Re: [SCITT] Call for adoption - SCITT Architecture

"Smith, Ned" <ned.smith@intel.com> Mon, 14 November 2022 20:03 UTC

Return-Path: <ned.smith@intel.com>
X-Original-To: scitt@ietfa.amsl.com
Delivered-To: scitt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 946E8C14F743 for <scitt@ietfa.amsl.com>; Mon, 14 Nov 2022 12:03:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.096
X-Spam-Level:
X-Spam-Status: No, score=-7.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=intel.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Xv2bB2kBcgSM for <scitt@ietfa.amsl.com>; Mon, 14 Nov 2022 12:03:47 -0800 (PST)
Received: from mga11.intel.com (mga11.intel.com [192.55.52.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 65CEEC14F720 for <scitt@ietf.org>; Mon, 14 Nov 2022 12:03:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1668456227; x=1699992227; h=from:to:subject:date:message-id:references:in-reply-to: content-id:content-transfer-encoding:mime-version; bh=IKqPKGLgiP8no8Aql8hoR6xHrHmy1bqNtrM33B0tif4=; b=c6FuxDee/6DO7vOTcC4zOD2RliR25D8vvd4Fqwp0xoaEPDNQn51qE7us xTwOprGY3X/rwnoxJ8FObUa9h5NnMpZDmcmUmpStAMprA0VDXH1qTMg6o NXC1LzlY5Ep3zjw9Bk5gXyB3MYl8FQ0YnNA7wFwJGcf2qVMCAfAhrIC3m D3zA7oqRY1MxRdSte3YmQHWj8WZ+xpPHiINj7PlWVmevFJLhAbcP39h70 xD0dCW8LUTTKIw2pUG+fixnO6silufEmMNDViRkAmsWzKZOYUIwhvi9rT drUBi8Zo81EQbOrIvABxXx0e/Lf0QciGTRuzcIvMLLu1mgfew4/xf+Ps2 A==;
X-IronPort-AV: E=McAfee;i="6500,9779,10531"; a="309699236"
X-IronPort-AV: E=Sophos;i="5.96,164,1665471600"; d="scan'208";a="309699236"
Received: from fmsmga008.fm.intel.com ([10.253.24.58]) by fmsmga102.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Nov 2022 12:03:46 -0800
X-ExtLoop1: 1
X-IronPort-AV: E=McAfee;i="6500,9779,10531"; a="702147178"
X-IronPort-AV: E=Sophos;i="5.96,164,1665471600"; d="scan'208";a="702147178"
Received: from fmsmsx603.amr.corp.intel.com ([10.18.126.83]) by fmsmga008.fm.intel.com with ESMTP; 14 Nov 2022 12:03:46 -0800
Received: from fmsmsx611.amr.corp.intel.com (10.18.126.91) by fmsmsx603.amr.corp.intel.com (10.18.126.83) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.31; Mon, 14 Nov 2022 12:03:46 -0800
Received: from fmsmsx612.amr.corp.intel.com (10.18.126.92) by fmsmsx611.amr.corp.intel.com (10.18.126.91) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.31; Mon, 14 Nov 2022 12:03:45 -0800
Received: from fmsedg601.ED.cps.intel.com (10.1.192.135) by fmsmsx612.amr.corp.intel.com (10.18.126.92) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2375.31 via Frontend Transport; Mon, 14 Nov 2022 12:03:45 -0800
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (104.47.55.100) by edgegateway.intel.com (192.55.55.70) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.1.2375.31; Mon, 14 Nov 2022 12:03:45 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=UN2q6zUojFsoI2FXeswUcYERS/x2uHYbxrK6RRQlDEqcUeRft+pA4FMQV+HsemUtOfX27dUrxmyWNmfFzgxRqZZF2tip82FYVwuZPpLC054JnkV8fpE986Qerq4+8Znnn0geYiLzmVQnzT+m3c4xrSuavw2CyAyFwoG9JMkX+YoF6JqHaSUgLG1tCeeu65QH5nSwTDebK07kRThKUpfkDUmousDh3grpSPKpYIGUq3OX1z0e6CKyB9/d7yWfCu9MTFMQclldogKOhpZJ8Rp/sqW3eKrn44ysjcQuMUOUrILm9J7R0Q7Tw9imXe4cMdnDS0iUQNhbmtmiTmIPh/QReQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=IKqPKGLgiP8no8Aql8hoR6xHrHmy1bqNtrM33B0tif4=; b=KmpKqdjDFcNhDdQP6KyJZw4OarcjpEQ6pMu+Eb8AOTcvsG6mpkF+EesQ8kh67lZZYLZExm1C+8h1Si+KE5jlGBBWVvuhqvDb/Vz+RBXUN5uK4I0xc4Fxj2dOPqtzwARzlcV5Uc4svmT8qSKoG+xlDHjUEvcChNq5knspwfc5xXbkXVysbcLfNaj3OiVD4sxRVoHBY87yxCk/57MBmdVhqmWwkMtjnn6Rm8eqvkMpNmuAVle7DJyVNZQ6PQ0e6sV+E2UYTUoYHnib26FX0eVo+qqSbOM0aRVnJmsSWMyj36Ir2pvBAz5XgjS+NNEcp6y4v10OFlr5UP2OxMayvDJrSg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=intel.com; dmarc=pass action=none header.from=intel.com; dkim=pass header.d=intel.com; arc=none
Received: from CO1PR11MB5169.namprd11.prod.outlook.com (2603:10b6:303:95::19) by MW4PR11MB5869.namprd11.prod.outlook.com (2603:10b6:303:168::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5813.17; Mon, 14 Nov 2022 20:03:44 +0000
Received: from CO1PR11MB5169.namprd11.prod.outlook.com ([fe80::a348:c554:f45d:2e75]) by CO1PR11MB5169.namprd11.prod.outlook.com ([fe80::a348:c554:f45d:2e75%7]) with mapi id 15.20.5813.017; Mon, 14 Nov 2022 20:03:44 +0000
From: "Smith, Ned" <ned.smith@intel.com>
To: Eliot Lear <lear@lear.ch>, Hannes Tschofenig <Hannes.Tschofenig@arm.com>, "scitt@ietf.org" <scitt@ietf.org>
Thread-Topic: [SCITT] Call for adoption - SCITT Architecture
Thread-Index: Adj4GkNnAj6pDrqoT42mv3OdDr0QSAASR9eA//97goA=
Date: Mon, 14 Nov 2022 20:03:43 +0000
Message-ID: <94AABEC5-939A-48EB-B589-AAE7EDEA9F6B@intel.com>
References: <DBBPR08MB591573B5A97DADD9F0EEC2E9FA059@DBBPR08MB5915.eurprd08.prod.outlook.com> <3d32726d-03e0-7c29-1e2b-e911bab44a60@lear.ch>
In-Reply-To: <3d32726d-03e0-7c29-1e2b-e911bab44a60@lear.ch>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.66.22102801
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=intel.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CO1PR11MB5169:EE_|MW4PR11MB5869:EE_
x-ms-office365-filtering-correlation-id: cd6a5fa0-e280-4655-4ad1-08dac67b553e
