Re: Optimizing OCSP - Time for some spec work ?
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
David A. Cooper <[email protected]> writes: >I also don't see how this "I've checked the entire chain from the cert you >requested all the way up to the root. You're welcome" extension would work. See my previous message, it's not meant to be perfect, just an improvement on current usage. In particular: >Consider a scenario in which a CA's private key had been compromised, and its >certificate had been revoked. In that case the browser vendors [0 again, from the previous message] push out an emergency update because they don't trust revocation checking to get the job done. So it really depends on the usage scenario. If you can make it better than the current mess, that's at least some progress. Peter. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix