[lamps] Re: WG Last Call: draft-ietf-lamps-rfc6211-update-00 (Ends 2026-09-15)
Michael StJohns <msj@nthpermutation.com> Tue, 08 September 2026 21:40 UTC
Return-Path: <msj@nthpermutation.com>
X-Original-To: spasm@mail2.ietf.org
Delivered-To: spasm@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 898E413749D4A for <spasm@mail2.ietf.org>; Tue, 8 Sep 2026 14:40:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788903615; bh=Si6ouBT0GPYGv8gd/jits9DmgVZhgl7p9dv7cQyvIwI=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=Jx82ZXmKtwYpJKAjQ6QIia1XB1tSz4YsKbFR9q0iCaVzcodxB0Vd09ppNyVfqO+Zt 7OgyiVG/n3nSX9HyDsHQAu5KXBG+KIzt+HOzuKDNkxIxLKPd21M3rUH/OttMx1TXhb Oh1v8lDVmP6bAu/Au9qX5sPUii3FHd+8rO3JkOto=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=nthpermutation-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k06reUsCn3Al for <spasm@mail2.ietf.org>; Tue, 8 Sep 2026 14:40:14 -0700 (PDT)
Received: from mail-qt1-x836.google.com (mail-qt1-x836.google.com [IPv6:2607:f8b0:4864:20::836]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D25D713749D43 for <spasm@ietf.org>; Tue, 8 Sep 2026 14:40:14 -0700 (PDT)
Received: by mail-qt1-x836.google.com with SMTP id d75a77b69052e-52f83889a93so52311721cf.2 for <spasm@ietf.org>; Tue, 08 Sep 2026 14:40:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nthpermutation-com.20251104.gappssmtp.com; s=20251104; t=1788903608; x=1789508408; darn=ietf.org; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:content-type:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Qinkpq26/1a7aCkcUaJfKcPpf/d/Z5EL4+i49bQOTZU=; b=mPFkVRrSM7MWlSx+n2Huo53c8MUYY+pj4vb6kja7kk5jzDXnmEltps/mKaftmRH0yR LxS+bhEcjtx29XCJlc0OFMHdSiBh/OE7vu9/hGc1y1bT1cz1oWWv4oe/cn9hcUDJbTdv E8NfShUInB1BKuIfQnO9JzPmsvZqowrXRXBslTikJHqeKmxYdlbHYxpwtuH8OETx5lWs 4iG2UVgD/X1Y5NwNCFjGnrveGtpTgjcF9hESi+vNe0s13xk/j/hVgsZ8nJTVQlJJ1AI0 8VocVt9TmRqycOk99XafKuAJn0ryBxjHjHnjwWDzGnDcOote4iw7KV4acGjKVrOYrKDk wIhA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788903608; x=1789508408; h=in-reply-to:autocrypt:from:content-language:references:cc:to :subject:user-agent:mime-version:date:message-id:content-type :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Qinkpq26/1a7aCkcUaJfKcPpf/d/Z5EL4+i49bQOTZU=; b=hUrmPB/y0GEqDn87PhUEBB8z4AhbEBqOk2/QyVFULlv8Klk6aEyjuHpu3D3OYZc3UZ 33YrjN/D0yXrUxPfkQMN/1mEMqyRTAWIpJ8rR3Up6nL0tVB4y1yPOlvtiFSTJJQW6M+V 7wxEkpYTsAIujSfAg76CkCoWyMjcXV6Q6SnD0E+MLyoUAHoWT5tMmWO8Nvy8xNrSQEGD Ncugggf7mPnQczWpZb4YLWLpadFTNYJO1a5WJXveCBt6eQXzdGWL6hyyzXpaE+h5TISQ d+/fq28KlHMRt6QY66fybwWB+foFz6OL7qlmZMtXluY1v/37LrpSI65rv5yQA8aUqX17 h2CA==
X-Gm-Message-State: AFuF++m0uktnYHMd3ei3iVeFgfsamcFOgQ0+FRrjOqBQNtsYb7HSLXtn Guog1vLIiHe1r0qvuwVbhSSOGIZgXdPmVi3nwBH6tMx6T3hC0nmOVHZuWf9/e2zcIdE=
