Re: [CDNi] I-D Action: draft-ietf-cdni-https-delegation-subcerts-05.txt

Christoph Neumann <Christoph.Neumann@broadpeak.tv> Thu, 05 October 2023 07:57 UTC

Return-Path: <Christoph.Neumann@broadpeak.tv>
X-Original-To: cdni@ietfa.amsl.com
Delivered-To: cdni@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3286C151098 for <cdni@ietfa.amsl.com>; Thu, 5 Oct 2023 00:57:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=broadpeakshare.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GKEzjWAGHYbK for <cdni@ietfa.amsl.com>; Thu, 5 Oct 2023 00:57:35 -0700 (PDT)
Received: from EUR03-DBA-obe.outbound.protection.outlook.com (mail-dbaeur03on2121.outbound.protection.outlook.com [40.107.104.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0DCDC15154E for <cdni@ietf.org>; Thu, 5 Oct 2023 00:57:35 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HBW4A6ugHZFkfEBXMbkOvxeuWT+LtyRIBwUQR9RkhL2EZHVqI/kRatyL2W5yu61LG8BCC3KAOKb3Eoj4R3a61F5sZHR709YxbXbmz/LYBJb/JdhydvolQEROyAsy5Or4pgsOMyobWnFv2Fe/fowsmb6ZyNt8toC2iHinRco0Z+h6zqyhhrrZEsBg0RlvImU0m9pAFvSHmkbDHJKS2/aHf9kZnebKF8/hl6TEmhZYzSRUjRN8Zt0gWVn/4B5S7RSr1pSyjsJuJ/FE8z9KAlqOjd0UBF/w755h02V1wnrJ5Qkcrc5cpNDlnWxzynFFQ705ai+Y15yCJRy6s1supR3jfQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+eLPP6do5YV8Dp0z/24jXDP4cZ1WyUztSMfu5++tRjM=; b=WO2Emlv3VAqRPe3nDnI1AOuRRunDqJEm8PqEb4rTCDOJqB3uo/6klxxvpKm4pa5CGqyN5JSlzAy+kQGze3eUm2Bje6xA3f/kkEHHQBrHz6SLbp0fzbCc1cKGarUIeYfOp99JG06a1EWlBfPFW/wIQVEb4b7HYZLuN5k9xVG7BuUhcHrIpErdtZiKgZ+DTmmGtm0nlqEmWDba6vkHESJLhZKEYJK3RwCezxkry0rcMuBSVivtDpRd/CgYaPY2jOC7gkeJKFwrS4XRzkh6U2srlK23kLfZ9p7sCR9ZgFfu3cODyrUQ1PYB5bXrkkqhXyU9MU3Fouh4Tego3qoWEfbXjQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=broadpeak.tv; dmarc=pass action=none header.from=broadpeak.tv; dkim=pass header.d=broadpeak.tv; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=broadpeakshare.onmicrosoft.com; s=selector2-broadpeakshare-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+eLPP6do5YV8Dp0z/24jXDP4cZ1WyUztSMfu5++tRjM=; b=Is47HCwaLgS+F7uICxhA+r8yi5bHzci1ZiNMNSYEDnSozfOVtw5La4OW4SjTyQp201JQEcJHyd0DZY2JdyDhk3OY0R39oPj0CrrtfYVMhXsfCyXKLYKWRtr0s0Vu9/BvX38mIdpXmNTk/CwZCK0Lc9mOvbgmzFvmQ8bhFzkPnFY=
Received: from PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:af::17) by AS8PR10MB6770.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:5bc::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6838.37; Thu, 5 Oct 2023 07:57:32 +0000
Received: from PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM ([fe80::fa09:2574:7cf8:e25d]) by PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM ([fe80::fa09:2574:7cf8:e25d%7]) with mapi id 15.20.6838.033; Thu, 5 Oct 2023 07:57:31 +0000
From: Christoph Neumann <Christoph.Neumann@broadpeak.tv>
To: "cdni@ietf.org" <cdni@ietf.org>
Thread-Topic: [CDNi] I-D Action: draft-ietf-cdni-https-delegation-subcerts-05.txt
Thread-Index: AQHZ92EUXE+lAaL88EW8JlWMcBsOwLA604aw
Date: Thu, 05 Oct 2023 07:57:31 +0000
Message-ID: <PR3PR10MB415744B1DDE36FADA94A69D58FCAA@PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM>
References: <169649242443.52233.18268073416166429524@ietfa.amsl.com>
In-Reply-To: <169649242443.52233.18268073416166429524@ietfa.amsl.com>
Accept-Language: en-US, fr-FR
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=broadpeak.tv;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PR3PR10MB4157:EE_|AS8PR10MB6770:EE_
x-ms-office365-filtering-correlation-id: 4274a9e1-8577-4210-b169-08dbc578ba86
