A method of certifying a host-identification mapping extension included in
a digital certificate, the digital certificate issued and signed by a
specific certification authority. In an exemplary embodiment of the
invention, the method includes assigning a trust value for each
certification authority included in a set of certification authorities. A
digital certificate containing the host-identification mapping extension
therein is received, with the host-identification mapping extension
further containing a plurality of identification attributes therein. The
plurality of identification attributes are evaluated, along with the
trust value assigned to the specific certification authority issuing the
digital certificate. A determination is then made, based upon the
plurality of identification attributes and the trust value, as to whether
the host-mapping extension is to be certified.