[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )

Michael StJohns <[email protected]> Tue, 29 Oct 2024 13:41:59 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8201264161095115890==
Content-Type: multipart/alternative;
 boundary="------------an77WlqxJzwYsWPnktqtmryM"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------an77WlqxJzwYsWPnktqtmryM
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Actually -

The text "The parameters for id-alg-noSignature..." implies an 
AlgorithmIdentifier rather than just an OBJECT IDENTIFIER.    Instead -

NoSignatureAlgorithm SIGNATURE-ALGORITHM ::= { IDENTIFIER 
id-alg-noSignature PARAMS TYPE DIGEST-ALGORITHM are preferredAbsent } -- 
the digest algorithm default is SHA1

Or something similar.

Mike


On 10/29/2024 11:47 AM, Russ Housley wrote:
> Sean Turner was looking at this recently.  Sean, can you offer an 
> opinion?
>
> Russ
>
>> On Oct 29, 2024, at 11:41 AM, Deb Cooley <[email protected]> wrote:
>>
>> opinions?
>>
>> Deb
>>
>> On Sat, Oct 12, 2024 at 6:36 AM RFC Errata System 
>> <[email protected]> wrote:
>>
>>     The following errata report has been submitted for RFC5272,
>>     "Certificate Management over CMS (CMC)".
>>
>>     --------------------------------------
>>     You may review the report below and at:
>>     https://www.rfc-editor.org/errata/eid8137
>>
>>     --------------------------------------
>>     Type: Technical
>>     Reported by: David von Oheimb <[email protected]>
>>
>>     Section: C.1
>>
>>     Original Text
>>     -------------
>>     NoSignatureValue contains the hash of the certification request.
>>
>>     Corrected Text
>>     --------------
>>     NoSignatureValue contains the SHA-1 hash value of the
>>     certification request.
>>     The hash value given by NoSignatureValue SHOULD be ignored.
>>
>>     Notes
>>     -----
>>     The hash value was not sufficiently defined because the choice of
>>     the hash algorithm was not specified.
>>     At that time presumably the use of SHA-1 was implied.
>>
>>     I suggest requiring SHA-1 here simply for backward compatibility.
>>     >From today's perspective more flexibility may be demanded and
>>     SHA-1 likely no more is the best choice.
>>
>>     Anyway I see no real value in NoSignatureValue (pun intended), so
>>     it should not matter.
>>     For this reason I propose ignoring the hash value.
>>
>>     Instructions:
>>     -------------
>>     This erratum is currently posted as "Reported". (If it is spam, it
>>     will be removed shortly by the RFC Production Center.) Please
>>     use "Reply All" to discuss whether it should be verified or
>>     rejected. When a decision is reached, the verifying party
>>     will log in to change the status and edit the report, if necessary.
>>
>>     --------------------------------------
>>     RFC5272 (draft-ietf-pkix-2797-bis-07)
>>     --------------------------------------
>>     Title               : Certificate Management over CMS (CMC)
>>     Publication Date    : June 2008
>>     Author(s)           : J. Schaad, M. Myers
>>     Category            : PROPOSED STANDARD
>>     Source              : Public-Key Infrastructure (X.509)
>>     Stream              : IETF
>>     Verifying Party     : IESG
>>
>> _______________________________________________
>> pkix mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>
>
> _______________________________________________
> pkix mailing list [email protected]
> To unsubscribe send an email [email protected]


--------------an77WlqxJzwYsWPnktqtmryM
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">Actually -</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">The text "The parameters for
      id-alg-noSignature..." implies an AlgorithmIdentifier rather than
      just an OBJECT IDENTIFIER.    Instead - <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">NoSignatureAlgorithm
      SIGNATURE-ALGORITHM ::= { IDENTIFIER id-alg-noSignature PARAMS
      TYPE DIGEST-ALGORITHM are preferredAbsent } -- the digest
      algorithm default is SHA1</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Or something similar.</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Mike</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">On 10/29/2024 11:47 AM, Russ Housley
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      Sean Turner was looking at this recently.  Sean, can you offer an
      opinion?
      <div><br>
      </div>
      <div>Russ<br>
        <div><br>
          <blockquote type="cite">
            <div>On Oct 29, 2024, at 11:41 AM, Deb Cooley
              <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> wrote:</div>
            <br class="Apple-interchange-newline">
            <div>
              <div dir="ltr">
                <div>opinions?</div>
                <div><br>
                </div>
                <div>Deb<br>
                </div>
              </div>
              <br>
              <div class="gmail_quote">
                <div dir="ltr" class="gmail_attr">On Sat, Oct 12, 2024
                  at 6:36 AM RFC Errata System &lt;<a
                    href="mailto:[email protected]"
                    moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
                  wrote:<br>
                </div>
                <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">The
                  following errata report has been submitted for
                  RFC5272,<br>
                  "Certificate Management over CMS (CMC)".<br>
                  <br>
                  --------------------------------------<br>
                  You may review the report below and at:<br>
                  <a href="https://www.rfc-editor.org/errata/eid8137"
                    rel="noreferrer" target="_blank"
                    moz-do-not-send="true" class="moz-txt-link-freetext">https://www.rfc-editor.org/errata/eid8137</a><br>
                  <br>
                  --------------------------------------<br>
                  Type: Technical<br>
                  Reported by: David von Oheimb &lt;<a
                    href="mailto:[email protected]"
                    target="_blank" moz-do-not-send="true"
                    class="moz-txt-link-freetext">[email protected]</a>&gt;<br>
                  <br>
                  Section: C.1<br>
                  <br>
                  Original Text<br>
                  -------------<br>
                  NoSignatureValue contains the hash of the
                  certification request. <br>
                  <br>
                  Corrected Text<br>
                  --------------<br>
                  NoSignatureValue contains the SHA-1 hash value of the
                  certification request. <br>
                  The hash value given by NoSignatureValue SHOULD be
                  ignored.<br>
                  <br>
                  Notes<br>
                  -----<br>
                  The hash value was not sufficiently defined because
                  the choice of the hash algorithm was not specified.<br>
                  At that time presumably the use of SHA-1 was implied.<br>
                  <br>
                  I suggest requiring SHA-1 here simply for backward
                  compatibility.<br>
                  &gt;From today's perspective more flexibility may be
                  demanded and SHA-1 likely no more is the best choice.<br>
                  <br>
                  Anyway I see no real value in NoSignatureValue (pun
                  intended), so it should not matter.<br>
                  For this reason I propose ignoring the hash value.<br>
                  <br>
                  Instructions:<br>
                  -------------<br>
                  This erratum is currently posted as "Reported". (If it
                  is spam, it <br>
                  will be removed shortly by the RFC Production Center.)
                  Please<br>
                  use "Reply All" to discuss whether it should be
                  verified or<br>
                  rejected. When a decision is reached, the verifying
                  party  <br>
                  will log in to change the status and edit the report,
                  if necessary.<br>
                  <br>
                  --------------------------------------<br>
                  RFC5272 (draft-ietf-pkix-2797-bis-07)<br>
                  --------------------------------------<br>
                  Title               : Certificate Management over CMS
                  (CMC)<br>
                  Publication Date    : June 2008<br>
                  Author(s)           : J. Schaad, M. Myers<br>
                  Category            : PROPOSED STANDARD<br>
                  Source              : Public-Key Infrastructure
                  (X.509)<br>
                  Stream              : IETF<br>
                  Verifying Party     : IESG<br>
                </blockquote>
              </div>
              _______________________________________________<br>
              pkix mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a><br>
              To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a><br>
            </div>
          </blockquote>
        </div>
        <br>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre class="moz-quote-pre" wrap="">_______________________________________________
pkix mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
</pre>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>

--------------an77WlqxJzwYsWPnktqtmryM--


--===============8201264161095115890==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK

--===============8201264161095115890==--