Re: [lamps] Éric Vyncke's No Objection on draft-ietf-lamps-samples-07: (with COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Thu, 03 February 2022 06:50 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F40243A1F45; Wed, 2 Feb 2022 22:50:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.596
X-Spam-Level:
X-Spam-Status: No, score=-14.596 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=e4gdeOnx; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=EGR8rPnD
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wNorzWNF5QiD; Wed, 2 Feb 2022 22:50:38 -0800 (PST)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 024A73A1F3F; Wed, 2 Feb 2022 22:50:35 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3142; q=dns/txt; s=iport; t=1643871037; x=1645080637; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=jrGk/BXk0JwdIMUofXGO9M2b31NBz4WzQgub0TFcvgY=; b=e4gdeOnx1yTxVIZXjDFx5IRNDpsidXo74eSiwbRD2OVCg58ev6sAoLoD kEEnGVVS4e7cX2fFIng3QZJcCuNeK5hNXhDFtfoGO2fCAGipdnhjXv81C jq6GoOjU/w5TZQl/JNo0p7C85ZIrS91eXi1qipQ+Rg8kaGuKiw7S4br7m U=;
IronPort-PHdr: A9a23:SmK4ixKt+uTCjB4zodmcuWEyDhhOgF28FgIW659yjbVIf+zj+pn5J0XQ6L1ri0OBRoTU7f9Iyo+0+6DtUGAN+9CN5XYFdpEfWxoMk85DmQsmDYaMAlH6K/i/aSs8EYxCWVZp8mv9P1JSHZP1ZkbZpTu56jtBcig=
IronPort-Data: A9a23:RFMIOKlGtW5wHZ7TBE5y0+Po5gwsJERdPkR7XQ2eYbSJt1+Wr1GztxIZWTvVOP2JYTD3c9wnO4qzp0IB6sXVn4RrTAVq+3o1RFtH+JHPbTi7wugcHM8zwvUuxyuL1u1GAjX7BJ1yHi+0SiuFaOC79yEmjfjQH9IQNcadUsxPbV48IMseoUoLd94R2uaEsPDha++/kYqaT/73YDdJ7wVJ3lc8sMpvnv/AUMPa41v0tnRmDRxCUcS3e3M9VPrzLonpR5f0rxU9IwK0ewrD5OnREmLx5RwhDJaulaz2NxdMSb/JNg/IgX1TM0SgqkEd/WppjeBqb7xFNBw/Zzahx7idzP1Aq422QgQkFqbNg+8aFRJfFkmSOIUXqOWceybg4Jf7I0ruNiGEL+9VJF03OMsY/eJzDGtD+P8wJDECbxuOnf7wy7W+IsFsgdk4KMT6FJ0etXBk1jzSS/0hRPjrT7/D68Md3TosiIVKFPPGfI8CYD93aBnbSxxCJllRD4gx9M+sj3znaHhTqFuUv7Ef4mXPwkp2yreFGMHNc8ePbcRYgkjeoXjJl0z4DwoVHN2S1TTD9Wij7sfDnizTVoMcCL248eRxjViawCoVBQF+aLcRiZFVkWakUN5ZbkcT4Cdr9+459VegSZ/2WBjQnZJNhTZEM/I4LgHwwFvlJnLo3juk
IronPort-HdrOrdr: A9a23:ZB4G36kh6eJOEMZNFWx6A8NmdfvpDfN8iWdD5ihNYBxZY6Wkfp+V/cjzhCWbtN9OYh4dcIi7Sda9qXO1z+8T3WGIVY3SHDUOy1HYUr2KirGSgAEIeheOt9K1sJ0BT0EQMqyKMbEXt7ee3OD8Kadd/DDlytHruQ699QYWcegCUcgJhG0VZnf5Yy9LrUt9dOcE/fGnl6x6Tk+bCAwqh7OAdwA4tob41rn2vaOjRSRDKw8s6QGIgz/twqX9CQKk0hAXVC4K6as+8EDe+jaJo5mLgrWe8FvxxmXT55NZlJ/K0d1YHvGBjcATN3HFlhuoXoJ8QLeP1QpF5N1HqWxa1+UkkS1QZvib2EmhJl1dZiGdgDUI5QxerUMKD2Xo20cL7/aJGQ7SQPAx9L6xOiGpm3bI+usMjJ6iGwmixsRq5dSqplWj2zGAbWAZqqL/y0BS4tI7njhRV5ATZ6RWqpFa9ERJEI0YFCa/84w/FvJyZfusqMq+XGnqJUwxhFMfjeBEn05DaCuuUwwHoIiYwjJWlHd2ww8Rw9EehG4J8NY4R4Nf7+rJP6x0nPUWJ/VmI55VFaMEW4+6G2bNSRXDPCabJknmDrgOPzbIp4Ts6Ls46em2cNgDzYc0mp7GTFRE3FRCNH7GGImLxtlG4xrNSGKyUXDkzdxf/YFwvvnmSL/iIUS4ORsTegub0r0i6+HgKoKO0aNtcrbexDHVaPN0NiXFKu5vFUU=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D0AQDWHflh/5ldJa1aHQEBAQEJARIBBQUBQIFJBQELAYFRVgeBUTcxhEmDRwOFOYUOgwIDgSmPEYpqglMDVAsBAQENAQFBBAEBhQUCF4NIAiU3Bg4BAgQBAQESAQEFAQEBAgEGBIEJE4VoDYZCAQEBAQIBEhERDAEBNwEPAgEGAhgCAiYCAgIwFQULAgQBDQUigmKCZgMNIQGTAI82AYE6AoofeoExgQGCCAEBBgQEhQ0YgjcJgRAqgw6EHoJbJIQIJxyBSUSBFScMEIJnPoRcgwE3gi6RNXFlBGoYLh4VTiRMkh04gl1GjU6cUwqDRp9dBS6Dcowcl3mFTo4qglIgoQwdhHkCBAIEBQIOAQEGNYFCJoFZcBVlAYI+URkPjiAMFhWDOopedDgCBgEKAQEDCQGCOohLKoE/XQEB
X-IronPort-AV: E=Sophos;i="5.88,333,1635206400"; d="scan'208";a="982326793"
Received: from rcdn-core-2.cisco.com ([173.37.93.153]) by rcdn-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 03 Feb 2022 06:50:34 +0000
Received: from mail.cisco.com (xbe-rcd-003.cisco.com [173.37.102.18]) by rcdn-core-2.cisco.com (8.15.2/8.15.2) with ESMTPS id 2136oYFk029400 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Thu, 3 Feb 2022 06:50:34 GMT
Received: from xfe-rcd-004.cisco.com (173.37.227.252) by xbe-rcd-003.cisco.com (173.37.102.18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Thu, 3 Feb 2022 00:50:33 -0600
Received: from xfe-rcd-005.cisco.com (173.37.227.253) by xfe-rcd-004.cisco.com (173.37.227.252) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14; Thu, 3 Feb 2022 00:50:33 -0600
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (72.163.14.9) by xfe-rcd-005.cisco.com (173.37.227.253) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.986.14 via Frontend Transport; Thu, 3 Feb 2022 00:50:33 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=V4xh0nVo6331IrS8NlJUNTvbCvERnnF4jjtVUir90H2+zWIsDcvrOxIp27hmi1AiDgYHfDuXXsvC2RC4vajYPaKakEqx3wglHWGwnIa6KGz1VKBmcwZP8+e1BmPu65Av9Ytry/Xz5BwCjFDdkGEU9xdmTNwQ5Qt1ZVzLVr/MKhryLh0LNX3YMSp7yWG8UZ7i6TZjaYA3KnuJGf1zfdErb9aJy6wIZKl0DSeNaZavT/1W3JgL/9xc3go2h3P4cg4Ca/McPe01SKvDdIyQatwnBqGHswLbDL4DxmOx2Q/wvprUYeSRhsNtRPRNYeeFW3RG48IrKre/WRRUUe8BWzjaqg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=jrGk/BXk0JwdIMUofXGO9M2b31NBz4WzQgub0TFcvgY=; b=JJ14cz/t9TDcVO0vUZzFuMQ5ULIMHKK+GD12/BH25/dl2UEbrfukk/hU1e0V1mXu7TgekmpzbZFFl0h0bmeKQ0w0cyjUnjg1vlMIWXqbjxas1QSdD/JgJymGQJHcEIYQ3kt2S4oSxboA3y+4H0ZDwwrBzDa+F6YlYRmmI/1L3xzqsAfWqeXH10gMHq4DA3Lu2xq0G2Jd6Mid3LdaUt3OiMr0Ub3fCOcqZ2VWZSxyYxiLKDrAFDd11w6RW+dIOsxqQ27mYHqq1Ucpczg/P5SoFEnwYoOV+LQWB8qxaTaZ+b2s6Zhr3Nk+ClBbKik9TbhwSkV66Kkpt/3Yr4Q1lD2bCQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jrGk/BXk0JwdIMUofXGO9M2b31NBz4WzQgub0TFcvgY=; b=EGR8rPnD+u2SrhFXk2sUsaqi7XoN03Wam11w3zjDNwQ71UImU3N4OdVUZ2OkxpE+ocCV6BFCBMrfRSpa2OcQadyXaMf+FvVZEQ4t2qRkagyLfjgOgm6I5H+PlcdVxdv9uWwWl9e7r4fJiDfibKlBqzvkEuyyvGf3H6mujEFbT0w=
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by DM6PR11MB3417.namprd11.prod.outlook.com (2603:10b6:5:68::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4951.11; Thu, 3 Feb 2022 06:50:31 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::143c:310d:4a0:ce8c]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::143c:310d:4a0:ce8c%3]) with mapi id 15.20.4951.012; Thu, 3 Feb 2022 06:50:31 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, The IESG <iesg@ietf.org>
CC: "spasm@ietf.org" <spasm@ietf.org>, "lamps-chairs@ietf.org" <lamps-chairs@ietf.org>, "draft-ietf-lamps-samples@ietf.org" <draft-ietf-lamps-samples@ietf.org>, "housley@vigilsec.com" <housley@vigilsec.com>, "tim.hollebeek@digicert.com" <tim.hollebeek@digicert.com>
Thread-Topic: [lamps] Éric Vyncke's No Objection on draft-ietf-lamps-samples-07: (with COMMENT)
Thread-Index: AQHYGHeIZeQ3//hHUUqf58Yq8LPs+6yBdH4A
Date: Thu, 03 Feb 2022 06:50:31 +0000
Message-ID: <8B42E5BF-4317-4FDA-A932-FCC4AA082DC7@cisco.com>
References: <164121362047.8756.3046187711723091521@ietfa.amsl.com> <87iltxm232.fsf@fifthhorseman.net>
In-Reply-To: <87iltxm232.fsf@fifthhorseman.net>
Accept-Language: fr-BE, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.57.22011101
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 54839f34-5bae-4283-f7eb-08d9e6e17886
x-ms-traffictypediagnostic: DM6PR11MB3417:EE_
x-microsoft-antispam-prvs: <DM6PR11MB3417412A45F4C295E4CC608AA9289@DM6PR11MB3417.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: gQg5rCYPvoQNcTa9pLKH+/BhdH9+qvy8SbUE9T0Qb0MvJT8zdAu0JHkOZTXfb6A45Y83r+PV+HFzzwHpxwroXIbH5E9uDGcb1ceClL4cbCc1SDkxcr087q2S6N/rcq3tAAntOiOD2Bt8Lt1dM1D0aJTyYqZ5SpeOqN5E+CZ+QcsmEbwmAxbcjhGLEjJ5bnLhIR2sBIfk2S99Aho7wM3siXV1o2VC+aaSjfT5VOnqohEbZNY0q9HvU2royUDJ/XfqSGIt6fk7A39UKAvGcUoTzx7b6+VVWXhDL2t0SIlw/9xcvER5efGUmK7GomogYltn/Kn/Twmzciz4NHawB9O3oh9hqbVw2uII0EznlrJk5HBRfMsQb2JjAXK2QoH5HBCwTwJEJ8hNkzTc1D9qgfmnsEKMkMppgtjQv8RR2pDo4KPHPdtxIfSQwzx2Y6KiC+F2vI9h89mHoRXr24WLbQI1z1KzbgIM5xIM9z/EiKOJ6WL7CxFvVnBOa97yBr3VzfuvR5DhBwUEWwLjJCsnWTfmIokpDVzAapxxYzz+stpR8pqPQQz1qf/pMibEtDF6L9kqfva6eU2mKpwoioD2rigsuQLZUkEFnLzBNC6fFaSq8y9b9zpIBfJaRG+UN08wxEq+0m1wzGHHUZv3qsucfDWVIjHuTK2W3HxnMNJyTc+7kVqmd0VE0bkukU/i8Ns2QJWyB/xc7d7v55mhDrsqGaTT6sU1QdDLDDLS/EfwCPuqk0FIKurUI+D+CrNcdIgrWmhh
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB4966.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(366004)(8936002)(64756008)(66446008)(66476007)(66946007)(66556008)(86362001)(4326008)(122000001)(5660300002)(91956017)(76116006)(54906003)(110136005)(38070700005)(316002)(2906002)(2616005)(38100700002)(66574015)(6506007)(33656002)(186003)(71200400001)(6486002)(83380400001)(224303003)(508600001)(36756003)(6512007)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 2OIWxaHYg7Dp9/WhzAkCEJAUELtWzmrjqMH9TLO6xYJdrT0IoL7PtNPtgKe7/d7RxGZn86lRvlajTFH2saAuGnxlgVWx57WvMkUmPZyZtzX9XanAiVHZB3VBv2oHnW3ExdVp7/g1Hj9HJHV1mzMYQ9TXl+wV/Ps7h/UmQmWLUD6b+PtQK+dnk/DwHQiPzX5IDoEKaVqfPoExRSHfHbkEtXr9v9+OJGKg6L2viryiRtq9yA5uz84BEGP0rvJarDWbsWujKmrm5PuySw2CoBPnKJ6axhAjsVuKBDc9I1Zvwu+ecEDGFZM+VrvZgEoG5S/072zgVycBHcYqEAufAF1F9z8RfxMsxLkcgNAWw57CE365BoOkD+GC+KugEUarToujWgQ6CYdWhzz27dg5L0Mvw5INDjS7qLGmGmGH4hyePWoe79pZ6fDfz4UzUAXo5uRTkabySdZiu2PRmldBfWIq4RXPc7fKj8lKELZIQJ8ZP6hy8yJuk3dvtKMOmyyw7FdSn+uyYmMDQJsaJVmgGp8JYokhwmZtM+uiDTPsQV9TusvD75TzmFvnk/9wMriO9ZcGWba50foJahRty+bflbnUsB18+qo9lysWfgUbaMDb3Ooneb74wvvbGjTCjbf8po1S7nMjiIj7AM7VFPoqKyAT1NF59Hkd5oyHZdYCqMtRsPEfvf/m4X7kDuqleUauHoGwjx8Y+kwT2OebgWdeMM2HNtPZkxfgegzW5PzJt7gusrG6ZXwFFEk/gneJskTG5S00cyaFNKOAsXAqkQnCRmHyXfCPgeJC3wWkOJu9hKmwqjzlbOWWS60CX/j2oOwZdB2dXEYpCZGFxE4p645nmYAPVp4imP4Z5z21XWk4gyRrH3JbxjG9VFhQUJ6cilDMOg/5lxmYvq1q9TOyOoyk0Lpeb0aq6qcaAuTfW7PxAzBAIbtBA5E9Zrnrpg3WpEteCkm7TEF39ZKTroBZyueifTBCwHTrQ1j8Ll+Ga8bANmIz/Vaa6lIPlmretAIck+2HMGWj2/mVuwgjKpjVzo7K8Fr+c0R45o5XsMTmZ+kUCyKVNLCy00Ib2H1XlGdSV3Xz20AMO27N3H7vBUinBDgO/QvVo9rmdWnDOz4+9jHvtSpSBrD0chl9L1VS4JyK4SoEbDzrKOXsWDUt+EptnpeCOl0/3XZxnp3ve01dK3g3V5SrCFuJe6OcKvgH1amO+FlsIgS78tvtNs3gKbpht0yU+BA92CfmnDb2o13wP1BnfHa2cWzxwRl1kvOHjSRKig6qpN8pM70cgwVelqwTmmCNHKmftIJEWUC1BYseTG6kc33PKKCp6M2qw/DhnW9mvHjqOc6YpJSgsedrdK6m4YuseaeyFpW6yNodJDB+HnITR3Ncie8SBwcZIuXTRauD1a37EOzZReiJy10C0TIG6DjOnlja1/OUMziVRZJfSVIxoztQLCQdwsTV7bTnctf93HIt6G5tPGzg+5TVaR3tlCzd+M2nvVTziTBxnxkaIABgM5LnUII//pgYPIu5T25XfRmwi0apDHA7xkSLKMl1YXMsSxlmW0Ztv433eZFnhWy3OVNU3TPXW1iZYv8G2AFiG9TXtvF6b2kcLYr/GvRBvb4od/qhax7px6ssFn631tLRlrwqATJ98O70Fdg9lhu1jUYTlqJNEY+/3QHiMuSdff89ITahRzHhi75BAZuCdGIkdjAp5UY=
Content-Type: text/plain; charset="utf-8"
Content-ID: <4D7D1F84A66FE140A8D640A1BDF3B50D@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 54839f34-5bae-4283-f7eb-08d9e6e17886
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Feb 2022 06:50:31.2527 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: MLjZcpVhBNZCsiASW39/hacVi1xPkwfHace0YTZrr4UrOyVPlAe5cqzntMDoW/r1hWA5HqV/aV2xrbAjg6g4RA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR11MB3417
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.18, xbe-rcd-003.cisco.com
X-Outbound-Node: rcdn-core-2.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/UM88pzqnJq8HLIqWWo7j9_h6gfk>
Subject: Re: [lamps] Éric Vyncke's No Objection on draft-ietf-lamps-samples-07: (with COMMENT)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Feb 2022 06:50:52 -0000

Daniel

Thank you for your reply, it is indeed sensible not to have dozens of invalid certs

Regards

-éric


On 02/02/2022, 21:57, "Daniel Kahn Gillmor" <dkg@fifthhorseman.net> wrote:

    Hi Éric--

    On Mon 2022-01-03 04:40:20 -0800, Éric Vyncke via Datatracker wrote:
    > -- Section 2.2 & 2.3 --
    > Would it be useful to include expired certificates ? 

    This is a great question, and the LAMPS WG did consider it during
    discussion of the draft.  The conclusion that we came to (which i helped
    to drive, as editor) is that there are *many* ways that a certificate
    can be invalid (in general, or for use with S/MIME in particular), and a
    draft that hosts a zoo of invalid certificates would be much larger and
    more complex than this simple document.

    Expiration is one flavor of invalidity, but why not also test missing
    subjectAltName?  or subtly wrong keyUsage or eKU?  or a malformed public
    key?  and so on…  It's kind of like Anna Karenina 😛

    Rather than try to decide (and fight over) what sort of invalid
    certificates to supply in the draft, we decided to stick with just valid
    certs here.

    The certs should be valid for about three decades, so hopefully in that
    time they'll be useful for a lot of different projects.

    > And/or a CRL for those examples ? Would providing those additional
    > examples make possible more extensive testing?

    The certs are expected to be used for testing, and to be used without
    having to maintain any online infrastructure for this testing.

    §2.3 specifically says "none of the certificates include either an OCSP
    indicator or a CRL indicator", so i think including a CRL would just add
    to the confusion.

    If we want to produce samples that expire or can be revoked, i think
    that would be a separate project, similar to the "multiple forms of
    invalidity" described above.

    > -- Section 4 --
    > <joke>Please s/Alice Lovelace/Ada Lovelace/ ;-) </joke> (to be ignored of
    > course but I could not resist) Alas not applicable to Charles/Bob Babbage or
    > Alan/Carlos Turing or Grace/Dana Hopper :-)

    we each nod to the legends in our own peculiar ways :)

       --dkg