[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )
Deb Cooley <[email protected]> Tue, 29 Oct 2024 11:43:28 -0400
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAGgd1Od4u_f7yCuQVEtwzvR9_xa+9QJ9D9Ehfe-v0oQeZOza8g@mail.gmail.com> |
--===============3598935359147446463== Content-Type: multipart/alternative; boundary="0000000000004cdf9f06259f73a9" --0000000000004cdf9f06259f73a9 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable obsoleted by RFC 6402? On Tue, Oct 29, 2024 at 11:41=E2=80=AFAM Deb Cooley <[email protected]> = wrote: > opinions? > > Deb > > On Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System < > [email protected]> wrote: > >> The following errata report has been submitted for RFC5272, >> "Certificate Management over CMS (CMC)". >> >> -------------------------------------- >> You may review the report below and at: >> https://www.rfc-editor.org/errata/eid8137 >> >> -------------------------------------- >> Type: Technical >> Reported by: David von Oheimb <[email protected]> >> >> Section: C.1 >> >> Original Text >> ------------- >> NoSignatureValue contains the hash of the certification request. >> >> Corrected Text >> -------------- >> NoSignatureValue contains the SHA-1 hash value of the certification >> request. >> The hash value given by NoSignatureValue SHOULD be ignored. >> >> Notes >> ----- >> The hash value was not sufficiently defined because the choice of the >> hash algorithm was not specified. >> At that time presumably the use of SHA-1 was implied. >> >> I suggest requiring SHA-1 here simply for backward compatibility. >> From today's perspective more flexibility may be demanded and SHA-1 >> likely no more is the best choice. >> >> Anyway I see no real value in NoSignatureValue (pun intended), so it >> should not matter. >> For this reason I propose ignoring the hash value. >> >> Instructions: >> ------------- >> This erratum is currently posted as "Reported". (If it is spam, it >> will be removed shortly by the RFC Production Center.) Please >> use "Reply All" to discuss whether it should be verified or >> rejected. When a decision is reached, the verifying party >> will log in to change the status and edit the report, if necessary. >> >> -------------------------------------- >> RFC5272 (draft-ietf-pkix-2797-bis-07) >> -------------------------------------- >> Title : Certificate Management over CMS (CMC) >> Publication Date : June 2008 >> Author(s) : J. Schaad, M. Myers >> Category : PROPOSED STANDARD >> Source : Public-Key Infrastructure (X.509) >> Stream : IETF >> Verifying Party : IESG >> > --0000000000004cdf9f06259f73a9 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">obsoleted by RFC 6402?<br></div><br><div class=3D"gmail_qu= ote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Oct 29, 2024 at 11:41=E2= =80=AFAM Deb Cooley <<a href=3D"mailto:[email protected]">debcooley1@= gmail.com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style= =3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding= -left:1ex"><div dir=3D"ltr"><div>opinions?</div><div><br></div><div>Deb<br>= </div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_= attr">On Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System <<a href= =3D"mailto:[email protected]" target=3D"_blank">rfc-editor@rfc-edit= or.org</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"m= argin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left= :1ex">The following errata report has been submitted for RFC5272,<br> "Certificate Management over CMS (CMC)".<br> <br> --------------------------------------<br> You may review the report below and at:<br> <a href=3D"https://www.rfc-editor.org/errata/eid8137" rel=3D"noreferrer" ta= rget=3D"_blank">https://www.rfc-editor.org/errata/eid8137</a><br> <br> --------------------------------------<br> Type: Technical<br> Reported by: David von Oheimb <<a href=3D"mailto:David.von.Oheimb@siemen= s.com" target=3D"_blank">[email protected]</a>><br> <br> Section: C.1<br> <br> Original Text<br> -------------<br> NoSignatureValue contains the hash of the certification request. <br> <br> Corrected Text<br> --------------<br> NoSignatureValue contains the SHA-1 hash value of the certification request= . <br> The hash value given by NoSignatureValue SHOULD be ignored.<br> <br> Notes<br> -----<br> The hash value was not sufficiently defined because the choice of the hash = algorithm was not specified.<br> At that time presumably the use of SHA-1 was implied.<br> <br> I suggest requiring SHA-1 here simply for backward compatibility.<br> >From today's perspective more flexibility may be demanded and SHA-1 lik= ely no more is the best choice.<br> <br> Anyway I see no real value in NoSignatureValue (pun intended), so it should= not matter.<br> For this reason I propose ignoring the hash value.<br> <br> Instructions:<br> -------------<br> This erratum is currently posted as "Reported". (If it is spam, i= t <br> will be removed shortly by the RFC Production Center.) Please<br> use "Reply All" to discuss whether it should be verified or<br> rejected. When a decision is reached, the verifying party=C2=A0 <br> will log in to change the status and edit the report, if necessary.<br> <br> --------------------------------------<br> RFC5272 (draft-ietf-pkix-2797-bis-07)<br> --------------------------------------<br> Title=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: Certificate M= anagement over CMS (CMC)<br> Publication Date=C2=A0 =C2=A0 : June 2008<br> Author(s)=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: J. Schaad, M. Myers<br> Category=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : PROPOSED STANDARD<br> Source=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : Public-Key Infrast= ructure (X.509)<br> Stream=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : IETF<br> Verifying Party=C2=A0 =C2=A0 =C2=A0: IESG<br> </blockquote></div> </blockquote></div> --0000000000004cdf9f06259f73a9-- --===============3598935359147446463== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHBraXgtbGVhdmVAaWV0Zi5vcmcK --===============3598935359147446463==--