Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 8FF87C1D6FBA
	for <spasm@ietfa.amsl.com>; Tue,  7 Jan 2025 13:11:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.805
X-Spam-Level: 
X-Spam-Status: No, score=-2.805 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7,
	RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001,
	RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
	T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
	URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=vigilsec.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 3tHNssF1B7fu for <spasm@ietfa.amsl.com>;
	Tue,  7 Jan 2025 13:11:26 -0800 (PST)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id 8E3C3C1D5C5B
	for <spasm@ietf.org>; Tue,  7 Jan 2025 13:11:26 -0800 (PST)
Received: from mail3.g24.pair.com (localhost [127.0.0.1])
	by mail3.g24.pair.com (Postfix) with ESMTP id BDAE2D10F8;
	Tue,  7 Jan 2025 16:11:25 -0500 (EST)
Received: from smtpclient.apple (unknown [96.241.2.243])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by mail3.g24.pair.com (Postfix) with ESMTPSA id AAA1BD0FE4;
	Tue,  7 Jan 2025 16:11:25 -0500 (EST)
Content-Type: text/plain;
	charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3826.200.121\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <14932.1736283948@obiwan.sandelman.ca>
Date: Tue, 7 Jan 2025 16:11:15 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <569C3C7E-8EF5-4298-9B15-87C9ADA222F8@vigilsec.com>
References: <C61AE8CA-3692-43E0-ACE4-8BB0DEDB6D8B@vigilsec.com>
 <1DC465AC-81D9-4CC8-BC8A-685992CF92F4@vigilsec.com>
 <72BE2942-545F-406A-B473-49A5804562DA@vigilsec.com>
 <211674A1-1440-433B-904D-8E433808A37D@vigilsec.com>
 <B3ACD3B4-1371-462C-937C-65A9F80EA3E8@vigilsec.com>
 <47718815-ea2b-47dc-9372-c88de0a7bf70@ddvo.net>
 <58982402-0310-4D0C-ADAD-2CF7D93A4CD5@vigilsec.com>
 <2972.1736281328@obiwan.sandelman.ca>
 <CED56F79-6F9C-4101-B639-809C0282E5CD@vigilsec.com>
 <14932.1736283948@obiwan.sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.3826.200.121)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com;
 h=content-type:mime-version:subject:from:in-reply-to:date:cc:content-transfer-encoding:message-id:references:to;
 s=pair-202402141609; bh=5t5dIQ0PyVZ42sK6+7OmUON2+QwtxeCiE6fM/CUxAWA=;
 b=UlqILusA6mS86pPv+/deqqdWyCjG042EyJi+cU/xteGXmqI4eGtr0eeX+Xva1l8VTUnrav4I6iHyjjze9cZsI4/zi8n10OL44ZFvNMtMSNVzegNE4Dwsjtbt+eDmQ+3SoqSWm0N/16AuTIoFTynab96a/MuPFMYQpLHi38mPHlGmFTbolHe9LnYCiR3KUtvVu396n6vjbUg9Gogqd9GRtoNybdfyA4IZHOYNlnC03UOWs2SRrjiys/DHQXRYTAESCguydleaRHErpVStmdlxIjQ7N2dfSlqWL185EWJGJIOjAJ4FaJyw+xEaadjgywn1lN00g47pzAJwbMIDwYre1g==
X-Scanned-By: mailmunge 3.11 on 66.39.134.11
Message-ID-Hash: ACG3JCWUXK6RNECR6TMYUTLYIGQ6BWHY
X-Message-ID-Hash: ACG3JCWUXK6RNECR6TMYUTLYIGQ6BWHY
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-spasm.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: LAMPS <spasm@ietf.org>, David von Oheimb <dev@ddvo.net>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5Blamps=5D_Re=3A_WG_Last_Call_for_draft-ietf-lamps-rfc7030-csratt?=
	=?utf-8?q?rs?=
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/spasm/gFjW_VlaNgvM6fuD4cqTp_CsNvU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>



> On Jan 7, 2025, at 4:05=E2=80=AFPM, Michael Richardson =
<mcr+ietf@sandelman.ca> wrote:
>=20
>=20
> Russ Housley <housley@vigilsec.com> wrote:
>> (1) Attributes{}, CRIAttributes, PKInfoAlgorithms still need to be
>> IMPORTed from PKCS-10.  Just ATTRIBUTE need to move.  I needs to be
>> IMPORTED from PKIX-CommonType-2009, which is where you are already
>> importing EXTENSION.
>=20
> okay, so I need to create a new import.  Well, there is already one =
above,
> which I think I can extend.
>=20
> https://github.com/lamps-wg/lamps-rfc7030-csrattrs/pull/29/files
> =
https://github.com/lamps-wg/lamps-rfc7030-csrattrs/blob/asn1-fixes-jan2025=
/CRITemplateModule.asn

You just need to move ATTRIBUTE to the one for PKIX-CommonType-2009.

>=20
>> (2) id-extensionReqTemplate should be renamed to align with other
>> things in that registry.
>=20
> I'll go read the IANA registry to learn the naming.

My edit changed id- to id-aa- as the prefix.

   id-aa-extensionReqTemplate OBJECT IDENTIFIER ::=3D
     { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9)
       smime(16) aa(2) extnReqTemplate(TBD3) }

   --  like extensionRequest, but with OPTIONAL Extension extnValues
   --  original definition was in PKCS#9 RFC 2985 section 5.4.2
   at-extensionReqTemplate ATTRIBUTE ::=3D {
       TYPE ExtensionReqTemplate IDENTIFIED BY =
id-aa-extensionReqTemplate }

Russ=

