[COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-cert-14
Ivaylo Petrov <ivaylopetrov@google.com> Tue, 22 July 2025 07:58 UTC
Return-Path: <ivaylopetrov@google.com>
X-Original-To: cose@mail2.ietf.org
Delivered-To: cose@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 452C04810FBA for <cose@mail2.ietf.org>; Tue, 22 Jul 2025 00:58:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -17.6
X-Spam-Level:
X-Spam-Status: No, score=-17.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 04H-dbLRoB5b for <cose@mail2.ietf.org>; Tue, 22 Jul 2025 00:58:50 -0700 (PDT)
Received: from mail-ua1-x929.google.com (mail-ua1-x929.google.com [IPv6:2607:f8b0:4864:20::929]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 233DA4810E90 for <cose@ietf.org>; Tue, 22 Jul 2025 00:58:43 -0700 (PDT)
Received: by mail-ua1-x929.google.com with SMTP id a1e0cc1a2514c-87f74a28a86so6754814241.2 for <cose@ietf.org>; Tue, 22 Jul 2025 00:58:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1753171122; x=1753775922; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=Fd+CVaWsJkmZuVpRcxrDRGJIq6m9ZsWGADVQpmO1+lM=; b=fQCEcoR1U6StjLRkxTCmQK1IX0TghKwc0SBSFMaBn6Escx3RGTrFY00TU/AcAYVS6m jl0aOk2OzxtYMGWD1BLHKHhozTi0LmNKzJUAf/YNpDeLN9btOOHZzuaE0S4IEKpyKFLw 9C8ybDcM5va/MU/L0QGvHur0i3jjBwBnRj0Wnx9Xmf5m22cXJg46x1pgc4KgfL7CkDZH 6VgVUSiUDbYmNDVg690PqXh9U2Q4ofSB7tKY4zI6o5UBS1XhKiccWZwXPVC3QfR2q0P2 96N/yGocWleVC/ujD5Eg3eQaAJJG2f1iV5fTHQh56YzzpBH/eKxqIbNp8tEaayV/FIG0 mQQQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1753171122; x=1753775922; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=Fd+CVaWsJkmZuVpRcxrDRGJIq6m9ZsWGADVQpmO1+lM=; b=AIr16E9BK47pzH7HVk/anEx0Oxbk3QvhFoqaklR3fBNHblHJtVQfk0MJstg6b4egZe 3vV0IaVBSc/c4WJJ8UGhHVA3MlXjkejDVL3Tz/BnazhWr63uRzi0RNYrZqJqYKbbjEFp tA461QkgpI+LrVDO53l4xUEHTKXtsLC5gvCw26OC3NNInSO8Ogrlyll8nalyyGr4PyJz 8RqMVb1H/U6WJchhg09xxpXz/hwctqgcGMZObPAdbDPoOXUSLEZbPKWBizZt3N4i7vKC GhLkMRAyNrqjwMvtZ1qnu96BgViSb+QsTk6pR4PjQU/FjfbAl9nh3NGiBAM5x6hawm3U vl4Q==
X-Forwarded-Encrypted: i=1; AJvYcCWeveZanyJ6NTiHTpLp2iyVsPop8LDY3usLzK6KXJxfiQz6xEVpZ4Vh+Sc1jc5/aRFsF9pl@ietf.org
X-Gm-Message-State: AOJu0Yy3Td1m6S/egd+xQXJGv2ma22FwIIErSgc+yamXBpg/jkY+rCBG qGPjv885shzWRLBRjA83jvVnySOJWOucy1rQbfSMe3S7BQJ6N+6JKX+uxU/GA8UvG4UocSIzhmi dw4YpBzpO9kiz58Yzmluwwrj8XzDU2FFW+qoTviQ8
X-Gm-Gg: ASbGncsd4zB3fljktFkgoRsnCPJd/+E+pFhpRF8ag3s4N2gTwfuvXbKP/An/QeegWG9 q9ucI8fAj6ItNp0aMkZQryLkA9XcsFAq5CXxxm62na6sl6sxMHR5PC2hcZJtW5cjl9XUtKREEi0 J99BZQSGzvYOo36NcLRQEAGwS2ewesRSyRCQJzHOQ7YVqmrNHttS/hyhK9gB+Y880+a9fXmXOYu CoxRUyN
X-Google-Smtp-Source: AGHT+IHlvM+OVi4Qa6NCer94i+VECsQsH/PZe3OwCQ/UX8vD6kJkhXZMvYyQPaLPMHgPgv+uwkkvbcMH2xU7xJnKY2s=
X-Received: by 2002:a05:6102:4bc8:b0:4e7:dbd2:4605 with SMTP id ada2fe7eead31-4f8999a7d1amr12780161137.24.1753171122214; Tue, 22 Jul 2025 00:58:42 -0700 (PDT)
MIME-Version: 1.0
References: <CAE+mDdx=2Wz4MjRDR7BaohU+C6Sr1QZc_S5f6AK5zo5b0jO_EA@mail.gmail.com> <CAE+mDdwH7KA8W=9S3cV4SS3zfB=hhPxHx-f0Cm5VndrJSuJs4w@mail.gmail.com> <PAXPR07MB884459791FCABB4A1E852CF7F45DA@PAXPR07MB8844.eurprd07.prod.outlook.com>
In-Reply-To: <PAXPR07MB884459791FCABB4A1E852CF7F45DA@PAXPR07MB8844.eurprd07.prod.outlook.com>
