[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )

Russ Housley <[email protected]> Tue, 29 Oct 2024 11:47:15 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
--===============2727685333133327399==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F"


--Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Sean Turner was looking at this recently.  Sean, can you offer an =
opinion?

Russ

> On Oct 29, 2024, at 11:41 AM, Deb Cooley <[email protected]> wrote:
>=20
> opinions?
>=20
> Deb
>=20
> On Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System =
<[email protected] <mailto:[email protected]>> wrote:
>> The following errata report has been submitted for RFC5272,
>> "Certificate Management over CMS (CMC)".
>>=20
>> --------------------------------------
>> You may review the report below and at:
>> https://www.rfc-editor.org/errata/eid8137
>>=20
>> --------------------------------------
>> Type: Technical
>> Reported by: David von Oheimb <[email protected] =
<mailto:[email protected]>>
>>=20
>> Section: C.1
>>=20
>> Original Text
>> -------------
>> NoSignatureValue contains the hash of the certification request.=20
>>=20
>> Corrected Text
>> --------------
>> NoSignatureValue contains the SHA-1 hash value of the certification =
request.=20
>> The hash value given by NoSignatureValue SHOULD be ignored.
>>=20
>> Notes
>> -----
>> The hash value was not sufficiently defined because the choice of the =
hash algorithm was not specified.
>> At that time presumably the use of SHA-1 was implied.
>>=20
>> I suggest requiring SHA-1 here simply for backward compatibility.
>> >=46rom today's perspective more flexibility may be demanded and =
SHA-1 likely no more is the best choice.
>>=20
>> Anyway I see no real value in NoSignatureValue (pun intended), so it =
should not matter.
>> For this reason I propose ignoring the hash value.
>>=20
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". (If it is spam, it=20
>> will be removed shortly by the RFC Production Center.) Please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party =20
>> will log in to change the status and edit the report, if necessary.
>>=20
>> --------------------------------------
>> RFC5272 (draft-ietf-pkix-2797-bis-07)
>> --------------------------------------
>> Title               : Certificate Management over CMS (CMC)
>> Publication Date    : June 2008
>> Author(s)           : J. Schaad, M. Myers
>> Category            : PROPOSED STANDARD
>> Source              : Public-Key Infrastructure (X.509)
>> Stream              : IETF
>> Verifying Party     : IESG
> _______________________________________________
> pkix mailing list -- [email protected]
> To unsubscribe send an email to [email protected]


--Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;">Sean Turner =
was looking at this recently. &nbsp;Sean, can you offer an =
opinion?<div><br></div><div>Russ<br><div><br><blockquote =
type=3D"cite"><div>On Oct 29, 2024, at 11:41 AM, Deb Cooley =
&lt;[email protected]&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div><div =
dir=3D"ltr"><div>opinions?</div><div><br></div><div>Deb<br></div></div><br=
><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On =
Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System &lt;<a =
href=3D"mailto:[email protected]">[email protected]</a>&gt=
; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid =
rgb(204,204,204);padding-left:1ex">The following errata report has been =
submitted for RFC5272,<br>
"Certificate Management over CMS (CMC)".<br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href=3D"https://www.rfc-editor.org/errata/eid8137" rel=3D"noreferrer" =
target=3D"_blank">https://www.rfc-editor.org/errata/eid8137</a><br>
<br>
--------------------------------------<br>
Type: Technical<br>
Reported by: David von Oheimb &lt;<a =
href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a>&gt;<br>
<br>
Section: C.1<br>
<br>
Original Text<br>
-------------<br>
NoSignatureValue contains the hash of the certification request. <br>
<br>
Corrected Text<br>
--------------<br>
NoSignatureValue contains the SHA-1 hash value of the certification =
request. <br>
The hash value given by NoSignatureValue SHOULD be ignored.<br>
<br>
Notes<br>
-----<br>
The hash value was not sufficiently defined because the choice of the =
hash algorithm was not specified.<br>
At that time presumably the use of SHA-1 was implied.<br>
<br>
I suggest requiring SHA-1 here simply for backward compatibility.<br>
&gt;=46rom today's perspective more flexibility may be demanded and =
SHA-1 likely no more is the best choice.<br>
<br>
Anyway I see no real value in NoSignatureValue (pun intended), so it =
should not matter.<br>
For this reason I propose ignoring the hash value.<br>
<br>
Instructions:<br>
-------------<br>
This erratum is currently posted as "Reported". (If it is spam, it <br>
will be removed shortly by the RFC Production Center.) Please<br>
use "Reply All" to discuss whether it should be verified or<br>
rejected. When a decision is reached, the verifying party&nbsp; <br>
will log in to change the status and edit the report, if necessary.<br>
<br>
--------------------------------------<br>
RFC5272 (draft-ietf-pkix-2797-bis-07)<br>
--------------------------------------<br>
Title&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: =
Certificate Management over CMS (CMC)<br>
Publication Date&nbsp; &nbsp; : June 2008<br>
Author(s)&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: J. Schaad, M. =
Myers<br>
Category&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : PROPOSED =
STANDARD<br>
Source&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : Public-Key =
Infrastructure (X.509)<br>
Stream&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : IETF<br>
Verifying Party&nbsp; &nbsp; &nbsp;: IESG<br>
</blockquote></div>
_______________________________________________<br>pkix mailing list -- =
[email protected]<br>To unsubscribe send an email to =
[email protected]<br></div></blockquote></div><br></div></body></html>=

--Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F--


--===============2727685333133327399==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK

--===============2727685333133327399==--