Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Esko Dijk <esko.dijk@iotconsultancy.nl> Mon, 17 February 2020 08:15 UTC

Return-Path: <esko.dijk@iotconsultancy.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C8A591201E4 for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 00:15:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.89
X-Spam-Level:
X-Spam-Status: No, score=-1.89 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=iotconsultancynl.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DQLask1waKZ4 for <ace@ietfa.amsl.com>; Mon, 17 Feb 2020 00:15:31 -0800 (PST)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-ve1eur03on0706.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe09::706]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1CE8120100 for <ace@ietf.org>; Mon, 17 Feb 2020 00:15:28 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=W0gasizcyb9aWWbo8Yl3IbDq+jWwPQ9spI7cb+T3pcn8NbbO5h6uZKUBpBG+wiCvDdfZQ1gHQIvoIn1MwFG/EWKa44hVDVaqDPspxuMkO57oeAmet7XpT3B7uGU4Yf2nQgkWsr25IsC/lHt/YHppv3I5xdHgoapvMGr9S4z82HqfAAdM6+DmZd1amfJy+o1wkyyHgyPsx6+PxeMLntgyxJR5frN6NUvuT5kglj+f6q0V5r7jVjXXumT1VJZAl+3VmVGhs0X2p13FkoRcuIB4EQbV/zR73PvxtcCv2f5LF92dJQpzELPwbSxY8OpSq6YrptATm3xH9rDJdfHrwkBRFw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=k3EvHq/NOfN6/x4VqmHWxeLNRgg0uWVAOQVZnFMrfoI=; b=EXENK4qBNSCX97Fn+EUJKLtS48DcG0HTtvdZEHW8/cbOOru6z+lar8i7LXgYc5xyYFc3a5yVeT7eDnXJvFLAHN1hlkSV7qW1+qg1nFJg9kBNSktWPwLBFDbq8ARjgvGqB4oaj7UlBSlOCX7sf96E9zu3Z+X8+y5MiB+jeXkodgkNHYNi9uSE/uxYiOJeKxkCmVfPHx9xB8B7Q3xW+xMCIXW3iuQwDgPiztd9G1HU07brfM7kqavCqZ6v/COivJcfPtL7X957GithtC6s6fqQcnaHLoTvq3NeHwbT6uj6b3qe9xm/aelCgp7RVGPRd2ewpFRH8TCz0nl10C8Bzss9GA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=iotconsultancy.nl; dmarc=pass action=none header.from=iotconsultancy.nl; dkim=pass header.d=iotconsultancy.nl; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=iotconsultancynl.onmicrosoft.com; s=selector2-iotconsultancynl-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=k3EvHq/NOfN6/x4VqmHWxeLNRgg0uWVAOQVZnFMrfoI=; b=GuqgE3X4wbFcG14+PD/kqDkUrqFISC5amhLg2bdfdwTZ66OoAf78xn1sGqPpme3WrfHUqNoylN2nFFPok7GcPRk7K92OyaU3XWeBfdPFyo902/G+Aa1O2hQ/rLz/rbJqO+PsjFZMSHjrmxegzsb1V8lsY+P4m4mL+PhrvnYco6s=
Received: from AM5P190MB0275.EURP190.PROD.OUTLOOK.COM (10.161.62.28) by AM5P190MB0420.EURP190.PROD.OUTLOOK.COM (10.161.92.161) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2729.25; Mon, 17 Feb 2020 08:15:24 +0000
Received: from AM5P190MB0275.EURP190.PROD.OUTLOOK.COM ([fe80::287f:e6f2:a17:a59f]) by AM5P190MB0275.EURP190.PROD.OUTLOOK.COM ([fe80::287f:e6f2:a17:a59f%7]) with mapi id 15.20.2729.032; Mon, 17 Feb 2020 08:15:24 +0000
From: Esko Dijk <esko.dijk@iotconsultancy.nl>
To: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
Thread-Index: AQHVxLs5a84UpdRvE0O3c4mcfUR7gKfd8DaAgEFZfBA=
Date: Mon, 17 Feb 2020 08:15:24 +0000
Message-ID: <AM5P190MB0275CEAAE1AE5E11BE9C3410FD160@AM5P190MB0275.EURP190.PROD.OUTLOOK.COM>
References: <157833360921.8003.6238594444996424752@ietfa.amsl.com> <BN7PR11MB25472BD695322671615371F5C93C0@BN7PR11MB2547.namprd11.prod.outlook.com>
In-Reply-To: <BN7PR11MB25472BD695322671615371F5C93C0@BN7PR11MB2547.namprd11.prod.outlook.com>
Accept-Language: en-US, nl-NL
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=esko.dijk@iotconsultancy.nl;
x-originating-ip: [2001:1c02:3103:6d00:a978:3cbd:1e0a:ed5b]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d37ae892-bc51-49b8-b26d-08d7b3818a16
x-ms-traffictypediagnostic: AM5P190MB0420:
x-microsoft-antispam-prvs: <AM5P190MB0420C9EE7F64E3E5711A9758FD160@AM5P190MB0420.EURP190.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0316567485
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(136003)(366004)(39830400003)(396003)(346002)(376002)(199004)(189003)(2906002)(86362001)(66556008)(64756008)(66446008)(9686003)(76116006)(66476007)(66946007)(71200400001)(5660300002)(55016002)(44832011)(66574012)(966005)(81166006)(81156014)(186003)(508600001)(33656002)(6506007)(52536014)(8676002)(8936002)(110136005)(316002)(7696005)(53546011); DIR:OUT; SFP:1102; SCL:1; SRVR:AM5P190MB0420; H:AM5P190MB0275.EURP190.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: iotconsultancy.nl does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: P+lerzMoJQSg/M8k8TJU9RowAxo6bEPqNsHC8sa6x+/3q3LfIiJeo721ZbBwrO+zCA13vK2UXQ3Vdw6YtN4JgcfhW00JNsJjghEBW7LPZUBzMq+em6GS7tdxiy8u1bu0QVKTMYh6L+tNWYQVnqRrZVat0n6yo/gs9VVaeMz/oX9i/CIMesN7mpvGVMag6NHYYuDYW4gZ7yyh5HAqwUS3b8xL3kkVB/PZb0aLUwD6x7CBZkkR2EvMpVIJ1KErPLh2WgrZnpVaBWyVnyVzaUYOO+3EQ9wXkz7bQrfu834Sknu33CbDmFBLM9C1XYdrgTEyEcBcPZXaWp5rT19F+wTRRb/NvUJItDx5t1vMm3ZdFKLOw1Z2AtCY3IttbhsMbUhbBy5sZv97KaBBuVgKd47AhjdBtE3gP+6jHE/9VGlaz1PSkkbcX3j00IaMmcrrhn2qrxSmlRJTwD72WUq9BFiSrPcyHpN06GiyLwODi9flcKlDTEw8sYmfRYrkXRlqlr6wIbHKOB9JPnGApriXIDR7dA==
x-ms-exchange-antispam-messagedata: 1naqP525j57Kr2tsbgQgzDrZfXf+2qjxT2YGqlVkyo3/TDs7oir9WO//MdExQZzlkzuQ1xU7wQkbRUULNVKySl+tyr1JDP0hLgqtGic4yTWY5oePcJoyIHrZAWSCF7N08ST4Ovbpx2nNyhxZk2y4wZnhLgYn0uliRIDdlD54m0gk+VPZoeRY8QgCBzrSzXBmZWzlA4l12I6QOXIGj+bxcw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: iotconsultancy.nl
X-MS-Exchange-CrossTenant-Network-Message-Id: d37ae892-bc51-49b8-b26d-08d7b3818a16
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Feb 2020 08:15:24.3411 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 58bbf628-15d2-46bc-820b-863b6774d44b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: nNmPC5SPdhAvl1Ho6Wh+ylBPcMD4gaR7YLnFeRI9XQoxwlRs5eiNIyY6p09rOmkNOhth0bt8mw4L/6+idhdD2n6o6lQF2UTu3wRd511rDVQ=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5P190MB0420
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/lso3dUtnqd54t2IOJI5DqhUtljs>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Feb 2020 08:15:34 -0000

