--- 1/draft-ietf-lamps-hash-of-root-key-cert-extn-06.txt 2019-06-29 07:13:30.478886803 -0700 +++ 2/draft-ietf-lamps-hash-of-root-key-cert-extn-07.txt 2019-06-29 07:13:30.510887611 -0700 @@ -1,18 +1,18 @@ Network Working Group R. Housley Internet-Draft Vigil Security -Intended status: Informational June 28, 2019 -Expires: December 30, 2019 +Intended status: Informational June 29, 2019 +Expires: December 31, 2019 Hash Of Root Key Certificate Extension - draft-ietf-lamps-hash-of-root-key-cert-extn-06 + draft-ietf-lamps-hash-of-root-key-cert-extn-07 Abstract This document specifies the Hash Of Root Key certificate extension. This certificate extension is carried in the self-signed certificate for a trust anchor, which is often called a Root Certification Authority (CA) certificate. This certificate extension unambiguously identifies the next public key that will be used at some point in the future as the next Root CA certificate, eventually replacing the current one. @@ -25,21 +25,21 @@ Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." - This Internet-Draft will expire on December 30, 2019. + This Internet-Draft will expire on December 31, 2019. Copyright Notice Copyright (c) 2019 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents @@ -422,22 +422,20 @@ ext-HashOfRootKey EXTENSION ::= { -- Only in Root CA certificates SYNTAX HashedRootKey IDENTIFIED BY id-ce-hashOfRootKey CRITICALITY {FALSE} } HashedRootKey ::= SEQUENCE { hashAlg HashAlgorithm, -- Hash algorithm used hashValue OCTET STRING } -- Hash of DER-encoded -- SubjectPublicKeyInfo - HashAlgorithmId ::= AlgorithmIdentifier {DIGEST-ALGORITHM,{ ... }} - id-ce-hashOfRootKey OBJECT IDENTIFIER ::= { 1 3 6 1 4 1 51483 2 1 } END Author's Address Russ Housley Vigil Security 516 Dranesville Road Herndon, VA 20170