[Technical Errata Reported] RFC6960 (6165)

RFC Errata System <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
The following errata report has been submitted for RFC6960,
"X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid6165

--------------------------------------
Type: Technical
Reported by: Yury Strozhevsky <[email protected]>

Section: 1

Original Text
-------------
---

Corrected Text
--------------
   o  Appendix B.1 provides correct KeyHash type processing description. Now SHA-1 hash must be calculated for responder's public key ASN.1 value without tag, length and unused bits.


Notes
-----
The RFC6960 changes OCSP protocol in part of KeyHash type calculation. In RFC2560 there is the description:
   KeyHash ::= OCTET STRING -- SHA-1 hash of responder's public key
   (excluding the tag and length fields)

But in Appendix B.1, which is the major OCSP descriptive module, stated:
KeyHash ::= OCTET STRING -- SHA-1 hash of responder's public key
                         -- (i.e., the SHA-1 hash of the value of the
                         -- BIT STRING subjectPublicKey [excluding
                         -- the tag, length, and number of unused
                         -- bits] in the responder's certificate)

The difference is in what would be under SHA-1 hash. In RFC2560 KeyHash would be calculated for entire BIT STRING value, with "unused bits" byte (first byte in BIT STRING value), but Appendix B.1 in RFC6960 states that SHA-1 hash must be calculated for BIT STRING value without "unused bits".

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC6960 (draft-ietf-pkix-rfc2560bis-20)
--------------------------------------
Title               : X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP
Publication Date    : June 2013
Author(s)           : S. Santesson, M. Myers, R. Ankney, A. Malpani, S. Galperin, C. Adams
Category            : PROPOSED STANDARD
Source              : Public-Key Infrastructure (X.509)
Area                : Security
Stream              : IETF
Verifying Party     : IESG
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.