Re: [Rats] draft-ounsworth-rats-x509-evidence-00

Henk Birkholz <henk.birkholz@sit.fraunhofer.de> Thu, 09 November 2023 13:40 UTC

Return-Path: <henk.birkholz@sit.fraunhofer.de>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD28BC17EB7B for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 05:40:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.597
X-Spam-Level:
X-Spam-Status: No, score=-1.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, GB_ABOUTYOU=0.5, NICE_REPLY_A=-0.091, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sit.fraunhofer.de header.b="0cHYhPX/"; dkim=pass (1024-bit key) header.d=fraunhofer.onmicrosoft.com header.b="diOc/3Z4"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W1yW2NSyRf_y for <rats@ietfa.amsl.com>; Thu, 9 Nov 2023 05:40:11 -0800 (PST)
Received: from mail-edgeka27.fraunhofer.de (mail-edgeka27.fraunhofer.de [IPv6:2a03:db80:4420:b000::25:27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0DB01C137380 for <rats@ietf.org>; Thu, 9 Nov 2023 05:32:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sit.fraunhofer.de; i=@sit.fraunhofer.de; q=dns/txt; s=emailbd1; t=1699536772; x=1731072772; h=message-id:date:subject:to:references:from:in-reply-to: content-transfer-encoding:mime-version; bh=ZTGADqriyiXmKITFsCoXszeRP3tTGvj7OoNh4JHXyg4=; b=0cHYhPX/HPwNwnhT/wnEni2P6yEyGXVmsn8mecvIyWUXKap5NHSEukhT cw/K6STmmQsJ4XaCg4CoDWpaiIS2pMBkY7sLl7sLeGdhne/N9/aH5Sser J0RXcG81CuWn20YxHu8n6zb21cbYtI/BP3FWl2toUkfqLsYObNjCOFtra UT50Wdt+vLMdlfFgPb9iJhRq7yDyUsObuUmWSCr87lv7oCa8EsE6jWk+c aGJEfn5OOUpoS1WkDbc6WcsE91ett8SyPnARG7RmEDpXJOcTDB1GQsMMu lpJO9MZe8zRQfouejhn43uAaYnhzPWjInxHyNHR5S2cIQ8Ihglq/KcTiK Q==;
X-CSE-ConnectionGUID: I5jv5K/sTWmka4H1fPDTTQ==
X-CSE-MsgGUID: V8WJ6TwBRCOze4/k3Wd8tg==
Authentication-Results: mail-edgeka27.fraunhofer.de; dkim=pass (signature verified) header.i=@fraunhofer.onmicrosoft.com
X-IPAS-Result: A2HeAwAp3kxl/xoBYJlaHgEBCxIMQIFEC4I5eoFdhFODT41iLQOcUoEsFIERAy4fCQ8BAQEBAQEBAQEIAS4LCwQBAQMBA4R/AocoJzQJDgECAQMBAQEBAwIDAQEBAQEBAQIBAQYBAQEBAQEGBgKBGYUvOQ2DFmqBHQEBAQEBAQEBAQEBAQEdAjUMDRsBHgEBAQEDAQEhDwEFCAEBLAQIDwsRBAEBAQICIwMCAicLFAkIBg0GAgEBgnoBgioDMRSsIHqBMoEBggkBAQaBB1BBrggYX4FfCQkBgRAug1yELgGKBxcfgVVEgRUnDoJ1PoIfQgEBA4EoARECAUyDL4JohmOCAxUuBzKBCgwJgQODUoNCiX9dIgVCcB0DBwN/ECsHBC0bBwYJFBgVIwZRBCgkCRMSPgSBY4FRCn8/Dw4Rgj8iAgc2NhlIglsVDDRKdhAqBBQXgRIEahsVHjcREhcNAwh0HQIRIzwDBQMEMwoSDQshBVYDQgZJCwMCGgUDAwSBNgUNHgIQGgYNJwMDE00CEBQDOwMDBgMLMQMwVUQMUQNvHzYJPA8MHwIbHg0nKAI1QwMRBRICFgMnGQQnBA4DGSsdQAIBC209NQkLG0QCJ54+gwEVVFwEU1gDNlRCOBjELDQHgjGBX4FZBgyKFpUNBhMvhAGMc4Y8kW9kmD+NZZVdhGYCBAIEBQIOCIFjgSZwTSRPgmcJSRkPjiAMFoNWhRSKZnU7AgcBCgEBAwmLSwEB
IronPort-PHdr: A9a23:gNC7pRxvDnHmQkDXCzKPy1BlVkEcU8jcIFtMudIu3qhVe+G4/524Y RKMrf44llLNVJXW57Vehu7fo63sCgliqZrUvmoLbZpMUBEIk4MRmQkhC9SCEkr1MLjhaClpV N8XT1Jh8nqnNlIPXcjkbkDUonq84CRXHRP6NAFvIf/yFJKXhMOyhIXQs52GTR9PgWiRaK9/f i6rpwfcvdVEpIZ5Ma8+x17ojiljfOJKyGV0YG6Chxuuw+aV0dtd/j5LuvUnpf4FdJ6/UrQzT bVeAzljCG0z6MDxnDXoTQaE5Sh5MC0ckk9vBDH09CzcZpbBjSmgi81m2A6UG9erbaEZfm/84 J5aE1zh0DoWZz8kzUX+358V7upR9R6ggBc4mLyIQb+vL9hZTpvTfvYRGDVOYppjcjJYOduOY YIfA7AfPedZitDeuXVX8QSvLDidWMf1yzB6vGSt5oQlj/kzGiba3A09Jt8QiU6OlYTQKYYfX d2olrHk8BqeZKlpyGatsIrQdAEMhqmPd+tUKpPRkmpsRhqYhXeRo6HUOmOs3PUdikew0bRvX LuFiXA3lzxD4Qihz8kiqbPzosUP0VXE8y8l5J80KojrAF4+YMSjFoNXrT3fLYZtX8c+Fnlho z1polVnkZuyfSxPxZgoyh3WMaPBfZKB/xTjU+icO3F0iSEtdLG+gkOq+FO7gq3nV8ay2UpXt CcNjNTWt34M2hCSosiKQ/dw5AGgjB6BzQnO7OFDL00u063dLp8q2LkrkZQP90/EG0fL
X-Talos-CUID: 9a23:FiG78mxQACfkjdFC2NGyBgU1R8I7L16a10vvJkyxVUYwRoW5dWOprfY=
X-Talos-MUID: 9a23:VVQ6jQi7BN/YnZNOujjKxMMpCpdXwfqSF2o3urIUtpXDNndPN2eBg2Hi
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="2661133"
Received: from mail-mtaka26.fraunhofer.de ([153.96.1.26]) by mail-edgeka27.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 14:32:49 +0100
IronPort-SDR: 654cdf7f_3rwpaP6F1MEYYU1QcZ9MqDOpJR5Ftr1yqdiugPI6fGFuAAo 8TT58VyLliqLKptkRq9xN3Car8HogZTW8KiPvDA==
X-IPAS-Result: A0BsCQAp3kxl/3+zYZlaHgEBCxIMQAkcgR8LgWdSBz41WIEFhFKDTQEBhS2GQAGBdC0DOAGcGYEsFIERA1YPAQMBAQEBAQgBLgsLBAEBhQYChyUCJzQJDgECAQECAQEBAQMCAwEBAQEBAQMBAQUBAQECAQEGBIEKE4VoDYZMAQEBAQMBARARDwEFCAEBFBgECA8LEQQBAQECAiMDAgInCwcNCQgGDQYCAQEeglwBgioDMQIBARCgNQGBQAKKKHqBMoEBggkBAQYEBIFPQa4IGF+BXwkJAYEQLoNchC4BigcXH4FVRIEVJw6CdT6CH0IBAQOBKAERAgFMgy+CaIZjggMVLgcygQoMCYEDg1KDQol/XSIFQnAdAwcDfxArBwQtGwcGCRQYFSMGUQQoJAkTEj4EgWOBUQp/Pw8OEYI/IgIHNjYZSIJbFQw0SnYQKgQUF4ESBGobFR43ERIXDQMIdB0CESM8AwUDBDMKEg0LIQVWA0IGSQsDAhoFAwMEgTYFDR4CEBoGDScDAxNNAhAUAzsDAwYDCzEDMFVEDFEDbx8WIAk8DwwfAhseDScoAjVDAxEFEgIWAycZBCcEDgMZKx1AAgELbT01CQsbRAInnj6DARVUXARTWAM2VEI4GMQsNAeCMYFfgVkGDIoWlQ0GEy+EAYxzhjyRb2SYP41llV2EZgIEAgQFAg4BAQaBYzxpcE0kT4JnCUYDGQ+OIAwWg1aFFIpmQjM7AgcBCgEBAwmLSgEB
IronPort-PHdr: A9a23:R6cUVhdHCa2/++LINRV/VHDHlGM+/N/LVj580XJao6wbK/fr9sH4J 0Wa/vVk1gKXDs3QvuhJj+PGvqynQ2EE6IaMvCNnEtRAAhEfgNgQnwsuDdTDDkv+LfXwaDc9E tgEX1hgrDmgZFNYHMv1e1rI+Di89zcPHBX4OwdvY+PzH4/ZlcOs0O6uvpbUZlYt5nK9NJ1oK xDkgQzNu5stnIFgJ60tmD7EuWBBdOkT5E86DlWVgxv6+oKM7YZuoQFxnt9kycNaSqT9efYIC JljSRk2OGA84sLm8CLOSweC/FIweWUbmRkbZmqN5hGveZDIgzPHkNJ86BaYZ/DRVrATVxK4s od6ZTiz1ig+BmV6+TnKm5xxkZ9/iUfywn43ydvYYaaec6FMIoLjR8g4Ylp5UMV0XHEeDb/gX a4RFtFZD+hRv4WnuVsPrD7nJheCXb/w2xZ5tyPSx6w14d46Sjrvw1A9DdkprHTVsez4Kp4oC 9nk6bTpwDn+cqlO9QrStYOSTQFw8amORbRhXO2JymN2M1icjg6z6t38Yji31+4ggm3L1uBxR duAoFB5pAgoiDqx1vsRuMr5iIsbxHP+zwE+2p0wJduyFGpiYNHxQ9NA8iCAMI1uRdk+Bntlo zs+1ugesIWgL0Diqbwizh/bLvmbequhuEylWvyYPDF4g3xoYvSzikX6/Uuhz7jkX9KvmBZRr yVDm8XRrH1FyRHJ68aGR/c8tkes0DqCzUbSv8lKO0kpk6rcJZM7hLk2k5sYq0PYGSHq3k7xi cer
IronPort-Data: A9a23:3pf+Fa75FeVt93CGjj13JAxRtHfCchMFZxGqfqrLsTDasY5as4F+v jQfWWDUPPiCNDCnL4x0O47j8U0OupCDztdqSwVspH1mZn8b8sCt6fZ1gavT04N+CuWZESqLO u1HMoGowPgcFyOa/FH3WlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2+aEuvDnRVvW0 T/Oi5eHYgT8gmYlaj58B5+r8XuDgtyi4Fv0gXRjPZinjHeG/1EJAZQWI72GLneQauG4ycbjG o4vZJnglo/o109F5uGNy94XQWVWKlLmBjViv1INM0SUbriukQRpukozHKJ0hU66EFxllfgpo DlGncTYpQvEosQglcxFOyS0HR2SMoV+yJjpe3qZ7PWvwlSFKHuvmKlBDHkPaNhwFuZfWQmi9 NQDLSwVKB2TjOLwzqiyV+9sgcouNo/nMevzuFk5kGqfXKlgGM+SBfyQure03x9o7ixKNfbTY clfYzt1bxTHZw9nIVYLTpwklfquhn7xficepF/9Sa8fvDCKlVIui+aF3Nz9f4XVRtR1n3ahq 0HM4WDmDT4QC/+b1m/Qmp6rrqqV9c/hY6oIHaGj3v9nnFPVwXYcYCD6TnPi/KL82xH7Ao0Ob hVOpWwwqO45skKxR8T7Xxq2rWTCshN0t8dsLtDWITqlk8L8ywiDD3UCTjlPZcZgs8kzRDcw0 USOkc+vDjtq2IB5g1rAnltNhWrqYXJHHnxIfiIeUwoO7v/qpYx53FqFTc9uHOTxxpf5EC35i WLC5iUvpaQhvehS3YWC/HfDn22NoLrNRVUL/Qn5ZD+uwT54Q4+HXLaWz2bnw8xOF6una2WQn WMlnpGe5d8eDJvWmy2qRv4MLY6T5P2EEWP9h3hzE7kI6gad+3yqVt1V6zRQfU1sMtg2fAH4R ErpvSJQ+55hE3+4ZoBnY4+KKpoLzIqxMf/HR/zrft51TZwpTzC+/QZqfl+242DhtGMOgJMPE 