Re: draft-housley-ct-keypackage-receipt-n-error-00

Russ Housley <[email protected]>
Newsgroups gmane.ietf.smime
Message-ID <[email protected]>
Jim:

>>> 8.  Is there a requirement that systems should accept
>>> KeyPkgIdentifier.attribute values that they do not understand as it
>>> can be reflected in the receipt without having to decode it?
>> 
>> As with all CMS processing, unrecognized attributes are ignored.  I'm not
> sure
>> this needs to be repeated further.  It comes up here:
>> 
>>       * badUnsignedAttrs is used to indicate that the unsignedAttrs
>>         within SignerInfo contains one or more attributes.  Since
>>         unrecognized attributes are ignored, this error code is used
>>         when the object identifier for the attribute is recognized, but
>>         the value is malformed or internally inconsistent.
> 
> 
> I don't think that this is an acceptable solution ore response at this
> point.
> 
> If I send you 
> 
> Key package id and receipt request ::= {
>   pkgID = { random OID you never heard of, binary value }
>  receiptReq = {
>   encryptReceipt FALSE,
>   receiptsFrom - absent
>   receiptsTo = {Me}
> }}
> 
> You have three options:
> 
> 1 - say that the signed attribute is bad because you do not understand a
> piece if it and neither process nor receipt the package
> 2 - say that you don't care that the signed attribute is bad and process it
> and return a receipt because you do not need to understand the key package
> identifier
> 3 - say that you ignore things you do not understand and process the package
> but do not return a receipt.

Does this text resolve you concern?

      * badUnsignedAttrs is used to indicate that the unsignedAttrs
        within SignerInfo contains one or more attributes.  Since
        unrecognized attributes are ignored, this error code is used
        when the object identifier for the attribute is recognized, but
        the value is malformed or internally inconsistent.  In
        addition, this error code can be used when policy prohibits an
        implementation from supporting unsigned attributes.

Russ
_______________________________________________
smime mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/smime
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.