Re: draft-housley-ct-keypackage-receipt-n-error-00
Russ Housley <[email protected]>
| Newsgroups | gmane.ietf.smime |
|---|---|
| Message-ID | <[email protected]> |
Jim:
>>> 8. Is there a requirement that systems should accept
>>> KeyPkgIdentifier.attribute values that they do not understand as it
>>> can be reflected in the receipt without having to decode it?
>>
>> As with all CMS processing, unrecognized attributes are ignored. I'm not
> sure
>> this needs to be repeated further. It comes up here:
>>
>> * badUnsignedAttrs is used to indicate that the unsignedAttrs
>> within SignerInfo contains one or more attributes. Since
>> unrecognized attributes are ignored, this error code is used
>> when the object identifier for the attribute is recognized, but
>> the value is malformed or internally inconsistent.
>
>
> I don't think that this is an acceptable solution ore response at this
> point.
>
> If I send you
>
> Key package id and receipt request ::= {
> pkgID = { random OID you never heard of, binary value }
> receiptReq = {
> encryptReceipt FALSE,
> receiptsFrom - absent
> receiptsTo = {Me}
> }}
>
> You have three options:
>
> 1 - say that the signed attribute is bad because you do not understand a
> piece if it and neither process nor receipt the package
> 2 - say that you don't care that the signed attribute is bad and process it
> and return a receipt because you do not need to understand the key package
> identifier
> 3 - say that you ignore things you do not understand and process the package
> but do not return a receipt.
Does this text resolve you concern?
* badUnsignedAttrs is used to indicate that the unsignedAttrs
within SignerInfo contains one or more attributes. Since
unrecognized attributes are ignored, this error code is used
when the object identifier for the attribute is recognized, but
the value is malformed or internally inconsistent. In
addition, this error code can be used when policy prohibits an
implementation from supporting unsigned attributes.
Russ
_______________________________________________
smime mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/smime