Re: Should a CRL be required for an OCSP service provider to assert status.
Peter Bowen <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAK6vND-s-iSPznDQWCqYnfRnOXgLygN_L0qXnr69L2hof2BZaQ@mail.gmail.com> |
On Wed, Jun 8, 2016 at 1:21 PM, daniel bryan <[email protected]> wrote: > So i ran into an interesting situation today that sparked a conversation. [...] > The vendor tool fails to create a database because a CRL is not present. > During my discussion with the vendor, they said, although they could > technically create a database without the CRL in this case, they don't feel > that they have the authority to do so. But, on the contrary, they also > allow the OCSP service owner to perform "instant revocation" which marks a > serial as revoked regardless if the CA owner revokes the serial, or > publishes a CRL. My initial thought is an OCSP service should be able to > assert any status as long as the CA has delegated authority to the service > via the OCSP Signing certificate. > > Ok, with that whole semi organized info dump about what I know here are the > official questions. > > Q1: Should an OCSP service provider be able to assert a status of revoked > when the serial is not revoked on the CA. > > Q2: Should an OCSP service provider be able to assert a status of good for a > truly valid issued certificate when no CRL has been created by the CA There seems to be some confusion between "CRL" and "database", so I'm not entirely clear on your question. A Certificate Revocation List (CRL) is a specific signed data structure defined in X.509. There is no general requirement that CAs publish a CRL. Many CAs only offer revocation information via OCSP or some other mechanism. There is nothing in the OCSP RFCs that says _how_ a OCSP Responder knows about the status of certificates. That is outside of the protocol. It is entirely possibly to use OCSP without having a CRL published by the CA. The OCSP responder could get information directly from the CA via some out of band method or the OCSP responder operator could be responsible for managing revocation for all the CA certificates (there is a model where the CA just issues and another party handles revocation). As to your questions, those are both policy questions. There is nothing in the technical standards (either ISO/IEC|ITU-T or IETF) that will provides a definitive answer to your questions. Different PKIs implementing the standards may have different answers to your questions. Thanks, Peter _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix