Index | Thread | Search

From:
Theo Buehler <tb@theobuehler.org>
Subject:
Re: rpki-client: SPKI in TALs
To:
Job Snijders <job@bsd.nl>
Cc:
tech@openbsd.org
Date:
Tue, 20 Jan 2026 13:55:40 +0100

Download raw body.

Thread
On Tue, Jan 20, 2026 at 12:50:05PM +0000, Job Snijders wrote:
> On Tue, Jan 20, 2026 at 09:02:12AM +0100, Theo Buehler wrote:
> > This is an almost entirely mechanical diff. The pkey hanging off
> > struct tal always confuses me since pkey always makes me think of
> > EVP_PKEY. The combo with pk and opk in a couple of functions makes
> > this worse.
> > 
> > So: rename tal->pkey{,sz} to tal->spki{,sz} and pk/opk to pkey/opkey
> > and adjust a couple of nearby comments. Update from RFC 7730 to RFC
> > 8630 while there.
> 
> To me it is not immediately clear from the new (or old) variable names
> 'pkey' and 'opkey' what those variables might contain, perhaps the names
> 'tal_pkey' and 'cert_pkey' would've been more descriptive? Anyhow...

I agree. I have plenty of follow-up cleanups lined up and I'm trying hard
to make things as easy to follow as possible, so sometimes intermediate
steps aren't perfect yet.