Re: [Ace] Call for adoption: draft-selander-ace-edhoc-oscore-profile-00

Christian Amsüss <christian@amsuess.com> Mon, 12 September 2022 16:04 UTC

Return-Path: <christian@amsuess.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6C82C14CF08 for <ace@ietfa.amsl.com>; Mon, 12 Sep 2022 09:04:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.909
X-Spam-Level:
X-Spam-Status: No, score=-6.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QQCSeMiEviuF for <ace@ietfa.amsl.com>; Mon, 12 Sep 2022 09:04:28 -0700 (PDT)
Received: from smtp.akis.at (smtp.akis.at [IPv6:2a02:b18:500:a515::f455]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D7B27C14F742 for <ace@ietf.org>; Mon, 12 Sep 2022 09:04:25 -0700 (PDT)
Received: from poseidon-mailhub.amsuess.com (095129206250.cust.akis.net [95.129.206.250]) by smtp.akis.at (8.17.1/8.17.1) with ESMTPS id 28CG4JAD059682 (version=TLSv1.2 cipher=ECDHE-ECDSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 12 Sep 2022 18:04:19 +0200 (CEST) (envelope-from christian@amsuess.com)
X-Authentication-Warning: smtp.akis.at: Host 095129206250.cust.akis.net [95.129.206.250] claimed to be poseidon-mailhub.amsuess.com
Received: from poseidon-mailbox.amsuess.com (hermes.amsuess.com [10.13.13.254]) by poseidon-mailhub.amsuess.com (Postfix) with ESMTP id 4556BF3DC; Mon, 12 Sep 2022 18:04:19 +0200 (CEST)
Received: from hephaistos.amsuess.com (unknown [IPv6:2a02:b18:c13b:8010::aa6]) by poseidon-mailbox.amsuess.com (Postfix) with ESMTPSA id E4F4111A10; Mon, 12 Sep 2022 18:04:18 +0200 (CEST)
Received: (nullmailer pid 2700215 invoked by uid 1000); Mon, 12 Sep 2022 16:04:18 -0000
Date: Mon, 12 Sep 2022 18:04:18 +0200
From: Christian Amsüss <christian@amsuess.com>
To: Ace Wg <ace@ietf.org>, Daniel Migault <mglt.ietf@gmail.com>
Message-ID: <Yx9YgvkzSKG4Eydl@hephaistos.amsuess.com>
References: <CADZyTkk6dhz4w6CbDjXwu3Rd4own1wJGWgVoc+Xqz3_cm4utOg@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="2faHdttYdE2Yzpj1"
Content-Disposition: inline
In-Reply-To: <CADZyTkk6dhz4w6CbDjXwu3Rd4own1wJGWgVoc+Xqz3_cm4utOg@mail.gmail.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/YHeJMEBEhBT4VGXAP-07D2gARZw>
Subject: Re: [Ace] Call for adoption: draft-selander-ace-edhoc-oscore-profile-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Sep 2022 16:04:30 -0000

Hello chairs, group,

On Mon, Sep 12, 2022 at 11:26:21AM -0400, Daniel Migault wrote:
> This work stats a Call for adoption of the following document:
> Ephemeral Diffie-Hellman Over COSE (EDHOC) and Object Security for
> Constrained Environments (OSCORE) Profile for Authentication and
> Authorization for Constrained Environments (ACE) [1].

I've read this document and can review it in its working group phase.

I'd have a slight preference for the document to offer fewer options, or
making recommendations as to what to use and what not (like, do we need
several pages of text on using /authz-info, when EAD_1 can be used? Does
comb_req need to be optional? Does osc_ms_len need to be negotiated?) --
but that's the kind of comments well suitable for work inside the WG,
and should not impede adoption..

Best regards, and thanks to the authors for providing this work
Christian

-- 
To use raw power is to make yourself infinitely vulnerable to greater powers.
  -- Bene Gesserit axiom