Revocation publishing lifecycle

daniel bryan <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CAJKvcBRL6PX7d+mJWcBTqF-2z2irtxQ7-6czR79FcGj9H+C-CQ@mail.gmail.com>
Hello, Should a CA provide a CRL for it's entire lifetime?

For example, CA1 is good for 4 years, and the first year it issues 1 year
certs and provides revocation status via CRLs. Year 2, CA1 stops issuing,
and a new issuing CA2 is stood up. Year 3, all the certificates from CA1
have expired.

Should CA1 make revocation data available until CA1 expires, so that users
can be informed of the revocation status of expired certificates. (EG:
opening an old email from a revoked user).

Thanks,

--Dan

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.