Re: [Lake] FW: New Version Notification for draft-ietf-lake-traces-06.txt

John Mattsson <john.mattsson@ericsson.com> Thu, 31 August 2023 05:52 UTC

Return-Path: <john.mattsson@ericsson.com>
X-Original-To: lake@ietfa.amsl.com
Delivered-To: lake@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 482D8C151532 for <lake@ietfa.amsl.com>; Wed, 30 Aug 2023 22:52:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fDbZgwSbpv4n for <lake@ietfa.amsl.com>; Wed, 30 Aug 2023 22:52:11 -0700 (PDT)
Received: from EUR03-DBA-obe.outbound.protection.outlook.com (mail-dbaeur03on2042.outbound.protection.outlook.com [40.107.104.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 33B68C14CE44 for <lake@ietf.org>; Wed, 30 Aug 2023 22:52:10 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=jnFL5Qev1d92cjtXyBMuKpbpDSiZ4tiJAxqAynxjMMOLMdVJD+FEDuVuTVTHa0Qw3ht9e0oEIFDt7C6ksqQv8hVeWVP6G+ySTF1agrUi2Fm2RNNrCsmCudNh3PwvKWy3sbKjcVCU9DZ5nQ85jXVJt0aS2/vvMVXXBMezlzvGQn3TiIt4akLVQr/e2bOXsBnFidzKqNohqtKlpVVAfLMQ/JY2GgcX2WSf/0HzTKUTFHdphOZM1/1uX8b5qxf3LNAKPs/TL9Nu64ZiAOdISylD3yKQreOKe5vGUKRXvPnWJc290FF167UB5dgeqWP89TzlwW4hAxzOObIq4p6OysWKUg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=QjsrUMVK+qP/Ba5Cm6QfBFCcx/ThlX3OyKhxiNVyR/k=; b=cHkA9YB1RYm06OKuyCqFtLORCPN/Gw0uWTiWY8f8vna4O979bBeXiTENS3Nt4XnY6jEkU2p69QUvkO8DDnDG2etnDQY6Ty6T6GEk9SG86drYeO4lSAKSZX/uAYHxwhARwB0g1rl50D9Hw4Mnmmseak3fyfQDRpXUM6y8TVwx3cMAv2jOvgfL7YFUxG1qMCJdRIudP6sd41hm56eSl2jqptzGV0Mgg+ove5SA1wfu+usoTzyztUZNpIWnVhUfhUw4G2qDxhfBlyUZWea6Jxpmm97RNykqwTxG/gU/N9Ti4r1i6IGmYU382yF0PCOAGDa8ASHemcLPoueO5Lz8HBV9rQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QjsrUMVK+qP/Ba5Cm6QfBFCcx/ThlX3OyKhxiNVyR/k=; b=BUK1a88JD55J4a3qKhc1X9RO1DhjRpkv+CBIW40WTbp4+L/7qCcw4ou9rKFmTmLGSZygkWgal6oMOw2o14+Opmo4WgZB9Q5EDMm70JzOUlET64M0Mkwi/ZN1wwTSNRJAEfaS35U11CVKgc5UmRhmUEgQdSv2ljGbJuDw/42MpCs=
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com (2603:10a6:150:114::10) by AS8PR07MB7687.eurprd07.prod.outlook.com (2603:10a6:20b:25d::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6745.20; Thu, 31 Aug 2023 05:52:08 +0000
Received: from GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::cf5e:848b:9613:bfd]) by GVXPR07MB9678.eurprd07.prod.outlook.com ([fe80::cf5e:848b:9613:bfd%7]) with mapi id 15.20.6745.020; Thu, 31 Aug 2023 05:52:08 +0000
From: John Mattsson <john.mattsson@ericsson.com>
To: Paul Wouters <paul.wouters=40aiven.io@dmarc.ietf.org>, "lake@ietf.org" <lake@ietf.org>
Thread-Topic: [Lake] FW: New Version Notification for draft-ietf-lake-traces-06.txt
Thread-Index: AQHZ2Ad7ETbkcovYC0W9BPRou48YfrABeeIIgABDj4CAAi6SiQ==
Date: Thu, 31 Aug 2023 05:52:08 +0000
Message-ID: <GVXPR07MB9678882949D45D61408CBBD189E5A@GVXPR07MB9678.eurprd07.prod.outlook.com>
References: <169304545597.51436.1963389582687768125@ietfa.amsl.com> <GVXPR07MB96785B4596D953EEB357824C89E7A@GVXPR07MB9678.eurprd07.prod.outlook.com> <CAGL5yWZ_7Y7WEg5qsQ3vc6Nk6W9Br2OYNkzwmXO5o4iiqD03vA@mail.gmail.com>
In-Reply-To: <CAGL5yWZ_7Y7WEg5qsQ3vc6Nk6W9Br2OYNkzwmXO5o4iiqD03vA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GVXPR07MB9678:EE_|AS8PR07MB7687:EE_
x-ms-office365-filtering-correlation-id: 46cccd50-c2bf-496b-2c91-08dba9e669a2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: EQ5iH0olalB4Z/hRWbcZvawOlDI6K0m4YHHxsjiMbq4QQmLovvHplOhTcOi8Y3Op5cTWnX33UzsWQPiXBSH5xQ/rDKxFLKx0/tNMQtVIG7z/69GNOdBxAiQ+xgf56H5ZWp4oUjDKVQ5UiQFfLwBp9xCidinHwE6FnLcL3POZaABxM2DBEcwl9p+RTJU+7D2QVCVkzNvEZJhqtHOBEsTetwiKkP2yB53vjFHxKR2oGWvC+N2nyd1d6pNcbg2Q2oqIvjL7KSeP7+SymfCqlRXAVPHbf4wufTMnq/nY6Uvb3PYGZBy8jdxcgBrr5/elnsSGRbPtrVf7Kzp8fuz2HVZhTrlnUyk4q8Yt7FIwVAlozCZR/3Idb+9oY2Z2zIksguvmJ1zhvfeS4auJCGEiUlOvA5hpMBnVTjKlzGsS529D72IPdYyt05PlNm/mo2LDRqGmJqdTYQR/HKw+Y42OyonKlCdsJavC96EInnK0SkFt/LWUj/uqPqiqsjXDdNY35O1sjZ07Baf470M0Cad/4aO3ZJvLrSopeEF5fjHqBeVekLDybeJkvuLQAuO3btVEe5UkC7RH6DKYaUcrlo83cn2vXgjyN/HrU3Vk/kqAzMrvKBenLpeDBJ7uxn+YPgkppzx+IPT4IoyYSa2wwqzaANGfhg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVXPR07MB9678.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(396003)(376002)(39860400002)(366004)(136003)(346002)(451199024)(1800799009)(186009)(5660300002)(52536014)(64756008)(66946007)(316002)(110136005)(66446008)(44832011)(66556008)(76116006)(2906002)(66476007)(8676002)(8936002)(41300700001)(7696005)(6506007)(9686003)(26005)(53546011)(55016003)(15650500001)(38070700005)(122000001)(166002)(71200400001)(478600001)(966005)(83380400001)(86362001)(38100700002)(82960400001)(33656002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: VmFwt/gh55yuIQnr76fxlboKlf68VYhtuVIa3XNYKtDyjyqALWi/wOR8DXxzrd2HKMef61uNfbZKjP/8NCfODudevDlFMl7Wj+Qr4aQs46vvLZkOronRw77tmOPViPJIVIRasjYBlx3CEitQ5AKUku3SWWYVqZOd/WPk3/xNUfGHB/HhkDnKhCdcmFPiuwFmJBv0z074BHHk0/Ubd98rHwMYBf3TPmcSbZaT+1r9L7un3Tr+y6cLhpZotQ+xAPlQDjL7EtKXsTl3ZhDSFRwNiSdT/B4jGsmaHTQ/gcv6gq0+lDMaHomJ/+zHuM1FDHgr9XESVz3Y5TGkLOt1nZ61EnayUPwRxvG8Db/c7nAJ6j1m8eScwrTE9gUTvsnkl+sBOttz/qGpijWrsLx9W4vbLv0gCL54YGV/TlcoAmWe/lmrWuwbFb5IbCF4jOK7T7v44OsLZhIdVdCupC42Tiz2MFzKsm6T23mrjDIEpkzDte4tD3XtK+maplWh7txyDC6oBxjsbH+oaZIIJlAC+u/WlLxwQw80S7/nObl9XivrhqS3ZtIbVrbfFlVwPyGKxQS9eCn1Y0Rkp2IVYmC9hN0nmoKTsXkwArgTrt4KnryPw70Ba0pMG02HQHv//3YprdadSCgWn0GIcEkgpNa77q25Xyrnd36T/3a+Idqfi1vQtTuDFjExY1AephCtPHbMdkbFEQwYxwTw/LTVLB7COVuz1cjRk2Inhr+i7vx2QKIx6zOrQsPjMvyaLNtx7TBUVZ3tjU1ciWrV0g7Uj2B58SOJWOffNb0f7knvfzAkzLO1CxO9i9K4/CUYT8ta8x1IRGMphxxECYccKY03yZ9/xItgWYPK7Oszgi2U1zuDq2FCuUDaSgB47Q3OF5HbDqGGmmC7O/hPzFjqhK4vn3F0VYnREaLy2r9S/1qqMCN63Wd9x7P7eZXCg/SZPYuPNBxcnUgc9DdGRbUUZ1CDB1fOFPth/ZVp4J9plT1u5GJil2M2lJY76ixk3bXPw3NnJY/EPWYApqn7vmsSoqVZxKQmPQWUo4FiR8IxvJrSfeQpZBwgaVP8N+46SHbSRn7maze6RR99NSzkdRQ2qHdOejoMwsCpT5SWKiv9dZ3/Q17UDUZX2JjOu8LZZcLWjZdXKyiSYq/ssOnXoYHsiPwDavXsiMfVtQaklzCFegEHWragIKrjE9Bkt5cf+3UNYxPJ6IGQLnV1TbwbD+R5nQLGDNHd8pop95tB7JVkFXCNRqb0yhOcy3AeUPDxLhyZLANNMVJlPja09IUY/aOgVULI74tZzepCEXtxhib7NBAJrjguzOicjm2eSN8wiA8GBQQbMaPxLyka9J4+YFsvozT6q/ERP5wmRRlfcmC2G5E8mQ38iQv6VPGog1fiWTxKHIUwdzuxfKtXHOYDgYYBdiyVway1E04A5PzISPmG5lg/1lv6dVaqM+4jTceTu1yVzHirrPUestJLKxI118Oq3krWmPtJeJukVxDrb21RsiusP1cRVJ5UYf1qK9EsbetHHpjlUA7Op4Ml+8EytSqb4q2RWLBFX+bZltL9b141TpnmTESztsdHLbxhyIecB7vChsN2ksiPXP7uQMR4c+yRJYlDeDR0nk0SnkKUiSHK7apZiPal31FIDok=
Content-Type: multipart/alternative; boundary="_000_GVXPR07MB9678882949D45D61408CBBD189E5AGVXPR07MB9678eurp_"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GVXPR07MB9678.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 46cccd50-c2bf-496b-2c91-08dba9e669a2
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Aug 2023 05:52:08.2473 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: uBaQE1FsvDGE2P09ayNaq9ZIDA7Um9a2vsCb5f3IFD1vE1XjONW02pD6e0MyIaKnxpaTIGpcaW/4keMyOWL4raLRltO66O/PO1ZyT/awnMo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR07MB7687
Archived-At: <https://mailarchive.ietf.org/arch/msg/lake/sLhE1x4v0o4nA7AKAZpRztqJ7to>
Subject: Re: [Lake] FW: New Version Notification for draft-ietf-lake-traces-06.txt
X-BeenThere: lake@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Lightweight Authenticated Key Exchange <lake.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lake>, <mailto:lake-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lake/>
List-Post: <mailto:lake@ietf.org>
List-Help: <mailto:lake-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lake>, <mailto:lake-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Aug 2023 05:52:15 -0000

Hi,

I made a PR
https://github.com/lake-wg/edhoc/pull/442/files

While writing the PR I realized that there are two more types of invalid ephemeral public keys. There are also several other types of invalid encodings that implementations should catch.

The PR has been checked by several implementors and we have already gotten strong proof that this is an important thing to have:
“these are very useful and I already caught several bugs in my implementation that need to be fixed”

Cheers,
John

From: Lake <lake-bounces@ietf.org> on behalf of Paul Wouters <paul.wouters=40aiven.io@dmarc.ietf.org>
Date: Tuesday, 29 August 2023 at 22:24
To: John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org>
Cc: lake@ietf.org <lake@ietf.org>
Subject: Re: [Lake] FW: New Version Notification for draft-ietf-lake-traces-06.txt

On Tue, Aug 29, 2023 at 12:23 PM John Mattsson <john.mattsson=40ericsson.com@dmarc.ietf.org<mailto:40ericsson.com@dmarc.ietf.org>> wrote:
Hi,

Implementations not following requirements is unfortunatly more common than they should be [1]. To minimize the risk for non-compliant EDHOC implementations, should we add an invalid test vector with an invalid G_X? NIST (and EDHOC) mandates point validation. Around half of the G_X values are invalid so it is easy to find one.

I have no objection to this, but please do it sooner rather than later. Eg before the end of the IETF LC.

Paul