Re: [Cbor] [Rats] [Last-Call] Segmented strings (Re: EAT profiles (was Re: Iotdir last call review of draft-ietf-rats-eat-13))

Thomas Fossati <Thomas.Fossati@arm.com> Wed, 22 June 2022 08:35 UTC

Return-Path: <Thomas.Fossati@arm.com>
X-Original-To: cbor@ietfa.amsl.com
Delivered-To: cbor@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0733FC15D48F; Wed, 22 Jun 2022 01:35:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level:
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=mFVB7rw7; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=mFVB7rw7
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mMzDTCHNWjLa; Wed, 22 Jun 2022 01:35:14 -0700 (PDT)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on2050.outbound.protection.outlook.com [40.107.21.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB7A1C157B3B; Wed, 22 Jun 2022 01:35:12 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass; b=SNcaDQ3ae+EzMpPsUb769upttV4g+J/6Einkq4zbFn320/nNhfEn+WbOrx3Drn2w9eMZKZt6P9gTYxvybT+c7UvXgpjLV4+vTQxT5/DJcEltDW8oM4CxQmoF8F3fNfDUOzAtH6zWL/SpHqxYE8/TP/QjYdfm4pIwIcySXQMVQTNZU34nPKgGIl6XMfEQ8UQFXZYBD5M21VZJSbLEOvY06sFgCALMG9tkKYsnCVUftYBj8rOHXSkbW2BjCD+ya8LAYU4+Q3yWBYy27IoiAYxOasT2M8lX+Gml69YGnKwySvPVOKB6Wty7JZ8TMHo6ueAgiPxmqyS4Y0e4eacafCYJzw==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=C5IFiIU3G8DrT4GLNJfYvqAR/FMIzj407VgmTlwY73g=; b=XnUrIPCeEnlz7WAY+e2GDTw6no8xFjBGwypr7cZ9tH3+s6/75KPeo0srWAm7mmJSucQGBUllF0/v3BQhgP46LsHOVvMBLmxArvA1PR8jWm4rdo8FGzxh7FrEdOtQm3+wETlq5GjrONDn9f54hd52lX1P27qTUE5ZzIp2v2E5/pfANNe8IgJGEzGaKDW8vFSa8+7/WRhH3RmiIKKR5JkmPrrcrATsQlqKdaHcyiIIX2NqBFkS6LT0juOTY2ExXaGZiXWSjTy/f3SXMHqJpKX9bTaZd/Dl5ufrQ8b5MZWZgEZ63ijaI2PzDeUKhFmFkibPb5ZNThEH68QV+oyJpsu+cg==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 63.35.35.123) smtp.rcpttodomain=ietf.org smtp.mailfrom=arm.com; dmarc=pass (p=none sp=none pct=100) action=none header.from=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1 spf=[1,1,smtp.mailfrom=arm.com] dkim=[1,1,header.d=arm.com] dmarc=[1,1,header.from=arm.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=C5IFiIU3G8DrT4GLNJfYvqAR/FMIzj407VgmTlwY73g=; b=mFVB7rw7afr4+3kywJ4nydidAaKy7EkX54q/LgN5BZZVczU2SWgsh+TOGTuB7UrquR4dC8a+x1ml+heIT3TdhJaiGHHOgRwR1MK0chySNWj4SQY7iFimW6valLSoPWPeEfiDgp+3FhTeaBqIunWXZ3a25TQUH491hn0ZmKJfco4=
Received: from AS9PR06CA0158.eurprd06.prod.outlook.com (2603:10a6:20b:45c::16) by DBAPR08MB5797.eurprd08.prod.outlook.com (2603:10a6:10:1a1::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5373.15; Wed, 22 Jun 2022 08:35:08 +0000
Received: from VE1EUR03FT038.eop-EUR03.prod.protection.outlook.com (2603:10a6:20b:45c:cafe::f8) by AS9PR06CA0158.outlook.office365.com (2603:10a6:20b:45c::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5353.16 via Frontend Transport; Wed, 22 Jun 2022 08:35:08 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com; pr=C
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT038.mail.protection.outlook.com (10.152.19.112) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5353.14 via Frontend Transport; Wed, 22 Jun 2022 08:35:07 +0000
