[TLS] Security of CertificateStatus?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[TLS] Security of CertificateStatus?



I am concerned about the CertificateStatus extension.
It only allows for one OCSP response which is the
validity of the server's certificate.  The problem I
see is that most certificate chains have intermediate
CA's and their status should also be checked by the
client.

I'm not too familiar with OCSP yet, so am I missing
something?  Does the OCSP response contain the
validity of an entire certificate chain?

Thanks,

Mike

_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.