Re: Amendment to CABF Baseline Requirements<

[email protected] (Martin Rex)
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Peter Bowen wrote:
>
> Russ Housley <[email protected]> wrote:
>>
>> RFC 5280 says:
>>
>> ub-organization-name-length INTEGER ::= 64
>> ub-organizational-unit-name-length INTEGER ::= 32
>>
>> The UpperBounds ASN.1 module (the 8th edition) says:
>>
>> ub-organization-name                       INTEGER ::= 64
>> ub-organizational-unit-name                INTEGER ::= 64
>>
>> So, we may already be in a place where implementations conforming to X.509
>> will produce a certificate that cannot be decoded by an implementation that
>> conforms to RFC 5280.
>>
>> I wish we gad gotten a heads-up ?
> 
> It is even worse. 7th and 8th (and maybe prior releases) removed the usage
> of ub- from the schema. The schema itself no longer bounds DirectoryStrings
> and X.509 explicitly says they are unbounded.


It's actually worse than that.  What newer revisions of X.509 and X.520 say
is explicitly irrelevant for rfc5280.  rfc5280 is firmly bolted
onto the limits of the 08/2005 edition of X.509 !

A while ago I wanted rfc5280-update to adopt the X.509 11/2008 fix
for the CRL processing semantics of what is a formally provable
specification defect in X.509 08/2005 and rfc5280 -- and I was faced
with violent oppostion in PKIX WG (potentially by implementors of
the broken semantics), which insisted on the broken semantics to
remain wedlocked to the defect in X.509 08/2005.


With respect to the suggested change of lifting the limitations:
I'm violently opposed to removing these limits, because subject DNames
exceeding these limits are likely going to face interop problems with the
installed base of our (non-browser) software.


-Martin

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.