[Rats] draft-voit-rats-trustworthy-path-routing updated

"Eric Voit (evoit)" <evoit@cisco.com> Fri, 26 June 2020 01:11 UTC

Return-Path: <evoit@cisco.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81E2B3A10BD for <rats@ietfa.amsl.com>; Thu, 25 Jun 2020 18:11:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.599
X-Spam-Level:
X-Spam-Status: No, score=-9.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=KVHhgtFx; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=094CsXQA
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i0-phCsH-yyU for <rats@ietfa.amsl.com>; Thu, 25 Jun 2020 18:11:32 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D7283A10BA for <rats@ietf.org>; Thu, 25 Jun 2020 18:11:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8043; q=dns/txt; s=iport; t=1593133892; x=1594343492; h=from:to:subject:date:message-id:mime-version; bh=Wb1WyisIIkYc2zrQrt+4/q2EYdDJSzCcTw7uVaylLrY=; b=KVHhgtFx13osqLGeGcoNwCJ/YYqy8trAXVcwT4S12pyofgDT8tfNd6bK TTbnu+wqyn9RkGKgkpvU27dJAtlvVgSErrHhbL+DzI1WfxpOQI4gfIMTs CSPOWWXrprLqYPfECnHFQekcjAnyJdearGkgK/DS6kDvrBSTclCKZ0Okr o=;
X-Files: smime.p7s : 3975
IronPort-PHdr: =?us-ascii?q?9a23=3A22Ei0R2OR3pWcnqasmDT+zVfbzU7u7jyIg8e44?= =?us-ascii?q?YmjLQLaKm44pD+JxWGv6dsgUPHG4LB5KEMh+nXtvXmXmoNqdaEvWsZeZNBHx?= =?us-ascii?q?kClY0NngMmDcLEbC+zLPPjYyEgWsgXUlhj8iK6PFRbXsHkaA6arni79zVHHB?= =?us-ascii?q?L5OEJ8Lfj0HYiHicOx2qiy9pTfbh8OiiC6ZOZ5LQ69qkPascxFjA=3D=3D?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0AQCgAYSvVe/5FdJa1ghCVRB28rLS8?= =?us-ascii?q?sCoQmg0YDjUyYWIJSA1UEBwEBAQkDAQElCAIEAQGERwKCJgIkOBMCAwEBCwE?= =?us-ascii?q?BBQEBAQIBBgRthVsBC4VuAQEXER0BATgLBgEZAQMBASsCBDAXBgkBBBMIBhS?= =?us-ascii?q?DBYF+TQMfDwEOoh0CgTmIYXaBMoMBAQEFgTYCDkGDNRiCBwcJgTiBU4EUiX4?= =?us-ascii?q?agUE/gVSFZwEBAgEBgV2DEjOCLZkXgRGaSgqCW4QqglaBRpERgnKBGIgNknO?= =?us-ascii?q?RQ4oYlDYCBAIEBQIOAQEFgWoigVZwFRqDCglHFwINkg6FFIVCdAI1AgYIAQE?= =?us-ascii?q?DCXyNaAGBEAEB?=
X-IronPort-AV: E=Sophos;i="5.75,281,1589241600"; d="p7s'?scan'208";a="779905547"
Received: from rcdn-core-9.cisco.com ([173.37.93.145]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 26 Jun 2020 01:11:31 +0000
Received: from XCH-RCD-004.cisco.com (xch-rcd-004.cisco.com [173.37.102.14]) by rcdn-core-9.cisco.com (8.15.2/8.15.2) with ESMTPS id 05Q1BVRm015290 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL) for <rats@ietf.org>; Fri, 26 Jun 2020 01:11:31 GMT
Received: from xhs-aln-002.cisco.com (173.37.135.119) by XCH-RCD-004.cisco.com (173.37.102.14) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 25 Jun 2020 20:11:31 -0500
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 25 Jun 2020 20:11:30 -0500
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 25 Jun 2020 21:11:30 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=gsIi0N3JulwlZAIziYmf81uDCGzvYWxVOQxnz/IEfCJTaQHfrVtSm4NMwd+3vnVdtQINPeLGUefGCanvdsGpipdF3KTHDlL8eDQCu3FtpAe/2SDzVnVUqWlSN8n4lT8QBXCHK/jLWbb5I/P9ExQnuUjqd8w0k2p64G70BJr5MaYEqy1vBmP9FU8OStqANqI8nWhGxdHiQpwD82UaF7RQ01dlLVTs32e0GLqTaDjcxVl61dtCpOPDmnFAk2dtUMiqPssgClYY53bBMlVbJ4uMHPzkRJ83gY3402Q5+nNBZRqWnVk1rpF1J3x2FQf7YxQA9mhoZGhWRDiEt2JeTjcFqA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3DwXGq0TxCtHvoVdOO11xuGqvKWUrUX8oWIWjiNP30M=; b=YPHoM8Ac3pZrvE+jvYOHMvp+5H7L1QO8NSrjKglr6n01yHqcQBaiXUm+P1ghy0/+e3CxKqrZERksNNIk1AhwJ/fEqoA1M76Hm1lTHtVcctMOQD+jXamdSJF4kYlKXW+mkrM65RJWfAgy6XCkAR3p9NY/5ESyDU7Urvz7L3ysi3ptusUkkVU2hJS6byvFKjWgu+HIKJMJnMZhT9JFihaSq/mJL0uutqOoReKg1pzKyyBioBoKdghsedrbgTNbrIH8HHUTSrq7RZipzUNzDYZWMKCwd/7k8Y6E7sVG54EqJX6NzY83vKmTNNCarf9vAkDZNVpA+YYdl4B43dR7801H/g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3DwXGq0TxCtHvoVdOO11xuGqvKWUrUX8oWIWjiNP30M=; b=094CsXQASXELOvCHmMsjCPh3XbK8O03z//OCGjgEb+glhSZ22mLxjvbQQpi0PtF6lWAI5Zhu7pkrEBoSr7i5BX4G1LgHqNud90tmdBn1nsGiJg5EQvzWhTG0JTno8XHT1/Lv+kJSrDJlYQmemRWvcmMrc9jfzboaj/fw8W60e5k=
Received: from BL0PR11MB3122.namprd11.prod.outlook.com (2603:10b6:208:75::32) by MN2PR11MB4238.namprd11.prod.outlook.com (2603:10b6:208:188::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3131.21; Fri, 26 Jun 2020 01:11:29 +0000
Received: from BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::20ac:d8b4:4a4f:4290]) by BL0PR11MB3122.namprd11.prod.outlook.com ([fe80::20ac:d8b4:4a4f:4290%7]) with mapi id 15.20.3131.023; Fri, 26 Jun 2020 01:11:29 +0000
From: "Eric Voit (evoit)" <evoit@cisco.com>
To: "rats@ietf.org" <rats@ietf.org>
Thread-Topic: draft-voit-rats-trustworthy-path-routing updated
Thread-Index: AdZLQCLuiyDkoxMqSPSfT3Ptq4IDbA==
Date: Fri, 26 Jun 2020 01:11:29 +0000
Message-ID: <BL0PR11MB3122F3604B23BDAD2DB304A6A1930@BL0PR11MB3122.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [173.38.117.87]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: cca3ce6e-eb89-4af4-0759-08d8196ddb5a
x-ms-traffictypediagnostic: MN2PR11MB4238:
x-microsoft-antispam-prvs: <MN2PR11MB423893AC3F5208CC832001A7A1930@MN2PR11MB4238.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0446F0FCE1
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: QsmgRMgQWn2QLwx0GDpUTfcoFNXCzI9ezeB9u+6ApN+sIzw6GKQaRYPPhBz4Gs3Xqsb4axhJq/W3XRip3404WhgvfS+yepddjnesqjEkxgxQJajt5jpuFc9GDY7PmEDJxy1cFRM8d5nwqGs0nOifv3lYLw36zZr90jSA5rHbq1TgHtMjbhQKby9zTM50pgr7vGxOwiXNgehDg3M69W8ToldItOkfiDijjXZ1QeMWMg4lCxsAKSCdXQuSkZYliXWnTJqgIge385tqjpPRS4siLqCGEIZrabTQepV4oHlvEg/mw6adD22+crCl3u4/Smd++JtUIC1ei/uIOYoXF/cZJs7kQL4PW/ZXdAYj1v86ineW0MFuAQXyO48gUmqe8fb3L+yt/4XVnlqMexqWOYBnug==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL0PR11MB3122.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(346002)(39860400002)(366004)(136003)(376002)(396003)(33656002)(15650500001)(66574015)(26005)(83380400001)(64756008)(6506007)(53546011)(2906002)(66946007)(478600001)(7696005)(186003)(966005)(99936003)(316002)(66446008)(66556008)(52536014)(6916009)(9686003)(8676002)(71200400001)(66476007)(8936002)(76116006)(5660300002)(66616009)(55016002)(86362001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: 166Q94Zv3NPXwXnVHLDihDcMeeoERhopHysR/fOn9eO93P/XzYRC0U1nH/zXpB9wN+sHREm8uvwrB1Tw7lSWFHCjpwj4O5xhSg/g4PcNac8WO+E4EC5UE3+DsHzdDAju8Y65N3epCjkIdYvsKylN7dxuyLz4OXu4FVApBhYRYU/uL17JyTa5aN4Y55EuQX50oliZZQbotyIiqMZebqI7IFghfh1MDw7aZYaTXvKFmSezpD2smPBZLlYGGMvuUS8h0MP/30H6hd7OhgwKEESt0VXN9/fyLNVwb7Xcwx74XPW9FphTqxjCJfh/V0RXH/uKJlrpgi3fM9QJwv1eFepJQ+ikL0a0ZXYvEMrPRD6QNQmboDIWTqAWZP0d69Bqr3nk+0BW0Y4xQLIzR74tR4ZueM5p2yeanzLQR4IpUe+OYyI55U8LcQwG0uKkmZRg2Oq572gZLbNu0f34xUPAHv6PDmtInJ+IvXDYeISgtxIQszL4w1JX84xRBCPmnixHotUF
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; boundary="----=_NextPart_000_0603_01D64B1E.A2B28980"; micalg=SHA1
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL0PR11MB3122.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cca3ce6e-eb89-4af4-0759-08d8196ddb5a
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jun 2020 01:11:29.3736 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: HOm3r3MUnvAk+UXp01RhDC4Br5t18VPiHzM1Kml2NihoSvNK1A3cZgBJpSRqHXle
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4238
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.14, xch-rcd-004.cisco.com
X-Outbound-Node: rcdn-core-9.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/ZyCyZ4hgQ3naUVlcFMjHDPmtZpQ>
Subject: [Rats] draft-voit-rats-trustworthy-path-routing updated
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Jun 2020 01:11:35 -0000

