All,
I've added a question and answer to
https://wiki.mozilla.org/CA:CertificatePolicyV2.1#Frequently_Asked_Questions
The question:
"3. How do I technically constrain an external subordinate CA
certificate that will only be used to issue end-user certificates
intended for client authentication?"
See the wiki page for the answer.
Please reply if you have feedback on this.
Thanks,
Kathleen