Re: [Rats] What's to EAT? - terminology clarification

Laurence Lundblade <lgl@island-resort.com> Mon, 18 November 2019 05:31 UTC

Return-Path: <lgl@island-resort.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16A1A12088E for <rats@ietfa.amsl.com>; Sun, 17 Nov 2019 21:31:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t39UCZji0hgQ for <rats@ietfa.amsl.com>; Sun, 17 Nov 2019 21:31:12 -0800 (PST)
Received: from p3plsmtpa09-07.prod.phx3.secureserver.net (p3plsmtpa09-07.prod.phx3.secureserver.net [173.201.193.236]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D673D1208E5 for <rats@ietf.org>; Sun, 17 Nov 2019 21:31:12 -0800 (PST)
Received: from dhcp-96dc.meeting.ietf.org ([31.133.150.220]) by :SMTPAUTH: with ESMTPA id WZczi6zpnoPMbWZd0itHBp; Sun, 17 Nov 2019 22:31:11 -0700
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Laurence Lundblade <lgl@island-resort.com>
In-Reply-To: <24439.1574051408@dooku.sandelman.ca>
Date: Mon, 18 Nov 2019 13:31:08 +0800
Cc: "rats@ietf.org" <rats@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <8C37D486-D4CD-414D-962B-31993C5991B6@island-resort.com>
References: <229E0A72-4B44-4C9A-AD0A-142A13020C9A@intel.com> <MWHPR21MB0784058F591C52EEB31E0736A3770@MWHPR21MB0784.namprd21.prod.outlook.com> <4F586E15-9CF7-4824-87F2-8E2C20D1AF1D@intel.com> <MWHPR21MB078439E9EB07E3BB72E15137A3760@MWHPR21MB0784.namprd21.prod.outlook.com> <71173EC8-A167-47B9-B0F1-05759D59890B@akamai.com> <20191113071244.onqdgo2roqt7efb6@anna.jacobs.jacobs-university.de> <B555FC8E-FF3B-468A-B3DF-9F10DD6FBBF6@island-resort.com> <20191114141138.dipzizem6a6wh6cr@anna.jacobs.jacobs-university.de> <24439.1574051408@dooku.sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.3445.9.1)
X-CMAE-Envelope: MS4wfGGT4wcM12U3JvjDujTuoSsT5EHFmhxwtXGmgNvEU9JD0YtOlDyJCJ5voBYdGt7xBOeVHnsB8FxoE2tNsmrvSn3qJvEd3JnBPB6XT4u/lHUnQZVQU3op cLcsxeeGtaZTqVvHLPSpH93gtEOViwln0C2XmchyE3eNsNqVZ3d9kYk7PRDFo3yy+EL9EYn7alwMRrpdabAbmbOwtpgXha8NiOVRfKLYcYXyhAIOXBtAUTQI
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/cZrmPZ1cLxBQeiKkkDzkdkD5VSo>
Subject: Re: [Rats] What's to EAT? - terminology clarification
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote Attestation Procedures <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Nov 2019 05:31:16 -0000

Seems to me that the CDDL in the EAT draft is working well to define claims that are mechanically serialized into JSON or CBOR and added to JWT and CWT.

Isn’t that the end of the story? Is there a problem with the EAT doc?

LL


> On Nov 18, 2019, at 12:30 PM, Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> 
> 
> If we are going to use JWT/CWT for the security of EATs, then I am skeptical
> that CDDL (or any other Data Modeling language) brings anything to the table.
> 
> What we need are clear semantic descriptions of claims.
> Often we will need some anciliary data associated with the claim, and
> sometimes that data will be more complex than a single binary blob.  In those
> cases, a bit of CDDL will benefit us.
> 
> I don't think that a YANG model will help us at all for this.
> 
> -- 
> ]               Never tell me the odds!                 | ipv6 mesh networks [ 
> ]   Michael Richardson, Sandelman Software Works        | network architect  [ 
> ]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails    [ 
> 	
> 
> _______________________________________________
> RATS mailing list
> RATS@ietf.org
> https://www.ietf.org/mailman/listinfo/rats