Simon Josefsson | 3 Aug 2012 11:09
Favicon
Gravatar

OCSP algorithm agility: criticality?

All,

For the RFC2560 update, I reviewed the text copied from RFC 6277 and
noticed that it is silent on whether the client extension should or
could be marked as critical or not.

Is there some guidance on what a client should specify?  Is this
something that an implementer can chose, or should this be something an
administrator or user should be able to specify?

I'm guessing that in most situations you would want the extension
non-critical, but I wouldn't rule out situations where the client would
want to require the OCSP responder to support this extension.  Does that
reflect what others believe?

And finally, does any of these considerations belong in 2560bis?

/Simon
_______________________________________________
pkix mailing list
pkix <at> ietf.org
https://www.ietf.org/mailman/listinfo/pkix


Gmane