Re: Authorised responders OCSP and id-kp-OCSPSigning

Joel Kazin <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
I agree.

On 2/28/2021 2:27 PM, Stefan Santesson wrote:
>
> Came across this question on OCSP where I wander how various 
> implementers chose to interpret the requirements.
>
> And shamefully I can’t recall how we thought when we published this.
>
> The text says that a CA can choose to either:
>
>   * Sign the OCSP response itself, or
>   * Explicitly delegate OCSP signing to another entity
>
> It then states that delegation SHALL be indicated by inclusion of the 
> id-kp-OCSPSigning extended key usage
>
> So, as I read this, the id-kp-OCSPSigning extended key usage is NOT 
> required if the CA issues OCSP responses itself using the same key as 
> was used to sign the certificate.
>
> This because there is no delegation taking place.
>
> So I wander:
>
>  1. Do people here agree with my interpretation
>  2. Do implementations in general agree with this interpretation, or
>     do they all enforce id-kp-OCSPSigning always?
>
> Stefan Santesson
>
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.