[Anima] FW: New Version Notification for draft-friel-acme-integrations-01.txt

"Owen Friel (ofriel)" <ofriel@cisco.com> Tue, 02 July 2019 19:04 UTC

Return-Path: <ofriel@cisco.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 197F21206E0 for <anima@ietfa.amsl.com>; Tue, 2 Jul 2019 12:04:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.5
X-Spam-Level:
X-Spam-Status: No, score=-14.5 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=h+ZUEC6k; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=xGEykkdk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id N3qarnBgJ8Oq for <anima@ietfa.amsl.com>; Tue, 2 Jul 2019 12:04:39 -0700 (PDT)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BED681200D5 for <anima@ietf.org>; Tue, 2 Jul 2019 12:04:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3080; q=dns/txt; s=iport; t=1562094279; x=1563303879; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=D1Ehrq9H8pjFJiwI9RI1QhvcWmZWy0yaILIJlQkrRIU=; b=h+ZUEC6kfSHz9s81HsXN5rHOTHiwj0prtVYRnM5ktxUNRris4e2pq0dm W9GVxhhUv6Gx7qgHMu/PKom9zBWboF9BDhkHtAYhdEan503efUnIdOPfL tbYlXYSqFr3DI3dHN5xA36M/Ac6Lw2+iZ9qiaJdVm0DlRagrEhHHuf5e2 I=;
IronPort-PHdr: 9a23:+Ny7uBzEF/NA6JLXCy+N+z0EezQntrPoPwUc9psgjfdUf7+++4j5YR2N/u1j2VnOW4iTq+lJjebbqejBYSQB+t7A1RJKa5lQT1kAgMQSkRYnBZuCB1f6IfrCZC0hF8MEX1hgrDm2
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AXAABQqhtd/5FdJa1lGwEBAQEDAQEBBwMBAQGBUwYBAQELAYFDUANqVSAECygKhBKDRwOEUooMgluXRIEugSQDVAkBAQEMAQElCAIBAYRAAheCAiM0CQ4BAwEBBAEBAgEFbYo3DIVKAQEBAQMSEREMAQE1AwsEAgEIEQQBAQMCJgICAjAVBgEBBQMCBAESCBqDAYFqAx0BAgyaJQKBOIhgcYEygnkBAQWBNgIOQYMIGIISCYEMKAGLXheBQD+BEUaCTD6CYQEBAgEBFoFJgwgygiaOZoUfljQJAoIWhlSNRIIrbIYvjieNMIc8j3ACBAIEBQIOAQEFgVA4gVhwFRqDDQmCOINxhRSFP3IBgSiMZwGBIAEB
X-IronPort-AV: E=Sophos;i="5.63,444,1557187200"; d="scan'208";a="590307707"
Received: from rcdn-core-9.cisco.com ([173.37.93.145]) by rcdn-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 02 Jul 2019 19:04:38 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by rcdn-core-9.cisco.com (8.15.2/8.15.2) with ESMTPS id x62J4cBZ029244 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 2 Jul 2019 19:04:38 GMT
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Tue, 2 Jul 2019 14:04:37 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Tue, 2 Jul 2019 15:04:36 -0400
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Tue, 2 Jul 2019 14:04:36 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=D1Ehrq9H8pjFJiwI9RI1QhvcWmZWy0yaILIJlQkrRIU=; b=xGEykkdkUOIESFklbZjnglobF2LuO69a5BNGjVL2p4TpW/Z20IRvNRRn22PxIggY3Hpk83/iwNQWiLg2Ag6p4Dg97A/xGYf+NYOMnRKLzjaN5bUO9gO/59wJgLIHsyetzTfZOuo3mQgvuuygP/LxDtm5KGvI/7yT0KZIdWW3iUU=
Received: from DM6PR11MB3385.namprd11.prod.outlook.com (20.176.123.12) by DM6PR11MB2553.namprd11.prod.outlook.com (20.176.95.160) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2032.20; Tue, 2 Jul 2019 19:04:35 +0000
Received: from DM6PR11MB3385.namprd11.prod.outlook.com ([fe80::496e:2b30:2186:fb23]) by DM6PR11MB3385.namprd11.prod.outlook.com ([fe80::496e:2b30:2186:fb23%7]) with mapi id 15.20.2032.019; Tue, 2 Jul 2019 19:04:35 +0000
From: "Owen Friel (ofriel)" <ofriel@cisco.com>
To: "anima@ietf.org" <anima@ietf.org>, Rifaat Shekh-Yusef <rifaat.ietf@gmail.com>
Thread-Topic: New Version Notification for draft-friel-acme-integrations-01.txt
Thread-Index: AQHVMQb4X6tqrYd/KEe6IqDPJ/uJ2Ka3rneA
Date: Tue, 02 Jul 2019 19:04:35 +0000
Message-ID: <DM6PR11MB3385A59B984127385DE49720DBF80@DM6PR11MB3385.namprd11.prod.outlook.com>
References: <156209339375.23780.16389385862360970000.idtracker@ietfa.amsl.com>
In-Reply-To: <156209339375.23780.16389385862360970000.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=ofriel@cisco.com;
x-originating-ip: [64.103.40.22]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 5bbcd0a8-bcab-44b4-149f-08d6ff201f9d
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:DM6PR11MB2553;
x-ms-traffictypediagnostic: DM6PR11MB2553:
x-ms-exchange-purlcount: 6
x-microsoft-antispam-prvs: <DM6PR11MB25531AF3D22D1CAD77748C6DDBF80@DM6PR11MB2553.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 008663486A
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(136003)(376002)(396003)(39860400002)(366004)(346002)(199004)(189003)(13464003)(476003)(5660300002)(68736007)(33656002)(86362001)(7736002)(66066001)(6436002)(53546011)(26005)(446003)(66446008)(64756008)(73956011)(76176011)(478600001)(316002)(55016002)(6306002)(8936002)(99286004)(110136005)(25786009)(14454004)(966005)(14444005)(71190400001)(6506007)(66946007)(52536014)(229853002)(8676002)(66556008)(186003)(102836004)(2906002)(2473003)(9686003)(256004)(66476007)(305945005)(11346002)(2501003)(76116006)(74316002)(81166006)(15650500001)(486006)(66574012)(81156014)(7696005)(3846002)(71200400001)(6116002)(53936002); DIR:OUT; SFP:1101; SCL:1; SRVR:DM6PR11MB2553; H:DM6PR11MB3385.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: KurJ4ZKMLloi8GVXaQhchkSW8Z0bQxFI98HE4Xtx6iksbmF720fVeT81K3gq9/DrHEsAku66lxc4Jy/m/mgSluwoViw+crFe2Z85IoJMo9qRcetzE2mRYRajdLbmsAJph217XS4LG13v1UKPzWm7PbwsN4HVR/Z2Q4tEyW+3DeGb3wegbQ+vkimsadCAF6/pyI11w/FqsyLbKP9peVhVHLnD5qGgd3Rujm/l+mNOF7reMR5SBj1hQHgxWxpEAlPwuFsNu2DSaVJ14i4qFe021ZJ2FcwfayXHARj8UFrVmSfM+a/GMtBlZgqGx+W11NyEj7UfzzkT8deLsRC3ZKbQoqACX5wd9wc2FAAwvcMsSvqJodp2EC78RBuKrce0+YRv1HtBLebDQa3opYtoeZQcdEJtntDnpn/CvqebOiYn5U8=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 5bbcd0a8-bcab-44b4-149f-08d6ff201f9d
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Jul 2019 19:04:35.1859 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ofriel@cisco.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR11MB2553
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.13, xch-aln-003.cisco.com
X-Outbound-Node: rcdn-core-9.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/BBMIMDQv7gt2Sitas-kVL5kl-UM>
Subject: [Anima] FW: New Version Notification for draft-friel-acme-integrations-01.txt
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jul 2019 19:04:42 -0000

All,

This early draft https://datatracker.ietf.org/doc/draft-friel-acme-integrations/ covers how BRSKI could potentially be integrated with an ACME CA for cert issuance.

What is the WG initial feedback on this idea? I have requested 10mins at IETF105 to present/discuss.

Related work is https://datatracker.ietf.org/doc/draft-yusef-acme-3rd-party-device-attestation/, which covers how ACME could be used to issue device certs, but does not use BRSKI. We are currently discussing offline with Rifaat how we could potentially integrate both approaches. 

Owen

-----Original Message-----
From: internet-drafts@ietf.org <internet-drafts@ietf.org> 
Sent: 02 July 2019 19:50
To: Richard Barnes <rlb@ipv.sx>; Owen Friel (ofriel) <ofriel@cisco.com>
Subject: New Version Notification for draft-friel-acme-integrations-01.txt


A new version of I-D, draft-friel-acme-integrations-01.txt
has been successfully submitted by Owen Friel and posted to the IETF repository.

Name:		draft-friel-acme-integrations
Revision:	01
Title:		ACME Integrations
Document date:	2019-07-02
Group:		Individual Submission
Pages:		17
URL:            https://www.ietf.org/internet-drafts/draft-friel-acme-integrations-01.txt
Status:         https://datatracker.ietf.org/doc/draft-friel-acme-integrations/
Htmlized:       https://tools.ietf.org/html/draft-friel-acme-integrations-01
Htmlized:       https://datatracker.ietf.org/doc/html/draft-friel-acme-integrations
Diff:           https://www.ietf.org/rfcdiff?url2=draft-friel-acme-integrations-01

Abstract:
   This document outlines multiple advanced use cases and integrations
   that ACME facilitates without any modifications or enhancements
   required to the base ACME specification.  These use cases are not
   immediately obvious from reading the ACME specification and thus are
   explicitly documented here.  The use cases include ACME issuance of
   subdomain certificates, and ACME integration with EST and TEAP.

                                                                                  


Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat