[Ace] Re: Last Call comment on draft-ietf-ace-oscore-gm-admin (defaults + error handling)
Marco Tiloca <marco.tiloca@ri.se> Mon, 23 February 2026 14:15 UTC
Return-Path: <marco.tiloca@ri.se>
X-Original-To: ace@mail2.ietf.org
Delivered-To: ace@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4439CBC34454; Mon, 23 Feb 2026 06:15:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=ri.se
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qQzWlQiK4XOy; Mon, 23 Feb 2026 06:15:50 -0800 (PST)
Received: from MM0P280CU010.outbound.protection.outlook.com (mail-swedensouthazon11012047.outbound.protection.outlook.com [52.101.77.47]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5B5B7BC34440; Mon, 23 Feb 2026 06:15:50 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ypTr23DqhyUjLarJQp8lzXtqhotv8Qfz4mnAcVqKgmrvB5zGnaG/ubblo88HJ/GbNEBEW5fk4GUkgPHzb+M5DDVG5iuLk6mhiA1WezhFzNfzd82dWjl2scnQBYrHy6XM2uu72S+T3Z9lMYVhyvI/2Von7l/s5be9v+vmAfmLVWqADfI/m2AdXgD6o0H/7TNnnCbjNPKwWmqo4C/6ixq914PJEQPxZ/8w9mZ+qyONvD7P/f0DMhWZduwSGbf99+3rUSXxtoBrMz6s0BdvHo6gQu3EKZZr5/aqpJC4a0uox+OMIFX5IQ8xPNTHZQwORw8BbqevHj5BOoYGBPcjj0zHCQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=2pVBPUp2tuNO5rInYdY2gY64n3I1hkxwqca2NZ4JuDE=; b=Ady6RGtKXxOxNbGmy/SLUK7eoeW9LHevkM6EE5JEiL/xTnBq5kWKEbY9o8ZMY+VawRqaDLOdeQ+HoMgWB9CikQ3dPK/Cx8VTLPgJw0bAguT9EGnYrcg2Li9trpj3vCswve8hmq8Zm585JCahDONBqrxYyF3yIfpd2WuvuSzk0Vs3mbTGB6A53CDUO9DhiSnedvF3toCw1G3HP9CC0YMrQdn1Q5MG1UWm1wQU6TCo7wsNfSuV8SjFwRdBeRFAs3PNpaacoDxUB7z/oLNCLKXBmfuatoS7dw1g4mvBRuvl9k+83AZ+oewOUyddCSKdfsbRJLJ/hkHtHIUuiQv8ToYT3Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2pVBPUp2tuNO5rInYdY2gY64n3I1hkxwqca2NZ4JuDE=; b=vP+U8WvbzUdPMK/VYkJ45hXLvRao54MdfIfhaDWefkUyhS+Kfh0nopx+b0HdEZyWiHt+vq8Rus4gQTMRB+IuIdgsFMpDVBI/zN4yfp9Cf7a912k0zfHXFXoj2B95JV/0ISqbF4WNo6GwQS3wVwKn2IEj/LBd2ThW4Qpu6ke7AEPAGFKos/goJdlE4Qj+wWQ8+NoYBpJ0xNuNmVPIbRME0qF+ff0QFY5oSWnXADzzYSviiuURC5UhBr4vzH+CnNat31YVR4W+IEs2zFwv09liixxNfy49XMiiJLalkLWv1JI3pYu0OCyjHBvRZZxl76MfqsX3HMj3MyMtVFgnscJmKQ==
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17) by GV3P280MB1783.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:245::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9632.21; Mon, 23 Feb 2026 14:15:41 +0000
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::71be:25c4:bd56:50f0]) by GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::71be:25c4:bd56:50f0%3]) with mapi id 15.20.9632.017; Mon, 23 Feb 2026 14:15:41 +0000
From: Marco Tiloca <marco.tiloca@ri.se>
To: Meir Goldman <fazon=40fazoncore.org@dmarc.ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
Thread-Topic: Last Call comment on draft-ietf-ace-oscore-gm-admin (defaults + error handling)
Thread-Index: AQHcnI+iYMGm8Qo2nUyjADIdA05SsbWQY298
Date: Mon, 23 Feb 2026 14:15:41 +0000
Message-ID: <GVYP280MB04642954AA6D72411B0F51169977A@GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM>
References: <TLZP290MB03039E045BF7AC08FAD18EE5B561A@TLZP290MB0303.ISRP290.PROD.OUTLOOK.COM>
In-Reply-To: <TLZP290MB03039E045BF7AC08FAD18EE5B561A@TLZP290MB0303.ISRP290.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_Enabled=True;MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_SiteId=5a9809cf-0bcb-413a-838a-09ecc40cc9e8;MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_SetDate=2026-02-23T14:15:41.034Z;MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_Name=K2 Intern;MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_ContentBits=1;MSIP_Label_680afd86-dcf7-4483-b9eb-5af1dcd104e1_Method=Standard;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ri.se;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVYP280MB0464:EE_|GV3P280MB1783:EE_
x-ms-office365-filtering-correlation-id: 3c433b72-054e-4c72-8d5e-08de72e606c6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|376014|19092799006|1800799024|7053199007|38070700021|8096899003;
x-microsoft-antispam-message-info: 7Fc5JjxNensnDcQNAYb340seNg0YeXss8AGGCCiIGV7UmbelJsz6iI7BbT+cy5ab8zLnvgOmpvs5v0FyO++beZqTJxJ42ILFwu2pktDUnamVCJSBgML6VwcyQUe+n7qYx5aXHzVHe3iNX84fH8Y1sWMmlThAJ/dMNxWQuNsXRyu/gf4NOB69TpOObcE+1ZmnCypwFWOKHv2ozgEap3e4eV8DxwYatnyuY4V000+dpAS4s1GY3ZrQIiFI1xsOFUQFBDyp2h+0L3TKkQo9sLcXKdItZhq3VhhL2ecgJIXzgDQza82KF/tigqx83N5MxeQgPcp8T+uj/NY/ejZHY8t73sRZMGDbDjl0Z6ez3HeJwovLiC91rRSTb0yXzly+IcUA92a+yzV0T1rFG1b827rvU8RH0J6khFaZQO1QkVHBsYLOh8lqYBEDMhPbUWmY2XP5Ei5WcAvZ9EomO7QKGTda7FJco5W3Cp9FrCX3z8B2Hd6qfGw/hJiz58bJ0GJsd1WS1HTuc+HtTC5PO6RX+hHpm0aKty7sY+yXu80gUV9nXJ0dnit1qaF2YAzY8572ZRyr/bOq3YLoxGjb+HtRocmI+BU+h3Vpv5ikc7DgJX3qyMd38yWr1WA4mdcrHES7HH0V+IPJA+M/q4jM0/P91rCP3JiHNGRyTs5oYN9nTXxg11PhGMmQEA2hd/d6aQA8d2uCbXqRplWJ8i8u1QzbtfeOqn1VeXUWO6YGIKA029B8IiIFfU7y1xefmGV4mwTI7d6h3aAJfNVwY0PenDWMoEuiEOjqsKNcqqdkvyl/X6O+gRpUM9onfvb5uce+pxzxu7122S1DjFUXF6wA4KcCMzH+Qytu0GqT9V3vPEFTGftAy5sk/RC9UPMgSDLjtAzTMR84otWXitP5ybhD/uxiGxAm17CoCZxFa7GO5VKpvSGpYvZfiWBuuPOmz5KvSBX0Jb2miwkvquLtWRfK3H53XEvEEjQgs61kpJQpz2hRajATR9FY/KPU/koYM6K7zKIV/lMxeAgyiaO2dTJEb+ir9AtQuLnd1w9bgRndmtLmpFqXNGyboFd6CZuw5a7vSqBjs56t8hytLV9tuXrK6comidLih8S6arB1PrIj9CMlBZtRR6pFLpNkUPQIr4FYHqwdVDG/qPVgveDfrBwxt1JWif8yGLkFURjxa7eY4uEcIsjDPtyxr4fEulhad7yGm98qelX6OYdry0VBw+HXFuPEBUy6FxBSrYWiqS3+clKD48FMoaPU8h/6x+cmzfhfITfCllZu4tShO/t4dmCXCQNOCj/1uW+iDu0ZNzIE+dxvvMbq1bSZQLlhQuOTQn0U6wVX0cIgJWkuJ3CxfO7g4NqN3q4fNay1+H0q/HJjrkWU4VypCioVZxg9xSbjjQMXfggkPMU8yA/BJGWupBuOmGcDTl10u1JcsjnlmPNw2HSY87D2ugfYFFYnDuoSSnUUPpuX49vhy9v+crHHfYV/EXbJNTK/znhclQSXhgev41umHUojMW+f7owmx5acX6HEg6C2FdJs0vaIfl6UBdhRm7Y0xlZbLQD3NIAeIcAtZemhv21Kbxc=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(19092799006)(1800799024)(7053199007)(38070700021)(8096899003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: WuEFuuo2/p/Eg36HtGWTxCcjK1fF9RMM0s9ZsL3NgMeEclRLhCuJxPHnAxZrYSLcdqjVMPkV+f2J+3W7uiFNHu8JHw6rFWmF4dLETQTSiB7mTMhArV6oLbbhro8nEi6958F9LYO3WZP8JJF3cVopcA3a7ZyAa1HIaK/otVaT812zkkcX/hfNZB6fOSwxgVmJJEl/od5L6PZGJJTEN/5bUvQqZkU8O624RfK/rjKWSFDO+MLYcfkXc8mBVjsSlJxBZBhRZ0YTVoadFFfBpMtVesQfHreCtF0AFyoGZgT9o7YhL4NXS4eFLJ3z78BY/jnez7IFNDe7B3EOsDsV8DsV2OVKp4KtDNiJk55GQH/lQdi6kB+di86L+/aO9Vyd2J1LJP4Vhv8ZH+Yf7sl7ywskjG9ZYoRjvZ53YdwPTmxVRe/2uICxsc3AYe8ViWpRpd9IRRyQYHyxL47jsogaVZF1dDXg+qwDa7SRJ+muEGdtW7x3CxeqF+eat36hbcBYwzGv2rvqELMx+wqruS/aJaQ+WC9NyOmW8vRs0VJXYZKYYavQW+Ms7KfwWUnuAVGT1yhXVHh6IhNAqnqkzNwIwaQr/GLqxmUlPjnoy1CXtf5npYpvc2eLdbvC5EXRh+J5hH+kJzSeoASmYE5GO8Un6rlj9qoYirBqNbNBPkOLZzemLu2WxBUIloATOCLrev9ewnWrthBEAGy6klQaXs4volSD5/OWmINMR/Kn8QUqV+XkVuM0ufxv2+nnWd++zM2TzH0vcyUGiHzC6v42cNYueaLDu4489Ttzj6ueqe6t8Rq9WTUz5jQKw+WSgDB6RzjReRitEaQF8dthjv9t9j4m6qy05NjJ3lMhbzEQIj+k54KprtefeHIexLFNgnz38pWMbICcUS2JnYXNVxxrnv2Rlcz4TRHDve0iNkL91ahddHmP12MmImJnEmd9a5euh5nDjGmu7ivQQDmNYKyaV0hHLhB/+uYdXAqRnp7L96LcmZh2K7/gagzjkf+VmqFZ6UqsAE2NNinqTXLBWbf3u7p8Kz2VXI78ajaj1bQKcnJvb36kf6gJ8mBmTMA2HRNstEkmf9WSUcIhod3uNiz5I78zf2+CTNLMffYHD6nhOjR0qS6ZIq7wQpuYqpvcsxf6NGvGpQsv5iUEAVQZPwFpS4XqclglZRjy1r3QD04T8Xh6+fFpt59rXkj0yk29D1kSwCwmF5hzrjjbqvfcQt2LYwp/Q8ehHKWaDSVOYtEW2EhkfnWa/ntaAnhlpVBr2ggLfBqFWVg+CKlYGJ8fzQSolTuOraUtjEwgJFhWOPypkOJZuXZQCRCFeMtAjP+IUFim7UU1HqOOF86ljD7+n/pdHca2hFDepMMIwHUVYWi5t3WnQIJPag0rj41SKWSwqylTGLnGsCF9J2Tc2J6rZdpOqkBXKeCx9seVeYjeCCFU1GgZiELXROZmIY39fyjpdV2jcqyqsllf2ea7VpCzSHLqc0264lzQiPZUypGaa/T6dtOkR8MBs+p4ZwYs0HHrrzS086trI/PjPIT+xj526QP9ufwWg9mNzWJr2Fje4e+Xd5asAuex++mEMmg9w377MJr8aKxEByMcPKMa3f822tjQxJ3sphUBK1UsDYo0JHRYc9qyBWTVlO7dWWUUZ+ewzPkbDf8y/0G0UuZEyLI5i6F+QH+PNjyEMQcQoO0A6Dnaaq3KH5uBIr9AvwurR9dmLb/U1kUfo3tR
Content-Type: multipart/alternative; boundary="_000_GVYP280MB04642954AA6D72411B0F51169977AGVYP280MB0464SWEP_"
MIME-Version: 1.0
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 3c433b72-054e-4c72-8d5e-08de72e606c6
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Feb 2026 14:15:41.4683 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: VjjE03wnBtCXOHFsoMVdyei1wQzoCUOQrctG6x5JpAR+pvY/4IMlaO0vMTbC1gMvfUVUhi4csxUQg3Tu4RbJAg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV3P280MB1783
Message-ID-Hash: ZBMVCG53XJ3ZHRBGJXVPEPUYPQ2XIFSY
X-Message-ID-Hash: ZBMVCG53XJ3ZHRBGJXVPEPUYPQ2XIFSY
X-MailFrom: marco.tiloca@ri.se
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ace.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Ace Wg <ace@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ace] Re: Last Call comment on draft-ietf-ace-oscore-gm-admin (defaults + error handling)
List-Id: "Authentication and Authorization for Constrained Environments (ace)" <ace.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/J79F-zw4U9XR2yH92M0SqcOFEvs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Owner: <mailto:ace-owner@ietf.org>
List-Post: <mailto:ace@ietf.org>
List-Subscribe: <mailto:ace-join@ietf.org>
List-Unsubscribe: <mailto:ace-leave@ietf.org>
Hello Meir, Thanks for you comments! Please see our replies inline below. Best, /Marco ________________________________ From: Meir Goldman <fazon=40fazoncore.org@dmarc.ietf.org> Sent: Friday, February 13, 2026 3:24 AM To: last-call@ietf.org <last-call@ietf.org> Subject: [Last-Call] Last Call comment on draft-ietf-ace-oscore-gm-admin (defaults + error handling) You don't often get email from fazon=40fazoncore.org@dmarc.ietf.org. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Thanks for the -14 update and the added “Operational Considerations” section. Two suggestions to further reduce interop and security risk: 1) Please ensure consistent normative language around defaults across all sections (avoid any remaining MUST/SHOULD ambiguity when defaults are referenced). ==>MT We have re-checked the whole document, and we think that all is already consistent. In particular, we do not find any MUST/SHOULD ambiguity. In Section 5.2: * The defined values are overall RECOMMENDED to be used as default values. Exceptions are allowed and one reason for that is explicitly mentioned. * Each of the specific default values is introduced using SHOULD. This also applies for those that rely on an external definition in Sections 14.1-14.3 of draft-ietf-ace-key-groupcomm-oscore. That document also defines default values in the same spirit, i.e., as RECOMMENDED to be used as default values, and by introducing those using SHOULD. In Section 5.3: * It is stated that the Group Manager refers to the default values from Section 5.2, where further details are specified. As per Section 5.2, those are RECOMMENDED to use as default values, and deviations are allowed. See: > For each parameter not specified in the POST request, the Group Manager refers to default values as specified in Section 5.2. * It is stated that, if the Group Manager uses a default value different from the recommended one for a given parameter, then the Group Manager MUST indicate the chosen, non-default value in its response to the Administrator client. See: > If the POST request did not specify certain parameters and the Group Manager used default values different from the ones recommended in Section 5.2.1 and Section 5.2.2, then the response payload MUST also include those parameters, specifying the values chosen by the Group Manager for the current group configuration. (The same applies to other operation defined in Section 6.4) <== 2) For error handling, confirm that all CoAP response codes and problem-details payload requirements are specified in a clean, linear way so implementations behave consistently and do not leak unnecessary information. ==>MT We have re-checked the whole document, and we think that CoAP response codes and problem-details payload requirements are indeed specified in a clean, linear way and as intended. Please