Re: Managing Long-Lived CA certs
"Erik Andersen" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Hi Peter, We live in a very changeable world. Today's implementations are junk tomorrow. If we are not allowed to do anything that is not supported by current implementations, it is like trying to stop the world. Erik -----Oprindelig meddelelse----- Fra: Peter Gutmann [mailto:[email protected]] Sendt: 18 July 2017 05:32 Til: Erik Andersen <[email protected]>; PKIX <[email protected]> Emne: Re: [pkix] Managing Long-Lived CA certs Erik Andersen <[email protected]> writes: >What about the private key usage period extension That would be the obvious choice, but PKIX says you're not allowed to use it. No reason given, you just can't. This would imply that support for it in implementations is going to be hard to find... Peter. = _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix