commoncriteria / commoncriteria/authserver

Comments on FIA_X509_EXT.1/AuthSvr

Open
#21 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Makefile
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

FIA_X509_EXT.1/AuthSvr has several comments on it that are being reproduced here for tracking purposes.

  1. Re: extendedkeyusage field - "If IKE extended key usage is not prevalent and this breaks IKE implementations (even if not critical), omit this requirement."
  2. Re: certificates not asserting anyExtendedKeyUsage (OID 2.5.29.37.0) - "See above about IKE key usage potentially breaking implementations."
  3. Re: certificates requiring Client Authentication purpose - "Some rumbling at IETF that this is for “Web” authentication, only and shouldn’t apply for EAP-methods supporting TLS mutual authentication. Poll vendors, and follow IETF to maybe allow other purposes (or none?)."
  4. Re: certificates requiring Server Authentication purpose - "See IETF rumblings about 'web only' above."
  5. Re: certificates requiring ipsec-ike purpose - "Check to see if this is actually used in iPsec products (RFC indicates EKU is not recommended?)."

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the five comments under FIA_X509_EXT.1/AuthSvr and investigate the referenced IKE, EAP-method, TLS mutual-authentication, EKU, and IETF guidance. Done means each comment has a documented resolution or an explicit decision about the corresponding requirement.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.