Re: Private key usage period extension
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <9A043F3CF02CD34C8E74AC1594475C73F4C7B87A@uxcn10-5.UoA.auckland.ac.nz> |
Erik Andersen <[email protected]> writes: >This extension was included in RFC 3280 with a heavy health warning. It was >omitted from RFC 5280 (except for A.2). It's been deprecated since RFC 2459. At that time no-one was ever able to give a coherent explanation for this that got much beyond "PKIX doesn't do that sort of thing" [0]. >In my mind, the validity of the private key should not spread outside the >validity period of the certificate. It's not meant for that, in fact it's the exact opposite, it's an extremely useful extension for when you want to say that, for example, a signing key is valid for one year but the certificate used to verify its signatures is valid for ten years. The lack of a capability for doing this has been plaguing cert-based signatures for years, leading to all manner of workaround hacks to deal with verifying signatures after the cert has expired. Peter. [0] Years later people retconned explanations for it, but none of them were terribly credible. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix