Re: [Ace] Warren Kumari's No Record on draft-ietf-ace-extend-dtls-authorize-06: (with COMMENT)

John Mattsson <john.mattsson@ericsson.com> Thu, 09 March 2023 20:05 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31679C1522D3; Thu, 9 Mar 2023 12:05:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C1Kgww9DV7PD; Thu, 9 Mar 2023 12:05:17 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on20629.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d00::629]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1748EC15155E; Thu, 9 Mar 2023 12:05:16 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Q/9Fw7GhtigVWx2UIJYyoGLXS2a+Q/97i2P/6QF1frabMYhgBqmtkOGJsmRp0/XCtLv3bP9uDcdAo+tlvztYFJYMMdiy4wOvLTBageLrDA4qvgf7RmyrK9QRMvZ7SuAvfgaZ77BdrkZao9ENRK+GZ5CXpTAvUXhDkzEJQ6gFJeBBolI5M1bbwmq4ZzDxjFB9n5oVhktDvrG1cP0jd4WwCR2pnqmARSIMvrl2BZL9tOXNnkTFI9pq5KXQuanrKFMErkIGNElq8BE50ced7sqpZpVMlyydJSR2K4NjuUxGQd/xAusBbVrK0aUHD1Hicmx1TVSvc7KMbp5j6gP+gKwu7Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Zk9RnsTC+IojVdxNBmSFX/w2ka1SqbzLsaK6chCckmY=; b=CsGjipEx7Uu4+4jH7SV1AF7NR5mMrCEjLxmEkYWApf6P2skmBIZUB5EoL2EmWOtYDi+tlXZ+KYew7nB1KBSeseObynYaudVDQPLUR1cYxLL6Ci2m/Oqmk8V4ndxp3NVDbtj38juHLwc1hrcgZsyt7XPOQBWVUzADRa0B4ksurPP+w7RmbxA7tbGhYl+Mxe1/XtKplPkHFWqrXe7LPLA9hQUK+OWtgiD6r8UqwJKO1ouTjU7+HKpu0TEHo0915Je2J66QGYZqLllsk18L4GV63VTN+EYVl8avkIAxhyMs1pj838SA9V5DILqZ3EyF9uTFM/7HuRFI1esEFN0lcB+C5A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Zk9RnsTC+IojVdxNBmSFX/w2ka1SqbzLsaK6chCckmY=; b=SlKN26MDgP5yOu7mCo9FCDjaQqut4ZyxvsmgrjMy4WP2g+jjKuUaAu5U7bfZDAqC2XsH9RLn5Ed2Lbb9FA36IjfpqGtTXQZsOZsii3s2c3dUoPzT51r4+unJ9hdpEQbpTeNdfcKBt1qAi+U9ODr2kUKPH9cIi/dHrTtwCfNkxdY=
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by AS2PR07MB8978.eurprd07.prod.outlook.com (2603:10a6:20b:555::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6178.18; Thu, 9 Mar 2023 20:05:12 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::6ec3:856a:ffc7:9526]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::6ec3:856a:ffc7:9526%8]) with mapi id 15.20.6178.017; Thu, 9 Mar 2023 20:05:11 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Warren Kumari <warren@kumari.net>, The IESG <iesg@ietf.org>
CC: "draft-ietf-ace-extend-dtls-authorize@ietf.org" <draft-ietf-ace-extend-dtls-authorize@ietf.org>, "ace-chairs@ietf.org" <ace-chairs@ietf.org>, "ace@ietf.org" <ace@ietf.org>, "mglt.ietf@gmail.com" <mglt.ietf@gmail.com>, "yingzhen.ietf@gmail.com" <yingzhen.ietf@gmail.com>, "opsdir@ietf.org" <opsdir@ietf.org>
Thread-Topic: Warren Kumari's No Record on draft-ietf-ace-extend-dtls-authorize-06: (with COMMENT)
Thread-Index: AQHZQUmUthYs5ye6/U2bVpBOWe0vVK7zAYRM
Date: Thu, 09 Mar 2023 20:05:11 +0000
Message-ID: <GVXPR07MB9678E71A61D04C6156BB1C1089B59@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <167647121090.18573.3274019337028183530@ietfa.amsl.com>
In-Reply-To: <167647121090.18573.3274019337028183530@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|AS2PR07MB8978:EE_
