Re: [lamps] [EXTERNAL] Call for adoption for draft-ito-documentsigning-eku

Mike Ounsworth <Mike.Ounsworth@entrust.com> Wed, 11 August 2021 18:38 UTC

Return-Path: <Mike.Ounsworth@entrust.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7D933A1FF4 for <spasm@ietfa.amsl.com>; Wed, 11 Aug 2021 11:38:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZWcG1U29ji5o for <spasm@ietfa.amsl.com>; Wed, 11 Aug 2021 11:38:04 -0700 (PDT)
Received: from mx07-0015a003.pphosted.com (mx07-0015a003.pphosted.com [185.132.183.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC1B13A1FF2 for <spasm@ietf.org>; Wed, 11 Aug 2021 11:38:03 -0700 (PDT)
Received: from pps.filterd (m0242864.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 17BIU4Th019118; Wed, 11 Aug 2021 13:38:00 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=mail1; bh=5Fxvy+f59wrxnoF0kJs7hfnOGBVHiO7YgTjQFySBXM0=; b=T6KbnfhKAHmoz7e4nux+LqWzEoFUISFit7uGcr+kRdHKhzt3DkwAgLQjzSP+IQJnyKBW mMCbh9/BbJ3hz4wpfkuwfeajsVu2e2kgpsIiFI+K2XiM7WKKOKwf8FqRporrCi66Wxqc CEXn35HLE2on30HWZgffKYGRSYQeV8etukm2J9bDyarcPS98aElgXx85UI8dlN59q8Ra x2IDjEIaYpit9KcFBGZ28d+fEuVY+T0jWCS2Le8DjooMvyIpAPrNlmeoQnz1t59I6rEs h/kAMZ3HM/Isx7BDnojJvsJE5JtfrnXtGrcmuiTEhPbMbYsRGlxQsl8DQRsoKmZU/jie 7g==
Received: from nam02-dm3-obe.outbound.protection.outlook.com (mail-dm3nam07lp2042.outbound.protection.outlook.com [104.47.56.42]) by mx08-0015a003.pphosted.com with ESMTP id 3aby8aaj4e-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 11 Aug 2021 13:38:00 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=KgJXtQRd/IYyC4ad93gSdCYIZmbayFueafCjyJ8eXdd7+MAHetymwGKh7G2a4CIp17Z83zlJM95v6zgDoOHwipmHz2b8zbF1ggT07ge+4fzpWxFG20/+JD8Z0RGlQ0dk0UmOg/Y8B5QrBZAGT54PHNkKgGbGkh/dklvazn/9sz1cFCkts9JwgvhUabVfFnKfiAi5JiKypYl+uJTIfrur2QwKgc61x3a6ae8OeJnaMYF5kEsT6+P4QROgGlZMXVcayQ73gUotQqCfTn0yphjfThRAocGneLbFBi0baamObg7vchkGCEgP5z+W2CvfWrTPaIhjfyRcKvPcht2ahulFjw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=5Fxvy+f59wrxnoF0kJs7hfnOGBVHiO7YgTjQFySBXM0=; b=btlSGzNRZjsymr12RIymV1+O7qBe74CPokYGP1ott12JCn3jLcqgsec8I7jVkua7n1+55acUAFUyriqOMZRQ72Nc2zTBjl9BnEmfado+49kGkYrR1czEHBlFIzg1pWyziRFuXOWgDKb1A+JNlOH4QlrD79NVwDXtaLTNdAlq78Xo8g8odYH6MkFMEt8npNGkPziiMwA5zZNA9eIyotNvBBvg4DzKdR9B1oJVl3m61KsZnpEdzEdnmvsbP+Hqfp7AmTGxO2suVQgRfTLtWLGP+c8vn0lyoEG+QiEIKFmDRJZY7Iq4e6CRgoFcoe56mV/0yAsOx0awTus97Iu3ZMiZUg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from DM8PR11MB5736.namprd11.prod.outlook.com (2603:10b6:8:11::11) by DM5PR11MB1578.namprd11.prod.outlook.com (2603:10b6:4:e::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4415.13; Wed, 11 Aug 2021 18:37:58 +0000
Received: from DM8PR11MB5736.namprd11.prod.outlook.com ([fe80::2920:8181:ca3f:8666]) by DM8PR11MB5736.namprd11.prod.outlook.com ([fe80::2920:8181:ca3f:8666%3]) with mapi id 15.20.4394.023; Wed, 11 Aug 2021 18:37:58 +0000
From: Mike Ounsworth <Mike.Ounsworth@entrust.com>
To: Russ Housley <housley@vigilsec.com>, LAMPS WG <spasm@ietf.org>
Thread-Topic: [EXTERNAL] [lamps] Call for adoption for draft-ito-documentsigning-eku
Thread-Index: AQHXgmt1z55XWRgbdUqoUsbqUdCKAKtuuMhw
Date: Wed, 11 Aug 2021 18:37:58 +0000
Message-ID: <DM8PR11MB57365BBAB5E6B457144303EF9FF89@DM8PR11MB5736.namprd11.prod.outlook.com>
References: <CD589623-52EE-4958-80AB-73F0CFB3A36E@vigilsec.com>
In-Reply-To: <CD589623-52EE-4958-80AB-73F0CFB3A36E@vigilsec.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: vigilsec.com; dkim=none (message not signed) header.d=none;vigilsec.com; dmarc=none action=none header.from=entrust.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 123b896e-1c64-4d18-0682-08d95cf72427
x-ms-traffictypediagnostic: DM5PR11MB1578:
