[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CA=True for an OCSP certficat




Stephen Kent wrote:
I was not looking at the validation algorithm, but rather at our definitions of extensions. I think it is very unfortunate to have a mismatch between the two, as you describe.

What do others think?
I think the mismatch between the two is by design : Be lenient in what you accept, strict in what you produce.

The validation algorithm defines what RFC 3280 accepts, the rest of the text what it produces, and it would be good to write this explicitly somewhere so that there's no confusion. Especially this mean the validation algorithm should not be used a reference text to help define the certificate format of RFC 3280.