[pkix] Re: [Technical Errata Reported] RFC3280 (9097 )

Russ Housley <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
RRC 3280 is obsolete; it has been replaced by RFC 5280.  I do not see any reason to process this errata.

Russ

> On Aug 10, 2026, at 12:42 PM, [email protected] wrote:
> 
> The following errata report has been submitted for RFC3280,
> "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"
> 
> --------------------------------------
> You may review the report below and at:
> https://errata.rfc-editor.org/eid9097/
> 
> --------------------------------------
> Type: Technical
> Reported by: Peng Yuan <[email protected]>
> 
> Section 4.1.2.2 says:
> 
> Original Text
> -------------
> The serial number MUST be a positive integer assigned by the CA to
>   each certificate.  It MUST be unique for each certificate issued by a
>   given CA (i.e., the issuer name and serial number identify a unique
>   certificate).  CAs MUST force the serialNumber to be a non-negative
>   integer.
> 
> Corrected Text
> --------------
> The serial number MUST be a positive integer assigned by the CA to
>   each certificate.  It MUST be unique for each certificate issued by
>   a given CA (i.e., the issuer name and serial number identify a
>   unique certificate).  CAs MUST force the serialNumber to be
>   positive integer.
> 
> Notes
> -----
> r/non-negative/positive
> The text contains inconsistent requirements for the certificate
> serialNumber. The first sentence requires the serial number to be a
> positive integer, which excludes zero. However, the last sentence
> requires CAs to force the serialNumber to be a non-negative integer,
> which permits zero. These two requirements are contradictory and may
> cause ambiguity for certificate issuers regarding whether a serial
> number of zero is permitted. The last sentence should use "positive
> integer" instead of "non-negative integer" to maintain consistency
> within this section.
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party  
> will log in to change the status and edit the report, if necessary.
> 
> --------------------------------------
> RFC3280 (draft-ietf-pkix-new-part1)
> --------------------------------------
> Title               : Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
> Publication Date    : May 2002
> Author(s)           : R. Housley, W. Polk, W. Ford, D. Solo
> Category            : Proposed Standard
> Source              : pkix (sec)
> Stream              : IETF
> Verifying Party     : IESG

_______________________________________________
pkix mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.