[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC 3279: ECDSA and ECDH keyUsage Text



Sean P. Turner wrote on 03/17/2005 03:13:14 PM:

> 
> I'm a little confused by the keyUsage paragraphs (3.2.5) in RFC 3279. 
> It seems like the current text on applies to CAs and CRL issuers.  I 
> believe the text needs to be modified as follows to address end 
entities:
> 
> replace (before the list of digitalSignature, nonRepudiation, and 
> keyAgreement) "If the keyUsage extension is present in a CA or CRL 
> issuer certificate" with "If the keyUsage extension is present in an end 

> entity certificate."
> 
> and
> 
> replace (before the list of digitalSignature, nonRepudiation, 
> keyAgreement, keyCertSign, and cRLSign) "If the keyUsage extension is 
> present in a CA certificate" with "If the keyUsage extension is present 
> in a CA or CRL issuer certificate."

These replacements seem reasonable.

> 
> I think this was just a cut and paste error.  Sorry for the spam if 
> somebody else already caught this.
> 
> spt
>