In the Applicability Statement for Secure Health Transport, it doesn't say
(in my reading) that you can't trust a certificate without a certificate
distribution point (aka a CRL).
See section 4.1.3: "STAs MAY by policy enforce either restriction (or any
other more restrictive policy) but need not. STAs MAY support any valid,
non-expired, non-revoked and trusted certificate."
direct-certifica...@googlecode.com
unread,
Nov 16, 2012, 3:16:30 PM11/16/12
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
Accorting to RFC 5280, A certificate without a CDP is considered to have a
CDP status of "UNDETERMINED". I would argue that a certificate missing a
CDP is *not* a non-revoked certificate and that I can't trust it. Googling
this issue, you'll find that most posts/documents agree these certificates
should be rejected.