Re: [Anima-bootstrap] authz in the form a cert chain.. from SIDR work

Carsten Bormann <cabo@tzi.org> Thu, 13 October 2016 11:48 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: anima-bootstrap@ietfa.amsl.com
Delivered-To: anima-bootstrap@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1CB2A1294E8 for <anima-bootstrap@ietfa.amsl.com>; Thu, 13 Oct 2016 04:48:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g8Vo4ZTByrq4 for <anima-bootstrap@ietfa.amsl.com>; Thu, 13 Oct 2016 04:48:09 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D57DD1294A3 for <anima-bootstrap@ietf.org>; Thu, 13 Oct 2016 04:48:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id u9DBm3Nc003291; Thu, 13 Oct 2016 13:48:03 +0200 (CEST)
Received: from nar-4.local (p5DC7E34C.dip0.t-ipconnect.de [93.199.227.76]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3svprg1NNNz3PmT; Thu, 13 Oct 2016 13:48:03 +0200 (CEST)
Message-ID: <57FF74B5.5020004@tzi.org>
Date: Thu, 13 Oct 2016 13:49:09 +0200
From: Carsten Bormann <cabo@tzi.org>
User-Agent: Postbox 4.0.8 (Macintosh/20151105)
MIME-Version: 1.0
To: "Max Pritikin (pritikin)" <pritikin@cisco.com>
References: <BFB13000-E62E-4A5F-9003-F8227F914974@cisco.com>
In-Reply-To: <BFB13000-E62E-4A5F-9003-F8227F914974@cisco.com>
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima-bootstrap/53buGv1uFwoESrrVNa593pgiqWA>
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, "anima-bootstrap@ietf.org" <anima-bootstrap@ietf.org>
Subject: Re: [Anima-bootstrap] authz in the form a cert chain.. from SIDR work
X-BeenThere: anima-bootstrap@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Mailing list for the bootstrap design team of the ANIMA WG <anima-bootstrap.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima-bootstrap>, <mailto:anima-bootstrap-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima-bootstrap/>
List-Post: <mailto:anima-bootstrap@ietf.org>
List-Help: <mailto:anima-bootstrap-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima-bootstrap>, <mailto:anima-bootstrap-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Oct 2016 11:48:10 -0000

Max Pritikin (pritikin) wrote:
> And each member of the sales channel repeats this process as it resales the device?
> Right down to the “Sesame Bix Box Retail” having a PKI and issuing the final bill of sale:

Actually, for some organizations investing in designing security
solutions that's the point:
Security solutions can be designed to favor certain business
arrangements and make others artificially hard.

(In this, case, of course the manufacturer would build a platform to
enable Sesame to run this process.  Manufacturer is happy: more control
over the channel.  This also probably easily justifies the entire
expense of running the platform.  And then later, that platform can be
turned into a "profit center", because security ensures lock-in.)

Grüße, Carsten