Requesting information on Time stamp authority certificate expiry.

Anoop Gulati <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CAEZbcisdn226uNoG4NVv8R3rGPz7A=2PVCPR7nRbiM7Zi-UBhw@mail.gmail.com>
Hi Team,
Happy 2018!

I'm requesting some clarification on the status of a timestamped signature
when the timestamp authority (TSA) certificate expires.

My understanding is timestamp is applied to a digital signature to ensure
the digital signature continues to stay valid past the lifetime of the
signing certificate.
RFC 3161, in section 4.3 briefly talks about TSA certificate lifetimes but
it does not clarify the situation of a natural TSA certificate expiry.

We recently experienced an enterprise-wide outage when java started to
error out on a signed & timestamped jar file when the TSA certificate
expired.
Windows, on the other hand does not error out on signed & timestamped files
on TSA certificate expiry.

So, it seems like, even implementation between platforms is not consistent.
Hence I'm writing to understand how expiry of a TSA certificate impacts
existing signed and timestamped files.
Sincere apologies in advance if this is not the right platform to discuss
this, I was not able to find a working group specifically for digital
timestamp & TSAs.

Thanks,

Anoop

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.