Re: [lamps] AlgorithmIdentifier parameters NULL value - Re: InfoTypeAndValue in CMP headers

"Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com> Mon, 21 September 2020 15:59 UTC

Return-Path: <hendrik.brockhaus@siemens.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 434C13A09A4 for <spasm@ietfa.amsl.com>; Mon, 21 Sep 2020 08:59:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=siemens.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lfGeiFGTGPYy for <spasm@ietfa.amsl.com>; Mon, 21 Sep 2020 08:59:06 -0700 (PDT)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-eopbgr130041.outbound.protection.outlook.com [40.107.13.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF4653A09C1 for <spasm@ietf.org>; Mon, 21 Sep 2020 08:59:05 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lrqoh9Ea2r+6Rxu8XVxgtjgfgS3IPzyc4pE8dSrbqW7d4/Kzi9KCamHbzAb+kqRmIc7tvXJs9U3RcIoCWzz0UMxEfsJG0VOjC4aJZ8c4ZsNmZocE//XFN1RtUX4I6vGbE0XS0DDmKMbkryKqBvt+KZueGfiwyK6yZvEoxIzDIISz58G4wynyDRQ+iKdyKz5gpeP1zkbEsVsrGCKkkKY3hBk4ifizXI30HAeARLD93RtlyiCEmT19y6NGq4wh596XvgKHsc6ZeqWHo2G30wo9BqWF7VweSB8Ujnu+6/HMCo5epQY9KDq+h7gQ2fw06vRuYLteeTUVkhH7QqDrhEj71A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gOk9CEA2B2xC4TQTd+pYe1JN6NQc3JLGTu4900gmA1Y=; b=MadVO6d4+oGTlU2nh0h9e81aQLHNVSSlidbIWe9iRRjSgpLsV0gvPHB11EXk5aRGrhqNyPmj6DpGVXfgb+Eq711m+5mQ9oWC5QhOhxvzW64SGbuqi59okIumlL1X41hVUoTuQec/d+zSW2jk9vNOYEq7nVFW/2494B0yKyqmY7nd029GBHI1orGnDRCXTta10fBRS/ETza880IZStsceBoV4D728oG02iDnVsoayJ91/EltJyi5BVjPqdMCJeKlv7rdF03q9Ya8D7wwGujwbS5szdz1gLnk8+moLh1zrvGkeBqkGWT/KB2O3Yqzb1EqLdgzfgdHwwCBnQihV+2myuw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.onmicrosoft.com; s=selector1-siemens-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gOk9CEA2B2xC4TQTd+pYe1JN6NQc3JLGTu4900gmA1Y=; b=OG2XpElOexzISdxBX5yOfX+520g2ZQDSab6i6XJlrAwOwlwC0o/cRMkc0WzLrsUNhOVzF8mJNsuNnVGK38b8huU2FPSdf+WxQ8HDxqG5jyXLAIRdIAsajA8kNOLo6lXUYnL6dgYC3ufvNVNt2irllPwvfphsWjXbJWAg551eWn4=
Received: from AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:208:dd::17) by AM9PR10MB4037.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:1fe::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3391.23; Mon, 21 Sep 2020 15:59:03 +0000
Received: from AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM ([fe80::815c:e3e3:e2be:5eed]) by AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM ([fe80::815c:e3e3:e2be:5eed%6]) with mapi id 15.20.3391.024; Mon, 21 Sep 2020 15:59:03 +0000
From: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
To: Russ Housley <housley@vigilsec.com>
CC: "Peylo, Martin (Nokia - FI/Espoo)" <martin.peylo@nokia.com>, "david.von.oheimb@siemens.com" <david.von.oheimb@siemens.com>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: AlgorithmIdentifier parameters NULL value - Re: InfoTypeAndValue in CMP headers
Thread-Index: AQHWisO2vajruGgquEqHFV9K9oNE26lpgUsAgAApB4CAABxVgIAABMEAgAABqACACV2kIA==
Content-Class:
Date: Mon, 21 Sep 2020 15:59:03 +0000
Message-ID: <AM0PR10MB2418D165412209BC64A5435AFE3A0@AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM>
References: <e649e4c6-d349-7bfb-15d2-9d7ef5fb4fdd@siemens.com> <D0E22972-42D5-4E64-9497-BB6E69E32443@vigilsec.com> <f10ec248-d06d-079c-2098-81d219733a8e@siemens.com> <HE1PR07MB3100DFE27740CE863AF2EC049B200@HE1PR07MB3100.eurprd07.prod.outlook.com> <3FF3366C-91DC-4B5E-8724-5C2C15AE1372@vigilsec.com> <2140bb28-326e-1d63-3c56-bfc875242432@siemens.com> <A9069D62-687B-4C07-9CCA-CB713F9E9140@vigilsec.com>
In-Reply-To: <A9069D62-687B-4C07-9CCA-CB713F9E9140@vigilsec.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Enabled=true; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_SetDate=2020-09-21T15:59:01Z; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Method=Standard; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Name=restricted-default; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_ActionId=874faf74-0aa5-46cc-bef3-c6d12ec8d076; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_ContentBits=0
document_confidentiality: Restricted
authentication-results: vigilsec.com; dkim=none (message not signed) header.d=none;vigilsec.com; dmarc=none action=none header.from=siemens.com;
x-originating-ip: [165.225.200.169]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 075571d7-b362-49f9-a2cc-08d85e4742f9
x-ms-traffictypediagnostic: AM9PR10MB4037:
x-ld-processed: 38ae3bcd-9579-4fd4-adda-b42e1495d55a,ExtAddr
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <AM9PR10MB4037A241FE700BAA2CE4335EFE3A0@AM9PR10MB4037.EURPRD10.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:1227;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: fWqCSNPTyHNz7hIYmGL0Oys1vWFOvx6XaxDcCaggg9U9nkplQ0sLvbU/i/HzIs8eikQKTFRvRamSPyV6O1kVwV837KlYkXTYXRQEVJfVhhtZzEs0YM7T+i/leyhyRpOOxyXf56UIizYMeidZzmujxL+EtXW3v+h7hlm5vXpAIUsUKtgi9rZvn6f/7vfbCY9k93ri8YFWErp1zT3f+ik0WhBCEVpMmh9Tk0VYFIUKHrtQd0eXFYPtWhla72Ou3a/Ab9iyLfUUsDdXveiDiFB8qDsQ+N2D0aDbzUqH5S4VQTKQs4/yb+aM+I5m3F8rhIaf4Wu6DREeZujr7ys5eAb6rg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(4636009)(396003)(346002)(39860400002)(366004)(376002)(136003)(316002)(2906002)(86362001)(33656002)(8676002)(8936002)(66946007)(76116006)(55236004)(6506007)(7696005)(83380400001)(5660300002)(52536014)(66556008)(9686003)(55016002)(4326008)(66476007)(6916009)(71200400001)(54906003)(26005)(186003)(478600001)(66446008)(64756008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: cqAh1B+tD68XIsscDuZQCWlxpzIcTU0hBn+gGEfvCsWX10FFFPi2ixiYV2/p4BZ7cga1p46HN99q04Lfwn3remeUFCiMCWIQkZPKnyrMcEoH9z4nBroqncL5w8nvkk9X3BRDMbPZ/zg5ZBxG4MlV+vmlmAXJAqpPoo+zll0GQUBkRR1sHnHpkMp7zLWznNjgWpvh577PW2h/b/AQHw2HIwp5l+B85F6ibMGYqRbyfGH6rHIJDr+wEn68F7pGx62XJhm90RxL6n+ztLmG/CT/cVAyooMuN6/geXMk+YQ1SibCCZEQo6XA8SJYeOxuKkyD0yBcwDCB7t4cL2FpeakfGGc2nF1mKtXIbVZacbMORlmXs+KY6LmzJJ96rSGrqtd1RrlpRbIJw4K6wHGFrHhKpVmYG0ZGjx/GaE9t6u69h6D1eDokb3YPHbGiVbb0tCAwv7B8Qa4ctpopVDA2LueXd9y1QFn2UUoDzc+xnABYTIOVVasQ6IPA2VjE+zyTHnvWEheeGO0fcEQrnceQW8HuEvp6eMTZvCgAwVlguWhxAuryONDJvnDljDxEWtdOlLzlK/GvwSdQx+NUNJGRZ7OMl/oB5zIwAEwxa05Qx98SUAqRlRlqfsWWbWG+iVNVgmlNgVaaZx9F+g0R0c+4zZ+PvQ==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AM0PR10MB2418.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 075571d7-b362-49f9-a2cc-08d85e4742f9
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Sep 2020 15:59:03.1530 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ANql8YHrYfzQAllNdULDsTkcS4M+AajpRlsdHNrV0Z/TXNqSassxSEC8xm8TkkJN6+DgiJClHtkGr9Qu8/CsyZR2QaI7yK3plhfa/KR8pjM=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9PR10MB4037
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/5wnHxbRsms9NPYIyDW2dVZsUGDI>
Subject: Re: [lamps] AlgorithmIdentifier parameters NULL value - Re: InfoTypeAndValue in CMP headers
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Sep 2020 15:59:07 -0000

Russ

> Von: Russ Housley <housley@vigilsec.com> 
> 
>> David:
>>
>>> Hendrik:
>>>
>>> I think that draft-ietf-lamps-cmp-updates should be revised to say that the parameters field MUST NOT be present in the description of the Signing Key Pair Types (s 5.3.19.2), Encryption/Key Agreement Key Pair Types (s 5.3.19.3), and Preferred Symmetric Algorithm (s 5.3.19.4).
>> Here I disagree - why not allow CMP servers to specify specific key parameters, e.g., to accept only certain elliptic curve(s).
>>
> The parameter only allows one, so to do that, ECC would have to appear over and over.  If that is the right answer, much text needs to be added.
>

Sorry, I missed the continuation of this thread. 
I would add the following note to 5.3.19.2 and 5.3.19.3:
-------snip-------
Note: In case you whish to offer several EC curves, you need to put several id-ecPublicKey elements, one each per named curve.
-------snip-------
In Section 5.3.19.4 only one specific symmetric algorithm with specific parameters can be specified. I think the note above is not required there.
Does this solve your issue?

- Hendrik