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: JB3d1miQBLKuvfu7HDHDaVp6LiLMWGMmxBiriAt/JSUmBhmMo5Iv1CxZxKnBzRRHBHbxnSG+CCX3S2neHtnPI3L04pu4cNymX94tyoCnHPvkq59MDXjDxFbcw+G7Q0vUItfnSmNHG4vyGfuXsIL2hNwsE8xV1tmjF6d6c9TH/qjjkl3MCGN2twESii8IDxhRIz0+uAkSXSoFyFgatN1AE4W2iJBhj4k8o5ZQF0q5xVOOJxGjjnwMirmwp8D2wRrGN9eMHnqnI3FzrUGWt3vW97ysjh5X8anTRQiK2Wlmaq48zTLbxyLrpC4BlViHpl/4tG3Ur73chnVklenIWneap/z24G/D+QwpN/DPvgKgjrCnB5hjb6rf408gQ3yZIXqQgSp+QO46DsC+atmmVuNgk5NI0jPrdvCSdU8W5lP7UYX9xH4vdyppnWcGI0RbpKICWBoX2VuTocgccE5z5j67IRhLMzTsxK0L9KY5DigthGGNhY52V5U7KvxGegUUx9Tfxk9126rSRf6AnllMV8084QwtzycVpjkDvx5zUrhU/mLWc3inMJoTK/L6wuG9XWv2wIP1yihyZ4obKgt3AqA2wtFuqFYNp42/EEpQPnL87ZyQh9ktZp8lvUeG3ifxbwG2OLiWHyNedzk9vqOaJRPQCQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(366004)(39850400004)(396003)(346002)(376002)(136003)(230922051799003)(451199024)(1800799009)(186009)(64100799003)(55016003)(66899024)(9686003)(53546011)(7696005)(6506007)(966005)(45080400002)(478600001)(38100700002)(15974865002)(86362001)(38070700005)(33656002)(122000001)(2906002)(6916009)(66574015)(83380400001)(26005)(71200400001)(76116006)(66946007)(66556008)(66476007)(8936002)(316002)(66446008)(64756008)(8676002)(52536014)(5660300002)(41300700001)(18886075002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: g3uuzTSkQKshoou4Vy9d4nbqoK2SFQqTSKTExNRQIBm35rYAVG8rY7gZSyDyJqCFR7NNY1xmDBpCxQHs8ek6Spu0b1WObUtur+kCnGMiGuorRszKiUY81bClWeio3yIrwBDrksGWj1nFRwh/GTLoqsy7Z9BqG6paf9nqal7Kc2dgdkO3hDnOY8IrFnMMw8atJng1wGiE/MGgizQfnRsuelXBSCLUpxr2pRDXEYctZhBpCYqlg78c0npKuwA9z7pBQIxZYuMFg8/m2LptE62x9KzV3qA6ujQudoFt07J4gRgFLs4Dch35FwfrUS5clot8q7A/wKilB//7owedPXy6uVgfLcJc0dKDuk9Fur2e5cpy76fC6yjFwdkexlpKnfL8/+wRLDnbxhXWWnk/G9ZUoL8ImVidIwXvJQQ782YPftDeK9Ypc3AgL63r4is3gu95grcxcTfTRXOZ/eEpUkfER0y8LctBlsmGppVyp4IGHJfUdrjo9oIZGTvDOojZaErZVYI1UYcCKZmUJXtWz9Bzz/blSO7tGFoqSLdsNgS9mf1Lf4i4K5bXTqVOLu2R+3RNghD2iHaYu/oUKFlwBSvHQmnPaRG7K/fDSj4M4H6yGAP21/z/s5aVrIQmkw3pa8eyYyHT7Yu0h1zMRVnH8NrwcBocL7FbVIfcjP1vs3dRy4y9Efp+25BYmGooejHKe5xX0TimycWP0NjLrwBMib2TODaD3e/MXMs4g26suIR4k+cebZDR547CZ5GDHVz/lTCPUOSCteokkqMOEJIVooXw9UGM9QWZ0Aqaw5hhof5V43llry9T/9SJBYJF29dD+I7CSXJGOF0PRkEYM8hKoCfogApsV9Qa/GN7WXGJncmtPihG6IICnrtEmf9Mvl0Me6xPdnpdvdRQvxMnnXHcb1iHdmGf2982R0LpKWLLz4jkoERg7HV/6AsFtlvJZtwGJk1nAvXUOJaJsDFFYF7w9v6vz177iAPHvrYS5nmuBcF68JL/5EhR4AZyOzGlr80V8Bnn6DwTOjjeaAbt7Y4TOmYyNd9LF0qnlrGPihYbKnhX9cwt9QQgFgUy+mbE5bssSJ6B5k0w+5kbS5LZPZXJIpH1Q6Q+tnNA9JMO8pHfx/8lE0Ot1Pw1dgB4RUbh6gnDTUuAq5aYOHTADtSoOIlvrJk2r46vPofZOrT5G1SnwIi2rHaoP08NLDzkk8H6KzPfRs6zhTeYMCt5X4KK3pQ5yqKHFz7oKCB05WOCSysrXGLycpiAnXIJ20SRlG5pRasTo3rzdXCLCCpcqEzsjzWri9el5J//OkqnGh8O4hClLTGYx2lYq+JM/0hsmnxHjzyF7iSVqhmWBo+Kxd32S6G1LBKDgub70mc9ZQe9a7RaLJp7x0kY/jGXBH+aoHeOfblUv1RWYcXiuwdhf/mSyCtFpNdlKBmbjbSCPkE6HnjRNPtLMVIXmFLMJ6zLK1RhiLnyMMyrNG0UVSX+u8H4ie/x85n+Qrq7Vcs7XOC7EP1FW/MUj8u/ekG+L5cw5rFoxnKMc8ycq9SeIBlvC26O4TVwBep8/9NcTuWw9eCBAGgcmfnD3m+6B6VTsCIwytp1Jjj8HaAzS0N1jbO9e8nPaEiYqM9bHA==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: broadpeak.tv
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PR3PR10MB4157.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 4274a9e1-8577-4210-b169-08dbc578ba86
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Oct 2023 07:57:31.8576 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0ebe44ea-c9c9-438d-a040-7e699f358ed4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: CQKRvFs6L1EwwhLL0zxS4b6mXgkNkSq7F0xxVk1Cm4NcCKsQD/l8JTLRJ1iFuOmgLAY1FH0JxQjkqiYiCAtl7odPySccJk/8kPgFmxNZGDA=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR10MB6770
Archived-At: <https://mailarchive.ietf.org/arch/msg/cdni/s7ZcgzlgzOS61kSGSgQxAVlPYZs>
Subject: Re: [CDNi] I-D Action: draft-ietf-cdni-https-delegation-subcerts-05.txt
X-BeenThere: cdni@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This list is to discuss issues associated with the Interconnection of Content Delivery Networks \(CDNs\)" <cdni.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cdni>, <mailto:cdni-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cdni/>
List-Post: <mailto:cdni@ietf.org>
List-Help: <mailto:cdni-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cdni>, <mailto:cdni-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Oct 2023 07:57:40 -0000