Received: ("Tessian outbound 6f53897bcd4e:v120"); Wed, 22 Jun 2022 08:35:07 +0000
X-CheckRecipientChecked: true
X-CR-MTA-CID: d591746d9b1727e2
X-CR-MTA-TID: 64aa7808
Received: from ea1df67c19a3.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 1EFCDCFD-CC21-426D-B7B1-87D75378BA1C.1; Wed, 22 Jun 2022 08:35:01 +0000
Received: from EUR02-AM5-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id ea1df67c19a3.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 22 Jun 2022 08:35:01 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=U1Y/wTHb+UFGZan4tq55GAFXo+8QeviDi2HCA7ksPK1W8qtiN9XZ2mmD9Gr0Cz3KbUmppnHWZlVA4WBDRhQZ9FiFvx1wRFyor9460/ftPEZrN03MutaTalpe7rRJBHQQVOU6/3VdB5yOLMQPowEvq29AOXFIHII4bT7c50xk9rpjMbGcBakxvLsxeug/WjACAWCOK7tfD8WMvKrXPEfBxGD62Yd8y3kFj/ETAkTh0PLyVAUrS864MZekecJ8WDM5aXUH+Rn2irzlpFPaSyrH+sgKP7DVwcxYlhGrkKknsGc/TqvbeQbLz1Ex3QxZX/SNhv3McAy0jdxAePRYDFiNWQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=C5IFiIU3G8DrT4GLNJfYvqAR/FMIzj407VgmTlwY73g=; b=SFmgJdG3g+0hDU2h1du1F2VElq1zpAFp+T5t/b8Eo2PLclX8OTY/xd3sFE3x8jM2dDhQ+BQF4NKaX5/nXiZClF6HRv2QHIAE/RgxPbCpb/i4yeYbmLnP/euUwlX+FlNw4FzC9/uf0EvSl6rvY5YkJWwGERSJoUnY7AuYEK1L3oLH14ECCaTyMnsmA6flLoNFbwEyDNSaXfaZFl9XIjw9daQphHJ+dVRt5MtTEPAWzv/W8JlAPSpBzQ5Be0lbSTjs/oWGeyVu5+tVD4Rz9WflJsKffIlmYvxtFA+Lb1mNEsK0WN6b6mDN3FpvSoH46CZqQcCJvUPMtcHeMGw3n/Lzzw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=C5IFiIU3G8DrT4GLNJfYvqAR/FMIzj407VgmTlwY73g=; b=mFVB7rw7afr4+3kywJ4nydidAaKy7EkX54q/LgN5BZZVczU2SWgsh+TOGTuB7UrquR4dC8a+x1ml+heIT3TdhJaiGHHOgRwR1MK0chySNWj4SQY7iFimW6valLSoPWPeEfiDgp+3FhTeaBqIunWXZ3a25TQUH491hn0ZmKJfco4=
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com (2603:10a6:10:251::8) by DBBPR08MB4743.eurprd08.prod.outlook.com (2603:10a6:10:d9::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5353.15; Wed, 22 Jun 2022 08:34:59 +0000
Received: from DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::a45e:c9e6:74af:caff]) by DB9PR08MB6524.eurprd08.prod.outlook.com ([fe80::a45e:c9e6:74af:caff%3]) with mapi id 15.20.5353.022; Wed, 22 Jun 2022 08:34:59 +0000
From: Thomas Fossati <Thomas.Fossati@arm.com>
To: Laurence Lundblade <lgl@island-resort.com>, "\"Martin J. Dürst\"" <duerst@it.aoyama.ac.jp>
CC: Carsten Bormann <cabo@tzi.org>, Eliot Lear <lear@cisco.com>, "iot-directorate@ietf.org" <iot-directorate@ietf.org>, "draft-ietf-rats-eat.all@ietf.org" <draft-ietf-rats-eat.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, rats <rats@ietf.org>, "cbor@ietf.org" <cbor@ietf.org>
Thread-Topic: [Rats] [Last-Call] Segmented strings (Re: EAT profiles (was Re: Iotdir last call review of draft-ietf-rats-eat-13))
Thread-Index: AQHYfJa5f8Vysphih0qslkLeHVQeB61JBsyAgBIjeV0=
Date: Wed, 22 Jun 2022 08:34:59 +0000
Message-ID: <DB9PR08MB65243BF31B5E2336D0E594719CB29@DB9PR08MB6524.eurprd08.prod.outlook.com>
References: <165443386776.35361.12898474920348394274@ietfa.amsl.com> <E267AEDE-D1DB-415B-B28F-DD78A517D27A@island-resort.com> <A38F37B7-2E81-451F-86BA-0A041760EB7E@tzi.org> <9E4661C8-DFB7-4BC3-A7B5-150C774917F0@island-resort.com> <8C044EB7-92CF-4306-9025-FD667E1B0F22@tzi.org> <B7C27559-92B6-4426-821B-431A08341C72@island-resort.com> <6CDA1CA0-A59A-4ED7-903F-0B6829F08075@tzi.org> <AC2E17A1-52E7-455F-8959-091D58AA291F@island-resort.com> <9a938d66-55b9-c4e4-a5cf-0d655a90fcbd@it.aoyama.ac.jp> <42D33BB4-CEBC-41C0-BDA3-947BD015634E@island-resort.com>
In-Reply-To: <42D33BB4-CEBC-41C0-BDA3-947BD015634E@island-resort.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Authentication-Results-Original: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-MS-Office365-Filtering-Correlation-Id: ad292ea2-c526-434c-fae7-08da542a1d49
x-ms-traffictypediagnostic: DBBPR08MB4743:EE_|VE1EUR03FT038:EE_|DBAPR08MB5797:EE_
X-Microsoft-Antispam-PRVS: <DBAPR08MB5797BEE5142C2D7CE9C471359CB29@DBAPR08MB5797.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: kpYAbCNlM8/inFGjd8aFQiw5rOsGEyB4KFCEQ45Qimg9FuBeucaHc84MP+J3gCbWLjyVviJI0U8NjgwqZMmIIGbtmPGJxSQ/7Fqy+NZsCCbHcFOJoaddB+bx5iub4531Hhl1i9pa5ZHtcxx1tOlzUxVdSkMIqp/qG1Y82dG6yJ6R6sFjXnYArSXKAhEt5Zdv/meQRf86XFgbf9rRCNQCfOjQkzFT8XL1Wwtyxh2zWMpNN5f9LYVEOXtiljva8r22EO2MI0dkwyJ8W/UoT+expjKPXULxpYvSMBxCsukasdlbUAiprR7SPbAC3A8l+2XHcaQEn+pSREXUrs6kQJiwvQkR/XBVkrUADou9JgZHxXwiulyBP7e3Sm1pbXNZX3Tbd4zlYIvEs/3VlNwdziaC7y76KR/M6UyWQarrow8F3jJpqSr2Iuns5QJGKbR08oLf+EKXY9edpL1VBsh0uaKdHgQv44STUChKEw6knGl6BIYOQTubsglJd4sw+9r6aunuHJ6UYEB2PvDQwmV+Gn1AyVy5/s35kp/u+vbdJ45BZLBaXTfyFnGvuNUYZqUF70EbStlhhx7P8EnO9y8NQtDUmt547SUtbvGmH3XEycerXxIbN37nf+SlGQKN0mkMPOyowBqbQ4RTWIxi8L6sAapzcjD9nWqP9K5HonHCshkAu/QZejZ6rYRNk70xjJxbQB1u5vgjgztTaSCjfSykScN6RzEZ3ct8kjqEUyn5uAAZwWoegHKJcjavuRRCmoVyoq4DMs9m6HPFrvr/v+3qo0+zow==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9PR08MB6524.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(39860400002)(346002)(376002)(396003)(366004)(136003)(54906003)(478600001)(8936002)(52536014)(66946007)(4326008)(2906002)(122000001)(8676002)(316002)(38070700005)(110136005)(9326002)(86362001)(5660300002)(33656002)(66476007)(91956017)(71200400001)(76116006)(66446008)(66556008)(64756008)(7696005)(6506007)(38100700002)(41300700001)(26005)(9686003)(83380400001)(55016003)(186003); DIR:OUT; SFP:1101;
Content-Type: multipart/alternative; boundary="_000_DB9PR08MB65243BF31B5E2336D0E594719CB29DB9PR08MB6524eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB4743
Original-Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT038.eop-EUR03.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: 5417427d-99c5-45e4-fe46-08da542a17d1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Se5ocHOdmzEjwwi8lqmadhgmn8+GZRHIENXhEduc5GDOP/NseGwqOvR5/Yqx7kmSQGpf1eFp1am9YUQypBtRUCuL5l+r9eVG53EBx2NjcfNCPrXe9ewRw6g0TndFt8YTs77bcVFFkfJYjHNQS+IiRUxegqIFRRlW6enEGiJXy/xkEXKVPYA2DJEV+GAZKn5pVDo5A696SDTh1LUGOjvJLr5WUeEYCKruNgpkvluQ3K34nXI9LE832/F6w6Bg+RzdAPtdRW/4q4B8l5ma9TZKOCarkhcE/7rwj40fWj+Mw8/Tpi4pNUASKHGqc5vf99kSFFPtDc8ze+/EATE8dnNmLjynvOQhpoHJBEQfS75kTbgshXDxANVFefjTTDx4jSpc+KKk1LgpsTwIoolB9cqVJHsu/kva0dB4jMI20PVaqxvozRqjqlF3yn+iRP+7Nz29Iuv0nqm7Vl3gW9CfK8v8UYczFCAsCLpSaZRZK7PMo42aHtXlnHA6bcH6vrnu4axq3gKb/l2TaG+dND8xIQSAvKtDacejPT2gEtkBa+ThMaiAZluXS/NlOeQck7GnolHrENwjgTHahek9OfXfbBgm2ovECHyTS/IY+z+oEJkbzUvTiRvlM+i2Q8s2tCCClA8ZXwULFmHwdKSCv+ezcG6syG4LUiUBj7uIVQyPho60ZHqvRkrhUfYT0/UE5QFBxugyp2BckyvT1i3Qb+5/+8AlyjsMA1z3HadYC+llAbsXOfhJB5Ns11BdxxBGM+k5fdExmLv/B19145O2axkL7UQrnw==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(13230016)(4636009)(136003)(39860400002)(376002)(346002)(396003)(40470700004)(46966006)(36840700001)(86362001)(110136005)(26005)(54906003)(8676002)(4326008)(70206006)(70586007)(186003)(81166007)(40460700003)(450100002)(6506007)(7696005)(478600001)(33656002)(36860700001)(9686003)(55016003)(83380400001)(2906002)(40480700001)(82740400003)(52536014)(41300700001)(47076005)(9326002)(82310400005)(356005)(336012)(316002)(8936002)(5660300002); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Jun 2022 08:35:07.7548 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: ad292ea2-c526-434c-fae7-08da542a1d49
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: VE1EUR03FT038.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBAPR08MB5797
Archived-At: <https://mailarchive.ietf.org/arch/msg/cbor/y94RbVX05VlNf7axYfkH-LWR2po>
Subject: Re: [Cbor] [Rats] [Last-Call] Segmented strings (Re: EAT profiles (was Re: Iotdir last call review of draft-ietf-rats-eat-13))
X-BeenThere: cbor@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Concise Binary Object Representation \(CBOR\)" <cbor.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cbor>, <mailto:cbor-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cbor/>
List-Post: <mailto:cbor@ietf.org>
List-Help: <mailto:cbor-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cbor>, <mailto:cbor-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jun 2022 08:35:16 -0000

Hi Laurence,

> Laurence Lundblade <lgl@island-resort.com> wrote:
>
> We could provide a base constrained device profile in the EAT document:
>
> 7.2.1 - CBOR only (no JSON)
> 7.2.2 - No indefinite-length maps or arrays
> 7.2.3 - No indefinite-length strings
> 7.2.4 - Preferred encoding required
> 7.2.5 - COSE_Sign1 protection
> 7.2.6 - Receiver must accept ES 256, ES384 and ES 512. Sender must
>         send one of these.
> 7.2.7 - DEB is not used
> 7.2.8 - UEID serves as a verification key identifier (a bit awkward as
>         the unverified token contents must be decoded to get the key
>         to verify the contents)
> 7.2.9 - (Not sure what to recommend for Endorsement identification)

We can leave it open for now.  Common best practices will emerge in
time.

> 7.2.10 - A new single unique nonce is used for every token request
> 7.2.11 - 7.2.14 - No recommendation made as this varies too much by
>                   use case
> 7.2.15 - The token should not be a CBOR tag. It is assumed the
>          carrying protocol identifies the token as a nonce
> 7.2.16 - No recommendation for manifests or evidence as this varies
>          too much by use case

All sounds good and reasonable to me.

cheers, thanks,
t


IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.