Re: RFC 5280 - Clarification on the Location where CRL URL should be Obtained

"Santosh Chokhani" <[email protected]> Wed, 28 Feb 2024 08:13:49 -0500
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
CRL URL needs to be obtained from the certificate or using other local means or doing LDAP lookup for the issuer DN in the certificate and obtaining proper attribute for the issuer DN LDAP entry.

 

CRL URL in issuer certificate will have pointer to the CRL to check the revocation status of the issuer certificate and NOT the subject certificate.

 

From: pkix [mailto:[email protected]] On Behalf Of Dhaura Pathirana
Sent: Wednesday, February 28, 2024 1:18 AM
To: [email protected]
Subject: [pkix] RFC 5280 - Clarification on the Location where CRL URL should be Obtained

 

Hi all,

 

Kindly requesting assistance in clarifying the location where CRL URL should be obtained in order to do CRL validation on a X509 certificate since it was not specifically clear in the specification [1]. 

1.	Should we extract the CRL URL from the certificate itself or from the issuer certificate associated with the validating certificate?
2.	Furthermore, if the default behavior is to obtain the CRL URL from the certificate itself and if the CRL URl is unavailable in the certificate itself, is it customary to obtain it from the issuer certificate?

Any assistance on these two questions would be greatly appreciated.

 

[1] - https://datatracker.ietf.org/doc/html/rfc5280

 

Thank you.

Kind regards,

Dhaura.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix