Re: [Rats] draft-ounsworth-rats-x509-evidence-00

Henk Birkholz <henk.birkholz@sit.fraunhofer.de> Thu, 09 November 2023 14:43 UTC

Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6848EC1522CB for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 06:43:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.598
X-Spam-Level:
X-Spam-Status: No, score=-6.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, GB_ABOUTYOU=0.5, NICE_REPLY_A=-0.091, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sit.fraunhofer.de header.b="5KqrDulm"; dkim=pass (1024-bit key) header.d=fraunhofer.onmicrosoft.com header.b="pi271mzV"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gP8aKutK9Lnr for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 06:43:27 -0800 (PST)
Received: from mail-edgeka27.fraunhofer.de (mail-edgeka27.fraunhofer.de [IPv6:2a03:db80:4420:b000::25:27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA99FC14CE2C for <rats@ietf.org>; Thu, 9 Nov 2023 06:43:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sit.fraunhofer.de; i=@sit.fraunhofer.de; q=dns/txt; s=emailbd1; t=1699541007; x=1731077007; h=message-id:date:subject:to:references:from:in-reply-to: content-transfer-encoding:mime-version; bh=5eISQI+5a14HGUs0+FqpRwbaaiRmSewNC2h0yw9b+S4=; b=5KqrDulmSeaoEm7QXLmyKOl8+eRoW3M2oHRRdvin/Eo1WPO0MKflE3bf wXfOOfI1MS1JWyoefyH2omkgYZVHnGUgxnGD0GHy4YSiseqNSTAd67AGI qfPefyUY0H7DnmHOg7Ky0BrzOnGW+KkLX5MJLW7XdEPUiZUdU1h7eY6mQ vLgqT31gSfLDkNu2j0bJ2LbdhZOivYy4DMvbYgjr+7wsTW4+qORcfqfjk tvs7J55NBFxe1kmUzn4JC9j/Tzb+aAYBnjReh0h9//ExGk7W0RrAhF/0R pZ3gfiK8SAFe49YY4F4DuifjgKqlfKOPYp1fULKuQFaOafrSIPNTlnBsC Q==;
X-CSE-ConnectionGUID: pB/Nu8lZTo6bD1WoImXfnA==
X-CSE-MsgGUID: tNFJu3rNSnOIyMilnPozow==
Authentication-Results: mail-edgeka27.fraunhofer.de; dkim=pass (signature verified) header.i=@fraunhofer.onmicrosoft.com
X-IPAS-Result: A2HgAwDV7kxl/x0BYJlagQmBT4I5eoFdhFODT41iLQOcUoEsgSUDLh8JDwEBAQEBAQEBAQgBLgsLBAEBAwEDhH8ChygnNAkOAQIBAwEBAQEDAgMBAQEBAQEBAgEBBgEBAQEBAQYGAoEZhS85DYMWaoEdAQEBAQEBAQEBAQEBAR0CDSgMDRsBHgEBAQECAQEBIQ8BBQgBASwMCwQLEQQBAQECAiMDAgInCxQJCAYBDAYCAQGCegGCKgMOIxSsFnqBMoEBggkBAQaBB1BBrggYX4FfCQkBgRAug1yELgGKBxcfgVVEgRUnDoJ1PoIfQgEBAgGBOwEBg3uCaIZjggMVLgMEMoEKDAmBA4NSjUNdIgVCcB0DBwN/ECsHBC0bBwYJFBgVIwZRBCgkCRMSPgSBY4FRCn8/Dw4Rgj8iAgc2NhlIglsVDDQERnYQKgQUF4ESBGobFR43ERIXDQMIdB0CESM8AwUDBDMKEg0LIQVWA0IGSQsDAhoFAwMEgTYFDR4CEBoGDScDAxNNAhAUAzsDAwYDCzEDMFVEDFEDbx82CTwPDB8CGx4NJygCNUMDEQUSAhYDJxkELAQOAxkrHUACAQttPTUGAwsbRAInnkCDFksJNiYBA0MOAlgDCysHQgQBBkJICJMFsSc0B4IxgV+BWQYMihaVDQYTL4QBjHOGPJFvZJg/II1FlSyFFwIEAgQFAg4IgWOCFk0kT4JnCUkZD44sFoNWhRSKZnUCOQIHAQoBAQMJi0sBAQ
