revised cert format and deprecation schedule

Jim Rees rees at
Fri Apr 16 23:22:35 EST 2010

I'm up to my knees in openssl x.509 cert code right now and although I'm not
crazy about yet another cert format, I'm ecstatic at the thought of using
pki without the nightmare of asn1.  Thanks for taking this on.