X-Gm-Gg: AYBFou1uISJKkA9j66Ts8T48wdaNkSKtLXG2KBW3VqzBAwxgH2gfahxt+W+li8mYRNO fXRbHnlZKX3W1ni1vT1ww3smFnvjpuZyqRj6nVht9MdyFGz0ILNooqBYbZb86lLnL+RTjlPfJ8p 5i3zhHB5nlAviUreWZHcGRDHFwunWhCbMuCloZi35VXe8oR5wP00LzxZhiwO6RD2XqC0cb2Esyt jGYu849zOzUv9vyhSd/k87Pzbqc/OjBzw6JynVmtXFfiDnMpRPMXEYHB/sbRtN0tZw10xf5yswj 4Hvz1KtfvGrifrKmR3Z8E/a3ACjGk4QPP/ybbM2HX8qIIJWMxWdteasKPwYbC0IG42TsH75xgqx Zb7inrJASFfcrHjdfEfXeJEE8OxcJxoh5jGavQMdaqtBIe9fVq4RUCohdnouM9w3oVWPjT4gzZk Sr4rn6bqoK+ZQ5yWybAbk0YRu7EKAcx/4raEoAtfp74GKrSHLB5MATU7TUXgSJp/w4mj0nXEhmm 10ANWx0krtU6n3U5m6E9cufo2F/F0FGTeCz4II=
X-Received: by 2002:a05:622a:c7:b0:530:4327:6c8c with SMTP id d75a77b69052e-53054a35c32mr358746541cf.49.1788903607538; Tue, 08 Sep 2026 14:40:07 -0700 (PDT)
Received: from [192.168.1.21] (pool-108-31-82-55.washdc.fios.verizon.net. [108.31.82.55]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-5308d8d3eddsm44890621cf.0.2026.09.08.14.40.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 14:40:06 -0700 (PDT)
Content-Type: multipart/alternative; boundary="------------W8wACxTTjcLgvv33H2t8K6DE"
Message-ID: <710a432b-f7c5-45b5-98e4-2c90ea049f50@nthpermutation.com>
Date: Tue, 08 Sep 2026 17:40:04 -0400
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Russ Housley <housley@vigilsec.com>
References: <P11L2Ae--Z-9@cbonnell.com> <D655ACA6-754A-4BEC-9BF5-A962A8878AA3@vigilsec.com> <ba1b2abf-1472-4682-af72-4ff25fd42458@nthpermutation.com> <52A67BFA-CD14-43A8-AC6B-CA2556CD3961@vigilsec.com> <F18B6CFB-1BC5-4AA5-91A7-09CB008564C2@vigilsec.com>
Content-Language: en-US
From: Michael StJohns <msj@nthpermutation.com>
Autocrypt: addr=msj@nthpermutation.com; keydata= xlMEaYFkXhMJKyQDAwIIAQEHAgMEOdOOntc+rmV7lEMu7/N40GZj92v3Adfmv2aM5c+d8E8O JkeckP4/VEuGbS1X9f8eMQXlZ1HP+5wXd0MEXgP9ks03TWljaGFlbCBTdEpvaG5zIChLZXkg Zm9yIHRvZGQpIDxtc2pAbnRocGVybXV0YXRpb24uY29tPsKTBBMTCAA7FiEEZa5rMVt/UsI1 H75faOOlrKh630kFAmmBZF4CGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQaOOl rKh630lP4wEAoV3d9ShCq/OW/uVaVolebc2vzqMyzxYb5cWTq7H0F0wBAJe+PhUWULDMpwIY 8QyRKcUk0M3ESCBrn6YNw1gfhQQtzlcEaYFkXhIJKyQDAwIIAQEHAgMEnFdeZEzyxCp87sqf v8PyE9E2UJpY2spRMmp8YGg2pSwW0ExAJd/ucqn7BVJJuwKI+ZsFnya2yMneNrFC9ZRpJAMB CAfCeAQYEwgAIBYhBGWuazFbf1LCNR++X2jjpayoet9JBQJpgWReAhsMAAoJEGjjpayoet9J ifwBAJOUOlX+49Si1O7xkQpsdWud7YBmWkV7jWBqXQhU1vxlAQCSQCT4g9hwV2bHDrT3UJ2Y k6wVu0KD6I/E/t6hrdcRcg==
In-Reply-To: <F18B6CFB-1BC5-4AA5-91A7-09CB008564C2@vigilsec.com>
X-Antivirus: Norton (VPS 260908-10, 9/8/2026), Outbound message
X-Antivirus-Status: Clean
Message-ID-Hash: CKGHWHRK5R2ZKC7LQDY5WPB4RD3BGOIY
X-Message-ID-Hash: CKGHWHRK5R2ZKC7LQDY5WPB4RD3BGOIY
X-MailFrom: msj@nthpermutation.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF LAMPS <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: WG Last Call: draft-ietf-lamps-rfc6211-update-00 (Ends 2026-09-15)
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/0bVOz4zvJSfPvEYEumAg24QDs2w>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>
Hi Russ -
Not sure why it compiles with the {} - that's read to mean the set
containing the single value id-aa-CMSAlgorithmProtect OID rather than
just the OID.
Let me take a look at the information object syntax and see what's up.
In any event, I don't think we use the {} notation for any other ATTRIBUTE.
What happens if you add the Attribute structure definition to what
you're compiling? I think that the ATTRIBUTE.&id stuff in the attribute
structure will probably blow up if it sees the doubled {{}} that would
result if you did strict substitution.
Mike
On 9/8/2026 16:59, Russ Housley wrote:
> Mike:
>
> Re comment 2: By the way, it compiles without the { } too.
>
> Russ
>
>> On Sep 8, 2026, at 4:50 PM, Russ Housley <housley@vigilsec.com> wrote:
>>
>> Mike:
>>
>>> On Sep 8, 2026, at 4:04 PM, Michael StJohns <msj@nthpermutation.com>
>>> wrote:
>>>
>>> While you're doing this to fix an error, would it make sense to
>>> update the definition of aa-cmsAlgorithmProtection ?:
>>>
>>> aa-cmsAlgorithmProtection ATTRIBUTE ::= {
>>> TYPE CMSAlgorithmProtection
>>> COUNTS MAX 1
>>> IDENTIFIED BY id-aa-CMSAlgorithmProtect
>>> }
>>>
>>> 1) The attribute is a single entry as defined in the text (nit)
>>
>> This could be added, but it does more than address the errata.
>>
>>> 2) I don't think there should be {} around
>>> id-aa-CMSAlgorithmProtection (bug)
>>
>> The module in RFC 6211 compiles without error.
>>
>>> 3) The body text needs to match the ASN.1 module.
>>> id-aa-CMSAlgorithmProtect vs id-aa-CMSAlgorithmProtection (bug)
>>
>> Yes, this was resolved in my last edit based on Corey's comment.
>>
>>> 4) Maybe do the entire document instead as the body text mostly
>>> mis-matches the module and updating the module (except to fix (3)
>>> above) is more painful?
>>
>> Sean needs to review as my co-author. Once he has done so, I'll post
>> the -01 version so that you can see that the changes are straightforward.
>>
>> Russ
>>
>>>
>>>
>>> On 9/8/2026 15:24, Russ Housley wrote:
>>>> Thanks. I've corrected these in my edit buffer. I'll post the -01
>>>> version soon.
>>>>
>>>> Russ
>>>>
>>>>> On Sep 8, 2026, at 2:47 PM, Corey Bonnell
>>>>> <dev=40cbonnell.com@dmarc.ietf.org> wrote:
>>>>>
>>>>> Hello,
>>>>> I reviewed draft-ietf-lamps-rfc6211-update-00. The document is
>>>>> ready to proceed, modulo the following comments:
>>>>>
>>>>> 1. The OID names in the abstract and section 2
>>>>> (id-aa-CMSAlgorithmProtection) are disjoint from Appendix A
>>>>> (id-aa-CMSAlgorithmProtect). This document is a good
>>>>> opportunity to align them all.
>>>>> 2. A few typos:
>>>>> 1. Abstract: "in definition" -> "in the definition"
>>>>> 2. Abstract: "alway" -> "always"
>>>>> 3. Section 4: "registr" -> "registry"
>>>>>
>>>>>
>>>>> Thanks,
>>>>> Corey
>>>>> _______________________________________________
>>>>> Spasm mailing list -- spasm@ietf.org
>>>>> To unsubscribe send an email to spasm-leave@ietf.org
>>>>
>>>>
>>>> _______________________________________________
>>>> Spasm mailing list --spasm@ietf.org
>>>> To unsubscribe send an email tospasm-leave@ietf.org
>>>
>>>
>>> _______________________________________________
>>> Spasm mailing list -- spasm@ietf.org
>>> To unsubscribe send an email to spasm-leave@ietf.org
>>
>
- [lamps] WG Last Call: draft-ietf-lamps-rfc6211-up… Tim Hollebeek via Datatracker
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Daniel Van Geest
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Tim Hollebeek
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Corey Bonnell
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Michael StJohns
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Michael StJohns
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Carl Wallace
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Russ Housley
- [lamps] Re: WG Last Call: draft-ietf-lamps-rfc621… Carl Wallace