Re: [Technical Errata Reported] RFC4211 (4797)
Megan Ferguson <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Lijun, We have edited this report to contain your correction in the Notes field as requested. Thank you. RFC Editor/mf On Sep 8, 2016, at 7:16 AM, Lijun Liao <[email protected]> wrote: > Just correction: > > The Notes should be as follows: > ------------------------------------------ > > The original text conflicts with the following text block (just several lines later). > > " The fields of POPOSigningKey have the following meaning: > ... > > signature contains the POP value produce. If poposkInput is > present, the signature is computed over the DER-encoded value of > poposkInput. If poposkInput is absent, the signature is computed > over the DER-encoded value of certReq." > > > On Thu, Sep 8, 2016 at 4:00 PM, RFC Errata System <[email protected]> wrote: > The following errata report has been submitted for RFC4211, > "Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)". > > -------------------------------------- > You may review the report below and at: > http://www.rfc-editor.org/errata_search.php?rfc=4211&eid=4797 > > -------------------------------------- > Type: Technical > Reported by: Lijun Liao <[email protected]> > > Section: 4.1 > > Original Text > ------------- > 3. The certificate subject places its name in the Certificate > Template structure along with the public key. In this case the > poposkInput field is omitted from the POPOSigningKey structure. > The signature field is computed over the DER-encoded certificate > template structure. > > Corrected Text > -------------- > 3. The certificate subject places its name in the Certificate > Template structure along with the public key. In this case the > poposkInput field is omitted from the POPOSigningKey structure. > The signature field is computed over the DER-encoded value of > certReq > > Notes > ----- > The original text conflicts with the following text block (just several lines later). > > " The fields of POPOSigningKeyInput have the following meaning: > > sender contains an authenticated identity that has been previously > established for the subject. > > publicKeyMAC contains a computed value that uses a shared secret > between the CA/RA and the certificate requestor. > > publicKey contains a copy of the public key from the certificate > template. This MUST be exactly the same value as is contained in > the certificate template." > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party (IESG) > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC4211 (draft-ietf-pkix-rfc2511bis-08) > -------------------------------------- > Title : Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF) > Publication Date : September 2005 > Author(s) : J. Schaad > Category : PROPOSED STANDARD > Source : Public-Key Infrastructure (X.509) > Area : Security > Stream : IETF > Verifying Party : IESG > > > > > -- > Lijun Liao _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix