Re: [Editorial Errata Reported] RFC5280 (7634)

Rebecca VanRheenen <[email protected]> Wed, 8 Nov 2023 14:11:30 -0800
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Hi Paul and Roman,

We are unable to verify this erratum that the submitter marked as editorial.  
Please note that we have changed the “Type” of the following errata 
report to “Technical”.  As Stream Approver, please review and set the 
Status and Type accordingly (see the definitions at 
https://www.rfc-editor.org/errata-definitions/).

You may review the report at: 
https://www.rfc-editor.org/errata/eid7634

Please see https://www.rfc-editor.org/how-to-verify/ for further 
information on how to verify errata reports.

Further information on errata can be found at: 
https://www.rfc-editor.org/errata.php.

Note that we are sending this to you both as ADs of the Security Area as 
the pkix Working Group has closed.

Thank you.

RFC Editor/rv


> On Sep 8, 2023, at 2:15 PM, RFC Errata System <[email protected]> wrote:
> 
> The following errata report has been submitted for RFC5280,
> "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile".
> 
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid7634
> 
> --------------------------------------
> Type: Editorial
> Reported by: Nick Harper <[email protected]>
> 
> Section: 4.1
> 
> Original Text
> -------------
>   Certificate  ::=  SEQUENCE  {
>        tbsCertificate       TBSCertificate,
>        signatureAlgorithm   AlgorithmIdentifier,
>        signatureValue       BIT STRING  }
> 
> Corrected Text
> --------------
>   Certificate  ::=  SEQUENCE  {
>        tbsCertificate       TBSCertificate,
>        signatureAlgorithm   AlgorithmIdentifier,
>        signature            BIT STRING  }
> 
> Notes
> -----
> The definition in section 4.1 disagrees with the definition in appendix A.1 (page 116) on whether the name of the field containing the signature is "signatureValue" or "signature". This error appears in RFC 3280 and RFC 2459 as well.
> 
> The versions of X.509 in force when RFCs 2459, 3280, and 5280 were published use neither of those names. (Those versions of X.509 considered a signature to be an encrypted hash and called the field "encrypted".) The current version, ITU-T X.509 (10/2019), defines this field to be "signature" in section 6.2.1. (X.509 defines the Certificate type using a component type of SIGNATURE, which has two fields named "algorithmIdentifier" and "signature".)
> 
> In addition to changing the field name in the definition of the Certificate type in section 4.1, the title and text of subsection 4.1.1.3 should be updated to replace "signatureValue" with "signature".
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party  
> can log in to change the status and edit the report, if necessary. 
> 
> --------------------------------------
> RFC5280 (draft-ietf-pkix-rfc3280bis-11)
> --------------------------------------
> Title               : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
> Publication Date    : May 2008
> Author(s)           : D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, W. Polk
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
> 

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix