[API Proposal]: Make GenericNameAsn (and related) available via X509SubjectAlternativeNameExtension
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start with src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/X509Certificates/X509SubjectAlternativeNameExtension.cs and review the existing EnumerateDnsNames() and EnumerateIPAddresses() APIs. Compare the proposed aggregate and per-type enumeration designs with the related internal ASN classes; done requires a settled public API design rather than simply exposing the currently internal types.
Written by the indexing model from the issue text.
Description
Background and motivation
I'm the maintainer of a small ACME compatible server software, that connects ACME to ADCS.
Currently the implementation uses CERTENROLLLib to validate data around CSRs.
I now tried to move that CSR validation into managed code, to have only small code snippets that need COM interop at all and else have a generic ACME server, that might support multiple backends.
While src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/X509Certificates/X509SubjectAlternativeNameExtension.cs would contain lots of the code, that is necessary to read CSRs (and especially the SANs), all besides DnsNames and IPAddresses is marked internal, which leads to duplicating code from some of those classes into my own project.
API Proposal
namespace System.Security.Cryptography.X509Certificates
{
public sealed class X509SubjectAlternativeNameExtension : X509Extension
{
// existing API omitted
public IEnumerable<GeneralNameAsn> EnumerateAlternativeNames();
}
}
API Usage
var certificateRequest = CertificateRequest.LoadSigningRequest(
Convert.FromBase64String(order.CertificateSigningRequest),
HashAlgorithmName.SHA256,
CertificateRequestLoadOptions.UnsafeLoadCertificateExtensions
);
var alternativeNames = certificateRequset.CertificateExtensions.OfType<X509SubjectAlternativeNameExtension>().SelectMany(x => x.AlternativeNames);
Alternative Designs
Since there are already methods for DnsNames and IPAddresses EnumerateDnsNames(), EnumerateIPAddresses()
There could be enumeration by type
namespace System.Security.Cryptography.X509Certificates
{
public sealed class X509SubjectAlternativeNameExtension : X509Extension
{
// existing API omitted
public IEnumerable<OtherNameAsn> EnumerateOtherNames();
public IEnumerable<string> EnumerateRfc822Names();
public IEnumerable<byte[]> EnumerateX400Addresses();
public IEnumerable<byte[]> EnumerateDirectoryNames();
public IEnumerable<EdiPartyNameAsn> EnumerateEdiPartyNames();
public IEnumerable<string> EnumerateUris();
public IEnumerable<string> EnumerateRegisteredIds();
}
}
Risks
This entails making a bunch of classes public, that currently are internal
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- PR merge metrics
- PR metrics pending
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
agentic-workflows untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
area-System.Reflection blocking-clean-ci-optional Known Build Error os-mac-os-x untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area-CodeGen-coreclr untriaged
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 78/100
-
area-VM-meta-mono untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
dotnet/AspNetCore.Docs#37699 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SubtitleEdit/subtitleedit#15108 · 1 comment ·
-
area/docs-content Bug pulumi/docs
Difficulty 1/5 1-3 hours Newbie friendliness 94/100
-
Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PowerShell/PSResourceGet#2056 ·