Re: [sacm] [Rats] CoSWID and EAT and CWT

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Fri, 22 November 2019 00:08 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C7B08120129; Thu, 21 Nov 2019 16:08:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=48zv2WDq; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=armh.onmicrosoft.com header.b=fe36e5Ei
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZWQu_UhMaW9A; Thu, 21 Nov 2019 16:08:45 -0800 (PST)
Received: from EUR03-DB5-obe.outbound.protection.outlook.com (mail-eopbgr40044.outbound.protection.outlook.com [40.107.4.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4244B120091; Thu, 21 Nov 2019 16:08:45 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=n/7gcMRfOr7PE9gQM15bB8OlanQkQNaJQxhyWdzxa8U=; b=48zv2WDqARrFqP94I+jZe0BYIBZVVRN6hAcKuGhn7R5sjzywo5+pIHlVZaxtU+2muc2LOpADeJF3sWG40K7oCqeGvQu8IQaZms71fVEpTcQ4V7fEeqklXOlkQ1PzIsHwRweMtKF1as+olvmQkzWNqXzsk1CBnAlEzcaDwIOOkqU=
Received: from VI1PR0801CA0073.eurprd08.prod.outlook.com (2603:10a6:800:7d::17) by AM5PR0801MB1715.eurprd08.prod.outlook.com (2603:10a6:203:3c::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.16; Fri, 22 Nov 2019 00:08:42 +0000
Received: from VE1EUR03FT036.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e09::204) by VI1PR0801CA0073.outlook.office365.com (2603:10a6:800:7d::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.18 via Frontend Transport; Fri, 22 Nov 2019 00:08:42 +0000
Authentication-Results: spf=fail (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=none action=none header.from=arm.com;
Received-SPF: Fail (protection.outlook.com: domain of arm.com does not designate 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by VE1EUR03FT036.mail.protection.outlook.com (10.152.19.204) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.17 via Frontend Transport; Fri, 22 Nov 2019 00:08:42 +0000
Received: ("Tessian outbound f7868d7ede10:v33"); Fri, 22 Nov 2019 00:08:42 +0000
X-CR-MTA-TID: 64aa7808
Received: from 7deece26b04e.1 (ip-172-16-0-2.eu-west-1.compute.internal [104.47.12.57]) by 64aa7808-outbound-1.mta.getcheckrecipient.com id 8108176C-8565-492A-90B5-D3D78D399050.1; Fri, 22 Nov 2019 00:08:37 +0000
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04lp2057.outbound.protection.outlook.com [104.47.12.57]) by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 7deece26b04e.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Fri, 22 Nov 2019 00:08:37 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=hFHhCa2rukkJdctgLZO12Wc/5vYFK4QMF9oo+ZSYCBtFU81J/xjEESKrDVPz85Lj2aV7MZqTdsm0qxHNSS6n7HysWAxEPaMi1LjwYqGgx8QY7zjeH0Unp1HWzYfD4XIHaYxf0CnWOHTSzceIIIFfL9TLDSAQqCMH5RU5ee0SQK+bp+knOEZRIxZA7OBmLPVEyxVAKfRNzANKqQBZ9E8eeYo6Wuew6EjhcAxQ8+/q56KLCRcv7m5p4O0gzB/5VU+ykSdkkhfLv7ZwRlFWd4+miaYRDgmeidVN1HSkFT9Ag5Inawoi0xUforke7iVKEoTRJg8L6YtyL4YpP2vtoddjfw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b7Ds5BpYp+gs7Ff/rBIWKWQiapJRGVRDz0xZL9OSZTI=; b=VjUFKCHjKHpSqCy8Sm/nqAngeestFJZI2VGbdvBSwRBHd9+VUd1L50I04FV7Zvp1MZ5Mq3+JnVjMCkohzuf8V0Wr1eLNcBTCLfrq6IZD8HTUg//9jSA/5WuesaKkJjaIrhpMiX5WUK1Km6sWavxZH105f17LK9NOso12GocHQbOmO2pCzJvGk60duTuPtwpAP77M765BDQ2vZh2qDFQzf3itd1Meue/wy4PlciT2t29+aM82rf3KCRiDz6CrzgkHHovyDGRsRdEhkwKVhWb/VI9kUKgirhToCD6gwWTPJ9GzrPH/gb339f+0A01rZuZOEJcUv90qxAKUR63KSJwyKg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b7Ds5BpYp+gs7Ff/rBIWKWQiapJRGVRDz0xZL9OSZTI=; b=fe36e5EiPP1Wo1TZPRaZhH95b/9JV/wNfDKWyLu9XVxx3FeMITa2CR8SrK46SUG0DWLhkgfGGyvFIXTZOojpuZ6Noy16ux10Wo/oJuXmRaUALBNZKGp8KRa8gPfVSn78nVTLrp5sG+6zUTWVf1441KTpSqfYvxLS8JzEnV7+j40=
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com (52.133.245.74) by VI1PR08MB3165.eurprd08.prod.outlook.com (52.133.14.155) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2474.17; Fri, 22 Nov 2019 00:08:36 +0000
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d]) by VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d%7]) with mapi id 15.20.2451.031; Fri, 22 Nov 2019 00:08:36 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: Laurence Lundblade <lgl@island-resort.com>, "sacm@ietf.org" <sacm@ietf.org>, "rats@ietf.org" <rats@ietf.org>
Thread-Topic: [Rats] CoSWID and EAT and CWT
Thread-Index: AQHVoAOGy2FbzysCYU2Z3In7IgWA1KeWUdGA
Date: Fri, 22 Nov 2019 00:08:36 +0000
Message-ID: <VI1PR08MB5360236E3583EBD3A78085EDFA490@VI1PR08MB5360.eurprd08.prod.outlook.com>
References: <2A12D8A3-722A-44D1-8011-218C89C8B50B@island-resort.com>
In-Reply-To: <2A12D8A3-722A-44D1-8011-218C89C8B50B@island-resort.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 5c4b810c-5216-496b-a116-c7e9dac9f224.0
x-checkrecipientchecked: true
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
x-originating-ip: [31.133.147.34]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: 30e9eb8a-4339-4741-6fe2-08d76ee02283
X-MS-TrafficTypeDiagnostic: VI1PR08MB3165:|AM5PR0801MB1715:
X-MS-Exchange-PUrlCount: 1
X-Microsoft-Antispam-PRVS: <AM5PR0801MB17157A72A1E1D3499E28A06DFA490@AM5PR0801MB1715.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
x-ms-oob-tlc-oobclassifiers: OLM:4941;OLM:4941;
x-forefront-prvs: 02296943FF
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(346002)(136003)(376002)(396003)(366004)(39860400002)(53754006)(199004)(189003)(2501003)(74316002)(7736002)(2906002)(6436002)(229853002)(6306002)(9686003)(6116002)(54896002)(236005)(790700001)(6246003)(66066001)(3846002)(33656002)(7696005)(2201001)(76176011)(316002)(55016002)(86362001)(110136005)(53546011)(102836004)(6506007)(5660300002)(186003)(66556008)(66476007)(26005)(64756008)(66446008)(52536014)(76116006)(66946007)(256004)(71200400001)(99286004)(11346002)(71190400001)(14454004)(478600001)(8936002)(81156014)(81166006)(8676002)(25786009)(446003)(606006); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR08MB3165; H:VI1PR08MB5360.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: oebQG72Vj4FPKA6sUr11fwhonUhyy40HT1CiClcvQzHQxs1PwBk5I59RJ7MZgZN31Uj/EF1Fyul/d+eJrrZ9MKm8mXcwFWcGejwOOgYwTK+R8E6a1UEAgxMHmK1Jt7e608xVEOgAUn82uDWGj7cEtpFJWRv0HJAjJ4phpvyidJ7HJdTOrXN1kaEtZTUD0mEJ39aoJOfxO6sjsdiakSyRnML0jEv/K0JqBpBmd+5JIwzg5Rm2nHpoULyKyrKSB5dtsi2JV73yd7Pei1cyP/3g56Wuh8z2PRjzLta5hz2gKqO5lcZNIgaOVYFpyaxiCgKzNy6rQ0rTaxuQ4rVewhfz4gk71t8LoVVR8lCLVcJ6e2tGHmUG3Bq6HkmFF4qnZmSVcWurrDWXlOFQ50GbC7QeZXkFdLxMYa3/6BhpJ23phT25PttJ9eESxMskbE/SqCOr8G/s6YyoQ7O0Q474x2UsVosNXPgFi8aUi1zPDLMTZe8=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_VI1PR08MB5360236E3583EBD3A78085EDFA490VI1PR08MB5360eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB3165
