Re: [pkix] [Technical Errata Reported] RFC3029 (6445)

Sean Turner <sean@sn3rd.com> Mon, 21 June 2021 15:15 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 597D33A0A83 for <pkix@ietfa.amsl.com>; Mon, 21 Jun 2021 08:15:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.199
X-Spam-Level:
X-Spam-Status: No, score=-0.199 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ovQkhOVD-Wwd for <pkix@ietfa.amsl.com>; Mon, 21 Jun 2021 08:15:49 -0700 (PDT)
Received: from mail-qv1-xf29.google.com (mail-qv1-xf29.google.com [IPv6:2607:f8b0:4864:20::f29]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4FAF73A0A73 for <pkix@ietf.org>; Mon, 21 Jun 2021 08:15:49 -0700 (PDT)
Received: by mail-qv1-xf29.google.com with SMTP id g19so4725126qvx.12 for <pkix@ietf.org>; Mon, 21 Jun 2021 08:15:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=PqJmCTu8VntP1BO8KcjJ7PksqHYyobeSowYh3ZpgwAg=; b=m3J3VvBOW1liZECkyBjuBOoWGM4xxIEFkzfCILnSt9XTm2WLk4D5AR6xwWQS0qtH5Y 8TJnuCXIQa+Ad5hZLk58FIzsgasRAKqPo/0OZ2UPu2+Rbq4tky0xM86kY/LV7ZpBlgJL pXD3eTLgvo/UOstrHgAhjaAdinqtGdyNpesZc=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=PqJmCTu8VntP1BO8KcjJ7PksqHYyobeSowYh3ZpgwAg=; b=UxbBPZtXMnJG1kG0ROhmUvSVoPiY9UtgA4DjDZANQc0ObWr5BjPGzzO0KpimQBTrNE ey5Pwm8Prb4T+fbv9BpIMGeOCRLxl2KHgRVCeaKrdUPNYQZohMzF/pvT3+CGMPfy+xIU ePSIkuAx3xBssr1G9lmowvk1mRT8eN/jpJdyP77b+Of3b76y1dbriV6HKXMNWgbMexnK GP9VrjcsrVR8hG1aGW60MNniOgfS14iJdNFUw8f7Gt1RapK3NNGyVP8DKlzQ2vSMCLn5 oTYNq7OnvZiANSFUezu7Y38Lrl/aQYvsKmNIXO8lLMQn8Z6Ljg4oYrX7/Prv5VGNByZ4 Qseg==
X-Gm-Message-State: AOAM5306ZRezfsLV/EPVQNV2WRtU7RbNsZ53SeaS6bVxseARSP3exqWA LmjXB0vDi8QMJVPd8tQVkZmTog==
X-Google-Smtp-Source: ABdhPJwVk7pjfvHCIzdx1YylRi6VzIDVj6OaQqpA6bcdXkgcoATvb0vxUUuadNfy8FhmVW0fkJRSAw==
X-Received: by 2002:ad4:5343:: with SMTP id v3mr20472217qvs.45.1624288547149; Mon, 21 Jun 2021 08:15:47 -0700 (PDT)
Received: from smtpclient.apple (pool-71-178-177-131.washdc.fios.verizon.net. [71.178.177.131]) by smtp.gmail.com with ESMTPSA id h9sm10242109qkj.66.2021.06.21.08.15.46 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 21 Jun 2021 08:15:46 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.100.0.2.22\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <86A4492F-800C-427A-AFB0-067B62811EC7@vigilsec.com>
Date: Mon, 21 Jun 2021 11:15:45 -0400
Cc: Roman Danyliw <rdd@cert.org>, Benjamin Kaduk <kaduk@mit.edu>, IETF PKIX <pkix@ietf.org>, Stefan Santesson <stefan@aaa-sec.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <DBFEA73F-F043-47A2-8032-99C3C523720A@sn3rd.com>
References: <20210226211211.B1F30F40763@rfc-editor.org> <86A4492F-800C-427A-AFB0-067B62811EC7@vigilsec.com>
To: Russ Housley <housley@vigilsec.com>
X-Mailer: Apple Mail (2.3654.100.0.2.22)
Archived-At: <https://mailarchive.ietf.org/arch/msg/pkix/LdgbL_uu8PmX6aued5oQrIlX21s>
Subject: Re: [pkix] [Technical Errata Reported] RFC3029 (6445)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jun 2021 15:15:54 -0000

Is “Version” used in the module? Maybe what they meant to do was:

version                      Version DEFAULT 1 ,

kind of like what they did for Nonce.

Maybe the easiest thing to do is change:

nonce                        Nonce OPTIONAL,

to 

nonce                        INTEGER OPTIONAL,

and just delete Nonce and Version from the module?

spt

> On Feb 26, 2021, at 23:33, Russ Housley <housley@vigilsec.com> wrote:
> 
> It turns out that there are other places where Integer is used in the same module, so this is a better fix:
> 
> 
> OLD:
> 
> Version ::= Integer
> 
> 
> NEW:
> 
> Integer ::= INTEGER
> 
> Version ::= Integer
> 
> 
>> On Feb 26, 2021, at 4:12 PM, RFC Errata System <rfc-editor@rfc-editor.org> wrote:
>> 
>> The following errata report has been submitted for RFC3029,
>> "Internet X.509 Public Key Infrastructure Data Validation and Certification Server Protocols".
>> 
>> --------------------------------------
>> You may review the report below and at:
>> https://www.rfc-editor.org/errata/eid6445
>> 
>> --------------------------------------
>> Type: Technical
>> Reported by: Russ Housley <housley@vigilsec.com>
>> 
>> Section: Appendix E
>> 
>> Original Text
>> -------------
>> Version ::= Integer
>> 
>> 
>> Corrected Text
>> --------------
>> Version ::= INTEGER
>> 
>> 
>> Notes
>> -----
>> INTEGER must be in all capital letters for the ASN.1 Module to compile.
>> 
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". If necessary, please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party  
>> can log in to change the status and edit the report, if necessary. 
>> 
>> --------------------------------------
>> RFC3029 (draft-ietf-pkix-dcs-07)
>> --------------------------------------
>> Title               : Internet X.509 Public Key Infrastructure Data Validation and Certification Server Protocols
>> Publication Date    : February 2001
>> Author(s)           : C. Adams, P. Sylvester, M. Zolotarev, R. Zuccherato
>> Category            : EXPERIMENTAL
>> Source              : Public-Key Infrastructure (X.509)
>> Area                : Security
>> Stream              : IETF
>> Verifying Party     : IESG
> 
> _______________________________________________
> pkix mailing list
> pkix@ietf.org
> https://www.ietf.org/mailman/listinfo/pkix