Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

"Panos Kampanakis (pkampana)" <pkampana@cisco.com> Mon, 17 February 2020 16:46 UTC

Return-Path: <pkampana@cisco.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF068120879 for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 08:46:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.502
X-Spam-Level:
X-Spam-Status: No, score=-14.502 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=lBPLPoko; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=oXV9Agcz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7c1HAcuKxuCf for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 08:46:47 -0800 (PST)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD27E120841 for <ace@ietf.org>; Mon, 17 Feb 2020 08:46:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=9888; q=dns/txt; s=iport; t=1581958006; x=1583167606; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=/I6zprueXZasAOOVmkXHvblYslkVE9wpQvkuln0c/mw=; b=lBPLPokoGwxRTasEeEtQ3MBrJPkBIFXUd2c0LRVMT9VrT46gMonQTr0z ckIJgPg4Yt9X5ve/cqTPGhgvrdoxShAIgLWW6DjOBKVm+Obh3H/YBjDXV dAgSzpmAGlD6V5CbU6e6vGFL2R9nq4Q5OQ2JHfLwm4Xofz5BE9kvsnrV4 M=;
X-Files: smime.p7s : 4024
IronPort-PHdr: 9a23:/0T3qhVKhjHqpOUF0wbKLitgZonV8LGuZFwc94YnhrRSc6+q45XlOgnF6O5wiEPSA9yJ8OpK3uzRta2oGXcN55qMqjgjSNRNTFdE7KdehAk8GIiAAEz/IuTtankiH81HTFZj9lmwMFNeH4D1YFiB6nA=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0C/EACwwkpe/5pdJa1mHgEMNxeDHFAFbCstIAQLKoQUg0YDinpOghGYEYFCgRADVAIHAQEBCQMBARgLCgIEAQGEQAJMBYEzJDgTAgMNAQEFAQEBAgEFBG2FNwyFZgEBAQEDAQEQER0BASwMCwQCAQgRBAEBKwICAiULHQgCBAESCAYUgwWBfU0DHw8BAgyhQgKBOYhidYEygn8BAQWBLwEDAg5BgysYggUHCYE4gVODTQyGeBqBQT+BEUeCTD6CZAEBAgEBGIEUARIBCRqDDjKCLI1WG4JshnGYNAqCOoNtgjs7ao8igkl7hxuQO45piHCSQQIEAgQFAg4BAQWBaSJnWw4IcBUaIYJsCUcYDZIQhHAkhT90gSmLRYIyAQE
X-IronPort-AV: E=Sophos;i="5.70,453,1574121600"; d="p7s'?scan'208";a="430965978"
Received: from rcdn-core-3.cisco.com ([173.37.93.154]) by alln-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 17 Feb 2020 16:46:46 +0000
Received: from XCH-ALN-005.cisco.com (xch-aln-005.cisco.com [173.36.7.15]) by rcdn-core-3.cisco.com (8.15.2/8.15.2) with ESMTPS id 01HGkjfU008070 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 17 Feb 2020 16:46:45 GMT
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by XCH-ALN-005.cisco.com (173.36.7.15) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 17 Feb 2020 10:46:45 -0600
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 17 Feb 2020 11:46:44 -0500
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Mon, 17 Feb 2020 11:46:44 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EMZIgxH+KsC0Dk2FzPL6kyQISSh85WWdI7IF0Gf0mbhPgxA6iQKCYpgAZ3lIC2qLeus7RdAHhSTv+uQUCv9yzAvOFXA1bVlNUoDPEKjUG8RmOW+WE0gXVkyRjUfuH08ftmSIuOGaAVv08BtK4N3yPLv+QOPgOvr6dbTkrm1FmhWmA/8FlJR8/iO3XEJeHZjQwrD4CBU6EqXEHEVHTlWTvpIB7pPXWOLnhrq7LBv0qGIWT30CAqTlcfbXzlTZ2WXOXa4USFRGy1tNGApx9iqSl5PlsrBWKLFN1PeQu0RrDiC4KJyNP7in3Pi7R50GQ1yh3SzjRAvay0+CCIjiPn70qQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PTccrAnY+gP8V/CfXhbHgtDZ/zoRDoac2OzFr+qq0rQ=; b=Wy6YN83tfIuVz1vZyqBFbWdjmIf2F4ewgvs0bqD6owHVOrHwCcuX28W0xSgXCQb/+4IvwBW4d3p5vP2NwRKFvJbDb/Q24KZPQwmS1sJDftk/fU+A4ALeHl7T39ompcd+WRgTTATW3pWAjin7uv/Nsje6g/RZQrpom2wRCGG9eGvCasORxh1itfrdqat0Y8EwlWhadA89dphdPVbB2y7tuNIyUBvFG//sMI0rCXTPJHdjyDX+qXwgonpCmVskPs7sjIjYlGyk62xqlASKizl6BdRbPVg3PPJG/yM1HBpzs93PehY47t2X/zFhJYD3S4dnvr0Lo29F7ci/Nra5/budlQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PTccrAnY+gP8V/CfXhbHgtDZ/zoRDoac2OzFr+qq0rQ=; b=oXV9Agczzcx+M4IG8PCPBrFzyswhxKj3a9QPIigupQiL9PAXpote+oZ6iR8Z2/z8VZbOpELQpTZvksPumMA1qBqFVYRZtA73d97dEzvDL8OwZops0QrYKiBQxoc+4Wwf4N813Y0Wk8jDgYwFMoFm+jD64lhdPw4EqjL6SGNJnj8=
