[Anima] FW: New Version Notification for draft-ietf-anima-brski-prm-13.txt
"Fries, Steffen" <steffen.fries@siemens.com> Fri, 05 July 2024 12:01 UTC
Return-Path: <steffen.fries@siemens.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 82496C1D5C7E for <anima@ietfa.amsl.com>; Fri, 5 Jul 2024 05:01:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id akgAOtsYfdEN for <anima@ietfa.amsl.com>; Fri, 5 Jul 2024 05:01:28 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2057.outbound.protection.outlook.com [40.107.22.57]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B35A9C1CAF51 for <anima@ietf.org>; Fri, 5 Jul 2024 05:01:28 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=SS4zzL7eh5aD11PY4fRbRqJm0SwGWVSWTxcbr9rKxroY/hwt/XhWP8itAWtHRkdp1veo+hz2VwCZ/ogswWpjeIL4/iSJp4J7M+YzSNMB2Rh73fyf7E8xaysS3iP8VqF3U5yskQbaPXvntXCSgMlDs8K1uVbX+RbksJPX/0udIDfu8exCkvLtMOAq3JfQYuMNhz5x9I0Qd+iPwffkZIkQVmu8K4oiPlQp0jPH6WUveKcVhdm6ZS1UJDKHjw4QHSGeV0OQ5AVWUAC5XHSjZS/WPOvhg19XmGa61QoD6+QOH5m2rWpT9DSrl2nd2S7TPPpUnevpf9VNAdyKKGQBQ7/hDg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=AT35vZnWsItHMZHEGVG6giID1ZrKD0kUIsCy8G3GI44=; b=cXID3IWU/aXFeBJ2gUEQYqskRFzeoc6yZ1F4ubu5I1xxhk+9e6J6NqfYFsJyH4zWlzQbUxCdQ2R54gcavYNzNDW24Fj9Zb54iSn78Bb7vQh8dOtXWLWhhDX7sND0nvG7kL+DGNAZkugM1zRSZztnUfXe9mcY+uK45IHvnl47dmeUdzPyCx50e4xFeSsWzXEJf1jSd3baiXcMmrEVBYesjdXZzNlTq3wsfVkz9cgYNIJDdvuGhdS1laLgQ9aJJSJIE8ipapWP06WlI+4wvEuYvsYdwRLYhWhsGyh+JxvzhpL1tnGtXhcRe7fjAXK4H9zs3wLcdIDEv8J/M7CF4SNatQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=AT35vZnWsItHMZHEGVG6giID1ZrKD0kUIsCy8G3GI44=; b=wm7ltq/qj9s5z5GgSfCKptVrZcxVMm9hWD/KtSUvLn+BZUv5UX+QrlMJPe/Fn7uwAi8+X3zmShr8hZ3oEzt6O2qfHlNLmOg4YvLPH9WSZbuxAEfqcvAJL2d/faX7t1OrzV4zqLy6KcxGHNwqQs5bRIneWBaU91hT46zyiLCWyKay2A0XlxPaFkB780qqqWd+Z1QUQ4zk1so/7mjq7BMDDTlFwvqkbQ3llJQy/avTCWNBuzOfzRivLGcNlLzHydsLKK0N9oaOgcrQKR7rA7VcIIMQRUC4OFQiZlO7kAL5vuEgYYUFoiJ/LIsvoZdGfqgP4ifdz40jsIoxN0sEUn2dBw==
Received: from DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:3c6::22) by PAVPR10MB7057.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:302::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7719.32; Fri, 5 Jul 2024 12:01:26 +0000
Received: from DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM ([fe80::634b:e5d0:8c00:762a]) by DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM ([fe80::634b:e5d0:8c00:762a%3]) with mapi id 15.20.7741.017; Fri, 5 Jul 2024 12:01:25 +0000
From: "Fries, Steffen" <steffen.fries@siemens.com>
To: "anima@ietf.org" <anima@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-anima-brski-prm-13.txt
Thread-Index: AQHaztH9HZnq4x4lRkCExjCIwY7OCLHoBriQ
Date: Fri, 05 Jul 2024 12:01:25 +0000
Message-ID: <DB9PR10MB6354BC718CB7187FACFC49ADF3DF2@DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM>
References: <172018042130.1351411.7064307168106181847@dt-datatracker-5f88556585-g8gwj>
In-Reply-To: <172018042130.1351411.7064307168106181847@dt-datatracker-5f88556585-g8gwj>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=52c1eb2a-a949-4392-8599-55e3b157966b;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2024-07-05T11:55:07Z;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DB9PR10MB6354:EE_|PAVPR10MB7057:EE_
x-ms-office365-filtering-correlation-id: baa9c621-fb6b-4751-3951-08dc9cea31d5
x-ms-exchange-atpmessageproperties: SA
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|366016|376014|1800799024|38070700018;
x-microsoft-antispam-message-info: 7HGL7LJZXub4gryZ+TjAGtgYDzTj4Qm2UEB0UpnExaEnW4qyqGyTZESDMnxOd+zCCwLt0ovs577NZG/rwnYZCpisr5UlDrksJQpkBz5vklf4AfgP7uHQI73J7WMPp3M288VZAx+mk9HKiBJEo7g0OdAtfSbzcbKyXaeSMj0F4E9kSykWVSoSLfY837i6vqmj7LShkZj6wGL0PAaSx9V8+GNKhz1c/CftpS8IJTToYWb98fvyns6nhAHBCk3tW7ISoXZeKQGMu/UIcGnKJ8Ali0/OpQNBLCDoIus4Avz3LF65OBahHhrNozdHUcwDv+4WimHrLI/4qi0vEqzouOwpWf29ENRbgd83v/mkOOd1PugRU4rf6hGqIIUirQVmIaQW8mQ9IWQWXPoV/7uuHMserFs+PaGXJJ44hlLcyNV/lG9OnDTBg7IfB3DEdYhMO/mG0EmzJki151bw18LGft94QTDZs1cTxdpujf1KZ9MboXerxwexzAUBgICY9P1VprVn0/GvTRkXwpXORECvF3JcDQ2+LrhLVT1UKqem0RYPZroZIMIN0lKjzv+m48KYUBEzuA/Mvl12fee771d0A85pk8UFxECeYlnjUBcxIJ70EPODL1tFisCicBuuZNueSAjr4kuL49OX2whGlmRjKh76PVcZa2NsRASrqqn9Sxc0p0N6Fi/CAITkNETVC/Kadg8F77fREk+OOp7tdT2+vgzhDYOP8jso2il8Lb92uxX+kqD4xnRWTPkPRWB125PwF8SXHjolk0c6+ptqZFq1WXTBXSYvZTU++UnxbvWaiXS1U8tv2M1zS6TJGe0GJzO2UsSS0X3YW51Pqe0MzH8NcIZ+JZiO9ZvcCqLQSjs+7BJt0u3XXFRvVDXv+sTcGIF8zB1X/eXJO6tOSLulyEsQDvDI7eCE1SS58ws8kb4jI4sfuBe+6G8qcGJ8Y8pR++LwkI2J+8uFrW+NcbtrnFpJme6lVrBcaOHcoRYuxG6/fLHXlYWIxVbCM0/PQl/hZjUY6u1woi6wzVtE0ZPpp3u6Nr/kxmtqztSgAVKOz4H84AMZHbcIZE/v/DChbfxKA0c1h6p9hkGkQmEnhXGYN7Tt0M24NUH4rDn4dshOynOKFeXhiwD4ou/cg0exPYcXBQ+1NqeZXz4lbLWZ5pTC7BwLXqrzHbpTs2nlm6gxNVxXoeftrhAdf4EPBHNOXcsbls5FinDmDsbYq1lizO9zj5gSu1+0zmovgEhuz44OGzpnSpb9Z7qLdzdu3E2HpXTEosJAiA+1rSyirQmNgk7/cBzeaz1RQKfFTOGOpEnMZe5NAuR5ve2VSBaCmUSK/3Pkrq08Ne1uJ6ShWyfP0QSwmGUnqVLyeR55v5giK+TBg8na1pOqMnU=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(376014)(1800799024)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Yl7RV4vx6ynN5isbPjhwno+DP3LpF7lX9RBropyKyV2Ur+fX20ld40jQNow1mphNIxmsg0uA3rrkQ+6nNa68rXaqxL5bAu0p9fMN8TIm9rwL50C5bTI63vRrT4752ZB2OpyWZtHysudF+iDN+FxJOUKE+JvrNAEw1rYDk0a7deH+ISQzk+3ELuIvCSQqKg8lXm91e/H7An9EVDsnFYf6qnucCEpVF1n1Jbuhv6ESgCwQb7m2A/EcmrJv4PnrgORWLms3r0c4KYFcBjuywv6FDYfAj2MQfWtEhvdD8CLwZirBGbfVx3bU3vmMx9Jiw+qmhISnkLrRFyNOh5riIEpkvLHSG+rCohmbt3S+/4cqnt4tsXupKVwa6Oxv/ym2KUtCDyCjxPRBv0yL5prTgOGb2uEzTVsFhPU6xM7KtJMpWg6qaNgb8nFjoSFd/J3zz6y7obxY91R4BQC1+kX8beawoGM72LuPHlf9G32dmwcZUxUKkNcvYcH1UYvx5zWQ+HqNWfeRLWg0J3L6xV4RkzQgPFKMe/SSmM88cM95iegA38y8BvadFvm6DPieZS3PJYYBBVl+BkoJBDCrGSruBoWHexdduYitfougd+FgR843sGUTeIgl3RgydTmbGMvpyijcrFH1tpvfFTFYaQP/03C+GP6mRyRlKM4unhh/4VDwBs1gUYxFk2alof/QIp8DiFD7r1cm/Z/I4ppgZLIzSd4qJIFHIy0bPZ3/EJH6Nq2Ue3VhKQ3FCrZ/BtZ5JcEbj7FYMsjNtgCdZ1g2jETZJCSqAVdOwCI8WbRhdXbIWWx79Zhw21S0vBLJc8oRq7AOpdF84FBuhnrShjd2KlkM0vUetie7bYzynU+ytANjFqU8yCHrGE2FE3mZWKMe5z83Iy2RFZThv4sZ8bfxBvgpoedOeN97qVnSG8FeCeqI5jODvYeWMVzLjEkK+oVSTi48UBTaOWiJWheOA5nZMh4+NFXQuE62hLHemwdWunDtDqv90I7yUlqYKfKis+qBnbBra5zhbcV1ae7mPcWwuXO17naylleim/kgjtpDr49CQVsqas4u3ZDfY9PlMtXLtIdGAdCNCm8K4GZXjpcSEtXqt58wOf9BmGN6wuNkXDK/+wtLATBYhR0ZmDmSYjSLzEi7H46pmSu5sMaZw/NpMjEXRTtf6jc249Xxsl05FX/G5toMd6OuGRiwClA5tFxbsdxDxcbWxE9LmL36q+UX5PumzHWXPNQGof9KoDD8DyiNuJJtdQ2R2PTCWPqhOZ82JBhCwTEZrszGGVLdsaP2+wdp1HLztyYMjhaoISQTzEqwRouGkOOXTnySo5F16I0ROpIHv+bRSUixXoduh+C/xe6jLfEib7zNWjNgbu1qB/IIqYbPoJ2gmM53kXJc6qnBgTYQptN0H+zpjVCTszJep6jRsMeMBoHmhioYuJE4E5Qd05lflQaKTLdAMo2q89l3heJ0Tog4Wu9PUbQY+LfM21qfxkNPOhM1grrpn3paksFmLDUy+oN3+9oiiBY1B21JgaTDUUCvmn69FAyxQoPTb1fJn2Xoq14na7AP3wX0hvDWc7jtYrZ602GfcTp4J9AlEyD5iYI4
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB9PR10MB6354.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: baa9c621-fb6b-4751-3951-08dc9cea31d5
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Jul 2024 12:01:25.1869 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: /zXmVAh+6ASdBB+aJEioU2IrX69WCjmOeoI0qx2xNtNb4dUR3Wj689jqaP2dDxJHKQ5LOzO0ZEsCGthdrd7IrAgQsbXCVu3BuOJhWcD1Tqo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PAVPR10MB7057
Message-ID-Hash: ZQ7U43LHXEAJGOKOVJ7WKEIZHRIPJRSP
X-Message-ID-Hash: ZQ7U43LHXEAJGOKOVJ7WKEIZHRIPJRSP
X-MailFrom: steffen.fries@siemens.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-anima.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Anima] FW: New Version Notification for draft-ietf-anima-brski-prm-13.txt
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/ESbYuwtuzOklIIT7nspM2mBs4ck>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Owner: <mailto:anima-owner@ietf.org>
List-Post: <mailto:anima@ietf.org>
List-Subscribe: <mailto:anima-join@ietf.org>
List-Unsubscribe: <mailto:anima-leave@ietf.org>
Hello all, We just posted an updated version of BRSKI-PRM. The draft includes several changes resulting specifically from the last part of the detailed Shepherd review (big thanks to Matthias), which improved structure and readability. Here is the list of main changes from IETF draft 12 -> IETF draft 13: - Deleted figure in Section "Request Artifact: Pledge Voucher-Request Trigger (tPVR)" for JSON representation of tPVR, as it has been replaced by CDDL - Updated reason-content description in status response messages (enroll-status, voucher-status, and status-response. - Updated CDDL source code integration to allow for automatic verification - Reordered description in Section 7.3 and in Section 7.2 to better match the order of communication and artifact processing. - Updated CDDL for the request-enroll trigger in Figure 13 according to the outcome of the interim ANIMA WG meeting discussions on April 19, 2024 - Included statement in Section 7.2.2 for using the advanced created-on time from the agent-signed-data also for the PER, when the pledge has no synchronized clock - updates examples in Annex 1, 2, 4 to match prototypes - updated RVR to contain idevid-issuer as described in RFC 8995 in Section 7.3.2 We will provide a status update during the ANIMA WG session of the upcoming IETF meeting. Best regards Steffen -----Original Message----- From: internet-drafts@ietf.org <internet-drafts@ietf.org> Sent: Friday, July 5, 2024 1:54 PM To: Michael C. Richardson <mcr+ietf@sandelman.ca>; Eliot Lear <lear@cisco.com>; Michael Richardson <mcr+ietf@sandelman.ca>; Fries, Steffen (T CST) <steffen.fries@siemens.com>; Werner, Thomas (T CST SEA-DE) <thomas-werner@siemens.com> Subject: New Version Notification for draft-ietf-anima-brski-prm-13.txt A new version of Internet-Draft draft-ietf-anima-brski-prm-13.txt has been successfully submitted by Steffen Fries and posted to the IETF repository. Name: draft-ietf-anima-brski-prm Revision: 13 Title: BRSKI with Pledge in Responder Mode (BRSKI-PRM) Date: 2024-07-05 Group: anima Pages: 103 URL: https://www.ietf.org/archive/id/draft-ietf-anima-brski-prm-13.txt Status: https://datatracker.ietf.org/doc/draft-ietf-anima-brski-prm/ HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-anima-brski-prm Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-anima-brski-prm-13 Abstract: This document defines enhancements to Bootstrapping a Remote Secure Key Infrastructure (BRSKI, RFC8995) to enable bootstrapping in domains featuring no or only limited connectivity between a pledge and the domain registrar. It specifically changes the interaction model from a pledge-initiated mode, as used in BRSKI, to a pledge- responding mode, where the pledge is in server role. For this, BRSKI with Pledge in Responder Mode (BRSKI-PRM) introduces a new component, the Registrar-Agent, which facilitates the communication between pledge and registrar during the bootstrapping phase. To establish the trust relation between pledge and registrar, BRSKI-PRM relies on object security rather than transport security. The approach defined here is agnostic to the enrollment protocol that connects the domain registrar to the domain CA. The IETF Secretariat
- [Anima] FW: New Version Notification for draft-ie… Fries, Steffen
- [Anima] Update on draft-ietf-anima-brski-prm-13.t… Fries, Steffen