Re: [lamps] I-D Action: draft-ietf-lamps-5g-nftypes-08.txt

Russ Housley <housley@vigilsec.com> Tue, 29 November 2022 18:35 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66F2EC14CF06 for <spasm@ietfa.amsl.com>; Tue, 29 Nov 2022 10:35:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 01deH-CEyPM8 for <spasm@ietfa.amsl.com>; Tue, 29 Nov 2022 10:34:59 -0800 (PST)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 771D4C14F730 for <spasm@ietf.org>; Tue, 29 Nov 2022 10:34:59 -0800 (PST)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 216A313DDA5 for <spasm@ietf.org>; Tue, 29 Nov 2022 13:34:58 -0500 (EST)
Received: from [10.0.1.2] (pfs.iad.rg.net [198.180.150.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 139C013DB38 for <spasm@ietf.org>; Tue, 29 Nov 2022 13:34:58 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.21\))
Date: Tue, 29 Nov 2022 13:34:57 -0500
References: <166974649066.15718.9377366891632255700@ietfa.amsl.com>
To: LAMPS <spasm@ietf.org>
In-Reply-To: <166974649066.15718.9377366891632255700@ietfa.amsl.com>
Message-Id: <FFC6C6A9-FB96-4EFD-AD1F-8BE752668B01@vigilsec.com>
X-Mailer: Apple Mail (2.3445.104.21)
X-Scanned-By: mailmunge 3.10 on 66.39.134.11
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/G3G2mZm9K-0WoJWnc03-TlexKh4>
Subject: Re: [lamps] I-D Action: draft-ietf-lamps-5g-nftypes-08.txt
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Nov 2022 18:35:04 -0000

This update is the result of the IESG Evaluation.  The document is on the agenda for Thursday, so hopefully this resolves all of the concerns.

The biggest addition is this requirement:

  If the NFTypes contain more than one NFType, the NFTypes MUST appear
  in ascending sort order.

In addition, there was a minor adjustment to the example certificate.

Russ


> On Nov 29, 2022, at 1:28 PM, internet-drafts@ietf.org wrote:
> 
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Limited Additional Mechanisms for PKIX and SMIME WG of the IETF.
> 
>        Title           : X.509 Certificate Extension for 5G Network Function Types
>        Authors         : Russ Housley
>                          Sean Turner
>                          John Preuß Mattsson
>                          Daniel Migault
>  Filename        : draft-ietf-lamps-5g-nftypes-08.txt
>  Pages           : 12
>  Date            : 2022-11-29
> 
> Abstract:
>   This document specifies the certificate extension for including
>   Network Function Types (NFTypes) for the 5G System in X.509v3 public
>   key certificates as profiled in RFC 5280.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-lamps-5g-nftypes/
> 
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-lamps-5g-nftypes-08.html
> 
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-lamps-5g-nftypes-08