[saag] Re: [Ext] Re: draft-paulwh-crypto-components-02 : recommended, MTI, OIDx

Christian Huitema <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
On 2/17/2025 10:48 AM, Salz, Rich wrote:
>>>> Hrm. This points to another reason to promote IANA registries instead of (or in addition to) OIDs.
>>> I don't think so. OIDs can be created and used by anyone, but OIDs not in a standards-track RFC seem to me just like private-use identifiers.
>> Maybe you don't deal much with PKIX or CMS. The OIDs there are absolutely the way that the cryptographic components are identified.
> Yes, I know.
>
> I guess I wasn't clear.  Anyone can define an OID and use it in an RFC.  I am saying that if that RFC is Informational, not in the IETF stream, or anything else -- THAT IS NOT STANDARDS-TRACK -- then there is little noticeable difference between that(those) OID and private-use space in an IANA registry.  Using your example, I can define a new PKCS#8 private key type that and publish an Individual draft or Experimental. But unless it came from LAMPS and is on the standards track, it's just (er) yelling into the wind, or a private-use identifier.

OID have the property of being unique. That is only one of the functions 
of the registry. The other functions are:

* being well known, a.k.a., "the spec is available"

* having a documented recommendation produced by WG or experts, from 
"recommended" or "mandatory" to "maybe not", using terminology generally 
chosen by the WG.

You could achieve those other functions by registering an OID in the 
IANA registry, but that forces the registry to verify that this OID is 
indeed unique, e.g., use an organization code that is properly 
registered, and that whoever asks for the registration is authorized to 
use names under that OID branch. That's an extra burden for IANA. Other 
methods, like large random numbers, are somewhat easier to manage.

-- Christian Huitema

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.