You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please update the EV Checker to allow for the intermediate certificates in the chain to not contain an OCSP responder URL in the authorityInformationAccess field. The CA/Browser Forum Baseline Requirements changed this from a MUST to a SHOULD.
Instead of checking for OCSP at the intermediate certificate level, please have the EV Checker verify that the cRLDistributionPoints field in the intermediate certificates do contain an HTTP URL, as required by the BRs.
The text was updated successfully, but these errors were encountered:
Update: The certificate chains for the test websites in Bugzilla #1717711 were updated so that the intermediate certificates also have the OCSP URI in the AIA, so they can no longer be used for testing resolution for this issue.
WilsonKathleen
changed the title
EV Checker -- BRs no longer require OCSP URI in the AIA
EV Checker -- BRs no longer require OCSP URI in the AIA of intermediate certificates
Jun 15, 2022
WilsonKathleen
changed the title
EV Checker -- BRs no longer require OCSP URI in the AIA of intermediate certificates
EV Checker: BRs no longer require OCSP URI in the AIA of intermediate certificates
Jun 15, 2022
Please update the EV Checker to allow for the intermediate certificates in the chain to not contain an OCSP responder URL in the authorityInformationAccess field. The CA/Browser Forum Baseline Requirements changed this from a MUST to a SHOULD.
Instead of checking for OCSP at the intermediate certificate level, please have the EV Checker verify that the cRLDistributionPoints field in the intermediate certificates do contain an HTTP URL, as required by the BRs.
The text was updated successfully, but these errors were encountered: