[SCITT] Re: New draft: The Coverage Attestation Profile (draft-hillier-coverage-attestation-00), and a request to break it

Iman Schrock <team@emiliaprotocol.ai> Fri, 21 August 2026 15:36 UTC

Return-Path: <team@emiliaprotocol.ai>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id DEFC712D69C6C for <scitt@mail2.ietf.org>; Fri, 21 Aug 2026 08:36:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787326616; bh=HhVhPVCKIYG8pKfUOYiPvSR2mCNqA4QtimPSwwUjPBg=; h=References:In-Reply-To:From:Date:Subject:To; b=zBZdEkvCpLB+Vfk58fXXszgrduWQhV32y/wyKi83Ux8somH4R9LdUTaq9a1D7THUt Os9tWYsADUmY/Ou2E1o9Sf6HSXQVipMkM5LGlHPtrgLwf2pGoLu7G1nCXbbEOS6FCn oJxjebl/UnVZGCT4qdBJRWhlecZGu8+j9ATR/n9U=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=emiliaprotocol.ai
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z0cRaMwTvtOd for <scitt@mail2.ietf.org>; Fri, 21 Aug 2026 08:36:56 -0700 (PDT)
Received: from mail-oi1-x232.google.com (mail-oi1-x232.google.com [IPv6:2607:f8b0:4864:20::232]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4EF2612D69C67 for <scitt@ietf.org>; Fri, 21 Aug 2026 08:36:56 -0700 (PDT)
Received: by mail-oi1-x232.google.com with SMTP id 5614622812f47-4ab89cff9c7so470473b6e.2 for <scitt@ietf.org>; Fri, 21 Aug 2026 08:36:56 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787326610; cv=none; d=google.com; s=arc-20260327; b=Eu0puMONBRd2v7SE/xelkYDu70hZUwvijkZ1Wst2UHYpVuP4FR96pDSTCgx0WBWstH Mj7SA9gTWRHoK2KHcRmis0py6thZZAyKtVUFicoBS7eBoXlTGwI3hxjnOQXBNZCTfxkt MLBq07BMX4LVKjiSbk7fb3PfxGtXj/FrrjK6qe/ZkBi07IAWrpgSYnb5ny4u6cH3Ro2/ lGxxSytWUD2jCuyiqpzTpKrBlNt2SEKLtQxnrfFfPxboVrg3Iekb6igyIcS0a2XYMj+/ N5wFzJhteKuhKV3185NAAkwiA2SVWX36OWxTUJI+yIMB8pyaqo/ErPXp8S/pXK/Tj+zV yUrw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=HhVhPVCKIYG8pKfUOYiPvSR2mCNqA4QtimPSwwUjPBg=; fh=Anxmu+iCZVTaF0nwB+Di1xcbGc8IAUY7lT1BcRHJn1c=; b=abPzgG1ugQbZYaRhkzw77B+zrRt8lf0zKHNnJXl34G56RLxOv2duLdT3MFHPk+0zSO ZPb0O6l66LQmnrNF9HiOuWxrlFtDpaPwrPw4RoHpJFbMvzjV+VavMIbmBBPGviRLdNFe i90Z2TJhbsiG9ETHFCFA9UDap/My++tTDVzuCIvdg9dk8ulSRYl2xLvn4oA6fub9Cmfu cv/DcwvlQ2lhB18dKF8T5gi7lK5+7egPNbNJpEuS5O7pysHTH06SazbqmrNFJ1DkptCS /0w7cokxyMo4kZ+M2MEyvEY2A3yKrgu2uy0ZZ1jYopVKUFs9NYh5PqkjT+HQfzJXLwGR fpBQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=emiliaprotocol.ai; s=google; t=1787326610; x=1787931410; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HhVhPVCKIYG8pKfUOYiPvSR2mCNqA4QtimPSwwUjPBg=; b=p/FUQxMUFPuzZH+CnnpO/OAbiJIsan0QotlMEoVx9xPcEQ5Lsl01v2vRx+DdspGnT6 WuY5z1jvgbFC9fH0IWH/W859s10upcrJcCovMmdo96OLQxxL69LeGN1OHpYVzmgllpvP qvGKOdln/RtOlgxl0BqZh7AShbO9gbf0pyadwlFOhNu2AYmurIPY9oZZeb0Y2UbkgwOQ mzARlX03cTqgViAJdt+VZgLwZewIiR6TGGJ03bKhefVpdoB+MXti9CtRZTDcu2WXDIth SyB4I67dCFbGMIor/oTgQeg70ALaoohOMROrsb8GFBocCtI2hyvJFMO9qFmYSE5BadWx M+Vw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787326610; x=1787931410; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HhVhPVCKIYG8pKfUOYiPvSR2mCNqA4QtimPSwwUjPBg=; b=pMZzjZ5TqDgepZwEtbx+eX7GDmsV0lGzyY56bpzfDjyIiprJWZNC3EZLNy1woG9dbz i4PVe2gpwTHlZMqafo8F750XsETKSK/rHaUPJLYiMR1ryQZS1SpzVFVojeyRZavGT4Ir aLHTr2u+ydYR91swDo4oYCnM8knMn0recNLm3VSA95ZHuYOcGXWLwIh8wZve8jKTsR9T i+WLnPF2cGEY+AfoSXZBtDjvSx9aCso8800upmMvfP2d4snZysrlzTiB/7eF6pEMXpyB ao42WxV3ZZiXy+uxGrH62Qt9XQj0nGvgIQsSyGVkcHOKfPBkUASYkRYxVERSClEaCM45 lL6Q==
