[OAUTH-WG] Re: [Editorial Errata Reported] RFC7636 (8458)

Madison Church <mchurch@staff.rfc-editor.org> Wed, 09 July 2025 14:33 UTC

Return-Path: <mchurch@staff.rfc-editor.org>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4B36041E674A for <oauth@mail2.ietf.org>; Wed, 9 Jul 2025 07:33:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=staff-rfc-editor-org.20230601.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1UNmXd8cbXN2 for <oauth@mail2.ietf.org>; Wed, 9 Jul 2025 07:33:10 -0700 (PDT)
Received: from mail-il1-x129.google.com (mail-il1-x129.google.com [IPv6:2607:f8b0:4864:20::129]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D0B5941E6741 for <oauth@ietf.org>; Wed, 9 Jul 2025 07:33:10 -0700 (PDT)
Received: by mail-il1-x129.google.com with SMTP id e9e14a558f8ab-3df2dbe85d1so48883345ab.0 for <oauth@ietf.org>; Wed, 09 Jul 2025 07:33:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=staff-rfc-editor-org.20230601.gappssmtp.com; s=20230601; t=1752071590; x=1752676390; darn=ietf.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=wh5ulzmeFI32tQHI98A2v0B0lKLUxbivqqdtKUtggLM=; b=uWlD6KUZAAVrgiG+rceR4Zq18/+N9V5RXAytfyPNCSC01i/2pVPauB5QegNXQF+oA8 SOvZG6LUzWH6L/038in0NaRx+E9EvUp9FvZhcHsmtefJ9Ll1RN7ZYVn0rSsXHSFiqfh/ tX/lDlhYtvm50gkhv2CnNv0xiAkQMONig2v2AzlwTtOjIcAPaFUL2l/WqiNml7wOJH85 bk1Qxsy3JeMQzPzLG/krpiblsOoueKU9gGT/c7VYBMaJhZFITRD0nGKTbK0l//+3pFKZ CV8yN1V7rJtvL5jD+OZK1wlUTSjArKDm4fY6iZxb0Cne27PDoxZvgxvyUeEL7Ggmov9K +jGQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1752071590; x=1752676390; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=wh5ulzmeFI32tQHI98A2v0B0lKLUxbivqqdtKUtggLM=; b=ZJuOAe75lZVNC+jSWWLgrOg5aScayF8VyGA2Ex6r9ofM7uxY8AMlwklHzquEYtCRGD jEUftv/C6tH8uVEpP0ZpAxGwwLb7qk2/isEOEGxc9RJOO6ImHmIQL00GEgRD8y421ZNH t5tv2xfDl1LFWieN0SvFo763lICu2XNfU8+iRRwFHYDGcUV8cx/guKujsxBmWS87NFUv SaKyrnk9WNpJVZBHMYbprksOTi+JhIMufcIkDg+uKDSbRrILbBt+9uz/UEKzKXH69B1H R7KL1/0xTqDUmBbKHPrVlIYKEZgOycsC27uX9IXnrYAdZJEkBfpU7uCVLBUL39g9GvlU 7Lbw==
X-Forwarded-Encrypted: i=1; AJvYcCXfRHcES6I0xnJD2uaA8NtTjOLf+QzZUlkpVIu4gnQPDUu1co1R+z7/yG71mrKC+CSL9/HDvA==@ietf.org
X-Gm-Message-State: AOJu0Yy64GqnhnX65FSD8UY53FxUY0fnrMAGZ/PH5EJ84X03wwl/8PgP MC/QTZykyk25QPBv8qwkZJsfolo/r5SIa4roGu+FinXDh80+m3IhPKxjZkZUdPkf9NkaCg==
X-Gm-Gg: ASbGnct8d5U3uKnXp7S4rkGJc31k4Ea1sIolw4YSW5AqJdPLkOmigKwh9smAGLuN345 KwQO0n5GT/2FXb4npbH+jsmCRTLBO5LQ+5Hs5/nCPPaSfvNgqWQ5vcQvdrpjFxGUHbSJ56tga6P E9Wtuhq76+hE2bRkoLg9Un/uLKC+q84Hx+0blVSzmKP6OwpUhzlk117F0KPGVZ42u5TwHJFh+yw UVFBxF2HJzsjClTDYdBr/t6tjH3fUw+20mYJMvRm+Tz+MOsYrEPj5VfzsZrjyvpipiJuPhrRnhL XjBfSDYOJ6Ma362HCBjF3fV/OZulL6t+u6lsyNuIeVfhk1k4+g5KxhrIlgu8BfX5ExUz//zt5BY lM9BtWkYcaKwlQ1Ha
X-Google-Smtp-Source: AGHT+IFKG+tUa7i+UFoNubQLJjzCqADIIw3eYxCzeFBNeZ29gaXSsTweU7JAy1UpeZttY5wpRJAw8A==
X-Received: by 2002:a05:6e02:440d:20b0:3df:29c8:49ff with SMTP id e9e14a558f8ab-3e16710d02bmr20700055ab.22.1752071590161; Wed, 09 Jul 2025 07:33:10 -0700 (PDT)
Received: from smtpclient.apple ([173.216.253.173]) by smtp.gmail.com with ESMTPSA id e9e14a558f8ab-3e0f9b8ea1fsm38391955ab.26.2025.07.09.07.33.08 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 09 Jul 2025 07:33:09 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.600.51.1.1\))
From: Madison Church <mchurch@staff.rfc-editor.org>
In-Reply-To: <LV8PR01MB8677D99EDA22900C1B0FF772BD76A@LV8PR01MB8677.prod.exchangelabs.com>
Date: Wed, 09 Jul 2025 09:32:58 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <388ABAE5-4A04-47C6-A71A-C5F4FD710AE6@staff.rfc-editor.org>
References: <20250613101218.4B876265CD6@rfcpa.rfc-editor.org> <LV8PR01MB8677D99EDA22900C1B0FF772BD76A@LV8PR01MB8677.prod.exchangelabs.com>
To: Deb Cooley <debcooley1@gmail.com>
X-Mailer: Apple Mail (2.3826.600.51.1.1)
Message-ID-Hash: 2RSNSFWU2WW42Z3EHPB67M32M7X2YKGO
X-Message-ID-Hash: 2RSNSFWU2WW42Z3EHPB67M32M7X2YKGO
X-MailFrom: mchurch@staff.rfc-editor.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: RFC Editor <rfc-editor@rfc-editor.org>, Jeffrey S Walden <jwalden@mit.edu>, "n-sakimura@nri.co.jp" <n-sakimura@nri.co.jp>, "naa@google.com" <naa@google.com>, "oauth@ietf.org" <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: [Editorial Errata Reported] RFC7636 (8458)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/a4E60YRPae_jh_GhFcnYiiBLlXs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Hi Deb,  

