Re: [Ace] ace-coap-est: unclear definition of /.well-known/est URI

Esko Dijk <esko.dijk@iotconsultancy.nl> Fri, 21 September 2018 08:08 UTC

Return-Path: <esko.dijk@iotconsultancy.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C513130E11 for <ace@ietfa.amsl.com>; Fri, 21 Sep 2018 01:08:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, T_DKIMWL_WL_MED=-0.01, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=iotconsultancynl.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GYmYSaL1Mmlj for <ace@ietfa.amsl.com>; Fri, 21 Sep 2018 01:08:37 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0091.outbound.protection.outlook.com [104.47.2.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5AB6E130DE1 for <ace@ietf.org>; Fri, 21 Sep 2018 01:08:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=iotconsultancynl.onmicrosoft.com; s=selector1-iotconsultancy-nl; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yxop0XqK8BYSCMM2lkYLYLuYWC3kT9/ii/dc0U6l+lQ=; b=ZZyODPZM9roytqJChQ5UIeTxZte73GxBUQ7e9AFEBjwwluNZAaDUtO3xzQcSCV+J2GO3/zxXV3vD8mhlKyx/mXn0rrrp0x6QsKKlz8uI+beVOMLeccPO86botjCouvIlFmKQlHOamKWUghPUm+HtNsRjuzXh3u/Dlihcby+itL8=
Received: from DB6P190MB0054.EURP190.PROD.OUTLOOK.COM (10.172.229.12) by DB6P190MB0309.EURP190.PROD.OUTLOOK.COM (10.175.242.13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1143.18; Fri, 21 Sep 2018 08:08:33 +0000
Received: from DB6P190MB0054.EURP190.PROD.OUTLOOK.COM ([fe80::74a4:5356:e25e:c0b1]) by DB6P190MB0054.EURP190.PROD.OUTLOOK.COM ([fe80::74a4:5356:e25e:c0b1%5]) with mapi id 15.20.1143.017; Fri, 21 Sep 2018 08:08:33 +0000
From: Esko Dijk <esko.dijk@iotconsultancy.nl>
To: Michael Richardson <mcr+ietf@sandelman.ca>
CC: "consultancy@vanderstok.org" <consultancy@vanderstok.org>, "Panos Kampanakis (pkampana)" <pkampana@cisco.com>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] ace-coap-est: unclear definition of /.well-known/est URI
Thread-Index: AdRKqeFCUK1AzigFR5qvzUaQ2+R0GgAAdGzwAJTV7HAAalmT4AAs2fUAAGVhPIAAAC+vgAAAisCAAAmarAAAGJIIEA==
Date: Fri, 21 Sep 2018 08:08:32 +0000
Message-ID: <DB6P190MB0054057F6705EF006DD3B77CFD120@DB6P190MB0054.EURP190.PROD.OUTLOOK.COM>
References: <DB6P190MB005479015E3F02D4028541A9FD1B0@DB6P190MB0054.EURP190.PROD.OUTLOOK.COM> <39ff6ec1903c4c3a9d333c41a38a1ad9@XCH-ALN-010.cisco.com> <DB6P190MB00548845B38C0B0DF2380CD1FD180@DB6P190MB0054.EURP190.PROD.OUTLOOK.COM> <fc396115e9a54f80babfe9a9f5ae9e74@XCH-ALN-010.cisco.com> <DB6P190MB005441A30B3C3414EFF55D5EFD1D0@DB6P190MB0054.EURP190.PROD.OUTLOOK.COM> <26476.1537455069@localhost> <1c3188c5281a3bc921b97c9c7bc6b053@bbhmail.nl> <DB6P190MB00547429FEA6C0B70337AB69FD130@DB6P190MB0054.EURP190.PROD.OUTLOOK.COM> <29572.1537472820@localhost>
In-Reply-To: <29572.1537472820@localhost>
Accept-Language: en-US, nl-NL
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=esko.dijk@iotconsultancy.nl;
x-originating-ip: [2001:1c02:3100:b700:1856:ce37:3c5a:7053]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DB6P190MB0309; 6:sxPjd2zv7iRUAvhZ22z72G968K27YWcC/6jH5rciqP+s4OfxeXHbyj3kXiV6Ue6QLU8CRV/5rPCziVECUFjMMIJYPmHYW5XDis5OCCwlBI0wQtBvcSkgxfJkgFmNxB6WC0vRF2pUzRpRB+RpW2bbmuuRRDmfPfYTgLnTDXIDVWDpwVf4GiO30T8Pso5j8hle/1/pNdISO+bxhxVzrQ8gbymkaSXAAaFdC6VVelwC2gXs3sEBnPvYmWt8jfH66Hr1SyDytW525ADgywXst0ss1mk3l2KAtQ41pKtwW3z/B3By4Xfv0803M6viN99cHzYRyJqf3faHNs+oIk+aovLLLspOYq4LEabxFnDhcDGAti039YQFteHOEiVj1p2zdxkisGaSGy29YxHVyeZcFJXFLlVApYW6zyJM9thCw2RoxD36TTIlg+vAvpwtqPP70w2rxURgdAdQA+3tSp4zGxp34Q==; 5:3A3qRlpOn0z84Ku+NPx+TGIaqLD5la9Mo2LwEBYLdlBu5Pv1mLlEkVEMDXhaDn1TIFVRhU7cRmVDpsLRiRtVZUUAZpQlJ/BWYUaarjPKm6z+TDA+wKMl32S1FrJZzdLQCrURZlM6ptBhBKd2xuusgbEXcg6p4BOdf4mFWVnk25s=; 7:aFbJn2BsFkmQhNtWWSuNfOlxt7mNwC5yxSo7UMrpUthL2C6YXzoQFy5VSe+Kf8naEZTLBwhJhzmAtUa3OwIPwWfYyFMz5ytPZ4RhSvnbeH1V5BW8cIgiOkTj/Ho8BX+DkKvrrx1hb/PzNeQjkI/+kMhUPQ41YgP6yTZRaM8c6w+4qm1++x/eMG2nPfYuFUMzBNPTzV6MVeO0cOP69pmrxfvpV8FiZlahVb8FiAcmiEzDc0uWAG76TqDVCcuVWfDd
