
From turners@ieca.com  Mon Nov 26 16:08:32 2012
Return-Path: <turners@ieca.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4482821F84F1 for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 16:08:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.293
X-Spam-Level: 
X-Spam-Status: No, score=-102.293 tagged_above=-999 required=5 tests=[AWL=-0.028, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hYqYmtv3-pIC for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 16:08:31 -0800 (PST)
Received: from gateway06.websitewelcome.com (gateway06.websitewelcome.com [69.93.35.3]) by ietfa.amsl.com (Postfix) with ESMTP id A782521F84F0 for <keyprov@ietf.org>; Mon, 26 Nov 2012 16:08:31 -0800 (PST)
Received: by gateway06.websitewelcome.com (Postfix, from userid 5007) id 1ABCA9A0E7019; Mon, 26 Nov 2012 18:08:31 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway06.websitewelcome.com (Postfix) with ESMTP id 0F3FB9A0E6FE4 for <keyprov@ietf.org>; Mon, 26 Nov 2012 18:08:31 -0600 (CST)
Received: from [108.45.19.185] (port=65273 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1Td8j0-0001dL-N9; Mon, 26 Nov 2012 18:08:30 -0600
Message-ID: <50B4047D.9030306@ieca.com>
Date: Mon, 26 Nov 2012 19:08:29 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:16.0) Gecko/20121026 Thunderbird/16.0.2
MIME-Version: 1.0
To: phoyer@actividentity.com, mpei@verisign.com, smachani@diversinet.com
References: <20120925225523.54FCBB1E003@rfc-editor.org>
In-Reply-To: <20120925225523.54FCBB1E003@rfc-editor.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.19.185]:65273
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 6
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: phill@hallambaker.com, keyprov@ietf.org
Subject: Re: [KEYPROV] [Editorial Errata Reported] RFC6030 (3364)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Nov 2012 00:08:32 -0000

Any objections to marking this as accepted?  Seems right to me.

spt

On 9/25/12 6:55 PM, RFC Errata System wrote:
> The following errata report has been submitted for RFC6030,
> "Portable Symmetric Key Container (PSKC)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3364
>
> --------------------------------------
> Type: Editorial
> Reported by: Simon Josefsson <simon@josefsson.org>
>
> Section: 3
>
> Original Text
> -------------
>        ----------------        ----------------
>        | KeyPackage   |    0..1| DeviceInfo   |
>        |--------------|--------|--------------|
>        |              |--      | SerialNumber |
>        ----------------  |     | Manufacturer |
>                |         |     | ....         |
>                |         |     ----------------
>
>
>
> Corrected Text
> --------------
>        ----------------        ----------------
>        | KeyPackage   |    0..1| DeviceInfo   |
>        |--------------|--------|--------------|
>        |              |--      | SerialNo     |
>        ----------------  |     | Manufacturer |
>                |         |     | ....         |
>                |         |     ----------------
>
>
>
> Notes
> -----
> Figure 1 mentions a DeviceInfo field called "SerialNumber" however it should be "SerialNo".
>
> Instructions:
> -------------
> This errata is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC6030 (draft-ietf-keyprov-pskc-09)
> --------------------------------------
> Title               : Portable Symmetric Key Container (PSKC)
> Publication Date    : October 2010
> Author(s)           : P. Hoyer, M. Pei, S. Machani
> Category            : PROPOSED STANDARD
> Source              : Provisioning of Symmetric Keys
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>

