Re: [lamps] On the need for standardization of software-based interoperable private keys [was: Re: draft-ietf-lamps-samples: PKCS12 expertise needed (including objects for comparison)]

Stephen Farrell <stephen.farrell@cs.tcd.ie> Thu, 05 August 2021 12:33 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F32AD3A0F46 for <spasm@ietfa.amsl.com>; Thu, 5 Aug 2021 05:33:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tbrj-7pgO7gM for <spasm@ietfa.amsl.com>; Thu, 5 Aug 2021 05:33:31 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-eopbgr60124.outbound.protection.outlook.com [40.107.6.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 926B53A0F41 for <spasm@ietf.org>; Thu, 5 Aug 2021 05:33:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AbUk5pyebSJUfUn45Q9CmcMP0ENfQHgJon7HDgQMydndRGOFvfFgzrYNUIdTPezDBZ01CarMdYSRdUPrLtORvnTFee5Y7BgPdcYLTzeQ/B4Se1RSa9+zZ0NVL/lPvEp8GNTn5rSMN/VGHW2hEXZwA0s4bwWCHVZjwxLprffF+gT6zVtDUnpKSIkWzXbjBw3xpCl0z80yW1mzlubGN1sUQnsqu40rq48M/o7nf8m/Tkt9O8USZzbN+NuW+7ojR9fv0HyEqdvZkOn+te9R+7AW130kDEICvt0gGlOv56ZPiGfZrCPTe7PJfXIzl3L9BpKNJVOrHBz5MmwPjp62Mh0p9A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LUsXZoc+jIUQUaAHpjQwqD0dGmNAOO2i6PyzMxwwa7Y=; b=XfAix5TB7g4Dn27to6EjxLib7kv70RfB78of72EIY4ZHTlFYhU9W826IkCplE3KXm9K4Tcpvotrl0nbQ77kqWAo5puQge4rZWSeGkkGPlAD4U5NJwRw4zE7rRuSIL/2Ovyu9a3v6A+7JE/+PMjKWpQ6BboFG5bxaoQSnc0aA8ksNrLn0lrhILukWUdCSle1oXxZAifcB6yBJYnBRHyZW2a/Rdbz8FdjpTkFsZNl2cn62UNFuBmU998xmlqeeBQmVjpW4G0chZl7qnnkJbW8zw6b/glVve7ZNHfKSdH/ivXlQEKp6b9w1VXWBVCDXtChvN86ayYXYhr50Uw/yX1WHhA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LUsXZoc+jIUQUaAHpjQwqD0dGmNAOO2i6PyzMxwwa7Y=; b=C1RYDG+IYkzPuNWoEPOOK3ipkXLVnH6wUcrBpHGtNhkXPrtFXrIUmlO5rcUXoFz8L7pGxxpQGcRl7gn4Dvy1y7Avnfjf93YDYfSMNDV6d4nRlK3NQwKYZT5K/R5tihdjv47OVmg7alhBibqmbu5RLxGPdmQgTvmxUi0VKI3bde1sbiC8vNXKBBTuOE/tk9R+yBtkbRGG4YZAJS4PYD/KP0j9dbCbeTtcrJ2v5xN0Lr0QTv8JpfxMTUMfqT5n6Z+qosFDs+MnnYLIe6cf7znJFt3AYUTndN1T0nKibNmgDpihiABeVeXlV1AcgbGaqqtvozbjDIbmNDqaYaXepsQDDg==
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by DB7PR02MB4249.eurprd02.prod.outlook.com (2603:10a6:10:47::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4373.25; Thu, 5 Aug 2021 12:33:28 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::4198:a9d1:7246:8272]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::4198:a9d1:7246:8272%3]) with mapi id 15.20.4394.017; Thu, 5 Aug 2021 12:33:28 +0000
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, LAMPS WG <spasm@ietf.org>
