Skip to content

Commit

Permalink
Add a SHOULD NOT in security considerations for using clientAuth/serv…
Browse files Browse the repository at this point in the history
…erAuth and imUri key purposes, per suggestion by Paul Wouters.
  • Loading branch information
Rohan Mahy committed Dec 9, 2024
1 parent 609a595 commit 19d1edb
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions draft-ietf-lamps-im-keyusage.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,10 @@ The Security Considerations of {{!RFC5280}} are applicable to this
document. This extended key purpose does not introduce new security
risks but instead reduces existing security risks by providing means
to identify if the certificate is generated to sign IM identity credentials.
Issuers SHOULD NOT set the `id-kp-imUri` extended key purpose and an
`id-kp-clientAuth` or `id-kp-serverAuth` extended key purpose, as that would
defeat the improved specificity offered by having an `id-kp-imUri` extended key
purpose.

# IANA Considerations

Expand Down

0 comments on commit 19d1edb

Please sign in to comment.