Re: [Rats] draft-ounsworth-rats-x509-evidence-00

Henk Birkholz <henk.birkholz@sit.fraunhofer.de> Thu, 09 November 2023 14:52 UTC

Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B82D2C17C899 for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 06:52:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.597
X-Spam-Level:
X-Spam-Status: No, score=-6.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, GB_ABOUTYOU=0.5, NICE_REPLY_A=-0.091, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sit.fraunhofer.de header.b="Ke5+YoRC"; dkim=pass (1024-bit key) header.d=fraunhofer.onmicrosoft.com header.b="j83t7Bzf"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y7DnVruz5GEi for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 06:52:26 -0800 (PST)
Received: from mail-edgeka24.fraunhofer.de (mail-edgeka24.fraunhofer.de [IPv6:2a03:db80:4420:b000::25:24]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C5580C187705 for <rats@ietf.org>; Thu, 9 Nov 2023 06:51:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sit.fraunhofer.de; i=@sit.fraunhofer.de; q=dns/txt; s=emailbd1; t=1699541515; x=1731077515; h=message-id:date:subject:to:references:from:in-reply-to: content-transfer-encoding:mime-version; bh=sBRFWHEkPJFZL01BX8sQkJOF+tFDXLkqCA0UAPcbPuM=; b=Ke5+YoRCQbRdTJdbVaf74IdudMMqpK3qtV5NNzuEkTbjgOGpOMgfZT23 ZNyq/9dMoEvnrmGwcg1n1Ogg30cXRDmdw40EkWskVX5/1fowgdkNJ/gai yuzXvrLkvRI8rODqWQ/y9yYNK5s4ZpfRN0rdbLsLVbsqo5zrXovSLvo+v FnVNAypfv9ls9uC4pGHBItQMhV7RQisXB1SOXfKn4nOvQNs6X83zruwln DoaBmzl09yO7rMJgo4uDmH0POv52+26NEKZTmNV22bSnrBsVKmoCW7wxo sf9A/sn7Eediza/koOQ3hnU+o7T/KJ2Oi5ULR8hHbku5ca2Sq1D6M46t8 w==;
X-CSE-ConnectionGUID: IbyySuX0T4KivRCYiv49qA==
X-CSE-MsgGUID: xHr1HlJwRPaT62ejgTwJOQ==
Authentication-Results: mail-edgeka24.fraunhofer.de; dkim=pass (signature verified) header.i=@fraunhofer.onmicrosoft.com
X-IPAS-Result: A2HiAwDs8Exl/xoBYJlaHgEBCxIMQIFEC4IRKHqBXYRTg0+NYi0DnFKBLIElAy4fCQ8BAQEBAQEBAQEIAS4LCwQBAQMBA4R/AocoJzQJDgECAQMBAQEBAwIDAQEBAQEBAQIBAQYBAQEBAQEGBgKBGYUvOQ2DFmqBHQEBAQEBAQEBAQEBAQEdAg0oDA0bAR4BAQEBAgEBASEPAQUIAQEsDAsECQIRBAEBAQICIwMCAicLFAkIBgEMBgIBAYJ6AYIqAw4jFJBYmzh6gTKBAYIJAQEGgQdQQa4IGF+BXwkJAYEQLoNchC4BigcXH4FVRIEVJw6CdT6CH0IBAQIBgTsBAYN7gmiGY4IDFS4DBDKBCgwJgQODUo1DXSIFQnAdAwcDfxArBwQtGwcGCRQYFSMGUQQoJAkTEj4EgWOBUQp/Pw8OEYI/IgIHNjYZSIJbFQw0BEZ2ECoEFBeBEgRqGxUeNxESFw0DCHQdAhEjPAMFAwQzChINCyEFVgNCBkkLAwIaBQMDBIE2BQ0eAhAaBg0nAwMTTQIQFAM7AwMGAwsxAzBVRAxRA28fNgk8DwwfAhseDScoAjVDAxEFEgIWAycZBCwEDgMZKx1AAgELbT01BgMLG0QCJ55AgwEVSwk2JgEDQw4CWAMLKwc1DQQBBkJICJIcabEnNAeCMYFfgVkGDIoWlQ0GEy+EAYxzhjyRb2SYPyCNRZUshRcCBAIEBQIOCIFjghZNJE+CZwlJGQ+OIAwWgQoBDII/hRSKZnUCOQIHAQoBAQMJi0sBAQ
IronPort-PHdr: A9a23:wj+iLBTFPdM5HGEqPYTgaNfUudpsou2eAWYlg6HP9ppQJ/3wt523J lfWoO5thQWUA9aT4Kdehu7fo63sHnYN5Z+RvXxRFf4EW0oLk8wLmQwnDsOfT0r9Kf/hdSshG 8peElRi+iLzKh1OFcLzbEHVuCf34yQbBxP/MgR4PKHyHIvThN6wzOe859jYZAAb4Vj1YeZcN hKz/ynYqsREupZoKKs61knsr2BTcutbgEJEd3mUmQrx4Nv1wI97/nZ1mtcMsvBNS777eKJqf fl9N3ELI2s17cvkuFz4QA2D62E1fk4WnxFLUG2npBv6C77eniTa6bRR1HbFNND3c50qQSn4v pg7dBSwswIuawY8tzHepsJQo6sAhB309Hkdi4SBYtHOKKVUbK35ec8fVTVAX+lWfjB+A6ywX 7BMHesMYMJgkdTNp0kxrhevBhSoVMrSyRlVp2H8gI4h9+oLTlDj/h1jO8tWt1D1r87bJaYyb +qV4pfo7j/za89U2yzl2bbESR94/t2uRp5BKujsykw0RzrPiQyKptbCLTWy2d8QlkWUqM94W fON00kHlCF0jQOo4t10h6/5posVzXT2+XwhzrkqL92eZRZHPIb0RcgYp2SbLYxwWsQ4XyRyt T0nzqFToZegZ3tiIPUPwhfeb7mKf4eF4Ru5CKCfOz5lgnJidr+lwRq/ogCsyez5A9G9y00C7 jFEnd/Fqm0X2lTN59KGRPpw8gbp2TuG2w3JrOARCU4unLfdK5kvz6R2kZwWsE/ZGTTxllmwh 6iTHng=
X-Talos-CUID: 9a23:zEjoU2i25Hn1du6Ocq+l6CjfXDJuU3fM3UzNExeEVUVoVoe+eF6OpPJ9up87
X-Talos-MUID: 9a23:hxQuvw7aoLIztAkG7Zk5gYmJxox4w773KEQvjq8+svXabyFyNAuCrhOOF9o=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="2713978"
Received: from mail-mtaka26.fraunhofer.de ([153.96.1.26]) by mail-edgeka24.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 15:51:51 +0100
IronPort-SDR: 654cf205_5+/gQl8x30xwpDzMLSoGlFOWaeFw6rWUnE/+XIArVfz6QeU 6IHBE88UWbDBECKv91gvfwNpZm/7owXGCyZoenQ==
X-IPAS-Result: A0ByCQDs8Exl/3+zYZlaHgEBCxIMQAkcgR8LgWcqKAc+NViBBYRSg00BAYUthkABgXQtAzgBnBmBLIElA1YPAQMBAQEBAQgBLgsLBAEBhQYChyUCJzQJDgECAQECAQEBAQMCAwEBAQEBAQMBAQUBAQECAQEGBIEKE4VoDYZMAQEBAQIBAQEQEQ8BBQgBARQYDAsECQIRBAEBAQICIwMCAicLBw0JCAYBDAYCAQEeglwBgioDDiMCAQEQkFiPTQGBQAKKKHqBMoEBggkBAQYEBIFPQa4IGF+BXwkJAYEQLoNchC4BigcXH4FVRIEVJw6CdT6CH0IBAQIBgTsBAYN7gmiGY4IDFS4DBDKBCgwJgQODUo1DXSIFQnAdAwcDfxArBwQtGwcGCRQYFSMGUQQoJAkTEj4EgWOBUQp/Pw8OEYI/IgIHNjYZSIJbFQw0BEZ2ECoEFBeBEgRqGxUeNxESFw0DCHQdAhEjPAMFAwQzChINCyEFVgNCBkkLAwIaBQMDBIE2BQ0eAhAaBg0nAwMTTQIQFAM7AwMGAwsxAzBVRAxRA28fFiAJPA8MHwIbHg0nKAI1QwMRBRICFgMnGQQsBA4DGSsdQAIBC209NQYDCxtEAieeQIMBFUsJNiYBA0MOAlgDCysHNQ0EAQZCSAiSHGmxJzQHgjGBX4FZBgyKFpUNBhMvhAGMc4Y8kW9kmD8gjUWVLIUXAgQCBAUCDgEBBoFjPIFZTSRPgmcJRgMZD44gDBaBCgEMgj+FFIpmQjMCOQIHAQoBAQMJi0oBAQ
IronPort-PHdr: A9a23:d1npUBOvJCy8Bx45VJcl6nZKDBdPi9zP1nM99M9+2PpHJ7649tH5P EWFuKs+xFScR4jf4uJJh63MvqTpSWEMsvPj+HxXfoZFShkFjssbhUonBsuEAlf8N/nkc2oxG 8ERHEQw5Hy/PENJH9ykIlPIq2C07TkcFw+6MgxwJ+/vHZXVgdjy3Oe3qPixKwUdqiC6ZOFeJ Qm7/z7MvMsbipcwD6sq0RLGrz5pV7Z9wmV0KFSP2irt/sri2b9G3mFutug69slGA5W/Wp99Y KxTDD0gPG1w38DtuRTZZCek5nYXUTZz8FJCA13swz31fsivniel6eNg2Re3I9XrF+ELCQipt 5xOYUPQjWBXPhI30E7e0eh/2fE+wlqr8h4vmJKLSpObEP5ie7OCfNI1QkNdYcd+Wxx6QZG9Y tYrN9RcDeZKkIrxtlgTqUuXOAqKGcLxwGJrnVv49/Jr9sYwUiXfhAsEPtEVnmXVjOv/FIksc cO//K30zzfYd8Jo1QzysdfkUAsNkKquYLF1aprow052DQyfqUeWjoPeIha42aMoq2SKzbJHd d2PjkEcrCVr+jWJ9uclio7ttI5Mkl776i955qttGYDgGBsoKc7hEYFXsTmdLZczWM45XmV07 T4z0aZV0XbaVC0DyZBiwgLWSNXdLc6G+Bv+UuaWLzpiwn5oK/qzhBe3pFCp0fa0FtK131BDs jdfn5HSu2oM2R3e5onPSvZ08kq7nzfa/w7J4/xCIUc6mLCdLJgkw7UqkYEUv1iFFSjz8Hg=
IronPort-Data: A9a23:O1Xuw67kcZUorZbPLQph5QxRtD3CchMFZxGqfqrLsTDasY5as4F+v mUXD2CDOKnfMzb2fYp0aYri8kNUvZKDnIBjQVBlry9jZn8b8sCt6fZ1gavT04N+CuWZESqLO u1HMoGowPgcFyOa/FH3WlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2+aEuvDnRVvW0 T/Oi5eHYgT8gmYlaj58B5+r8XuDgtyi4Fv0gXRjPZinjHeG/1EJAZQWI72GLneQauG4ycbjG o4vZJnglo/o109F5uGNy94XQWVWKlLmBjViv1INM0SUbriukQRpukozHKJ0hU66EFxllfgpo DlGncTYpQvEosQglcxFOyS0HR2SMoVj+q/Me36RqvWK3nP+KHXc0qVvEUY5aNhwFuZfWQmi9 NQDLSwVKB2TjOLwzqiyV+9sgcouNo/nMevzuFk5kGqfXKlgGM+SBfyQure03x9o7ixKNfbTY clfYzt1bxTHZw9nIVYLTpwklfquhn7xficepF/9Sa8fvDCKllwugOCF3Nz9XPezBth6u3ajt 0Xm81nYJkoHP9+Gxm/Qmp6rrqqV9c/hY6oSHbu+++UsnEaYxmsdBRsXWnO0pOn/jEOiM/pUI lYQ0jAjoag16UqnVd7zQwKxunPCtRkZM/JKGvEhwACA1qSS5ByWblXoVRYYNYdj5ZBzHGN7k wbTwJX3AHpk9rOPQG+b9rCaoCn0NSV9wXI+WBLohDAturHLiI8phw/JTtFtHbTzidvwGDrqx CuNojR4jLIW5fPnHY3glbweq2v0/sKbfR1//QjNQGOu4yVwYYPvNcTi6kHW4bwEZMyVR0WI9 ipM0cWPzvE8PbfUngy0QcIJAO6I4dSBO2bimlJBJcQq2Ams3H+BRrpuxg9CCn1nCPtZRg+xU nTv4VtQwLRxIEqVabRGZtPtKsYykonlO9fXdtHVSdtscJFBTRK1+gNuaXHN2Gq3okwnkPw8C 6y6auepN24RUo58/Qq1RsAc8L4l/T8/zmXtXqLGzwyr/L6dRXyNQ5IXGQKqQsFgy43cuyTT0 dJUF/XS+iVlSOekPxXmq98CH24FPV0QJM7QqfUOUsWhPwA/OmUqK8GJ8IMbY4Y/wphkzLbZz EqcBH1d5kH030DcCAOwbXtmVrPjcLB/oV8/Pg0uJVyY4GciU6n+8JYgc4YLQpd/+NxB1fJUS 9w3S/eECNlLSRXF/G05Rrv5p4pAah+qpFyvOwyIXTsBRKNjFjf5ooLcQgjS9Sc1HnWWs+k6q OaezQ/1e8cIaDljK8f0U8iR6W2Nk0ITo89IZHuQEOJvIB3t1KNINx3OiuQGJpBQCBfbmRqf+ QWkITYZgujvsYYFycT7g4KEo7j0FOEkLE5RHjTY342XLgjfxHKomqVbYdaLfBfcdWL6w7qjb uNr1MPBMOULsVJJkohkGZN55Psay/q2gJEC1SViPnHAT2rzO4NaOnPcgPV+7Pxc9IFWqS6de xyp+OADHZ6rJcm8MloaBDR9X9S5zftOxwXjt6UkEn7buh1y0qGMC3hJHh+2jydYErt5HaUlz colu+8U8waPsQUrAPnXkhFr83mwEVJYX5UFrp06BKrZujgvwHxGYr3eDXbSy7OLYNNuLEIrA 2G1gIzvurdi/XfBIkEDTSX14elghJo1qE9ryn0GLA+3gdbrvKI88yBQ1jUVdT5r6Ct7/dh9A UVVEnFkBL6v+m5ojfdTXmr3FABmAgaYy3PLyFAItTP4SW+0WkzkMV8NOeSE1x0c+GdyJzJe/ K+qzVj0dTPQeODwwSoAdkp3oNPzTdFK11PjmeL2O++nDpUFcT7erav2XlUxqjzjGtIXuE3Lg cJI7dRAQ/T3GgBIqpJqFrTA86obTS61AVBrQNZjzfsvJn7dcjTj4gq+ARm9Ve0VLsOb7HLiL dJlI/9OcBGM1CyuiDQ/LoxUKp9WmM8Z3vYzSonJF0Un7YTG9iFItajO/BfQnGUoGtVisfgsI 7PrKg6tLDaiumt2qUTs8u9/JWuKUfsVblbd3ce00tkzObAtjeVOSXw2g5yI5yi7EQ0+8xyt6 VaJI+ecyuF50o1jkrf9CqgJVU3+Ndr3U//O6wyp9chHadTUK8rVqgcJsR/dMh9LOacKEcFC/ VhXXAUbAGue1Frub13kpg==
IronPort-HdrOrdr: A9a23:vB8FMKyZFQthipOLVY+iKrPxouskLtp133Aq2lEZdPULSKOlfp GV8MjziyWYtN9IYgBZpTnyAtj6fZq8z+893WB1B9mftWbdyQ2Vxe1ZnOjfKl7bamXDH4xmpN 5dmsFFYbWaZzkbsS+T2nj7Lz9K+qjjzEncv5a4854bd3APV0gP1XYaNu7FeXcGADVuNN4cLt 6x98BHrz2vdTA8dcKgHEQIWODFupniiI/mSQRuPW9t1CC+yReTrJLqGRmR2RkTFxlVx605zG TDmwvloo2+rvCAzAPG3WO71eUdpDKh8KoPOCW/sLlbFtzesHfnWG2nYczCgNkBmpDi1L/tqq iNn/5vBbUx15qbRBDOnfKk4Xic7N+F0Q6k9bbfuwqnnSWxfkNHN+NRwY1eaRfX8EwmoZV117 9KxXuQs95NAQrHhzmV3am9a/hGrDvHnZMZq59ns1VPFY8FLLNBp40W+01YVJ8GASLh8YgiVO 1jFtvV6vpaeU6TKymxhBgY/PW8GnAoWhuWSEkLvcKYlzBQgXBi1kMdgMgShG0J+p4xQ4RNo+ 7ELqNrnrdTSdJ+V9MLOM4RBc+sTmDdSxPFN2yfZVzhCaEcInrI74X65b0kjdvaC6DgDKFC6K gpfGkoxFLaIXiedvFm9Kc7jCzwfA==
X-Talos-CUID: 9a23:z64I22H29M3x+MLaqmJC9l4fQMYLaUTE3UnoeEGIGDZoVbqaHAo=
X-Talos-MUID: 9a23:xXLo6AnZm/SGNLm5zo58dnpEH/4r/ouLOHsctrUKhuigbjF7OC6S2WE=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="70128780"
Received: from 153-97-179-127.vm.c.fraunhofer.de (HELO smtp.exch.fraunhofer.de) ([153.97.179.127]) by mail-mtaKA26.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 15:51:49 +0100
Received: from XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) by XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27; Thu, 9 Nov 2023 15:51:49 +0100
Received: from DEU01-BE0-obe.outbound.protection.outlook.com (104.47.7.169) by XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27 via Frontend Transport; Thu, 9 Nov 2023 15:51:49 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=H7TYEWW/nxUNGT/FqTBAbUUjyHp022/kx08xQtLxvBW97NhrDOfy75dZ8tPtmYY+0og6xMkkYB8ugnXPYjJKMRZT7I4JejKn8jiEAIyAgCsRyDmm5Q6tfov1hZHW2lYahSbDmRtR1xAMrlmqB7akhdkYaPQIDRhTG0PxMIR2eLOeSccbAcNGX7TIopCKePlrF05w5tGhKYCufg5Jikeel+Cr/5z5XYUvkzxS+XhJ11ab83GkSQsVoDdojcsVXUx9BpvwQrrtFUh3xnkMkMTMkEyihvhDPuSZJT65I9JbGS2tp96hz0V40ulhDpcU2B0YT2eu4mw8LZgp3CwEsY8alQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=AGDgH76Dd77auiVEvpu29W8Tc0SMA4Pm/8aDfHGa3Lg=; b=Xrb0ontyiwml4lkE0Si3XnQNWV/qYPVOHcEnFUc6v9JeS7VbR+kRtdOZYqaQiVlRDz/yRrKBV6Dc1h7CrqlPHBV9PdbqKAib/FVKDL4kZBfxlZer93+XGbEzvtLSNFs3VqCo3yQnYd5FS12yuZcGScjXQv4HUCrqYlZv7UbYbFef3CeEKk6GNGGH3kSIG9IPscOhF+1AyzXRwZ3mQwoad7ctPDHJc2vhhA1+UkIipCSnxgrWzK2UJtUhIZusyOtqDOJKI9qFUBGvvcscandJt7XONGR46rMFQGawjEyCavGw5UpIVP4BZUy/ztCQ6yiBes5ErmdsCR1DIVPh2JbcqA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=sit.fraunhofer.de; dmarc=pass action=none header.from=sit.fraunhofer.de; dkim=pass header.d=sit.fraunhofer.de; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fraunhofer.onmicrosoft.com; s=selector2-fraunhofer-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=AGDgH76Dd77auiVEvpu29W8Tc0SMA4Pm/8aDfHGa3Lg=; b=j83t7BzfLltmx7iiGoAtWiGdXS+zie5LPV5XhzWkdykul8AUkNuIvb5KsLfB79MJy+Lq0oLIksFyiHVbHFVHKbXlTjjspYVdSg17DJsDY3JUkms8Qbo1rg2OznOgSuMEg/MpdyJ0OHWHmGSoLr0eNXHahoLZd10fWwbhNE0T508=
