Re: [Technical Errata Reported] RFC4211 (4797)
Lijun Liao <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CANNx7D_NPPYOekz4yOv7N-dE9Fa5VBkWKay2ADNQdS91YwP=GA@mail.gmail.com> |
Just correction:
The Notes should be as follows:
------------------------------------------
The original text conflicts with the following text block (just several
lines later).
" The fields of POPOSigningKey have the following meaning:
...
signature contains the POP value produce. If poposkInput is
present, the signature is computed over the DER-encoded value of
poposkInput. If poposkInput is absent, the signature is computed
over the DER-encoded value of certReq."
On Thu, Sep 8, 2016 at 4:00 PM, RFC Errata System <[email protected]
> wrote:
> The following errata report has been submitted for RFC4211,
> "Internet X.509 Public Key Infrastructure Certificate Request Message
> Format (CRMF)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=4211&eid=4797
>
> --------------------------------------
> Type: Technical
> Reported by: Lijun Liao <[email protected]>
>
> Section: 4.1
>
> Original Text
> -------------
> 3. The certificate subject places its name in the Certificate
> Template structure along with the public key. In this case the
> poposkInput field is omitted from the POPOSigningKey structure.
> The signature field is computed over the DER-encoded certificate
> template structure.
>
> Corrected Text
> --------------
> 3. The certificate subject places its name in the Certificate
> Template structure along with the public key. In this case the
> poposkInput field is omitted from the POPOSigningKey structure.
> The signature field is computed over the DER-encoded value of
> certReq
>
> Notes
> -----
> The original text conflicts with the following text block (just several
> lines later).
>
> " The fields of POPOSigningKeyInput have the following meaning:
>
> sender contains an authenticated identity that has been previously
> established for the subject.
>
> publicKeyMAC contains a computed value that uses a shared secret
> between the CA/RA and the certificate requestor.
>
> publicKey contains a copy of the public key from the certificate
> template. This MUST be exactly the same value as is contained in
> the certificate template."
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC4211 (draft-ietf-pkix-rfc2511bis-08)
> --------------------------------------
> Title : Internet X.509 Public Key Infrastructure Certificate
> Request Message Format (CRMF)
> Publication Date : September 2005
> Author(s) : J. Schaad
> Category : PROPOSED STANDARD
> Source : Public-Key Infrastructure (X.509)
> Area : Security
> Stream : IETF
> Verifying Party : IESG
>
>
--
Lijun Liao
_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix