Re: Should a CRL be required for an OCSP service provider to assert status.

[email protected] (Martin Rex)
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Stephen Kent wrote:
> 
> I think it's appropriate to cite X.509 text in response to Daniel's 
> questions.
> However, EU legislation is not the same as ITU or IETF standards, and 
> one should note that distinction, where appropriate.

In this case, EU legislation just uses the existing extensibility
of the OCSP protocol in a straightforward and sensible fashion,
so that is just fine.


>
> For example, I recall that PKIX did not endorse the notion of OCSP
> providing an indication of a cert as valid, vs. not revoked,
> when folks have posed that question in the past.

Now that is a funny interpretation of the facts.  ;-)

When the OCSP spec was last revised, that very notion was actually
standardized.  Yes, there was a significant amount of dissenters,
but they ended up in the rough for conveying the notion as part of 
the OCSP protocol, albeit without the (obvious&existing) means
(CertHash extension) that ended up in the EU legislation.


See the diffs for Section-2.2 Response of the OCSP revision:

https://tools.ietf.org/rfcdiff?url1=rfc2560&url2=rfc6960


-Martin

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.