Re: Should a CRL be required for an OCSP service provider to assert status.
[email protected] (Martin Rex)
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Stephen Kent wrote: > Martin, > > The June 2013 OCSP revised text expanded the discussion of what "good" > means, noting that it is an indication that no cert issued with the > serial number in question, and within its validity interval, was > revoked. It also retained the statement that "good" is not an indication > that a cert is valid. I don't see any indication in the revised text of > Section 2.2 to support your assertion that the revisions represent a > retreat from the earlier PKIX position on OSCP as other than a > revocation status protocol. > > Yes, the EU defined a _private_ extension (CertHash) to support the > notion of expanding the scope of OCSP. If an OCSP server operator > assumes that all of the OCSP clients it deals with recognize this > private, non-critical extension, then it is obviously free to make use > of it. Your description is missing the point. The really interesting change was the change in the definition of "revoked", where an updated OCSP responder can report "revoked" in situations where the previous spec sort-of implied "good". The change allows OCSP responders to narrow the situation where they respond with "good", but it does not require it. However, the client can recognize the different "good" semantics in the response, that is what is important. -Martin _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix