Re: [Danish] Charter Text and the Problem Statement

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Mon, 21 June 2021 05:10 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: danish@ietfa.amsl.com
Delivered-To: danish@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F1023A2245 for <danish@ietfa.amsl.com>; Sun, 20 Jun 2021 22:10:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level:
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=wkmQgIYF; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=wkmQgIYF
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pll54nq5WJdF for <danish@ietfa.amsl.com>; Sun, 20 Jun 2021 22:10:49 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2070.outbound.protection.outlook.com [40.107.22.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8013B3A2243 for <danish@ietf.org>; Sun, 20 Jun 2021 22:10:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=I8sIAPwilgirT5rhlHN1dEMW4Irfx3tonG4gzXc+Upc=; b=wkmQgIYF4etHfxYafAC4Nglm2GJhnF27eUtwU9niIZ3I90xFlN/+bL8Q5qc745r0JLHCdB+nW2UYFHCpy7JtbgdmUO8HEnJ1gog7MlPzlokSu7G1sZcBZjWuGKuiK2QQM0/4nQe8YYSKCNLwxgHC9A5m4iB0pq4XbirOLXvCnP0=
Received: from DB3PR06CA0011.eurprd06.prod.outlook.com (2603:10a6:8:1::24) by DBBPR08MB5883.eurprd08.prod.outlook.com (2603:10a6:10:206::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.16; Mon, 21 Jun 2021 05:10:46 +0000
Received: from DB5EUR03FT019.eop-EUR03.prod.protection.outlook.com (2603:10a6:8:1:cafe::b4) by DB3PR06CA0011.outlook.office365.com (2603:10a6:8:1::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.18 via Frontend Transport; Mon, 21 Jun 2021 05:10:46 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DB5EUR03FT019.mail.protection.outlook.com (10.152.20.163) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.16 via Frontend Transport; Mon, 21 Jun 2021 05:10:44 +0000
Received: ("Tessian outbound 92494750bf3c:v96"); Mon, 21 Jun 2021 05:10:44 +0000
X-CR-MTA-TID: 64aa7808
Received: from f289a8a1ab78.1 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 887DFD59-1A9A-4002-82E3-868A0B443666.1; Mon, 21 Jun 2021 05:10:38 +0000
Received: from EUR02-VE1-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id f289a8a1ab78.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Mon, 21 Jun 2021 05:10:38 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Ca5AuA9G9uDb10nBnC/tpbGpOcPfv/iVjkQmiBt+GCuI85wLORVyY7SK11JOWBNrOinMGhHK5KiPyhRF00m9Uv7XyClPIeffVddmkN1zM6iYTULbwGQvKS737+mM0VBDsSv3JBb3q8KD4fhKYHlTTv76H5PuD5Yg8qeiZJwfL8dlLlIsOVzkOtMAfoScqesJZbRFGb7GiYW7S4+oyvAEapMNUsnzmD/McwYMqSvbQa/BV8vN8AS8i2vSH9W/3dg6APi0n+zWohOY01NU3N6csYlrGSgZsQu16TQig46rKvxSUAE2jBRb4vpdE0Qd5ngTcnufqQsSETI7UZmbawykig==