References: <87czr0ww0d.fsf@fifthhorseman.net> <FF939B28-528B-47F9-9C0C-6585D1B02FBE@vigilsec.com> <87mtq3ukk0.fsf@fifthhorseman.net> <CAErg=HHQMZ1jk+bVxA=MzVvW+9ucie7bu-N6O8Asnp0V8Rf9Bg@mail.gmail.com> <30546.1627850836@localhost> <CAErg=HHKL-E5yT0UnPKcLfMQU41iDg7GGgjsSXs3eRg8daJRkg@mail.gmail.com> <87wnp347iu.fsf@fifthhorseman.net> <1388.1627996026@localhost> <87pmuu42hf.fsf@fifthhorseman.net> <20862.1628113377@localhost> <656985A5-BED4-4BA8-9233-B3C93966016C@ll.mit.edu> <877dh03x35.fsf@fifthhorseman.net>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Message-ID: <722a1f15-8ac8-54f2-3c7a-14c7ed92c6ef@cs.tcd.ie>
Date: Thu, 05 Aug 2021 13:33:26 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0
In-Reply-To: <877dh03x35.fsf@fifthhorseman.net>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="dKR4XiaGbm8a23Z46LmaCrmefZRozspjg"
X-ClientProxiedBy: DB6PR0301CA0066.eurprd03.prod.outlook.com (2603:10a6:4:54::34) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [10.244.2.124] (95.45.153.252) by DB6PR0301CA0066.eurprd03.prod.outlook.com (2603:10a6:4:54::34) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4394.16 via Frontend Transport; Thu, 5 Aug 2021 12:33:27 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: b6fb756d-b042-4b48-9e6c-08d9580d39ce
X-MS-TrafficTypeDiagnostic: DB7PR02MB4249:
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-Microsoft-Antispam-PRVS: <DB7PR02MB4249E3D38D9BAF0E1FB89320A8F29@DB7PR02MB4249.eurprd02.prod.outlook.com>
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Oob-TLC-OOBClassifiers: OLM:3631;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: ileG+xxoEvvwrpTRvvN0c6jX6xsZSkSyl7Oli/yXnh4Tadh9abNbSfXiIwM5v4W8KcmotrYIgRO7gCr2bW93Yza5xin/aJpq9F7aOV7yNl7POx1sPHQFerzIfq0pyV044fO/mq8HGoe9tkrg0+n0PFJLP8IjtA8WPcPjPmY1ozcNaxhh5db1coqY1dUsOkmGaNRKkl7gopByPoJSKTqcwphdbh93oHay02+Exyg5uPSDSd5oF6Fzz0J6fM//O5StAaxh4jG6iIMNdTm63YL5eZs5MzOOYhDPwwR+O8QB8CZWbmc787B1AniEXZHeS+q+eqZZkWpadQETSDTd6utJf6nrPgU9p4WqCT4hdWCrf/ASn8Tz4VoZQtDyy7z+1HGrUT7CQ/6Rwh5fWOGiSl1jXuw7Cc+JhS+t5ADnj6X3sEAFbvaBicJBcADyrHqOBRQ/DSn1BJtbowBe5+P2DDm8mR6bDJJD139WWHFv7X/jI8GDK10WVZwy7Elpbvz27UOszJFGvl4lxxQDoyRMUnpPha9KVb5WMj2rOK0se6WnUSDb5EQulVBHdpRUGOzXTZpQO5uYwiQ3/aLBN4ZIsPeT6jPnZNfB8IKX1MLlysReR+TRQcQwdcU/h8lHPK3LDdqh/VdMspP07ANQCs1PnxM9l3LOR0ttfggcUAgAqw6BGnB09G3e9tbsH2TW0Lp5TvRKfidJsna9JLfHORPfes/u80rAURzdsjQUcD+Hdcr4ps4aunE1SBMyRcSWzVj5542pdbxvZZhOYQdFXL/t+Z8vcm6p1rMd/lNzfyNFaANuCdT8aqi228jv20/d/gTb1IwtaxqqSWp41EEwZduvBDLBow==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(136003)(346002)(376002)(39850400004)(366004)(8676002)(6486002)(83380400001)(110136005)(186003)(5660300002)(16576012)(316002)(956004)(53546011)(2616005)(31696002)(8936002)(33964004)(786003)(38100700002)(235185007)(21480400003)(66556008)(66946007)(26005)(36756003)(86362001)(44832011)(2906002)(66616009)(31686004)(66476007)(966005)(478600001)(85893002)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 