Re: RFC 5280 - Clarification on the Location where CRL URL should be Obtained
Dhaura Pathirana <[email protected]> Thu, 29 Feb 2024 10:14:05 +0530
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAL4nJSYFt-7cjEqwD3j6p2z1z_OeDqjdnJWjF_x+WppEVSu7xQ@mail.gmail.com> |
Hi all, Thank you very much for your quick responses. Kind regards, Dhaura. On Wed, 28 Feb 2024 at 18:43, Santosh Chokhani <[email protected]> wrote: > CRL URL needs to be obtained from the certificate or using other local > means or doing LDAP lookup for the issuer DN in the certificate and > obtaining proper attribute for the issuer DN LDAP entry. > > > > CRL URL in issuer certificate will have pointer to the CRL to check the > revocation status of the issuer certificate and NOT the subject certificate. > > > > *From:* pkix [mailto:[email protected]] *On Behalf Of *Dhaura > Pathirana > *Sent:* Wednesday, February 28, 2024 1:18 AM > *To:* [email protected] > *Subject:* [pkix] RFC 5280 - Clarification on the Location where CRL URL > should be Obtained > > > > Hi all, > > > > Kindly requesting assistance in clarifying the location where CRL URL > should be obtained in order to do CRL validation on a X509 certificate > since it was not specifically clear in the specification [1]. > > 1. Should we extract the CRL URL from the certificate itself or from > the issuer certificate associated with the validating certificate? > 2. Furthermore, if the default behavior is to obtain the CRL URL from > the certificate itself and if the CRL URl is unavailable in the certificate > itself, is it customary to obtain it from the issuer certificate? > > Any assistance on these two questions would be greatly appreciated. > > > > [1] - https://datatracker.ietf.org/doc/html/rfc5280 > > > > Thank you. > > Kind regards, > > Dhaura. > _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix