[Anima] Request for feedback on new version including title and repo name - Re: I-D Action: draft-ietf-anima-brski-async-enroll-05.txt

David von Oheimb <David.von.Oheimb@siemens.com> Wed, 09 March 2022 14:14 UTC

Return-Path: <David.von.Oheimb@siemens.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 030AC3A11CC; Wed, 9 Mar 2022 06:14:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.904
X-Spam-Level:
X-Spam-Status: No, score=-6.904 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G2n2HSkyXdZW; Wed, 9 Mar 2022 06:14:45 -0800 (PST)
Received: from gecko.sbs.de (gecko.sbs.de [194.138.37.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 234793A12A7; Wed, 9 Mar 2022 06:14:19 -0800 (PST)
Received: from mail2.sbs.de (mail2.sbs.de [192.129.41.66]) by gecko.sbs.de (8.15.2/8.15.2) with ESMTPS id 229EEABV028725 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 9 Mar 2022 15:14:12 +0100
Received: from [139.22.40.113] ([139.22.40.113]) by mail2.sbs.de (8.15.2/8.15.2) with ESMTPS id 229EE8wg020852 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 9 Mar 2022 15:14:09 +0100
Message-ID: <391dd098bf6c11bd456a99ca5ebaa57dd69df89b.camel@siemens.com>
From: David von Oheimb <David.von.Oheimb@siemens.com>
To: anima@ietf.org
Cc: Hendrik Brockhaus <Hendrik.Brockhaus@siemens.com>, "Fries, Steffen (T CST)" <steffen.fries@siemens.com>, Eliot Lear <elear@cisco.com>, Michael Richardson <mcr+ietf@sandelman.ca>, anima-chairs@ietf.org
Date: Wed, 09 Mar 2022 15:14:08 +0100
In-Reply-To: <164669170301.9071.6233639082825237833@ietfa.amsl.com>
References: <164669170301.9071.6233639082825237833@ietfa.amsl.com>
Content-Type: multipart/alternative; boundary="=-FbbYUcKhPL2MxlMhkk0k"
User-Agent: Evolution 3.38.3-1
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/D9Aml3Xta9H08OjvQDFeFtorR8E>
Subject: [Anima] Request for feedback on new version including title and repo name - Re: I-D Action: draft-ietf-anima-brski-async-enroll-05.txt
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Mar 2022 14:14:48 -0000

In preparation of IETF 113, where I'm going to provide a brief status
update on the draft,
I uploaded on Monday draft version 05 of BRSKI-AE, with the following
changes since version 04:

* David von Oheimb became the editor.
* Streamline wording, consolidate terminology, improve grammar, etc.
* Shift the emphasis towards supporting alternative enrollment protocols.
* Update the title accordingly - preliminary change to be approved.
* Move comments on EST and detailed application examples to informative annex.
* Move the remaining text of section 3 as two new sub-sections of section 1.

Are there any objections to updating the title to:

   BRSKI-AE: Alternative Enrollment Protocols in BRSKI

which reflects much better the new focus of the document?

Moreover,  I suggest renaming the repository etc. to, e.g.,

   https://github.com/anima-wg/anima-brski-ae

Unfortunately we have not heard back from Eliot regarding the subsection
on EST use.
So all we could do there was to try to maintain it in line with the rest
of the document,
while more work would be needed to clarify open points and fill in some
more detail.

We recently found that also the subsection on CMP use needs some further
detail, 
as indicated by the ToDo there. We are going to provide it with the next
version.

To sum up, the only open issues that we see are in section

   5. Examples for signature-wrapping using existing enrollment
protocols

Feedback on the revised BRSKI-AE text (i.e., all of the document) is
most welcome, 
ideally already before the conference such that we may address issues
there.

 David


On Mon, 2022-03-07 at 14:21 -0800, internet-drafts@ietf.org wrote:
> 
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the Autonomic Networking Integrated Model
> and Approach WG of the IETF.
> 
>         Title           : BRSKI-AE: Alternative Enrollment Protocols
> in BRSKI
>         Authors         : David von Oheimb
>                           Steffen Fries
>                           Hendrik Brockhaus
>                           Eliot Lear
>         Filename        : draft-ietf-anima-brski-async-enroll-05.txt
>         Pages           : 30
>         Date            : 2022-03-07
> 
> Abstract:
>    This document enhances Bootstrapping Remote Secure Key
> Infrastructure
>    (BRSKI, [RFC8995]) to allow employing alternative enrollment
>    protocols, such as CMP.
> 
>    Using self-contained signed objects, the origin of enrollment
>    requests and responses can be authenticated independently of
> message
>    transfer.  This supports end-to-end security and asynchronous
>    operation of certificate enrollment and provides flexibility where
> to
>    authenticate and authorize certification requests.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-anima-brski-async-enroll/
> 
> There is also an htmlized version available at:
> https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-async-enroll-05
> 
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-anima-brski-async-enroll-05
> 
> 
> Internet-Drafts are also available by rsync at
> rsync.ietf.org::internet-drafts