RFC 2632 (rfc2632) - Page 3 of 13


S/MIME Version 3 Certificate Handling



Alternative Format: Original Text Document

< Previous
Next >


RFC 2632         S/MIME Version 3 Certificate Handling         June 1999


2. CMS Options

   The CMS message format allows for a wide variety of options in
   content and algorithm support. This section puts forth a number of
   support requirements and recommendations in order to achieve a base
   level of interoperability among all S/MIME implementations. Most of
   the CMS format for S/MIME messages is defined in [SMIME-MSG].

2.1 CertificateRevocationLists

   Receiving agents MUST support the Certificate Revocation List (CRL)
   format defined in [KEYM]. If sending agents include CRLs in outgoing
   messages, the CRL format defined in [KEYM] MUST be used.

   All agents MUST be capable of performing revocation checks using CRLs
   as specified in [KEYM]. All agents MUST perform revocation status
   checking in accordance with [KEYM]. Receiving agents MUST recognize
   CRLs in received S/MIME messages.

   Agents SHOULD store CRLs received in messages for use in processing
   later messages.

   Agents MUST handle multiple valid Certificate Authority (CA)
   certificates containing the same subject name and the same public
   keys but with overlapping validity intervals.

2.2 CertificateChoices

   Receiving agents MUST support PKIX v1 and PKIX v3 certificates. See
   [KEYM] for details about the profile for certificate formats. End
   entity certificates MAY include an Internet mail address, as
   described in section 3.1.

   Receiving agents SHOULD support X.509 attribute certificates.

2.2.1 Historical Note About CMS Certificates

   The CMS message format supports a choice of certificate formats for
   public key content types: PKIX, PKCS #6 Extended Certificates and
   X.509 Attribute Certificates. The PKCS #6 format is not in widespread
   use. In addition, PKIX certificate extensions address much of the
   same functionality and flexibility as was intended in the PKCS #6.
   Thus, sending and receiving agents MUST NOT use PKCS #6 extended
   certificates.







Ramsdell                    Standards Track


< Previous
Next >


Web Standards & Support:

Link to and support eLook.org Powered by LoadedWeb Web Hosting
Valid XHTML 1.0! Valid CSS! eLook.org FireFox Extensions