Vittek Robert wrote:
I'd say that with it you *know* that you have the information or that you don't have it, so you quit the current state of uncertainty, and it's not just decreasing a probability.RFC 3280 states that: An entry MUST NOT be removed from the CRL until it appears on one regularly scheduled CRL issued beyond the revoked certificate's validity period. This CRL may be crucial for the validation process, hence I MUST NOT miss it. [...] The retention period may decrease the probability of missing revocation information of recently expired certificate to the acceptable limit.
It has been standardized in OCSP. It's the Archive Cutoff extension. RFC 2560/&4.4.4Has this been standardized already? In what RFC (or perhaps ETSI document)?
Not including an equivalent for CRL was an amazing oversight.I'm 100% for porting that extension from OCSP to 3280bis's CRL profile, the only question is if we keep the same OID, which would a bit illogical there : "id-pkix-ocsp 6"