Re: Amendment to CABF Baseline Requirements<
[email protected] (Martin Rex)
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Peter Bowen wrote: > > Russ Housley <[email protected]> wrote: >> >> RFC 5280 says: >> >> ub-organization-name-length INTEGER ::= 64 >> ub-organizational-unit-name-length INTEGER ::= 32 >> >> The UpperBounds ASN.1 module (the 8th edition) says: >> >> ub-organization-name INTEGER ::= 64 >> ub-organizational-unit-name INTEGER ::= 64 >> >> So, we may already be in a place where implementations conforming to X.509 >> will produce a certificate that cannot be decoded by an implementation that >> conforms to RFC 5280. >> >> I wish we gad gotten a heads-up ? > > It is even worse. 7th and 8th (and maybe prior releases) removed the usage > of ub- from the schema. The schema itself no longer bounds DirectoryStrings > and X.509 explicitly says they are unbounded. It's actually worse than that. What newer revisions of X.509 and X.520 say is explicitly irrelevant for rfc5280. rfc5280 is firmly bolted onto the limits of the 08/2005 edition of X.509 ! A while ago I wanted rfc5280-update to adopt the X.509 11/2008 fix for the CRL processing semantics of what is a formally provable specification defect in X.509 08/2005 and rfc5280 -- and I was faced with violent oppostion in PKIX WG (potentially by implementors of the broken semantics), which insisted on the broken semantics to remain wedlocked to the defect in X.509 08/2005. With respect to the suggested change of lifting the limitations: I'm violently opposed to removing these limits, because subject DNames exceeding these limits are likely going to face interop problems with the installed base of our (non-browser) software. -Martin _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix