Re: [lamps] Comments on CMP Updates, draft-ietf-lamps-rfc4210bis-07

Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com> Fri, 26 January 2024 08:29 UTC

Return-Path: <Tomas.Gustavsson@keyfactor.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE976C15153F for <spasm@ietfa.amsl.com>; Fri, 26 Jan 2024 00:29:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.004
X-Spam-Level:
X-Spam-Status: No, score=-2.004 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=keyfactor.com header.b="i0MYxziW"; dkim=fail (2048-bit key) reason="fail (body has been altered)" header.d=keyfactorinc.onmicrosoft.com header.b="gbYBvHnB"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZuNYb2kYFkQe for <spasm@ietfa.amsl.com>; Fri, 26 Jan 2024 00:29:03 -0800 (PST)
Received: from mx0b-0041f601.pphosted.com (mx0b-0041f601.pphosted.com [148.163.143.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF919C14CE2E for <spasm@ietf.org>; Fri, 26 Jan 2024 00:29:03 -0800 (PST)
Received: from pps.filterd (m0365590.ppops.net [127.0.0.1]) by mx0b-0041f601.pphosted.com (8.17.1.24/8.17.1.24) with ESMTP id 40Q7oaUS026844; Fri, 26 Jan 2024 08:29:02 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=keyfactor.com; h=from:to:cc:subject:date:message-id:references:in-reply-to :content-type:mime-version; s=pps1; bh=b4EVwQ1nQjvWDDdg5NjNy9f5V wFOzAE/1vabX6AE7pA=; b=i0MYxziWR57u+V/hEs/c86G59KeqFKonrZ3/hb92L 3EmUrwyHN08nvmMpUeOuNMl8A4I7ExMmECV534boBu1o2QPvouCxXCzjozy6H9W4 C80nGDWol4cnecpi1yth3b52+VNPZI4aiITtPOaHM0Ho0azNvu4a0hOZZfd7a9Vd dz466Q3tQYrPgW49g0P79f5azv0iSRB7j1tvc/CNKaL0AnPXQ9bY2yW9qly2J6wF ymP15IzkODyemTx2/GntP1+ZatZXk68uQxsBOcbkjLAHQ6Wt8TvpLkCpd/Ys5Muz p6g1f+YdQGsX6kT7FOhhnmDM1mbso4tJ5PI8aUjxG8bYw==
Received: from eur01-ve1-obe.outbound.protection.outlook.com (mail-ve1eur01lp2050.outbound.protection.outlook.com [104.47.1.50]) by mx0b-0041f601.pphosted.com (PPS) with ESMTPS id 3vtmg19ran-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 26 Jan 2024 08:29:02 +0000 (GMT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=gsGfHzD6t1MUHBxEzR2TlZRcoV9TC/iVeprUoaFvuJKtqoIvROopEMW/5sapr5IL/i9wT7NCc5v8oNPLNEY2ecAnBZjkRaLrWvPBta/7d/3vrXvrN7ECPNOa3tqHmh/rP7H4GjpigtEltjzla2/Ps2rEI+MoiQ2m4zuWSwpBHwqMksqhK+YLYtiR1xVhQF1xIALZ2l0V46ZQMCA2UMeFOj5Cl5C9yOox3L4g8NYkzjM/vPIhJTTlo1zq8yaR/xauxf6HGxNndwiU5p7o4nkK9b5sekikU+03y9VN5cb7UIl7blgjPLCZ0ZCYG3eKtcp7LxtQ387TCFwfcEKL1L2WqQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=OMnvAf3dKMneiD96qFBEtucBDLNTyxaOp4J5kjgAPsU=; b=Ow8N/dcFocxp8Tl0cSq4XRmgawJF2/HT3L6620Z65aRXCfZgLAPTviaBxr+9XZTTgQsZRrebBO3XlGKxgAp4o7Dy3xQjR8vI4y9KztVoBAneYs8mOgtZRyjSxy6llG32Bs98OJkBz1yH5edkyv1GVrwL5Aobxz4zlOa652BOjQuVWSJd+n6MHrczzphndk7McaPS8WPGzSfGt4aFYJLi2Wr8Npla77BkOTTHf4tQggBMJ+8LTmzEF2cHH52UBuIBegRmsu80qx56Gb/gVH29hmaBV83RHqTQwyFmA9StlZusRseTreqQsKb75GBRU6l+DGds9RQkiNE/UKDAftT85w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=keyfactor.com; dmarc=pass action=none header.from=keyfactor.com; dkim=pass header.d=keyfactor.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=KeyfactorInc.onmicrosoft.com; s=selector1-KeyfactorInc-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=OMnvAf3dKMneiD96qFBEtucBDLNTyxaOp4J5kjgAPsU=; b=gbYBvHnBL0D0NWR8mKakwV7PmjqafvpUSqJCWO9FSKgDPsRL5tHwmgJRTT/wLb7BttwlUVk0fznzCCaN5aDQsexL7scm6h8fnYJ/akQwgqR52YH3NJduagYECVBndns3zv1wHZdKjTjCEB0iYvvogFo178lRdLC6H3fVzvp//4a5rvYk1WvtYDo8+a4GW2zo49gBy0X9HeVEj6bKF5Db0IibrWVGF1hRrH0ZayMpxX6x812j8zwRoKYbAuvPVOt64HPDkWXA63EWIgYA4WTFXpMZCt40QT3OQODlusXbW8q3JyW0z900Ro3kCo7tH9NGMzuasmHuOBv301lWCPGU5Q==
Received: from DU0PR03MB8696.eurprd03.prod.outlook.com (2603:10a6:10:3ef::5) by DB9PR03MB9856.eurprd03.prod.outlook.com (2603:10a6:10:45c::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7228.26; Fri, 26 Jan 2024 08:23:31 +0000
Received: from DU0PR03MB8696.eurprd03.prod.outlook.com ([fe80::b8c:a1e7:eaca:c408]) by DU0PR03MB8696.eurprd03.prod.outlook.com ([fe80::b8c:a1e7:eaca:c408%7]) with mapi id 15.20.7228.027; Fri, 26 Jan 2024 08:23:31 +0000
From: Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com>
To: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
CC: "spasm@ietf.org" <spasm@ietf.org>
Thread-Topic: Comments on CMP Updates, draft-ietf-lamps-rfc4210bis-07
Thread-Index: AQHaT5edcAvoHWpQFk6Bh7LNDUfcarDqt66wgAEJL4M=
Date: Fri, 26 Jan 2024 08:23:31 +0000
Message-ID: <DU0PR03MB8696C7612DB3DBF0CC343FC386792@DU0PR03MB8696.eurprd03.prod.outlook.com>
References: <DU0PR03MB86969B1265A930380C034B8B867A2@DU0PR03MB8696.eurprd03.prod.outlook.com> <DB9PR10MB571556E9A0F8CD865A947C98FE7A2@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM>
In-Reply-To: <DB9PR10MB571556E9A0F8CD865A947C98FE7A2@DB9PR10MB5715.EURPRD10.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=a3e8344e-aeea-4e3b-a50d-42bdf57d58c4; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2024-01-25T16:27:47Z; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU0PR03MB8696:EE_|DB9PR03MB9856:EE_
x-ms-office365-filtering-correlation-id: 15bdd93b-f565-45e1-c848-08dc1e4814e6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: VtkDzxVgV3mEaxqXwzrKmqF+qWzINvaCjM7Er04H0m+vOme5M77KPEsGz4ykC5oQvTHpKWFsrYIRnj3kidlXrAykOoaiblXU5TXT7lTHWubLylGRDMprFgJe1tE6W0FTrFsGsixvp82vHK6zylIN+Wz476KwElsiSfV962SZcw3etoXKtHEb0BiLgHEhxYe4QI56szzIiNw/VOIHAE/P1nm8wArLlkZIqa+3S1iL42LMzWHQgXRS0peptmCb2nJ60IP/Aqf6RA2i3apEZ9TPGnNAIzOczS2S87vb/k5PFEt5nR30YY7WSAMoE+sIBlF58ygjTejZTQWG9J7bWjb2TeAs0xDRWYLi8w9n2pSNinpEc3bsgdP4n7g3eZ/0j4Rw9+OxF5jpFsXjiN6zBoiZtvKr5rv7g4wETpxiA2kpnU1svM5RRW3229Cr3QeoEM49P9rTTr9pKR9F3es4bXQvxx3UO7bgtqZZEostDUd83tEFUxjyvksNKapIcRJMy5dCUyhxZcCLofXLGWH+pHMM0v+Oi9+Q/XxWiWUDgR0YYdxo61Omi0yv4kMjEzLyPW/xjkzKYE11ZQwZXgBoPE2MJmvxovki4z6BITSfUfGMvLIZg8XN59JiQSyjG/YiKDNOdH6ZwBjrRDykWLG1rZ03Tw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU0PR03MB8696.eurprd03.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(346002)(136003)(366004)(376002)(396003)(39850400004)(230922051799003)(230273577357003)(230173577357003)(451199024)(64100799003)(1800799012)(186009)(2906002)(15650500001)(5660300002)(33656002)(38100700002)(966005)(26005)(86362001)(478600001)(19627235002)(41300700001)(166002)(38070700009)(7696005)(53546011)(83380400001)(6506007)(71200400001)(9686003)(122000001)(316002)(64756008)(6916009)(8936002)(8676002)(52536014)(4326008)(91956017)(66446008)(66476007)(66556008)(66946007)(76116006)(55016003)(19627405001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: l+/6Az2Eqn7LBvseQrcy9xdFMCjg+LYep8pvqKgGMraN2u3QhoYnDirGo0uGudBhfJXRMGn42rR8G7n3cXI8aJvtlLIAcNZJuGPQ0Et4Q42lyEEef3RD1H5ZQKFg07liyyaP+q+H7Zzb4sz7KwT0egvK7IfpE2e2yg6aJAscUQ4FmqREzZSyk4pW2VkpjGmz3QDgr4OaEEWs90h6xmRlmjUpVMRT/5EIDfC/ksTLsvEbdCH98Sw1kMBlQqvi31kxSl/dgDsT42jX6cBeSmq7/TCfcbtgP3p38sRgn6T8LwCJjYCll0jtLYw/9crDeKzXJ8jisRxLUjistO8yMj0TRDhejtnv6QOaYNKZeTPhJRTipIlgZ8UlUjdG3fnJSv8JnanO4ao/O2OWZJZajXpz6Ch1wyVH4MdBGBLuZyfXi6DzkbPYoQ1qLmqsZ7PD+d4qNglomiqRa6zOPT3P/WZJ+Hto2qmqb7JkJyOiu6qpvd8+Ierc7USvpq7Oaw7h20cKPMrGq+3SiJ/4OHduB1og3xqVSn4A8gFcV+dTb7Cy1wlXgI4188RNEpT5nGvfZpa+4CGcyJ1n8dXbRqlTi50j1Bjd3taJv0E+3OYeFQBxbd3EEmeNwGrjaicmeyszs1CvKnWI2O7JH5ADBsl9W2G3DDzMsSP63cED6Ke/vsfU0XjBWAHgT8/MhztBJMEX9WidlJWOownetjSaifiObs24N4OL3HDtH6/2RmcgeP2nT9XQQDCJMc4oFu2VlqROnozKRWAbYRYiFCAmgg4ZcJzJPxA/3Gfzb6laBFk1IMeY5HLamSm4NK7vyL8y3rf1R/YwcpdsOtjfZ3s0JXHQOEEORpiU2padZb3fd1wPhLjAPcBEvCj1NJyINiUeNObDkoRwKVzbkT5qux6oIwidcLBoi/ZpwcsIIZk7XAIW3vKRBFuR7fLRtwXJ2NS5y/iZ+agnePhGWsfN/Oqz9T64b/8DhfTNJmJ6AaFI5B6sYg3ZnJxudyFIrAOTg2dhP8Aw8LDKvvUprbtYb/CiQSrQbgdnWMGyuCCHotVTZ+aMxOJak4vtw+9d9zseKqL7rwtUDj/biqhna3U/A7LJfyPJM0H4RAY3Q0MuTKsOnpvSFK0sbM6eVzR0tt2C2JOyFP3OAnAgigFGUXH5jaOpkh7YbwJv8L8Xqe6hbXifCivxmTOk9JkLJEhbrD9aJ8M9l2yY4CArvYEhG6413A3rzBZZT9chHRmWYTDRDu469rOZA/sAla1ti71pvARjdnGZewjA7INGjbFGwWj6dl71Zs3WGJAW5g9EQanarjo8e8ln21rzsaTv1LgCLmeMWWNp8fJdkqCtasVcgIjpPk45h1TNFJ+p3EKmy8OhfmH6L4I8Jn4eE2hM3Cb+ENXzEt0Hp5Ps0nClLv/nxvC4Gm0jM+CPuzICTFwwiRxlQ+wY5cuBmHvToRErL6bP3sfAGoSMreWYZkwrIj7NtP/dxmku27ax6JMCguhpgGesEBDtQvvMRgXqUIOJbEkXqs9z1duwRFlbXXZCsWseJLFtTR5SMwlWA9Nh9vnfWp02YeY3ezeKjhanfT/W5MlOXLepyJW8MnLugAKp
Content-Type: multipart/alternative; boundary="_000_DU0PR03MB8696C7612DB3DBF0CC343FC386792DU0PR03MB8696eurp_"
MIME-Version: 1.0
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: Mi5aPPCeCA0egWuX08vB0Ikoiku446ZQDrOGWks9bwhyda1A5YesdSbam09s7HOXyZf4Ng2MtXR6HDJ7yhtuQS6MlCrKYA20imXPNMpv2aJQ9AAXAszaXlMzo9Qv2ts4YrE8PSp5KPZlYkDN8Tcg85zp0CDKEEV6Pw65D7PUf7bjWQ+ZRoYCbkZg+qyZZieqmAQ1A1//lNeq10+y6tYq7gvowEo8pB0RH9KxyevyT+3ougWhEsEAS+UpMrlwHd+SdV0Nv8XOZg2gtRdN7RrQIfTAciVEXccMU8YuTzrh6wOt03UIo9kvbZc8izBHqT2mL/VMCztzoVT+hWIQe9Cbjm5EbCVRIKc3ZOpCgF6A7Xh+g6fzZFbm5iw8RW8YPDqBiCVCRuTnWGL6tcREiv1g2OsNfKNW1DjbecS76cLVLhrJvrwugq+9NhSrOg5PB3QhPiqybc5LMtpCzFF18O/G0rPzAu/gKjRXfLl/RO30ilxxetUvk85QAVWX5Re+zXZcl08g2whz3fpyjjlI5WsH4Fj921gjtxUq3AXojCCbPYIMbQ48/yiK+sLSyEjDgKi6VIt0NLfOwBDyP5LmRFrCT5mmM3vwTOV4ZXeJGbcRr7+v+m5k7xJ7XNW7M4OZNt8g
X-OriginatorOrg: keyfactor.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU0PR03MB8696.eurprd03.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 15bdd93b-f565-45e1-c848-08dc1e4814e6
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jan 2024 08:23:31.6443 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: c9ed4b45-9f70-418a-aa58-f04c80848ca9
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 6GM4B7lR97AoEvEdNphB7AyBEy5J/pvyG59wJaM5cUZ+KLSeZiFx8ZuejqoB1JDICmuGG0IsFmucs+j8c85oP9SZe+WR5890YtzaXlkH3co=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR03MB9856
X-Proofpoint-GUID: ClEeSlfajGpodpnb65gBBzGLpcXsG_VL
X-Proofpoint-ORIG-GUID: ClEeSlfajGpodpnb65gBBzGLpcXsG_VL
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1011,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-01-25_14,2024-01-25_01,2023-05-22_02
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/syAIqdzpmWXFMvuzhXclRoKFWtk>
Subject: Re: [lamps] Comments on CMP Updates, draft-ietf-lamps-rfc4210bis-07
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: This is the mail list for the LAMPS Working Group <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 Jan 2024 08:29:08 -0000

Thank you.

Additional: In section 4.3 I think it's good to explicitly call out raVerified POP in a subsection. It is quite commonly used.
It is mentioned in 5.1.1.3 and 5.2.8.4 and deserves a description under 4.3 imho.

Regards,
Tomas


________________________________
From: Brockhaus, Hendrik <hendrik.brockhaus@siemens.com>
Sent: Thursday, January 25, 2024 5:30 PM
To: Tomas Gustavsson <Tomas.Gustavsson@keyfactor.com>
Cc: spasm@ietf.org <spasm@ietf.org>
Subject: AW: Comments on CMP Updates, draft-ietf-lamps-rfc4210bis-07

Hi Tomas Thank you for your feedback. There is still some work ongoing completing the work on rfc4210bis. You can see the latest editor’s copy on github. https: //lamps-wg. github. io/cmp-updates/#go. draft-ietf-lamps-rfc4210bis. html I will


Hi Tomas



Thank you for your feedback.

There is still some work ongoing completing the work on rfc4210bis. You can see the latest editor’s copy on github.

https://lamps-wg.github.io/cmp-updates/#go.draft-ietf-lamps-rfc4210bis.html<https://urldefense.com/v3/__https://lamps-wg.github.io/cmp-updates/*go.draft-ietf-lamps-rfc4210bis.html__;Iw!!BjbSd3t9V7AnTp3tuV-82YaK!wjf3KcqAVljkHXjOHmGMBJfUPsO8NIvzo9Z_LU9ayytZ-YUOP0BoKM4zskjsCOoHw2SapMtyiuwWlo5T8LMZgmHhHfcuUJlT7vwV$>



I will respond to your comments in detail later.



Hendrik



Von: Spasm <spasm-bounces@ietf.org> Im Auftrag von Tomas Gustavsson
Gesendet: Donnerstag, 25. Januar 2024 15:49
An: spasm@ietf.org
Betreff: [lamps] Comments on CMP Updates, draft-ietf-lamps-rfc4210bis-07



Hi,



I'm not sure how much work is currently going on on this draft? I started reading it and have a bunch of comments. Perhaps it's being thought of already, but posting it here if anyone is interested.

I acknowledge that updating CMP, to something that includes new things like KEMs, and yet makes CMP easier to use and deploy on scale, is a truly monumentous task.



Here some points for discussion after reading through parts of the draft.



  1.  Section 4.2.2.1 describes it as mandatory that the CA can send a CMP message to the end entity directly. I think this is an extremely rare case, and very hard to interpret. CAs can virtually never make an on-line connection to end entities, so this scheme assumes an out-of-band deliver of the CMP message, which is hard to envision imho. At least without stating that this is outside of the scop. The most basic cases I know of always involve some RA that initiates the request to the CA. This is confusing to me.

  1.  Section 4.4 on root CA key update seems very verbose.

It discusses the odd case of CA rollback to great lengths, which I'm sure is extremely rare.

We discussed during the period of RFC9480, about the need for OldWithNew, which is why RFC9480 have both NewWithOld and OldWithNew as optional in 5.3.19.15. I don't think it is good to bring that back here in the form of: "Thus, when a CA updates its key pair it must generate two extra cACertificate attribute values if certificates are made available using an X.500 directory (for a total of four: OldWithOld, OldWithNew, NewWithOld, and NewWithNew).".

Using an x.500 directory as reference I don't think is a good one.

  *   Keeping these optional enables us to cut down on the verbose wording quite some. You can basically remove the whole section 4.4.1, or shorten it substantially.

  *   It would be good if section 4.4 gave more advice on the standard use case of CA Renewal

  *   Section 4.4.2.x seems to assume an LDAP directory. Also nothing that is common, I don't think the CMP draft should specify which LDAP attributes to look up ("Look up the cACertificate attribute in the repository"). Either CMP have a mechanism to distribute new certificates, or it's out of scop and we can remove those words.

  *   The section assumes support for X.509 v1, without extensions. I don't think this is appropriate. CMPv3 makes extensive use of extensions in the specification so assuming X.509v3 with extensions I think would be better. CMPv3 will not work without extensions anyhow.



  1.  Section 5.1.3.4 talks about Alice and Bob. I think the CMP specification should make use of CMP terminology. I.e. from RFC4210, is it an End Entity, CA, RA or KGA.

     *   This flows into Appendix E as well

  1.  Section 5.2.5 should be removed imho. It says it is out of scope, why define ASN.1 data structures for something that is out of scope of the document? I think it's right to keep it out of scope, but then the whole section can be removed.

     *   KEM keys and message protection:Sections 5.1.3.4, Appendix E: For message protection I wish some more guidance could be provided, or I fear there will be much confusion and many alternatives asked. I think the case of an end entity possessing solely a KEM key will be rare. The more common case is probably that the end entity have both a signature key and a KEM key. In that case isn't it more efficient to use the signature key/cert to authenticate also the request for a KEM key? In essence the same way an IDevID is used to request an operational certificate. The way it is worded in 5.1.3.4 "In case the sender of a message has a KEM key pair". Given the extra roundtrip outlined in Appendix E, I would prefer "In case the sender of a message only has a KEM key pair". I would like it described the case where KEM key certificates are requested, using normal signature based protection, and hope that could be the preferred scenario.

        *   Migrating existing systems to that model is much easier than to move to only using KEMs and extra rountrips (or suppliing every RA and CA with KEM certificates just to avoid a round-trip).



Best regards,

Tomas