Re: [Rats] Call for adoption (after draft rename) for Yang module draft

Schönwälder, Jürgen <J.Schoenwaelder@jacobs-university.de> Wed, 13 November 2019 11:14 UTC

Return-Path: <J.Schoenwaelder@jacobs-university.de>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E89301200FF for <rats@ietfa.amsl.com>; Wed, 13 Nov 2019 03:14:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=jacobsuniversity.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4n4-FQIvnFi2 for <rats@ietfa.amsl.com>; Wed, 13 Nov 2019 03:14:26 -0800 (PST)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0627.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe02::627]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2DF361200CD for <rats@ietf.org>; Wed, 13 Nov 2019 03:14:26 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=SqKPtePLFGnRrhir/6XWnxGhgkOpgdbEWR+SdvQxObK6vLw5N5FZo6X8spLyVmwkLCdCNDLwWKD4EX2fnnAOARueMP8fEc9dG60dBhLXT+G70Qj9RoN4wHKCS84sWSvR8JPYrwW7xJHGPxRRYsV+Nc8nTupc/eNP+TobOxf+dKFhKD67CQqyha7GAHQ7YIvyFYEk7LgFaAzWkumILsKKpO9PbxnAWZyhW6ps2hIXGub6KvAINua1DFTQiEvUvQgLN4iAiF/2SGBvdDsZKPB7SDF7HrHzPMpJNAELbyrSXohvAH0dqknxpsL9W77/0MU1ZLEABoJ4VYeQpmXNRf96qA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uLDtJDFx0Gn06qNI/E5ySzQ0TzquAnUxKyjq7VUBxEU=; b=mmGPLWgkgMWbQ+RVc3Rj/5JtukImeST4i8GdapzztxhmKm4WiPNDh5U+2XnExNvS0VKhXkgssAndTcAk/4DItVEocBouGZxzRDpOXu5hcEZD1RpsQj5D/rCo5A+fIEZTZp8+hkxgH8hqeoldh3r5o4eF0kr/bcVSpGPGKEYLRgGqd5AlZxiH6rCoW2hnU6yZHCB+JgtJUyRspLFJJEklz8lhII/hpDmF8+WnlRyoI2osuyYwACzz/4lXMPUWNb+r3jFabw391iaIkHmFVcsS17ll2vAoiX/hHgn70V0Ry8umQKjHMtdhDFBNDH4eQmNXapLtNRixCyCacC/bb3cuXA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jacobs-university.de; dmarc=pass action=none header.from=jacobs-university.de; dkim=pass header.d=jacobs-university.de; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jacobsuniversity.onmicrosoft.com; s=selector2-jacobsuniversity-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uLDtJDFx0Gn06qNI/E5ySzQ0TzquAnUxKyjq7VUBxEU=; b=eqdnqx6M9B3A1fT4saBrY2sXl7KbrCjwAAVtYd27P/+Jz42pH143OTotppnOfffNsW1iaJ9Fb5u2V77WwrtULWkcjaQirpQS0njOxLhaP+N+Wv6+g4+oZ6fnQrCzLfK88z4D/fSqaFgYM2TBTpEXx+JE5nz1Y0z+NcV9cKCaEhg=
Received: from AM5P190MB0482.EURP190.PROD.OUTLOOK.COM (10.161.65.11) by AM5P190MB0289.EURP190.PROD.OUTLOOK.COM (10.161.89.150) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2430.24; Wed, 13 Nov 2019 11:14:17 +0000
Received: from AM5P190MB0482.EURP190.PROD.OUTLOOK.COM ([fe80::6c6c:2cd2:11dd:2aff]) by AM5P190MB0482.EURP190.PROD.OUTLOOK.COM ([fe80::6c6c:2cd2:11dd:2aff%5]) with mapi id 15.20.2451.023; Wed, 13 Nov 2019 11:14:17 +0000
From: "Schönwälder, Jürgen" <J.Schoenwaelder@jacobs-university.de>
To: Michael Richardson <mcr+ietf@sandelman.ca>
CC: Laurence Lundblade <lgl@island-resort.com>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] Call for adoption (after draft rename) for Yang module draft
Thread-Index: AQHVmhIl8/lytau3hU+AhCwtIdg/0aeI8tQA
Date: Wed, 13 Nov 2019 11:14:17 +0000
Message-ID: <20191113111416.22xikah475zyxdro@anna.jacobs.jacobs-university.de>
References: <ce5f8206-74dc-36bb-0093-a93045d5c67f@sit.fraunhofer.de> <0A7E3A4F-8534-4E98-BCB7-1454E07699F4@island-resort.com> <C3AE2645-49C8-4313-BCED-02FEB576B614@cisco.com> <1C8A1884-A37D-45E3-8C11-2FC5A083B245@island-resort.com> <ba12a686-1b34-21a3-388c-bbe01c01a408@sandelman.ca> <4A83CDF5-D29F-4279-8B03-E9D23299EB53@island-resort.com> <0C6940B0-E93F-4274-9D00-DEC4119B8F69@island-resort.com> <85c7c287-48e3-83e7-900e-8e50ce43eba3@sandelman.ca> <147FEACA-56F0-43A0-8F25-639D0613E4BD@island-resort.com> <22fd43c8-7d6e-2dd8-c29a-aa86ee894ff6@sandelman.ca>
In-Reply-To: <22fd43c8-7d6e-2dd8-c29a-aa86ee894ff6@sandelman.ca>
Reply-To: "Schönwälder, Jürgen" <J.Schoenwaelder@jacobs-university.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-clientproxiedby: BE0P281CA0007.DEUP281.PROD.OUTLOOK.COM (2603:10a6:b10:a::17) To AM5P190MB0482.EURP190.PROD.OUTLOOK.COM (2603:10a6:206:1d::11)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=J.Schoenwaelder@jacobs-university.de;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [2001:638:709:5::7]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b4117e6f-8ce9-495e-f2a6-08d7682a9fc9
x-ms-traffictypediagnostic: AM5P190MB0289:
x-ms-exchange-purlcount: 1
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <AM5P190MB0289B589F93757198F28EF39DE760@AM5P190MB0289.EURP190.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0220D4B98D
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(366004)(346002)(376002)(396003)(136003)(39850400004)(189003)(199004)(76176011)(786003)(316002)(43066004)(99286004)(1076003)(25786009)(478600001)(52116002)(6506007)(102836004)(53546011)(476003)(54906003)(7736002)(305945005)(386003)(4326008)(46003)(186003)(8936002)(256004)(6246003)(446003)(11346002)(14454004)(6512007)(6306002)(86362001)(486006)(6486002)(6436002)(229853002)(71190400001)(6116002)(64756008)(66446008)(81156014)(66556008)(66476007)(81166006)(66946007)(5660300002)(8676002)(4001150100001)(71200400001)(2906002)(3450700001); DIR:OUT; SFP:1101; SCL:1; SRVR:AM5P190MB0289; H:AM5P190MB0482.EURP190.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: jacobs-university.de does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: MZzJVJsJeaJABtkKR8kIDsLUGLN4rDACrUJsiFJoawSlUqlbLKmn4eDogjA4KsCBl6qMj7HZ/6lYzOfRR5zhGmc8ylQE3cirzm7NPfQg/nog3qXWeVl5Lzk1GoDZOncKBv1Qa7cmLFQR5A5eVD/KziCL8BIIBm0ZN4jXwM2nOed7jaqIqDhQRhbRWI0np8q37l0UKncLHlWXM3sC540Lc9AhjLfpADYCfT7t075x1ZCgagma59E7tZRrd5TdoxUi1oUmupcxBVqEKDxtf8NuKamN3PvYmiYS1ORnb7kOIhFeXdBtfxzf38+4TJKpFojCqXu5YyvKOeP97BaDqWiJspKAUoHvhCzf7i1YQlgj/hRsQjEaQACvWF4xU3tlvy4xBPpOgpfASfGiQL3iMB4zkpic3PkybGKq6s9tqc/KZDA5SQRaHwl72/qnIJvN1Q22AoH+vtEu72DNwLgojN+cmJnXWWjNxh5QhJMt1O+35Gc=
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <11074CB553AD294FB8F95A55803E1B42@EURP190.PROD.OUTLOOK.COM>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: jacobs-university.de
X-MS-Exchange-CrossTenant-Network-Message-Id: b4117e6f-8ce9-495e-f2a6-08d7682a9fc9
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Nov 2019 11:14:17.6321 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f78e973e-5c0b-4ab8-bbd7-9887c95a8ebd
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: g7+lwNYDZEWKxzkEYLXeisYyUQlfALGBdH5iliHVZxCvUS5fXpB22lziOXieJLNC48eSyTy1Pe+WHM4HewVHLNSCcUdSj2kFv7IcYoymsv8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5P190MB0289
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/LrJThbUYR0DMP8VZRsSu8_mD0tg>
Subject: Re: [Rats] Call for adoption (after draft rename) for Yang module draft
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2019 11:14:29 -0000

On Wed, Nov 13, 2019 at 07:04:40PM +0800, Michael Richardson wrote:
> 
> 
> On 2019-11-13 1:56 a.m., Laurence Lundblade wrote:
> >
> > Got that one totally wrong. I even knew everything you describe about YANG.
> >
> > I still think it is better if we just stick to EAT / CWT / JWT claims described with CDDL as the way we define claims in RATS, except for a few TPM-specific claims. 
> 
> Nothing I've said is opposed to that.
> I rather agree.  I don't think that EAT is complex enough to require a
> definition in YANG.
> 
> But, that also has nothing to do with whether we'd need a YANG signing
> standard if we defined them in YANG.
> We wouldn't, because we'd be signing JSON, CBOR (or XML if someone
> insisted) using JSOE and COSE.
>

I am still confused but so far for me it may make sense to have the
following:

- A YANG defined transport for "tokens" which likely treats tokens as
  opaque objects.

- A way to include arbitrary YANG defined data as claims in some form
  of "tokens" that can carry YANG defined data. There is lots of stuff
  defined in YANG models that may be reused as claims.

- Whether we need a YANG defined "token" format is unclear to me. It
  is also unclear to me why we would need it specifically for TPMs.

While there is a lot of talk here about different kinds of "token"
recently, I note that this term is not defined in
draft-birkholz-rats-architecture-03.txt nor in
draft-thaler-rats-architecture-01.txt.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <https://www.jacobs-university.de/>