Re: Managing Long-Lived CA certs
"David A. Cooper" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
So, you intentionally delete the quote I provided from RFC 5280 saying that use of the private key usage period extension is "neither deprecated nor recommended" so that you can falsely claim that the "PKIX RFCs for the last twenty years" have said the same thing. So, you are trying to claim that "the PKIX RFCs for the last twenty years" have said something, even though you know that RFC 5280, which is 9 years old, doesn't say that. In addition, even the text you quote doesn't support your claim that "PKIX says you're not allowed to use it." Before May 2008, PKIX said that you're not allowed to mark the extension as critical, which is not the same as "not allowed to use it." While PKIX previously recommended against the use of the extension, it has not done so for the past 9 years. On 07/18/2017 10:16 AM, Peter Gutmann wrote: > David A. Cooper <[email protected]> writes: > >> Can you provide a citation for your claim that "PKIX says you're not allowed >> to use it. No reason given, you just can't."? > Um, the PKIX RFCs for the last twenty years, starting with 2459: > > 4.2.1.4 Private Key Usage Period > > This profile recommends against the use of this extension. CAs > conforming to this profile MUST NOT generate certificates with > critical private key usage period extensions. > > Peter. > > _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix