Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 45CE9C14F61F
	for <spasm@ietfa.amsl.com>; Thu, 23 May 2024 12:59:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level: 
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5,
	RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
	URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001,
	URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=vigilsec.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 8Bm9i_s5KgEF for <spasm@ietfa.amsl.com>;
	Thu, 23 May 2024 12:59:26 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest
 SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id 7C1A4C16943D
	for <spasm@ietf.org>; Thu, 23 May 2024 12:59:26 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1])
	by mail3.g24.pair.com (Postfix) with ESMTP id 60B2D103B1D;
	Thu, 23 May 2024 15:59:25 -0400 (EDT)
Received: from smtpclient.apple (unknown [96.241.2.243])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by mail3.g24.pair.com (Postfix) with ESMTPSA id 44B03103CA4;
	Thu, 23 May 2024 15:59:25 -0400 (EDT)
Content-Type: text/plain;
	charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.1\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <47e2986d-dcfe-4acc-aa18-a253c230ee49@nthpermutation.com>
Date: Thu, 23 May 2024 15:59:14 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <BEDB38D1-0C5E-4EF9-A6EF-717747837F67@vigilsec.com>
References: <d83723fe-6033-43d4-b2c5-9dd9f5989893@nthpermutation.com>
 <9F6362A6-FB58-48A7-8AD6-9132758604D3@redhoundsoftware.com>
 <47e2986d-dcfe-4acc-aa18-a253c230ee49@nthpermutation.com>
To: Mike StJohns <msj@nthpermutation.com>
X-Mailer: Apple Mail (2.3731.700.6.1.1)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com;
 h=content-type:mime-version:subject:from:in-reply-to:date:cc:content-transfer-encoding:message-id:references:to;
 s=pair-202402141609; bh=74UcKPMuu76Bh9vmZZ/CJ/R/EJiD76w4Lb+2P2WusZs=;
 b=BQKglt7jMtBrIKveQenNg/5dsuQh6sEw+dmWs24i5FtgigczBv5m02J5Eill5TcFGnfBvDPOL5tNOxn0oAS670soeojLto/uh7lz9Tqyfx/UyFcZKjVs7WsscDRRXiiH6/uRaxwxPmNuDPUlO2dAoCVDilt+V1Tn9N+P8sP8uZZ8HzOuzIGhg2ksSrMPC47ppzBkVKqfmGpZvgzt4qIrM3cR7F6ta9nOY4HWEQv1n2pmmAPkP/Aq7e8k7w+WZTBWXrB0yt1CkHg/hX6VwBX4RF/v6GpOm6Xb2qjHBPKd2Cw5H26uNedTdgbeF96N3W/MTPDMUJmKPpX6nB+LdeovLg==
X-Scanned-By: mailmunge 3.11 on 66.39.134.11
Message-ID-Hash: A6BN4OAHBF66YBZ7P6BDGFEXTX5ZFB7O
X-Message-ID-Hash: A6BN4OAHBF66YBZ7P6BDGFEXTX5ZFB7O
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-spasm.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: Carl Wallace <carl@redhoundsoftware.com>, spasm@ietf.org
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: =?utf-8?q?=5Blamps=5D_Re=3A_=5BEXTERNAL=5D_Re=3A_WG_Last_Call_for_draft-ietf?=
 =?utf-8?q?-lamps-csr-attestation-09?=
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

Mike:

> In my case, I deal with both ASN1 SIGNED objects and flat signed =
objects of various flavors.   If I see the [0] tag, I know I can =
continue the parsing of the structure without first looking up the =
meaning of the OID and figuring out what the meaning of the various bits =
are (Syntax parsing vs semantic assignment).  I can pass a parsed ASN1 =
tree structure to the validator/object creator associated with the OID =
rather than stopping after parsing the top level.

The ASN.1 tools that I use do not allow processing as you describe.  The =
look up of the OID is required before parsing can continue.  In pyasn1, =
you can provide a map of the supported OIDs and the associated types.  =
Doing this just lets the library do the lookup.  Otherwise, the lookup =
is done by the application, and then a separate call to the parser is =
needed to handle the open type (a.k.a. ANY in the old ASN.1 syntax).

With Carl's suggestion, the OTHER-CERT-FMT defined in RFC 5911 handles =
the cases where the certificate has an ASN.1.  It is identical to the =
TypedCert in the existing document (with slightly different field =
names).

With Carl's suggestion, non-ASN.1 encoded certificates as given an ASN.1 =
type of OCTET STRING, and then decoding will just provide the octets to =
the application, which is exactly what TypedFlatCert does.

When the early versions of this document were posted, I observed that =
TypedCert and TypedFlatCert could be merged in this way.  I still think =
that they should be merged.

Russ

