Re: RFC 5280 - Clarification on the Location where CRL URL should be Obtained
"Santosh Chokhani" <[email protected]> Wed, 28 Feb 2024 08:13:49 -0500
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
CRL URL needs to be obtained from the certificate or using other local means or doing LDAP lookup for the issuer DN in the certificate and obtaining proper attribute for the issuer DN LDAP entry. CRL URL in issuer certificate will have pointer to the CRL to check the revocation status of the issuer certificate and NOT the subject certificate. From: pkix [mailto:[email protected]] On Behalf Of Dhaura Pathirana Sent: Wednesday, February 28, 2024 1:18 AM To: [email protected] Subject: [pkix] RFC 5280 - Clarification on the Location where CRL URL should be Obtained Hi all, Kindly requesting assistance in clarifying the location where CRL URL should be obtained in order to do CRL validation on a X509 certificate since it was not specifically clear in the specification [1]. 1. Should we extract the CRL URL from the certificate itself or from the issuer certificate associated with the validating certificate? 2. Furthermore, if the default behavior is to obtain the CRL URL from the certificate itself and if the CRL URl is unavailable in the certificate itself, is it customary to obtain it from the issuer certificate? Any assistance on these two questions would be greatly appreciated. [1] - https://datatracker.ietf.org/doc/html/rfc5280 Thank you. Kind regards, Dhaura. _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix