Re: [lamps] [EXTERNAL] Re: I-D Action: draft-ietf-lamps-im-keyusage-00.txt

Mike Ounsworth <Mike.Ounsworth@entrust.com> Wed, 17 April 2024 15:42 UTC

Return-Path: <Mike.Ounsworth@entrust.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E09A3C14F680 for <spasm@ietfa.amsl.com>; Wed, 17 Apr 2024 08:42:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.695
X-Spam-Level:
X-Spam-Status: No, score=-2.695 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id odgh0FpJc_pB for <spasm@ietfa.amsl.com>; Wed, 17 Apr 2024 08:42:42 -0700 (PDT)
Received: from mx07-0015a003.pphosted.com (mx07-0015a003.pphosted.com [185.132.183.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D2E2C14F5ED for <spasm@ietf.org>; Wed, 17 Apr 2024 08:42:41 -0700 (PDT)
Received: from pps.filterd (m0242864.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 43HDjrvo014701; Wed, 17 Apr 2024 10:42:39 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h= from:to:cc:subject:date:message-id:references:in-reply-to :content-type:mime-version; s=mail1; bh=1eFg/HHVq3t/WgrJo8/XhARP krInNYQwHOHOjwSkVrs=; b=JDqXeJjvwPIOUrLC5ZwwB0iKqmzs3GANwdU1Wkq0 VPo0wQwpvkI5eiLWmbgc+teyRTFn9bn0pEAAE5vMUBZWb8IE5H5aflRIj/op3ia3 /W73ewBHQ44KtZCuL6AslQoyN9fUCKznDCCe9r+Bi38h0u96coU55WX2HXN5UBz7 7M0AtfS/fCvsUu2JmWCBDVMjsaEPgZZtLD+YGLgPgk09kZrhS6IZh9OaEBQQgJGU Vdqp2Anzbtql5iwtxNZSza0GJ2amsU9YzHVn9KAsbr1HHp54DGnAX0zm6BmkI4Y6 585e8KsFbW+GlutUGP/s6VsC1OJc2Tc3TeKO7hZBY+XK/Q==
Received: from nam02-bn1-obe.outbound.protection.outlook.com (mail-bn1nam02lp2040.outbound.protection.outlook.com [104.47.51.40]) by mx08-0015a003.pphosted.com (PPS) with ESMTPS id 3xfpr0hcax-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 17 Apr 2024 10:42:38 -0500 (CDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NmQpH7NnrLJNpvy8a+2wntFm4msKXz35hxqDJtwt80TPu7txkS+gJwK5b3aoQfPkZxinVz44JG+mVep+zJHxBX7Zq7VlgTV90mKwl23ykxzIAPFBT+tcDQYrS5nb9kjaEBhPKf+Rwp0NptIcVY5EtCVwajGqZ9oyFTJtfeugu//uWJFQRB0/QCkK5st79n/STuxlU6gpTzu1cHv0hE98qi2EkhE2M5qJmCo4wjoJtBjNvTtv42nx01fqgqP8dv5KtQANyFtFBHIPAlEw0izmi4s0plGlEGmzDTrsDRVTjEBcrepJChhQq2Jve2ic/cDmUS1AMT4ygwXUUU3GcCN2vQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=67pA6z4LWntcwkJXNjWrtW5uJ+m+RHWpgalZJ3hNm0w=; b=EkVaw8emNfO9j0PJv9p/mLmChngKJ4fRQLyiry+f0CjBAu8iRKurzFjdRbB/Q6bsJQCJ1TFclKFUk4f/QOW9FTjYgQcPSRiav0b0TxLEQiEklsQGH27VDmtTfzPwFDMaYuqGT1YGVwVthL1tXK+vM6JKgE6AbLqdU9dho9vwlBl4achufEkPoKWWZArruKxLSccClCTnpYyTp8IsbAw7V6KI+N9tKnp0rvbHBTBnD01KunwezWtN6C1toPyJ9loZapBcFTr0RN2/rROe4Hh/Xe9Un1Ki9eeHtu02cBzTEQzbTyp2Yd5aEXlLZGnNYGk1zqA2qvxNF/kt/+Sq15/OpQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from CH0PR11MB5739.namprd11.prod.outlook.com (2603:10b6:610:100::20) by DS7PR11MB7860.namprd11.prod.outlook.com (2603:10b6:8:e9::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7472.37; Wed, 17 Apr 2024 15:42:35 +0000
Received: from CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::11f2:792f:10c4:f173]) by CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::11f2:792f:10c4:f173%5]) with mapi id 15.20.7472.027; Wed, 17 Apr 2024 15:42:35 +0000
From: Mike Ounsworth <Mike.Ounsworth@entrust.com>
To: Rohan Mahy <rohan.mahy@gmail.com>
CC: Russ Housley <housley@vigilsec.com>, Rohan Mahy <rohan.ietf@gmail.com>, LAMPS <spasm@ietf.org>
Thread-Topic: [EXTERNAL] Re: [lamps] I-D Action: draft-ietf-lamps-im-keyusage-00.txt
Thread-Index: AQHaj2K/Z6MrXXukZkyhEzxBIY0fbrFpze+AgAAJFYCAAWpP0IABQbaAgAAY32A=
Date: Wed, 17 Apr 2024 15:42:35 +0000
Message-ID: <CH0PR11MB5739A5999D59A046D056812C9F0F2@CH0PR11MB5739.namprd11.prod.outlook.com>
References: <171320513468.22285.6899802433610546466@ietfa.amsl.com> <B508131E-0554-471F-94FD-4AA2A0A95346@vigilsec.com> <CAKoiRuYCSwdzwKwSXdyLCNm5Z3DzzzLZzSyDO7DGWHTSeUj-fA@mail.gmail.com> <2E8965D1-F0D8-4947-8A6B-19B822EEFA4C@vigilsec.com> <CH0PR11MB5739FF2B9A378DF7ADFF24E69F082@CH0PR11MB5739.namprd11.prod.outlook.com> <CAKoiRuY5Caq_61+99RQiaRkeKUAou=fiLj+HadajzhwhLKOdAA@mail.gmail.com>
In-Reply-To: <CAKoiRuY5Caq_61+99RQiaRkeKUAou=fiLj+HadajzhwhLKOdAA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH0PR11MB5739:EE_|DS7PR11MB7860:EE_
x-ms-office365-filtering-correlation-id: 8932953c-0472-4a9e-c7db-08dc5ef500dd
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: gznUX4OyxLs186Mf5B5fqjZ3eSSQU9D9Wdg98vaU8OpB/ZHLvAsremAYLqIS/IpJb8O/NXYYt6SRC0jWMtBiVMCv3btnXcRhg2mRl0AbedZw7akj4yRkp153J/hMpiI8z0DblJuY8lXw3qd/ynvKPYhIfSHRKof5rG6sMDRsN0DEEq062Qq/xYeKNRVLZWzL0aP05r+bQVOhZPCKoHpEGg3TP4biigj9xFrwlYqqXKmLpxyo6UyLjNkvNIxEyHTMtJAssGm4TSnvPZRZHoe/gofGBuX3CTYATW6Bjj+hjAM6NpgejWYq0DZLBeZmQwSpG79gl7fLCEfRVs1jktKBLdLZwF2E4KWDIYKchgsZIN5pSM6/7aqiIXz9/GfRcxvu38If62CvbO/2oI3dkG720BZvTVcNWXrFgRk1uaE1zop4zdCUnNCZy2p2Y/qVnsG4w/U8wCUjhAXL5SRbYZotQmce66T6hnE2YLgRspKM+jkyJqnDQtOJPxvv870Ko0SRnY19tZUZP/B/zvOUe65hRbz7TwAc9SBuyDxwGnNMGZ4BHq2jybcukuVo+CRCpvtaQoGVg7rqxIQ8S1Zjkoe25J4GtiUjgXAu0GrxesWZNEmRjYgEXZRzqDTNyfTG86hlQgcMS/IOlFF72pAswN7Igv9/OtoLCZTZymZciRteKCYhkYRwtugdlgx3i7RyNBr3fXdkFuawk1bPSI28qYikCGh0IpkBjB/A++3byugadPY=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5739.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(366007)(376005)(1800799015)(38070700009); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: skNFJypnwbbSURaQRsjxmTCbCTuJ9IZw/jePMxZmjqZhNvlfYxk5b83ajH4hL0u4eakm23ZTRR/YRXKv+038wdj22tgxlJ3rIwhQPUe0fcHpr8fW4clowmAqhh45j5dk2mkO5whgaBHfHA2QnDY0XKxTzcmZSjnY/kbLnkr6XvMGu2XTF2M0gUZ/x4KCyxs1Nl4HOcPFcAOl+ELOr3DmHJdJC1xpYZiGNP5XkuTcI2knR7BM5SUOLoBPIARA5lLho0PhSazDFoN3Bn1dMYLYRuz/RATEB5esbIkv3a3wCHOgnTFqFa8XV0hlO3gFI25/Btpe6pIAOWDkVzvJW7X+sFK+h1tapsfShtU87UZtc08sK4Z6GPwp4MjWHcZOf8RdDxzgR2GKmedtIURloUJklVb8Cb6ceElmWhLPDDFKFyFtTu99gsWlOyj6D8VFbccHmz3KpSNfeBXcFY41jGe/vOj1iu0Km0CILHKQIwEAVp+ou9XLNEroMReoApC2Aob3KJ9yX2SYlRKCHI22+AS/utpS7+0lH3dK+1fs/DsyAOBMAWXbaP8c144gvPjxv48XvCtrVBqUpNBFdYKZsT2+OHdQ7a+4gcz9MAaRKQmdzOqygyC618LGYbugJVOlFoxxU71smTQ02G5GGBr7JB9e9XuuaV+Sx/qcuSA9SOopIQU9pST7Y3zhPCxXQiE8BIpcOfmtx6KlRWK5PPCQam/A4I2Wa+GhMwNg2qQ5DclZ3ehc9nLXTdQPbx2RQ5G0Du2XCzKSN2IdjGTgPgI7JFp+MhCUfAdNbUEMpJ3VN0w5hX4iv42x55Rtf5JVVyQ+GoqivbtkGrwNK5OUFlM8PHH8Ys94cLJeesT/KRTXbyVzAor6PwOkCWJZBlnl3aVTMFDXOEPM+E745E2q9lbo/dF8HLkwrwM38HhPr5ZdXoioYq80c3GkLGU3Yoi0m3jETrGLZ4ILzx45y72cuMRZh+qLM8zVPnr9rz1Y8XZPcOwxEaG8cRUre5UDL8hWOlx4UwJjpZNVWdS3BLUo8FmmF7QeZNNOP3KwlE2tkRhL7hiHm5VyNVLkHZ4JwkB7fwhlKvTk9EB5mfWQfOUQphwxV3/9MR4Zp+PlDMvl598eHyC2+7qNrfoY8TLZCZ5ZGT9qAIvfNl+hYkiovF2kEgsuweESoxRItE7jx4QfDimIBnTFsT2uN15+WyCWB0MhhuqF4xO5NBS5eFhQ4+uYDD/Z4BYtXY83VJ54JNhczrs+XBotD+HPC3yKEWzeodfPPThrXVjM9pG9UO1KKJT58GTrvFOSAV5TEjgjbKdoSca4uK7bSuxdZH90FCoC+xlToSFnDkk56FKi5bomuH8gvZnTKLNBzi5YXVZU5y3CZx6TKVF+LfyvPtujdR829ronbvIN/NYC8oNxpV2UjqjrwuEu44h/OvLJpAYaKgcJH+8ocj4L80tyf7KRoExiXzIKHRb+pTjJDsDILO2YXHqnlRABiYmsqoOkcpzPkZn13TxU/AVURbTHF5vtHtud/NNjHyF7EDdMVexdOewfAbDhPKdci+9dd6+CindcX2krJDREztF0ecP3vtR3jtQUse6UrH2wB26VlOvpSX+6hzswHXtfsDGQoA==
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="2.16.840.1.101.3.4.2.1"; boundary="----=_NextPart_000_0078_01DA90B3.F4AB8C80"
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5739.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8932953c-0472-4a9e-c7db-08dc5ef500dd
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Apr 2024 15:42:35.3901 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 0C6hDglrppUT1SvbfvPAZLycrr4kznOHjvAdrQsDb+jOJGJOEUQf0Fh2rrlbBEXj3kWzv2/K++SXRC5eAdcGBE7TgVecV9XRbHbEE0RnND0=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS7PR11MB7860
X-Proofpoint-GUID: Ha5x1a3z_WodLm218nnaxDESlWP80zDb
X-Proofpoint-ORIG-GUID: Ha5x1a3z_WodLm218nnaxDESlWP80zDb
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-04-17_13,2024-04-16_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1011 impostorscore=0 phishscore=0 bulkscore=0 mlxscore=0 suspectscore=0 adultscore=0 spamscore=0 mlxlogscore=999 malwarescore=0 lowpriorityscore=0 priorityscore=1501 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2404010003 definitions=main-2404170109
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/KNtAaIUho_1A9rldG4p-qXdDwb0>
Subject: Re: [lamps] [EXTERNAL] Re: I-D Action: draft-ietf-lamps-im-keyusage-00.txt
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Apr 2024 15:42:47 -0000

Hey Rohan,

 

> “It should be perfectly fine to use this with XMPP, MIMI, or a proprietary messaging system.”

 

I don’t know the IM space very well, but we hear a lot about cross-protocol attacks if you, for example, use the same key with S/MIME and PGP. Probably that applies to encryption keys more than signature keys, but regardless, I think it’s gonna need more than the words “it should be fine” to make a convincing argument that it’s ok to use a single certificate across multiple IM protocols :P

 

---

Mike Ounsworth

 

From: Rohan Mahy <rohan.mahy@gmail.com> 
Sent: Wednesday, April 17, 2024 9:10 AM
To: Mike Ounsworth <Mike.Ounsworth@entrust.com>
Cc: Russ Housley <housley@vigilsec.com>; Rohan Mahy <rohan.ietf@gmail.com>; LAMPS <spasm@ietf.org>
Subject: Re: [EXTERNAL] Re: [lamps] I-D Action: draft-ietf-lamps-im-keyusage-00.txt

 

Thanks Mike, The semantics of the EKU is an Instant Messaging identity. It should be perfectly fine to use this with XMPP, MIMI, or a proprietary messaging system. Unless you have some reason to do otherwise, a very natural way to express this 



Thanks Mike,

The semantics of the EKU is an Instant Messaging identity. It should be perfectly fine to use this with XMPP, MIMI, or a proprietary messaging system. 

 

Unless you have some reason to do otherwise, a very natural way to express this identity would be to use a URI identifier of any relevant scheme in the subjectAltName. (XMPP already has a custom SAN identifier type but that was not strictly necessary.)

 

I'll take a stab at some more generic text for the Intro and Security Considerations.

 

Thanks again for the review. I will fix the other small errors as well.

-rohan 

 

On Tue, Apr 16, 2024, 12:14 Mike Ounsworth <Mike.Ounsworth@entrust.com <mailto:Mike.Ounsworth@entrust.com> > wrote:

Hey Rohan,

 

I’m a novice on the IM topic, but I’ll provide a review of your document anyway (feel free to ignore).

 

The introduction mentions that the driving motivation is IM apps built on top of MLS, and then says “or others see: MIMI”. Are all IMs considered equal, or is it important to be able to say “This cert is for MikeGram, and that cert is for RohanChat?”. IE would it be better if this draft created the specific EKUs that MIMI needs for the specific IM protocols that you’re designing now?

 

It would be good to expand the Security Considerations section to be clear about what security is gained by using the mechanism, including what the expectation is of verifiers who are looking for this EKU. Again, I think some discussion of using the same cert across different IM protocols would be good.

 

 

Why is it called id-kp-imUri? Why “Uri”? Perhaps this is clear in the mimi arch docs, but could use repeating here.

 

 

Typo? The IANA Considerations section asks for “id-kp-im-eku”, but the ASN.1 Module defines “id-mod-im-eku”. I think the latter is the better name, to indicate that this is the identifier of an ASN.1 module.

 

 

To Russ’ question about whether this draft should also cover SANs: the intro already says

“The subjectAltName of these certificates can be an IM URI, for example.”

Out of curiosity, which SAN type would be used for that?

 

---

Mike Ounsworth

 

From: Spasm <spasm-bounces@ietf.org <mailto:spasm-bounces@ietf.org> > On Behalf Of Russ Housley
Sent: Monday, April 15, 2024 4:22 PM
To: Rohan Mahy <rohan.ietf@gmail.com <mailto:rohan.ietf@gmail.com> >
Cc: LAMPS <spasm@ietf.org <mailto:spasm@ietf.org> >
Subject: [EXTERNAL] Re: [lamps] I-D Action: draft-ietf-lamps-im-keyusage-00.txt

 

I thought it was worth asking. I think the xmpp: URI in the SAN would be a very reasonable solution. Russ On Apr 15, 2024, at 4: 49 PM, Rohan Mahy <rohan. mahy@ gmail. com> wrote: Hi Russ, I don't understand why an XmppAddr identifier type 

I thought it was worth asking.  I think the xmpp: URI in the SAN would be a very reasonable solution.

 

Russ

 

 

On Apr 15, 2024, at 4:49 PM, Rohan Mahy <rohan.mahy@gmail.com <mailto:rohan.mahy@gmail.com> > wrote:

 

Hi Russ,

I don't understand why an XmppAddr identifier type would have been strictly needed, since anyone could have put either an xmpp: URI or an im: URI into a SAN without any extensions (as a URI type).

 

I'm happy to go look at some old discussions, but I don't know the history.

Thanks,

-rohan

 

 

 

On Mon, Apr 15, 2024 at 11:28 AM Russ Housley <housley@vigilsec.com <mailto:housley@vigilsec.com> > wrote:

Rohan:

RFC 6120 defines the way to carry a client name (Jabber ID) in the subjectAltName extension.  Should this document be expanded to address subjectAltName as well as extended key usage?

Russ


> On Apr 15, 2024, at 2:18 PM, internet-drafts@ietf.org <mailto:internet-drafts@ietf.org>  wrote:
> 
> Internet-Draft draft-ietf-lamps-im-keyusage-00.txt is now available. It is a
> work item of the Limited Additional Mechanisms for PKIX and SMIME (LAMPS) WG
> of the IETF.
> 
>   Title:   X.509 Certificate Extended Key Usage (EKU) for Instant Messaging URIs
>   Author:  Rohan Mahy
>   Name:    draft-ietf-lamps-im-keyusage-00.txt
>   Pages:   5
>   Dates:   2024-04-15
> 
> Abstract:
> 
>   RFC 5280 specifies several extended key purpose identifiers
>   (KeyPurposeIds) for X.509 certificates.  This document defines
>   Instant Messaging (IM) identity KeyPurposeId for inclusion in the
>   Extended Key Usage (EKU) extension of X.509 v3 public key
>   certificates
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-lamps-im-keyusage/ <https://urldefense.com/v3/__https:/datatracker.ietf.org/doc/draft-ietf-lamps-im-keyusage/__;!!FJ-Y8qCqXTj2!eOQUtDAA8uwHi6mlSlRXJVJrnm_r5CwAKy09oCl_Q3itf786AeEtm2xwcGhxxxWefFHr1_P4naZzm9xvxEoUKqOy538S$> 
> 
> There is also an HTML version available at:
> https://www.ietf.org/archive/id/draft-ietf-lamps-im-keyusage-00.html <https://urldefense.com/v3/__https:/www.ietf.org/archive/id/draft-ietf-lamps-im-keyusage-00.html__;!!FJ-Y8qCqXTj2!eOQUtDAA8uwHi6mlSlRXJVJrnm_r5CwAKy09oCl_Q3itf786AeEtm2xwcGhxxxWefFHr1_P4naZzm9xvxEoUKn1iEEOp$> 
> 
> Internet-Drafts are also available by rsync at:
> rsync.ietf.org::internet-drafts
> 
> 
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org <mailto:Spasm@ietf.org> 
> https://www.ietf.org/mailman/listinfo/spasm <https://urldefense.com/v3/__https:/www.ietf.org/mailman/listinfo/spasm__;!!FJ-Y8qCqXTj2!eOQUtDAA8uwHi6mlSlRXJVJrnm_r5CwAKy09oCl_Q3itf786AeEtm2xwcGhxxxWefFHr1_P4naZzm9xvxEoUKhkjFbRj$> 

_______________________________________________
Spasm mailing list
Spasm@ietf.org <mailto:Spasm@ietf.org> 
https://www.ietf.org/mailman/listinfo/spasm <https://urldefense.com/v3/__https:/www.ietf.org/mailman/listinfo/spasm__;!!FJ-Y8qCqXTj2!eOQUtDAA8uwHi6mlSlRXJVJrnm_r5CwAKy09oCl_Q3itf786AeEtm2xwcGhxxxWefFHr1_P4naZzm9xvxEoUKhkjFbRj$>