Authorised responders OCSP and id-kp-OCSPSigning
Stefan Santesson <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Came across this question on OCSP where I wander how various implementers chose to interpret the requirements. And shamefully I can’t recall how we thought when we published this. The text says that a CA can choose to either: Sign the OCSP response itself, or Explicitly delegate OCSP signing to another entity It then states that delegation SHALL be indicated by inclusion of the id-kp-OCSPSigning extended key usage So, as I read this, the id-kp-OCSPSigning extended key usage is NOT required if the CA issues OCSP responses itself using the same key as was used to sign the certificate. This because there is no delegation taking place. So I wander: Do people here agree with my interpretation Do implementations in general agree with this interpretation, or do they all enforce id-kp-OCSPSigning always? Stefan Santesson _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix