[pkix] Re: more errata

Russ Housley <[email protected]> Mon, 20 Jan 2025 10:31:47 -0500
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
--===============7328646132327868737==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_4F0C1D2C-91C6-4016-80F1-091CED3A6EF3"


--Apple-Mail=_4F0C1D2C-91C6-4016-80F1-091CED3A6EF3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8



> On Jan 19, 2025, at 7:03=E2=80=AFAM, Deb Cooley <[email protected]> =
wrote:
>=20
> RFC5912 (4145, 4244)


 RE: Errata 4145: REJECT

I just compiled the original syntax in RFC 5912.  It worked fine.  Also, =
the definition of SIGNATURE-ALGORITHM provides some explanation:

--  &Value - contains a type definition for the value structure of
--              the signature; if absent, implies that no ASN.1
--              encoding is performed on the value

The errata says that the use of &Value does not work if the signature =
value is not ASN.1 encoded.  They proposed change is one way to handle =
it, but it does not support the many signature values that are ASN.1 =
encoded.


 RE: Errata 4244: ACCEPT

This is a better translation of the old ASN.1 in RFC 5280 to the new =
ASN.1 syntax.


Russ=

--Apple-Mail=_4F0C1D2C-91C6-4016-80F1-091CED3A6EF3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"overflow-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;"><br =
id=3D"lineBreakAtBeginningOfMessage"><div><br><blockquote =
type=3D"cite"><div>On Jan 19, 2025, at 7:03=E2=80=AFAM, Deb Cooley =
&lt;[email protected]&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div><div style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: 400; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;">RFC5912 (4145, =
4244)</div></div></blockquote><div><br></div><br></div>&nbsp;RE: Errata =
4145: REJECT<div><br></div><div>I just compiled the original syntax in =
RFC 5912. &nbsp;It worked fine. &nbsp;Also, the definition of =
SIGNATURE-ALGORITHM provides some =
explanation:</div><div><br></div><div><div>-- &nbsp;&amp;Value - =
contains a type definition for the value structure of</div><div>-- =
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;the signature; if =
absent, implies that no ASN.1</div><div>-- &nbsp; &nbsp; &nbsp; &nbsp; =
&nbsp; &nbsp; &nbsp;encoding is performed on the =
value</div></div><div><br></div><div>The errata says that the use of =
&amp;Value does not work if the signature value is not ASN.1 encoded. =
&nbsp;They proposed change is one way to handle it, but it does not =
support the many signature values that are ASN.1 =
encoded.</div><div><br></div><div><br></div><div>&nbsp;RE: Errata 4244: =
ACCEPT</div><div><br></div><div>This is a better translation of the old =
ASN.1 in RFC 5280 to the new ASN.1 =
syntax.</div><div><br></div><div><br></div><div>Russ</div></body></html>=

--Apple-Mail=_4F0C1D2C-91C6-4016-80F1-091CED3A6EF3--


--===============7328646132327868737==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK

--===============7328646132327868737==--