cabforum / code-signing

Repository for the CA/Browser Forum Code Signing Certificate Chartered Working Group
https://cabforum.org/code-signing-working-group/
21 stars 10 forks source link

Update requirements around OCSP for expired certificates #21

Open XolphinMartijn opened 1 year ago

XolphinMartijn commented 1 year ago

4.9.10 currently reads:

... CAs MAY provide OCSP responses for Code Signing Certificates and Timestamp Certificates for the time period specified in their CPS, which MAY be at least 10 years after the expiration of the certificate. ...

This seems to specify that CAs MAY keep OCSP responses for up to 10 years after expiration. However, for CRL, this is a MUST. Do we need cleanup /clarification of this language?