Re: RFC 5280 - Clarification on the Location where CRL URL should be Obtained
Michael StJohns <[email protected]> Wed, 28 Feb 2024 12:56:50 -0500
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
To be more precise - See the CA provider's Certification of Practice - a template for one is here. https://www.ietf.org/rfc/rfc3647.txt A commercial CA will have something like this explaining the responses to your question _for the certificates issued by them._ BTW - this maining list is for protocol questions, and the yours evoke more a customer service type of question. In other words talk to your CA first. Later, Mike On 2/28/2024 8:13 AM, Santosh Chokhani wrote: > > CRL URL needs to be obtained from the certificate or using other local > means or doing LDAP lookup for the issuer DN in the certificate and > obtaining proper attribute for the issuer DN LDAP entry. > > CRL URL in issuer certificate will have pointer to the CRL to check > the revocation status of the issuer certificate and NOT the subject > certificate. > > *From:*pkix [mailto:[email protected]] *On Behalf Of *Dhaura Pathirana > *Sent:* Wednesday, February 28, 2024 1:18 AM > *To:* [email protected] > *Subject:* [pkix] RFC 5280 - Clarification on the Location where CRL > URL should be Obtained > > Hi all, > > Kindly requesting assistance in clarifying the location where CRL URL > should be obtained in order to do CRL validation on a X509 certificate > since it was not specifically clear in the specification [1]. > > 1. Should we extract the CRL URL from the certificate itself or from > the issuer certificate associated with the validating certificate? > 2. Furthermore, if the default behavior is to obtain the CRL URL from > the certificate itself and if the CRL URl is unavailable in the > certificate itself, is it customary to obtain it from the issuer > certificate? > > Any assistance on these two questions would be greatly appreciated. > > [1] - https://datatracker.ietf.org/doc/html/rfc5280 > > Thank you. > > Kind regards, > > Dhaura. > > > _______________________________________________ > pkix mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix