Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider removing Subject Key Identifier from end-entity certificates #7446

Closed
aarongable opened this issue Apr 22, 2024 · 1 comment
Closed

Comments

@aarongable
Copy link
Contributor

Per the BRs, Section 7.1.2.7.6, the Subject Key Identifier extension is NOT RECOMMENDED for end-entity Subscriber certificates.

This is because the SKID is mostly useful for path-building. It's important for it to exist in issuer certificates, so that it can be matched to the AKID of certs that they issue. But no one is building a path up to an end-entity certificate, so in those the SKID is simply consuming bytes with no real purpose.

@aarongable
Copy link
Contributor Author

This will be done as part of our profiles work. Closing this bug as we have made our decision on how to approach this and it does not need to be tracked independently.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant