[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )

Michael StJohns <[email protected]> Tue, 29 Oct 2024 13:51:38 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============6435675175216325616==
Content-Type: multipart/alternative;
 boundary="------------fLtdH00liUViiWFIeDR4URBw"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------fLtdH00liUViiWFIeDR4URBw
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

And this is what I get for going backwards in my emails.   I think 6402 
fixed it properly - ignore my email.

We *really* need a "Rejected - fixed in later RFC" or "Rejected OBE" status.

Mike

On 10/29/2024 11:43 AM, Deb Cooley wrote:
> obsoleted by RFC 6402?
>
> On Tue, Oct 29, 2024 at 11:41 AM Deb Cooley <[email protected]> wrote:
>
>     opinions?
>
>     Deb
>
>     On Sat, Oct 12, 2024 at 6:36 AM RFC Errata System
>     <[email protected]> wrote:
>
>         The following errata report has been submitted for RFC5272,
>         "Certificate Management over CMS (CMC)".
>
>         --------------------------------------
>         You may review the report below and at:
>         https://www.rfc-editor.org/errata/eid8137
>
>         --------------------------------------
>         Type: Technical
>         Reported by: David von Oheimb <[email protected]>
>
>         Section: C.1
>
>         Original Text
>         -------------
>         NoSignatureValue contains the hash of the certification request.
>
>         Corrected Text
>         --------------
>         NoSignatureValue contains the SHA-1 hash value of the
>         certification request.
>         The hash value given by NoSignatureValue SHOULD be ignored.
>
>         Notes
>         -----
>         The hash value was not sufficiently defined because the choice
>         of the hash algorithm was not specified.
>         At that time presumably the use of SHA-1 was implied.
>
>         I suggest requiring SHA-1 here simply for backward compatibility.
>         >From today's perspective more flexibility may be demanded and
>         SHA-1 likely no more is the best choice.
>
>         Anyway I see no real value in NoSignatureValue (pun intended),
>         so it should not matter.
>         For this reason I propose ignoring the hash value.
>
>         Instructions:
>         -------------
>         This erratum is currently posted as "Reported". (If it is
>         spam, it
>         will be removed shortly by the RFC Production Center.) Please
>         use "Reply All" to discuss whether it should be verified or
>         rejected. When a decision is reached, the verifying party
>         will log in to change the status and edit the report, if
>         necessary.
>
>         --------------------------------------
>         RFC5272 (draft-ietf-pkix-2797-bis-07)
>         --------------------------------------
>         Title               : Certificate Management over CMS (CMC)
>         Publication Date    : June 2008
>         Author(s)           : J. Schaad, M. Myers
>         Category            : PROPOSED STANDARD
>         Source              : Public-Key Infrastructure (X.509)
>         Stream              : IETF
>         Verifying Party     : IESG
>
>
> _______________________________________________
> pkix mailing list [email protected]
> To unsubscribe send an email [email protected]


--------------fLtdH00liUViiWFIeDR4URBw
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">And this is what I get for going
      backwards in my emails.   I think 6402 fixed it properly - ignore
      my email.  <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">We *really* need a "Rejected - fixed in
      later RFC" or "Rejected OBE" status.</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Mike<br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">On 10/29/2024 11:43 AM, Deb Cooley
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAGgd1Od4u_f7yCuQVEtwzvR9_xa+9QJ9D9Ehfe-v0oQeZOza8g@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">obsoleted by RFC 6402?<br>
      </div>
      <br>
      <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On Tue, Oct 29, 2024 at
          11:41 AM Deb Cooley &lt;<a href="mailto:[email protected]"
            moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
          wrote:<br>
        </div>
        <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
          <div dir="ltr">
            <div>opinions?</div>
            <div><br>
            </div>
            <div>Deb<br>
            </div>
          </div>
          <br>
          <div class="gmail_quote">
            <div dir="ltr" class="gmail_attr">On Sat, Oct 12, 2024 at
              6:36 AM RFC Errata System &lt;<a
                href="mailto:[email protected]" target="_blank"
                moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a>&gt;
              wrote:<br>
            </div>
            <blockquote class="gmail_quote"
style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">The
              following errata report has been submitted for RFC5272,<br>
              "Certificate Management over CMS (CMC)".<br>
              <br>
              --------------------------------------<br>
              You may review the report below and at:<br>
              <a href="https://www.rfc-editor.org/errata/eid8137"
                rel="noreferrer" target="_blank" moz-do-not-send="true"
                class="moz-txt-link-freetext">https://www.rfc-editor.org/errata/eid8137</a><br>
              <br>
              --------------------------------------<br>
              Type: Technical<br>
              Reported by: David von Oheimb &lt;<a
                href="mailto:[email protected]"
                target="_blank" moz-do-not-send="true"
                class="moz-txt-link-freetext">[email protected]</a>&gt;<br>
              <br>
              Section: C.1<br>
              <br>
              Original Text<br>
              -------------<br>
              NoSignatureValue contains the hash of the certification
              request. <br>
              <br>
              Corrected Text<br>
              --------------<br>
              NoSignatureValue contains the SHA-1 hash value of the
              certification request. <br>
              The hash value given by NoSignatureValue SHOULD be
              ignored.<br>
              <br>
              Notes<br>
              -----<br>
              The hash value was not sufficiently defined because the
              choice of the hash algorithm was not specified.<br>
              At that time presumably the use of SHA-1 was implied.<br>
              <br>
              I suggest requiring SHA-1 here simply for backward
              compatibility.<br>
              &gt;From today's perspective more flexibility may be
              demanded and SHA-1 likely no more is the best choice.<br>
              <br>
              Anyway I see no real value in NoSignatureValue (pun
              intended), so it should not matter.<br>
              For this reason I propose ignoring the hash value.<br>
              <br>
              Instructions:<br>
              -------------<br>
              This erratum is currently posted as "Reported". (If it is
              spam, it <br>
              will be removed shortly by the RFC Production Center.)
              Please<br>
              use "Reply All" to discuss whether it should be verified
              or<br>
              rejected. When a decision is reached, the verifying party 
              <br>
              will log in to change the status and edit the report, if
              necessary.<br>
              <br>
              --------------------------------------<br>
              RFC5272 (draft-ietf-pkix-2797-bis-07)<br>
              --------------------------------------<br>
              Title               : Certificate Management over CMS
              (CMC)<br>
              Publication Date    : June 2008<br>
              Author(s)           : J. Schaad, M. Myers<br>
              Category            : PROPOSED STANDARD<br>
              Source              : Public-Key Infrastructure (X.509)<br>
              Stream              : IETF<br>
              Verifying Party     : IESG<br>
            </blockquote>
          </div>
        </blockquote>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre class="moz-quote-pre" wrap="">_______________________________________________
pkix mailing list -- <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
To unsubscribe send an email to <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
</pre>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>

--------------fLtdH00liUViiWFIeDR4URBw--


--===============6435675175216325616==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK

--===============6435675175216325616==--