[COSE] Open source implementation of CBOR Encoded X.509 Certificates (C509 Certificates)

John Mattsson <john.mattsson@ericsson.com> Tue, 25 May 2021 17:48 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F23613A1735 for <cose@ietfa.amsl.com>; Tue, 25 May 2021 10:48:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.698
X-Spam-Level:
X-Spam-Status: No, score=-2.698 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.698, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DjVwR2B0VSsM for <cose@ietfa.amsl.com>; Tue, 25 May 2021 10:48:08 -0700 (PDT)
Received: from EUR02-AM5-obe.outbound.protection.outlook.com (mail-eopbgr00066.outbound.protection.outlook.com [40.107.0.66]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D2A3C3A1734 for <cose@ietf.org>; Tue, 25 May 2021 10:48:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bLBTkMUOA0cLzVzA74ngivsY+piHamB4FFhTshHbtyBmVNF0b3Aqbwl++WrTfc2N2+tCgrGf2voVqn8LQ2PbdXqAibIo/8yJkr7hZk6gkJLep8RmgWnb/d0SGTq8j1ltSZcN6fX+u2BYsnXURpjPjF3HA1+9xGsYGznfZdciGKbC7VuwxV/RTBrw1oNIdBPtG41CzL3D2yV9PmQFYxCVkQhbtsgU3gqhqzsv+Bm2B9yZp7hldFn6eJ2mOmrPy1WB8lqMIEiNY9OLzKuPXnbJSf3uKi9ABUNtLJYxVqg3jwCKj8ntYzN3x8uNGLh09JPJ4NAofkwR9D8sUX6SmvAbOw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8AGUHiXDz+eAKbCu19ak2cMhsZXN26ZNjUOHvVETBqE=; b=do36J2lCHfirhb8M/QKvZBM++1nlXrdrFKEE2nGN5pm6lZL+mp6AkuiPfhmJBcOTQJmW6AfvQn6CVceECm0Zg4gKNCKRefAeoIM1eQ72mXzUAWFo5yTB98pmPQW4jnhNgRqhVYmR/H1nDGMcxMj9FdxGOKPpFGmHndeUbCp4rkZdbMMGeB3Dbmda9ezZjWnKKWpKzz9j9b5BJTOeesvTvJYMSO1upyeuScNsA1gggVKyGcsgbw4KMj1NIt97b61TD1W3FPas8GLz8THRThor6KHJCqDNBqcH0+e0L4mmOo4lXDrMRtVFpemeXyOZEPNp7rEElT5JL26zrLxeUOCcpQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8AGUHiXDz+eAKbCu19ak2cMhsZXN26ZNjUOHvVETBqE=; b=TpBqsQAZkBQJ+hl5dcrPquGMszv6uRb+WMFGy56jggbJw42TVqYJpYx2RJXR/hyxEL9iU7cZuO2GZpbTR9iTmxlYEbiNx0ujy2x+eq3eFlw8JjAkwApIxJ4ijcQxxxQkzCYB1f5/LCUiOtxSWbANtYJKLMQVRiJtI0prF9Z/n0g=
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com (2603:10a6:3:4b::8) by HE1PR0701MB2092.eurprd07.prod.outlook.com (2603:10a6:3:20::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4173.13; Tue, 25 May 2021 17:48:02 +0000
Received: from HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::b071:a4a:817d:2d3]) by HE1PR0701MB3050.eurprd07.prod.outlook.com ([fe80::b071:a4a:817d:2d3%11]) with mapi id 15.20.4173.020; Tue, 25 May 2021 17:48:02 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: "cose@ietf.org" <cose@ietf.org>
Thread-Topic: Open source implementation of CBOR Encoded X.509 Certificates (C509 Certificates)
Thread-Index: AQHXUYGE5UKBeIolhE6yCsbfZoKwmKr0eD0W
Date: Tue, 25 May 2021 17:48:02 +0000
Message-ID: <HE1PR0701MB305053050C67B340D073FEF189259@HE1PR0701MB3050.eurprd07.prod.outlook.com>
References: <HE1PR0701MB3050A74FF321033B5EBBDDAE89259@HE1PR0701MB3050.eurprd07.prod.outlook.com>
In-Reply-To: <HE1PR0701MB3050A74FF321033B5EBBDDAE89259@HE1PR0701MB3050.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [81.225.97.222]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1083a849-d6aa-4279-9f70-08d91fa53e30
x-ms-traffictypediagnostic: HE1PR0701MB2092:
x-microsoft-antispam-prvs: <HE1PR0701MB20922E0558F0B4AF50D0133D89259@HE1PR0701MB2092.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: +xxrm6IRcotT/YFXaDPEjL7OYDty1LvwPDQzFfckLcUqQFhXBmyU0SuNAvn5xRiRIAqpElvn922B0OJoCCm/oUg3eOWcO4MxcUdfqQS2mskUU5RO+JjlEBLtiXXLrdwSmP8aaYXfquNwrQS6pRk62pFT3YJQCez5AnyMdzH2Mr0PmpyZEmdPRIdPY+OP18V8qfXbWrQ5W2kWhpENjcw+At6zLWDoS5+k9lvwXHhjFicGmTluApbgNVL0IFcjglg0ZIfMCwEuUBpOkGjant9HI+uDYGMt8hvux0mO6k0S5hcRQkqv64BLWHErohCHftnSEwX8mWRHr3VdmQV/SuBG47UizoVnzAPqPlJHQDGUcICOK/3IxsN52gaPhdGutqCsfjHPZqB8VR5TzmPnkYeE7RLTpifCt5BDWvVap+Jl+u4LLQDNm/LhuJeNyZ6zBypeCwse2xVQIQ3xnjkx/h6OFgKLegjPj4FghisWqLeuE2YVIKCrejT9mDfrHSjGR1Z+mZtyG64C7D/vqzeFpV4ePn5qwBKampUCCq8ilosvC0nEVxrty7HmHvq4uG5h4vNQWUi95P3iGibtlUKCuJOoUQbzfccErVW6p0N5iE2vmY6kwt7nP04+cjWWX5dl6v1YCj5m6Qm0kprnAXfSTILE3QKYQbu1gCVuaHTGz1jeuBTvhbF9t8D0NNmj6eqFWCr0SwROwY1bI538NtnaaeZy7A==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0701MB3050.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(39860400002)(376002)(396003)(366004)(136003)(346002)(2906002)(71200400001)(86362001)(76116006)(66446008)(7696005)(6916009)(6506007)(8676002)(66616009)(966005)(66476007)(53546011)(66946007)(66556008)(64756008)(8936002)(166002)(44832011)(83380400001)(5660300002)(478600001)(26005)(186003)(9686003)(52536014)(55016002)(99936003)(316002)(122000001)(38100700002)(2940100002)(33656002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: qoy9fGQrcg7TIXPoyXhVtFwRv0oKgpUrmUOm5++5Gug527Dn35ZN0fJ/sR5zF8RbgoeprlO6S/KR5m0z2jdkP5tJI6bA3RSIR7tbJbpHEDuwcM6h/aha6Xi4aXIh75cuzS4XXjrfjwAVgM86fnvyMzAwh6Ih7PCedQxu2IqK2jJADYiFJdEztTRpFZBMD6+0ZZNayxjcUy6kgEpsHI8a1eg54RaDDagbpDZQwDCELkNgDe/4m8I5nqPAXGHJ/obKYnPwU5NQjOQY5yRv7TyhxMY4lhQ2dUVNBrEk1IjK4fa9XWj7MMzGeZD0E64XrP5RDteMiKfN9iwp7rGy9VPzTYW8pyFJjrZG7wuLSRtnp/NQDJsbRfU9xwGA0v0G+h/gYSn76VwS4PmibBre+PVKK0qwKBNNQS1YnqUE3PzoC4iooNLt72CovVB/8vuMPEtljf9KcTS48f2E2hc1VKoIi1bHmHh+osumFkSlHgVddax5mQqZsAc63527xnshOnr+lned/gKk0NrV56rWTLdXBb4D8ifXdwmhDEA42eIBK6JAfyz6LplQmzySJ6qVWn6Y7xTlfG09Ov8ZXteRU71YdA0efWsVVhjFUKWVWzLwpIDnc+KIlPnJ+QhCPva6MXCU0aFDCAnN0e97T/T76v3pnf0DgX6oRtfk88YdMjRGjuv4OrAcBIHBxck8nH13VeH0rK5xLd91JvxJLxgQpzYmX9qDo7D67xHJbM2EGwznH+FG4WeC2URnNL6j2YSKMH/Q2po0jzAHhIKqvoXTDcz1YKhbdej9FQLDmAE5h+wbouBzTtv/kPOvaTn6TOce43dLWwiueCIMf0TkVBplaCOteYD+v3RvokkRAZbol1xscrCVWtkUp2ifmomAAGh7H9TZukVXi6i6SpuLsxodHjd/foab7H9DmtNZOLBx8Lr71ERyiO5chxjgcJ7bGdU1Sbo87nx9egu0zlmU9M4BF6EFYX1u/ZFiLY8auzsiG0BKrQXgA0g6AdgxeQftqw6Kc5Tp+o4dRcbgbEKUXatzvtnJRa3/KfhvQ1kweLhYdhuhe5jFF+B8ZZFNy2GPpqKp7vHK458pu+9FulOBZcONCCxQMlHXDWA83DVfNNkDbwGM26mLMxiR5m+VzaRPffGt8tzXKAhEoF276hl99WkFBwRBJ03XMowXYtIUWjeAaIujXMAd/6fw1B2JS+sVYaNR0oK1zBoe/4EzYZfwrV7yePmZmwf6gDDGZd1XvupvFQalKSUBdryvUcp5JpavJwEQm8tWJEAQb83gAFPH6sKnidNRe5F6eDszYylr9q7e1lYiXoDf01TzkZzZmciaUwUf0Kubiu2uITpEae4QS/LhAE/rBw==
x-ms-exchange-transport-forked: True
Content-Type: multipart/mixed; boundary="_004_HE1PR0701MB305053050C67B340D073FEF189259HE1PR0701MB3050_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0701MB3050.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1083a849-d6aa-4279-9f70-08d91fa53e30
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 May 2021 17:48:02.1795 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: xKzMyxkI172xW6TqgxGpRKmUuNUdjruruqXXKzm5XZ0ErWFS2o3yxWYJNFUU95FY1Iyvh3v5CUHnhGUmXu4t7TjbXWAW0NmBitd2ixwPk/s=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2092
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/6EFchYR9nMmX9OrVYLL_1x4UIH4>
Subject: [COSE] Open source implementation of CBOR Encoded X.509 Certificates (C509 Certificates)
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 May 2021 17:48:14 -0000

Thanks to autocompletion, I accidently sent this mail to CORE instead of COSE. Obviously, I need to send more mails to COSE to train the algorithm…

Cheers,
John

From: core <core-bounces@ietf.org> on behalf of John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
Date: Tuesday, 25 May 2021 at 18:26
To: core@ietf.org <core@ietf.org>, TLS@ietf.org <TLS@ietf.org>, lake@ietf.org <lake@ietf.org>, uta@ietf.org <uta@ietf.org>, spasm@ietf.org <spasm@ietf.org>
Subject: [core] Open source implementation of CBOR Encoded X.509 Certificates (C509 Certificates)
Hi,

There has been a lot requests from people in different working groups for souce code to try out C509 certificates. I just released my example implementation of a DER X509 to CBOR C509 encoder written in Rust.

CBOR encoded X509 (RFC 5280) is one of the main future work item for the COSE WG. C509 is specified as a CBOR encoding of the DER TBSCertificate sequence, which is then combined with a signature over the DER or CBOR encoding. C509 can be used as a compression mechanism complementing RFC 8879, or as a "natively signed" CBOR certificatice encoding still following RFC 5280.

The Rust implementation supports reading a certificate from file or downloading a certificate chain from a HTTPS server. The certificate chain is encoded to COSE_X509, COSE_C509, as well as TLS Certificate and CompressedCertificate messages with X509 and C509. Size comparisions can be found in the draft.

The Rust implementation can be found here:
https://github.com/cose-wg/CBOR-certificates/tree/master/c509<https://protect2.fireeye.com/v1/url?k=2a6ab0a6-75f18997-2a6af03d-86e2237f51fb-7667cbbe53d45aaa&q=1&e=925c08c9-de3a-40c0-aa7c-482922bdd63f&u=https%3A%2F%2Fgithub.com%2Fcose-wg%2FCBOR-certificates%2Ftree%2Fmaster%2Fc509>

The latest version of the draft:
https://datatracker.ietf.org/doc/draft-ietf-cose-cbor-encoded-cert/

Please send comments and suggestions to core@ietf.org only, which is where discussion should take place.

Cheers,
John