> UnknownExtension:     OBJECT ID =
OID value: 2.5.29

OID description:
Object Identifier for Version 3 certificate extensions.
no explanation for .3

> and for iaik.x509.extensions.ExtendedKeyUsage
> what is KeypurposeId: 2.16.840.1.113730.4.1?
I assume step-up :-)

