Re: Coding Of Public Signature Algorithm Identifier
Mikael Olsson <[email protected]> Wed, 15 Jan 2003 00:47:56 +0100
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Clavister AB |
| Message-ID | <[email protected]> |
[Resending after resubscribing with my new address; it would seem that the list has gone closed-posting since I last posted. Good :)] Tom, all, The views of a programmer that dislikes bloat... Tom-PT Taylor wrote: > > 1) use the OIDs. In that case, how do I specify the encoding in our record: > use only the value portion of the OID as encoded in ASN.1, or use the entire > ASN.1 object? If you decide to go this route, I beg you: do NOT use ASN.1 encoding. It's an open invitation to disaster. Reference: - "ASN.1 parsing errors exist in implementations of SSL, TLS, S/MIME, PKCS#7 routines" http://www.kb.cert.org/vuls/id/748355 - "CA-2002-03: Multiple Vulnerabilities in Many Implementations of the Simple Network Management Protocol (SNMP)" http://www.cert.org/advisories/CA-2002-03.html > 3) establish our own list of signature algorithm identifiers, covering the > same ground as the RFC 3279 OIDs. My personal opinion would be to establish a separate registry. A _small_ one. How does two entries sound? For example: - 1024-bit RSA encrypted SHA-1 digest - 2048-bit RSA encrypted SHA-1 digest Seriously, the X.509 and IPsec registries cover far more ground than is needed for a protocol as "small" as itrace, in my opinion. -- Mikael Olsson, Clavister AB Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden Phone: +46 (0)660 29 92 00 Mobile: +46 (0)70 26 222 05 Fax: +46 (0)660 122 50 WWW: http://www.clavister.com