Re: [Rats] Attestation for non-TPM based Network Devices

"Smith, Ned" <ned.smith@intel.com> Fri, 01 December 2023 17:27 UTC

Return-Path: <ned.smith@intel.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 811F1C14F5F5 for <rats@ietfa.amsl.com>; Fri, 1 Dec 2023 09:27:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.105
X-Spam-Level:
X-Spam-Status: No, score=-7.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=intel.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2dg6nSVjFX72 for <rats@ietfa.amsl.com>; Fri, 1 Dec 2023 09:27:12 -0800 (PST)
Received: from mgamail.intel.com (mgamail.intel.com [192.55.52.151]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 650E3C14F5FB for <rats@ietf.org>; Fri, 1 Dec 2023 09:25:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1701451524; x=1732987524; h=from:to:subject:date:message-id:references:in-reply-to: content-id:content-transfer-encoding:mime-version; bh=jxqN0ztvjLTHwzC6YDbstwFapVkb6+GwaCSkxz5ZVc4=; b=EQSkH6k+tvtKoJJl2fVE6MHt2Qy4lISfoEJv6P8qmHw/74F3K9Ci9/um lNPwdAFnzfcwJCPz1Kd1Y0rBKb8xjMrEv70KCHx2RWNDK2nq1v3WaFatW sgqqmW41NvHg4TqgjOt/2G8Cm4MTD63a0+OZIz2vbadIX7GOr48RvEJeU OT/cK1noZC/UOoQOzUIx80/T6DmJNe3gVhD5uYoXJQk0C57bB6QnRFuz3 LlRBoh5kzyazHUmAfs60GiHb7dQIYq1HqgrrVetE5I7j/+jg/HkuFRdj/ EfRe6O4GC9tAWBle8bZXfEnSVtaGSqk6sXybdsB9knXF3yy9fME/8CKY/ w==;
X-IronPort-AV: E=McAfee;i="6600,9927,10911"; a="373709164"
X-IronPort-AV: E=Sophos;i="6.04,242,1695711600"; d="scan'208";a="373709164"
Received: from orsmga001.jf.intel.com ([10.7.209.18]) by fmsmga107.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 01 Dec 2023 09:25:23 -0800
X-ExtLoop1: 1
X-IronPort-AV: E=McAfee;i="6600,9927,10911"; a="804131671"
X-IronPort-AV: E=Sophos;i="6.04,242,1695711600"; d="scan'208";a="804131671"
Received: from orsmsx603.amr.corp.intel.com ([10.22.229.16]) by orsmga001.jf.intel.com with ESMTP/TLS/AES256-GCM-SHA384; 01 Dec 2023 09:25:23 -0800
Received: from orsmsx610.amr.corp.intel.com (10.22.229.23) by ORSMSX603.amr.corp.intel.com (10.22.229.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.34; Fri, 1 Dec 2023 09:25:22 -0800
Received: from orsedg603.ED.cps.intel.com (10.7.248.4) by orsmsx610.amr.corp.intel.com (10.22.229.23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.34 via Frontend Transport; Fri, 1 Dec 2023 09:25:22 -0800
Received: from NAM11-CO1-obe.outbound.protection.outlook.com (104.47.56.169) by edgegateway.intel.com (134.134.137.100) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.1.2507.34; Fri, 1 Dec 2023 09:25:22 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HxJ2+zkfOOe2ossMDQwPSIEzi+SwpfExWga3RWEfXZugemnwamm33fi9PqX5CCTFyBy14qLh1G4EU8jTH9sw6Ju2sZMYnBslZuSHJyVIn9CXYQCQtbEvk2Sr09BnbSkCQnyV/4zD8wF3icJwoVN3aI9yrS/SDZtiLoNecOaqQFbn7iTwEvskE4rcmVd9lipsfJGA0h6SWyPJ4jCXWGyh3wteRGlgrgUoQfKtkrfxIOkrrousxBgqz/3Z/fg3Or5KYlTay9VUL+EbjH56vebJpgqEme2U5EPdwqYH+qL5Phch5P24VrZN7ctXar9XExjbQsMNFpYgs7yLeb7TjKNajg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=jxqN0ztvjLTHwzC6YDbstwFapVkb6+GwaCSkxz5ZVc4=; b=exIwY0n8TTNDOFktxtZ9LbrTghMdqkHxItLhQUOZWskeU6nFNywgXZHdEi9be1DmqNED21vymqB2iK/HqbWmEgg36uLkJ6S3q1p5dncKHF3Kasp3cPQ73Mrod6Zrnzze0ArvhY6k8j8atnJUCpJO/tSTZwg/jRXgm4SGnS3PVvbt9xpeXhATzHi+iQQ2jYea0SpbBQIZ0oqKt9OeyMg8s/ZPqc98WHs/VMfwiarYBxdyxEq3VntB+uwtK/PXjfcV7nAbQog8/Z/oj5DlXOFOguvL/nJEZd0M0+HD1ziyqPT6vTLzH4HuS/3fxlaQ3hVNHrh43etG5xph7Eldiq6jsw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=intel.com; dmarc=pass action=none header.from=intel.com; dkim=pass header.d=intel.com; arc=none
