Re: Coding Of Public Signature Algorithm Identifier

Mikael Olsson <[email protected]> Wed, 15 Jan 2003 00:47:56 +0100
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
[Resending after resubscribing with my new address; it would seem that 
 the list has gone closed-posting since I last posted. Good :)]

Tom, all,

The views of a programmer that dislikes bloat...

Tom-PT Taylor wrote:
> 
> 1) use the OIDs.  In that case, how do I specify the encoding in our record:
> use only the value portion of the OID as encoded in ASN.1, or use the entire
> ASN.1 object?

If you decide to go this route, I beg you: do NOT use ASN.1 encoding.
It's an open invitation to disaster.

Reference:
- "ASN.1 parsing errors exist in implementations of SSL, TLS, S/MIME, 
   PKCS#7 routines"
  http://www.kb.cert.org/vuls/id/748355
- "CA-2002-03: Multiple Vulnerabilities in Many Implementations of the 
   Simple Network Management Protocol (SNMP)"
  http://www.cert.org/advisories/CA-2002-03.html

> 3) establish our own list of signature algorithm identifiers, covering the
> same ground as the RFC 3279 OIDs.


My personal opinion would be to establish a separate registry.
A _small_ one. How does two entries sound? For example:
- 1024-bit RSA encrypted SHA-1 digest
- 2048-bit RSA encrypted SHA-1 digest

Seriously, the X.509 and IPsec registries cover far more ground than
is needed for a protocol as "small" as itrace, in my opinion.


-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com