Re: Managing Long-Lived CA certs
"David A. Cooper" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Can you provide a citation for your claim that "PKIX says you're not allowed to use it. No reason given, you just can't."? RFC 5280 says: This specification obsoletes [RFC3280]. Differences from RFC 3280 are summarized below: * Section 4.2.1.4 in RFC 3280, which specified the privateKeyUsagePeriod certificate extension but deprecated its use, was removed. Use of this ISO standard extension is neither deprecated nor recommended for use in the Internet PKI. "Use of this ISO standard extension is neither deprecated nor recommended" doesn't sound like "you just can't" to me. On 07/17/2017 11:31 PM, Peter Gutmann wrote: Erik Andersen <[email protected]> writes: What about the private key usage period extension That would be the obvious choice, but PKIX says you're not allowed to use it. No reason given, you just can't. This would imply that support for it in implementations is going to be hard to find... Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix