Re: Managing Long-Lived CA certs
"Dr. Pala" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Organization | OpenCA Labs |
| Message-ID | <[email protected]> |
Hi Carl, you are totally right :D That case would be covered by the revocation of the CA key. However, there are also other types of compromises (e.g., the system is compromised, but the key is not - certificates issued by non-authorized person). Keep in mind that in the ecosystem where this happens (device certs and many others) certificate revocation is not really checked... this would limit the exposure for non-catastrophic compromise events. Does this make sense ? What do you think ? Cheers, Max [*] = I know that checking revocation is still, regrettably, not common... On 7/17/17 5:42 PM, Carl Wallace wrote: > [...] > [CW] Wouldn't the protection need to come in the form of revocation? > If the CA key is compromised, the validity period in certificates > cannot be trusted. [...] -- Best Regards, Massimiliano Pala, Ph.D. OpenCA Labs Director OpenCA Logo _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix