[Rats] draft-birkholz-rats-network-device-subscription-00

"Eric Voit (evoit)" <evoit@cisco.com> Wed, 24 June 2020 16:41 UTC

Return-Path: <evoit@cisco.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23AC43A1059 for <rats@ietfa.amsl.com>; Wed, 24 Jun 2020 09:41:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.599
X-Spam-Level:
X-Spam-Status: No, score=-9.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=S4EOrz2m; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=lIzGQ1mI
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZohC8SXfopQB for <rats@ietfa.amsl.com>; Wed, 24 Jun 2020 09:41:32 -0700 (PDT)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68E353A1045 for <rats@ietf.org>; Wed, 24 Jun 2020 09:41:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7678; q=dns/txt; s=iport; t=1593016889; x=1594226489; h=from:to:cc:subject:date:message-id:mime-version; bh=CEQdcP4o4gVp+kwO2tnleSY9zPBP9iLzubaRIgPGNdg=; b=S4EOrz2m5eIQ6D5L2pMnhFicp5CdWuh2LVrKfcSP8ZxJ7A0Y5cZX/ncE 29TisYsdmh/synFbz0XJUFkVs3GrdQ7WJfnUaj0mzLHTCZxI00f2nFWrP h4i2upynR4UegBvoeWw27k3DSC3hEimMksXxHWvkg59J9+IKvZSCTBcyY Y=;
X-Files: smime.p7s : 3975
X-IPAS-Result: A0BuCACCgfNe/4kNJK1mHgEBCxIMgX8LgVIpKAdvKy0vLAqEGoNGA41FmFeBLoEkA1UEBwEBAQkDAQEYDQgCBAEBhEcCghUCJDYHDgIDAQEBAwIDAQEBAQUBAQECAQYEbYVbAQuFcgEBAQEVER0BATcBCwYBGQQBAQ0BHQIEMB0JAQQOAQQIBhSCOUyBfk0DHw8BDqwRAoE5iGF2gTKDAQEBBYE2Ag5BgyYYggcHCYE4gVOBFIluDxqBQT+BVIVnAQECAQGBXRUnglYzgi2ZFIERiXiQTgqCWoQpglWBRpELgnGBGIgNkm2FNIwFiheUNAIEAgQFAg4BAQWBWgQugVZwFRqDCglHFwINjh6DcYUUhUJ0Ag4nAgYIAQEDCXyPPgGBEAEB
IronPort-PHdr: 9a23:UHiY4hxqBuIjUNLXCy+N+z0EezQntrPoPwUc9psgjfdUf7+++4j5ZRWFt/RgkFGPWp/UuLpIiOvT5qbnX2FIoZOMq2sLf5EEURgZwd4XkAotDI/gawX7IffmYjZ8EJFEU1lorHC2LUYTH9zxNBXep3So5msUHRPyfQN+OuXyHNvUiMK6n+C/8pHeeUNGnj24NLhzNx6x6w7Ws5ob
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.75,276,1589241600"; d="p7s'?scan'208";a="492412180"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by alln-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 24 Jun 2020 16:41:20 +0000
Received: from XCH-ALN-005.cisco.com (xch-aln-005.cisco.com [173.36.7.15]) by alln-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 05OGfKYU011213 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 24 Jun 2020 16:41:20 GMT
Received: from xhs-rtp-001.cisco.com (64.101.210.228) by XCH-ALN-005.cisco.com (173.36.7.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Wed, 24 Jun 2020 11:41:20 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-rtp-001.cisco.com (64.101.210.228) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Wed, 24 Jun 2020 12:41:19 -0400
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Wed, 24 Jun 2020 11:41:19 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kMpOvTEIq+JVaoFVWhsO9WJ0XUKJJN+Q6Ifx3zWZVU+BFIuMTS4tNwa9sDC0g9SwyUCzmCPx7VWWdwcqORGxIJQXo3GXJE7ItF9Lp/1dTX/5OTx8my/JwmXWMLj1PRMtoaL6HJ4G+fRhesZCxrNQ4/TjRb6YIXqnIoVFv/92/A+hbaC58IkN8r7ciSwEhk/kFBSYKTp0KqxfyY+BmuQL9q0i7Huokx0opnfo0DkbmaVHJ6YoHlSbfz7WgwEnEf5W1lLQgo1TQ4M/sAkviQmISz0k0/4LRlWinqqimzLFCFUfDw6SGDvRjSfQy2X628ZmLmnGTBzG9tte2ohIzgW4lw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=sqr15QN6rWQLJ+DWt4Ph++TWXI5GAhRTu2pzEiK1c9w=; b=PFJYsgbHEsh/b1dvyTCH2Wf0GLKKBN7xCjKOJ7dJTM7EPTJVSSJKhfGR2PsN2EaErtDNd3Kfn2g2F9g+OissVmcUA9uq6lwv8qBcWVHIzJGGGDF8ktPW6jPB3tEBPrY1RrJ3C+G3vJ0MRYaGh9JZeS9J+YqM65G+M7eg4ZqmkahZrjIyrLnzGDVQh+lt2Npfg4E9hy3vm0bSApk4WqwVT/W2W42+rVOMS09W7m40ydH0FLYKSQdkHZlmg7OW0dnoLPE3Cmi8a5dGFxweYSEqecrK9/jhCR1R6um+Kb75PIrxtB6n8zNAuQjyZBK9fH4BlujqDZkCH7xsT1hnozo18g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=sqr15QN6rWQLJ+DWt4Ph++TWXI5GAhRTu2pzEiK1c9w=; b=lIzGQ1mI85SmE5njWRW/3V5o4YclZ5m7SdMutOZWjI6MRZn9QGek5gnau9LmDueDLmk6ThCYti4leoNn3gL9+s6jDBgcAe0w2gTSJLXQrj9v6lwaIz5Nb6/11Sg2e8FDXxrZKmvwcdfTlK6YWg6M34zY6sNt3Vm4PCgCFKv/OoA=
Received: from BL0PR11MB3122.namprd11.prod.outlook.com (2603:10b6:208:75::32) by MN2PR11MB4382.namprd11.prod.outlook.com (2603:10b6:208:18c::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3109.22; Wed, 24 Jun 2020 16:41:18 +0000
Received: from BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::20ac:d8b4:4a4f:4290]) by BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::20ac:d8b4:4a4f:4290%7]) with mapi id 15.20.3109.027; Wed, 24 Jun 2020 16:41:18 +0000
From: "Eric Voit (evoit)" <evoit@cisco.com>
To: "rats@ietf.org" <rats@ietf.org>
CC: "Birkholz, Henk" <henk.birkholz@sit.fraunhofer.de>, Wei Pan <william.panwei@huawei.com>
Thread-Topic: draft-birkholz-rats-network-device-subscription-00
Thread-Index: AdZKRjugUmuktT1iTCKR70EUNGNj/g==
Date: Wed, 24 Jun 2020 16:41:18 +0000
Message-ID: <BL0PR11MB31221B4EE75AADDB4685CBDEA1950@BL0PR11MB3122.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [173.38.117.72]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: cf5d000d-09b4-4f34-fb25-08d8185d6b58
x-ms-traffictypediagnostic: MN2PR11MB4382:
x-microsoft-antispam-prvs: <MN2PR11MB438294581A27194F0AAB36B2A1950@MN2PR11MB4382.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0444EB1997
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: pHLiBSJvkF31TpXYZvxhGEXm6pA2wnz+m2nczfGPWwfSTtE5weUAcXF5uiHMiighfXC1UazXU4oUmbQmmJh1tXWIskUbeWwMf3ATUPPtGZruGp4ye77hqu/eI4dsQXyHVGoqjuWHhYpDyTHTGZP5JEB+j5XYXgfveZhIw/7ysD7hAN/QtuPOvfwAobe23JodEwSQ3fvj5Y2GRGsxcMYONQ62P3BrGkwXBNhLIcBuunOxhR97wkDyOzOj53YxPR8KUqsk85bOI+BeMn9sBJQZo/kGUTQijL1Wk2ZzEhwjMjDDKY3Vn71Ka+7OD3p8fjd3GkwUFcHyNvMULU43EisCEvmvX3+YEv7wlO/GACopaFSF+ger74nVvPPCpxjU1XQXoYgZ59GxgleeZOvbrLLEFw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL0PR11MB3122.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(346002)(39860400002)(376002)(366004)(136003)(396003)(7696005)(66476007)(66446008)(66946007)(76116006)(64756008)(316002)(33656002)(66556008)(66616009)(52536014)(8936002)(54906003)(71200400001)(4326008)(2906002)(26005)(55016002)(186003)(86362001)(9686003)(6916009)(5660300002)(8676002)(53546011)(6506007)(99936003)(478600001)(83380400001)(966005)(66574015); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: UnxYJx3vQfPx9830Z10AcK0nhxt3naGuQjDPm7lJLnmh7LMrW7IMI1MyNdRrrTV5zNkga/tK88rFbkJFMKBZ0q0mxLSEs/TzRPQC7agahw1ONPGPEP3rhNoJZfDr90IFE0PqRdFe+XOZHjsl7jNI7tHifbGkOUPJ4/mYZ15POBnjlBq3TcKzDCWD+yDM6az9SAZr8974p6N3OAzgO3ynfcXHzSQA4f7Lgh1R190/0HZ8WwvOAegjjpfWtjCyR4aqUoPv2mw1fN/hTT9idrgvvyaSuIgzkqPYcwe88u/23mzq8SrOju63sdqUqvoyFCdM0w3BFa+f9/lp8P2fCVmJFKWdvMzxXdSP3ADWVw01Leb+Te2zvNuFz49+2S9v/vhodD7FTkfcPH+4ZkXLWtabMybi2KGXxXyY7DcdGL1w1i4wkHXHM2bDZXCUeVDlGGpjQMadyEdZ9gJY58yGq17znq/4ffA2N0ds+IjklpWmcn6/+i7gdYyuF6BQ40/S5r0N
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; boundary="----=_NextPart_000_03D2_01D64A24.B7AEC290"; micalg="SHA1"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: cf5d000d-09b4-4f34-fb25-08d8185d6b58
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Jun 2020 16:41:18.3744 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LejflKE2l9BjxMf0+4GyV1DkRtzDlWzyViZIQ/qfDNu7VpH1MoL7Tfoa65w2PF/y
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4382
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.15, xch-aln-005.cisco.com
X-Outbound-Node: alln-core-4.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/255WWWWszWZuZdWWh8j--OltmJA>
Subject: [Rats] draft-birkholz-rats-network-device-subscription-00
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jun 2020 16:41:34 -0000

Hi All,

This draft defines how to subscribe to a stream of attestation related 
Evidence on TPM-based network devices.  When subscribed, a Telemetry stream of 
verifiably fresh YANG notifications (which are generated when TPM PCRs are 
extended) are pushed to the subscriber.

This draft integrates:
 *  Section 5 of draft-voit-rats-trusted-path-routing-01
 *  Elements of draft-xia-rats-pubsub-model

Thanks!

Eric, Henk, and Wei


-----Original Message-----
From: internet-drafts@ietf.org <internet-drafts@ietf.org>
Sent: Wednesday, June 24, 2020 12:19 PM
To: Eric Voit (evoit) <evoit@cisco.com>; Wei Pan <william.panwei@huawei.com>; 
Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
Subject: New Version Notification for 
draft-birkholz-rats-network-device-subscription-00.txt


A new version of I-D, draft-birkholz-rats-network-device-subscription-00.txt
has been successfully submitted by Eric Voit and posted to the IETF 
repository.

Name:		draft-birkholz-rats-network-device-subscription
Revision:	00
Title:		Attestation Event Stream Subscription
Document date:	2020-06-24
Group:		Individual Submission
Pages:		20
URL: 
https://www.ietf.org/internet-drafts/draft-birkholz-rats-network-device-subscription-00.txt
Status: 
https://datatracker.ietf.org/doc/draft-birkholz-rats-network-device-subscription/
Htmlized: 
https://tools.ietf.org/html/draft-birkholz-rats-network-device-subscription-00
Htmlized: 
https://datatracker.ietf.org/doc/html/draft-birkholz-rats-network-device-subscription


Abstract:
   This document defines how to subscribe to a stream of attestation
   related Evidence on TPM-based network devices.




Please note that it may take a couple of minutes from the time of submission 
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat