Re: [Acme] [Technical Errata Reported] RFC8555 (7565)
Aaron Gable <aaron@letsencrypt.org> Thu, 13 July 2023 20:52 UTC
Return-Path: <aaron@letsencrypt.org>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CDD49C15155C for <acme@ietfa.amsl.com>; Thu, 13 Jul 2023 13:52:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=letsencrypt.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bLtCG_4WirUz for <acme@ietfa.amsl.com>; Thu, 13 Jul 2023 13:52:06 -0700 (PDT)
Received: from mail-qt1-x832.google.com (mail-qt1-x832.google.com [IPv6:2607:f8b0:4864:20::832]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8413BC151701 for <acme@ietf.org>; Thu, 13 Jul 2023 13:52:06 -0700 (PDT)
Received: by mail-qt1-x832.google.com with SMTP id d75a77b69052e-403aa5d07caso9142221cf.0 for <acme@ietf.org>; Thu, 13 Jul 2023 13:52:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=letsencrypt.org; s=google; t=1689281525; x=1691873525; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=EHUS5uOdRcA8RI+GdWa6qYwrQ3ekONdQjru0HokC51Y=; b=KNmTvXArOwdELy4Frc/lVFxbq/UKppgI6+2cEDe4SneF4qa1/ddXDAG/cYojkXY9Df sPX9teTFYYgxRzEpl4O5tfWk429QGD60dkbVvQ+50CmC+ygXvyoCo4jq0/wTC3ubPXtz i/xC5XoejTnN+ZlcoIxSHCP86whIir1NYYjMs=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1689281525; x=1691873525; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=EHUS5uOdRcA8RI+GdWa6qYwrQ3ekONdQjru0HokC51Y=; b=U+HxqNz5oCdeNcoQ7P/57AueG02p1/SqtKhQiIjpkqi1AbmRbnAQsx377kEKiPV7Bj 44Nm3qwpl+xw0bqT/2dpbOIFx+7d3RELmlKQ/rinB9o4+XKELERY6WsWG7IOwtMiufvB VdPJcis5Qr71hra43MlEz4RAdDEehGtQMTfbVk2P3TTd7N+dbBYUJ/Md75kENOAubWDb MS+qr0q49ZPuIri65vTypffTafGSo3pHu6DVGyeMjBgX8X9KwOLsAJe1xt+Urfhp5mdE JK3zxayF2jv5R/dljZtIBxfKv45yxZnmUYFJtkJCikUlozEsoQqDIW7vNbR95ghewwQ/ YooQ==
X-Gm-Message-State: ABy/qLa+aj9DZV+Ws6wVHw0I/yI8TTGfnGnoesyHoJMuesB3anxRkksR SyFFB9toDtPC7OfFl5Yt19FMcHbbknFo0EKUE/qaDw==
X-Google-Smtp-Source: APBJJlGZUGzgW42Vfv1Cpj/adqSbx6Yr1NhRBS+NebkzDX8yMZeFpVsMOOIFGZgpa5uJrfo56ZaTRszJ/XFnhQVxfm8=
X-Received: by 2002:a05:622a:c8:b0:403:a63d:9a2e with SMTP id p8-20020a05622a00c800b00403a63d9a2emr3460545qtw.10.1689281525598; Thu, 13 Jul 2023 13:52:05 -0700 (PDT)
MIME-Version: 1.0
References: <20230713161911.45BA9E6638@rfcpa.amsl.com> <CAL02cgQw8VT-+6=K94tjVt=stF_Z_OKkzyS7hqHFnKXKj_+Sig@mail.gmail.com>
In-Reply-To: <CAL02cgQw8VT-+6=K94tjVt=stF_Z_OKkzyS7hqHFnKXKj_+Sig@mail.gmail.com>
From: Aaron Gable <aaron@letsencrypt.org>
Date: Thu, 13 Jul 2023 13:51:54 -0700
Message-ID: <CAEmnErfEBsPK5WorQ3C+xYf87Er-nSHf+kFPDS92257OAM6eNA@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Cc: RFC Errata System <rfc-editor@rfc-editor.org>, jsha@eff.org, cpu@letsencrypt.org, jdkasten@umich.edu, rdd@cert.org, paul.wouters@aiven.io, decoole@radium.ncsc.mil, debcooley1@gmail.com, ynir.ietf@gmail.com, Paul@rasdoc.com, acme@ietf.org
Content-Type: multipart/alternative; boundary="0000000000004264ca060064819a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/M_sMAEp6C8BJfsJaaVwxJb07Ovc>
X-Mailman-Approved-At: Fri, 14 Jul 2023 03:00:56 -0700
Subject: Re: [Acme] [Technical Errata Reported] RFC8555 (7565)
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Jul 2023 20:52:11 -0000
