Re: Optimizing OCSP - Time for some spec work ?

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Kurt Roeckx <[email protected]> writes:

>I don't see how that can work if you're not allowed to return good for a 
>non-issued certificate 

RFC 6960 says:

   The "good" state indicates a positive response to the status inquiry.  
   At a minimum, this positive response indicates that no certificate
   with the requested certificate serial number currently within its
   validity interval is revoked.  This state does not necessarily mean
   that the certificate was ever issued or that the time at which the
   response was produced is within the certificate's validity interval.

So you're explicitly permitted to return "good" for a non-issued certificate.
   
>and that the serial numbers should be random.

How would the way serial numbers are generated affect things?  In other
words, to reverse your comment, how would it *not* work with random serial
numbers?

Peter.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.