From: Ivaylo Petrov <ivaylopetrov@google.com>
Date: Tue, 22 Jul 2025 09:58:15 +0200
X-Gm-Features: Ac12FXx8DknZnU0pOW_RNOkv-uN2-u5u6vuqKJqADcNSgmKbR6m0XM6gfo2gNDw
Message-ID: <CAE+mDdyOrMHCLUP4YEMZXqT-xhe0_7+-jY+zUm=D2VeGtxVuyw@mail.gmail.com>
To: Göran Selander <goran.selander@ericsson.com>
Content-Type: multipart/alternative; boundary="000000000000f90f07063a7ff557"
Message-ID-Hash: SNIZQYXINPGVHHENFUMKOBFPXKS6KX6K
X-Message-ID-Hash: SNIZQYXINPGVHHENFUMKOBFPXKS6KX6K
X-MailFrom: ivaylopetrov@google.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-cose.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Ivaylo Petrov <ivaylopetrov=40google.com@dmarc.ietf.org>, cose <cose@ietf.org>, Cose Chairs Wg <cose-chairs@ietf.org>, "draft-ietf-cose-cbor-encoded-cert.authors@ietf.org" <draft-ietf-cose-cbor-encoded-cert.authors@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-cert-14
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/ufmKbIxOsM_mK_sJgjROxJkmSqg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Owner: <mailto:cose-owner@ietf.org>
List-Post: <mailto:cose@ietf.org>
List-Subscribe: <mailto:cose-join@ietf.org>
List-Unsubscribe: <mailto:cose-leave@ietf.org>
Hi Göran, Thanks for addressing my comments. Your PR looks good to me! Thanks, Ivaylo On Mon, Jul 21, 2025 at 8:58 AM Göran Selander <goran.selander@ericsson.com> wrote: > Hi Ivaylo, > > > > Thanks for your review! > > > > We agree with all the comments and have tried to address them in PR #261 > <https://github.com/cose-wg/CBOR-certificates/pull/261> (separate commit > for the nits): > > > > Please let us know if we missed something. > > > > Göran > > > > *From: *Ivaylo Petrov <ivaylopetrov=40google.com@dmarc.ietf.org> > *Date: *Sunday, 6 July 2025 at 15:25 > *To: *cose <cose@ietf.org> > *Cc: *Cose Chairs Wg <cose-chairs@ietf.org>, > draft-ietf-cose-cbor-encoded-cert.authors@ietf.org < > draft-ietf-cose-cbor-encoded-cert.authors@ietf.org> > *Subject: *[COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-cert-14 > > Posting this here as an individual. > > > > The draft fills an important gap and it is generally easy to read. > > > > Here are my high level comments and questions: > > > > 1. > > > As the contents of c5b, c5c, c5t, and c5u are untrusted input, the > header parameters > > > can be in either the protected or unprotected header bucket. The trust > > > mechanism *MUST* process any certificates in the c5b, c5c, and c5u > parameters as > > > untrusted input. The presence of a self-signed certificate in the > parameter *MUST * > > *> NOT* cause the update of the set of trust anchors without some > out-of-band confirmation. > > > > I would expect something in the security considerations to point back at > this, but I didn't see anything. > > > > 2. c5b, c5c, c5t, c5u have early allocations. Probably those should be > referenced in the draft instead of TBD1... > > > > 3. Sec 3.6 Deterministic encoding > > > > What happens if the decoder doesn't know the int value for an extensionID? > Does this have security implications? > > > > 4. The security considerations section feels fairly short. It might be > more relevant to discuss elsewhere, but how should an implementation behave > when invalid input is provided? For example in sec 3.1.10. > > > > > > Nits: > > > > 5. FYI: The formatting of the table in sec 9.4 and a number of others > afterwards in the PDF version is broken. > > 6. s/certificates with over 50%/certificates by over 50%/ > > 7. s/CBOR ecoding/CBOR encoding/ > > 8. s/subjectPublicKey consist of only/subjectPublicKey consists of only/ > > 9. s/as well as the any leading 0x00/as well as any leading 0x00/ > > 10. s/certSerialNumberm/certSerialNumber/ > > 11. s/SAFI is not present/SAFI are not present/ > > 12. s/the unused bits in max IPAddress is set to ones/the unused bits in > max IPAddress are set to ones/ > > 13. s/with the the difference/with the difference/ > > 14. s/An empty CBOR array indicate/An empty CBOR array indicates/ > > 15. s/constrained wireless links/constrained wireless link/ > > 16. For the example HTTPS certificate chains... - the sentence sounds not > very clear. > > 17. s/C509 use dedicated/C509 uses dedicated/ > > 18. s/Because of difference in size,/ Because of the difference in size,/ > > 19. s/common key usage digitalSignature/common key usage of > digitalSignature/ > > > > -- Ivaylo > > > > On Fri, Jul 4, 2025 at 5:15 PM Ivaylo Petrov <ivaylopetrov@google.com> > wrote: > > This note starts a Working Group Last Call (WGLC) for the *CBOR Encoded > X.509 Certificates (C509 Certificates)* specification > https://www.ietf.org/archive/id/draft-ietf-cose-cbor-encoded-cert-14.html. > The WGLC will run for a bit over two weeks, ending after the Hackathon at > IETF 123 on Sunday, July 20, 2025. > > > > Please review and send any comments or feedback to the working group at > cose@ietf.org. Even if your feedback is “this is ready for publication”, > please let us know. A note from the authors is also useful. > > > > Thank you, > > -- Ivaylo and Mike, COSE Chairs > > > > P.S: I will be providing a review as an individual shortly, but I wanted > to start the WGLC sooner rather than later. > >
- [COSE] WGLC for draft-ietf-cose-cbor-encoded-cert… Ivaylo Petrov
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Ivaylo Petrov
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Marco Tiloca
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Michael Jones
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Lijun Liao
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Göran Selander
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Marco Tiloca
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Göran Selander
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Ivaylo Petrov
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Ivaylo Petrov
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Göran Selander
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Ivaylo Petrov
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Robert Moskowitz
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Robert Moskowitz
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Lijun Liao
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Robert Moskowitz
- [COSE] Re: WGLC for draft-ietf-cose-cbor-encoded-… Lijun Liao