86XXuj0BElLFJk96iS9Qtks9IMCxwc89Dv1fo/6xRH26oiuTieZZpldOWTfc91jyr2PpTjU1 NNtN8Gq7RF7e8+mawn19b8jF3w7HUIZN7vX9fMOLvWiJzB4El4PE/XSmLMtW7J0lpRvy9vnw CuPZV96+nHe21v8NgS4WlJyYujOXLF+j04BEw4CAFKK40UnMKGTtPoxVp1vZrQ21v1R/dgtR dk/RsiwKPBuSDPGxjcjUafAvLFSLBSGuAbfEBemMR4efoFhTTPn4tXLXBXi3whQAzuVtfkRm ayB1ATaSsAHHyBnPtfnWMyyxnzguEotuf9AcHbJBvJxe0zc1pdgBAKsr/0wIuAKcQ7iwBnD3 SmoIB4on8v/iK5rz8vsmoa/sJaPL+tyOmF4Dlvrx++6GgeC91Xy3LIadviDeA7scV/d+YKgV L1z9O79OvhWp2R6mdNwPJgzxJ1v+ua1gaFRyzllO3D5b16LLLdECVve1Oltspx9/JNoiTGUa GmupOYDYa6oPfn7GmE/PAAmN+SP9c8FkwnosMgaHh/I2z9VzpGmD2NpIBi+uA5MJuBUMaQk4 9sbluw41gidsicuY/G61n161mLUNXERcbQVhrdDCq/Rtwcb4FVjY5vdNyzI3K+ye+h8ancNH DvFq5fB1pJ9x1XDeUUdDXLi//RQrrVQtQFozG0tHUWomN3EjaUzhDlUwyUGfjpIxzoW1tBDG 3VZGHB0AY6s/D5YotdJcE7xOgNGBTyfolfQzXlQnkLnbkCYbE7/B0xjBvSo42Yi7HN6QjhX2 Jq62VTVe2/mU++p1xRjRHM/jeLoSOJA0zHrmeelLpyjJIY7az+0uZ2eTzMEhDW/CPxgmXCdg /dh+dtxTqjJNSQwhakfIKvC3JQyTCG0HkBzcctDzogoQ16FICqT3AKQIX+fYslOfvzG0XGpA vxUe/5gaU6M6zasnBs6W4g3PL5GrNw47oEje5TqB1I8nZmxkz5LiK/Upw/C3DIFYtM3ncgEf 9abM3rIF2GLnnJbllPctMQOaCLyfdAAYxa6x+yvtvkAE5UYqux3bEUuyf2Osm6INBd8tQeh1 O8Zi3Q6E8Q5oWi0o7bRLw==
IronPort-HdrOrdr: A9a23:wFzdCqzwaj9fBfaIfBgaKrPwC71zdoMgy1knxilNoHtuA66lfq GV7ZcmPHrP41wssR4b9OxoR5PwJk80maQY3WBzB9eftWvd1ldARbsKhbcKqAeAJ8SRzIFg/J YlU5IkVZnbC19kgd3h6BS5FdEBzbC8gcWVrNab9SwxCTxNL5tbySdVMG+gYylLrQB9dPwEKK Y=
X-Talos-CUID: 9a23:h8lAlW8qMgKchAdASDqVv3YkPe5/cFuA9UvdOgzjCSUyFJKVcWbFrQ==
X-Talos-MUID: 9a23:4H34nw0rgLx7/QY30waLtYVOPjUj5v3xC1EtkKU/tuqOKyhvNBiXsxezXdpy
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="6.03,289,1694728800"; d="scan'208";a="70116736"
Received: from 153-97-179-127.vm.c.fraunhofer.de (HELO smtp.exch.fraunhofer.de) ([153.97.179.127]) by mail-mtaKA26.fraunhofer.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 Nov 2023 14:32:47 +0100
Received: from XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) by XCH-HYBRID-03.ads.fraunhofer.de (10.225.9.57) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27; Thu, 9 Nov 2023 14:32:47 +0100
Received: from DEU01-BE0-obe.outbound.protection.outlook.com (104.47.7.169) by XCH-HYBRID-04.ads.fraunhofer.de (10.225.9.46) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.27 via Frontend Transport; Thu, 9 Nov 2023 14:32:47 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Dup8+s6ZpvWav9p/g8N898VltKIVgT/aszM5zXiDDTHC3A1dXHSSSiSWHFr3gBMIqlQJl8l5lZLp7kZsy8EwOaLSqMOJxaD+B1L0NxfHFKTnC6XeH0AmUve0PZbDqprboskod59MBY18npuiKNu7Pa4pLNq9OHcn9hncNgSTG73fytW4GNWWwc8Ut2uygshgMna/Y3LRniP0T1VLtoO/5LjWQ43zf652LjMbL5VNmc98pGzv1QWbzfVuB4QwLviOujEfekQ+ahosBSXWvGCvmlcwgrKnpqR71e8BP9O9no5XtJoSkW3pwURknilSFzcxbpSSAH5HTvfZRL0eE7lD3w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=OoQYpUNPiXWj2UOshOfNr5HyEO36gQY3+a0uy8iuULA=; b=hRspzKsFSLjF2hGRVUDyK7QjuRYzxBEg/oOz+kWdZTryJdxVWjttNY4VW+53MZk6V4zu2fiB48T31bCuwF/CxDFRFSmVkd+ysGoZTcrnMm741CDGxoxXpe4qK5wzPM40X/cwtkeGZRCK/R5hiF7T7JvuovxJJqS0PPdIbIlFgYMgyqWOqm+6yc4hEmfxg6VJnWxA7f5h+2bXYyMXpy8cua48XLmB1OT4IabiKA7+pxXfNo4ptmxP76lSVlyJBsxvssp9vEeAzoC9AzoFF8GuncX11T73BCdEHquy5TD6cjyutMJL4rd2XkDvF/qHk9KC8tAZlx1nTLvnAq11Pk+Gkg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=sit.fraunhofer.de; dmarc=pass action=none header.from=sit.fraunhofer.de; dkim=pass header.d=sit.fraunhofer.de; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fraunhofer.onmicrosoft.com; s=selector2-fraunhofer-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OoQYpUNPiXWj2UOshOfNr5HyEO36gQY3+a0uy8iuULA=; b=diOc/3Z4IVRsJOXPfkMc57gT4ZMvqS0Zfaxd2vhiiM1KvF14wyAYY4LrigZRs3SAw4uzcOthiuQevQR2Q9MuIedUu2pDUG5c2Wy980jpnyEO0kB1L31h3K+9q5cJibEYm8QbyxQGCV6ga1BjvxTUZ+XfaffKRRL/rsmhnb4Lqig=
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8) by BEZP281MB2820.DEUP281.PROD.OUTLOOK.COM (2603:10a6:b10:5d::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6977.18; Thu, 9 Nov 2023 13:32:45 +0000
Received: from FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a]) by FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM ([fe80::30a4:de38:a6f2:252a%4]) with mapi id 15.20.6977.018; Thu, 9 Nov 2023 13:32:45 +0000
Message-ID: <02ede7ed-abb3-ca25-3b93-3ae7fc0035e7@sit.fraunhofer.de>
Date: Thu, 09 Nov 2023 14:32:44 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: rats@ietf.org
References: <6FCC00F5-1FAE-4CCD-9ED2-DA2BA923E7F7@island-resort.com> <011801da130d$74579390$5d06bab0$@gmx.net> <PH0PR02MB7256944BAD4E6910520FD6FAF2AFA@PH0PR02MB7256.namprd02.prod.outlook.com> <013f01da1310$53dc4540$fb94cfc0$@gmx.net>
From: Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
In-Reply-To: <013f01da1310$53dc4540$fb94cfc0$@gmx.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
X-ClientProxiedBy: FR0P281CA0190.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:ab::15) To FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:4c::8)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: FR0P281MB2879:EE_|BEZP281MB2820:EE_
X-MS-Office365-Filtering-Correlation-Id: ab3c4a0f-8669-4cdf-b8e8-08dbe1285b80
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: td6tgVBoaqbggGu3lhjGdjHaRYS5N4S+ngESoj3rmAt1gfvMMHnlVINE2FdWQ3qz8yKXAtMfFC6Z/CqVwcRZ1x+DpPW4+7atF9aHCy0Ili4lp+sk09aivwQGZw+nZTo+dWOHej37Gl/aSsz7wkPijUPsBQ9qjaFKo4hV1ogKZLeEsI7gpWlgoyve818IUQeJQQ5NPXwNLquDTYubzMTzhcZFgXcgmgBI1e6X8Kk6v/k9iFvhluqhnwiqXGtuPyUqO593Nn4juKsuWrZr6rWoRMEpjFINn4jvITuUgBQOXhZTJbGLmigt1RgW7ufQcBVGlPPpCdWNYIz5y0hlBqF1R9xN6jM/vFEsGMuotORuSa+bAselkqJ9mjXI6f+wYE1+TGuxV3s14jhy38tXVcqiFwrujOM76iFlLhqBLJo37RK1FNqhMh71qzMvFkwxEIwLmDRBlSvgeF8CELloB6chcvlMbZ5IUKRgqCJXSMq594MXu9CEpn4J0iDXGhsPp1mJ1KKP4e4FBeIKNb53iD8HgyrnL1iDaiJfqYtVJCWIP2nY0r/Y1a5IZJ8I5riOpFK4Rgqy0bj6Db5PoSG4/Gzr9qA0EvDMblYQ9SRF3slk/Chak4w8eyRofHjjbdE9vgfeKWauLjFk/0Rlsa+ltcGED77wLRAsqynd2VoINZBtE5UibikpO3pgJ6wyCVs15s5B5tPirFlZIU/unSWSJTjJbo6c7kOqw7Oe6bO1+kS+jd4=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(136003)(376002)(39860400002)(396003)(346002)(366004)(230922051799003)(230173577357003)(230273577357003)(451199024)(1800799009)(186009)(64100799003)(2906002)(26005)(41300700001)(83380400001)(5660300002)(31686004)(2616005)(966005)(6512007)(6486002)(6506007)(44832011)(53546011)(8936002)(38100700002)(478600001)(31696002)(86362001)(8676002)(66476007)(6916009)(316002)(66556008)(82960400001)(66946007)(43740500002)(45980500001); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 4JUPtHWed1YthP4bsYXbfrRnn4GHwBQ5hZvYb7W5V96O8uCv2Fqi3gDE7t0gBbioDelbwm6eDG0HjpXebj9w0BCC5czr2bMSyOzPS5YgiMpTiOZIpg18oAP3sg/uwcRubrwsjbu3QTLwgAJ/rj4D0Eh595XIga+zdqWWNpguv1OYja0dcrcRV98ywltwhW61xEGl3tAgl30Ib2DsgpmdGMJA7RPheFNNNTOQB+FnqhFgSDZudxGtEEwxkxYnRIYrL4jfxg83//+9gThvw2TISdqvYC5oEtxncMJXEeeF91thIh0TcD3sWOm79Hjtb7pU0fwgfi+HBpB+VwswiHirOeTe7XELXsC8hE+xPnoFP8soL174CMta2FwGdyLJUaI95VLUYqKiP2lRoYcMaC8DL1wVOAUipMoKn4nlk8H7BNribHtCAVobFa5hWjRKTxXBTDgHCqmJbshBhV5ptxpCkSSYzKU50ExbSaJP4IHA1aUNcqlWbFVcPyvvvjF0AaS/r2w7FlUEt7n3HF7FnMeKIRI7fg+x89MhDAZyEIpEB6LIJfmSlPkq0UVaJuN3Lo8v4ckUnQ6hA4XSzhX1E76qHi2YFlF8SRFjV4b2bCtAV9+ItMs0hRIy8jEEjMKDguLBn+vzqehCBl81sMWaQpR5rpzxyARCDn0jXQy7g1nZAhDysrmKjq+qRGofyJeqbPsEE7IUCvSb9Be7hW8iza9ojM8Jji3kMHD7ZSiFs1kQaNEoAXONyQ+hn6cGcSwgbpXyusNaAF0gTpV4CFUhtMExBdeR+X/lQ8vhFNntuUoXQ7P3CU4DOKPzt2OG9qOQNnZVMK5fWKe1QkEWuNe9vH4Zi0c44jVPwRGE7HWT09RYYjYBxPJYNLnufhiKLhvSumKufJVNMEUM1y2OjJRmCwcIh7WY77XF2LkUFoChnGfo8YKEdV3u6e3ebk1i92vzB3zVjWgW8mn6tnHXYb7j7i3mFc4jnJMWPp0Be4/MeZSgYvhtwKDW9XqYJ5ThNOZtu3UM7VFVDHRQuWkSgCvefMkKXkeEcsuCuOEifnsGdeEbh1eZZuQ7v/QTXx3oDMCou/gfV8nAVDi1ENweff/z5E/hqQz6sBoNH094dGVaIUESLtHMehXtiZfxl+e17futuYbDbUoy5caO6mw8pfQz3aQTs+3pHGHOOo4LHfNN5+Hzw0wx6OuRCaCgkcFaXvqW9ccBNSDV8chisVYjxzt+HMUQTZF9lcT/qjlxOzBSTJ0yjCGB1sxNQpklr2wm/xry1GqrDBdyn4ve/kdhwZsVXuOBwMxdnO3h607+X5yVzhw758vzcxEswTUDrBAjP2PIdQ9niAlgy4RM6eJ6M92+S1STUCMe9efDk4mNxdx7Z4WC1aF5l0UJhnEXcg3ax51h60WTPh8Hm5biuiLkQOz0u/Xb9Xt/WJbDCLsPdfH7CgtFAb6L9mGwb0XnVmGXf250ADJwud4ygKLCL8Xsj/7RJalERtvgfBwHPjYOSYosZtUw02cJ6We3/nTaF03r199NH9A7jveLSE5TtMYP9ImdWZvpAdg0bi8o7Y0KGKIJMKSFZcR9ARjtSDUfZ8eLb/rf+HgMFdekfvKWlL1WdgPIvydww1gc7qu0CaeTsbiQ8apOY0A=
X-MS-Exchange-CrossTenant-Network-Message-Id: ab3c4a0f-8669-4cdf-b8e8-08dbe1285b80
X-MS-Exchange-CrossTenant-AuthSource: FR0P281MB2879.DEUP281.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Nov 2023 13:32:45.4360 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: f930300c-c97d-4019-be03-add650a171c4
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: UnE1H32jUgD/uZ23geXCtWD58w0nWV70DJW2Zw478XV9VHkmImXp2w/GIm1LO7ogsg2zNohy3O8JJJex4d/rGsnairfdxs7XYljLQlIVzxI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BEZP281MB2820
X-OriginatorOrg: sit.fraunhofer.de
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/bJTfEOIVyB1F9Sfk-8u5fCNJbXE>
Subject: Re: [Rats] draft-ounsworth-rats-x509-evidence-00
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Nov 2023 13:40:15 -0000

Well....

