Re: [Ace] Warren Kumari's No Objection on draft-ietf-ace-key-groupcomm-17: (with COMMENT)

Marco Tiloca <marco.tiloca@ri.se> Fri, 15 December 2023 17:23 UTC

Return-Path: <marco.tiloca@ri.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1598C14CF1D; Fri, 15 Dec 2023 09:23:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ri.se
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FmM42kAX5_if; Fri, 15 Dec 2023 09:23:02 -0800 (PST)
Received: from GV3P280CU006.outbound.protection.outlook.com (mail-swedencentralazon11010001.outbound.protection.outlook.com [52.101.75.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 10E59C14F5E4; Fri, 15 Dec 2023 09:23:01 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UfxN0VqTVduzCXX0eHrhmrCnzlct2Gn/99tLD4fmBzRW+HjaYfrmzZDfvAvYE3rf4XOk9KFh4crSr7R9VXDkBSUP3atKNdY/GorzLzPclOdT/pVdcSRp/bHChL7/nAevu+ydJvfTv0nwpfmYi+2AyX3VmcbHRypoVO95t9RSo5feord89+orNFuXcthboJSwvGwUsOxl9i0PFM83Znfki0KnAQBNeMr534Z7rJq8zh/nPQBd3XiWtFUIXnTQ62fLKLKnTYzV3QY4wjc3dePgoUEpaWu3/a0IBt3V4c/7vPiuqj6VAzL5u7dPISajI7vZAJnittEVqvfuKLe/nrZjkw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=o4AlmSYJTTY4q68oI0bY+d+I8t6LppApSpcUuYWeB8s=; b=fbBM07rgxeQqtlOAvHznkuJGHHLqzM+9O14sT2P/fLSC3Mx6VJfT6zzo3TmL80PQa7JUCWVApwv20lusytEJgER+80YNj0aioD/U8+VWnit7Z8C+1zRneXKaf3H72RX1AC3VwA1BQbqmmz9NHZ1UVy85v1jMA1sUDJrCreiSw1IH0yxtRi0rkkPYE3PGPlULjAXOdmYoo19NTNBoELRSPRisYgqxZTQRFeDH4OOkFr9pO4G8ukbH6BRYjRFbFAH8pBPoAfcaNrlOPd3a3859RAzvto5IVOnPiNaHwMMMTjinVgo6nxsWkTRCXslusSJmX61vi8b6KH57fShoAcK5nw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=o4AlmSYJTTY4q68oI0bY+d+I8t6LppApSpcUuYWeB8s=; b=PDAKj9i5HFX2kAUVNQ7P63F+Mur7Y/aw8QgnInRssLctMj3tvGbrO16gzvjkcpXZd+bxnH2npH3JWPEGOQCnkHph5GlYUh+XoaRV58jQqWs+/AUJEGowIF9RrFGRdq4NU4D4YHFK3onO3BvD8zpm8hwznYl/lhhe0DhdueE+d/M=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ri.se;
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17) by GV3P280MB0001.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:14::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7091.31; Fri, 15 Dec 2023 17:22:58 +0000
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::49f4:9d27:4b68:cdab]) by GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::49f4:9d27:4b68:cdab%4]) with mapi id 15.20.7091.030; Fri, 15 Dec 2023 17:22:58 +0000
Message-ID: <080bb7a1-3ce2-4f10-b045-2420983a4a78@ri.se>
Date: Fri, 15 Dec 2023 18:22:55 +0100
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: Warren Kumari <warren@kumari.net>, The IESG <iesg@ietf.org>
Cc: draft-ietf-ace-key-groupcomm@ietf.org, ace-chairs@ietf.org, ace@ietf.org, mglt.ietf@gmail.com, Francesca Palombini <francesca.palombini@ericsson.com>
References: <170128766702.2854.10197854210438647153@ietfa.amsl.com>
From: Marco Tiloca <marco.tiloca@ri.se>
