[pkix] [Technical Errata Reported] RFC3280 (9097)

[email protected]
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
The following errata report has been submitted for RFC3280,
"Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"

--------------------------------------
You may review the report below and at:
https://errata.rfc-editor.org/eid9097/

--------------------------------------
Type: Technical
Reported by: Peng Yuan <[email protected]>

Section 4.1.2.2 says:

Original Text
-------------
The serial number MUST be a positive integer assigned by the CA to
   each certificate.  It MUST be unique for each certificate issued by a
   given CA (i.e., the issuer name and serial number identify a unique
   certificate).  CAs MUST force the serialNumber to be a non-negative
   integer.

Corrected Text
--------------
The serial number MUST be a positive integer assigned by the CA to
   each certificate.  It MUST be unique for each certificate issued by
   a given CA (i.e., the issuer name and serial number identify a
   unique certificate).  CAs MUST force the serialNumber to be
   positive integer.

Notes
-----
r/non-negative/positive
The text contains inconsistent requirements for the certificate
serialNumber. The first sentence requires the serial number to be a
positive integer, which excludes zero. However, the last sentence
requires CAs to force the serialNumber to be a non-negative integer,
which permits zero. These two requirements are contradictory and may
cause ambiguity for certificate issuers regarding whether a serial
number of zero is permitted. The last sentence should use "positive
integer" instead of "non-negative integer" to maintain consistency
within this section.

Instructions:
-------------
This erratum is currently posted as "Reported". Please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party  
will log in to change the status and edit the report, if necessary.

--------------------------------------
RFC3280 (draft-ietf-pkix-new-part1)
--------------------------------------
Title               : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
Publication Date    : May 2002
Author(s)           : R. Housley, W. Polk, W. Ford, D. Solo
Category            : Proposed Standard
Source              : pkix (sec)
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
pkix mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.