Coding Of Public Signature Algorithm Identifier
"Tom-PT Taylor" <[email protected]> Mon, 13 Jan 2003 12:50:07 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
One piece of our proposed ITRACE record is a public signature algorithm identifier. The identifiers I have been able to track down for this purpose are in RFC 3279 (sec. 2.2), and take the form of OIDs. It seems a pity to get so complicated for a handful of algorithms, but that may be what we are stuck with unless we establish a registry of our own. I can see these alternatives: 1) use the OIDs. In that case, how do I specify the encoding in our record: use only the value portion of the OID as encoded in ASN.1, or use the entire ASN.1 object? 2) specify the hash algorithm and the encryption algorithm as separate items, concatenated. The hash algorithm can be the two-octet identifier taken from the IANA IPSEC registry (http://www.iana.org/assignments/ipsec-registry). The encryption algorithm would probably best come from the two-octet "IPSEC Authentication Methods" signature codepoints in the same registry (i.e. codepoints 2, 3, and 8). Thus the complete signature algorithm identifier would be a four-octet field. 3) establish our own list of signature algorithm identifiers, covering the same ground as the RFC 3279 OIDs. Opinions? Tom Taylor [email protected] Ph. +1 613 736 0961 (ESN 396 1490)