Re: [Acme] New Version Notification for draft-ietf-acme-star-delegation-08.txt

Thomas Fossati <Thomas.Fossati@arm.com> Mon, 10 May 2021 18:07 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1B203A25B6; Mon, 10 May 2021 11:07:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=lyBYnWf4; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=lyBYnWf4
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jS63sxPMSwjn; Mon, 10 May 2021 11:07:26 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2065.outbound.protection.outlook.com [40.107.20.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9BA873A25B4; Mon, 10 May 2021 11:07:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=qWeF96Hv2RHVt20cMShS4w3KxodJSbayA61W3tctiBE=; b=lyBYnWf4BVApXNO/wlkrPYYItYLJ7u2DvRmJcnyqsyP/vu9zNr1PC088SePVgH5sUOLr3Q4ZdHB8SQCKAnSM21TnynyjIMJO0fzMEUUPOVtzPgsb6bQWyINM2clPG0QYXzqe6FjbOgUDQpjAxMLROT2gFL/Ur7bpnMrWaXShfcY=
Received: from AM5PR0701CA0050.eurprd07.prod.outlook.com (2603:10a6:203:2::12) by AM9PR08MB6146.eurprd08.prod.outlook.com (2603:10a6:20b:2db::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25; Mon, 10 May 2021 18:07:17 +0000
Received: from AM5EUR03FT043.eop-EUR03.prod.protection.outlook.com (2603:10a6:203:2:cafe::4a) by AM5PR0701CA0050.outlook.office365.com (2603:10a6:203:2::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4129.12 via Frontend Transport; Mon, 10 May 2021 18:07:17 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT043.mail.protection.outlook.com (10.152.17.43) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.25 via Frontend Transport; Mon, 10 May 2021 18:07:17 +0000
Received: ("Tessian outbound 13cdc29c30b8:v91"); Mon, 10 May 2021 18:07:16 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: f75de3889ffbf364
X-CR-MTA-TID: 64aa7808
Received: from 2faaf12c7d57.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 4D499121-3F40-47FE-B271-483CE1357C64.1; Mon, 10 May 2021 18:04:01 +0000
Received: from EUR04-HE1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 2faaf12c7d57.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 10 May 2021 18:04:01 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kuPB0FTFWUgmy+PYt2xfQifXPqehuJWSV0NzMCfstRAJBw64PaAqvZnm/XFitExR+ZA62zGf7J0GhUtsZuLArrdkkvPhhfekENwzczlolj27HxFoJVRLYcOuWSvAhrAQGNvBtDzBFOgIeZzNA0kDK8DsjInlmjBDIOLsMlXX+bbnRTFbSfm0uAVAtDSi+OJDG+L6reL2hWvWMCVyVRuXPh5Wf2bUXxwDnxexL85+r5gPwaNDa5OD9W/wh4tmOMuuMmXL9sqAR22V44miB06iFPPQVnEviqVn0Xpn+PAFxk0OSv4AZk4wsflL+W3SDqHDjPyZzEvI+w4O2g4P09yukg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=qWeF96Hv2RHVt20cMShS4w3KxodJSbayA61W3tctiBE=; b=Z9JcjwBXo1+GqT1oWkumwJx5x+3cvaMzbIuKPI68ioSdOjZOQU8givxiQjMpsYqi/Q24e0PQlA5BpDozTLNAsUd2iy1HiOXidOVgQWddYoTY+fIvmMDQODi9coiz4g3pxlLKKdDe4DygxuJLmaHM8pWuyiUJozuRR3YOA86N3pnJt3IrTQvFaANALeGJYi217C4J5DI8Hb7hcI/+xdpeKJPvyzkmpRJb9ftqYHgh1kwrP6ldcT4b+GUZ8rW0UwsuDPdchIApJ3eyGteryyruqjxyO/52jd+vxtNHtXKJtJgWrPQrHcEvO6uJBJ6pqXyCnfv9z77mQBRZ934rpn7nYw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=qWeF96Hv2RHVt20cMShS4w3KxodJSbayA61W3tctiBE=; b=lyBYnWf4BVApXNO/wlkrPYYItYLJ7u2DvRmJcnyqsyP/vu9zNr1PC088SePVgH5sUOLr3Q4ZdHB8SQCKAnSM21TnynyjIMJO0fzMEUUPOVtzPgsb6bQWyINM2clPG0QYXzqe6FjbOgUDQpjAxMLROT2gFL/Ur7bpnMrWaXShfcY=
