Re: Should a CRL be required for an OCSP service provider to assert status.
Stephen Kent <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Martin, The June 2013 OCSP revised text expanded the discussion of what "good" means, noting that it is an indication that no cert issued with the serial number in question, and within its validity interval, was revoked. It also retained the statement that "good" is not an indication that a cert is valid. I don't see any indication in the revised text of Section 2.2 to support your assertion that the revisions represent a retreat from the earlier PKIX position on OSCP as other than a revocation status protocol. Yes, the EU defined a _private_ extension (CertHash) to support the notion of expanding the scope of OCSP. If an OCSP server operator assumes that all of the OCSP clients it deals with recognize this private, non-critical extension, then it is obviously free to make use of it. Steve _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix