Re: Managing Long-Lived CA certs

"David A. Cooper" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
So, you intentionally delete the quote I provided from RFC 5280 saying 
that use of the private key usage period extension is "neither 
deprecated nor recommended" so that you can falsely claim that the "PKIX 
RFCs for the last twenty years" have said the same thing.

So, you are trying to claim that "the PKIX RFCs for the last twenty 
years" have said something, even though you know that RFC 5280, which is 
9 years old, doesn't say that.

In addition, even the text you quote doesn't support your claim that 
"PKIX says you're not allowed to use it." Before May 2008, PKIX said 
that you're not allowed to mark the extension as critical, which is not 
the same as "not allowed to use it." While PKIX previously recommended 
against the use of the extension, it has not done so for the past 9 years.

On 07/18/2017 10:16 AM, Peter Gutmann wrote:
> David A. Cooper <[email protected]> writes:
>
>> Can you provide a citation for your claim that "PKIX says you're not allowed
>> to use it. No reason given, you just can't."?
> Um, the PKIX RFCs for the last twenty years, starting with 2459:
>
>     4.2.1.4  Private Key Usage Period
>
>     This profile recommends against the use of this extension.  CAs
>     conforming to this profile MUST NOT generate certificates with
>     critical private key usage period extensions.
>
> Peter.
>
>

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.