Re: [IPsec] CRL checking when selecting a certifcate

2009-09-04 Thread Tero Kivinen
David Wierbowski writes: > > Tero, thanks for the comments and the clarification on how to read a lower > case must. I do have a few more comments. > > >So implementations cannot just search uppercase "MUST/SHOULD/MAY" > >texts and assume it is enough to make sure those are correct. It also > >n

Re: [IPsec] CRL checking when selecting a certifcate

2009-09-03 Thread David Wierbowski
Tero, thanks for the comments and the clarification on how to read a lower case must. I do have a few more comments. >So implementations cannot just search uppercase "MUST/SHOULD/MAY" >texts and assume it is enough to make sure those are correct. It also >needs to do what the text says... > I th

[IPsec] CRL checking when selecting a certifcate

2009-09-03 Thread Tero Kivinen
David Wierbowski writes: > > In a recent append Tero said: > > >Then the responder is already going against the RFC4306 which says > >"Certificate revocation checking must be considered during the > >chaining process used to select a certificate. " meaning the responder > >cannot send certifiate

[IPsec] CRL checking when selecting a certifcate

2009-09-02 Thread David Wierbowski
In a recent append Tero said: >Then the responder is already going against the RFC4306 which says >"Certificate revocation checking must be considered during the >chaining process used to select a certificate. " meaning the responder >cannot send certifiate which itself considers revoced. Only ca