The AIA extension should be SHOULD instead of MUST for subscriber certificates. This is because the permissible accessMethods are both optional. (id-ad-caIssuers is a SHOULD, and id-ad-ocsp is a MAY.) Thus, it seems reasonable to make AIA a SHOULD as well, since no RP can depend on a particular accessMethod being present regardless.
See https://github.com/cabforum/servercert/pull/665/changes from @e3n0
The AIA extension should be SHOULD instead of MUST for subscriber certificates. This is because the permissible accessMethods are both optional. (id-ad-caIssuers is a SHOULD, and id-ad-ocsp is a MAY.) Thus, it seems reasonable to make AIA a SHOULD as well, since no RP can depend on a particular accessMethod being present regardless.
See https://github.com/cabforum/servercert/pull/665/changes from @e3n0