Re: Requesting information on Time stamp authority certificate expiry.
Jim Schaad <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
> -----Original Message----- > From: Peter Gutmann [mailto:[email protected]] > Sent: Friday, January 5, 2018 6:27 PM > To: Jim Schaad <[email protected]>; 'Anoop Gulati' > <[email protected]>; [email protected] > Subject: Re: [pkix] Requesting information on Time stamp authority > certificate expiry. > > Jim Schaad <[email protected]> writes: > > >The correct rule ought to be, when the TSA certificate expires the > >signature expires and it no longer tells you anything more. > > Just because the cert has expired doesn't mean the signature automatically > invalidates itself. The TSA countersig still tells you that the signed item was > OK at time X, if you securely store a copy of it after the expiry time (or > countersign it yourself, or whatever) you can refer back to your known-good > copy to check that it's still OK. I was referring to the TSA signature not the original signature. On a new copy you cannot assume anything. I agree that if you securely store the item while it was originally good then you can still make some assumptions about it still being the same as it originally was. > > It's really an ecumenical matt^H^H^Hpolicy issue as to how you manage this. > > Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix