Re: [Technical Errata Reported] RFC5280 (5802)

Jim Schaad <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Looking at the document, this is not a comment in the ASN.1 definition as it
is not part of the ASN.1 module at the bottom of the file.   However I agree
that just updating this apparent comment would not make any real difference
and "Hold for Document Update" is appropriate.

Jim


-----Original Message-----
From: pkix <[email protected]> On Behalf Of Russ Housley
Sent: Tuesday, August 6, 2019 9:16 AM
To: [email protected]
Cc: Roman D. Danyliw <[email protected]>; IETF PKIX <[email protected]>; Ben Kaduk
<[email protected]>
Subject: Re: [pkix] [Technical Errata Reported] RFC5280 (5802)

At the time that these values were assigned, TLS was primarily a protocol
for WWW security.  It has since been used in may other environments.  I do
not see how a change to the comment in the ASN.1 definition will make any
real difference, but I do not really have an objection.

I suggest that this be marked as "Hold for Document Update"

Russ


> On Aug 6, 2019, at 11:56 AM, RFC Errata System <[email protected]>
wrote:
> 
> The following errata report has been submitted for RFC5280, "Internet 
> X.509 Public Key Infrastructure Certificate and Certificate Revocation
List (CRL) Profile".
> 
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid5802
> 
> --------------------------------------
> Type: Technical
> Reported by: Nikos Mavrogiannopoulos <[email protected]>
> 
> Section: 4.2.1.12
> 
> Original Text
> -------------
>  id-kp-serverAuth             OBJECT IDENTIFIER ::= { id-kp 1 }
>  -- TLS WWW server authentication
>  -- Key usage bits that may be consistent: digitalSignature,
>  -- keyEncipherment or keyAgreement
> 
>  id-kp-clientAuth             OBJECT IDENTIFIER ::= { id-kp 2 }
>  -- TLS WWW client authentication
>  -- Key usage bits that may be consistent: digitalSignature
>  -- and/or keyAgreement
> 
> Corrected Text
> --------------
>  id-kp-serverAuth             OBJECT IDENTIFIER ::= { id-kp 1 }
>  -- TLS server authentication
>  -- Key usage bits that may be consistent: digitalSignature,
>  -- keyEncipherment or keyAgreement
> 
>  id-kp-clientAuth             OBJECT IDENTIFIER ::= { id-kp 2 }
>  -- TLS client authentication
>  -- Key usage bits that may be consistent: digitalSignature
>  -- and/or keyAgreement
> 
> Notes
> -----
> The proposed change removes the WWW part of the description. In practice
these object identifiers are used for server and client applications, but
not necessarily web applications. In particular:
> - openssl verification considers them unconditionally even if the 
> server is not a web server or the client a web client
> - There is no object identifier that can be used for protocols like 
> SMTP, IMAP, POP3, LDAP, radius, ...; in practice all these protocols 
> are deployed with the identifiers for WWW
> - Standards like common criteria assume that these object identifiers are
for generic server and clients [0].
> 
> [0]. https://www.niap-ccevs.org/MMO/PP/-442-/#FCS_TLSC_EXT.1.1
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please 
> use "Reply All" to discuss whether it should be verified or rejected. 
> When a decision is reached, the verifying party can log in to change 
> the status and edit the report, if necessary.
> 
> --------------------------------------
> RFC5280 (draft-ietf-pkix-rfc3280bis-11)
> --------------------------------------
> Title               : Internet X.509 Public Key Infrastructure Certificate
and Certificate Revocation List (CRL) Profile
> Publication Date    : May 2008
> Author(s)           : D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R.
Housley, W. Polk
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.