Return-Path: <jodonogh@qti.qualcomm.com>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id D09ACF108AAD
	for <rats@mail2.ietf.org>; Tue, 19 May 2026 13:52:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1;
	t=1779223964; bh=ndGcEXXnLKQbhRT0i7UQgKc+ku1Fe7O5LDYv3w4nICQ=;
	h=From:To:Subject:Date;
	b=l5ZznMkcIcreZ3CyFj7zJpJ0zdiF2JzZGE3uH2J1FUclfBOBvcKTMyac5n8j8LXnd
	 vmQXT+EWxEV2kN5zY/At073d9w+pASBmgtTrL1e80lLKW1m2LFlv92J2z/oTuggZFW
	 orMFs6kqJp2zV3/6YpDbwAmFf0m8QPncJhn4eqGI=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.695
X-Spam-Level: 
X-Spam-Status: No, score=-2.695 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7,
	RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001,
	RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001,
	SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=qualcomm.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 8-i03h6MhfHB for <rats@mail2.ietf.org>;
	Tue, 19 May 2026 13:52:44 -0700 (PDT)
Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com
 [205.220.168.131])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id 5D86CF108AA5
	for <rats@ietf.org>; Tue, 19 May 2026 13:52:42 -0700 (PDT)
Received: from pps.filterd (m0279867.ppops.net [127.0.0.1])
	by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id
 64JEwdUX1725320
	for <rats@ietf.org>; Tue, 19 May 2026 20:52:41 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h=
	content-type:date:from:message-id:mime-version:subject:to; s=
	qcppdkim1; bh=gw4z7vsUvJLkazBF2+3kxIe8jnTLDjUTrXelQja9o/I=; b=gg
	8Nk3IT7HIHaJIyYkdX1E500X7ug57l9aBkBCNSQqnxChSMCTYqrF2pUFbyiSnty7
	+cPlf8O6skmVqYOnQPo0o1X2uubrHUhq+0E9UKB8oDse6l7UK1WT9oVubNHDb6iw
	74/pOdYeS3lsH/MbtmKMEjpd4WTQuOVTcVZy0MWWoa2iiljeKgwsrM2mVlARYcOW
	fTWY09oMdsdNLRAp17sfp+ajFh3oWvZVKk36aMUWAdcsr1wW3xSigV2jFU6QFl2a
	BNFZJGTYI8e9dXtqEopcQKJQZEVSd8wwDgr2GwT5tfYMh8rnQ5UhQcdZnFqXqQxv
	aEVk4scL3RNExf3ISHKQ==
Received: from co1pr08cu001.outbound.protection.outlook.com
 (mail-co1pr08cu00104.outbound.protection.outlook.com [40.93.10.100])
	by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4e8t3qheu8-1
	(version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT)
	for <rats@ietf.org>; Tue, 19 May 2026 20:52:41 +0000 (GMT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;
 b=Wcw73K3zT79ZRabtxRwPZhH4sdlMCOBx+NcOHAr7CRJAfznWEJB6rMEkaLna7CJxVswKFWsMoH1BB6kTVqQL0GgcWaSvGcaYtqBdAET6Hg9LCPzOAZFcro/1G56mW5m35RRXoVbhhdEYYqXDLPzXGYdFYOBmG+L4bQlJPwoJR+QU26DL1cCXWe0R8ydMwLS98q5PDHkSsEZQn+FfWeN3BVZ1kpPIa992szq00Gk50DTjUfc2RTHNqSRJgeLK9kOdH+XLI3WCfs07u1Af8/6xu+3blb/dYIvThEpjXBloAX8JF35vaDClgcGF78R10P6OFl6ernBrg0rdfw+YQHGBQg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
 s=arcselector10001;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
 bh=gw4z7vsUvJLkazBF2+3kxIe8jnTLDjUTrXelQja9o/I=;
 b=hlv1+2LEuzxNz86FHsviu2916Gk9llU4IlGxfxn8B2Q2mfzyneC/EGgKvHAizZ3+uxcaRH6WKXY8+bORa2JictyCgKr47XhypN1yXrsK6cqAkwWsMZAVG3KABl8HX0fWlkCExY4NykBRSRrc9sqC80TpgmKXAbd5nEAz+D2cvo/E4qjxRsZeFkn+CcE8vhKpOQc0Hx8B+V0E4KegxkxBg3vii8Eff7wY/yg1dyKRBl6DFBIgw+0LlFnNd0Uzem3St5hT9rlvHudjzIDwhyl+dEp1kqIQ8x/1ZNfwRB72l4ASnkn4k19Rf/+BNHlL3eK7KJb2q0SIerliYqT8whIPgg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
 smtp.mailfrom=qti.qualcomm.com; dmarc=pass action=none
 header.from=qti.qualcomm.com; dkim=pass header.d=qti.qualcomm.com; arc=none
Received: from DS4PR02MB10844.namprd02.prod.outlook.com (2603:10b6:8:2ab::21)
 by DM8PR02MB8139.namprd02.prod.outlook.com (2603:10b6:8:1c::14) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.25.23; Tue, 19 May
 2026 20:52:38 +0000
Received: from DS4PR02MB10844.namprd02.prod.outlook.com
 ([fe80::723c:4b42:2f11:ba]) by DS4PR02MB10844.namprd02.prod.outlook.com
 ([fe80::723c:4b42:2f11:ba%3]) with mapi id 15.21.0025.022; Tue, 19 May 2026
 20:52:38 +0000
From: Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>
To: rats <rats@ietf.org>
Thread-Topic: CoRIM signing
Thread-Index: AQHc58/jYyGqGiLLhkaoKx0Wo0FeAQ==
Date: Tue, 19 May 2026 20:52:38 +0000
Message-ID: 
 <DS4PR02MB10844919EA0D15D844AC65D23F2002@DS4PR02MB10844.namprd02.prod.outlook.com>
Accept-Language: en-US, en-GB
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
msip_labels: 
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DS4PR02MB10844:EE_|DM8PR02MB8139:EE_
x-ms-office365-filtering-correlation-id: a9d1bd7d-d510-4e74-dc99-08deb5e8900b
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: 
 BCL:0;ARA:13230040|376014|366016|1800799024|11063799006|38070700021|8096899003|18002099003|56012099003;
x-microsoft-antispam-message-info: 
