3 Feb 2011 19:22
Guidelines for Need for CRL/OCSP?
Henry B. Hotz <hotz <at> jpl.nasa.gov>
2011-02-03 18:22:29 GMT
2011-02-03 18:22:29 GMT
If your certificates are always issued with really short lifetimes (a few hours) it makes no sense to incur the deployment overhead of maintaining CRL/OCSP infrastructure. OTOH if they have lifetimes of a year or more, it seems foolish not to. Is there any recommended policy covering this? Any recommended crossover point that could be referenced in another specification? ------------------------------------------------------ The opinions expressed in this message are mine, not those of Caltech, JPL, NASA, or the US Government. Henry.B.Hotz <at> jpl.nasa.gov, or hbhotz <at> oxy.edu _______________________________________________ pkix mailing list pkix <at> ietf.org https://www.ietf.org/mailman/listinfo/pkix
-----------------------
Pierre Pavlenyi, P.Eng
Identity Management Architect
ppavlenyi <at> carillon.ca
The opinions expressed here are strictly my own, and do not represent those of any other party.
On 2011-02-03, at 1:24 PM, Sean Turner wrote:
> Start using OCSP as soon as your CRL might be bigger than an OCSP response ;)
>
> spt
RSS Feed