[pkix] [Errata Held for Document Update] RFC7030 (4384)

RFC Errata System <rfc-editor@rfc-editor.org> Wed, 19 August 2020 19:59 UTC

Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1663B3A0A65; Wed, 19 Aug 2020 12:59:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BAwjWqibFjHD; Wed, 19 Aug 2020 12:59:12 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E830A3A0A64; Wed, 19 Aug 2020 12:59:12 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id 074DCF4078A; Wed, 19 Aug 2020 12:58:55 -0700 (PDT)
To: pierce.leonberger@baesystems.com, pritikin@cisco.com, peter@akayla.com, dharkins@arubanetworks.com
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Cc: rdd@cert.org, iesg@ietf.org, pkix@ietf.org, rfc-editor@rfc-editor.org
Content-Type: text/plain; charset="UTF-8"
Message-Id: <20200819195855.074DCF4078A@rfc-editor.org>
Date: Wed, 19 Aug 2020 12:58:55 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/pkix/2YlBSWSCYgyrPXOiOHcLnilsDhk>
Subject: [pkix] [Errata Held for Document Update] RFC7030 (4384)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Aug 2020 19:59:14 -0000

The following errata report has been held for document update 
for RFC7030, "Enrollment over Secure Transport". 

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid4384

--------------------------------------
Status: Held for Document Update
Type: Technical

Reported by: Pierce Leonberger <pierce.leonberger@baesystems.com>
Date Reported: 2015-06-02
Held by: Roman Danyliw (IESG)

Section: 4.5.2

Original Text
-------------
CsrAttrs ::= SEQUENCE SIZE (0..MAX) OF AttrOrOID

AttrOrOID ::= CHOICE (oid OBJECT IDENTIFIER, attribute Attribute }

Attribute { ATTRIBUTE:IOSet } ::= SEQUENCE {
     type   ATTRIBUTE.&id({IOSet}),
     values SET SIZE(1..MAX) OF ATTRIBUTE.&Type({IOSet}{@type}) }

Corrected Text
--------------
AttrOrOID ::= CHOICE {
      oid OBJECT IDENTIFIER, 
      attribute Attribute{YouNeedToDefineOrReferenceAnObjectSet}
}

Notes
-----
1. The AttrOrOID CHOICE was started with a '(' versus a '{'.

2. Attribute{} is a parameterized type and you are missing the parameter reference within the AttrOrOID CHOICE for "attribute".

3. You need to define or reference the object set to be used in #2.

Highly recommend you create an ASN.1 Module as part of this specification.  This will make it clear which specifications (and the versions there of) you are importing types from (i.e. Attribute{}) and the tagging that should be used (module level).  If you need to define a new object set for #3 then this new module would be the perfect home for it.

--------------------------------------
RFC7030 (draft-ietf-pkix-est-09)
--------------------------------------
Title               : Enrollment over Secure Transport
Publication Date    : October 2013
Author(s)           : M. Pritikin, Ed., P. Yee, Ed., D. Harkins, Ed.
Category            : PROPOSED STANDARD
Source              : Public-Key Infrastructure (X.509)
Area                : Security
Stream              : IETF
Verifying Party     : IESG