Received: from BN7PR11MB2547.namprd11.prod.outlook.com (52.135.255.146) by BN7PR11MB2657.namprd11.prod.outlook.com (52.135.244.147) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.25; Mon, 17 Feb 2020 16:46:43 +0000
Received: from BN7PR11MB2547.namprd11.prod.outlook.com ([fe80::2d8b:4fd5:9d28:a1c7]) by BN7PR11MB2547.namprd11.prod.outlook.com ([fe80::2d8b:4fd5:9d28:a1c7%6]) with mapi id 15.20.2729.032; Mon, 17 Feb 2020 16:46:43 +0000
From: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>
To: Esko Dijk <esko.dijk@iotconsultancy.nl>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
Thread-Index: AQHVxLtE07rr0EyB+EKjyAxbFxjZSqfd7nmAgEFc3wCAAIsqoA==
Date: Mon, 17 Feb 2020 16:46:42 +0000
Message-ID: <BN7PR11MB254744B1A4F01D82B46EE9BCC9160@BN7PR11MB2547.namprd11.prod.outlook.com>
References: <157833360921.8003.6238594444996424752@ietfa.amsl.com> <BN7PR11MB25472BD695322671615371F5C93C0@BN7PR11MB2547.namprd11.prod.outlook.com> <AM5P190MB0275CEAAE1AE5E11BE9C3410FD160@AM5P190MB0275.EURP190.PROD.OUTLOOK.COM>
In-Reply-To: <AM5P190MB0275CEAAE1AE5E11BE9C3410FD160@AM5P190MB0275.EURP190.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=pkampana@cisco.com;
x-originating-ip: [2001:420:c0c4:1008::31f]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 922ec58f-e6c6-4580-2a65-08d7b3c8f7f6
x-ms-traffictypediagnostic: BN7PR11MB2657:
x-microsoft-antispam-prvs: <BN7PR11MB26576819F76C9644C7DB218AC9160@BN7PR11MB2657.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0316567485
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(366004)(396003)(39860400002)(376002)(136003)(346002)(189003)(199004)(53546011)(81166006)(33656002)(8676002)(81156014)(86362001)(5660300002)(186003)(7696005)(110136005)(8936002)(2906002)(66476007)(71200400001)(66556008)(966005)(478600001)(66574012)(9686003)(316002)(52536014)(66616009)(66446008)(64756008)(66946007)(55016002)(76116006)(6506007); DIR:OUT; SFP:1101; SCL:1; SRVR:BN7PR11MB2657; H:BN7PR11MB2547.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: frP+5wzSGW8L0Pml9A52dHJZbLdRU5vYPvU98o4qhwirLq5/sg+aWRV2jV52THf5Pwm8XWQmAV1PSVOBU9OPakSR0Dy4Ue1w9PLwEtBmuvo2R0/6DjZMZhWulWzz7aM7ue9SiWM+deyrPWBy5NsecXg5JBK66D9RUcKQmR7WRiNsBWTYNEJNGCKhPNZVjTiJ7edqocjTT53+jJ+lqlos29XYoWReJ5QmTXopVRm4LSsCF6bctGHKCavCvE30oXIkm6QChHCQJZtepBe6Tj2Rov3Q+EpFnzDNbqf3KVqgU0XLgMQfM4bHsyVPZHMWUhGDvijC5g3NFk78dFB9cbw2gx9824AEUM2vCzAW0GY5grzMjPkcb74VGiqNmPCj4FzdqVh0YF/15TntE4oAzoJf3RUojDedOPMe3uJ8Ey7MkRVkhYtnsJJ58NEs/zmxHgQCkN9Hta1MxKx6FxtbFJJ0sLGfyLNhQBvcwTM4BeGRSkCZROB5cJPQapdSv2nGRl8f5uu4C6YAL7EHkTJfca9CSw==
x-ms-exchange-antispam-messagedata: d4vk2SLdvqi0kDSIgzYN2EPzOfFrk6wEho09dzUZvXQ/QcNrdp75hUTaNSeE0qpHl9h1WUZA+tJU9s9SMDuD4KiGOALOK67BoPTiyQKRed+3kSGpHabv13DIuQrWxoR1nKbfvg88qkcSHTWdmJOE37GkODvUamgNSm6f4Wh0rxk=
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_0038_01D5E587.EB069340"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 922ec58f-e6c6-4580-2a65-08d7b3c8f7f6
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Feb 2020 16:46:42.8961 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 3c1HGvfUiW6oh9rFV4I3tgaeyWbTlt0CsFrCXjUAqgMbGDH4+toYtGCzM6n4YWCZLKs7eMHhLQrrc6T6KhhBCQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN7PR11MB2657
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.15, xch-aln-005.cisco.com
X-Outbound-Node: rcdn-core-3.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/7biELjRUFVzMfS0I7wDuuBVXU8s>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Feb 2020 16:46:51 -0000

Thank you for this Esko. Hmm, point taken.

I consider this a minor change and we will incorporate it in the AUTH48 phase. 
I am planning to rephrase to
   "[...] If the client had requested Content-
   Format TBD287 (application/pkix-cert), the
   server would respond with a single DER binary certificate.
   That certificate would be in a multipart-core container specifically
   in the case of a response to /est/skc query."

Let us know if you have any objections.

Rgs,
Panos

-----Original Message-----
From: Esko Dijk <esko.dijk@iotconsultancy.nl>
Sent: Monday, February 17, 2020 3:15 AM
To: Panos Kampanakis (pkampana) <pkampana@cisco.com>; ace@ietf.org
Subject: RE: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Hello Panos,

I noticed one sentence in Appendix A that seems inconsistent with the rest of 
the I-D, or at least gives an incomplete view :

   If the client had requested Content-
   Format TBD287 (application/pkix-cert) by querying /est/skc, the
   server would respond with a single DER binary certificate in the
   multipart-core container.

The client here could also have POSTed to resource /est/sen with Accept:TBD287 
option, indicating it is requesting TBD287 for simple enrollment, and the 
server would respond with a single DER binary certificate 
(application/pkix-cert). So the current text might suggest that POSTing to 
/est/skc is the only way to request TBD287 format, which is not the case since 
/est/sen also may support it too.

Best regards
Esko


IoTconsultancy.nl  |  Email/Skype: esko.dijk@iotconsultancy.nl

-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of Panos Kampanakis (pkampana)
Sent: Monday, January 6, 2020 19:12
To: ace@ietf.org; i-d-announce@ietf.org
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Hello,

This iteration addresses all IESG reviews. More details on the feedback and 
how we addressed it are in the git issues here

Rgs,
Panos


-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org
Sent: Monday, January 06, 2020 1:00 PM
To: i-d-announce@ietf.org
Cc: ace@ietf.org
Subject: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt


A New Internet-Draft is available from the on-line Internet-Drafts 
directories.
This draft is a work item of the Authentication and Authorization for 
Constrained Environments WG of the IETF.

        Title           : EST over secure CoAP (EST-coaps)
        Authors         : Peter van der Stok
                          Panos Kampanakis
                          Michael C. Richardson
                          Shahid Raza
	Filename        : draft-ietf-ace-coap-est-18.txt
	Pages           : 51
	Date            : 2020-01-06

Abstract:
   Enrollment over Secure Transport (EST) is used as a certificate
   provisioning protocol over HTTPS.  Low-resource devices often use the
   lightweight Constrained Application Protocol (CoAP) for message
   exchanges.  This document defines how to transport EST payloads over
   secure CoAP (EST-coaps), which allows constrained devices to use
   existing EST functionality for provisioning certificates.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-ace-coap-est/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-ace-coap-est-18
https://datatracker.ietf.org/doc/html/draft-ietf-ace-coap-est-18

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-coap-est-18


Please note that it may take a couple of minutes from the time of submission 
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
Ace mailing list
Ace@ietf.org
https://www.ietf.org/mailman/listinfo/ace