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: NF1906BaUNt7XV2Nt1HNhWww8my7Y6RgYftx6uoZOOIBXwAZ9XSVnxL5yupz/EhBqYMtdQBjanaiPTNvZxcICordSralGxJCx2dkHtXH4In2M1fTUd4uIIb80IZ8g1grscbpFJYDeQlrhb7vqo/MWCy3g0KwwuLPYxuRLk0rUnIlLKTuBWmUwUWpiihtzRAf/TeFasC9yl8Pj7qKNQRswLkUYc86DSKvC0ckuXttkcivAzufXwK83n8W1gKfxM5+4uNQBysuq78Kgotqkk7XRYlBvVa1ucetHF98fDHctVd/HsnLkRF7pIdYZq8T5EW+8EMrKKUODetEi7Jfo8TYHKkDEi2V8EttqOr5D6p8p+LwIPU8P+pkwCzFHrH3nZWJdb+4VhcTFeUk5WqdzE9rqWNMIaWLi8CqVK7X8KfYkrm0CzwjdJsICd+13MFeU94ViPEJRlH9SgIBv7fXCQK7slyi4iZfstBH1F4qZazLUdI6Xss+eaWSPY1VHagDvMOw08Ii2ZyfvvySYwZS7dpXyca84vqsr04Das6g6ChtB9A3KpM4bgRjCmTwt4kU/7cynH1Lyf5Be8NTtRB0ULavEunQZpX0DCSMzc2IYHYfsiJQ2jdgiYMvqDCtbHDKvjrb8xtWSFutzvPRXULRMOsnwHFGFLdYA1hAnqWB6KCTB1ZxHyYBdcMooKBUGO6BI57j4p3TwdDBeVWogjMXDz45t3wC2i9D651EgcABM2Lecbu0prOQLC4VG/mD6g1c1JnIvB0fSUiJ3XD9aUBRCBQ9MGBA38WobBYru3LCx3mQN5X+aOpDYB3X5yZSeY4279J1
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO1PR11MB5169.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(366004)(376002)(136003)(396003)(39860400002)(346002)(451199015)(36756003)(86362001)(33656002)(38100700002)(122000001)(38070700005)(6506007)(53546011)(82960400001)(110136005)(966005)(6486002)(316002)(71200400001)(478600001)(2906002)(5660300002)(2616005)(186003)(41300700001)(66446008)(26005)(8936002)(83380400001)(66476007)(66946007)(76116006)(66556008)(64756008)(8676002)(6512007)(91956017)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: cMkKFXxp5siF7tot2WcJgn142CNCHqvLscFHCmLTP9DXpLWWw/Iub0VJZG0ByWyUqgbb5/yZpek/vT2QjLFq95hRlGevTf2bjBlRfQIQuilSwTgj3EVE7/v1sKGUxulYBTeCOkiQJu5ud2MLXNtmA9a8Q3LdWsRiALcJVOvlcAOxwotpeYqm4xOy02mxWEL2kaOXL4hWZUlLS7hn+MCYqbmDlWOliADWcmyIOG8vXzZM1ZP6LgZiL2mg2t6Y2h+4CZyvNZ1UVDzcf270h6OwW6OyNZCuHdxuZ/6fEGCX2VA1WcRHNGO1qworMFm1fvCw3HgEEKD1IFOd96t2w5gEpqbpKw9JFogGrzxaSRQvVe7tr30sDZh9n2X3FO78W8liY5vNb6IXHY9HdPZxgrRomFnAVyq8KGLp1EH8Ui8rKvOOZzvbjg2M+1DPqmeEfd+1MTv/J3PaRVcOUPyeStBsTp+aHeiL+3SX3HgubhfFcpqN646b2Mt9TY1z/a+7Sy6nTIcdbfvH7oXecm1KvJP6jP0pG3KC0qx0DDlmM6gwZb/zq/sEuKPzD/cQ8i7fl6kxwtyOzYNPe84mBefGGx3SufeW9U/ciSTYvCYBxXpnQHZTwTxhfEKRBkmE7G4eL7KV71s+A5YOXxTXKy5GMnxI55a6mJpSaK7x3ww05GWop9h+FvbFNlW3ethcgOfXVvTj40hkF09PRcGpczd1YNJ7VYRNcJPtF1KEAG2PThNxv6mgGkSGVwoET62yXPaXadEtRn/b8WQrUzFUzXd51sHs3sVDxABfua3BJuPETUR07NTbKedH5ZICXUmSUv85CSvHV1xTb5yp5i4bPIotJezvjjV6kHAkf6ngNs/b54XeXvCi/2dLSTUQL18dDD17RQJgzM0cMQUIs3pVbqj7yziEW+khI4x09q20TZ30OgHGuDfMmy+BL/+s3XDlHcZs0kW0xtq2ReWMeLI20yuMpmzZihhC4b+p8ErGg92oww3keyUM79MM0p/JEiJk0j0Dfet10jDgYKwODiaJQ2P/LZ8Y1/aMH1sKjISfMCAOUgp/9riFb3jElbOklHK8jJQWmA1X0E8P+dCnMJtsW3j7XFL8KBrdV8TSU76UBrgRXJsCR21ykqHADdFmUcmGvCVTPGFHwH7LgkX2noPMR2M1yyevTBX4Hy2IJwCk1e9JuL1ifChxtO96J4vMU2odh0lZqUe+co22Tz/qqlT62QCiYIYVRxAFCCKRndQteHOssd7aH0HBJEcSri4CkWF8KZ4QvhFqGhs2FcP1UcquXrZDlR3gH/cmfX3rwlpvhERCXZxt4SrVm0UIXi3DozRt0AuvcK/CgqhIOM/ZQeNJcv7gonzVrukGR84TMcgP/jhLQ6ZMMiA4rL1emKhKAD6p/C7XoRifTi5UMB3IQCrRcQn4RZiaKacjWf7YyjyXamwdHsjBtjYeVzaHHh3IXopLBBTdNjtjCTR9Bsvf4t5/fGy9XtdlRS1w1d14AfiQDryFwb97/BaWYZLDKPHRT614i3jVOl0lTMNHDxuT4YknyT31M2zXwLE6iorjvgioc3qpCyJS8KVFbEncPgOh47rFbDkIcfhw0H//aJ74bsSe0Cmh6Gg1UA==
Content-Type: text/plain; charset="utf-8"
Content-ID: <C09101772A3D5C46B84897FAE54EA79C@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO1PR11MB5169.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cd6a5fa0-e280-4655-4ad1-08dac67b553e
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Nov 2022 20:03:43.9456 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 46c98d88-e344-4ed4-8496-4ed7712e255d
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: qR+Ld5xQQucpKyceh4JmQ2dyM/saW7z8WuYvX8GY8eQetLlYrKMSEbvE9Gqotzffquzplv82h/j+a9kwn3w7iw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR11MB5869
X-OriginatorOrg: intel.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/kKzst_IRZm08zESbS6JTs3t4w4A>
Subject: Re: [SCITT] Call for adoption - SCITT Architecture
X-BeenThere: scitt@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scitt>, <mailto:scitt-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt/>
List-Post: <mailto:scitt@ietf.org>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scitt>, <mailto:scitt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Nov 2022 20:03:51 -0000

Dick Brooks pointed to:
>proprietary trust registries in use within the software supply chain today. (https://www.einpresswire.com/article/545051889/announcing-the-sag-ctr-tm-community-trust-registry-for-digitally-signed-software?r=pawKHGm9JeOss4tpbO), 
which cites IP.

On 11/14/22, 11:58 AM, "SCITT on behalf of Eliot Lear" <scitt-bounces@ietf.org on behalf of lear@lear.ch> wrote:

    I am in favor of adoption, and I would be willing to review the document 
    (as I have in the past).

    However...

    I would request an early IPR check.  We have had a sad record lately of 
    late disclosures.

    Eliot

    On 14.11.22 12:18, Hannes Tschofenig wrote:
    > Hi all,
    >
    > Following the positive feedback at the IETF SCITT meeting in London last week we want to start a call for adoption of the SCITT architecture document.
    >
    > Here is the document, which serves as a starting point for future work in the group:
    > https://datatracker.ietf.org/doc/html/draft-birkholz-scitt-architecture-02
    >
    > Please, provide your feedback on the mailing list by *November 28th*.
    >
    > Ciao
    > Hannes & Jon
    >
    > IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
    >