note that error responses from the Group Manager are not necessarily all of the same kind. In fact, they belong to different areas of pertinence. For example, some requests that result in an error response are bad/unauthorized request from an access control point-of-view, hence they are handled from the perspective of the ACE framework as such, consistent with RFC 9200. In such cases, we are intentionally not using a problem-detail payload. If a payload ought to be present at all, that is actually expected to have Content-Format "application/ace+cbor". Examples of such error responses are: * In Section 4, the error responses with error code 4.00, 4.01, 4.03, 4.00. * In Section 6, the 4.03 error response. Another case is purely transport-related, and simply inherited from the intended use of CoAP and its extensions. While a problem-detail payload is in principle possible to be used here (unless otherwise expected), it is not required by this document. Examples of such error responses are: * In Section 4.1, the 4.04 error response. * In Section 6, the 4.05 error response. * In Section 6.6 and 6.7, the 4.04 error responses. * In Section 6.7, the 4.09 error response. Another case is broadly related to a request being malformed. While a problem-detail payload is in principle possible to be used here (unless otherwise expected), it is not required by this document. Examples of such error responses are: * In Sections 6.3 and 6.7, the 4.00 error responses. Finally, some requests result in an error response specifically pertaining to an error at the application level, when those requests are processed by one of the resource handlers defined in this document. For some of those cases, where applicable, we have indeed defined the payload of the error response to have Content-Format "application/concise-problem-details+cbor". That's intended to provide the Administrator client with actionable feedback, again related to actual application-level processing at the resource handlers defined in this document. Examples of such error responses are: * In Section 6.3, the 5.03 error response, with problem-detail error-id 12 or 11. * In Sections 6.6 and 6.7, the 5.03 error response, with problem-detail error-id 12. * In Section 6.6.1, the 5.03 error response, with problem-detail error-id 4 or 9 as specified in the referred Section 6.2 of draft-ietf-ace-key-groupcomm-oscore. * In Section 6.6.2, the 5.03 error responses, with problem-detail error-id 9 as specified in the referred Sections 9.2 and 9.4 of draft-ietf-ace-key-groupcomm-oscore. * In Section 6.8, the 4.00 error response, with problem-detail error-id 10. * In Section 6.8.1, the 4.04 error response, with problem-detail error-id 6. <== Regards, Meir Goldman FAZON Foundation fazon@fazoncore.org https://fazon.org
- [Ace] Re: Last Call comment on draft-ietf-ace-osc… Marco Tiloca