Re: [Last-Call] Last Call: <draft-ietf-rats-yang-tpm-charra-12.txt> (A YANG Data Model for Challenge-Response-based Remote Attestation Procedures using TPMs) to Proposed Standard

"Eric Voit (evoit)" <evoit@cisco.com> Fri, 28 January 2022 20:57 UTC

Return-Path: <evoit@cisco.com>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 139843A0900; Fri, 28 Jan 2022 12:57:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.597
X-Spam-Level:
X-Spam-Status: No, score=-9.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=OAOJ5L+t; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=Feahgmeh
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ig5r18i97S3o; Fri, 28 Jan 2022 12:57:07 -0800 (PST)
Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0DA0D3A128D; Fri, 28 Jan 2022 12:57:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=11427; q=dns/txt; s=iport; t=1643403427; x=1644613027; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=FUftgU8M0qjbgRVWU+O0JE1jKBrFINka+nfPAhlMDow=; b=OAOJ5L+taJVg08v15VLd9XTb9ojhAI+CWOkSxAh9TrybY4hdP6EmaMFf 0BKcmKfcf+FJfx0+pOpdvwKIVVDEgGPbYzyjw299K93K8ptqGPzqauSIZ lGAP3DyyzDy8OoxZV6T0RQ7OCaCpWa7n1QiHu0B5x1bseO6l0ARPr7D07 E=;
X-Files: smime.p7s : 3975
IronPort-PHdr: A9a23:1jxwAxE4VNHChHi4FKNOMZ1GfiYY04WdBeZdwpYkircbdKOl8tyiOUHE/vxigRfPWpmT8PNLjefa8sWCEWwN6JqMqjYOJZpLURJWhcAfhQd1BsmDBAXyJ+LraCpvGsNEWRdl8ni3PFITFtz5YgjZo2a56ngZHRCsXTc=
IronPort-Data: A9a23:M7XQUK8a91Xu/4jesI5JDrUDQ3+TJUtcMsCJ2f8bNWPdYAtShnVHkjtMCC3fZaGVIjmmON5rK9ThqxtC/NSA/mJROEEx9HRgCWoVsqIpbvzEdxypZXzPJJOdEktssMwSNITOIMxlFCCMr02hOOnv9SEnifjRSuqkBbLNMC0vFVA8EX4og01px7Zj0tRk3dWwa+/hVb0e9OWEaQD4swNJ3kIoB4Or9Es34ar44GpGtFJiPvwb4lbQy3BIUpwWfarsdiKiGNB9E7/hTY4v7l0WEkA1XvsV51jMfo/TKiXmeZaPe1je4pZqc/L62EIa/3ZiivpT2Mc0MC+7tR3Yx7id9/0V3XCAYV9B0pzkwIzxYTEBe81NFfUuFIv8HJSKmZf7I3sq3Jfb664G4EkeZeX08wvsaI1E3aRwxDslNnhviw8qqY9XRNWAhux7RCXqFJkUtnclxjbDALN/GdbIQr7B4plT2zJYasJmRKmFIZFGL2s0Kk2cPXWjOX9PYH46tOq2gXjjWzZZs1mS46Ew5gA/ySQhgea9YYGMJ4PiqcJ92xzwSnj912jjCx8Gcd2S1TTA6HuwnarelCX0HZ4KEfiz9vdwmlS7x2EPBlsRT1TTif+wjEWvHc1eLUMZ5gIhqKEz8AqgSdyVdwexvGWsvxMAVZxXCeJSwBuE1rGR6AaQB3IfZj9MdNJgs9U5LRQw2lOhlN7zGXpoqrL9YXKQ8LTSpzKoOigSKX0qfi4YCwUf6sTloIY9gwiJQtsLOKq8lcGwEjj0xxiLoTQwwbIJgqYj26y28U3DnimErITCSQgz6w7LGGmi62tEiCSND2CzwULQ4fAFJ4GDQxzY5D4PmtOV66YFCpTlqcBEe81VdJnB2hpPGGO0bYZTIqQc
IronPort-HdrOrdr: A9a23:efAv96DM3B5OExXlHegAsceALOsnbusQ8zAXPh9KKCC9I/b3qynxppsmPEfP+UkssHFJo6HmBEDyewKjyXcV2/heAV7GZmnbUQSTXfpfBOfZsljd8mjFh5JgPMRbAulD4b/LfCJHZK/BiWHSebtNsbr3kpxAx92uskuFJjsaDZ2Imj0JcjpzZXcGPTWua6BJcKa0145inX6NaH4XZsO0Cj0uRO7YveDGk5rgfFovGwMnwBPmt0Lp1JfKVzyjmjsOWTJGxrkvtULflRbi26mlu/anjjfBym7o6YhMkteJ8KoBOCXMsLlWFtzfsHftWG1TYczEgNnzmpDo1L8eqqiIn/7nBbUr15qeRBDsnfKn4XiQ7N9n0Q6T9bbfuwq5nSQ8LwhKVvaoQuliA0HkAgMbzaJB+bMO0GSDu5VNCxTc2Cz7+tjTThlv0lG5uHw4jIco/jFiuKYlGfRsRLYkjQlo+VY7bVXHwZFiFPMrANDX5f5Qf1/fZ3fFvnN3yNjpWngoBB+JTkULp8TQilFt7T9E5lpdwNZakmYL9Zo7RZUB7+PYMr5wnLULSsMNd6pyCOoIXMPyAG3QRhDHNn6UPD3cZe06EmOIr4Sy7KQ+5emsdpBNxJwumI7ZWFcdrmI2c1KGM7zH4HSKyGGFfIyQZ0WZ9ihu3ekOhlSnfsuYDcSqciFbr/ed
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BSAACBV/Rh/5JdJa1RCRwBAQEBAQEHAQESAQEEBAEBQIFGBwEBCwGBUS4oB3csLjcxiBADhFlghQ6DAgOQOYpqgS4UgREDVAQHAQEBCgMBASoLDAQBAYIQgnUCg2ACJTQJDgECBAEBARIBAQUBAQECAQYEgQkThWgNhkIBAQEBAgEBARAuAQEsCwEECwIBCBIDAyMLAiULFw4CBAENBQgGFIIEX4IOVwMNERABDqMuAYE6AoofeIEzE26CCAEBBgQEgUpBgwIYgjAHAwaBOgGBU4E6iyUXEByBSUSBFUOCZz6CYwEBA4EoAQgKAQkaFYM4gi6ROAk+LgYBYwQnKwEURyAKLxAhHwEKBBAJBooXiEiCbgGMBYwAkHSBbQqDRYE5hC2DGoIAlHkVg3KMGJd4HZYsIIxslCkcAQKEaQIEAgQFAg4BAQaBYTxpcHAVO4JpURkPjiAMFhWDOoUUhUp0OAIGCwEBAwmNTAEB
X-IronPort-AV: E=Sophos;i="5.88,324,1635206400"; d="p7s'?scan'208";a="896893157"
Received: from rcdn-core-10.cisco.com ([173.37.93.146]) by rcdn-iport-9.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 28 Jan 2022 20:57:05 +0000
Received: from mail.cisco.com (xbe-aln-001.cisco.com [173.36.7.16]) by rcdn-core-10.cisco.com (8.15.2/8.15.2) with ESMTPS id 20SKv37I018612 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Fri, 28 Jan 2022 20:57:05 GMT
Received: from xfe-rtp-004.cisco.com (64.101.210.234) by xbe-aln-001.cisco.com (173.36.7.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Fri, 28 Jan 2022 14:57:03 -0600
Received: from xfe-rtp-002.cisco.com (64.101.210.232) by xfe-rtp-004.cisco.com (64.101.210.234) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Fri, 28 Jan 2022 15:57:02 -0500
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (64.101.32.56) by xfe-rtp-002.cisco.com (64.101.210.232) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14 via Frontend Transport; Fri, 28 Jan 2022 15:57:02 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=g8L4wEeovHwCOVZwX40rUoCbz2S7g5hj/k+/ZPYY0VFn03flsofAj6LuqnkqD7TSEaNaRx/CpaqCrL8OAeSYl8eTDOGVUlv6zcc4S1MO2ZVyMF68ultDPgNINn1Evz+8iAiDE+DudE6UQ77wh58OfhfC7IrY8b8dbG1POKEipiWgoSYmj60o++gTXJEaygSldoODoNwWwRoNJhuRSN9tOrMRoS23khGadNKw9JiB4Oa7Q3ORppGmrAt29rk9Pd3flEVjQtQdat8EbV5nR7OxBudaP+9R6jYm3oJPxCDWLjs1if4vmUnzVaS1pk4Ug0ATJhrBYKI1rdy8tUn92ZGjZA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=7Fq35z8gDlPFlHrvbh7e3jUBZy6C5hZOw+nBkBkrlxE=; b=RZAKorH91qERMC8SMVKcJ3g3eVTSHMLEHE8KV6jy7AL+aroROAvvo58qq9T6iwkZeD1G/X2rMy65nkPmUGTv8TcAi8ZVd/ous5XbHVEExO3xLI4iy4GKEPDNbbdjY61A8zNWL2BqaVuhBUSvTrNlsRrFeC6JYJEYDam7mHEsCC2XZRVAaFurkY65S6pnYiIxEB9mmO8wgYobkZMCrGvaUNR8ZArUy0QUvbLQ5VlV/kaEsfoDmiXWJYcHJG5boAXCeacFqk0Yvpd0x/yDzbEA8t9iE+mXB54eh4+tzXS8a/4kdiaLVWi8GMb4oc7+P8I58ifIhMUT9xExsxj7UCzsVw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7Fq35z8gDlPFlHrvbh7e3jUBZy6C5hZOw+nBkBkrlxE=; b=FeahgmehG6QOUAQTizAR2cm0y2rzJD+MpWI6cWYKT4NSjH3RqZ+7oH7P9/UbKoRx9Q6mBmUWnofoAApfu1oyGkzNbEq+nT0aMRxND7bLvgM+xkhj6ivii4hUq4kvoVgzZgK3deWT+RlciqIpZmALlKP1JAVVERc1c6ao3W6OjFM=
Received: from BL0PR11MB3122.namprd11.prod.outlook.com (2603:10b6:208:75::32) by MWHPR1101MB2302.namprd11.prod.outlook.com (2603:10b6:301:5a::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4930.17; Fri, 28 Jan 2022 20:57:00 +0000
Received: from BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::39cb:878b:6c5f:b599]) by BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::39cb:878b:6c5f:b599%3]) with mapi id 15.20.4930.019; Fri, 28 Jan 2022 20:57:00 +0000
From: "Eric Voit (evoit)" <evoit@cisco.com>
To: tom petch <daedulus@btconnect.com>, "last-call@ietf.org" <last-call@ietf.org>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
CC: "rdd@cert.org" <rdd@cert.org>, "rats-chairs@ietf.org" <rats-chairs@ietf.org>, "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>, "rats@ietf.org" <rats@ietf.org>, "nancy.winget@gmail.com" <nancy.winget@gmail.com>, "draft-ietf-rats-yang-tpm-charra@ietf.org" <draft-ietf-rats-yang-tpm-charra@ietf.org>
Thread-Topic: Last Call: <draft-ietf-rats-yang-tpm-charra-12.txt> (A YANG Data Model for Challenge-Response-based Remote Attestation Procedures using TPMs) to Proposed Standard
