[lamps] Re: [EXTERNAL] Re: WG Last Call for draft-ietf-lamps-csr-attestation-09

Russ Housley <housley@vigilsec.com> Thu, 23 May 2024 19:59 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45CE9C14F61F for <spasm@ietfa.amsl.com>; Thu, 23 May 2024 12:59:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level:
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=vigilsec.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Bm9i_s5KgEF for <spasm@ietfa.amsl.com>; Thu, 23 May 2024 12:59:26 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C1A4C16943D for <spasm@ietf.org>; Thu, 23 May 2024 12:59:26 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 60B2D103B1D; Thu, 23 May 2024 15:59:25 -0400 (EDT)
Received: from smtpclient.apple (unknown [96.241.2.243]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 44B03103CA4; Thu, 23 May 2024 15:59:25 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.1\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <47e2986d-dcfe-4acc-aa18-a253c230ee49@nthpermutation.com>
Date: Thu, 23 May 2024 15:59:14 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <BEDB38D1-0C5E-4EF9-A6EF-717747837F67@vigilsec.com>
References: <d83723fe-6033-43d4-b2c5-9dd9f5989893@nthpermutation.com> <9F6362A6-FB58-48A7-8AD6-9132758604D3@redhoundsoftware.com> <47e2986d-dcfe-4acc-aa18-a253c230ee49@nthpermutation.com>
To: Mike StJohns <msj@nthpermutation.com>
X-Mailer: Apple Mail (2.3731.700.6.1.1)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com; h=content-type:mime-version:subject:from:in-reply-to:date:cc:content-transfer-encoding:message-id:references:to; s=pair-202402141609; bh=74UcKPMuu76Bh9vmZZ/CJ/R/EJiD76w4Lb+2P2WusZs=; b=BQKglt7jMtBrIKveQenNg/5dsuQh6sEw+dmWs24i5FtgigczBv5m02J5Eill5TcFGnfBvDPOL5tNOxn0oAS670soeojLto/uh7lz9Tqyfx/UyFcZKjVs7WsscDRRXiiH6/uRaxwxPmNuDPUlO2dAoCVDilt+V1Tn9N+P8sP8uZZ8HzOuzIGhg2ksSrMPC47ppzBkVKqfmGpZvgzt4qIrM3cR7F6ta9nOY4HWEQv1n2pmmAPkP/Aq7e8k7w+WZTBWXrB0yt1CkHg/hX6VwBX4RF/v6GpOm6Xb2qjHBPKd2Cw5H26uNedTdgbeF96N3W/MTPDMUJmKPpX6nB+LdeovLg==
X-Scanned-By: mailmunge 3.11 on 66.39.134.11
Message-ID-Hash: A6BN4OAHBF66YBZ7P6BDGFEXTX5ZFB7O
X-Message-ID-Hash: A6BN4OAHBF66YBZ7P6BDGFEXTX5ZFB7O
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Carl Wallace <carl@redhoundsoftware.com>, spasm@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [lamps] Re: [EXTERNAL] Re: WG Last Call for draft-ietf-lamps-csr-attestation-09
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

Mike:

> In my case, I deal with both ASN1 SIGNED objects and flat signed objects of various flavors.   If I see the [0] tag, I know I can continue the parsing of the structure without first looking up the meaning of the OID and figuring out what the meaning of the various bits are (Syntax parsing vs semantic assignment).  I can pass a parsed ASN1 tree structure to the validator/object creator associated with the OID rather than stopping after parsing the top level.

The ASN.1 tools that I use do not allow processing as you describe.  The look up of the OID is required before parsing can continue.  In pyasn1, you can provide a map of the supported OIDs and the associated types.  Doing this just lets the library do the lookup.  Otherwise, the lookup is done by the application, and then a separate call to the parser is needed to handle the open type (a.k.a. ANY in the old ASN.1 syntax).

With Carl's suggestion, the OTHER-CERT-FMT defined in RFC 5911 handles the cases where the certificate has an ASN.1.  It is identical to the TypedCert in the existing document (with slightly different field names).

With Carl's suggestion, non-ASN.1 encoded certificates as given an ASN.1 type of OCTET STRING, and then decoding will just provide the octets to the application, which is exactly what TypedFlatCert does.

When the early versions of this document were posted, I observed that TypedCert and TypedFlatCert could be merged in this way.  I still think that they should be merged.

Russ