Received: from CO1PR11MB5169.namprd11.prod.outlook.com (2603:10b6:303:95::19) by SA1PR11MB8393.namprd11.prod.outlook.com (2603:10b6:806:373::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7046.27; Fri, 1 Dec 2023 17:25:21 +0000
Received: from CO1PR11MB5169.namprd11.prod.outlook.com ([fe80::9033:4536:8538:e366]) by CO1PR11MB5169.namprd11.prod.outlook.com ([fe80::9033:4536:8538:e366%5]) with mapi id 15.20.7046.023; Fri, 1 Dec 2023 17:25:20 +0000
From: "Smith, Ned" <ned.smith@intel.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] Attestation for non-TPM based Network Devices
Thread-Index: AQHaJHpyv5GP2VKgdk2SFf6YvgUv77CUJ6YA
Date: Fri, 01 Dec 2023 17:25:20 +0000
Message-ID: <9A3015E5-9ADB-4F60-B3CD-E90E2940537F@intel.com>
References: <00faf326-f590-4afd-9451-2ac754ae199d@gmx.net>
In-Reply-To: <00faf326-f590-4afd-9451-2ac754ae199d@gmx.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.79.23112723
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=intel.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CO1PR11MB5169:EE_|SA1PR11MB8393:EE_
x-ms-office365-filtering-correlation-id: 9e591fb1-50cf-4f00-3af3-08dbf2927ecf
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: V5dB2oFGkU2Fyyqh8D402rBB1wynsxmOReuswiizZxpTF4ah0wyQc/lyu+nuC5qCUpFegtF1LrTuDUJJCA1H8pwlHtKwpBMp54+4QEBDNy7mZfRQkI8/QJ7lyJtROxOdonn/+meGQ0nVnCcgBSrfEi5NTwipoMikxJGH2nAlfKFdoDWm4miasvdrjQic9iaZm3RbQ+xzjD4gVESfekwmAsbrZdaW8BlhS4v+ylqDN1EqtWhsThFo19crclA3N7A41TDbrP1G67XIJJr2WqqTDsuWKBc4w1pOE42lY1T/Dwysbpsp7TSlEoCxxnZyz1honRYTQ8o0QOG78arVthAc9qPgve6vn7M/Qkgf+hcv/4sDKz8A7Q6OUj6+0A7VCRO1IcpzcTzD12HQeJFkeBXcRg0RB4nNTc73pBoaXmhBgoYNcYkiGbe0rHX2/7j/pbfPlljPhsRzL+D3ayBxp9DFviylUJLoeK4WrbwRkcoXiyOaEgF6ENSC89qjLi4cM2EJ56cI4LFLPwRkgxP4fkKQG9rzXBkDW73SpbtIE9XJrVJy5k94Zb7SD5TsrCZWltrL1Y9JDgg1WIijyq56yhmFJDLcQdRbZ8GfNDYLaN9PshSnMVipCRNubbVV77Vww7+Cd5PhDp4auxONGwcQjl/d5Q==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO1PR11MB5169.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(346002)(136003)(376002)(39860400002)(366004)(396003)(230922051799003)(186009)(1800799012)(451199024)(64100799003)(110136005)(64756008)(66446008)(66476007)(66556008)(122000001)(316002)(76116006)(86362001)(6512007)(41300700001)(2906002)(66946007)(38070700009)(5660300002)(38100700002)(33656002)(82960400001)(83380400001)(26005)(966005)(6486002)(2616005)(36756003)(478600001)(6506007)(8936002)(8676002)(71200400001)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: rBVkTGpcFIqABz9QiNEiwKm9hSflH79R6hU2WBrRWnyDR5+ZLwnX7UNfV1/3IPMvRRTKJJcKdPRSPsEPWmvmI7swwESWKkwiYcOTqZxW+AUbGTi7+BgH7Sa6APvpa2Vl5BlbO7tlL4RolfFwvs/zJ47tdSE1HSACugIJ3kbh8u12/00aS7v6XcUdw/F1O/26emfag9Yc+jDQIdf1ss8ZSZ8LLbBIAuZJfUeJ5VxECbIxXq6EHeNq6K9OFIfZCzh0owyiNAtTt3MyXhXiyTRmkWln4PVLlbxXtPYRCSUtQTMty8kLjJ8BuFGQTAqrooHPxam2rI6YJ+CrCBBbNwm9Q28xnZRWwe5rfQdPbaYDJlZn3gWDbUdIsU/HHBLoI0obmuUDooG3qVDsSdlVEkt1/lKpm32PI6WoJ6kzak8qKYXAdiiIWYFrdHgFRsiii87yhqVyFugwl1e+6Qu24KPo8k5VsASACC2CRjmSGDsF0fO2/tcGLDfEqyoN2r/BDp50mRkekR4v5P53QQa7H3GnQkdDcsLwpzE4lyGPHHaCHa3tYq2ZvFyZHBeACuHPf40OV3tZbcRLChRw0XXvC27xS5PtWunoTbdTXgfXDuyrJeBYrGoeWUMo3NXQnIc+3OameeK01fV7Sd8HJ73n7QS++4C+4EFENG5MHdrTaytAQ3FR2+8TVhxW6U+lyBoqN4XNdDVCSzkvCg6Ba3XOpGANe1q9zFKI+XSaIR+OkPjm3ts4PlGtich3p+snWTKKG84kJdxT0sX2Zya8Cv5CcKeNtwtRirL93OHwrmXA9quy1TqL96hWQ54tBlDNUzFvRNwbRufqz4+MqmF/7asoLhVlOjlxo9HdPzmh50Ll2tJnh97SyRQ0SpAyUVG6bjXxv0QataB4lzwrGImRmsa4FsH0bdp1ow4NeEfU71rDCkpda9CyFt2QXGs/ioyMXUi0gdpizAeYF9FzXpB7J0IipDimF6JLcvFAVpmkEAuDy3bR4de3tu15tJvjpBRbMTC235cF+2eifuuV9UogKCus0XAJhH1gRmJVmHphD+2bVixMCjHP299dQ0YLSuZBHQKz3dZGw+oqXU3w/SFDjwV4YFyp5H+K3sp3Y05ncHU4DdRzd27obJSK4ZN8ZHBcA90ZVqhPX/ouqmoGxcEAiUyW1tr/ho86KeXmLuhhfPtuMV2JDtMnf31y08o8HYIXVGHZ5pZ8S7wkabyUgp24AlRKRjdEknhoRlgL+YfWJj3D3UwcBXiBYaWTphIydncVC3t3XcfK7aZ4A9Jiw11XDVpKxPeuGx6TbbzYMCm2iQ4Rp8XIMloSzu16+JoMC5XizyXL6IrPwwiWCQT3MC2R8WsM2l5VE06ByuCxDRwIa2+ITZ3+OeArqQre31Xh/8DKchiQBLSt5j4pLMI+6HLyHwAgzKVHh7Y+XxYTqwiQetC6M/EVaS3DKUEcaMRrdiikWOqhMtVGDnImawvZuie+F3XZN7BygPwC2FkbAoxR3FEkW+mSo98djYyeYqodh6MKVJJCevRsa4jl1nMJsQLvHupE9sNODZTl6NIC+1CQJLyJgllG6tvXSYAzWsSEtcPeN8VAo6MFwnCsE5opAdwY/FhrwFXRCw==
Content-Type: text/plain; charset="utf-8"
Content-ID: <193D15AD3D7D8046BFBEFC9D08CB537F@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO1PR11MB5169.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9e591fb1-50cf-4f00-3af3-08dbf2927ecf
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Dec 2023 17:25:20.9160 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 46c98d88-e344-4ed4-8496-4ed7712e255d
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: XQpUgPzLdYB7mnjLXxj8HjEIxJIAhXgb8O31EOTW3Var3uL9VfRxZI1XqWGGyq+xSCPQ4WP6Hwyws10NEYbjWQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR11MB8393
X-OriginatorOrg: intel.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/OnYIlaagZLHGL7vlR7IvJzD4ESI>
Subject: Re: [Rats] Attestation for non-TPM based Network Devices
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Dec 2023 17:27:16 -0000

Hannes,
The RATS WG is defining conceptual message wrapper (https://datatracker.ietf.org/doc/draft-ftbs-rats-msg-wrap/) and interaction models (https://datatracker.ietf.org/doc/draft-ietf-rats-reference-interaction-models/). There has also been work on using TLS to convey attestation messages (https://www.ietf.org/archive/id/draft-fossati-tls-attestation-03.html). 

Are you proposing something other than these? 

Thanks,
Ned

On 12/1/23, 9:18 AM, "RATS on behalf of Hannes Tschofenig" <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org> on behalf of hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net>> wrote:


Hi all,




the RATS working group has been working on several documents that define
how TPM-based evidence is conveyed from a networking device to the
management infrastructure. Examples include
draft-ietf-rats-yang-tpm-charra and draft-ietf-rats-yang-tpm-charra.




I was wondering who in the group is interested to work with me on a
generic approach for conveying attestation information that goes beyond
TPMs?




Please drop me a private message.




Ciao


Hannes




_______________________________________________
RATS mailing list
RATS@ietf.org <mailto:RATS@ietf.org>
https://www.ietf.org/mailman/listinfo/rats <https://www.ietf.org/mailman/listinfo/rats>