[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Certificate suspension




If you browse the archives of this mailing list, you will find in late November and early December of 2007 a discussion of "on-hold certificates in CRLs"

Most appear to share your sentiments about suspension, but apparently there are some regulatory requirements that are satisfied by the possibility of suspension.

Yoav

On Jan 23, 2008, at 3:49 AM, Stephen Wilson wrote:



I'm wondering to what extent is X.509 certificate suspension used in practice?

Most if not all publicly visible CPs describe suspension, in almost exactly the same way as they do revocation. Yet in my experience, I cannot ever recall a commercial CA or a closed/vertical PKI actually doing suspensions.

To my mind, suspension is riddled with difficulties, not anticipated by the way CRLs work. I could go into my concerns in a separate e- mail. But if anyone can point to suspension being offered in practice (or failing that, a critique of suspension) that would be appreciated!

Thanks in advance.

Cheers,

Stephen Wilson