Re: Authorised responders OCSP and id-kp-OCSPSigning
Joel Kazin <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
I agree. On 2/28/2021 2:27 PM, Stefan Santesson wrote: > > Came across this question on OCSP where I wander how various > implementers chose to interpret the requirements. > > And shamefully I can’t recall how we thought when we published this. > > The text says that a CA can choose to either: > > * Sign the OCSP response itself, or > * Explicitly delegate OCSP signing to another entity > > It then states that delegation SHALL be indicated by inclusion of the > id-kp-OCSPSigning extended key usage > > So, as I read this, the id-kp-OCSPSigning extended key usage is NOT > required if the CA issues OCSP responses itself using the same key as > was used to sign the certificate. > > This because there is no delegation taking place. > > So I wander: > > 1. Do people here agree with my interpretation > 2. Do implementations in general agree with this interpretation, or > do they all enforce id-kp-OCSPSigning always? > > Stefan Santesson > > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix