Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certificate OIDs #32

Open
bluegate010 opened this issue Mar 22, 2023 · 1 comment
Open

Certificate OIDs #32

bluegate010 opened this issue Mar 22, 2023 · 1 comment
Labels
enhancement New feature or request future For a future release

Comments

@bluegate010
Copy link
Contributor

There had been a question of what kind of SPDM OIDs we might need to add to the alias certs generated by Caliptra. We discussed how SPDM is introducing the "generic certificate model" where no OIDs are needed, so no problem here. However, in the latest draft, SPDM Slot 0 is required to use either the Device cert model or Alias cert model, and not the Generic cert model.

That being said, there is no "shall" requirement directing the use of these OIDs - they are only "strongly recommended for new deployments".

SPDM 1.3 is still in draft form. We could ask that the stricture against generic certs in slot 0 be lifted. Or, we could work to add the necessary OIDs in the certs generated by Caliptra. In either case I don't think any changes are necessary to ROM.

@steven-bellock
Copy link
Collaborator

SPDM 1.3 is still in draft form.

It won't be for long, so if you want it to be resolved in 1.3 you should file an issue today (preferably yesterday).

@varuns-nvidia varuns-nvidia added enhancement New feature or request future For a future release labels Oct 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request future For a future release
Projects
None yet
Development

No branches or pull requests

3 participants