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=I8sIAPwilgirT5rhlHN1dEMW4Irfx3tonG4gzXc+Upc=; b=T29JpGOeUIHfVq51XPr3AyNm+KH1yjqML5PUzPl1Y6xOvMyBCq2E5JAyKRwng0gcSWyd9G1WOAHmWPShPimhV9ayVoNZfmtrF3ov444lSKXEd7bmNIG0R9yn4s7LNnW0ao5HgAJmOl/xnDboH5ElsYTVukUkS7msLqQfYIYQh7LUg0INwoK2p0RKTj6zDcE01zLKfuMab1JpuF7u8kWeTqTRJV9arm1GgiNiExtgYhdbJsbe7b87c0E6Ghy90SMRXknHRHSAK1+Xr4bS0VmmZqCFplDg82tqPP1bhJ0SmdO5MF+Hx/KFo979vhcHOD5TsKdgXoy3RIPTw8BIRvmRcA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=I8sIAPwilgirT5rhlHN1dEMW4Irfx3tonG4gzXc+Upc=; b=wkmQgIYF4etHfxYafAC4Nglm2GJhnF27eUtwU9niIZ3I90xFlN/+bL8Q5qc745r0JLHCdB+nW2UYFHCpy7JtbgdmUO8HEnJ1gog7MlPzlokSu7G1sZcBZjWuGKuiK2QQM0/4nQe8YYSKCNLwxgHC9A5m4iB0pq4XbirOLXvCnP0=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DBBPR08MB6250.eurprd08.prod.outlook.com (2603:10a6:10:1f5::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.19; Mon, 21 Jun 2021 05:10:37 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::69cf:4429:a804:7f41]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::69cf:4429:a804:7f41%3]) with mapi id 15.20.4242.023; Mon, 21 Jun 2021 05:10:37 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
CC: "danish@ietf.org" <danish@ietf.org>
Thread-Topic: [Danish] Charter Text and the Problem Statement
Thread-Index: Addin8Z32g6ibl9RQiW6iIvXVU0WhwAVq2gAABL3x4AAGNNDAAAroAeQAD1ePYAAGAHboAAc2eSAAA9o/EA=
Date: Mon, 21 Jun 2021 05:10:37 +0000
Message-ID: <DBBPR08MB5915DB801CD6D3FFD8D69E96FA0A9@DBBPR08MB5915.eurprd08.prod.outlook.com>
References: <DBBPR08MB5915066E1CE5BDB2D695A8DAFA0F9@DBBPR08MB5915.eurprd08.prod.outlook.com> <CAEfM=vQehhvSNeBNitJJjisEbimn_gizoo8VTtHWUJ1zSU+rQg@mail.gmail.com> <DBBPR08MB5915D8FC201DFEB31F7D8EA8FA0E9@DBBPR08MB5915.eurprd08.prod.outlook.com> <CAEfM=vTHPmDcOimf9xOvkYgeObbHvpfG1uZUVjBJFhykrZNafg@mail.gmail.com> <DBBPR08MB5915C107E3620968DFE34D97FA0C9@DBBPR08MB5915.eurprd08.prod.outlook.com> <23295.1624134481@localhost> <DBBPR08MB591546610B09B3606721EF2CFA0B9@DBBPR08MB5915.eurprd08.prod.outlook.com> <5631.1624225291@localhost>
In-Reply-To: <5631.1624225291@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: C7057483F601F04283354F4EFD489AC6.0
x-checkrecipientchecked: true
Authentication-Results-Original: sandelman.ca; dkim=none (message not signed) header.d=none; sandelman.ca; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.123.248]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: b322628c-a682-435e-35fd-08d93472ec6d
x-ms-traffictypediagnostic: DBBPR08MB6250:|DBBPR08MB5883:
X-Microsoft-Antispam-PRVS: <DBBPR08MB5883CBD7E8C10877D7E1E3A1FA0A9@DBBPR08MB5883.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:6430;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: 09+0Cd528FEL3g2RLSNvlmZxmlz68siZSu/Z+Behcg4HPzCRZakVOYJjWDZarleuBx5EdFEdAJgNUV99ltKwNr230HOyAIUYRoZMshGkJXhkZedQNKmU9Lau8SUDiX9HKDoxqrJP13knBpqIAUTRKvfCH1TZyTas0eHrkN3G5ljiZzjmrbhEApMUqLy2w1usOtUM9kH8QAVhUmybS86KcJDh8AUNtK5vPe6xjGzvtTuBQdhHNBzYwKKEEVBz8kVocoI+2ivKLDsCJuLkYi31PFxwzs6j+tg+96U5FqmGfc2PNFD1L82N+OyHUviBv2LfUxqcQ1O9aVn+pNOMy6GCx+6x6IInIWsPwGQ2fbStpnOB8/D8YmLx5ROEws3dBXYCcbk05tV1aXZVnGFHIXr5mXBIT4ZxpzTQN6U2W3rBWJ4oseERRzvkBpkV/0dOMZJ47W6d0tyAerAEv/vCVYoTIxD7dUmzqumYngnh5M8ennNvK5GdNv4EIheaVLx8koG7+jK0q0Z8JBbk/PPoF8lp/wDr6fsjXs7Dkm0g2cgbXTzJPDw2ydaFndoonFEnuXMxLpNTLg0z2Gu2jssP5N7OQVzPFwBXNPyNwtzNgRdh6ao=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(396003)(376002)(136003)(39850400004)(346002)(66946007)(76116006)(316002)(2906002)(83380400001)(71200400001)(4326008)(66556008)(66446008)(64756008)(122000001)(38100700002)(66476007)(33656002)(6506007)(26005)(8936002)(5660300002)(186003)(55016002)(9686003)(7696005)(8676002)(52536014)(4744005)(86362001)(478600001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: AdydV8nYGM4+VE4uKkHXBNSTUofvdtynWYMt16p8ctfnw29K32ZNMBEqvNGhtiRC3zBbVyHlMsGp39n2D+ZUBU5OCocFAHPzHjdh9cN4MYY0DoMSJZinZ3NBr7uYmzOSjjkpVGduNYZl/vuvziM+L+AFhmsVgHT87De4wIu2gso6L7xUWsRJC/Qxxr2k4I0ziB9MJP5P/bsMzu/bfBf11NAdMTPkrBEN4LYVUULTsmif40w0HE4u+YWVpCpnLBiOLZ5pa9b46IMZCMswEKIa2G0O/KqA3CQc8KNQDK8Fma0BvMiyKbX4V1vknm04g4UcHgouvxotld4vJ2LmfNDx1W0cQ9VdJqk44vf2gMxz8o/wP/nGCWoDFmCRwLhnMEgW56scdtdHzyhPYW8I4CqUyFEPk7wtA4eu16sBTHwQUn9chBPUdYF4QpVo+tYK73hkRVzQzBo7V/IZS/dkk5tQ61GPgv38PmERXp/P3GkM/lKzITDI6NdQrmu0JdJnY8ve92rUXRe55jEZWYxwOnMx0IiTt7VxaPNuKoF8Xdd7OasEE/rpV49I6T9UBNFHDAT6m/miRBCWJl65lbmaZfZdl3U43R4wsZ1XbPV9Vbq+ASPhXMobju8bD6RxMQ6QbJVdAXuyIsm8eTe/LBBxEgJ4iit1BNeZC6SkhcnoQe5QjpoOYgVjumuGzNhhw4cI3WuCQRK0bkAxJAwy79D0KzluPyIuF0Kcq/zKOaZy3z6Mf4/K5VI1D1nAc/CrBLdpTizxeWKA5woXix4GOvzN2HGRGPlL+nKr+YZxKECoRnsdhRjvWJLAWKh9e+ron8qOhWIU5bsQCwTyzYRHQR3n18ysddT+mS1s3ge+gsNmWsmfMB3pFbC6yNEaXKLG9hXe0ySXI8YPFGSRM6AlwOF8CcPSKVQV25n5idnwoLcxI5z9Op8JMnFnlLxjooSSsdAANAINZkgOMfNXigbrQuGhjMTbO5jsS+cBmxrA48AjfU+hrDQw+8+wq4dD3I0p1Vrc6DWWKXzaaTsUWCC5/HcPg7sQdEcP5CTluusSk5zjeNd8LHgG9v18uXq2Glp5xaUi5l4RHIsrkZ3nKzjoUnBdlRfhnzbUahZ+SYKsZSKq5hdu8pPdeMbf7gPtfSmA8Z4KzXRvBIvTX3HRsqmEg8RZUIjKROXSsu7pRhY0zR6pP3BmI78jCWlOrM5gFr/L0BMQoyKuDIiQEoolJK4J7/fgNtxUO2HIInOf3fgTI6vHiAnDObo00YXhjdTNi0ezxfH+wxwFzLA+0yVP7j7i0i1GffGbYFNG936HlJ4Mya2EcSwIhmNYyHGrp8a4flcrMny5E+JR
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB6250
Original-Authentication-Results: sandelman.ca; dkim=none (message not signed) header.d=none; sandelman.ca; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR03FT019.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 2872b84c-54bb-43d6-558e-08d93472e81a
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: bRSI/q2QQg2+FV1pqy1aMkvFxSjBBJlW++LSFnF75y9pro1Pt1N3EHMy0FaShTjF1BwRNoHS7DOqrVzXelVxP8D8BT2+l+d0FffXf7yhe7OcW/wAGtU9s7mYsU89USvwSNI9Q8AcX92/lfi0qIYQW8GAtPg3d0oFia1HEaJA8aowBEym+Tu751cXNOaCbldUJOXClR30+8jmBdWYu5M4KDPiusraJ134ujKxlQ26Br7+xyEkrXB5SkUrqZvLkb7Nfafhx3S4+GEDgcT0mbeuKe5EuarfSi7KC3AwMd5jw0tWGKlNilWUZwcOMzkJDxBxjI1zN0Y2xwn5jE9j5qCbJOPeV7V+IQyVzfFyGjBPfKjvzOupuT8n3D++afN1PZJQ8PDYhDTf/nKLbrjNlivMJdQHG8oXUktLCFIBZN4a73rofT5XBRxOMRZsrpw0xAbiXsnGcyQ2UQfTAKOkRbDtU8OR4etSMDf62Y6l0z8mKqiko54F9W8OmzSeRECzfS4Jm/3YmELJxXJM2QdDMocJAzF1GGMInzkJbzmprB2aZCxf4Ik0ejsTrV3c7/3pSSWI1XjimfP+JffYBsMmc9obG29IHmvm6GsZyRGVZC2ft4jsTgcDszsKc3d9NVSrcI9Ee8EYFcZDyxrzXdmYI/i16OJY2oRolrxieVOvX3VJN0I=
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(396003)(39850400004)(136003)(376002)(346002)(36840700001)(46966006)(8936002)(7696005)(356005)(186003)(316002)(36860700001)(26005)(6506007)(81166007)(8676002)(9686003)(82740400003)(83380400001)(47076005)(82310400003)(33656002)(55016002)(86362001)(4326008)(52536014)(2906002)(336012)(478600001)(4744005)(5660300002)(6862004)(70586007)(70206006); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Jun 2021 05:10:44.7062 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b322628c-a682-435e-35fd-08d93472ec6d
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: DB5EUR03FT019.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBBPR08MB5883
Archived-At: <https://mailarchive.ietf.org/arch/msg/danish/qZXxPsklJJiHCj4Ftjc_EXNg4wo>
Subject: Re: [Danish] Charter Text and the Problem Statement
X-BeenThere: danish@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: DANE AutheNtication for Iot Service Hardening <danish.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/danish>, <mailto:danish-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/danish/>
List-Post: <mailto:danish@ietf.org>
List-Help: <mailto:danish-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/danish>, <mailto:danish-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Jun 2021 05:10:53 -0000

Hi Michael,

One remark:

> If you use DANISH, then you don't need to onboard the device (i.e. enroll it with a new certificate), because you already have secure access to the correct certificate via DNS(SEC).

In the past we used different keys for different purposes. A manufacturer provided key was used for a relatively small number of tasks (typically for obtaining operational keys). For use with application services we used a different key. We used yet another key for firmware updates and again another for attestation.

What has changed?

Ciao
Hannes

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.