Re: [Acme] Secdir last call review of draft-ietf-acme-star-delegation-06

Thomas Fossati <Thomas.Fossati@arm.com> Thu, 25 March 2021 20:02 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 05C003A2BA7; Thu, 25 Mar 2021 13:02:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=e8/8kKNG; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=e8/8kKNG
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EBy8NiiJRCrw; Thu, 25 Mar 2021 13:02:46 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30052.outbound.protection.outlook.com [40.107.3.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 36BF23A2BA5; Thu, 25 Mar 2021 13:02:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GeyQ4lQw3xR6egm5kj0aoEImLhIpgM2G0qLaPwHN7zM=; b=e8/8kKNGza8vGlPPiE9KCYVBXLRTpRA8Iavs6hDtKPAhZ1sZtYqD8jV28GopyPJFSYdwcQGL/TD6El4beiH4HUR8r0oEoHVB5QTCccD6rtNY1Ii+qx/7AdT2YtzT/gcu3tPG16j1wbUy+W4sQi9V+4EiDm1tlc2A6rzzs+EQgGU=
Received: from DB6PR1001CA0007.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:4:b7::17) by AM0PR08MB5540.eurprd08.prod.outlook.com (2603:10a6:208:144::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.24; Thu, 25 Mar 2021 20:02:43 +0000
Received: from DB5EUR03FT024.eop-EUR03.prod.protection.outlook.com (2603:10a6:4:b7:cafe::f4) by DB6PR1001CA0007.outlook.office365.com (2603:10a6:4:b7::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.24 via Frontend Transport; Thu, 25 Mar 2021 20:02:43 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DB5EUR03FT024.mail.protection.outlook.com (10.152.20.67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.25 via Frontend Transport; Thu, 25 Mar 2021 20:02:43 +0000
Received: ("Tessian outbound 2220e7a8bae2:v89"); Thu, 25 Mar 2021 20:02:43 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: 47473d3831906583
X-CR-MTA-TID: 64aa7808
Received: from 2c0da51a87fe.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 56A4BF10-67E2-4354-978C-02BF9D0610E6.1; Thu, 25 Mar 2021 20:02:37 +0000
Received: from EUR04-DB3-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 2c0da51a87fe.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 25 Mar 2021 20:02:37 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RkdcxyFShJobj2TAmKRJ8LaoeR5Gib8OKiPQxUdKSHxA2nohiaCZK4hCS31MFrlU5FualuXilqw28e4myEZem1M7sLS2+yZgF5onXTlRu8d2Zki/uz3Zw3ti2X46J0IMBKoU2LP3+CESaDYeWVRlHT+3S7lcQVUaDVSfCAWICGyampUmkShfd4xqrm604HZKAP65YH8Q5QBv6L17OCH38aYCEaF8JGADUBcs0RVwTudaii8G+cdI3buWpMAGpgdehYqy/lTmE4vRPUw+9hKUmwROUL0ZANb8VLS7jKh5q/oYEGXIj7YYvxRXiVFhW+P38+9ELJAYKrQGz5VINmde3Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GeyQ4lQw3xR6egm5kj0aoEImLhIpgM2G0qLaPwHN7zM=; b=E8+W1P/bysX0fS/HkuZAgVg1OUS6pT46o7hJKd4QRpbidSXS8cpw1ZdZ3IJbcSIFElwTbWNA4RQWtD4+4y+iWWSWDB5bk7iUvjbvZsQp1dyDtf10ZW7iqBLGiXpZ2nMHg+S9jtVwMPf22OQMm8us4WJqPx+I5vO/T3OJBMAlzGnjG0O697oh+HWTQvA39j+vpphU5l3uO1jLvuWdDpEugaeBlHCLszWdkFMzpSv6ZSXxaPMt/uWLLBAgzNjA5TM3uuwPduzMLS02NQaYofXIWlq8v8+T8Q8R3ZSt6KNprPo7L0ZjLHdjUoGF9AaQO+UmhH4pSKzg+1AGhWDDLjrKLA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GeyQ4lQw3xR6egm5kj0aoEImLhIpgM2G0qLaPwHN7zM=; b=e8/8kKNGza8vGlPPiE9KCYVBXLRTpRA8Iavs6hDtKPAhZ1sZtYqD8jV28GopyPJFSYdwcQGL/TD6El4beiH4HUR8r0oEoHVB5QTCccD6rtNY1Ii+qx/7AdT2YtzT/gcu3tPG16j1wbUy+W4sQi9V+4EiDm1tlc2A6rzzs+EQgGU=
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com (2603:10a6:10:251::8) by DB7PR08MB2972.eurprd08.prod.outlook.com (2603:10a6:5:1b::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3955.18; Thu, 25 Mar 2021 20:02:36 +0000
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::e9e7:ea3a:3bca:5b3c]) by DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::e9e7:ea3a:3bca:5b3c%7]) with mapi id 15.20.3977.026; Thu, 25 Mar 2021 20:02:36 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: Russ Housley <housley@vigilsec.com>, Yaron Sheffer <yaronf.ietf@gmail.com>
CC: "last-call@ietf.org" <last-call@ietf.org>, IETF ACME <acme@ietf.org>, Thomas Fossati <Thomas.Fossati@arm.com>
Thread-Topic: [Acme] Secdir last call review of draft-ietf-acme-star-delegation-06
Thread-Index: AQHXGR2r2oa7NsdVgEiTKC6gi2ySeKqEGPKAgArWDICAAYJUAIAA8qSAgAA6AYCAAzYfAIAAU5WAgAAJr4A=
Date: Thu, 25 Mar 2021 20:02:35 +0000
Message-ID: <14A30220-C467-451C-BE06-2D5836C111FE@arm.com>
References: <161575930310.2025.16866904323712710819@ietfa.amsl.com> <3DDC13CC-4789-459D-9DA2-E023BC372D8C@arm.com> <2FF4DF9C-2CE4-4E88-8334-D2D953E06BD4@gmail.com> <966179D0-B67B-4CDF-9A4C-CF9F0B1D04E2@vigilsec.com> <51B3FE70-67D4-4F6F-8F5D-43182186F55D@arm.com> <D525861A-5B91-47B5-92A1-7C312C514BDA@vigilsec.com> <E4734052-E56F-4321-A3C3-79C38F8DAC96@gmail.com> <9164FE04-FF66-44D8-888F-790B9E294CD4@vigilsec.com>
In-Reply-To: <9164FE04-FF66-44D8-888F-790B9E294CD4@vigilsec.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.47.21031401
Authentication-Results-Original: vigilsec.com; dkim=none (message not signed) header.d=none; vigilsec.com; dmarc=none action=none header.from=arm.com;
x-originating-ip: [82.12.10.179]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 508011ed-745c-40ee-2e5f-08d8efc8f3dd
x-ms-traffictypediagnostic: DB7PR08MB2972:|AM0PR08MB5540:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <AM0PR08MB55408880E4B83F516ABC4AB59C629@AM0PR08MB5540.