Revocation publishing lifecycle
daniel bryan <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAJKvcBRL6PX7d+mJWcBTqF-2z2irtxQ7-6czR79FcGj9H+C-CQ@mail.gmail.com> |
Hello, Should a CA provide a CRL for it's entire lifetime? For example, CA1 is good for 4 years, and the first year it issues 1 year certs and provides revocation status via CRLs. Year 2, CA1 stops issuing, and a new issuing CA2 is stood up. Year 3, all the certificates from CA1 have expired. Should CA1 make revocation data available until CA1 expires, so that users can be informed of the revocation status of expired certificates. (EG: opening an old email from a revoked user). Thanks, --Dan _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix