[pkix] [Errata Held for Document Update] RFC6844 (4070)

RFC Errata System <rfc-editor@rfc-editor.org> Thu, 04 September 2014 12:57 UTC

Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FDF01A887A; Thu, 4 Sep 2014 05:57:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -107.57
X-Spam-Level:
X-Spam-Status: No, score=-107.57 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.668, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IcyJgS7M9i1q; Thu, 4 Sep 2014 05:57:56 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) by ietfa.amsl.com (Postfix) with ESMTP id 14A4F1A8876; Thu, 4 Sep 2014 05:57:56 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id 7F5E11801A4; Thu, 4 Sep 2014 05:57:08 -0700 (PDT)
To: jinmei@wide.ad.jp, philliph@comodo.com, rob.stradling@comodo.com
X-PHP-Originating-Script: 1005:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20140904125708.7F5E11801A4@rfc-editor.org>
Date: Thu, 04 Sep 2014 05:57:08 -0700
Archived-At: http://mailarchive.ietf.org/arch/msg/pkix/Yp0dqbNgqO2KnMKGIKaSk_bc9a0
Cc: pkix@ietf.org, Kathleen.Moriarty@emc.com, iesg@ietf.org, rfc-editor@rfc-editor.org
Subject: [pkix] [Errata Held for Document Update] RFC6844 (4070)
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2014 12:57:59 -0000

The following errata report has been held for document update 
for RFC6844, "DNS Certification Authority Authorization (CAA) Resource Record". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6844&eid=4070

--------------------------------------
Status: Held for Document Update
Type: Editorial

Reported by: JINMEI Tatuya <jinmei@wide.ad.jp>
Date Reported: 2014-08-05
Held by: Kathleen Moriarty (IESG)

Section: 3

Original Text
-------------
   $ORIGIN example.com
   .       CAA 0 issue "ca.example.net"


Corrected Text
--------------
   $ORIGIN example.com.
           CAA 0 issue "ca.example.net"


Notes
-----
The original text is obviously incorrect (or at least something not really intended) in that the owner name is absolute.  It just doesn't make sense to use $ORIGIN if we use an absolute owner name for the actual RR.  The "corrected text" is one representation of what I guess the author really intended.

There are other instances of the same kind of this error in this section, but I don't bother to list all of them as it should be obvious and the sense of the "fix" should be the same.

>From the verification of the errata:
The errata is correct as reported with the following caveat, some implementations of DNS presentation format assume all $ORIGIN statements are Fully Qualified Domain Names,
but others do not and those will take the domain name and append to it current origin. 
Thus the trailing dot removes any ambiguity that the name specified is FQDN. 

--------------------------------------
RFC6844 (draft-ietf-pkix-caa-15)
--------------------------------------
Title               : DNS Certification Authority Authorization (CAA) Resource Record
Publication Date    : January 2013
Author(s)           : P. Hallam-Baker, R. Stradling
Category            : PROPOSED STANDARD
Source              : Public-Key Infrastructure (X.509)
Area                : Security
Stream              : IETF
Verifying Party     : IESG