1 Apr 2007 17:46
Re: netscape-cert-renewal-url & beyond
Russ Housley <housley <at> vigilsec.com>
2007-04-01 15:46:41 GMT
2007-04-01 15:46:41 GMT
Such an extension is suitable for publication as an informational RFC, unless change control is released to the IETF, in which case a standards-track RFC is possible if there is sufficient interest. That said, it does nothing to help a relying party. It helps the subject of the certificate, but this same information could be provided to the subject when the certificate is issued without burdening all of the parties that make use of the certificate. Russ At 02:32 AM 3/31/2007, Anders Rundgren wrote: >Although the "netscape-cert-renewal-url" certificate extension does >not appear to be incorporated in any PKIX RFC, it is anyway >documented in vendor specs like: >http://msdn2.microsoft.com/en-us/library/aa378149.aspx > >I have two open questions regarding this particular extension: > >1. Is it supported by any PKI-clients and if so which ones? > >2. If it is not already supported on major scale wouldn't it be >worthwhile supporting such a facility? My personal experience >with certificates (I have had numerous), is that they tend to silently >expire, leaving you high and dry and concluding that "passwords are >better". When you have to "renew" from scratch you are thrown >into laborious processes which can take weeks to perform. > >If you have certificate and key in a connected device(Continue reading)
RSS Feed