[core] Review of draft-ietf-core-oscore-edhoc-10

Marco Tiloca <marco.tiloca@ri.se> Thu, 04 April 2024 17:20 UTC

Return-Path: <marco.tiloca@ri.se>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54A81C169405; Thu, 4 Apr 2024 10:20:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.098
X-Spam-Level:
X-Spam-Status: No, score=-7.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ri.se
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2S92nCgLrV5G; Thu, 4 Apr 2024 10:20:30 -0700 (PDT)
Received: from GVZP280CU001.outbound.protection.outlook.com (mail-swedencentralazon11021007.outbound.protection.outlook.com [52.101.75.7]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F2524C169402; Thu, 4 Apr 2024 10:20:29 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=KRpKWQTRplxQK4kQ8HSctxEVOBscZnN6jnQiSPjQ1aUDlsm4VdgGSOgLoZZ88lhR3vESe21TzVU25WPa9mZrVO6rI99gsaawGD+5W6jW/hIO5uuuViuTSuOT/2/i/FrebcVWxUjcbQc7T0OG+qLKOXcOW4s2JOqiTSl5torGNc219M4vuLCjCBZ7udmKOgdYE4TvvGWqzyDO1Sjbbb0OWdBMuxllXt+UJYRVnnsf8nBRnbfHAT14Ca+xj4f3nCGglnc+MgeTJfOwhn8dFml7vB7yyKlmm9oC8broOlj0aXvg0T0ZSESaMJh+7qfb2dPcStP31EOngwHnZW741Vbtfg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=1tYmbF0OdfYr247plMBUUi88PCMHm7xZ4B56VojhhBE=; b=HIF6+Xq+jpJCTTcpwQsHrfmKduR0dBs3iTvDAW1dfqNc6G71B3RyRG7Q1ZF/NUfD/0JieGh2mWv6hV5kG8fZy5E2Oaxg0QrtGjZjinPFIAsCtcG20oSEJAMqyDBCt0vizchYGGpzQYTm0F3eCxt66qTAiLg35tMirxs4WgCa+VHEHLCJdg7L+ai47aLqb0MMALYcYjnaW9IWVSfaIwb1mbe45qpH/+h1pHoiqSJGww9vTZiXebZ8osHxObg8RhzSMu/IE3xkOFrRqZ61+CdeTXI7F/rCUuvZrTkBzkKob8yCDexPE2GLV5q/k0MV2Fr7l1LV8riPbwSXKPb5Q6XG0w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1tYmbF0OdfYr247plMBUUi88PCMHm7xZ4B56VojhhBE=; b=bcUmIDcWGoNRHjdqqHjbJ2juoF0+2uwNSHzADs9pR52gWoaTQ/g4iHOZewPtUJKTCW448tCoH9B45lcuHkYbrsHQZM5CNfvYhq2vZNVgS7DFUgWgJZD1vmyNMgylsUOAOSfjwvOQtgdgn0e9e/LiG3RqclqXuo66xrW6RsvkGvI=
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17) by MM0P280MB0104.SWEP280.PROD.OUTLOOK.COM (2603:10a6:190:f::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.46; Thu, 4 Apr 2024 17:20:25 +0000
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::ac07:ed64:c098:f1f9]) by GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::ac07:ed64:c098:f1f9%4]) with mapi id 15.20.7409.042; Thu, 4 Apr 2024 17:20:25 +0000
Message-ID: <5c783b3c-ae8c-4959-8f86-4e60e4be8f28@ri.se>
Date: Thu, 04 Apr 2024 19:20:24 +0200
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Marco Tiloca <marco.tiloca@ri.se>
