Re: [COSE] CBOR Object Signing and Encryption (cose) WG Virtual Meeting: 2021-10-12

Göran Selander <goran.selander@ericsson.com> Tue, 05 October 2021 14:06 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3399F3A0E2C; Tue, 5 Oct 2021 07:06:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.552
X-Spam-Level:
X-Spam-Status: No, score=-2.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tl5zTjd97WJQ; Tue, 5 Oct 2021 07:06:09 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-eopbgr60071.outbound.protection.outlook.com [40.107.6.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 613393A0E2A; Tue, 5 Oct 2021 07:05:36 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=giQTRiVSUlspMTwKjKJCoXoKnja8YJcJCqIoA7bAd6mdFhnx+c/GMq1dMlmRGxzuF8Mjg1esmRg/82lmbEctkSv3+dpAx/OO/I0uGxQrooIJqPaVqlCXcTG+CjK/OwkxXA79SXa8fZXmZamg5VVkTev35Hx8Tc291LqT1DmYU7M/TI+QUiQwGUTK6LojdwSeoelA5C1ZRQx8VeUK9o3eo/sLlmhbzvi1nl8+Dlq+4cUSF3f2zP6eaxRUiIafGecDD1nRAsqdWhjMJp5B+1LZpfbtXAheHvLAuFd482F0wvFn7BEGGN9I1udNR2e7M7DUx7IRkCD3C083tU7t6xY/7g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gGt0GIiWw3txyMEvsOEFjIy9BwtvlZO54Qi49+mmh+Q=; b=ZSvv6pIXlOFENWK3tD7fnNfCpUpsA0YKcPF3qc6HKG13uRO3ChBuMg/laHNyUWrW4L5D/89kq7tRG8kj4MU8Mi2Aaq9PhFxe5mJv7y3dY6vnFkHAPhO23IbH87kek6Tdt4+G+Z5irwYmfVJ5uzwP+Qew9vi0zWlp+cHYKzXLPY6lknvbWiXedQxmxCuq70wJceNoiycHAh7E4ElQ3tpZKB47H+ZNLNdH9buuewumXodoAVNH9z8H/7jDRuo/cYm5hr+I5Xg5wKFoV2F7f7nQaF617atqIm5JhSTCAEoMVskgteKWfZMPghpWfnWwL2zpRtTHltdiMn1S7uM9AP2jwQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gGt0GIiWw3txyMEvsOEFjIy9BwtvlZO54Qi49+mmh+Q=; b=f7NsRHgTf5iyk0q2YvVOqgRJtW54DbJkIdlN20035viYRfBERDsFCHBLVbi5y2oGGQViZbF812uNrkyn/WbEKubGCZ5UM/cJdSZAwn6Eocpy4STsG5GS/ic+j8BeXc9lEmYEfq7lj+KC6rvnKDyTm5/mipBsdLYCo7RuZ4WNNao=
Received: from AM4PR0701MB2195.eurprd07.prod.outlook.com (2603:10a6:200:45::6) by AM4PR07MB3155.eurprd07.prod.outlook.com (2603:10a6:205:8::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4566.10; Tue, 5 Oct 2021 14:05:27 +0000
Received: from AM4PR0701MB2195.eurprd07.prod.outlook.com ([fe80::b14e:996c:5059:a9f4]) by AM4PR0701MB2195.eurprd07.prod.outlook.com ([fe80::b14e:996c:5059:a9f4%9]) with mapi id 15.20.4587.017; Tue, 5 Oct 2021 14:05:27 +0000
From: Göran Selander <goran.selander@ericsson.com>
To: Cose Chairs Wg <cose-chairs@ietf.org>
CC: Ivaylo Petrov <ivaylo@ackl.io>, cose <cose@ietf.org>
Thread-Topic: [COSE] CBOR Object Signing and Encryption (cose) WG Virtual Meeting: 2021-10-12
Thread-Index: AQHXtIZtNEj7S2GNvU6POgGBmAOSE6u51wEAgAqBQuw=
Date: Tue, 05 Oct 2021 14:05:26 +0000
Message-ID: <AM4PR0701MB219556AA46951ABA0EB58CBCF4AF9@AM4PR0701MB2195.eurprd07.prod.outlook.com>
References: <163284672770.16065.11816977009009151975@ietfa.amsl.com> <CAJFkdRy-LPEAtUZR8jBY3sk0E9Kt3RiARSGdezORqE15GRpjJA@mail.gmail.com>
In-Reply-To: <CAJFkdRy-LPEAtUZR8jBY3sk0E9Kt3RiARSGdezORqE15GRpjJA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 77814b43-e9a3-4474-7f0a-08d988092ecb
x-ms-traffictypediagnostic: AM4PR07MB3155:
x-microsoft-antispam-prvs: <AM4PR07MB3155F59C34A1501291823581F4AF9@AM4PR07MB3155.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: JjIo9CCRiH1SNj2TTcECxO/aAo4ZjqNDAkHtkVVOjU+HYFNAe9+SsDupswQx59Nhk9Lso7uk/PrSKQIQAYjxGiM5u93WTfgpH4yTcuWxdjz8+VY8I8Q/c+a4zIVvHvPUpHgHx8l561JmEtWk067kkIvCspAX3H2eTJWzstL2j8wDZWKP2Nik/B0ptMcuWJrP+xPzUGjp9KPl4NzisRnix9M26Sxw913LYqn2rjci2e1gJBEzfPUAyS3oGPy1NoFIeSR1h0EtYC9DvC6fYlFQEewaLPmu/9RMeVZsq8wDEiB0/vZMpJ8ZsCfgSW495WkXcclMD/jF5UvZpXCGzLX7cVPKeRhgt+fcIUgJ5DjuAIoKe7eGM+Zlw+uDq8h035FIiThsK1kkHMtQ9PJ71Vp2RTdtVWW8xEYGe0oJ0QZltR7/etCgOjzVS9P9AMoKdJkh8c1+n0pIxKOPhOH5CWQZKoEHg/NFKKz3vQtLREKbtyEV6EvhXSET5NPez5uq9Kxc217gsIoDgWR7UvExsPULzR+a0q8+7kmlxrxzY7cpHg107q3hvooGdW7tYuUaTAeaHUrSDcNgEbTd4swU5v4eO6ejcKPa1VCMdspJDLm3+TlbDzIEQvOepzKcJ8EFIbeqy4My5bKwwUmNqTusm/l+CYUnF+GikiLHsp+Mcnq8LRycNjEupfFozVIjxRP1esCs/VtGszCNfH5CV7Zq7I3mmf0w0SI9QwFj2NoG4H8n3pzNxrOJvskT4Z4ViuNBKlaZSdOKldzd3aAQMtQQBVpqJNWdLuSHVGdQwOsLq2ck+Mv9FcS1Kl+SWGUA+WOOe5cymHQMTwjFn5ZXSLBFtPibJg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM4PR0701MB2195.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(38100700002)(508600001)(55016002)(9686003)(66574015)(4001150100001)(6916009)(5660300002)(166002)(53546011)(6506007)(316002)(38070700005)(54906003)(83380400001)(7696005)(71200400001)(52536014)(16799955002)(2906002)(122000001)(966005)(186003)(76116006)(4326008)(66946007)(64756008)(33656002)(8936002)(91956017)(66476007)(86362001)(66446008)(66556008)(8676002)(26005); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: eKkN7E8y5Nrt5nKRWT+fmsOaOw2QdtvrucmfwijN1F1FYwKgis+KsuvN+rOS+mt26fLwxUXaMAN2gq8+AuItJ+29cObfnI1hehy5RIQbNQsjmt6uGPOSCTBZ0BH13gwEqpqGWEHM1thsRxpZShb5ls9gUawFia6hLVf1hzYcyUw5b0PselbwOgSH2+wv4sXyT2SaWpPqqOhXK8NiYs4Qlxg1UMsL9EiEScrf0K6WNnZgIFrNSxOkN19qoHk1VDGuQj1WLqxk5K71kcBwjw7u+ecGB7Cog9nF0NX5dRpzOl2Suwi5qXgeISC+QwpipbEWIg1ch5K0S948BCVRjTV3ZeIxOWfyk5/d1m0f+ss2QbARNTar2rQdJIrdkFGL/WXpfas84hvGHpKRcDDazbjh/DtJYRhBFCQ4K1EHFkt04YCfaXXf1cjDQEG+aODOH5lU/nGw7dR7y+FhJyWl3KPCax4lNyraUymCtEPixot/xy+8lewJR5Y4eyaFdlGxc9HdkKrxV/3IkDgHNslS8O5J9snKdoSGw1Vsegr5dnrbEOEk4Fh0FwIvKwGhKd4KTdwXX/wAB/UQEheThitrX31LAyXB+T8hqzF3VkBujDHiPcHsyO/wu7BweqwV01d8pMOsn1+yYC9hZah2dbQF62xVKE2EJvxfbHom9jtguOS1X09E2Yr2+F8IHejCz6QDVQ+99f6N3+eXUlJUo8ssxSAbIi0Pk6NB5NSNOmXMm76nE7HIMgh64sAKGhVIuPqlpzNNHqzH7n239NhWKo8TKImkPBhU2WN2ThnAgZivrJGiLLOpYEh7TNACSaNCAc6tLlaxLTDBb1C5f6iCN2yWqa5j77GR/6NKKy0JhixivVaa7d3uJWLhV4vfhVICJ8aFvwzJebvP5riqrArzZmJimZvCigwjoUEQASq1cP95QQx+SHaF71Ck/UjHDmt426GM12wWuvJkOZJnfuaVsFidU8iCp9PDByWTAcPFeL4dg0U3+fnNJSUsEDBs2aGNtT3ww6a5FVDhPmy2xV1dCWyI0UvOVnNloEuC15DgvQsBw1hZr26DDd8Qd9Ybr21kANE9ZBnIevtheOkElBNeR32KHKTy5ck9vI9FaLZAL6H8wlWZWBx7i+Lgpg7nOjX0kQOC0v3YYfJlkTPCHGbJOrdGksj02lrKcfaIYHBoAPxUZOETyMIkSo2Jf0VnKixYckEphDFav/rXWOoXsfn/MkLeB8Sgxo0Jk2UWxdzWO/CiF9vb79DdawWNG1X3VboleTy7XwpT8+vOzPDouDiUsoadWXi+9OobaHmfROm+WktKtsPb8qmJTQ05BfimGM1cl1/rqe3gtIyEb8j62DqY7kARHPkrgw==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_AM4PR0701MB219556AA46951ABA0EB58CBCF4AF9AM4PR0701MB2195_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AM4PR0701MB2195.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 77814b43-e9a3-4474-7f0a-08d988092ecb
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Oct 2021 14:05:26.9547 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: y0JNQamJd3pdjoJsgwCSmMfirhw3KaVNu0XSnCGpSHHUG47pkC0Pyi8L4t1IdvjPhJjvUaGQyFsToCys0lDo3FIeNBhwEONWPRVPh5wxlj8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR07MB3155
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/kflDoPnAtlRy85S4cwaBpupAR08>
Subject: Re: [COSE] CBOR Object Signing and Encryption (cose) WG Virtual Meeting: 2021-10-12
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Oct 2021 14:06:14 -0000

Hi,

Some comments on the agenda:

> - cbor-encoded-cert-02

The base specification of C509 has now been stable for a while and there is not much updates since IETF 111. We were hoping to get some reviews on in particular the new supported extensions and the specification of CSRs and CRLs. Unless there is some new input before the interim, I don't how we should make use of this agenda slot.

> other topics

A topic which we may want to discuss is the use of CBOR Web Tokens (CWT) as authentication credentials in COSE, analogous to how [1] describe the use of X.509.

In LAKE we have defined COSE header parameters for CWTs and CWT Claims Sets containing a COSE key, and will cover their use with EDHOC. But there is more that can be said how they should be used in general, associated security considerations, etc. Basically what [1] specifies about x5u, x5t, x5chain and x5bag. Both TLS and LAKE are discussing the use of CWTs so I think this would be a valuable contribution from the COSE WG.


Göran

[1] https://datatracker.ietf.org/doc/html/draft-ietf-cose-x509
[2] https://datatracker.ietf.org/doc/html/draft-ietf-lake-edhoc-11#section-9.6





From: Ivaylo Petrov <ivaylo@ackl.io>
Date: Tuesday, 28 September 2021 at 21:36
To: cose <cose@ietf.org>
Cc: Cose Chairs Wg <cose-chairs@ietf.org>
Subject: Re: [COSE] CBOR Object Signing and Encryption (cose) WG Virtual Meeting: 2021-10-12
Dear all,

We believe the working group might benefit from an interim meeting to
discuss some of the topics raised recently on the mailing list as well
as to try to make progress on some of the pending WG deliverables. We
have aimed to position the meeting in such a way that it should not be
in conflict with other known activities and it will allow us to have
some more time before the next IETF for follow-ups on the discussions.
In case this time does not work for you, please let us know and we
will consider moving the meeting (for example a week later). If you
believe other topics than the ones mentioned in the preliminary agenda
should be discussed, please also let us know!

Thanks,
Mike, Matthew and Ivaylo,
COSE chairs


On Tue, Sep 28, 2021 at 6:32 PM IESG Secretary <iesg-secretary@ietf.org> wrote:
>
> The CBOR Object Signing and Encryption (cose) WG will hold
> a virtual interim meeting on 2021-10-12 from 17:00 to 18:00 Europe/Zurich (15:00 to 16:00 UTC).
>
> Agenda:
> Preliminary agenda
>
> - kid supports ints
> - x509 and -bis documents advancement
> - cbor-encoded-cert-02
>
> Information about remote participation:
> https://ietf.webex.com/ietf/j.php?MTID=m6b66a43453dc56d79470f8cbee292bca
>
> _______________________________________________
> COSE mailing list
> COSE@ietf.org
> https://www.ietf.org/mailman/listinfo/cose