Re: [Technical Errata Reported] RFC5280 (5802)
Russ Housley <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
At the time that these values were assigned, TLS was primarily a protocol for WWW security. It has since been used in may other environments. I do not see how a change to the comment in the ASN.1 definition will make any real difference, but I do not really have an objection. I suggest that this be marked as "Hold for Document Update" Russ > On Aug 6, 2019, at 11:56 AM, RFC Errata System <[email protected]> wrote: > > The following errata report has been submitted for RFC5280, > "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile". > > -------------------------------------- > You may review the report below and at: > https://www.rfc-editor.org/errata/eid5802 > > -------------------------------------- > Type: Technical > Reported by: Nikos Mavrogiannopoulos <[email protected]> > > Section: 4.2.1.12 > > Original Text > ------------- > id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } > -- TLS WWW server authentication > -- Key usage bits that may be consistent: digitalSignature, > -- keyEncipherment or keyAgreement > > id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } > -- TLS WWW client authentication > -- Key usage bits that may be consistent: digitalSignature > -- and/or keyAgreement > > Corrected Text > -------------- > id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } > -- TLS server authentication > -- Key usage bits that may be consistent: digitalSignature, > -- keyEncipherment or keyAgreement > > id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } > -- TLS client authentication > -- Key usage bits that may be consistent: digitalSignature > -- and/or keyAgreement > > Notes > ----- > The proposed change removes the WWW part of the description. In practice these object identifiers are used for server and client applications, but not necessarily web applications. In particular: > - openssl verification considers them unconditionally even if the server is not a web server or the client a web client > - There is no object identifier that can be used for protocols like SMTP, IMAP, POP3, LDAP, radius, ...; in practice all these protocols are deployed with the identifiers for WWW > - Standards like common criteria assume that these object identifiers are for generic server and clients [0]. > > [0]. https://www.niap-ccevs.org/MMO/PP/-442-/#FCS_TLSC_EXT.1.1 > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC5280 (draft-ietf-pkix-rfc3280bis-11) > -------------------------------------- > Title : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile > Publication Date : May 2008 > Author(s) : D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, W. Polk > Category : PROPOSED STANDARD > Source : Public-Key Infrastructure (X.509) > Area : Security > Stream : IETF > Verifying Party : IESG _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix