Re: [pkix] [Technical Errata Reported] RFC5912 (3623)
"Jim Schaad" <ietf@augustcellars.com> Fri, 17 May 2013 08:30 UTC
Return-Path: <ietf@augustcellars.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CD7521F92CB for <pkix@ietfa.amsl.com>; Fri, 17 May 2013 01:30:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LrbDvZJL3Y4t for <pkix@ietfa.amsl.com>; Fri, 17 May 2013 01:30:17 -0700 (PDT)
Received: from smtp2.pacifier.net (smtp2.pacifier.net [64.255.237.172]) by ietfa.amsl.com (Postfix) with ESMTP id BAD9C21F924A for <pkix@ietf.org>; Fri, 17 May 2013 01:30:17 -0700 (PDT)
Received: from Philemon (unknown [88.214.187.250]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp2.pacifier.net (Postfix) with ESMTPSA id 0C88F2C9F7; Fri, 17 May 2013 01:30:13 -0700 (PDT)
From: Jim Schaad <ietf@augustcellars.com>
To: 'Erwann Abalea' <eabalea@gmail.com>, 'Jim Schaad' <jimsch@augustcellars.com>
References: <20130516110751.438AC62103@rfc-editor.org> <05f301ce5249$28be3f50$7a3abdf0$@augustcellars.com> <CA+i=0E4AWXcbMH7Q-zNnuRwCsqGqehEsGKn3bZVkDGsGd3L1kQ@mail.gmail.com>
In-Reply-To: <CA+i=0E4AWXcbMH7Q-zNnuRwCsqGqehEsGKn3bZVkDGsGd3L1kQ@mail.gmail.com>
Date: Fri, 17 May 2013 09:29:22 +0100
Message-ID: <064401ce52d8$a5eeb060$f1cc1120$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQKuR1tHlnNqYs/us1ZC1fWGtUuH3QIsBP1tAo5UC3+XI0+qAA==
Content-Language: en-us
Cc: 'RFC Errata System' <rfc-editor@rfc-editor.org>, 'Stefan Santesson' <stefan@aaa-sec.com>, jimsch@exmsft.com, 'Paul Hoffman' <paul.hoffman@vpnc.org>, pkix@ietf.org
Subject: Re: [pkix] [Technical Errata Reported] RFC5912 (3623)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 May 2013 08:30:22 -0000
The following text is from RFC 5280 id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 } CRLNumber ::= INTEGER (0..MAX) This says that the ASN.1 makes it a positive number > -----Original Message----- > From: pkix-bounces@ietf.org [mailto:pkix-bounces@ietf.org] On Behalf Of > Erwann Abalea > Sent: Thursday, May 16, 2013 5:01 PM > To: Jim Schaad > Cc: Stefan Santesson; Paul Hoffman; jimsch@exmsft.com; pkix@ietf.org; RFC > Errata System > Subject: Re: [pkix] [Technical Errata Reported] RFC5912 (3623) > > The certificate serialNumber is limited to [0 .. 256^20] in value. > The CRLNumber is limited to [-256^20 .. 256^20], it's not said to be a positive > integer. > > 2013/5/16 Jim Schaad <jimsch@augustcellars.com>: > > Reject > > > > The serial number MUST be a positive integer assigned by the CA to > > each certificate. > > > > > >> -----Original Message----- > >> From: RFC Errata System [mailto:rfc-editor@rfc-editor.org] > >> Sent: Thursday, May 16, 2013 12:08 PM > >> To: paul.hoffman@vpnc.org; jimsch@exmsft.com; > >> stephen.farrell@cs.tcd.ie; turners@ieca.com; kent@bbn.com; > >> stefan@aaa-sec.com > >> Cc: carl@redhoundsoftware.com; pkix@ietf.org; > >> rfc-editor@rfc-editor.org > >> Subject: [Technical Errata Reported] RFC5912 (3623) > >> > >> The following errata report has been submitted for RFC5912, "New > >> ASN.1 Modules for the Public Key Infrastructure Using X.509 (PKIX)". > >> > >> -------------------------------------- > >> You may review the report below and at: > >> http://www.rfc-editor.org/errata_search.php?rfc=5912&eid=3623 > >> > >> -------------------------------------- > >> Type: Technical > >> Reported by: Carl Wallace <carl@redhoundsoftware.com> > >> > >> Section: 14 > >> > >> Original Text > >> ------------- > >> -- CRL number extension OID and syntax > >> ext-CRLNumber EXTENSION ::= {SYNTAX > >> INTEGER (0..MAX) IDENTIFIED BY id-ce-cRLNumber } > >> id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 } > >> > >> CRLNumber ::= INTEGER (0..MAX) > >> > >> Corrected Text > >> -------------- > >> -- CRL number extension OID and syntax > >> CRLNumber ::= INTEGER > >> > >> ext-CRLNumber EXTENSION ::= {SYNTAX > >> CRLNumber IDENTIFIED BY id-ce-cRLNumber } > >> id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 } > >> > >> > >> Notes > >> ----- > >> The CRLNumber extension was not defined to use the CRLNumber type. > >> The CRLNumber type uses MAX to limit the maximum value. This > >> limitation is inconsistent with section 5.2.3 and Appendix B, which > >> allow CRLNumber values up to 20 octets in length. > >> > >> Instructions: > >> ------------- > >> This errata is currently posted as "Reported". If necessary, please > >> use > > "Reply > >> All" to discuss whether it should be verified or rejected. When a > >> decision > > is > >> reached, the verifying party (IESG) can log in to change the status > >> and > > edit the > >> report, if necessary. > >> > >> -------------------------------------- > >> RFC5912 (draft-ietf-pkix-new-asn1-08) > >> -------------------------------------- > >> Title : New ASN.1 Modules for the Public Key Infrastructure > > Using > >> X.509 (PKIX) > >> Publication Date : June 2010 > >> Author(s) : P. Hoffman, J. Schaad > >> Category : INFORMATIONAL > >> Source : Public-Key Infrastructure (X.509) > >> Area : Security > >> Stream : IETF > >> Verifying Party : IESG > > > > _______________________________________________ > > pkix mailing list > > pkix@ietf.org > > https://www.ietf.org/mailman/listinfo/pkix > > > > -- > Erwann. > _______________________________________________ > pkix mailing list > pkix@ietf.org > https://www.ietf.org/mailman/listinfo/pkix
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- [pkix] [Technical Errata Reported] RFC5912 (3623) RFC Errata System
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Jim Schaad
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Carl Wallace
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Erwann Abalea
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Carl Wallace
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Erwann Abalea
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Carl Wallace
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Erwann Abalea
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Piyush J.comain
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Piyush J.comain
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Erwann Abalea
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Jim Schaad
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Martin Rex
- Re: [pkix] [Technical Errata Reported] RFC5912 (3… Piyush Jain