Autocrypt: addr=marco.tiloca@ri.se; keydata= xsBNBFSNeRUBCAC44iazWzj/PE3TiAlBsaWna0JbdIAJFHB8PLrqthI0ZG7GnCLNR8ZhDz6Z aRDPC4FR3UcMhPgZpJIqa6Zi8yWYCqF7A7QhT7E1WdQR1G0+6xUEd0ZD+QBdf29pQadrVZAt 0G4CkUnq5H+Sm05aw2Cpv3JfsATVaemWmujnMTvZ3dFudCGNdsY6kPSVzMRyedX7ArLXyF+0 Kh1T4WUW6NHfEWltnzkcqRhn2NcZtADsxWrMBgZXkLE/dP67SnyFjWYpz7aNpxxA+mb5WBT+ NrSetJlljT0QOXrXMGh98GLfNnLAl6gJryE6MZazN5oxkJgkAep8SevFXzglj7CAsh4PABEB AAHNNk1hcmNvIFRpbG9jYSAobWFyY28udGlsb2NhQHJpLnNlKSA8bWFyY28udGlsb2NhQHJp LnNlPsLAdwQTAQgAIQUCWkAnkAIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRDuJmS0 DljaQwEvCACJKPJIPGH0oGnLJY4G1I2DgNiyVKt1H4kkc/eT8Bz9OSbAxgZo3Jky382e4Dba ayWrQRFen0aLSFuzbU4BX4O/YRSaIqUO3KwUNO1iTC65OHz0XirGohPUOsc0SEMtpm+4zfYG 7G8p35MK0h9gpwgGMG0j0mZX4RDjuywC88i1VxCwMWGaZRlUrPXkC3nqDDRcPtuEGpncWhAV Qt2ZqeyITv9KCUmDntmXLPe6vEXtOfI9Z3HeqeI8OkGwXpotVobgLa/mVmFj6EALDzj7HC2u tfgxECBJddmcDInrvGgTkZtXEVbyLQuiK20lJmYnmPWN8DXaVVaQ4XP/lXUrzoEzzsBNBFSN eRUBCACWmp+k6LkY4/ey7eA7umYVc22iyVqAEXmywDYzEjewYwRcjTrH/Nx1EqwjIDuW+BBE oMLRZOHCgmjo6HRmWIutcYVCt9ieokultkor9BBoQVPiI+Tp51Op02ifkGcrEQNZi7q3fmOt hFZwZ6NJnUbA2bycaKZ8oClvDCQj6AjEydBPnS73UaEoDsqsGVjZwChfOMg5OyFm90QjpIw8 m0uDVcCzKKfxq3T/z7tyRgucIUe84EzBuuJBESEjK/hF0nR2LDh1ShD29FWrFZSNVVCVu1UY ZLAayf8oKKHHpM+whfjEYO4XsDpV4zQ15A+D15HRiHR6Adf4PDtPM1DCwggjABEBAAHCwF8E GAECAAkFAlSNeRUCGwwACgkQ7iZktA5Y2kPGEwf/WNjTy3z74vLmHycVsFXXoQ8W1+858mRy Ad0a8JYzY3xB7CVtqI3Hy894Qcw4H6G799A1OL9B1EeA8Yj3aOz0NbUyf5GW+iotr3h8+KIC OYZ34/BQaOLzdvDNmRoGHn+NeTzhF7eSeiPKi2jex+NVodhjOVGXw8EhYGkeZLvynHEboiLM 4TbyPbVR9HsdVqKGVTDxKSE3namo3kvtY6syRFIiUz5WzJfYAuqbt6m3TxDEb8sA9pzaLuhm fnJRc12H5NVZEZmE/EkJFTlkP4wnZyOSf/r2/Vd0iHauBwv57cpY6HFFMe7rvK4s7ME5zctO Ely5C6NCu1ZaNtdUuqDSPA==
In-Reply-To: <170128766702.2854.10197854210438647153@ietfa.amsl.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------zGNWiRR0TtJTnOw9Hu2QAuvG"
X-ClientProxiedBy: FR4P281CA0221.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:e4::18) To GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: GVYP280MB0464:EE_|GV3P280MB0001:EE_
X-MS-Office365-Filtering-Correlation-Id: 52d5555f-22d9-4b88-f569-08dbfd927b89
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: wYWKAOwGfVKZg9WdvcF4pkEYEGqkmUJ5lf/4hZNaaazmwD6XJfhfnUsNbhC0lTrK7CaivwCrFt9ZQ+hJ8GlrmXfbyOOqxm93cvKzk2Y6kEqNmAsouzw0bfabbbL6fJVXjZhDwV2a0raytUboeuyKXNDRQOwKl29f1h9kA/sq/SKL6wdviQCMgzKHjQFEyaG13kdBMMnaj0r4whsjh0kfYJFAIgI74/oTkUg1xOa+jgQy1Oz0zLU26k55MaAfEukj0F883fzkgfFrJSm0ZzRicLrLzLUGP6Xd/PROCmFgP6SPJ+1Hw1don1QkHqC5BktQu5C9SA7vR49vpGS+jTozyoQ8sA4mTWTLioJ4eSnIlhYT2bYbqbeFettaJGWbjh+Mc2zxET+k1CTYI2f4i3x3bPsL8LfyI6jiH9ACuod0VXfA7ikD/xtIhlFF/duc1Tr3lzyGJtNzjpq1sQka2oHjFKHL3jtsMee0Dn6SB3jyAJ1p1skO65VOJvFMEWezS52Z1znW0S5HxLj7i6piWIhU0WMlDHaOqCFsNJqk0J7bjsRkaPS0sOS7BAmLZ05mJH1lsabrZIOHseHSNG6q2Y12CB1WX+cGSuEzaWPVanWaHRE3bN1NBOLD2qANSSnM6eiK6bZCMKYKL4Y04xxtiN+qjw==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(136003)(376002)(39860400002)(396003)(366004)(346002)(230922051799003)(1800799012)(186009)(451199024)(64100799003)(110136005)(316002)(66476007)(66556008)(66946007)(8676002)(6506007)(53546011)(8936002)(6486002)(5660300002)(4326008)(44832011)(31686004)(235185007)(45080400002)(478600001)(6666004)(31696002)(86362001)(21480400003)(41300700001)(83380400001)(2906002)(966005)(33964004)(26005)(6512007)(2616005)(36756003)(4001150100001)(166002)(38100700002)(45980500001)(43740500002); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: VvqkJJr/whrB58+r1M8mIlO9I1yzbR/sz0KLDkMCL7m/oInJjteRh5gNRF7PbZC89be0rmjXBklsNF+jJUmd/vEhou4uqpKonC8wtpIoIbO2b9RctxryOSgvnaQA8HXl501a/y4dfDf9yjwFFV1KwMMha9V9n9gYXxt+MJD8VAAR1LE/hzjBJsGVrVZYNJrXfM39vCNtru1VtxBNol62RranIyxTEhkZ3Vk/nnJUXh21meFmQ/tbaCesg2M6zUrPD1FTBuX40uVsJqoiFkK8WVDcWcxuS4mSlpFyn1tdn9yErbRPJVWePCdXrDmasKqRZ0Bcau36G6gpXEIXfuVRH15l7nhPI7SNjvghsC0JJhgARJsusJh0DDNeq6enUy1xhhFKJO4FYLjIoDiNvQOS0LeNEIw/AQLYFUg5Yz/gZRRExlA+RDjBfLdwK4bSqA1H6+Fie1KJvL5ljcEsVFQou2AypUJvs+NsYJp7Kg7rwP1aIDYQsmXUkPo6HAgHswZtXgS+DcWKn3TSqwqK6osQw0b8j6vE4efuBgFCfZ2ZjHjK0nPGKGvbxTgbfB5hVVPNkte8M1Ax4A5FhNdi4Z0RqPDgJ68f0gBM5AuoO5X1fUs0BSgvqS11T7tuUZS1nRYFaWobU/gIqJUhgWu4qcEafWodrvM++c3Fy9Pl5NmGKE38o6tsHGAsRwj9Erq8GY2NhWS0jTAj82qcNXc+f7gsc+3B66uMBFT3g8Gp8zPdhPPIykwDldq8IyC75RFI2L9ecznONb+FjL49N5bPGd8GU01uYd1Qi9Mn6v+RMvSSJWtZ0vwR48qUVWPm4r+EtS5dgXlSvKJ/oBtIgo5/goypIzSRZYCJZC/ZFOaQEV+oDRf5Caz589FQQV1cMp3U9YnRZZAZn8DzspWZ9wClTN3m9vwY/gGeUZPkrCxXJb4eYTZX5Ho8C06uDtjoVBI2fREECI67saiD5PLzDYDdqUb6Np/Bx4TuK5znjQUJTmeEdF4v6ItPB/nWSmis5CP95FM3gAmV+xVie16br8kUeQ5/i1ny/m9iVGndFUganFtuRmkdP8upD7w9f+BbkM/CotRDxOBkWOQJsnBd0nMpHzi6GZXHlSjQ+3EGUKr8q5F5m4iSoEX9S+dXAaSZe6AHdk05KbdbD0V3LO7Y1C/b0dxg8FMfO960CCHzqQaGCM3TF/jGnzE8y8lHfQgXYzrPg5ZiwUmAofK80HBnzWXoIhpGAkXdDdMDulyRTiKJa6X+7TQP9hgIdgzvBAVFl8hYTipme50cGlaC5MguUMKzHi7xCKDzY4PsFq9W9GA1cqSmqBNkf0UX9hhR3ffoZ9QlVJrAwToA57FyHu5Ld5WzetZYYRe0F/GTIIcqCyI0bvoJ/pikvoUFIctbiDmmG0vkqfemllIHKqwopk0e0OYO71Ke+jBqEo5t9d1tn27zlA4u5tMCo95K8IRTqp3RiLtPRLA3EbUrSZqswBOkjUTZG3Fbyg7s/eLO8u/6mfKKusXhDpx/0FtwU+gZ0HW3AbUqoTpN4P70cvqZrzdbUG3MVnywiI/PV9lVwh8OWPQIQrBEPOx4qRc+z/Z3060pSxsRh+ZF
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-Network-Message-Id: 52d5555f-22d9-4b88-f569-08dbfd927b89
X-MS-Exchange-CrossTenant-AuthSource: GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Dec 2023 17:22:58.4082 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: Go/ma1A1fCveQgwmz82kECPjXJQ1eBKPialaUFXmgnR3nmO/eDBiepjSleVrF+wevw6qIgXhW14/ywHu7GEm3Q==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: GV3P280MB0001
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/d7ivTDL5pzmf4dm-fkUMo0qdjZ8>
Subject: Re: [Ace] Warren Kumari's No Objection on draft-ietf-ace-key-groupcomm-17: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Dec 2023 17:23:06 -0000

Hello Warren,

Thanks a lot for your review! Please find in line below our detailed 
replies to your comments.

A Github PR where we have addressed your comments is available at [PR].

Unless any concern is raised, we plan to soon merge this PR (and the 
other ones related to other received reviews), and to submit the result 
as version -18 of the document.

Thanks,
/Marco

[PR] https://github.com/ace-wg/ace-key-groupcomm/pull/165

On 2023-11-29 20:54, Warren Kumari via Datatracker wrote:
> Warren Kumari has entered the following ballot position for
> draft-ietf-ace-key-groupcomm-17: No Objection
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
>
> Please refer tohttps://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fabout%2Fgroups%2Fiesg%2Fstatements%2Fhandling-ballot-positions%2F&data=05%7C01%7Cmarco.tiloca%40ri.se%7C4c1aa823359841f0231308dbf114ffad%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638368844728564431%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=glipPpF8qR4XdpmB2pNm5hBOYLOPxph4lOpOlbMHdV0%3D&reserved=0  
> for more information about how to handle DISCUSS and COMMENT positions.
>
>
> The document, along with other ballot positions, can be found here:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-ace-key-groupcomm%2F&data=05%7C01%7Cmarco.tiloca%40ri.se%7C4c1aa823359841f0231308dbf114ffad%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638368844728570855%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=xAxbw8qHY2nryW00RMHAW7ZpYqntdyEE96nqN%2FKBVWw%3D&reserved=0
>
>
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> Thank you for writing this document - I found it both useful, and an easy read.
>
> I do have a nit / readability suggestion:
>
> "New keying material is generated and distributed to the group upon
> membership changes (rekeying), if the application requires backward
> security (i.e., new group members must be prevented from accessing
> communications in the group prior to their joining) and forward
> security (i.e., former group members must be prevented from
> accessing communications in the group after their leaving)."
>
> I found this wording confusing - I think that it is the comma after "upon
> membership changes (rekeying)". This initially sounds like "new keys are
> generated on every membership change. If the application requires backward
> security then [something else / something additional". I *think* that just
> dropping the comma fixes it...

==>MT

We have rephrased the paragraph as follows.

OLD
 > New keying material is generated and distributed to the group upon 
membership changes (rekeying), if the application requires backward 
security (i.e., new group members must be prevented from accessing 
communications in the group prior to their joining) and forward security 
(i.e., former group members must be prevented from accessing 
communications in the group after their leaving).

NEW
 > New keying material is intended to be generated and distributed to 
the group upon membership changes (rekeying). If the application 
requires backward security (i.e., new group members must be prevented 
from accessing communications in the group prior to their joining), then 
a rekeying has to occur every time new members join the group. If the 
application requires forward security (i.e., former group members must 
be prevented from accessing communications in the group after their 
leaving), then a rekeying has to occur every time current members leave 
the group or are evicted from the group.

<==

>
> You also have a typo: "It is REQUIRED of application profiles of this
> specificaton to" - specification.

==>MT

Yes, fixed in a previous editorial PR at 
https://github.com/ace-wg/ace-key-groupcomm/pull/156/files

<==

>
>
>

-- 
Marco Tiloca
Ph.D., Senior Researcher

Phone: +46 (0)70 60 46 501

RISE Research Institutes of Sweden AB
Box 1263
164 29 Kista (Sweden)

Division: Digital Systems
Department: Computer Science
Unit: Cybersecurity

https://www.ri.se