[Acme] Re: [IANA #1451549] expert review for draft-ietf-acme-device-attest (acme)
Aaron Gable <aaron@letsencrypt.org> Mon, 18 May 2026 22:53 UTC
Return-Path: <aaron@letsencrypt.org>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C0718F063BE3 for <acme@mail2.ietf.org>; Mon, 18 May 2026 15:53:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779144782; bh=nLXNXS7F3vB98QfHMGEKhQb0OED7Z91/2GYex9w4Rhw=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=BTDucUPhKNGSlUNYPA/beqLlxzzGAIrzPKXqJDwSiXnLwIpFnb9HkUyLBXVFfOSXQ 4PeTNnDQDfCV9KUNEy+hCrAV0MhRbNK0ORruTKHUBifgcxcy+/eI9wKnloLPbuUSQQ a9p5CKR49d7MZZI0wnrKRCI6HSUMEnmSEWpRVjik=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=letsencrypt.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RZyceR-qn8q7 for <acme@mail2.ietf.org>; Mon, 18 May 2026 15:53:02 -0700 (PDT)
Received: from mail-ot1-x32c.google.com (mail-ot1-x32c.google.com [IPv6:2607:f8b0:4864:20::32c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 45DCBF063BDC for <acme@ietf.org>; Mon, 18 May 2026 15:53:02 -0700 (PDT)
Received: by mail-ot1-x32c.google.com with SMTP id 46e09a7af769-7dccb8644c4so1646158a34.0 for <acme@ietf.org>; Mon, 18 May 2026 15:53:02 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1779144781; cv=none; d=google.com; s=arc-20240605; b=lPdEIbiBU+S+P4jmBw04sYdN6yGq5TwZ3Kkt+10WZkc8nlq+T3gK6C4eqvmK3BKit/ FsCdJcJC24vSHL9AZi3p6BsJvtmfrIPS4OOFl1MLI0hXJLVrOp7tAYGFkUURITt+TLFd NLnXlnrvxCwM1VeKfPDOp1dB+DoG0loQnNdAXifZK69c9AMqiDeOUEQEVqPH9SmSCvbv ptp4jq07XuQ2ZUH/V42wMvbwtRMD/nDjtU0mjAuXD/nZpz0nwxEFIQQ4jflg/TEFNwod CO6QGsyj1CdhKliTjcLAazkwZEPbNXwRSwiCMfF8CwzisxOonNOSPLIwvuutmMoFKtFd rR+Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=k7TJ9OzrO+Q3m7E4kZn+ZINst23YzCIAdoGxInZIDBk=; fh=YCC0lYF5dBR7X1aUY2ixmw2s15CAUaw3Uld7/Lj4RKk=; b=K3A9Ey9bJHEfIAfiYg3mni3uSlN8iq7Znk8UDX4cb1H3QKLMxDv29ff9h0k7vois/e gVU+l7/BnCIxuIGjgQatsLlZ9d+jnn4vOX2qXfu9ndKCKnm5tuChNFQQtz9woa9GBozk 8c22RAZP0pSS1xw3NcegjepPKuHgdaPpPWH96nZwAKuoZ8E83doIaWyDtAnItydsN2sQ MXrePDIuoKNkO9FJVM+tHiJR8PHbqbU1pC4WFKUB9Y1DwIzFEOGEQ2IhH4+INVramlKR rbpEHV8qOF2QlqBH4pAUYPQWNuc8GSEIq+CPwCH4Ua+sQn7OQhlOJZmJxIi8nUuJygZW ABmw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=letsencrypt.org; s=google; t=1779144781; x=1779749581; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=k7TJ9OzrO+Q3m7E4kZn+ZINst23YzCIAdoGxInZIDBk=; b=UNc3T1kvKLGvTEUb2qclcpzx0bjoVwBs96AcW28wQJtKk8/zDnbAq0UiE0CwKEaYam Ykj3yb9yNDDDA94bo7ISZfekTkOCpcXlXZ1oOCkenIvZwQKsgfZuPFejTbEXbxayBZcO SnYp9aWp68O05JhQOeJCghcLkWLeGIc1OzF50=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779144781; x=1779749581; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=k7TJ9OzrO+Q3m7E4kZn+ZINst23YzCIAdoGxInZIDBk=; b=T8XOVt/0Kk+FrqRudKt/Sww9tvIs59Z4qy7bYMfB8GEBE1gSIl8NOut7EAxCuflQ8K GXpy4paqnZLNg+34AhROTGtvikw7lak/8FVQpHgxvm0GhBQ6PaPRdieIWEZ6pZFRD6dO buAGG+jVPjbs9pLE7pEIxNenWFccmoaHtRJK3dhWR4oLlNKGdkEHwkSzAhS9WOnp3tDw xMp8MhBqICRHZ97Lsiq10Fs64pHArfVABRjZPzyNbtLDpQi0nzxpPupry5cbwtWbelDA YV9/3bjYkIktdgl2/I2Bhfc6BN6VbkTmegfnNITdC9JSA1lURD7SQA7NRgHFGV+XSKSf ZWOg==
X-Forwarded-Encrypted: i=1; AFNElJ/md5cgUks/vRjC6Xe1rm2dLv8vy78TDBKjQJ9Fv/AG5WKvIIWWoRe3w6Pgpm/yUD4WeiCZ@ietf.org
X-Gm-Message-State: AOJu0Yzc3w6dcdhM+WoEgwv91ralREsfzr0wtyEoP3GZgGtvO0eGxwmf nbGljmVvxQubmaL2R0fNii6Gx8X9xJcGUW7fVO3103Jol2kz076fnLP12Bxe6csJIB80oEcW3I1 In+1Gg6Eoe9a6M+i4rM293Hm5x1KuRII1B1Wa2JOIEBW84nltszwgeXF6Eg==
X-Gm-Gg: Acq92OESVjb3h8oVEiBDy4nDyJnuZr8i0/raMkDEGUnE6K2eG7kqwJSxcw+o9CIyeFE 4+0H4TewOt4VLksx2/s4jCQPIJD4q3dv77M6yFFCPgqLfHmI4rSRgm8VXuRup5kQnYfYQ6YS6Zi NCt34y+K3sv0z6gXBm/viBHKjSFUQZDsLMq7WpaE0C7zXjpcaX7UsuKIOHo6Za3O3EQMOkuoisU aCGE51Ic9/HVRup5ZQzos3jtM54oS56kybE2ic7Jl4vB+Z1a4yJ8LpYBMZlSnKSJhwcgUSDOtDS e2TqzFX9D3hhorgY0g==
X-Received: by 2002:a05:6830:4991:b0:7dd:9b19:a87b with SMTP id 46e09a7af769-7e4ea072138mr11284749a34.4.1779144781554; Mon, 18 May 2026 15:53:01 -0700 (PDT)
MIME-Version: 1.0