IronPort-PHdr: A9a23:z3LiPxwojGeRHznXCzKPy1BlVkEcU8jcIFtMudIu3qhVe+G4/524Y RKMrf44llLNVJXW57Vehu7fo63sCgliqZrUvmoLbZpMUBEIk4MRmQkhC9SCEkr1MLjhaClpV N8XT1Jh8nqnNlIPXcjkbkDUonq84CRXHRP6NAFvIf/yFJKXhMOyhIXQs52GTR9PgWiRaK9/f i6rpwfcvdVEpIZ5Ma8+x17ojiljfOJKyGV0YG6Chxuuw+aV0dtd/j5LuvUnpf4FdJ6/UrQzT bVeAzljCG0z6MDxnDXoTQaE5Sh5MC0ckk9ZPFn36kv6QZGo9Xr+idMjxRnCLf2oc5IFXzGt3 6Vpdi/jpXpZZwJnqjnU358V7upR9Qqg/UMmxpzqO6iWEuVOQ4TcRdc8a1pQU9RUcBB+Pb6cU tAoAcMGOfp66ILgv0QurUucXlemVN32kQ5P3Efq/7Yi7u4LEVzmwy4qAuopnGyP8crxa6gqQ 6e4yPXv0GzPTM9zy23wsbTBXyAajMiBX5tdXdfA52NyTDHsrwqhhKHMEWzO7OYLkXmm9/Z4Z 8W+j0w2jwh7pBz24ZgctYDunpsrzXDU5Staz59pAIjrAF4+YMSjFoNXrT3fLYZtX8c+Fnlho z1polVnkZuyfSxPxZgoyh3WMaPBfZKB/xTjU+icO3F0iSEtdLG+gkOq+FO7gq3nV8ay2UpXt CcNjNTWt34M2hCSosiKQ/dw5AGgjB6BzQnO7OFDL00u063dLp8q2LkrkZQP90/EG0fL
X-Talos-CUID: 9a23:3dTK6WwRrVZoAI+hFcflBgUMMIcDby3Z/kvXfUWUUFluabilR1m5rfY=
X-Talos-MUID: 9a23:CYAqCgU0wE3AnVrq/CPKqhN/b91O2KKJKVEokJEAg86WMjMlbg==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="2668842"
Received: from mail-mtaka29.fraunhofer.de ([153.96.1.29]) by mail-edgeka27.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 15:43:24 +0100
IronPort-SDR: 654cf00b_SSto3+ulxx8faxUzly2kdLeHNnhx5Q/SwwkPZKiNVad3gVl iI4VGXL0mRpXqF3i6k7SeMnfALxQ0azgcI1BnkQ==
X-IPAS-Result: A0BuCQDV7kxl/3+zYZlaHgEBCxIMQAkcgR8LgWdSBz41WIEFhFKDTQEBhS2GQAGBdC0DOAGcGYEsgSUDVg8BAwEBAQEBCAEuCwsEAQGFBgKHJQInNAkOAQIBAQIBAQEBAwIDAQEBAQEBAwEBBQEBAQIBAQYEgQoThWgNhkwBAQEBAgEBARARDwEFCAEBFBgMCwQLEQQBAQECAiMDAgInCwcNCQgGAQwGAgEBHoJcAYIqAw4jAgEBEKArAYFAAoooeoEygQGCCQEBBgQEgU9BrggYX4FfCQkBgRAug1yELgGKBxcfgVVEgRUnDoJ1PoIfQgEBAgGBOwEBg3uCaIZjggMVLgMEMoEKDAmBA4NSjUNdIgVCcB0DBwN/ECsHBC0bBwYJFBgVIwZRBCgkCRMSPgSBY4FRCn8/Dw4Rgj8iAgc2NhlIglsVDDQERnYQKgQUF4ESBGobFR43ERIXDQMIdB0CESM8AwUDBDMKEg0LIQVWA0IGSQsDAhoFAwMEgTYFDR4CEBoGDScDAxNNAhAUAzsDAwYDCzEDMFVEDFEDbx8WIAk8DwwfAhseDScoAjVDAxEFEgIWAycZBCwEDgMZKx1AAgELbT01BgMLG0QCJ55AgxZLCTYmAQNDDgJYAwsrB0IEAQZCSAiTBbEnNAeCMYFfgVkGDIoWlQ0GEy+EAYxzhjyRb2SYPyCNRZUshRcCBAIEBQIOAQEGgWM8gVlNJE+CZwlGAxkPjiAMFoNWhRSKZkIzAjkCBwEKAQEDCYtKAQE
IronPort-PHdr: A9a23:Vk3Idh+ZTdl/nP9uWWy9ngc9DxPPxp3qa1dGopNykalHN7+j9s6/Y h+X7qB3gVvATYjXrOhJj+PGvqyzPA5I7cOPqnkfdpxLWRIfz8IQmg0rGsmeDkPnavXtan9yB 5FZWVto9G28KxIQFtz3elvSpXO/93sVHBD+PhByPeP7BsvZiMHksoL6+8j9eQJN1ha0fb4gF wi8rwjaqpszjJB5I6k8jzrl8FBPffhbw38tGUOLkkTZx+KduaBu6T9RvPRzx4tlauDXb684R LpXAXEdPmY56dfCmTLDQACMtR5+Gm8Wxwt3UjrDthHlWM624y/Fj7Rg6HGKDZPIb4EyXDuS7 aVVeBTF1XlXC2BjqGKC2akSxKgOuBP7+EV60bCPSYKzK8pDWaLlefU0dXtMTMN2axN+P6OBN KwBJu0FIcQfpJTluHsO/TnlWwP8Ovq0+zgSvmPUxrUH2c4hTCHZ/gY9J/UiqC+Js9GqO58AF u2xkI7VlDngU9ZEgzqk1IHlQisMmPyOdJ9cbNv/4xR0JSrk0WS9hKXLYGiv1OIvolWD8/JSc vOrqX8Dogt3hmGImfcTg67Rn7wS6kDU+wZ22doQcI7wWAt6e9miCJxKq2SAOpBrRt93W2hzo 3VSItwuvJe6eG0P1J0E7kSOLfKdepWO4hXtWfzXLTorzH5mebfqnx+p6gDg0ezzUMCozUxH5 jRIiNjCt30BllTT58GLR+E7/xKJ1yyGygbT7e9JOwYzk6/aIIQm2bk+itwYtkGrIw==
IronPort-Data: A9a23:FEcfX6kqO5N/612HCPSyUS/o5gyEI0RdPkR7XQ2eYbSJt1+Wr1Gzt xJJWWmCb/6KZWLycoggOdm+pE9TucTdn4BgHlRorXpkHltH+JHPbTi7wugcHM8ywunrFh8PA xA2M4GYRCwMZiaA4E3raNANlFEkvYmQXL3wFeXYDS54QA5gWU8JhAlq8wIDqtcAbeORXUXV4 rsen+WFYAX+gmcsYzpIg06+gEoHUMra6GtwUmMWOKgjUG/2zxE9EJ8ZLKetGHr0KqE88jmSH rurIBmRpws1zj91Yj+Xuu+Tnn4iHtY+CTOzZk9+AMBOtPTiShsaic7XPNJEAateZq7gc9pZk L2hvrToIesl0zGldOk1C3Fl/y9C0aJuxY/aJHmamOaowHb/bXS80/9JDHgGFNhNkgp3KTkmG f0wMzURdlaOl+m2hryhQ/RqhsMtIdOtMI53VnNIlGyCS6d5B8mcEuOTv4AwMDQY3qiiGd7ea swaLzBudhfAZBldEkwWFNQwhu61gHn4fTBC7l6YzUYyyzaOnVwujum9WDbTUs6IdMp2mxnFn GfX5DjVXj04EfKb9iXQpxpAgceKx0sXQrk6FLS+8PNxxkGIzWwUBhAQVFSTrvypzEizR7p3I EUO/gI0oKQy81GtQsL6UQGnqWSJ+BUbXrJ4CeQm8ymMx7bapQGDCQA5oiVpMYF98Z5pAGV1h xrQxYyvGzkpu/ubU3uA8LeToz6ofyQYRYMfWRI5ocI+y4CLiKk9lBvSSNZkHqOvyNrzHDD72 TeRqyYiwb4UiKY2O2+TpDgrWhr1/sCTHD0mrB7aRHyk5Q5fbYuoLd7go1vC4PoKaM7TQlCdt TJW04KT/cIfP6GrzSateeQqGK32xvCnNDaHv0VjMaN8/BuQ+lmiX7tq3hdAGGlTPP0pQwTZO H3ohVsJ5bt4HmebUqtsUofgV+Uo1ffBEPrmZND1b/1PQIp4RDaazidMZUKvgmfnynoomqBiO qWgUN2NCEwCAv9N1wuGROY60J4qyBshxGjVe4vJ8hS/3ZeaZ1+XUb0gInLXSswYtYSq+B709 fRbPOu0kyRvavX0OHTrwNRCPGI0ImgeLrGojc5uL8qoABdsQUMlAN/vmYIRQZRvxflpp72Z7 0OGexFqzXTkjif6MiSMUHdobY3vUbtZrX4WOS8NP06i60M8YLSAvbsuSJ8qQYYJrOBT7+Z4b /0gSfWyBv5iTjfm+TNESbLfqIdkVgqghCPQHi6DTQU8QaVdRF3yyoe5RjfsySgANTrolM0cp 7b76BjXb6BeTCtfDeHXSsmV8XWPgVYnltlfYW70M/hIWUC18IFVOy371fA2BMcXKCT8/DiR1 ifIIBE+ueXtipIHwNnLjIvZqoysPbJ0G0pELWzl/JKzDy37/3Wi86BEQu2nbTDQb0Kq2aSAN MF+7eDwD+0Dp3lO67FDKrdMybkvwefvq5tx7BVWLF+SY3uFUrpfc2S7h+9Rvahz95plkAqRW HPX3OJFOL+MafjXIHRIKCULNu28hOwpwB/M5vEIIWL/1i993JyDdW5wZxCsqihsHIFZAbMf4 9UKmZApslSkqx8QLNy5oDhe9D2MIlw+QqwXjMwmL7GxuDU76GNpQML6MTD30qGtet8XE0gNI