Re: Question about RFC 7030 - Enrollment over Secure Transport

"Peter Yee" <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
James,

 

                I consulted my co-authors. While none of us have a strong recollection of our discussions on this point, our feeling is that to make that statement a MUST would be inconsistent with how many CAs are deployed. Specifically, CA support of rollover is not mandatory. And since there’s a fallback mechanism (manual bootstrap), clients do have the ability to get new CA certs, albeit with a certain amount of effort. Whether CA’s should be required to support rollover is a different question.

 

                                -Peter

 

From: pkix [mailto:[email protected]] On Behalf Of Reilly James
Sent: Friday, May 22, 2020 3:55 AM
To: [email protected]
Subject: [pkix] Question about RFC 7030 - Enrollment over Secure Transport

 

Hello

 

We are looking at RFC 7030 – Enrollment over Secure Transport.

 

Is there a reason or thought process in section ‘4.1.3 CA Certificates Response’

   ‘The EST server SHOULD include the three "Root CA Key Update"

   certificates OldWithOld, OldWithNew, and NewWithOld in the response

   chain.  These are defined in Section 4.4 of CMP [RFC4210].’

 

why SHOULD rather than example MUST was used in the specification by the authors?

James

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.