x-ms-office365-filtering-correlation-id: 96b78bd1-7603-4bc1-675b-08db20d996c2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: bEDCZaNdEasw5nZI0+ktnRCdie+8N5l5hI1u2Y8Pnn6aeCmnHRZQvQnb+zU7+Mf+N2nYUMgaLVgPzeqammRrmwRjbDaRWY2WBjQPUBag+1EgFi8Usa73neX+YotzVze3Fs3+XENCQ8Zc+1WiDzh9I69ivMRLu48h8xTVN8uQTLDP+PgjbpWsZ6lxhgAwCqPx9aYcjkgRLU/TV663EC83pLbbTzj3wgjHSy7DgL/MXSi0CE6xVLcE84WvuXusmLlNNY82zFC51AN7KK4sjX9vODv01eQhTKcGuiIRTsgv+iBuFIgQ4IrY5v+eNsoRzeIKBBVO0ZDZr+YgadIVGVtHcxkDiZ2c/MtDM5RIMuCDsx+bAsQkUyXyz4+lXqDD7gGDLvT1Q/fervk9n+Mn5AG+go1aaCBN2AjcjPGmyiyDiIbZRz0NGKKm+4O+5lm/lAfr5NbURGmCTVVwppa/NesQR+qMN6e6qRNaYclWJUNv7rfhKsfe1z/6NSY/0GrkznkUtJ1rUvS5h9Z7n3nc+cT1qQLelI6yyVwlrgtww+lpc/ti+mL/3ZXVpQ/z8Rt1WanGlGk7SCVsRnkvbvNNovti+JDQxcoqomV6WP6mTwVPRH5N9H1dsD1SIWFYWU1xBMqxEds3+Yqq/zcMxG4AtfhCbGMPhmG0oVpn4LtFS0nPfNFBRxH4zCs3qkts3rIStZb7WyGqNosW8J4ak0cv5B3UbGo1uycLKLe++V2uM/LssIyzOOnakVwLW8CHMsoUNRM24cPNffJasJ4wZk9G6NCVEA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVXPR07MB9678.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230025)(4636009)(136003)(366004)(376002)(39860400002)(346002)(396003)(451199018)(316002)(110136005)(54906003)(86362001)(33656002)(186003)(38100700002)(55016003)(122000001)(166002)(26005)(83380400001)(53546011)(9686003)(6506007)(82960400001)(38070700005)(71200400001)(52536014)(7696005)(5660300002)(8936002)(478600001)(966005)(41300700001)(44832011)(64756008)(2906002)(66476007)(4326008)(8676002)(66946007)(66556008)(76116006)(66446008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Rq45WVISusx79SS3FRvtcsp0t/lDLM6ytVDGdguP5EOIIJWDkL2OEWurpkFXv3fHzO6prd1UjOhnW+bYo69AceLVFbNmertRw2Dc7pT+eYXSxcwuocpqDG36nh7pnNkGSjulq+C1lDu7oMUQyUNIR53m8KOGHuHi0sMnZZe0HXX2oSNK5SzkdeNDvYrxlCgvbebCqn4uqUT5gYrk+i3QfhIVvGARA69pnl5nGtaP/pOSNVQM1INrxMVNXhiVcnZ9gji4Pd4LwK1YsKTRxTNWSgA4oBFvP14gTvXjz0bZ15E7R5uZvNkzXyxT0Yz6nk88ulPIYsMrvTon7ZJ+veXYg2nQdcpHHSBfvqicUBs/ApYihgZaVFvmxz9ZV5WMzcfB9thISFU8v3fgXVusq3lDqCsLvathTZ7JLOlQazMPklEd6FRzPGPsxoLoGY5NDEstdbpCk/i6d25kaLXPHapuazLjJhGaOA6qzP13MT579EQpWBenCHBEzFqXPPijDSI2PbeY8oOf5rheM5+xtBYr4QeQ4XEw7xktUtwRT/HUUUR/Ll6pZCfKK5ku6Clg6aHTrdN1xjKL6t4t0k3D+qm0lSrpNnjC1o3cJqYS0s9KZulnrwzcoy4IRwR7kjDSI5cDzFj6OYc8eGqjL4dsF+E9jQ6Q2MBUKZDmSOcoL8cGp650nXtBFOTqqW5zElZseDrhaz7ptf0T/2jAkntkYKAliQW62eRrsgCcrScZJWt1uzbgquCw6MtE07hxfka5BQmJ1FfxEuzaXvVocq0D5fYmlEb+j1DAxoKq48ZEvG/1GUBRhlN64C+ssVPSxI+GEtoM6wBbEMJxOV/aOysXNr2spXu3wj5kQfrs7rYRYO1MX+jwuAokHiYWeEH2qbj6zI0eDbW1bhYLrnOGaE1XXonG7E/39n67pFngMnIVIzjVRDsrTjTrGXnjQagE/q5/WElx8+0RLMU+c8uZ34MGIZ1wLYmmB+/tm6fF80HvE6LWYA0/CFpKPCdj+0eMKB/fohyhXGJrRgMfQLSPOqGzMUnOqX7bTY4VuV3sk5kCjodsG4sL780RCODN0s4uOJOu2ZLHod6px8eZrZfqt/FADdmq/4+o1BkBK8+3PKpRvvFp7E+q3bkyBYo2Mm61taT2MVkWaOnqe2gHi6Z7bK+MtNfenbH+J2fzKoDtf5iEYpLtKxt8Pm4puc7qcHR5jD+s4m4Phb7AY02ye6TgOEwg1XHssVz89+E83JTA+aTPORC+hhsS/ZBBNWkugIViA3+fNjThoLkmNuKxiY1fb2Pgwu1lIKC7ZHOhlG4S6b8UFDQkBLiZBBQnMBopAdAb/UGOVYXOkAf+YzHAJCa4g46SKIrBSJfHce25ITWq2HRBhrXo+ISVkee8s2uqUxjr6NOR05dLz2V08RWDT6lSG4mYidiYC0aO//WBuUc0zHeuXAUovqLo2J/58F5VYqYaZhEfQP2fE1Z2Yq/ZzbWiTogvaP+4qkNseUdrje1VS/gXmoMHfJBQBcLb+BzwqyHBC91raXIGAwx4SZ98TeWn65jAZTSImAnxoYXECCW9l0F6wraKUXn9BWOVMc9lEKBW4IYUmIPN+JpbdCROfjAwJPL78URUmvF3l3HXaYe0vzI543Q4K2A=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB9678E71A61D04C6156BB1C1089B59GVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 96b78bd1-7603-4bc1-675b-08db20d996c2
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Mar 2023 20:05:11.1746 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 0emZw0Dv2/auurtc/RDMH8+Dfq5Q5C1cGy0bLUFB7tPkFTwD6BynP+/ij7OYbQhSFlbt/b+8+08tatc7zqblGIih0BljjIKNVSAC2UdsoPg=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS2PR07MB8978
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/iH7hlrNp2TPgUCxuv-SOF0nTzMg>
Subject: Re: [Ace] Warren Kumari's No Record on draft-ietf-ace-extend-dtls-authorize-06: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Mar 2023 20:05:21 -0000

Hi,

We have submitted draft-ietf-ace-extend-dtls-authorize-07. This version addresses all comments received from OpsDir and IESG.

- Expanded the terms ACE, CoAP, TLS, DTLS, OSCORE, AS, RS as suggested by OpsDir and John Scudder.
- Added some info on the ACE framework (RFC9200) including the information that both the Client and the RS may be constrained. This addresses the comments from Paul Wouters, Zaheduzzaman Sarker, and John Scudder
- Explained what DTLS is used for. This addresses the comment from Lars Eggert.
- Removed the sentences "The client can try TLS and DTLS in parallel to accelerate the connection setup. It is up to the implementation to handle the case where the RS reponds to both connection requests." This addresses the comments from Erik Kline, Warren Kumari, and OpsDir.
- Added "Non-constrained Clients and Resource Servers SHOULD support both TLS and DTLS.". This addresses comments from Paul Wouters, Robert Wilton, and Zaheduzzaman Sarker.
- Fixed all nits found by IESG.

Diff:           https://author-tools.ietf.org/iddiff?url2=draft-ietf-ace-extend-dtls-authorize-07

Cheers,
John

From: Warren Kumari via Datatracker <noreply@ietf.org>
Date: Wednesday, 15 February 2023 at 15:27
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-ace-extend-dtls-authorize@ietf.org <draft-ietf-ace-extend-dtls-authorize@ietf.org>, ace-chairs@ietf.org <ace-chairs@ietf.org>, ace@ietf.org <ace@ietf.org>, mglt.ietf@gmail.com <mglt.ietf@gmail.com>, mglt.ietf@gmail.com <mglt.ietf@gmail.com>, yingzhen.ietf@gmail.com <yingzhen.ietf@gmail.com>, opsdir@ietf.org <opsdir@ietf.org>
Subject: Warren Kumari's No Record on draft-ietf-ace-extend-dtls-authorize-06: (with COMMENT)
Warren Kumari has entered the following ballot position for
draft-ietf-ace-extend-dtls-authorize-06: No Record

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-ace-extend-dtls-authorize/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks to Yingzhen Qu for the helpful OpsDir review:
https://datatracker.ietf.org/doc/review-ietf-ace-extend-dtls-authorize-06-opsdir-lc-qu-2023-02-09/

I encourage the authors to review this, and respond to the "In case both the
client and server support both TLS and DTLS, it says here “It is up to the
implementation to handle”. However it also says “the client typically first
tries using DTLS”, this seems to give priority to DTLS. Please clarify."