x2ovoTgqYlY5HL/dysUKSCQ88tb3Y8DqTJb/m8kfl6poOfIttUz/R9W8Ak0cDhr8wV647pNH VZvZmJIJvSo3jZ3hcJ8cXimNCNfCTa4pEHg6Vs7u1fIbkuvV2eXKDUZPNSczXAn7mtzLz1pz JCF+knYUBLBXsL47g0tU2FL9t3hSt1Q8FXZucaFRs6qIbgzUQDHsISPO1UajgTBOtwgonHHq c1B3vdCWYeiOQE++6QEWpSnj5IOQxW6FUl+aPBG/pJRO1rDeTu3iAO8G2roduxjf/X1oFKFU epwLcdyVjO75iaEjhYfIYUue7ZUvvoY1OAuS4PRB1wtkuWg92JykZfq6CLBqnchQIxuneYDO 4rhTW++PVLKt0REuV3mjZdiAXW5U+kmdQen/eGS8cc1LbwhntxoU3kP1uqTgy3IHiphph6ah VaWLeuehelv0p9lkIbQA71OTVf8Y8/6UOOTthu/qZJSZNfIKt3DrB4RtkKhBQlNIL8NQJ5io NxhajIsMJ/t597ai1zkpqQ=
IronPort-HdrOrdr: A9a23:loqRAqrRBkUX8nmjoGY2GHsaV5ojeYIsimQD101hICG9E/b0qy nKpp9w6faaskdzZJheo6HkBEDtexzhHP1OkOss1NWZPDUO0VHARL2KhrGC/9SPIUPDHnQ078 tdmqFFebnNMWQ=
X-Talos-CUID: 9a23:A1Y+D2mIQSaeKlwIdbyRGR3PBPrXOUDt0XLRBmaSMmlScaOaGU+a36Ndo+M7zg==
X-Talos-MUID: 9a23:aN4jcw1Jn3oYMnGIPVgw+IVAlzUj8aafB2MIzsg8vtifaQAsFxW4ojCIXdpy
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="65987698"
Received: from 153-97-179-127.vm.c.fraunhofer.de (HELO smtp.exch.fraunhofer.de) ([153.97.179.127]) by mail-mtaKA29.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 15:43:23 +0100
Received: from XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) by XCH-HYBRID-03.ads.fraunhofer.de (10.225.9.57) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27; Thu, 9 Nov 2023 15:43:23 +0100
Received: from DEU01-BE0-obe.outbound.protection.outlook.com (104.47.7.168) by XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27 via Frontend Transport; Thu, 9 Nov 2023 15:43:23 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AAyeXNSAB30J48qq8b5NOLbEmbskGAJsUCzzCcz8muc0F44r87BZhrgVl+IRGbR702cbZJSn7CSLpqDB3kSw2bJYUQz4XHWnV9uelMq0+cjgodDlU4TgGZd5McW046+s1j+/LIKa5tAV3bsDLX9kVWAxPOxCoZdrlGTJN+jGzV9W2lVSAfXWGSWnS2k464S3SwEzER+ezB8Beyjs/dv7dsFvok8aqba6GF3QXWmZUi2ksgNJFY3WpZUHpNYMY6IqjWsmp94FRckVxm8CSEN1Z/bMfqcmWAytbhvkHp2nrnRJRjUUcTQomy6xB699NF6EnzZr4t1fPa/rdZ5mxo9pqg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=yW9Zn2hwn1/9lWQ6uX0xX6VJYnmgXjjVXcE568T620k=; b=VOCZbn4LZp96iWK7BMgliavQtXsM2fu62mB7Om2MdI9BsrpupB/AkOzIwl3adkzyLj7yTVHGP/6WhPdghLU6rHZ3feh0GKdMgz11DpiDpF0uk6KMu32huM7WSBhaGeBvw+PyIx1TzUTk67NulhVXI9FEzjZ8ZNkrW+9DJqVcYDaAHhvKZXEANLr9VjGej1fphJARzMefKWrBvuZN6u1S+QW9PD1WmsGtHhmgyUqfzryydo7vHr4XxT2BeKVd23vcnlE5IuW3PMKBL99kq/5u7TZp5mB2wHMW9NJL9VeBlD7S2pWJ10KYZV3TnVTCOGsJW+XXnIOJpB36I/li5Bx0Xg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=sit.fraunhofer.de; dmarc=pass action=none header.from=sit.fraunhofer.de; dkim=pass header.d=sit.fraunhofer.de; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fraunhofer.onmicrosoft.com; s=selector2-fraunhofer-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yW9Zn2hwn1/9lWQ6uX0xX6VJYnmgXjjVXcE568T620k=; b=pi271mzV3AkNwXUOiPlNFXyezmOTWWUHU3OfAoltJ/cupwHh8J36b8Vq3Yo2PtJspUbBh5HwJbuPODp35wl7gPz/el4Ou1dKTMz2e1TaEXSEQejAEDuyFB53ZAI7YEEAF73RjnJyUptpZOylJyLabnL1O7XWaOpqVoHxxfKgq4M=
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8) by FR0P281MB2430.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:25::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6954.29; Thu, 9 Nov 2023 14:43:21 +0000
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a]) by FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a%4]) with mapi id 15.20.6977.018; Thu, 9 Nov 2023 14:43:21 +0000
Message-ID: <9b8eb6e3-1b9b-7a0a-dffd-f8d0912a7bb6@sit.fraunhofer.de>
Date: Thu, 09 Nov 2023 15:43:20 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: hannes.tschofenig@gmx.net, 'Carl Wallace' <carl@redhoundsoftware.com>, rats@ietf.org
References: <6FCC00F5-1FAE-4CCD-9ED2-DA2BA923E7F7@island-resort.com> <011801da130d$74579390$5d06bab0$@gmx.net> <66c6191b-c393-69da-a849-f44da369917a@sit.fraunhofer.de> <7DC2D9E1-F052-48A1-B5A8-978D52275EE5@redhoundsoftware.com> <01e001da131a$a8c7ba30$fa572e90$@gmx.net>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
In-Reply-To: <01e001da131a$a8c7ba30$fa572e90$@gmx.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-ClientProxiedBy: VI1PR10CA0092.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:803:28::21) To FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: FR0P281MB2879:EE_|FR0P281MB2430:EE_
X-MS-Office365-Filtering-Correlation-Id: 4c7a7c3d-5ebe-4c7d-5ba1-08dbe132386d
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: m1ZqsxqTzcQSyTkZhMaWSe2wcRGu980+MGv5PUuRIKoieqXbEOqTIuc2c94WmwOeWzvPUy0fSsYzaEUp1QHGDBgTs44FjJhNdIJ2E+Sn80ZnuLs3crsKALba6JUEJ1KzaT9yJ0bbPFGOe0wwmjDxiLqWraCSf7XJCw16ocHE2R2vyMb/f4mwt1HK3izsDz6MIVhkqewyJpkWGLCdixByBL2cFYURdNQ8IA8XMTPCOQoti9MKWO1XZbuPBkw87T7JGHk+eVXgl66sDX0umiGhZKHUr8CPb3HDiv3AyJc6xOzo0e5iekdA+avlqDFdjzsbrfGw3CvTC8ef2T/Wn7cCrqvqo/Hs+azTrko1WBX0Vqgex5GI8LNrOZXsQG1cPO61LtbY/2gkSUyml07YGmbD4geHAewIiG4+rx7mkOm1lICRGExtm4TyahTf7udvUXb24aOsKa9By3FzmA7Halxg68bwbDNeRm4XC9YQTRuMyol+xu7xScLZfLx6RBse4hLjAExilq84F3qZN09lX+VLEUtEcKBRoAFFifdHUqTjzGbcIGMGdJRpVa5KiNIU3if+PgHuysEG9WxSZasFgp73kkEgn643/FoIpA2OEpBJqrSvRFXzQt/yN1nxo0tXLM2iNbRrxA1vV/s8zy5ckTdzLgj7NmPd3PfLLE7IfO/AHEcBt1qhgMG/RKIRlX/Ux7E1
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(346002)(39860400002)(376002)(366004)(396003)(136003)(230922051799003)(64100799003)(451199024)(186009)(1800799009)(6506007)(2616005)(6512007)(82960400001)(478600001)(66946007)(6486002)(8936002)(966005)(8676002)(5660300002)(31696002)(44832011)(41300700001)(86362001)(2906002)(66476007)(316002)(66556008)(53546011)(31686004)(83380400001)(38100700002)(43740500002)(45980500001); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: hD1W85yox8sB3JCGVEArWyGhTq7oj259zrNiBVCLD+3Oi1lnVdIHXaFXNsAi0fqCpiUlXLiNIkGGnkybq3KfxEo43NZX6lzVQbNXjzsKz5K4JKtUVEXEflJkcWhZBuctck2BwJ55R6AwkZK/ta0JAiRP5c0pffgfk3IHBIZzeDQ+/59bGL12eDUTUl9TbfEv+rAZDAJeIFnyHiocymQZAeoP/CBbxRGl4dsJdJqQRB3R9bvDpDW0BbxGMbsbd4QUwRxJA7KDfX60rFFTSFfRVgMXjkCwod8I9i88wpHChw3sd9oIHmishVNGm+zxGBLE330in3WQ/YKodQv/QDv42/tILnxF7w2X85v41mTJdiJYxkK3fNoo+wdFNsFclrxBtM9AGvLLQhtCdO7d0/Iwr6iKKTdI1hOgeQvNX0oLxF29575VlXcA274GVWPNrGtqC+ATnYA3mjI79cV8/C/bQM/3Zn1Ti+DwUHDeDpDWLe5ggIaKcXN9xVWoK2B8/fh2EockXK5Arjfaeh/NsSnDKDfsxO4ZpRKyNJ6olNOUcJ62rBvVb98u1PMtNaPIZFg+2sxVd2THDJ+nEet01X/irMCYSA6H9+950g2ws9xl2LFSyAaSrMhfhuEG1JvrX+QeqS+CEHYNH5k2KPzFTW3afqoYkLHhRgqHvkjWONXbz2UNm+0W9ftCgRz054kavl3bxP1MMYMhySY5P8d7+YlI+UCCZnurvx1G8pdbiTWbg9/gvs40AsM5siZSK2DHwZxT30QsDg9Y6ryl2dLbBkoQkIIooZCWVBLF3GIMpICVSJyHRJPW/9geOcvSUEhgfGreFdrVR2Ucls3Pfc8K1cFquKW52LryTtf3z8NQYlxwFjcdN42lNCwZstcRvcrZnUpGmzJHY8vVWA648ffJZCaX+OVg11tsi/p5dZINrS7OHXhLxFdymWDR4s8GrFDQ7TO5wBNJvifnv7orEocOoyXLgEWngy7vG0TEeLKNbh/OCdyoItoTPrareBR9AZAWxVkMCOfuh5F4IuZNr8do6wnYRo0UUM/CExVpv4OUvp5P6z92EnFUYYfw1ys6fkLjDdQAwDlXpT/Wf3O3IglBpzwF/IAr/zKWoCXdV7n9k2m4nhCJaFfZoRR/IMAlaGVPZ1Bq4O79xXE8Z28J8Y9YgFTO2WWU/9/h2rXPwf8CMzzRGNzrYdUlVRwYGZwWgIA87to4SduZGOK6YTC/AFgZ9Q6SsFLw6GYEAg81i2ZQgSArfzB3PiUGldicBBIt9KKT3M9r7PeOpCpeVg04MRTl4yOrre3cg7A9jOYcIpIROyaw5t9usz+97Vv16GrV6it0KAfX2qIWtFwrVt6eYQcr50tbTNhGCPEPGdTsGi3kQAPqtlbrGB0PPHjQLfFLf5r/7nudC52RCzr1KyjU31q2hAh4zhB+1NqkR41pbtFUhlk9b4KhLt0NR83ck2+CwH1lZD5sH20rEe3BfmmGRm3zLNJGWimes8Nn9HMGcQ3pOxmEG2nQB+D4fNAe3zLW/ZavGed2YKEziMHIEIUb41CWvE8JtC2CbOCLLc/6Pw3ZC8tU2ZIIRkRaQMVmYZd6G3BS5pT1ZxcmYFH0gdIjg2md/P061dJJRAhQc6hztaIID0D+DZXRkOh4bEba+mtlBiUs76YKoeWlAoseSIAHtcgK8XDhU60yvn/YY+Wa/TSklLM9pvc=
X-MS-Exchange-CrossTenant-Network-Message-Id: 4c7a7c3d-5ebe-4c7d-5ba1-08dbe132386d
X-MS-Exchange-CrossTenant-AuthSource: FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Nov 2023 14:43:21.6030 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: f930300c-c97d-4019-be03-add650a171c4
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 0qyAVzReZ7RfddvqOCTEzmh9IKb8yTScnEREPok1/rDXrQoPr/gEGV0I2BrR+ARNyKiRWs38fVhiiqjPczABxjhi3lQ4MFZ9iPP+/MjliBU=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: FR0P281MB2430
X-OriginatorOrg: sit.fraunhofer.de
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/CACukZNpVF5vxQKwZyM4RpzAa4g>
Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Nov 2023 14:43:32 -0000

On 09.11.23 15:40, hannes.tschofenig@gmx.net wrote:
> Hi Carl,
> 
> A few responses below:
> 
> * The use of CBOR/COSE in SUIT: At the start of the SUIT working group the participants expressed a strong preference to use CBOR/COSE and didn't want to use ASN.1/CMS. Brendan and I had written a draft that used ASN.1, which was inspired by work Russ did. It happens that work being proposed does not align with the expectations of the group. I remember Henk and Carsten being vocal proponents of CBOR & COSE at that time. Was it a good idea to use CBOR/COSE instead of ASN.1/CMS? Now that the standardization and implementation work is almost finished it is a bit too late to ask this question again.
> 
> * Do we want to provide claim definitions in ASN.1 format (as we do in the draft)? That was our understanding from the design team discussions.
> 
> * Should we keep the definition of the CBOR/COSE claim definitions in sync with the ASN.1 format? I believe there is value in doing so. There does not seem to be anything wrong with the semantics of the claims in EAT. We have received feedback already for better alignment since we have introduced a few bugs in the -00 submission.
> 
> * A question you did not ask was: Should all claims in EAT also be described in an ASN.1 format? Currently the draft only contains a subset of the claims. I have been asking myself the same question. It is somewhat likely that sooner or later all claims defined in EAT will need to be available in ASN.1 format.

Had the same thought, did not dare to voice it. I can imagine Mike 
groaning (as he wants to move fast). Not sure, if this I-D is the one to 
do that. Mike?

> 
> Ciao
> Hannes
> 
> -----Original Message-----
> From: RATS <rats-bounces@ietf.org> On Behalf Of Carl Wallace
> Sent: Donnerstag, 9. November 2023 14:45
> To: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; rats@ietf.org
> Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
> 
> 
> On 11/9/23, 8:09 AM, "RATS on behalf of Henk Birkholz" <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org> on behalf of henk.birkholz@sit.fraunhofer.de <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
> 
> 
> I think this discussion is mood as was pointed out in the meeting already. Please see:
> 
> 
> https://www.rfc-editor.org/rfc/rfc9334.html#figure-9 <https://www.rfc-editor.org/rfc/rfc9334.html#figure-9>
> 
> [CW] I don't think that diagram renders this discussion moot. X.509 certificate-based attestations have existed since before RATS (and before we called attestation evidence). There's not even much question about potential for including claims in an X.509 certificate within current RATS documents (see section C.3 of EAT). I think the questions are: 1) do we want to provide ASN.1 definitions for claims and 2) do we want to keep claim definitions (roughly) in sync across ASN.1/CBOR/JSON. Re: 1), there's seems to be general acceptance of defining claims in ASN.1 for the most part (though no one really answered Brendan's question regarding why ASN.1 was disallowed for SUIT but is allowed here). Question 2) needs some more discussion. There was an exchange between Mike and Laurence during the presentation yesterday that highlights a potential difference of opinion between I-D author(s) and participants in the working group that could impact the adoption question.
> 
> On 09.11.23 14:05, hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net> wrote:
>> Hi Laurence,
>>
>> The charter says:
>>
>> “
>>
>> Standardize data models that implement and secure the defined
>> information model (e.g., CBOR Web Token structures [RFC8392
>> <https://datatracker.ietf.org/doc/rfc8392/> <https://datatracker.ietf.org/doc/rfc8392/&gt;>], JSON Web Token structures
>> [RFC7519 <https://datatracker.ietf.org/doc/rfc7519/> <https://datatracker.ietf.org/doc/rfc7519/&gt;>]).
>>
>> “
>>
>> CWT and JWT are mentioned as examples. The group already works on
>> another evidence format, namely the TPM-based stuff.
>>
>> I would say that the document fits nicely within the scope of the charter.
>>
>> Regarding the document split. I am open to discussions about your
>> suggestion, which assumes adoption in the group.
>>
>> Ciao
>>
>> Hannes
>>
>> *From:*RATS <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org>> *On Behalf Of *lgl island-resort.com
>> *Sent:* Donnerstag, 9. November 2023 13:59
>> *To:* rats <rats@ietf.org <mailto:rats@ietf.org>>
>> *Subject:* [Rats] draft-ounsworth-rats-x509-evidence-00
>>
>> I think it might be better to split this into two drafts.
>>
>> First, define how to put CWT/JWT claims into ASN.1 and make an X.509
>> attestation token.
>>
>> Second, define the FIPS and CC status claims for CBOR, JSON and ASN.1.
>>
>> I wish we didn’t have to do the first, but understand that we might.
>> Note that the RATS charter says we work on CBOR and JSON. There was a
>> little discussion about ASN.1 back in the early days and we certainly
>> put it off back then. There was also YANG discussion. Search the RATS
>> mail archive for ASN.1.
>>
>> I’m much more interested in the FIPS and CC status claims. I would like
>> to define them for CBOR, JSON and ASN.1. If they are booleans this is
>> trivial. The would get registered in the CWT and JWT IANA registries.
>>
>> One of the reasons I’d like to define them for CBOR and JSON is so
>> there’s a known and accepted way to translate their ASN.1 claims into JSON.
>>
>> Also, the X.509 definition should be for Attestation Results as well as
>> Evidence. There’s no reason to restrict it and there’s no work to allow
>> use as Attestation Results.
>>
>> LL
>>
>> (sent incorrectly the first time only to the rats-chairs; meant it for
>> the list)
>>
>>
>> _______________________________________________
>> RATS mailing list
>> RATS@ietf.org <mailto:RATS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/rats <https://www.ietf.org/mailman/listinfo/rats>
> 
> 
> _______________________________________________
> RATS mailing list
> RATS@ietf.org <mailto:RATS@ietf.org>
> https://www.ietf.org/mailman/listinfo/rats <https://www.ietf.org/mailman/listinfo/rats>
> 
> 
> 
> 
> _______________________________________________
> RATS mailing list
> RATS@ietf.org
> https://www.ietf.org/mailman/listinfo/rats
>