Based on a requirement from the IETF PKIX WG and their profile of X.509 public-key certificates, I've raised a new defect report on X.509 (DR 278). The DR proposes modifying the text of clause 8.4.2.6 (4th edition) to lift the restriction that the freshestCRL extension be ONLY a certificate extension. This change aligns with the PKIX use of freshestCRL as a CRL extension. The full DR can be obtained at:
ftp://ftp.bull.com/pub/OSIdirectory/DefectResolution/DefectReports/X.509andRelated/DR_278.pdf
Sharon