Re: Should a CRL be required for an OCSP service provider to assert status.

Peter Bowen <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CAK6vND-s-iSPznDQWCqYnfRnOXgLygN_L0qXnr69L2hof2BZaQ@mail.gmail.com>
On Wed, Jun 8, 2016 at 1:21 PM, daniel bryan <[email protected]> wrote:
> So i ran into an interesting situation today that sparked a conversation.
[...]
> The vendor tool fails to create a database because a CRL is not present.
> During my discussion with the vendor, they said, although they could
> technically create a database without the CRL in this case, they don't feel
> that they have the authority to do so.  But, on the contrary, they also
> allow the OCSP service owner to perform "instant revocation" which marks a
> serial as revoked regardless if the CA owner revokes the serial, or
> publishes a CRL.  My initial thought is an OCSP service should be able to
> assert any status as long as the CA has delegated authority to the service
> via the OCSP Signing certificate.
>
> Ok, with that whole semi organized info dump about what I know here are the
> official questions.
>
> Q1: Should an OCSP service provider be able to assert a status of revoked
> when the serial is not revoked on the CA.
>
> Q2: Should an OCSP service provider be able to assert a status of good for a
> truly valid issued certificate when no CRL has been created by the CA

There seems to be some confusion between "CRL" and "database", so I'm
not entirely clear on your question.

A Certificate Revocation List (CRL) is a specific signed data
structure defined in X.509.  There is no general requirement that CAs
publish a CRL.  Many CAs only offer revocation information via OCSP or
some other mechanism.

There is nothing in the OCSP RFCs that says _how_ a OCSP Responder
knows about the status of certificates.  That is outside of the
protocol. It is entirely possibly to use OCSP without having a CRL
published by the CA.  The OCSP responder could get information
directly from the CA via some out of band method or the OCSP responder
operator could be responsible for managing revocation for all the CA
certificates (there is a model where the CA just issues and another
party handles revocation).

As to your questions, those are both policy questions.  There is
nothing in the technical standards (either ISO/IEC|ITU-T or IETF) that
will provides a definitive answer to your questions.  Different PKIs
implementing the standards may have different answers to your
questions.

Thanks,
Peter

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.