 wmz9xZSgHCMIhTIIqxwa/hvZhPI1EzbbVAD74Sa+iSbLyPyMn/t+0zhiOIaxRz2tfCw8Kh4B63a50yuLQyNi5NXiQzOUHx2rzcHc3zj3j5OqndHKzDXRE8kOFaaYemsP4CbJ0blaYZA8jQyCh/IPN5xXSEakRhbqerpmKLJ6AVyitXf5D/n/0uDrpW0fyIwobMiHcVXKCKrDkJKGwSa8sEYWU0EX92ROWLI+fuxkSa7jalnrlb3eKzaO3+gO/bLPFu310hNWfvVL1aCldD9Tzm3qV5l5tHs7IPITslh7gUTPFN1GYOSAABqS55ouF0yVVs/rFFACYV6Kn8FD9sQNr/kOsTQ/yWfAMlKNIyusSSQi4Vg6oCKNUhk2xnbvESpnCQH20H5Sdn/RCoSuqken1TqKtMvng8jF0CyuSFmT21M3rFuLiosT2Cet3PaMw6LxgZ1PrRpiaxjOhqMdmqaFHqVB0W15Z+0mE+I0ID8CJOXZBfXQFfYP5AG5iF3nH9bmVaqp6GRYLXGN1T7KCoeWHOxa1h4dFpDOJVe1zNowv4lgTrh8PO/EK3jgF9Z+5ab/uloU8EzP+G2rlw0W8Dlm75XgjAacxzbAZXwBQeQJcuFBojGeIngoN/oMNSIZ65Pm94ElCIsNpUkzGqAWTkBdfsREKg1ZJBl9077k9TLxNjSaVbYKer0pzgnldmNRm3rECePAQ6czH9x+0svJw3dImOp4dmg/khAlqMK+2I76HyWWBBGm6acAbCcVF/J+BehP
x-forefront-antispam-report: 
 CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DS4PR02MB10844.namprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(11063799006)(38070700021)(8096899003)(18002099003)(56012099003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 
 =?iso-8859-1?Q?aTB2qBYp8449VOSV8ujVWZMozcSdsflx8gSkCfWGuEruXHRPcpRtz4W0Ud?=
 =?iso-8859-1?Q?V/QqB+pP4TeYyLJoHWFbtYhI+VMyM04WsjpgLXfmQtzSo1Rr+rOpt1aT0y?=
 =?iso-8859-1?Q?IcaS8aoBobFcQPnCYR/ouNpj4WAkywuDGdjBjQvkVYdVLq84D+CGK4ZrLY?=
 =?iso-8859-1?Q?1g9DYp2Txqlbzaq7ErP5bErqXZM3Zx3s/CyBc62eAwB/wTMHFhVsBS3evn?=
 =?iso-8859-1?Q?Op/i538O1P+vT8GuCUBN4vKus2nWm+SpXAbs96aDzhg9whbdYPzEjoyj8v?=
 =?iso-8859-1?Q?QleX6NgqJMQQsvjPDkuYGM9cMYi2cTpY8MxZoNOBVjhyJVMcQfaOb3pb+f?=
 =?iso-8859-1?Q?fTRx9Wc7zLIf3GYePYGH7s45wdTRt8keaIHr4iL2KhxmMXOefJiaQQq7v1?=
 =?iso-8859-1?Q?s85B1I+hCADQ+VJQnvMwK5g+OndvaKAbaaVEyYNoywU57j4KobVPwAitjO?=
 =?iso-8859-1?Q?DsK5lpBcvXu6lN1oqFkiCazQ+jGKpdqYnIKZcoRNX8gOxMGWR8kQ+RMxfT?=
 =?iso-8859-1?Q?mseKah0858kzpXHkGlMclhtbmf/vgUXJQPkL2N05E/gWYC9Zayec5mYhEq?=
 =?iso-8859-1?Q?1PLhXffe8X7LIw+UXcteZRp1o4T/FwzdaiROjXBdpm2gRrqVO7qaGw1IZj?=
 =?iso-8859-1?Q?yj7A0v2TChQwbiy8+De+WFzqpdKjLhtec7pz5J6z6cMmziMGHdw5NG9knj?=
 =?iso-8859-1?Q?KE411Mkze2VjKvLACUZtmzW7ckDDgR5G9B93k4XVYiXaU248UOTx0/8mAL?=
 =?iso-8859-1?Q?ra9eRVpXM5a6Se+LcTR/NXHF093hoVSmJJJ63q9ZsgMA25V2EJD83Go5UO?=
 =?iso-8859-1?Q?9ZW0YI68r05PY57tiII+E8Pr9ZwHUjWlsTQCAZ6V/q+yY/segVf2Igr6fZ?=
 =?iso-8859-1?Q?EB6DVXDW4OttO4emuzv+1/syIGQgr2O55quWk5xS8vy6zTqC/Z+3ruZiUS?=
 =?iso-8859-1?Q?hyhE7JIlKnYfj7pFhDQl1ezmAUzOBUKgK/AAnn6A5iWMJSb3s3MVKZEXJQ?=
 =?iso-8859-1?Q?IcS6K+yW64NYM+QDJh2pkhV6mmQvuJ5A3WivLmzc3ciZbzzYKy5hP511Rc?=
 =?iso-8859-1?Q?ndpvlOvKtSAbG1ax6IwbGvtcqK5MpOUyS5tvs+MtdAZvSx/g2hqFybQsi5?=
