Re: [Rats] I-D Action: draft-ietf-rats-tpm-based-network-device-attest-05.txt
"Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com> Mon, 26 October 2020 21:04 UTC
Return-Path: <ncamwing@cisco.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C91083A0F0E for <rats@ietfa.amsl.com>; Mon, 26 Oct 2020 14:04:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.601
X-Spam-Level:
X-Spam-Status: No, score=-9.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=kHpIQ/lP; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=0cSiLnjR
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y_kUAEHBVesZ for <rats@ietfa.amsl.com>; Mon, 26 Oct 2020 14:04:34 -0700 (PDT)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0876C3A0E59 for <rats@ietf.org>; Mon, 26 Oct 2020 14:04:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5014; q=dns/txt; s=iport; t=1603746274; x=1604955874; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=7ka08uxvXUdMm2PyHSzHS88zbIPMAAh6ONplFW7njug=; b=kHpIQ/lPpblD8l1X0zFeQgccTjFWqJ2DZJIu9CZo9fb0wN7oZEbo9j3V INacj70Ojhuqj2gcM1tp9P8pdTdhp2pRfId7kT5F2nVbVZc+BmQrVNA7p LVFmQzcK1gRzx3OXeGjy6FtNMpfG9MAcB5w5qqrv344oa2kt+W7wenq3Y w=;
IronPort-PHdr: 9a23:zZ67LhbIiSaxWw5RWheTrOX/LSx94ef9IxIV55w7irlHbqWk+dH4MVfC4el21QaZD4fG7fNchvCQta38CiQM4peE5XYFdpEEFxoIkt4fkAFoBsmZQVb6I/jnY21ffoxCWVZp8mv9PR1TH8DzNF/PpHyq4CRUHBjjZkJ5I+3vEdvUiMK6n+m555zUZVBOgzywKbN/JRm7t0PfrM4T1IBjMa02jBDOpyhF
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CpBQDLOJdf/4YNJK1gHAEBAQEBAQcBARIBAQQEAQFAgU+BUlEHcFkvLAqEMoNJA40gJph6gUKBEQNVCwEBAQ0BARgIDQIEAQGBVYJ1AheBdAIlOBMCAwEBCwEBBQEBAQIBBgRthWEMhXIBAQEEAQEQEREMAQEsCwELBAIBCA4DBAEBAwImAgICJQsVCAgCBAENBSKDBAGCSwMuAQ6ZXwKBO4hodoEygwQBAQWBR0GDEhiBdhoJgQ4qgnKDcIJEhBMbggCBEScMEIJNPoJcAQECAQEVgREBEgEhF4MAM4Iskxg+pDQKgmqJBJF1Ax+DF4EqiGMFlDWGBY04inaVQgIEAgQFAg4BAQWBayNncHAVGiEqAYI+CUcXAg2OH4NxhRSFCQE4dAI2AgYBCQEBAwl8jDsBgRABAQ
X-IronPort-AV: E=Sophos;i="5.77,421,1596499200"; d="scan'208";a="590780433"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by alln-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 26 Oct 2020 21:04:32 +0000
Received: from XCH-RCD-002.cisco.com (xch-rcd-002.cisco.com [173.37.102.12]) by alln-core-12.cisco.com (8.15.2/8.15.2) with ESMTPS id 09QL4Wgl032135 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 26 Oct 2020 21:04:32 GMT
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by XCH-RCD-002.cisco.com (173.37.102.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 26 Oct 2020 16:04:32 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 26 Oct 2020 16:04:32 -0500
Received: from NAM11-CO1-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 26 Oct 2020 16:04:32 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=WGSfKp6LzNIm3mXYaYhYxxuoYfPX1TVAVUpUvbXMTqfx4aQnp52+CCZsh/I2t1sKcOvi5tQ6kKmhpM77TbgS+lMhi3duSY2ue0cgtfyEvAQ1sqA9yigTNKKOchKSE7VSx/XWY5o8zVo0g81GwNxHz8abJMDs/gP1W1BHAvyqR0GXlltLynabPt4cxk6kshCzYZsI2xsQW+RkUSb+pfe40BoBPS0MJL+acgSuWiLHUDPS7zc/hSY6FRCX/OlCR23XWNxY2ppRBk9NpyDnxzBd5Va3iipqEoMosWnwSoVM0lUynAxKb+BeVBJqYWXptncm8ZPQt+MWXqX0vlDpqtUnzw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7ka08uxvXUdMm2PyHSzHS88zbIPMAAh6ONplFW7njug=; b=Q2mjJorZjvVXlu8P2CHpDcTy3zx5qm1tDw+SbJCbcP9U4FXDxqt3mhncNVsvOWSjILmvnR8hv2/w30InJ2Qkxj4204Vj99sIYYG1cvxCtPM6ZMQSl5K01Q4wWl+O/WJYYW7frC7JyxKXHRshM1K8JQPS7V97vkeOIU/v45QM16Fv8YyuyR5+dfkihaVWYEZ+tl1kstg7MO3p567wz32rahmc2zF889JXyjJzE2oNDt4pYG2eYsJDlD59V7aV8mVxFDI81Esa2WtF7wlK9FD7hH3ZxToQJD71N3PIVKehWsJfBX34NG5zfyUTWw1mpTqblnQQOC0ubYlVIOExF0YjUg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7ka08uxvXUdMm2PyHSzHS88zbIPMAAh6ONplFW7njug=; b=0cSiLnjRt+T/aDH0h/EYEEEgdc7Hr/3Ix6xTaX83+gW7aOBHN+XuMNML0mN320HiZphUlILl+FNFG0fzfIcl5ATHjWeDSDguZzKQiOlj7K870QyYDp+jUyQVnPeh4aBIeoQwhFmk6nPcWNolCSeVHqFylF0sQc4j/3SzNvhgjO8=
Received: from BY5PR11MB4070.namprd11.prod.outlook.com (2603:10b6:a03:181::16) by BYAPR11MB3365.namprd11.prod.outlook.com (2603:10b6:a03:7e::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3477.27; Mon, 26 Oct 2020 21:04:27 +0000
Received: from BY5PR11MB4070.namprd11.prod.outlook.com ([fe80::8842:3f1e:4ffc:32c1]) by BY5PR11MB4070.namprd11.prod.outlook.com ([fe80::8842:3f1e:4ffc:32c1%3]) with mapi id 15.20.3477.028; Mon, 26 Oct 2020 21:04:27 +0000
From: "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>
To: Guy Fedorkow <gfedorkow@juniper.net>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, Dave Thaler <dthaler@microsoft.com>, "Smith, Ned" <ned.smith@intel.com>, "Panwei (William)" <william.panwei@huawei.com>, Mark Baushke <mdb@juniper.net>, Ira McDonald <blueroofmusic@gmail.com>, "Bill Sulzen (bsulzen)" <bsulzen@cisco.com>
CC: Jessica Fitzgerald-McKay <jmfmckay@gmail.com>, "Eric Voit (evoit)" <evoit@cisco.com>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] I-D Action: draft-ietf-rats-tpm-based-network-device-attest-05.txt
Thread-Index: AQHWq8GQITkCsaDsh0mSLCIxDC6kxamqTFeA//+cJgA=
Date: Mon, 26 Oct 2020 21:04:27 +0000
Message-ID: <25ABB469-D112-4592-BF13-C56F4725D6AB@cisco.com>
References: <160373503765.26087.6796865607217511838@ietfa.amsl.com> <BLAPR05MB7378D4884A906FD47F6657B1BA190@BLAPR05MB7378.namprd05.prod.outlook.com>
In-Reply-To: <BLAPR05MB7378D4884A906FD47F6657B1BA190@BLAPR05MB7378.namprd05.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.10.1b.201012
authentication-results: juniper.net; dkim=none (message not signed) header.d=none;juniper.net; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [72.163.2.231]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: bab1a581-a453-4841-9069-08d879f2b965
x-ms-traffictypediagnostic: BYAPR11MB3365:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <BYAPR11MB33655EF12B67EDBEE24D6CC3D6190@BYAPR11MB3365.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: XR/+VHg00486sFcw3MUKzoBRDMC2CcWhCf5zRS0HFyC0UWEO0jJ1RRLQKy9B+ZaividZpfYMFY4+4hVxq6jYt5Fuy+NhzVkcR1uc71hk6ApItBqO91iiyZ0VwMrp/Fk21JDB5l6jRsVdI6ObrqmTC3jImPDSYIMNma7oOSFJd6w3I/netfCCZZomYL3XFt5AoxG8VR2UTC3L1ObNtQgyAg+lrvC5jVz/kzsKnmh3h8GV7m3kW/inBveLYjvAsKGJRg88xS5PoHOctioLO4pAPx89lI5LpM6G2rTiouO3eYyfDn+Cro6664WnwauZOUkdFPff+Sp1Q73uOBhPH5r803p2M761OL08r50EKD/AuwwBMtCpgENi17JPJlopZF49DzxF7Jv1s53h+8nUCvcpQA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY5PR11MB4070.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(39860400002)(136003)(346002)(376002)(366004)(396003)(6512007)(26005)(86362001)(36756003)(4326008)(66946007)(2616005)(478600001)(110136005)(8936002)(6486002)(54906003)(316002)(76116006)(53546011)(66476007)(186003)(2906002)(91956017)(6506007)(5660300002)(66574015)(71200400001)(66446008)(64756008)(66556008)(6636002)(8676002)(4001150100001)(83380400001)(966005)(33656002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: BegEIMcAKNBw1fYT89Rz0HNHI4fqhfLPsGErVqfYf0EbyU1UtGJvWaDcF8QFtsnRQoNtW/zr0bv/3mAV6Mi8Lw3MrvCrJPbU9q697D411VLvzgmM3aSGLy5oFOFvzeUsEj3ofm+2WKJ6E0Ix/s4BrgY4nxmBsEVveqbg1igalMrm3PL5epDMLyue8dCsa6PrpAHvu6DmcMQwK5wXtBl+ZJeaWoVpyH2QSf2ZyQRdh/zuR/NduAy5QhBzCdH0IJlBvxjKSUfzhFoSmmOt7APsxyrJ1NzQx9SuFgPzH7+rYkcGtVi/3J78kxW5YePU5crEoxhSjb/6bDkE4aA1x2Hfu5Z/Daq27c1R18asmkaS7AmPBi9uQVfRaCTaTKAv+ShSRSL1LAieU+O8eD8V2JL3UFfj3CA1kJJRcjoTTQMqsYTfckLvah29P0/EY2VGjrvIuch8TOV6l+2v4WlA1qneH9wWZ2a60PM5SXVPN4fqFkb4mw5vOI6W7aU2v46QrBygRnljgYHwpDxStSrcfp2MaOD3ZyAye3udf5F9O5yH/SlfUFAMddi5q4UcRNR0rYgQP/UBybmXje1tsDdjCVFXGtLTKM4zwzyjSB3wA8YBCNcdwMW4ECdZNQOWayTM7g10Jp6Ozke8jmlOQAOfUAHeaw==
Content-Type: text/plain; charset="utf-8"
Content-ID: <4254C7D1CF658C4488B53A1650555531@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY5PR11MB4070.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: bab1a581-a453-4841-9069-08d879f2b965
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Oct 2020 21:04:27.1553 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: AVpyRqbwYmF885hyLtwbjLd8ndiCkjoY46O8FsiRNeCevu+QpKp29w5m7vB2aKW4ml8+sFmfQY8NuKLEJCAfVA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB3365
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.12, xch-rcd-002.cisco.com
X-Outbound-Node: alln-core-12.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/60E2Z1G_HHvumJzDmHTroHJVlJM>
X-Mailman-Approved-At: Mon, 26 Oct 2020 14:10:02 -0700
Subject: Re: [Rats] I-D Action: draft-ietf-rats-tpm-based-network-device-attest-05.txt
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2020 21:04:36 -0000
Hi RATs participants and authors of the draft-ietf-rats-tpm-based-network-device-attest document, Can you also please confirm whether or not you are aware of any relevant undisclosed IPR that may apply to this draft? Thanks, Nancy On 10/26/20, 12:56 PM, "Guy Fedorkow" <gfedorkow@juniper.net> wrote: Greetings colleagues, I've checked in the -05 version of the RATS RIV specification. As far as I know, this version addresses all the comments from WG Last Call, plus others from earlier reviewers. Please take a look, and if your remark wasn't addressed properly, let me know and I'll correct the corrections. And of course if anyone spots collateral damage, please point it out! Thanks all /guy Juniper Business Use Only -----Original Message----- From: RATS <rats-bounces@ietf.org> On Behalf Of internet-drafts@ietf.org Sent: Monday, October 26, 2020 1:57 PM To: i-d-announce@ietf.org Cc: rats@ietf.org Subject: [Rats] I-D Action: draft-ietf-rats-tpm-based-network-device-attest-05.txt [External Email. Be cautious of content] A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Remote ATtestation ProcedureS WG of the IETF. Title : TPM-based Network Device Remote Integrity Verification Authors : Guy Fedorkow Eric Voit Jessica Fitzgerald-McKay Filename : draft-ietf-rats-tpm-based-network-device-attest-05.txt Pages : 43 Date : 2020-10-26 Abstract: This document describes a workflow for remote attestation of the integrity of firmware and software installed on network devices that contain Trusted Platform Modules [TPM1.2], [TPM2.0], as defined by the Trusted Computing Group (TCG). The IETF datatracker status page for this draft is: https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-ietf-rats-tpm-based-network-device-attest/__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i7HIYHiPg$ There are also htmlized versions available at: https://urldefense.com/v3/__https://tools.ietf.org/html/draft-ietf-rats-tpm-based-network-device-attest-05__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i74K3PRzY$ https://urldefense.com/v3/__https://datatracker.ietf.org/doc/html/draft-ietf-rats-tpm-based-network-device-attest-05__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i7EVVqwYo$ A diff from the previous version is available at: https://urldefense.com/v3/__https://www.ietf.org/rfcdiff?url2=draft-ietf-rats-tpm-based-network-device-attest-05__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i7CSmkfSE$ Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. Internet-Drafts are also available by anonymous FTP at: https://urldefense.com/v3/__ftp://ftp.ietf.org/internet-drafts/__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i71-Q1Ydk$ _______________________________________________ RATS mailing list RATS@ietf.org https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/rats__;!!NEt6yMaO-gk!TB2y-zn6l6cA57KkgR_-lgmWRtPHcbBhAin0NFydKucXTTIvEY_o6fkG1_i7w-wSnkI$
- [Rats] I-D Action: draft-ietf-rats-tpm-based-netw… internet-drafts
- [Rats] FW: I-D Action: draft-ietf-rats-tpm-based-… Guy Fedorkow
- Re: [Rats] I-D Action: draft-ietf-rats-tpm-based-… Nancy Cam-Winget (ncamwing)
- [Rats] FW: I-D Action: draft-ietf-rats-tpm-based-… Eric Voit (evoit)
- Re: [Rats] I-D Action: draft-ietf-rats-tpm-based-… Guy Fedorkow