Authorised responders OCSP and id-kp-OCSPSigning

Stefan Santesson <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Came across this question on OCSP where I wander how various implementers chose to interpret the requirements.

And shamefully I can’t recall how we thought when we published this.

 

The text says that a CA can choose to either:

 
Sign the OCSP response itself, or
Explicitly delegate OCSP signing to another entity
 

It then states that delegation SHALL be indicated by inclusion of the id-kp-OCSPSigning extended key usage

 

So, as I read this, the id-kp-OCSPSigning extended key usage is NOT required if the CA issues OCSP responses itself using the same key as was used to sign the certificate.

This because there is no delegation taking place.

 

So I wander:

 
Do people here agree with my interpretation
Do implementations in general agree with this interpretation, or do they all enforce id-kp-OCSPSigning always?
 

 

Stefan Santesson

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.