[Secdispatch] SPIFFE in the IETF

Justin Richer <jricher@mit.edu> Wed, 26 July 2023 01:51 UTC

Return-Path: <jricher@mit.edu>
X-Original-To: secdispatch@ietfa.amsl.com
Delivered-To: secdispatch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E941C151B0F for <secdispatch@ietfa.amsl.com>; Tue, 25 Jul 2023 18:51:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.105
X-Spam-Level:
X-Spam-Status: No, score=-6.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_DOTEDU_SHORT=1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mit.edu
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NBSXIyXPW12c for <secdispatch@ietfa.amsl.com>; Tue, 25 Jul 2023 18:51:33 -0700 (PDT)
Received: from outgoing-exchange-1.mit.edu (outgoing-exchange-1.mit.edu [18.9.28.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 50FE7C159A24 for <secdispatch@ietf.org>; Tue, 25 Jul 2023 18:51:32 -0700 (PDT)
Received: from w92exedge4.exchange.mit.edu (W92EXEDGE4.EXCHANGE.MIT.EDU [18.7.73.16]) by outgoing-exchange-1.mit.edu (8.14.7/8.12.4) with ESMTP id 36Q1pUVI002064 for <secdispatch@ietf.org>; Tue, 25 Jul 2023 21:51:31 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=outgoing; t=1690336291; bh=CC9+y+SmTLnOWaoHCMSGOZAg6SrnmahJ2OhPSXDo0x8=; h=From:Subject:Date:Message-ID:Content-Type:MIME-Version; b=dcjEvq+2mJ1ShVtdlQGWGz4Z7+p0+Sn62Gtb0K/OX4rnY8I/Ao2IZ85bY7ZwnMJqx NxkskPi3qYUfVHydiVYyCtBCDZRTYar3NsBo1nHHWjfvXvFAXbc4bjypJ/iUyL3tYK 3tJKbF68EaSA6l59bmXVxbIn0jfoc29SrJ70e3OmgbBCHjef1L1xt4fcel/fqEL9U4 HBlTlF/02UE6Gzh0qqA/LByfqkx9YHpMmX8djDCZhXzNyF4R0ryGr7ipa6AOFAjB2g x9Heo6etMeOfmDivsIudT0vhYlVEncPcjNjpibdCoRsQmnKMnuGPNW0wy3hIPT4zwY N4lSN/RtLA7/A==
Received: from w92extsm2.exchange.mit.edu (18.7.74.56) by w92exedge4.exchange.mit.edu (18.7.73.16) with Microsoft SMTP Server (TLS) id 15.0.1497.48; Tue, 25 Jul 2023 21:51:11 -0400
Received: from oc11exhyb6.exchange.mit.edu (18.9.1.111) by w92extsm2.exchange.mit.edu (18.7.74.56) with Microsoft SMTP Server (TLS) id 15.0.1497.48; Tue, 25 Jul 2023 21:51:29 -0400
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (104.47.58.108) by oc11exhyb6.exchange.mit.edu (18.9.1.111) with Microsoft SMTP Server (TLS) id 15.0.1497.48 via Frontend Transport; Tue, 25 Jul 2023 21:51:29 -0400
Received: from DM6PR01MB4444.prod.exchangelabs.com (2603:10b6:5:78::15) by PH7PR01MB8162.prod.exchangelabs.com (2603:10b6:510:2b2::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6631.29; Wed, 26 Jul 2023 01:51:26 +0000
Received: from DM6PR01MB4444.prod.exchangelabs.com ([fe80::7fe8:9de9:e874:3835]) by DM6PR01MB4444.prod.exchangelabs.com ([fe80::7fe8:9de9:e874:3835%4]) with mapi id 15.20.6609.032; Wed, 26 Jul 2023 01:51:25 +0000
From: Justin Richer <jricher@mit.edu>
To: "secdispatch@ietf.org" <secdispatch@ietf.org>
Thread-Topic: SPIFFE in the IETF
Thread-Index: AQHZv2OvPma6dFN+ukKNUW1rIx40XQ==
Date: Wed, 26 Jul 2023 01:51:25 +0000
Message-ID: <1705B504-4728-4B18-836B-39930E72A491@mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=mit.edu;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM6PR01MB4444:EE_|PH7PR01MB8162:EE_
x-ms-office365-filtering-correlation-id: 56457a56-3922-4ff5-94d1-08db8d7ad25d
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: rjqqO6HPSezIefGCV8XDD+Ay9aA/Pf4iL6okeflxM/KZgSaPDrqNn7OUBy0UWfVzsh5FgiF9afnww0YdJi/o5I29OY3wHKJwbfqxHvOwqhVS54/Li0PKaG/0+ZWOHU9YuFS8JT8FMOLb/iLoMPrd6BSrmX3fZCho29EI9IiJMxQYzKQ8Oz9GFj+Ty1YIBlhEyNjde91uUtRVBfTXG/ikXBLp2e/bhnOW+abYFIvptTBdrfsPRocC7LNe3YlMENoSnQz/JCS8vnWwnuulrZIQx7eAlgwPClk5vLkJ2zPpUmIm9sDKxQR3gyDf2GTEyYpP8h/WmxOb2zs2+2soDwlL28SADZwKX7UorRO+5qoOh/EbS1PXSomLEktkeP4EjfiWtZ4q1DcOWxU3P2Kv+hKbZHwmxqYKQ55nhr39oxiaO5rBEH+cpksKQf2E8HwG7OBn1fdEdxTcD1fcCwMHrhC2XpruZL3wgdF54Yz1BggrnwH8H8mr82CD8rcuBHZC/6Ygbykqwuer8FtCNvPPsxzO+NHI0YeQa4XoJ04Wm/VduZXH+8YIZJs6aDNmLYWsZIS5KchIbdY3UeI/VuDCT1v1gW9oB+osNBVT4DVjzELeSpI=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR01MB4444.prod.exchangelabs.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(136003)(366004)(376002)(39860400002)(346002)(396003)(451199021)(41300700001)(76116006)(8676002)(66476007)(66556008)(66946007)(64756008)(66446008)(8936002)(6916009)(91956017)(5660300002)(316002)(786003)(38070700005)(2906002)(4744005)(122000001)(166002)(478600001)(36756003)(33656002)(966005)(6486002)(6512007)(75432002)(6506007)(86362001)(26005)(186003)(71200400001)(38100700002)(2616005)(3480700007); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: lQRbCLP5jDMUECR9E+3NEBfrdMDAcYV8ztRl1p4i7QRgp/fSnfeZ+gWOq3puT84MF2x/eMrq69MjU8s7yHWZY2quxoFmiX9KKPoZ9qT8r7Eh2rR506kj5yv+xKIQE5Ys1nFNSuaRI8F10rzzBUd5EvFUCF3mGn6+J2LgZtJaKi2J4+w5T3Sax8yoA0XDDuJTSUNr0+FxCdGwjvG4wf8YsJlbXuTLUP0J325zYiHbSt3R+JKKJl6TZ0FrLR86zexlw3lGUeYUM1cQVfzLLUovm94BCF4hxMpDmtmsAqdF5fPOoeDAaEUbtqIlLMTHwkk3+51sCgS8C0bcrjonYBzb+yDeVZQnZO9PtB1hw287f2IODEEwawnjZOpEzUGGUEVtOoke3Slk1W/XYPbtbRpODhqJk1nCc1ZcpXhr1J494da1+kLcpfAq961JQ8NTFOyyJ+05PPaKlK7LFDbfehUFKqFfPWtCZ14b5R2siuMrOAOatla5yZDwJtyatFNFD0Q5W6dfwuqVBzg/EuNf17BIEmcGLvknmsdhwEIAQY+K2x+IijOBaKYKpRXXU28dqA4PQoSYpfKfKbD8Eo9xUnCWje6XLAjY2uuCbF4+SeQmZiNGYPsU+OqgFB1UERUTQTg6oOAySufxgu2nHL5lBItIFcSxZPBroJStoVz3iQ1Azc3h/p99StRMymvDK9SqcmS+JDwvDPxdkrqYmWjzXiPqixwQYo2Feotm3vfNSGdgkFNn6jam35W6GAJxEl9WK/IK3y6CUbH3BVvDXa7dL08h9+3m5nb2Y48IGgk9K8Y0RWWyQo7iHIcblgydgeV+z/fvAkvQgkzPdsztzowx9WslFmOtYg57WdISIrrJrUKGCp+NaKG2pV1iUDxRHoQeUxTJde2xceZI88J0gBDYVmK8dxLQTBirQ8pykbWvmridOfdtdi6ImmED5gF7GJrsLAWW/KVv2EZ4wP0qPY+QigCWwzwigu17Kgyq4e+zUv0++kmcCFXhyZRWiRCFEVs7qJTLm+4YhykxY6eaf6dh5qTc/UF24w2OlB2AFLHIydjWAJHwIwIBha8FOPPdPvVP3bHZSYlpzi2UD6ZjPP9g21UdKoNsez1jU+YXKm6A6p7wXhbnXOwQi1QQyjVlmZC7PSWSBCw+GI73d2ufKfp75VSy2a5XynZ9XCiL9xT0FBeDYz6QXV/0mDoJ7/IwXZwIDDPhKcs0/y7Z5YfC3zoKaPNanDVe0vOOk3CW5KhSdtZO9aG8FJuaJ7zg5k67Yyv2ag6wRe23ca8uBrFnXFL6PMcTDqCeC+OhrIWAuno3VY5XDKzsRKp+NSBk+Kv7T7YaGa+GcGkFGUN0NXr/Eh4om221qEoAxn3GE/skp+vmsHXXpBgmLqgOnEUsKxeJym9dCqLji0eDxMM9zE1suEgn84pt4uSPHchPTgF5mHdAEDdNV04+/x64At9lZLJRyBVjaaK/xLVCuD4mHhni0Ezueq4Q9dal2l8qPlopjaMxXMp7PS2f6uyAxs8dyKFtvg2EC2NtmyFB4p6ZMROctFfNlsgRJWk3i3p4Kpk8g2OWmerUm3w49pJ9vyV2AtjIsCkjrvki
Content-Type: multipart/alternative; boundary="_000_1705B50447284B18836B39930E72A491mitedu_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR01MB4444.prod.exchangelabs.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 56457a56-3922-4ff5-94d1-08db8d7ad25d
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jul 2023 01:51:25.7719 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 7bKy6A2w8Od9QdJ9oppYJ17ciZNXaV6mVLE/ZnheRo7NXUoWdCfb1JXU3gbdNlA+
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR01MB8162
X-OriginatorOrg: mit.edu
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/p0QuWYTDLizZpyfj6mA2z7cd4j0>
Subject: [Secdispatch] SPIFFE in the IETF
X-BeenThere: secdispatch@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Security Dispatch <secdispatch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch/>
List-Post: <mailto:secdispatch@ietf.org>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdispatch>, <mailto:secdispatch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Jul 2023 01:51:37 -0000

Hi All,

My presentation was cut off today because of time constraints, but the slides are available here:

https://datatracker.ietf.org/meeting/117/materials/slides-117-secdispatch-spiffe-for-ietf

The biggest takeaway from the talk was meant to be that we’re trying to form a community to figure out which, if any, of these workload-identity-related problems are IETF flavored. To start that community and conversation, we’ve started a mailing list called WIMSE, for Workload Identity in Multi System Environments:

https://www.ietf.org/mailman/listinfo/wimse

The proposers of the list have put together a use case document that we’ll be publishing to the list once we can wrestle it into I-D format.

Additionally, please feel free to reach out to me directly for more information — but please at least read the slides first. :)

Thanks, and I look forward to seeing you on WIMSE.
 — Justin