Re: [MLS] recharter text

Brendan McMillion <brendanmcmillion@gmail.com> Sun, 12 November 2023 22:17 UTC

Return-Path: <brendanmcmillion@gmail.com>
X-Original-To: mls@ietfa.amsl.com
Delivered-To: mls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94BE2C1519A6 for <mls@ietfa.amsl.com>; Sun, 12 Nov 2023 14:17:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wWO72sUzB210 for <mls@ietfa.amsl.com>; Sun, 12 Nov 2023 14:17:14 -0800 (PST)
Received: from mail-ed1-x533.google.com (mail-ed1-x533.google.com [IPv6:2a00:1450:4864:20::533]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BF7A8C1519A0 for <mls@ietf.org>; Sun, 12 Nov 2023 14:17:14 -0800 (PST)
Received: by mail-ed1-x533.google.com with SMTP id 4fb4d7f45d1cf-544455a4b56so5906580a12.1 for <mls@ietf.org>; Sun, 12 Nov 2023 14:17:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1699827432; x=1700432232; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=O/oY9okZnDWyficsnkZ1ealswSuvzcPBisPi+c6SyIU=; b=X0F1i21xxBuIb+GpAIEdngFz8DMf3QUY3+fl8prMTqGDUrJzRHhu5B+oeH1ujMwVLr 4GNNGoEte46ZvcrHu4YFcSw+7vOeuE84GQBO6j/5BhGMnJZHOjQBLueZIkzrdkMAk0Bg QLOUHJL6xIvFG5F/aGEA6Kw7LAlawb+1EjY24PoYOTk68N0Luf/8JfI3GtS/t49ALFv7 V0T8zjwHgmxkF4kcCJ37mOYnzCQpLohSWAIMFGGgUme8Nr1UG1jlfC9UJv/DC841F3OW v2UtSOLMZwmA5bLOUssYausYiWMqTMBigRb6rSaFnFWQ3ndwvxG+YdfKSo2tLYiUPN0L 0vUg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1699827432; x=1700432232; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=O/oY9okZnDWyficsnkZ1ealswSuvzcPBisPi+c6SyIU=; b=vJ3qyUHPEwuLVzut4wMcBSd70e5qizHMjgpXLGASVSfTgIff2prLnx5bFbKw/v352F ePzyfYlzNe8nbCKktlNiGXIWlfUGMIH6VkcBLURnHm/gIe1bSkEtmSo1Bv+TjDhiaB7C xgL5BkR3rik9odnzIaOaGYKh488xtokxlE/L68ZhZ0NFiFTj76Na4xLdImNbakzqK6SW KfLPIkp2Xc/sghi3fdgPED8lpgyjOppabiJqqseW2NwbhhwMcWEkl8jo14lSz88T7nHj qXuiIpM4fKVwF44Zetaa+CemPxkJ7eJDujXRxaWcT1X4tWjLjhCWpPo+f/cUT02N/m/K RfMg==
X-Gm-Message-State: AOJu0YwPx7S2dWvHAIWusPY6l780MPR1+NCQP3BpfDJEqO7iUAs+tGxq d7Vsza2XQvRuAN1L6UyewlYf6/6l0xQkvkLdaY1pzvOYjyw=
X-Google-Smtp-Source: AGHT+IESrIICH+G3t+XMozswcRcvzDZ4WtxSyr3obJG3/pd+4azPCvOWBmwg75z17AouoiSYjIVgEmTpCCPcg782BwE=
X-Received: by 2002:aa7:c993:0:b0:53d:a17a:7576 with SMTP id c19-20020aa7c993000000b0053da17a7576mr3745336edt.8.1699827431722; Sun, 12 Nov 2023 14:17:11 -0800 (PST)
MIME-Version: 1.0
References: <E7722644-F886-46AF-A262-D3404CBDC99B@sn3rd.com> <CACsn0cnXFs4R90F=7mvXsYggN=_QRJCvBVW+VF4EHd_8oEE8wg@mail.gmail.com> <3ee585b6-5144-d65b-75e0-5f78ab7cdb53@nohats.ca>
In-Reply-To: <3ee585b6-5144-d65b-75e0-5f78ab7cdb53@nohats.ca>
From: Brendan McMillion <brendanmcmillion@gmail.com>
Date: Sun, 12 Nov 2023 14:17:00 -0800
Message-ID: <CAJTd26Keyirkwdm3wS4oDphiOjvuDjHUR65ryE2Vt4ApBvf1Kw@mail.gmail.com>
To: Paul Wouters <paul@nohats.ca>
Cc: Watson Ladd <watsonbladd@gmail.com>, Sean Turner <sean@sn3rd.com>, MLS List <mls@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000003f539b0609fbeacb"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mls/kBNZJMfQPqRDrVVbLg8KAKQ8S3U>
Subject: Re: [MLS] recharter text
X-BeenThere: mls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Messaging Layer Security <mls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mls>, <mailto:mls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mls/>
List-Post: <mailto:mls@ietf.org>
List-Help: <mailto:mls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mls>, <mailto:mls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Nov 2023 22:17:18 -0000

Commenting specifically on the taxonomy proposed by Richard in the PR:

"Support for Verifiable Credentials" -- I think this is too narrow, and
should instead say "Support for new credential types." Credentials are
similar to ciphersuites in that the wg should generally be open for
business to standardize new ones (when there's support / belief that they
would be valuable).

"Support for common operational patterns in messaging applications" -- On
the other hand this seems too broad, in that arbitrary endless work could
fit under this umbrella. The two drafts listed under this category are
"Last resort KPs" and "KP context". I've been concerned about the utility
of these drafts. They specify that new information be put inside of the
KeyPackage and signed. But I don't believe there's much security value in
having this information signed. The drafts also require application logic
outside of the extension to work correctly, so using the extension is not
any operationally simpler than a solution that's entirely application-level.

I'd also like to see a call-out to work on support for the "user trees"
idea that was mentioned during the meeting.

On Sat, Nov 11, 2023 at 4:17 AM Paul Wouters <paul@nohats.ca> wrote:

> On Fri, 10 Nov 2023, Watson Ladd wrote:
>
> > Does a saving clause of "such other extensions as the working group
> > consensus deems advisable" sound good?
>
> No - Recursive chartering loops are not allowed :-)
>
> The charter shows the important things the WG want to work on first.
>
> Having statements along the lines of "anything goes" won't help keep
> the WG stay focussed and won't help us evaluate how the WG is doing
> on its goals. I would not like to see 20 draft documents that are all
> in flight and not getting proper attention because everyone is working
> on their own draft only and no one is reviewing all the other drafts.
>
> However, you get a beverage of choice for your pentest of the chartering
> system :)
>
> Paul
>
> _______________________________________________
> MLS mailing list
> MLS@ietf.org
> https://www.ietf.org/mailman/listinfo/mls
>