Re: Managing Long-Lived CA certs

Carl Wallace <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <D5925287.981D0%[email protected]>
Inline..

From:  pkix <[email protected]> on behalf of "Dr. Pala"
<[email protected]>
Organization:  OpenCA Labs
Date:  Monday, July 17, 2017 at 10:19 AM
To:  <[email protected]>
Subject:  [pkix] Managing Long-Lived CA certs

>     
>  
> 
> Hi PKIX,
>  
> 
> I have a small question for the list regarding long-lived CA certificates.
> Especially in the context of device certificates, we often see the use of
> extra long-lived certificates for Root and Sub CAs (e.g., 35+ years) combined
> with limited key sizes (e.g., p256).
>  
> 
> Until we have a supported mechanism for reprovisioning devices (...), one
> possible solution for limiting the exposure of the private key would be to
> have a scoped certificate issuance period.
>  
> 
> What I am thinking about would be adding an extension that says: "This CA can
> issue certificates from up to 5 years from the validFrom, after this, just use
> it to provide revocation information". This might provide some protection in
> case the CA key is compromised after the initial 5 years of validity (e.g.,
> certificates issued after that date shall be rejected).

[CW] Wouldn't the protection need to come in the form of revocation? If the
CA key is compromised, the validity period in certificates cannot be
trusted.
>  
> 
> Does such extension exists today ? If not, could this be some work for
> LAMPS/SPASM WG ?
>  
> 
> Cheers,
>  Max
>  
>  
> -- 
>  
>  Best Regards, 
>  Massimiliano Pala, Ph.D.
>  OpenCA Labs Director
>  
>  
>  
>  
>  
> _______________________________________________ pkix mailing list
> [email protected] https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
eibffaoijngmjaee.png (image/png, 3.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.