Re: [Rats] Review of draft-birkholz-rats-daa

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Wed, 26 May 2021 13:59 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D77F43A2F7A; Wed, 26 May 2021 06:59:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=gyg3lpNY; dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=gyg3lpNY
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SerSMjw7WQYz; Wed, 26 May 2021 06:59:08 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-eopbgr150080.outbound.protection.outlook.com [40.107.15.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24F983A2F71; Wed, 26 May 2021 06:59:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QZA6IPvIiht0ftuyn/YWXf4Ma2FHA2H3OESZdTNFYng=; b=gyg3lpNYQ5q89ZRPuluUh/rdCC4cCtJmgAqKrnmYETx2qsTdcOq8yhSs3CLgeJbFuYwG7jrkTAhr3MSX/5z9rmdeybCNPX4u2UTRe0ezPlqcWO3zjmC8Qh745RRxIr+AySocaIrRDEjkZxzb+mmqYfkoPoP8LiWtTXIR/8vI2X4=
Received: from AM6P191CA0080.EURP191.PROD.OUTLOOK.COM (2603:10a6:209:8a::21) by DB6PR0801MB1637.eurprd08.prod.outlook.com (2603:10a6:4:3a::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4150.27; Wed, 26 May 2021 13:59:01 +0000
Received: from AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com (2603:10a6:209:8a:cafe::b7) by AM6P191CA0080.outlook.office365.com (2603:10a6:209:8a::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4173.20 via Frontend Transport; Wed, 26 May 2021 13:59:01 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=pass action=none header.from=arm.com;
Received-SPF: Pass (protection.outlook.com: domain of arm.com designates 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT035.mail.protection.outlook.com (10.152.16.119) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4129.25 via Frontend Transport; Wed, 26 May 2021 13:59:01 +0000
Received: ("Tessian outbound 0f1e4509c199:v92"); Wed, 26 May 2021 13:59:00 +0000
X-CR-MTA-TID: 64aa7808
Received: from bcc9414d97c1.2 by 64aa7808-outbound-1.mta.getcheckrecipient.com id 29E3988E-7BB6-47E1-B1FF-9369DDA303D9.1; Wed, 26 May 2021 13:58:53 +0000
Received: from EUR05-AM6-obe.outbound.protection.outlook.com by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id bcc9414d97c1.2 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Wed, 26 May 2021 13:58:53 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BXhXUlg20TOdOHz+fVe0br+N+Hrbiw3zh1ucKA9SMbd4ikjc1MpbJF431ycGNNsNbNCaru8tCClM/jF6ZVzHFF6jKBcg2EtTGtL6VXv6XiUO6j5nyk/wTV0IViLARfFEXb+ubIhSo+jYFTLt8V3tv3rmEuJDf+ujGS0h2DnEOE6VkNgGe33HYX4ze97UpgfguhFMQPX2gOMG+4A3g2GDIWKhJ46EpcnsKF1VC5TiAqmnbUHZQZ14WfHypvdlusAeZSU8LXFvmrTlOvlLRv6vwtTUHG8aSU1SJuGzIsbncYEb1cBOIvTAOm3AN20Vmfo1eD9ZkPL1mAUUrcJvENzt2Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QZA6IPvIiht0ftuyn/YWXf4Ma2FHA2H3OESZdTNFYng=; b=iPRInfX5cCSay7su3HEwyXdvuXh29QzHhZAKKJFOduC/mwBBOlBdp/Vnn+2Rl4Q/J+U9+jMkm1aAOTByKH/b6DkH1KoTHz4Xxfse5XEpX90ytgLmmeF07g99k5T/NQpSErPKnJnpbNR4E141K1WAQKwh4M6q2UxVR8piKoRiqxrIDv3GXjXY/uYjKogIhcA3vAIccVZvoGQp26X/0924lWqFI3TAk5VcEt1JZ2zYB4CL0v4YNQbusx+TnvsvIBIMmFQ4uc/iVGeXU2eoC6IHzt+aUTI44+DoIbyxOVJjr52A+zNKl8ng5jqzbG1NkptuE2FAH31TskBnsFgN4tyNhQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=QZA6IPvIiht0ftuyn/YWXf4Ma2FHA2H3OESZdTNFYng=; b=gyg3lpNYQ5q89ZRPuluUh/rdCC4cCtJmgAqKrnmYETx2qsTdcOq8yhSs3CLgeJbFuYwG7jrkTAhr3MSX/5z9rmdeybCNPX4u2UTRe0ezPlqcWO3zjmC8Qh745RRxIr+AySocaIrRDEjkZxzb+mmqYfkoPoP8LiWtTXIR/8vI2X4=
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com (2603:10a6:10:20d::17) by DB6PR08MB2661.eurprd08.prod.outlook.com (2603:10a6:6:17::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4129.26; Wed, 26 May 2021 13:58:51 +0000
Received: from DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9]) by DBBPR08MB5915.eurprd08.prod.outlook.com ([fe80::3405:8699:991d:b2e9%9]) with mapi id 15.20.4150.027; Wed, 26 May 2021 13:58:51 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "draft-birkholz-rats-daa@ietf.org" <draft-birkholz-rats-daa@ietf.org>
CC: "rats@ietf.org" <rats@ietf.org>, Thomas Fossati <Thomas.Fossati@arm.com>
Thread-Topic: Review of draft-birkholz-rats-daa
Thread-Index: AQHXUicvJq5JZhB/2Euw8worVT3R7qr1uvdA
Date: Wed, 26 May 2021 13:58:50 +0000
Message-ID: <DBBPR08MB59152A44396C2E7EF9ED79CAFA249@DBBPR08MB5915.eurprd08.prod.outlook.com>
References: <2AC24A3A-C295-4BAC-8007-4D0B75C6C60B@arm.com>
In-Reply-To: <2AC24A3A-C295-4BAC-8007-4D0B75C6C60B@arm.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 3904A24FB45EAD4D921E4C8FA72B0ECE.0
x-checkrecipientchecked: true
Authentication-Results-Original: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
x-originating-ip: [80.92.119.239]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 1c7766e7-bf36-491a-a718-08d9204e6a34
x-ms-traffictypediagnostic: DB6PR08MB2661:|DB6PR0801MB1637:
x-ms-exchange-transport-forked: True
X-Microsoft-Antispam-PRVS: <DB6PR0801MB1637C6A4BDE93FBF4EF5AD32FA249@DB6PR0801MB1637.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
nodisclaimer: true
x-ms-oob-tlc-oobclassifiers: OLM:10000;OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: e2r16h7akReTAvm5FQr8fCvYppk1xxrOoqigg6hXc9UrYVhKMGvk7zs2LnhuJzJYEIyvpc9c5EGHyI1EPC1jGSt3P2gXprluJ97A9ZVzhR16CyGQcouNc9p6yrknqBJCUG8AEz6OqmlODD89UxUWD2U4cCez59vQlxvkaki4fw9ln0nb+gr6uqcf3LR0Qh1R7zdhFGthkNkt87v3dnhVoT14NWDl1yD25uq85wUsaaKB/N5rrqBf9VgHP27l8VZuiLpz7dqCqeqFMJ1mpQmesRxHmrP02qkxrYqH/KHKpjLtX9cdJCTq1mIEuRCwkrFiAsaEpiniJ2LL/gXcBFt+ClKHJORGJmJN6i8ODNFY9t9OjaWO8/Qq4GOlvWpspEXO6XwH6DpNKaJE9JdcCfmk9u+0kyaRcEomPu/5R5Ls6wwC9oW989/r2fGMn/IHFFH5l5PwyaXuvgT2KNjHPn/dkR2q5ebY73aFZZ4FZDCMN7OHbt6RCVAkcTZJZ/tyh5p5tinAmIrlcJybH106ryWvpQrQzkFo1tBN07epcxSzp9BO1SRYFjcDdE/FkoiEUqNGjQ8Uqk4O5Kv4Omjb7/ApRNRFY5f1mAu7fkdQtw/fvJk3mOmzw1VFi466dWP3tmisRp57lMsjffTY31O+X4HBnl6YHHDte3LwxDKrfzDZuXW72PpkvbEM+tXmVFiTwDvpSN2GzaywvHKB2LEIUXRI0QRp3yOrycObeMmxNckpG58=
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DBBPR08MB5915.eurprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(136003)(396003)(376002)(346002)(39850400004)(366004)(8676002)(186003)(966005)(6916009)(8936002)(2906002)(4326008)(450100002)(7696005)(66476007)(38100700002)(52536014)(83380400001)(478600001)(9686003)(122000001)(5660300002)(86362001)(64756008)(66556008)(71200400001)(66446008)(26005)(66946007)(33656002)(54906003)(53546011)(6506007)(316002)(55016002)(76116006); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: Bic6E8okkpRW3iPY7j5HI5aGmR8DoTILm3IbovkMbL0V2u/H1C7R7Se8RfNFWspaxtVBvP3uCM3p+kOTrPnm4oxkkajwc+8075o8b4HAu2ogE1FSUKXEAI9hu3ipsLY57ZIkxgdbrwVedOaAhWXKGUFQJ/ASqAkosI1IfMr2JGicdD3qHDNZNphSTNU1P2Z3+DWxWFrtBLLP8AUfni+GdxIr18W71ogFM9+bO4mdjPwEjBHfKNu8TvUjSDhvG04F1XazsxRqqCWIGImtpegDqWoMB6bn00LoOyZEEZfSpE8ho0qmi+OYWMlc8AZd/SNUUc8w0kMk5zDDsQCIqXTCHZa041H3x6IE6Rv79hFlyEPFUudjR3YffF0HFnYkj5VIb1d3ohWCmIgAIXkkP5WaFTyBJ/sXVlpUZYvOYuVHNLrIiW90CjX81nkhODF8eiicMjmzE8mYj4UdhZW7NYvfqZpHPpwZX85HceEtCaabxWMmdk/u27FZa1pZWz0E6Qo58tsg4wYPNsPlCPwwtIDCWmHd6hFmu6rLGYnTDpmqWUtSwQzozoDepoY/X+RNRiaFgW5c63Jgs3GDx26KaZE/x9tovWoWWou5Eyz1+9we9LEYtJgTQMOmc3pmajmKhE3jx6sZ5F5g3v2rOqBM5iv55ly7WIvJsojsUamcnDv1fAvbVwpvwC2EFZC0D3dIZRtDTenMQdawpcg21wyPVQGlp3dfSouK5WrZ0PL2ClHJO3St5Wo5LxFWoXcCvl87Y3GTThQsEISO5IrOg7VjTz742pXRcj3puJtvHQGLGjXFHs5RafIx2CpdpIE2GTVvbHUwICnNIs+wK3Cb4ZNIXwtlbHEMeK7XkrGdfZ2wq8spU+G4vT4D76iAZf63AqJtcUWG3mWngFaTvzPI5jy5+68QoVRI+Xek0tj5aXX+qYY2FUF0zMWIPjAsE5X8OMqcXXtuiVwfh23lhuMXwDOSRgA4vHRwZZjYAp7QAfM3NMKXAbSISwesqQbiPG2wQkiUlNApkgafyoq7UxBbnPSY273IRasxkNlCkdfx+5RmxuxzzhpIOzr7yLRxWf9JO+yYwS5qoJesPvr7HUq0fWB9p4H+KI7TGqoCJpM2kmOdVCQVI3IVCrC9e5EeBOChQJTvfsNv3Wr7GGx04N2ndgYr8VCpJ14w4uAP86ch8psvmNMdGYJqCPNButcTNmt9HMXhuNkb8maRoaBs/PfDCkaP/VS+lNdMlvSlihdxRfMTiYBu9lWChY6HP8wUaozXmRVAYn8MauhGoOCvFVCVKq79/39tgySQqfhcGBB7MrOM/Qixkjl4iCCEMWniXxRpM5XBL0u5
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6PR08MB2661
Original-Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com
X-MS-Office365-Filtering-Correlation-Id-Prvs: 615bfaa9-5831-4a49-299a-08d9204e6436
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: zkonGOnfZDFeJ/xRHgr5WJxNc9Dpa0bCss0RXVctvi1GBbOgEPa+uU+BF84GgXdbQJv2Yd4vK9E7Fmg/Q745Us3f0yBOPXgFW6VzWICtoFuQlm7bZVMfptNaknTorGMwtsoMQ7Mu7Qg3ZolcvIE1HVrFG7kxuFXqzt1jTJiPtJU4cUESvajJRL1/Np5AD7dNOxaN6NWpocZCA8o1vs/Ctbb6HNurwPuILCvP6Ssnmr1D/+PsxjUUwTwn4+Ce105DftpCLJTiKemn8Kl9FMWqX9RWQ2NYRG282wD1UrvLbN8JOaSS1wfF2IGH7zso9cNY4t+ApRZfNY6OwDMXkMkZKZnL9Ah/gRB+xKntS8a92UTrdVgsodeXPNtD3wCj5Qwwvx5nYLfARyUoxKfsP49fCtj2XujQ3br9k2XYQ4i2EB6oZnMyZQOlwf6FwSUtZgMb8DpIapb+qoDI/ohz34T5qQZG0hHcTBq4W0me8q47+EDwuzWIAmpfTWhQ60CDDXNUf5AuakURmnlpt1mN35odNsD7iiC2Dok86e//llmm1kcqtBElpniY1fRWy+3Tf7maTkhPF3nd96h/uuzpFEKSI1OYAzDuKdN1VqY4328715v73DS+/u1mc/bgqWk7lLsb/asQDnuN806B3YHIJW7L9anvVRh1AaEyISD9oUYGFg9/a3ptiWxbgBfqLXVZqF3MfAR8HImPwcbREJYiTmS9SeonraGLre8oUBXObmI/8EG0IRnezhyviiuEWF9SbTgdhDU4x3X1wWA+i8Ul7JLMaw==
X-Forefront-Antispam-Report: CIP:63.35.35.123; CTRY:IE; LANG:en; SCL:1; SRV:; IPV:CAL; SFV:NSPM; H:64aa7808-outbound-1.mta.getcheckrecipient.com; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; CAT:NONE; SFS:(4636009)(136003)(346002)(39850400004)(396003)(376002)(46966006)(36840700001)(6506007)(70206006)(70586007)(36860700001)(186003)(81166007)(336012)(52536014)(316002)(33656002)(83380400001)(7696005)(82740400003)(55016002)(478600001)(53546011)(356005)(6916009)(966005)(5660300002)(9686003)(4326008)(8676002)(47076005)(86362001)(26005)(2906002)(82310400003)(450100002)(8936002)(54906003); DIR:OUT; SFP:1101;
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 May 2021 13:59:01.0185 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 1c7766e7-bf36-491a-a718-08d9204e6a34
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-AuthSource: AM5EUR03FT035.eop-EUR03.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6PR0801MB1637
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/nDfZ0sU9Hqtfwf6py4JSY6ERA8E>
Subject: Re: [Rats] Review of draft-birkholz-rats-daa
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 May 2021 13:59:13 -0000

Hi Henk,

I have not been following the RATS work closely and hence I was wondering whether this document is supposed to become part of the architecture document?
In any case, [DAA] has to be a normative reference. I would also like to see the privacy properties articulated in more detail, particularly when DAA is used with an attestation token that potentially contains a lot of claims.

Ciao
Hannes

-----Original Message-----
From: RATS <rats-bounces@ietf.org> On Behalf Of Thomas Fossati
Sent: Wednesday, May 26, 2021 2:04 PM
To: draft-birkholz-rats-daa@ietf.org
Cc: rats@ietf.org; Thomas Fossati <Thomas.Fossati@arm.com>
Subject: [Rats] Review of draft-birkholz-rats-daa

Hi RATS-DAA authors,

I have reviewed draft-birkholz-rats-daa-00 and I think this is a useful document, plus it is short and sweet.

I may have a few editorial suggestions, but I'd like to ask one meta question first - apologies if this was brought up in previous
conversations:

Is it really necessary to introduce the new "DAA Issuer" role?

It seems to me that if the JOIN and SIGN phases are considered as two separate attestation protocols, the Issuer could be mapped to a couple of well-known RATS roles depending on the phase it is involved in:
* Verifier for JOIN - plus an authorisation RP on top that grants
  the group credentials to the authenticated Attester;
* Endorser for SIGN.

Cheers, thank you.

t








IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
_______________________________________________
RATS mailing list
RATS@ietf.org
https://www.ietf.org/mailman/listinfo/rats
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.