Re: Managing Long-Lived CA certs

"Erik Andersen" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Peter,

We live in a very changeable world. Today's implementations are junk
tomorrow.

If we are not allowed to do anything that is not supported by current
implementations, it is like trying to stop the world.

Erik

-----Oprindelig meddelelse-----
Fra: Peter Gutmann [mailto:[email protected]] 
Sendt: 18 July 2017 05:32
Til: Erik Andersen <[email protected]>; PKIX <[email protected]>
Emne: Re: [pkix] Managing Long-Lived CA certs

Erik Andersen <[email protected]> writes:

>What about the private key usage period extension

That would be the obvious choice, but PKIX says you're not allowed to use
it.
No reason given, you just can't.  This would imply that support for it in
implementations is going to be hard to find...

Peter.




=

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.