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: VE1EUR03FT036.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(136003)(396003)(39860400002)(346002)(376002)(1110001)(339900001)(53754006)(199004)(189003)(40434004)(6246003)(790700001)(5660300002)(478600001)(11346002)(3846002)(76176011)(26826003)(8936002)(186003)(14454004)(99286004)(2906002)(33964004)(6116002)(52536014)(81166006)(102836004)(7696005)(7736002)(105606002)(2501003)(26005)(81156014)(8676002)(336012)(53546011)(6506007)(33656002)(446003)(316002)(110136005)(66066001)(55016002)(450100002)(2201001)(16586007)(25786009)(36906005)(236005)(70206006)(6306002)(9686003)(54896002)(22756006)(76130400001)(606006)(229853002)(70586007)(86362001)(356004)(14444005)(74316002)(5024004)(71190400001); DIR:OUT; SFP:1101; SCL:1; SRVR:AM5PR0801MB1715; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Fail; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; A:1; MX:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: b59ce4d2-fecb-4bb8-3dc7-08d76ee01eaf
X-Forefront-PRVS: 02296943FF
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: V7gxqsHScOAUX7H6mpWdPqD8cngpgWJX6MDk2cOT4uel3y7P2FeMnRpPZ6W/ksdRUkHw4L/S8BCkDhBnotol2mHIcLUDkA2+PLCWuCxfL2Ee8jLbTD7tO8ms3agT3N/NHJl84x4iz5Q4LFqI85g1qsxQLF+pXolTjE4UmfTG5hJRJWh1Ga3XzuFno4C5cyqfDhMoPP4fzDzwsW9WVhyaubUhdX0a6cFba9m0ju1L+xgXjcfaBhtVe+PSqX5xJvNPBTijggDi8sS9EVB0rGVCgew3qs1Z4r3gPbaKKJAIgPyymqahgGqhOUf99hL/abJ2TAbfVA3pTAHfz+8L65dMqfTtQyNgRs1W30nTEwcRyKyY4H8N2sd4NVWI17T8bCVXAYWI5VZ0gayKblQ8TQc+PiEEURqsdvggxMfDVifDxAjZCpKE7DKArQtR3qZaXiaTFFXBonivgSLC6XJrNV6u/aKoP5NnQpiG8Bo7YX2Yxwk=
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 22 Nov 2019 00:08:42.5602 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 30e9eb8a-4339-4741-6fe2-08d76ee02283
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5PR0801MB1715
Archived-At: <https://mailarchive.ietf.org/arch/msg/sacm/hV6sad2q6-shbrgD9js-zqsYJcw>
Subject: Re: [sacm] [Rats] CoSWID and EAT and CWT
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: SACM WG mail list <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sacm/>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Nov 2019 00:08:49 -0000

Hi all

Can someone send an example around how this would actually look like?

Ciao
Hannes

From: RATS <rats-bounces@ietf.org> On Behalf Of Laurence Lundblade
Sent: Thursday, November 21, 2019 8:35 AM
To: sacm@ietf.org; rats@ietf.org
Subject: [Rats] CoSWID and EAT and CWT

Hi,

I’m not on the SACM list, but did look at the archive. Hopefully I’m not out of sync.

My thought is to register one claim for CWT that is an entire CoSWID (in CDDL the concise-swid-tag).

That way CoSWID can grow and develop on its own without lots of adds and subtracts to the CWT registry. It has its own IANA registry with its own experts and such. Seems like the coupling / factoring is about right.

This would also be the way I’d like to have it in EAT attestation. We’ve done a mini version of this with the location claim<https://tools.ietf.org/html/draft-ietf-rats-eat-01#section-3.8>.

Then if you just want to sign a CoSWID CWT style, this works pretty well too. It has a slight overhead compared to having all the CoSWID data items as direct CWT claims in that it will have an additional map layer, but that is only about three bytes.

LL

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.