[OPSAWG] Eric Rescorla's No Objection on draft-ietf-opsawg-mud-24: (with COMMENT)
Eric Rescorla <ekr@rtfm.com> Tue, 05 June 2018 07:46 UTC
Return-Path: <ekr@rtfm.com>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id AA333130F07; Tue, 5 Jun 2018 00:46:21 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Eric Rescorla <ekr@rtfm.com>
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-opsawg-mud@ietf.org, Joe Clarke <jclarke@cisco.com>, opsawg-chairs@ietf.org, jclarke@cisco.com, opsawg@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.81.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <152818478168.18034.4488898331989905016.idtracker@ietfa.amsl.com>
Date: Tue, 05 Jun 2018 00:46:21 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/CJcD8ZfFO8vCEI6pPdWR1AKRRW4>
Subject: [OPSAWG] Eric Rescorla's No Objection on draft-ietf-opsawg-mud-24: (with COMMENT)
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.26
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Jun 2018 07:46:23 -0000
Eric Rescorla has entered the following ballot position for draft-ietf-opsawg-mud-24: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html for more information about IESG DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-opsawg-mud/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Thanks for addressing my DISCUSS. " signature" and validating the signature across the MUD file. The Key Usage Extension in the signing certificate MUST be present and have the bit digitalSignature(0) set. When the id-pe-mudsigner extension is present in a device's X.509 certificate, the MUD signature file MUST have been generated by a certificate whose subject matches the contents of that id-pe-mudsigner extension. " Isn't the extension required to be present.
- [OPSAWG] Eric Rescorla's No Objection on draft-ie… Eric Rescorla