[lamps] Re: WG Last Call for draft-ietf-lamps-automation-keyusages-01

"Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com> Tue, 07 January 2025 14:59 UTC

Return-Path: <hendrik.brockhaus@siemens.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 14CFEC1E7256 for <spasm@ietfa.amsl.com>; Tue, 7 Jan 2025 06:59:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xzRQy3WqhMfE for <spasm@ietfa.amsl.com>; Tue, 7 Jan 2025 06:59:35 -0800 (PST)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2075.outbound.protection.outlook.com [40.107.22.75]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 92424C1E7244 for <spasm@ietf.org>; Tue, 7 Jan 2025 06:59:35 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=VODdvwwu5IId8mZ1pGCwAqQUse8QcQ4rcfK6RhnkBGdEnAbLd8PHF1qL83VokfqzoPhEmlQoYi/bQMVV/3l50tN3jyWS1tGdwq+P3RbMKTKEx3w136WlMKm3I1SIuQkR9lwmElPEE8SmzdCjGErNPqV1mnS64WKkOaX3pYoVNyPwUo+rXQ2w7XlPak+AYO1SNR7txxPIorlNkg2lHya9N7GDURfZN6VGV/Hpn1oMZhCSotAFQsnyzMDT/G3/T9yTAQ4uVui61vUMqIIcwGesogALxLiFczw+xn2uKlgghGsnCY4OJ9T1R/plbJaBADtgSys8uTBvieNILenm4foYqA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=cQysA/BqpCpHq17U9dTE15N9XAiljWc7sYN/5JiA96A=; b=ZsiDyJyqv4G5s0kcY1vuYdK+l2bzWoBQH6rs5Kr2AeSMWpwE/zvk/7xgu6JjF9C37l9R7Skly0weZSHAJLoFBb2f3kmiVyKa/SRCnA0rc1z1wU3/VTiGMe0hxEjwaXS6+e0iJz5Wm1f2e+dc553VmE3OYn8OSPae2MRMkIr56hvfKe+mrZNyfaprhoBJNKy+wzHyx6nfWTmDBWaxWffY+QSQLiSNXjVO1UbgxE1DvAbHncVVGrHumVzByoJxg20uH+APTaAmSTbHUN64QR6i+YqF0vJDu/P+2SstT+mPrAP89nexYah916uN32v1j0ScjjNKDuiwzDSx8yB08HrxPA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cQysA/BqpCpHq17U9dTE15N9XAiljWc7sYN/5JiA96A=; b=0IN4e3qwHYF0epGefRaZ0PORyNOSWc9taatIgDsI6T4gx31Thl79rIUd5Ie9XwTuVVPyUI3jHB52eBhHwFCcFWoPeM8GxSyodgJ/6AEbln8rSaDdp9XqvVC7H20h0CzA6Cq8YSE0lGcpIUlmcZYm0onm5B0ic7AfHqOGJWdF7/eCn5ZZPWLj/i0D5qOCq2CvotyJj3PyjIj4qrefXVn5sgDnaMhnQRaFLozxXndLBwA0zVV8oATvfxVIS+PCYX+kZ5encxhwZHr+SBAc9U+11WpDWCNdCk01FGICGyBvmcMtNc8dmMc6ETGSIoOfVgUnBNBzyQpNCI1bbmaZBJTqCQ==
Received: from DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:2ee::5) by VI1PR10MB3181.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:803:13d::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8335.10; Tue, 7 Jan 2025 14:59:33 +0000
Received: from DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM ([fe80::8b02:6852:93f4:50a]) by DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM ([fe80::8b02:6852:93f4:50a%5]) with mapi id 15.20.8335.007; Tue, 7 Jan 2025 14:59:32 +0000
From: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
To: Russ Housley <housley@vigilsec.com>
Thread-Topic: [lamps] WG Last Call for draft-ietf-lamps-automation-keyusages-01
Thread-Index: AQHbWHp0GAHaAL5KkEmbXjBUDv9r4bMLRkSA
Date: Tue, 07 Jan 2025 14:59:32 +0000
Message-ID: <DB9PR10MB57156D51051D923D95488043FE112@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM>
References: <73E989E4-D5A3-4247-B37E-C007A74A270A@redhoundsoftware.com> <AS4PR10MB5720A52390D0A80E6BDB1E26FE052@AS4PR10MB5720.EURPRD10.PROD.OUTLOOK.COM> <SN7PR14MB649223AEDA807101E9A2A90E83052@SN7PR14MB6492.namprd14.prod.outlook.com> <7C9C86F9-69E3-40EC-A94F-8BAB4AB55337@redhoundsoftware.com> <DB9PR10MB5715254195247031C10847C1FE062@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM> <575576cf-00f1-4047-8585-1bf48572aab7@nthpermutation.com> <DB9PR10MB57152014FE1E6A603388286DFE002@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM> <DD1190EF-4BA6-4E74-B94B-D339A2260325@vigilsec.com>
In-Reply-To: <DD1190EF-4BA6-4E74-B94B-D339A2260325@vigilsec.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=da59397d-28c5-4633-81c9-511749164bc8;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2025-01-07T11:59:32Z;MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DB9PR10MB5715:EE_|VI1PR10MB3181:EE_
x-ms-office365-filtering-correlation-id: 1e222710-dbab-4993-3732-08dd2f2be4cb
x-ms-exchange-atpmessageproperties: SA
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|38070700018;
x-microsoft-antispam-message-info: S4l9v3rJEE+gkssujE1UUeEy133/6Xyhznhol5agsBLGhWgRld4qA5+nZQko4EcPelwhBwFoVtSSDa4/lFRdc9JrSfpA7Nxshrtddy0St9ILRKADz1fO+cZqqw9UIi5L8IXtZzhrSCBkN/cAz45Axma4aXj7UtwaC0GEIjtY8M7xMbrkFaDnAHq/XBFr/xmDA4Bh4WG4k49GiOx0784axQnfb0IZ+mun7MONBtNcyxPdJ/q2x3XCE1AE4txZNqL1KOnpaXMv5nMrfvRhlglVVMX5rmA9Y/bkcNMIFqmltYDLzPAcQzS5cgHuPLxkXeGxK6y2b1Jctv9d63KigILUqctmWwg1y7c+fby6dvWr3dmCZpEVAo09GnF5LybMxMM06pOs+TOf7UomFfoDDeo91W/QmFYgaNDTSae3y+S+J0LXtW8kWjiuCJjqO0I6UtDDEX5PsJzxuvdtWyGmFT51vFh2el7HGwscNs31qAldsePWD5AnlgGtOk9uwXDdON4rGA38RQTpAE6/EmdPALFOj1pIi81xG4EDjk9hj9jJ+r2lIEuJEruCnWxk4zecu/VGQXn5TzO56nFtVP3kV0g7shKl0/LZdWUWUfYv5tEong8jEARCiUbzrPUai5TtlSNvzKp4osQFpDOLPhCLf1ZDMNZXGK0MgcdhwfUYG4h/aaVX636ekd6C4FBJlHikv11lBcunpeuPSW4O+0teVC6NB64Wa09hz9K2fxp6hX8/FUd9Q2mOFN+DSmnFgqufIoOh/xQMz5UiRIgq4LwKRQ3j4+P42H85LtOnJDccQJAEeyWznDC6nu5Q6J4Tus+3MsY1YJUY5qdUQokmKlYylpgl7xYEfCnpsxqL/xUWNnvWvDlVsKNVXo7VarCu2iG7DMh6HnDjQwFO+dxm5jQ8ulNKKIA+tx6kdqn0GWu1k3obfArMNCqfxHWkJvXtDnNuvnRvW+rm0KExKLK4UFuL1n6dORlorx7pSDTyO/cMjpaq48VTSeAH6eE2KyYiHAYvRJmm2vGR2BXteWCXM5P2VnsQth5G31Df143/j/oClJmwWKpj8j+t3MccXg+bQxhjqLHBzdxEUfajjI55TVlebk1/1GCTiBHDl0ww6gvBG7N0X/b+DYGP3DhUmOJCu7ZY2NE+x/h/xXLhtjV6u+0xMKil59QTXRByN5vFvs9KI3tAJ2g6HS37sPAoMlKbKAdtpBFxB7zJG0qDXgJSi999auod3DLsLkmWX7rdCV4zs71M0XHRtb96g/0iNfuSnb2HdezrtgUlE+6L2GwBm60rg+InO3gBjx6FOtlu6DNuwI/9ISDZkNQmjwdtz7gkKHNyBBfr2WAZ1sqlGXukpxCCtZkdOVqRZ+plJC5dUX7agdDru0aJLqJxYLs85JjjyEYJwNNvmsVPPhZPCI6hZeC8LSzaHF3xIqzm+3hXUePekC33krlujKKWeOm8xB1DD5JPoyDW
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: OALHHVNmF9H/0L3kq4BRjoV009piM4FCv+XGylhD/vwTp/bj87XxV/C/6iE+Hc66lgTyWWv1Hhn2RUO+yRJ/FJE4AQgbTTCXkJqoDq6B160g5pEV9b05cYP9uPEIsLOXsaiVavuGUnOYv7HcxuwQyaF3CPerTEDJl2kkZsWGk5tHVEYNT58RwWZlW1/hSKgESgSJ3zIl82wHzY++AsMaTvQ8OJSnWdTSgtSQMAvy/7pJu2rWSiDEruArcqibH8lwYSQG+yDvBBL1UVon8eAKeUlhf6MafYOoZ+N+V06M/UsS66PGjNWuf+yGNB3jdKqGugJ3433NwCSLG753o1UysfirYG1KwRUotLoTi4TlXooATig+ZWsdlRDjvn25gzvHTRHD53M6IYYMOzMsnin8TT0f1fsXWWSaCxMWFXLfIxbNkRtaFQIdEPVqGLHA7Upu5Kd0BkrhAJwxV2KH3Jh84prVid2pK7LJyAMJ6W62eKBb6oWJqL0gCILZ10WNOMMrk7JCpJsMZtHTX5xO2Qaeb1hgRFqPVSJ2Sx5DOSYjP9ROchIVG1enElkX9em6/yD6dDXU5HlwmRWUGHvInroevbDPODcz8nnsfScHTTu4KnElKr7NC1w5fLHVR2Txl043fwmyQVGec90e+RuuMJ5HPg22UHs6rxIVgPHlXg1kGXaEPVPW+S7dH8J0BTNfwCRr1dJ5ra1GfWlwiTb+77w6JxTskmPct6JPs+C3o8sFyesr2/MH3Z1fI/mvE99Mj/iNmcpEZn9UG7zRMGcWSAP4LrmFsCvepKFEc3ovMMwvif3cxodeg8iWJa49xDx+HlXV/PA2wRPhQJm4oaX+e6IeeLAvT40E3I9T+Z91E5mCZcT/f0RpJs4TUe4gIZDXYeCT0WGrWoVRQRdTZhu0otC5OUHfXQtLzfrQzsqXO+hF5lwauOYmgJZZcGr+K/q5POUJotapmktkXEnCwE0BQ0T0zQrkIJR6OeRN6Tp+LODv1Be7/03yxu1zrOMjrlCJy5+S+CnheVPgcmdeiaR1JkOHxm+FS4eGTRIiF//RcD8zEqnMvSQ31RkXDm9unoLg+NrmT4Z4nbxPpK363C4qVIx0h2ox9exyoJLclePVdhU0AcV2W4NB7RTxwnPKFOq+QsNwhvH7TQxAqG+R70KURTJa6xQgzP3wsZPdK4NvoTCY8yHRTg5LOIl+c8yjXMoWqMSp2WhiCSjN+fn5EQFuK/FsmIbPin2AgLzUteoMvJtLYUSxS52Fjk5J2dSc2eNDZI0p+j38cj4i9zt+56C9k6p+U0Zf2SARsSFeSPZ1aUDBnMKsJ0LIAsrDhgUbCELPOgrsoHg3hLEIq3LAPz57bFQ5HhIiuCtCyxOT2YEXAcJT5G3cw0JouR+1BhF8EYoxZWbazvQ7vhAk6AHlgtEPqiFmFIaHw4aiI76ONZSnD8eCKTxXNi3to2bRDVhi/Bx+4Gk+vBHMM4UJZX0lEY9AUQKnd3vLJYywwwTxxBXHE+c75NawyI2OQW1csXfpNvi+EELJ8tmjgXccdAa4Pf0xjgon7GVSP2JyuGWDlPeufiZoCtMvwqVWDQw2xi0l1vU6FdruG94B+lmlWUyESwJlakvuqw==
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 1e222710-dbab-4993-3732-08dd2f2be4cb
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jan 2025 14:59:32.4903 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: lkA7dR25fu/8qUcMea+7HOpiGvDiC4CtH8p828uBqXNvQmMXPcP0JeFTcJ0KD3dEULPvkKaP36UrAp4jLJt5ejVJFE0MZ4s/pzQyqtGOHJ4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR10MB3181
Message-ID-Hash: 2RL4MGHNHU6MN3CIOBWUIYHF5YVLONB3
X-Message-ID-Hash: 2RL4MGHNHU6MN3CIOBWUIYHF5YVLONB3
X-MailFrom: hendrik.brockhaus@siemens.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-spasm.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "spasm@ietf.org" <spasm@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [lamps] Re: WG Last Call for draft-ietf-lamps-automation-keyusages-01
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/31eNiIFDT889WwKZBfSXcnWG6gM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Owner: <mailto:spasm-owner@ietf.org>
List-Post: <mailto:spasm@ietf.org>
List-Subscribe: <mailto:spasm-join@ietf.org>
List-Unsubscribe: <mailto:spasm-leave@ietf.org>

