[Iot-directorate] Re: draft-ietf-suit-update-management-12 telechat Iotdir review

Brendan Moran <brendan.moran.ietf@gmail.com> Fri, 03 July 2026 11:01 UTC

Return-Path: <brendan.moran.ietf@gmail.com>
X-Original-To: iot-directorate@mail2.ietf.org
Delivered-To: iot-directorate@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E1CFD10D8C1BB for <iot-directorate@mail2.ietf.org>; Fri, 3 Jul 2026 04:01:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1783076473; bh=tMO+Yr2EobOvcEyJrNzs5e873FBvpFXICDwfZzUUbD8=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=VTiSq/RGjXMC7bnbU98dpyLc3FhPY0PzlWjgrgeO0FJ4bxlxcyEJ79vm+zQ7VLygE Dcap3fL8fnBJXSxkNihn0wsE5lygz9444EEaBKW2KcX1xYamyBNmJiO2+dLXwz1ecS 4Dr0WsOwE7d2ekywdpL56FgbDEubSjPRsDpSBDV8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kZVLS1GDTcyc for <iot-directorate@mail2.ietf.org>; Fri, 3 Jul 2026 04:01:12 -0700 (PDT)
Received: from mail-pg1-x52f.google.com (mail-pg1-x52f.google.com [IPv6:2607:f8b0:4864:20::52f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BD67210D8BF3A for <iot-directorate@ietf.org>; Fri, 3 Jul 2026 04:00:33 -0700 (PDT)
Received: by mail-pg1-x52f.google.com with SMTP id 41be03b00d2f7-c969ad04c1dso245957a12.0 for <iot-directorate@ietf.org>; Fri, 03 Jul 2026 04:00:33 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1783076433; cv=none; d=google.com; s=arc-20260327; b=am7U05UNL8JLvL/1+vdPFnGqwnNnmLw1SIX3+3JAF2QtyHgnMtIbNNyjhXH1PoN1VC Rds9ljyWz+9ezZ5zUYhxdbmwjQOn+SYy8LYwiJNyId2qIGvVLd5mAvyD8FJh4oM7t+5Q rdDY8HLBUUE+uVw7Eg4grW2ANUB1cpvFBkG2zS8UIhF57IMbW/Y1c79yB8W+Mm9gu/Ap ndNbEohFH7hLEm90oRFpfTVS2kl0ocT2OIcq9C6/EnxmXy1yfKq90f2mmvDZsO7z5JXt NOM3RgvGLP7iVU8vdvMjPaVLSGsW+JX6JQL3J0bGh9FTic32sVE/p+xeYFNEAzlXMYLj z41Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=tMO+Yr2EobOvcEyJrNzs5e873FBvpFXICDwfZzUUbD8=; fh=l46CDzKTU21HWzn8+oCY49r+IEmQIYe7m4zA5cUUSls=; b=G0de4rB7hLRmWrOYlB78k2YOTyvQAMarvtEs8Cfr2Tr5EUrSdyf12HJm44oGQTA/bL i2Mrxa/nssRW8PxoRLRsY5Wxo3ZsgmPZHkFS5yJ/h37Q3UhG+qAEATuCoZvtK0b3Z4GX 1CknWXX0t8CYhEx2O3cwmQ7F5HcqxTbTmNzXXBcuO/Ooi9J7NfUnpbNwKIV1sfYxibRZ adCyUN4gzO4ODBFRvzoPSZYvKTd0l1bZGiPqlrggXia7awCFhNXH6CHuX1z6bLbGhq63 FjU37CNjsGEIEUYNwpLBb759IICwLWHQ44Eh8AzTEaWsTr5y5pknohxDmmmmGGdEKrNr H3Aw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783076433; x=1783681233; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=tMO+Yr2EobOvcEyJrNzs5e873FBvpFXICDwfZzUUbD8=; b=oyrIgYnScFeDE2tOm5GqhAzf12A7/KIuUim+eHyBnG85iOjSqNsv38KbdnFuQmgJXl V3pbgoCNMD/WmTjRX8GGIbMz8eVroLmUpd7RVh98ufic8zmt2h76R1JWijV5ZjUVYv3D LJ/X6jV5g/OK97covH+kteg/IWGtHydn2l4/SS6Lw236A7LWIoF0ZNNrPe2Ea5wd54ll RetRAyScpKK9w1a/NE6PlDoODXYTuODytt1ddWoZSYx+aFcEWIU6awhGKGxCxKDe8WT/ b50T5YIILeZOacddbp7lWv/vWbIWCeK4wgKQnkfbzfysZtspmCrDpB1ym6AJh4AQN0qF dn6A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783076433; x=1783681233; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=tMO+Yr2EobOvcEyJrNzs5e873FBvpFXICDwfZzUUbD8=; b=nZp1LW+YgzEZRaZQszA7rJNM+PYxbjc6d8H8cXVNl7Fn4BNlKFg2UgK0sjlvT0FD0L cMsJotrSxJbA/wAIt1EIXF5maBMIkn768pTzCz4aZgmrS/9Ag0bbZUzbPOqSxpvHpygq TFk2pXufavoAuXu99R1uwWHysr6kkD3n5Qk4xtFG9G7m0MploI9hjrxLireHu3uXJkhI CT8fXA6rSrU8H+y58/Rd0I0/5URb34JMq02M8B3q602vbIEWWOkQtUwZTvig8QN/r5wq GT/ItqWR6AAHHoaS8OQS59AzPgVQ9BqMsDW+IZwmVlJ49IqVEqHkARUTfvultX/Xoaq0 MpqA==
X-Gm-Message-State: AOJu0YzBQZCcNckjXPpRstf6jVF8bvt3HC1VEjrTBKlvtJHA/6YfM9Jo OTPEX++D2JS4BsvMEfLPl+tQxradeeKnXkboqf9yGOX8cdVUxzVtXWxK9Jxeg61lgQs9kArP5WV 2ESADlp6K0R6e+qo0nwCDti4KwzFvr/s=
X-Gm-Gg: AfdE7cn4pKNSU+m00B9CI5Bf8ekAgKmYkb7x7Dy0194seZcZBeasAAKhlnWuEDarV6F BplNaZlsVVV7gM0VKmPeYKk/6FPWtigAI2YAr5HCmRUTcBHRdSBls7d3RdMdeZhlHUlytQTSLBT EQSEB1zkU4d0Ok1IJ4g9L7Pn1au5NnQSUT1MKsEcdVvJt+ZYOY/GHKOIatsPCCUWoBtyhAY7+Vn 9dRpzabSAG/sk77m4NLC7AhIzuMIU+v31OSVQd8c9Usx/S5y14Wdq7Y+0CJXzJnomEBtDQ=
X-Received: by 2002:a05:6a21:6088:b0:3b8:58c:97b8 with SMTP id adf61e73a8af0-3bfed21410amr11375389637.22.1783076432609; Fri, 03 Jul 2026 04:00:32 -0700 (PDT)
MIME-Version: 1.0
References: <178229383919.1520243.6304873578277219142@dt-datatracker-f9b87776f-8pmmg>
In-Reply-To: <178229383919.1520243.6304873578277219142@dt-datatracker-f9b87776f-8pmmg>
From: Brendan Moran <brendan.moran.ietf@gmail.com>
Date: Fri, 03 Jul 2026 12:00:21 +0100
X-Gm-Features: AVVi8Ce30VUEk8utt05NRmoZ_pHk6cWjfBvwjcKqZUfGPrwVWMozCjJfANlzI14
Message-ID: <CAPmVn1OjihjqHY=GZcdtMfuDvZxMFp59Tj=zuiZ5Li-NaJM3=g@mail.gmail.com>
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Content-Type: multipart/alternative; boundary="0000000000005f83da0655b2d582"
Message-ID-Hash: MWVBKTJQSX6PPHNTHEIOI2662BQKAH25
X-Message-ID-Hash: MWVBKTJQSX6PPHNTHEIOI2662BQKAH25
X-MailFrom: brendan.moran.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: iot-directorate@ietf.org, draft-ietf-suit-update-management.all@ietf.org, last-call@ietf.org, suit@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Iot-directorate] Re: draft-ietf-suit-update-management-12 telechat Iotdir review
List-Id: Mailing list for the IoT Directorate Members <iot-directorate.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/iot-directorate/zb3bLjK2KuVWw5ARNjODxLb_IxE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iot-directorate>
List-Help: <mailto:iot-directorate-request@ietf.org?subject=help>
List-Owner: <mailto:iot-directorate-owner@ietf.org>
List-Post: <mailto:iot-directorate@ietf.org>
List-Subscribe: <mailto:iot-directorate-join@ietf.org>
List-Unsubscribe: <mailto:iot-directorate-leave@ietf.org>

Hi Hannes,

Thank you for your review. I have taken all these comments into
consideration and published a new version which I hope will address all
your concerns.

https://datatracker.ietf.org/doc/draft-ietf-suit-update-management/


Best Regards,
Brendan

On Wed, 24 Jun 2026 at 10:37, Hannes Tschofenig via Datatracker <
noreply@ietf.org> wrote:

> Document: draft-ietf-suit-update-management
> Title: Update Management Extensions for Software Updates for Internet of
> Things
> (SUIT) Manifests Reviewer: Hannes Tschofenig Review result: Ready with
> Issues
>
> Thanks to the authors for their work on the document.
>
> I have reviewed the draft and here are a few comments.
>
> The definition of "primary cell" in the terminology section is not
> necessary
> since the term is only used once throughout the document. I would just
> explain
> it in the section where it is used.
>
> I would make [semver] an informative reference and move the text describing
> semantic versioning from page 9 to an earlier part, for example to the
> terminology section. This is particularly relevant since you are not using
> the
> referenced write-up in its entirety.
>
> Semantic versioning, as described in semver.org, allows additional labels
> for
> pre-release and build metadata to be used as extensions to the
> MAJOR.MINOR.PATCH format. Section 3.1, however, says "build numbers MUST
> NOT be
> included". I suggest to clarify this difference to the referenced semantic
> versioning. In Section 4.4.1 you define numerical values (-3, -2 and -1)
> for
> alpha/beta/rc pre-releases. Semantic versioning, however, allows arbitrary
> pre-release identifiers and it might be worth pointing this difference out.
>
> If a suit-parameter-update-priority does not define whether a larger value
> implies a higher priority then it will be difficult to guarantee
> interoperability. I would define an ordering without leaving it to
> applications.
>
> References: I-D.ietf-suit-information-model became RFC 9124.
>
> The heading of Section 3.4 says "text-current-version" but it should say
> "suit-text-current-version" instead.
>
> In Section 4.6.3 you list permissions and one of them is creatdir_append. I
> think this is a typo. Should it be createdir_append?
>
> The suit-wait-event-other-device-version, which defines a wait operation
> for
> other device to match version, is defined in a way that interoperability
> will
> be very difficult to accomplished.
>
> The use of suit-coswid in a manifest will raise the concern that anyone
> with
> access to such a manifest will be able to quickly make assessments about
> the
> security of the device. This is desirable in the hands of the right person
> but
> not necessarily suitable for everyone. This might be something to bring up
> in
> the security consideration section.
>
> The specification states that time-of-day and day-of-week are interpreted
> as
> "Local Time". It may be useful to clarify whether this refers to the
> device-configured local timezone, how daylight-saving time transitions are
> handled, and what behavior is expected when timezone information changes
> during
> device operation.
>
> Unrelated to the review of this draft but important for the publication of
> the
> SUIT manifest, which is a normative dependency: I do not understand why the
> manifest specification has a normative dependency on this document. This
> document defines optional extensions.
>
>
>
>