Summary

  • RFC 3001 put ASN.1 object identifiers into URI form as urn:oid, inheriting uniqueness from the older delegated OID tree rather than creating it in the URN layer.
  • RFC 3061 replaced the first specification three months later, clarified the registration authority and canonical syntax, but still defined neither resolution nor validation.

urn:oid:1.2.3 looks self-contained. It is short, regular and globally usable. Yet the most important facts about it are absent from the characters: who assigned the arc, whether the assignment was valid, what the number denotes, and where a machine could obtain an authoritative answer.

That absence was not an accidental gap hidden by later complexity. It was visible in the original namespace documents. In November 2000, Michael Mealling published RFC 3001, an Informational specification for expressing ASN.1 object identifiers as Uniform Resource Names. OIDs already formed a hierarchical assignment system. The first arc identified an authority—0 for ITU-T, 1 for ISO, 2 for their joint assignment—and a recipient could allocate further numbers below an assigned node. The URN work did not create those rights. It gave the resulting dotted number a portable URI wrapper.

The surrounding URN framework mattered. RFC 2141 described URNs as persistent, location-independent resource identifiers. A namespace identifier determined how to interpret the namespace-specific string. That architecture could absorb a legacy identifier system without converting the identifier into a network location. oid named the namespace; the decimal arcs carried the OID. Neither part supplied an address.

RFC 3001 said uniqueness and persistence followed from the rules of OID assignment. Its lexical-equivalence rule was exact string equality. Its scope was global. But under resolution it stated that no mechanism was defined, and under validation it did the same. A conforming string could therefore be carried and compared even when the receiving application had no standard service to resolve it and no standard procedure to verify that the claimed number had been assigned correctly.

The document also left its institutional seam in public view. In the namespace registration template, the declared-registrant section included an editorial plea: “I need help here. I’m not comfortable being the ‘registrant’.” It then named the ISO/IEC JTC1 SC6 secretariat. The sentence should not be inflated into a story of crisis or conflict; the RFC does not establish either. What it does establish is more interesting: a clean identifier syntax could be publishable while the prose naming the responsible institutional authority was still visibly unsettled.

In February 2001, RFC 3061 obsoleted RFC 3001. The replacement removed that question and explained why ISO/IEC JTC1 SC6 was the appropriate registration authority: it was the body able to interpret and change the ASN.1 standard. It also tightened the namespace-specific syntax. Components were decimal digits separated by dots; leading zeros were forbidden; the human-readable descriptions sometimes attached to OID nodes were excluded. A name would carry the canonical numeric path, not a shifting mixture of numbers and labels.

Those changes reduced representational ambiguity. They did not turn the representation into evidence of entitlement. Exact equality answers whether two canonical character strings match. It does not answer whether an allocation was valid, whether a claimant still controlled the node, or whether the named object existed. The top arcs and delegated branches locate an identifier in an authority structure, but the visible prefix is not a signed receipt from that authority.

Nor did RFC 3061 add a universal lookup service. Its scope remained global; its resolution and validation sections still defined no mechanism. This distinction is easy to lose because modern interfaces often combine naming, search, retrieval and authentication behind one box. The RFCs kept them separate. A name could be globally scoped because its assignment regime prevented collision, yet resolution could remain application-specific, private, future work or simply unavailable.

Later URN work makes the evidence boundary easier to state. RFC 8141, published in 2017, distinguishes a string that is syntactically a URN from a URN validly assigned under its namespace rules. That later terminology should not be projected backwards as if it appeared in 2000. It nevertheless clarifies the same danger: grammar can establish form, not institutional fact.

The history of urn:oid is therefore not a failed attempt to build a resolver. It is a case of deliberate layering. OID authorities assigned numbers. The namespace specification made those numbers portable. Applications could compare their canonical spellings. Any resolver, directory, certificate, registry record or other validation evidence had to declare its own authority and operating behavior.

That division preserved room for local systems and future services. It also imposed a discipline that remains useful: never let a formal-looking identifier silently inherit more evidentiary power than its specification gives it. A global name can coordinate references across organizations. It cannot, on typography alone, prove who controls the name or what reality lies behind it.

Sources