Re: Should a CRL be required for an OCSP service provider to assert status.

[email protected] (Martin Rex)
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Stephen Kent wrote:
> Martin,
> 
> The June 2013 OCSP revised text expanded the discussion of what "good" 
> means, noting that it is an indication that no cert issued with the 
> serial number in question, and within its validity interval, was 
> revoked. It also retained the statement that "good" is not an indication 
> that a cert is valid. I don't see any indication in the revised text of 
> Section 2.2 to support your assertion that the revisions represent a 
> retreat from the earlier PKIX position on OSCP as other than a 
> revocation status protocol.
> 
> Yes, the EU defined a _private_ extension (CertHash) to support the 
> notion of expanding the scope of OCSP. If an OCSP server operator 
> assumes that all of the OCSP clients it deals with recognize this 
> private, non-critical extension, then it is obviously free to make use 
> of it.

Your description is missing the point.

The really interesting change was the change in the definition of
"revoked", where an updated OCSP responder can report "revoked"
in situations where the previous spec sort-of implied "good".

The change allows OCSP responders to narrow the situation where they
respond with "good", but it does not require it.  However, the client
can recognize the different "good" semantics in the response, that is what
is important.

-Martin

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.