[pkix] [Technical Errata Reported] RFC5272 (8137)
RFC Errata System <[email protected]> Sat, 12 Oct 2024 03:36:14 -0700 (PDT)
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
The following errata report has been submitted for RFC5272, "Certificate Management over CMS (CMC)". -------------------------------------- You may review the report below and at: https://www.rfc-editor.org/errata/eid8137 -------------------------------------- Type: Technical Reported by: David von Oheimb <[email protected]> Section: C.1 Original Text ------------- NoSignatureValue contains the hash of the certification request. Corrected Text -------------- NoSignatureValue contains the SHA-1 hash value of the certification request. The hash value given by NoSignatureValue SHOULD be ignored. Notes ----- The hash value was not sufficiently defined because the choice of the hash algorithm was not specified. At that time presumably the use of SHA-1 was implied. I suggest requiring SHA-1 here simply for backward compatibility. >From today's perspective more flexibility may be demanded and SHA-1 likely no more is the best choice. Anyway I see no real value in NoSignatureValue (pun intended), so it should not matter. For this reason I propose ignoring the hash value. Instructions: ------------- This erratum is currently posted as "Reported". (If it is spam, it will be removed shortly by the RFC Production Center.) Please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party will log in to change the status and edit the report, if necessary. -------------------------------------- RFC5272 (draft-ietf-pkix-2797-bis-07) -------------------------------------- Title : Certificate Management over CMS (CMC) Publication Date : June 2008 Author(s) : J. Schaad, M. Myers Category : PROPOSED STANDARD Source : Public-Key Infrastructure (X.509) Stream : IETF Verifying Party : IESG _______________________________________________ pkix mailing list -- [email protected] To unsubscribe send an email to [email protected]