[Rats] Re: Submission of Trustworthy Acquisition of Credentials using Remote Attestation (TACRA) draft
Serhii Nikolaichuk <nikolaichuk.s.f@gmail.com> Sat, 12 September 2026 22:52 UTC
Received: from mail-wm1-x32d.google.com (mail-wm1-x32d.google.com [IPv6:2a00:1450:4864:20::32d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 6910130 for <rats@ietf.org>; Sat, 12 Sep 2026 22:52:50 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=ZFMOVUDD; arc=pass ("google.com:s=arc-20260327:i=1"); spf=pass (mx.ietf.org: domain of nikolaichuk.s.f@gmail.com designates 2a00:1450:4864:20::32d as permitted sender) smtp.mailfrom=nikolaichuk.s.f@gmail.com; dmarc=pass (policy=none) header.from=gmail.com
Received: by mail-wm1-x32d.google.com with SMTP id 5b1f17b1804b1-49d0da752ffso26209005e9.3 for <rats@ietf.org>; Sat, 12 Sep 2026 15:52:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789253563; cv=none; d=google.com; s=arc-20260327; b=h3/sAUevmdAHabFC9GPFxc3O8vjn60QkSsILVw80kM1nNHZdmpBleHO10HrQLfpj0q eXDKEiS2mPT5aEQcZgHHORpYduKI3As2CeP57leS7zFDZCK9SS3w4t+xzzWByBsECFcN 2wekvkjOjMdQWky4r0l2TGjTpYJrFEKBo78caZLXZSF4VhGEct4QwnkgrLjbezT8b5fp t4kqnazKEBhcw3PyqKGXUc/eCcLEkafs4d6RHhE4b2SitXsVuJcEn67y8mWy4hZ2R4OF wKol+3UNAV8VdKsuiaXUgPAsBjNnE+tuklQ4LIqwYT7llfO2GdJu0GUByrvGEcd7FtGQ /FvQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:mime-version:references:in-reply-to :from:dkim-signature; bh=qTCahDF5JbJqGNg4bBkYljlhkmJuYVeSnvZG/VsRISo=; fh=xcXkub78Y3o9x6jMgyWpb0GKr8EQ9fIvPj/HPqnU5eg=; b=JWrNQEJBWI7Z6LdSP/PvPePC3/ubDvstAgnZKjX1fcNOJK68Ty6VFY/TBpAx0m3CJR SF/02P+DWj3FhlvkpK8YkT0139v1aFyHFNIvUZ2BJR0R3AJC4pYCsCfQ5b576s2UzpGe D/7PlsVfv0Nstl1OTflP6sZivkSrZq/BcvRadTU7aYIaOE1GmIvC4atQ4ULXM1/Pr/xB gu3H7tRF5zAtlMRi1uOKpkzAnVmdlf888/Dgx6zIu1b07vwgXn+CCAzOip4dvtMGHaiK n0rPY0pdc0ZezaMzWXfkt2R6IdbQJaAj4LZS/nxvpKKfwUbY1GB2MUk/UF5rB3QMCn8T B+vQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789253563; x=1789858363; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:mime-version:references :in-reply-to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=qTCahDF5JbJqGNg4bBkYljlhkmJuYVeSnvZG/VsRISo=; b=ZFMOVUDDG+/gE+oPM9JH3P/QODDzzha0NM/idmgrkxRGmvOgJbygZDbavVm8QLFtMJ szAlcDy+0nyYgNGliFNi0cMMbonjGPf/xAE0Z++NEOVCIx5AxAaBPtSdfOPQXZYipYlO u7/Yaj8xQDPwTnVgSi8FdQCviHP3JajvgBSKowTJnUUNWN7EaVR0eJQXcPAKDL7ehoAv NddE6liAU7Gt7XLuyOfgKettbtpJQ1qaou8kJVeThBD+aCSzP6lAcPr6yvg+Fsz7TgRx TbY669DsprKz+lek1vpaORldBGqixiNkv6QCplV6dkVPffFEqcVl8Oemu25SrcJB5BHC dESQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789253563; x=1789858363; h=content-type:cc:to:subject:message-id:date:mime-version:references :in-reply-to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qTCahDF5JbJqGNg4bBkYljlhkmJuYVeSnvZG/VsRISo=; b=dwJXtwdZMoPa1bMZAnWctChY4ReYTnx+6GP9fTd5TuI3m4hVMs7Fb37Tp3BNIEicRp hXM2c7q9pifA+V41RJHBd7VoHEXEZWgaGA+WYNO0vZaEjqQyJq7Z7/cd32tQlS7a7l3D JaKRzF28p6N4rfAAQ1StZsT1zDuE0y9CeTGwVdBFKYKrdWv9BipFHYNCWA00tCFN+SmL GfgeNdp/rQqSe+qfw+S6oPKSNuXEbnbdSBjKZNL6sU8PPQpiKLCFJSUoXfJbXF/3XjRh hseCzqi2Zzh10uin5HJjzm7eZnnG+kWvdSFYP3IUmrPcUmZhX6fgN+BOpPYof0LA1zUY oH9g==
X-Gm-Message-State: AFuF++lf3hQfTSSL5Yzb5NXad7w39XeTzgsYM2TWJ51ls7jDOq9rvLfl 0HrRhL1VP4b3fDuvB5YUePc1G629UuDhoRsFbAB1VU1NxWbFohfRP5+QTZTOpE821UscP8vql9N TLaG1S6pCoKvXQYdebB3BZJd97RcylQ==
X-Gm-Gg: AYBFou0YwAApx5LaM2al/IvhyikXQbInzQF7Dy378Z03Sk3AwNYIM0mHVsHJsFRixey KdhFL2wwDgROLQU4Hf7tZIzFiLkTChqbibflbC7YzJl+nnN5Mg/FTnU8pdtZLy3EkUHhO3SnLM4 bkAzx9MCckGoaZyQPPvK94ox2ZUVDqJlSZE0FG7o9+P6TA9f4t5mV47zYGjc0hUJMr5eEpveXfx ebfgaAxdNMARDmkXdbN3dXXueknGGh0/rhddgV4MvirnpaNkSMmR5wgFtZ17W0hTnNKY+jT5VDG Ru4QuvEWDceLoJmVqBs36B3KQAQG9OJUmrMIKI0UYyWWLY08s2r8KXti75qlanSjHDOL2tcvcv5 8l5YG9NDQozw99d1IQow4Ux4xoPWHinCZBNaFo46hJf3JYo7IX6d+Q9Vu1hBmRKxXUV4ujt0M4Z 8bMytwMnBhjpR36WXiGws=
X-Received: by 2002:a05:600c:3145:b0:49c:fc6e:8cae with SMTP id 5b1f17b1804b1-49e619bbca8mr109128105e9.18.1789253562950; Sat, 12 Sep 2026 15:52:42 -0700 (PDT)
Received: from 101988054943 named unknown by gmailapi.google.com with HTTPREST; Sat, 12 Sep 2026 15:52:41 -0700
Received: from 101988054943 named unknown by gmailapi.google.com with HTTPREST; Sat, 12 Sep 2026 15:52:41 -0700
From: Serhii Nikolaichuk <nikolaichuk.s.f@gmail.com>
In-Reply-To: <DM3PR11MB873497E037D270B6005D2E3F9ABE2@DM3PR11MB8734.namprd11.prod.outlook.com>
References: <DM3PR11MB873497E037D270B6005D2E3F9ABE2@DM3PR11MB8734.namprd11.prod.outlook.com>
MIME-Version: 1.0
Date: Sat, 12 Sep 2026 15:52:41 -0700
X-Gm-Features: AcwNN1WXhay7Tp3yGIgI0JNzG_ZIDUcda0RgEhivEAjncWnbM9DvZaF1zmxT7pg
Message-ID: <CADj3X6tsNTUnoEbgAYFtBX7q=j90gG3nwK5NDYD1sG=z6uFOPA@mail.gmail.com>
To: Mark.Novak@outlook.com
Content-Type: multipart/alternative; boundary="0000000000000869cf065b510ffc"
X-Spam-Level: *
X-Spamd-Bar: +
Message-ID-Hash: OYNGCW4HJ7ID4G7H376NO3IVWNUFBDWL
X-Message-ID-Hash: OYNGCW4HJ7ID4G7H376NO3IVWNUFBDWL
X-MailFrom: nikolaichuk.s.f@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-rats.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: rats@ietf.org, henk.birkholz@ietf.contact, mcr+ietf@sandelman.ca
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Rats] Re: Submission of Trustworthy Acquisition of Credentials using Remote Attestation (TACRA) draft
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/yaGG4sVf4pCfJ0HNPPRv3Xg0cG8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>
Mark, Henk, Michael, Thank you for TACRA. I read -00, and since you asked for feedback on the binding and on architecture boundaries, here is a contribution from measurement rather than opinion, with the artifacts public so anyone can re-run. 1. CSR/CEK-to-Evidence binding (Sections 4.4, 5.2, 5.3, the "TBD"). A concrete construction that verifies end to end: put SHA-512(freshness || CSR) in the attestation freshness field (REPORT_DATA on SEV-SNP) and have the Credential Authority recompute it. I ran the enrollment case on a Google SEV-SNP guest: the guest generates the CSK and CSR, takes a present-nonce, binds REPORT_DATA = SHA-512(nonce || CSR), and returns a VCEK-signed report; the CA recomputes the binding, verifies the report and its VCEK chain to ARK-Milan, and verifies the CSR's proof of possession, then issues. Retrieval is the same shape with SHA-512(freshness || CEKpub). Worked example and verifier are in the repository below, under tacra/. 