[sidr] Fwd: [Errata Rejected] RFC6487 (3168)

Stewart Bryant <stbryant@cisco.com> Mon, 06 May 2013 12:30 UTC

Return-Path: <stbryant@cisco.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ECF6C21F8EAC for <sidr@ietfa.amsl.com>; Mon, 6 May 2013 05:30:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -109.299
X-Spam-Level:
X-Spam-Status: No, score=-109.299 tagged_above=-999 required=5 tests=[AWL=1.299, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id slKmDZhOpPKm for <sidr@ietfa.amsl.com>; Mon, 6 May 2013 05:30:38 -0700 (PDT)
Received: from ams-iport-4.cisco.com (ams-iport-4.cisco.com [144.254.224.147]) by ietfa.amsl.com (Postfix) with ESMTP id 56E6321F8EA5 for <sidr@ietf.org>; Mon, 6 May 2013 05:30:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7975; q=dns/txt; s=iport; t=1367843437; x=1369053037; h=message-id:date:from:reply-to:mime-version:to:subject: references:in-reply-to; bh=b3i8UH3FQEKLrwtNavKuXttPO09CX1u6ptwXhe9X4LY=; b=DUiAewFXlOUJeUJUBCnAT76Kuo/85mdtF+V3A92pbTBz5D+5dr5zN2nM o2BJ3rddDlYrcpY5tcDdBFtjINwafcaN12NAU3vbZtoLv5FEMYB50BR0I Z3SIpMiSJikcQrOD95cx+HU41cOTVBmbtu1unItRNYQJUQVWRtRV6br/+ c=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AtMGAFShh1GQ/khN/2dsb2JhbAA2GoMHN4katWiBBBZ0gh8BAQEEeA0EHAMBAgoWDwkDAgECATsCCAYBDAYCAQGICAwzvnmNZIE8GAaDTQOXLpE0gw55
X-IronPort-AV: E=Sophos; i="4.87,621,1363132800"; d="scan'208,217"; a="13764553"
Received: from ams-core-4.cisco.com ([144.254.72.77]) by ams-iport-4.cisco.com with ESMTP; 06 May 2013 12:30:36 +0000
Received: from cisco.com (mrwint.cisco.com [64.103.70.36]) by ams-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id r46CUYIi016325 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 6 May 2013 12:30:34 GMT
Received: from [IPv6:::1] (localhost [127.0.0.1]) by cisco.com (8.14.4+Sun/8.8.8) with ESMTP id r46CUW59009255; Mon, 6 May 2013 13:30:33 +0100 (BST)
Message-ID: <5187A268.5010703@cisco.com>
Date: Mon, 06 May 2013 13:30:32 +0100
From: Stewart Bryant <stbryant@cisco.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:17.0) Gecko/20130328 Thunderbird/17.0.5
MIME-Version: 1.0
To: "sidr-chairs@tools.ietf.org" <sidr-chairs@tools.ietf.org>, sidr wg list <sidr@ietf.org>
References: <20130506122439.12042B1E003@rfc-editor.org>
In-Reply-To: <20130506122439.12042B1E003@rfc-editor.org>
X-Forwarded-Message-Id: <20130506122439.12042B1E003@rfc-editor.org>
Content-Type: multipart/alternative; boundary="------------010100000603060207070500"
Subject: [sidr] Fwd: [Errata Rejected] RFC6487 (3168)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: stbryant@cisco.com
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 May 2013 12:30:43 -0000

Whilst this change was supported by one author and one of the chairs,
it is a technical change and thus outside the scope of change
permitted in an errata.

The correct approach is for a member of the WG to produce a
short update draft and test that this has WG and IETF consensus.

Please can the chairs drive this process.

- Stewart


-------- Original Message --------
Subject: 	[Errata Rejected] RFC6487 (3168)
Date: 	Mon, 6 May 2013 05:24:39 -0700
From: 	RFC Errata System <rfc-editor@rfc-editor.org>
To: 	<dmandelb@bbn.com>, <gih@apnic.net>, <ggm@apnic.net>, 
<robertl@apnic.net>
CC: 	<stbryant@cisco.com>, <iesg@ietf.org>, <rfc-editor@rfc-editor.org>



The following errata report has been rejected for RFC6487,
"A Profile for X.509 PKIX Resource Certificates".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6487&eid=3168

--------------------------------------
Status: Rejected
Type: Technical

Reported by: David Mandelberg <dmandelb@bbn.com>
Date Reported: 2012-03-26
Rejected by: Stewart Bryant (IESG)

Section: 4.8

Original Text
-------------
    or non-critical.  A certificate-using system MUST reject the

    certificate if it encounters a critical extension it does not

    recognize; however, a non-critical extension MAY be ignored if it is

    not recognized [RFC5280].

Corrected Text
--------------
    or non-critical.  A certificate-using system MUST reject the

    certificate if it encounters an extension not explicitly mentioned

    in this document.  This is in contrast to RFC 5280 which allows

    non-critical extensions to be ignored.

Notes
-----
Other sections of the same document contradict the original section 4.8:



Section 1:



    Any extensions not explicitly mentioned MUST be absent.  The same

    applies to the CRLs used in the RPKI, that are also profiled in this

    document.



Section 8:



    Certificate Extensions:

          This profile does not permit the use of any other critical or

          non-critical extensions.
  --VERIFIER NOTES--
    This is a technical change to the RFC and needs to be addressed though the IETF consensus process and rather than via the errata process.

--------------------------------------
RFC6487 (draft-ietf-sidr-res-certs-22)
--------------------------------------
Title               : A Profile for X.509 PKIX Resource Certificates
Publication Date    : February 2012
Author(s)           : G. Huston, G. Michaelson, R. Loomans
Category            : PROPOSED STANDARD
Source              : Secure Inter-Domain Routing
Area                : Routing
Stream              : IETF
Verifying Party     : IESG

.