From turners@ieca.com  Mon Nov 26 16:09:15 2012
Return-Path: <turners@ieca.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEF6321F8514 for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 16:09:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.289
X-Spam-Level: 
X-Spam-Status: No, score=-102.289 tagged_above=-999 required=5 tests=[AWL=-0.024, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gqS2ziVQKfXG for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 16:09:15 -0800 (PST)
Received: from gateway11.websitewelcome.com (gateway11.websitewelcome.com [67.18.82.12]) by ietfa.amsl.com (Postfix) with ESMTP id CA5F921F84FA for <keyprov@ietf.org>; Mon, 26 Nov 2012 16:09:12 -0800 (PST)
Received: by gateway11.websitewelcome.com (Postfix, from userid 5011) id D5D5B850A600A; Mon, 26 Nov 2012 18:09:11 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway11.websitewelcome.com (Postfix) with ESMTP id C8AE2850A5FEA for <keyprov@ietf.org>; Mon, 26 Nov 2012 18:09:11 -0600 (CST)
Received: from [108.45.19.185] (port=65274 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1Td8jg-0001pD-3K; Mon, 26 Nov 2012 18:09:12 -0600
Message-ID: <50B404A7.8050205@ieca.com>
Date: Mon, 26 Nov 2012 19:09:11 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:16.0) Gecko/20121026 Thunderbird/16.0.2
MIME-Version: 1.0
To: phoyer@actividentity.com, mpei@verisign.com, smachani@diversinet.com
References: <20121003200453.B0CFA72F1D4@rfc-editor.org>
In-Reply-To: <20121003200453.B0CFA72F1D4@rfc-editor.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.19.185]:65274
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 14
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: phill@hallambaker.com, keyprov@ietf.org
Subject: Re: [KEYPROV] [Editorial Errata Reported] RFC6030 (3370)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Nov 2012 00:09:15 -0000

Any objections to marking this as accepted?  Seems right to me.

spt

On 10/3/12 4:04 PM, RFC Errata System wrote:
> The following errata report has been submitted for RFC6030,
> "Portable Symmetric Key Container (PSKC)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3370
>
> --------------------------------------
> Type: Editorial
> Reported by: Simon Josefsson <simon@josefsson.org>
>
> Section: 6.3
>
> Original Text
> -------------
>         id="KC0001"
>
>
>
> Corrected Text
> --------------
>         Id="KC0001"
>
>
>
> Notes
> -----
> The PSKC data in figure 8 does not pass a XML Schema validation -- the reason is a typo in the Id attribute name.
>
> Instructions:
> -------------
> This errata is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC6030 (draft-ietf-keyprov-pskc-09)
> --------------------------------------
> Title               : Portable Symmetric Key Container (PSKC)
> Publication Date    : October 2010
> Author(s)           : P. Hoyer, M. Pei, S. Machani
> Category            : PROPOSED STANDARD
> Source              : Provisioning of Symmetric Keys
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>

From wwwrun@rfc-editor.org  Mon Nov 26 20:49:10 2012
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA91721F847F for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 20:49:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level: 
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Gr5es0SPNJfR for <keyprov@ietfa.amsl.com>; Mon, 26 Nov 2012 20:49:10 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [IPv6:2001:1890:123a::1:2f]) by ietfa.amsl.com (Postfix) with ESMTP id 4B56421F8479 for <keyprov@ietf.org>; Mon, 26 Nov 2012 20:49:10 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id A0CC4B1E002; Mon, 26 Nov 2012 20:41:25 -0800 (PST)
To: phoyer@actividentity.com, mpei@verisign.com, smachani@diversinet.com, stephen.farrell@cs.tcd.ie, turners@ieca.com, phill@hallambaker.com, Hannes.Tschofenig@gmx.net
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20121127044125.A0CC4B1E002@rfc-editor.org>
Date: Mon, 26 Nov 2012 20:41:25 -0800 (PST)
Cc: keyprov@ietf.org, rfc-editor@rfc-editor.org
Subject: [KEYPROV] [Technical Errata Reported] RFC6030 (3418)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Nov 2012 04:49:11 -0000

The following errata report has been submitted for RFC6030,
"Portable Symmetric Key Container (PSKC)".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3418

--------------------------------------
Type: Technical
Reported by: Simon Josefsson <simon@josefsson.org>

Section: 7 and 11

Original Text
-------------
Section 7:
       <Signature>

Section 11:
               <xs:element name="Signature"
                    type="ds:SignatureType" minOccurs="0"/>


Corrected Text
--------------
Section 7:
       <ds:Signature>

Section 11:
               <xs:element ref="ds:Signature" minOccurs="0"/>


Notes
-----
It seems the Signature element is in the wrong namespace, making PSKC incompatible with the XMLDsig specification.

There is a thread on this on the XMLSec mailing list:

http://thread.gmane.org/gmane.text.xml.xmlsec/4178

Both Aleksey Sanin (author of the XMLSec library) and G. Ken Holman (XML
expert) appear to believe this is an error in the XML schema for PSKC:

http://thread.gmane.org/gmane.text.xml.xmlsec/4178/focus=4181
http://thread.gmane.org/gmane.text.xml.xmlsec/4178/focus=4185

This was brought up on the keyprov mailing list:

http://thread.gmane.org/gmane.ietf.keyprov/1011

/Simon

Instructions:
-------------
This errata is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party (IESG)
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC6030 (draft-ietf-keyprov-pskc-09)
--------------------------------------
Title               : Portable Symmetric Key Container (PSKC)
Publication Date    : October 2010
Author(s)           : P. Hoyer, M. Pei, S. Machani
Category            : PROPOSED STANDARD
Source              : Provisioning of Symmetric Keys
Area                : Security
Stream              : IETF
Verifying Party     : IESG

From turners@ieca.com  Tue Nov 27 15:34:07 2012
Return-Path: <turners@ieca.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33F1E21E803A for <keyprov@ietfa.amsl.com>; Tue, 27 Nov 2012 15:34:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.232
X-Spam-Level: 
X-Spam-Status: No, score=-102.232 tagged_above=-999 required=5 tests=[AWL=0.033, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wA2JOGb7lfOm for <keyprov@ietfa.amsl.com>; Tue, 27 Nov 2012 15:34:06 -0800 (PST)
Received: from gateway07.websitewelcome.com (gateway07.websitewelcome.com [67.18.53.18]) by ietfa.amsl.com (Postfix) with ESMTP id 5925C21E8030 for <keyprov@ietf.org>; Tue, 27 Nov 2012 15:34:06 -0800 (PST)
Received: by gateway07.websitewelcome.com (Postfix, from userid 5007) id 48C7897BB5C5F; Tue, 27 Nov 2012 17:34:04 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway07.websitewelcome.com (Postfix) with ESMTP id 3C76897BB5C29 for <keyprov@ietf.org>; Tue, 27 Nov 2012 17:34:04 -0600 (CST)
Received: from [108.45.19.185] (port=57470 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1TdUfF-0005jF-79; Tue, 27 Nov 2012 17:34:05 -0600
Message-ID: <50B54DEC.5070302@ieca.com>
Date: Tue, 27 Nov 2012 18:34:04 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:16.0) Gecko/20121026 Thunderbird/16.0.2
MIME-Version: 1.0
To: phoyer@actividentity.com, mpei@verisign.com, smachani@diversinet.com,  simon@josefsson.org, keyprov@ietf.org
References: <20121003074727.A303DB1E003@rfc-editor.org>
In-Reply-To: <20121003074727.A303DB1E003@rfc-editor.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.19.185]:57470
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 4
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: phill@hallambaker.com
Subject: Re: [KEYPROV] [Technical Errata Reported] RFC6030 (3369)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Nov 2012 23:34:07 -0000

I'm a little hesitant to make this change through an errata.  Two reasons:

1) This was the last discuss point to get resolved.  It was two SHOULDs 
before it became MUST oathman/iana.

2) It's changing 2119 language.

If there's really multiple implementations out there do it differently 
could we spin a simple paragraph draft that explains there's no reason 
to restrict it & the old/new text to get this fixed more formally?

Question: Do any of the other implementations fall over if you use 
something without a prefix?

spt


On 10/3/12 3:47 AM, RFC Errata System wrote:
> The following errata report has been submitted for RFC6030,
> "Portable Symmetric Key Container (PSKC)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3369
>
> --------------------------------------
> Type: Technical
> Reported by: Simon Josefsson <simon@josefsson.org>
>
> Section: 4.3.1
>
> Original Text
> -------------
>     <Manufacturer>:  This element indicates the manufacturer of the
>        device.  Values for the <Manufacturer> element MUST be taken from
>        either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>        Private Enterprise Number Registry [IANAPENREG], using the
>        Organization value.  When the value is taken from [OATHMAN],
>        "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>        from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>        "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>        value from [IANAPENREG]>").
>
> Corrected Text
> --------------
>     <Manufacturer>:  This element indicates the manufacturer of the
>        device.  Values for the <Manufacturer> element MAY be taken from
>        either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>        Private Enterprise Number Registry [IANAPENREG], using the
>        Organization value.  When the value is taken from [OATHMAN],
>        "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>        from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>        "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>        value from [IANAPENREG]>").
>
> Notes
> -----
> The only thing changed is relaxing MUST to MAY.
>
>
>
> The requirement that manufacturer strings begin with "oath." and "iana." is often ignored by implementations/deployments.  Further, none of the examples throughout the document conform to the syntax.  While we could regard these as implementation/deployment and editorial document bugs, I would argue that we could just as well relax the technical requirement because there appears to be no harm in allowing free-form text.  This is what people appear to be using out there already.
>
>
>
> Examples of non-conforming <Manufacturer> fields out there:
>
> http://tools.ietf.org/html/draft-hoyer-keyprov-pskc-algorithm-profiles-01
>
> http://download.gooze.eu/otp/seeds/20120919-test001-4282.xml
>
> Instructions:
> -------------
> This errata is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC6030 (draft-ietf-keyprov-pskc-09)
> --------------------------------------
> Title               : Portable Symmetric Key Container (PSKC)
> Publication Date    : October 2010
> Author(s)           : P. Hoyer, M. Pei, S. Machani
> Category            : PROPOSED STANDARD
> Source              : Provisioning of Symmetric Keys
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>

From simon@josefsson.org  Wed Nov 28 12:30:50 2012
Return-Path: <simon@josefsson.org>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02BBF21F867D for <keyprov@ietfa.amsl.com>; Wed, 28 Nov 2012 12:30:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.909
X-Spam-Level: 
X-Spam-Status: No, score=-99.909 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_HOST_EQ_D_D_D_D=0.765, HELO_MISMATCH_COM=0.553, HOST_EQ_STATICB=1.372, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HhnY-Vejny7t for <keyprov@ietfa.amsl.com>; Wed, 28 Nov 2012 12:30:49 -0800 (PST)
Received: from yxa-v.extundo.com (static-213-115-179-173.sme.bredbandsbolaget.se [213.115.179.173]) by ietfa.amsl.com (Postfix) with ESMTP id 9324C21F841A for <keyprov@ietf.org>; Wed, 28 Nov 2012 12:30:47 -0800 (PST)
Received: from latte.josefsson.org (host-95-193-126-252.mobileonline.telia.com [95.193.126.252]) (authenticated bits=0) by yxa-v.extundo.com (8.14.3/8.14.3/Debian-5+lenny1) with ESMTP id qASKU7qp000325 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Wed, 28 Nov 2012 21:30:09 +0100
From: Simon Josefsson <simon@josefsson.org>
To: Sean Turner <turners@ieca.com>
References: <20121003074727.A303DB1E003@rfc-editor.org> <50B54DEC.5070302@ieca.com>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:121128:stephen.farrell@cs.tcd.ie::evEPYuuwIKHcRw7c:1Rx8
X-Hashcash: 1:22:121128:smachani@diversinet.com::gnD27iMq5P+Qr/fH:FxZ
X-Hashcash: 1:22:121128:turners@ieca.com::/H0sksVCHVl4Nn0q:9qNc
X-Hashcash: 1:22:121128:hannes.tschofenig@gmx.net::Ae6BWV7Kh7CFl7Oz:69tq
X-Hashcash: 1:22:121128:keyprov@ietf.org::qlndabZpu3/Sy9Uo:ZmKP
X-Hashcash: 1:22:121128:phoyer@actividentity.com::Fhp1oDTU93gZWUBC:OyVM
X-Hashcash: 1:22:121128:mpei@verisign.com::Gm+auUg1EXGKKNEy:siS2
X-Hashcash: 1:22:121128:phill@hallambaker.com::Ufw14gSRbP1t0P8p:l3WM
Date: Wed, 28 Nov 2012 21:30:02 +0100
In-Reply-To: <50B54DEC.5070302@ieca.com> (Sean Turner's message of "Tue, 27 Nov 2012 18:34:04 -0500")
Message-ID: <87txs9h3n9.fsf@latte.josefsson.org>
User-Agent: Gnus/5.130006 (Ma Gnus v0.6) Emacs/24.3.50 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
X-Virus-Scanned: clamav-milter 0.97.3 at yxa-v
X-Virus-Status: Clean
Cc: phill@hallambaker.com, keyprov@ietf.org
Subject: Re: [KEYPROV] [Technical Errata Reported] RFC6030 (3369)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Nov 2012 20:30:50 -0000

I am also interested in learning how other implementations behave.

I understand you would want more implementer feedback before approving a
change like this.  The PSKC files I have seen all violate the MUST, but
I can't claim to have seen any representative proportion of all PSKC
files.  If people can share example PSKC files used in various
deployments, that would help.

The alternative to adopt this change is to update the examples
throughout the document to follow the MUST language.

/Simon

Sean Turner <turners@ieca.com> writes:

> I'm a little hesitant to make this change through an errata.  Two reasons:
>
> 1) This was the last discuss point to get resolved.  It was two
> SHOULDs before it became MUST oathman/iana.
>
> 2) It's changing 2119 language.
>
> If there's really multiple implementations out there do it differently
> could we spin a simple paragraph draft that explains there's no reason
> to restrict it & the old/new text to get this fixed more formally?
>
> Question: Do any of the other implementations fall over if you use
> something without a prefix?
>
> spt
>
>
> On 10/3/12 3:47 AM, RFC Errata System wrote:
>> The following errata report has been submitted for RFC6030,
>> "Portable Symmetric Key Container (PSKC)".
>>
>> --------------------------------------
>> You may review the report below and at:
>> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3369
>>
>> --------------------------------------
>> Type: Technical
>> Reported by: Simon Josefsson <simon@josefsson.org>
>>
>> Section: 4.3.1
>>
>> Original Text
>> -------------
>>     <Manufacturer>:  This element indicates the manufacturer of the
>>        device.  Values for the <Manufacturer> element MUST be taken from
>>        either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>>        Private Enterprise Number Registry [IANAPENREG], using the
>>        Organization value.  When the value is taken from [OATHMAN],
>>        "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>>        from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>>        "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>>        value from [IANAPENREG]>").
>>
>> Corrected Text
>> --------------
>>     <Manufacturer>:  This element indicates the manufacturer of the
>>        device.  Values for the <Manufacturer> element MAY be taken from
>>        either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>>        Private Enterprise Number Registry [IANAPENREG], using the
>>        Organization value.  When the value is taken from [OATHMAN],
>>        "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>>        from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>>        "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>>        value from [IANAPENREG]>").
>>
>> Notes
>> -----
>> The only thing changed is relaxing MUST to MAY.
>>
>>
>>
>> The requirement that manufacturer strings begin with "oath." and "iana." is often ignored by implementations/deployments.  Further, none of the examples throughout the document conform to the syntax.  While we could regard these as implementation/deployment and editorial document bugs, I would argue that we could just as well relax the technical requirement because there appears to be no harm in allowing free-form text.  This is what people appear to be using out there already.
>>
>>
>>
>> Examples of non-conforming <Manufacturer> fields out there:
>>
>> http://tools.ietf.org/html/draft-hoyer-keyprov-pskc-algorithm-profiles-01
>>
>> http://download.gooze.eu/otp/seeds/20120919-test001-4282.xml
>>
>> Instructions:
>> -------------
>> This errata is currently posted as "Reported". If necessary, please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party (IESG)
>> can log in to change the status and edit the report, if necessary.
>>
>> --------------------------------------
>> RFC6030 (draft-ietf-keyprov-pskc-09)
>> --------------------------------------
>> Title               : Portable Symmetric Key Container (PSKC)
>> Publication Date    : October 2010
>> Author(s)           : P. Hoyer, M. Pei, S. Machani
>> Category            : PROPOSED STANDARD
>> Source              : Provisioning of Symmetric Keys
>> Area                : Security
>> Stream              : IETF
>> Verifying Party     : IESG
>>

From turners@ieca.com  Thu Nov 29 07:25:47 2012
Return-Path: <turners@ieca.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A14E21F8826 for <keyprov@ietfa.amsl.com>; Thu, 29 Nov 2012 07:25:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.253
X-Spam-Level: 
X-Spam-Status: No, score=-102.253 tagged_above=-999 required=5 tests=[AWL=0.012, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vMK8hdo4nGg4 for <keyprov@ietfa.amsl.com>; Thu, 29 Nov 2012 07:25:33 -0800 (PST)
Received: from gateway12.websitewelcome.com (gateway12.websitewelcome.com [69.93.154.13]) by ietfa.amsl.com (Postfix) with ESMTP id 957A121F8C16 for <keyprov@ietf.org>; Thu, 29 Nov 2012 07:25:26 -0800 (PST)
Received: by gateway12.websitewelcome.com (Postfix, from userid 5007) id 3D1643B8629BE; Thu, 29 Nov 2012 09:25:23 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway12.websitewelcome.com (Postfix) with ESMTP id 2C3423B862963 for <keyprov@ietf.org>; Thu, 29 Nov 2012 09:25:23 -0600 (CST)
Received: from [108.45.19.185] (port=57960 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1Te5zM-0004j6-6h; Thu, 29 Nov 2012 09:25:20 -0600
Message-ID: <50B77E5F.2080508@ieca.com>
Date: Thu, 29 Nov 2012 10:25:19 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:16.0) Gecko/20121026 Thunderbird/16.0.2
MIME-Version: 1.0
To: phoyer@actividentity.com, mpei@verisign.com, smachani@diversinet.com,  keyprov@ietf.org
References: <20121127044125.A0CC4B1E002@rfc-editor.org>
In-Reply-To: <20121127044125.A0CC4B1E002@rfc-editor.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.19.185]:57960
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 14
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: phill@hallambaker.com
Subject: Re: [KEYPROV] [Technical Errata Reported] RFC6030 (3418)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Nov 2012 15:25:49 -0000

Authors and List,

This seems right to me.  Objections?

spt

On 11/26/12 11:41 PM, RFC Errata System wrote:
> The following errata report has been submitted for RFC6030,
> "Portable Symmetric Key Container (PSKC)".
>
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3418
>
> --------------------------------------
> Type: Technical
> Reported by: Simon Josefsson <simon@josefsson.org>
>
> Section: 7 and 11
>
> Original Text
> -------------
> Section 7:
>
>         <Signature>
>
>
>
> Section 11:
>
>                 <xs:element name="Signature"
>
>                      type="ds:SignatureType" minOccurs="0"/>
>
>
>
> Corrected Text
> --------------
> Section 7:
>
>         <ds:Signature>
>
>
>
> Section 11:
>
>                 <xs:element ref="ds:Signature" minOccurs="0"/>
>
>
>
> Notes
> -----
> It seems the Signature element is in the wrong namespace, making PSKC incompatible with the XMLDsig specification.
>
>
>
> There is a thread on this on the XMLSec mailing list:
>
>
>
> http://thread.gmane.org/gmane.text.xml.xmlsec/4178
>
>
>
> Both Aleksey Sanin (author of the XMLSec library) and G. Ken Holman (XML
>
> expert) appear to believe this is an error in the XML schema for PSKC:
>
>
>
> http://thread.gmane.org/gmane.text.xml.xmlsec/4178/focus=4181
>
> http://thread.gmane.org/gmane.text.xml.xmlsec/4178/focus=4185
>
>
>
> This was brought up on the keyprov mailing list:
>
>
>
> http://thread.gmane.org/gmane.ietf.keyprov/1011
>
>
>
> /Simon
>
> Instructions:
> -------------
> This errata is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC6030 (draft-ietf-keyprov-pskc-09)
> --------------------------------------
> Title               : Portable Symmetric Key Container (PSKC)
> Publication Date    : October 2010
> Author(s)           : P. Hoyer, M. Pei, S. Machani
> Category            : PROPOSED STANDARD
> Source              : Provisioning of Symmetric Keys
> Area                : Security
> Stream              : IETF
> Verifying Party     : IESG
>

From turners@ieca.com  Thu Nov 29 09:14:33 2012
Return-Path: <turners@ieca.com>
X-Original-To: keyprov@ietfa.amsl.com
Delivered-To: keyprov@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D48121F8B0F for <keyprov@ietfa.amsl.com>; Thu, 29 Nov 2012 09:14:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.261
X-Spam-Level: 
X-Spam-Status: No, score=-102.261 tagged_above=-999 required=5 tests=[AWL=0.004, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AlCkzcRWy5Iv for <keyprov@ietfa.amsl.com>; Thu, 29 Nov 2012 09:14:33 -0800 (PST)
Received: from gateway02.websitewelcome.com (gateway02.websitewelcome.com [67.18.80.20]) by ietfa.amsl.com (Postfix) with ESMTP id EB3E021F8AE6 for <keyprov@ietf.org>; Thu, 29 Nov 2012 09:14:32 -0800 (PST)
Received: by gateway02.websitewelcome.com (Postfix, from userid 5007) id BFA348F46766C; Thu, 29 Nov 2012 11:14:31 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway02.websitewelcome.com (Postfix) with ESMTP id 8801E8F46750E for <keyprov@ietf.org>; Thu, 29 Nov 2012 11:14:31 -0600 (CST)
Received: from [108.45.19.185] (port=49788 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1Te7h2-00076H-0w; Thu, 29 Nov 2012 11:14:32 -0600
Message-ID: <50B797F7.9050804@ieca.com>
Date: Thu, 29 Nov 2012 12:14:31 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:16.0) Gecko/20121026 Thunderbird/16.0.2
MIME-Version: 1.0
To: keyprov@ietf.org
References: <20121003074727.A303DB1E003@rfc-editor.org> <50B54DEC.5070302@ieca.com> <87txs9h3n9.fsf@latte.josefsson.org>
In-Reply-To: <87txs9h3n9.fsf@latte.josefsson.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.19.185]:49788
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 12
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: phill@hallambaker.com
Subject: Re: [KEYPROV] [Technical Errata Reported] RFC6030 (3369)
X-BeenThere: keyprov@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Provisioning of Symmetric Keys \(keyprov\)" <keyprov.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/keyprov>, <mailto:keyprov-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/keyprov>
List-Post: <mailto:keyprov@ietf.org>
List-Help: <mailto:keyprov-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/keyprov>, <mailto:keyprov-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Nov 2012 17:14:33 -0000

List,

Do others have examples they are willing to share?

spt

On 11/28/12 3:30 PM, Simon Josefsson wrote:
> I am also interested in learning how other implementations behave.
>
> I understand you would want more implementer feedback before approving a
> change like this.  The PSKC files I have seen all violate the MUST, but
> I can't claim to have seen any representative proportion of all PSKC
> files.  If people can share example PSKC files used in various
> deployments, that would help.
>
> The alternative to adopt this change is to update the examples
> throughout the document to follow the MUST language.
>
> /Simon
>
> Sean Turner <turners@ieca.com> writes:
>
>> I'm a little hesitant to make this change through an errata.  Two reasons:
>>
>> 1) This was the last discuss point to get resolved.  It was two
>> SHOULDs before it became MUST oathman/iana.
>>
>> 2) It's changing 2119 language.
>>
>> If there's really multiple implementations out there do it differently
>> could we spin a simple paragraph draft that explains there's no reason
>> to restrict it & the old/new text to get this fixed more formally?
>>
>> Question: Do any of the other implementations fall over if you use
>> something without a prefix?
>>
>> spt
>>
>>
>> On 10/3/12 3:47 AM, RFC Errata System wrote:
>>> The following errata report has been submitted for RFC6030,
>>> "Portable Symmetric Key Container (PSKC)".
>>>
>>> --------------------------------------
>>> You may review the report below and at:
>>> http://www.rfc-editor.org/errata_search.php?rfc=6030&eid=3369
>>>
>>> --------------------------------------
>>> Type: Technical
>>> Reported by: Simon Josefsson <simon@josefsson.org>
>>>
>>> Section: 4.3.1
>>>
>>> Original Text
>>> -------------
>>>      <Manufacturer>:  This element indicates the manufacturer of the
>>>         device.  Values for the <Manufacturer> element MUST be taken from
>>>         either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>>>         Private Enterprise Number Registry [IANAPENREG], using the
>>>         Organization value.  When the value is taken from [OATHMAN],
>>>         "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>>>         from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>>>         "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>>>         value from [IANAPENREG]>").
>>>
>>> Corrected Text
>>> --------------
>>>      <Manufacturer>:  This element indicates the manufacturer of the
>>>         device.  Values for the <Manufacturer> element MAY be taken from
>>>         either [OATHMAN] prefixes (i.e., the left column) or from the IANA
>>>         Private Enterprise Number Registry [IANAPENREG], using the
>>>         Organization value.  When the value is taken from [OATHMAN],
>>>         "oath."  MUST be prepended to the value (e.g., "oath.<prefix value
>>>         from [OATHMAN]>").  When the value is taken from [IANAPENREG],
>>>         "iana."  MUST be prepended to the value (e.g., "iana.<Organization
>>>         value from [IANAPENREG]>").
>>>
>>> Notes
>>> -----
>>> The only thing changed is relaxing MUST to MAY.
>>>
>>>
>>>
>>> The requirement that manufacturer strings begin with "oath." and "iana." is often ignored by implementations/deployments.  Further, none of the examples throughout the document conform to the syntax.  While we could regard these as implementation/deployment and editorial document bugs, I would argue that we could just as well relax the technical requirement because there appears to be no harm in allowing free-form text.  This is what people appear to be using out there already.
>>>
>>>
>>>
>>> Examples of non-conforming <Manufacturer> fields out there:
>>>
>>> http://tools.ietf.org/html/draft-hoyer-keyprov-pskc-algorithm-profiles-01
>>>
>>> http://download.gooze.eu/otp/seeds/20120919-test001-4282.xml
>>>
>>> Instructions:
>>> -------------
>>> This errata is currently posted as "Reported". If necessary, please
>>> use "Reply All" to discuss whether it should be verified or
>>> rejected. When a decision is reached, the verifying party (IESG)
>>> can log in to change the status and edit the report, if necessary.
>>>
>>> --------------------------------------
>>> RFC6030 (draft-ietf-keyprov-pskc-09)
>>> --------------------------------------
>>> Title               : Portable Symmetric Key Container (PSKC)
>>> Publication Date    : October 2010
>>> Author(s)           : P. Hoyer, M. Pei, S. Machani
>>> Category            : PROPOSED STANDARD
>>> Source              : Provisioning of Symmetric Keys
>>> Area                : Security
>>> Stream              : IETF
>>> Verifying Party     : IESG
>>>
>
