[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )
Michael StJohns <[email protected]> Tue, 29 Oct 2024 13:41:59 -0400
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============8201264161095115890==
Content-Type: multipart/alternative;
boundary="------------an77WlqxJzwYsWPnktqtmryM"
Content-Language: en-US
This is a multi-part message in MIME format.
--------------an77WlqxJzwYsWPnktqtmryM
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Actually -
The text "The parameters for id-alg-noSignature..." implies an
AlgorithmIdentifier rather than just an OBJECT IDENTIFIER. Instead -
NoSignatureAlgorithm SIGNATURE-ALGORITHM ::= { IDENTIFIER
id-alg-noSignature PARAMS TYPE DIGEST-ALGORITHM are preferredAbsent } --
the digest algorithm default is SHA1
Or something similar.
Mike
On 10/29/2024 11:47 AM, Russ Housley wrote:
> Sean Turner was looking at this recently. Sean, can you offer an
> opinion?
>
> Russ
>
>> On Oct 29, 2024, at 11:41 AM, Deb Cooley <[email protected]> wrote:
>>
>> opinions?
>>
>> Deb
>>
>> On Sat, Oct 12, 2024 at 6:36 AM RFC Errata System
>> <[email protected]> wrote:
>>
>> The following errata report has been submitted for RFC5272,
>> "Certificate Management over CMS (CMC)".
>>
>> --------------------------------------
>> You may review the report below and at:
>> https://www.rfc-editor.org/errata/eid8137
>>
>> --------------------------------------
>> Type: Technical
>> Reported by: David von Oheimb <[email protected]>
>>
>> Section: C.1
>>
>> Original Text
>> -------------
>> NoSignatureValue contains the hash of the certification request.
>>
>> Corrected Text
>> --------------
>> NoSignatureValue contains the SHA-1 hash value of the
>> certification request.
>> The hash value given by NoSignatureValue SHOULD be ignored.
>>
>> Notes
>> -----
>> The hash value was not sufficiently defined because the choice of
>> the hash algorithm was not specified.
>> At that time presumably the use of SHA-1 was implied.
>>
>> I suggest requiring SHA-1 here simply for backward compatibility.
>> >From today's perspective more flexibility may be demanded and
>> SHA-1 likely no more is the best choice.
>>
>> Anyway I see no real value in NoSignatureValue (pun intended), so
>> it should not matter.
>> For this reason I propose ignoring the hash value.
>>
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". (If it is spam, it
>> will be removed shortly by the RFC Production Center.) Please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party
>> will log in to change the status and edit the report, if necessary.
>>
>> --------------------------------------
>> RFC5272 (draft-ietf-pkix-2797-bis-07)
>> --------------------------------------
>> Title : Certificate Management over CMS (CMC)
>> Publication Date : June 2008
>> Author(s) : J. Schaad, M. Myers
>> Category : PROPOSED STANDARD
>> Source : Public-Key Infrastructure (X.509)
>> Stream : IETF
>> Verifying Party : IESG
>>
>> _______________________________________________
>> pkix mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>
>
> _______________________________________________
> pkix mailing list [email protected]
> To unsubscribe send an email [email protected]
--------------an77WlqxJzwYsWPnktqtmryM
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">Actually -</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">The text "The parameters for
id-alg-noSignature..." implies an AlgorithmIdentifier rather than
just an OBJECT IDENTIFIER. Instead - <br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">NoSignatureAlgorithm
SIGNATURE-ALGORITHM ::= { IDENTIFIER id-alg-noSignature PARAMS
TYPE DIGEST-ALGORITHM are preferredAbsent } -- the digest
algorithm default is SHA1</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Or something similar.</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Mike</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">On 10/29/2024 11:47 AM, Russ Housley
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:[email protected]">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
Sean Turner was looking at this recently. Sean, can you offer an
opinion?
<div><br>
</div>
<div>Russ<br>
<div><br>
<blockquote type="cite">
<div>On Oct 29, 2024, at 11:41 AM, Deb Cooley
<a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a> wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div dir="ltr">
<div>opinions?</div>
<div><br>
</div>
<div>Deb<br>
</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Sat, Oct 12, 2024
at 6:36 AM RFC Errata System <<a
href="mailto:[email protected]"
moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">The
following errata report has been submitted for
RFC5272,<br>
"Certificate Management over CMS (CMC)".<br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href="https://www.rfc-editor.org/errata/eid8137"
rel="noreferrer" target="_blank"
moz-do-not-send="true" class="moz-txt-link-freetext">https://www.rfc-editor.org/errata/eid8137</a><br>
<br>
--------------------------------------<br>
Type: Technical<br>
Reported by: David von Oheimb <<a
href="mailto:[email protected]"
target="_blank" moz-do-not-send="true"
class="moz-txt-link-freetext">[email protected]</a>><br>
<br>
Section: C.1<br>
<br>
Original Text<br>
-------------<br>
NoSignatureValue contains the hash of the
certification request. <br>
<br>
Corrected Text<br>
--------------<br>
NoSignatureValue contains the SHA-1 hash value of the
certification request. <br>
The hash value given by NoSignatureValue SHOULD be
ignored.<br>
<br>
Notes<br>
-----<br>
The hash value was not sufficiently defined because
the choice of the hash algorithm was not specified.<br>
At that time presumably the use of SHA-1 was implied.<br>
<br>
I suggest requiring SHA-1 here simply for backward
compatibility.<br>
>From today's perspective more flexibility may be
demanded and SHA-1 likely no more is the best choice.<br>
<br>
Anyway I see no real value in NoSignatureValue (pun
intended), so it should not matter.<br>
For this reason I propose ignoring the hash value.<br>
<br>
Instructions:<br>
-------------<br>
This erratum is currently posted as "Reported". (If it
is spam, it <br>
will be removed shortly by the RFC Production Center.)
Please<br>
use "Reply All" to discuss whether it should be
verified or<br>
rejected. When a decision is reached, the verifying
party <br>
will log in to change the status and edit the report,
if necessary.<br>
<br>
--------------------------------------<br>
RFC5272 (draft-ietf-pkix-2797-bis-07)<br>
--------------------------------------<br>
Title : Certificate Management over CMS
(CMC)<br>
Publication Date : June 2008<br>
Author(s) : J. Schaad, M. Myers<br>
Category : PROPOSED STANDARD<br>
Source : Public-Key Infrastructure
(X.509)<br>
Stream : IETF<br>
Verifying Party : IESG<br>
</blockquote>
</div>
_______________________________________________<br>
pkix mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a><br>
To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a><br>
</div>
</blockquote>
</div>
<br>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
<pre class="moz-quote-pre" wrap="">_______________________________________________
pkix mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
</pre>
</blockquote>
<p><br>
</p>
</body>
</html>
--------------an77WlqxJzwYsWPnktqtmryM--
--===============8201264161095115890==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK
--===============8201264161095115890==--