Re: [lamps] Opsdir last call review of draft-ietf-lamps-cmp-updates-18

"Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com> Mon, 16 May 2022 08:57 UTC

Return-Path: <hendrik.brockhaus@siemens.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D76FC157B32; Mon, 16 May 2022 01:57:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t-RsAUsmpitC; Mon, 16 May 2022 01:57:14 -0700 (PDT)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04on061e.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0c::61e]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 23446C14F607; Mon, 16 May 2022 01:57:12 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Q44xhAdhbhpwEf40BbeLClAS3LGOgboxwAxZHt3ZKvTRrUpG//DC1eC41KeqKpNv+ns1eI02l9qRD2+knh7/p4rS30w2hTp98cBVYxW/geu/4tjfTxBENh6X4ZveEI/6GaAMrebydxp/WazElTeAyI6CCnFU8v/aFAholthXIxgcpKZaHC8Zf/LaSXV+XsjgoyvdfhXdtHEW9+j4TZjxxcKlP3GqIOaVE+M9WTkhgfvJIX4NP2qjDklNqgWhdUCMxJYGRhyH4+SQp2I+PAzmlyHzVYcq1/Q6iHsp5kxriE+aS6H6FClMCiNoOrIxjnc/KbmPpFsmcH/Z3vhh1/XRGg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=WKvKebAimf10Baku0TScL8Rv1EghmbRQh7jYqkEQqcA=; b=Cb64Ja1c65CNyx3+hfkCZZ3R1WlwnXPyVOaBWb7ixmB2dCJnKP2QPh7ejLeJvVTy/9roDQ252SFNDxUgANygvnKEP07FjzyAP5SUFEu+TYUDzDNnX4VtC32DawCNoQopjOHiC8wgDhLhvNacY1Kk8TpEN3NiUFIsBh7K6tcH2r5pVu8zA56k49Vda4QgL7jGeFZ1kJFCpJZBOCnSpHLxTyE7uDW0rtAR1pjnX209Qe6PHpDISuS5S53PZ/Nlsv625MSFwVwSES4QR2rfDCIui7UhQK0TEsopO450pIcU/VS8XAB5SN7FCLF/g4eaxJAMVdXiBOtiJG6/XJQyhIWl9A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WKvKebAimf10Baku0TScL8Rv1EghmbRQh7jYqkEQqcA=; b=tTDnffXGCOyLzeMpEMwoMz+Taz5OR12v53ah9G4NCSep3GvjIS0cm7Y74WXdBdzKnFek4ShaAfccmxDd1Xxj8MKxugZU5auLzuzx4DYy6k44J5aSpDbvVhDpY9OteKnTIOfPKKmNOtLK+Y0otJEO2gjQYaFunNTMKoclhCmtTLXUXtLCPsjxxdi95/mThhrG+TkNgT9f1r0WfXhNY0gJNTQ9YN+h8MqDHSrIAxJ6TIbpweUq9llKllHFPIdUo8TrPsXumFY37wjDgItcCC0BMESZ0/iq6Y76akGTQryy/lhrI8PnwMmIHQNMguXqde9fnXajVQ58WdiuIaJSx7Ekxg==
Received: from DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:4:b1::18) by AM0PR10MB2641.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:208:125::26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5250.14; Mon, 16 May 2022 08:57:09 +0000
Received: from DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM ([fe80::ed10:9fc:bb3f:bbb1]) by DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM ([fe80::ed10:9fc:bb3f:bbb1%12]) with mapi id 15.20.5250.018; Mon, 16 May 2022 08:57:09 +0000
From: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
To: Shwetha Bhandari <shwetha.bhandari@gmail.com>, "ops-dir@ietf.org" <ops-dir@ietf.org>
CC: "draft-ietf-lamps-cmp-updates.all@ietf.org" <draft-ietf-lamps-cmp-updates.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: Opsdir last call review of draft-ietf-lamps-cmp-updates-18
Thread-Index: AQHYZzalYhK98ttiAk6284PDh3DLv60hDZbA
Date: Mon, 16 May 2022 08:57:09 +0000
Message-ID: <DB6PR1001MB1269B42461363DA4D61D5959FECF9@DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM>
References: <165249373655.55913.14164055756040318256@ietfa.amsl.com>
In-Reply-To: <165249373655.55913.14164055756040318256@ietfa.amsl.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Enabled=true; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_SetDate=2022-05-16T08:57:07Z; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Method=Standard; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_Name=restricted-default; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_ActionId=f0f5f595-903b-4475-a549-05002ea6660c; MSIP_Label_a59b6cd5-d141-4a33-8bf1-0ca04484304f_ContentBits=0
document_confidentiality: Restricted
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: fc36139c-2d13-4263-4d24-08da371a0f7d
x-ms-traffictypediagnostic: AM0PR10MB2641:EE_
x-microsoft-antispam-prvs: <AM0PR10MB2641A7C43A882A71F511DC43FECF9@AM0PR10MB2641.EURPRD10.PROD.OUTLOOK.COM>