Yeah, both of these clarifications (the existing one about additional prepended zero octets, and the new one about leading zeros) are explicitly laid out in RFC 7518: > Section 3.4 Digital Signature with ECDSA > ... > The octet sequence representations MUST NOT be shortened to omit any leading zero octets contained in the values. > Section 6.3.1.1 "n" (Modulus) Parameter > ... > Note that implementers have found that some cryptographic libraries > prefix an extra zero-valued octet to the modulus representations they > return, for instance, returning 257 octets for a 2048-bit key, rather > than 256. Implementations using such libraries will need to take > care to omit the extra octet from the base64url-encoded > representation. It's not clear to me why RFC 8555 has a reminder for *either* of them, but I don't think there's any particular harm in having a reminder for both, either. Aaron On Thu, Jul 13, 2023 at 1:31 PM Richard Barnes <rlb@ipv.sx> wrote: > This seems correct to me. I would mark it Verified. > > On Thu, Jul 13, 2023 at 12:19 PM RFC Errata System < > rfc-editor@rfc-editor.org> wrote: > >> The following errata report has been submitted for RFC8555, >> "Automatic Certificate Management Environment (ACME)". >> >> -------------------------------------- >> You may review the report below and at: >> https://www.rfc-editor.org/errata/eid7565 >> >> -------------------------------------- >> Type: Technical >> Reported by: Paul Breed <Paul@Rasdoc.com> >> >> Section: 8.1 >> >> Original Text >> ------------- >> The "Thumbprint" step indicates the computation specified in >> [RFC7638], using the SHA-256 digest [FIPS180-4]. As noted in >> [RFC7518] any prepended zero octets in the fields of a JWK object >> MUST be stripped before doing the computation. >> >> Corrected Text >> -------------- >> The "Thumbprint" step indicates the computation specified in >> [RFC7638], using the SHA-256 digest [FIPS180-4]. As noted in >> [RFC7518] any additional prepended zero octets in the fields of a JWK >> object >> MUST be stripped before doing the computation. >> Fixed length fields such as found in ECDSA keys should be their >> natural length and >> leading zero octets should not be stripped. >> >> Notes >> ----- >> This comment was really aimed at the leading 0 octet sometimes used with >> RSA, but the comment is not RSA specific. ECDSA keys can have fixed length >> fields (X,Y) where there can be leading zeros. This led me astray in >> implementing an ECDSA thumbprint routine for ACME. The result was that >> 1/128 ECDSA keys failed to generate t humbp[rint as leading zeros were >> removed. >> >> Instructions: >> ------------- >> This erratum is currently posted as "Reported". If necessary, please >> use "Reply All" to discuss whether it should be verified or >> rejected. When a decision is reached, the verifying party >> can log in to change the status and edit the report, if necessary. >> >> -------------------------------------- >> RFC8555 (draft-ietf-acme-acme-18) >> -------------------------------------- >> Title : Automatic Certificate Management Environment (ACME) >> Publication Date : March 2019 >> Author(s) : R. Barnes, J. Hoffman-Andrews, D. McCarney, J. >> Kasten >> Category : PROPOSED STANDARD >> Source : Automated Certificate Management Environment >> Area : Security >> Stream : IETF >> Verifying Party : IESG >> > _______________________________________________ > Acme mailing list > Acme@ietf.org > https://www.ietf.org/mailman/listinfo/acme >
- Re: [Acme] [Technical Errata Reported] RFC8555 (7… Richard Barnes
- [Acme] [Technical Errata Reported] RFC8555 (7565) RFC Errata System
- Re: [Acme] [Technical Errata Reported] RFC8555 (7… Aaron Gable
- Re: [Acme] [Technical Errata Reported] RFC8555 (7… Corey Bonnell
- Re: [Acme] [Technical Errata Reported] RFC8555 (7… Deb Cooley