commoncriteria / commoncriteria/authserver
Comments on FIA_X509_EXT.1/AuthSvr
Open
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
FIA_X509_EXT.1/AuthSvr has several comments on it that are being reproduced here for tracking purposes.
- Re: extendedkeyusage field - "If IKE extended key usage is not prevalent and this breaks IKE implementations (even if not critical), omit this requirement."
- Re: certificates not asserting anyExtendedKeyUsage (OID 2.5.29.37.0) - "See above about IKE key usage potentially breaking implementations."
- Re: certificates requiring Client Authentication purpose - "Some rumbling at IETF that this is for “Web” authentication, only and shouldn’t apply for EAP-methods supporting TLS mutual authentication. Poll vendors, and follow IETF to maybe allow other purposes (or none?)."
- Re: certificates requiring Server Authentication purpose - "See IETF rumblings about 'web only' above."
- Re: certificates requiring ipsec-ike purpose - "Check to see if this is actually used in iPsec products (RFC indicates EKU is not recommended?)."
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the five comments under FIA_X509_EXT.1/AuthSvr and investigate the referenced IKE, EAP-method, TLS mutual-authentication, EKU, and IETF guidance. Done means each comment has a documented resolution or an explicit decision about the corresponding requirement.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100