Re: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-07.txt

Guillaume Bichot <Guillaume.Bichot@broadpeak.tv> Wed, 27 October 2021 09:55 UTC

Return-Path: <Guillaume.Bichot@broadpeak.tv>
X-Original-To: cdni@ietfa.amsl.com
Delivered-To: cdni@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7CAD3A0418 for <cdni@ietfa.amsl.com>; Wed, 27 Oct 2021 02:55:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=broadpeakshare.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AtOzgpW0g9fb for <cdni@ietfa.amsl.com>; Wed, 27 Oct 2021 02:55:40 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2116.outbound.protection.outlook.com [40.107.20.116]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 25E543A00B2 for <cdni@ietf.org>; Wed, 27 Oct 2021 02:55:39 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EIrhHXjkhJPDwGOoB0K5xmpkjJ8dLV7FeEcEj41hs+XS/VMSwTCqWrhvhsIpc8yathGSsrjm8hQlfjYIkUfyyA576uKLplm6Olxa9phzL64pITCFtCGHdSzN5UiE0E00mFQAODk3cV5gCpBV0my9Ii3TZDZ6QNIHCzOpeAtH04gZkLtwt8UdOgNQI9qSe5Ie2GUtmuBmUIszxB7gIkvvIFSqbWtVWd4+GV5uUbDByYwPtVoS23ForzggpRxEh/gXgO1phYm32HscTRHIgjjMHYXjVG1j9D2PXffZl7oIf57Hb/aLhGodyQqE8+KvfVhujCzqMZjfmf7FbKNxIfq8SQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=7wvyQh8bTvtwv5FR36zTmmlTspJXBI6/4pSP6X4oEwM=; b=Pz580wj72YQXtF7SOvH+hrW+xfnyKVkj/mnt09AgwcjbyHUFDIqmp3RsBJX9EbrUMiAW158y0aeJEvt6V1/9JBFQLLMCd/KJHKda6AKQtDXic+VL4nO8RpZ+GKQFLxSGjS480LfgUkP7WK/lsuYdF/GRxM39R+ZyAu/Gz/X5sSG2/zDQgMOgI7uxE/Y2gDF97rte5SbTdSoHqRTSC1lOqqcJE3Mw676DNAKx6HGEVVZzt0IM3hducyr2zmvGTUgGizZlxuaRclvq4ZjBNfyaIBLUJstqVI90cDnnve4huigzJYEVIq9YuMuLm3G7eLr+HhB95tCwlKq1df3nFAs3tg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=broadpeak.tv; dmarc=pass action=none header.from=broadpeak.tv; dkim=pass header.d=broadpeak.tv; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=broadpeakshare.onmicrosoft.com; s=selector2-broadpeakshare-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7wvyQh8bTvtwv5FR36zTmmlTspJXBI6/4pSP6X4oEwM=; b=K55TIQlGJLdhUKi6Kn0nXI05+WDVlFjMGtqaB/6x7w07el/wBHziRGfnQgUsgOZSDZHfQJjNKysFT6hML+3NxOG+GD1EJYlplq0u5GeUEwSfkUbZYMfDh5d1VowfYcix6y6jistxT7uO0mDQUjJ/wuFDRcw3lQDrJfXsUKCZZbk=
Received: from PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:96::6) by PAXPR10MB4751.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:102:dd::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4628.18; Wed, 27 Oct 2021 09:55:31 +0000
Received: from PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM ([fe80::ac23:766f:c440:5d3a]) by PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM ([fe80::ac23:766f:c440:5d3a%6]) with mapi id 15.20.4628.020; Wed, 27 Oct 2021 09:55:31 +0000
