Re: [Technical Errata Reported] RFC4211 (4797)

Lijun Liao <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CANNx7D_NPPYOekz4yOv7N-dE9Fa5VBkWKay2ADNQdS91YwP=GA@mail.gmail.com>
Just correction:

The Notes should be as follows:
------------------------------------------

The original text conflicts with the following text block (just several
lines later).

"     The fields of POPOSigningKey have the following meaning:

      ...

      signature contains the POP value produce.  If poposkInput is
      present, the signature is computed over the DER-encoded value of
      poposkInput.  If poposkInput is absent, the signature is computed
      over the DER-encoded value of certReq."


On Thu, Sep 8, 2016 at 4:00 PM, RFC Errata System <[email protected]
> wrote:

> The following errata report has been submitted for RFC4211,
> "Internet X.509 Public Key Infrastructure Certificate Request Message
> Format (CRMF)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=4211&eid=4797
>
> --------------------------------------
> Type: Technical
> Reported by: Lijun Liao <[email protected]>
>
> Section: 4.1
>
> Original Text
> -------------
>    3.  The certificate subject places its name in the Certificate
>        Template structure along with the public key.  In this case the
>        poposkInput field is omitted from the POPOSigningKey structure.
>        The signature field is computed over the DER-encoded certificate
>        template structure.
>
> Corrected Text
> --------------
>    3.  The certificate subject places its name in the Certificate
>        Template structure along with the public key.  In this case the
>        poposkInput field is omitted from the POPOSigningKey structure.
>        The signature field is computed over the DER-encoded value of
>        certReq
>
> Notes
> -----
> The original text conflicts with the following text block (just several
> lines later).
>
> "   The fields of POPOSigningKeyInput have the following meaning:
>
>       sender contains an authenticated identity that has been previously
>       established for the subject.
>
>       publicKeyMAC contains a computed value that uses a shared secret
>       between the CA/RA and the certificate requestor.
>
>       publicKey contains a copy of the public key from the certificate
>       template.  This MUST be exactly the same value as is contained in
>       the certificate template."
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC4211 (draft-ietf-pkix-rfc2511bis-08)
> --------------------------------------
> Title               : Internet X.509 Public Key Infrastructure Certificate
> Request Message Format (CRMF)
> Publication Date    : September 2005
> Author(s)           : J. Schaad
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>
>


-- 
Lijun Liao

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.