[SCITT] Re: Action requested: Focused Working Group Last Call on Section 4 of the CCF Profile

Iman Schrock <team@emiliaprotocol.ai> Sat, 26 September 2026 22:04 UTC

Received: from mail-oo2-x1b.google.com (mail-oo2-x1b.google.com [IPv6:2607:f8b0:4864:31::1b]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id E3D4730 for <scitt@ietf.org>; Sat, 26 Sep 2026 22:04:07 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=emiliaprotocol.ai header.s=google header.b=j54jbDGB; arc=pass ("google.com:s=arc-20260327:i=1"); dmarc=pass (policy=quarantine) header.from=emiliaprotocol.ai; spf=pass (mx.ietf.org: domain of team@emiliaprotocol.ai designates 2607:f8b0:4864:31::1b as permitted sender) smtp.mailfrom=team@emiliaprotocol.ai
Received: by mail-oo2-x1b.google.com with SMTP id 006d021491bc7-6c72bd8a02fso1121371eaf.0 for <scitt@ietf.org>; Sat, 26 Sep 2026 15:04:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790460241; cv=none; d=google.com; s=arc-20260327; b=LIvyeP59tVGaH//BADwSrJE3ndlUduYpxjWaZTw9/6GoLp7DhXepdmoH2kvgFT2eNe 1aScG9QMZTN0cU5sgzxjZJ9fLPji+moGZss2OSJTNdlYfjyZbb3JHJ8lZuXccDbcPBJ2 VKnFa+P1uEWHj455xlmeo4SRdjXFAkSCJEdgXbDJSzs24YxtrFWmUAwBrgOWMiKC8U/A 8pZw02Xirfq/SzLQgCYByf3p09dRKNCo4Lxe4GGV3dkJ+XgkQHAeG8KHCcVv3OvwmH9L XEER4IB3A8hKeyKvGo4fpObywdyv0+wKaFmKDr5Xjreahi5idcexCLVG6W/KfK0FOzKo lplw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=LyE/Kc0uOPKTteJukd/+eqBgMKnB0tjmCzWOqgXjMaI=; fh=WaKycUmmrSnljSprrvttL9/n7epFt0TzEWk++/5i2/g=; b=qEiWxdDa2ksAKtc7p1k/SDnniPNO7UDdj6IFJ4cvltIoDvOinBulWTSxCTJIOGnxAx sUL6jHGKhV+eXB7V88Qgh2gmgI42EbMCUMo93E5WXqoFm/oBQ+PVs383nQs7OsuCLWsj BTSXKsBB8VabgYNuUKv7jSL5L8DxAnHh7cjNWHWC12xKgM8Eb/yRtN2rb6pMvhhpy24z g6sHmWpERWFtlraO/kGgqOkxX6lgRjblXEgixRH1IbVbAwRsTE9sPBYgEG41yO2tH1A7 sjc6OVP1llgC3I2W8h8+/6VVcuMzc3Vcq4K94rIZ+etkXp1UAQXQVDqO6nARgfg4WXrX iAWA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emiliaprotocol.ai; s=google; t=1790460241; x=1791065041; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=LyE/Kc0uOPKTteJukd/+eqBgMKnB0tjmCzWOqgXjMaI=; b=j54jbDGBC0S7h7No0fJxE6Lps13qMK4nlQbdmGx3LT4cqZ/wMYSJKR4ZpC185Ajzgm pmm0BnZs0KSy3zv9EOwORkfSpH2nnO31ggKLYiqcI2yEksPkVUhsyyj2v/X2QX5d7c6r glKi5CgGm6UAD5kvkETiSvIt0Ybq7M+CU9ahcNV/wC88Nmcaz0gsQ9mkhaFHBs6CTBwc f2V1BJGzRc4/rSIhjIooSi/h89L/GwKYgGm3lwPcJ2X+/cFrobHtkv6oDg/jXYWLhnFt w4tg+kmNhLAZrQGIaNSorgbMvhhfFB9Z+6RitToAGBAMFIxv0QgUkaMpRklLb/G8X9tR vjDg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790460241; x=1791065041; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=LyE/Kc0uOPKTteJukd/+eqBgMKnB0tjmCzWOqgXjMaI=; b=kytCA9cmmoWYGyzErQdtEDeMNOX3zljCiJQsMiyuT49eJUQtwUfqMSVyMCAZI+fq/6 SI2xxNjjKY7Ebi7eeqlcRkZHFxFOzBCTZ7Uv/x3ltQkFl9JOna7qif+NhjcJyTQurNmT T2U2Gw4Ajeel7a1qA80XV+idNn7L8LFjIUknG6UCL5zgmLXHMwVPGWkzoZuweq5n9x2d 3qe6ZdTwfk9az1wHZIzxaCQEiL7YxFF3bZAT5aSdvUTTRrUYyWgzlsWZDXVtrHLzJw4/ G0HCWw+dwkYiJLY76Iacdzl8CiqO/oe4PrUerDs0P/AEL91geQbD79IZ/QHqokFuHPlR OSdA==
X-Gm-Message-State: AFuF++k5qtkeeB3Mu8EH1i1pQ76XvhR3vk1LmAm7lebu6CUv9OMKY+tL W2xfA+4yFFHAEUWHFRw2IOA1uupekHMNgYjBiTzOzgQihWysxsC9bMKGzAge4D6/AShHG+Pj8I2 gm9n8Rg4YEFG4F3PQiIVNt7Fhppd+cwkGZVza50S8Mm+d8odBvULVY4/5
X-Gm-Gg: AYBFou3QHC0+wpTGreJGG4bF9kPhUhiWX6JLNEPsgZlmQHPmdxVs4rTAboBLF2QrVdG ltSi7M8v2t6VWy21W0qCzbyxIdrmZekYPcCl5pOqLSvZ6c2ArjSfPxvgCaHMzmD/OxmB0jc2ruJ TL0p1Yn/cUZOvUX1Kip5FD8m8FoNcUn7+A2avRxvuefrJimalFGW/UnIDZzcg1zyTbMhkNW0K42 axCHKOCeOg5JO17YCUPiMO5dLU9vrxu/5ooaabnh8qQ0/14s/HGBJn1LtoPk7e1O7b6p4asuD7B AYhObYDwwaa3eNaoLzoXC36LEeIkw7PXTTyXzyWeffNczX9h9CbwSfq9LFJ0JRpup/VWhps8+PO 1EutsI/PW04jHz5RXDE7G8ROm10m0dG+rcyy4AmmDHJlylhPvT87AS8UiOzzmm0w3SflVK1L7pX ko0byD3NBM+3QCKeoNGVGcH2yaJbGTczR9P4UmAw==
X-Received: by 2002:a4a:e845:0:b0:6c9:80d8:a1ef with SMTP id 006d021491bc7-6d4410d6085mr8548052eaf.44.1790460241206; Sat, 26 Sep 2026 15:04:01 -0700 (PDT)
MIME-Version: 1.0
References: <SA1PR21MB6104F2BECAE29404CFB07DF9A2802@SA1PR21MB6104.namprd21.prod.outlook.com> <SA1PR21MB61048DF3E73A2AAAA07A330EA2802@SA1PR21MB6104.namprd21.prod.outlook.com>
In-Reply-To: <SA1PR21MB61048DF3E73A2AAAA07A330EA2802@SA1PR21MB6104.namprd21.prod.outlook.com>
From: Iman Schrock <team@emiliaprotocol.ai>
Date: Sat, 26 Sep 2026 15:03:49 -0700
X-Gm-Features: AclHuK-R-4YFi3KEKGPdNOBNwIDpZ4CLiizVeQg9uPOCERTuRXMeXJjcxNU6Q_Q
Message-ID: <CAOfgHgof0U2_0hktMPZNaxxgD4YnZ9xU+Sk6G9YMO3Tzp9HvTQ@mail.gmail.com>
To: scitt@ietf.org
Content-Type: multipart/alternative; boundary="000000000000a96c9c065c6a024b"
X-Spamd-Bar: --
X-MailFrom: team@emiliaprotocol.ai
X-Mailman-Rule-Hits: header-match-scitt.ietf.org-3
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-scitt.ietf.org-0; header-match-scitt.ietf.org-1; header-match-scitt.ietf.org-2
Message-ID-Hash: OB4B2PGWGQ2YRJ5BTUGFLETU5QAF2DF3
X-Message-ID-Hash: OB4B2PGWGQ2YRJ5BTUGFLETU5QAF2DF3
X-Mailman-Approved-At: Sun, 27 Sep 2026 14:59:57 +0000
CC: scitt-chairs@ietf.org
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [SCITT] Re: Action requested: Focused Working Group Last Call on Section 4 of the CCF Profile
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/FmclkmQ4eDiyOTB409P0WJSjdEk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Hi Nicole and chairs,

Thanks for organizing this focused review. I worked through Section 4 and
reproduced the cases below. I support adding consistency receipts. I think
a small revision is needed to make the verifier's acceptance rules
unambiguous.

1. Multiple proofs: what does success cover?

Section 4.1 requires every proof to compute the same newer root. Section
4.2 only checks signatures against newer roots from proofs that match the
caller's older_root.

For example, take a valid signed receipt for R8 to R12 and append another
proof whose older root is not R8 and whose newer root is not R12. The
algorithm still accepts it. The R8-to-R12 proof remains sound; the receipt
as a whole no longer meets Section 4.1.

Could we align the algorithm with that requirement by checking that all
consistency proofs in the array compute one newer root, verifying the
signature against that root, and separately requiring at least one
older-root match? That would also need only one signature verification. If
the intent is to validate only the selected relation, could Section 4.1 say
that explicitly instead?

2. Is an unchanged tree an intended success case?

Section 4 specifies 0 < m < n. With a three-leaf tree, however, an anchor
at the third leaf and a single left sibling covering the first two leaves
produces (R3, R3). A genuine signature over R3 then passes the receipt
algorithm.

That establishes no growth, rather than a forged history. If strict
extension is intended, rejecting paths with no right sibling would exclude
this case. If unchanged trees should be accepted, could the definition and
examples say so explicitly?

Could Section 4 clarify whether the canonical-anchor MUST is a producer
requirement, since Section 4.2 says a verifier cannot check it without m?

Signed receipt-level vectors for these cases would help independent
implementations agree on the expected results. These look addressable
within Section 4, without redesigning the profile.

Best,
Team EMILIA

On Fri, 25 Sep 2026 17:44:45 +0000, Nicole Bates <nicolebates=
40microsoft.com@dmarc.ietf.org> wrote:

SCITT Working Group, The CCF Profile previously completed Working Group
Last Call, but the CCF specific consistency proof format and verification
algorithm now defined in Section 4 of draft 05 were not part of that
review. At the Area Director’s request, the chairs are conducting a focused
Working Group Last Call on Section 4 only. Please review Section 4 and
respond to the list by Friday, October 9, 2026, indicating whether: • You
support Section 4 and believe the document is ready to advance; or • You
believe changes to Section 4 are required before the document advances.
Please describe the specific changes or concerns. The other sections are
not being reopened because they were reviewed and accepted through the
previous Working Group Last Call. This focused confirmation is needed
before the document can continue through the publication process. Draft 04
discussed consistency proofs and the need to audit consistency between CCF
ledger states, but it did not define a CCF specific consistency proof
format or verification algorithm. Draft 05 adds that material in Section 4,
including: • The CCF consistency proof representation and canonical anchor
• Section 4.1, defining the COSE_Sign1 encoding and header requirements for
consistency receipts • Section 4.2, defining the consistency proof
verification algorithm Section 4 defines how a verifier can determine
whether an older CCF ledger state is consistent with a newer state,
complementing the inclusion proofs already reviewed by the Working Group.
Please consider whether the consistency proof definition is technically
correct, complete, and sufficiently clear for interoperable implementation.
Feedback would be particularly helpful on: • The proof representation and
canonical anchor definition • Computation of the older and newer Merkle
roots • Use of a previously trusted older root • COSE signature and
detached payload processing • Handling of multiple consistency proofs Draft
05: https://datatracker.ietf.org/doc/draft-ietf-scitt-receipts-ccf-profile/
Diff from draft 04 to draft 05:
https://author-tools.ietf.org/iddiff?url1=draft-ietf-scitt-receipts-ccf-profile-04&url2=draft-ietf-scitt-receipts-ccf-profile-05&difftype=--html
Thank you, Nicole For the SCITT chairs