Russ

I submitted an updated version of the draft containing the changes described below.

I understand the point about the ambiguity of the term 'domain' here. I tried to address the point with the best of my English :-) However, I had some difficulty finding an alternative wording expressing 'different application domains' more clearly. Maybe that's why my proposal doesn't yet meet expectations. But I am open to concrete suggestions.

>Von: Russ Housley <housley@vigilsec.com>
>Gesendet: Freitag, 27. Dezember 2024 17:15
>
>Hendrik:
>
>>
>> [HB] I think certificates containing id-kp-safetyCommunication may
>> also include EKUs like id-kp-clientAuth/id-kp-serverAuth or other EKUs
>> required by the used security protocol. Therefore, I adapted the text as follows
>and transferred it to the draft:
>> OLD
>>   The id-kp-safetyCommunication KeyPuposeId should not be asserted together
>>   with one of the KeyPurposeIds id-kp-configSigning, id-kp-trustanchorSigning or
>>   id-kp-updateSigning.
>> NEW
>>   None of the keyPurposeId's specified in this document are intrinsically mutually
>>   exclusive.  Instead, the acceptable combinations of those KeyPurposeId's with
>>   others in this document and with other KeyPurposeId's specified elsewhere are
>>   left - properly - to the relying parties in a particular operational use domain.  For
>>   example, an application domain may specify: 'The id-kp-safetyCommunication
>>   KeyPuposeId SHOULD not be included in an issued certificate together with
>>   one of the KeyPurposeId's id-kp-configSigning, id-kp-trustanchorSigning, or
>>   id-kp-updateSigning, and that a relying party in the association MUST ignore
>>   any of these KeyPurposeId's if id-kp-safetyCommunication is one of the
>>   specified key purposes in a certificate.' Other domains may specify other rules.
>
>I think that the meaning of "domain" is very unclear in the proposed text. I continue
>to believe that the place for documenting acceptable combinations is the certificate
>policy.

[HB] I will use "area of application" or "industrial sector" instead of "application domain". 
I also tried to better differentiate 'technical standards' and 'certificate policies'.

NEW
   None of the keyPurposeId's specified in this document are intrinsically mutually
   exclusive.  Instead, the acceptable combinations of those KeyPurposeId's with
   others specified in this document and with other KeyPurposeId's specified
   elsewhere are left to the technical standards of the respective area of application
   and the certificate policy of the respective PKI.  For example, a technical standard
   may specify: 'Different keys and certificate MUST be used for safety
   communication and for trust anchor updates, and a relying party MUST ignore the
   KeyPurposeId id-kp-trustanchorSigning if id-kp-safetyCommunication is one of
   the specified key purposes in a certificate.', and the certificate policy may specify:
   'The id-kp-safetyCommunication KeyPuposeId SHOULD not be included in an
   issued certificate together with the KeyPurposeId id-kp-trustanchorSigning.'
   Technical standards and certificate policies of other area of application may
   specify other rules.  Further consideration on prohibiting combinations of
   KeyPurposeIds is described in the Security Considerations section of this
   document.

Hendrik