From nobody Wed Aug  2 10:17:37 2023
Return-Path: <sebastian@sebbe.eu>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id CC110C14CE3F
 for <acme@ietfa.amsl.com>; Wed,  2 Aug 2023 10:17:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level: 
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001,
 RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
 T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
 URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=sebbe.eu
Received: from mail.ietf.org ([50.223.129.194])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id IHHn1_YyvR5C for <acme@ietfa.amsl.com>;
 Wed,  2 Aug 2023 10:17:31 -0700 (PDT)
Received: from dns2.sebbe.eu (dns2.sebbe.eu [IPv6:2001:470:dff1:1:10::2])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest
 SHA256) (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 06CA4C14CF18
 for <acme@ietf.org>; Wed,  2 Aug 2023 10:17:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sebbe.eu;
 s=root; h=Date:To:From:cc; bh=0LeX+z6nbdYEERsNC0tdA+B30ha1+uX6194vJlWHK8s=;
 b=bGRP4CMsJ8LtYi68/CUNfS4xLGH9CqfFFpf9Y2owjtGWPzPlRVmzCn6EZ2rCKAq+3alIW+n4Ml
 hqqVtkR8gFfvlJvZf6EGsbPPipydKcxrX27YpTOkmjuFkleSeEb4ycSEwz8IAotWYugQv0RGgApgl
 CjKIRbramwPwwPbLGfuU=;
Received: from localhost ([127.0.0.1] helo=sebastian-desktop)
 by sebbe.eu with esmtp (Exim 4_94_RC0-31-83e8da8c0-XX)
 (envelope-from <sebastian@sebbe.eu>) id 1qRFTS-000CvZ-0B
 for acme@ietf.org; Wed, 02 Aug 2023 19:17:26 +0200
Received: from [192.168.1.188] (helo=DESKTOPA5BEHQI)
 by sebbe.eu with esmtpa (Exim 4_94_RC0-31-83e8da8c0-XX)
 (envelope-from <sebastian@sebbe.eu>) id 1qRFTR-000CvW-L4
 for acme@ietf.org; Wed, 02 Aug 2023 19:17:25 +0200
From: "Sebastian Nielsen" <sebastian@sebbe.eu>
To: "'Mailing List'" <acme@ietf.org>
References: <169099211414.11957.13218136675686326535@ietfa.amsl.com>
 <C33D08FE-DB2A-4319-9FCD-45B6C2379D55@msweet.org>
 <CAOG=JU+Mp5SrP2mxeG==tRd+b9LLw3+KU3YcA7Dkx4yuk_G6Bg@mail.gmail.com>
In-Reply-To: <CAOG=JU+Mp5SrP2mxeG==tRd+b9LLw3+KU3YcA7Dkx4yuk_G6Bg@mail.gmail.com>
Message-ID: <006b01d9c565$35b148c0$a113da40$@sebbe.eu>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_006C_01D9C575.F93ADC10"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQFyCAfi5epXzZ2YAJPgq2oxnWYfWgE2sAicAkiqeYWwirilQA==
Content-Language: sv
X-Encryption-Target: external
Date: Wed, 02 Aug 2023 19:17:26 +0200
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/gorsT_JLb_7aoyprNDSGnu071bI>
Subject: Re: [Acme] 
 =?utf-8?q?Fwd=3A_New_Version_Notification_for_draft-sweet?=
 =?utf-8?q?-iot-acme-04=2Etxt?=
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>,
 <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>,
 <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Aug 2023 17:17:35 -0000

This is a multipart message in MIME format.

------=_NextPart_000_006C_01D9C575.F93ADC10
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

7) Validity of certificates:  =
<https://www.ietf.org/archive/id/draft-sweet-iot-acme-04.html#name-iot-de=
vice-certificates> =
https://www.ietf.org/archive/id/draft-sweet-iot-acme-04.html#name-iot-dev=
ice-certificates

=20

>> I disagree with short validity.

If the certificate is restricted to local domain names only, I suggest =
allowing validity up to 10 years.

=20

HOWEVER, if local certificates should be accepted by browsers as root, =
THEN there must be a mechanism, similar to DNS Rebinding protection, =
that prohibits an external site (that are not an RFC1918-IP or local =
resources) or a resource received externally (for example an email) from =
hyperlinking or redirecting to a .local resource, an private, loopback =
or local IP, or a mDNS resource.

=20

In the same thing, I see that reuse of key material, mentioned in 4.11 =
is no problem, as long as key material is NEVER reused along multiple =
devices (eDellSupport and such).

If key material is reused among the same user only (same local network), =
I see no risks.

=20

4.9 and 3.3 solves any issues that may exist with attacks, since each =
root certificate will only recongnize whatever exist on the very same =
local network.

=20

Since the device SHOULD regenerate certificate (4.5) when a =
=E2=80=9Cfactory reset=E2=80=9D is done, a device which changes owner =
(through selling on marketplace as used product) will not pose a =
security risk.

=20

There could be good to impose a rule, that a IoT device, should, on each =
power up:

Set a flag =E2=80=9CNeverConnected =3D true=E2=80=9D

Do power up connection.

If a connection to a network for which it owns a certificate is found, =
then:

=E2=80=9CNeverConnected=E2=80=9D should be set to false.

=20

IF a pairing of a new user is done to the device, AND the pairing is not =
done through a existing user (Pairing done with a button or similar) =
=E2=80=93 AND =E2=80=9CNeverConnected=E2=80=9D is set to true, then it =
should do an automatic factory reset, or require a factory reset.

=20

However, if a new user is paired into the device through an old user, =
there is clear evidence the device is still possessed by the old user, =
and it does not make sense to reset the device otherwise.

=20

This ultimately protects a device which changes hands into a new user =
from any malicious attacks, even by the previous user, even if the new =
user does NOT factory reset the device.

=20

=20

                        Best regards, Sebastian Nielsen


------=_NextPart_000_006C_01D9C575.F93ADC10
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.E-postmall18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DSV link=3Dblue =
vlink=3Dpurple style=3D'word-wrap:break-word'><div =
class=3DWordSection1><div><div><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>7) Validity of certificates: =
</span><span style=3D'font-family:"Arial",sans-serif'><a =
href=3D"https://www.ietf.org/archive/id/draft-sweet-iot-acme-04.html#name=
-iot-device-certificates"><span =
lang=3DEN-US>https://www.ietf.org/archive/id/draft-sweet-iot-acme-04.html=
#name-iot-device-certificates</span></a></span><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p></o:p></span></p></div><div=
><p class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p></di=
v><div><p class=3DMsoNormal style=3D'margin-left:65.2pt'><span =
lang=3DEN-US style=3D'font-family:"Arial",sans-serif'>&gt;&gt; I =
disagree with short validity.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>If the certificate is =
restricted to local domain names only, I suggest allowing validity up to =
10 years.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>HOWEVER, if local certificates =
should be accepted by browsers as root, THEN there must be a mechanism, =
similar to DNS Rebinding protection, that prohibits an external site =
(that are not an RFC1918-IP or local resources) or a resource received =
externally (for example an email) from hyperlinking or redirecting to a =
.local resource, an private, loopback or local IP, or a mDNS =
resource.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>In the same thing, I see that =
reuse of key material, mentioned in 4.11 is no problem, as long as key =
material is NEVER reused along multiple devices (eDellSupport and =
such).<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>If key material is reused among =
the same user only (same local network), I see no =
risks.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>4.9 and 3.3 solves any issues =
that may exist with attacks, since each root certificate will only =
recongnize whatever exist on the very same local =
network.<o:p></o:p></span></p><p class=3DMsoNormal><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>Since the device SHOULD =
regenerate certificate (4.5) when a =E2=80=9Cfactory reset=E2=80=9D is =
done, a device which changes owner (through selling on marketplace as =
used product) will not pose a security risk.<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>There could be good to impose a =
rule, that a IoT device, should, on each power =
up:<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>Set a flag =
=E2=80=9CNeverConnected =3D true=E2=80=9D<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>Do power up =
connection.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>If a connection to a network =
for which it owns a certificate is found, then:<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>=E2=80=9CNeverConnected=E2=80=9D=
 should be set to false.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>IF a pairing of a new user is =
done to the device, AND the pairing is not done through a existing user =
(Pairing done with a button or similar) =E2=80=93 AND =
=E2=80=9CNeverConnected=E2=80=9D is set to true, then it should do an =
automatic factory reset, or require a factory =
reset.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>However, if a new user is =
paired into the device through an old user, there is clear evidence the =
device is still possessed by the old user, and it does not make sense to =
reset the device otherwise.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'>This ultimately protects a =
device which changes hands into a new user from any malicious attacks, =
even by the previous user, even if the new user does NOT factory reset =
the device.<o:p></o:p></span></p></div><div><p class=3DMsoNormal =
style=3D'margin-left:65.2pt'><span lang=3DEN-US =
style=3D'font-family:"Arial",sans-serif'><o:p>&nbsp;</o:p></span></p></di=
v></div><div><blockquote style=3D'border:none;border-left:solid #CCCCCC =
1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm'><p =
class=3DMsoNormal><span lang=3DEN-US><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
lang=3DEN-US>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0 </span>Best regards, Sebastian =
Nielsen<o:p></o:p></p></blockquote></div></div></body></html>
------=_NextPart_000_006C_01D9C575.F93ADC10--

