Re: Review of draft-ietf-krb-wg-pkinit-alg-agility-06

Tom Yu <[email protected]> Wed, 21 Mar 2012 08:03:54 -0400
Newsgroups gmane.ietf.krb-wg
Message-ID <[email protected]>
Jeffrey Hutzelman <[email protected]> writes:

> 3) This document assigns the following values, drawn from registries
>    not yet managed by IANA.  Please confirm that these values have
>    actually been assigned and are correct:
>
>    - id-pkinit-kdc OID arc (id-pkinit 6)

There is no known conflict for this OID, but I had not recorded it
yet.  The ASN.1 module in Appendix A defines neither this OID nor its
children.  It possibly should, while also mentioning that they are
used as RFC 3280 AlgorithmIdentifier OIDs, and that they have no
associated parameters when used as such.

>    - Error type KDC_ERR_NO_ACCEPTABLE_KDF (82)

There is no known conflict for this error code, and I have recorded it
earlier.  It does not appear in the ASN.1 module, but we have tended
not to use ASN.1 to define error code assignments (unlike for preauth
and typed-data numbers).

Additionally, I already recorded the following assignments:

   TD-CMS-DIGEST-ALGORITHMS ::= INTEGER 111
   TD-CERT-DIGEST-ALGORITHMS ::= INTEGER 112

though to be syntactically correct ASN.1, they should be:

   td-cms-digest-algorithms     INTEGER ::= 111
   td-cert-digest-algorithms    INTEGER ::= 112

They also do not appear in the ASN.1 module.
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg