Re: Private key usage period extension clarification
"Erik Andersen" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Denis, Thanks for your comments. I agree with your proposed NOTE 2. However, this note should not give the impression that it reflects the semantic for the extension. There are other usages of this extension as described in document (http://www.icao.int/publications/Documents/9303_p12_cons_en.pdf). Stefan also had some other example. You gave yourself also another example, so I still like to include my proposed note i addition. Regards, Erik Fra: Denis [mailto:[email protected]] Sendt: 09 May 2016 10:13 Til: Erik Andersen <[email protected]>; Directory list <[email protected]>; PKIX <[email protected]> Emne: Re: [pkix] Private key usage period extension clarification Erik, I agree with the change proposals up to NOTE 1. However, I do not agree with the current NOTE 2 which states: NOTE 2 - If the verifier of a digital signature wants to check that the certificate has not been revoked, for example, due to key compromise, up to the time of verification, then a valid certificate will still exist for the public key at verification time. After the certificate(s) for a public key have expired, a signature verifier cannot rely on compromises being notified via CRLs. Erik's comment is: "It is difficult to tell what that note wants to say that is particular to this extension. Maybe the writer had some undocumented semantic in mind". I agree that the note is far from being crystal clear, but it is dealing with the verification of a digital signature before and after the expiry of the certificate. Denis's comment is: "Note 2 is trying to explain the verification of a digital signature before and after the expiry of the certificate. This has nothing to do with the private key usage period extension and thus it should be deleted". However, I would propose to replace it with a useful clarification. Replace NOTE 2 of 8.2.2.5 with: The period of use of the private key corresponding to a public key can only be enforced if both the private key and the corresponding certificate are placed in a tamper resistant hardware module that contains a reliable clock synchronized with UTC. When this is not the case, it can help a signer to avoid to use a signing private key up to the very end of the validity period of the certificate. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix