Re: Managing Long-Lived CA certs

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
David A. Cooper <[email protected]> writes:

>Can you provide a citation for your claim that "PKIX says you're not allowed
>to use it. No reason given, you just can't."?

Um, the PKIX RFCs for the last twenty years, starting with 2459:

   4.2.1.4  Private Key Usage Period

   This profile recommends against the use of this extension.  CAs
   conforming to this profile MUST NOT generate certificates with
   critical private key usage period extensions.

Peter.


_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.