* Version 1.7.3 (unreleased)
+** New option to certtool: --generate-proxy.
+This will generate a Proxy Certificate from an end entity certificate.
+You will need to specify the proxy certificate's private key with
+--load-privkey, the user certificate with --load-certificate and the
+private key used to sign the new proxy certificate with
+--load-ca-privkey. Certtool will query for proxy path length and the
+policy language OID. Currently only OIDs that have an empty policy
+are supported (which includes the two OIDs defined by RFC 3820).
+
+** Certtool --certificate-info now prints information for Proxy Certificates.
+Before the proxy extension was just printed as DER encoded data.
+
+** New APIs to set proxy subject names and get/set proxy cert extension.
+
** Fix parsing of pathLenConstraints in BasicConstraints with missing cA.
** Added self-test to test for regressions of pathLenConstraint bug.
** Fix import of ASCII armored OpenPGP keys.
Patch by ludovic.courtes@laas.fr (Ludovic Courtès).
-** Certtool --certificate-info now prints information for Proxy Certificates.
-Before the proxy extension was just printed as DER encoded data.
-
-** New option to certtool: --generate-proxy.
-This will generate a Proxy Certificate from an end entity certificate.
-You will need to specify the proxy certificate's private key with
---load-privkey, the user certificate with --load-certificate and the
-private key used to sign the new proxy certificate with
---load-ca-privkey. Certtool will query for proxy path length and the
-policy language OID. Currently only OIDs that have an empty policy
-are supported (which includes the two OIDs defined by RFC 3820).
-
-** New APIs to set proxy subject names and get/set proxy cert extension.
-
** API and ABI modifications:
gnutls_x509_crt_set_proxy_dn: ADD.
gnutls_x509_crt_set_proxy: ADD.