logo       

CMP issue and question: msg#00199

ietf.x509

Subject: CMP issue and question

In draft-ietf-pkix-ipki3cmp-08.txt the "Direct TCP Management Protocol"
defines polling times to be an absolute time.
I think it would be better to make it a relative time. Less time skew
issues etc.

Also, if the CA issues a certificate that has a value specified (start
time, or some random extension) that the end entity
did not specify would that be considered Granted or GrantedWithMods. I can
argue either way.


Mike





<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise