Skip to content

Improve resilient OCSP certificate revocation checker - #140

Open
madislm wants to merge 1 commit into
web-eid:v4from
madislm:AUT-2981
Open

madislm wants to merge 1 commit into
web-eid:v4from
madislm:AUT-2981

Conversation

@madislm

@madislm madislm commented Oct 2, 2026

Copy link
Copy Markdown

AUT-2981

Signed-off-by: Madis Jaagup Laurson <madisjaagup.laurson@nortal.com>

@madislm madislm changed the title Improve resilient OCSP certificate revocation checker- #138 Improve resilient OCSP certificate revocation checker Oct 5, 2026
@madislm
madislm force-pushed the AUT-2981 branch 4 times, most recently from 5a45d6d to 56d68ae Compare October 5, 2026 12:17
Signed-off-by: Madis Jaagup Laurson <madisjaagup.laurson@nortal.com>
public static void validateKeyUsageDigitalSignature(X509Certificate certificate) throws OCSPCertificateException {
Objects.requireNonNull(certificate, "certificate");
final boolean[] keyUsage = certificate.getKeyUsage();
if (keyUsage == null) {

@mrts mrts Oct 8, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should requiring the Key Usage extension be configurable?

RFC 6960 §4.2.2.2 requires the OCSP Signing EKU for delegated responders, but does not require a Key Usage extension. RFC 5280 §4.2.1.12 requires consistent usage when both extensions are present.

The existing SK OCSP responder certificate has the OCSP Signing EKU but no Key Usage extension. Making this requirement configurable would preserve compatibility with it while allowing integrators to enforce the stricter policy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants