Re: [Iotops] OPC UA FLC and TLS
Christer Holmberg <christer.holmberg@ericsson.com> Tue, 03 August 2021 20:02 UTC
Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: iotops@ietfa.amsl.com
Delivered-To: iotops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 411803A30EF
for <iotops@ietfa.amsl.com>; Tue, 3 Aug 2021 13:02:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.553
X-Spam-Level:
X-Spam-Status: No, score=-2.553 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1,
DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001,
URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id lPSWiLfztHMO for <iotops@ietfa.amsl.com>;
Tue, 3 Aug 2021 13:02:03 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com
(mail-db8eur05on2040.outbound.protection.outlook.com [40.107.20.40])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id B59F03A30F0
for <iotops@ietf.org>; Tue, 3 Aug 2021 13:02:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Jk9FLP2VOFzU3myPRU4H4bNEMDxRBlQWHzIFxJQxHI1dYhwoZ9a7gRDQYBa8hfFjsosvGbOdUE50nfmjPMPMhmBK3xUyIcAyuV8a1jirbNLLgkyjk8YoMxj0aioO5yCA0Rs29rl892zuK6xgiGl7GnT91lpcH+cQC0kwotdjS8Y86H2sO1LpdMHY+XfaCPi6nNzAze+yrnxLn1Ppb+vtUMoi5GVf7RfvGHGKmEyOrpU6sX5apO7X7Qh1o62N8DjjsticeZsSA+wHTfWE9UWi78dRnUALaxjlnQMspqlo5czxoNpmAGEjjzOQWbaZpX00kf7rfAvswXgjsOlJ5Sc06w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=SzrZ3J5BENHu/L4EkE3WQYjvvAjHqXxR1bZ+AJnz7C0=;
b=U7kUEc2u5xphpKmjI00+D1GrLFj+ukPqfR+ZfNk/26XYd8Knwx+Ytgp7kDSRWu4P+T9ZBDY7zhju+GrsHZd1wO3ozAqF+KqziUY5D0YKxH3JIbyjL3lgV45X1p+WVpCCgy2/D5NcHA76wRSUW4skchur/I6R+4f9QOcvk7SC2RY8eY1j7wXp6SyvEUj0Oxs3pwaCvdW/PFnYTmiXICswl4ytYOoSpx2rHCZXRJXRXp5sBrTER9d+Sk+0G9vfwwx1scTpuMTHdG1Cnl8awYZSFJoriX914zIjfTGnF+q7rYMlW8YhqtBU+GaNH2KJCKO0utU7iNZH/kX23VOH86WmlQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com;
dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com;
s=selector1;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=SzrZ3J5BENHu/L4EkE3WQYjvvAjHqXxR1bZ+AJnz7C0=;
b=dvNYlTW0gJndXiwLaudqum+kLmP61HRwM6jHP/EUB4YEZD7d7adx5BPQQST+WLxsRgDpZ5aPo4vR/vHTMmBTBe/oQI297/QnoRIqrfnjF3+F5hZqNJNyAsPD0/QJThEJJYfYAnD5ntwips/Qrdm0JFzRfUe0Q7fv/8+GKtsxtyc=
Received: from HE1PR07MB4441.eurprd07.prod.outlook.com (2603:10a6:7:9f::27) by
HE1PR0702MB3771.eurprd07.prod.outlook.com (2603:10a6:7:88::31) with
Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.4394.10; Tue, 3 Aug 2021 20:02:01 +0000
Received: from HE1PR07MB4441.eurprd07.prod.outlook.com
([fe80::e8b0:f0a5:f77f:5802]) by HE1PR07MB4441.eurprd07.prod.outlook.com
([fe80::e8b0:f0a5:f77f:5802%6]) with mapi id 15.20.4394.015; Tue, 3 Aug 2021
20:02:01 +0000
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, Eliot Lear <lear@lear.ch>,
"iotops@ietf.org" <iotops@ietf.org>
Thread-Topic: [Iotops] OPC UA FLC and TLS
Thread-Index: AdeEa2bLnohQow63Tf29sTDrh4zlBAABzJEAAA2Y6gAA/kkAQA==
Date: Tue, 3 Aug 2021 20:02:00 +0000
Message-ID: <HE1PR07MB4441B83EC401C00F6B75490A93F09@HE1PR07MB4441.eurprd07.prod.outlook.com>
References: <HE1PR07MB4441973D24954117AFB6804693EB9@HE1PR07MB4441.eurprd07.prod.outlook.com>
<1dd35348-c00c-ba43-1876-dced553218a4@lear.ch> <14062.1627583936@localhost>
In-Reply-To: <14062.1627583936@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: sandelman.ca; dkim=none (message not signed)
header.d=none;sandelman.ca; dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: ca0f50d7-7226-4657-cf1d-08d956b98e9d
x-ms-traffictypediagnostic: HE1PR0702MB3771:
x-microsoft-antispam-prvs: <HE1PR0702MB3771F9DA9B22894DC2BB1D2493F09@HE1PR0702MB3771.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: oQoqeQ50e2zOlNbAsQK4DJW9f/0v0Mj5IzD5unkopWAV5Wyf6q3Xh7o2OxqrTEYyDERvZKsKEY3AzOwPI/1WJMXBBli+FZUcDFypabdfYqG93apKkdNwZVfv/Teqjh6fPIH2vi76Mg8r+W4nkaoHBxI9jutqPduiWXuUeF8Z0hB0RYCaNNUxrIAb/VcQKbm8wxxVRrrpuHWTC7CSV70JWh8oyv9kjlhg4AU3SYorUWe1R5R0v4sx6EjZBCjRR8zcTjM6Ls1ymMLITDmRaCG0PJ5dSk4rNGktYl1SK6Zy3bdEFeIIow1S3c1d6s2uOJCbHMXJOEpxU8mz5lMbgmjN39JTJd14Lla+bXCi9iv8GU499e3np7ScUKTSTTKlkWFTst3AyE9AUUeZmFrYRwXHMZmN+/3W+K98HfVihvwuKaUtvG1E86+hT1zKp7R4zjMqbDxJ7+azQPT44+MrlO6PoVX2asc/o/e9zecuI30Rky9K6lGZm1RFif8WgRDMooAKbRLF59h+tWXW9iNhiJyApU7UQcaK8wjEVF/N9mJ6scnCNscHIm+S7L8GLVtE9jEP4S/+yp8NTw2t5rb6A9D54p7QreCQhJ7K7B7LKMIeZPpBmLVQB+JNkmm3qoSRQa7LfKx/cojV3YEP8TdIUNh9JCxZQ4dg3qvQi7r9+1oUi1BhoOZ/B1bS7dZnC2lskgJm4I25oTDirv6cl726lC5hHA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM;
H:HE1PR07MB4441.eurprd07.prod.outlook.com; PTR:; CAT:NONE;
SFS:(4636009)(39860400002)(366004)(136003)(396003)(346002)(376002)(2906002)(66476007)(8936002)(66446008)(66556008)(66946007)(64756008)(26005)(8676002)(71200400001)(33656002)(4744005)(316002)(110136005)(52536014)(83380400001)(5660300002)(186003)(44832011)(76116006)(478600001)(7696005)(38070700005)(9686003)(122000001)(38100700002)(86362001)(6506007)(55016002);
DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?utf-8?B?REZIVHA0MC9iaTdiNXRIZUxVQjdXTHhjNGFUQzd4c2NhT0QzMytnNm1FeUNM?=
=?utf-8?B?STNQUWZEekljOXpLT3RvMGkyTGVVWE9IeWFCNERyZjlZWmt5QjdaVXZIN3ND?=
=?utf-8?B?SUpWU09PcUtFK044Ym85NzZ6cElxbUxoN1ZENUNsd2JFREttcVRWblNqckRW?=
=?utf-8?B?MzdsSzZMWXBwOStFOGlBSmlWRXA3TTNsTDJqTkRXQXo1M1FxdDhYV2F5bU9l?=
=?utf-8?B?TUErTUZUV0ljd3ppWElHWS9OalBTam9uV2xEWHU5WTkxemgzV25VeG5sQUJ5?=
=?utf-8?B?WUN3MEwvS3FOeFlGTXJmWmYwS1FxbVNNOC82QUVnR0h2emEyZkN4amVJbVZt?=
=?utf-8?B?dWtQQ2Z1K2FWcFVNQnh6dlcwQllJWEhvQUhCdHJGclRFVVFhR3U4b282bUll?=
=?utf-8?B?Q0lVWGxuQU1nVDY0OWs2UnJESHh5SzBXNVFvM2hxV1A5ZVhJdjRBa3FzeXp1?=
=?utf-8?B?UENFY1ZVSXpWUTNRQkE5Snk0TkpUZExmU0ZtajM3TmxlZXlIeXBVY0VweXZO?=
=?utf-8?B?WklyNCtic1NrYU1jODhZVjAyZzlvK2JkUGNCN1Nac0NOQ2pid0F4aG9UZXhQ?=
=?utf-8?B?NWtQcVh5dlVhVGNhMjFwQWV4VUJPdjZzRjdZN1oyUWIrZ0UrTjVxaWhFNFls?=
=?utf-8?B?NnhFa0VudzE5ZzRkWkwwckZSbDd2Nyt1N1loa1dVVlNmbmRsSFcvZEVIOHdR?=
=?utf-8?B?UUdrWVFML2lSWmhpMCtQQzV5S1h6OUtra0VZdXYzbjgvc2NUb3RxZU5HejVK?=
=?utf-8?B?MlBqNGQwTE5uU3oyczdzbm5MVmJlNUZ0MVVVaHdQRDV4R0lOUSsyc3dvdWpF?=
=?utf-8?B?b3pFNnc1SjRtMGlwUjZReSsrZnZPUm8rQWkybk5JNE1wTnVXOEl1VXF1dUZG?=
=?utf-8?B?a0dUZ2tXK1JiWCtRM3FVbjh6U0JjbG5JVTUyaXRJbVViL0g4Nm03a0lqNENV?=
=?utf-8?B?bW8yYkI4UG41aXl5OFhidzBidFRvbFluVXNWcUVOSGlkNUorYWh0SHR5cEMv?=
=?utf-8?B?d3BYNzJSRTJOT2FjSWlQaHlJTGJBTlZyRTU4Nm14SlhNZ0UwclZnRmdqNllY?=
=?utf-8?B?Q2czM1FRU1BTT080eUlXdzM4TE8zK1RTaURnQnJYMG5JcFFYa2s0aHRKcVJw?=
=?utf-8?B?OWlOVnI2S1k3Tzd5QlBFUXYwbUVEekw0VnZrcVNFZ2d5b0VrTEJ6U2VTOGFY?=
=?utf-8?B?a21aSVlrTWRSSzdKVjhuNnFmWXpxN1FySFlnMkMwVnM0cDlHelRZSTFIa1Qv?=
=?utf-8?B?TXNlTmRDYzJ4dDB5dXdvS3dpQ2Z5ZlZpWGhPRGdPSlV6R0xZRExVcjJENFpu?=
=?utf-8?B?RExiQ3dGNFJJUDEwSXVES3Y0dGc0RmNaTmxubXVJaTBtaHVYNXpURHFCZTFR?=
=?utf-8?B?NXYzN3lhZkJrNGdOU1lmMWVHQ1VuOEFPT3E1KzVUYU1PZzBjQ0x0UXlUOWN0?=
=?utf-8?B?WllZbERwR2FFZ3ovY3NMdS9OdkRYUUJPSitGeWJ4WFR3RFBLVllUV2NYNktK?=
=?utf-8?B?SkV1bkxuaStDWUR0bldKc0pwd0NTZURQZ05DRnp3WVBvQ0t3aS9ZbmVjL2FG?=
=?utf-8?B?bWRsc0d1K3VKNWhGQ2psdGdRNkhUUjZKSnlBMXE4NmFYMDVyRGYvbEl5K21v?=
=?utf-8?B?d3AxV0o0YVdMblhVclozQ1BNY0FZaTVORmd1aks3NFI4U2tSaUFBRXMzaHhK?=
=?utf-8?B?K0dEcmVFM01FSlg3NnliR3FNVlRrLzlZS080aWp5OU1KZlpCNEd5cmFraVYv?=
=?utf-8?Q?YJe4vPxqstWRHwxCWgHL6juEaU0o75fJqa7faD7?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR07MB4441.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ca0f50d7-7226-4657-cf1d-08d956b98e9d
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Aug 2021 20:02:01.0141 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: iQddoEeaz68KLwHIAGM5KETjdoebm7Jp9N2PepgwDsXqFlK296vGpOhwik8UALx9qR4MkhYAfJmlSgwmqj3QCZKV+UX3BNPSIgSqNRWZuqY=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0702MB3771
Archived-At: <https://mailarchive.ietf.org/arch/msg/iotops/6izNOIyhW9-kyTF8VbcMO7mGx4M>
Subject: Re: [Iotops] OPC UA FLC and TLS
X-BeenThere: iotops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IOT Operations <iotops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/iotops>,
<mailto:iotops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iotops/>
List-Post: <mailto:iotops@ietf.org>
List-Help: <mailto:iotops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/iotops>,
<mailto:iotops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Aug 2021 20:02:09 -0000
Hi, >>> When I watched the YouTube video from them iotops session someone claimed >>> that OPC UA FLC “re-invented” TLS. What was meant by that? >>> >> That was my mistake. Other organizations (not OPC UA) have reinvented TLS, >> but OPC UA is just out of date, so far as I can tell.[1] > > My understanding is that OPC UA has a legacy DCOM based system that uses RSA signature for authentication, but is not related to TLS/SSL/etc. > But that they use TLS and DTLS (1.3 even) in the latest specifications. The original OPC protocol, referred to as "classic OPC", is based on DCOM. OPC UA is not bound to some specific OS/platform/technology, and you can use other algorithms than RSA. Regards, Christer
- [Iotops] OPC UA FLC and TLS Christer Holmberg
- Re: [Iotops] OPC UA FLC and TLS Eliot Lear
- Re: [Iotops] OPC UA FLC and TLS Michael Richardson
- Re: [Iotops] OPC UA FLC and TLS Christer Holmberg