The following errata report has been held for document update
for RFC5652, "Cryptographic Message Syntax (CMS)".
--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=5652&eid=3867
--------------------------------------
Status: Held for Document Update
Type: Editorial
Reported by: Jos Breek <jos(_dot_)breek(_at_)ul(_dot_)com>
Date Reported: 2014-01-16
Held by: Kathleen Moriarty (IESG)
Section: 5.3
Original Text
-------------
digestAlgorithm identifies the message digest algorithm, and any
associated parameters, used by the signer.
Corrected Text
--------------
digestAlgorithm identifies the message digest algorithm, and any
associated parameters, used by the signer in the signature Generation
Process.
Notes
-----
The text stated that the message digest algorithm is "used by the signer". It
is unclear for what purpose the message digest algorithm is used. This
recommendation is editorial and was accepted.
Additional text provided was not accepted as there is no requirement that
digest used on the body is the same as the digest used in the signature
operation.
The following sentence was suggested (and rejected):
"The message digest algorithm shall be equal to the message
digest algorithm used in the signatureAlgorithm field."
With the explanation in the original errata report for this additional sentence
as:
There are implementations that use the message digest algorithm specified in
the messageDigest field instead of the message digest algorithm specified in
the signatureAlgorithm.
Is the purpose of the messageDigest field to nest the hashing algorithm used in
the signing process? If so, please use the corrected text to clarify the goal
of the field.
--------------------------------------
RFC5652 (draft-ietf-smime-rfc3852bis-00)
--------------------------------------
Title : Cryptographic Message Syntax (CMS)
Publication Date : September 2009
Author(s) : R. Housley
Category : DRAFT STANDARD
Source : S/MIME Mail Security
Area : Security
Stream : IETF
Verifying Party : IESG
_______________________________________________
smime mailing list
smime(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/smime