[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Certificate suspension
The U.S. Treasury PKI does not support suspension mainly due to obvious
issues encountered with digital signature related transactions, and
future validation of those transactions.
The problem is, if you are willing to honor signatures produced using
certificates from an infrastructure that does support suspension, you
wind up in the same boat. It has been a topic of much debate.
Russ Housley wrote:
I have said many times that I wish we had deprecated certificate
suspension in RFC 2459 and all of its successors. As you say, it is
riddled with difficulties, and those have been discussed many times over
the years.
When we were working on RFC 2459 someone from the financial community
argued that it was needed. So, it was not deprecated. You can look at
the archives for the recurring discussion.
Russ
--
Regards,
Todd E. Johnson