RFC 5280 - Clarification on the Location where CRL URL should be Obtained

Dhaura Pathirana <[email protected]> Wed, 28 Feb 2024 11:47:33 +0530
Newsgroups gmane.ietf.x509
Message-ID <CAL4nJSYSJtgKPBmk+LGwYaeyk34i7CRibQ3qnLiNtaLUkVLiSg@mail.gmail.com>
Hi all,

Kindly requesting assistance in clarifying the location where CRL URL
should be obtained in order to do CRL validation on a X509 certificate
since it was not specifically clear in the specification [1].

   1. Should we extract the CRL URL from the certificate itself or from the
   issuer certificate associated with the validating certificate?
   2. Furthermore, if the default behavior is to obtain the CRL URL from
   the certificate itself and if the CRL URl is unavailable in the certificate
   itself, is it customary to obtain it from the issuer certificate?

Any assistance on these two questions would be greatly appreciated.

[1] - https://datatracker.ietf.org/doc/html/rfc5280

Thank you.
Kind regards,
Dhaura.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix