Re: [lamps] draft-ietf-lamps-rfc4210bis was: Re: WG Last Call: draft-ietf-lamps-x509-policy-graph-01

"Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com> Mon, 11 December 2023 07:22 UTC

Return-Path: <hendrik.brockhaus@siemens.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44C1AC14F5F6 for <spasm@ietfa.amsl.com>; Sun, 10 Dec 2023 23:22:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2tvvK3rLf13y for <spasm@ietfa.amsl.com>; Sun, 10 Dec 2023 23:22:02 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2052.outbound.protection.outlook.com [40.107.20.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EFAF2C14E513 for <spasm@ietf.org>; Sun, 10 Dec 2023 23:22:01 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=apRnAaZaw2dVys07CdxkLxTR2j/rhoF1nM3lZCwMLUQsUg/Ku7Rm5Y2lzsVPYh62t0iFXHTLwIJvQIDJvHmfMlgmdqbTikAe4mJopbxZPwID+i5u8oMrCgUW8pWwRdMMSMx2WrRa8rvVE/T27uVBETibRm20ub9v9irPoxzTe5YIogAOkD4QTvJqEQ+0KaC1DHwKf9kBWgpRnJQ7luAwLvIYzv3f2iHxXD09Tporn5SpC4bMiKw3Udnb8Wmle0oOZtZLncvWV0ac2+4abYUaA/cDrKzZt1QgBDgBQJl287HbimcLPZPrQtLBLaLeUppVEk2JHtcXKXVa6gW0S7eyqQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SHKuxMyWtkqu0dVpWyS/HTD06oTOUSWuq3fZacnJylM=; b=BubWBq3UTNugprhAEPGglxIAT/CIwKF9MELdw60Qh/BkkXosnvcQfXwLqwp7KYTBEg1k5ClTM+37RvZ8QIhDZ0AB5Lu6PNhKhpj1zR8b+UbTkcuU/4sfNsBLjzZ1i/p4EMYa4GTL4cdLoqBnVdD3cE7lWMNyu2v2ydGcMfpo1pZKiC5FxugUGsGfgLwOFJVRZex4Cz/zmBmf/Dcsz1XOWQndHx1ybgqjHnCxM5f+W7iwyvkWAzuLnTC6tdvaM6cO50rXks6bqkrNDD2j/USpQV1RTUy8A3ilRdQo+Ibg7WIyNoVqM2pyiu+Vr7ab6DGwUWYrkA6agZHp8+8JAoBdAg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SHKuxMyWtkqu0dVpWyS/HTD06oTOUSWuq3fZacnJylM=; b=NibIqBUvamKDmGWJS2o4Vs9Q2cT+p7/3YfPJPo4YI1T9tnjHscA5/3xmKb8EBR0lSbkuX115sobkF3iKYUDEzSMRtq8O2Ayw8AY7ytN6j4HBgCk8orR+IpBfC2sO63ic2ziSNNZvQS30+wrpFi0Mnup2HX2qp+PmR6T9p0LE4kJ9heCThXXLZe6Hl2XoZeVbRNa2dal8H+wNJPvqVJ3THmih5JEUOLsHDZmxUUiVYHTC6RgNSyRELLcRnQfhyd4b1jt51Vm12X4fHfqC17a1dwLIsg6obfDm7iHX4WhHY89Jam82MHNei38l5GMvpaRSL5uisvAanXp8UFth8v9Yvg==
Received: from DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:2ee::5) by DU0PR10MB6629.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:403::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7068.32; Mon, 11 Dec 2023 07:21:59 +0000
Received: from DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM ([fe80::5d5e:4a77:9a61:89d2]) by DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM ([fe80::5d5e:4a77:9a61:89d2%7]) with mapi id 15.20.7068.029; Mon, 11 Dec 2023 07:21:59 +0000
From: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
To: Michael StJohns <msj@nthpermutation.com>, Russ Housley <housley@vigilsec.com>
CC: LAMPS <spasm@ietf.org>
Thread-Topic: [lamps] draft-ietf-lamps-rfc4210bis was: Re: WG Last Call: draft-ietf-lamps-x509-policy-graph-01
Thread-Index: AQHaKuoqWKBxthK6Iku2/A9KzmT/mLCjrUOw
Date: Mon, 11 Dec 2023 07:21:59 +0000
Message-ID: <DB9PR10MB571578EC6E7A86F55ACA66C5FE8FA@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM>
References: <99DEDEBF-35D7-4EE5-BABF-63A9F6D02C29@vigilsec.com> <3EEC4C31-31E2-462C-BB82-010F17E996A0@vigilsec.com> <3931a166-c465-4861-8101-50ebadb99a21@nthpermutation.com> <4CEF723E-614F-446A-8D80-EC63AF07C8F5@vigilsec.com> <d66f65e1-0119-46a0-8764-29fc65f63e75@nthpermutation.com> <801C3122-0410-426E-BFB8-F269CA1DA9D9@vigilsec.com> <73092f78-ba01-4709-9e39-7658e300e788@nthpermutation.com> <FBBC550B-257A-4189-84AA-E6493EC008F2@vigilsec.com> <3ae04ff9-7ad5-40fb-8552-832a3a43847b@nthpermutation.com> <F070F503-DE63-4E86-A2AA-BB77CC618F90@vigilsec.com> <53b35103-eff1-43f4-9a11-d7ed9b9771c2@nthpermutation.com>
In-Reply-To: <53b35103-eff1-43f4-9a11-d7ed9b9771c2@nthpermutation.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=6fab3a56-0d8c-4c3b-b3bd-ab56f7de0181; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2023-12-11T07:13:31Z; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DB9PR10MB5715:EE_|DU0PR10MB6629:EE_
x-ms-office365-filtering-correlation-id: 3a40e5db-d545-48cb-7eb6-08dbfa19dcf7
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: QjEH5tID1I6NEVzTBiiMK83d2eYBFM6a32riaaWTmGS1IwSk9YqQzhqekpZ1rQbqHvhWE7m1JnyUyziqeY83eSh6TQsc2y+YBffFWo4Rq8yUZAohDI+ClcsHgeUCnzpqzvejCeOEtKNY9bYvGdCjUEQlOy/C+cAIKPxetYk952InSHwT/+KXroHH7tU1L25gIzQnqpivzgsoY6yXtoLThHOkFLjoGZJ+UGejAOEv5WuLSNqmjF/juchP7P0IiBGJhv1mSMG1XpjFtquIMPBGZyhOL6u/ZZICGzoUI3knG/ssDZZnYE70UIBgvhZyTo16/JvQLH/RUlduN/ZtgH8xCYA3b9HoFHlFxz3svPSoz/Adt8kO4J/4MNLQgTgDWplnX6MbeJ8AmADsCCBgTkRoiIugBk6bG5ISGDMcTHwsptsuxhxrgqcl1jRH7gVRc8wk/FnB2y7H4Wl3h1q1OPaRXw95k/3djEoGzBu9XTmZRZygikxdyEKXD+bHW1nIUfYnRgzXyFNDDANXRqjwlj+lmtRFd3yGsTM/diMJoC8PxBReJoTNRy5XSNS5SAhjWzhul/Bs4ZT33THMD8l174gXFYtm/Ks6hZzf+SuZaQaPncs=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(39860400002)(366004)(376002)(346002)(396003)(136003)(230922051799003)(186009)(1800799012)(451199024)(64100799003)(66899024)(55016003)(478600001)(53546011)(26005)(71200400001)(6506007)(966005)(7696005)(9686003)(166002)(82960400001)(38070700009)(38100700002)(122000001)(86362001)(33656002)(41300700001)(5660300002)(76116006)(66476007)(64756008)(66446008)(2906002)(83380400001)(66946007)(110136005)(52536014)(4326008)(316002)(8676002)(8936002)(66556008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EuSaVtwmtKdr9fXTcOvFf9GXWm1H/hfNw5iBfZTsWoSujdRHXB1+smlL5ZipeHbbrOS8pCHP3yUpDoADeU0v0tm7K7x1xsqsh6OLrXC2rMm56Z7fEj2FhFALXKEDk/89UGnwJBk/47DxuVNOXmu8NMLfWX3kYJvvFpM/vSNBDDy7uIeKDwP730yFriTQpi6ZfTK8PzDs0kbqLpqc82oRGEg9RlYUPm/F7JBYQiuy1Kj36rs7F+JDMPuNlc9JDp64fPZDGJhFNhQqt3Yc6PPh+iXV6ohbeqVj+JLlGLrXLRrM9Ka48XcEXlbuqAluZ1OUPnyXEo3QANBP8M/8LleyFvoWENHkc80+ZjdcOFQrBLOB6AL2yntZZNQ3qpQu3vsPbeli1sG3Ep+UUONGFsKb67E1teRtDwxFXqyU1iB3SI3A+OlG4Y6BcOq/jzOUMzLsl6rv1b1wT6MQ9hKA5hUi/tY1T6Gdx04ASzXFjaeucgCFyVGhd4bSiVBLHJ7lhrfWs746bNNFhzanfGLFcZK+yNdjhX4rpUWRxAhg6zLf5NKJ0eeWA/0eBWPsEMHBGp2nY2OGwr8mpXPFbCjJ2OHAUC1oBqgBRw8YYR1LvmWOnqYewd5+2RD3VIJWWiGH5rXkSAe/M5tlwi/qrWg2Le/NeeDiTBLvJ/CSJxK5ZnpDObapLe9EJH6ocQbwDdu/IhsFaD/g3DLNIHr8dMplgUP8Lg0D9vZfd/sqMNAPguKc+7Kx4KeyFMGVoyWwHDHEuYg1hGNTN1r78GFoMCXSpU5pSpJFibOSTKZpY8Aa7ZPo0BS2mDIKb0MPyjqGWjjS+8ticvLwkS/hzea0V02x2uwF/sfC3voCspDAvA9RJHn1fXYiYCj2jwh8nyXz9x7DSLFKQBAmPOys0RROEdyHRoDv8tmusIWsu+lrs9m/xYi5VNKDYhX1UiNggVbLY3jhacGjgw1e/R35WvvKrzmx2VlSJOksqMc3xeUwlzarTCaAjoyzzylPwPsDrkQatItnpfk9vOy9mBPRhGBJCBNYjbKLj2JkFiHuUQawIx0TmJ1kF3bA0mT6s+7RObxXwBSxxA8qYWJ97uCtZurV4HmzmI1NTRvmf4uYX6DRGR8NHrzP6sytaHxeQvJ5PXSZv5+aZY0OYkNmXPb6dYYi0IkFtjNGEYiaZPTFvR0Gp+VQKxLZPinsTxq1JOdjga/EknFbw1n+ENlhFL0iyvVU9PltAlJ2JuEY5kYfHP79tzC9kWj9QY7j7dOBvl9rIxqmaMnckiHCTG3e1TehxySMGJO64+fOR4G9OqJkhTioLeB7RMqHBPMd33r/tdKiiV9Zd+lQwnUMyc7e3kIGRR9n9/aVFoZK6fRxuCDxJssCrTiEmzaFTKOkHipGF+kRwKOmHtEugoxTbC5bzvi12EKBIY4gk3URxaXDj+uuDqw9JWb2g8a6yl0Obmc56d6iljGJozqRyGGqyhLuywN1KEFKKnUaood8j1QFxdAmDZRxJgz4TUd+I8nHH11wB1wxCoSCBhZv0ldwLaZJviyKlqE1/5HoxgyRrE9ga0/J/emoPVI7/MtOkd7En3nuXYZ0NMR0jezMTY429qTYmksNoImqVkWCnKJ8QQ==
Content-Type: multipart/alternative; boundary="_000_DB9PR10MB571578EC6E7A86F55ACA66C5FE8FADB9PR10MB5715EURP_"
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 3a40e5db-d545-48cb-7eb6-08dbfa19dcf7
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Dec 2023 07:21:59.0831 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: om8JyN9etPeI6XBEfgl12iocWCth8oSb6uuw7LmRr+7wphJE6vS2CWn+v++0ONhyWXuhXYW7EBRViK8vqomnzx17ABfYu1dQZj/Zcuz4nyI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0PR10MB6629
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/sF8yuB3uMDZ2ykAXGdPL2LeMrx8>
Subject: Re: [lamps] draft-ietf-lamps-rfc4210bis was: Re: WG Last Call: draft-ietf-lamps-x509-policy-graph-01
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Dec 2023 07:22:06 -0000

Mike

Thank you for pointing this out. I was also thinking about how to best express this.
My understanding is that 4210bis obsoletes 4210 and 9480 and updates 5912. In parallel 6712bis obsoletes 6712 and 9480.
I am preparing updated versions of both -bis drafts on https://github.com/lamps-wg/cmp-updates/ reflecting the released documents RFC9480 - RFC9483.
I am currently following the discussion on cms-kemri regarding the KDF input as is may also affect the specification of KEM-based message protection in 4210bis Section 5.1.3.4.

As always, any feedback or proposal are welcome.

Hendrik

Von: Spasm <spasm-bounces@ietf.org> Im Auftrag von Michael StJohns
Gesendet: Samstag, 9. Dezember 2023 22:53
An: Russ Housley <housley@vigilsec.com>
Cc: LAMPS <spasm@ietf.org>
Betreff: [lamps] draft-ietf-lamps-rfc4210bis was: Re: WG Last Call: draft-ietf-lamps-x509-policy-graph-01

Thanks for the changes in the write up.  Comment below.


On 12/9/2023 4:19 PM, Russ Housley wrote:

Mike:



On 12/8/2023 2:56 PM, Russ Housley wrote:

I didn't actually notice that one at the time - now RFC 9480. But what a mess.   I see that there is a RFC4210bis  document in progress (https://datatracker.ietf.org/doc/draft-ietf-lamps-rfc4210bis/) and not one for 4211 - is that the one you meant?  I also see that the 4210bis document is missing an Obsoletes RFC9480 tag, except it can't have one because RFC9480 updates multiple documents... I'm not seeing this as a shining example of what to do....  the only saving grace is that the referenced document here  is only cutting and pasting  a single upstream document.



Yes, I meant RFC 4210.



RFC 4210 is updated by RFC 6712, RFC 9480, and RFC9481.  rfc4210bis should obsolete RFC 4210 and RFC 9480.



Except that RFC9480 doesn't just update RFC 4210. It also updates RFC 5912 and RFC 6712. If you obsolete 9480, what does that mean for the changes marked within that document that apply to 5912 and 6712? Generally "Obsolete" in RFC speak means "completely replaced", but the 4210bis document doesn't completely replace RFC9480.

Can a document be "Updated By" a second document that's marked as Obsolete?

As I said - this looks like a mess.

Mike