[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )
Russ Housley <[email protected]> Tue, 29 Oct 2024 11:47:15 -0400
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
--===============2727685333133327399== Content-Type: multipart/alternative; boundary="Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F" --Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Sean Turner was looking at this recently. Sean, can you offer an = opinion? Russ > On Oct 29, 2024, at 11:41 AM, Deb Cooley <[email protected]> wrote: >=20 > opinions? >=20 > Deb >=20 > On Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System = <[email protected] <mailto:[email protected]>> wrote: >> The following errata report has been submitted for RFC5272, >> "Certificate Management over CMS (CMC)". >>=20 >> -------------------------------------- >> You may review the report below and at: >> https://www.rfc-editor.org/errata/eid8137 >>=20 >> -------------------------------------- >> Type: Technical >> Reported by: David von Oheimb <[email protected] = <mailto:[email protected]>> >>=20 >> Section: C.1 >>=20 >> Original Text >> ------------- >> NoSignatureValue contains the hash of the certification request.=20 >>=20 >> Corrected Text >> -------------- >> NoSignatureValue contains the SHA-1 hash value of the certification = request.=20 >> The hash value given by NoSignatureValue SHOULD be ignored. >>=20 >> Notes >> ----- >> The hash value was not sufficiently defined because the choice of the = hash algorithm was not specified. >> At that time presumably the use of SHA-1 was implied. >>=20 >> I suggest requiring SHA-1 here simply for backward compatibility. >> >=46rom today's perspective more flexibility may be demanded and = SHA-1 likely no more is the best choice. >>=20 >> Anyway I see no real value in NoSignatureValue (pun intended), so it = should not matter. >> For this reason I propose ignoring the hash value. >>=20 >> Instructions: >> ------------- >> This erratum is currently posted as "Reported". (If it is spam, it=20 >> will be removed shortly by the RFC Production Center.) Please >> use "Reply All" to discuss whether it should be verified or >> rejected. When a decision is reached, the verifying party =20 >> will log in to change the status and edit the report, if necessary. >>=20 >> -------------------------------------- >> RFC5272 (draft-ietf-pkix-2797-bis-07) >> -------------------------------------- >> Title : Certificate Management over CMS (CMC) >> Publication Date : June 2008 >> Author(s) : J. Schaad, M. Myers >> Category : PROPOSED STANDARD >> Source : Public-Key Infrastructure (X.509) >> Stream : IETF >> Verifying Party : IESG > _______________________________________________ > pkix mailing list -- [email protected] > To unsubscribe send an email to [email protected] --Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;">Sean Turner = was looking at this recently. Sean, can you offer an = opinion?<div><br></div><div>Russ<br><div><br><blockquote = type=3D"cite"><div>On Oct 29, 2024, at 11:41 AM, Deb Cooley = <[email protected]> wrote:</div><br = class=3D"Apple-interchange-newline"><div><div = dir=3D"ltr"><div>opinions?</div><div><br></div><div>Deb<br></div></div><br= ><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On = Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System <<a = href=3D"mailto:[email protected]">[email protected]</a>>= ; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid = rgb(204,204,204);padding-left:1ex">The following errata report has been = submitted for RFC5272,<br> "Certificate Management over CMS (CMC)".<br> <br> --------------------------------------<br> You may review the report below and at:<br> <a href=3D"https://www.rfc-editor.org/errata/eid8137" rel=3D"noreferrer" = target=3D"_blank">https://www.rfc-editor.org/errata/eid8137</a><br> <br> --------------------------------------<br> Type: Technical<br> Reported by: David von Oheimb <<a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>><br> <br> Section: C.1<br> <br> Original Text<br> -------------<br> NoSignatureValue contains the hash of the certification request. <br> <br> Corrected Text<br> --------------<br> NoSignatureValue contains the SHA-1 hash value of the certification = request. <br> The hash value given by NoSignatureValue SHOULD be ignored.<br> <br> Notes<br> -----<br> The hash value was not sufficiently defined because the choice of the = hash algorithm was not specified.<br> At that time presumably the use of SHA-1 was implied.<br> <br> I suggest requiring SHA-1 here simply for backward compatibility.<br> >=46rom today's perspective more flexibility may be demanded and = SHA-1 likely no more is the best choice.<br> <br> Anyway I see no real value in NoSignatureValue (pun intended), so it = should not matter.<br> For this reason I propose ignoring the hash value.<br> <br> Instructions:<br> -------------<br> This erratum is currently posted as "Reported". (If it is spam, it <br> will be removed shortly by the RFC Production Center.) Please<br> use "Reply All" to discuss whether it should be verified or<br> rejected. When a decision is reached, the verifying party <br> will log in to change the status and edit the report, if necessary.<br> <br> --------------------------------------<br> RFC5272 (draft-ietf-pkix-2797-bis-07)<br> --------------------------------------<br> Title : = Certificate Management over CMS (CMC)<br> Publication Date : June 2008<br> Author(s) : J. Schaad, M. = Myers<br> Category : PROPOSED = STANDARD<br> Source : Public-Key = Infrastructure (X.509)<br> Stream : IETF<br> Verifying Party : IESG<br> </blockquote></div> _______________________________________________<br>pkix mailing list -- = [email protected]<br>To unsubscribe send an email to = [email protected]<br></div></blockquote></div><br></div></body></html>= --Apple-Mail=_8F2BC79C-5E58-4539-BCE8-2032DC3E6E2F-- --===============2727685333133327399== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHBraXgtbGVhdmVAaWV0Zi5vcmcK --===============2727685333133327399==--