Re: [Acme] Fwd: New Version Notification for draft-sweet-iot-acme-04.txt
Sebastian Nielsen <sebastian@sebbe.eu> Wed, 02 August 2023 17:41 UTC
Return-Path: <sebastian@sebbe.eu>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 117B9C151984 for <acme@ietfa.amsl.com>; Wed, 2 Aug 2023 10:41:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.107
X-Spam-Level:
X-Spam-Status: No, score=-7.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sebbe.eu
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fJ7S2mvo_7qF for <acme@ietfa.amsl.com>; Wed, 2 Aug 2023 10:41:19 -0700 (PDT)
Received: from dns2.sebbe.eu (dns2.sebbe.eu [IPv6:2001:470:dff1:1:10::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0E05DC16B5BF for <acme@ietf.org>; Wed, 2 Aug 2023 10:41:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sebbe.eu; s=root; h=Date:To:From:cc; bh=yqYW6bouyc5bvF20mQwTdewP9Rd84SDWq0YOUtTGaX4=; b=n4Bcq4x/g38OEkwTYJF5f3hOCLHGolgllT6UlxKScUTzp3ji+DgyM0BeH9CjyhKstnWRg9EPT+ azRB4WK5abTsSVGHKtL9rnNmGfMrYZ34M31fdgUVJ3R23d7rp8Z/9u5onFRauGUaUgUFNwZxTatMZ GIl4S4yjCXGJSdZYigmE=;
Received: from localhost ([127.0.0.1] helo=sebastian-desktop) by sebbe.eu with esmtp (Exim 4_94_RC0-31-83e8da8c0-XX) (envelope-from <sebastian@sebbe.eu>) id 1qRFqJ-000D1M-Kb for acme@ietf.org; Wed, 02 Aug 2023 19:41:03 +0200
Received: from [192.168.1.188] (helo=DESKTOPA5BEHQI) by sebbe.eu with esmtpa (Exim 4_94_RC0-31-83e8da8c0-XX) (envelope-from <sebastian@sebbe.eu>) id 1qRFqJ-000D1J-By for acme@ietf.org; Wed, 02 Aug 2023 19:41:03 +0200
From: Sebastian Nielsen <sebastian@sebbe.eu>
To: 'Mailing List' <acme@ietf.org>
References: <169099211414.11957.13218136675686326535@ietfa.amsl.com> <C33D08FE-DB2A-4319-9FCD-45B6C2379D55@msweet.org> <CAOG=JU+Mp5SrP2mxeG==tRd+b9LLw3+KU3YcA7Dkx4yuk_G6Bg@mail.gmail.com> <006b01d9c565$35b148c0$a113da40$@sebbe.eu> <CAOG=JU+74EamEG+0OzNV5vG-Fia6dXRy57Y95180k5gt6owRXw@mail.gmail.com>
In-Reply-To: <CAOG=JU+74EamEG+0OzNV5vG-Fia6dXRy57Y95180k5gt6owRXw@mail.gmail.com>
Message-ID: <00c201d9c568$82baa140$882fe3c0$@sebbe.eu>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_00C3_01D9C579.46440D80"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQFyCAfi5epXzZ2YAJPgq2oxnWYfWgE2sAicAkiqeYUA4s06TwIEVjRZsHOK4XA=
Content-Language: sv
X-Encryption-Target: external
Date: Wed, 02 Aug 2023 19:41:03 +0200
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/DjKrUJyWqF81EnLmao4JOaVRPyw>
Subject: Re: [Acme] Fwd: New Version Notification for draft-sweet-iot-acme-04.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Aug 2023 17:41:25 -0000
>>Then why use ACME to begin with?
What I understand it was to make it easier for “newbies” to set up a device. So the device can automatically do “inclusion” of itself once it connects to a network.
I see no security problems with allowing longer certificates, since the certificates are only locally used, and hard-restricted to the particular network that uses the certificate.
For certificates on the internet, its important with short lifetimes, revocation and such, since there unauthorized people can get on board. For local networks this isn’t a risk.
A non-revoked certificate is only a risk if a malicious actor gets its hand on a device after It changed owner, what my suggestion of mandatory reset if it is not connected, or connected to a network the device doesn’t recongnize based on certificate AND a new user is paired through a method that doesn’t require cooperation by a already paired user/device.
These 2 circumstances together is clear evidence that the device itself is not being owned by the same user anymore, thus it should erase any keys and certificates for security, both so the new user cannot act maliciously against the old user, AND so the old user cannot act maliciously against the new user.
Best regards, Sebastian Nielsen
- Re: [Acme] Fwd: New Version Notification for draf… Amir Omidi
- [Acme] Fwd: New Version Notification for draft-sw… Michael Sweet
- Re: [Acme] Fwd: New Version Notification for draf… Sebastian Nielsen
- Re: [Acme] Fwd: New Version Notification for draf… Amir Omidi
- Re: [Acme] Fwd: New Version Notification for draf… Sebastian Nielsen
- Re: [Acme] [Iotops] Fwd: New Version Notification… Michael Sweet
- Re: [Acme] Fwd: New Version Notification for draf… Michael Sweet
- Re: [Acme] Fwd: New Version Notification for draf… Carl Wallace
- Re: [Acme] New Version Notification for draft-swe… Michael Sweet