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8) by BEZP281MB3303.DEUP281.PROD.OUTLOOK.COM (2603:10a6:b10:25::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6954.30; Thu, 9 Nov 2023 14:51:46 +0000
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a]) by FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a%4]) with mapi id 15.20.6977.018; Thu, 9 Nov 2023 14:51:46 +0000
Message-ID: <1ebfa3e2-f0e3-0b09-13b6-ccb55384e415@sit.fraunhofer.de>
Date: Thu, 09 Nov 2023 15:51:45 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: hannes.tschofenig@gmx.net, 'Carl Wallace' <carl@redhoundsoftware.com>, rats@ietf.org
References: <6FCC00F5-1FAE-4CCD-9ED2-DA2BA923E7F7@island-resort.com> <011801da130d$74579390$5d06bab0$@gmx.net> <66c6191b-c393-69da-a849-f44da369917a@sit.fraunhofer.de> <7DC2D9E1-F052-48A1-B5A8-978D52275EE5@redhoundsoftware.com> <01e001da131a$a8c7ba30$fa572e90$@gmx.net> <9b8eb6e3-1b9b-7a0a-dffd-f8d0912a7bb6@sit.fraunhofer.de> <01ec01da131b$c66ce140$5346a3c0$@gmx.net>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
In-Reply-To: <01ec01da131b$c66ce140$5346a3c0$@gmx.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-ClientProxiedBy: VI1P195CA0068.EURP195.PROD.OUTLOOK.COM (2603:10a6:802:59::21) To FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: FR0P281MB2879:EE_|BEZP281MB3303:EE_
X-MS-Office365-Filtering-Correlation-Id: 42349df5-bb5f-4ba6-4a26-08dbe1336582
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: k+eV9QCdiWADDi+WmMOIFDVR0F2S/Wzn0ybgDEBUfd8L+jsY6ox+jRjhDOle1ZTAnPZs3xr3YUbog2zLTLhtLvLXvHx0xaFQhSp1orn3mK/aBDKICanEGEq/4rUNZ5Av6yEbOwuBAXtobqGPNYyc0unqpsc5XK8jE5tPkrjakYgZNkU6u95HApSSoTOSCouUTunX5siWXck9EO411Z8oK9NWhOgQGrZDi16VdIEGyFgMXbJUdUvdprnoohJt1rnN5/HhdC0gX8MtWGb+uEEiZ1/qBkVDp1YrtxcCMD8II5FXETD6K6vMKduo/CLb/MIvKK4NMUjdxdUHJST+cpEzu2meScPaYucJeq09uceeGFIuNudZEdzArU7D/Ua9SSqJ4kwsQMNeikuy7CzBOqf6rc0DfeeXVVn6w7NK40us04pXzcjfzOsHjWi87AWEMbeMsnRuOSm+VRSQmU6zYzlJyZZCxmh6SZmSxkL8eGjN3ABK3FxHBMUN3X9d1oQwKXCaulEDSwACu5YJmiQrcVSheiJjPZ7n3sI5gh4sJYAKE/3KDUSbQZSHYGpYngf0LOjoQfBTxwkPl/7eg8XbyVz2Yz0eOGKsny46BWkR2+KgBpU67y8W9q/8wO7ln6ORCk2VhBHdIQEWRTCR7hL3EyteTKlSH6jDjymXQ2ol5JmAat/gTGjPEOAreGx8wVbwT9tS
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(136003)(346002)(376002)(366004)(396003)(39860400002)(230922051799003)(64100799003)(451199024)(1800799009)(186009)(6512007)(2616005)(82960400001)(478600001)(6486002)(8936002)(966005)(8676002)(5660300002)(31696002)(44832011)(41300700001)(86362001)(2906002)(66556008)(66946007)(66476007)(316002)(53546011)(6506007)(31686004)(38100700002)(83380400001)(43740500002)(45980500001); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: pZEAIy8HAhKtJtxNtMfnCbLycaHKdX3uVILJsxVtaRB/PbN7mkSBj9O5ey3JiEgPL2gmUoS4HoaoGYxw8heojdOIoScvlsClburlAjwhHotqKvxxSBq/bMX0+nw8sbUhx+23sRVW4UTpH2um/gefIBHMtFCmGlIEEpy/efdkhh8rNHaUJQoQS+4E9+isoFD5YkwYFXEIr6JOi39T3czU/AfQJtjMB+BwrAB6JPWlVBsgl1cj5poiLTKalAs5OvRxMFhDIwa1G9txPRV/PmBC/J0PKXLa+/7VFD6Y2YUbfbEn+FLkyRuqAl4b71cGHfWwSIgnXSrfBF2rcErVJyMdHkkahrk++W2LTHuUZ1Wk5wvv93cH2RIg9YcLd+J12l6EcbHXsHdMFNurkZwepHZYAUOo7mthiOaOeC4wXCjibYVeR9QrDSqzeVreU9I/nJFOW5kJPg/Elgp2I3g9y+1n5C0x3ZasAYBEvPVFr7hr6Ua1VU09Y3wA+L95gq2irPCMGmGNj/LEuEK6SsvuAvFFpnQF8vmk332DmvGXNrij3WFa3cpWjBQV1NAf5ttbk7qUTqaTtnHXKcGHxAe0xYlMxFcXZjL5L7jw51x9rMVnBxeDnA6BZvuZeacO6E23eGaOFdHNJ/ai8dhg0wVn72/nvEWxQQXDFO7/3lIBNWjUct+1ZilCCJNBEWCuuZ0XYF9P5op/dxNJluvkN5yTdqqA4qQLvf/Ti2F5GJTtzrNF6JNfbOo8sGU8whXPl3G5Ay7E9nJKwzRc1A3HCoI3cA3jtgLHiUtETiXuMfpVsi+3alNdOXapRtoIaQrKkji/zj50JIOu2UEBLVcviOM80umUjjIGsHF1u5MgZ0DNtS5+tIyIeDJwjJzZTw9C6CBK766CQqeN9hZG/jHAwic5QuqQPhsBo8ch/cWgOd6sBh8HTL8Eq+Jq+I2pFwagqF0Hj9JN0RzI/o/yZ9jkc6NDe3kf61A8mglfGlDp7AjQhy56tx8q6ur9GuAge9lBY9Lc3b+z/rO3IH2ZReP4Y4QmLJmC8i8g0AyYhJ4tQHy1RhOrWp3aVR/MFGknevOG/powBwBXzfGEQrwpSqL2FO4GcBxjPjXzHZu+uYv5XOgWlqY313YMYMh0zC39s3V62DaCKQBb976Y+C95EkReGDdKe6BGAruQkrW0jV2ttpyuVKN1Y1GR1pwnwjcIMhdd9UjR/YixrZvMc+iJ7iYyEbaP5wydAfbRNmHEAYPxGe6YWyBfrFzngkg8wJLPskR7wn1YbkGr09EUr8DTZu7VpTLyux1HWPOmz82SBOYIXMqZnVe9uprx7mM/Yrro6khWnrYbtgIXEG4Y9oBrqi3gBrOdNTZ25wfhpZyQ91OSQYhDVov0a0QuyMokoQDKKRsb/voKYu5XHmITOx1miEaFBvCKL+3ugrjJ5B5glc8WAQ+rBKpRSDYgmyVF+ftwS7YJnH47cFeX+O8nrohRvCcYLJTLmCAJnCN87seqKQoN6dKUT5J4M5b3C0Y9hqolL6Urk0x8kbZmuDnv7F2ZUfYqqQCIFBn4pZsNzgnETmrCZ7jdhbokD4GiOq6wXEn3ubwxjZKdZUFf7Y5ePj+QC+BcOzbfWV8w1vP36WjmiUbzLK/E60YdPBYKBV7wxgmlMELnpclQYfy9ZyrYyXuJpls4yS/gQl1XfBP6D02/l/GEJVUZHSgx34w=
X-MS-Exchange-CrossTenant-Network-Message-Id: 42349df5-bb5f-4ba6-4a26-08dbe1336582
X-MS-Exchange-CrossTenant-AuthSource: FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Nov 2023 14:51:46.6793 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: f930300c-c97d-4019-be03-add650a171c4
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: 21VqAHlTuqlRh6NBUNQ0FXV9H6xRJo3WbeSBkmiPwtEBSHKepzaKgS5YKpRQKnD5WdX02TTjOCPJKATaSfehcJrLvtluiettyGR2HPgP8Ro=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BEZP281MB3303
X-OriginatorOrg: sit.fraunhofer.de
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/XbgIS1uZVnhOdsmLzsRjyfacBKk>
Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Nov 2023 14:52:31 -0000

Hi Hannes,

If we agree on a content style template/example based for the "new" 
Claims in the I-D, I'll commit to adding the existing EAT Claims (only 
Claims that made it to the registry yet) based on that style asap.

Viele Grüße,

Henk

On 09.11.23 15:48, hannes.tschofenig@gmx.net wrote:
> Hi Henk,
> 
> I am wondering whether it takes long to make this mapping of the claims. Since you expressed interesting in helping with the draft, this may be something you could be looking at 😉
> 
> Now I am more worried about the time delay introduced via the process.
> 
> Ciao
> Hannes
> 
> -----Original Message-----
> From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
> Sent: Donnerstag, 9. November 2023 15:43
> To: hannes.tschofenig@gmx.net; 'Carl Wallace' <carl@redhoundsoftware.com>; rats@ietf.org
> Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
> 
> On 09.11.23 15:40, hannes.tschofenig@gmx.net wrote:
>> Hi Carl,
>>
>> A few responses below:
>>
>> * The use of CBOR/COSE in SUIT: At the start of the SUIT working group the participants expressed a strong preference to use CBOR/COSE and didn't want to use ASN.1/CMS. Brendan and I had written a draft that used ASN.1, which was inspired by work Russ did. It happens that work being proposed does not align with the expectations of the group. I remember Henk and Carsten being vocal proponents of CBOR & COSE at that time. Was it a good idea to use CBOR/COSE instead of ASN.1/CMS? Now that the standardization and implementation work is almost finished it is a bit too late to ask this question again.
>>
>> * Do we want to provide claim definitions in ASN.1 format (as we do in the draft)? That was our understanding from the design team discussions.
>>
>> * Should we keep the definition of the CBOR/COSE claim definitions in sync with the ASN.1 format? I believe there is value in doing so. There does not seem to be anything wrong with the semantics of the claims in EAT. We have received feedback already for better alignment since we have introduced a few bugs in the -00 submission.
>>
>> * A question you did not ask was: Should all claims in EAT also be described in an ASN.1 format? Currently the draft only contains a subset of the claims. I have been asking myself the same question. It is somewhat likely that sooner or later all claims defined in EAT will need to be available in ASN.1 format.
> 
> Had the same thought, did not dare to voice it. I can imagine Mike groaning (as he wants to move fast). Not sure, if this I-D is the one to do that. Mike?
> 
>>
>> Ciao
>> Hannes
>>
>> -----Original Message-----
>> From: RATS <rats-bounces@ietf.org> On Behalf Of Carl Wallace
>> Sent: Donnerstag, 9. November 2023 14:45
>> To: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; rats@ietf.org
>> Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
>>
>>
>> On 11/9/23, 8:09 AM, "RATS on behalf of Henk Birkholz" <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org> on behalf of henk.birkholz@sit.fraunhofer.de <mailto:henk.birkholz@sit.fraunhofer.de>> wrote:
>>
>>
>> I think this discussion is mood as was pointed out in the meeting already. Please see:
>>
>>
>> https://www.rfc-editor.org/rfc/rfc9334.html#figure-9
>> <https://www.rfc-editor.org/rfc/rfc9334.html#figure-9>
>>
>> [CW] I don't think that diagram renders this discussion moot. X.509 certificate-based attestations have existed since before RATS (and before we called attestation evidence). There's not even much question about potential for including claims in an X.509 certificate within current RATS documents (see section C.3 of EAT). I think the questions are: 1) do we want to provide ASN.1 definitions for claims and 2) do we want to keep claim definitions (roughly) in sync across ASN.1/CBOR/JSON. Re: 1), there's seems to be general acceptance of defining claims in ASN.1 for the most part (though no one really answered Brendan's question regarding why ASN.1 was disallowed for SUIT but is allowed here). Question 2) needs some more discussion. There was an exchange between Mike and Laurence during the presentation yesterday that highlights a potential difference of opinion between I-D author(s) and participants in the working group that could impact the adoption question.
>>
>> On 09.11.23 14:05, hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net> wrote:
>>> Hi Laurence,
>>>
>>> The charter says:
>>>
>>> “
>>>
>>> Standardize data models that implement and secure the defined
>>> information model (e.g., CBOR Web Token structures [RFC8392
>>> <https://datatracker.ietf.org/doc/rfc8392/>
>>> <https://datatracker.ietf.org/doc/rfc8392/&gt;>], JSON Web Token
>>> structures
>>> [RFC7519 <https://datatracker.ietf.org/doc/rfc7519/> <https://datatracker.ietf.org/doc/rfc7519/&gt;>]).
>>>
>>> “
>>>
>>> CWT and JWT are mentioned as examples. The group already works on
>>> another evidence format, namely the TPM-based stuff.
>>>
>>> I would say that the document fits nicely within the scope of the charter.
>>>
>>> Regarding the document split. I am open to discussions about your
>>> suggestion, which assumes adoption in the group.
>>>
>>> Ciao
>>>
>>> Hannes
>>>
>>> *From:*RATS <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org>>
>>> *On Behalf Of *lgl island-resort.com
>>> *Sent:* Donnerstag, 9. November 2023 13:59
>>> *To:* rats <rats@ietf.org <mailto:rats@ietf.org>>
>>> *Subject:* [Rats] draft-ounsworth-rats-x509-evidence-00
>>>
>>> I think it might be better to split this into two drafts.
>>>
>>> First, define how to put CWT/JWT claims into ASN.1 and make an X.509
>>> attestation token.
>>>
>>> Second, define the FIPS and CC status claims for CBOR, JSON and ASN.1.
>>>
>>> I wish we didn’t have to do the first, but understand that we might.
>>> Note that the RATS charter says we work on CBOR and JSON. There was a
>>> little discussion about ASN.1 back in the early days and we certainly
>>> put it off back then. There was also YANG discussion. Search the RATS
>>> mail archive for ASN.1.
>>>
>>> I’m much more interested in the FIPS and CC status claims. I would
>>> like to define them for CBOR, JSON and ASN.1. If they are booleans
>>> this is trivial. The would get registered in the CWT and JWT IANA registries.
>>>
>>> One of the reasons I’d like to define them for CBOR and JSON is so
>>> there’s a known and accepted way to translate their ASN.1 claims into JSON.
>>>
>>> Also, the X.509 definition should be for Attestation Results as well
>>> as Evidence. There’s no reason to restrict it and there’s no work to
>>> allow use as Attestation Results.
>>>
>>> LL
>>>
>>> (sent incorrectly the first time only to the rats-chairs; meant it
>>> for the list)
>>>
>>>
>>> _______________________________________________
>>> RATS mailing list
>>> RATS@ietf.org <mailto:RATS@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/rats
>>> <https://www.ietf.org/mailman/listinfo/rats>
>>
>>
>> _______________________________________________
>> RATS mailing list
>> RATS@ietf.org <mailto:RATS@ietf.org>
>> https://www.ietf.org/mailman/listinfo/rats
>> <https://www.ietf.org/mailman/listinfo/rats>
>>
>>
>>
>>
>> _______________________________________________
>> RATS mailing list
>> RATS@ietf.org
>> https://www.ietf.org/mailman/listinfo/rats
>>
>