<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>

<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902"  docName="draft-ietf-lamps-rfc7299-update-02" number="9158" submissionType="IETF" category="info" consensus="true" updates="7299" obsoletes="" xml:lang="en" tocInclude="true" sortRefs="true" symRefs="true" version="3">

  <front>
    <title abbrev="CRMF Algorithm Requirements Update">Update to the Object Identifier Registry for the PKIX Working Group</title>
    <seriesInfo name="RFC" value="9158"/>
    <author initials="R." surname="Housley" fullname="Russ Housley">
      <organization abbrev="Vigil Security">Vigil Security, LLC</organization>
      <address>
        <postal>
          <street>516 Dranesville Road</street>
          <city>Herndon</city>
	  <region>VA</region>
          <code>20170</code>
          <country>United States of America</country>
        </postal>
        <email>housley@vigilsec.com</email>
      </address>
    </author>
    <date year="2021" month="November"/>
    <area>Security</area>


<keyword>Certificate Request Message Format</keyword>
<keyword>CRMF</keyword>
<keyword>CRMF Registration Controls</keyword>
<keyword>Alternate Certificate Formats</keyword>

    <abstract>
      <t>RFC 7299 describes the object identifiers that were assigned by the
      Public Key Infrastructure using X.509 (PKIX) Working Group in an arc
      that was allocated by IANA (1.3.6.1.5.5.7).  A small number of object
      identifiers that were assigned in RFC 4212 are omitted from RFC 7299,
      and this document updates RFC 7299 to correct that oversight.</t>
    </abstract>
  </front>
  <middle>
    <section anchor="intro" numbered="true" toc="default">
      <name>Introduction</name>
      <t>When the Public Key Infrastructure using X.509 (PKIX) Working Group
      was chartered, an object identifier arc was allocated by IANA for use by
      that working group.  After the PKIX Working Group was closed, <xref target="RFC7299" sectionFormat="bare">RFC 7299</xref>
      was published to describe the
      object identifiers that were assigned in that arc.  A small number of
      object identifiers that were assigned in <xref target="RFC4212"
      sectionFormat="bare">RFC 4212</xref> are not included in RFC 7299, and this document
      corrects that oversight.</t>
      <t>The PKIX Certificate Management Protocol (CMP) <xref target="RFC4210"
      format="default"/> allocated id-regCtrl-altCertTemplate
      (1.3.6.1.5.5.7.5.1.7), and then two object identifiers were assigned
      within that arc <xref target="RFC4212" format="default"/>, which were
      intended to be used with either PKIX CMP <xref target="RFC4210"
      format="default"/> or PKIX Certificate Management over CMS (CMC) <xref
      target="RFC5272" format="default"/> <xref target="RFC5273"
      format="default"/> <xref target="RFC5274" format="default"/> <xref
      target="RFC6402" format="default"/>.</t>
      <t>This document describes the object identifiers that were assigned in
      that arc, establishes an IANA registry for that arc, and establishes
      IANA allocation policies for any future assignments within that arc.</t>
    </section>

    <section anchor="iana-considerations" numbered="true" toc="default">
      <name>IANA Considerations</name>
      <t>IANA has created a new subregistry.</t>
      <section anchor="smi-security-for-pkix-crmf-registration-controls-for-alternate-certificate-formats-registry" numbered="true" toc="default">
        <name>"SMI Security for PKIX CRMF Registration Controls for Alternate Certificate Formats" Registry</name>
        <t>Within the "Structure of Management Information (SMI) Numbers (MIB Module Registrations)" registry, IANA has created the "SMI Security for PKIX CRMF
Registration Controls for Alternate Certificate Formats" subregistry (1.3.6.1.5.5.7.5.1.7). The initial contents of this subregistry are as follows:</t>

<table anchor="table"> 
  <name>New SMI Security for PKIX CRMF Registration Controls for Alternate Certificate Formats Subregistry</name>   
  <thead>
    <tr>
      <th>Decimal</th>   
      <th>Description</th>
      <th>References</th>
    </tr>
  </thead>
  <tbody>         
    <tr>
      <td>1</td>
      <td>id-acTemplate</td>
      <td><xref target="RFC4212"/></td>
    </tr>
    <tr>
      <td>2</td>
      <td>id-openPGPCertTemplateExt</td>
      <td><xref target="RFC4212"/></td>
    </tr>
  </tbody>
</table>

<t>Future updates to the registry table are to be made according to the
Specification Required policy defined in <xref target="RFC8126" format="default"/>.  The expert is
expected to ensure that any new values are strongly related to the work
that was done by the PKIX Working Group.  In particular, additional object
identifiers should be needed for use with either the PKIX CMP or PKIX CMC to
support alternative certificate formats.  Object identifiers for other purposes
should not be assigned in this arc.</t>
      </section>
    </section>
    <section anchor="security-considerations" numbered="true" toc="default">
      <name>Security Considerations</name>
      <t>This document populates an IANA registry, and it raises no new
security considerations.  The protocols that specify these values
include the security considerations associated with their usage.</t>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>

<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.8126.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.7299.xml"/>
      </references>
      <references>
        <name>Informative References</name>

<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.4210.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.4212.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5272.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5273.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.5274.xml"/>
<xi:include href="https://xml2rfc.ietf.org/public/rfc/bibxml/reference.RFC.6402.xml"/>

      </references>
    </references>


  </back>
</rfc>
