[pkix] Re: [Technical Errata Reported] RFC3280 (9097 )

Denis <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
RFC 3280 has been replaced by RFC 5280. Hence, this errata report on  
RFC 3280  is irrelevant.

    Request for Comments: 5280
    Obsoletes: 3280, 4325, 4630

However the same text is present in RFC 5280. See my comments below.

> The following errata report has been submitted for RFC3280,
> "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"
>
> --------------------------------------
> You may review the report below and at:
> https://errata.rfc-editor.org/eid9097/
>
> --------------------------------------
> Type: Technical
> Reported by: Peng Yuan<[email protected]>
>
> Section 4.1.2.2 says:
>
> Original Text
> -------------
> The serial number MUST be a positive integer assigned by the CA to
>     each certificate.  It MUST be unique for each certificate issued by a
>     given CA (i.e., the issuer name and serial number identify a unique
>     certificate).  CAs MUST force the serialNumber to be a non-negative
>     integer.
>
> Corrected Text
> --------------
> The serial number MUST be a positive integer assigned by the CA to
>     each certificate.  It MUST be unique for each certificate issued by
>     a given CA (i.e., the issuer name and serial number identify a
>     unique certificate).  CAs MUST force the serialNumber to be
>     positive integer.
>
> Notes
> -----
> r/non-negative/positive
> The text contains inconsistent requirements for the certificate
> serialNumber.
>
> The first sentence requires the serial number to be a positive integer, which excludes zero.
>
> However, the last sentence requires CAs to force the serialNumber to be a non-negative integer,
> which permits zero.

Zero is neither positive nor negative, it is neutral; hence the current 
text is not incorrect.
The proposed corrected text does not clarify whether zero is permitted 
or not.

Denis

> These two requirements are contradictory and may
> cause ambiguity for certificate issuers regarding whether a serial
> number of zero is permitted. The last sentence should use "positive
> integer" instead of "non-negative integer" to maintain consistency
> within this section.
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> will log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC3280 (draft-ietf-pkix-new-part1)
> --------------------------------------
> Title               : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
> Publication Date    : May 2002
> Author(s)           : R. Housley, W. Polk, W. Ford, D. Solo
> Category            : Proposed Standard
> Source              : pkix (sec)
> Stream              : IETF
> Verifying Party     : IESG
>
> _______________________________________________
> pkix mailing list [email protected]
> To unsubscribe send an email [email protected]

_______________________________________________
pkix mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.