Re: [Dtls-iot] Secure Time (again)

Hannes Tschofenig <hannes.tschofenig@gmx.net> Tue, 11 August 2015 14:40 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: dtls-iot@ietfa.amsl.com
Delivered-To: dtls-iot@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCFB61A8F46 for <dtls-iot@ietfa.amsl.com>; Tue, 11 Aug 2015 07:40:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.61
X-Spam-Level:
X-Spam-Status: No, score=-2.61 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i0kzOqe9aTKn for <dtls-iot@ietfa.amsl.com>; Tue, 11 Aug 2015 07:40:37 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 50CA71A8BBF for <dtls-iot@ietf.org>; Tue, 11 Aug 2015 07:40:37 -0700 (PDT)
Received: from [192.168.131.134] ([80.92.114.74]) by mail.gmx.com (mrgmx102) with ESMTPSA (Nemesis) id 0MPqtK-1ZT2cF2mYc-0051Ob; Tue, 11 Aug 2015 16:40:33 +0200
Message-ID: <55CA0950.9050305@gmx.net>
Date: Tue, 11 Aug 2015 16:40:16 +0200
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.8.0
MIME-Version: 1.0
To: Michael StJohns <msj@nthpermutation.com>, Eric Rescorla <ekr@rtfm.com>
References: <55C4D1CE.6010802@gmx.net> <55C79A90.5070900@nthpermutation.com> <55C9CFB4.5070702@gmx.net> <CABcZeBPfV9fmu_67sT0ewf+dRy5Ww4_nZUeQyhBQ9+RsHb_g2g@mail.gmail.com> <55CA0692.9000509@gmx.net> <55CA0837.5050008@nthpermutation.com>
In-Reply-To: <55CA0837.5050008@nthpermutation.com>
OpenPGP: id=4D776BC9
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="3j8cvJ60n0TEvpr0RvKWgp3Cv26MVGVfN"
X-Provags-ID: V03:K0:8kMpCDmWiB8SNwlZSlj1US8ASOttq/i/2W6ewZtnXIOSm//+Lni dlGLaS+7OByn7InZml6HpSz/xxRceU4Rs74JOQHfTtKtu7wEYyN/VKw7gm6XXzjTL8D+zSv Az6n0pZk6C2cGXY3buRfjnR7vFN0C4BHFN9ID/pm6E4/9P1+VnJqEOM58QFI9fn7e9i+8fp yvFA8YdysZ2Kio9BUMHtg==
X-UI-Out-Filterresults: notjunk:1;V01:K0:N/RFC17ydEw=:/dHsLBt4nCPixTWHEHi+ig Nx/o8hp+tqCJabuYQo91DnW6gwkfrDxCOnRNR0P+1WKO315puZlSgGSp++sjA8K3AaWkvBkBk 1kZerhxxNp7B7+xLzBv05e5CTaOUQjfqrF4IxJxXTBoF2k+T3nYmSUuaV3bi1wO1Pn/kxvR7/ DnGIfbIRlU0ULcas06oHlrniku9f63/Ge3oGLht2jGTD28Rd5xYH6JSXcXHC7vZUwfQ5kTxjv B+pMjiUENoyOhRY0juIgoL4lbScEig65aVfdJOjCKZ5/vjpC5PODENh1uVSIXnecOnVTzFdjT V5tU0p3DyEOZkggcHqRpPjGpN/5ed4jCPq5dBiCl62tw+sR54W1kzNJms9nm3a4Lpa+/C3wh8 /txzPOvhVVBRfEqrtpGJGC7+LIA0cOh9HvsMbC1PCiJ2Y283gzUjeVLLr11TQfxbI1B54l2DP mNhkAi5sM6lsPvzUiWZugZ7bK+7PZf+wZ6TMM3wRRK+Djj7+a3zi/Mte7bAJyJG7fuNBp8NOQ uPuQ+dnDmr8q2C7jM5AY7+WXwD1bKf5+zxz1E8fEDc/q9vFKWCGlYitHJbaoaECKpjH2vseZ5 L+qxZl+RibC/dZ3YSpaGEMRX3gI7+9i/4lvBqjZ+1kJ3XE4WDW7ax5JaGMeygeHg8jm5taQ9N TB3aCY/B9L0OY1v1peejktjGuOSSn1NX7U9epTHgRSoqMx8LRkU9VGAasEDSxCN7i1JF0LNyj VKET6BLV31edSV1m
Archived-At: <http://mailarchive.ietf.org/arch/msg/dtls-iot/_GAcGAz7-fnpEC4tiYmAa8vzVIo>
Cc: dtls-iot@ietf.org
Subject: Re: [Dtls-iot] Secure Time (again)
X-BeenThere: dtls-iot@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DTLS for IoT discussion list <dtls-iot.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dtls-iot/>
List-Post: <mailto:dtls-iot@ietf.org>
List-Help: <mailto:dtls-iot-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dtls-iot>, <mailto:dtls-iot-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Aug 2015 14:40:40 -0000

> Yup - but not all IOT devices will do DTLS or TLS.  And time in DTLS or
> TLS isn't "secure".
> 
> I think for this version, you should assume that DTLS and TLS will not
> be a source of time and write accordingly.

That's fair!