Re: Private key usage period extension
Stephen Farrell <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Erik, I've a separate question: does anyone use this extension or should we put it on a virtual/mental list of stuff to be deprecated when/if someone has the energy? S. On 06/05/16 09:42, Erik Andersen wrote: > X.509 has a specification of the Private key usage period extension > (8.2.2.5). This extension is a little confusing. It has notBefore and > notAfter specification. However, the text says: > > > > The notBefore component indicates the earliest date and time at which the > private key could be used for signing. If the notBefore component is not > present, then no information is provided as to when the period of valid use > of the private key commences. The notAfter component indicates the latest > date and time at which the private key could be used for signing. If the > notAfter component is not present then no information is provided as to when > the period of valid use of the private key concludes. > > > > With a little ill will, this can be read as the private key validation > period may extend beyond the validity of the public key. Note 1 adds to the > confusing, as it says: > > > > NOTE 1 - The period of valid use of the private key may be different from > the certified validity of the public key as indicated by the certificate > validity period. With digital signature keys, the usage period for the > signing private key is typically shorter than that for the verifying public > key. > > > > It is the word "typical" that confuses me. It implies it could be different. > > > > This extension was included in RFC 3280 with a heavy health warning. It was > omitted from RFC 5280 (except for A.2). > > > > In my mind, the validity of the private key should not spread outside the > validity period of the certificate. > > > > Have I misunderstood something? > > > > Erik > > > > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix > _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix
smime.p7s
(application/pkcs7-signature, 3.8 KB) - not displayed