Re: [certid] Comments on draft-saintandre-tls-server-id-check-04
Nelson B Bolyard <nelson@bolyard.me> Fri, 04 June 2010 17:11 UTC
Return-Path: <nelson@bolyard.me>
X-Original-To: certid@core3.amsl.com
Delivered-To: certid@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
with ESMTP id 3EF6A3A69D8 for <certid@core3.amsl.com>;
Fri, 4 Jun 2010 10:11:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.001
X-Spam-Level:
X-Spam-Status: No,
score=0.001 tagged_above=-999 required=5 tests=[BAYES_50=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QydOHHXc2xjm for
<certid@core3.amsl.com>; Fri, 4 Jun 2010 10:11:46 -0700 (PDT)
Received: from smtpauth17.prod.mesa1.secureserver.net
(smtpauth17.prod.mesa1.secureserver.net [64.202.165.29]) by core3.amsl.com
(Postfix) with SMTP id 54AE53A687E for <certid@ietf.org>;
Fri, 4 Jun 2010 10:11:45 -0700 (PDT)
Received: (qmail 7192 invoked from network); 4 Jun 2010 17:11:31 -0000
Received: from unknown (24.5.142.42) by smtpauth17.prod.mesa1.secureserver.net
(64.202.165.29) with ESMTP; 04 Jun 2010 17:11:30 -0000
Message-ID: <4C0933C1.4000004@bolyard.me>
Date: Fri, 04 Jun 2010 10:11:29 -0700
From: Nelson B Bolyard <nelson@bolyard.me>
Organization: Network Security Services
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1;
rv:1.9.1b1pre) Gecko/20081004 NOT Firefox/2.0 SeaMonkey/2.0a2pre
MIME-Version: 1.0
To: Peter Sylvester <peter.sylvester@edelweb.fr>
References: <201005311518.o4VFIHAw022209@fs4113.wdf.sap.corp> <4C08244D.9010809@bolyard.me>
<4C08C8EC.1050200@edelweb.fr>
In-Reply-To: <4C08C8EC.1050200@edelweb.fr>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Cc: certid@ietf.org
Subject: Re: [certid] Comments on draft-saintandre-tls-server-id-check-04
X-BeenThere: certid@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Representation and verification of identity in certificates
<certid.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/certid>
List-Post: <mailto:certid@ietf.org>
List-Help: <mailto:certid-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/certid>,
<mailto:certid-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 04 Jun 2010 17:11:48 -0000
On 2010-06-04 02:35 PDT, Peter Sylvester wrote: >> The phrease "the (most specific) Common Name field in the subject field" >> is not plural. There is at most one Common Name attribute in the name >> that is *the* most specific one. The words "most specific" refer to its >> position in the list of RDNs, which are arranged (as encoded in the >> certificate Name field) from most general (first) to most specific >> (last). So, the most specific Common Name is the last of the Common >> Name attributes in the sequence of RDNs, as encoded in the certificate. >> > You can have two AVAs of the same type in the on RDN, i.e. > two common names in the same RDN. There the interpretation > of most-significant is not clear. Agreed, in principle. In practice, I've never seen a certificate produced by a real CA with multiple AVAs in a single RDN. I've seen them in certs produced by test scripts, and by people playing with OpenSSL. :) > There term of 2818 itself is wrong, there is no such thing > a 'Common Name field'. Agreed, whole heartedly. Still, we know what they meant. But I'm glad this mistake is not repeated in your draft. > If one puts no more than one AVA of type CN into an > RDN, and only one of such RDN, the result is ok. I agree with the first part of that. Don't see why the second restriction is necessary for the result to be OK. > The "(most specific)" is a kind of hint not to put more > than one unless you want to attack like a \0 :-) Yes, an attach to which software that ignores the "most specific" requirement will be vulnerable. > /P > > PS: I "like" the *.ietf.org cert use by the server 'ietf.org' :-)
- [certid] Comments on draft-saintandre-tls-server-… Nelson B Bolyard
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… =JeffH
- Re: [certid] Comments on draft-saintandre-tls-ser… Nelson B Bolyard
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… =JeffH
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… =JeffH
- Re: [certid] Comments on draft-saintandre-tls-ser… Sean Turner
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Love Hörnquist Åstrand
- Re: [certid] Comments on draft-saintandre-tls-ser… ArkanoiD
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… =JeffH
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… Love Hörnquist Åstrand
- Re: [certid] Comments on draft-saintandre-tls-ser… Joe Orton
- Re: [certid] Comments on draft-saintandre-tls-ser… Kaspar Brand
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Sylvester
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Sylvester
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Sylvester
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… ArkanoiD
- Re: [certid] Comments on draft-saintandre-tls-ser… Henry B. Hotz
- Re: [certid] Comments on draft-saintandre-tls-ser… Matt McCutchen
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Nelson B Bolyard
- Re: [certid] Comments on draft-saintandre-tls-ser… Sean Turner
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Saint-Andre
- Re: [certid] Comments on draft-saintandre-tls-ser… Peter Sylvester
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… Nelson B Bolyard
- Re: [certid] Comments on draft-saintandre-tls-ser… Martin Rex
- Re: [certid] Comments on draft-saintandre-tls-ser… Nelson B Bolyard
- [certid] Moving RFC 2818 to Historic (was Comment… Alexey Melnikov
- Re: [certid] Moving RFC 2818 to Historic (was Com… Peter Saint-Andre
- Re: [certid] Moving RFC 2818 to Historic (was Com… Sean Turner
- Re: [certid] Moving RFC 2818 to Historic (was Com… Alexey Melnikov
- Re: [certid] Comments on draft-saintandre-tls-ser… Henry B. Hotz