Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bound validity periods to 90 days. #383

Merged
merged 2 commits into from
Feb 8, 2019
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions draft-yasskin-http-origin-signed-responses.md
Original file line number Diff line number Diff line change
Expand Up @@ -961,6 +961,9 @@ able to make even one unauthorized signature.
Certificates with this extension MUST be revoked if an unauthorized entity is
able to make even one unauthorized signature.

Certificates with this extension MUST have a Validity Period no greater than 90
days.

Conforming CAs MUST NOT mark this extension as critical.

A conforming CA MUST NOT issue certificates with this extension unless, for each
Expand All @@ -987,6 +990,15 @@ extension. This OID might or might not be used as the final OID for the
extension, so certificates including it might need to be reissued once the final
RFC is published.

Some certificates have already been issued with this extension and with validity
periods longer than 90 days. These certificates will not immediately be treated
as invalid. Instead:

* Clients MUST reject certificates with this extension that were issued after
2019-05-01 and have a Validity Period longer than 90 days.
* After 2019-08-01, clients MUST reject all certificates with this extension
that have a Validity Period longer than 90 days.

### Extensions to the CAA Record: cansignhttpexchanges Parameter {#caa-cansignhttpexchanges}

A CAA parameter "cansignhttpexchanges" is defined for the "issue" and
Expand Down Expand Up @@ -2061,6 +2073,7 @@ draft-06
* Add a security consideration for future-dated OCSP responses and for stolen
private keys.
* Define a CAA parameter to opt into certificate issuance.
* Limit certificate lifetimes to 90 days.

draft-05

Expand Down