Updates from v02 of draft-voit-rats-trusted-path-routing go into 
draft-voit-rats-trustworthy-path-routing-00  (I needed to do a file rename due 
to an IETF submission glitch).  Changes include:

   o  Added timing diagram that aligns to the architecture draft and the 
interaction model draft.
   o  The Attester's AIK is included within the Stamped Passport.  This 
eliminates the need to provision to AIK certificate on the Relying  Party.
   o  YANG modules integrate fully with charra as well as NETCONF cryptotypes 
and keystores.

Thanks,
Eric

-----Original Message-----
From: internet-drafts@ietf.org <internet-drafts@ietf.org>
Sent: Thursday, June 25, 2020 6:20 PM
To: Eric Voit (evoit) <evoit@cisco.com>
Subject: New Version Notification for 
draft-voit-rats-trustworthy-path-routing-00.txt


A new version of I-D, draft-voit-rats-trustworthy-path-routing-00.txt
has been successfully submitted by Eric Voit and posted to the IETF 
repository.

Name:		draft-voit-rats-trustworthy-path-routing
Revision:	00
Title:		Trusted Path Routing
Document date:	2020-06-25
Group:		Individual Submission
Pages:		26
URL: 
https://www.ietf.org/internet-drafts/draft-voit-rats-trustworthy-path-routing-00.txt
Status: 
https://datatracker.ietf.org/doc/draft-voit-rats-trustworthy-path-routing/
Htmlized: 
https://tools.ietf.org/html/draft-voit-rats-trustworthy-path-routing-00
Htmlized: 
https://datatracker.ietf.org/doc/html/draft-voit-rats-trustworthy-path-routing


Abstract:
   There are end-users who believe encryption technologies like IPSec
   alone are insufficient to protect the confidentiality of their highly
   sensitive traffic flows.  These end-users want their flows to
   traverse devices which have been freshly appraised and verified.
   This specification describes Trusted Path Routing.  Trusted Path
   Routing protects sensitive flows as they transit a network by
   forwarding traffic to/from sensitive subnets across network devices
   recently appraised as trustworthy.




Please note that it may take a couple of minutes from the time of submission 
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat