spdx / spdx/cryptographic-algorithm-list

Should we include in the list certificate-pki standard like X509 in the list?

Open
#49 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
No language data
Stars
8
Forks
4
PR merge metrics
No merged PRs in 30d

Description

Rationale

This ticket is a consequence of the discussion developed on #36

Certificates are an interesting case for the Security Profile. The are not algorithms but they use them.

Request

  • Do we include certificates on the List?
    • If yes, can we describe the basic arguments to do so?
    • If not, can we explain why?
  • If we include them, how do we do so?
    • Do we create a specific category?
    • Do we create a supra structure or a different structure for these cases?

DoD

  • Agreement on including or not the certificates or not on the list
    • If the agreement is to include them, example of how they would be included
    • If the agreement is to not include them, then link to the PR that removes X509 from the list.
      • PR merged

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the discussion referenced in issue #36 and reviewing how X509 currently appears in the list. Resolve whether certificates belong in the list and, if so, document an inclusion example and structure; otherwise link the PR that removes X509 and confirm it is merged.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.