Hello Panos,

I noticed one sentence in Appendix A that seems inconsistent with the rest of the I-D, or at least gives an incomplete view :

   If the client had requested Content-
   Format TBD287 (application/pkix-cert) by querying /est/skc, the
   server would respond with a single DER binary certificate in the
   multipart-core container.

The client here could also have POSTed to resource /est/sen with Accept:TBD287 option, indicating it is requesting TBD287 for simple enrollment, and the server would respond with a single DER binary certificate (application/pkix-cert). So the current text might suggest that POSTing to /est/skc is the only way to request TBD287 format, which is not the case since /est/sen also may support it too.

Best regards
Esko


IoTconsultancy.nl  |  Email/Skype: esko.dijk@iotconsultancy.nl 

-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of Panos Kampanakis (pkampana)
Sent: Monday, January 6, 2020 19:12
To: ace@ietf.org; i-d-announce@ietf.org
Subject: Re: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt

Hello,

This iteration addresses all IESG reviews. More details on the feedback and
how we addressed it are in the git issues here 

Rgs,
Panos


-----Original Message-----
From: Ace <ace-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org
Sent: Monday, January 06, 2020 1:00 PM
To: i-d-announce@ietf.org
Cc: ace@ietf.org
Subject: [Ace] I-D Action: draft-ietf-ace-coap-est-18.txt


A New Internet-Draft is available from the on-line Internet-Drafts
directories.
This draft is a work item of the Authentication and Authorization for
Constrained Environments WG of the IETF.

        Title           : EST over secure CoAP (EST-coaps)
        Authors         : Peter van der Stok
                          Panos Kampanakis
                          Michael C. Richardson
                          Shahid Raza
	Filename        : draft-ietf-ace-coap-est-18.txt
	Pages           : 51
	Date            : 2020-01-06

Abstract:
   Enrollment over Secure Transport (EST) is used as a certificate
   provisioning protocol over HTTPS.  Low-resource devices often use the
   lightweight Constrained Application Protocol (CoAP) for message
   exchanges.  This document defines how to transport EST payloads over
   secure CoAP (EST-coaps), which allows constrained devices to use
   existing EST functionality for provisioning certificates.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-ace-coap-est/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-ace-coap-est-18
https://datatracker.ietf.org/doc/html/draft-ietf-ace-coap-est-18

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-coap-est-18


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
Ace mailing list
Ace@ietf.org
https://www.ietf.org/mailman/listinfo/ace