[pkix] review of draft-ietf-pkix-rfc2560bis-15

"Peter Rybar" <rybar@nbusr.sk> Tue, 02 April 2013 14:36 UTC

Return-Path: <prvs=08043c62bd=rybar@nbusr.sk>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A4C4421F8B04 for <pkix@ietfa.amsl.com>; Tue, 2 Apr 2013 07:36:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.906
X-Spam-Level: *
X-Spam-Status: No, score=1.906 tagged_above=-999 required=5 tests=[BAYES_50=0.001, HELO_EQ_SK=1.35, HOST_EQ_SK=0.555]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QOQjBQd1D3SA for <pkix@ietfa.amsl.com>; Tue, 2 Apr 2013 07:36:17 -0700 (PDT)
Received: from mail.nbusr.sk (mail.nbusr.sk [84.245.65.227]) by ietfa.amsl.com (Postfix) with ESMTP id 88B0C21F8A7E for <pkix@ietf.org>; Tue, 2 Apr 2013 07:36:15 -0700 (PDT)
Message-Id: <201304021436.r32EaC6i004048@mail.nbusr.sk>
From: Peter Rybar <rybar@nbusr.sk>
To: 'Stefan Santesson' <stefan@aaa-sec.com>, sts@aaa-sec.com
Date: Tue, 02 Apr 2013 16:36:11 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Office Outlook, Build 11.0.6353
Thread-Index: AQFaQn1rWGWmOJQLB6oJfMxBH8dluJmktKLggAAW9QCABgr9kA==
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
In-Reply-To: <8D3D17ACE214DC429325B2B98F3AE71293D36BC5@MX15A.corp.emc.com>
X-NAI-Spam-Flag: NO
X-NAI-Spam-Level: ***
X-NAI-Spam-Threshold: 6
X-NAI-Spam-Score: 3.6
X-NAI-Spam-Version: 2.3.0.9362 : core <4536> : streams <932583> : uri <1382886>
Cc: pkix@ietf.org
Subject: [pkix] review of draft-ietf-pkix-rfc2560bis-15
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Apr 2013 14:36:17 -0000

Stefan,

When revoked for "not-issued" is created by OCSP server then according to actual rfc2560bis is unclear, what must be included in thisUpdate and nextUpdate fields.
Rfc2560bis must also define rules for value of thisUpdate and nextUpdate fields.


RFC 2560:
   - thisUpdate: The time at which the status being indicated is known
                 to be correct
   - nextUpdate: The time at or before which newer information will be
                 available about the status of the certificate


Peter