Re: Private key usage period extension
"Erik Andersen" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
It seem like we just leave as it is. I could suggest a new note saying something like "This Specification does not specify any semantic associated with this extension. This has to be defined for the individual usage". Regards, Erik -----Oprindelig meddelelse----- Fra: Peter Gutmann [mailto:[email protected]] Sendt: 07 May 2016 07:09 Til: Erik Andersen <[email protected]>; Directory list <[email protected]>; PKIX <[email protected]> Emne: RE: [pkix] Private key usage period extension Erik Andersen <[email protected]> writes: >This extension was included in RFC 3280 with a heavy health warning. It >was omitted from RFC 5280 (except for A.2). It's been deprecated since RFC 2459. At that time no-one was ever able to give a coherent explanation for this that got much beyond "PKIX doesn't do that sort of thing" [0]. >In my mind, the validity of the private key should not spread outside >the validity period of the certificate. It's not meant for that, in fact it's the exact opposite, it's an extremely useful extension for when you want to say that, for example, a signing key is valid for one year but the certificate used to verify its signatures is valid for ten years. The lack of a capability for doing this has been plaguing cert-based signatures for years, leading to all manner of workaround hacks to deal with verifying signatures after the cert has expired. Peter. [0] Years later people retconned explanations for it, but none of them were terribly credible. = _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix