Re: [Technical Errata Reported] RFC3779 (7653)

Russ Housley <[email protected]> Fri, 12 Jan 2024 15:08:32 -0500
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
This looks good to me.

Russ

> On Jan 12, 2024, at 1:17 PM, Job Snijders <[email protected]> wrote:
> 
> Dear all,
> 
> The errata text has been updated to reflect this conversation: 
> https://www.rfc-editor.org/errata/eid7653
> 
> Good to mark as verified?
> 
> Kind regards,
> 
> Job
> 
> On Thu, 28 Sep 2023 at 16:17, Stefan Santesson <[email protected] <mailto:[email protected]>> wrote:
>> Hi,
>> 
>> It was a while since I was into the details of ASN.1 and feel a bit 
>> unsure what is correct here.
>> 
>> I agree with Russ on his thoughts.
>> 
>> /Stefan
>> 
>> 
>> On 2023-09-27 17:29, Russ Housley wrote:
>> > Two thoughts below.
>> >
>> >> The following errata report has been submitted for RFC3779,
>> >> "X.509 Extensions for IP Addresses and AS Identifiers".
>> >>
>> >> --------------------------------------
>> >> You may review the report below and at:
>> >> https://www.rfc-editor.org/errata/eid7653
>> >>
>> >> --------------------------------------
>> >> Type: Technical
>> >> Reported by: Job Snijders <[email protected] <mailto:[email protected]>>
>> >>
>> >> Section: 3.2.3
>> >>
>> >> Original Text
>> >> -------------
>> >> Section 3.2.3.4 <http://3.2.3.4/>:
>> >> Any contiguous series of AS identifiers MUST be combined into a single range
>> >> whenever possible.
>> >>
>> >> Section 3.2.3.8 <http://3.2.3.8/>:
>> >> The ASRange type is a SEQUENCE consisting of a min and a max element,
>> >> and is used to specify a range of AS identifier values.
>> >>
>> >> Corrected Text
>> >> --------------
>> >> Section 3.2.3.4 <http://3.2.3.4/>:
>> >> Any contiguous series of AS identifiers MUST be combined into a single range
>> >> or, whenever possible, represented as a single ASId.
>> > I don't like "or, whenever possible". That is not well specified and thus unlikely to yield a canonical result. In my view, this text is not an improvement to the existing text.
>> >
>> >> Section 3.2.3.8 <http://3.2.3.8/>:
>> >> The ASRange type is a SEQUENCE consisting of a min and a max element,
>> >> and is used to specify a range of AS identifier values. The min and max
>> >> elements MUST specify two distinct AS identifiers.
>> > This statement seems clear to me, and I think it is an improvement over the current text.
>> >
>> > Russ
>> >
>> >> Notes
>> >> -----
>> >> The introduction in section 1 stresses that the objective of the encoding rules in section 2 and section 3
>> >> is to produce unique encoding and minimal size encoding of the information.
>> >>
>> >> Allowing ASRanges where the minimum value is the same as the maximum value clearly violates the
>> >> objective of specifying a canonical form (in order to produce a unique representation); however the
>> >> specification as-is doesn't forbid min & max to be the same value. The corrected text addresses this.
>> >>
>> >> Instructions:
>> >> -------------
>> >> This erratum is currently posted as "Reported". If necessary, please
>> >> use "Reply All" to discuss whether it should be verified or
>> >> rejected. When a decision is reached, the verifying party
>> >> can log in to change the status and edit the report, if necessary.
>> >>
>> >> --------------------------------------
>> >> RFC3779 (draft-ietf-pkix-x509-ipaddr-as-extn-03)
>> >> --------------------------------------
>> >> Title               : X.509 Extensions for IP Addresses and AS Identifiers
>> >> Publication Date    : June 2004
>> >> Author(s)           : C. Lynn, S. Kent, K. Seo
>> >> Category            : PROPOSED STANDARD
>> >> Source              : Public-Key Infrastructure (X.509)
>> >> Area                : Security
>> >> Stream              : IETF
>> >> Verifying Party     : IESG

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix