Re: [Technical Errata Reported] RFC5280 (5802)
Jim Schaad <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Looking at the document, this is not a comment in the ASN.1 definition as it is not part of the ASN.1 module at the bottom of the file. However I agree that just updating this apparent comment would not make any real difference and "Hold for Document Update" is appropriate. Jim -----Original Message----- From: pkix <[email protected]> On Behalf Of Russ Housley Sent: Tuesday, August 6, 2019 9:16 AM To: [email protected] Cc: Roman D. Danyliw <[email protected]>; IETF PKIX <[email protected]>; Ben Kaduk <[email protected]> Subject: Re: [pkix] [Technical Errata Reported] RFC5280 (5802) At the time that these values were assigned, TLS was primarily a protocol for WWW security. It has since been used in may other environments. I do not see how a change to the comment in the ASN.1 definition will make any real difference, but I do not really have an objection. I suggest that this be marked as "Hold for Document Update" Russ > On Aug 6, 2019, at 11:56 AM, RFC Errata System <[email protected]> wrote: > > The following errata report has been submitted for RFC5280, "Internet > X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile". > > -------------------------------------- > You may review the report below and at: > https://www.rfc-editor.org/errata/eid5802 > > -------------------------------------- > Type: Technical > Reported by: Nikos Mavrogiannopoulos <[email protected]> > > Section: 4.2.1.12 > > Original Text > ------------- > id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } > -- TLS WWW server authentication > -- Key usage bits that may be consistent: digitalSignature, > -- keyEncipherment or keyAgreement > > id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } > -- TLS WWW client authentication > -- Key usage bits that may be consistent: digitalSignature > -- and/or keyAgreement > > Corrected Text > -------------- > id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } > -- TLS server authentication > -- Key usage bits that may be consistent: digitalSignature, > -- keyEncipherment or keyAgreement > > id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } > -- TLS client authentication > -- Key usage bits that may be consistent: digitalSignature > -- and/or keyAgreement > > Notes > ----- > The proposed change removes the WWW part of the description. In practice these object identifiers are used for server and client applications, but not necessarily web applications. In particular: > - openssl verification considers them unconditionally even if the > server is not a web server or the client a web client > - There is no object identifier that can be used for protocols like > SMTP, IMAP, POP3, LDAP, radius, ...; in practice all these protocols > are deployed with the identifiers for WWW > - Standards like common criteria assume that these object identifiers are for generic server and clients [0]. > > [0]. https://www.niap-ccevs.org/MMO/PP/-442-/#FCS_TLSC_EXT.1.1 > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or rejected. > When a decision is reached, the verifying party can log in to change > the status and edit the report, if necessary. > > -------------------------------------- > RFC5280 (draft-ietf-pkix-rfc3280bis-11) > -------------------------------------- > Title : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile > Publication Date : May 2008 > Author(s) : D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, W. Polk > Category : PROPOSED STANDARD > Source : Public-Key Infrastructure (X.509) > Area : Security > Stream : IETF > Verifying Party : IESG _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix _______________________________________________ pkix mailing list [email protected] https://www.ietf.org/mailman/listinfo/pkix