Re: Private key usage period extension

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <9A043F3CF02CD34C8E74AC1594475C73F4C7B87A@uxcn10-5.UoA.auckland.ac.nz>
Erik Andersen <[email protected]> writes:

>This extension was included in RFC 3280 with a heavy health warning. It was
>omitted from RFC 5280 (except for A.2).

It's been deprecated since RFC 2459.  At that time no-one was ever able to
give a coherent explanation for this that got much beyond "PKIX doesn't do
that sort of thing" [0].
 
>In my mind, the validity of the private key should not spread outside the
>validity period of the certificate.

It's not meant for that, in fact it's the exact opposite, it's an extremely
useful extension for when you want to say that, for example, a signing key is
valid for one year but the certificate used to verify its signatures is valid
for ten years.  The lack of a capability for doing this has been plaguing
cert-based signatures for years, leading to all manner of workaround hacks to
deal with verifying signatures after the cert has expired.

Peter.

[0] Years later people retconned explanations for it, but none of them were 
    terribly credible.


_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.