[Ace] draft-ietf-ace-key-groupcomm-oscore

Jim Schaad <ietf@augustcellars.com> Thu, 30 January 2020 23:16 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 47A8812022E; Thu, 30 Jan 2020 15:16:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.793
X-Spam-Level:
X-Spam-Status: No, score=-0.793 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, LOCALPART_IN_SUBJECT=1.107, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yf5NVD2VEtyx; Thu, 30 Jan 2020 15:16:28 -0800 (PST)
Received: from mail2.augustcellars.com (augustcellars.com [50.45.239.150]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38EBE1200F7; Thu, 30 Jan 2020 15:16:25 -0800 (PST)
Received: from Jude (73.180.8.170) by mail2.augustcellars.com (192.168.0.56) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Thu, 30 Jan 2020 15:16:19 -0800
From: Jim Schaad <ietf@augustcellars.com>
To: draft-ietf-ace-key-groupcomm-oscore@ietf.org
CC: ace@ietf.org
Date: Thu, 30 Jan 2020 15:16:17 -0800
Message-ID: <010b01d5d7c3$47d36ad0$d77a4070$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AdXUuS1YkeMOHqDuQo661Ct1JSFA6w==
Content-Language: en-us
X-Originating-IP: [73.180.8.170]
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/Uz1BfItsJfbwsNKdAbn4WT_wm9I>
Subject: [Ace] draft-ietf-ace-key-groupcomm-oscore
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Jan 2020 23:16:29 -0000

This is not a finished review - but I wanted to get it out.

Jim


General - Should the concept of a legal requester be part of the information
that is transported with the public key?  I don't believe that this is
currently done, but would additionally allow for a server to ignore comments
from individuals who are not authorized for that role.

Section 2.2 - must new security parameters be regenerated on each membership
change?

Section 2.2. - Does completion of a group rekeying include confirmed
redistribution before the version number is incremented?

Section 4.2.1 - I think that we are going to need a discussion on a couple
of issues related to the OSCORE half of how these values are going to be
created.  Pieces of the discussion are: 1. What is the POP her going to try
and prove.  Specifically is timeliness part of the discussion.  2. What do
we do about  token which grants access to multiple topics.  Is joining the
second group considered to be a re-join rather than an original join for the
purposes of this discussion?  3.  What are the interactions about cached
public keys, when are these ok and how is this communicated to the client as
a failure?

Section 4.3 - Does it make sense to return a new rsnoce as part of these
errors?