2 Feb 2010 02:33
OCSP Trusted Responder
Sean Mullan <Sean.Mullan <at> Sun.COM>
2010-02-02 01:33:26 GMT
2010-02-02 01:33:26 GMT
I have a question about OCSP Trusted Responders and how they are
validated. RFC 2560 defines a Trusted Responder as:
-- a Trusted Responder whose public key is trusted by the requester
Is there any requirement that an implementation automatically trust a
responder's public key if its certificate is directly issued by a root
CA and the intermediate CA that issued the certificate being checked
chains back to the same root CA?
It would seem that this case would still require some sort of additional
local configuration to designate the responder's certificate as trusted.
Thanks,
Sean
_______________________________________________
pkix mailing list
pkix <at> ietf.org
https://www.ietf.org/mailman/listinfo/pkix
RSS Feed