Re: Managing Long-Lived CA certs
Carl Wallace <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <D5925287.981D0%[email protected]> |
Inline.. From: pkix <[email protected]> on behalf of "Dr. Pala" <[email protected]> Organization: OpenCA Labs Date: Monday, July 17, 2017 at 10:19 AM To: <[email protected]> Subject: [pkix] Managing Long-Lived CA certs > > > > Hi PKIX, > > > I have a small question for the list regarding long-lived CA certificates. > Especially in the context of device certificates, we often see the use of > extra long-lived certificates for Root and Sub CAs (e.g., 35+ years) combined > with limited key sizes (e.g., p256). > > > Until we have a supported mechanism for reprovisioning devices (...), one > possible solution for limiting the exposure of the private key would be to > have a scoped certificate issuance period. > > > What I am thinking about would be adding an extension that says: "This CA can > issue certificates from up to 5 years from the validFrom, after this, just use > it to provide revocation information". This might provide some protection in > case the CA key is compromised after the initial 5 years of validity (e.g., > certificates issued after that date shall be rejected). [CW] Wouldn't the protection need to come in the form of revocation? If the CA key is compromised, the validity period in certificates cannot be trusted. > > > Does such extension exists today ? If not, could this be some work for > LAMPS/SPASM WG ? > > > Cheers, > Max > > > -- > > Best Regards, > Massimiliano Pala, Ph.D. > OpenCA Labs Director > > > > > > _______________________________________________ pkix mailing list > [email protected] https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix
eibffaoijngmjaee.png
(image/png, 3.1 KB) - not displayed