This is why we in PKI can't have nice things.
Cheers,
Steve.
Stephen Wilson
Managing Director
Lockstep Technologies
E: [email protected]
M: +61 (0)414 488 851
W: http://lockstep.com.au
T: @steve_lockstep
Lockstep Technologies develops unique new smart ID solutions that
enhance privacy and prevent identity theft. Lockstep Consulting provides
independent specialist advice and analysis on digital identity and privacy.
-----Original Message-----
From: "Peter Gutmann" <[email protected]>
Sent: Wednesday, 19 July, 2017 1:25am
To: "David A. Cooper" <[email protected]>
Cc: "[email protected]" <[email protected]>
Subject: Re: [pkix] Managing Long-Lived CA certs
David A. Cooper <[email protected]> writes:
>So, you intentionally delete the quote I provided from RFC 5280 saying that
>use of the private key usage period extension is "neither deprecated nor
>recommended" so that you can falsely claim that the "PKIX RFCs for the last
>twenty years" have said the same thing.
So you intentionally quibble over trivia in order to turn this into a long and
pointlessly boring argument...
>From drafts of 2459 around 20 years ago until 5280 the spec said you shouldn't
use PKUP (3280 was even more strongly worded than the original 2459 text I
cited, "This extension SHOULD NOT be used within the Internet PKI"), and then
5280 removed mention of it. The majority of the PKI implementations I'm aware
of date from well before 5280, when the "don't use PKUP" was in force. That's
why I pointed out that support for it in implementations could be hard to
find.
Peter.
_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.