Thread-Index: AQHYDSc5n2p6K/W6SEuTBb8BuMGR5qx45lBw
Date: Fri, 28 Jan 2022 20:56:59 +0000
Message-ID: <BL0PR11MB3122393BC167FDFA512EB43DA1229@BL0PR11MB3122.namprd11.prod.outlook.com>
References: <164217699418.11825.9399537345020124861@ietfa.amsl.com> <61E7F4E1.90002@btconnect.com>
In-Reply-To: <61E7F4E1.90002@btconnect.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1d2b886c-27f8-430b-ccbc-08d9e2a0ba7f
x-ms-traffictypediagnostic: MWHPR1101MB2302:EE_
x-microsoft-antispam-prvs: <MWHPR1101MB230272CEE442853DE301CE78A1229@MWHPR1101MB2302.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: HspqddsD/3jNbWhrcSghOvPKht9qdpNn+r9huTJMaPLrgoWFbrINckB3CkEdKWt+jRncoQ7TRHtlPEbrADmPsQcWQXm0Th5baoQRqsu9Ey5tVomeMGKi7AXEHLA/sSra+xmTCvxUqbx0J7rRMWQp77yJJoy++Jb8K/Lr2CGClBNPhHRpbrHubmzZuXdNnJL/UIGCCnmyWxtVL6zfVjcOMXl+xJcNazqpCpb/+lnds5utCrpCPnYFiwf44EyQyF5pnXpWgnNTHFu3J67yAa2uLiGLf0yMDTsgcZjqrgaMC8iXEB1A7pDNs/z+GKZObZbHged4ESGQe7y6LhhGZbQ1nk2IQ1E6gPELpI736htUYNqfDJScEcEbFFFj4y6ajtey6XIPvHzTDMYzMdKBUXEYCnoCDr4hjUHagsoSwnXBZUiDOsSXrFIFKhgYFUZ9FLjFDuI1GhoNJ6ocPoCeCqLytvzpR1FvABUbjHjX2xmgKrlzGBmGyL0wX266J6cgO1OAocK80yRl5XCnLtJNDkpx3M4IVbCBc1Gft5JSBpoXQ6CBySirkKjugnso9j7lqDeGl3QnbRa4akDX+/aqn5wOguNpAZMM/p5hdOfB2Yh9EvGKSo9+xbikf26YtoAc4zCb7WZR7pKCIOMviPJXNr7zgCI7z66mthER5sUsBk1C18W1lfg9uPp3JqrXZZtQMJZOvN6UQ3HNGqeMf6uzLl+u3aHP5VXPKAk5DhhP0pzl2cBnnbLd2jNWAbT1CXyTpaBI8iSdUpEVRFR0495tlgq/vLsQ5b0KlAL9Gu2wMng9MX2hX3B4RDxvVBZB73nYdStAWSmGGpPp2ciQDCJUbLuGlQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL0PR11MB3122.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(366004)(316002)(296002)(71200400001)(66574015)(64756008)(66476007)(76116006)(66446008)(66946007)(2906002)(9686003)(4326008)(186003)(5660300002)(86362001)(26005)(8676002)(8936002)(7696005)(66556008)(53546011)(83380400001)(6506007)(33656002)(52536014)(966005)(38070700005)(508600001)(110136005)(54906003)(38100700002)(55016003)(122000001)(99936003)(20210929001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: N+F9cco5AJmChj3xKCZ2cqYEbuhXXFMZQiYIeEkoDMfqBl75ZDmUCmXl5uvPB2uf72PIe9JojUuCpD2BlGX1WQTkjYz7MTEU7zNWoxVuRrxQqGI8Z9+xJ5hGDadyPUtIsoU0NEr0EUGKR39FEvHbCRoH7XtMeJy8VsgT2uk7ub2jHSMWio1g3W4byttozRSNrx4INDheElCSkpJQgiSXV96zpe7Cthk98eD0W6jQJ8l25udrMZOJlfaPcDdYlFSTlrweCwSYEYtAqFfqlF43EpXOqDL1doeURVRGYl/wjrP0S7VmKJO2owItKpcQ4qzNrIoFtuFluNgVEoG6Qq3bKiqjAPNSIrEF3P962/9XRBeibCosZre1AP1vtCUKKXHbVqeRSyIxSYzRSvJfs2Y8QrefluRgBZ3K1T3jDs9UNpWnLDHF5p+qmds2oJ+y0MV/b98sdkk52S8nDKJMEuQ64Ox7D9IE91JftaNowVIWUPm1s8Dxcn224TCr3Yv9c7HuIYWhdc/ePSzE/o1g39iv72EPhYwO/3dLnZzRxw7nEVKD6RIW07iJf4v4XpYdSWHa2gGPqBR2LM7EQcboOFN9tDx4YuSV7fwKzG8qWYhwZx8vZG/g1/C3Vu6IpmzbHfly3KUj2/Ui97A/j4fCj9AZ60cgJ/6QM1D2GOW8XNO0Uz/P9NKpThkNyb0+vrTfGkxCWJWc2buWPs5ObtHevEiQKXWQUegpHvxK/WGDomL3zTQiFvzKh4EK4sUkx9m0ys3ot3afBLxuCLDXZ/SPgSpIkfYTT3FPtkB0xT8iMPQ+fkQ+QirCitVJ6IvhPXCm1KuFYUt/c5zWg7k8DTXs5yp3m1yK4cptJb8uBHYD/OvjsOJK8aBzeHzIODEi5LXU/cVG4onhUpUT3+VsHwp10kga04TnRCrDaVNAsmTVB5RZCVsFIFauQBbUEWHoEab/KE8Zrsm3EQUDVhxoRmGMRGeKxj86N8rhoWv+9M2Ikqq3XIoXlyB/vepku0u368osWKSCN0uQI8olg22QFpdgpkzMRhK35Y+tvh7hLOPEDXM8WaE7hTmso3a5GgJhKmsY6MiDPdk/mgtXJr0v5aCs74lMBD8zKpa9n3UZ8elmQE2HQTjnpbO3jQQ8tPvWSCC4LLupZHzZ01i9g3BxmrtlErk6catWdSf3wVvd7w6B2gDL6vaHZ8q5WRKMrhfiQ7vIufUBqMh/km6tlnMN9AjZXkMTVaUuOb124ElmTi6HdQKTGUKLdHNEpUSakU3uDc5tCflQWHhTwBmVTgAgXSgrnqSox7pYXUFcc87SjBRMwtsIq/y5g7iUzLxj4+DDESZI5pJsQutsikEz+4yi4Js178gm0A7iSXkgs5g0PhJl9SHwtwRNR+QTujZXi/vuIyMI6eLvSzPPZgWwZ4Y7qgxblAc3UwR3VOkjUauR0lWvKmFdUBwMC+YLe2sZgxEdzcQPvVe0NkrKvZYCQgeQfZRxoW1Y+45miP/+EvsN7rmELUCKPxKPPUGOYhCPxbGnhbLfZ9UOw8xWeB4vIJD9KKzEaHfqvdDk/uSoyfjpCil66yirluw=
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="SHA1"; boundary="----=_NextPart_000_045F_01D8145F.245357C0"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL0PR11MB3122.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1d2b886c-27f8-430b-ccbc-08d9e2a0ba7f
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Jan 2022 20:57:00.0280 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: kJSh1UQSUJGVkK1b+UMbwlXSEjij+j67wG5MX5zQo3vweFa8GOYv5HgIy26uChmL
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR1101MB2302
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.16, xbe-aln-001.cisco.com
X-Outbound-Node: rcdn-core-10.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/iN2oee9vDoGX8qS1nSj8mBFq4Pk>
Subject: Re: [Last-Call] Last Call: <draft-ietf-rats-yang-tpm-charra-12.txt> (A YANG Data Model for Challenge-Response-based Remote Attestation Procedures using TPMs) to Proposed Standard
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Jan 2022 20:57:12 -0000

Hi Tom,
Hi Henk,

Tom: from your other thread, the requested references from the YANG model
have been updated throughout the document as requested.   We will post a new
version as soon as the other topics below are covered to your satisfaction.

Henk: there is one change I hope you can help with.  Search on **Henk.

> From: tom petch, January 19, 2022 6:24 AM
> 
> These comments are separate from my previous comments on references in the
> YANG modules.  That said,
> 
> 'import' in YANG module must have a YANG reference clause which must be a
> Normative Reference in the I-D Reference.

This has been updated as part of references fix from your other email.  And
new text inserted prior to each YANG model describes the embedded references
from the draft's Normative list.

> ietf-hardware must has a prefix of 'hw' as per RFC8348  throughout the I-D

Change made.

> /http:datatracker/https:/datatracker/
> in both modules

Change made.
 
>         reference
>           "draft-ietf-rats-yang-tpm-charra";
> perhaps
>         reference
>           "RFC XXXX: A YANG Data Model for Challenge-Response-based Remote
> Attestation Procedures using TPMs";

Change made.
 
>       identity attested_event_log_type {
>         description
>           "Base identity allowing categorization of the reasons why and
/and/an/ ?

Change made.

>         leaf TPMS_QUOTE_INFO {
> most YANG identifiers have been changed to lower case; should this one be?

Multiple review discussions have driven this to be upper case because there
is a 1:1 correspondence with an identical object defined by TCG.

>       grouping boot-event-log {
> could do with more explanation and/or references for this. 

I made the group description:
      "Defines a specific instance of an event log entry 
       and corresponding to the information used to 
       extended the PCR";

e.g. are there
> semantics for the uint32 event-type?

** Henk, can you improve this ietf-tpm-remote-attestation.yang leaf
description with a reference:

    leaf event-type {
        type uint32;
        description
          "log event type";
    }

> Security Considerations mention the use of NACM; should the RPC have a
> default deny-all?

Added "with a default setting of deny-all".
 
>             leaf physical-index {
> should this reference the YANG RFC8348 rather than the SMI equivalent?

It could.  The initial requirement was driven by someone who wanted to allow
operations to make an easy mapping to corresponding Entity MIB data they
currently used.  In the end the populated info will be the same.

>             leaf manufacturer {
> these are often modelled as Privat Enterprise Numbers as registered with
IANA -
> see e.g. draft-ietf-dots-telemetry

This could be done.  Nobody in the WG suggested a purpose for leveraging a
mechanized list of values here.  I expect the major use would be for manual
debugging / manual checking if something went wrong.  Certainly a formal
list could be maintained.  It just didn't seem important yet.

>         reference
>           "RFC XXXX: tbd";
> as above

Updated.

>       identity tpm20 {
>         if-feature "tpm12";
> looks odd - if correct then worth an explanatory note

Fixed.

Eric

> Tom Petch
> 
> On 14/01/2022 16:16, The IESG wrote:
> >
> > The IESG has received a request from the Remote ATtestation ProcedureS
> > WG
> > (rats) to consider the following document: - 'A YANG Data Model for
> > Challenge-Response-based Remote Attestation
> >     Procedures using TPMs'
> >    <draft-ietf-rats-yang-tpm-charra-12.txt> as Proposed Standard
> >
> > The IESG plans to make a decision in the next few weeks, and solicits
> > final comments on this action. Please send substantive comments to the
> > last-call@ietf.org mailing lists by 2022-01-28. Exceptionally,
> > comments may be sent to iesg@ietf.org instead. In either case, please
> > retain the beginning of the Subject line to allow automated sorting.
> >
> > Abstract
> >
> >
> >     This document defines YANG RPCs and a small number of configuration
> >     nodes required to retrieve attestation evidence about integrity
> >     measurements from a device, following the operational context
defined
> >     in TPM-based Network Device Remote Integrity Verification.
> >     Complementary measurement logs are also provided by the YANG RPCs,
> >     originating from one or more roots of trust for measurement (RTMs).
> >     The module defined requires at least one TPM 1.2 or TPM 2.0 as well
> >     as a corresponding TPM Software Stack (TSS), included in the device
> >     components of the composite device the YANG server is running on.
> >
> >
> >
> >
> > The file can be obtained via
> > https://datatracker.ietf.org/doc/draft-ietf-rats-yang-tpm-charra/
> >
> >
> >
> > No IPR declarations have been submitted directly on this I-D.
> >
> >
> > The document contains these normative downward references.
> > See RFC 3967 for additional information:
> >      draft-ietf-rats-tpm-based-network-device-attest: TPM-based Network
> Device Remote Integrity Verification (None - Internet Engineering Task
Force
> (IETF))
> >      draft-ietf-rats-architecture: Remote Attestation Procedures
> > Architecture (None - Internet Engineering Task Force (IETF))
> >
> >
> >
> >
> > _______________________________________________
> > IETF-Announce mailing list
> > IETF-Announce@ietf.org
> > https://www.ietf.org/mailman/listinfo/ietf-announce
> > .
> >