[Errata Verified] RFC4211 (4797)

RFC Errata System <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
The following errata report has been verified for RFC4211,
"Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=4211&eid=4797

--------------------------------------
Status: Verified
Type: Editorial

Reported by: Lijun Liao <[email protected]>
Date Reported: 2016-09-08
Verified by: Stephen Farrell (IESG)

Section: 4.1

Original Text
-------------
   3.  The certificate subject places its name in the Certificate
       Template structure along with the public key.  In this case the
       poposkInput field is omitted from the POPOSigningKey structure.
       The signature field is computed over the DER-encoded certificate
       template structure.

Corrected Text
--------------
   3.  The certificate subject places its name in the Certificate
       Template structure along with the public key.  In this case the
       poposkInput field is omitted from the POPOSigningKey structure.
       The signature field is computed over the DER-encoded value of
       certReq

Notes
-----
The original text conflicts with the following text block (just several lines later).

"     The fields of POPOSigningKey have the following meaning:
      ...
 
      signature contains the POP value produce.  If poposkInput is
      present, the signature is computed over the DER-encoded value of
      poposkInput.  If poposkInput is absent, the signature is computed
      over the DER-encoded value of certReq."

--------------------------------------
RFC4211 (draft-ietf-pkix-rfc2511bis-08)
--------------------------------------
Title               : Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)
Publication Date    : September 2005
Author(s)           : J. Schaad
Category            : PROPOSED STANDARD
Source              : Public-Key Infrastructure (X.509)
Area                : Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.