Autocrypt: addr=marco.tiloca@ri.se; keydata= xsBNBFSNeRUBCAC44iazWzj/PE3TiAlBsaWna0JbdIAJFHB8PLrqthI0ZG7GnCLNR8ZhDz6Z aRDPC4FR3UcMhPgZpJIqa6Zi8yWYCqF7A7QhT7E1WdQR1G0+6xUEd0ZD+QBdf29pQadrVZAt 0G4CkUnq5H+Sm05aw2Cpv3JfsATVaemWmujnMTvZ3dFudCGNdsY6kPSVzMRyedX7ArLXyF+0 Kh1T4WUW6NHfEWltnzkcqRhn2NcZtADsxWrMBgZXkLE/dP67SnyFjWYpz7aNpxxA+mb5WBT+ NrSetJlljT0QOXrXMGh98GLfNnLAl6gJryE6MZazN5oxkJgkAep8SevFXzglj7CAsh4PABEB AAHNNk1hcmNvIFRpbG9jYSAobWFyY28udGlsb2NhQHJpLnNlKSA8bWFyY28udGlsb2NhQHJp LnNlPsLAdwQTAQgAIQUCWkAnkAIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRDuJmS0 DljaQwEvCACJKPJIPGH0oGnLJY4G1I2DgNiyVKt1H4kkc/eT8Bz9OSbAxgZo3Jky382e4Dba ayWrQRFen0aLSFuzbU4BX4O/YRSaIqUO3KwUNO1iTC65OHz0XirGohPUOsc0SEMtpm+4zfYG 7G8p35MK0h9gpwgGMG0j0mZX4RDjuywC88i1VxCwMWGaZRlUrPXkC3nqDDRcPtuEGpncWhAV Qt2ZqeyITv9KCUmDntmXLPe6vEXtOfI9Z3HeqeI8OkGwXpotVobgLa/mVmFj6EALDzj7HC2u tfgxECBJddmcDInrvGgTkZtXEVbyLQuiK20lJmYnmPWN8DXaVVaQ4XP/lXUrzoEzzsBNBFSN eRUBCACWmp+k6LkY4/ey7eA7umYVc22iyVqAEXmywDYzEjewYwRcjTrH/Nx1EqwjIDuW+BBE oMLRZOHCgmjo6HRmWIutcYVCt9ieokultkor9BBoQVPiI+Tp51Op02ifkGcrEQNZi7q3fmOt hFZwZ6NJnUbA2bycaKZ8oClvDCQj6AjEydBPnS73UaEoDsqsGVjZwChfOMg5OyFm90QjpIw8 m0uDVcCzKKfxq3T/z7tyRgucIUe84EzBuuJBESEjK/hF0nR2LDh1ShD29FWrFZSNVVCVu1UY ZLAayf8oKKHHpM+whfjEYO4XsDpV4zQ15A+D15HRiHR6Adf4PDtPM1DCwggjABEBAAHCwF8E GAECAAkFAlSNeRUCGwwACgkQ7iZktA5Y2kPGEwf/WNjTy3z74vLmHycVsFXXoQ8W1+858mRy Ad0a8JYzY3xB7CVtqI3Hy894Qcw4H6G799A1OL9B1EeA8Yj3aOz0NbUyf5GW+iotr3h8+KIC OYZ34/BQaOLzdvDNmRoGHn+NeTzhF7eSeiPKi2jex+NVodhjOVGXw8EhYGkeZLvynHEboiLM 4TbyPbVR9HsdVqKGVTDxKSE3namo3kvtY6syRFIiUz5WzJfYAuqbt6m3TxDEb8sA9pzaLuhm fnJRc12H5NVZEZmE/EkJFTlkP4wnZyOSf/r2/Vd0iHauBwv57cpY6HFFMe7rvK4s7ME5zctO Ely5C6NCu1ZaNtdUuqDSPA==
To: Roman Danyliw <rdd@cert.org>
Cc: The IESG <iesg@ietf.org>, draft-ietf-core-oscore-edhoc@ietf.org, "core-chairs@ietf.org" <core-chairs@ietf.org>, "core@ietf.org" <core@ietf.org>, "cabo@tzi.org" <cabo@tzi.org>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------xIwNwDOvBsCyauWt6UA4ajeV"
X-ClientProxiedBy: GV3PEPF00002BB5.SWEP280.PROD.OUTLOOK.COM (2603:10a6:144:1:0:6:0:a) To GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: GVYP280MB0464:EE_|MM0P280MB0104:EE_
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: bsth5s/PEVS43paxBoKyEZcaUFTGknzjY7U+TDAwokACM+NWRTXWlcLfAVT48k6xI0uQWbPiUI24rPLrg16pO1zsatMzC5XJC9D/zK89KuJIwgdQjPBnAta3/zsOtLRR0jZ3QBS/aMstN1PBgwbsMKrYBXPsut6xB9QCa3gAoLfDg6zG+ClR83GqP9bS/ZNbvSWWZXWQ+uTASo5TaLQV7UZYIlfTk0rYGb+ZRCsbobCgjSZw3Fe2xposR97oj8SRW46PVKWdlE4/b0MHkjOMwRxkdZOKU5Day4OWYYGfB0msh0LxZAvbTuXBlJaOaC/APFBhikSJtmi4LTz4/uc/04objScZG8iL0vsE8z/ApvViI/g+WStknH8KCTgXfV1MqxII9jZ0EnQbTXFCOKjHCO+ad2LWYHYR/4hEyZ/M4mrk1JT0W7edgSwSy86eg3axmFEMq9Nm9xqtem34CpkeeNTANw2BkxefkQ0XTXw2MSnaYrHPcGdNhYO/kRPaqIHRPHCLiExA+gc503L1w6pjHCEC13ng9tMXQ96QHRke3Aje/KB266TXBTsSKeVr6ddxEPe3krwFmes9v03DCDjOGZC2uUtvuPoxyzJ7PCTDRyw=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015)(366007); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: pVdVMyIJUZTImALvyw6MVriwuaod4Xwvn0sez56Ikjjo8EGuuQCCg2k4FOp6Hlm2y6ugFJZiNo95XVSuSdkrid0t6NMTWrzr+peKqMvcnTFFhhVfh8XisevTmoCBEj4han43TQTdxzZtG5nNdKLjh9BrmcN4YRBGmB/zkoiVD4lD7Dbt4511hfLPUJnwz1ZHe0wJ/xUKPmskPdTPXoXHLyWis52I/h9gSJQ8eY2+6T0UN6pdPYf02eiQ6NuBiJPg9dG4F4k+JFc6cCh6WXPAA1ULXFsuH+7j/x/cIjTVaN+arkaNxl0L8q2+Mi7wuAnUvnmpe/qsv7dVheUdqIhPoAp+TtE9Ma80p9wY5tOaVIAbNoi49h4tyFnzELx+EULXti1v/EGgwZlsJi68kpcQJX0bLpV0fQD4yHRLIosN1AsPW2X1giwUJttdFWJ8ISG6hHx8iL59i8VOKyIJB1cBWMokfHI54o/HOVyOGls40M2CuidU4hydImgz35SCB7uffjDUBeKob3zh26xy4ovqtliWMqWXXZJd9Qlxv0SFzgtQyEKaxk3y+cq1ra8yEaxEPreadzoUP3LDe4ITZkWQyb7gQJVe2c6x0R9DDnf2QtuJlp/g13aTraUcdneHnuZLF2nKerug8113Qy3W7fsujLyMBLZ8yoPcwrfUCLiTE5MB6O4rYdPryWmHbO1yqQkcgvnK/hJb2CL6WZDdO9aX8Eq2tk/TSJL/T55Zl96FpUoRCf/SurRdtnAzUgI+Dr3fFgehs+oJod9ywZ2kFU+4jWLqGNbBo8ofvbSX0n+LK05Sf1OCwf96kwLbtyoENtpRJS+LH/UeuMw2fE3PIjgouVbIAldJ+CsU7XnlNtlZ3vCxoKVH8wu1aXC4xon1J16NrVhpSubDjShM3asW4li8T7qeg5KhZRiuVg9L7/T48GlY2FDwoHpTPnMsqRAwyBAEVMS0MDiihCLVFYTfSS3TVoXVmYIVX9H7Fl6Bhnfa+B5AeUc2ufKvXqpZplnGF3sd8ndbzd3EPSYCv18r9vjqvZpxG+/FmqJ5tr40JfTBfyDEBWM4WQ1NkwaaeM02HGJFLwdZkpTHm3e3aEFpo69aOiJN45qwgXqC4BteaCJDsa46A2DVeVO15CSgEMyYtqGWY4rnl5fygBFGoJaodh+FJSk98AlLBrOW93X4eZF3Z4ClNcz1+8h9o0Unxq7PswDioOtI/r3sc8K9ZqGpXRZ+sN/G+16QjLnZ9njQGM5YXbSmg0GreGXqMtid91kGsxWCB4wRxUR1nr9eDpW701qOTt7ZtS0o8MTPOtBcj3ENCLZwVUUd3niUtYLH+IxKvIXdKPFDpVtEjzwPaxUFZbxDxkFE/odywUMoIy9efCIvM97aR6GwujWIh/NGEKTCDc5HWApyXNN0wfyU661rkn9FvFxEbdJiAErnm+b5hoDf4cCo1PnPmnH6sUcm11+BLZmUu7m8fbzhHX7DOy8J9ic/6wM2iYbywczPW6EVNY6Wv15vO77Tn5BlUM5v6r6rpzJKdx3C/B2qrZrNkP7EcAhbWhGHG4cU0B50oMFCI3hkFVmwb/vIVwjj9VvWy4jEKLEr
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-Network-Message-Id: b78664ea-0e39-4cfe-fbbc-08dc54cb845a
X-MS-Exchange-CrossTenant-AuthSource: GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Apr 2024 17:20:25.6388 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: OP7o2E8Ya+/eEUiu7kEe/Q8dG2m1W3ZxP711Qxq3MPHnDkK7zgghUFQgrvrrBYQ6O5XwjIjs5kSfxt4Fnl3Ltw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MM0P280MB0104
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/-AupIQ2HcY1tIh1FaF0T14Pi1Hk>
Subject: [core] Review of draft-ietf-core-oscore-edhoc-10
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Apr 2024 17:20:34 -0000

Hello Roman,

Thanks a lot for your review! Please find at the end of this mail our 
reply to your comment archived at [COMMENT].

A Github PR where we have addressed your comment is available at [PR].

Unless any concern is raised, we plan to soon merge this PR (and the 
other ones related to other received reviews), and to submit the result 
as version -11 of the document.

Thanks,
/Marco

[COMMENT] 
https://datatracker.ietf.org/doc/draft-ietf-core-oscore-edhoc/ballot/#draft-ietf-core-oscore-edhoc_roman-danyliw

[PR] https://github.com/core-wg/oscore-edhoc/pull/24

=========

** References.  [RFC8392], [RFC5280] and 
[I-D.ietf-cose-cbor-encoded-cert] are being used to references to create 
registry in Section 8.3.  They should be normative references.

==>MT

We have made the following changes:

* We have made RFC 8392 and RFC 5280 normative references.

* The codepoint 3 for C509 certificates is not an initial entry for the 
new IANA registry anymore. This registration can instead be requested in 
the "IANA Considerations" section of draft-ietf-cose-cbor-encoded-cert.

* We have removed the reference to draft-ietf-cose-cbor-encoded-cert.

<==

-- 
Marco Tiloca
Ph.D., Senior Researcher

Phone: +46 (0)70 60 46 501

RISE Research Institutes of Sweden AB
Box 1263
164 29 Kista (Sweden)

Division: Digital Systems
Department: Computer Science
Unit: Cybersecurity

https://www.ri.se