Re: [Anima] MichaelR/Rob/*: RFC8995 errata concerns
Michael Richardson <mcr+ietf@sandelman.ca> Wed, 31 January 2024 04:39 UTC
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33127C151094; Tue, 30 Jan 2024 20:39:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.807
X-Spam-Level:
X-Spam-Status: No, score=-2.807 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2PONBN38AlbW; Tue, 30 Jan 2024 20:39:34 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A8F42C151077; Tue, 30 Jan 2024 20:39:33 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id 2E9A83898D; Tue, 30 Jan 2024 23:39:32 -0500 (EST)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 65a7R6pf3qAG; Tue, 30 Jan 2024 23:39:30 -0500 (EST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id A91053898C; Tue, 30 Jan 2024 23:39:30 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sandelman.ca; s=mail; t=1706675970; bh=2aSOiloiH7uKshyMQzYXsCBc2JFLxNxrdPb1krUnlGI=; h=From:To:cc:Subject:In-Reply-To:References:Date:From; b=syQ3Gwv5+SR/BWnhtflnD792Pzmi5xwG9hMizkff0QRJIkRkZWUPl6HDgPEstsyIF n4zZ4Zr0d7VSpGzvmKo6Eo8lnmCjgvFFFNUyIpZWMFX4BxuMp1fn17Kcn1URtK5nJ5 SG76bO4UERHuONW0NBS1l1dFNW/pWVt5AGF/zS1ZvSHdOduftZJV1/Jx9c69BP0bix K9Fvp0I3MfFsdh9r0i7Z0dU2DjZzatZM55gauYycWMAqDTeS0toPTlyNpdMucdc805 TWt8mG23J1EX07FJCTOZsNX7z2V+WScCEZWDBvf9bsp5JZf+WA24MNG+TjAKXs5DL0 dgm6kK+BBjX4Q==
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id A11F273; Tue, 30 Jan 2024 23:39:30 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Toerless Eckert <tte@cs.fau.de>
cc: "Rob Wilton (rwilton)" <rwilton=40cisco.com@dmarc.ietf.org>, "anima@ietf.org" <anima@ietf.org>, draft-ietf-anima-brski-cloud@ietf.org
In-Reply-To: <ZbmxALT76BcRakxO@faui48e.informatik.uni-erlangen.de>
References: <20210805211714.GC57091@faui48e.informatik.uni-erlangen.de> <9465.1628200645@localhost> <20210806003134.GA47840@faui48e.informatik.uni-erlangen.de> <7466.1628378147@localhost> <LV8PR11MB853636871E286AA42FDAE178B56C2@LV8PR11MB8536.namprd11.prod.outlook.com> <29353.1705509924@obiwan.sandelman.ca> <ZbmxALT76BcRakxO@faui48e.informatik.uni-erlangen.de>
X-Mailer: MH-E 8.6+git; nmh 1.7+dev; GNU Emacs 28.2
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Tue, 30 Jan 2024 23:39:30 -0500
Message-ID: <7127.1706675970@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/T0647aIwfwuOBkrBbM5F35ksDRY>
Subject: Re: [Anima] MichaelR/Rob/*: RFC8995 errata concerns
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jan 2024 04:39:38 -0000
Toerless Eckert <tte@cs.fau.de> wrote:
> I am not sure what to do about this in general, but i think the really
> important issue is that we ask for support of SNI in BRSKI cloud to
> support actual cloud deployment (with shared IP address) of registrars,
> when pledges only have TLS 1.2 - because RFC8995 did not require it.
> So, i did open: https://github.com/anima-wg/brski-cloud/issues/134
I replied. There is no SNI issue.
We actually thought it all through, and that errata was the result.
There is a potential issue in 3.3.1 that reading the issue made me think
about. But, it's not an SNI issue. It's a Implicit Trust Anchor or not issue.
--
Michael Richardson <mcr+IETF@sandelman.ca> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
- [Anima] MichaelR/Rob/*: RFC8995 errata concerns Toerless Eckert
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Michael Richardson
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Toerless Eckert
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Michael Richardson
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Rob Wilton (rwilton)
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Michael Richardson
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Toerless Eckert
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Michael Richardson
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Toerless Eckert
- Re: [Anima] MichaelR/Rob/*: RFC8995 errata concer… Michael Richardson