Re: [Rats] Call for adoption (after draft rename) for Yang module draft

Guy Fedorkow <gfedorkow@juniper.net> Mon, 25 November 2019 15:21 UTC

Return-Path: <gfedorkow@juniper.net>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8AA4D120105 for <rats@ietfa.amsl.com>; Mon, 25 Nov 2019 07:21:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level:
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=hsDFryzm; dkim=pass (1024-bit key) header.d=juniper.net header.b=R0zxJlbv
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ApCDgYi93Umw for <rats@ietfa.amsl.com>; Mon, 25 Nov 2019 07:21:36 -0800 (PST)
Received: from mx0a-00273201.pphosted.com (mx0a-00273201.pphosted.com [208.84.65.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08CC81200B3 for <rats@ietf.org>; Mon, 25 Nov 2019 07:21:35 -0800 (PST)
Received: from pps.filterd (m0108159.ppops.net [127.0.0.1]) by mx0a-00273201.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id xAPFHumu008505; Mon, 25 Nov 2019 07:21:35 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=PPS1017; bh=9IkPSr49HIJwEeXg3BkJxLD+1m93xcdh3ducf+mWj8M=; b=hsDFryzmhmonO7D+OngqZk9gFeofDNWuYYxLK20x60b64ocEbLJV6X2bjKnAwzm1GyI/ 4LVwvSkUyo4ArUl0rSJbu9WeWH6d2oYrb3kuQlQJ5rAmriDsVUuOdIqpTwBC8GpI402y LeW1yG+k9sklC2QALmYR6pdwdV6IzPsDLL3UsMeOULbPqqMElon9J6eMFiJaiF6mGQFK hnYBAN/QQ7dlq43wXVP6Nn7/RHs8UJtIiQjWHJVCw6S3khL5hLQbAp3ZymbrVFX34Ukx CYPewDPS6KNep/ZXnzcMCJC1EOy7Eevp7/XS3aJQJvcqBIpF4p9F7kLpX202iqG7Med1 0A==
Received: from nam03-dm3-obe.outbound.protection.outlook.com (mail-dm3nam03lp2050.outbound.protection.outlook.com [104.47.41.50]) by mx0a-00273201.pphosted.com with ESMTP id 2wf3m03107-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 25 Nov 2019 07:21:35 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AtQt5KgMHS1EgRzmxJ7SF77JaMSPz+qS6xNghiySCRbQLsy55jxHiHwVSxRLqiUtxoT1azeClMhLI8JIfz2eJ+QM95d2sgvzLjpRl9lEd6Crp5JRfJrGPjCZUGTYj5hL+NUh7jPAb4BGyX9VOfAUKtNmoectV+4STm5SeUm9AnhgZzwIlV8j2nb07ia02AElNRrtuuZ2A9V2toeP7gwAo/KNgD4Jv8A5I0Un11q0wvKfb0SHxZ495nvwkIbyrgFz9Ja3SNxYpt4tVHQRWRMrUgDRdmz5mIfpQpNUz0kO2GHSwqdAUDjuoI5uqEw/k832/oFaHjbv1IAELz2DsLITFQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9IkPSr49HIJwEeXg3BkJxLD+1m93xcdh3ducf+mWj8M=; b=lSQS3JB7KU65pi4c64x4wj0BZccCCVumuXXY5j2zZ2E3aE7yp6FL5WfYiY6rAVm8F4TEMVDgH7O7tHknxOayGySlvIVZkT64SfZ25vMiKMNEJOSjZr33YKEyXrZ9VvMt1+/M+dLV7gjLo1y8Wv3ea8vNzoM88GWqsDjp8fyWqTl8YhCy2oBbXtEfDxj8t3jy/P4DBg41lmmsgFCJrWWgdRrgooDw7sZO8D8W5MXG8On9/bFQVnF0LSmjEK8NVbJmUChpbRzVjnm075DTlzXTYIa/+sCa1bG3NF/oL1jtcXChigXxut/q4z6zTdAfY6ExGbu+Ifv+qfkvuno+mAvHvQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=9IkPSr49HIJwEeXg3BkJxLD+1m93xcdh3ducf+mWj8M=; b=R0zxJlbv4V6VOHprOnWU/y3kpxDZDcyXX5ao2/84uK/yVEGwd3VnY+iyVYBV35Kof7Idwc6/GX6uNyh/mIWgkgzeL0u0id4zhmxLbQzSJFq2yhKZGm8P5emz94KwCIx9Mcy5YJ3ZvlOY4PK+wBsuo3OyMZ7nS/XKfAEpFDZuhzM=
Received: from BYAPR05MB4248.namprd05.prod.outlook.com (20.176.251.147) by BYAPR05MB6295.namprd05.prod.outlook.com (20.178.50.80) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2495.13; Mon, 25 Nov 2019 15:21:33 +0000
Received: from BYAPR05MB4248.namprd05.prod.outlook.com ([fe80::457d:474a:1f33:9a2b]) by BYAPR05MB4248.namprd05.prod.outlook.com ([fe80::457d:474a:1f33:9a2b%4]) with mapi id 15.20.2495.014; Mon, 25 Nov 2019 15:21:33 +0000
From: Guy Fedorkow <gfedorkow@juniper.net>
To: "Smith, Ned" <ned.smith@intel.com>, Michael Richardson <mcr+ietf@sandelman.ca>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] Call for adoption (after draft rename) for Yang module draft
Thread-Index: AQHVlCwI8/lytau3hU+AhCwtIdg/0ad+jL2AgAAHhQCAAAO1AIAF46wAgACM2YCAAJAzgIAAtdsAgAB9XUCAAqYNAIABt5oQgA09+gCAANUuAIAC4dUQ
Content-Class:
Date: Mon, 25 Nov 2019 15:21:33 +0000
Message-ID: <BYAPR05MB4248CE2260A526DE940D0E3ABA4A0@BYAPR05MB4248.namprd05.prod.outlook.com>
