diff options
author | job <> | 2021-02-02 13:58:26 +0000 |
---|---|---|
committer | job <> | 2021-02-02 13:58:26 +0000 |
commit | 9137e5c05b0ad875bb841164b316a51799dd0d1c (patch) | |
tree | c63e4588ffd3f98bf74da36df689a9a253f1fd8a /src | |
parent | a6cc9591e3bac019dd87bed952159a2f5bddb71d (diff) | |
download | openbsd-9137e5c05b0ad875bb841164b316a51799dd0d1c.tar.gz openbsd-9137e5c05b0ad875bb841164b316a51799dd0d1c.tar.bz2 openbsd-9137e5c05b0ad875bb841164b316a51799dd0d1c.zip |
Add a bunch of RPKI OIDs
RFC6482 - A Profile for Route Origin Authorizations (ROAs)
RFC6484 - Certificate Policy (CP) for the RPKI
RFC6493 - The RPKI Ghostbusters Record
RFC8182 - The RPKI Repository Delta Protocol (RRDP)
RFC8360 - RPKI Validation Reconsidered
draft-ietf-sidrops-rpki-rta - A profile for RTAs
Also in OpenSSL: https://github.com/openssl/openssl/commit/d3372c2f35495d0c61ab09daf7fba3ecbbb595aa
OK sthen@ tb@ jsing@
Diffstat (limited to 'src')
-rw-r--r-- | src/lib/libcrypto/objects/obj_mac.num | 12 | ||||
-rw-r--r-- | src/lib/libcrypto/objects/objects.txt | 15 |
2 files changed, 26 insertions, 1 deletions
diff --git a/src/lib/libcrypto/objects/obj_mac.num b/src/lib/libcrypto/objects/obj_mac.num index ba75ec246e..c02ac3e9f8 100644 --- a/src/lib/libcrypto/objects/obj_mac.num +++ b/src/lib/libcrypto/objects/obj_mac.num | |||
@@ -998,3 +998,15 @@ id_tc26_gost_3410_12_512_paramSetTest 997 | |||
998 | id_tc26_gost_3410_12_512_paramSetC 998 | 998 | id_tc26_gost_3410_12_512_paramSetC 998 |
999 | id_tc26_hmac_gost_3411_12_256 999 | 999 | id_tc26_hmac_gost_3411_12_256 999 |
1000 | id_tc26_hmac_gost_3411_12_512 1000 | 1000 | id_tc26_hmac_gost_3411_12_512 1000 |
1001 | id_ct_routeOriginAuthz 1001 | ||
1002 | id_ct_rpkiManifest 1002 | ||
1003 | id_ct_rpkiGhostbusters 1003 | ||
1004 | id_ct_resourceTaggedAttest 1004 | ||
1005 | id_cp 1005 | ||
1006 | sbgp_ipAddrBlockv2 1006 | ||
1007 | sbgp_autonomousSysNumv2 1007 | ||
1008 | ipAddr_asNumber 1008 | ||
1009 | ipAddr_asNumberv2 1009 | ||
1010 | rpkiManifest 1010 | ||
1011 | signedObject 1011 | ||
1012 | rpkiNotify 1012 | ||
diff --git a/src/lib/libcrypto/objects/objects.txt b/src/lib/libcrypto/objects/objects.txt index 8e533530f2..46d3dc75b2 100644 --- a/src/lib/libcrypto/objects/objects.txt +++ b/src/lib/libcrypto/objects/objects.txt | |||
@@ -257,7 +257,11 @@ id-smime-ct 6 : id-smime-ct-contentInfo | |||
257 | id-smime-ct 7 : id-smime-ct-DVCSRequestData | 257 | id-smime-ct 7 : id-smime-ct-DVCSRequestData |
258 | id-smime-ct 8 : id-smime-ct-DVCSResponseData | 258 | id-smime-ct 8 : id-smime-ct-DVCSResponseData |
259 | id-smime-ct 9 : id-smime-ct-compressedData | 259 | id-smime-ct 9 : id-smime-ct-compressedData |
260 | id-smime-ct 24 : id-ct-routeOriginAuthz | ||
261 | id-smime-ct 26 : id-ct-rpkiManifest | ||
260 | id-smime-ct 27 : id-ct-asciiTextWithCRLF | 262 | id-smime-ct 27 : id-ct-asciiTextWithCRLF |
263 | id-smime-ct 35 : id-ct-rpkiGhostbusters | ||
264 | id-smime-ct 36 : id-ct-resourceTaggedAttest | ||
261 | 265 | ||
262 | # S/MIME Attributes | 266 | # S/MIME Attributes |
263 | id-smime-aa 1 : id-smime-aa-receiptRequest | 267 | id-smime-aa 1 : id-smime-aa-receiptRequest |
@@ -436,6 +440,7 @@ id-pkix 9 : id-pda | |||
436 | id-pkix 10 : id-aca | 440 | id-pkix 10 : id-aca |
437 | id-pkix 11 : id-qcs | 441 | id-pkix 11 : id-qcs |
438 | id-pkix 12 : id-cct | 442 | id-pkix 12 : id-cct |
443 | id-pkix 14 : id-cp | ||
439 | id-pkix 21 : id-ppl | 444 | id-pkix 21 : id-ppl |
440 | id-pkix 48 : id-ad | 445 | id-pkix 48 : id-ad |
441 | 446 | ||
@@ -472,6 +477,8 @@ id-pe 10 : ac-proxying | |||
472 | !Cname sinfo-access | 477 | !Cname sinfo-access |
473 | id-pe 11 : subjectInfoAccess : Subject Information Access | 478 | id-pe 11 : subjectInfoAccess : Subject Information Access |
474 | id-pe 14 : proxyCertInfo : Proxy Certificate Information | 479 | id-pe 14 : proxyCertInfo : Proxy Certificate Information |
480 | id-pe 28 : sbgp-ipAddrBlockv2 | ||
481 | id-pe 29 : sbgp-autonomousSysNumv2 | ||
475 | 482 | ||
476 | # PKIX policyQualifiers for Internet policy qualifiers | 483 | # PKIX policyQualifiers for Internet policy qualifiers |
477 | id-qt 1 : id-qt-cps : Policy Qualifier CPS | 484 | id-qt 1 : id-qt-cps : Policy Qualifier CPS |
@@ -589,6 +596,10 @@ id-cct 1 : id-cct-crs | |||
589 | id-cct 2 : id-cct-PKIData | 596 | id-cct 2 : id-cct-PKIData |
590 | id-cct 3 : id-cct-PKIResponse | 597 | id-cct 3 : id-cct-PKIResponse |
591 | 598 | ||
599 | # PKIX Certificate Policies | ||
600 | id-cp 2 : ipAddr-asNumber | ||
601 | id-cp 3 : ipAddr-asNumberv2 | ||
602 | |||
592 | # Predefined Proxy Certificate policy languages | 603 | # Predefined Proxy Certificate policy languages |
593 | id-ppl 0 : id-ppl-anyLanguage : Any language | 604 | id-ppl 0 : id-ppl-anyLanguage : Any language |
594 | id-ppl 1 : id-ppl-inheritAll : Inherit all | 605 | id-ppl 1 : id-ppl-inheritAll : Inherit all |
@@ -604,7 +615,9 @@ id-ad 3 : ad_timestamping : AD Time Stamping | |||
604 | !Cname ad-dvcs | 615 | !Cname ad-dvcs |
605 | id-ad 4 : AD_DVCS : ad dvcs | 616 | id-ad 4 : AD_DVCS : ad dvcs |
606 | id-ad 5 : caRepository : CA Repository | 617 | id-ad 5 : caRepository : CA Repository |
607 | 618 | id-ad 10 : rpkiManifest : RPKI Manifest | |
619 | id-ad 11 : signedObject : Signed Object | ||
620 | id-ad 13 : rpkiNotify : RPKI Notify | ||
608 | 621 | ||
609 | !Alias id-pkix-OCSP ad-OCSP | 622 | !Alias id-pkix-OCSP ad-OCSP |
610 | !module id-pkix-OCSP | 623 | !module id-pkix-OCSP |