Re: [saag] SECDISPATCH WG Summary from IETF 106

Brian Campbell <bcampbell@pingidentity.com> Fri, 17 January 2020 20:43 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D78141200F3 for <saag@ietfa.amsl.com>; Fri, 17 Jan 2020 12:43:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=pingidentity.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iJNVNPR1UMi9 for <saag@ietfa.amsl.com>; Fri, 17 Jan 2020 12:43:24 -0800 (PST)
Received: from mail-lj1-x22a.google.com (mail-lj1-x22a.google.com [IPv6:2a00:1450:4864:20::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAB8612006B for <saag@ietf.org>; Fri, 17 Jan 2020 12:43:23 -0800 (PST)
Received: by mail-lj1-x22a.google.com with SMTP id a13so27770643ljm.10 for <saag@ietf.org>; Fri, 17 Jan 2020 12:43:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=BEKZOIx4AXNTOWW97/ua8nO+/hSteLB/EAbk+cmXfBU=; b=WEYU68sIOjxx0m2RA+MlhE78xrCPjSMH21epO4I9omb46Y1+C39tG6CtcvDMBbyoYh wNVTsbnWRP/WkN4bN+c0MX41YmElHK+arUJwmEeYub0TLc2WFkZCFadEsWvbKC2PZMuA PpeHCSyGYwAQ8rugJV2Tfr+Z56vEonmLeuwARy0tc3IVx2b/obWmJO/0ZAVYgVTnGvd1 8ANyJI/IBylNLmAJy+xA5d7B6Dd/TEHbSItCnhKDoTH1tG+XLja+r2bOVpZnSYLucyWV U0oaj3WNGY7FGz92HwRYKf8HOTx6ghzvuNZIKN01puDdrpA5rdVCC7YkcJswyZJSHpxd QJ7g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=BEKZOIx4AXNTOWW97/ua8nO+/hSteLB/EAbk+cmXfBU=; b=uEcRHMDFVF8AYreF8Gewr4ixF3cJR7sKgT3ttnhGE2A2H+yQyJUdl2bV1tHTaEXTvw MgUKjqRCa1CJcBFQwXpLT6acE59tqW6jdeOoB2DK0VKrGAW0z1LQreeybOH8ZFTaJVpj NwTqrGlg3rTKkhy78MZ5Ajnbgi5P0IeVB5cC70RjWV29kH94V1C0U/H03xA40XT3xpqB YagXnaHlkMxyBV2qpIUigXLJpIf3gNFBQx8sKnx0Fre4fuzHWb/Us0tQGETF3eBud5Gy TTuEEQ+w/8JLu8T/FRvtPhIaGkXt1bJg7opQpuUqkdRjk+c/r/E39Q5fUmhjY7SEQHFj QWKA==
X-Gm-Message-State: APjAAAXPnVodTb8wUwVbMCacT32GmEZukW7ZMSEI/ei68SCFmFoLFFBg ipfjZvDK/osnaPkJUjUUaTh0wYLAQ98qRM8vIf4bCKbe4AGg/P8TGMvJZ+G1ezPVeC8iWDAg0oq 5aQ4js9Bq4OrSiY96Sg==
X-Google-Smtp-Source: APXvYqymQWziLXd91hPvqIu8c7wVtloY5sq5MuEQ3dibuU9WoxFwVfapyqvnctNRTLKL4OVEBcQk1Np55EdV2pbtfUE=
X-Received: by 2002:a2e:9687:: with SMTP id q7mr6494577lji.232.1579293802072; Fri, 17 Jan 2020 12:43:22 -0800 (PST)
MIME-Version: 1.0
References: <3088D698-1616-4A74-9CBC-4A9345E46C15@ericsson.com>
In-Reply-To: <3088D698-1616-4A74-9CBC-4A9345E46C15@ericsson.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Fri, 17 Jan 2020 13:42:55 -0700
Message-ID: <CA+k3eCQbFFc5WFGFrhQNnxS=ipeh9rjRTrRudGi2OaCo3pZXaA@mail.gmail.com>
To: Francesca Palombini <francesca.palombini=40ericsson.com@dmarc.ietf.org>
Cc: "saag@ietf.org" <saag@ietf.org>, "secdispatch@ietf.org" <secdispatch@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000011a392059c5bfe4e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/iW4UbT-6HDkUeRXaNYk7JlhCYNE>
Subject: Re: [saag] SECDISPATCH WG Summary from IETF 106
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Jan 2020 20:43:27 -0000

 Apologies folks, I'm responsible for the rushed and awkward presentation
about reverse proxies and TLS client certificates at the very end of the
SECDISPATCH session in Singapore, which is mentioned below with "no draft
yet--> needs draft". It took me a little while to get through the work but
I'm happy to share that there is now an actual draft available. Here it is
in the fancy new HTML format:
https://www.ietf.org/id/draft-bdc-something-something-certificate-01.html
as well as the good ol status page:
https://datatracker.ietf.org/doc/draft-bdc-something-something-certificate/


On Tue, Nov 19, 2019 at 9:34 PM Francesca Palombini <francesca.palombini=
40ericsson.com@dmarc.ietf.org> wrote:

> The SECDISPATCH WG met on Tuesday November 19.  The agenda items were
> dispatched as follows:
>
>
>
> (1) Problem statement for post-quantum multi-algorithm PKI (Max Pala)
>
> drafts:  https://datatracker.ietf.org/doc/draft-pq-pkix-problem-statement/
>
>
> https://datatracker.ietf.org/doc/draft-ounsworth-pq-composite-sigs/
>
> --> dispatch to LAMPS WG (confirm on mailing list)
>
>
>
> (2) OCSPv2 - Improving OCSP Responses (Max Pala)
>
> LAMPS & PKIX discussions:
>
> Draft:  https://tools.ietf.org/html/draft-pala-ocspv2-00
>
> --> create a BoF for small focused WG
>
>
>
> (3) Privacy Pass Protocol (Nick Sullivan)
>
> drafts: https://datatracker.ietf.org/doc/draft-privacy-pass/
>
> --> work on charter text then BoF for small focused WG
>
>
>
> (4) HTTP Request signing (Justin Richer)
>
> draft: https://tools.ietf.org/html/draft-cavage-http-signatures
>
> --> dispatched to HTTPBIS WG
>
>
>
> (5) Communication Network Perspective on Malware Lifecycle (Joachim Fabini)
>
> draft:
> https://datatracker.ietf.org/doc/draft-fabini-smart-malware-lifecycle/
>
> --> check the IAB project (talk to Ted)
>
>
>
> (6) Securing protocols between proxies and backend (HTTP?) servers (Brian
> Campbell)
>
> draft: Looking for support/contributors, no draft yet
>
> --> needs draft
>
>
>
> Detailed minutes will be coming in the next couple of weeks.
>
>
>
> Thanks,
> Francesca
>

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._