Ignore self issued certificates when checking path length constraints. Duplicate OIDs in policy tree in case they are allocated. Use anyPolicy from certificate cache and not current tree level.
I'll remember to try to compile this with warnings enabled next time :-)
This is currently *very* experimental and needs to be more fully integrated with the main verification code.