From: Guillaume Bichot <Guillaume.Bichot@broadpeak.tv>
To: "frederic.fieau@orange.com" <frederic.fieau@orange.com>, "cdni@ietf.org" <cdni@ietf.org>
Thread-Topic: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-07.txt
Thread-Index: AdfKdw5Q1WaU7+z9QuW9dslhw4XhoA==
Date: Wed, 27 Oct 2021 09:55:31 +0000
Message-ID: <PR3PR10MB4239549D9A291E67AC2B74C4E1859@PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=broadpeak.tv;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: a6c844f9-be02-443a-31ef-08d9992fe9eb
x-ms-traffictypediagnostic: PAXPR10MB4751:
x-microsoft-antispam-prvs: <PAXPR10MB4751E402F71EA2A6B602409FE1859@PAXPR10MB4751.EURPRD10.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:4714;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 55y0dXLpyXNEvnSZ9CrbKhubteu7YKtvgsyEbHi27czINYLMuGV8bHcmegWryfNxuBr1/i0/Y5dgHkMKdZI3ysajTAbbu7jjqPU/VrRXY6fZd6m5Utea0rv6cYyIIz7kXH3y/gsa8jLRkViRREpf9E9EIlb0OEbxF9B/CFgKDKVh/cojXNjGCBajnveMwn0GafzNIEa4TvxObxfdqN/IwR8uEnGmB8uoFW/GbJgM3czSTZt3IzraR1eQ1/fiMoQz4ZCOcBKqqGNJUmOKaYxTE/CINMdHRJSJEMJbopkt6mhJAAW5nBShkCa4J8w59N3myn20t4ZN7gpZStR1eFbaxGC1I2ulDxXhMzseVyKMdDFMheV1Bl/jLRIPtlvgBGBiF4/u2e+nglBqf2hHNbtfP/+qXEFaeJVvKH0Tf2VP5XdWJ1ooVwhuQFBNVHzrB/ur+fs14wDV3nAqLAbBqu6Ewsnz6qB5jbhrEUBPjegG62EV+fmhbHt6BtKL9MzOp5t3K90l+c6kXl1gm6Yu0O3NqakKoNPbaIl93ayvS7b6AzxTp39KRzMqQW0YiUYilJ/b+Wm01fv42wk2ZiGozVbw53db5ptMwUBMaO7uSPwMm+RX+DcwU6iMumoC5v2XmCg/9FCAd4Qh32To9ltURvb10fdC+GpdDQNLwVFURvkIb1O26RTFO8cKTpM68pwzqvNZ7W+f1YgkmpRBCG4XSPTFR6St1dR6+5Hhr+qKdf58o9gyPVJvMqvEv+YFODtKjG8AniEkLvM4/MgfNs7yvZgHjP5zthJXzQ3izi9GLnw1iYqvayc8ALh5Gz+ccshhOET2nubmpF6xbWpcZBCEbFn7jg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(4636009)(366004)(186003)(966005)(71200400001)(66574015)(55016002)(8676002)(508600001)(8936002)(33656002)(45080400002)(30864003)(5660300002)(52536014)(38100700002)(316002)(38070700005)(66476007)(83380400001)(15974865002)(64756008)(110136005)(2906002)(66556008)(53546011)(76116006)(6506007)(122000001)(66946007)(86362001)(7696005)(9686003)(66446008); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: dYekomVIyA01knVksQGe4X6gUJ+ZBMxI4IJw8xM9asF+GJ+FD3L8yCfPX/qMtoTvA29Hpn+WSk8uhVnpppm3umZiXNa77mwHhTFOUwgPLwH3u9SU/DMEpHwlWPRGV31Xrezg722Z5v1/gkCUwi3NZb3DeazPBOb5esA8LHZXOS3AKw0hmLGAXn7CHa0A/0u/meUDVul2hv7MILEMP8tPPMoZNs5bvkWNCn3HgLj9Ej2WRu48FZzr4Dme6D2OEYr91sXJRqGtfBOUTvVoHz3+4vwiTO7Qon78nhFnPOg81xjLY6PTqqaoyCDG5oljEaEb68Iq7UTWkvS09KEyeVZTUInPFsSFHFqjxsT65eKWo6QRgJ0TPEZBeczZ3wJzRXLyPDz+XTrtHmhhtx/PCZHu2gUMWCvbGYDisFXSzDfRqQqatV4Egv5Ic/PXyw/smjOD9jPXSyJaPaihasqtbtqPbv45XgfGyTCCzCuZOxLNgbi52fFMczhg2wiiepc+4hCw/qF7sM0IZPVR68qTFUBPUi2yPmPIpiKZUlXAPzdoQHcAdaFwAFogODVijraSA+D/RvhCqxukCUPnl/MWvsdDlFw31OXokiLWe13nzVPwdN3CYABst0eBbTQ9lXEiwi8V5lSVpRscsCd7fnie3gFewFjCD5YdCl/K8sprxKbrWAZngaSICk8xFQbQodKL68a9Hb9QtUnePRWXKx5RZwmRX2SNFmmDn+zU2vAzQvK86pleCpk4gNJlCZVVEU4vex5u5IvXkrZumqR4bC5bgnl36ecjksqgQhZEe/hn3Wdkr6ujgJ00kROnTHiVBzuBx4w/VmY9R7k7QUkdv0EqcwCTwjnKINfCgldMhbnBgGZQBzlLrTxcq5Ccb/eUF7PJc9HNow1wKA+MpW1c8umSknT0GSo8NrhwyM9VDcKjFVShoaOOwuLdFJALfwEGDhYx/Z5TUtBABIQEWZRvpNrnQcVNzsg4y8DhgdNh78uxseO+LupC025JDaIiZ3xJl5AdZQ/TAyhL5TjO7eBjruDEqTZaxLlLldPCJj/Bn0MdqxLXsWIEyr/ppeglXTxZqv/RbU0sHfOl5t5eaecIOXcgEr1oOUXbC++kxKo8SfofLK3yY3jnLGPCZkNMip6I+iLZONyEQMWYs4RN0LUrHX14IBe6LV8RHMzJFjuwvD5RO6LjiAKpIMw4Ds9OEjtU8kftNyO8CGHzzZisS44iyiD5SWEwti96me1tMMCjGcluaAg3o/ch8MylbHuL6uBVAtM3WpRNWrbh2984tmIP4kCWiia0auY1GssqWedMJ84mWqSW/myg6MCLFI0MLuwg3e5/xU5veenWEbXco9K1z4T+4u6q+vR/JQ27QgJnBwIu1/x57Ws1r4uv1ntUluS5eZfX7sgGJj1SZuJNX1M+G4Gvob5hYhVsENFr6eQjVtiAHp7oEOzk2KBHwms6YMRLSp5UlgedGenucUzYokIvEDA0sqCWpJB7WVemA5tSWq4vyWyTpX2nGVqxi9xSCHN/DLsazQ0hDjnrL2mLkGZu6Ejh+/mLeCJ/cle8iExA/oWvHLAv2yRNbsdvlGDZ2n5A5X2rY5gqspDeIIzwQQZw5Ab4uQvhVxdUD6S+i7Z5k3FkhisNqz3y/A/PCK9q7kKGHe/Qa5kUFiyjw+Dvjna2II9WN+HxCJ2osrzI147SA854duoudZYnuOjCFP3hFUpcxLDATTsOqzUgDCAK+AiE/0UoK2/ggA==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: broadpeak.tv
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PR3PR10MB4239.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: a6c844f9-be02-443a-31ef-08d9992fe9eb
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Oct 2021 09:55:31.5747 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0ebe44ea-c9c9-438d-a040-7e699f358ed4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Dja6PmLSi3H9svciy/M+GE4Nrd4wv5vpXFZiY30YAovmwDym/Tq6p7dwkp9vabl+04PnWpiSFA1qOvyCLHXriAv1wTYjfVjW+CD0kgMutho=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PAXPR10MB4751
Archived-At: <https://mailarchive.ietf.org/arch/msg/cdni/y3601X7Q4ZLAZuIWNzqQGJRsjcM>
Subject: Re: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-07.txt
X-BeenThere: cdni@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This list is to discuss issues associated with the Interconnection of Content Delivery Networks \(CDNs\)" <cdni.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cdni>, <mailto:cdni-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cdni/>
List-Post: <mailto:cdni@ietf.org>
List-Help: <mailto:cdni-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cdni>, <mailto:cdni-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Oct 2021 09:55:46 -0000

Frederic, all

Section 3:
One read the following: " This document only considers the Short-term, Automatically-Renewed   (STAR) certificates in Automated Certificate Management  Environment(ACME) [RFC8739]"
However I think, it looks like the  draft proposal is mostly  assume  RFC 9115.

section 4: 
There is an inversion between uCDN and dCDN. One should read: 
" In order for CDNs to negotiate on which methods are supported, the Footprint and Capabilities interface as defined in RFC8008, allows a  dCDN to send a FCI capability type objects, named  FCI.SupportedDelegationMethods, to uCDN.
Regarding the name of the FCI object, I suggest a name that is less ambiguous (delegation method refers to request routing). For instance: FCI.HttpsDelegation.
This said, I am not sure whether that new  FCI object is required. If it is  planned to define one MI object per HTTPS delegation method then FCI already informs the uCDN about the generic MI objects supported by the dCDN.  A new FCI object would be required if you need to communicate about options supported within a said HTTPS delegation method that is not the case in your draft.

Section 5:
It refers to a ACME/STAR API  as part of RFC8739 which does not define such API. 
The MI.AcmeStarDelegationMethod contains the property "credentials-location-uri" for which there is no explanation about how to use that property, neither in this draft  nor in  RFC 9115.
Basically it is unclear how the dCDN should proceed. Why a CSR template? The CSR template should be known in advance on both sides. Who decides about the delegated name ? is it the IdO (the uCDN) or the dCDN? In other words who builds the delegation configuration? In RFC 9115, it is assumed that before all, the uCDN gathers a delegation configuration applying for that dCDN gathering the necessary domain name mapping (e.g. cp.uCDN.com:cp.uCDN.dCDN.com) . 

All this process must be synchronized with the CDNi delegation process. When a uCDN configures the dCDN for streaming delegation, it must first ensure the dCDN is ready (configured) for certificate delegation. How is it guarantied? 

I think there should be a paragraph about whether such mechanism about delegated certificate mechanism applies to CDNi delegation based on HTTP redirect. 

Guillaume

-----Original Message-----
From: Guillaume Bichot 
Sent: Monday, October 11, 2021 4:17 PM
To: frederic.fieau@orange.com; cdni@ietf.org
Subject: RE: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-06.txt

Frederic,
there is small mistake in your draft and may be missing registration tasks.

Section 5.1 Extension to HostMetadata object and section 5.2 Extension to PathMetadata object

Strictly speaking, you do not extend the HostMetadata or the PathMetadata object. Instead, you propose to create a new Generic Metadata object. Therefore, you do not need 5.1 or even 5.2 either. Both MI.HostMetatada and MI.PathMetadata objects have a property (metadata) that refers to a list (an array) of generic metadata objects (MI.GenericMetadata).

So instead you should just remove these subsections. I think they bring confusion as there is nothing specific regarding  5.1  versus 5.2.   As any other MI generic metadata object, the AcmeStarDelegationMethod configuration object can be attached to a host name or to host name + a path pattern. 

In you 5.1 example, you indicate "hostmetadata" as a property to the MI.HostMetadata object which does not exist indeed. The correct name is "metadata".

Your new object should be describe like this :

Following the example above, the MI.HostMetadata can be modeled 
           for ACMEStarDelegationMethod as:     

                   {    
               "metadata": [    
                       {        
                   "generic-metadata-type": "MI.AcmeStarDelegationMethod",      
                   "generic-metadata-value": {  
                      "star-proxy": "10.2.2.2", 
                      "acme-server" : "10.2.3.3",       
                      "credentials-location-uri": "https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ucdn.com_credentials&d=DwIFAw&c=udBTRvFvXC5Dhqg7UHpJlPps3mZ3LRxpb6__0PomBTQ&r=XniVbishGiO2Ao9hKqSc-hTVIWCi3T-x6GdHR4ZTgoM&m=c_x5S7bwh6JWaEEwARG0xZ8OLIYNYAEkb0z-xR_XbLI&s=KTnh0aLbZNxM3zWC4ydGNFUzGBoWs7J-NDNl89xI8As&e= ",  
                      "periodicity": 36000,     
                      "CSR-template": Json/Text of the CSR template (see 4.2)   
                       }}]      
                   }

Section 8
I think you must also register a new FCI payload type as well as a new CDNI Supported Delegation Methods. 

Guillaume

Guillaume Bichot
Principal Engineer, Head of Exploration
broadpeak
m: +33 685 597 666    p: +33 222 740 350 guillaume.bichot@broadpeak.tv

Broadpeak, S.A.S.|Registered offices at 15 rue Claude Chappe, Zone des Champs Blancs, 35510 Cesson-Sévigné, France | Rennes Trade Register: 524 473 063 This e-mail and its attachments contain confidential information from Broadpeak S.A.S and/or its affiliates (Broadpeak),  which is intended only for the person to whom it is addressed. If you are not the intended recipient of this email, please notify immediately the sender by phone or email and delete it. Any use of the information contained herein in any way, including, but not limited to, total or partial disclosure, reproduction, or dissemination, by persons other than the intended recipient(s) is prohibited, unless expressly authorized by Broadpeak. Broadpeak, S.A.S. and its affiliates respect privacy laws, and is committed to the protection of personal data. Emails and/or attachments thereof exchanged between us may include your personal data which may be processed by Broadpeak and/or its affiliates according to applicable privacy laws & regulations. In compliance with Regulation (EU) 2016/679 (GDPR) and applicable implementation in local legislations, you can exercise at any time your rights of access, rectification or erasure of your personal data, as well as your rights to restriction, portability or object to the processing.
For such purpose, or to know more about how Broadpeak processes your personal data, you may contact Broadpeak by mail (Headquarters address listed here) or by email (privacy@broadpeak.tv).
Local authority :  Commission Nationale Informatique et Libertés (CNIL): 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07 or www.cnil.fr



-----Original Message-----
From: CDNi <cdni-bounces@ietf.org> On Behalf Of frederic.fieau@orange.com
Sent: Wednesday, October 6, 2021 5:40 PM
To: FIEAU Frédéric INNOV/NET <frederic.fieau@orange.com>; cdni@ietf.org
Subject: Re: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-06.txt

Hi all,

A quick recap of the main changes:
- Removed sections related to the "Delegated Credentials" delegation method
- Added FCI meta data to sync CDNs on the delegation methods that are supported
- Added a HostMatch pattern to trigger a delegation method


Regards,
Frederic

-----Message d'origine-----
De : CDNi [mailto:cdni-bounces@ietf.org] De la part de frederic.fieau@orange.com Envoyé : mercredi 15 septembre 2021 16:08 À : cdni@ietf.org Objet : Re: [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-06.txt

Hi all,

I posted a new version of the draft-ietf-cdni-interfaces-https-delegation. 
This last version only includes support for the ACME-STAR method for now and adds FCI metadata for delegation methods negotiation between CDNs.

Please feel free to review and comments.

Regards,
Frederic



-----Message d'origine-----
De : CDNi [mailto:cdni-bounces@ietf.org] De la part de internet-drafts@ietf.org Envoyé : vendredi 10 septembre 2021 16:01 À : i-d-announce@ietf.org Cc : cdni@ietf.org Objet : [CDNi] I-D Action: draft-ietf-cdni-interfaces-https-delegation-06.txt


A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Content Delivery Networks Interconnection WG of the IETF.

        Title           : CDNI extensions for HTTPS delegation
        Authors         : Frederic Fieau
                          Emile Stephan
                          Sanjay Mishra
	Filename        : draft-ietf-cdni-interfaces-https-delegation-06.txt
	Pages           : 10
	Date            : 2021-09-10

Abstract:
   The delivery of content over HTTPS involving multiple CDNs raises
   credential management issues.  This document proposes extensions in
   CDNI Control and Metadata interfaces to setup HTTPS delegation from
   an Upstream CDN (uCDN) to a Downstream CDN (dCDN).


The IETF datatracker status page for this draft is:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-cdni-interfaces-https-delegation%2F&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=BHhqMqIpAXerqLsl%2B7LZXOrFdYUkpCcdmkuerx0RTdQ%3D&amp;reserved=0

There is also an HTML version available at:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-ietf-cdni-interfaces-https-delegation-06.html&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=zhCZArN81bLaL8K7Q226vnNTGCR8Q%2Fb0CAnM8rMEmpE%3D&amp;reserved=0

A diff from the previous version is available at:
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Frfcdiff%3Furl2%3Ddraft-ietf-cdni-interfaces-https-delegation-06&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=4QAiMS2XZMJrM69hHR1mkmDv3UpcBoDlSRAGPl9CgFE%3D&amp;reserved=0


Internet-Drafts are also available by anonymous FTP at:
https://eur02.safelinks.protection.outlook.com/?url=ftp%3A%2F%2Fftp.ietf.org%2Finternet-drafts%2F&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=GcL79D%2BP86q%2F6HUya2HoF5o4AyUv7kBntEqr%2FpQ%2BNo0%3D&amp;reserved=0


_______________________________________________
CDNi mailing list
CDNi@ietf.org
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fcdni&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=UYyQ0zXCnhLnBNmUsjPooYwJKTLDH63%2FcmSGlDMW%2FtU%3D&amp;reserved=0

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.

_______________________________________________
CDNi mailing list
CDNi@ietf.org
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fcdni&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=UYyQ0zXCnhLnBNmUsjPooYwJKTLDH63%2FcmSGlDMW%2FtU%3D&amp;reserved=0

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.

_______________________________________________
CDNi mailing list
CDNi@ietf.org
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fcdni&amp;data=04%7C01%7Cguillaume.bichot%40broadpeak.tv%7Ce4f35d52b7d94482923f08d988df8abc%7C0ebe44eac9c9438da0407e699f358ed4%7C0%7C0%7C637691315957921384%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;sdata=UYyQ0zXCnhLnBNmUsjPooYwJKTLDH63%2FcmSGlDMW%2FtU%3D&amp;reserved=0