Re: [Lake] Roman Danyliw's No Objection on charter-ietf-lake-01-00: (with COMMENT)

Göran Selander <goran.selander@ericsson.com> Thu, 27 April 2023 07:06 UTC

Return-Path: <goran.selander@ericsson.com>
X-Original-To: lake@ietfa.amsl.com
Delivered-To: lake@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F0721C151B17; Thu, 27 Apr 2023 00:06:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9J5DvR1snfIm; Thu, 27 Apr 2023 00:06:11 -0700 (PDT)
Received: from EUR04-VI1-obe.outbound.protection.outlook.com (mail-vi1eur04on0630.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0e::630]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8D1D3C151B16; Thu, 27 Apr 2023 00:06:10 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=MY2K1CBZe0CRv/ThvE92wYlqQfke111PL7HqBQSIrMhAH7VJ1Zs0Zj8Yk03XiudjSZRbOlfhiqSntVB6M0Z2nIckIkbFyXJTyGB/J/tdcWbSatvimj4oa8eXkalncypKaH2sDp59K4iybUOUcBBqNOS61b7dOE0pHjeFwQo3mDXUX25+TpjNtD3LqkiKKENjCCfWY6hETO8XqbdPjUlCHwxzLSO7ZjecKUu8fvGECt+hGnYyX7mbXSmDP7Qhj4xetdmv7+Nf//rEVElldq+Hhw5oay4aIBgwC9lv/MWYg5SYqMUuihFmShioIWdipviwSJ9iWipm4nhPKseLJEvpQQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=P/Idx7EryCmvptfYWjlzgZlwxSQisUjH+2EiazILc8A=; b=fvUBOyaOQmQW8SGa/AQ8wh8wtbo9MFzRudU8y0SAtBRKhOs5RQCaNtx9Fi+vm1/VUu1TTlOyyXK5Feuyo9M2Ef1117zIwaxnPbzm3Nr2Tt+kp2jstPEsfmtj94VFIWzEKzxb/B7OLm/IrBOnpsDNrgqJn4NPRi00GTUCV054qSP2PrUY9e89y0andO1my0C9IQG+6mLIEV9eRBYtxa3uPFaEgPS1xHDO49typ6YBJ4F1PpDHHh13bI3AAJmQSHuiG3gN5GcV3/RDIbLCSBdYleuzMR0dPAT0mOreXV2YAbBChxT/z7oE1ROT98cdpqx5Hd1uK6uvKfa2nrpBkFcGvg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=P/Idx7EryCmvptfYWjlzgZlwxSQisUjH+2EiazILc8A=; b=Ata9n7WJprJCRLOkFepFrKJS3tfKk8z1yovur6MdEu+CC0LmVcdjosQqTNA5NpHmjlEC+x89D5x2UDAHZYdgGAlHQzdzLhmOsmvLQBKBzSKQW7O1Ytha45aLqESWAhfeckRh2kuzt9pfIqyjsrMBbdt+pFtRVEN/FHUIihPuUT8=
Received: from PAXPR07MB8844.eurprd07.prod.outlook.com (2603:10a6:102:24a::19) by DB9PR07MB7163.eurprd07.prod.outlook.com (2603:10a6:10:213::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6340.22; Thu, 27 Apr 2023 07:06:04 +0000
Received: from PAXPR07MB8844.eurprd07.prod.outlook.com ([fe80::8988:c72f:b40c:734b]) by PAXPR07MB8844.eurprd07.prod.outlook.com ([fe80::8988:c72f:b40c:734b%3]) with mapi id 15.20.6340.022; Thu, 27 Apr 2023 07:06:04 +0000
From: Göran Selander <goran.selander@ericsson.com>
To: Roman Danyliw <rdd@cert.org>, The IESG <iesg@ietf.org>
CC: "lake-chairs@ietf.org" <lake-chairs@ietf.org>, "lake@ietf.org" <lake@ietf.org>
Thread-Topic: [Lake] Roman Danyliw's No Objection on charter-ietf-lake-01-00: (with COMMENT)
Thread-Index: AQHZeHuBCQHHw2EV4USyBAEQuILHM68+riJn
Date: Thu, 27 Apr 2023 07:06:04 +0000
Message-ID: <PAXPR07MB8844A40BD9AF3353C17C2420F46A9@PAXPR07MB8844.eurprd07.prod.outlook.com>
References: <168253996640.29658.1187050581538295847@ietfa.amsl.com>
In-Reply-To: <168253996640.29658.1187050581538295847@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PAXPR07MB8844:EE_|DB9PR07MB7163:EE_
x-ms-office365-filtering-correlation-id: 16823b02-8edf-421f-34da-08db46edddd6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: LpCOjCIiNuiKnJSyQBjxqHgnBO1CBgPsCO3HT8MKwHIjS3qVRVLunZlrnf1eqAjPwhEby082GzHTJ23V848b+67fgZHcOt08923OeWhd/Crs4Q8gqvKUtqgIm9Nd6leqOKamdd3941utwjL8AoSS+V+Ri/WfQLHIIlaucqGcyWg+NdeOyPg+wG5q2VVQis8nAX9sTd0arvuNiy26gSsPyF8hS2lCDdQeiUHkr0hKrqlF2y3lXTTu5hXkvKDGBX7wjY2wGmuvk3f6vLPVVGSfCRSmOU8h2+P33La0TTwXZ1Qj7Vnyr+ZvhX+KNvYuOPOkCDrkifGyQhxjoVAoaqsY6pjKkBM+/rgGoyhARVI+/ZXQYaYw22dJkUjp/6ziZ3CD4Y/HYZ9gD2W+gJjxBmgfH4JD50TJTAXzkQwbhiKhcG2VhOPkK3F3IOBG2W8oYI/89iPQlGenoGj+O/nnhXsh7RO2pNOGjBo17K1+oE2LLumoSNk/XNexi/af2F+kIaErUphX4raugDFaookeMtV9CykoJBDSfs2Eem1uULaMfiKhMjpKDi6P2vU20Xq6pwMw/fwcCyrh1+wA2kHBmcUvZ7SUQuCIrGhD75s7sZ7QNco=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PAXPR07MB8844.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(396003)(136003)(376002)(346002)(39860400002)(366004)(451199021)(86362001)(38070700005)(33656002)(166002)(2906002)(55016003)(71200400001)(53546011)(7696005)(186003)(9686003)(26005)(966005)(6506007)(66556008)(66476007)(66446008)(4326008)(66946007)(110136005)(91956017)(76116006)(478600001)(64756008)(316002)(82960400001)(5660300002)(122000001)(38100700002)(41300700001)(8676002)(54906003)(52536014)(8936002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 7va1EfcxZPIc5UKyEpSKeJprCmU9wq2bwtV1StPQpari0HBzm2KUIolJOIaT9dC5G/WgOE9+kAdwSREWleM75fxGKRoylvUFmuyBIHxBn8afSXiEO/4uxZ1wWakq15LS+Ukur1EzDAx9mI1OLY+54Hmof7uxsZzDenxOZF7l37alLkyyZzTPKDQ/bHsDeK4pNRgmCqbk/Kte5kmo9IWo6J4WJut8uc9AifYRYyXdfEBLEgnOnDSCYdvoDETeK3n32U/0tCpjww+05TjUdL+QlS2b06geSzZJaTHJDs3mwGa6Q6lsOhPJFVain1HvYizjYZ8xPqSj6RBPW6cmpBrgLTS250w4Syh1i/r49HlOTnGXRGaiXMxCFMETxY66SjIT55w+NQRbfgDk9/yAOn7UDw1xnmw6mv98+2n88yNjDQaOa/wfzBC+XmR34BAly/LFuWQLOQ3whlutPLGuqXYl9zZ/dIuhcVBjW+mZduCk1by4/EQvIL28bho43MHn0wdnY5QXNoXe3zhmHvor2cfpUCA1DjfmmakQ6ITzlS4Q4H6e8PZgk2gWpjUbznPfPd8BFWL9QONlhl7LVjg+yPXb9TPX88uaNE+z1U6A7VR3q8uCsVshMlTbcrIC5AuPmgYbKGw19SkA58idrHsiEpF0qAV1y0ufPPrJbOZVENuUkelpFGVZl5I57mdlT49kJT8mNVzK9dwkTXAIiODgsah3BkYOp0RTXvc/fdVkJWS52NM9Q6T7Z0FRzZ/p+PADqIdqRl+LimwTEsFJEWn7JXALxbiUSu7QsScw3XEPqslEFsGItmKZ9mYjac5S0LlPk4Dx9jGao8qWFIZD0RrJsbN6Sndssx0j4+SJwX5hxrdMInkNSBWrtLIvDutwsXkzKtDkSzWi6UjotkVPzsaNR+vNj7QEx8ochIpffE7iq5FR9TQ8cmaJ88NgmVoLEvUb6r8JV+tpv7zt6ahE7mTQufynBM8+zVGvN2E6cfyuapECF1vRA0vziq/F8taN4ofWvX4l+BMPNmyJ+/TBL47cupwuVRKEmU4xTeRUEMwr+lIFzoNXtJtkGUyXKl/59NxBn0Ro6wy9czD+DtB+13eMrhwRmBplIxPNzuV1Hj1JwKru0xj1KJW991wxnsqr6y8Tx9/K6AKJx6f0wMZy7wFBrjGChJSoY9RD4XVqpqmTCgJWKHHYFkNYPeEy7X2eusaH3b1Gf573pBkbgyULC5Rl02kCECWnrEcwyx31fMFk7Duy6UPwLXxaI5umG7FrVBn0dUGvDfjp9pFq/6lW6+9arz7naTF3dEd8rrOSq8yzqUv9RQFs4Iii6h7PYWNJNYdfmlkdFvB7FZ/VQPbTv3kOv/hFO1csmZv/2ihNrLCHwKkbM0prHQtiwFDWEjxaTk6qrCpssLfvzLtrgVJuHcpfLu+Z275szwJ+4ZT+i39vWsknv75VpGeGjI165/w2uyPOYV3HCAnA294OjiXKEh2L3v7zs2VgyBybmgtBi+khc80gu1hNA9KIAQMx0Z5Z91ET6YcvyTYIQV5/T6cGJSMsCSQAIC3sSahX2oPqtbp4jSh6f7+aR4gh40Dev6fwuCdbL4xSpEO+4Cahqobl42SnccBNgwtpPTYU3Viyo/HBV7vEIZg=
Content-Type: multipart/alternative; boundary="_000_PAXPR07MB8844A40BD9AF3353C17C2420F46A9PAXPR07MB8844eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAXPR07MB8844.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 16823b02-8edf-421f-34da-08db46edddd6
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Apr 2023 07:06:04.5624 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: w9B8kstEuKZkN7ZWv8xzg6vesB3ZLjBpcKNIjSO3r9ztKTFvEuUPD9FsZWj8/AvhZ1vXuJccf+6NvD2TZAfNcLoGGAP5VWFdyLFRqVNXK4Q=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR07MB7163
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/SqaQlF3kigOE_Pr7XW_2S-6HL4o>
Subject: Re: [Lake] Roman Danyliw's No Objection on charter-ietf-lake-01-00: (with COMMENT)
X-BeenThere: lake@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lake>, <mailto:lake-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake/>
List-Post: <mailto:lake@ietf.org>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lake>, <mailto:lake-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Apr 2023 07:06:15 -0000

Hi Roman,

From: Lake <lake-bounces@ietf.org> on behalf of Roman Danyliw via Datatracker <noreply@ietf.org>
Date: Wednesday, 26 April 2023 at 22:13
To: The IESG <iesg@ietf.org>
Cc: lake-chairs@ietf.org <lake-chairs@ietf.org>, lake@ietf.org <lake@ietf.org>
Subject: [Lake] Roman Danyliw's No Objection on charter-ietf-lake-01-00: (with COMMENT)
Roman Danyliw has entered the following ballot position for
charter-ietf-lake-01-00: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)



The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/charter-ietf-lake/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

> Remote attestation of EDHOC peers, for instance using the available work from
the RATS work group

Unbounded, this could be a large body of work.  Can the WG commit now to reuse
the RATS work? or at least commit to adopting someone else's attestation
framework.  It would be helpful to constrain this work in some way.


Remote attestation integrated in the handshake has been discussed in LAKE for years but only ended up being mentioned since edhoc-14 waiting the protocol to complete. The discussion I’m aware of was based on the reuse of existing IETF work specifically EAT/RATS, so that has always been the mindset. There is now work based on TLS which has progressed more rapidly that acknowledges other formats for encoding evidence besides EAT [1] and which extends the current RATS architecture [2]. The work in LAKE should reuse as much as possible existing work from RATS and TLS but with an additional eye on making the solution very lightweight. There should not be room for defining a new attestation framework, but I think similar extensions as mentioned above should be in scope, if necessary.

Is this better:

OLD
Remote attestation of EDHOC peers, for instance using the available work from the RATS working group.
NEW

Remote attestation of EDHOC peers, reusing as much as possible available work from the RATS and TLS working groups.

?

Göran


[1] draft-fossati-tls-attestation
[2] draft-bft-rats-kat