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:3968;OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: anOE1E8Ztw/HesLaZdW7jdAz1TOcwkR+hlNRfDIjQOUlj/Z5S7wr1OlrWPtuHtwLCoC8SaBIV9xGx7zrqrwiemlhcb8VR33yyA2Nhjmjv7WkhXZz8mLJEwcyaL9GTO+BvueAFn0I1SPfr6eBRSVJ1m88futHUnTo1pOyGJ5xDSqLNIJSaQz4cIBc4P8BYJqZu+VZc2k5IL82I6+ACTq8lvcu/r/CMcyS3BNzhPot+Iyxdr/Y8iNySdYzl6Yk4wTHxhW1H6IYkBDGYuYbuuq3udnOl1miYZNlhyzX8xi1r8iF8orEdOaUJUAdql1slDpQdNJgJZEfFNrs4wdlIzcj55AdTjJoR5cAAgEPjs+44mg/hf/DbO4oGHDVBLO7C6nk0uYKsQYt82J2DJgW8Q1bYOGkP6eSRnwd34/GT6ZoaZKTE8NP0LHRkeHL/G4c2bpvvOozqlmtvvlI5yk6CKhtlgTuX1HAhEiYuV0M/nWHrR7sCWgtrzv+rH+FyijCp2OtYH5JfshWOD5RWNBnInFi0oyLwl0vaCAJLmOtgaYFk7NZ/R9XKjLxc7AI07SqK8UklhqOfO+ZL8QW6Vb9aGYafUH8OlLGJF6orhoGhyugbp/oKuQiHGkknYDdPXZU9Ay4KebzN1nrgowhJacGHLg0MeDohaqxVYwX8/tMXSpIjp1vx+L5gGgf0MSfxmKDJFz1Qgu81feak5EQQCM6+VMaZug1bnnvFjEXm50zS8KQZ1t+oivY2QpFrKTb9TZI2BDqt99/sR16NTlpnu1eMkGraQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9PR08MB6524.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(39860400002)(366004)(396003)(136003)(376002)(26005)(316002)(33656002)(6486002)(83380400001)(71200400001)(110136005)(36756003)(8676002)(8936002)(186003)(86362001)(4326008)(91956017)(66446008)(478600001)(38100700001)(966005)(6512007)(64756008)(54906003)(66946007)(6506007)(2906002)(53546011)(66556008)(66476007)(5660300002)(76116006)(2616005)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: xNDn0FR3R7ttYH6VUL35Qk4G5CLpWt82mHJi61F7ljMyIwE0Uv/5S2yOjm35Lv9u7BkMCvsKkhGgbCYxKIdECxyPYkPD+ydK5tSrWecglW/ZK5pX0frlj6HL2BbqQYZnnNC/Vs8EJO3ahMh4S0UBAv2YSyc35UUNMsi+DmnQDA5YdDhryZDpRrC/Up8ndR3g0y3Fqo+8HMPjRroLycyuUGqVgktrb045wW5kQc5GrHwzI3cHJIwoCfdFWGPLKmAz6xMZrmjBzTEt33MyiUcj8DmtVGXZc5MsugnJoz0E7fDl9Cux4tw0QBJdB9Atl+iw/AYSOCiOEcJCrzYtwGlWXxD9NPKeWlqDC+MThlYYthSVBg+5qmRNFdDtTbTm8pcEuHkitW/+MXABd4WEguF6fJdtRNvo7247B0hsEe+yjk5G6KDAxqAHlV788Ov+OZQxyYzUL8e3XSS93B4mrwMUuM7ffAxB6WErZFgwOE2d5KpB+idYTIgbPUdQ0Ra6YGAnHpD2Gm4knZTm4SSlCEAgknsmp26+ZrwcU/c+ri8/8YYkgAtScyXC6iBYWLXTpbOniatWa5kdTU+zVVigtgf2l8Tm2IdVw2o80YiqDIiKOAdZ9savZrbE6nJw9ii9Ptyq2lXvtGXtdns5W2SlLUuQYpiqkvzuoQplA6VMj9uGzaJ3KpQqFUlaEq/pz2VNQxIjQDM5ndsnORnh0f/anr3I+4Y35uIYkv6dIa6/V982cQW/vvhmIa9nZ5yRDmRddqiLh6J8O3F/5ZbhhJlBBT/KT16rD4JERPEPmtyE5Kb2Ixv1Ww2qoGUgQIXkEsea0QA6DLodmkuFCX9/H3ZOeRMurxSA0fom9zKbya8qqRSNsTka/w8wvDCuJ+qVNMbBVkbUXHMefvayPlQ9I7++usxp/ULh1miYgAGFUYE3X4frZSK+2k8jc7qKR77YjkSh4kAQG6aAO1K4EtklNVf7657aCQeGh1cl5FhySzFlkXUCIkxwExPmGcV8pojSy4XZ/3pX2CuKrpiO/mAi/HEDOMPJ3isgs277PsS8MikDWtt0+jyeUN55cojb0LAEw7F4rRQsVSr6FUxrN7AehWRBmAfYqayi90rR/LiIPqIgzj337PilgkO9qCNvLnnwBChza1450SeDr7YCbtvckdhkO2HWlikdZenRQr4rOfCpijEfnQIZ8vHyz68Kh4UjTykSJn1oqfdRh1f8fcE4h9F6OVzSFklVyiquMlPZmZ5WEgYFWwQRAf7XzTn3wAOXUr61+Xnlx1fUYqt1FjVDijgiYKLoNpC9ig/5VeJBodxXzsqDxS0GUdkzD5iAKvAnLqyeZXIe
Content-Type: text/plain; charset="utf-8"
Content-ID: <40C30F5699599C408D773305E42B0F90@eurprd08.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR08MB2972
Original-Authentication-Results: vigilsec.com; dkim=none (message not signed) header.d=none; vigilsec.com; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR03FT024.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 29384782-217f-4ee4-69e3-08d8efc8ef4e
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: OwO5u+2ZZjI2FswzR+/7i0LsEuba+mtI3CJlkj82bq2RAYhQCaYxOosp5YQ5pgLcTXdUK1KSey+4aIIDrYuuTQTltOJGJNH5nuOdlu9m6MRvoqbBQkupcWPBRQ1rnUXoCv8bFKg3dpgVQLJcs+fzmiy0DL4dr6jKWOryiLxvRRFb09NhvxvY+97qUAk43aAy9F6YJX87ZGqq+be3eEzoslAG5jmCKLt0YDJjTq0MqHuL7KWgVjCkm7JIEvmH2G8saJlWv0d6nrwGAiEPfGw+15kxUk11y1/LfBBqir5HH9G3go83PKqChiAw9r8KSNlJlYpQaQE56bGlcjTb87YhS5Rz3rN4eh9QY3iLN/KqKdE366UyiMkI4xfwUml1LqHzd5IDHOLp9Pe4mqDoB0mX2OSivzX2i6tYFH8dIwyWilqOg+yKpLaPmCiiuEB2WSGCCctIf3tzy4XgG0L+aqauuRhfDGXbhEQgL8DReLNoAht/Kvy/nNHjKJF7iOXzk06ip+yMRc7tUxl0LDvlyQWiH9dhlJNz5a8bdmnOy0mZfvbx54tRqg5J223MrOnmxd4TCUgzQucS1g6jph7CPmleVHW/CawbsF1dUuPYmzfSQJ2RpaZ236LIGyayEMLfZH5GNwFE5yNbfqAVwXSWu0O0tSsOVbJExo9XyDp0dWSs0fE84kLFn5lDbvHnTSfvziNkIza0S/AM4KSbJg7d2m3Yoe9pZjUDvTz6ievrFUPiur0=
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(396003)(39860400002)(346002)(376002)(136003)(36840700001)(46966006)(6512007)(2906002)(82310400003)(70206006)(82740400003)(70586007)(81166007)(33656002)(356005)(86362001)(83380400001)(110136005)(54906003)(478600001)(966005)(8676002)(6506007)(2616005)(316002)(36756003)(53546011)(186003)(4326008)(450100002)(6486002)(36860700001)(5660300002)(8936002)(26005)(336012)(47076005); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Mar 2021 20:02:43.6701 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 508011ed-745c-40ee-2e5f-08d8efc8f3dd
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: DB5EUR03FT024.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR08MB5540
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/mshehbZppB87RU8SC5CYPp1uYHU>
Subject: Re: [Acme] Secdir last call review of draft-ietf-acme-star-delegation-06
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Mar 2021 20:02:53 -0000

Hi Russ,

On 25/03/2021, 19:28, "Russ Housley" <housley@vigilsec.com> wrote:
>
> You will see my comments in those issues.

Thanks very much!

We have prepared https://github.com/yaronf/I-D/pull/167/files

Could you please review it and see if fixes your remaining concerns?

Cheers, t

> Russ
>
> > On Mar 25, 2021, at 10:28 AM, Yaron Sheffer <yaronf.ietf@gmail.com> wrote:
> >
> > Hi Russ,
> >
> > Please see the remaining open issues from your review - we have
> > reopened the GitHub issues:
> >
> > https://github.com/yaronf/I-D/issues/139
> > https://github.com/yaronf/I-D/issues/145
> > https://github.com/yaronf/I-D/issues/146
> > https://github.com/yaronf/I-D/issues/147
> > https://github.com/yaronf/I-D/issues/148
> >
> > Thanks,
> >     Yaron

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.