[pkix] Re: [Technical Errata Reported] RFC3280 (9097 )
Denis <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
RFC 3280 has been replaced by RFC 5280. Hence, this errata report on
RFC 3280 is irrelevant.
Request for Comments: 5280
Obsoletes: 3280, 4325, 4630
However the same text is present in RFC 5280. See my comments below.
> The following errata report has been submitted for RFC3280,
> "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"
>
> --------------------------------------
> You may review the report below and at:
> https://errata.rfc-editor.org/eid9097/
>
> --------------------------------------
> Type: Technical
> Reported by: Peng Yuan<[email protected]>
>
> Section 4.1.2.2 says:
>
> Original Text
> -------------
> The serial number MUST be a positive integer assigned by the CA to
> each certificate. It MUST be unique for each certificate issued by a
> given CA (i.e., the issuer name and serial number identify a unique
> certificate). CAs MUST force the serialNumber to be a non-negative
> integer.
>
> Corrected Text
> --------------
> The serial number MUST be a positive integer assigned by the CA to
> each certificate. It MUST be unique for each certificate issued by
> a given CA (i.e., the issuer name and serial number identify a
> unique certificate). CAs MUST force the serialNumber to be
> positive integer.
>
> Notes
> -----
> r/non-negative/positive
> The text contains inconsistent requirements for the certificate
> serialNumber.
>
> The first sentence requires the serial number to be a positive integer, which excludes zero.
>
> However, the last sentence requires CAs to force the serialNumber to be a non-negative integer,
> which permits zero.
Zero is neither positive nor negative, it is neutral; hence the current
text is not incorrect.
The proposed corrected text does not clarify whether zero is permitted
or not.
Denis
> These two requirements are contradictory and may
> cause ambiguity for certificate issuers regarding whether a serial
> number of zero is permitted. The last sentence should use "positive
> integer" instead of "non-negative integer" to maintain consistency
> within this section.
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> will log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC3280 (draft-ietf-pkix-new-part1)
> --------------------------------------
> Title : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
> Publication Date : May 2002
> Author(s) : R. Housley, W. Polk, W. Ford, D. Solo
> Category : Proposed Standard
> Source : pkix (sec)
> Stream : IETF
> Verifying Party : IESG
>
> _______________________________________________
> pkix mailing list [email protected]
> To unsubscribe send an email [email protected]
_______________________________________________
pkix mailing list -- [email protected]
To unsubscribe send an email to [email protected]