Re: OID encoding help

Robert Moskowitz <[email protected]> Sun, 7 May 2023 13:19:52 -0400
Newsgroups gmane.ietf.x509
Message-ID <[email protected]>
Or since 1.3.6.1.4.1.6715.2.6.6 is defined to have a bit-string value of 
126 bytes, there is no need for anything but that 126-byte Endorsement.

On 5/7/23 12:24, Robert Moskowitz wrote:
> Russ,
>
> That gets me half way there.   The whole point of the OID is to encode 
> the DRIP Broadcast Endorsement (draft-ietf-drip-registries-09, sec 
> B.3) CERT RR 254 is for encoding "certificates" per a private OID, in 
> this case, 1.3.6.1.4.1.6715.2.6.6
>
> An example of a 126-byte DRIP Broadcast Endorsement is:
>
> 64508ac066306cc02001003ffe3ff8058eb731967e48293470a73efd272fb7de1fffd73a33c2ae5e12f1a0bb8da5baef394da2d9d5e8ed832001003ffe00000589bbba7c404b16bb7834240bb19829151f5a673f46c600cea5a89ee4833e82a30ccb7db9a55161759a6ac29bc5fd9393a2cc4e378d2f483fcea687ad52012b410e89ca2c86f0630e
>
> So how do I put it all together?
>
> And wrt to using CERT RR, it is a bit of a hack, as there is really 
> nothing else existing now that we can stick this in.  Jim Reid feels 
> we should just create a specific RR, and Jim knows this stuff much 
> better than I.  But for this initial testing setup CERT RR is what we 
> are using.
>
> Bob
>
> On 5/7/23 11:18, Russ Housley wrote:
>> I'm nor sure how CERT RR is solving your problem, but that is not 
>> your question.
>>
>> Since you are using pyasn1...
>>
>> >>> from pyasn1.type import univ
>> >>> from pyasn1.codec.der.decoder import decode as der_decoder
>> >>> from pyasn1.codec.der.encoder import encode as der_encoder
>> >>> import binascii
>> >>> oid = univ.ObjectIdentifier('1.3.6.1.4.1.6715.2.6.6')
>> >>> s = der_encoder(oid)
>> >>> print(binascii.hexlify(s))
>> 060a2b06010401b43b020606
>> >>> 
>>
>> Russ
>>
>>
>>> On May 7, 2023, at 9:02 AM, Robert Moskowitz 
>>> <[email protected]> wrote:
>>>
>>> I am asking here, as this seems like a place I can at least get 
>>> directions on where to ask for help.
>>>
>>> Challenge:  write simple python code to create an OID object.
>>>
>>> Background:
>>>
>>> In draft-ietf-drip-registries, there is a 126-byte RATS-styled 
>>> Endorsement object call the DRIP Broadcast Endorsement (sec B.3). 
>>> This object is intended to be available publically via DNS.  For 
>>> testing and perhaps onwards all we are finding is to use the CERT RR 
>>> and encode this as a private OID object.  For initial work we will 
>>> use oid = "1.3.6.1.4.1.6715.2.6.6", with the Endorsement as type 
>>> BIT-STRING.
>>>
>>> So....
>>>
>>> But I cannot google up any advise on how to do this.  Given how 
>>> fixed this is, it might even be possible to hand-figure this out and 
>>> just make the object without involking some python asn1 library. But 
>>> I am just stuck.
>>>
>>> So can anyone pitch in, or at least point me to some advise postings.
>>>
>>> Oh, I am doing this in F38 which has the python3-pyasn1 libary.
>>>
>>> thanks
>>>
>>> Oh course an 'easier' way would be to extent the TLSA RR to support 
>>> this type of 'certificate'.  We are already using the TLSA RR for 
>>> the SPKI we get when we make DETs (rfc 9374).  That is easy, as we 
>>> get the DER with the keypair generation.  But then this would be a 
>>> change to TLSA and changes like that to existing RR rarely go well.
>>>
>>> Bob
>>>
>>>
>>> _______________________________________________
>>> pkix mailing list
>>> [email protected]
>>> https://www.ietf.org/mailman/listinfo/pkix
>>
>
>
> _______________________________________________
> pkix mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/pkix

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix