[Acme] Re: [iesg] Re: Mike Bishop's Discuss on draft-ietf-acme-device-attest-08: (with DISCUSS and COMMENT)

Mike Bishop <mbishop@evequefou.be> Wed, 15 July 2026 19:24 UTC

Return-Path: <mbishop@evequefou.be>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 72C451176042D; Wed, 15 Jul 2026 12:24:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784143453; bh=WcCFBNdpIXoh8OO8vWKqqGVPzVnYSEIbqAKqdoU/3l4=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=Q/DS1FyFqBIk2EgyAX+iJsoqBEcwi06lkP19D/1scNeNEi4dfMywUhSVSGIJ24JyL KttWHE3fyO5J4AN94HWe025bWnuWgByhxV66b3N2IrLK7JLWNlDFHkJmn+n8OS+xlQ h0T3T6NQDvZNzfeUNCP6Up0aT7Qvy90YyEg3zmEQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=evequefou.be
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0tVaxVe7R-bl; Wed, 15 Jul 2026 12:24:12 -0700 (PDT)
Received: from BN8PR05CU002.outbound.protection.outlook.com (mail-eastus2azon11021123.outbound.protection.outlook.com [52.101.57.123]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9ECFF11760421; Wed, 15 Jul 2026 12:24:12 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=cDgptpUGzjTxRYFzcmC3TBUmMEEpVrdywI7+nj9Tp79QivsGaTsSIUo7hQ4eolyO/85T03iS+B2s4ov9W/QI38zr61A21C6PFOJXwqWCW6CGqutA4g58caAEhWW0TJyOtR6Ql0qI64nZYHFm/8oy8mHBEW/aKB/sNkg1fQzBL/d0OBgmsxSb6HDF2POmiEc2DRPmafYM4qiR66DkGP3y4WZlicd81tfL0cNzRevVwnBMP/eMCwUEYNN08ASZIY4S0tX4c1379tgJYRx3H3w5eB0epvP95+0/FmYDaZUXzQ7IsrpBAk3tzZCT1b2FmBvODPd2ZrexFnYu2KvX+0TRuQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=WcCFBNdpIXoh8OO8vWKqqGVPzVnYSEIbqAKqdoU/3l4=; b=cn9qsB166mhVhdzAkA8BrwvpXzJNIdol5Fwfk91Gh7nIdEjw/o5mMPkofkK5DLQlf2roCFRcE1Pl8pVqXupahW27R4dw/3TJnQL1MeXihDbQ0vKaU/7xUBdmNxdaU34G/zDe8hjCZN+/vcgDKMdRSGxk7ijxe64ciOd0mdAIcSDF4TF/RMrA+G8LY+wUkOV6xh+/AqC5YlQeRHlh/xOwCZpW6QJDU+TD7MHhw5M+smnkFvK9m4MQsX/AUy45djmZelwrQhRSuocOlpPTHYEdBRhSVZ0Rb5ECE534bfatpGNjClbH3zGxVP7Qn6Wia6KX7O3bD8sVaxS6WI0ZWQHmgw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=evequefou.be; dmarc=pass action=none header.from=evequefou.be; dkim=pass header.d=evequefou.be; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=evequefou.be; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WcCFBNdpIXoh8OO8vWKqqGVPzVnYSEIbqAKqdoU/3l4=; b=hilZurn3LusF7GyL+WkVzErWpNmGr9jyepf3EehqDSjxA5lPOUIdYDYwxyk7U0749nFfNKODJVz7sp70ayRFSYCJIDLuVFsKahg1NCB1fOlIflGMdNhdn9kbqjI0n4F07P4cXPXhUh9ECpdaIMWGbRGUOAGvS9zZIeGmM2n5+2Y=
Received: from IA0PPF726CD7A1F.namprd22.prod.outlook.com (2603:10b6:20f:fc04::d2b) by SJ2PR22MB4556.namprd22.prod.outlook.com (2603:10b6:a03:563::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.202.19; Wed, 15 Jul 2026 19:24:02 +0000
Received: from IA0PPF726CD7A1F.namprd22.prod.outlook.com ([fe80::8390:9dee:ad0:9ee0]) by IA0PPF726CD7A1F.namprd22.prod.outlook.com ([fe80::8390:9dee:ad0:9ee0%7]) with mapi id 15.21.0223.008; Wed, 15 Jul 2026 19:24:02 +0000
From: Mike Bishop <mbishop@evequefou.be>
To: Corey Bonnell <dev@cbonnell.com>, Deb Cooley <debcooley1@gmail.com>
Thread-Topic: [Acme] Re: [iesg] Re: Mike Bishop's Discuss on draft-ietf-acme-device-attest-08: (with DISCUSS and COMMENT)
Thread-Index: AQHdFItg1PUtaQYONUmLqQRb8N8WwbZu9dUs
Date: Wed, 15 Jul 2026 19:24:02 +0000
Message-ID: <IA0PPF726CD7A1FC4BDC03AE404D2EB9ABADAF82@IA0PPF726CD7A1F.namprd22.prod.outlook.com>
References: <178343345094.440753.12217487480236395708@dt-datatracker-57b5d8f849-v5cht> <OwxYspW--F-9@cbonnell.com> <CAGgd1Of83a=XYUXKx_9P4qSMbWB4ggcjNT+HkKE8D_6+sJaiFg@mail.gmail.com-Oxb21Uc----9> <Oxb797v--F-9@cbonnell.com>
In-Reply-To: <Oxb797v--F-9@cbonnell.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=evequefou.be;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: IA0PPF726CD7A1F:EE_|SJ2PR22MB4556:EE_
x-ms-office365-filtering-correlation-id: 7db228ef-2ba8-46da-622a-08dee2a6a0e6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|376014|23010399003|4022899009|13003099007|38070700021|10067099003|4143699003|6133799003|8096899003|56012099006|18002099003|22082099003;
x-microsoft-antispam-message-info: 93JsMTpjE5QJzerCJtnK2ARq588iDtAr0AppyOnQIdi7Dohv2f+RIWzYQ4VgwaYEH6GfiTRUj2zdRtqsStRB9y/T5gOt5jkuTQtCfJgpSGzL3NDF8ec1zhtaZdApNchXHRE+WCqzaT5OyyJhOXwkOIJqpvs0CTSSzuKTFMExTZzKPvFpLsmZB+Rh5MSPYMHjsIyJ7LMOyDV9iD1ddSaU8IHU6tvRnJ/lJATVcT70lVVwqQMAiV+nsMENh+uN9iZcUsi/FpEW+GzItPZfhMAsR6Y1M+nMJOhxTdmPAjjUFK48DX7K5/tbUTg+c+r+gHc+2a3lx6nzfRcAMHeed0PwhjV5DOXtHu8e7vZJH02AP2iMjvQGJZeomnRA3tPUWpa7CJsCZsQlm+ZDvn7hZnczjhoyg3HOS53IlJK+PC15Sqddmbq8+ec47RkFZa2SeyIMmhrlId1TDfF+5cb9mL6SliuEXL+GNZ+U5T+VRD0eDgicNDXyRB4BRHSEkb+X2MlaUNb2PKFNOrbPOCONTFiS+0R2o/lde8bjLo9OzvTGO6TcaIXTjaKBniPlTqOkZbVvR0ifHNMUehAKH+RGIgb2sifODrC8qxpwwuSjKBRdAMkocSjQXWO4gXjnY1pcaxLwa5U5LbhgWldHtKwm6czX8iwt+Je2cuUSWnO2OHRydi4=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:IA0PPF726CD7A1F.namprd22.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(376014)(23010399003)(4022899009)(13003099007)(38070700021)(10067099003)(4143699003)(6133799003)(8096899003)(56012099006)(18002099003)(22082099003);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: h78oOz+fIDAR4f8IRtU7cNnJTFQnd2G/atNm9+1skVmcMXOXqbjNQsvK1A9xkZDLE2h3wNJE+5+EMg5jd8CLklGe5L89qamMcdnhdIBs+X3ft1WgTYTARr4rfNRsH2/iJsIuE7tE+Cgl1jFdnowtFJ3T1Oa6joVjsR/FNBc6OAl2Qb7KtHco7EYptGsHqSv8APNXnW15zu7KjOJBiwWPNI9ZVSlUtHkH2d5/QBty8AKVqiEqy4Sk70Iq6sJLcrVeDe4g3RDGHMOFTdizgA+DfkrhnckfUgOGLFLAAN/IoNvR6Lg/+i6sl0z/IqWt6EGJqRgkRSpRMLjgvpPTP4dIPXdAKD6JqmQ1ufUhPYkbMMdEWU1RTRUgofwcn+N/M9vHO41fE/TkBohryTKnhdk/VWjm1bQcd39XqnNKdMD4+rqjj1