CRL in DSig interop test set

Ari Kermaier <[email protected]>
Newsgroups gmane.ietf.xmldsig
Message-ID <[email protected]>
Dear All,

In the new interop test set, merlin-xmldsig-twenty-three, there is one test 
signature that troubles me a little. The one called 
signature-x509-crt-crl.xml implies signature validation processing that 
isn't really described by the specification. It's all well and good that 
the X509Data element can be used to transport a CRL. However, actually 
using the CRL should be part of certificate path validation, rather than 
signature validation per se. I mean, we might as well be testing whether 
DSig implementations can correctly parse an AuthorityInfoAccess extension 
in the certificate and execute an OCSP lookup based on the contents. So, 
IMHO, deciding to check a certificate against a CRL is application-specific 
functionality that shouldn't really be introduced into interop testing for 
the DSig spec in general.

Cheers,

Ari


Ari Kermaier    [email protected]
Senior Software Engineer
Phaos Technology Corp.    http://www.phaos.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.