[Plants] Re: MTCLogEntry extensibility

Valery Smyslov <smyslov.ietf@gmail.com> Thu, 01 October 2026 13:50 UTC

Received: from mail-lf2-x11.google.com (mail-lf2-x11.google.com [IPv6:2a00:1450:4864:36::11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id EB5C946 for <plants@ietf.org>; Thu, 01 Oct 2026 13:50:46 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=ZUpl4pSp; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx.ietf.org: domain of smyslov.ietf@gmail.com designates 2a00:1450:4864:36::11 as permitted sender) smtp.mailfrom=smyslov.ietf@gmail.com
Received: by mail-lf2-x11.google.com with SMTP id 2adb3069b0e04-5ba4257f97fso507226e87.1 for <plants@ietf.org>; Thu, 01 Oct 2026 06:50:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790862645; x=1791467445; darn=ietf.org; h=content-language:thread-index:content-transfer-encoding :content-type:mime-version:message-id:date:subject:to:from:from:to :cc:subject:date:message-id:reply-to:content-type; bh=zLKyiDF50nELHJNk4SqdfyL6DXkIz7O5ACul18GEEAI=; b=ZUpl4pSpjqsty1+fLaGF/VNjhJxBhO/2pvhC0LEuB7HUSZwRG2+jg3rCnVIBWhpgDC 9Xs4IKDjqfHV9pAzg6q79pl4A2gatH8pzo0S7ztzc09L32QLrwo1ZntgT1papBl0lOlZ 7cAnFqVNH6aA845K8c8rFnLGM6nPGOx+ByXsThSqKjfgpuPPSv6ZMemPcKN3GVK3GbXI AJscPsCyrHPtUpLbfQmqhUvxpUPSpopM9LhMHFQ6ddyA+XmSL0m/NUwx+LyfvO9uEPl0 ETE3VPi8IBefh0S/fPAc8Tu99nuypGh3n9jyVmXNXLMiVD7jYf9mOAx55ACa7JZKiynB tKcg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790862645; x=1791467445; h=content-language:thread-index:content-transfer-encoding :content-type:mime-version:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=zLKyiDF50nELHJNk4SqdfyL6DXkIz7O5ACul18GEEAI=; b=US13w/2cmjWVSRslwa+3Z94y/73Om2rKtZTkXD95tFrqhz1WQVi1nJD64iC91/9TPc yiizZNeOIoNnvJiyyJHg1AS6fUO9FCOZ41rDTLpiOAUOrvnxvklR+Oa+L7DZoh0OUzGQ Pq4ynHARnDd6BpTaiet6QcF8l//gV0FyP/3szSu7Dd1rFnGsaotX9bzpdtr8TFZRQGYy Ntdg5goZdw/fdsktSZY8ZRwKz1Y6ugALTGhne7N5SUUng4yLDi/FYSEvF2bfiQ1MqZKG +3xPDz3vrZ1JzW07aqyjby19+C4Ke01GU7jTxjhmXu/3Cjmy9wVO8I9Xm/6nmMqyX1y8 Hl2g==
X-Forwarded-Encrypted: i=1; AKwUvByQEaipimSQc9FjfdFWW9YS0k0y9TGZs/gEuvej4bxzD0sgm2zGQL06lin6TVH5u7o2hpGz5Ew=@ietf.org
X-Gm-Message-State: AFq9FYLkEPieGXGNzldeVyZEq2bG4uONpUfOAmS8e9VgrF7xld6MTNj/ i9ebmaljUe7K1UGTsRZqYqhn6vV8eCiYIOwsBfO95HjoqmHu+Xic1nNm
X-Gm-Gg: AYBFou1P4d1paO2ereJiMAvHtgfIfZrvkwx8ayyBNewC3plIzPuYBkRMeZJA5pza8C5 su9P8DJSD0wPEZJQJYHLRTDob4tfSM56PrbcuxW6IT7gaNhQsBVn8H8G1Pg7ylb/qmp89CmVuv3 Uyjdg3N/sKdqinbY5rDS7yxjnxnNtam2a/SRMIkdoXJPsYO/0VVKF4KfnreLCQ7X8UFBEjJStaN MOZYXboPjNhdxts7rLP+xqPn1RGQxv4nVoS5m8t3u0OyCJqgyNVVyGAmMGTjdJzRJSvltiI3voz f4qIh1bqmZQpPYntvT/sIAi3bY0FnXN5lNdXgVuHhPInC2aHFYFUbPlt9ONaaioT2PU6cOQXi2i c/J6et4x7gr4jF/y9L+kKOGM3jwUUrY5FGIm0qIePEdqyjbj5BsQL7CVxZlNq9PL67UQ22q5BnX foq3t4SIw/DJcrR42A6UDRA/StJJ9IStnm/X3Pm9P08x9uCO7wFdgOgmXAkswZUs8cWg0rMJMcc HixXA==
X-Received: by 2002:ac2:528a:0:b0:5ba:3e29:2255 with SMTP id 2adb3069b0e04-5ba432aae97mr843088e87.2.1790862645258; Thu, 01 Oct 2026 06:50:45 -0700 (PDT)
Received: from BuildPC ([93.188.44.204]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5bb7b84b3c4sm23498e87.12.2026.10.01.06.50.43 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 01 Oct 2026 06:50:44 -0700 (PDT)
From: Valery Smyslov <smyslov.ietf@gmail.com>
To: ilariliusvaara@welho.com, plants@ietf.org
Date: Thu, 01 Oct 2026 16:50:43 +0300
Message-ID: <1db301dd51ab$db1cfb30$9156f190$@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 16.0
Thread-Index: Ad1RqPFSVbU5CUT8TSKIJ9ZQaQWUAw==
Content-Language: ru
X-Spamd-Bar: /
Message-ID-Hash: GYM4G4SIWXRYISWPLXNZKDOVQJFU37XY
X-Message-ID-Hash: GYM4G4SIWXRYISWPLXNZKDOVQJFU37XY
X-MailFrom: smyslov.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Plants] Re: MTCLogEntry extensibility
List-Id: "PKI, Logs, And Tree Signatures" <plants.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/plants/cBRJ3PxTARogE2IUwI3QM0JxYF4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/plants>
List-Help: <mailto:plants-request@ietf.org?subject=help>
List-Owner: <mailto:plants-owner@ietf.org>
List-Post: <mailto:plants@ietf.org>
List-Subscribe: <mailto:plants-join@ietf.org>
List-Unsubscribe: <mailto:plants-leave@ietf.org>

H Ilari,

> > My concern is that the type of the MTCLogEntry is not known to the relying party.
> > The relying party needs to reconstruct the MTCLogEntry to validate the inclusion proof
> > and the algorithm in the Section 7.2 blindly assumes that the entry
> > always has the tbs_cert_entry format. In case this format is extended in the future,
> > how the relying party would know that a particular MTCProof structure
> > corresponds to a new format (I assume the relying party supports both formats)?
> 
> If the thing RP is processing is a certificate, it is tbs_cert_entry.
> If it is something else (defined later), then it is something else.

So, the data format for log entries for certificates is fixed forever?
I think that this can become a limitation in future...

> E.g., in-tree revocation list could have type of intree_crl_entry.
> 
> 
> > In my opinion, the MTCProof should include MTCLogEntryType, so that
> > the relying party would know how to reconstruct MTCLogEntry.
> > Something along the lines:
> 
> No, this would be insecure.

Why?

Regards,
Valery.

> 
> 
> 
> 
> -Ilari
> _______________________________________________
> Plants mailing list -- plants@ietf.org
> To unsubscribe send an email to plants-leave@ietf.org