RFC 5280 - Clarification on the Location where CRL URL should be Obtained
Dhaura Pathirana <[email protected]> Wed, 28 Feb 2024 11:47:33 +0530
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAL4nJSYSJtgKPBmk+LGwYaeyk34i7CRibQ3qnLiNtaLUkVLiSg@mail.gmail.com> |
Hi all, Kindly requesting assistance in clarifying the location where CRL URL should be obtained in order to do CRL validation on a X509 certificate since it was not specifically clear in the specification [1]. 1. Should we extract the CRL URL from the certificate itself or from the issuer certificate associated with the validating certificate? 2. Furthermore, if the default behavior is to obtain the CRL URL from the certificate itself and if the CRL URl is unavailable in the certificate itself, is it customary to obtain it from the issuer certificate? Any assistance on these two questions would be greatly appreciated. [1] - https://datatracker.ietf.org/doc/html/rfc5280 Thank you. Kind regards, Dhaura. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix