spdx / spdx/cryptographic-algorithm-list
Should we include in the list certificate-pki standard like X509 in the list?
Open
Nobody has claimed this yet.
question
- Dominant language
- No language data
- Stars
- 8
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
Rationale
This ticket is a consequence of the discussion developed on #36
Certificates are an interesting case for the Security Profile. The are not algorithms but they use them.
Request
- Do we include certificates on the List?
- If yes, can we describe the basic arguments to do so?
- If not, can we explain why?
- If we include them, how do we do so?
- Do we create a specific category?
- Do we create a supra structure or a different structure for these cases?
DoD
- Agreement on including or not the certificates or not on the list
- If the agreement is to include them, example of how they would be included
- If the agreement is to not include them, then link to the PR that removes X509 from the list.
- PR merged
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the discussion referenced in issue #36 and reviewing how X509 currently appears in the list. Resolve whether certificates belong in the list and, if so, document an inclusion example and structure; otherwise link the PR that removes X509 and confirm it is merged.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100