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com (2603:10a6:10:251::8) by DB7PR08MB3099.eurprd08.prod.outlook.com (2603:10a6:5:26::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4108.27; Mon, 10 May 2021 18:03:58 +0000
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::e9e7:ea3a:3bca:5b3c]) by DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::e9e7:ea3a:3bca:5b3c%7]) with mapi id 15.20.4108.031; Mon, 10 May 2021 18:03:57 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: The IESG <iesg@ietf.org>, Richard Barnes <rlb@ipv.sx>, Carsten Bormann <cabo@tzi.org>
CC: "acme@ietf.org" <acme@ietf.org>, "draft-ietf-acme-star-delegation.all@ietf.org" <draft-ietf-acme-star-delegation.all@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-acme-star-delegation-08.txt
Thread-Index: AQHXRcPRO9P5T/7ToUCOSAw924W1nKrdEusA
Date: Mon, 10 May 2021 18:03:57 +0000
Message-ID: <0C87D451-052C-4233-8FDE-EE4BFD5DD308@arm.com>
References: <162066852357.13569.18000542013377602308@ietfa.amsl.com>
In-Reply-To: <162066852357.13569.18000542013377602308@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.48.21041102
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [82.12.10.179]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 507f8cef-d9ae-41c2-f615-08d913de7291
x-ms-traffictypediagnostic: DB7PR08MB3099:|AM9PR08MB6146:
X-Microsoft-Antispam-PRVS: <AM9PR08MB6146DBBF26A1576FA99C16D29C549@AM9PR08MB6146.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:9508;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: MDrITxpAzjQRr2d7GBzxkzasJ/OtKNVuSSa+bbB21dVeA3gr8JnVKl6qE0n2WbIr9/y3zlWAZBmqKnkOjr37YGGDRYmKGMe3FpplYxcX2Vw4p46Ox0eMS2X5/GiZqjDkedCIP0CnwAJYk9kKQkr+e4DShgHt42GflfxZld5wB3MKg5gTcqIWoC6NeVJ57YLwkCvfV/5E14OjnYgoQTdspayC1Z5O7wbABC7IW+up5kXiQwgYcb3ME9pY8B3FM8gaKQgWeN0zrGM3XTUWW9FyPxw0SKzWyrTOP9y0Bs+7LxhxkgkG4uAdrgjSgkD5r1GtbzLVadW9tR/LuhxJK7xMIGAzUpvKYySy4FG95RrNVABqxLnQEBpDNaQ6ZyE7hFb49itErj4gJ5MgMbvDprRXS9gBo4rc8FiTKQsyOYYTKp5CD04CKawgYiCnsq2RaGncs6pyRjpizAXo0kZNhxMmm4VcF0a3N/cDOBUDl6+WAbJu3AASfIymtzgrF0F52/CwCPbW1fzyWlmKKlZhyo5vFUiVZrw5846h/EtIz+oRfbqANzZM2dkdgiu/GTD6yFjM9B0spLZDiwhIfRO+eWQkHGfiWOoxK96vmfp/ilz2zQB2mqP/mVNFbJ6MQVy2hJEq2VQVFfOYHmXA9TfFKroBUkNfKts+EgRaav/J0RKfE0NL0zIpwQBSu3AYUbZyAhyceb6x4kv3bi99Xhs1OR79P6DtRcJ30pq676pRSjRh/Ob1GY3bcQLhrjpjlAf/EowzFGFkr2+n5O2NcolYr1zNLg==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9PR08MB6524.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(136003)(376002)(366004)(39830400003)(396003)(2906002)(66476007)(4326008)(71200400001)(6506007)(33656002)(2616005)(66556008)(8936002)(5660300002)(8676002)(91956017)(66946007)(83380400001)(76116006)(966005)(478600001)(54906003)(26005)(86362001)(110136005)(6512007)(36756003)(64756008)(66446008)(316002)(6486002)(15650500001)(186003)(38100700002)(122000001)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: b/KWaU8WQtm2bLYsNvgk2uRL70vg4L3GlZZaqBM7kzpAjNr+J+CqCoM2VvtBz3nBP7ina6AyMv8h3XjzAXGkhkf948bOGp/RF3T19iekxyhnGI84LCuz/eIU/bvyKniaVDR+gTDqXmvFEq3/b4mj3ysXUVes7I76WMZuAakhA/A+aSnZTR8X9qSgMfS1EARYDgtS2Ub0N7PXCgnaFQJgsnIwXVnJMg6F3SNTOnl5RCzWkhFc7zJKHpUuL3b2IDKu6d/IMSbV/DFcdbYGJ9oU6CQev3ZeEzuzasfM0elDrdC9Vnc7OQWZVvFRUH3tpm7woSg2i1apxw/E/qfDTBiTgDUhJKzhQkAEzOfjTiktxS1jq5Vf8ZxAk6HGwTMEsAgZhI3y8dFrlQPy2SReH0KJbqMG6z2y61zVt3U+nW7nLhRWuyXXJ1puYFdfPMdont6GBR1WHgcgAUrdiOghWlRUBv738dRcqKeApryiZMhR6OXWjt53uilHQiCfrxpkBLlE9guLol+r7X+oaRB7pAXqpxaAKOzYAh5gsDqEJPiodWW3VWTqvE+CzCs4tjspKypY1/qzDtLkORmHo0uWOrSWWvc9mejvGJ0c0uPbEMYMYRbjj+DdulAZl6pAjA25PjAsncKmN5/Cm8UnCcR+jsV9rmKNINs1eZkfSRVqQ14j5+gSLvoNTuhdX8aWLdJDPbwiEbs36FNZ64w9NgahYegeLmxyGoEReGysCd/KJHS6jYNcqTM8ya5RrN68DQ7+JXZSPcoiRNs3t+YMvLGtK7xbbFH3kxfqq9d+I60N4oDlI9oejEOPlGOWoQ2fC75Y/EUR9AWmZm9BM2uZuFb21GGGFs05OJ6za4ciivuSfrLzslMj6m+YHcNVKnu5zyELmS+dYa4SFOJAcxsS46VKzjCX2qD7a52EkY1nBtl9kAvoiMIlGKm7LMLxphJJWIbSjXxnOxpg3lkzhNWI1d4fEYJRzd/+LkIq815ElsoYha4kBoxCKPp9CT6Das6WM8gfNAB875Ou3Mql0VVI6uNjEcKxFQ7Z4eSqRM7kt3AoxZDs+GwTM8wzSHZWYCbdIjPpKaHQkMmCqjO0Pa3AVc1Ekh4ZpwmUh0BNoJXPecDn+VWL8YLj7Zvqa6AxL+Ho+DP61R6jUe3RjBS9MMqhc92pBEKMEjHZFC7VzXLc/Qt8DzbD/Xzs39N9MtJAytyKHiy5XUXI+A1fdvBJHfiHD98+hYIesImjOROhoUd0VKVz20uP8VRNoZqCCYFrl1oPZjgo0m1AyqgqAF/ARBdGm4JKRPZR78JBxxy5BX1pmgASBb40ZWQ96cMi2LCOpP7TzgkFIga8
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <85B91D86ACD74443B4FBE8A6CBA054BA@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR08MB3099
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT043.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: d36ca8f0-4557-480c-41ae-08d913ddfb5e
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: OFVM5E18rJKdIFTKDS/ViqqoubEb4K4l7jPljwulKBz4fL31r3A/gox6ebDpJ5Bo6GuXgM2fx095ZIKFEaABZrGGJq9Crc2wPBmoJ6LX+0Qfxd2n8OmstDFP9rwRg6/oP9hTzxVAfR2tKbaXkaQrK8i2cMEZTBN77ykIlyOCDVydxJV1n6r+EV868nHzFZieg4a5dfYCsbgJGToBrx0Fep73xsH8zj0dbeRq8+jkuO3ASt5bLr4b1J/7EtSEycq2Iv/1pIcVFzJ3KHzszkNrDhXYUzGGtEO9pg5D6awxwyliF9bkwPuV0K5ARkPoXaQu/PslCNuu6PvySa2kyu25cbC93V0L8AxAm7K/aM4LYZiM+a/kAYrnfINp0NG4o+gbOHt4ok4KWmEfxoaX0DrjFS2sHVaClBuGVSDur13S0V46Kj1KPyE+wXXfW4isyw8F4KfxAEB3XqyGO/8eJm1Olk0KgPKoOivWDBtcGVB18ku5WXkRxmGuUaHNTQFNBLBf5krixASwj85LhmXoh8r6ae2YlIffOGFndrv9Pf3xByJnPEJJo93UUbuvWPLLChcqsjSp8hQFWbC6YUMNEV+uPB4T1PkNjsmAIgehwFKk8PvNoUuWMfP4tPQ77YQAsJ5gyLe0SUdOXf29khrRswV8anULyGHLuI8UPvpNZFoF+Z5rsVo+n7s+32UBZoudI9JcGeN6Lkn9K5z+5Hu1AcNGgMeZhzfzvLhnzp1M5mm+KYfblhwnsCXFRc2xJzsIyP24/XpRFoLzI+gPdcpFFTcesw==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(136003)(376002)(39840400004)(346002)(396003)(36840700001)(46966006)(86362001)(36860700001)(6506007)(478600001)(15650500001)(36756003)(83380400001)(2906002)(966005)(70206006)(336012)(70586007)(33656002)(5660300002)(8676002)(2616005)(6486002)(356005)(8936002)(82310400003)(26005)(450100002)(186003)(4326008)(6512007)(110136005)(54906003)(81166007)(47076005)(316002); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 May 2021 18:07:17.4563 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 507f8cef-d9ae-41c2-f615-08d913de7291
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT043.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9PR08MB6146
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/T4qZwBB8SELaqnuFXX0hN0w1clU>
Subject: Re: [Acme] New Version Notification for draft-ietf-acme-star-delegation-08.txt
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 May 2021 18:07:29 -0000

Hi all,

We have just published version -08 of the ACME delegation draft [0].

We think it addresses the feedback we received from the IESG (all the
DISCUSS positions as well as the vast majority of the COMMENTs), plus
Carsten's review over the CDDL and JSON-schema bits, plus Richard's IANA
Expert review.

In particular, see below for a summary of the three main DISCUSS
positions and the corresponding actions:
* Missing IANA expert guidance (Lars and Francesca): added;
* CDDL and JSON-schema review comments (Francesca): addressed Carsten's
  input;
* Delegation scope (Richard): moved from per-identifier to per-order.

It took us a while, apologies for the delay, and many thanks to all
involved.

We have tracked each of the reviews in separate Github issues [1], which
you can use (if you want to) as a starting point to follow any further
discussion inter nos, and the resulting edits.  Otherwise you can have a
look at the massive diff [2].  Yet another alternative is the clean,
synoptic view of the changes in Appendix A.1 [3].

We will follow up on Ben's review in a separate thread as it may require
some further back and forth.

Cheers, thanks!

[0] https://www.ietf.org/archive/id/draft-ietf-acme-star-delegation-08.html
[1] https://github.com/yaronf/I-D/issues?q=is%3Aissue+label%3A%22ACME+STAR+Delegation%22+and+label%3A%22IESG+review%22
[2] https://www.ietf.org/rfcdiff?url2=draft-ietf-acme-star-delegation-08
[3] https://www.ietf.org/archive/id/draft-ietf-acme-star-delegation-08.html#section-a.1









IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.