[Rats] Re: Call for adoption: draft-deshpande-rats-multi-verifier-04 (Ends 2026-04-24)

Manu Fontaine <Manu@hushmesh.com> Wed, 22 April 2026 22:47 UTC

Return-Path: <manu@hushmesh.com>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5B087E131A28 for <rats@mail2.ietf.org>; Wed, 22 Apr 2026 15:47:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776898033; bh=aDJyX5dLGPm8o0ElOeVNGYMYMxDO++Ph6FXDdNDf8uA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=tmL/A03Ls7Zq2fgaFVjAgRDkVy5NBPwyT5rn1tyYaUCj/KOLEirzlCx5sOPmlR8Ge DK7LsovXJ4+NX7Q8G7ReI1KrvYexxdJTfJ9R4sNxSHIUtx5CFOsSRzns7mDWVYGv55 Y7jEPrL/FPU6qeMskYrLg7wbWvS1TIk/e8JSK3Nw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=hushmesh-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0-eEIWGIxGRs for <rats@mail2.ietf.org>; Wed, 22 Apr 2026 15:47:12 -0700 (PDT)
Received: from mail-ej1-x634.google.com (mail-ej1-x634.google.com [IPv6:2a00:1450:4864:20::634]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 1AF12E1319D3 for <rats@ietf.org>; Wed, 22 Apr 2026 15:47:09 -0700 (PDT)
Received: by mail-ej1-x634.google.com with SMTP id a640c23a62f3a-ba7a1cc0380so815373766b.2 for <rats@ietf.org>; Wed, 22 Apr 2026 15:47:09 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1776898028; cv=none; d=google.com; s=arc-20240605; b=gGXe6Cova+YSdtlce7rjdZFrdOVbpOYs1X8FCGA8S+r2ChXp/9MIw4DX+LQ5GAUvBE 2sqv8fKbTvAA+Y7C7GAdcG9+GLzr/+ychFGY3/9trLmwnWQSPf9Mkja93nT9Os4AqEHT izGhfTX+8pIzuqj6aaXl42tieI00SUA0uIxdzin9Kk2Mv3BikQXe8VsjfW85RvKcd0gk 3+/ySJNUbGzocGndxbCFbAt31T4TfSnGahOBZregYLqT8VmWQmpQKbfkcB8l8/M8uIGb fUYJB47y+fGD/EpRz9KAidHvKMQZ6Vx4p3313VRqR+/JWRjsGkysIJcf+UTUZy+Bcu4C x6Fw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=AcprIt467cfXR+A0ENrMOZOYTvFLXgTfkQWPmaydkDA=; fh=ypPDDc/hbdt4WXFETl7USw1EzwwlNRmyQ2lYJhNdLCE=; b=NzlNFAFNI6dwkq35qh2QusH9el7DJPJh0ZMgJ88nCsxdb04YjGBnxAoPzO3fFsciB8 yjDLa6Bp/ukT0GrYszNCNP304VIXZDq+oZpdsmYumWM0ejG9pLcR5UftIIsBLYtNAs0+ ylDomg+EGh9Bhi7o9jonVPN83PB+ZIS3Z3+uF4J3TSaKB98XY1L1D4PDuhoJuCoOPHct 6AKIu7v+yYf3gVsxXgZw9C//G4PcFNKdc+uZq9kZoTX0I8EyubGF8jvtRwU72Cvvhnev B7kTdB/nyhRi0xkgbWyVEjlrVfZ1dsI//rNovX1GvaajTgWxG10SgG+m/OMriMaGMyjv cv5g==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hushmesh-com.20251104.gappssmtp.com; s=20251104; t=1776898028; x=1777502828; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=AcprIt467cfXR+A0ENrMOZOYTvFLXgTfkQWPmaydkDA=; b=cq94ZKkcNCvkS5+J/vbuBIseGzEv4h/GWcCY37siETv2mav/McFK4cC3srjOLv76mU 0fIU/BuGykWDv/7qXzD4XYRVKDmD+Gk7LCDtKd/Ay/oTfx3SLVwpAXYfHyYvQr0kcxlP i/3lSY6OGaOE6Y0i18z07C5llWhY09mubqXl+7NfwY7gurJeHswVxTiUQ21yIKCUzUN+ aeoDPgu+tnU52MFBRYB3/jSQdq2S0F+6+QvcB1hXcYSIo3csByReXCPaRXU7MoEHWJtC 8hhbkyMlsbxxZb0rVWwY2iVGTN/Vv4nhjN4Zy66WIUhjvlAzaXXfxmfzUG57/7qmNU03 eiEw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776898028; x=1777502828; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=AcprIt467cfXR+A0ENrMOZOYTvFLXgTfkQWPmaydkDA=; b=OwxytP0ylqv14QEh2E+2Hdfdb8/E7Z7t5jO/vi+AsvIDgXyvVNH1t7/w1UcROoSY0M v2xegDX6HjSvroQdp8eD5Fpt6Ad4Q9oT3KCwWB+WIOP4Pcf8Z7eDlhreG6Qw7GvGK7Qu +GAQeu0fEKY06QtVxv25lW7Iy6lXk57wAxQ1JP87wnr770B29VdZ9ZK5h3A3FLILigPV x0/Paqzdq/nr6t6aJF6Ao5mfxwmXdYcCMCaiI7mw3JhOn5HTXD1gG+VvhO4AxplK2InD LhMopE60oreMDLZHp6X1uftkhg7dx5TAls7duDTJjynBy6C3gekl7qjFTfy4pUlspCDP MWOg==
X-Forwarded-Encrypted: i=1; AFNElJ92Ha60Vqs7+YhBarkm+Y3qJUjldobq1piC8GuESUg6m/iHs9OlfJG7Z971VlGvhJwgdBrM@ietf.org
X-Gm-Message-State: AOJu0Yyv8PGh1iAGkMsPJoQnUuCHhwd6FhRgeBcKz3XAN4KjuTIDkaNn 7QDAv563Kk/sTEw8T+Q842S4q72R9djfvZ3v6OkGyUznZar/QhINcxGxRFX3qtcDvulurZ1sG+O EJKazRiRQo48y59JERDa1htMh7kRopTZMrjIK78fCyg==
X-Gm-Gg: AeBDietQ8OhWokbnYfOJibRIvvtMo5enmQidQUDe35uexqt3qEadayqTYRUTq1S1pNx pGbHsWym+EkZO5B0kweFWX1q5F8PEd4w2x4sCvIjgsorcgA/xOdQoKwEffDB+UaSg7BgIFefEy3 dU3f/fYfrpZj38dxtwlkw5+KnEiiQHcc8nLqf+TynB1J6p3A0vbNeIqZy39KIMtcyXGlJKvEZ+g eaA73gPiVH1D8NQsAJ7FgHLer7jwmUk5qbo6nrdViiXotQmIkwfgVLvmybDliD5lLkFbdsrvxqI h/XbeIiU9J1dCiU8hxR7nLbrgrnywsrysY83yHNOWvdeZNB0Ahs=
X-Received: by 2002:a17:907:3f22:b0:ba4:8883:7f33 with SMTP id a640c23a62f3a-ba488838064mr1273556866b.10.1776898027912; Wed, 22 Apr 2026 15:47:07 -0700 (PDT)
MIME-Version: 1.0
References: <177643631672.70056.16474393035056250188@dt-datatracker-b45949c58-5szpr> <DB9PR08MB8699985F787BAF9E21A0C32FEF2D2@DB9PR08MB8699.eurprd08.prod.outlook.com>
In-Reply-To: <DB9PR08MB8699985F787BAF9E21A0C32FEF2D2@DB9PR08MB8699.eurprd08.prod.outlook.com>
From: Manu Fontaine <Manu@hushmesh.com>
Date: Wed, 22 Apr 2026 18:46:56 -0400
X-Gm-Features: AQROBzDLFDbdaElV19BlGkWAjj_lIpyLnasYIsRnBcChXWcdPBUOtgXvZ4akJN8
Message-ID: <CAHu=PL0k6=JNp=CT9j_PJ68eTD+e=uf+0SnDh53a=asNKAyWzg@mail.gmail.com>
To: Simon Frost <Simon.Frost@arm.com>
Content-Type: multipart/alternative; boundary="000000000000c18e7c0650144fd1"
Message-ID-Hash: L4GRIND2NOJ5O26HSW3IKUYUR4MD3N2D
X-Message-ID-Hash: L4GRIND2NOJ5O26HSW3IKUYUR4MD3N2D
X-MailFrom: manu@hushmesh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "rats@ietf.org" <rats@ietf.org>, "rats-chairs@ietf.org" <rats-chairs@ietf.org>, "draft-deshpande-rats-multi-verifier@ietf.org" <draft-deshpande-rats-multi-verifier@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Re: Call for adoption: draft-deshpande-rats-multi-verifier-04 (Ends 2026-04-24)
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/CHKms9fHWVCITnh9JSxxQvRxEoQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>

Apologies for not participating actively, I don't have enough bandwidth.

We agree this work is important; our perspective is that all relying party
trust decisions are compositions, which require multi-verifier
architectures (we currently operate a network of "verifiers of verifiers".)

We also strongly share Usama's security and privacy concerns, which amplify
with each additional independent system. We wish RATS approached the
problem from the relying party's perspective.

The full CC value proposition can only be achieved by minimizing trust
dependencies all the way to the relying party. This proposition degrades
quickly with any additional independent system added to the attester's
trust base (we sort of disagree with the sentence: "The Verifier is not
part of the Attester’s Trusted Computing Base").

We hope these issues get addressed later.

Thanks,
M


On Wed, Apr 22, 2026 at 6:42 PM Simon Frost <Simon.Frost@arm.com> wrote:

> I support adoption. The need for multi verifiers is growing and adoption
> will help bring an appropriate level of rigor to address the challenges
> from the additional complexity.
>
> Thanks
> Simon
>
> -----Original Message-----
> From: Ned Smith via Datatracker <noreply@ietf.org>
> Sent: 17 April 2026 15:32
> To: rats@ietf.org; rats-chairs@ietf.org;
> draft-deshpande-rats-multi-verifier@ietf.org
> Subject: [Rats] Call for adoption: draft-deshpande-rats-multi-verifier-04
> (Ends 2026-04-24)
>
> This message starts a rats WG Call for Adoption of:
> draft-deshpande-rats-multi-verifier-04
>
> This Working Group Call for Adoption ends on 2026-04-24
>
> Abstract:
>    IETF RATS Architecture, defines the key role of a Verifier.  In a
>    complex system, this role needs to be performed by multiple Verfiers
>    coordinating together to assess the full trustworthiness of an
>    Attester.  This document focuses on various topological patterns for
>    a multiple Verifier system.  It only covers the architectural aspects
>    introduced by the Multi Verifier concept, which is neutral with
>    regard to specific wire formats, encoding, transport mechanisms, or
>    processing details.
>
> Please reply to this message and indicate whether or not you support
> adoption of this Internet-Draft by the rats WG. Comments to explain your
> preference are greatly appreciated. Please reply to all recipients of this
> message and include this message in your response.
>
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [2].
> Appropriate IPR disclosures required for full conformance with the
> provisions of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of
> any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
>
> Thank you.
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-deshpande-rats-multi-verifier/
>
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-deshpande-rats-multi-verifier-04.html
>
> A diff from the previous version is available at:
>
> https://author-tools.ietf.org/iddiff?url2=draft-deshpande-rats-multi-verifier-04
>
> IMPORTANT NOTICE: The contents of this email and any attachments are
> confidential and may also be privileged. If you are not the intended
> recipient, please notify the sender immediately and do not disclose the
> contents to any other person, use it for any purpose, or store or copy the
> information in any medium. Thank you.
> _______________________________________________
> RATS mailing list -- rats@ietf.org
> To unsubscribe send an email to rats-leave@ietf.org
>