[Technical Errata Reported] RFC5272 (7629)
RFC Errata System <[email protected]> Mon, 4 Sep 2023 05:12:40 -0700 (PDT)
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
The following errata report has been submitted for RFC5272, "Certificate Management over CMS (CMC)". -------------------------------------- You may review the report below and at: https://www.rfc-editor.org/errata/eid7629 -------------------------------------- Type: Technical Reported by: Piotr Popis <[email protected]> Section: 3.2.1.3.4. Original Text ------------- For the PKI Response, SignedData allows the server to sign the returning data, if any exists, and to carry the certificates and CRLs corresponding to the PKI Request. If no data is being returned beyond the certificates and CRLs, the EncapsulatedInfo and SignerInfo fields are not populated. Corrected Text -------------- For the PKI Response, SignedData allows the server to sign the returning data, if any exists, and to carry the certificates and CRLs corresponding to the PKI Request. If no data is being returned beyond the certificates and CRLs, the eContent field in the EncapsulatedContentInfo and SignerInfo fields are not populated. Only if the server is unable to sign the response (and unable to use any RecipientInfo options of the AuthenticatedData content type), and at the same time it should send a negative response, Full PKI Response SignedData type containing a CMC Status Info control MUST be returned using a CMCFailInfo with a value of internalCAError and a bodyPartID of 0, and the eContent field in the EncapsulatedContentInfo as well as SignerInfo fields MUST not be populated. Notes ----- This change is needed to comply with Errata ID 7379 (the first para) and covers the case (the second para) where the server shall send a negative response (Full PKI Response) as it is unable to sign the certificate and at the same time it is unable to sign the response itself (e.g. due to a loss in connection to the HSM). Instructions: ------------- This erratum is currently posted as "Reported". If necessary, please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party can log in to change the status and edit the report, if necessary. -------------------------------------- RFC5272 (draft-ietf-pkix-2797-bis-07) -------------------------------------- Title : Certificate Management over CMS (CMC) Publication Date : June 2008 Author(s) : J. Schaad, M. Myers Category : PROPOSED STANDARD Source : Public-Key Infrastructure (X.509) Area : Security Stream : IETF Verifying Party : IESG