Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Esko Dijk <esko.dijk@iotconsultancy.nl> Mon, 17 February 2020 16:49 UTC

Return-Path: <esko.dijk@iotconsultancy.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF9FB12088D for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 08:49:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.89
X-Spam-Level:
X-Spam-Status: No, score=-1.89 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=iotconsultancynl.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E38gDBxQ7yyK for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 08:49:20 -0800 (PST)
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04on0727.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0d::727]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7F4BF12088A for <ace@ietf.org>; Mon, 17 Feb 2020 08:49:19 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=O3QbuzdbqZtb9jQjcBT2CtRRTqKb9W/EPiBgip5W+d4Q2slUuN1dgdhDB7d5ouXS2i0WG2CYf5XTI6mqMTQ3aH/O3o5Eo8aK45QVZzKV6bzazFDauJPCLalx+3oru9zzyYcPWj49FfALThtmV25o48QC4JMhMSh3UdPASeh1uuKpLZdOFa50xIEkxZ23WETh0jvn3Qpd3R6hASkl/z2hQzjUzp6LOblA9YLWPVFd455X2aP5ekfwa6eFivmKzoZVdP3GS2QDI7Js9tFwM72F3DgsE548F6NkucKtsf/eYwat6A4m3LEnRrgPcuSEBlj0bXyCVlSthOq5XmM4wKj1hQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=e0ZSVs23mUPxR54SIc708JD/KPYI0fjDpVE4S6Sx3/M=; b=ESFkbgFbs5/9kiRhDqvqMRVsDBJ4tYvBaZTC2GQEsVjRLMSjUsJBhO4LubWOY8bMr1Ab9mavokNPHaC1mkSJjihlabLQnakSfoLdIYX2Cq6XxBtXJaPxJIoE8taE1sNLUMCZ8uqCV9/ala5y8GKn7XD0MErhV3WVeqWr1mmDkJQImQ8bPrm6RxPQlYvwabVH3FWFmMxuqtLYxzp1YAtDGpf+olxaZuPdULZipLtgEkHCvPZ9R32stLUJgKIrOo+F3UAWqJor3fNna9U6W1S4ynJ9e8n+M9bnX4hh/ItoWjd0cIfkfmauXwSD+A9GhAgB1qEl568iqq2Ic/y3/hQIcQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=iotconsultancy.nl; dmarc=pass action=none header.from=iotconsultancy.nl; dkim=pass header.d=iotconsultancy.nl; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=iotconsultancynl.onmicrosoft.com; s=selector2-iotconsultancynl-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=e0ZSVs23mUPxR54SIc708JD/KPYI0fjDpVE4S6Sx3/M=; b=hUC4BEVzdynwH9OUVQElBF1eii5gjti+o0BY0fXoQkmjtQSqLrI+4efu5XdKnZjDtPDfFV+KiankXsCnevyxCY1iNYAFEPhaVBxrfWDGAUPkncYVVm97zQgOTSaV9m1bp1WbGyVNGTEdvPNe1qY5IEi4G7WhHfbaWB211mZyCQ4=
Received: from AM5P190MB0275.EURP190.PROD.OUTLOOK.COM (10.161.62.28) by AM5P190MB0386.EURP190.PROD.OUTLOOK.COM (10.161.66.13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.25; Mon, 17 Feb 2020 16:49:13 +0000
Received: from AM5P190MB0275.EURP190.PROD.OUTLOOK.COM ([fe80::287f:e6f2:a17:a59f]) by AM5P190MB0275.EURP190.PROD.OUTLOOK.COM ([fe80::287f:e6f2:a17:a59f%7]) with mapi id 15.20.2729.032; Mon, 17 Feb 2020 16:49:13 +0000
From: Esko Dijk <esko.dijk@iotconsultancy.nl>
To: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
Thread-Index: AQHVxLs5a84UpdRvE0O3c4mcfUR7gKfd8DaAgEFZfBCAAJCBAIAAAIGA
Date: Mon, 17 Feb 2020 16:49:13 +0000
Message-ID: <AM5P190MB0275F8D2FBDC87037FCFE60CFD160@AM5P190MB0275.EURP190.PROD.OUTLOOK.COM>
References: <157833360921.8003.6238594444996424752@ietfa.amsl.com> <BN7PR11MB25472BD695322671615371F5C93C0@BN7PR11MB2547.namprd11.prod.outlook.com> <AM5P190MB0275CEAAE1AE5E11BE9C3410FD160@AM5P190MB0275.EURP190.PROD.OUTLOOK.COM> <BN7PR11MB254744B1A4F01D82B46EE9BCC9160@BN7PR11MB2547.namprd11.prod.outlook.com>
In-Reply-To: <BN7PR11MB254744B1A4F01D82B46EE9BCC9160@BN7PR11MB2547.namprd11.prod.outlook.com>
Accept-Language: en-US, nl-NL
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=esko.dijk@iotconsultancy.nl;
x-originating-ip: [2001:1c02:3103:6d00:7824:73b4:cb71:9a42]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 959bfdbc-577a-4e0a-ffe0-08d7b3c9519b
x-ms-traffictypediagnostic: AM5P190MB0386:
x-microsoft-antispam-prvs: <AM5P190MB03868A25BBF98280823363CDFD160@AM5P190MB0386.EURP190.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0316567485
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39830400003)(346002)(366004)(396003)(136003)(376002)(189003)(199004)(7696005)(5660300002)(86362001)(81156014)(8676002)(81166006)(6506007)(66574012)(110136005)(66556008)(53546011)(64756008)(66476007)(76116006)(8936002)(44832011)(66946007)(186003)(66446008)(52536014)(55016002)(9686003)(2906002)(33656002)(71200400001)(966005)(508600001)(316002); DIR:OUT; SFP:1102; SCL:1; SRVR:AM5P190MB0386; H:AM5P190MB0275.EURP190.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: iotconsultancy.nl does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: kYHTWaJADIu6tNMyiWEsajXD/0oO8G8OYR+qEHxyRLmlt9cXW1ajQZoWItjANCNQscoc06jw4S5ZmzYeTQ1ao4XP/zm6vDa3Pi1Hi0duOoyIP/nzvQuNTwFjwdFvZawHMZ2SKqtmqYR+s02pPVqEJvFdtCHyLSnVbwYnZVUDZL7KIv+MTtKO6VldXK9WYgxNcQy9rxedS3MWWSFdO0SHuHs2oqQcUyeOXAgHFZ1EvwU+eiQj/lgRNdBllwC0lvwgY7qZgqsHFGaxYNlAIo8NkrMAf2WBQkY2cbBUJGR1ms17GVchXEyPvZV0wDLMI1rqlMc2rGVTBpbKypfqiLIxmMAwX7b5nZdyqxSmBhxx+lyECebXWLVqPEqB3qPB5aQMuwcMiiUCaBRvg9TwzW7ukxystJ5h39OiLfsbQvndQIdqXmi0hMRDjMIYgHQnJfq63Lun2ZY6sEjUBa8uBFtgYSS9AAAfU5u35Y5CWdIq2nfay4jHK87GvqxxUBv7VuuuBPDe3t6sM1ozd73MwuhOdg==
x-ms-exchange-antispam-messagedata: jKNTey3Pr9dObOZUPnEncHtDNMmRIcffDmbDIYD3QlRBYRxTfvI6SGCsnnKZz3yE7C1pVFDDU0g/LAHx+4ky2PmLp+iTKeKiDquZf7r6MY0HFEar2Ag7BIpIciG7nkJwubiUUAxorj/RA937I/FHcPJGx1X0eKxA0zO4QubPtIaRsala12tW7+ScVF8ICxDU9eBFz7GUSza8UvbOzpTmkw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: iotconsultancy.nl
X-MS-Exchange-CrossTenant-Network-Message-Id: 959bfdbc-577a-4e0a-ffe0-08d7b3c9519b
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Feb 2020 16:49:13.3781 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 58bbf628-15d2-46bc-820b-863b6774d44b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: fp6jvqV5nEFsIZ9iJ4iSLgWp1LN/710intqjjceGHXGAnT8uMAgaAoXlRpyh5apuIKIopgyZnIzvJpJlSRTCOpVWwdrRJAdqqJo51/cRru4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5P190MB0386
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/f8CrmKnpP1Oo6cAl20rqRwDigd8>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Feb 2020 16:49:27 -0000

Thanks, the proposed text is fine! Agree it is a minor item.

Esko

-----Original Message-----
From: Panos Kampanakis (pkampana) <pkampana@cisco.com> 
Sent: Monday, February 17, 2020 17:47
To: Esko Dijk <esko.dijk@iotconsultancy.nl>; ace@ietf.org
Subject: RE: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Thank you for this Esko. Hmm, point taken.

I consider this a minor change and we will incorporate it in the AUTH48 phase. 
I am planning to rephrase to
   "[...] If the client had requested Content-
   Format TBD287 (application/pkix-cert), the
   server would respond with a single DER binary certificate.
   That certificate would be in a multipart-core container specifically
   in the case of a response to /est/skc query."

Let us know if you have any objections.

Rgs,
Panos

-----Original Message-----
From: Esko Dijk <esko.dijk@iotconsultancy.nl>
Sent: Monday, February 17, 2020 3:15 AM
To: Panos Kampanakis (pkampana) <pkampana@cisco.com>; ace@ietf.org
Subject: RE: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Hello Panos,

I noticed one sentence in Appendix A that seems inconsistent with the rest of 
the I-D, or at least gives an incomplete view :

   If the client had requested Content-
   Format TBD287 (application/pkix-cert) by querying /est/skc, the
   server would respond with a single DER binary certificate in the
   multipart-core container.

The client here could also have POSTed to resource /est/sen with Accept:TBD287 
option, indicating it is requesting TBD287 for simple enrollment, and the 
server would respond with a single DER binary certificate 
(application/pkix-cert). So the current text might suggest that POSTing to 
/est/skc is the only way to request TBD287 format, which is not the case since 
/est/sen also may support it too.

Best regards
Esko


IoTconsultancy.nl  |  Email/Skype: esko.dijk@iotconsultancy.nl

-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of Panos Kampanakis (pkampana)
Sent: Monday, January 6, 2020 19:12
To: ace@ietf.org; i-d-announce@ietf.org
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Hello,

This iteration addresses all IESG reviews. More details on the feedback and 
how we addressed it are in the git issues here

Rgs,
Panos


-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org
Sent: Monday, January 06, 2020 1:00 PM
To: i-d-announce@ietf.org
Cc: ace@ietf.org
Subject: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt


A New Internet-Draft is available from the on-line Internet-Drafts 
directories.
This draft is a work item of the Authentication and Authorization for 
Constrained Environments WG of the IETF.

        Title           : EST over secure CoAP (EST-coaps)
        Authors         : Peter van der Stok
                          Panos Kampanakis
                          Michael C. Richardson
                          Shahid Raza
	Filename        : draft-ietf-ace-coap-est-18.txt
	Pages           : 51
	Date            : 2020-01-06

Abstract:
   Enrollment over Secure Transport (EST) is used as a certificate
   provisioning protocol over HTTPS.  Low-resource devices often use the
   lightweight Constrained Application Protocol (CoAP) for message
   exchanges.  This document defines how to transport EST payloads over
   secure CoAP (EST-coaps), which allows constrained devices to use
   existing EST functionality for provisioning certificates.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-ace-coap-est/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-ace-coap-est-18
https://datatracker.ietf.org/doc/html/draft-ietf-ace-coap-est-18

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-coap-est-18


Please note that it may take a couple of minutes from the time of submission 
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
Ace mailing list
Ace@ietf.org
https://www.ietf.org/mailman/listinfo/ace