Coding Of Public Signature Algorithm Identifier

"Tom-PT Taylor" <[email protected]> Mon, 13 Jan 2003 12:50:07 -0500
Newsgroups gmane.ietf.itrace
Message-ID <[email protected]>
One piece of our proposed ITRACE record is a public signature algorithm
identifier.  The identifiers I have been able to track down for this purpose
are in RFC 3279 (sec. 2.2), and take the form of OIDs.  It seems a pity to
get so complicated for a handful of algorithms, but that may be what we are
stuck with unless we establish a registry of our own.  I can see these
alternatives:

1) use the OIDs.  In that case, how do I specify the encoding in our record:
use only the value portion of the OID as encoded in ASN.1, or use the entire
ASN.1 object?

2) specify the hash algorithm and the encryption algorithm as separate
items, concatenated.  The hash algorithm can be the two-octet identifier
taken from the IANA IPSEC registry
(http://www.iana.org/assignments/ipsec-registry).  The encryption algorithm
would probably best come from the two-octet "IPSEC Authentication Methods"
signature codepoints in the same registry (i.e. codepoints 2, 3, and 8).
Thus the complete signature algorithm identifier would be a four-octet
field.

3) establish our own list of signature algorithm identifiers, covering the
same ground as the RFC 3279 OIDs.

Opinions?

Tom Taylor
[email protected]
Ph. +1 613 736 0961 (ESN 396 1490)