[x500standard] CRL version text

  • From: "Erik Andersen" <era@xxxxxxx>
  • To: "Directory list" <x500standard@xxxxxxxxxxxxx>, "SG17-Q11" <T13sg17q11@xxxxxxxxxxxxx>
  • Date: Thu, 17 Apr 2014 17:46:42 +0200

Hi Folks,

The version component of the certificate revocation list (7.10 of X.509) has
the following text:

"The version field shall indicate the version of the encoded revocation
list. If the extensions component flagged as critical is present in the
revocation list, the version shall be v2. If no extensions component flagged
as critical is present in the revocation list, the version shall either be
absent or present as v2."

It has a couple of problems:

The extensions component cannot be flagged critical, only included
extensions.

It is not clear what an absent version component means.

Any commnents?

 

 

Other related posts:

  • » [x500standard] CRL version text - Erik Andersen