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: 647591e3-6389-4b04-1be0-08d61f996c81
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(7021125)(8989299)(4534165)(7022125)(4603075)(4627221)(201702281549075)(8990200)(7048125)(7024125)(7027125)(7023125)(5600074)(711020)(2017052603328)(7153060)(7193020); SRVR:DB6P190MB0309;
x-ms-traffictypediagnostic: DB6P190MB0309:
x-microsoft-antispam-prvs: <DB6P190MB030920C46F546B699B5F3E46FD120@DB6P190MB0309.EURP190.PROD.OUTLOOK.COM>
x-exchange-antispam-report-test: UriScan:(158342451672863);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(5005006)(8121501046)(3002001)(10201501046)(3231355)(944501410)(52105095)(93006095)(93001095)(149027)(150027)(6041310)(20161123560045)(20161123564045)(20161123562045)(20161123558120)(2016111802025)(6043046)(201708071742011)(7699051); SRVR:DB6P190MB0309; BCL:0; PCL:0; RULEID:; SRVR:DB6P190MB0309;
x-forefront-prvs: 0802ADD973
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(376002)(346002)(366004)(396003)(136003)(39830400003)(199004)(189003)(99286004)(256004)(2900100001)(102836004)(44832011)(229853002)(5660300001)(46003)(68736007)(76176011)(316002)(446003)(5250100002)(11346002)(97736004)(6506007)(486006)(476003)(7696005)(33656002)(6436002)(106356001)(9686003)(25786009)(74316002)(4326008)(93886005)(53936002)(14454004)(86362001)(6116002)(71200400001)(71190400001)(105586002)(54906003)(7736002)(508600001)(8936002)(186003)(74482002)(6246003)(81156014)(305945005)(81166006)(2906002)(8676002)(55016002); DIR:OUT; SFP:1102; SCL:1; SRVR:DB6P190MB0309; H:DB6P190MB0054.EURP190.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: iotconsultancy.nl does not designate permitted sender hosts)
x-microsoft-antispam-message-info: Jx12N/Lp5lFrDCGWu3hXRzP6h8Z2+8sAC0EVSSg6i2HDFq1jAS/jBNOugmvAA1dy5aEMZazxON5enqCcX8HGJTr1WqYwrfr9bazfTayz7ECwMdYkuyIufakgjI/scNBlK9oPEhQ+1+30iegKmKWYGWGmqUwOUdytYuqXVbVnsdYjmhZwvluBtl+dCncd/TnolpvD4YUxGULs36D4e9eW3Lv+LtSjYFoDZHFRvQV++IFNd8ykxTk+CtREeVi1Wc5mS8QA0hB/HlVk0ADHeLbLubD5KkiFVV8wHjazj7nPhOlpOLR5Lz+xWWbFfW5VFmlVmU8x4MyJqEWoGHH2fpMIcC7RLYLCDGuSeEWHy01bD7s=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: iotconsultancy.nl
X-MS-Exchange-CrossTenant-Network-Message-Id: 647591e3-6389-4b04-1be0-08d61f996c81
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Sep 2018 08:08:32.9901 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 58bbf628-15d2-46bc-820b-863b6774d44b
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6P190MB0309
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/G6N39Igj4r5ikSIQ8Un5dTDF8I0>
Subject: Re: [Ace] ace-coap-est: unclear definition of /.well-known/est URI
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Sep 2018 08:08:39 -0000

> I've seen it just return </est>, but I guess if you want to return the 
> port number, you have to return the hostname... <:61616/est> won't do? 

The closest thing valid according to the ABNF definitions would be
<coaps://:61616/est>

But unfortunately CoAP by its RFC 7252 URI definition forbids using an empty host (reg-name) in a CoAP URI.

> So I've assumed that discovery happens on 5684, under DTLS. 
> You are suggesting that we need to run an unencrypted CoAP to offer the 
> discovery option as well. 

Ok, discovery can happen on port 5684 - in general a CoAP server MAY support discovery on 5684 and MUST support it on 5683 if discovery is offered.
For our purposes, ace-coap-est could require that an EST server MUST offer discovery on port 5684. And we avoid any long-URI issues in the return payload.

Esko