[Anima] [Errata Held for Document Update] RFC8994 (7558)

RFC Errata System <rfc-editor@rfc-editor.org> Mon, 15 January 2024 10:57 UTC

Return-Path: <wwwrun@rfcpa.amsl.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC98DC14F5ED; Mon, 15 Jan 2024 02:57:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.658
X-Spam-Level:
X-Spam-Status: No, score=-1.658 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tn-uGPVyL4IH; Mon, 15 Jan 2024 02:57:33 -0800 (PST)
Received: from rfcpa.amsl.com (rfcpa.amsl.com [50.223.129.200]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 142CBC14F5E5; Mon, 15 Jan 2024 02:57:33 -0800 (PST)
Received: by rfcpa.amsl.com (Postfix, from userid 499) id CB5831A49952; Mon, 15 Jan 2024 02:57:32 -0800 (PST)
To: william.atwood@concordia.ca, tte+ietf@cs.fau.de, Michael.H.Behringer@gmail.com, sbjarnason@arbor.net
From: RFC Errata System <rfc-editor@rfc-editor.org>
Cc: rwilton@cisco.com, iesg@ietf.org, anima@ietf.org, rfc-editor@rfc-editor.org
Content-Type: text/plain; charset="UTF-8"
Message-Id: <20240115105732.CB5831A49952@rfcpa.amsl.com>
Date: Mon, 15 Jan 2024 02:57:32 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/uHgGUaZIeVtk7LfttJm8CTEa3JM>
Subject: [Anima] [Errata Held for Document Update] RFC8994 (7558)
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Jan 2024 10:57:37 -0000

The following errata report has been held for document update 
for RFC8994, "An Autonomic Control Plane (ACP)". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid7558

--------------------------------------
Status: Held for Document Update
Type: Editorial

Reported by: J. William Atwood <william.atwood@concordia.ca>
Date Reported: 2023-07-02
Held by: Rob Wilton (IESG)

Section: 6.2.1

Original Text
-------------
   ACP nodes MUST NOT support certificates with RSA public keys of less
   than a 2048-bit modulus or curves with group order of less than 256
   bits.  They MUST support certificates with RSA public keys with
   2048-bit modulus and MAY support longer RSA keys.  They MUST support
   certificates with ECC public keys using NIST P-256 curves and SHOULD
   support P-384 and P-521 curves.

   ACP nodes MUST NOT support certificates with RSA public keys whose
   modulus is less than 2048 bits, or certificates whose ECC public keys
   are in groups whose order is less than 256 bits.  RSA signing
   certificates with 2048-bit public keys MUST be supported, and such
   certificates with longer public keys MAY be supported.  ECDSA
   certificates using the NIST P-256 curve MUST be supported, and such
   certificates using the P-384 and P-521 curves SHOULD be supported.

Corrected Text
--------------
   ACP nodes MUST NOT support certificates with RSA public keys whose
   modulus is less than 2048 bits, or certificates whose ECC public keys
   are in groups whose order is less than 256 bits.  RSA signing
   certificates with 2048-bit public keys MUST be supported, and such
   certificates with longer public keys MAY be supported.  ECDSA
   certificates using the NIST P-256 curve MUST be supported, and such
   certificates using the P-384 and P-521 curves SHOULD be supported.

Notes
-----
The second paragraph in the original text appears to be a more carefully-written version of the first paragraph.  Therefore the first paragraph should be deleted and the second paragraph retained.

--------------------------------------
RFC8994 (draft-ietf-anima-autonomic-control-plane-30)
--------------------------------------
Title               : An Autonomic Control Plane (ACP)
Publication Date    : May 2021
Author(s)           : T. Eckert, Ed., M. Behringer, Ed., S. Bjarnason
Category            : PROPOSED STANDARD
Source              : Autonomic Networking Integrated Model and Approach
Area                : Operations and Management
Stream              : IETF
Verifying Party     : IESG