Re: [smime] [Technical Errata Reported] RFC5652 (6250)

Jim Schaad <ietf@augustcellars.com> Thu, 06 August 2020 23:58 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A66BE3A0A0C for <smime@ietfa.amsl.com>; Thu, 6 Aug 2020 16:58:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1q1slHXuJYPg for <smime@ietfa.amsl.com>; Thu, 6 Aug 2020 16:58:13 -0700 (PDT)
Received: from mail2.augustcellars.com (augustcellars.com [50.45.239.150]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B9B223A08FF for <smime@ietf.org>; Thu, 6 Aug 2020 16:58:12 -0700 (PDT)
Received: from Jude (73.180.8.170) by mail2.augustcellars.com (192.168.0.56) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Thu, 6 Aug 2020 16:58:05 -0700
From: Jim Schaad <ietf@augustcellars.com>
To: 'RFC Errata System' <rfc-editor@rfc-editor.org>, housley@vigilsec.com, rdd@cert.org, kaduk@mit.edu, paul.hoffman@vpnc.org, blaker@gmail.com
CC: smime@ietf.org
References: <20200806215815.240BFF40757@rfc-editor.org>
In-Reply-To: <20200806215815.240BFF40757@rfc-editor.org>
Date: Thu, 06 Aug 2020 16:58:03 -0700
Message-ID: <069201d66c4d$6e994b70$4bcbe250$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 16.0
Content-Language: en-us
Thread-Index: AQFBIBo5eNzWorCSF43k72cqIaNNhqpWWpxQ
X-Originating-IP: [73.180.8.170]
Archived-At: <https://mailarchive.ietf.org/arch/msg/smime/4eWAVR4Gc1f3W2Zb_IM-I73xJeY>
Subject: Re: [smime] [Technical Errata Reported] RFC5652 (6250)
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Aug 2020 23:58:15 -0000

Look right to me

-----Original Message-----
From: smime <smime-bounces@ietf.org> On Behalf Of RFC Errata System
Sent: Thursday, August 6, 2020 2:58 PM
To: housley@vigilsec.com; rdd@cert.org; kaduk@mit.edu;
paul.hoffman@vpnc.org; blaker@gmail.com
Cc: rfc-editor@rfc-editor.org; smime@ietf.org
Subject: [smime] [Technical Errata Reported] RFC5652 (6250)

The following errata report has been submitted for RFC5652, "Cryptographic
Message Syntax (CMS)".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid6250

--------------------------------------
Type: Technical
Reported by: Russ Housley <housley@vigilsec.com>

Section: 9.2

Original Text
-------------
   If the authAttrs field is present, the content-type attribute (as
   described in Section 11.1) and the message-digest attribute (as
   described in Section 11.2) MUST be included, and the input to the MAC
   calculation process is the DER encoding of authAttrs.  A separate
   encoding of the authAttrs field is performed for message digest
   calculation.  The IMPLICIT [2] tag in the authAttrs field is not used
   for the DER encoding, rather an EXPLICIT SET OF tag is used.  That
   is, the DER encoding of the SET OF tag, rather than of the IMPLICIT
   [2] tag, is to be included in the message digest calculation along
   with the length and content octets of the authAttrs value.

Corrected Text
--------------
   If the authAttrs field is present, the content-type attribute (as
   described in Section 11.1) and the message-digest attribute (as
   described in Section 11.2) MUST be included, and the input to the MAC
   calculation process is the DER encoding of authAttrs.  A separate
   encoding of the authAttrs field is performed for message digest
   calculation.  The IMPLICIT [2] tag in the authAttrs field is not used
   for the DER encoding, rather an EXPLICIT SET OF tag is used.  That
   is, the DER encoding of the SET OF tag, rather than of the IMPLICIT
   [2] tag, is to be included in the MAC calculation along
   with the length and content octets of the authAttrs value.

Notes
-----
The paragraph is talking about the input to a MAC calculation, not the input
to message digest calculation.

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please use
"Reply All" to discuss whether it should be verified or rejected. When a
decision is reached, the verifying party can log in to change the status and
edit the report, if necessary. 

--------------------------------------
RFC5652 (draft-ietf-smime-rfc3852bis-00)
--------------------------------------
Title               : Cryptographic Message Syntax (CMS)
Publication Date    : September 2009
Author(s)           : R. Housley
Category            : DRAFT STANDARD
Source              : S/MIME Mail Security
Area                : Security
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
smime mailing list
smime@ietf.org
https://www.ietf.org/mailman/listinfo/smime