Hi all,

I submitted a new version of the internet draft related to delegated credentials.
This update takes into account the secdir reviews of the previous draft.
The draft now specifies that, if used, the private key must be encrypted using JWE, whereas the public key used for encryption can be announced in the FCI.DelegatedCredentials.

Christoph

-----Original Message-----
From: CDNi <cdni-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org
Sent: Thursday, October 5, 2023 9:54 AM
To: i-d-announce@ietf.org
Cc: cdni@ietf.org
Subject: [CDNi] I-D Action: draft-ietf-cdni-https-delegation-subcerts-05.txt

Internet-Draft draft-ietf-cdni-https-delegation-subcerts-05.txt is now available. It is a work item of the Content Delivery Networks Interconnection
(CDNI) WG of the IETF.

   Title:   CDNI Metadata for Delegated Credentials
   Authors: Frederic Fieau
            Emile Stephan
            Guillaume Bichot
            Christoph Neumann
   Name:    draft-ietf-cdni-https-delegation-subcerts-05.txt
   Pages:   12
   Dates:   2023-10-05

Abstract:

   The delivery of content over HTTPS involving multiple CDNs raises
   credential management issues.  This document defines metadata in the
   CDNI Control and Metadata interface to setup HTTPS delegation using
   Delegated Credentials from an Upstream CDN (uCDN) to a Downstream CDN
   (dCDN).

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-cdni-https-delegation-subcerts/

There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-ietf-cdni-https-delegation-subcerts-05

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-cdni-https-delegation-subcerts-05

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
CDNi mailing list
CDNi@ietf.org
https://www.ietf.org/mailman/listinfo/cdni
Broadpeak, S.A. Registered offices at 15 rue Claude Chappe, Zone des Champs Blancs, 35510 Cesson-Sévigné, France | Rennes
Trade Register: 524 473 063
This e-mail and its attachments contain confidential information from Broadpeak S.A. and/or its affiliates (Broadpeak), which is intended only for the person to whom it is addressed.
If you are not the intended recipient of this email, please notify immediately the sender by phone or email and delete it. Any use of the information contained herein in any way, including, but not limited to, total or partial disclosure, reproduction, or dissemination, by persons other than the intended recipient(s) is prohibited, unless expressly authorized by Broadpeak. Broadpeak, S.A. and its affiliates respect privacy laws, and is committed to the protection of personal data. Emails and/or attachments thereof exchanged between us may include your personal data which may be processed by Broadpeak and/or its affiliates according to applicable privacy laws & regulations.
In compliance with Regulation (EU) 2016/679 (GDPR) and applicable implementation in local legislations, you can exercise at any time your rights of access, rectification or erasure of your personal data, as well as your rights to restriction, portability or object to the processing.
For such purpose, or to know more about how Broadpeak processes your personal data, you may contact Broadpeak by email privacy@broadpeak.tv.
Local authority : Commission Nationale Informatique et Libertés (CNIL): 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07 or http://www.cnil.fr/