[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RFC 3279: ECDSA and ECDH keyUsage Text




I'm a little confused by the keyUsage paragraphs (3.2.5) in RFC 3279. It seems like the current text on applies to CAs and CRL issuers. I believe the text needs to be modified as follows to address end entities:

replace (before the list of digitalSignature, nonRepudiation, and keyAgreement) "If the keyUsage extension is present in a CA or CRL issuer certificate" with "If the keyUsage extension is present in an end entity certificate."

and

replace (before the list of digitalSignature, nonRepudiation, keyAgreement, keyCertSign, and cRLSign) "If the keyUsage extension is present in a CA certificate" with "If the keyUsage extension is present in a CA or CRL issuer certificate."

I think this was just a cut and paste error. Sorry for the spam if somebody else already caught this.

spt