Skip to content

SC-XXX: Set presence of id-ad-caIssuers and AIA extension to MAY for Subscriber Certificates.#665

Open
e3n0 wants to merge 4 commits intocabforum:mainfrom
e3n0:aia
Open

SC-XXX: Set presence of id-ad-caIssuers and AIA extension to MAY for Subscriber Certificates.#665
e3n0 wants to merge 4 commits intocabforum:mainfrom
e3n0:aia

Conversation

@e3n0
Copy link
Copy Markdown

@e3n0 e3n0 commented May 6, 2026

Since clients can build chains using either AKID/SKID matching or Issuer/Subject matching, and TLS servers typically serve a chain sufficient for verifying the Subscriber Certificate, id-ad-caIssuers is unnecessary for typical TLS cert use cases.

This ballot proposes marking id-ad-caIssuers MAY instead of SHOULD for Subscriber Certificates in 7.1.2.7.7 and, since id-ad-ocsp is also MAY in the BRs, proposes marking the AIA extension MAY instead of MUST for Subscriber Certificates.

@e3n0 e3n0 requested a review from a team as a code owner May 6, 2026 20:01
@e3n0 e3n0 changed the title SC-XXX: Set presence of id-ad-caIssuers and AIA extension to MAY. SC-XXX: Set presence of id-ad-caIssuers and AIA extension to MAY for Subscriber Certificates. May 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant