Re: Private key usage period extension

"Erik Andersen" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
It seem like we just leave as it is. I could suggest a new note saying
something like "This Specification does not specify any semantic associated
with this extension. This has to be defined for the individual usage".

Regards,

Erik

-----Oprindelig meddelelse-----
Fra: Peter Gutmann [mailto:[email protected]] 
Sendt: 07 May 2016 07:09
Til: Erik Andersen <[email protected]>; Directory list
<[email protected]>; PKIX <[email protected]>
Emne: RE: [pkix] Private key usage period extension

Erik Andersen <[email protected]> writes:

>This extension was included in RFC 3280 with a heavy health warning. It 
>was omitted from RFC 5280 (except for A.2).

It's been deprecated since RFC 2459.  At that time no-one was ever able to
give a coherent explanation for this that got much beyond "PKIX doesn't do
that sort of thing" [0].
 
>In my mind, the validity of the private key should not spread outside 
>the validity period of the certificate.

It's not meant for that, in fact it's the exact opposite, it's an extremely
useful extension for when you want to say that, for example, a signing key
is valid for one year but the certificate used to verify its signatures is
valid for ten years.  The lack of a capability for doing this has been
plaguing cert-based signatures for years, leading to all manner of
workaround hacks to deal with verifying signatures after the cert has
expired.

Peter.

[0] Years later people retconned explanations for it, but none of them were 
    terribly credible.

=

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.