Re: Should a CRL be required for an OCSP service provider to assert status.
[email protected] (Martin Rex)
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Stephen Kent wrote: > > I think it's appropriate to cite X.509 text in response to Daniel's > questions. > However, EU legislation is not the same as ITU or IETF standards, and > one should note that distinction, where appropriate. In this case, EU legislation just uses the existing extensibility of the OCSP protocol in a straightforward and sensible fashion, so that is just fine. > > For example, I recall that PKIX did not endorse the notion of OCSP > providing an indication of a cert as valid, vs. not revoked, > when folks have posed that question in the past. Now that is a funny interpretation of the facts. ;-) When the OCSP spec was last revised, that very notion was actually standardized. Yes, there was a significant amount of dissenters, but they ended up in the rough for conveying the notion as part of the OCSP protocol, albeit without the (obvious&existing) means (CertHash extension) that ended up in the EU legislation. See the diffs for Section-2.2 Response of the OCSP revision: https://tools.ietf.org/rfcdiff?url1=rfc2560&url2=rfc6960 -Martin _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix