Re: Question about RFC 7030 - Enrollment over Secure Transport
"Peter Yee" <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
James,
I consulted my co-authors. While none of us have a strong recollection of our discussions on this point, our feeling is that to make that statement a MUST would be inconsistent with how many CAs are deployed. Specifically, CA support of rollover is not mandatory. And since there’s a fallback mechanism (manual bootstrap), clients do have the ability to get new CA certs, albeit with a certain amount of effort. Whether CA’s should be required to support rollover is a different question.
-Peter
From: pkix [mailto:[email protected]] On Behalf Of Reilly James
Sent: Friday, May 22, 2020 3:55 AM
To: [email protected]
Subject: [pkix] Question about RFC 7030 - Enrollment over Secure Transport
Hello
We are looking at RFC 7030 – Enrollment over Secure Transport.
Is there a reason or thought process in section ‘4.1.3 CA Certificates Response’
‘The EST server SHOULD include the three "Root CA Key Update"
certificates OldWithOld, OldWithNew, and NewWithOld in the response
chain. These are defined in Section 4.4 of CMP [RFC4210].’
why SHOULD rather than example MUST was used in the specification by the authors?
James
_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix