[Dtls-iot] DTLS/TLS IoT Profile Draft Status

Hannes Tschofenig <hannes.tschofenig@gmx.net> Fri, 31 July 2015 21:15 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: dtls-iot@ietfa.amsl.com
Delivered-To: dtls-iot@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C63D81A0095 for <dtls-iot@ietfa.amsl.com>; Fri, 31 Jul 2015 14:15:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.91
X-Spam-Level:
X-Spam-Status: No, score=-1.91 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M_CtpYhZkNC4 for <dtls-iot@ietfa.amsl.com>; Fri, 31 Jul 2015 14:15:32 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D44851A0041 for <dtls-iot@ietf.org>; Fri, 31 Jul 2015 14:15:31 -0700 (PDT)
Received: from [192.168.131.133] ([80.92.122.31]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0LZiLk-1Yc1Gg0aTM-00lXRs; Fri, 31 Jul 2015 23:15:30 +0200
Message-ID: <55BBE557.3090206@gmx.net>
Date: Fri, 31 Jul 2015 23:15:03 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.8.0
MIME-Version: 1.0
To: "dtls-iot@ietf.org" <dtls-iot@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="CsKBxrsBFKNsQROJL7JmSDCTe4sFohP97"
X-Provags-ID: V03:K0:e7i9DvAaWZ3IQAXmxm7dLQogpAfVEFBm+ly26CLza6Ar7vg+aRt 9TvwBmdMLh0aoDmTBh0yjwDRb+OwnZZVxgsi70+cdHkLtfhQ18HIIffiH8GTEMsj1xIblZ6 Sa142eEgvojR5NiRyMH8jU0E22rdP7ZMx7gUZcBT21p0+K6PSAnt9hVIDXHBDQ2W41ply6C jQYdg1l6nv+Q29dNqzxhw==
X-UI-Out-Filterresults: notjunk:1;V01:K0:WbSeEnhSmrA=:+K1HNZ6bnP87/KkRjOaUsn wprx+pLzJn0N4usm5xUAVldPgJ1ZJaF3p+XbmTM2P8+AfoW+8rHZZ5SOvpCxqI78lyYshup3V mItpkzXsexbaOnoyqhCp2sjomGD6QlYwTEIBu41eMTRH/8WDeKWQrUYxH1HbArgP8MYjr5Wxw CYjXstTNq+eG354fnTdco3Hzy7KhXHJrSve5hvBVBWZ5r+QnwliAsHOLCAF44VrCt22AhvbZI Ayk9n0k+XBGDyy02GlQ1QUtpdR60H6KkPoMqRHGQ68sPeb97sWcjWaIdNQPlvLsfuMNf6BlJ+ Y3G2i6CQHcjIKf0NoNEEtTvnUpo9CgEUhbSTVGvxjC6x1Tx69MxdGgr+EGC8g4MN2kFz0+WSb GuDEPrf3v8/2ibPpAOxkg7vgdcKomKYlEk9BbI9YX1omz8fv2E4viE5p4jfSk1TwXqaS745r8 4VZ1BDOTFxQxzUHbLLXNlLhPZOYbhbHaAdz+Eq8iwxtKf5ZFo9IfNlsBYAzxhzDWPEl8CCFOF gZ8bjHsYTeShWfqtvjBrQf8g84LNZU8ED3eCNkB8hatrTI2D2P4LHSRMDIULjg6fVzBF1C3Kq fgUIjbgFQswDV7IphbwPQ7Wdx5k2Ybr7sDXFMF6bYsFTh/G2NPmLxZVvwhkSFP74Jjs1T08Mt Hf8fImUvg8s8lqnvPswB5vYCPTsJgA1jfC7CEBQ3GEPOFGA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/dtls-iot/CYUuoFtnyvSlvbVCx96lQkfB51o>
Subject: [Dtls-iot] DTLS/TLS IoT Profile Draft Status
X-BeenThere: dtls-iot@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DTLS for IoT discussion list <dtls-iot.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dtls-iot/>
List-Post: <mailto:dtls-iot@ietf.org>
List-Help: <mailto:dtls-iot-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 Jul 2015 21:15:35 -0000

Hi Stephen,

based on your review we have created a number of tickets in the DICE WG
issue tracker, as you can see here:
http://trac.tools.ietf.org/wg/dice/trac/report/1

Over the last few weeks we have been trying to resolve these issues and
here is the current status.

The updated draft can be found at:
https://github.com/hannestschofenig/tschofenig-ids/blob/master/dice-profile/draft-ietf-dice-profile-14.txt

* Replacing TLS_PSK_WITH_AES_128_CCM_8 with TLS_PSK_WITH_AES_128_CCM
http://trac.tools.ietf.org/wg/dice/trac/ticket/24

Recommended Action: Close ticket based on CFRG discussion:
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00643.html

* Unique Key Pair per Device
http://trac.tools.ietf.org/wg/dice/trac/ticket/25

Recommended Action: Close ticket based on your response:
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00623.html

* Interoperable Software Update Mechanism
http://trac.tools.ietf.org/wg/dice/trac/ticket/26

Recommended Action: Close ticket based on our changes.

* Ed25519
http://trac.tools.ietf.org/wg/dice/trac/ticket/27

Recommended Action: Close ticket based on our changes.

* IP Addresses in Certificates
http://trac.tools.ietf.org/wg/dice/trac/ticket/28
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00625.html

### Still open ###

* Timer Setting
http://trac.tools.ietf.org/wg/dice/trac/ticket/29

Recommended Action: Close ticket based on your response
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00642.html

* Reference to Heninger Paper
http://trac.tools.ietf.org/wg/dice/trac/ticket/30

Recommended Action: Close ticket based on our changes.

* Reference to mathewson-no-gmtunixtime
http://trac.tools.ietf.org/wg/dice/trac/ticket/31
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00628.html

### Still open ###

* Secure Time
http://trac.tools.ietf.org/wg/dice/trac/ticket/32
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00629.html

### Still open ###

* Hardware-based Random Number Generator
http://trac.tools.ietf.org/wg/dice/trac/ticket/33

Recommended Action: Close ticket based on our changes.

* RFC 7539 (ChaCha20 and Poly1305) a SHOULD/MUST implement?
http://trac.tools.ietf.org/wg/dice/trac/ticket/34
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00632.html
http://www.ietf.org/mail-archive/web/cfrg/current/msg07082.html

### Still open ###

* Privacy Considerations
http://trac.tools.ietf.org/wg/dice/trac/ticket/35

### Still open ###

* Appendix C. DTLS Fragmentation -- Not complete?
http://trac.tools.ietf.org/wg/dice/trac/ticket/36
http://www.ietf.org/mail-archive/web/dtls-iot/current/msg00640.html

Recommended Action: Close ticket based on our changes.

* DTLS Server-Initiated Session Resumption
http://trac.tools.ietf.org/wg/dice/trac/ticket/37

Recommended Action: Close ticket based on redrawn figure in Section 4.1.1.2.

* Certificate Chain in DTLS/TLS
http://trac.tools.ietf.org/wg/dice/trac/ticket/38

Recommended Action: Close ticket based on our changes.

To summarize: I believe issues #24-#27, #29, #30, #33 #36, #37, and #38
can be closed.
Please confirm whether you are indeed happy with the suggested changes.

The following issues are still open: #28, #31, #32, #34, #35

Ciao
Hannes