[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Certificate suspension
The U.S. Treasury does not support suspension mainly due to obvious
issues encountered with digital signature related transactions, and
future validation of those transactions. The problem is, if you are
willing to honor signatures produced using certificates from an
infrastructure that does support suspension, you wind up in the same
boat. It has been a topic of much debate.
Russ Housley wrote:
I have said many times that I wish we had deprecated certificate
suspension in RFC 2459 and all of its successors. As you say, it is
riddled with difficulties, and those have been discussed many times over
the years.
When we were working on RFC 2459 someone from the financial community
argued that it was needed. So, it was not deprecated. You can look at
the archives for the recurring discussion.
Russ
--
Regards,
Todd E. Johnson