Re: Optimizing OCSP - Time for some spec work ?
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Kurt Roeckx <[email protected]> writes: >I don't see how that can work if you're not allowed to return good for a >non-issued certificate RFC 6960 says: The "good" state indicates a positive response to the status inquiry. At a minimum, this positive response indicates that no certificate with the requested certificate serial number currently within its validity interval is revoked. This state does not necessarily mean that the certificate was ever issued or that the time at which the response was produced is within the certificate's validity interval. So you're explicitly permitted to return "good" for a non-issued certificate. >and that the serial numbers should be random. How would the way serial numbers are generated affect things? In other words, to reverse your comment, how would it *not* work with random serial numbers? Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix