Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials
Steve Lasker <Steve.Lasker@microsoft.com> Wed, 10 August 2022 19:30 UTC
Return-Path: <Steve.Lasker@microsoft.com>
X-Original-To: scitt@ietfa.amsl.com
Delivered-To: scitt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B2C52C14CF0A for <scitt@ietfa.amsl.com>; Wed, 10 Aug 2022 12:30:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.687
X-Spam-Level:
X-Spam-Status: No, score=-7.687 tagged_above=-999 required=5 tests=[AC_DIV_BONANZA=0.001, BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.582, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wAowgJjmO3Kz for <scitt@ietfa.amsl.com>; Wed, 10 Aug 2022 12:30:12 -0700 (PDT)
Received: from na01-obe.outbound.protection.outlook.com (mail-cusazon11020025.outbound.protection.outlook.com [52.101.61.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87870C14F735 for <scitt@ietf.org>; Wed, 10 Aug 2022 12:30:12 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=JYfvVLcMKpJ/w3JnBO2i3bG+ufs1G6kefMqhRcnhy6e2ewku1PBzqCSV6p38AK39SGq5eU9oc/WoNeX7Xof1+U7dMO/DjE8mUOHibQF7o/LB1O8rjdhdktx3sC48BBSPCWEUz0XWnzg0nvVdli6g2Fx6cjVs5ORcbNsfdoEISGdg3QKztdhlhMhv9xei110LLJ/zWUqYhC5LZIgjq+B2MaMkwh/JT4IN/HYPKn5GALD7x/Qq3qF+0mGIU6bQfDajqsjB5alv8wB4Jj37SfQSVCXlIMK20ocFCLnLj/ebcSkv9vzTUPj8ch08kXBlktA5P6Yd+XBzLBbYiN8jRLNdMA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=GTtUBO5Zv5Yt+cT0P1JFLKjQhxnsoocvJV+yF5DiC0k=; b=l3bhZD7atKJItQSfnHDHwMcz6vZYsMFlCW4eh62rYtpUIrAVynrSpMm4PvjVFJSrh5iQIMqhBTZsenQhsHpiPsHawhmLOI0bs2kc0L6TIlsl45s2AekPOQsTcdT2acRJRTEts/r1fm6XUB7iNT4p4WA9EHQRR6ikJAnXhYpANTGmyHOGLiqtyXPbTxJYmTQgnxTEaTC8M38oy2RKYi8Wt8X7lfY+NlgRI75M4CBoyURuDpdgXYwCpyJ2jLNB9qUtAGE1Dq9IX6IBC54gJp8czuxzMa+MU2bvRwf+K5BDdRio4KnQ03B0XDKBNOF+ntY/KLZZ0uJNY0lDOVdEV5G4aw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=GTtUBO5Zv5Yt+cT0P1JFLKjQhxnsoocvJV+yF5DiC0k=; b=KNbfEjMcT90KcrEHOzD0UQ9XU5jSbKZRtkN+QRnHWx8k3Beilko9wd6pPrXs6avdJuztVKu5WmlRVdNqYMoWKzVvbcjM+wrWPFbUpdTj8LfzUv+izB7nupbT/ndFy/+Jaiw7YzU9Tf6WYDNAOx+OKNBIV4xv+YcFAFD0IEEiOVg=
Received: from DS7PR21MB3341.namprd21.prod.outlook.com (2603:10b6:8:80::16) by DM4PR21MB3058.namprd21.prod.outlook.com (2603:10b6:8:5e::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5546.7; Wed, 10 Aug 2022 19:29:47 +0000
Received: from DS7PR21MB3341.namprd21.prod.outlook.com ([fe80::3026:6e6e:1b7a:98cb]) by DS7PR21MB3341.namprd21.prod.outlook.com ([fe80::3026:6e6e:1b7a:98cb%7]) with mapi id 15.20.5546.003; Wed, 10 Aug 2022 19:29:47 +0000
From: Steve Lasker <Steve.Lasker@microsoft.com>
To: "dick@reliableenergyanalytics.com" <dick@reliableenergyanalytics.com>, "'Hart, Charlie'" <charlie.hart@hal.hitachi.com>, Orie Steele <orie@transmute.industries>
CC: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org>, "scitt@ietf.org" <scitt@ietf.org>
Thread-Topic: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials
Thread-Index: AQHYp1C0dfe5ViVjoUuG0EEpKzBX6q2dVW0AgAAox4CACv4hAIAADYoAgAAFSTA=
Date: Wed, 10 Aug 2022 19:29:47 +0000
Message-ID: <DS7PR21MB33412D4FE3057A382A2B7A939C659@DS7PR21MB3341.namprd21.prod.outlook.com>
References: <CAN8C-_K-w5QQqrZDS9VH2-gzOO9e+HS8b9nGvG+ZBjJ-PM-MCw@mail.gmail.com> <LV2PR21MB3350154C13FA8A6F9D940FA79C9C9@LV2PR21MB3350.namprd21.prod.outlook.com> <13e501d8a738$1b277ed0$51767c70$@reliableenergyanalytics.com> <CAN8C-_JvDwS4CTBJMm9YN8jdXnLATPg0j3xO5BFs+yraWZc2Yg@mail.gmail.com> <144801d8a73c$adb8dec0$092a9c40$@reliableenergyanalytics.com> <OS3PR01MB75270FA0BFF65C76B2AD2D58D19C9@OS3PR01MB7527.jpnprd01.prod.outlook.com> <OS3PR01MB75272702BC43C5DA50A57081D19C9@OS3PR01MB7527.jpnprd01.prod.outlook.com> <170b01d8a766$6cf8b110$46ea1330$@reliableenergyanalytics.com> <DS7PR21MB33410F208AF17F985E9D7F609C659@DS7PR21MB3341.namprd21.prod.outlook.com> <607401d8acec$42946370$c7bd2a50$@reliableenergyanalytics.com>
In-Reply-To: <607401d8acec$42946370$c7bd2a50$@reliableenergyanalytics.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=22516ac1-149f-4a17-822f-30f9b6138475; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2022-08-10T19:25:05Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d829700e-5614-4296-1628-08da7b06afbc
x-ms-traffictypediagnostic: DM4PR21MB3058:EE_
x-ld-processed: 72f988bf-86f1-41af-91ab-2d7cd011db47,ExtAddr
