anima-wg / constrained-voucher

This is a repo for the IETF Internet Draft about constrained vouchers in CBOR
2 stars 4 forks source link

Fix Section 13 (RPK) text and remove part that requires PKIX operations #255

Closed EskoDijk closed 1 year ago

EskoDijk commented 1 year ago

In general, fix some typos. Specific, end of Section 13 (13.3) mentions that the Pledge has to do PKIX operations while it doesn't support these. That part is to be moved elsewhere.

That part is:

   In other cases, if the MASA signing key is based upon a PKI (see
   [I-D.richardson-anima-masa-considerations] Section 2.3), then a
   certificate chain may need to be included with the voucher in order
   for the pledge to validate the signature.  In CMS signed artifacts,
   the CMS structure has a place for such certificates.

   In the COSE-signed Constrained Vouchers described in this document,
   the x5bag attribute from [I-D.ietf-cose-x509] is used to contain the
   needed certificates and chain.