Re: Coding Of Public Signature Algorithm Identifier
Jim Duncan <[email protected]> Wed, 15 Jan 2003 11:36:50 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
Marcus Leech writes: > "Taylor, Tom-PT [CAR:5N00:EXCH]" wrote: > > > > If we used the OIDs, they would appear as the 9-octet or 11-octet hex-string > > constants I identified yesterday. This does seem like bloat, but there > > would be no need for an ASN.1 parser to handle them. > > > > So far I've had Mikael's note and a private one from Daniel Senie in favour > > of a separate IANA registry. Marcus, how do we proceed? > > > I have to say that I'm thrilled that there's some traffic on this list. I was > beginning to think that things were dying. Things _are_ dying, but there's traffic about it anyhow. ;-) > If the general feeling is that OIDs are baaaaad (and I have to agree that > if it means we need an ASN.1 parser, we'll be vulnerable), then I don't > have any problem with a new IANA registry. Please add my name to the vote against using OIDs. I've taken a lot of heat for my opinion on ASN.1 parsers, but I'll continue to say that the complexity (and the concomitant risk to security) far outweighs any perceived benefits. In general, use XML. In this case, perhaps a new registry is the best way to go. My two cents' worth. Jim == Jim Duncan, Product Security Incident Manager, Cisco Systems, Inc. http://www.cisco.com/warp/public/707/sec_incident_response.shtml E-mail: [email protected] Phone(Direct/FAX): +1 919 392 6209