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: u0/avPfejuuNoK4JHYHMp818eqM5c18YGVrUoJZ/mE0B2fhXBUCVOMRj+q/LbAu897NXwUKa3LMPhSUkUozUUWA0v0VNB9DdlP2jQvVWACOAkXPiZ0264zw7QWehxCfDqylqSdKZlTWyHSBJ+Rx8vecpxu17TBQLyAhC0OGA4F6Yop7vtg2kyn+hE20qGfQ+m5w8eDODHdu8VKYpZnMSIBGUWpFV7CWXb1P4vcwGNTy8ooIaYHvhrO0iTMY98QZrhW+Sg0Sc8ULNL6w0+pJdG0eOmKN4m8+pbA2PRSF9wL3sudFOir0Au8scw16yQN+TnSrEMIBOo/6RGT7S3fo3VLP3ytMorgMFF4FyBm8yqVnn6BX8PxqBSvyqgRY6bJ9HEmYjVHr+47OcSXX6E/+lLnPrL/CBygCqqwlYq1Vk0iPMdq/FqJnJt3R4X8fRoEhkDwVpF5yGRCCf+dnzJeQtYkvr8PEWJn+V3mjaI/fZlPEUMOJr1sdcU8SntQlNi1SOGeZGZVi1sGxPh/sIRI9Z/C3eP7un41BT7zVPxFHCEBm4VOClA4FJWlgHDmIaND53dww880yl8mdN5qtoh4urnXgkNkVS7vTfj1cnhF19ticwCdrPTKhTjsd4aXEGGvbWcCVmRtr8mVFp0DIHT+Bu8G0EFPqnqypYcW2vbSiMV7jv23nMwqHUr83cLuAfM0MPP3GO51q/4GxukuUt7Yc9F47MQ2/ZiELGI0ahKCwxSZNL5oOmS6S0/j44I0qRhlM6TFuBLoTdjYqHqKy857We1StEYfkQuoyqPwWUO/ePPe8=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(15650500001)(82960400001)(55016003)(33656002)(6506007)(64756008)(66446008)(66556008)(76116006)(54906003)(66946007)(66476007)(122000001)(83380400001)(9686003)(8676002)(71200400001)(4326008)(110136005)(2906002)(7696005)(508600001)(52536014)(66574015)(186003)(86362001)(316002)(966005)(26005)(8936002)(38070700005)(5660300002)(38100700002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: qd/GBpI8dar9s6zoHrNffgSnIsGss1BbQUmE6jYL4YIjIL1nVZSzHq3hGhJBFeuTm2gdvVJstiebBm6T/a5INTKrGVs++5JSQZeXfip8JocrtZrb6/vh57OMeBBv7TZSDLWRfbiOFSBkg/qFUh/0XMsR/OHtlegdJ1gU2DkFP0BvBj93W4KDspTf8aR4WejUOTZUJhTHWzVKlv00rRQOKpK/Sw/PnxofuRK3v9oOPXfUZnNauNgq9r+VciPbUhQIkavaF1XosXvVY/C42fBnW+EMSKcNTX4/6y6vpiAN+pGlkJBbs6nRX/f2fUhklf9TU97e1hmAZ4J/9vtXfGnFyxUIzZ+CSKQArW1JQpxfKNM2CvqCXvPtFykcTuf7Cwq07JwxN/gHvTBv/ixgQaUA0fQgVuQ99QvaBfz5hn8kmdUu1gmKpexno8X9JRo/gMAC2KzEhWQIFhpYHGUm+fuuJddeGEr5WcPpl2nKEEw9j7w+viLYBuqXt8QtPlHYToCRmGytuVLwZdRObjFQLXu10BPbU5V/Yx1tmWQz3sWfStSDppGzURFyNFDBIcRgos9dedWsapA9/DkDMMkPbGNx2mYcsOyNuV/OjittzFyWN++591Lb4eqrtACKxGMlnOjCAP+T/JdyRG07cmlaGWnR9v4tbV7ouZRrlYEOVf+N8lsqyS2Hc5+sgB7gXXsjY3NGbvdXE793DRGUeOllU+396mRvI6U9cSp2GdbLpHkPI4r/a5Mg2PM9c+wMuVSJGFopN2g6yjDfjzMdFJRcnU/vlotOj0gWOxTwuiN+cA2dyI7EHQcy/AEVoo5Y1bDYCrEpb64iJXYGe/u2WlYvuH3D7qaInVaRLTtbgITJ4wdQmxhORu6bkRb+0XJAZkYlhcmUAv+SFnY8jLwdo4XLOYYoWhpBxwexewYTs1qnYalJ10k5lF1tXDJy2zT9+Z9M0S7eMY9KgR4rW6zaplAW4+M89Lo/4Mg2PAtALpsjP2gsvsa4i1pPjAK91UhNB3tdXiy+fzPMMYQIsbSVxhLmMQZQJtFRY9zJFjb495IanW1ivVYiDWtaLKB4jpEBby3LUhNWAQ47BIwxpPi8W0twTowC3PAPN3gOxeJ1K/hFg6c8eDRsWSvK8qLqXcNOwDGUYnYdsw6JzIDfYWqM7iDRXmc5zdR86NUdldqYi582hzG5e62FIepnZyzCIqSm8A7EdO8ptYa/7Te1Du64FWAPVR+eGZKZRW4xIgwxoQrj1+0PdhVLCjEpSrdk2R2R9ExQ+xIStA2wEZmPhMuay9dgW8hmSNHfyZw2Kh3ho9c6gS/gJiAS0WvAcgQjzSoZvSmiHx9CnjtomMh7MtOyoOtFmCdavCEAdBKd6xu9UxC+WlnNZZd1sIpA8JA2TZ028z3iw7Rgg20YzvIjNJ6ZS3ujKiEYhfxTqtslfTDRr7ZJt2LnWNPiN+JDgO1jm6Gak+UQA/0SPkCvKm5uxOlMIe9nd0gPmjz7qtEUB/dd4XA0gbSNw26/Ga6YRV1HvK/HLpYz61PyN5OuVbi2keQqG67usVf6W355MRUcAU+aQHNq2dH/DrfS4vcyG78WGO/bEuH20uAVyNaX+N3oz10dBq11SLqropw+wCUAObAsMQY0jgdKZ3ntDpQUHCgF11QTp8+QeofjTKT6pUzJqIpft5tVvtV3QH+h4uj+VGgNRBLb/Y70Kf001jRen/NHGwv+ZEqTC+obX9liUIZGknUWb0tialfPEm5qHeVC9khZi5clF/gnJ4g=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB6PR1001MB1269.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: fc36139c-2d13-4263-4d24-08da371a0f7d
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 May 2022 08:57:09.4268 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: pJXfLDZKyBa+jXq7jc7xFu3h//gLLbbbTQV9iHvTJB4lQyIic7hsTGH4GJ9dQfjtrPI924BNQic4cRGfOeVTrGB+DsE7Z5tDBd5yMr11XO0=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR10MB2641
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/u8w6g4rcVdeGwQtzeuRyMAEm8-Q>
Subject: Re: [lamps] Opsdir last call review of draft-ietf-lamps-cmp-updates-18
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 May 2022 08:57:17 -0000

Dear Shwetha Bhandari

Thank you for your review and comments.

> Von: Shwetha Bhandari via Datatracker <noreply@ietf.org>
> 
> 
> 1) Overall it is quite confusing on how these updates will be published - will there
> be bis for each RFC4210, RFC5912 and RFC6712?

There was a discussion at IETF 113 LAMPS meeting on CMP Updates style vs. RFC4210bis.
Please see the meeting minutes: https://datatracker.ietf.org/meeting/113/materials/minutes-113-lamps-01.pdf
As Russ points out in the shepherd writeup, the WG decided to go ahead with the CMP Updates document and provide a consolidated bis document in a later step.
Regarding RFC5912, CMP Updates only updates the ASN.1 module for CMP.
In detail it is like this, 
  - Section 2 and Appendix A.1 update RFC4210, 
  - Appendix A.2 updates RFC5912 Section 9, and 
  - Section 3 updates RFC6712.

Russ added this strategy also to the shepherd writeup:
   When this update was started, the number of updates was expected to
   be smaller.  It is recognized that complex update documents place a
   burden on implementers.  So, when LAMPS WG tries to progress CMP to
   Internet Standard, a bis document will be produced to combine the
   base specification and the updates.

> 
> 2) The sections that update RFC6712 - There seems to be circular dependency
> between this draft and draft-ietf-lamps-lightweight-cmp-profile. Assuming the
> RFC6712 updates will be published as RFC6712 bis, Section 3.6.  HTTP
> Request-URI: "  Further path segments, e.g., as specified in the Lightweight CMP
>    Profile [I-D.ietf-lamps-lightweight-cmp-profile], could indicate PKI
>    management operations using an operationLabel <operation>.  A valid
>    full CMP URI can look like this:..."
> This text is redundant and confusing as the operationLabel <operation> is only
> defined in draft-ietf-lamps-lightweight-cmp-profile. Why should it be referenced
> in 6712 bis? 6712 bis with the text changes proposed in this draft does not
> restrict extension of the URI path.

CMP Updates introduces the general concept on how URI path segments may be used with CMP. As a concrete path segment CMP Updates defines the 'p'. For further path segments CMP Updates refers to Lightweight CMP Profile. It is planned to publish CMP Updates together Lightweight CMP Profile.

Russ stated in the shepherd writeup of Lightweight CMP Profile the following:
  There are four related Internet-Drafts that are coming to the IESG
  at roughly the same time.  Please publish all four at the same
  time with consecutive RFC numbers.  The documents are:
    1.  draft-ietf-lamps-cmp-updates
    2.  draft-ietf-lamps-cmp-algorithms
    3.  draft-ietf-lamps-lightweight-cmp-profile
    4.  draft-ietf-ace-cmpv2-coap-transport

> 
> 3) General question on CMP server operations and management - is there a
> document that covers data model, APIs to configure and collect operational
> statistics of a CMP server? I could not find one. IF there is one, how will these
> updates impact that.

I am not aware of additional documents covering such data models.


I hope, I sufficiently addressed your comments. If not or if you have further questions, please let me know.

Hendrik