[pkix] Re: [Technical Errata Reported] RFC3280 (9097 )
Russ Housley <[email protected]>
| Newsgroups | gmane.ietf.x509 |
|---|---|
| Message-ID | <[email protected]> |
RRC 3280 is obsolete; it has been replaced by RFC 5280. I do not see any reason to process this errata. Russ > On Aug 10, 2026, at 12:42 PM, [email protected] wrote: > > The following errata report has been submitted for RFC3280, > "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile" > > -------------------------------------- > You may review the report below and at: > https://errata.rfc-editor.org/eid9097/ > > -------------------------------------- > Type: Technical > Reported by: Peng Yuan <[email protected]> > > Section 4.1.2.2 says: > > Original Text > ------------- > The serial number MUST be a positive integer assigned by the CA to > each certificate. It MUST be unique for each certificate issued by a > given CA (i.e., the issuer name and serial number identify a unique > certificate). CAs MUST force the serialNumber to be a non-negative > integer. > > Corrected Text > -------------- > The serial number MUST be a positive integer assigned by the CA to > each certificate. It MUST be unique for each certificate issued by > a given CA (i.e., the issuer name and serial number identify a > unique certificate). CAs MUST force the serialNumber to be > positive integer. > > Notes > ----- > r/non-negative/positive > The text contains inconsistent requirements for the certificate > serialNumber. The first sentence requires the serial number to be a > positive integer, which excludes zero. However, the last sentence > requires CAs to force the serialNumber to be a non-negative integer, > which permits zero. These two requirements are contradictory and may > cause ambiguity for certificate issuers regarding whether a serial > number of zero is permitted. The last sentence should use "positive > integer" instead of "non-negative integer" to maintain consistency > within this section. > > Instructions: > ------------- > This erratum is currently posted as "Reported". Please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party > will log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC3280 (draft-ietf-pkix-new-part1) > -------------------------------------- > Title : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile > Publication Date : May 2002 > Author(s) : R. Housley, W. Polk, W. Ford, D. Solo > Category : Proposed Standard > Source : pkix (sec) > Stream : IETF > Verifying Party : IESG _______________________________________________ pkix mailing list -- [email protected] To unsubscribe send an email to [email protected]