[Lake] Re: WG Last Call: draft-ietf-lake-edhoc-impl-cons-06 (Ends 2026-05-18)

Elsa Lopez Perez <elsa.lopez-perez@inria.fr> Tue, 12 May 2026 11:32 UTC

Return-Path: <elsa.lopez-perez@inria.fr>
X-Original-To: lake@mail2.ietf.org
Delivered-To: lake@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C4628ED0C153; Tue, 12 May 2026 04:32:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778585544; bh=I8D0TuMkFaNfT+IPqztLZDpqkyDMhpFeUlfbznLbSGc=; h=Date:Subject:To:References:From:In-Reply-To; b=nC5Plhb2rwmSzxE65JyyADhQpIAoJ0pqGkCjbRvwtr4X04yF5Kj7aT8FoVeSjGjiw igvXtdyJ4Smt+ywslqO3N0l134uL2Inhi+2dhMjKnp8TitsMc/IwbWoTv+EAn+J6pc Er2zafsfkaOOKcgXb5CanM1eKTMchTBQGC7P29To=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.395
X-Spam-Level:
X-Spam-Status: No, score=-4.395 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=inria.fr
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aiMX2z4mrygv; Tue, 12 May 2026 04:32:21 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 780C5ED0C05C; Tue, 12 May 2026 04:31:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=inria.fr; s=dc; h=message-id:date:mime-version:subject:to:references:from: in-reply-to; bh=3r5o9KG8zxpDFkLXJYuYAOAbP6gwehQNl0j0q91B9PM=; b=bulhg11ypw5KFhomPXNE1ZAh5lDWv6826ULLgLaY/1gakXH4BQsvtccg mJruRCrcacddJPniTlu99ujZn4ku3ubJk2ig4wLpwyoU7M2PcfIJtoF9N T4oZoH0+BPbvjhq1pLccKuLxupQGbUrphQEMHBne8niKOHgueoFPF+Lba o=;
X-CSE-ConnectionGUID: NMqGq+RgQ16+OfkEVuv4Sw==
X-CSE-MsgGUID: RoZ++OOuSTC+dqJ8HTNrmg==
Authentication-Results: mail3-relais-sop.national.inria.fr; dkim=none (message not signed) header.i=none; spf=SoftFail smtp.mailfrom=elsa.lopez-perez@inria.fr; dmarc=fail (p=none dis=none) d=inria.fr
X-IronPort-AV: E=Sophos;i="6.23,230,1770591600"; d="scan'208,217";a="146342141"
Received: from unknown (HELO [10.1.22.0]) ([217.110.184.17]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 12 May 2026 13:31:35 +0200
Content-Type: multipart/alternative; boundary="------------0pqg5FzOktudZqxZF7GW2NnN"
Message-ID: <8cc96834-c1f8-460f-b8a6-6bbd4bf1c046@inria.fr>
Date: Tue, 12 May 2026 13:31:29 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Mališa Vučinić <malisa.vucinic@inria.fr>, draft-ietf-lake-edhoc-impl-cons@ietf.org, lake-chairs@ietf.org, lake@ietf.org
References: <177788532081.417983.10205368038562516448@dt-datatracker-787b78d5f6-p2rl2>
Content-Language: en-US
From: Elsa Lopez Perez <elsa.lopez-perez@inria.fr>
In-Reply-To: <177788532081.417983.10205368038562516448@dt-datatracker-787b78d5f6-p2rl2>
Message-ID-Hash: JTZCB43VF42QSRICTGRLCWDJWXHTC4BE
X-Message-ID-Hash: JTZCB43VF42QSRICTGRLCWDJWXHTC4BE
X-MailFrom: elsa.lopez-perez@inria.fr
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Lake] Re: WG Last Call: draft-ietf-lake-edhoc-impl-cons-06 (Ends 2026-05-18)
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/WH2nSYEb_Mi4nPg98xrgwaM--Jk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Owner: <mailto:lake-owner@ietf.org>
List-Post: <mailto:lake@ietf.org>
List-Subscribe: <mailto:lake-join@ietf.org>
List-Unsubscribe: <mailto:lake-leave@ietf.org>

Hi all,

I have reviewed draft-ietf-lake-edhoc-impl-cons and I support proceeding 
with the publication of this document.

However, I would like to raise a minor point.

The document (particularly on trust policies (Section 3) and credential 
retrieval/validation in the side-processing framework (Section 4))  is 
directed towards the public-key authentication methods defined in RFC 
9528. Since the Working Group is working on standardizing EDHOC-PSK 
(draft-ietf-lake-edhoc-psk), I think it would be useful to add a brief 
scoping statement in the Introduction clarifying this.

EDHOC-PSK introduces additional implementation considerations, such as 
indistinguishable error handling of message_3 to preserve identity 
protection and resumption PSK lifecycle management. These could be 
addressed in a future revision of the document.

Best regards,

Elsa Lopez Perez

On 5/4/26 11:02, Mališa Vučinić via Datatracker wrote:
> As discussed during the IETF 125 meeting in Shenzhen, this message starts a WG Last Call for:
> draft-ietf-lake-edhoc-impl-cons-06
>
> This Working Group Last Call ends on 2026-05-18
>
> Abstract:
>     This document provides considerations for guiding the implementation
>     of the authenticated key exchange protocol Ephemeral Diffie-Hellman
>     Over COSE (EDHOC).
>
> File can be retrieved from:
>
> Please review and indicate your support or objection to proceed with the
> publication of this document by replying to this email keepinglake@ietf.org
> in copy. Objections should be explained and suggestions to resolve them are
> highly appreciated.
>
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [1].
> Appropriate IPR disclosures required for full conformance with the provisions
> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
>
> Thank you.
>
> [1]https://datatracker.ietf.org/doc/bcp78/
> [2]https://datatracker.ietf.org/doc/bcp79/
> [3]https://datatracker.ietf.org/doc/rfc6701/
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-lake-edhoc-impl-cons/
>
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-lake-edhoc-impl-cons-06.html
>
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-lake-edhoc-impl-cons-06
>