References: <8B173958-FC2A-4D1D-A81C-F324AB632CD7@cisco.com> <147F9159-6055-4E55-ABDC-43DFE3498BF1@island-resort.com> <ce5f8206-74dc-36bb-0093-a93045d5c67f@sit.fraunhofer.de> <0A7E3A4F-8534-4E98-BCB7-1454E07699F4@island-resort.com> <C3AE2645-49C8-4313-BCED-02FEB576B614@cisco.com> <1C8A1884-A37D-45E3-8C11-2FC5A083B245@island-resort.com> <HE1PR0702MB375366C5F7FE5C497C35D73B8F740@HE1PR0702MB3753.eurprd07.prod.outlook.com> <7106C9D3-8ED1-419E-81F8-4CDA799BEDAE@intel.com> <MWHPR21MB07844F61BEFAE03F9E7DD290A3770@MWHPR21MB0784.namprd21.prod.outlook.com> <6E7D64B4-2049-4D0A-ADC5-CA3F0647779B@island-resort.com> <MWHPR21MB07840B6CF7BEE0A11ABE54BFA3700@MWHPR21MB0784.namprd21.prod.outlook.com> <10511.1574490818@dooku.sandelman.ca> <8363AFEC-C92C-466D-8F2C-CE7A3E94370B@intel.com>
In-Reply-To: <8363AFEC-C92C-466D-8F2C-CE7A3E94370B@intel.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled=True; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId=bea78b3c-4cdb-4130-854a-1d193232e5f4; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Owner=gfedorkow@juniper.net; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate=2019-11-25T15:21:31.7996436Z; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name=Juniper Business Use Only; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Application=Microsoft Azure Information Protection; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId=49814622-9f1d-4187-a703-0720dde41898; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Extended_MSFT_Method=Automatic
dlp-product: dlpe-windows
dlp-version: 11.3.2.8
dlp-reaction: no-action
x-originating-ip: [18.20.166.171]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 69b73f26-4989-4b3f-3576-08d771bb27bd
x-ms-traffictypediagnostic: BYAPR05MB6295:
x-microsoft-antispam-prvs: <BYAPR05MB6295D402982AC98EBB4E48D1BA4A0@BYAPR05MB6295.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:6790;
x-forefront-prvs: 0232B30BBC
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(346002)(376002)(396003)(39860400002)(136003)(366004)(13464003)(189003)(199004)(7736002)(66066001)(66946007)(5660300002)(52536014)(66476007)(66446008)(64756008)(66556008)(76116006)(81156014)(81166006)(9686003)(6306002)(110136005)(99286004)(316002)(6436002)(229853002)(8936002)(55016002)(14454004)(8676002)(33656002)(256004)(71200400001)(71190400001)(478600001)(7696005)(186003)(76176011)(2501003)(966005)(86362001)(11346002)(446003)(6246003)(3846002)(6116002)(2906002)(305945005)(26005)(25786009)(102836004)(6506007)(53546011)(74316002); DIR:OUT; SFP:1102; SCL:1; SRVR:BYAPR05MB6295; H:BYAPR05MB4248.namprd05.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: SSyzTswuXEvG6WMg5cWMkZJ+bZxQv2sdP7sLP+lOlhKQfJmDS9Ft84bfM3ic2xHty6iwhapdqjeaO/XBRESyLMK9t2gZFWDCeD7rP692rXMCoeihJXdwdpdo9SSAEqgK0l67gvRN5FO4UClOrsJDKER/eaL7TQ6+2g/NS1CcSAuRpx+BRihCMsHJ9OUwzTagb0DHw9pHDQ8HVayrEuqPDD7wL0s0OfJmIHFtfFnuqZw9WYsHxudF+OrK1GzaVQTcwbnBLUYi7IJ2IwcA+tdbsLAXSo2B3bpn5TlbBSoYktRLgcFOnmoB8eXK5fLMmhpTLGlHEIfqtm5pUApBFhab6jEQuNZTFUoqpTwgosLPZwrUBnz6HlsWFdPDAMSV6z8L1HrJfj64m/tFL0GOasak4jXiUCYeL1NjSyj19LSF3OdwYH404RMmr6c+q+XmdEtmsGep5rYaoL6yTjyUjxKwZPfkc0gZ2RShggnHoPPaqe8=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: 69b73f26-4989-4b3f-3576-08d771bb27bd
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Nov 2019 15:21:33.5059 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: i1Tt9erBlPrx9yEkqWzFlwGvtEhbvuHUeodAgLq7TS4j7+r2Wg25WZHRGOrrB6Kr6zg6tr26EbL6I62BwIv1VA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB6295
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-25_03:2019-11-21,2019-11-25 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 malwarescore=0 priorityscore=1501 suspectscore=0 bulkscore=0 phishscore=0 mlxscore=0 clxscore=1015 spamscore=0 adultscore=0 impostorscore=0 lowpriorityscore=0 mlxlogscore=953 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911250137
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/8h1udiFVPZSZ2hy5yhF_Yi6Vlac>
Subject: Re: [Rats] Call for adoption (after draft rename) for Yang module draft
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Nov 2019 15:21:37 -0000

Hi Ned,
  The Step Zero I've been keeping at the back of my mind is RFC 8572, which already has a number of complicated mechanisms to reach out and obtain configuration information.  I think a RIV-style attestation exchange could be added to the steps without deleterious interactions.
  That's not to say that RFC 8572 is the only applicable environment, it's just one that seems like a good match.
  /guy



Juniper Business Use Only

-----Original Message-----
From: RATS <rats-bounces@ietf.org>; On Behalf Of Smith, Ned
Sent: Saturday, November 23, 2019 2:17 PM
To: Michael Richardson <mcr+ietf@sandelman.ca>;; rats@ietf.org
Subject: Re: [Rats] Call for adoption (after draft rename) for Yang module draft

The step-0 protocol may have payload size or timing limitations that prevents fully attesting. This is the case for 802.1X ethernet ports. 

On 11/22/19, 10:33 PM, "RATS on behalf of Michael Richardson" <rats-bounces@ietf.org on behalf of mcr+ietf@sandelman.ca>; wrote:

        > discoverable by the Verifier.   That step could have included the EAT
        > or the TPM data
    
    I have a todo item to write up:
      1) a use case for Attestation at BSKI onboarding time.
         (really this is a RIV sub-case, I think)
    
      2) a document explaining how to carry EAT in BRSKI voucher-requests and
         RFC8366 vouchers.

_______________________________________________
RATS mailing list
RATS@ietf.org
https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/rats__;!8WoA6RjC81c!WBOTLYKwF7oGS_PDI_8B6397ox_eo22P68lVRLKBHlP2nNJzBT67iO4pPLrQmQ6zj9g$