From: "NAKAMURA, Hiroshi" Date: 2007-08-09T10:06:39+09:00 Subject: Re: ruby-openssl: == incorrect for X509-Subjects -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, Hadmut Danisch wrote: > c=File.open(ARGV[0]) {|f| f.read} > c=OpenSSL::X509::Certificate.new(c) > > d=c.dup > > puts c.subject == d.subject I'm not the original author but I think it's intentional. DN equality is very hard to implement correctly. Almost impossible. You can add the following as a workaround if you understand the problem and it's enough for your usage though I don't think it should be defined by default. It's equality of DER, not of Name. module OpenSSL module X509 class Name def ==(other) !other.nil? and other.class == Name and to_der == other.to_der end end end end Regards, // NaHi -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) iQEVAwUBRrpoCB9L2jg5EEGlAQK+Dwf+Nywq3S3Da6WYhTlBJvzx1Rrb8GCQGmH1 ZTfyrlA/r+3lpBXCSQrrk6uTjY94+aX+lt4in49rdVrIu5d1Q1GVfRL5scZOAkci C7NUmexcuGk0cBQvHwuYwGDCB8TwpwOb+1DvcwRUaEkow25MWaKuQZoJS5mlC2gk A//CZJJN4R2Yc7H6AB0G9Dvp/G6fWiAVjVagHkJEdCJED82lfbd7p5JOlCoFwsFH mkr1aJCCMdMXrJahyxxCaKnPeIy1Jv7TUZAHK5ixGbIS+Cp2+4JacQi/S/86p5oB IOQr/QHD6I19+Fs++pCA6JtfQEcNZqIHclrhHWUX4StsEKuzvMWgjQ== =7Dtz -----END PGP SIGNATURE-----