Re: [Technical Errata Reported] RFC5280 (7661)
Russ Housley <[email protected]> Thu, 28 Sep 2023 11:54:49 -0400
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
Cross certification results in each CA issuing a certificate to the other. Dropping the second sentence is not helpful in my view. Russ > On Sep 28, 2023, at 9:10 AM, RFC Errata System <[email protected]> wrote: > > The following errata report has been submitted for RFC5280, > "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile". > > -------------------------------------- > You may review the report below and at: > https://www.rfc-editor.org/errata/eid7661 > > -------------------------------------- > Type: Technical > Reported by: Benjamin Strauss <[email protected]> > > Section: 3.5 > > Original Text > ------------- > (g) cross-certification: Two CAs exchange information used in > establishing a cross-certificate. A cross-certificate is a > certificate issued by one CA to another CA that contains a CA > signature key used for issuing certificates. > > Corrected Text > -------------- > (g) cross-certification: Two CAs exchange information used in > establishing a cross-certificate. > > Notes > ----- > The removed sentence is factually inaccurate and misleading: "A cross-certificate is a certificate issued by one CA to another CA that contains a CA signature key used for issuing certificates." > A "signature key used for issuing certificates" would be a private key. A certificate simply does not contain a private key. A definition of "cross-certificate" for the purpose of this RFC is already provided in section 3.2, so there is no point in elaborating here. > (The definition given in section 3.2 conflicts with the narrower, and more generally used, definition given in RFC 4949, but that is beside the point.) > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC5280 (draft-ietf-pkix-rfc3280bis-11) > -------------------------------------- > Title : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile > Publication Date : May 2008 > Author(s) : D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, W. Polk > Category : PROPOSED STANDARD > Source : Public-Key Infrastructure (X.509) > Area : Security > Stream : IETF > Verifying Party : IESG