[cabfpub] Profiling OCSP & CRLs

Peter Bowen pzb at amzn.com
Mon Jul 10 13:53:59 MST 2017


> On Jul 10, 2017, at 1:47 PM, Jeremy Rowley via Public <public at cabforum.org> wrote:
> 
> A shorter validity period for responders isn’t painful, but could we have a looser interpretation on hardware?  What if delegated responder certs were stored in FIPS 140-2 Level 2 if they were short periods?  

I think this is very reasonable, especially given that many other PKIs use Level 2 for issuing CAs.

Thanks,
Peter
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cabforum.org/pipermail/public/attachments/20170710/6f58aa9e/attachment.html>


More information about the Public mailing list