 =?iso-8859-1?Q?qc0GiLeNAny6hsXDCMWLD/1UwK7EHh6utiytq4Eo6MlaN0VwAtCCrPvm/k?=
 =?iso-8859-1?Q?AXJ92nxR6e0Ju8HbPZ4x75V9g59U0f3QQiuDKucrcoyXSp9TFYHxPXLEnF?=
 =?iso-8859-1?Q?RTYKkdPbhhCcp8rR16FXA0Ej11TNuU5F1zCeFZfhOHJqteNygbPB7xaEAQ?=
 =?iso-8859-1?Q?xnJQBQVh6ffKnQfkXtpi+O1hpv+UOQz25ODodoKTmDNIkdt7nfjQuOsOBu?=
 =?iso-8859-1?Q?7U5R+VhA+NgHQlKm2/Ij8bphaK4IgvgxP87F05MHiDSjVgNPM2Ow0gC+nR?=
 =?iso-8859-1?Q?8nB/DSja2YQnAUz79qcLc4PC1qd2oYxLKV6ANyTseDwSy2lq7hsEi5bZ9r?=
 =?iso-8859-1?Q?DK4KRcV4owH40qXgZJmgroriGEFIRSPuxbMjLNXe1RINqASg7n9vGXqUsu?=
 =?iso-8859-1?Q?I3FH2HdImji7q/ih4rWJzNK65g2k5F/r0oVHeS4cs0NoqFF9mPNbFBSQa4?=
 =?iso-8859-1?Q?nSVg/KGduWgHh4965ovojnSpkgoOYGo6PTlP2MDJWHBEKe8beva/WNqvEA?=
 =?iso-8859-1?Q?TiTXLjyUbTxao8VyOgFxz6+OB3TLF1g1kOFIXLo49zE2B4eG8p5VeajkfY?=
 =?iso-8859-1?Q?wdBYHGdtSegx4iExcy13dVDnGLgiGN7DBWk+RlT7BAlgG2YZFoGi4Kg6wF?=
 =?iso-8859-1?Q?+ahZfJM1pg=3D=3D?=
Content-Type: multipart/alternative;
	boundary="_000_DS4PR02MB10844919EA0D15D844AC65D23F2002DS4PR02MB10844na_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: 
	gEAqKC5cXu9VDyvkhtDy1JD6QQr1ekBZFx5ZtLmXwYjG7x+E02PT1DGDbFitJW2CCGvxyw5NFoMpc9Gh+Th7UNqmzodf3j3YsTYXXOezG8YRA9vVTCVxdTz9jnst8IOwPsM8Bq1N8naYR2xWzCr/BXLWDUXMPn+bT5liTEiEQKEsD/BHQFS8I8KbEuffwpuV8/4KOqPZijqWkUV2nkAC7aKgVBmiGqj3/BImdWQZt6gpnB/9TYK4TIpGvXKh0N0UzVqiyj2h1Xok3x9gzzsbh1IAHSoqvO7EGjtMffv9wiIKAYw1CkbtYf9UF20ww3UGRzFAvPr9jUx2vHcY8yvEYA==
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: 
	aEiGZ6edPx1EVcXlVRbwo3VPjVgWjFkHQkznvrFEkTlHS0ufoM48UpzJ0kLplIBsffiWoA6UJR/giqD2qZ21h5j084huwxnod50xZ3b5+Gf3xssEsJtuswLYjX5XiEvt/3fi6OBbA8fpccfQyyhpkay0crWpvQyIyYh4lSkTayfWU2LTgPQ3KH66oIs2i81Z2OkwNVX4syGocNHUjsBWqd3nC/7EmQcgbS2eYS8aFInSpxL5tAozILetWbPA3okLZSCGaUy7egBu4dVpgtnFw6hZOrVCUkk8HlEfFWtwWUaqMAsl7DhJAh+QuA4Lcswu1u1WRm9Yxc3DfwFrKcRW89BjgBD1w7nLR126hflg60PVaWSRhYrlU+LUddpUXOknAeJzOg7Q3sibgthXIA8d4h0hUrvi5EiAN/AFwvzP/iZMcGz5PnnmUyrpsSzDZjfriVcgrSWfqypz6WZJNDGPz7g0Ysq/wT2R7WkffoeIcucu47CGxcEDJut45QJ/MqOLupmmVbKipWkxvts3fOW7K47QI7yfE3YNdqP8DLEeM90+ihBNjivtdSbBZGIU8oRB2VtZwcOEKmZ2JwG7W41jTSHc/25CL7ZHGUELChaJ6Wz9J7g8iAdTfvvmA5jqk5Hi
X-OriginatorOrg: qti.qualcomm.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DS4PR02MB10844.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 
 a9d1bd7d-d510-4e74-dc99-08deb5e8900b
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 May 2026 20:52:38.6870
 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 98e9ba89-e1a1-4e38-9007-8bdabc25de1d
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 
 qlZChfG85VssdB9p3PxCqsd0nTM1bnhm7daCqctEOYW1pRJT4BgscV68E91GsaH1X/2PZXPH3l3kxMeairRF9Goo3/76xlcPEp0cdnfc8Jk=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM8PR02MB8139
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNTE5MDIwOCBTYWx0ZWRfXycJnHZIYQigE
 +9r6VEepr55IuGIQT531/s7KhUpBLqz605rFSMMMQYFWmFmFz2rAV5efqnl9Dn1I9pVLLTCS2MN
 wcODEeRwBGz0ilqk9+bzGxP96eawgATWBgn2VK6+Rb+Z5i1mNqsQYz+g00rBm4pCyws6Yty6jxO
 RsxMShscDu2ayDWraec9CBvoUmhb893xVmFlUNY+u9M8gEFf3ERr8ARK4EyRv++tAsrainx1iBZ
 MF+qiVFD/N5ZLlQSq/Rsk2mv5hCZAOGT/zlQudowbwnVH0Veue53Gjc6X+zLSzWrf2R8FJklAGy
 46itQYVM/Zxyx1ddZ/cbxb+gI5f4rOJhRhS86lmpzkfkuBke78nJC8UIiUJbzeEOPAdhEtJKyil
 n0gEQPVwkrsVqaPUDbQcNRQ0ODUQyTjBnWYn6ix37DqtSWcKijSAe5r+l3/ZL6h2tEZ3Cd4suJf
 HvuhUdmRAkaTebH0JfA==
X-Authority-Analysis: v=2.4 cv=N9cZ0W9B c=1 sm=1 tr=0 ts=6a0ccd99 cx=c_pps
 a=vSKo55tUflx2CybR9Niq7g==:117 a=z/mQ4Ysz8XfWz/Q5cLBRGdckG28=:19
 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=xqWC_Br6kY4A:10 a=NGcC8JguVDcA:10
 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=eoimf2acIAo5FJnRuUoq:22
 a=t7SGAzXjczZrgDhsc44A:9 a=wPNLvfGTeEIA:10 a=VUH9XsewnSWWKEQW:21
 a=frz4AuCg-hUA:10 a=_W_S_7VecoQA:10
X-Proofpoint-GUID: 52qIkHQCaE1iTQq5qORi61Jti_sRkgpC
X-Proofpoint-ORIG-GUID: 52qIkHQCaE1iTQq5qORi61Jti_sRkgpC
X-Proofpoint-Virus-Version: vendor=baseguard
 engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.51,FMLib:17.12.100.49
 definitions=2026-05-19_05,2026-05-18_01,2025-10-01_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0
 priorityscore=1501 impostorscore=0 adultscore=0 lowpriorityscore=0
 suspectscore=0 malwarescore=0 spamscore=0 phishscore=0 clxscore=1011
 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound
 adjust=0 reason=mlx scancount=1 engine=8.22.0-2605130000
 definitions=main-2605190208
Message-ID-Hash: 2YBCGBCQ3HTZQGOBLLWM7NYG4JTYYI33
X-Message-ID-Hash: 2YBCGBCQ3HTZQGOBLLWM7NYG4JTYYI33
X-MailFrom: jodonogh@qti.qualcomm.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-rats.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BRats=5D_CoRIM_signing?=
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/rats/C7P9mvQgjTS708iZOL4E_1TNJmg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>

--_000_DS4PR02MB10844919EA0D15D844AC65D23F2002DS4PR02MB10844na_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hi CoRIM editors,

A couple of points on draft-ietf-rats-corim-10.

I believe there are valid use-cases for a Signed CoRIM to have multiple sig=
neds (i.e. allow COSE_Sign in addition to COSE_Sign1.

An example of such a use-case is a dual-signed artifact (e.g. signed by a s=
ilicon vendor and an OEM, or both classically and PQC signed). The alternat=
ive would be to produce separate sets of CoRIM with the same payload.

I believe this would be a straightforward change.

In addition, I have a question on the text:
The ref-claims in a reference-triple-record can contain one or more entries=
. This multiplicity can have different meanings:

  1.
Each ref-claims entry can represent a different possible state of the Envir=
onment.
  2.
Each ref-claims entry can represent a possible state of a different measure=
d element (identified by its mkey) within the Environment.

Note that the same semantics can be expressed using multiple Reference Valu=
e Triples.
Allowing different meanings for the same record seems like a recipe for int=
eroperability problems in future. Is there a good reason for this rather th=
an either defining a new triple (dependent-value-triple-record) or simply u=
sing multiple reference-value-triples.

Best regards
Jeremy

--_000_DS4PR02MB10844919EA0D15D844AC65D23F2002DS4PR02MB10844na_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Hi CoRIM editors,</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
A couple of points on draft-ietf-rats-corim-10.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
I believe there are valid use-cases for a Signed CoRIM to have multiple sig=
neds (i.e. allow COSE_Sign in addition to COSE_Sign1.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
An example of such a use-case is a dual-signed artifact (e.g. signed by a s=
ilicon vendor and an OEM, or both classically and PQC signed). The alternat=
ive would be to produce separate sets of CoRIM with the same payload.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
I believe this would be a straightforward change.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
In addition, I have a question on the text:</div>
<div id=3D"section-5.1.5-8" class=3D"elementToProof" style=3D"text-align: l=
eft; text-indent: 0px; margin: 20.8px 0px 20.8px 3ch; font-family: Aptos, A=
ptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
The <code style=3D"font-family: &quot;Noto Sans Mono&quot;, SFMono-Regular,=
 Menlo, Monaco, Consolas, &quot;Liberation Mono&quot;, &quot;Courier New&qu=
ot;, monospace;">
ref-claims</code>&nbsp;in a&nbsp;<code style=3D"font-family: &quot;Noto San=
s Mono&quot;, SFMono-Regular, Menlo, Monaco, Consolas, &quot;Liberation Mon=
o&quot;, &quot;Courier New&quot;, monospace;">reference-triple-record</code=
>&nbsp;can contain one or more entries. This multiplicity can have differen=
t meanings:</div>
<ol start=3D"1" style=3D"text-align: left; margin: 0px 0px 0px 6ch; padding=
-left: 0px;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); margin=
: 20.8px 0px;">
<div id=3D"section-5.1.5-9.1.1" class=3D"elementToProof" role=3D"presentati=
on" style=3D"margin: 0px;">
Each <code style=3D"font-family: &quot;Noto Sans Mono&quot;, SFMono-Regular=
, Menlo, Monaco, Consolas, &quot;Liberation Mono&quot;, &quot;Courier New&q=
uot;, monospace;">
ref-claims</code>&nbsp;entry can represent a different possible state of th=
e Environment.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); m=
argin: 20.8px 0px;">
<div id=3D"section-5.1.5-9.2.1" class=3D"elementToProof" role=3D"presentati=
on" style=3D"margin: 0px;">
Each <code style=3D"font-family: &quot;Noto Sans Mono&quot;, SFMono-Regular=
, Menlo, Monaco, Consolas, &quot;Liberation Mono&quot;, &quot;Courier New&q=
uot;, monospace;">
ref-claims</code>&nbsp;entry can represent a possible state of a different =
measured element (identified by its
<code style=3D"font-family: &quot;Noto Sans Mono&quot;, SFMono-Regular, Men=
lo, Monaco, Consolas, &quot;Liberation Mono&quot;, &quot;Courier New&quot;,=
 monospace;">
mkey</code>) within the Environment.</div>
</li></ol>
<div id=3D"section-5.1.5-10" class=3D"elementToProof" style=3D"text-align: =
left; text-indent: 0px; margin: 20.8px 0px 20.8px 3ch; font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0);">
Note that the same semantics can be expressed using multiple Reference Valu=
e Triples.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Allowing different meanings for the same record seems like a recipe for int=
eroperability problems in future. Is there a good reason for this rather th=
an either defining a new triple (dependent-value-triple-record) or simply u=
sing multiple reference-value-triples.</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Best regards</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Jeremy</div>
</body>
</html>

--_000_DS4PR02MB10844919EA0D15D844AC65D23F2002DS4PR02MB10844na_--