x-microsoft-antispam-prvs: <DM5PR11MB157839AC1D427D0D3DAD0DBD9FF89@DM5PR11MB1578.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: LAbLnG++pjgTMmWloI2IW8PZvFRM5MGuaM0zBphfWFZA3/Xslp6R46kEg3gQQK6yobi3AKB36zu9eRb94SutmRmT737mxMUntNgsBUMmIYmrzsQLaSj3nJbXv26Rlu3wci4cvwnJvg33qp1ydqElqfsVMZDggnkYQHg+alkHnptGX6U7fzWW9mX6pCsi1KuanJY+3WFM9rg4J5sImDF8KK78mHrxqLjqktWec3hQzQr7KJj3XsGXhqPgxt3r8jIxP2hKTR7pB9ZGROLmnoLHq7OYh+6peItsPHkWt6BCkPNHTDPnZhE+nE6O4tTwqwNSROapNP/n0nKjnGQelJocspC6elxF+wjl2xCqwsqgl3I4LE70bt4J8ZtTMSyi2YZVhpHuPSemF1m2Jg0Uf1Gw7IchQM9/UUD851f2c1LodDxmXN9DO4WIy/Etlcc+SEVnySoYx6ZtrbXi14AaKzR1dNuRcSIKVyVzwiIWxJEqTMALYsrmk/nVwgtU0QW+/NDGlFheYhFKok+lVAwkBhEmPEkLDiHLKVSPj50FWBtm4vrbdarjVSLxmDXrEfTNEyOIlB5T/9J6K84QXqvAQf8yCKqYqHrldOncOUBmb7xXN+yqTleJTQ+trDvlCCoVbhH5siVZB9DeCH8c8m4XhhCbSGOYoaYcGQ7LMge1UovIvENbwAfLOs+iVzkbhOQugBXJjWQXtXzR7Cz+eqpy0Ua+0ULWmRyxxDglgSdd9fjEpeSO/syoedw4sMZTnx8sCTImZPFC8cUyrceLRjIp1whqxOKFJFE3hDj7joLFsiFQ5WE=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM8PR11MB5736.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(346002)(366004)(376002)(39850400004)(396003)(136003)(66446008)(64756008)(66556008)(66476007)(55016002)(66946007)(38100700002)(8936002)(9686003)(8676002)(26005)(186003)(71200400001)(33656002)(52536014)(7696005)(478600001)(86362001)(83380400001)(53546011)(6506007)(966005)(2906002)(122000001)(316002)(76116006)(110136005)(5660300002)(38070700005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: QvqCapzMFwCSvbgnA4V48TqQs2XiR/xfp0+ThWZw6tu53B+hHGbhvC4MhMTlvUbMGuda9snPmVdS0cra6F70S2QFTtOSmDBWSm39dnjRvGhd7fJFerH+ERGXYQK9Z4BLPDgbRuKf+C2pLCPRNsju3Y/alK3BUz1V6+FDkGAGNGej//7wpaiD/n4kYoLkaZqt44pfGUwhR9nFrnwVV/MlxCx3ShWHY5D6osX4Zvs8rUFgSFrVLbhyJz/yn6clHF5uhdSPgQEmzdhehr8fsZswrZSywyvPrWOpYV0Q7BEXs6279wP9Qp3KY5Z4IM9SBGjt1O/7ys8rCetdXg3znxqzaTH4VMRcn2mTtChdvE3rQwX6F7VS5pDt+i7V3YzL7mJXCFr+OXZQQtdrdCj/pSo3c2Ckdy7LV7JPWQfA+F2JYYkanbEFCFkunCbyvzRmUw3zoXJo/EGhNM5/YDWVjWrXrZBpgWbJWrowjbe15mp4kDYgF4zXTLPWWbLkOXhee7DmKS7pyYZrmaiJWqh0X67AR9nCQAJYhY0uKJzfpdKOpAp/cWSY68xXS42mYPylz4hm7XicRF92V0IYMKiiANC29jg9hQKcMPxRxDco8X0pJRFzOjXg9Cg4Xnm1ldP4XdctWXSZrtkDMC7g2pmKb1d36Bz3iDXDcEYoi7V4fp1UR8RNCANADZwkS3Naaz7Tr7te6iRnTSrMPcWNghM65RdurfIelUqCbY/kFK8/J17TYJ8+BEMBRjDznqWPshAWXTERfT0I4a2I8mbaoz7lodPcuBC6UsPcyPw34a6GJdjV3LRFq9VECqieDi5H3lAyDOrJrXvDFXwVeOpJV5IwAin/wgciQJ5lskc+L10sUuJpX4KbHdpNNNol+ciTsFiiXEXLwk0JpolYlx6S0aP7l9apAm91exKLQZk9pQO5TZzwWBFCYWiY3oKJG0ymofKjeN0mdiD6HcSl4SQR9xIu675/pc+Pyj+XWYIDLbjXiN38CCMF4CP1FWI2vLZSPIaz70DcZ1YtW8uInSp2/TzBoPJz79moelMFe7yrH1wkT9AqsEsLqXY+TOdvElkW6A4/51jvwSBQf0ACj5NTTzg96ix3CSsB7BUjBieeUJwebpIpgbT3AR/VHFPPzi3+OS9bCDnyFl+aAN9PI5ERkSGGzlH6+a5KYGFmQaZISx3ZCSYmDLxAOcHeoXU3vgJmsNI4fAacq3397/T/PX/nQ6ls8Kp5JPOLPe0A6r/XtXrfOHLxOgR2n7/S3N33LwR7zR/yNz/gt2pR7UOxyygofBdf+zrO8QYZHkS4F20xMzvvQ0Ogp1yGYMH7RaIRuen3RGymV8mP
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM8PR11MB5736.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 123b896e-1c64-4d18-0682-08d95cf72427
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Aug 2021 18:37:58.1586 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Z9SPMhH0RLc+Q+ixgjCNEYEbFsA2N/jUhP/lPWKhrpdnBtgA/0gngV6VK35MeUMtzBpQ9XuOOqNzhEJUeihCrQJhW9xS4dDR0y74MpVghzc=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR11MB1578
X-Proofpoint-GUID: yVb_jDPsM3KhIcivwO_OdQegggPeG9Wl
X-Proofpoint-ORIG-GUID: yVb_jDPsM3KhIcivwO_OdQegggPeG9Wl
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.391, 18.0.790 definitions=2021-08-11_06:2021-08-11, 2021-08-11 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 mlxscore=0 phishscore=0 lowpriorityscore=0 mlxlogscore=746 adultscore=0 clxscore=1011 suspectscore=0 spamscore=0 bulkscore=0 priorityscore=1501 malwarescore=0 impostorscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2107140000 definitions=main-2108110126
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/0fI08qGH83cKEscBAd0Zuv8Cd8Q>
Subject: Re: [lamps] [EXTERNAL] Call for adoption for draft-ito-documentsigning-eku
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Aug 2021 18:38:10 -0000

Entrust supports the direction of creating a reserved EKU OID which can be used to indicate that a CA issues document signing certificates or that a subscriber certificate is a document signing certificate. RFC 5280 provides EKU OIDs for the other public trust certificates which we issue. It would make sense to have another OID for document signing.

I have not followed the complete discussion on this draft, but we support the general concept.

---
Mike Ounsworth
Software Security Architect, Entrust

-----Original Message-----
From: Spasm <spasm-bounces@ietf.org> On Behalf Of Russ Housley
Sent: July 26, 2021 5:13 PM
To: LAMPS WG <spasm@ietf.org>
Subject: [EXTERNAL] [lamps] Call for adoption for draft-ito-documentsigning-eku

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.

______________________________________________________________________
We have already discussing the assignment of an object identifier for document signing, and we had a presentation at IETF 111.  Following the IETF 111 presentation, no one spoke against against adoption of this work.  This call is to see if there is rough consensus for the LAMPS WG to proceed with this work.

Please send your reply about whether you support adopting draft-ito-documentsigning-eku as a WG document.  Please voice your support or raise concerns by 14 August 2021.

For the LAMPS WG Chairs,
Russ
_______________________________________________
Spasm mailing list
Spasm@ietf.org
https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/spasm__;!!FJ-Y8qCqXTj2!NfhmBW_ewUS5UbfURRsf2Wx62pnE3Ez00rdlztPQHgBvFHmO24tDxxb-ul-ujJjLWY2pVm4xbA$