Re: [x500standard] SV: Re: SV: Private key usage period extension

Stefan Santesson <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Erik

From:  <[email protected]> on behalf of Erik Andersen <[email protected]>Hi Stefan,
 

Thanks for the clarification. You wrote at some time that the extension is not worth fixing. It is against my responsibility as rapporteur and editor. If it is broken it shall be fixed or deprecated.



I have one issue left. I do not like that either notBefore or notAfter can be omitted. notAfter could mean that the private key is valid until the sun burns out. If not specified, it could default the end of the validity of the cert validity period. Something similar for an omitted notBefore.


I’m afraid I do not agree.

The default function of a certificate is that both notBefore and notAfter are undefined with regard to private key usage period.
This means that the verifier using this certificate can assume that the private key can be used at least during the validity of the certificate.

In this extension you can set the notBefore and notAfter independently.

I don’t see anything strange or broken with that. It means that the undefined time is undefined = default behaviour.

/stefan

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.