Re: Amendment to CABF Baseline Requirements

Carl Wallace <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <D50BEDEE.85E5F%[email protected]>
Ah, I assumed you had all the browser folks covered and sought broader
comments (hence posting here). If breaking non-browser instances is of no
concern, feel free to ignore my comment.

From:  Jeremy Rowley <[email protected]>
Date:  Thursday, April 6, 2017 at 12:40 PM
To:  Carl Wallace <[email protected]>, Ben Wilson
<[email protected]>, "[email protected]" <[email protected]>
Subject:  RE: [pkix] Amendment to CABF Baseline Requirements

> Can you point to any browser software that cares about these limits?  I can’t
> find any.
>  
> 
> From: pkix [mailto:[email protected]] On Behalf Of Carl Wallace
> Sent: Thursday, April 6, 2017 10:28 AM
> To: Ben Wilson <[email protected]>; [email protected]
> Subject: Re: [pkix] Amendment to CABF Baseline Requirements
>  
> 
> Given these ASN.1 upper bounds are automatically enforced by ASN.1 compiler
> generated code, how do we hand wave this away? These changes are a recipe for
> interoperability pain.
> 
>  
> 
> From: pkix <[email protected]> on behalf of Ben Wilson
> <[email protected]>
> Date: Thursday, April 6, 2017 at 12:24 PM
> To: "[email protected]" <[email protected]>
> Subject: [pkix] Amendment to CABF Baseline Requirements
> 
>  
>> 
>> Does anyone want to comment on my draft amendment to the CA/Browser Forum’s
>> Baseline Requirements for SSL/TLS Certificates which would remove the
>> 64-character limit on the commonName and organizationName,  as an exception
>> to RFC 5280?  The text of the relevant Baseline Requirement provision is
>> found below with the proposed additional language in ALL CAPS.  The reason
>> for the first change (commonName) is there are FQDNs (in Subject Alternative
>> Names) that are longer than 64 characters.  The reason for the second change
>> (organizationName) is that there are organizations with names longer than 64
>> characters.
>>  
>> 7.1.4.2.2.             Subject Distinguished Name Fields
>> a.            Certificate Field: subject:commonName (OID 2.5.4.3)
>> Required/Optional: Deprecated (Discouraged, but not prohibited)
>> Contents: If present, this field MUST contain a single IP address or
>> Fully-Qualified Domain Name that is one of the values contained in the
>> Certificate’s subjectAltName extension (see Section 7.1.4.2.1).
>> MAXIMUM LENGTH:  NO STIPULATION.  (THIS IS AN EXCEPTION TO RFC 5280 WHICH
>> SPECIFIES AN UPPER BOUND OF 64 CHARACTERS.)
>> b.            Certificate Field: subject:organizationName (OID 2.5.4.10)
>> Optional.  
>> Contents: If present, the subject:organizationName field MUST contain either
>> the Subject’s name or DBA as verified under Section 3.2.2.2. The CA may
>> include information in this field that differs slightly from the verified
>> name, such as common variations or abbreviations, provided that the CA
>> documents the difference and any abbreviations used are locally accepted
>> abbreviations; e.g., if the official record shows “Company Name
>> Incorporated”, the CA MAY use “Company Name Inc.” or “Company Name”.  Because
>> Subject name attributes for individuals (e.g. givenName (2.5.4.42) and
>> surname (2.5.4.4)) are not broadly supported by application software, the CA
>> MAY use the subject:organizationName field to convey a natural person
>> Subject’s name or DBA.
>> MAXIMUM LENGTH:  256 CHARACTERS (THIS IS AN EXCEPTION TO RFC 5280 WHICH
>> SPECIFIES AN UPPER BOUND OF 64 CHARACTERS.)
>>  
>> Thanks,
>> Ben Wilson
>> _______________________________________________ pkix mailing list
>> [email protected] https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
smime.p7s (application/pkcs7-signature, 4.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.