Re: [pkix] TPM Privacy CA - in the wild?

Michael StJohns <msj@nthpermutation.com> Thu, 07 July 2022 18:44 UTC

Return-Path: <msj@nthpermutation.com>
X-Original-To: pkix@ietfa.amsl.com
Delivered-To: pkix@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 835ADC15D445 for <pkix@ietfa.amsl.com>; Thu, 7 Jul 2022 11:44:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.783
X-Spam-Level:
X-Spam-Status: No, score=-3.783 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, NICE_REPLY_A=-1.876, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nthpermutation-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rLrpzaQY6qVi for <pkix@ietfa.amsl.com>; Thu, 7 Jul 2022 11:44:13 -0700 (PDT)
Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4285BC13CF78 for <pkix@ietf.org>; Thu, 7 Jul 2022 11:44:02 -0700 (PDT)
Received: by mail-qk1-x72a.google.com with SMTP id v6so14081012qkh.2 for <pkix@ietf.org>; Thu, 07 Jul 2022 11:44:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nthpermutation-com.20210112.gappssmtp.com; s=20210112; h=message-id:date:mime-version:user-agent:subject:content-language:to :cc:references:from:in-reply-to:content-transfer-encoding; bh=qYHcOGxT60cDzyqp0JDgJwUO7vg9e4lZxXV1QvGF2W4=; b=S6/ZuOFzR3VnLKTuUUQLiytsVt8oaBak4B1RtUJeaRRNM1xoXXFPm7DWfjyjAsCkss YmHO6LIA9zCiFoyz0BRq69XCOIpri60jfyMMIT8UnGdP06klP9JrMQ+J6C0lT6lddYDA PldS6+FwucHRdpvy8q5ZRJWTeGuEYMPJp5gZH+eTlPMB250rPXnwiX0nCpNp1vpQra9K 65cim5Rqlwtx3e9Rfq2u0C9Q52c3RluXxa//QZFUZ01SNyQZZTNjT6a4g61CAuxL/WkM RmbvrPxxSZzcfW0qkfSJ8cYhfV+/VOV8WMHgJGJ5Z2hRNBwthpeMcKSXjHvXEfltgNvt giqw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:message-id:date:mime-version:user-agent:subject :content-language:to:cc:references:from:in-reply-to :content-transfer-encoding; bh=qYHcOGxT60cDzyqp0JDgJwUO7vg9e4lZxXV1QvGF2W4=; b=tRi4CmWYi3EL3cC9h6kjoC95gowQ7kGvriVoFgBe5/TfH09yzDxQojmnmyLCYs36O/ gAhdvsSOGZouGL+60kBJKpcxxaf++mpCN/zPZwpCeGaRtQ3vmDfudZTMDdqUFd8TrPtp tZVrSZ8EcE1cyzSAZV+2UF3nyyK4oN6zFC0lCNcLVEqNc0z5mC2pXeDG9c9fRiKSdRl6 3VzlMQJYSNYYVxAFranhhDKqbx+Qv299Bjnm07mxdkXQjAtzoec8ZaCc8P8Uijt1qwdn W3chm72H4SoUDytf4qPDI6VoQJjTk3pdHu33qNjAGBV77kPgTHj5BxfqlcsQyiDoHEUw tgRQ==
X-Gm-Message-State: AJIora9Hf7PSsU/N5nOlxKhGvgZSEJYjVG7TIJFr3MFtE25l0JhJJKvl b9l0ybxWBopv4IC1IXIe0CR/HfmeK1lBvr9F
X-Google-Smtp-Source: AGRyM1uuSnIgHK2HsaZFFxKj7251M0jCG8AO1w457AXLpdJQeHLLQoxmmj6dh0VeY4ULR3VUoK5Mvg==
X-Received: by 2002:a05:620a:13a3:b0:6af:a58:c139 with SMTP id m3-20020a05620a13a300b006af0a58c139mr33259041qki.751.1657219441167; Thu, 07 Jul 2022 11:44:01 -0700 (PDT)
Received: from [192.168.1.23] (pool-108-51-33-15.washdc.fios.verizon.net. [108.51.33.15]) by smtp.gmail.com with ESMTPSA id c26-20020ac8661a000000b0031e9b5ead3asm1368650qtp.76.2022.07.07.11.44.00 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 07 Jul 2022 11:44:00 -0700 (PDT)
Message-ID: <a7c788b5-31fb-7f4a-fcfa-e75859bd828a@nthpermutation.com>
Date: Thu, 07 Jul 2022 14:44:00 -0400
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0
Content-Language: en-US
To: noloader@gmail.com
Cc: IETF PKIX <pkix@ietf.org>
References: <d0286448-b6ed-419d-2d29-b1d0b44834d0@nthpermutation.com> <CAH8yC8mX-KomExBT51c2z_QwGjWdmCpVexe-NECJ5cPY2ivgXA@mail.gmail.com>
From: Michael StJohns <msj@nthpermutation.com>
In-Reply-To: <CAH8yC8mX-KomExBT51c2z_QwGjWdmCpVexe-NECJ5cPY2ivgXA@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/pkix/0lVuHXA6n0PYohwmYkl4TDuLr2g>
Subject: Re: [pkix] TPM Privacy CA - in the wild?
X-BeenThere: pkix@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: PKIX Working Group <pkix.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pkix>, <mailto:pkix-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pkix/>
List-Post: <mailto:pkix@ietf.org>
List-Help: <mailto:pkix-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pkix>, <mailto:pkix-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Jul 2022 18:44:15 -0000

Hi Jeff -

On 7/7/2022 11:44 AM, Jeffrey Walton wrote:
> Hi Mike,
>
> On Thu, Jul 7, 2022 at 11:35 AM Michael StJohns <msj@nthpermutation.com> wrote:
>> Does anyone know of any public CA that's issuing certificates for TPM
>> attestation keys using the Direct Anonymous Attestation scheme?   Aka
>> "Privacy CA".
> I don't have an answer for your question, but... if you ask on a
> Mozilla list, like dev-security-policy@mozilla.org, you may get an
> answer. Some of the Mozilla lists work closely with the CAs.
>
> Another list of interest may be the CA/Browser Forums. That's where
> the CA's and Browsers collude. But I think that list is read-only for
> the general population.
>
> Jeff

Thanks for the suggestions, but as of right now I don't subscribe to 
those lists and I'm loath to do so if I can get the information here.  I 
do know that more than a few CAB and Mozilla folk hang out here.   If I 
don't hear anything on this list, I'll probably start bugging one of the 
Trusted Computing Group groups for information.

Thanks! Mike