4FfBYYni8W3whedRDA5ar2zi9FOKHt3XRqjoyOUOyFjFojE3tmyXWkbaRJ+6pnzzEbw9JpKFgU1ZjPvW/3W6433AIfVcPTwVljWzsTEOUi5wer7P+E7uYGITRzkCyRa/PO+/gUrAtPcp9zVu+3aBcu4j/TxNpWQ2Lppqr/qB/ST0RquQMn7cyi8IzmW1Bhyxj5PyKYN+RcY1FQQ2fRM58cc5UHs09ibxGz2oTJdV/9P1h9gIBW94iX4kYrkk6MuMDm2saKjsD1hbxy0t2aM9be72U+GTtKDqojej8b+8ZvpDw/QX79ACv4hkF69yq7Iwp6274Jz9mOEcjLfUm2HWfyNnmw/9t8L544PQQ0LtPHemv/Hz14NuCNaGJ+Y3kevw9fcCWOPHItzdQI4KEqBxAj6bcSdYAjKjO0qYTcdUxNkuKXAsmyjWAaaKpGWZcVIrqzYz6SvhKI6KIXntLxIcFCZzhhNhI3ulzhUceYLItz0HWppsFHP07eDEvg9ksrWrq/BUgJFOg2BADHPELwuvLBIclGj76WUM0YKkXUKm+hPjQx/Bo+DLmhdWfzcx5NsSWDroBjhwUmNwv0j7mbxF0cCsmXAiBqRNum95eqi0Y5Z2PWEpceCd8R1kZY8Z7ZObHYlLi1Son+aXdbYOslm/KLo4a4yTOr3J5qOmMj2rh2kUeBWMzsVJnFjF+nq9OECBW4I+9Pj1R3hBh20ZcebQfLBS3VWhSrD/uu7foRWFhactdDADAW1yAII0nzTtPzft5lp+gULf6CwqQUta+yAimncHEUq0YMQ6B6A6/kzsbfsyN6kJj4Gq3qOby5EenGDj7FRgXIBd7m+ZL5y8Btw9LJmBhJEvQ26WnXxtMPXWJheraeVfvMHA/2i3KbgkBj62gruxlT5CYHyKvPEeh3bVw2TzEb1/doNz0jz2wmd7B+wS7PA1kCjG7JPJElaPvK2JhVufxRdRlgrueurNL3nJVtBZJ3Z7Ks7TGedRygsagIMGhth9dSxSV+IvvIRlBz8OKTIOTnNvEun7fBr9kl1+5nhugzuxFYnAjVJzDklcT+Gs5U1i6Eg4gAN2JNuVRnL4bnQcpsxEfMdAo7+tTqp1fMpGbjC+Giemi8nK2WA/KPAFnYrL/pnrBkNhaM5F9+gwX3XBIM4zLLnh5NW4+9En8NPzNrs/FKOUJeX3rMzJRvlSsSw4dI2p8I53vVphTxAHbIe3F53q9VO9ODM7fD0PgNNHHQf30YaP6eNO1W6yq7K8uZU8LmTaB8VMPwFlffsLgUJdlLuW5P5B9E/Fd+NgQcOJ7E2Lv0elnZYw4czCNKyF7zGZbRzEKBgVJ0PX1Z7Q
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: b6fb756d-b042-4b48-9e6c-08d9580d39ce
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Aug 2021 12:33:28.0405 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: G0zA+W1RJY0jI1mJXfnFv+b3ibs6Nvjc1+rcLuSsA2d8eYGiz1f9/NslCk9Zg8j5
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR02MB4249
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/4M0ZOvJDniGjFdIjEVsIRKLEQ4U>
Subject: Re: [lamps] On the need for standardization of software-based interoperable private keys [was: Re: draft-ietf-lamps-samples: PKCS12 expertise needed (including objects for comparison)]
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Aug 2021 12:33:38 -0000

Hiya,

On 05/08/2021 13:17, Daniel Kahn Gillmor wrote:
> I sympathize with the grumbling about it, but I'd hope that the experts
> in the IETF LAMPS WG can at least come to a consensus that there is
> value in standardizing interop for decryption-capable private keys.

We tried that before [1] but it might be worth
another shot. The previous attempt got wrapped
up in a then-fashionable transport that never
really took off and was also affected by now-
expired IPR.

That'd need to be a separate WG though. Not
sure if it'd be better scoped to mail or to be
more broad.

I think the critical question, then as now, is
whether or not applications would adopt.

Cheers,
S.

[1] https://tools.ietf.org/wg/sacred/