Re: [Dtls-iot] Version -14 Submitted

Stephen Farrell <stephen.farrell@cs.tcd.ie> Fri, 21 August 2015 13:33 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: dtls-iot@ietfa.amsl.com
Delivered-To: dtls-iot@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 736981A9023 for <dtls-iot@ietfa.amsl.com>; Fri, 21 Aug 2015 06:33:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.311
X-Spam-Level:
X-Spam-Status: No, score=-4.311 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zsZcdNnXaSyK for <dtls-iot@ietfa.amsl.com>; Fri, 21 Aug 2015 06:33:38 -0700 (PDT)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 969341A901F for <dtls-iot@ietf.org>; Fri, 21 Aug 2015 06:33:38 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id 6DB92BF53; Fri, 21 Aug 2015 14:33:37 +0100 (IST)
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Yzd0qXC6tg3a; Fri, 21 Aug 2015 14:33:37 +0100 (IST)
Received: from [134.226.36.180] (stephen-think.dsg.cs.tcd.ie [134.226.36.180]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 441B6BF51; Fri, 21 Aug 2015 14:33:37 +0100 (IST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1440164017; bh=PtLKPVpLpxgj35d/cdLwfwbE4DuyiG1Wlv3Tb9f0KDA=; h=Date:From:To:Subject:References:In-Reply-To:From; b=Nk8FKUh7ji/5yX4Qf+MdQIbcMWH5FqjIDYHXvTl08jeQzNOXdE4Zt778Majm1WF5n Ag9fYfLn9+pY6ZZqZWSYERwHqMfP2eQbW6UDDNm6l7ZGaXbJbEoSBeDT/So7F8i/6F OcOqWm6m5Ic+iQGzX4TkMRLGmp1M9rr/X6MzALe8=
Message-ID: <55D728AD.8050905@cs.tcd.ie>
Date: Fri, 21 Aug 2015 14:33:33 +0100
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.8.0
MIME-Version: 1.0
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "dtls-iot@ietf.org" <dtls-iot@ietf.org>
References: <55D22C29.3060006@gmx.net> <55D2338F.5050306@cs.tcd.ie>
In-Reply-To: <55D2338F.5050306@cs.tcd.ie>
OpenPGP: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="pFsQlDaSNOaf08mQdPKrk9hVA5Scroao0"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dtls-iot/B9N_N8nEGxzPuRgMMrvCTBlvWX4>
Subject: Re: [Dtls-iot] Version -14 Submitted
X-BeenThere: dtls-iot@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DTLS for IoT discussion list <dtls-iot.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dtls-iot/>
List-Post: <mailto:dtls-iot@ietf.org>
List-Help: <mailto:dtls-iot-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 21 Aug 2015 13:33:40 -0000

Hiya,

On 17/08/15 20:18, Stephen Farrell wrote:
> 
> Hiya,
> 
> I plan to check over the diff and assuming all's well (which I
> do assume) start IETF LC unless the DICE chairs tell me to hold
> off for some reason.

Checking done, a few nits below but I've asked for IETF last call.
Please fix these before IESG evaluation (I don't mind if you do
'em now or later on).

Cheers,
S.


- 4.1.1.2 s/Figure 4 and Figure 4/Figure 4 and Figure 5/ I guess

- 6.1 s/has to be know./has to be known./

- 6.1 maybe some quotes would help here, i.e.

OLD: We call the above-listed information device credentials
NEW: We call the above-listed information "device credentials,"

- 6.1 s/are often called 'root of trust'/are often called a
       'root of trust'/

- 6.1 s/these initial device credential/these initial device
        credentials/

- 6.1 nicely says "it MUST be ensured that a different key pair"
I think that'd be better if you said "different secret key
materials" as then that'd also cover the pre-shared key case.
(I don't think there are cases where we want to recommend
the same secrets be on many devices and those be used with
TLS.)

- 6.2 s/shorted authentication tag/shorter authentication tag/

- 14: one of the changes doesn't read correctly, I think you're
saying the right thing but the surrounding text results in
oddness, maybe

OLD:

   Since many IoT devices do not have access to an
   accurate clock, it is RECOMMENDED to place a sequence of random bytes
   in the two components of the 'Random' structure when creating a
   ClientHello or ServerHello message and not to assume a structure when
   receiving these payloads.

NEW:

   However this structure is being deprecated for privacy reasons so
   it is RECOMMENDED to place a sequence of random bytes
   in the two components of the 'Random' structure when creating a
   ClientHello or ServerHello message and not to assume a structure when
   receiving these payloads.

But I'm not sure if my NEW suggestion there is quite right either.

- ID nits whines [1] about a few things, please check those out.

[1]
https://www.ietf.org/tools/idnits?url=https://www.ietf.org/archive/id/draft-ietf-dice-profile-14.txt


> 
> Thanks for the good discussion.
> 
> Cheers,
> S.
> 
> On 17/08/15 19:47, Hannes Tschofenig wrote:
>> Hi all,
>>
>> I had a chat with Stephen today and we went through all the issues as
>> recorded in the issue tracker.
>>
>> Stephen had a few remarks but was in general happy with the feedback
>> from DICE and CFRG.
>>
>> As a result, I have published version -14 with the proposed text (as
>> recorded in each individual issue at the WG tracker).
>>
>> I closed the issues in the tracker but you can still see them here:
>> http://trac.tools.ietf.org/wg/dice/trac/report/6
>>
>> Please have a look at the updated document. As you can see, there are
>> various changes in the document:
>> http://tools.ietf.org/rfcdiff?url2=draft-ietf-dice-profile-14.txt
>>
>> Ciao
>> Hannes
>>
>>
>>
>> _______________________________________________
>> dtls-iot mailing list
>> dtls-iot@ietf.org
>> https://www.ietf.org/mailman/listinfo/dtls-iot
>>
> 
> 
> 
> _______________________________________________
> dtls-iot mailing list
> dtls-iot@ietf.org
> https://www.ietf.org/mailman/listinfo/dtls-iot
>