Requesting information on Time stamp authority certificate expiry.
Anoop Gulati <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAEZbcisdn226uNoG4NVv8R3rGPz7A=2PVCPR7nRbiM7Zi-UBhw@mail.gmail.com> |
Hi Team, Happy 2018! I'm requesting some clarification on the status of a timestamped signature when the timestamp authority (TSA) certificate expires. My understanding is timestamp is applied to a digital signature to ensure the digital signature continues to stay valid past the lifetime of the signing certificate. RFC 3161, in section 4.3 briefly talks about TSA certificate lifetimes but it does not clarify the situation of a natural TSA certificate expiry. We recently experienced an enterprise-wide outage when java started to error out on a signed & timestamped jar file when the TSA certificate expired. Windows, on the other hand does not error out on signed & timestamped files on TSA certificate expiry. So, it seems like, even implementation between platforms is not consistent. Hence I'm writing to understand how expiry of a TSA certificate impacts existing signed and timestamped files. Sincere apologies in advance if this is not the right platform to discuss this, I was not able to find a working group specifically for digital timestamp & TSAs. Thanks, Anoop _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix