Re: [pkix] [Technical Errata Reported] RFC5912 (3623)

"Jim Schaad" <ietf@augustcellars.com> Fri, 17 May 2013 08:30 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CD7521F92CB for <pkix@ietfa.amsl.com>; Fri, 17 May 2013 01:30:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LrbDvZJL3Y4t for <pkix@ietfa.amsl.com>; Fri, 17 May 2013 01:30:17 -0700 (PDT)
Received: from smtp2.pacifier.net (smtp2.pacifier.net [64.255.237.172]) by ietfa.amsl.com (Postfix) with ESMTP id BAD9C21F924A for <pkix@ietf.org>; Fri, 17 May 2013 01:30:17 -0700 (PDT)
Received: from Philemon (unknown [88.214.187.250]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp2.pacifier.net (Postfix) with ESMTPSA id 0C88F2C9F7; Fri, 17 May 2013 01:30:13 -0700 (PDT)
From: Jim Schaad <ietf@augustcellars.com>
To: 'Erwann Abalea' <eabalea@gmail.com>, 'Jim Schaad' <jimsch@augustcellars.com>
References: <20130516110751.438AC62103@rfc-editor.org> <05f301ce5249$28be3f50$7a3abdf0$@augustcellars.com> <CA+i=0E4AWXcbMH7Q-zNnuRwCsqGqehEsGKn3bZVkDGsGd3L1kQ@mail.gmail.com>
In-Reply-To: <CA+i=0E4AWXcbMH7Q-zNnuRwCsqGqehEsGKn3bZVkDGsGd3L1kQ@mail.gmail.com>
Date: Fri, 17 May 2013 09:29:22 +0100
Message-ID: <064401ce52d8$a5eeb060$f1cc1120$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQKuR1tHlnNqYs/us1ZC1fWGtUuH3QIsBP1tAo5UC3+XI0+qAA==
Content-Language: en-us
Cc: 'RFC Errata System' <rfc-editor@rfc-editor.org>, 'Stefan Santesson' <stefan@aaa-sec.com>, jimsch@exmsft.com, 'Paul Hoffman' <paul.hoffman@vpnc.org>, pkix@ietf.org
Subject: Re: [pkix] [Technical Errata Reported] RFC5912 (3623)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 May 2013 08:30:22 -0000

The following text is from RFC 5280

   id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 }

   CRLNumber ::= INTEGER (0..MAX)

This says that the ASN.1 makes it a positive number

> -----Original Message-----
> From: pkix-bounces@ietf.org [mailto:pkix-bounces@ietf.org] On Behalf Of
> Erwann Abalea
> Sent: Thursday, May 16, 2013 5:01 PM
> To: Jim Schaad
> Cc: Stefan Santesson; Paul Hoffman; jimsch@exmsft.com; pkix@ietf.org; RFC
> Errata System
> Subject: Re: [pkix] [Technical Errata Reported] RFC5912 (3623)
> 
> The certificate serialNumber is limited to [0 .. 256^20] in value.
> The CRLNumber is limited to [-256^20 .. 256^20], it's not said to be a
positive
> integer.
> 
> 2013/5/16 Jim Schaad <jimsch@augustcellars.com>:
> > Reject
> >
> > The serial number MUST be a positive integer assigned by the CA to
> >    each certificate.
> >
> >
> >> -----Original Message-----
> >> From: RFC Errata System [mailto:rfc-editor@rfc-editor.org]
> >> Sent: Thursday, May 16, 2013 12:08 PM
> >> To: paul.hoffman@vpnc.org; jimsch@exmsft.com;
> >> stephen.farrell@cs.tcd.ie; turners@ieca.com; kent@bbn.com;
> >> stefan@aaa-sec.com
> >> Cc: carl@redhoundsoftware.com; pkix@ietf.org;
> >> rfc-editor@rfc-editor.org
> >> Subject: [Technical Errata Reported] RFC5912 (3623)
> >>
> >> The following errata report has been submitted for RFC5912, "New
> >> ASN.1 Modules for the Public Key Infrastructure Using X.509 (PKIX)".
> >>
> >> --------------------------------------
> >> You may review the report below and at:
> >> http://www.rfc-editor.org/errata_search.php?rfc=5912&eid=3623
> >>
> >> --------------------------------------
> >> Type: Technical
> >> Reported by: Carl Wallace <carl@redhoundsoftware.com>
> >>
> >> Section: 14
> >>
> >> Original Text
> >> -------------
> >>    -- CRL number extension OID and syntax
> >>    ext-CRLNumber EXTENSION ::= {SYNTAX
> >>        INTEGER (0..MAX) IDENTIFIED BY id-ce-cRLNumber }
> >>    id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 }
> >>
> >>    CRLNumber ::= INTEGER (0..MAX)
> >>
> >> Corrected Text
> >> --------------
> >>    -- CRL number extension OID and syntax
> >>    CRLNumber ::= INTEGER
> >>
> >>    ext-CRLNumber EXTENSION ::= {SYNTAX
> >>        CRLNumber IDENTIFIED BY id-ce-cRLNumber }
> >>    id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 }
> >>
> >>
> >> Notes
> >> -----
> >> The CRLNumber extension was not defined to use the CRLNumber type.
> >> The CRLNumber type uses MAX to limit the maximum value.  This
> >> limitation is inconsistent with section 5.2.3 and Appendix B, which
> >> allow CRLNumber values up to 20 octets in length.
> >>
> >> Instructions:
> >> -------------
> >> This errata is currently posted as "Reported". If necessary, please
> >> use
> > "Reply
> >> All" to discuss whether it should be verified or rejected. When a
> >> decision
> > is
> >> reached, the verifying party (IESG) can log in to change the status
> >> and
> > edit the
> >> report, if necessary.
> >>
> >> --------------------------------------
> >> RFC5912 (draft-ietf-pkix-new-asn1-08)
> >> --------------------------------------
> >> Title               : New ASN.1 Modules for the Public Key
Infrastructure
> > Using
> >> X.509 (PKIX)
> >> Publication Date    : June 2010
> >> Author(s)           : P. Hoffman, J. Schaad
> >> Category            : INFORMATIONAL
> >> Source              : Public-Key Infrastructure (X.509)
> >> Area                : Security
> >> Stream              : IETF
> >> Verifying Party     : IESG
> >
> > _______________________________________________
> > pkix mailing list
> > pkix@ietf.org
> > https://www.ietf.org/mailman/listinfo/pkix
> 
> 
> 
> --
> Erwann.
> _______________________________________________
> pkix mailing list
> pkix@ietf.org
> https://www.ietf.org/mailman/listinfo/pkix