[API Proposal]: Make GenericNameAsn (and related) available via X509SubjectAlternativeNameExtension

Open
#116,348 10 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Stale
Tech stack
csharp
Domain
api, security

Research direction

Start with src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/X509Certificates/X509SubjectAlternativeNameExtension.cs and review the existing EnumerateDnsNames() and EnumerateIPAddresses() APIs. Compare the proposed aggregate and per-type enumeration designs with the related internal ASN classes; done requires a settled public API design rather than simply exposing the currently internal types.

Written by the indexing model from the issue text.

Description

api-suggestion area-System.Security
Background and motivation

I'm the maintainer of a small ACME compatible server software, that connects ACME to ADCS.
Currently the implementation uses CERTENROLLLib to validate data around CSRs.
I now tried to move that CSR validation into managed code, to have only small code snippets that need COM interop at all and else have a generic ACME server, that might support multiple backends.

While src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/X509Certificates/X509SubjectAlternativeNameExtension.cs would contain lots of the code, that is necessary to read CSRs (and especially the SANs), all besides DnsNames and IPAddresses is marked internal, which leads to duplicating code from some of those classes into my own project.

API Proposal
namespace System.Security.Cryptography.X509Certificates
{
    public sealed class X509SubjectAlternativeNameExtension : X509Extension
    {
        // existing API omitted
        
        public IEnumerable<GeneralNameAsn> EnumerateAlternativeNames();
    }
}
API Usage
var certificateRequest = CertificateRequest.LoadSigningRequest(
    Convert.FromBase64String(order.CertificateSigningRequest),
    HashAlgorithmName.SHA256,
    CertificateRequestLoadOptions.UnsafeLoadCertificateExtensions 
    );

var alternativeNames = certificateRequset.CertificateExtensions.OfType<X509SubjectAlternativeNameExtension>().SelectMany(x => x.AlternativeNames);
Alternative Designs

Since there are already methods for DnsNames and IPAddresses EnumerateDnsNames(), EnumerateIPAddresses()
There could be enumeration by type

namespace System.Security.Cryptography.X509Certificates
{
    public sealed class X509SubjectAlternativeNameExtension : X509Extension
    {
        // existing API omitted
        
        public IEnumerable<OtherNameAsn> EnumerateOtherNames();
        public IEnumerable<string> EnumerateRfc822Names();
        public IEnumerable<byte[]> EnumerateX400Addresses();
        public IEnumerable<byte[]> EnumerateDirectoryNames();
        public IEnumerable<EdiPartyNameAsn> EnumerateEdiPartyNames();
        public IEnumerable<string> EnumerateUris();
        public IEnumerable<string> EnumerateRegisteredIds();
    }
}
Risks

This entails making a bunch of classes public, that currently are internal

Dominant language
C#
Stars
18.3k
Forks
5.6k
PR merge metrics
PR metrics pending

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dotnet/runtime

All issues in dotnet/runtime

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.