|
1051 | 1051 | </tr></thead> |
1052 | 1052 | <tfoot><tr> |
1053 | 1053 | <td class="left">Benjamin, et al.</td> |
1054 | | -<td class="center">Expires 25 December 2026</td> |
| 1054 | +<td class="center">Expires 26 December 2026</td> |
1055 | 1055 | <td class="right">[Page]</td> |
1056 | 1056 | </tr></tfoot> |
1057 | 1057 | </table> |
|
1064 | 1064 | <dd class="internet-draft">draft-ietf-plants-merkle-tree-certs-latest</dd> |
1065 | 1065 | <dt class="label-published">Published:</dt> |
1066 | 1066 | <dd class="published"> |
1067 | | -<time datetime="2026-06-23" class="published">23 June 2026</time> |
| 1067 | +<time datetime="2026-06-24" class="published">24 June 2026</time> |
1068 | 1068 | </dd> |
1069 | 1069 | <dt class="label-intended-status">Intended Status:</dt> |
1070 | 1070 | <dd class="intended-status">Standards Track</dd> |
1071 | 1071 | <dt class="label-expires">Expires:</dt> |
1072 | | -<dd class="expires"><time datetime="2026-12-25">25 December 2026</time></dd> |
| 1072 | +<dd class="expires"><time datetime="2026-12-26">26 December 2026</time></dd> |
1073 | 1073 | <dt class="label-authors">Authors:</dt> |
1074 | 1074 | <dd class="authors"> |
1075 | 1075 | <div class="author"> |
@@ -1135,7 +1135,7 @@ <h2 id="name-status-of-this-memo"> |
1135 | 1135 | time. It is inappropriate to use Internet-Drafts as reference |
1136 | 1136 | material or to cite them other than as "work in progress."<a href="#section-boilerplate.1-3" class="pilcrow">¶</a></p> |
1137 | 1137 | <p id="section-boilerplate.1-4"> |
1138 | | - This Internet-Draft will expire on 25 December 2026.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
| 1138 | + This Internet-Draft will expire on 26 December 2026.<a href="#section-boilerplate.1-4" class="pilcrow">¶</a></p> |
1139 | 1139 | </section> |
1140 | 1140 | </div> |
1141 | 1141 | <div id="copyright"> |
@@ -5264,10 +5264,10 @@ <h4 id="name-log-failures"> |
5264 | 5264 | <p id="section-12.2.1-5.1.1">While the incident is diagnosed, authenticating parties may still need new certificates.<a href="#section-12.2.1-5.1.1" class="pilcrow">¶</a></p> |
5265 | 5265 | </li> |
5266 | 5266 | <li class="normal" id="section-12.2.1-5.2"> |
5267 | | - <p id="section-12.2.1-5.2.1">If the CA operator and the CA instance are still trustworthy, repairing the incident without changing the CA requires less overhead.<a href="#section-12.2.1-5.2.1" class="pilcrow">¶</a></p> |
| 5267 | + <p id="section-12.2.1-5.2.1">If relying parties consider the CA operator and the CA instance still trustworthy, repairing the incident without changing the CA requires less overhead.<a href="#section-12.2.1-5.2.1" class="pilcrow">¶</a></p> |
5268 | 5268 | </li> |
5269 | 5269 | <li class="normal" id="section-12.2.1-5.3"> |
5270 | | - <p id="section-12.2.1-5.3.1">If either the CA operator or the CA instance are no longer trustworthy and must be replaced, the CA may still be needed to serve older, unupdated relying parties.<a href="#section-12.2.1-5.3.1" class="pilcrow">¶</a></p> |
| 5270 | + <p id="section-12.2.1-5.3.1">If relying parties consider either the CA operator or the CA instance no longer trustworthy and in need of replacement, the CA may still be needed to serve older, unupdated relying parties.<a href="#section-12.2.1-5.3.1" class="pilcrow">¶</a></p> |
5271 | 5271 | </li> |
5272 | 5272 | </ul> |
5273 | 5273 | <p id="section-12.2.1-6">This is mitigated by a CA instance consisting of a series of issuance logs (<a href="#issuance-logs" class="auto internal xref">Section 5.2</a>). After a log failure, the CA SHOULD increment its current issuance log to restore availability. Both the underlying log failure and the use of a new issuance log will be visible to monitors and SHOULD be treated as a PKI incident. Such PKI incidents can be handled by some combination of:<a href="#section-12.2.1-6" class="pilcrow">¶</a></p> |
|
0 commit comments