We are unable to verify this erratum that the submitter marked as editorial, so we changed the Type to “Technical”. As Stream Approver, please review and set the Status and Type accordingly (see the definitions at https://www.rfc-editor.org/errata-definitions/) Please see the discussion below for details. 

You may review the report at: https://www.rfc-editor.org/errata/eid8458.  

Information on how to verify errata reports can be found at: https://www.rfc-editor.org/how-to-verify/.

Further information on errata can be found at: https://www.rfc-editor.org/errata.php.

Thank you!
RFC Editor/mc

> On Jun 14, 2025, at 6:18 AM, Justin Richer <jricher@mit.edu> wrote:
> 
> This is not an error and the errata should be rejected. As per the ABNF definition in https://www.rfc-editor.org/rfc/rfc5234.html#section-21 the name contains "alphabetics, digits, and hyphens (dashes)", and not underscores. I believe the commenter is expecting the ABNF rule name of code-verifier to match the parameter name of code_verifier, but they do not need to be the same. While this is confusing, the text is correct as it stands. 
> 
> - Justin 
> From: RFC Errata System <rfc-editor@rfc-editor.org>
> Sent: Friday, June 13, 2025 6:12 AM
> To: rfc-editor@rfc-editor.org <rfc-editor@rfc-editor.org>
> Cc: Jeffrey S Walden <jwalden@mit.edu>; n-sakimura@nri.co.jp <n-sakimura@nri.co.jp>; naa@google.com <naa@google.com>; oauth@ietf.org <oauth@ietf.org>
> Subject: [OAUTH-WG] [Editorial Errata Reported] RFC7636 (8458)   The following errata report has been submitted for RFC7636,
> "Proof Key for Code Exchange by OAuth Public Clients".
> 
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid8458
> 
> --------------------------------------
> Type: Editorial
> Reported by: Jeff Walden <jwalden@mit.edu>
> 
> Section: 4.2
> 
> Original Text
> -------------
> code-challenge = 43*128unreserved
> 
> Corrected Text
> --------------
> code_challenge = 43*128unreserved
> 
> Notes
> -----
> The ABNF accidentally uses a hyphen/dash rather than an underscore in the code_challenge name in its rule.
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". (If it is spam, it 
> will be removed shortly by the RFC Production Center.) Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party  
> will log in to change the status and edit the report, if necessary.
> 
> --------------------------------------
> RFC7636 (draft-ietf-oauth-spop-15)
> --------------------------------------
> Title               : Proof Key for Code Exchange by OAuth Public Clients
> Publication Date    : September 2015
> Author(s)           : N. Sakimura, Ed., J. Bradley, N. Agarwal
> Category            : PROPOSED STANDARD
> Source              : Web Authorization Protocol
> Stream              : IETF
> Verifying Party     : IESG
> 
> _______________________________________________
> OAuth mailing list -- oauth@ietf.org
> To unsubscribe send an email to oauth-leave@ietf.org