Re: [Rats] Should we remove submods from EAT? (was Re: EAT Review Comments)

Laurence Lundblade <lgl@island-resort.com> Sat, 18 December 2021 19:05 UTC

Return-Path: <lgl@island-resort.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B85E3A10E6 for <rats@ietfa.amsl.com>; Sat, 18 Dec 2021 11:05:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WmOZbMoOhp5S for <rats@ietfa.amsl.com>; Sat, 18 Dec 2021 11:04:57 -0800 (PST)
Received: from p3plsmtpa09-01.prod.phx3.secureserver.net (p3plsmtpa09-01.prod.phx3.secureserver.net [173.201.193.230]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E672B3A10E5 for <rats@ietf.org>; Sat, 18 Dec 2021 11:04:57 -0800 (PST)
Received: from [192.168.1.7] ([75.80.148.243]) by :SMTPAUTH: with ESMTPA id yf0rmm2CKW3fByf0rmE0Oj; Sat, 18 Dec 2021 12:04:57 -0700
X-CMAE-Analysis: v=2.4 cv=dNFjJMVb c=1 sm=1 tr=0 ts=61be30d9 a=VPU1mRQhDhA4uSX60JRRww==:117 a=VPU1mRQhDhA4uSX60JRRww==:17 a=kj9zAlcOel0A:10 a=QyXUC8HyAAAA:8 a=3nvCFB78w9AtEvgaFSAA:9 a=CjuIK1q_8ugA:10
X-SECURESERVER-ACCT: lgl@island-resort.com
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.17\))
From: Laurence Lundblade <lgl@island-resort.com>
In-Reply-To: <6FE2B11E-2290-4CD3-AF92-547F2A205547@intel.com>
Date: Sat, 18 Dec 2021 11:04:56 -0800
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, Hannes Tschofenig <Hannes.Tschofenig@arm.com>, "rats@ietf.org" <rats@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <9E9FAFDA-B892-47CF-8375-58AFE6313F3C@island-resort.com>
References: <DBBPR08MB59150EEE386E675005A52124FA6E9@DBBPR08MB5915.eurprd08.prod.outlook.com> <B81765CF-8515-440B-A021-977FCD59D5E2@island-resort.com> <DBBPR08MB5915DD8BAA394E7D665E4C7DFA709@DBBPR08MB5915.eurprd08.prod.outlook.com> <E6E179AD-23AA-4B22-A0CE-26BED6BB2862@island-resort.com> <ABD665F5-777E-4A9C-8920-0135FA91FC7B@intel.com> <10720.1639667481@localhost> <6CBC3D74-7963-4127-A510-C6A0C54E5EFA@island-resort.com> <6FE2B11E-2290-4CD3-AF92-547F2A205547@intel.com>
To: "Smith, Ned" <ned.smith@intel.com>
X-Mailer: Apple Mail (2.3445.104.17)
X-CMAE-Envelope: MS4xfOxL4L6BDBIWFKXo66gmUTlf9EMq0VNAv58Wf5AHohdMjDkV631oloTKl+VLoR+TVU7MOkLs9J089YVakmoT8Q8yfUAtLEW7scaeVEVP5Y9puMsf4I4Y GLVVhoXuIUmQEoPcLK6P359iJUiFgGyGmtHZxutrpaagg4kv6L2Q+tnu7Ok1uEECSC6DfMq5ewtz5k2POpYURKt8l0zQTvBnh0Rm/XzYYJYZ29rzyXgJpPbm 6M4iy6uJsajP4jaqbD3WGwy+JOqoglqgi4uJbaIFjqZnJtty8kXg8rUSQ/NUoeiI
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/FuGKeIsprpHSCiEsFvJzUUidf98>
Subject: Re: [Rats] Should we remove submods from EAT? (was Re: EAT Review Comments)
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Dec 2021 19:05:03 -0000

On Dec 17, 2021, at 3:42 PM, Smith, Ned <ned.smith@intel.com> wrote:
> 
> (speaking not as chair)
> If submods claim is Evidence, then there is an expected Reference Values expression that matches it.

Note that a submod might be a whole other EAT token. Maybe the Verifier knows how to look into it, maybe the Verifier just knows to send it to another Verifier. For example, it might be for Secure Element that is soldered on to the circuit board and you might send it to a service that Verifies Secure Element attestations.

We could support both bstr and tstr for the submod name if it is really needed.

LL