Re: [x500standard] SV: Re: SV: Private key usage period extension
Stefan Santesson <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Erik From: <[email protected]> on behalf of Erik Andersen <[email protected]>Hi Stefan, Thanks for the clarification. You wrote at some time that the extension is not worth fixing. It is against my responsibility as rapporteur and editor. If it is broken it shall be fixed or deprecated. I have one issue left. I do not like that either notBefore or notAfter can be omitted. notAfter could mean that the private key is valid until the sun burns out. If not specified, it could default the end of the validity of the cert validity period. Something similar for an omitted notBefore. I’m afraid I do not agree. The default function of a certificate is that both notBefore and notAfter are undefined with regard to private key usage period. This means that the verifier using this certificate can assume that the private key can be used at least during the validity of the certificate. In this extension you can set the notBefore and notAfter independently. I don’t see anything strange or broken with that. It means that the undefined time is undefined = default behaviour. /stefan _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix