The following errata report has been rejected for RFC7935,
"The Profile for Algorithms and Key Sizes for Use in the Resource Public Key 
Infrastructure".

--------------------------------------
You may review the report below and at:
https://www.rfc-editor.org/errata/eid5737

--------------------------------------
Status: Rejected
Type: Technical

Reported by: Alberto Leiva Popper <[email protected]>
Date Reported: 2019-05-24
Rejected by: Alvaro Retana (IESG)

Section: 3.1

Original Text
-------------
algorithm (which is an AlgorithmIdentifier type):
   The object identifier for RSA PKCS #1 v1.5 with SHA-256 MUST be
   used in the algorithm field, as specified in Section 5 of
   [RFC4055].  The value for the associated parameters from that
   clause MUST also be used for the parameters field.

Corrected Text
--------------
algorithm (which is an AlgorithmIdentifier type):
   The object identifier for RSA (rsaEncryption) MUST be used for the
   algorithm field, as specified in Section 3.2 of [RFC3370]. The value
   for the associated parameters from that clause MUST also be used for
   the parameters field.

Notes
-----
The field described in the paragraph belongs to a public key. The way I 
understand it, particularly due to the inclusion of a digest, "RSA PKCS #1 v1.5 
with SHA-256" (sha256WithRSAEncryption) is not really a public key algorithm 
identifier; it's a signature algorithm identifier.

(Courtesy of Russ Housley) rsaEncryption also allows the public key to be used 
with PKCS#1 v1.5, RSASSA-PSS, and RSAES-OAEP.

All existing RPKI readers and writers that I've seen, as well as the global 
RPKI repository certificates themselves, currently use rsaEncryption as the 
public key algorithm of subjectPublicKeyInfo. Therefore, this change should 
also reflect existing practice.
 --VERIFIER NOTES-- 
Any changes to normative statements require WG consensus.  In this case, 
rfc7935 has been updated twice.  Discussion should happen in the sidrops WG.

--------------------------------------
RFC7935 (draft-ietf-sidr-rfc6485bis-05)
--------------------------------------
Title               : The Profile for Algorithms and Key Sizes for Use in the 
Resource Public Key Infrastructure
Publication Date    : August 2016
Author(s)           : G. Huston, G. Michaelson, Ed.
Category            : PROPOSED STANDARD
Source              : Secure Inter-Domain Routing
Area                : Routing
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
sidr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to