Re: RFC 5280 - Clarification on the Location where CRL URL should be Obtained

Dhaura Pathirana <[email protected]> Thu, 29 Feb 2024 10:14:05 +0530
Newsgroups gmane.ietf.x509
Message-ID <CAL4nJSYFt-7cjEqwD3j6p2z1z_OeDqjdnJWjF_x+WppEVSu7xQ@mail.gmail.com>
Hi all,

Thank you very much for your quick responses.

Kind regards,
Dhaura.

On Wed, 28 Feb 2024 at 18:43, Santosh Chokhani <[email protected]>
wrote:

> CRL URL needs to be obtained from the certificate or using other local
> means or doing LDAP lookup for the issuer DN in the certificate and
> obtaining proper attribute for the issuer DN LDAP entry.
>
>
>
> CRL URL in issuer certificate will have pointer to the CRL to check the
> revocation status of the issuer certificate and NOT the subject certificate.
>
>
>
> *From:* pkix [mailto:[email protected]] *On Behalf Of *Dhaura
> Pathirana
> *Sent:* Wednesday, February 28, 2024 1:18 AM
> *To:* [email protected]
> *Subject:* [pkix] RFC 5280 - Clarification on the Location where CRL URL
> should be Obtained
>
>
>
> Hi all,
>
>
>
> Kindly requesting assistance in clarifying the location where CRL URL
> should be obtained in order to do CRL validation on a X509 certificate
> since it was not specifically clear in the specification [1].
>
>    1. Should we extract the CRL URL from the certificate itself or from
>    the issuer certificate associated with the validating certificate?
>    2. Furthermore, if the default behavior is to obtain the CRL URL from
>    the certificate itself and if the CRL URl is unavailable in the certificate
>    itself, is it customary to obtain it from the issuer certificate?
>
> Any assistance on these two questions would be greatly appreciated.
>
>
>
> [1] - https://datatracker.ietf.org/doc/html/rfc5280
>
>
>
> Thank you.
>
> Kind regards,
>
> Dhaura.
>

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix