From nobody Tue Aug 23 09:57:57 2022
Return-Path: <housley@vigilsec.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 0E63EC14F75F
 for <spasm@ietfa.amsl.com>; Tue, 23 Aug 2022 09:57:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.905
X-Spam-Level: 
X-Spam-Status: No, score=-1.905 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001,
 RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
 T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001,
 URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
 autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id d7aiS6puT3lC for <spasm@ietfa.amsl.com>;
 Tue, 23 Aug 2022 09:57:54 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256)
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id F3B1AC14F73B
 for <spasm@ietf.org>; Tue, 23 Aug 2022 09:57:53 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1])
 by mail3.g24.pair.com (Postfix) with ESMTP id C932118EAF5;
 Tue, 23 Aug 2022 12:57:52 -0400 (EDT)
Received: from [10.0.1.2] (pfs.iad.rg.net [198.180.150.6])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by mail3.g24.pair.com (Postfix) with ESMTPSA id A3C55191DE6;
 Tue, 23 Aug 2022 12:57:52 -0400 (EDT)
From: Russ Housley <housley@vigilsec.com>
Message-Id: <9900F976-524C-4156-ADE4-05BC66466E06@vigilsec.com>
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_6670C42B-8846-4BDD-B38E-64178F01F0AF"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.21\))
Date: Tue, 23 Aug 2022 12:57:52 -0400
In-Reply-To: <VI1PR07MB6430B34418388DD1CFA2214193709@VI1PR07MB6430.eurprd07.prod.outlook.com>
Cc: tirumal reddy <kondtir@gmail.com>,
 Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com>, LAMPS <spasm@ietf.org>
To: "Peinado, German (Nokia - PL/Wroclaw)" <german.peinado@nokia.com>
References: <DM8PR14MB52376D8E7F6F414563238A18839F9@DM8PR14MB5237.namprd14.prod.outlook.com>
 <CAFpG3gciz2h+wTCnWy0Uazn+CLSKhWaCRnk6tNtptZriVtvseA@mail.gmail.com>
 <E1C193C7-F876-4F18-8AD8-8548F4BFA983@vigilsec.com>
 <CAFpG3geF2jxoMZfeXO9hLM+9z6Ovsn59eBhYYmEez7A=AfF4eA@mail.gmail.com>
 <2404FB76-F49E-4DBE-A8F9-7655EE210440@vigilsec.com>
 <CAFpG3gdq-O7-bqXFyLkQ0Rd8YW_G9WZkaii-__rBuA3MFbnPRg@mail.gmail.com>
 <DU0PR03MB86963D63921A321097313CDE86659@DU0PR03MB8696.eurprd03.prod.outlook.com>
 <CAFpG3gddN0QaiBiGoQL1Qja_gc14JRz_BncaHXdZLMSRjMUDPQ@mail.gmail.com>
 <AM0PR07MB64199F0D22F6ECFFAF09B68793659@AM0PR07MB6419.eurprd07.prod.outlook.com>
 <21CFD228-67C6-407E-A09F-EA17804F4E45@vigilsec.com>
 <AM0PR07MB6419BE4D292E95D3DC80F1D493649@AM0PR07MB6419.eurprd07.prod.outlook.com>
 <429F80EE-FCF6-4403-9526-8CF8FED26A04@vigilsec.com>
 <VI1PR07MB6430B34418388DD1CFA2214193709@VI1PR07MB6430.eurprd07.prod.outlook.com>
X-Mailer: Apple Mail (2.3445.104.21)
X-Scanned-By: mailmunge 3.09 on 66.39.134.11
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/U9lip0ctdvSgElROvy691YzPCWQ>
Subject: Re: [lamps] Call for adoption of draft-housley-lamps-3g-nftypes
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime
 \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>,
 <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>,
 <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Aug 2022 16:57:56 -0000


--Apple-Mail=_6670C42B-8846-4BDD-B38E-64178F01F0AF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Thanks for the reply.  Agreed.

Russ


> On Aug 23, 2022, at 12:53 PM, Peinado, German (Nokia - PL/Wroclaw) =
<german.peinado@nokia.com> wrote:
>=20
> Russ:
> =20
> SA3 meeting is ongoing, and it is an e-meeting. Let=E2=80=99s wait =
until the end of the week when the meeting finishes.
> =20
> Thanks,
> German
> =20
> From: Russ Housley <housley@vigilsec.com =
<mailto:housley@vigilsec.com>>=20
> Sent: Tuesday, August 23, 2022 5:50 PM
> To: Peinado, German (Nokia - PL/Wroclaw) <german.peinado@nokia.com =
<mailto:german.peinado@nokia.com>>
> Cc: tirumal reddy <kondtir@gmail.com <mailto:kondtir@gmail.com>>; =
Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com =
<mailto:Tomas.Gustavsson@keyfactor.com>>; LAMPS <spasm@ietf.org =
<mailto:spasm@ietf.org>>
> Subject: Re: [lamps] Call for adoption of =
draft-housley-lamps-3g-nftypes
> =20
> German:
> =20
> Has the discussion taken place?  If not, how much additional time is =
needed?
> =20
> Russ
> =20
>=20
>=20
> On Aug 11, 2022, at 7:40 AM, Peinado, German (Nokia - PL/Wroclaw) =
<german.peinado@nokia.com <mailto:german.peinado@nokia.com>> wrote:
> =20
> Russ:=20
> =20
> Thanks for the feedback.
> =20
> Regarding my request on letting SA3 to discuss this draft and =
consequently to postpone the current deadline to the support or =
opposition to adoption of the draft, does it sound reasonable and =
beneficial?
> =20
> Thanks,
> German
> =20
> From: Russ Housley <housley@vigilsec.com =
<mailto:housley@vigilsec.com>>=20
> Sent: Wednesday, August 10, 2022 5:37 PM
> To: Peinado, German (Nokia - PL/Wroclaw) <german.peinado@nokia.com =
<mailto:german.peinado@nokia.com>>
> Cc: tirumal reddy <kondtir@gmail.com <mailto:kondtir@gmail.com>>; =
Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com =
<mailto:Tomas.Gustavsson@keyfactor.com>>; LAMPS <spasm@ietf.org =
<mailto:spasm@ietf.org>>
> Subject: Re: [lamps] Call for adoption of =
draft-housley-lamps-3g-nftypes
> =20
> =20
> German:
> =20
> Yes, I agree that clear that this extension is expected yo bu used in =
a PKI that is internal to the 5G provider.
> =20
> Russ
> =20
>=20
>=20
>=20
> On Aug 10, 2022, at 3:34 AM, Peinado, German (Nokia - PL/Wroclaw) =
<german.peinado@nokia.com <mailto:german.peinado@nokia.com>> wrote:
> =20
> Dear All,=20
> =20
> My name is German Peinado, and I work in Nokia as SA3 delegate in =
3GPP. As rapporteur of the new SID TR 33.876 in rel-18 this topic =
caught.
> =20
> I agree with Tomas in his observation related to publicly trusted =
WebPKI CAs vs. internal CAs typically used in 3GPP networks. Thus, it =
would be good to make this assumption explicit in the draft as suggested =
by Tiru.=20
> =20
> The relevant document for the guard related to the usage of vendor =
certificate is TS 33.310 (NDS;AF). However this guard is not really =
applicable or valid in SBA scenario for 5G Core Network Functions that =
are basically virtual network functions. The usage of vendor =
certificates as trust anchor to establish initial trust with the CA was =
designed for base stations in LTE times, and adopted in 5G for physical =
base stations. This is an issue we are currently studying in the TR =
33.876.=20
> =20
> The overall draft looks quite straightforward, and of course relevant =
for the 5G Network Functions. A colleague from Ericsson in SA3 is =
proposing a discussion paper in upcoming SA3 meeting in 22nd -26th of =
August where this paper is mentioned to address one current format =
issue. Since this draft addresses a valid topic related to the certs =
used in 5G network functions as specified in 3GPP, I would kindly ask to =
this group to give at least one round of discussions in SA3 on this =
draft in the upcoming SA3 meeting, and consequently to postpone by a few =
weeks the current deadline (22.08) to voice the support or opposition to =
adoption of the draft. That way, you would receive feedback on that from =
SA3.=20
> =20
> Does it make sense for the group?
> =20
> Thanks,=20
> German
> =20
> =20
> From: Spasm <spasm-bounces@ietf.org <mailto:spasm-bounces@ietf.org>> =
On Behalf Of tirumal reddy
> Sent: Wednesday, August 10, 2022 8:55 AM
> To: Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com =
<mailto:Tomas.Gustavsson@keyfactor.com>>
> Cc: Russ Housley <housley@vigilsec.com <mailto:housley@vigilsec.com>>; =
LAMPS <spasm@ietf.org <mailto:spasm@ietf.org>>
> Subject: Re: [lamps] Call for adoption of =
draft-housley-lamps-3g-nftypes
> =20
> On Wed, 10 Aug 2022 at 12:02, Tomas Gustavsson =
<Tomas.Gustavsson@keyfactor.com <mailto:Tomas.Gustavsson@keyfactor.com>> =
wrote:
> I don't think 3GPP networks will make use of certificate transparency =
logs. These are internal telco networks and will not use publicly =
trusted WebPKI CAs for issuing TLS certificates. I don't think publicly =
trusted CAs could even issue these certificates as it may contain other =
information than what's allowed by Baseline Requirements, such as =
internal hostnames/IPs.
> =20
> Thanks. Please update the draft to say the deployment model uses an =
internal CA and not a public WebPKI CA.
> =20
> =20
> There are some guards against malicious network functions built into =
the 3GPP specification, by the usage of vendor certificates for =
authenticating the network functions the MNO plans to put into it's =
network.
> =20
> A pointer to the relevant document will be helpful.
> =20
> -Tiru
> =20
> =20
> Cheers,
> Tomas
> =20
> From: Spasm <spasm-bounces@ietf.org <mailto:spasm-bounces@ietf.org>> =
on behalf of tirumal reddy <kondtir@gmail.com =
<mailto:kondtir@gmail.com>>
> Sent: Wednesday, August 10, 2022 7:22 AM
> To: Russ Housley <housley@vigilsec.com <mailto:housley@vigilsec.com>>
> Cc: LAMPS <spasm@ietf.org <mailto:spasm@ietf.org>>
> Subject: Re: [lamps] Call for adoption of =
draft-housley-lamps-3g-nftypes
> =20
> CAUTION: External Sender - Be cautious when clicking links or opening =
attachments. Please email InfoSec@keyfactor.com =
<mailto:InfoSec@keyfactor.com> with any questions.
> =20
> Hi Russ,
> =20
> Please see inline
> =20
> On Mon, 8 Aug 2022 at 21:01, Russ Housley <housley@vigilsec.com =
<mailto:housley@vigilsec.com>> wrote:
> Tiru:
> =20
> 1. Yes, this is a good topic to expand the Security Considerations.
> =20
> 2. This seems pretty obvious to me, but I will think about a sentence =
or two for a more complete explanation.
> =20
> Thanks. You may want to also discuss the privacy and security =
implications of using NFType in the certificate extension for RBAC. For =
example (1) If TLS 1.2 is used by network functions, pervasive =
monitoring is possible for an attacker to identify the NFTypes visible =
in the TLS handshake and can potentially target a specific NFType (e.g., =
subject to DDoS or launch a targeted attack). (3) Misuse of NFType to =
gain additional privileges and what are the potential remediation =
techniques ?=20
> =20
> Yes, the certificate is plaintext when TLS 1.2 is used, and it it =
encrypted when TLS 1.3 or IKEv2 is used.
> =20
> In TLS 1.3 (without encrypted client hello), SNI will not be encrypted =
and it is possible for an attacker to get the certificate content from =
certificate transparency logs to identify the NFTypes associated with =
the FQDN.
> =20
> =20
> I'm not sure what you mean about misuse of the NFType.  Are you =
talking about the trusted CA putting the wrong NFType in the =
certificate?
> =20
> No, trusted CA may not inject a wrong NFType and it can be validated =
by the network function sending the CSR to the CA.=20
> I meant the NFTypes and FQDN of network functions will be available in =
the certificate transparency logs. It exposes the internal/external =
network functions details to anyone on the Internet. It may also be =
possible for an internal attacker to host a malicious network function =
and misuse the NFType to gain additional privileges.
> =20
> Cheers,
> -Tiru=20
> =20
> Russ
> =20
> _______________________________________________
> Spasm mailing list
> Spasm@ietf.org <mailto:Spasm@ietf.org>
> https://www.ietf.org/mailman/listinfo/spasm =
<https://www.ietf.org/mailman/listinfo/spasm>

--Apple-Mail=_6670C42B-8846-4BDD-B38E-64178F01F0AF
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Thanks for the reply. &nbsp;Agreed.<div class=3D""><br =
class=3D""></div><div class=3D"">Russ</div><div class=3D""><br =
class=3D""><div><br class=3D""><blockquote type=3D"cite" class=3D""><div =
class=3D"">On Aug 23, 2022, at 12:53 PM, Peinado, German (Nokia - =
PL/Wroclaw) &lt;<a href=3D"mailto:german.peinado@nokia.com" =
class=3D"">german.peinado@nokia.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div =
class=3D"WordSection1" style=3D"page: WordSection1; caret-color: rgb(0, =
0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;"><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span class=3D"">Russ:<o:p =
class=3D""></o:p></span></div><div style=3D"margin: 0cm; font-size: =
11pt; font-family: Calibri, sans-serif;" class=3D""><span class=3D""><o:p =
class=3D"">&nbsp;</o:p></span></div><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span =
class=3D"">SA3 meeting is ongoing, and it is an e-meeting. Let=E2=80=99s =
wait until the end of the week when the meeting finishes.<o:p =
class=3D""></o:p></span></div><div style=3D"margin: 0cm; font-size: =
11pt; font-family: Calibri, sans-serif;" class=3D""><span class=3D""><o:p =
class=3D"">&nbsp;</o:p></span></div><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span =
class=3D"">Thanks,<o:p class=3D""></o:p></span></div><div style=3D"margin:=
 0cm; font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span=
 class=3D"">German<o:p class=3D""></o:p></span></div><div style=3D"margin:=
 0cm; font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span=
 class=3D""><o:p class=3D"">&nbsp;</o:p></span></div><div class=3D""><div =
style=3D"border-style: solid none none; border-top-width: 1pt; =
border-top-color: rgb(225, 225, 225); padding: 3pt 0cm 0cm;" =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D""><b class=3D""><span lang=3D"EN-US" =
class=3D"">From:</span></b><span lang=3D"EN-US" class=3D""><span =
class=3D"Apple-converted-space">&nbsp;</span>Russ Housley &lt;<a =
href=3D"mailto:housley@vigilsec.com" style=3D"color: blue; =
text-decoration: underline;" class=3D"">housley@vigilsec.com</a>&gt;<span =
class=3D"Apple-converted-space">&nbsp;</span><br class=3D""><b =
class=3D"">Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, August 23, 2022 =
5:50 PM<br class=3D""><b class=3D"">To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Peinado, German (Nokia - =
PL/Wroclaw) &lt;<a href=3D"mailto:german.peinado@nokia.com" =
style=3D"color: blue; text-decoration: underline;" =
class=3D"">german.peinado@nokia.com</a>&gt;<br class=3D""><b =
class=3D"">Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>tirumal reddy &lt;<a =
href=3D"mailto:kondtir@gmail.com" style=3D"color: blue; text-decoration: =
underline;" class=3D"">kondtir@gmail.com</a>&gt;; Tomas Gustavsson =
&lt;<a href=3D"mailto:Tomas.Gustavsson@keyfactor.com" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">Tomas.Gustavsson@keyfactor.com</a>&gt;; LAMPS &lt;<a =
href=3D"mailto:spasm@ietf.org" style=3D"color: blue; text-decoration: =
underline;" class=3D"">spasm@ietf.org</a>&gt;<br class=3D""><b =
class=3D"">Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [lamps] Call for =
adoption of draft-housley-lamps-3g-nftypes<o:p =
class=3D""></o:p></span></div></div></div><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">German:<o:p =
class=3D""></o:p></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div></div><div class=3D""><div style=3D"margin: =
0cm; font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">Has =
the discussion taken place? &nbsp;If not, how much additional time is =
needed?<o:p class=3D""></o:p></div></div><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><o:p class=3D"">&nbsp;</o:p></div></div><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">Russ<o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><br =
class=3D""><br class=3D""><o:p class=3D""></o:p></div><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt;" class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">On Aug 11, 2022, at 7:40 AM, Peinado, =
German (Nokia - PL/Wroclaw) &lt;<a =
href=3D"mailto:german.peinado@nokia.com" style=3D"color: blue; =
text-decoration: underline;" class=3D"">german.peinado@nokia.com</a>&gt; =
wrote:<o:p class=3D""></o:p></div></div><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><o:p =
class=3D"">&nbsp;</o:p></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Russ:<span =
class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">Thanks =
for the feedback.<o:p class=3D""></o:p></div></div><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">Regarding my request on letting SA3 to =
discuss this draft and consequently to postpone the current deadline to =
the support or opposition to adoption of the draft, does it sound =
reasonable and beneficial?<o:p class=3D""></o:p></div></div><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">Thanks,<o:p=
 class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">German<o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div><div class=3D""><div style=3D"border-style: =
solid none none; border-top-width: 1pt; border-top-color: rgb(225, 225, =
225); padding: 3pt 0cm 0cm;" class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><b class=3D""><span lang=3D"EN-US" =
class=3D"">From:</span></b><span class=3D"apple-converted-space"><span =
lang=3D"EN-US" class=3D"">&nbsp;</span></span><span lang=3D"EN-US" =
class=3D"">Russ Housley &lt;<a href=3D"mailto:housley@vigilsec.com" =
style=3D"color: blue; text-decoration: underline;" =
class=3D"">housley@vigilsec.com</a>&gt;<span =
class=3D"apple-converted-space">&nbsp;</span><br class=3D""><b =
class=3D"">Sent:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Wednesday, August 10, 2022 =
5:37 PM<br class=3D""><b class=3D"">To:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Peinado, German (Nokia - =
PL/Wroclaw) &lt;<a href=3D"mailto:german.peinado@nokia.com" =
style=3D"color: blue; text-decoration: underline;" =
class=3D"">german.peinado@nokia.com</a>&gt;<br class=3D""><b =
class=3D"">Cc:</b><span =
class=3D"apple-converted-space">&nbsp;</span>tirumal reddy &lt;<a =
href=3D"mailto:kondtir@gmail.com" style=3D"color: blue; text-decoration: =
underline;" class=3D"">kondtir@gmail.com</a>&gt;; Tomas Gustavsson =
&lt;<a href=3D"mailto:Tomas.Gustavsson@keyfactor.com" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">Tomas.Gustavsson@keyfactor.com</a>&gt;; LAMPS &lt;<a =
href=3D"mailto:spasm@ietf.org" style=3D"color: blue; text-decoration: =
underline;" class=3D"">spasm@ietf.org</a>&gt;<br class=3D""><b =
class=3D"">Subject:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Re: [lamps] Call for =
adoption of draft-housley-lamps-3g-nftypes</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">German:<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Yes, I agree that clear =
that this extension is expected yo bu used in a PKI that is internal to =
the 5G provider.<o:p class=3D""></o:p></div></div></div><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Russ<o:p class=3D""></o:p></div></div></div><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><br class=3D""><br class=3D""><br class=3D""><o:p =
class=3D""></o:p></div></div><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt;" class=3D""><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">On Aug 10, 2022, at 3:34 AM, Peinado, German =
(Nokia - PL/Wroclaw) &lt;<a href=3D"mailto:german.peinado@nokia.com" =
style=3D"color: blue; text-decoration: underline;" =
class=3D"">german.peinado@nokia.com</a>&gt; wrote:<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div style=3D"margin: =
0cm; font-size: 11pt; font-family: Calibri, sans-serif;" =
class=3D"">&nbsp;<o:p class=3D""></o:p></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Dear All,<span =
class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">My name is German Peinado, =
and I work in Nokia as SA3 delegate in 3GPP. As rapporteur of the new =
SID TR 33.876 in rel-18 this topic caught.<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">I agree with Tomas in his =
observation related to publicly trusted WebPKI CAs vs. internal CAs =
typically used in 3GPP networks. Thus, it would be good to make this =
assumption explicit in the draft as suggested by Tiru.<span =
class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">The relevant document for =
the guard related to the usage of vendor certificate is TS 33.310 =
(NDS;AF). However this guard is not really applicable or valid in SBA =
scenario for 5G Core Network Functions that are basically virtual =
network functions. The usage of vendor certificates as trust anchor to =
establish initial trust with the CA was designed for base stations in =
LTE times, and adopted in 5G for physical base stations. This is an =
issue we are currently studying in the TR 33.876.<span =
class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">The overall draft looks =
quite straightforward, and of course relevant for the 5G Network =
Functions. A colleague from Ericsson in SA3 is proposing a discussion =
paper in upcoming SA3 meeting in 22<sup class=3D"">nd</sup><span =
class=3D"apple-converted-space">&nbsp;</span>-26<sup =
class=3D"">th</sup><span class=3D"apple-converted-space">&nbsp;</span>of =
August where this paper is mentioned to address one current format =
issue. Since this draft addresses a valid topic related to the certs =
used in 5G network functions as specified in 3GPP, I would kindly ask to =
this group to give at least one round of discussions in SA3 on this =
draft in the upcoming SA3 meeting, and consequently to postpone by a few =
weeks the current deadline (22.08) to voice the support or opposition to =
adoption of the draft. That way, you would receive feedback on that from =
SA3.<span class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Does it make sense for the =
group?<o:p class=3D""></o:p></div></div></div><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">Thanks,<span =
class=3D"apple-converted-space">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">German<o:p class=3D""></o:p></div></div></div><div=
 class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
style=3D"margin: 0cm; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D"">&nbsp;<o:p class=3D""></o:p></div></div></div><div=
 style=3D"border-style: solid none none; border-top-width: 1pt; =
border-top-color: rgb(225, 225, 225); padding: 3pt 0cm 0cm;" =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><b =
class=3D""><span lang=3D"EN-US" class=3D"">From:</span></b><span =
class=3D"apple-converted-space"><span lang=3D"EN-US" =
class=3D"">&nbsp;</span></span><span lang=3D"EN-US" class=3D"">Spasm =
&lt;<a href=3D"mailto:spasm-bounces@ietf.org" style=3D"color: blue; =
text-decoration: underline;" =
class=3D"">spasm-bounces@ietf.org</a>&gt;<span =
class=3D"apple-converted-space">&nbsp;</span><b class=3D"">On Behalf =
Of<span class=3D"apple-converted-space">&nbsp;</span></b>tirumal =
reddy<br class=3D""><b class=3D"">Sent:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Wednesday, August 10, 2022 =
8:55 AM<br class=3D""><b class=3D"">To:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Tomas Gustavsson &lt;<a =
href=3D"mailto:Tomas.Gustavsson@keyfactor.com" style=3D"color: blue; =
text-decoration: underline;" =
class=3D"">Tomas.Gustavsson@keyfactor.com</a>&gt;<br class=3D""><b =
class=3D"">Cc:</b><span class=3D"apple-converted-space">&nbsp;</span>Russ =
Housley &lt;<a href=3D"mailto:housley@vigilsec.com" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">housley@vigilsec.com</a>&gt;; LAMPS &lt;<a =
href=3D"mailto:spasm@ietf.org" style=3D"color: blue; text-decoration: =
underline;" class=3D"">spasm@ietf.org</a>&gt;<br class=3D""><b =
class=3D"">Subject:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Re: [lamps] Call for =
adoption of draft-housley-lamps-3g-nftypes</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">On Wed, 10 Aug 2022 at =
12:02, Tomas Gustavsson &lt;<a =
href=3D"mailto:Tomas.Gustavsson@keyfactor.com" style=3D"color: blue; =
text-decoration: underline;" =
class=3D"">Tomas.Gustavsson@keyfactor.com</a>&gt; wrote:<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">I don't think 3GPP =
networks will make use of certificate transparency logs. These are =
internal telco networks and will not use publicly trusted WebPKI CAs for =
issuing TLS certificates. I don't think publicly trusted CAs could even =
issue these certificates as it may contain other information than what's =
allowed by Baseline Requirements, such as internal =
hostnames/IPs.</span><o:p =
class=3D""></o:p></div></div></div></div></div></blockquote><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Thanks. Please update the =
draft to say the deployment&nbsp;model uses an internal CA and not a =
public WebPKI CA.<o:p class=3D""></o:p></div></div></div></div><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">There are some guards =
against malicious network functions built into the 3GPP specification, =
by the usage of vendor certificates for authenticating the network =
functions the MNO plans to put into it's network.</span><o:p =
class=3D""></o:p></div></div></div></div></div></blockquote><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">A pointer to the =
relevant&nbsp;document will be helpful.<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">-Tiru<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">Cheers,</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">Tomas</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif;" class=3D"">&nbsp;</span><o:p =
class=3D""></o:p></div></div></div></div><div class=3D"MsoNormal" =
align=3D"center" style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif; text-align: center;"><hr size=3D"1" width=3D"98%" =
align=3D"center" class=3D""></div><div =
id=3D"gmail-m_-6043843296083028246divRplyFwdMsg" class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><b class=3D"">From:</b><span=
 class=3D"apple-converted-space">&nbsp;</span>Spasm &lt;<a =
href=3D"mailto:spasm-bounces@ietf.org" target=3D"_blank" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">spasm-bounces@ietf.org</a>&gt; on behalf of tirumal reddy =
&lt;<a href=3D"mailto:kondtir@gmail.com" target=3D"_blank" style=3D"color:=
 blue; text-decoration: underline;" =
class=3D"">kondtir@gmail.com</a>&gt;<br class=3D""><b =
class=3D"">Sent:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Wednesday, August 10, 2022 =
7:22 AM<br class=3D""><b class=3D"">To:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Russ Housley &lt;<a =
href=3D"mailto:housley@vigilsec.com" target=3D"_blank" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">housley@vigilsec.com</a>&gt;<br class=3D""><b =
class=3D"">Cc:</b><span class=3D"apple-converted-space">&nbsp;</span>LAMPS=
 &lt;<a href=3D"mailto:spasm@ietf.org" target=3D"_blank" style=3D"color: =
blue; text-decoration: underline;" class=3D"">spasm@ietf.org</a>&gt;<br =
class=3D""><b class=3D"">Subject:</b><span =
class=3D"apple-converted-space">&nbsp;</span>Re: [lamps] Call for =
adoption of draft-housley-lamps-3g-nftypes<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div></div><div class=3D""><div =
style=3D"border: 1pt solid rgb(156, 101, 0); padding: 2pt;" =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif; line-height: 12pt; =
background-color: rgb(255, 235, 156);" class=3D""><b class=3D""><span =
style=3D"font-size: 10pt; color: rgb(156, 101, 0);" =
class=3D"">CAUTION:</span></b><span class=3D"apple-converted-space"><span =
style=3D"font-size: 10pt;" class=3D"">&nbsp;</span></span><span =
style=3D"font-size: 10pt;" class=3D"">External Sender - Be cautious when =
clicking links or opening attachments. Please email<span =
class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"mailto:InfoSec@keyfactor.com" target=3D"_blank" style=3D"color: =
blue; text-decoration: underline;" =
class=3D"">InfoSec@keyfactor.com</a><span =
class=3D"apple-converted-space">&nbsp;</span>with any =
questions.</span><o:p class=3D""></o:p></div></div></div></div><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">Hi =
Russ,<o:p class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Please see inline<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">On Mon, 8 Aug 2022 at =
21:01, Russ Housley &lt;<a href=3D"mailto:housley@vigilsec.com" =
target=3D"_blank" style=3D"color: blue; text-decoration: underline;" =
class=3D"">housley@vigilsec.com</a>&gt; wrote:<o:p =
class=3D""></o:p></div></div></div></div><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">Tiru:<o:p =
class=3D""></o:p></div></div></div><div class=3D""><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt;" class=3D""><div =
class=3D""><div class=3D""><div class=3D""><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">1. Yes, this is a good =
topic to expand the Security Considerations.<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">2. This seems pretty =
obvious to me, but I will think about a sentence or two for a more =
complete explanation.<o:p =
class=3D""></o:p></div></div></div></div></div></blockquote><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Thanks. You may want to =
also discuss the privacy and security implications of using NFType in =
the certificate extension for RBAC. For example (1) If TLS 1.2 is used =
by network functions, pervasive monitoring is possible for an attacker =
to identify the NFTypes visible in the TLS handshake and can potentially =
target a specific NFType (e.g., subject to DDoS or launch a targeted =
attack). (3) Misuse of NFType to gain additional privileges&nbsp;and =
what are the potential remediation techniques ?&nbsp;<o:p =
class=3D""></o:p></div></div></div></div></div></div></div></blockquote><d=
iv class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">Yes, the certificate is plaintext when =
TLS 1.2 is used, and it it encrypted when TLS 1.3 or IKEv2 is used.<o:p =
class=3D""></o:p></div></div></div></div></div></blockquote><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">In TLS 1.3 (without =
encrypted client hello), SNI will not be encrypted and it is possible =
for an attacker to get the certificate content from certificate =
transparency logs to identify the NFTypes associated with the FQDN.<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">I'm not sure what you mean =
about misuse of the NFType.&nbsp; Are you talking about the trusted CA =
putting the wrong NFType in the certificate?<o:p =
class=3D""></o:p></div></div></div></div></div></blockquote><div =
class=3D""><div class=3D""><div class=3D""><div style=3D"margin: 0cm; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">No, trusted CA may not =
inject a wrong NFType and it can be validated by the network function =
sending the CSR to the CA.&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">I meant the NFTypes and =
FQDN of network functions will be available in the certificate =
transparency logs. It exposes the internal/external network functions =
details to anyone on the Internet. It may also be possible for an =
internal attacker to host a malicious network function and misuse the =
NFType to gain additional privileges.<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Cheers,<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">-Tiru&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><blockquote =
style=3D"border-style: none none none solid; border-left-width: 1pt; =
border-left-color: rgb(204, 204, 204); padding: 0cm 0cm 0cm 6pt; margin: =
5pt 0cm 5pt 4.8pt;" class=3D""><div class=3D""><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div></div></div><div class=3D""><div =
class=3D""><div class=3D""><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D"">Russ<o:p =
class=3D""></o:p></div></div></div></div></div></blockquote></div></div></=
div></div></div></blockquote></div></div></div></blockquote></div><div =
class=3D""><div style=3D"margin: 0cm; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D"">&nbsp;<o:p =
class=3D""></o:p></div></div><div style=3D"margin: 0cm; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span style=3D"font-size: =
9pt; font-family: Helvetica, sans-serif;" =
class=3D"">_______________________________________________<br =
class=3D"">Spasm mailing list<br class=3D""></span><a =
href=3D"mailto:Spasm@ietf.org" style=3D"color: blue; text-decoration: =
underline;" class=3D""><span style=3D"font-size: 9pt; font-family: =
Helvetica, sans-serif;" class=3D"">Spasm@ietf.org</span></a><span =
style=3D"font-size: 9pt; font-family: Helvetica, sans-serif;" =
class=3D""><br class=3D""></span><a =
href=3D"https://www.ietf.org/mailman/listinfo/spasm" style=3D"color: =
blue; text-decoration: underline;" class=3D""><span style=3D"font-size: =
9pt; font-family: Helvetica, sans-serif;" =
class=3D"">https://www.ietf.org/mailman/listinfo/spasm</span></a></div></d=
iv></blockquote></div></div></div></div></blockquote></div><br =
class=3D""></div></body></html>=

--Apple-Mail=_6670C42B-8846-4BDD-B38E-64178F01F0AF--

