Re: [CDNi] Review of draft-ietf-cdni-delegation-acme-00

frederic.fieau@orange.com Mon, 06 March 2023 13:49 UTC

Return-Path: <frederic.fieau@orange.com>
X-Original-To: cdni@ietfa.amsl.com
Delivered-To: cdni@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 08EECC15155A for <cdni@ietfa.amsl.com>; Mon, 6 Mar 2023 05:49:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aDKccex-_IO0 for <cdni@ietfa.amsl.com>; Mon, 6 Mar 2023 05:49:32 -0800 (PST)
Received: from relais-inet.orange.com (relais-inet.orange.com [80.12.66.39]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2F3D5C15152B for <cdni@ietf.org>; Mon, 6 Mar 2023 05:49:32 -0800 (PST)
Received: from opfedar07.francetelecom.fr (unknown [xx.xx.xx.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by opfedar26.francetelecom.fr (ESMTP service) with ESMTPS id 4PVg162c2BzFq6w; Mon, 6 Mar 2023 14:49:30 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; s=ORANGE001; t=1678110570; bh=xkhmGDIOVwxcypQuf+uTmeC/YHYYaYYs2GPz6AZeNug=; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; b=CBgVQkFwpWBdZ0VaLhAqFVP/bTl9rru6Y7w0JCnxe1FPioHA7PT3kunF8fbbKRtAd mJmuxM1p3yFZ4IRUVxxhSi5OH6Tyf4IxbTJN/JdF3ss8NiF8OdAu5K+D32vVkRAPcz rQiqogmgETE44/wUNedb5EQir+Ingmbo95lFHfkptHaGRkwmwoAJpsImiZnHs//hIr ztRy7Rv16SIunzMpij6uNjGbFfzdIxP9fZyXNxKNU5I7S1LlqNEG3rk1KWg5wCQQCM BHTCXoDtFdqjGBZwYL3wTY+vELSP23A5SDq0yBdj52RpL4cUBOM1tQrWU+dXGjoxw+ bIG2ywYMyllhg==
From: frederic.fieau@orange.com
To: "Kevin J. Ma" <kevin.j.ma.ietf@gmail.com>, Thomas Fossati <Thomas.Fossati@arm.com>
CC: "cdni@ietf.org" <cdni@ietf.org>
Thread-Topic: [CDNi] Review of draft-ietf-cdni-delegation-acme-00
Thread-Index: AQHZQwUo8UbGQUnHg0WRtqfsw90or67UaAeAgAA6TgCAAGbWAIAAWb2AgBCkHx4=
Date: Mon, 06 Mar 2023 13:49:29 +0000
Message-ID: <1823_1678110570_6405EF6A_1823_206_1_f139dbb6abd54934a21d59ab308acf20@orange.com>
References: <DB9PR08MB652409DB6C713082B2C21F499CA69@DB9PR08MB6524.eurprd08.prod.outlook.com>, <07C8B619-6B5F-4BCC-BC75-9E064E93156A@gmail.com>
In-Reply-To: <07C8B619-6B5F-4BCC-BC75-9E064E93156A@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.115.27.51]
Content-Type: multipart/alternative; boundary="_000_f139dbb6abd54934a21d59ab308acf20orangecom_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/cdni/a0GYoAQZx1-_oareSzszc4Jeji0>
Subject: Re: [CDNi] Review of draft-ietf-cdni-delegation-acme-00
X-BeenThere: cdni@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This list is to discuss issues associated with the Interconnection of Content Delivery Networks \(CDNs\)" <cdni.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cdni>, <mailto:cdni-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cdni/>
List-Post: <mailto:cdni@ietf.org>
List-Help: <mailto:cdni-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cdni>, <mailto:cdni-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Mar 2023 13:49:37 -0000

Hi Kevin, Thomas, all,


The following changes/PR have been made in the draft:


- in the time-window description use s/must/MUST/<https://github.com/FredericFi/cdni-wg/pull/24/commits/c421c6792df6f12c1c0bf8229635ad39fceb8969>



- In section 4.1: reference section 3.1 instead of 3<https://github.com/FredericFi/cdni-wg/pull/24/commits/f5120adb38aa9ea674f4dd5104798bd6ffc7f02b>


- reword the ACME-related security considerations<https://github.com/FredericFi/cdni-wg/pull/24/commits/73b2bd07a987f7e1bc7aff4f1a59afd763c3e368>


- "The last suggestion I have is to change the “lifetime” and “lifetime-adjust” attributes to “star-lifetime” and “star-lifetime-adjust”.


I'm posting the last version today.

Thanks,


regards,
Frederic


________________________________
De : Kevin J. Ma <kevin.j.ma.ietf@gmail.com>
Envoyé : dimanche 19 février 2023 01:55:27
À : Thomas Fossati
Cc : FIEAU Frédéric INNOV/NET; cdni@ietf.org
Objet : Re: [CDNi] Review of draft-ietf-cdni-delegation-acme-00

perfect.  thanx!

Sent from my iPhone

On Feb 18, 2023, at 2:34 PM, Thomas Fossati <thomas.fossati@arm.com> wrote:


Hi Kevin,

On 18/02/2023, 13:26, "Kevin J. Ma" kevin.j.ma.ietf@gmail.com<mailto:kevin.j.ma.ietf@gmail.com> wrote:
>   Thank you for helping to parse thatout.  One further clarification,
> are the "account credentials"/"user account" embedded in the URL or
> are they separately provided, i.e., is it provided in-band as part
> of the metadata/URL (like a signed URL) or through a completely
> separate out-of-band process?

In RFC9115 it's out-of-band -- see second bullet of §2.1 [1].

cheers!

[1] https://www.rfc-editor.org/rfc/rfc9115.html#section-2.1



IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.