2. That binding is to a genuine TEE and to the freshness handle, not to the CAS channel. Since the CAS is an untrusted conduit (Section 7.2) and relay is not yet discussed, a relay can sit between the Attester and the Credential Authority while every check above still passes: binding a public key, with or without a nonce, does not correlate the Evidence with the session, per the public analysis of binder mechanisms (Identity Crisis in Confidential Computing, ASIA CCS 2026; Intra-handshake.fail, CVE-2026-33697). The remedy is cheap: also fold a value derived from the CAS transport's shared secret, the RFC 9266 TLS exporter, into the freshness field, and say so in Security Considerations. 3. Architecture boundaries (Section 4). "Include CSKpub in Evidence" is not uniform across platforms, which the CAI plug-ins need to account for. Measured across the public clouds: - Google SEV-SNP / Intel TDX and AWS Nitro: the guest writes its own value into the report, so CSKpub goes in directly. - AWS SEV-SNP shared tenancy: the guest can write REPORT_DATA, but the report is VLEK-signed with CHIP_ID zeroed, so the Evidence names no machine; a credential there rests on the provider's key domain, not a chip. - Azure SEV-SNP: the paravisor owns REPORT_DATA (it binds a runtime-data hash at boot), so CSKpub has to travel through the paravisor's vTPM quote, not the SNP report. So the binding step needs three shapes: direct-in-report, provider-scoped, and vTPM-mediated. All of this is measured and reproducible; the reports, certificates, probe and verifier are in the repository [1], under tacra/. Happy to turn any of it into text for the draft. Serhii Nikolaichuk Austin, Texas [1] https://www.google.com/url?q=https://github.com/nikolaichuk7/geoar-verifier&source=gmail&ust=1789339961306000&sa=E On Fri, Sep 11, 2026 01:18 PM, Mark Novak <Mark.Novak@outlook.com> wrote: > Hello RATS WG, > Ahead of our interim meeting next Monday, I submitted the TACRA draft for > consideration by the RATS working group. > Draft: Trustworthy Acquisition of Credentials using Remote Attestation > (TACRA) > Revision: 00 (Sep 11, 2026) > This draft describes a credential acquisition architecture for remote > attestation and workload identity, allowing any workload to acquire any > credential type using any protocol. The document is intended to support > discussion within the WG on design goals, architecture, and protocol > integration points. > The draft is available at: > > - Datatracker: https://datatracker.ietf.org/doc/draft-novak-rats-tacra/ > - GitHub / source: https://github.com/TheBankster/rats-tacra/ > > We would welcome review and comments from the WG, especially on: > > - design goals and architecture boundaries > - the role of the Credential Acquisition System as a conduit > - interaction between the Attester and the CAS > - compatibility with existing credential acquisition mechanisms > > Thank you, and we look forward to feedback from the WG. > Best regards, > Mark Novak / Henk Birkholz / Michael Richardson > > _______________________________________________ > RATS mailing list -- rats@ietf.org > To unsubscribe send an email to rats-leave@ietf.org >
- [Rats] Submission of Trustworthy Acquisition of C… Mark Novak
- [Rats] Re: Submission of Trustworthy Acquisition … Serhii Nikolaichuk
- [Rats] Re: Submission of Trustworthy Acquisition … Mark Novak
- [Rats] Re: Submission of Trustworthy Acquisition … Serhii Nikolaichuk