Re: [Lake] [EXT] Re: EDHOC negotiation and errors

"Sipos, Brian J." <Brian.Sipos@jhuapl.edu> Fri, 24 February 2023 20:22 UTC

Return-Path: <Brian.Sipos@jhuapl.edu>
X-Original-To: lake@ietfa.amsl.com
Delivered-To: lake@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1D8BC14CE53 for <lake@ietfa.amsl.com>; Fri, 24 Feb 2023 12:22:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.397
X-Spam-Level:
X-Spam-Status: No, score=-4.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=jhuapl.edu
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g_TPq8us2yyy for <lake@ietfa.amsl.com>; Fri, 24 Feb 2023 12:21:59 -0800 (PST)
Received: from aplegw01.jhuapl.edu (aplegw01.jhuapl.edu [128.244.251.168]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D4754C151530 for <lake@ietf.org>; Fri, 24 Feb 2023 12:21:58 -0800 (PST)
Received: from pps.filterd (aplegw01.jhuapl.edu [127.0.0.1]) by aplegw01.jhuapl.edu (8.17.1.19/8.17.1.19) with ESMTP id 31OKJxgo016611; Fri, 24 Feb 2023 15:21:55 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jhuapl.edu; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=JHUAPLDec2018; bh=Z3aVMHtq4XpWF+dIOXhFQ6vwDy+ZFJ3iukbSYSZ5X40=; b=nAdoTa5dWNAs1Wvh9KMRqTyHNpfx9ReNc3T7IvbnrP5JHhwBfqQ72djJMaRLMCGl7zoH Xmj0qArgQfp6jalIOXamQVrpT4XYBV+Gfzgmcmcdl+qyueYi7UyrunVGypjqBO7gG/Xb 0uif3w0h2TeqWtz0TpKmaOa7E1zJKnAavSamdtZ1mImtJZYb2PpZkUIxBXXiy0FouYBA gfMZHC2clLdH5oIhKFuVh9aFRhd48WiHA+KQaJdLoHBHSL7Nlpk4qErBnk5Thy0iZVKo C/vw88q39M59bE50ELW6+b1WBkmKVx3r1cx3PiYlHB25wPYxyEUxYR5Kf1CtOGKNuU+n Ow==
Received: from aplex22.dom1.jhuapl.edu (aplex22.dom1.jhuapl.edu [10.114.162.7]) by aplegw01.jhuapl.edu (PPS) with ESMTPS id 3nwxr2hvcp-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 24 Feb 2023 15:21:55 -0500
Received: from APLEX21.dom1.jhuapl.edu (10.114.162.6) by APLEX22.dom1.jhuapl.edu (10.114.162.7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.21; Fri, 24 Feb 2023 15:21:54 -0500
Received: from APLEX21.dom1.jhuapl.edu ([fe80::20d7:9545:f01e:9b2]) by APLEX21.dom1.jhuapl.edu ([fe80::20d7:9545:f01e:9b2%5]) with mapi id 15.02.1118.021; Fri, 24 Feb 2023 15:21:54 -0500
From: "Sipos, Brian J." <Brian.Sipos@jhuapl.edu>
To: Michael Richardson <mcr+ietf@sandelman.ca>
CC: Göran Selander <goran.selander@ericsson.com>, "lake@ietf.org" <lake@ietf.org>
Thread-Topic: [EXT] Re: [Lake] EDHOC negotiation and errors
Thread-Index: AdlFcyNJVXSaBcDcS92pLvKgOKYffwATtiSHABaebwAAEdfNgAAceSTg
Date: Fri, 24 Feb 2023 20:21:54 +0000
Message-ID: <63885c9bfe864621829800e0cfe43832@jhuapl.edu>
References: <4d31baf067a94571956ef46efe025805@jhuapl.edu> <PAXPR07MB8844F5F2D059ED1E11EEB6ACF4A59@PAXPR07MB8844.eurprd07.prod.outlook.com> <eaf9618523934b219e890f597ccf6297@jhuapl.edu> <12828.1677014257@localhost>
In-Reply-To: <12828.1677014257@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [10.114.162.26]
Content-Type: multipart/signed; micalg="SHA1"; protocol="application/x-pkcs7-signature"; boundary="----=_NextPart_000_002F_01D94863.B97E61D0"
MIME-Version: 1.0
X-CrossPremisesHeadersFilteredBySendConnector: APLEX22.dom1.jhuapl.edu
X-OrganizationHeadersPreserved: APLEX22.dom1.jhuapl.edu
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.930,Hydra:6.0.562,FMLib:17.11.170.22 definitions=2023-02-24_14,2023-02-24_01,2023-02-09_01
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/XZQSLvXytyKPH9t0im2y2bUoyvo>
Subject: Re: [Lake] [EXT] Re: EDHOC negotiation and errors
X-BeenThere: lake@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lake>, <mailto:lake-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake/>
List-Post: <mailto:lake@ietf.org>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lake>, <mailto:lake-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Feb 2023 20:22:03 -0000

Michael,
I did have a chance to read through that document and in my case it's a MANET-like collection of autonomous nodes, where having a certificate with an appropriate EKU purpose under a trusted CA is sufficient to join a network. I see the value in having a separate online authority that is described in the -lake-authz document but it requires a more consistently connected network interior.

> -----Original Message-----
> From: Michael Richardson <mcr+ietf@sandelman.ca>
> Sent: Tuesday, February 21, 2023 4:18 PM
> To: Sipos, Brian J. <Brian.Sipos@jhuapl.edu>
> Cc: =?utf-8?B?R8O2cmFuIFNlbGFuZGVy?= <goran.selander@ericsson.com>;
> lake@ietf.org
> Subject: [EXT] Re: [Lake] EDHOC negotiation and errors
> 
> 
> Sipos, Brian J. <Brian.Sipos@jhuapl.edu> wrote:
>     > To Michael’s point about using x5u as an alternative, in my case this
>     > is for negotiating participation on a network so there is unfortunately
>     > no wider network available prior to EDHOC succeeding.
> 
> Then, you really need to read draft-selander-lake-authz, and join us perhaps,
> because we deal with that problem already.
> 
> --
> Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
>            Sandelman Software Works Inc, Ottawa and Worldwide
> 
> 
>