Re: [Rats] draft-ietf-rats-endorsements-00

Michael Richardson <mcr+ietf@sandelman.ca> Thu, 14 December 2023 13:26 UTC

Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: rats@ietfa.amsl.com
Delivered-To: rats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA514C14F603 for <rats@ietfa.amsl.com>; Thu, 14 Dec 2023 05:26:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DMpnBka-fEkv for <rats@ietfa.amsl.com>; Thu, 14 Dec 2023 05:26:33 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CD001C14F5E7 for <rats@ietf.org>; Thu, 14 Dec 2023 05:26:33 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id A7E491800E; Thu, 14 Dec 2023 08:26:31 -0500 (EST)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavisd-new, port 10024) with LMTP id n7j0o90RDi0d; Thu, 14 Dec 2023 08:26:30 -0500 (EST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8B72E1800C; Thu, 14 Dec 2023 08:26:30 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sandelman.ca; s=mail; t=1702560390; bh=nqCcX9gzfxmA8k1T5T/CZ03R20I4gKpr+tIrK0QiuNQ=; h=From:To:Subject:In-Reply-To:References:Date:From; b=d4DDjs9PvLP3rAB6H1zS79i/sQCxbKYXuL9+DECjVHmC1GD5rFqisbBzZCO2KRze4 t6et8sW4oNXtkMykKRAuNAJZ/jUFvH8/8Lq2Nk+HQOIzJZB1hFTa6sZ44JkeJ487EI oIkB3G48L0zPZYH0V5bQXs+FfhaIn32x19d6IcjtE11N0znhhFw9keb/+Gbl+GuKh6 DXjjHfcBaakJgS8kZ2BwvfrCfQDuNZEZSH2CjqzM/vipMai7sWv/61IOb8kmvvQVSx kL7Cq0HgsB+BPVArRKFLaFtcDnKr9Gei7NZNm5PqR1ZhfLiea9Ljr/gSHkYnOrNd5W GwO+BaKEcQSoQ==
Received: from localhost (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 86BF576; Thu, 14 Dec 2023 08:26:30 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: hannes.tschofenig=40gmx.net@dmarc.ietf.org, rats@ietf.org
In-Reply-To: <007101da2e02$b7cf0120$276d0360$@gmx.net>
References: <007101da2e02$b7cf0120$276d0360$@gmx.net>
X-Mailer: MH-E 8.6+git; nmh 1.7+dev; GNU Emacs 28.2
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Thu, 14 Dec 2023 08:26:30 -0500
Message-ID: <8973.1702560390@localhost>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/spgVZvJAgCzEaA49K1fP1zwD4eo>
Subject: Re: [Rats] draft-ietf-rats-endorsements-00
X-BeenThere: rats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Remote ATtestation procedureS <rats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rats>, <mailto:rats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats/>
List-Post: <mailto:rats@ietf.org>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rats>, <mailto:rats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2023 13:26:38 -0000

hannes.tschofenig=40gmx.net@dmarc.ietf.org wrote:
    > I read the RATS endorsement draft and was wondering whether the
    > document shouldn’t have become a section in the architecture
    > document.

I agree that in a different universe, that it could have been included.

I think that the architecture design team drew a line around the three core
components (Attester, Verifier, RP), and focused on getting consensus around
that.

For some environments, the Endorsements are configured (via
policy/configuration) in the Verifier.   Trying to cover that situation while
also defining a structure that allows for signed endorsements would have
confused some readers.

    > I am unclear about the direction it will take. Currently, it
    > reads a bit like a transcript of a hallway conversation.

I understand your complaint; I didn't find it too transcript-y, but I agree
that it spends a lot of text on pre-amble which might not have been necessary
if it were part of 9334.

    > Wouldn’t it be better to create a -bis of the architecture document and
    > to include the content of this document?

I don't object to making this document Update: 9334.
I feel that it might be two years too soon to do a -bis document.
But, if there is consensus to do what you suggest, it could be done.


--
Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide