Re: Issues with draft-ietf-smime-examples-05
Paul Hoffman / IMC <[email protected]> Sun, 14 Jan 2001 11:26:44 -0800
| Newsgroups | gmane.ietf.smime-examples |
|---|---|
| Message-ID | <p05010404b687ad2f1142@[165.227.249.17]> |
At 5:30 PM +0100 1/11/01, Magnus Svensson wrote:
>- AliceRSASignByCarl.cer:
>The asn1dump of the certificate in the draft-text is not a correct
>representation of the binary certificate. The binary certificate has has a
>different OID for the signature algorithm identifier (sha-1WithRSAEncryption
>(1 3 14 3 2 29)) which also results in a different signature value.
>Alice's RSA certificate conveyed within the example messages (for example
>5.2) has the OID that the draft-text specifies. If using the stand-alone
>binary certificate, this could lead to a conflict where you have two binary
>different certificates with the same issuer and serial number.
>I suppose that the stand-alone binary form ("AliceRSASignByCarl.cer") needs
>to be updated to be the same as the one present in the binary examples and
>the draft-text.
Sounds right to me. Jim Schaad: comments?
>- CRL's and nextUpdate field:
>None of the CRLs in the examples have the nextUpdate field present. I know
>that the field is optional in the ASN1 spec, but it is required to be
>present according to RFC 2459, sec 5.1.2.5.
Major yuck. Jim, could you re-generate the CRLs so that conform to
2459? It's OK if the next update for the CRLs is 2010. :-)
John Pawling has given me the updated examples for 6.2 and 11.5, so
I'm just waiting for the above before putting out -06.
--Paul Hoffman, Director
--Internet Mail Consortium