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: spqirEPWHx6azJ2WI/VbQUz/AIz/xOt8JraB5fIlW1wFJbaYyF3M2E5ZkPaLIfwbFD1iL/gxR4T5XILnz/EkTGsuky6LMHvtrXz9l6zGoZXXVBdPqEB2Nmy/w4BVNBnZb9LkjsSGgYGE5aBgeKC+aVC+mWg0aRwlBTorYRpdOKh8Z9SqG/Mcgu0Pz2jy0A5MkIoJ2JFSwvmZCa1x0frnuar0tDUMy4gR5GNx4mwvf5eFw124XmIyq+Ugocw3momJbffHjZlrer6UMtXqfJPPwebo51MM+Cbw46PIL/ZyFiT2P3VCsDGmGLWDj9XWx/YMOEhDj83ulA6WIEgMvk74BpzdKYGmI9GZHfALgk2FDqVDoGW91ccbQZQsy9/vkKlitxHbh/3f5Wq1hy6KiLOgBynKn4eQvmfSEEXYN4iNtYj10hzspwdDzbdzgvPfe/jH9fP6UYwY+sa7tEhsDbcZGWF1a9gZLsmxzcdITqXY+DIKbYCjpjSvtXF3Vi+ZoT3ufZOsLMco53HlpmPu8eaq2MHVNbmhpHlDIaCsDgmBkfx8HCHukD5ANI/6q7FeRFJRW4AXQXZAEyAeybsy5ZgtrF83TYH7FaoQW2/igFWL0E8BE16BJlEm4y60EKmehoMFQXV1a6IMIkkIXnDjEqm5MJrrtzCj4fEQlHy3OaGNItapxEZ+amlm7YJtuPu7qncaKMIfsfMQr1+Vi0/DpiMr/c6XhHza4+s4rluGXsOlVKcLCqlZQIqo40CmDdXNDx3HttaRNO9YJtcQDcjLTK1ddgbjplXHR+Pd+AH+U/9/myQULsgtl5J0dNtICrpg3jxBET6MextVVmlEGc1i13lFn8JpbpA3qG/lLCq4uAHaqMEDJ5iJswBFY+BkdyjZ5RjqYfX3SzFSMtSV6EPJYe+OWo829aMipHp/MOc961bmS8I=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DS7PR21MB3341.namprd21.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(366004)(396003)(376002)(346002)(136003)(39860400002)(451199009)(64756008)(66946007)(5660300002)(66476007)(66556008)(66446008)(4326008)(8676002)(76116006)(316002)(54906003)(55016003)(8990500004)(30864003)(8936002)(4001150100001)(52536014)(2906002)(82950400001)(82960400001)(122000001)(38100700002)(86362001)(38070700005)(40140700001)(33656002)(99936003)(166002)(478600001)(966005)(26005)(41300700001)(71200400001)(6506007)(110136005)(10290500003)(7696005)(53546011)(83380400001)(9686003)(186003)(66574015)(579004); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: XTYLpc32riQwf2KtkyLrBE25ziEYRNpwgVDDfvs4MvD0XsbU1f9eJsU+wK2Fb6t2H6dCnfZHfYa+3fZIO7H8EH+MNQnxsjbNsmYfWNDBWdXBIpCApeiOZrzhm/a68TRigp9B+/MxBguO5aETOHIbVs7sCqsBevMx9xgTORqPg1CwW7J4KZAAdvTKPRen7MJDYRopFPHKn2pL9oFfBK1wkamYVazO7bkFJ4aQy9GtrQVmC3NoYkYV3L/XrHSkFBfkP1fGtZ8/ANeA9rB1w0JkmR5tXjE4HwGNAO/kG8hfynqKZ6V0N3eWdEiu7djI4S3TrNIttuS17zbAFT/cnBETpMwC3SenoqlzA/HYFY2lCuZYAMFmrR0zIDA00HTC2IldItH0Gn1S9WXKojJki6j9blEUmqqZHKC3FgBw5P8JgUdFdj0LyLYPLIE7AIB+toAmboiynPDwCzsC7NqBAr0KoXC47IsADODwiDO2763QzyWBirW75p3S/Yp9rzQ6wFRIRoEOMenefU+ksCrOKOQt4BdvBlgpBLKVuzhL0rDyUZBo/FXZwDp2vVC/Ut+PBjxGYwMvWmgn84U/IsvUEW8ek6sAW4KmFGVQJsgLl2RiQHX/6iwOBc9AO6sIfQoRo87IHWoC2gH1KvuTNgoJl0g628RQNQP9fAZjohplQcBs1HeK/jxdi8QDNydYxZythuViyh3INMhfnttMgsa5a12/0ghQjNJicpe6V1V7p0h7WS0yHIn2k9dC9esBGnKLnEj7iCi7Ty1NVKVbc7K7OZRCIk0jBDQryAGGmKZq+lZc3nA/mwyVYrWbsdSMkxKKOkjgHk2UWyMiHGSkgTbK41MuxEhvgjGjT/a0XKHasNNXH2L5Vcq7z2Sto/t5GrCqF7vnTN7ikNtrGyufuzy2tMJ0el4tlXzMR8sSrt35WCkuE0ySRmP61tWKhFVoZUJUKtm9RpxqPNV3VVN3fvWjOVxzI5y801ofxXH1V9TeQiyIQHFHQcVtxVxuD4BEQDzAbsyVh+DoBza1hxSwNDTpjnkjJs0xn1I710iUQ6UIeuQt+nfH3ojgtTdnufTtGrI7gQHKwqKL0X3+RnizgqxDrsbpu0lKRPobio9Ldxvxo954Jn3Ri9QqCnXcgzoU424kS+y/E1NS1JvTdpzd6iM5LtH9exKv4yDSx+Ryu7OffC9rnQdQ839Nv/MkW5xUGhnZdNljMVkTkruiZf5B5xid+eNrmHU8wPleqntS4btlG0zzpGEyHF7/wQQtBb1sgukXg7Bk46CgNJ0f5zL59prlCoij6aUZXD8XeUWLkpy1y8y45xTFzQrYbCuNFj/t8HZ4wnRxbe5IwSGUM3lknsJ93SJnAkfJD1O6ubBL+ZiaAWe98WFUsepGcToh9D2kdaVzkAuqute0f+vT6kYNSe9jTcZd4ufAfF3+jSlvlNVeMSst0X7vprPEhaZgvRKtEnZl+FFMmFLCLi6k26UJgwD6cEjK30n3QrrD8gnVAr6XjGb1MmA7OSbjV+TjJqFyytbXC0g/pib5+rqCXVOV5Gg2voXOdCmOedxhzhjS+0H1/fzTKmJcaKc4Rxn9py7A5KGJMJB6
Content-Type: multipart/related; boundary="_006_DS7PR21MB33412D4FE3057A382A2B7A939C659DS7PR21MB3341namp_"; type="multipart/alternative"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR21MB3058
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/Co206cNpX8XwYoxbhAbozwPzwFk>
Subject: Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials
X-BeenThere: scitt@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scitt>, <mailto:scitt-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt/>
List-Post: <mailto:scitt@ietf.org>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scitt>, <mailto:scitt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Aug 2022 19:30:17 -0000
Merging threads from Orie Dick, I completely agree. This is what I've been sharing with Kathleen as well. Imagine each instance can configure their policy. They can have their own unique policy for their company, they can configure a deferment to another entity they trust for their industry (horizontal/vertical), or any means they want. We've implemented a similar pattern with Notary v2, it just happens to be on the client. In this case, we shift the policy to the eNotary within the SCITT instance. From: Orie Steele orie@transmute.industries<mailto:orie@transmute.industries> Sent: Wednesday, August 10, 2022 11:31 AM To: Steve Lasker Steve.Lasker@microsoft.com<mailto:Steve.Lasker@microsoft.com> Cc: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>; Hart, Charlie charlie.hart@hal.hitachi.com<mailto:charlie.hart@hal.hitachi.com>; Steve Lasker Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials > This just points to the value of having personal, company, industry policy based trust stores +1 to this, here are a few examples of how groups have formed their own trust systems: - https://www.iata.org/en/pressroom/pr/2020-12-16-01/<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.iata.org%2Fen%2Fpressroom%2Fpr%2F2020-12-16-01%2F&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C7abb715cafff4950746008da7afe7ebf%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957530868630952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=cY9Cu%2B9M%2FGZ%2Br0v2tbHTGmRDUvh3zfTXSpaFdC5bxFQ%3D&reserved=0> (aviation / travel) - https://vci.org/issuers<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fvci.org%2Fissuers&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C7abb715cafff4950746008da7afe7ebf%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957530868630952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=XIV4ul4dxni27vXrK1cgm3bLaYRPVXm%2BVwB9JWigftQ%3D&reserved=0> (healthcare) - https://support.apple.com/guide/keychain-access/what-is-keychain-access-kyca1083/mac<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.apple.com%2Fguide%2Fkeychain-access%2Fwhat-is-keychain-access-kyca1083%2Fmac&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C7abb715cafff4950746008da7afe7ebf%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957530868630952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=m7l44jaHTfJxbzwyjoYgwKJuGNGEgpZCB3lTR1HHncc%3D&reserved=0> (personal) You can imagine scenarios where a more limited set of issuers might be required, or cases where you really want to be very open. Regards, OS From: Dick Brooks <dick@reliableenergyanalytics.com> Sent: Wednesday, August 10, 2022 12:06 PM To: Steve Lasker <Steve.Lasker@microsoft.com>; 'Hart, Charlie' <charlie.hart@hal.hitachi.com>; Orie Steele <orie@transmute.industries> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org>; scitt@ietf.org Subject: RE: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials Steve, et al, Some industries have a specific set of CA's they have vetted and approved for use, i.e., energy industry transactions. I don't think a single root of trust can be implemented, practically across all industries, if my energy industry experience is any indicator. Thanks, Dick Brooks [cid:image001.png@01D8ACB4.8CEFDBD0] [cid:image002.png@01D8ACB4.8CEFDBD0] Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council - A Public-Private Partnership Never trust software, always verify and report!<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Freliableenergyanalytics.com%2Fproducts&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=p%2BCeSucz3q3DY7Q2C1EBIuZNIKsr38O7xLh7Q6278k4%3D&reserved=0> (tm) http://www.reliableenergyanalytics.com<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.reliableenergyanalytics.com%2F&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2BPFQpDL8UArnVJA4EMtVyYueNn6%2BbzmLGrLZJmxF6mA%3D&reserved=0> Email: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> Tel: +1 978-696-1788 From: Steve Lasker <Steve.Lasker@microsoft.com<mailto:Steve.Lasker@microsoft.com>> Sent: Wednesday, August 10, 2022 2:22 PM To: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>; 'Hart, Charlie' <charlie.hart@hal.hitachi.com<mailto:charlie.hart@hal.hitachi.com>>; Orie Steele <orie@transmute.industries<mailto:orie@transmute.industries>> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: RE: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials It's an interesting example of whether a single root trust store is the best solution. Just because the browser trusts a root certificate, doesn't mean it's something we individually, or as a company believe is appropriate. We'll just leave the specifics for obvious conclusion. This just points to the value of having personal, company, industry policy based trust stores From: SCITT <scitt-bounces@ietf.org<mailto:scitt-bounces@ietf.org>> On Behalf Of Dick Brooks Sent: Wednesday, August 3, 2022 11:26 AM To: 'Hart, Charlie' <charlie.hart@hal.hitachi.com<mailto:charlie.hart@hal.hitachi.com>>; Orie Steele <orie@transmute.industries<mailto:orie@transmute.industries>> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials That's correct, Charlie. OATI's root cert is not included in the browser trusted certificate store. I'm not sure why they chose to do this. Thanks, Dick Brooks [cid:image001.png@01D8ACB4.8CEFDBD0] [cid:image003.png@01D8ACB4.8CEFDBD0] Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council - A Public-Private Partnership Never trust software, always verify and report!<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Freliableenergyanalytics.com%2Fproducts&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=p%2BCeSucz3q3DY7Q2C1EBIuZNIKsr38O7xLh7Q6278k4%3D&reserved=0> (tm) http://www.reliableenergyanalytics.com<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.reliableenergyanalytics.com%2F&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2BPFQpDL8UArnVJA4EMtVyYueNn6%2BbzmLGrLZJmxF6mA%3D&reserved=0> Email: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> Tel: +1 978-696-1788 From: Hart, Charlie <charlie.hart@hal.hitachi.com<mailto:charlie.hart@hal.hitachi.com>> Sent: Wednesday, August 3, 2022 12:00 PM To: 'Orie Steele' <orie@transmute.industries<mailto:orie@transmute.industries>>; dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials (Side comment: I see that OATI is not a recognized root certificate authority by Mozilla or Apple - didn't check others - so the website is therefore inaccessible without relaxing security.) ________________________________ From: SCITT <scitt-bounces@ietf.org<mailto:scitt-bounces@ietf.org>> on behalf of Hart, Charlie <charlie.hart@hal.hitachi.com<mailto:charlie.hart@hal.hitachi.com>> Sent: Wednesday, August 3, 2022 11:48 AM To: 'Orie Steele' <orie@transmute.industries<mailto:orie@transmute.industries>>; dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> <dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> <scitt@ietf.org<mailto:scitt@ietf.org>> Subject: Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C Verifiable Credentials Thanks Dick. That is really helpful for SCITT a lot of related projects I am working on. Charlie ________________________________ From: SCITT <scitt-bounces@ietf.org<mailto:scitt-bounces@ietf.org>> on behalf of Dick Brooks <dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>> Sent: Wednesday, August 3, 2022 9:26 AM To: 'Orie Steele' <orie@transmute.industries<mailto:orie@transmute.industries>> Cc: 'Steve Lasker' <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> <scitt@ietf.org<mailto:scitt@ietf.org>> Subject: [EXT]Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable Credentials Orie, Here is a high-level overview of the authentication mechanism and tracking used today for OASIS, inter-tie electricity scheduling. Everything starts with the NAESB registry (EIR); https://www.naesb.org/pdf4/webregistry_mo_registration_quick_ref_guide_v1.0_0417.pdf<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1IukwuhEQqregcVfBu_YTf7qloyu0S9CLEMvuw998GuhDfEFcipDth2Xtizyt11QWJE_rg9tKWNdFy9sR6AYzFs5C9RVZkYIdTyO90iI560dk7KjlRPsssiji4ni2uFgQoviKwbEitz9W0A-Jkx8qlZ-bf02dT2GpXl7-qqNgMCReV-n9bPYr7-gF7wRDuDdEpNTctYLkQFh_ODy3F4KcLc2yzJA66rSl-AObqSJo6LSNwG5QHs27-jxMPvsyvzy25FLEf6Q2NCVCA80ajyeRx-DLlAeVOtx8sKKHCAdqS60vvgk6XONNeacK9KVifmF7%2Fhttps%253A%252F%252Fwww.naesb.org%252Fpdf4%252Fwebregistry_mo_registration_quick_ref_guide_v1.0_0417.pdf&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=etxzyiDAecD%2BVw%2F3BmprF1k%2FRPu0HCn14lPaNnbWKrY%3D&reserved=0> Entities involved in inter-tie electricity transactions must register with NAESB's EIR, see link above. The registration process requires a party to obtain a NAESB compliant X.509 certificate from an accredited certificate authority (ACA); https://www.naesb.org/pdf4/ac_authorities_2022.pdf<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1T_py857nSLdfkwTRZ1F7IUeOLa0Mr0av8bfeuUJwVfOrnlR9B8EzOzxv92Uz4iu2yhDeR4WKL_eKK39aC0HZNHbI0L6S2ynYyf3MIqoWrhcKic931Qc8ha00DiNeKcev3mIQGWSdmm3oQWFZZeYhZ_XBpcojw3HL66SqprENJXYRuXx_69m7-vIbXr6m_muJ25A0-WOODvl0ZvSKLB5bCCNQHy8CETUnFlhi7KK4XlPGw6ngc0NPELIFd66qeSsonDSqajtS6_XsVDeQZ9afWewRkWRR2CS3RPxKELdvgtWbTLdNUMEo_OVauUoZUAaf%2Fhttps%253A%252F%252Fwww.naesb.org%252Fpdf4%252Fac_authorities_2022.pdf&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=v2M6eAhls0eu6%2Bp4Nn3XKmU3GC0nBWos96KrgtE20Hc%3D&reserved=0> Entities use their digital certificates for identification in OASIS; https://www.naesbwry.oati.com/NAESBWRY/sys-index.wml<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1K2p4qEguxjMHN9-wdAstRzAre5VeA0Zed0mvgfndElWXB3ORaiJPQc8AT7JJNrTMjapfMno_fFQCf0Y62gyPgnjQbEmdVMFYieaur2q043F0tN564aUJcAdmTBs4wbQV9V3zBPE-_4E3LKMveTRd4EEA3R0FVZKKh4vLBs4hzSu8wqJmm85OMK7l0hlniB0BYAgK4rRAKxGyo9m2gQbGh64ogBMsxFwFgbsiArp0Y6fdpXW0-RGp2kcNruYE4OtklUzkSHLHYNwG_4xj3QZVT0CcrM1parwb_zHxkQwcXBjyXQwqawaXGq5azf6Ymysk%2Fhttps%253A%252F%252Fwww.naesbwry.oati.com%252FNAESBWRY%252Fsys-index.wml&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=31XeKqLVeV9oLxf7Sg%2FUdam27u3QmLP1UreuvtI%2Fg2w%3D&reserved=0> Inter-tie transactions are scheduled and tracked, using an E-TAG; https://en.wikipedia.org/wiki/NERC_Tag<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1jg0PAl4xaAUqdpMj0XlwOYUgtyWJ8AEDByMI06i_FhGx7hBsVedp3De0cfsLDJrOWQk0OpLsHA-LZhek33mGBHnd1yGGQeO7gyBdmpJ8iJUh1jEMhZRFRhVJl0de4TxzOc-JCGbVPgYXa-8-oyvGUdvqCL1u0riyE5i35ZXxhgFrK5jS167ftdpGerze8DpFzv01q-lfBzQY3KxMikI7Aq599QaeahZrP9NaHPsunaoGrxrKD2WGOgLGAbiIogZvwqD6F-rbN2lIbrdeJZSVYw42P3L69rJ7XlgeaYjhgkVyPIJ1HC1whjq-NLkd-N0k%2Fhttps%253A%252F%252Fen.wikipedia.org%252Fwiki%252FNERC_Tag&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=XoBtwbK6u%2FAnrVk%2BHUhz1TwQa3xO%2FsmSgQAfO%2F9Ydw0%3D&reserved=0> E-TAG's are used to "connect the dots" and settle transactions that flow across Balancing Authroities. Hope this helps. Thanks, Dick Brooks [cid:image001.png@01D8ACB4.8CEFDBD0] [cid:image003.png@01D8ACB4.8CEFDBD0] Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council - A Public-Private Partnership Never trust software, always verify and report!<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1uy0clDWHgs8Om4IdyHuQzeSluoA8y61U3xQt6svGk4U9mgvOzG2j87xdGPNZwfL_6NeZLyvs2RtDXbQkJ-uy5FySOKYDraC9BCS46sTnuZZuNABtffYE50uYM3Wm6rGdSXPbIPyLIo1S9U5eKgRY62SvXzyvZStiEIy-g4zrHrqiwoZ4G2AfwJHqEMJbnR-Z8wwwLfANn8naHWq7IhHtieZojGBeisJx2LyDGehov7fBpcHgRQuNF-I-Idh5jB6CnEp4puLs01qMMVa-dVd11j8FHVTLpLcooV6gqqaabRENW_QqNKXvWegEhvV1Ow4u%2Fhttps%253A%252F%252Freliableenergyanalytics.com%252Fproducts&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=WO%2BZi%2BAr4%2FUTZJT8Opz27A6C%2BIadHY2ZfoYmo2akbdA%3D&reserved=0> (tm) http://www.reliableenergyanalytics.com<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecure-web.cisco.com%2F1GaJ6l5AOFj6kxiBsMksWncl4vuiZ-pUmsWTXCh5o60xFuI9fXHdmN1JPI17VWNKtRAJykdCd5QOfGdmalJsZes_8gztMRvB-TvoYWb6WOAm14Usouk0VNKr4H31T9BT5T0w1SnOo7YCh-3jVo0P2A80_8zELCxl4Ngnjzy7TfQm5dwNV_k8eKhiVi6wwvKSudLmuLC5ig0f-n4vQfqd3zlefh4egnP1zyrbhWoo50tuzH3ceMULrOjDHUs9QVKGe8Q74awwW_o1b6KYbqOP7Z8sQrpBMjf_ClYd-WXRlq6NNIXX0Ncd2niPfogZIcU6Y%2Fhttp%253A%252F%252Fwww.reliableenergyanalytics.com%252F&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ZdtJugKy09%2FSGT2o7QNeItzWg2MZaJYhAKeUXCYEd%2B0%3D&reserved=0> Email: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> Tel: +1 978-696-1788 From: Orie Steele <orie@transmute.industries<mailto:orie@transmute.industries>> Sent: Wednesday, August 3, 2022 9:09 AM To: dick <dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>> Cc: Steve Lasker <Steve.Lasker=40microsoft.com@dmarc.ietf.org<mailto:Steve.Lasker=40microsoft.com@dmarc.ietf.org>>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable Credentials Thanks! I am interested in applying Verifiable Credentials to energy use cases, even if we don't have customers in that sector today. The calls are open (https://github.com/w3c-ccg/traceability-vocab#meetings<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1HgK84MRR4bzXYAE7Niaeb8pYlkoyIfmiR0g4Dwj3DQJAh8OlSJW5p7TckF_9U5dHGeGuxJhuDgslYxAZNOsxcRUvIxstDWa3DOjtKeNjD-_Hps6IsgjIJjvkoJM6z6RXWAtxjfWtD3HV63XpkV_CEsvexRY-o5lFOUDFBoLvOST5pm3bbQJt3vdY1-67GIT9kXmrMYnnWWXvjuDcZkNODE1fmxIV1SYT7tQT9JveadGh5Z92HkOF2nqx92HaLeF53pxMJ1kYS8DiFQiewlQiLm9iNH3U9ZkX9n0d4hCRmD8Sp062hKxDB9F-2b8UFejS%2Fhttps%253A%252F%252Fgithub.com%252Fw3c-ccg%252Ftraceability-vocab%2523meetings&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=eD1gkfcy6EdOQhPTZt60YGfplH%2BBOTCbp8vizRVjVqY%3D&reserved=0>), but fair warning that most of the work happens on github async, and we usually just process issues and PRs during call time. There are also aspects of Verifiable Credentials that I believe are relevant to the structure of endorsements / receipts: The concept of "evidence": - https://www.w3.org/TR/vc-data-model/#evidence<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1q-6jNVM6JiTVpXBQDNrSw3REGqFIliEx86xQ3m1hKtfX38eVvCRSGYTej4K2SK8mdFcn2JqBZgNoMPS_rcXVBpyF1l5PmPOoFcCN-jmLI5CobgwDRSgnNTCovBIYUYq-zsaSmiiEAjGR8kgswrCi8csy-ZzBotSGM-M-GgM63-EeON2WUp7tplgZcM0drfvbvSkPmJNyhQ7IVz_JWZxPH45UgBXDwg3rEsIvPQjU2jV8dtlLOSr9PG4zRhRFcn9AsvFV6OrKVwmbgHSCHZuRW-k3T397qO__A7xJXOWprvooFuCc9y3ROkMuPUf12DNw%2Fhttps%253A%252F%252Fwww.w3.org%252FTR%252Fvc-data-model%252F%2523evidence&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2FsWvdfNDYBI3WoU1LN4lbmsx7x0vlOGI34QzzCAY1EA%3D&reserved=0> - https://datatracker.ietf.org/doc/html/draft-ietf-cose-countersign#section-3.1<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F13CILjI0celZHQgVsa-DDsoLq4Y6By6DHs7W3LY0H0AaoPvolfKPwURAqZMWPsqbcYMf_kWUKJ-sA8NLPu8wziluBz0l68B1CFniaOfUMqbMnF6C6XI8csVpayR5nSduP0DzdtYVrex3bRpGSYyBCgbFgdA9HbqgX48TPfCCsHHqaKMfCgJpqP1qqkn_Rvw8fRnwCncrbvhrPVrZR2672B85djLFYzQp6QkfNZLX2m7CyYa7EPkxXYtqpqrgKQ86Yl61tsyZjFCIlMY3qaHk_-T7iJ8rYjvtEwV0uGSDPKFXIQ-beS1aVt3d7utZHCYYa%2Fhttps%253A%252F%252Fdatatracker.ietf.org%252Fdoc%252Fhtml%252Fdraft-ietf-cose-countersign%2523section-3.1&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=mUSC56LG0nx4EaHSdO3tLJ4q9VlDspGwafh8TQoryhg%3D&reserved=0> - https://datatracker.ietf.org/doc/html/rfc4998<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F17DAGq2foFEYXkhjzWI_n3yyo-dU8HMigJwlon4x4SGlq2nwnPypo_SZZqn_HVrT0rymuTwcEF4muUKWKqsOGLkvOVa-LFd_al2zZ_lLftgtmhzFQhRFS7caOQJT0nf29VQs3woHnI7EoIfq1qF_87Py293jXAOIKL085OwcNuJbugCi46HG7Aoa0iPHiyavETuibYIlyB9E0dX9ck-eC39YMnZLGZAbf_U_zNKqeI-AYJbaKiKSYOMap89Xfp9wsrscC0zBwrQyJbQeJeX0W6bmWhWAyUuBgeHltrwzsA_eV6OT02qMLpg525iRIanpK%2Fhttps%253A%252F%252Fdatatracker.ietf.org%252Fdoc%252Fhtml%252Frfc4998&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529574280%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=SHhsljNgSVVYvWo1dw%2Bb6v2rxQWIFArjtrv8ea9%2BXxA%3D&reserved=0> As one example. I am hopeful that the next version of the Verifiable Credentials specification can point more directly to IETF RFCs to make its arguments, even if the json data model can't be updated to support CBOR / COSE as a first class citizen this round. Perhaps the next charter for that WG might support this better, if we pave the way with examples. Regards, OS On Wed, Aug 3, 2022, 7:54 AM Dick Brooks <dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com>> wrote: I agree. This paper by Orie, Michael, Brian and Mahmoud is very useful as guide for terminology and semantics. I can provide the authors with a description of how we track electricity transactions for inter-tie scheduling, called OASIS a NAESB standard, if interested. Thanks, Dick Brooks Active Member of the CISA Critical Manufacturing Sector, Sector Coordinating Council - A Public-Private Partnership Never trust software, always verify and report!<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1uy0clDWHgs8Om4IdyHuQzeSluoA8y61U3xQt6svGk4U9mgvOzG2j87xdGPNZwfL_6NeZLyvs2RtDXbQkJ-uy5FySOKYDraC9BCS46sTnuZZuNABtffYE50uYM3Wm6rGdSXPbIPyLIo1S9U5eKgRY62SvXzyvZStiEIy-g4zrHrqiwoZ4G2AfwJHqEMJbnR-Z8wwwLfANn8naHWq7IhHtieZojGBeisJx2LyDGehov7fBpcHgRQuNF-I-Idh5jB6CnEp4puLs01qMMVa-dVd11j8FHVTLpLcooV6gqqaabRENW_QqNKXvWegEhvV1Ow4u%2Fhttps%253A%252F%252Freliableenergyanalytics.com%252Fproducts&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=DXomUPLSM%2BRIT4wrQDWVG%2BDn7upMbQRULX9fomj%2FteY%3D&reserved=0> (tm) http://www.reliableenergyanalytics.com<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecure-web.cisco.com%2F1GaJ6l5AOFj6kxiBsMksWncl4vuiZ-pUmsWTXCh5o60xFuI9fXHdmN1JPI17VWNKtRAJykdCd5QOfGdmalJsZes_8gztMRvB-TvoYWb6WOAm14Usouk0VNKr4H31T9BT5T0w1SnOo7YCh-3jVo0P2A80_8zELCxl4Ngnjzy7TfQm5dwNV_k8eKhiVi6wwvKSudLmuLC5ig0f-n4vQfqd3zlefh4egnP1zyrbhWoo50tuzH3ceMULrOjDHUs9QVKGe8Q74awwW_o1b6KYbqOP7Z8sQrpBMjf_ClYd-WXRlq6NNIXX0Ncd2niPfogZIcU6Y%2Fhttp%253A%252F%252Fwww.reliableenergyanalytics.com%252F&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=DmFF8ba5afxuV8rou%2FA0%2FC1LEnL5L4ky8ftI0Br40DM%3D&reserved=0> Email: dick@reliableenergyanalytics.com<mailto:dick@reliableenergyanalytics.com> Tel: +1 978-696-1788 From: SCITT <scitt-bounces@ietf.org<mailto:scitt-bounces@ietf.org>> On Behalf Of Steve Lasker Sent: Tuesday, August 2, 2022 8:21 PM To: Orie Steele <orie@transmute.industries<mailto:orie@transmute.industries>>; scitt@ietf.org<mailto:scitt@ietf.org> Subject: Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable Credentials Very cool, Orie. Love the sandbox experiments From: SCITT <scitt-bounces@ietf.org<mailto:scitt-bounces@ietf.org>> On Behalf Of Orie Steele Sent: Saturday, July 30, 2022 2:08 PM To: scitt@ietf.org<mailto:scitt@ietf.org> Subject: [SCITT] Endor: A SCITT PoC for W3C Verifiable Credentials I made this today: https://github.com/OR13/endor<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1JdHGvnoZNb-fsV-unMzNkw21OKT7rRYo5H60Wa4K-Q4p7fB8jPlLTjzltfaxYOFnI68iv9RdZu4eeZzCvslBoPZThRfqgjbkIpAc_QAmXII8wXvclTmJp1PwWBck7W8vUKCgPgTPKwAgR4azwJsBLeLGe7E_NyiTmvg20gtS7omF01B7xzwXNs2jk4HRv9cwHQUOknpcyXaDoXN69mDdag7A6KlfSI3EnnlDQtYrlaKovDQmzajAmTkxfuCfWTP_pf0IHh1ylWT3YFkVxRBNLDyDNrCvdIUdSvpseyxcBy2VV7YxaRLm7g0FGZCbhIv6%2Fhttps%253A%252F%252Fnam06.safelinks.protection.outlook.com%252F%253Furl%253Dhttps%25253A%25252F%25252Fgithub.com%25252FOR13%25252Fendor%2526data%253D05%25257C01%25257CSteve.Lasker%252540microsoft.com%25257C79cb3d326bec41bf51ac08da726fb0f1%25257C72f988bf86f141af91ab2d7cd011db47%25257C1%25257C0%25257C637948121310174010%25257CUnknown%25257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%25253D%25257C3000%25257C%25257C%25257C%2526sdata%253DGdRRD0aMpzOJQIcqCyhajcz2NXRZH4irlRR31FFausk%25253D%2526reserved%253D0&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=voIGaj9pQofJUwZAza2rZlsM7nEJZlKDhkol7UcJ86Y%3D&reserved=0> As it says in the readme, this is just a toy example I made up to experiment with. The nice thing about endorsing W3C Verifiable Credentials is that they are already an abstraction that applies to "non software supply chain" use cases... For example, we model cyber physical supply chain flows using them: https://w3id.org/eability<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F12vv3ms4fQAlyFEE4k1zPXuwNVQhbw5JZJG1gBL6pcqttkVpsiI3zrO00D8muCuDxuryJz9JNlTjNav5jhFZwmrDOzf2g002uvnOa4j5zplIUKqg9fIr9y-JZ4w5q4mXJXza6z62EHNy6BzBsjPIluYavv0fR109auX6z1titrQhnW1fmk_usfbPqwJgY780ZABU5QTV12sZSiHaInC4MzZokObYCrnulteZlYaIml9emeQtOkK5mYExh0HK13aas-6VpgxE3PbRyBO3h9W_wUt3BpoaWT0QrjMaAM3NSTsiDsayitR5Pm48JR4E_wr_U%2Fhttps%253A%252F%252Fw3id.org%252Feability&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=bahzXBxWNyOQksYOgzpnRTkOC8FMFuSyeNOTiU6Jtfg%3D&reserved=0> There are a number of organizations looking at oil and gas, steel, ecommerce, and agriculture supply chains. Often they will share some common trade documents such as Bills of Lading or Commercial Invoices. These are examples of "SCITT Artifact Types" which you might expect to see across various distinct supply chain use cases. However, as is the case with Oil and Gas needing to account for fluid dynamics, and software needing to account for compilers, build servers and various source files, there are cases where you may need to model components of a supply chain with Verifiable Credentials that are highly specific to the use case. If you can tolerate modeling in RDF, W3C Verifiable Credentials come with a built in abstract data model that integrates well with existing industry ontologies such as: - https://www.ebi.ac.uk/chebi/<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1xFJzJsWalPbOckWorQVNuB3cCxcqr_4Pnqdh8BSqQrkm5N_-bHyC7w5_vXmkyt3-yiVfIj2Taw61Ngm4aT3AjD2Qv9jcxLAp632sCb0f7Z5opQ1IopQYFh035H3GJnum5M15fE7-kYGBh8eU24y4DJKQAGfZ6-2bMGAFBVdqq-7OCluOKHpJ7klc1xO775JEUod25j8sSRq32VCH023VBaqj9QgsfC-48IxN6LcJbg6jK3GgYWuUW9etiMl5z6YA0zskfxChMC6yEEFi8jPu3jPIy1SKm5Zu3HDbk7_-aS_gzJ-Kg45rGJrtq0L6Yh9Y%2Fhttps%253A%252F%252Fnam06.safelinks.protection.outlook.com%252F%253Furl%253Dhttps%25253A%25252F%25252Fwww.ebi.ac.uk%25252Fchebi%25252F%2526data%253D05%25257C01%25257CSteve.Lasker%252540microsoft.com%25257C79cb3d326bec41bf51ac08da726fb0f1%25257C72f988bf86f141af91ab2d7cd011db47%25257C1%25257C0%25257C637948121310174010%25257CUnknown%25257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%25253D%25257C3000%25257C%25257C%25257C%2526sdata%253DbXykuDkWeLmveTLjWO5zepwu20MQ5H8LIcQJyCaKN%25252BM%25253D%2526reserved%253D0&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=FAAmMyGBcdzyJD4gYZhMTkML7Nv17ozGgimKrWPakzI%3D&reserved=0> - https://qudt.org/<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsecure-web.cisco.com%2F1wTZmUTRG0X-fSLt6dzZoQCNorRuSvOgI2Zkd9g1PT-Iict4ikGg0GMZvBAIgZsC1maaOAyMgHegWdFG3dXEcQrYKnrjpiOl7OWCtiRGcjVJC4W7PiyfkrkoEDMc-WVzXjqIc3RTjhCVEO2Hy1KcH5Xg8lqTshdNo9NGPllnHT63UctpLAAQ4N8tGBMfu3q7YUicxI0zcgap8yD60I8HL33SfI2MFnr2DphA42faHPK6e5mePI5N1MZuhmdt3ou2MvF4zqUj9xhZGwb3nRkquaaObQFWXt8G-nog2o8iwaQFLpUTsPJbOJlpOLnLalkAL%2Fhttps%253A%252F%252Fnam06.safelinks.protection.outlook.com%252F%253Furl%253Dhttps%25253A%25252F%25252Fqudt.org%25252F%2526data%253D05%25257C01%25257CSteve.Lasker%252540microsoft.com%25257C79cb3d326bec41bf51ac08da726fb0f1%25257C72f988bf86f141af91ab2d7cd011db47%25257C1%25257C0%25257C637948121310174010%25257CUnknown%25257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%25253D%25257C3000%25257C%25257C%25257C%2526sdata%253DQOs%25252F5MIMJSm%25252BkqzHSSxV6MtsA4mOIzanJ6Vwtpl4NO8%25253D%2526reserved%253D0&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=7dR9dM%2FZ%2FmdLsdJdPkAMq%2BdF4F8BforyM%2BF6vOyY1v8%3D&reserved=0> My main complaint against W3C Verifiable Credentials is the limitation to JSON representations, if we could represent RDF in CBOR, we would have the best of both worlds with the main remaining disadvantage being the namespace overhead inherent in RDF. If you drop that, you will likely need some registry or algorithm process for handling collisions and interoperability, but there are various solutions to those problems. If you feel I butchered any of the concepts or terminology, feel free to yell at me here or on github issues, as I said, I made this today, it's not reflective of actual SCITT architecture, it was just to explore the space. Regards, OS -- ORIE STEELE Chief Technical Officer www.transmute.industries<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecure-web.cisco.com%2F1Pqu2CqEyHo4isckQh51PNnQ8tUbRhJ7fbWyn-w7XWT8mKjJG9jHB52pzDC91cVOUDvvB6yXP7TPyKL-6KQw4nyDVUvafmadZHo9d8Ch-lC1xIGYylhkgiUeEJlkJzb-8_bPpc3HM-numNyVUnz3wy-QWiv7Bwzc0EZvjlrk8l2zMTP7sgOAXQE64zUCay7yyWGYJm91CoHDytU3DDP8fEQdoS8GBRvo94T1w1wYmTEFjJWuq9_05ol76LbaYkHTQoZhRROFIusDfu9XNDv5Ofj1Xk0y_YmZkz6KS0Mx2eClGFuUIOo_FtTiX7i0x16EI%2Fhttp%253A%252F%252Fwww.transmute.industries&data=05%7C01%7CSteve.Lasker%40microsoft.com%7C4f2be070beef426a340e08da7b0365a1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637957552529730969%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=0uMJrYEPGWdQ5VeY3plxWYc%2FHGYxbgDYxSJB85evg1M%3D&reserved=0>
- [SCITT] Endor: A SCITT PoC for W3C Verifiable Cre… Orie Steele
- Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable… Steve Lasker
- Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable… Dick Brooks
- Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable… Orie Steele
- Re: [SCITT] Endor: A SCITT PoC for W3C Verifiable… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Hart, Charlie
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Hart, Charlie
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Steve Lasker
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Orie Steele
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Steve Lasker
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Carl Wallace
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Steve Lasker
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Carl Wallace
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Steve Lasker
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Carl Wallace
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Steve Lasker
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… ProSapien Sam Smith
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Dick Brooks
- Re: [SCITT] [EXT]Re: Endor: A SCITT PoC for W3C V… Carl Wallace