[Rats] retrieving reference measurements

Guy Fedorkow <gfedorkow@juniper.net> Wed, 29 April 2020 13:56 UTC

Return-Path: <gfedorkow@juniper.net>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 336CD3A109F for <rats@ietfa.amsl.com>; Wed, 29 Apr 2020 06:56:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=vGCZku+g; dkim=pass (1024-bit key) header.d=juniper.net header.b=Qyc3m8uK
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HqHS2YQQl7UO for <rats@ietfa.amsl.com>; Wed, 29 Apr 2020 06:56:33 -0700 (PDT)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3812A3A10B4 for <rats@ietf.org>; Wed, 29 Apr 2020 06:56:33 -0700 (PDT)
Received: from pps.filterd (m0108163.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 03TDbgW8021770; Wed, 29 Apr 2020 06:56:31 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : content-type : mime-version; s=PPS1017; bh=jNFM6nYk+vGTVOZWeFu0BcZiH3B8YSFHnYir3LS/1sA=; b=vGCZku+gpj1vke7Avr52QM1p01ythtlxXkJzuFpRt6ppsdnjrqupojuz4wMG47cOFQU5 KB1Bi3dkOEbZjh11xV8Lft3sXhLHNgHvFB7LIj0RMft5Jcf+a17bZHxb002lO07UHzh4 I2bqlWI1kINsPWcRAUD1l8eweTnLTYmjCPkOcFzklroeNIZ6fSxjVBGeI/zfRluGZ7ig l+tLxbusl7JOBbjsTA5n0MdrK5a/xUN2u4htD8zWqYtBS6ZluRWUKqTGAsAEu1Rqfs59 dkWyCeKk0xLlBXLCvCbm/0Cos/y39suIAtJOkgjrTsw/cGKBC+DqW1ZrSNCMkLwajq+6 RQ==
Received: from nam11-bn8-obe.outbound.protection.outlook.com (mail-bn8nam11lp2177.outbound.protection.outlook.com [104.47.58.177]) by mx0b-00273201.pphosted.com with ESMTP id 30mhtuyp0g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 29 Apr 2020 06:56:31 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=fcfD7l8tcqWuzScESvIAuslqa8ycVtFMZbtUxkxraHpHHb7JqTOfSn35M23+0Y6mjX4loKOKGUnYbyFNScEOvYYSv3Hdgjp9+Ffxv1NZZTBlvLbzTLlAg/ssgaxPcOt7pXmsFku+NA7iIfsetHSwsVEzs56u2B3tQ9xtyVYw5LkRXUtMzpTcc4YNeWvT8SttpEDGBBcsH7Wqpt+E3kxouKYn4A4mWon0hC6GTaszsrFLU1caCIXGqvsvSiITwKYjmlOxhdRioOVRRdck5RwMNPjidMWVwdErFxlBejUQMF2VyFg1DpK3u1pbprEP1adicJj32J5X+lb9FBN6wdaQYQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jNFM6nYk+vGTVOZWeFu0BcZiH3B8YSFHnYir3LS/1sA=; b=ac3WvvnLRm/KCWL2d+QWU+oRLNkGV+I/RdXQpXVc2lue1TaBecOZ0IXWR7kq+18GANNyqHhzCdAQva2z+NN3ME/pXBZtOB9hY73QOfhrclqg2vhb3VdSyo2Efdvtd5RX6lS5Casq7BIQssGxmUQmdcB8SManGUxwCC8R15bTKpU2sSKvHUw14y5+BqlluMX78PT9cpXrUhP/EJeXMkM+pAQwDktxqxdxnI5BZcOkiUG+f6fr0yk63u8uLZlyYfbcxVqyXiYZWm4nluEUqfibVtYdqyPLSkW4ABIAbSemQwb/Wi1N9dnBJ/0q+xgU5NYy5eAxTXNFpemUcp4xtT4RpA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jNFM6nYk+vGTVOZWeFu0BcZiH3B8YSFHnYir3LS/1sA=; b=Qyc3m8uKv0JS8xoOsNXHl2JDw7cZcz2UjDCqy69vVDxKF9N2GinGItospjBxEKPOCJoeE7tzlFxS16lYbTpQpjPro00tUOT2tyfkG072OACwNu4vuQ5jH5oAAkNTocNLnlcY1FlO5zXktQ7cZYzltw9Ea36OM/iW8J3TQ2c5Ibc=
Received: from DM6PR05MB6889.namprd05.prod.outlook.com (2603:10b6:5:204::22) by DM6PR05MB5100.namprd05.prod.outlook.com (2603:10b6:5:36::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2958.8; Wed, 29 Apr 2020 13:56:29 +0000
Received: from DM6PR05MB6889.namprd05.prod.outlook.com ([fe80::99d5:e781:8291:de1]) by DM6PR05MB6889.namprd05.prod.outlook.com ([fe80::99d5:e781:8291:de1%7]) with mapi id 15.20.2979.013; Wed, 29 Apr 2020 13:56:29 +0000
From: Guy Fedorkow <gfedorkow@juniper.net>
To: Henk Berkholz <henk.birkholz@sit.fraunhofer.de>
CC: "rats@ietf.org" <rats@ietf.org>, Jessica Fitzgerald-McKay <jmfmckay@gmail.com>, William Bellingrath <wbellingrath@juniper.net>
Thread-Topic: retrieving reference measurements
Thread-Index: AdYeLLsj977MpbIWSBiRE1EIoB5bdg==
Date: Wed, 29 Apr 2020 13:56:28 +0000
Message-ID: <DM6PR05MB68895483D6F508C46748147FBAAD0@DM6PR05MB6889.namprd05.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled=True; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId=bea78b3c-4cdb-4130-854a-1d193232e5f4; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Owner=gfedorkow@juniper.net; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate=2020-04-29T13:56:26.6866068Z; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name=Juniper Business Use Only; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Application=Microsoft Azure Information Protection; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId=eea69583-02d4-4ccd-b201-763f49c0bf35; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Extended_MSFT_Method=Automatic
dlp-product: dlpe-windows
dlp-version: 11.3.2.8
dlp-reaction: no-action
authentication-results: sit.fraunhofer.de; dkim=none (message not signed) header.d=none;sit.fraunhofer.de; dmarc=none action=none header.from=juniper.net;
x-originating-ip: [66.129.241.10]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 54349b2e-23b9-463c-f1fa-08d7ec451db1
x-ms-traffictypediagnostic: DM6PR05MB5100:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <DM6PR05MB5100B9ACAE781907567D1035BAAD0@DM6PR05MB5100.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 03883BD916
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: nzmZSK5gJr6IJhjpbauLXV7pk6YUFOnPsiyzs2a52i+wq1frDHBJEuHis4J6OAL3n/PWgXl2vjv0QHVY22S+G5pOHuQ7YNQL2ZMqWneS3DqmEpCFMdVXroL+VKPZbjgx4a+NNrXrhsjQK7ttgrx3BpCknQ3Di3cHWHieJg/Dv9wAZQxjo8L2sFK/lSW3O0lkxgcxBUpgEHJQy1A8ahRt/NoSbxtYbn5vDDaMbWQWSAWXXPRMhxOzRDaVq1UospPbeNWwOmGXNHBR6LaHZ6c0wIST6n4mhAn6bFi8vqVIEQ7pfnZEtxhpKArd3hCqxcs3hS1J9UmqabYqUVRLO8RjXeUT/anZ+u/YQ3q5N5Tg56yTJAe16zogdUI9CnzwYCmjAgtNK1o4IRYZvziqGD/Cwak0SvQRP0BVSrSO9YpAFxdyU/OAfRhsTd7xZPJH4OUaub4NfqFuAXYT3M64FdAZgNIUiETrnw4hTDntKFhJxddPn26hPruwa/w9DclN/NC5/25Hgl+eP9TKmLssfQ7NWH6l0lIphFI8XqeBvM2iCQtDkkpXs08fhWPGGygdJNzt
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR05MB6889.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(39860400002)(136003)(376002)(396003)(366004)(346002)(8676002)(71200400001)(7116003)(6916009)(966005)(478600001)(107886003)(66476007)(66446008)(9686003)(66616009)(64756008)(55016002)(66574012)(4326008)(4744005)(66556008)(5660300002)(76116006)(66946007)(3480700007)(52536014)(99936003)(26005)(8936002)(7696005)(9326002)(33656002)(186003)(6506007)(54906003)(316002)(2906002)(86362001)(133083001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: GnVW9y3IPCnuEUCWtrSQKl5qjcDR0fgxiqJ1fgo65FFTw//aQX7b0lg53I7Zz9Si1o5STHMCgTTXOf/FKXdw6NK+50i0TV+pyx62X6nmBJ0t79tECyun5uTXiWOoDEPNsrMlIA0gXQNv8ppo+8jJFE7fIa6va1BkKepaKjiaRGuLGTlgVR6VcqfP/nlLsUdVMKl7BsrMZHycAEzpItNFalL032kRcEOqe8d5CS9KJMRxdeTfRKl9K04D3c4Tw4/Y/ppPh/3/BNhpGSA63Ml9zoUXtUHEGVZdPj2VlMixHodOX06EYr8fs/jsmsWg5+nmXBaEIjUm7o09673cVBwTn9xKT7OauEQWzm13icKy93ReCgWgNbll6ZXGFKljdchR9Yq4oRNweiRoml1mBvZbx2Uqc8bxKf3vm4TEOcyOhtfaohMWkvYigArdpBFNHP/5wHRyEqZnbaelneHrbbqF78bEehJx+zu4WvMdTVUn/WRgcTIoQQMqtoDTsZ3oC5GjGq5uVkqcd5fRot2ISof/it7o3zpEnVoRt7N2cwCc12vkculrcyiFJfaWfKoSbiLj1eVh7gCs0D2yvxxooan4gNeICv0WIYJxMo2ZiUonIc7yGyI3Ab2oyxYRFKNKsUG8GfPc3dJD+VsLr+hh47fPegMsMJvzNI9qYOpsJgg/5RUAwdHBzq8Kv/+EnsZTRAxUue9OCQrgq4hUoY+D3pRzSzYy1if+F5xo1rAcJ1BAtCj+gc8/D3m6X1VPS0uBRBpdtE0pBozxh0jVx64eMx6fElSozuJkWc3QonjiWrGmJCc=
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="SHA1"; boundary="----=_NextPart_000_00F3_01D61E0C.72BE4000"
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: 54349b2e-23b9-463c-f1fa-08d7ec451db1
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Apr 2020 13:56:29.0474 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: OB+xJRnlnh8Fn5DgDRiuN1PCEi9V7fapjkG4FEykC0kcef25GknK5KrgxcDkEJmsRXZrM4JBei/tqCtO5R8iVw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR05MB5100
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.138, 18.0.676 definitions=2020-04-29_05:2020-04-29, 2020-04-29 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 mlxlogscore=999 lowpriorityscore=0 suspectscore=0 adultscore=0 spamscore=0 impostorscore=0 clxscore=1015 mlxscore=0 malwarescore=0 priorityscore=1501 phishscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2003020000 definitions=main-2004290115
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/5gBrySkdtKz1M83tvHgcHHDtxhg>
Subject: [Rats] retrieving reference measurements
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Apr 2020 13:56:35 -0000

Hi Henk,

I see your proposal for identifying URIs for reference measurements in
https://tools.ietf.org/html/draft-birkholz-rats-mud-00

 

  I realize that some constrained devices may not want to do this, but do
you think draft-charra could be extended to allow retrieval of the signed
reference measurements directly from the device being attested, via the YANG
/ Netconf interface?

  Ironic as it may sound, I'm sure you know that many operators ensure that
their internet routers cannot access the public internet.

 

  Thanks,

/guy

 


Juniper Business Use Only