Re: [Acme] Secdir last call review of draft-ietf-acme-star-delegation-06

Russ Housley <housley@vigilsec.com> Thu, 25 March 2021 20:15 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9E8A3A2BE0 for <acme@ietfa.amsl.com>; Thu, 25 Mar 2021 13:15:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OZhgG7qtSz7E for <acme@ietfa.amsl.com>; Thu, 25 Mar 2021 13:15:03 -0700 (PDT)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 46D433A2BE2 for <acme@ietf.org>; Thu, 25 Mar 2021 13:15:03 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id E228F300BAF for <acme@ietf.org>; Thu, 25 Mar 2021 16:15:00 -0400 (EDT)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id gZqC452PtB6j for <acme@ietf.org>; Thu, 25 Mar 2021 16:14:58 -0400 (EDT)
Received: from [192.168.1.161] (pool-141-156-161-153.washdc.fios.verizon.net [141.156.161.153]) by mail.smeinc.net (Postfix) with ESMTPSA id 9B0E4300AFC; Thu, 25 Mar 2021 16:14:58 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.17\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <14A30220-C467-451C-BE06-2D5836C111FE@arm.com>
Date: Thu, 25 Mar 2021 16:14:58 -0400
Cc: Yaron Sheffer <yaronf.ietf@gmail.com>, "last-call@ietf.org" <last-call@ietf.org>, IETF ACME <acme@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <F4BCA7C6-7AAC-458C-9C96-28D4D231274A@vigilsec.com>
References: <161575930310.2025.16866904323712710819@ietfa.amsl.com> <3DDC13CC-4789-459D-9DA2-E023BC372D8C@arm.com> <2FF4DF9C-2CE4-4E88-8334-D2D953E06BD4@gmail.com> <966179D0-B67B-4CDF-9A4C-CF9F0B1D04E2@vigilsec.com> <51B3FE70-67D4-4F6F-8F5D-43182186F55D@arm.com> <D525861A-5B91-47B5-92A1-7C312C514BDA@vigilsec.com> <E4734052-E56F-4321-A3C3-79C38F8DAC96@gmail.com> <9164FE04-FF66-44D8-888F-790B9E294CD4@vigilsec.com> <14A30220-C467-451C-BE06-2D5836C111FE@arm.com>
To: Thomas Fossati <Thomas.Fossati@arm.com>
X-Mailer: Apple Mail (2.3445.104.17)
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/VfzOZih-4gL8aIGVtzMw0K-CQxo>
Subject: Re: [Acme] Secdir last call review of draft-ietf-acme-star-delegation-06
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Mar 2021 20:15:09 -0000

Thomas:

As I said in GitHub, I think the Abstract could be more clear.  There are two key points. First, the certificate contains the identifier that is delegated. Second, that the third party has control of the private key, and the certificate contains the corresponding public key.

All of the other topics have been sorted out.

Russ


> On Mar 25, 2021, at 4:02 PM, Thomas Fossati <Thomas.Fossati@arm.com> wrote:
> 
> Hi Russ,
> 
> On 25/03/2021, 19:28, "Russ Housley" <housley@vigilsec.com> wrote:
>> 
>> You will see my comments in those issues.
> 
> Thanks very much!
> 
> We have prepared https://github.com/yaronf/I-D/pull/167/files
> 
> Could you please review it and see if fixes your remaining concerns?
> 
> Cheers, t
> 
>> Russ
>> 
>>> On Mar 25, 2021, at 10:28 AM, Yaron Sheffer <yaronf.ietf@gmail.com> wrote:
>>> 
>>> Hi Russ,
>>> 
>>> Please see the remaining open issues from your review - we have
>>> reopened the GitHub issues:
>>> 
>>> https://github.com/yaronf/I-D/issues/139
>>> https://github.com/yaronf/I-D/issues/145
>>> https://github.com/yaronf/I-D/issues/146
>>> https://github.com/yaronf/I-D/issues/147
>>> https://github.com/yaronf/I-D/issues/148
>>> 
>>> Thanks,
>>>    Yaron
> 
> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
> _______________________________________________
> Acme mailing list
> Acme@ietf.org
> https://www.ietf.org/mailman/listinfo/acme