CRL in DSig interop test set
Ari Kermaier <[email protected]>
| Newsgroups | gmane.ietf.xmldsig |
|---|---|
| Message-ID | <[email protected]> |
Dear All, In the new interop test set, merlin-xmldsig-twenty-three, there is one test signature that troubles me a little. The one called signature-x509-crt-crl.xml implies signature validation processing that isn't really described by the specification. It's all well and good that the X509Data element can be used to transport a CRL. However, actually using the CRL should be part of certificate path validation, rather than signature validation per se. I mean, we might as well be testing whether DSig implementations can correctly parse an AuthorityInfoAccess extension in the certificate and execute an OCSP lookup based on the contents. So, IMHO, deciding to check a certificate against a CRL is application-specific functionality that shouldn't really be introduced into interop testing for the DSig spec in general. Cheers, Ari Ari Kermaier [email protected] Senior Software Engineer Phaos Technology Corp. http://www.phaos.com/