ccVEL6g4RPqlAL701gvBPLouatGZxBzqG7q4oKYOMS4XfX4zZAmxMokXlGqbppK7/U8kXdxKp4c0Mirz24iG9Pu/ieXmCOVIg+ajt7acucy3/vetjqAqCiv1qF+XCNvC88FwWrMQXnEtSQaP2hhi3lGEQD9NWRt6V+f24zWRWOrwG7c6piDJOBxaSLBevJysYA1wBV9NG3/0jCxC2H58x4E82S2aP1dXNtGe48oIykTxfvlOA2CBVG+lDa5YKUPUlpjY4n10sDoKgzyfY1u6tHusb7QcTXDGKlATYHq2r4LSA8FrR1AGLrX7fFbYbgt365JYUxNoDK4KzmgkdRg6Iy42TaSsvmN9gfnwdp6XGXYlzP1CTL/8on/tIvrFV5ddgDl93E+vneaNp0g+UC44ZxGbNc/yDAnQIFjSpyYb9qGcFAE5mLUlRTsiH3RdlYC2A6GqBQqrGPOlIK6dYyuHtcf/71eKh6hrIVO7NlbYzKfmJGSj+bQsdiOtgQOTjVML0W8e3M2In/QOZISLMsVoZPCGEfnQ5Y/7bdk3iglP/nsEZOvUGsY9M2SaPeV2SL5vdwCaSlOn8x2c8F1Iwm7lbfN8wUyGcDLjHKFbRBqlalHskK4SO0ibdwMai4YC1rSsWbLXKeXNSXcpMyqslhPZAjiX8qH+rPCs3115VXF5Mi924BfG0ije84xiLYQnagNwOMAHFOxe8N9jJzysZhz99dJSW4rr0k/8/M2rM3oFnL0Q7WKXFV7xT9gNG9+FRliDkKqfMR925rNKgH/fwDm48wR//bJ6PenEx8mvfaJ8CzRaT6Sjz/8uNQQFkLw2gWU/EXOXXhC6HFF10F0XBVNPqMXT3bd3Ae1zwjGkp6hUnK7rQQUdcUkmZGgk+BjTtT+MSPfcOZKiGWJrRy+T6nTLNGwqoKBxfqGx5j/38k45n7F8h9fafTVX9PK9gBVGdThVPvWWl5m7amAOzWOfLqu/1z8AsjKhBDxeiTUV7qnDoILSpFsSLsGx+64shrQcNLFJ93+HcTrsJAR1GNed9XD7xz3RPlTWjDZ6t1E/3N9oVXz2nggXi6J77/xLPoRg/XIp3b4cFgNcB5IqPu0YAvkGve3LYffgFu8NB3oufzFGLn20lj1iHuvrEmAyA1X762HgIhBZsrJ0WrHOK4DlvgerYAivZo7J35unmrsy333CngkEBozmVsNFEdbxZvjkir5ImmLBLNq5Df76zMvSjF0j+DrgUyH8zAyInOL3DXi28JrTbB/5zBXSqBR3/Y/ZOlRjMmZRypSyjWKkqT4FYp
Content-Type: multipart/alternative; boundary="_000_IA0PPF726CD7A1FC4BDC03AE404D2EB9ABADAF82IA0PPF726CD7A1F_"
MIME-Version: 1.0
X-OriginatorOrg: evequefou.be
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: IA0PPF726CD7A1F.namprd22.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7db228ef-2ba8-46da-622a-08dee2a6a0e6
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Jul 2026 19:24:02.4822 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 41eaf50b-882d-47eb-8c4c-0b5b76a9da8f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: aBPyKz/qoEg/TjZiQzi9gAqGN1wimc1ZAbsb5hJO+YAnOdHWPvManuyCzmph5wfMU1SUthHnT2J2LbIB7MzRdg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2PR22MB4556
Message-ID-Hash: 6AS4V3HWUXBDO5TPAXNMQCPGW4CVYFC2
X-Message-ID-Hash: 6AS4V3HWUXBDO5TPAXNMQCPGW4CVYFC2
X-MailFrom: mbishop@evequefou.be
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Dev=40cbonnell Com <dev=40cbonnell.com@dmarc.ietf.org>, Draft Ietf Acme Device Attest <draft-ietf-acme-device-attest@ietf.org>, The IESG <iesg@ietf.org>, Acme Chairs <acme-chairs@ietf.org>, Acme <acme@ietf.org>, Mike <mike@ounsworth.ca>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: [iesg] Re: Mike Bishop's Discuss on draft-ietf-acme-device-attest-08: (with DISCUSS and COMMENT)
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/o3HzG0dR65JI7kuLyUXkB0vs2lk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>

Yep, that looks reasonable. Thank you!
________________________________
From: Corey Bonnell <dev@cbonnell.com>
Sent: Wednesday, July 15, 2026 8:53 PM
To: Deb Cooley <debcooley1@gmail.com>
Cc: Dev=40cbonnell Com <dev=40cbonnell.com@dmarc.ietf.org>; Draft Ietf Acme Device Attest <draft-ietf-acme-device-attest@ietf.org>; Mike Bishop <mbishop@evequefou.be>; The IESG <iesg@ietf.org>; Acme Chairs <acme-chairs@ietf.org>; Acme <acme@ietf.org>; Mike <mike@ounsworth.ca>
Subject: Re: [Acme] Re: [iesg] Re: Mike Bishop's Discuss on draft-ietf-acme-device-attest-08: (with DISCUSS and COMMENT)

Thanks, Deb. I created this PR to hopefully make the BCP 14 words clearer: https://github.com/ietf-wg-acme/draft-bweeks-acme-device-attest/pull/31/changes.

Absent any comments, I'll merge and push a new version to the Datatracker once it opens up.

Thanks,
Corey



Jul 15, 2026, 14:31 by debcooley1@gmail.com:
Addressing only one point:

Section 3.2 and 4.2 quote RFC 8555 (CSR MUST) which is fine.   But what follows is the actual update.  Right now you have the MUST with rationale for why one might not, but that logically changes the MUST to a SHOULD, no?  (Mike suggests a 'MUST...unless...', but that is less clear, I think, but YMMV)

The update being made here softens the MUST to a SHOULD (I think), where the rationale you give shows when one might ignore the SHOULD.  After this draft is approved, that MUST turns into a SHOULD.

Does this make sense?

Deb



On Tue, Jul 7, 2026 at 1:11 PM <dev=40cbonnell.com@dmarc.ietf.org<mailto:40cbonnell.com@dmarc.ietf.org>> wrote:
Hi Mike,
Thank for your previous review as well as your insights on -08. Replies inline below:

> Although -08 now does explicitly update RFC8555, it doesn't state what the change is. I would presume that the MUST has become either a "SHOULD" or "MUST ... unless..." to permit this new path.

The bottom of sections 3.2 and 4.2 explain the difference:

"[RFC8555<https://ietf-wg-acme.github.io/draft-bweeks-acme-device-attest/draft-ietf-acme-device-attest.html#RFC8555>] section 7.4 mandates that "The CSR MUST indicate the exact same set of requested identifiers as the initial newOrder request". However, there are some environments where the Server requires validation of the identifier but does not include the identifier in certificates due to privacy concerns..."

I believe this makes the update explicit.

> You use a number of terms from other RFCs without direct pointers; I'd encourage you to add a Terminology section here for things like Assigner Authority (RFC4043).

We have explicit references to the RFC where the terminology is defined. Since these are normative references, we expect the reader to understand those RFCs before implementing this specification. Given this, copying the terminology into this document would be duplicative.

> A reference to Section 7.3.4 of RFC8555 would be useful here.

That's a good idea, we will add in the next version.

> What is the difference between 6.1.2 and 6.1.3? They appear to say the same thing, that multiple challenge types MAY be deployed in parallel.

They are similar, but cover different aspects. 6.1.2 alludes to using EAB/other OOB mechanisms for authentication whereas 6.1.3 alludes to the use of multiple challenge types.

> This is probably a SHOULD.

Several other reviewers opined that we should not be using BCP 14 words in section 7, as it is not appropriate to use such words when not describing interoperability.

> Please include links to the IANA registries.

Is this a common practice, and are these links durable? I've seen many RFCs published recently where the registry name is sufficient.

Thanks,
Corey



Jul 7, 2026, 10:12 by noreply@ietf.org<mailto:noreply@ietf.org>:
Mike Bishop has entered the following ballot position for
draft-ietf-acme-device-attest-08: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-acme-device-attest/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

# IESG review of draft-ietf-acme-device-attest-08

Thank you for your update, which addresses a number of my DISCUSS and COMMENT points.
I've updated this ballot to focus on the remaining issues.

CC @MikeBishop

## Discuss

In Sections 3.2 and 4.2, clients and servers MAY violate a MUST in RFC8555.
Section 7.4 reiterates this permission again and recommends the new,
noncompliant behavior.

Although -08 now does explicitly update RFC8555, it doesn't state what the
change is. I would presume that the MUST has become either a "SHOULD" or a
"MUST ... unless..." to permit this new path.


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

## Comments

### Section 2, paragraph 2

You use a number of terms from other RFCs without direct pointers; I'd
encourage you to add a Terminology section here for things like Assigner
Authority (RFC4043).

### Section 6.1.1, paragraph 1

A reference to Section 7.3.4 of RFC8555 would be useful here.

### Section 6.1.3, paragraph 1

What is the difference between 6.1.2 and 6.1.3? They appear to say the
same thing, that multiple challenge types MAY be deployed in parallel.

### Section 7.4, paragraph 1
```
Implementers should treat this privacy-preserving mode as the default
posture unless there is a specific operational requirement for the
```
This is probably a SHOULD.

### Section 9, paragraph 1

Please include links to the IANA registries.

## Nits

All comments below are about very minor potential issues that you may choose to
address in some way - or ignore - as you see fit. Some were flagged by
automated tools (via https://github.com/larseggert/ietf-reviewtool) so there
will likely be some false positives. There is no need to let me know what you
did with these suggestions.

### Typos

#### Section 3.2, paragraph 6
```
- PermanentIdentifier in the subjectAltName extension. See the
- ----
```

### Section 4.2
```
- Section 7 section for more information.
- --------
```



_______________________________________________
Acme mailing list -- acme@ietf.org<mailto:acme@ietf.org>
To unsubscribe send an email to acme-leave@ietf.org<mailto:acme-leave@ietf.org>