References: <RT-Ticket-1451549@icann.org> <rt-5.0.3-1056850-1777940412-289.1451549-9-0@icann.org> <rt-5.0.3-1262025-1778103671-706.1451549-9-0@icann.org> <rt-5.0.3-1270697-1778104046-1248.1451549-9-0@icann.org> <rt-5.0.3-725389-1778873757-1259.1451549-9-0@icann.org> <CAEmnErfp5_zmbkd09S2nq4N9OC4zH4=KAsZxpyb8TDJk_5J+5w@mail.gmail.com> <DS0PR14MB621685404C65FE3542448AE992032@DS0PR14MB6216.namprd14.prod.outlook.com>
In-Reply-To: <DS0PR14MB621685404C65FE3542448AE992032@DS0PR14MB6216.namprd14.prod.outlook.com>
From: Aaron Gable <aaron@letsencrypt.org>
Date: Mon, 18 May 2026 15:52:49 -0700
X-Gm-Features: AVHnY4Lj06KrkrjWKk_JgauXDdZXTyJNJ5xyjp74PlYpvtikvCVeElZzTuJV-h4
Message-ID: <CAEmnErc4ykrncHBKzOW149bsHtQuQB396diHwTFD8UG3w=yYpA@mail.gmail.com>
To: Corey Bonnell <Corey.Bonnell=40digicert.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000b575f906521f6c9e"
Message-ID-Hash: LRKK47SAO6E5KNXMIF4ZPXNPDFBRRCVI
X-Message-ID-Hash: LRKK47SAO6E5KNXMIF4ZPXNPDFBRRCVI
X-MailFrom: aaron@letsencrypt.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "drafts-expert-review-comment@iana.org" <drafts-expert-review-comment@iana.org>, "rlb@ipv.sx" <rlb@ipv.sx>, "acme@ietf.org" <acme@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: [IANA #1451549] expert review for draft-ietf-acme-device-attest (acme)
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/frMAYFDxPZHWDoGV1tJyHr1ZEy4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>
On Mon, May 18, 2026 at 6:42 AM Corey Bonnell <Corey.Bonnell= 40digicert.com@dmarc.ietf.org> wrote: > Hi Aaron, > > Thank you for another careful review of the document. We have proposed > fixes to address the three concerns in this PR: > https://github.com/ietf-wg-acme/draft-bweeks-acme-device-attest/pull/24 > > > > The first two items are straightforward, and the fixes should be obvious. > However, the third is more complex. > > > > I reviewed the ABNF for object identifiers in RFC 3061 and believe it is > defective in several ways: > > > > 1. It allows only one component. Per X.208 and subsequent updates, at > least two components are required. > > It allows multiple components. The top-level ABNF rule is `oid = number *( DOT number )`, allowing arbitrarily-many dot-separated numeric components. > > 1. It allows any number for the root component. However, the only > allowed values are the values 0, 1, and 2 per X.690. > > > 1. It allows any number for the second component. However, if the root > component is 0 or 1, then the second component must be between 0-39 > decimal. Several DER parsers also enforce that the second component be > between 0-39 even when the root component is 2, but that is more > restrictive than what is prescribed by X.690. I have no objection to > modifying the ABNF to enforce this, since it’s highly unlikely there will > be real-world breakage and would simplify the grammar by doing so. > > These are good points. (For the sake of posterity, it is not X.690 which creates these constraints; rather X.690 takes advantage of these constraints to enable a dense packing of the first two components into a single byte. The constraint is established by X.660, Section 6.2.1. And both the constraint itself and the BER/DER encoding taking advantage of it have prior precedent in the X.200 series, but the history there is murkier for me.) The ABNF you've proposed in the PR looks good to me, though it does still feel ridiculous that there's not a better document to reference for something as seemingly-common as producing an OID. Thanks, Aaron
- [Acme] [IANA #1451549] expert review for draft-ie… David Dong via RT
- [Acme] Re: [IANA #1451549] expert review for draf… Aaron Gable
- [Acme] Re: [IANA #1451549] expert review for draf… Corey Bonnell
- [Acme] Re: [IANA #1451549] expert review for draf… Sebastian Robin Nielsen
- [Acme] Re: [IANA #1451549] expert review for draf… Aaron Gable
- [Acme] Re: [IANA #1451549] expert review for draf… Corey Bonnell