Hi all,
Pursuant to RFC 7468 the attached patch replaces instances of
'CERTIFICATE CHAIN' in PEM headers with 'PKCS7'.
Fixes ticket
https://fedorahosted.org/pki/ticket/1699. I could not
reproduce any problems with `keytool' as mentioned in the ticket,
nor find cases online of programs supporting 'CERTIFICATE CHAIN' but
not 'PKCS7', so I think this is a good change to make. We can
address counterexamples if/when we have hard evidence of them :)
Cheers,
Fraser