they are self-assertions included in Evidence (as roots of trusts cannot 
produce Evidence about themselves).

Theses assertions about roots of trusts will have to be checked (I am 
deliberately not writing appraised) by a Verifier, to see if they match 
the capabilities of said root of trust's Endorsements.

But I agree, these Claims can appear in Evidence.


On 09.11.23 14:26, hannes.tschofenig@gmx.net wrote:
> Hi Jeremy
> 
> We briefly talked about the relationship between the DLOA claim and the 
> newly defined FIPS claim in the draft.
> 
> The difference is that DLOAs are essentially endorsements and the newly 
> defined FIPS claim is evidence. The idea is that the device performs a 
> self-test to compute the value.
> 
> Ciao
> 
> Hannes
> 
> *From:*Jeremy O'Donoghue <jodonogh@qti.qualcomm.com>
> *Sent:* Donnerstag, 9. November 2023 14:08
> *To:* hannes.tschofenig@gmx.net; 'lgl island-resort.com' 
> <lgl@island-resort.com>; 'rats' <rats@ietf.org>
> *Subject:* Re: [Rats] draft-ounsworth-rats-x509-evidence-00
> 
> Hi Laurence,
> 
> The existing DLOAs claim is one way that FIPS and/or CC claims could be 
> transmitted (since that is exactly what it was defined for).
> 
> Jeremy
> 
> On 09/11/2023, 15:06, "RATS" <rats-bounces@ietf.org 
> <mailto:rats-bounces@ietf.org>> wrote:
> 
> *WARNING:*This email originated from outside of Qualcomm. Please be wary 
> of any links or attachments, and do not enable macros.
> 
> Hi Laurence,
> 
> The charter says:
> 
> “
> 
> Standardize data models that implement and secure the defined 
> information model (e.g., CBOR Web Token structures [RFC8392 
> <https://datatracker.ietf.org/doc/rfc8392/>], JSON Web Token structures 
> [RFC7519 <https://datatracker.ietf.org/doc/rfc7519/>]).
> 
> “
> 
> CWT and JWT are mentioned as examples. The group already works on 
> another evidence format, namely the TPM-based stuff.
> 
> I would say that the document fits nicely within the scope of the charter.
> 
> Regarding the document split. I am open to discussions about your 
> suggestion, which assumes adoption in the group.
> 
> Ciao
> 
> Hannes
> 
> *From:*RATS <rats-bounces@ietf.org <mailto:rats-bounces@ietf.org>> *On 
> Behalf Of *lgl island-resort.com
> *Sent:* Donnerstag, 9. November 2023 13:59
> *To:* rats <rats@ietf.org <mailto:rats@ietf.org>>
> *Subject:* [Rats] draft-ounsworth-rats-x509-evidence-00
> 
> I think it might be better to split this into two drafts.
> 
>     First, define how to put CWT/JWT claims into ASN.1 and make an X.509
>     attestation token.
> 
>     Second, define the FIPS and CC status claims for CBOR, JSON and ASN.1.
> 
> I wish we didn’t have to do the first, but understand that we might. 
> Note that the RATS charter says we work on CBOR and JSON. There was a 
> little discussion about ASN.1 back in the early days and we certainly 
> put it off back then. There was also YANG discussion. Search the RATS 
> mail archive for ASN.1.
> 
> I’m much more interested in the FIPS and CC status claims. I would like 
> to define them for CBOR, JSON and ASN.1. If they are booleans this is 
> trivial. The would get registered in the CWT and JWT IANA registries.
> 
> One of the reasons I’d like to define them for CBOR and JSON is so 
> there’s a known and accepted way to translate their ASN.1 claims into JSON.
> 
> Also, the X.509 definition should be for Attestation Results as well as 
> Evidence. There’s no reason to restrict it and there’s no work to allow 
> use as Attestation Results.
> 
> LL
> 
> (sent incorrectly the first time only to the rats-chairs; meant it for 
> the list)
> 
> 
> _______________________________________________
> RATS mailing list
> RATS@ietf.org
> https://www.ietf.org/mailman/listinfo/rats