Re: [COSE] Paul Wouters' Discuss on draft-ietf-cose-countersign-09: (with DISCUSS and COMMENT)
Russ Housley <housley@vigilsec.com> Tue, 20 September 2022 14:58 UTC
Return-Path: <housley@vigilsec.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1FC3C1522D2; Tue, 20 Sep 2022 07:58:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.906
X-Spam-Level:
X-Spam-Status: No, score=-6.906 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uKI4HOM7v2WO; Tue, 20 Sep 2022 07:58:30 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9A0CDC14CF01; Tue, 20 Sep 2022 07:58:30 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 5E3BC147F8A; Tue, 20 Sep 2022 10:58:29 -0400 (EDT)
Received: from a860b60074bd.fios-router.home (unknown [96.241.2.243]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 3AD2A1500BC; Tue, 20 Sep 2022 10:58:29 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Message-Id: <7277D290-EB17-43AC-8817-FF9647CBBB0D@vigilsec.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_BBE6B699-FDCA-4DB1-852B-586390C15261"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.21\))
Date: Tue, 20 Sep 2022 10:58:28 -0400
In-Reply-To: <FC9567D0-B3D7-4ED5-BB83-CCCC1A343613@aiven.io>
Cc: IESG <iesg@ietf.org>, draft-ietf-cose-countersign@ietf.org, Cose Chairs Wg <cose-chairs@ietf.org>, cose <cose@ietf.org>, Michael Richardson <mcr+ietf@sandelman.ca>, Paul Wouters <paul.wouters@aiven.io>
To: Carsten Bormann <cabo@tzi.org>
References: <E226CF54-4C8C-490A-839A-6B0E3DF34EFC@vigilsec.com> <FC9567D0-B3D7-4ED5-BB83-CCCC1A343613@aiven.io>
X-Mailer: Apple Mail (2.3445.104.21)
X-Scanned-By: mailmunge 3.09 on 66.39.134.11
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/xUYBhjOuTZ-M8dHhKU6a-Sid1hE>
Subject: Re: [COSE] Paul Wouters' Discuss on draft-ietf-cose-countersign-09: (with DISCUSS and COMMENT)
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2022 14:58:35 -0000
Carsten: Do you have a webpage anywhere that can be pointed to by this document? Russ > On Sep 8, 2022, at 8:36 PM, Paul Wouters <paul.wouters@aiven.io> wrote: > > I am fine with a pointer to a downloadable source which can also contain the commands to install the software. Upon compromise, the pointer can be updated to protect the immutable RFC text. Wether it points to GitHub or IETF or elsewhere doesn’t matter to me. > > Paul > > Sent using a virtual keyboard on a phone > >> On Sep 8, 2022, at 16:04, Russ Housley <housley@vigilsec.com> wrote: >> >> >> >>> On Sep 8, 2022, at 1:47 AM, Carsten Bormann <cabo@tzi.org <mailto:cabo@tzi.org>> wrote: >>> >>> On 2022-09-08, at 04:14, Paul Wouters via Datatracker <noreply@ietf.org <mailto:noreply@ietf.org>> wrote: >>>> >>>> ---------------------------------------------------------------------- >>>> DISCUSS: >>>> ---------------------------------------------------------------------- >>>> >>>> gem install cbor-diag >>>> >>>> I am concerned about adding install commands for "programs from the internet" >>>> within an RFC. If the rubygem for some reason becomes malicious, we cannot >>>> pull it from the RFC (even if we pull it from the datatracker link, it would >>>> still live on in copies of the RFC elsewhere and malicious people could point >>>> to copies of those original RFCs to point people to downlod the malicious rubygem. >>>> >>>> I would be okay with an iet.org <http://iet.org/> download location of a ruby gem. >>> >>> “gem install” is the appropriate way to install rubygems software, not a “location of a rubygem”. >>> >>> What you seem to be asking for is some indirection so we can swap out the name of the gem in case cbor-diag becomes rogue. That does make some sense to me, but we’d need to install that indirection somewhere in a place maintained by the IETF. >>> >>> ➔ “Please consult https://www.ietf.org/software/cbor-diag <https://www.ietf.org/software/cbor-diag> for the way to install this software”. >>> And that page would contain instructions including “gem install cbor-diag” until that goes rogue. >>> >>> Can we get such a infrastructure of pages recommending software up and running? Do we mire ourselves in process issues (who gets change control etc.)? >>> >>> Data point from a quick search: >>> The RFCs that already suggest installing rubygems via a direct “gem install” include RFC 8152, RFC 8610, RFC 9052. >>> >>> (In reality, I’d expect the rubygems organization to act more quickly on a report of cbor-diag going rogue than the IETF would.) >>> >>> Grüße, Carsten >> >> >> Paul: >> >> Are you satisfied with this explanation? Or, would you prefer the pointer to https://www.ietf.org/software/cbor-diag <https://www.ietf.org/software/cbor-diag> >> >> Russ >>
- [COSE] Paul Wouters' Discuss on draft-ietf-cose-c… Paul Wouters via Datatracker
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Carsten Bormann
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Russ Housley
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Paul Wouters
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Carsten Bormann
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Russ Housley
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Carsten Bormann
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Russ Housley
- Re: [COSE] Paul Wouters' Discuss on draft-ietf-co… Paul Wouters