Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Profile History/Version support #25

Open
grandamp opened this issue Oct 24, 2017 · 3 comments
Open

Profile History/Version support #25

grandamp opened this issue Oct 24, 2017 · 3 comments

Comments

@grandamp
Copy link
Collaborator

Depending on the date of issuance, a sample certificate may conform to a prior version of a certificate profile.

Will older certificates be measured against the current profile, or the profile in effect the date of issuance?

@djpackham
Copy link
Contributor

@grandamp

  • FYI, we are developing the certificate profile templates in a way that it will be quick and easy to spin up new profiles as needed.
  • The more I think about it, the more it sounds like a good idea to include the logic to automatically compare the presented certificate against the profile that was in effect the date of issuance.

@mttcpr
Copy link
Contributor

mttcpr commented Nov 6, 2017

@djpackham
My understanding is this tool was supposed to be for checking conformance with FPKI profiles so submitted cert samples are more likely to pass review. I'd think automatically comparing a cert to an old version of the policy that no longer applies would be undesirable given that intent. If anything I think this should be a manual selection that always defaults to current.

@grandamp
What I think you're talking about here in combination with #24 is a tool for determining if millions of certs issued a year or more ago conformed at the time they were issued even though they may not now. While I could see that might yield some interesting output, is there a requirement for this kind of audit?

@mttcpr
Copy link
Contributor

mttcpr commented Nov 21, 2017

I added profile info to the configuration file to facilitate display of profile version/date, possibly for selection UI. Don't plan to move the needle on this more until things are more done..

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants