2.5. 更新 Section 5.1.3.1 - Shared Secret Information
2.5. 更新 Section 5.1.3.1 - Shared Secret Information
[RFC4210] Section 5.1.3.1 描述使用 id-PasswordBasedMac 算法, 基于 message authentication code (MAC) 对 PKIMessage 进行保护.
将第一段替换为以下文本:
在这种情况下, sender 和 recipient 共享具有足够 entropy 的 secret information (通过 out-of-band 方式或从先前的 PKI management operation 建立). PKIProtection 将包含 MAC value, protectionAlg MAY 是 CMP Algorithms [RFC9481] 中描述的选项之一. PasswordBasedMac 规定如下 (另见 [RFC4211] 和 [RFC9045]):
将最后一段替换为以下文本 (Note: 这修复 Errata ID 2616):
Note: RECOMMENDED 在单个 transaction 的所有 message 中保持 PBMParameter 的字段不变 (例如 ir/ip/certConf/pkiConf), 以减少与 PasswordBasedMac 计算相关的开销.