Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

Mike Ounsworth <Mike.Ounsworth@entrust.com> Wed, 11 January 2023 17:17 UTC

Return-Path: <Mike.Ounsworth@entrust.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C5DCC131C72; Wed, 11 Jan 2023 09:17:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.994
X-Spam-Level:
X-Spam-Status: No, score=-1.994 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=entrust.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CgvgaKB9-Ofm; Wed, 11 Jan 2023 09:16:59 -0800 (PST)
Received: from mx08-0015a003.pphosted.com (mx08-0015a003.pphosted.com [185.183.30.227]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA2B3C131C70; Wed, 11 Jan 2023 09:16:58 -0800 (PST)
Received: from pps.filterd (m0242863.ppops.net [127.0.0.1]) by mx08-0015a003.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 30BEDYEM024092; Wed, 11 Jan 2023 11:16:56 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=entrust.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=mail1; bh=PwxkVAb1jtgVzY+gLXJjSbXGhUj887f0dNEqM0KBLRc=; b=mcL/jI7ej+aZlW70pCWbriZltXqslSwt08VNaUovZo/ELUchT1w79EsI5oOh/0iUKZNc DlNGpuIbG8/pR2YpGlyaXO3bqAe8tmM4BmRxkWt/RUZ3x7jrrdZnSBGXXihrw8ea1+p6 Og7JZ0cxeX2ouzXb32VGEpxuQGyOEO6qivNRO0Nrr4XB2k8JckfdARnXD/1J4oNr4YQX UeOZdFBHyOD/DGvLnqjelV9yvHFj3lQnkKYIWVwZQ7ISwMuk0T8gw5riGc028rK89ZSa 9tKGT8bh/i7AXqNv1z+R/CaMioYMRxB48fbIEef+yhOj2UQFbz2w+uxm8JsyZJvMx3rG uw==
Received: from nam10-mw2-obe.outbound.protection.outlook.com (mail-mw2nam10lp2107.outbound.protection.outlook.com [104.47.55.107]) by mx08-0015a003.pphosted.com (PPS) with ESMTPS id 3n1k64jj0t-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 11 Jan 2023 11:16:55 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EFSu2B7R9KBhBzcC/rNyxhswjKLttr/Hsmtx/RVn73tIt+/Q2k4KPY36NxclA5sDNpUXIfJprwEGYg9ATWwvd9lu/c7IexNgFpyCRJdfge/nVVwi+cl7l4ioMRgDciA8Yej7pNeqECcWFo1k1wWM3robTmCe8A0M7gp1Qpljfa6MCJV7hrLo11sWp9EV/g/5A9eJA4QpSkcB0cxWeBUZ3JFL2cxF3a9sTQtFUAY648Wd2RJB/tBhBFFMz+Lt/KLO0bvxY3j8CLqIYOgkCTwEngakRNsvOTKT86sSF9CUw8kbAfy2Xp5P88CK81/38oqLPI3GBQieNRYkx4794JArtA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=PwxkVAb1jtgVzY+gLXJjSbXGhUj887f0dNEqM0KBLRc=; b=OABXfFa0Z+xJBwEG1in3pFkDpaE3zKODswfABE4dcpJwo1xHlUEQ9LczYdzKQxaHMb7QKdkobK+zUTOu4xHkkjSeK8Hf/kGo+utT0qHR0yHlvCdHhwvOMfF9sSUgebsQoOPfc2AktecwZvE9Y/HOlw7uWoXf77CgL36x6I+XPWuZUxWzrGW+2GHyMIRgU6Ra51nttOmooiERWgYnXT9v4VyK/s8+TGu4cmRw5c8wb2ybnLb9UGngv6KBsJ9kYTBKjtp6yvNhJC3Z/OPnWrtgWLgoGWqAClCftvx0P3eJ+4iKKUl4BNZPoUQGaeH5BaOcdH3PRvIWvSo95IIV3mkNSw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=entrust.com; dmarc=pass action=none header.from=entrust.com; dkim=pass header.d=entrust.com; arc=none
Received: from CH0PR11MB5739.namprd11.prod.outlook.com (2603:10b6:610:100::20) by SJ0PR11MB4942.namprd11.prod.outlook.com (2603:10b6:a03:2ac::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6002.13; Wed, 11 Jan 2023 17:16:50 +0000
Received: from CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::a95:6d:ab71:f8e1]) by CH0PR11MB5739.namprd11.prod.outlook.com ([fe80::a95:6d:ab71:f8e1%8]) with mapi id 15.20.5986.018; Wed, 11 Jan 2023 17:16:50 +0000
From: Mike Ounsworth <Mike.Ounsworth@entrust.com>
To: "Kampanakis, Panos" <kpanos=40amazon.com@dmarc.ietf.org>, Carl Wallace <carl@redhoundsoftware.com>, "aebecke@uwe.nsa.gov" <aebecke@uwe.nsa.gov>, LAMPS <spasm@ietf.org>
Thread-Topic: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02
Thread-Index: AQHZIX+pn12YR/e35kCX+0VEcvSFGa6X8W+AgACYSQCAALPowIAAFxKAgAADaFCAAAxIAIAABhhggAASZYCAAADpQA==
Date: Wed, 11 Jan 2023 17:16:50 +0000
Message-ID: <CH0PR11MB5739AEBE12E0BF0995E7431A9FFC9@CH0PR11MB5739.namprd11.prod.outlook.com>
References: <PH0PR00MB10003EC6A096FE0A363BBFB9F5459@PH0PR00MB1000.namprd00.prod.outlook.com> <PH0PR00MB10002A7A2850A1333B4F6C00F54A9@PH0PR00MB1000.namprd00.prod.outlook.com> <35BEB1D9-7EA5-4CD4-BADA-88CCB0E9E8F9@vigilsec.com> <6FB4E76C-0AFD-4D00-B0FC-63F244510530@vigilsec.com> <bd5a491c78c8406b8de6414aff4f5223@amazon.com> <SA0PR09MB72412D6BBBC556716B5FBDEDF1FF9@SA0PR09MB7241.namprd09.prod.outlook.com> <adfdcfcfb0f84c63b83bc60cb9a48cfa@amazon.com> <CH0PR11MB573917AD78637794B2A424249FFC9@CH0PR11MB5739.namprd11.prod.outlook.com> <ca14b6a4dc624d5a8721a76fba0e0b2f@amazon.com> <CH0PR11MB5739F7AB185E366BFEB9F1A69FFC9@CH0PR11MB5739.namprd11.prod.outlook.com> <774557DE-522F-4A3C-B360-6B7C9103F579@redhoundsoftware.com> <CH0PR11MB5739D1D766DDFC5B48D59E159FFC9@CH0PR11MB5739.namprd11.prod.outlook.com> <e820c36095a04a3697b4345d06d2f392@amazon.com>
In-Reply-To: <e820c36095a04a3697b4345d06d2f392@amazon.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CH0PR11MB5739:EE_|SJ0PR11MB4942:EE_
x-ms-office365-filtering-correlation-id: 2f520eed-306a-4797-6852-08daf3f7a084
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: efpHZK3m97Jhwi4r3bQdRApzzIrLtqjfLnPpKwoqxcOWSq3b5lfq/3zuisKjvrvTFXmab0lTmrLSxN5Jwb7uqlipviAJiySOifOcDg3k+CgdzMPKlHZk8JuQv5CG7u7KhbZFygLyIFTJ0jBukwMr3u/TEVbrntR7k10EoGfuUBgeE0vmrtY9NktZebc/n4blE4eV0wrPgPxfL7okJhayPkLZPyST1eXer+FDWcLbLMCVhrogZGVLklHpAzaIoJT00WeqZ4cQgsWkj+TAFYX36Uy7je4Ztpae5dlA+eH4mDfyMFggEz5tz1dMB4x3dSTb1XnlA1GFQsD6KIlga60WCg/3TR1v2Nx5v/KdPyjtoTU4gSHD3rIfPm3YTdvClfIujgZcc5Y41mWZuNcZSCe0yYC3fz8cEPY0rSkP1q0dDoXws5FPE1igyTgDhNVSgNJpjq5n0tCsmGD/TeEBIlNxvGQT7FHR/cPLnKkpvYEyCSb8BpPz7LLu0OrBRAJ13C5AZYa0k2B/xLBqVK8SJ+xoxiA1b/9LUOYfYQuGpSMoMMbUWROLbiLup/P3NpwFFuj9wSDiWkwo8W8yVOJgg9DinVHaGGxsESK5EPPT7tbdlh7uMaAe5V4Pi7SwzxN3QEOUjwbn3mbgpgNHKaoHbPTRgsG1/v9O/Iqknhxh8OxJZRg2s+LUSjbR9zpe/yR8OWbdhbDaMy4BOZb1EihruJ0yLJf0Gt0s1u8gdD7h6Pp3F3E=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CH0PR11MB5739.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(366004)(376002)(396003)(346002)(39860400002)(136003)(451199015)(38100700002)(122000001)(83380400001)(33656002)(38070700005)(166002)(86362001)(5660300002)(30864003)(2906002)(8676002)(66946007)(66556008)(66476007)(66446008)(64756008)(76116006)(52536014)(8936002)(41300700001)(55016003)(66574015)(26005)(9686003)(186003)(6506007)(53546011)(110136005)(316002)(478600001)(45080400002)(966005)(71200400001)(7696005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 2nOnXB8ip35SQbZ6z40JwiwjSksEWwBeCeFtpXcbxt3DyByhn9bRl+frDsbmFj/xMSxuNaugRRVOlpyA45+sw+3wv+e1qE0vBSZ0taheZhjpMsvfH5MAv6+5y6VNQiiYPxDpoyBt9ERvrlccTWDjh8d7an+SxWNHAZAkWHjv+lXxk+DIDnkNU22pZYFWoRZ5IZtOB6pfQNPDBb9/GnInnR74pUtxOHqVTgU3lUwc/9IhS8bI9+PS/QLKnbHiDIIHzybKC6a7EV7YR2lCISCap+nysaOz2qc+A/Dk0SLxuvGc5qn6r191IXm98WWhuwcXSyRDZDWg089U3poPe2DhEph0TPtkpyoQ9M3Ji3RPXT8KyCmfffGWBDmm6xBQMgaBZN4K3GLJPPy5g6U37DxqLC5l0w/g+/jlAHDhkyFUHGfcurfWdYSofRRh1RrRnZTyISYgxmYdaFU6s1Zphq645ctDAgw4PS4PqMdxt9PY2hUlOcODnpREhXPGEz5GRap/dOkt2GSUR4gKJ6xzqV8Sm8LVmnxjCyfKmX7ws1vV2JvUUc55ZGw3hktSLTjlAjuOjUYLEoNZqq2jl10+vvpQQON6yjJD/Ky3ILODXycMb3VI6YB0kDxjDfHuA2Aao7+en8Mek7OMjOl6GXj9bm+ESQOscE2Nl+ZRyvhom1pmo1Y2f+yYk1YB+5h34Q+P64YnCA+vghAOQcU233meW5oDVUDqvXHpvBhLhUC7LWUxRlZ2SCjXozHxJpg8PHzvzzoEHI6KsEOO5niGfAWRHr4m3EMyMk5oeckCGeTsJdj6AJ2DgSev0rc1D9AYv+xjbtauUeh2pDXSy0d2dgWyQQKt7XxypGd+ubTwWsqIyocxr4LSZHP6jVNkp2Q5ocA/qARgL8yq2FQG5R+MEywiKkKDn4s5a/U8H3gAK396crd5O9zvPp+u2hiXr5AtIiG0gr42oE0wkOc6jJdfwxJh8DCK54ATVxPMus+dncU0j8ulzsy0UptdpvaDsIzpn4IvVke87jErQ4JnL01DXEWZ/R/7XRuWSISTYjrRn0hGa8qqRbrSkdE5PK1ukJOEVW0Ga3usSHItOygs1PbOYVfH7LbsX/IL53YErWomCiOY+HLhNj9e7UvZTAdnXgiEvH+YMfv+vkZvGXdkEASLnHt1TS+/mYNQg7WpTQG+tjcoKKrP66OP2tbObLKkYEtkGiaW2SUA/+HDcTW0hIQ5v8DtM3LmGrJWBM+58ErVmXcSzBBoJ6GMPBIeXizSAopDZn+FFTjrAT4n5Yccp50t4KxsZQxRLOHrxCMgtWAH2Em5LM1G14D5CMXFkpNMWg/0RROLHOm3NyRR482yxx9YvHZJqj6Zw4StCVu2UaqkqnSPF8gzVwlsvnh7IuYMmEbUogLpls3V7FelJowqQ+FfdpXyAH4GIkN8bh685StIwAA3sGeiD5/NVYIegkL/+n13wHG7B8XzVdX+LUpVZJ2RUJjrCTL1whMk9tFszb5/vajnYPt6svwz0TdpypJKCdmZepzKTv4ZOXMzr2sTuxL0Kyk5QwTlRGabGtvnQQglkMgJ6vm1hZDsLP5pOdSHOsFQ06OVf78F
Content-Type: multipart/alternative; boundary="_000_CH0PR11MB5739AEBE12E0BF0995E7431A9FFC9CH0PR11MB5739namp_"
MIME-Version: 1.0
X-OriginatorOrg: entrust.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CH0PR11MB5739.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2f520eed-306a-4797-6852-08daf3f7a084
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Jan 2023 17:16:50.1225 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f46cf439-27ef-4acf-a800-15072bb7ddc1
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: XxvfiwrJKYEGjPvOsIsLjqgQ0ITzAWp5o279LVxxa369fescNZ4SVQUyAZxwNNVXh0bpWtfjl/uvzis0lfi/pmYJUIAQ9wVwjz6El+PgBqA=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR11MB4942
X-Proofpoint-GUID: mO4KqNXlcrpy747csQfYMmNTT8IF0X9t
X-Proofpoint-ORIG-GUID: mO4KqNXlcrpy747csQfYMmNTT8IF0X9t
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.923,Hydra:6.0.545,FMLib:17.11.122.1 definitions=2023-01-11_07,2023-01-11_02,2022-06-22_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 lowpriorityscore=0 mlxlogscore=999 malwarescore=0 clxscore=1015 priorityscore=1501 impostorscore=0 suspectscore=0 bulkscore=0 mlxscore=0 spamscore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2212070000 definitions=main-2301110126
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/NuG61TL9wyHaFvemdjbupGBFHh8>
Subject: Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Jan 2023 17:17:03 -0000

> then what stops this person that wants to mix and match write their own CSR application that signs with the classical private key from one PIV and then gets the other PIV to sign the CSR according to the draft?

Good question. Alright, you’ve convinced me to join you back on the fence.

---
Mike Ounsworth

From: Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org>
Sent: Wednesday, January 11, 2023 11:13 AM
To: Mike Ounsworth <Mike.Ounsworth@entrust.com>; Carl Wallace <carl@redhoundsoftware.com>; aebecke@uwe.nsa.gov; LAMPS <spasm@ietf.org>
Subject: [EXTERNAL] RE: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.
________________________________
How is someone going to mix and match now?

  1.  Get two PIVs that have one classical, one PQ cert/private key each. All certs have the same DN.
  2.  Write a custom TLS app that allows them to start a TLS connection, generate one signature with one PIV’s classical private key. Then get the other PIV and sign the same TLS connection which is left in some sort of waiting state with the second PIV’s PQ private key?
If the draft is preventing that, then what stops this person that wants to mix and match write their own CSR application that signs with the classical private key from one PIV and then gets the other PIV to sign the CSR according to the draft?

I know we are speculating here since this is not what Allie has suggested so far, but sorry I don’t see the difference.

From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> On Behalf Of Mike Ounsworth
Sent: Wednesday, January 11, 2023 11:17 AM
To: Carl Wallace <carl@redhoundsoftware.com<mailto:carl@redhoundsoftware.com>>; Kampanakis, Panos <kpanos@amazon.com<mailto:kpanos@amazon.com>>; aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: RE: [EXTERNAL][lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02


CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.

Sorry, I should be more precise:

By “mix & match” I mean that in the hybrid mode you present two certificates, one from each device when the relying party is really expecting you to present two certs from the same device. Yes you *could* structure your DNs or SANs to be unique per device, but this draft provides a binding mech that does not require any specific PKI naming conventions.


Under the assumption that this draft is providing a meaningful way to solve this problem, then I support its adoption.

If we believe that the mechanism in this draft is not doing that, ie that there are no PKI deployments in which this draft is actually providing stronger bindings than we already have with Subject / SAN names, then I may reconsider my support for adoption.

---
Mike Ounsworth

From: Carl Wallace <carl@redhoundsoftware.com<mailto:carl@redhoundsoftware.com>>
Sent: Wednesday, January 11, 2023 9:45 AM
To: Mike Ounsworth <Mike.Ounsworth@entrust.com<mailto:Mike.Ounsworth@entrust.com>>; Kampanakis, Panos <kpanos@amazon.com<mailto:kpanos@amazon.com>>; aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: [EXTERNAL] Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.
________________________________
Inline…

From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> on behalf of Mike Ounsworth <Mike.Ounsworth=40entrust.com@dmarc.ietf.org<mailto:Mike.Ounsworth=40entrust.com@dmarc.ietf.org>>
Date: Wednesday, January 11, 2023 at 10:12 AM
To: "Kampanakis, Panos" <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>, "aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>" <aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>>, LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

Again, I’m guessing at the intended use-case here.

Let’s say I am in possession of two PIV ID cards. They both belong to me, ergo will have the same Subject and SANs.

[CW] It is not necessarily the case that your two PIV cards would have the same subject DN or SAN. It’s common for people to be issued smart cards for different functions or even within different government agencies (or perhaps to have a personal card and a group/role card) such that one or both of subject DN and SAN differ.

But they are not the same device. If both PIV cards are hybrids, then there are 4 certs in play, all of which will have the same Subject and SANs, but you should not mix&match them. This draft provides a mechanism to tag which pairs of certs “belong together” even though they all belong to the same PKI logical entity.

[CW] I’m not certain what you mean by “mix and match” or why that ought not be done, but it sounds like you are suggesting the proposed new extension be used to bind one cert on a smart card to the other (presumably even if the holder only possesses one smart card). Why would that be needed? A common case is derived credentials, which typically do have same DN and SAN. Those are intended to be “mixed and matched”, i.e., I would expect to be able to access the same resources using my phone or tablet as I can with my PIV card (even if one featured RSA keys and the other EC keys).

[CW] The extension really can’t mean much more than that an entity is demonstrating control of the private key corresponding to the related cert identified in an attribute included in a CSR. The utility of this proof would be up to the relying party. Any proof of same identity or same hardware device would be achieved through something other than this extension (as currently described, anyway). If one were to require DNs to match (to avoid cross-organizational recognition), then Panos’ point seems right, i.e., why not just check the names.

---
Mike Ounsworth

From: Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>
Sent: Wednesday, January 11, 2023 8:49 AM
To: Mike Ounsworth <Mike.Ounsworth@entrust.com<mailto:Mike.Ounsworth@entrust.com>>; aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: [EXTERNAL] RE: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.
________________________________
If the related certs have the same DN (I was calling it same Subject or SAN in my email) then the verifier can rest assured the two certs belong to the same entity without the need of a new extension. That is what I was originally pointing out. Now, if there is no identity overlap as Allie suggested then I was saying that I am not sure what the verifier is supposed to do when it is presented with these two related certs with completely different identities.

From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> On Behalf Of Mike Ounsworth
Sent: Wednesday, January 11, 2023 8:33 AM
To: Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>; aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov> <aebecke=40uwe.nsa.gov@dmarc.ietf.org<mailto:aebecke=40uwe.nsa.gov@dmarc.ietf.org>>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: RE: [EXTERNAL][lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02


CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.

Panos,

I assume in their use-case, endpoints will treat matching SANs as necessary but not sufficient.

Making up an example here, if you’re receiving a TLS client-auth connection from DN: cn=Alice,dc=example,dc=com then both certs had better have the same DN (otherwise it’s totally unclear which user is trying to log in) *PLUS* one of them had better have a RelatedCertificate extn that lines up with the other cert to prove that both private keys are contained on the same hardware device (or wtv the semantics of that extension mean in their environment).

---
Mike Ounsworth

From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> On Behalf Of Kampanakis, Panos
Sent: Tuesday, January 10, 2023 8:43 PM
To: aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov> <aebecke=40uwe.nsa.gov@dmarc.ietf.org<mailto:aebecke=40uwe.nsa.gov@dmarc.ietf.org>>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: [EXTERNAL] Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

WARNING: This email originated outside of Entrust.
DO NOT CLICK links or attachments unless you trust the sender and know the content is safe.
________________________________
Hi Allie,
Thx. If there is no overlap between the Subject Name or SANs in the two related certs, should they be used at the same time in a PQ transition scenario since the verifier can only be talking to one identity at a time? To rephrase that, if the two related certs include completely different identities, wouldn’t that be a problem for the TLS, IKEv2, etc verifier?
- When the verifier is presented with a classical RSA peer cert, it confirms the identity of the cert is the identity it is talking to.
- When the verifier is presented with just one PQ peer related-cert, it will confirm the identity of the cert is the identity it is talking to.
- While still in the PQ transition phase, when the verifier is presented with one classical RSA peer cert and one PQ peer related-cert, what is it supposed to do if the identities in these certs are completely different? Verify only one identity and assume the other one belongs to the same peer because of POP at issuance?


From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> On Behalf Of aebecke@uwe.nsa.gov<mailto:aebecke@uwe.nsa.gov>
Sent: Tuesday, January 10, 2023 12:38 PM
To: Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>; Russ Housley <housley@vigilsec.com<mailto:housley@vigilsec.com>>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: RE: [EXTERNAL][lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02


CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.

Hi Panos,
  Thanks for the comments. It is not always the case that SANs will unambiguously identify a certificate, as they are not globally unique. Especially in the case that may arise in which a different CA has issued a related certificate, we want to provide strong assurance that the certificate is under the control of the correct end-entity. Matching names depends on mapping the namespaces of the issuers (which may suffice for discovery); our draft provides the existing (traditional) PoP nested in the new (PQC) PoP, which we think provides more assurance.

Cheers,
Alie

----
________________________________
From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> on behalf of Kampanakis, Panos <kpanos=40amazon.com@dmarc.ietf.org<mailto:kpanos=40amazon.com@dmarc.ietf.org>>
Sent: Thursday, January 5, 2023 9:33 PM
To: Russ Housley <housley@vigilsec.com<mailto:housley@vigilsec.com>>; LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: Re: [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

My previous objections and concerns have not been addressed, but maybe I had misunderstood the spirit of the draft. So let me repeat the last, most important, question after Mike's presentation of the draft in IETF-115.

It seems that the draft just wants to provide an extension that says cert A and cert B are related and owned by the same entity and allow a CSR to prove that the requester of Cert B also owns the private key for Cert A. In other words the flow would work as:
- Entity X generates a CSR for CertA and proves it owns the private key for A. The issuer generates CertA after verifying the ownership of private key A and the identity of X.
- Entity X generates a CSR for CertB which is related to CertA and proves it owns the private key for A and B. The issuer generates CertB (related-to-CertA) after verifying the ownership of private keys A and B and the identity of X.
- Entity X owns CertA and CertB which it uses to be authenticated in protocol Y. The protocol Y verifier gets CertA and CertB, it verifies the peer owns the private key for CertA, CertB and it confirms it trusts these certs were issued for Entity X.

Now let's forget the draft and say we do not use a new X.509 or CSR extension. And let's say the flow now works as
- Entity X generates a CSR for CertA and proves it owns the private key for A. The issuer generates CertA after verifying the ownership of private key A and the identity of X.
- Entity X generates a CSR for CertB and proves it owns the private key for B. The issuer generates CertB after verifying the ownership of private key B and the identity of X.
- Entity X owns CertA and CertB which it uses to be authenticated in protocol Y. The protocol Y verifier gets CertA and CertB, it verifies the peer owns the private key for CertA, CertB and it confirms it trusts BOTH of these certs were issued for the same entity Entity X.

Why is the former flow better over the latter? In other words, if CertA and CertB were issued separately, why could the verifier not just use the Subject Name or SANs to confirm the certs relationship while verifying?



-----Original Message-----
From: Spasm <spasm-bounces@ietf.org<mailto:spasm-bounces@ietf.org>> On Behalf Of Russ Housley
Sent: Thursday, January 5, 2023 6:02 PM
To: LAMPS <spasm@ietf.org<mailto:spasm@ietf.org>>
Subject: [EXTERNAL] [lamps] Call for adoption of draft-becker-guthrie-cert-binding-for-multi-auth-02

CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.



Do the changes that were made in -02 of the Internet-Draft resolve the concerns that were previously raised?

On behalf of the LAMPS WG Chairs,
Russ


> On Sep 15, 2022, at 11:44 AM, Russ Housley <housley@vigilsec.com<mailto:housley@vigilsec.com>> wrote:
>
> There has been some discussion of https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-becker-guthrie-cert-binding-for-multi-auth%2F&data=05%7C01%7Caebecke%40uwe.nsa.gov%7Cd4dd908b5872439f1f0408daef96c7fd%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C638085728259980926%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=nVzReEXbWrb8sHQPdGWv9G95WoP1GiKdjlHZP6DesmA%3D&reserved=0<https://urldefense.com/v3/__https:/gcc02.safelinks.protection.outlook.com/?url=https*3A*2F*2Fdatatracker.ietf.org*2Fdoc*2Fdraft-becker-guthrie-cert-binding-for-multi-auth*2F&data=05*7C01*7Caebecke*40uwe.nsa.gov*7Cd4dd908b5872439f1f0408daef96c7fd*7Cd61e9a6ffc164f848a3e6eeff33e136b*7C0*7C0*7C638085728259980926*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C2000*7C*7C*7C&sdata=nVzReEXbWrb8sHQPdGWv9G95WoP1GiKdjlHZP6DesmA*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!FJ-Y8qCqXTj2!d7f04rwCDRu50-kA9UKkJme_ySd-Afo_1Wb-dRjV7Oezr0g4VpHXxYq1FxaLj8rCLEwQyFlPuSPMoyO5iHbXgQ0o4LMPjD4qXsgkQtebag$>.  During the discussion at IETF 114, we agree to have a call for adoption of this document.
>
> Should the LAMPS WG adopt “Related Certificates for Use in Multiple Authentications within a Protocol” indraft-becker-guthrie-cert-binding-for-multi-auth-01?
>
> Please reply to this message by Friday, 30 September 2022 to voice your support or opposition to adoption.
>
> On behalf of the LAMPS WG Chairs,
> Russ
>

_______________________________________________
Spasm mailing list
Spasm@ietf.org<mailto:Spasm@ietf.org>
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fspasm&data=05%7C01%7Caebecke%40uwe.nsa.gov%7Cd4dd908b5872439f1f0408daef96c7fd%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C638085728259980926%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=qkCBqRILB587BacZgK9AHy6kqqQmfrTGeqv9dqm1RXg%3D&reserved=0<https://urldefense.com/v3/__https:/gcc02.safelinks.protection.outlook.com/?url=https*3A*2F*2Fwww.ietf.org*2Fmailman*2Flistinfo*2Fspasm&data=05*7C01*7Caebecke*40uwe.nsa.gov*7Cd4dd908b5872439f1f0408daef96c7fd*7Cd61e9a6ffc164f848a3e6eeff33e136b*7C0*7C0*7C638085728259980926*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C2000*7C*7C*7C&sdata=qkCBqRILB587BacZgK9AHy6kqqQmfrTGeqv9dqm1RXg*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!FJ-Y8qCqXTj2!d7f04rwCDRu50-kA9UKkJme_ySd-Afo_1Wb-dRjV7Oezr0g4VpHXxYq1FxaLj8rCLEwQyFlPuSPMoyO5iHbXgQ0o4LMPjD4qXsjiZu1rhQ$>
_______________________________________________
Spasm mailing list
Spasm@ietf.org<mailto:Spasm@ietf.org>
https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fspasm&data=05%7C01%7Caebecke%40uwe.nsa.gov%7Cd4dd908b5872439f1f0408daef96c7fd%7Cd61e9a6ffc164f848a3e6eeff33e136b%7C0%7C0%7C638085728259980926%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C2000%7C%7C%7C&sdata=qkCBqRILB587BacZgK9AHy6kqqQmfrTGeqv9dqm1RXg%3D&reserved=0<https://urldefense.com/v3/__https:/gcc02.safelinks.protection.outlook.com/?url=https*3A*2F*2Fwww.ietf.org*2Fmailman*2Flistinfo*2Fspasm&data=05*7C01*7Caebecke*40uwe.nsa.gov*7Cd4dd908b5872439f1f0408daef96c7fd*7Cd61e9a6ffc164f848a3e6eeff33e136b*7C0*7C0*7C638085728259980926*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C2000*7C*7C*7C&sdata=qkCBqRILB587BacZgK9AHy6kqqQmfrTGeqv9dqm1RXg*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!FJ-Y8qCqXTj2!d7f04rwCDRu50-kA9UKkJme_ySd-Afo_1Wb-dRjV7Oezr0g4VpHXxYq1FxaLj8rCLEwQyFlPuSPMoyO5iHbXgQ0o4LMPjD4qXsjiZu1rhQ$>
Any email and files/attachments transmitted with it are confidential and are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.
_______________________________________________ Spasm mailing list Spasm@ietf.org<mailto:Spasm@ietf.org> https://www.ietf.org/mailman/listinfo/spasm<https://urldefense.com/v3/__https:/www.ietf.org/mailman/listinfo/spasm__;!!FJ-Y8qCqXTj2!ZUMS1k83i98StJTO_4kmkV4RQ_MuqXrGbn4F4L_GU8lOAqRV5K-R6YNfePkWN23IZ8NXxkPUZT3av1IHUkQeEYw7$>