Re: [Technical Errata Reported] RFC3779 (7653)

Russ Housley <[email protected]> Wed, 27 Sep 2023 11:29:51 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Two thoughts below.

> The following errata report has been submitted for RFC3779,
> "X.509 Extensions for IP Addresses and AS Identifiers".
> 
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid7653
> 
> --------------------------------------
> Type: Technical
> Reported by: Job Snijders <[email protected]>
> 
> Section: 3.2.3
> 
> Original Text
> -------------
> Section 3.2.3.4:
> Any contiguous series of AS identifiers MUST be combined into a single range
> whenever possible.
> 
> Section 3.2.3.8:
> The ASRange type is a SEQUENCE consisting of a min and a max element,
> and is used to specify a range of AS identifier values.
> 
> Corrected Text
> --------------
> Section 3.2.3.4:
> Any contiguous series of AS identifiers MUST be combined into a single range
> or, whenever possible, represented as a single ASId.

I don't like "or, whenever possible". That is not well specified and thus unlikely to yield a canonical result. In my view, this text is not an improvement to the existing text.

> Section 3.2.3.8:
> The ASRange type is a SEQUENCE consisting of a min and a max element,
> and is used to specify a range of AS identifier values. The min and max
> elements MUST specify two distinct AS identifiers.

This statement seems clear to me, and I think it is an improvement over the current text.

Russ

> 
> Notes
> -----
> The introduction in section 1 stresses that the objective of the encoding rules in section 2 and section 3
> is to produce unique encoding and minimal size encoding of the information.
> 
> Allowing ASRanges where the minimum value is the same as the maximum value clearly violates the
> objective of specifying a canonical form (in order to produce a unique representation); however the
> specification as-is doesn't forbid min & max to be the same value. The corrected text addresses this.
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party  
> can log in to change the status and edit the report, if necessary. 
> 
> --------------------------------------
> RFC3779 (draft-ietf-pkix-x509-ipaddr-as-extn-03)
> --------------------------------------
> Title               : X.509 Extensions for IP Addresses and AS Identifiers
> Publication Date    : June 2004
> Author(s)           : C. Lynn, S. Kent, K. Seo
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG