[pkix] Re: [Technical Errata Reported] RFC5280 (8789 )
Deb Cooley <[email protected]> Wed, 4 Mar 2026 09:21:07 -0500
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <CAGgd1OeNdPfQizPt_wRn_hNJsSLiw=o0qZPdRu2pNA_pOr2HiQ@mail.gmail.com> |
--===============4505846138096274684== Content-Type: multipart/alternative; boundary="00000000000087a419064c33888e" --00000000000087a419064c33888e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable This is what the RFC editor has done - deleted 8789 as a duplicate, and left 5802 as validated. They aren't sure why the duplicate slipped through. Deb On Tue, Mar 3, 2026 at 5:37=E2=80=AFPM StJohns, Michael <msj@nthpermutation= .com> wrote: > Change the current one to rejected - duplicate. Leave the other one > alone. > > Neither errata has any meaningful real world impact however they=E2=80=99= re > resolved. > > Mike > > On Tue, Mar 3, 2026 at 17:33 Deb Cooley <[email protected]> wrote: > >> And as Corey has pointed out I validated the same basic text (errata >> 5802) back in 2024. >> >> So now we have the same basic hunk of text both 'validated' and 'HFDU'. >> That's fantastic. >> >> Deb >> >> On Tue, Mar 3, 2026 at 3:15=E2=80=AFPM Paul Hoffman <[email protected]= > wrote: >> >>> Caution: dead horse beating ahead. >>> >>> On 3 Mar 2026, at 12:02, Tim Hollebeek wrote: >>> >>> > Right, but for an errata to be appropriate, the original text has to >>> actually be "in error", not just that "some of us would write something >>> different if we were writing it today". I actually find the comment ver= y >>> useful, as it correctly indicates that these EKUs were in fact intended >>> primarily for web usage at the time the document was written. >>> >>> "intended primarily for web usage" was true in RFC 2459 in 1999. It was >>> much less true in RFC 3280 and then RFC 5280. Also, note that the >>> definition says nothing about "intended primarily for". >>> >>> > I've actually suggested a few times that we should fix the situation >>> by having two new EKUs (one for WebPKI and one for non-web), but there = are >>> drawbacks to that approach, and it should be a new RFC draft, not an er= rata. >>> >>> While I fully agree with "should be a new RFC", I think that RFC should >>> likely be titled "EKUs Considered Meaningless" and should deprecate the >>> EKUs, not add to the confusion. >>> >>> --Paul Hoffman >>> >>> _______________________________________________ >>> pkix mailing list -- [email protected] >>> To unsubscribe send an email to [email protected] >>> >> _______________________________________________ >> pkix mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> > --00000000000087a419064c33888e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>This is what the RFC editor has done - deleted 8789 a= s a duplicate, and left 5802 as validated.</div><div><br></div><div>They ar= en't sure why the duplicate slipped through.</div><div><br></div><div>D= eb</div></div><br><div class=3D"gmail_quote gmail_quote_container"><div dir= =3D"ltr" class=3D"gmail_attr">On Tue, Mar 3, 2026 at 5:37=E2=80=AFPM StJohn= s, Michael <<a href=3D"mailto:[email protected]">msj@nthpermutation= .com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"mar= gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1= ex"><div dir=3D"auto">Change the current one to rejected - duplicate.=C2=A0= Leave the other one alone. =C2=A0=C2=A0</div><div dir=3D"auto"><br></div><= div dir=3D"auto">Neither errata has any meaningful real world impact howeve= r they=E2=80=99re resolved. =C2=A0</div><div dir=3D"auto"><br></div><div di= r=3D"auto">Mike</div><div dir=3D"auto"><br><div class=3D"gmail_quote" dir= =3D"auto"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Mar 3, 2026 at 17:3= 3 Deb Cooley <<a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quo= te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204= );padding-left:1ex"><div dir=3D"ltr"><div>And as Corey has pointed out I va= lidated the same basic text (errata 5802) back in 2024.=C2=A0=C2=A0</div><d= iv><br></div><div>So now we have the same basic hunk of text both 'vali= dated' and 'HFDU'.=C2=A0 That's fantastic.</div></div><div = dir=3D"ltr"><div><br></div><div>Deb</div></div><br><div class=3D"gmail_quot= e"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Mar 3, 2026 at 3:15=E2=80= =AFPM Paul Hoffman <<a href=3D"mailto:[email protected]" target=3D"_bl= ank">[email protected]</a>> wrote:<br></div><blockquote class=3D"gmail= _quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204= ,204);padding-left:1ex">Caution: dead horse beating ahead.<br> <br> On 3 Mar 2026, at 12:02, Tim Hollebeek wrote:<br> <br> > Right, but for an errata to be appropriate, the original text has to a= ctually be "in error", not just that "some of us would write= something different if we were writing it today". I actually find the= comment very useful, as it correctly indicates that these EKUs were in fac= t intended primarily for web usage at the time the document was written.<br= > <br> "intended primarily for web usage" was true in RFC 2459 in 1999. = It was much less true in RFC 3280 and then RFC 5280. Also, note that the de= finition says nothing about "intended primarily for".<br> <br> > I've actually suggested a few times that we should fix the situati= on by having two new EKUs (one for WebPKI and one for non-web), but there a= re drawbacks to that approach, and it should be a new RFC draft, not an err= ata.<br> <br> While I fully agree with "should be a new RFC", I think that RFC = should likely be titled "EKUs Considered Meaningless" and should = deprecate the EKUs, not add to the confusion.<br> <br> --Paul Hoffman<br> <br> _______________________________________________<br> pkix mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">pki= [email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" targ= et=3D"_blank">[email protected]</a><br> </blockquote></div> _______________________________________________<br> pkix mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">pki= [email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" targ= et=3D"_blank">[email protected]</a><br> </blockquote></div></div> </blockquote></div> --00000000000087a419064c33888e-- --===============4505846138096274684== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IHBraXgtbGVhdmVAaWV0Zi5vcmcK --===============4505846138096274684==--