Re: Managing Long-Lived CA certs

"David A. Cooper" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Can you provide a citation for your
claim that "PKIX says you're not allowed to use it. No reason
given, you just can't."?

RFC 5280 says:

This specification obsoletes
[RFC3280]. Differences from RFC 3280 are summarized below:

* Section 4.2.1.4 in RFC 3280, which
specified the

privateKeyUsagePeriod certificate extension but
deprecated its

use, was removed. Use of this ISO standard extension
is neither

deprecated nor recommended for use in the Internet
PKI.

"Use of this ISO standard extension is neither deprecated nor
recommended" doesn't sound like "you just can't" to me.

On 07/17/2017 11:31 PM, Peter Gutmann wrote:

Erik Andersen <[email protected]> writes:

What about the private key usage period extension

That would be the obvious choice, but PKIX says you're not allowed to use it.
No reason given, you just can't. This would imply that support for it in
implementations is going to be hard to find...

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.