X-Gm-Message-State: AOJu0YyU5OrZg+qR7AHFem1l6Y/TSw9+tw8DQ26+0RbpL1pj40AuKbR8 MO5RyjXNemZtp9otDuqNlBM4IhBtr/5btAJNd4MT8OgTMSBXtxIggy3lILr089DJTs1PpifMeWF /Cd6p1FJdNL7cHPV1aq3q7ReLrc/jEG5huvtJSqVoYlsGPnkKRvMX00qk
X-Gm-Gg: AR+sD11oLozafDzPkZFRz3gtu9ukFqlhTm6uttIZ8IZjoCWWBTzXuOHNp6jbdawHOdy zcp7c4OE534Mz1qKB8k/W8oScpNmxhOX77ALzBKq94lwy/UH7JumUJ3xNupSr6C/gkG2a68884L 4fiNbS4hcSU7lU2d+U3SphZ42+RwRuwsWJEmL7v7l1q8eTaVms0093qQg8UgGAGTU/pc9Gqwv5m yjyrSzHpXOmHE+TDckTE3aiYDWF1HBnEfMueekKpBdgIHD37NuYaxLYmQBr8NqsYZMCUab/IdPm IhwnfnTKNA8zzGxYFcQpNdfSZc4GJ9aaSNPx0EYowpuEu2JdEgReaEYNGJ8YA261xpqKtNQEN+z 01mBnAYRP8scQlBPlzas8CfZB48evAJZ/DVlsQZUizmsYd2YGbkYR/V6b7Q==
X-Received: by 2002:a05:6808:1b22:b0:496:301:36b9 with SMTP id 5614622812f47-4b2eeec0e92mr6472338b6e.0.1787326609740; Fri, 21 Aug 2026 08:36:49 -0700 (PDT)
MIME-Version: 1.0
References: <BYAPR19MB280613FCD91EC0ED03A93970ADA42@BYAPR19MB2806.namprd19.prod.outlook.com> <CALc05oF+y8m9SicMQVj67mTv1gzq2f0Tw0-W0Vne6P6FLJ-rPQ@mail.gmail.com> <BYAPR19MB2806B7556B4AB84F63552AFCADA32@BYAPR19MB2806.namprd19.prod.outlook.com>
In-Reply-To: <BYAPR19MB2806B7556B4AB84F63552AFCADA32@BYAPR19MB2806.namprd19.prod.outlook.com>
From: Iman Schrock <team@emiliaprotocol.ai>
Date: Fri, 21 Aug 2026 08:36:39 -0700
X-Gm-Features: AcwNN1UulTA-q-j7d7jUJVmBsUhA2MYThw5UWKHWsM3567RWwk9XPxC_07YakKU
Message-ID: <CAOfgHgr=T7otgx-3SkvGiMAM9Nkor5J7TAE0HetEdhnNmYYvdQ@mail.gmail.com>
To: scitt@ietf.org
Content-Type: text/plain; charset="UTF-8"
Message-ID-Hash: 67XTQR255OE6FC3JF4OULYFU3JLDD372
X-Message-ID-Hash: 67XTQR255OE6FC3JF4OULYFU3JLDD372
X-MailFrom: team@emiliaprotocol.ai
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [SCITT] Re: New draft: The Coverage Attestation Profile (draft-hillier-coverage-attestation-00), and a request to break it
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/tfMrzQ06_9LMNfK22w2bOnFWbR4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Dr. Joel,

Thank you. You asked us to break it and then treated every break as
useful input instead of defending the draft. That makes me more
confident in the work, not less.

The right next step from our side is simple. We will preserve PR #630
as the pinned -00 reading. When you freeze -01, send the exact schema
and vector bundle. We will first run the unchanged -00 implementation
against it so any semantic movement is visible, then update separately
if the new text requires it. If it disagrees, the disagreement is the
result.

I also want to keep one boundary intact in the next round: CAP-1 can
make producer-declared coverage and internal accounting testable.
EMILIA can authenticate the issuer and bind supplied population
commitments and the report to a named reconciliation program. Neither
establishes that the source population was complete or honestly
enumerated.

This is exactly the kind of collaboration I hoped for. Looking forward to -01.

Best,
Dr. Iman