Re: [lamps] Murray Kucherawy's No Objection on draft-ietf-lamps-lightweight-cmp-profile-18: (with COMMENT)

"Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com> Fri, 13 January 2023 07:50 UTC

Return-Path: <hendrik.brockhaus@siemens.com>
X-Original-To: spasm@ietfa.amsl.com
Delivered-To: spasm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63552C1524AC; Thu, 12 Jan 2023 23:50:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=siemens.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CUCTybSOdSEx; Thu, 12 Jan 2023 23:50:38 -0800 (PST)
Received: from EUR02-AM0-obe.outbound.protection.outlook.com (mail-am0eur02on2042.outbound.protection.outlook.com [40.107.247.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 70F52C1522C3; Thu, 12 Jan 2023 23:50:38 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bs/iA10WHGr+lQbZAEFy2hUyyGSX1g7WLk2XlJuf2++NOBAkMNTS1oO/10lP/6q6RB8nhmOrZYdleuicowwKpl3syn97d/ccMrssmCJA2gWpnO2j0PKhmIvQ2MmacCfeeWH2wXnk0gaRetSWXlSTwpppXinJKBHXgK+c6iTaIbCw91cLw/rWWDtDGrnHNZymmMHcKY+pByDu5h5wDk77PY8Ka7Qt5qkGMyLQGVKi1ToF0hAHHTuWHCXqJFLbEnfi3zevDj/ZppJvi0eICNe4g+rA1yyqfQGhR0YVgjoIuN/RO0W0Kq9wI8yVK11uO4avcrZFfrwiOpQMIk9cDVhTAg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kRDkwa5Iv6reM7v3G1dglHnSH9lv8l3n2Y6HPrtxUNw=; b=gXb3tteTD2+hSTdoX+hO0U1/2Gpo6Jxn0606oVuKTEE0LPiptstbFU4kyRpQ7vy02Dl3Zj89tUePIXp+ijL+JcbxWJv+DqJBRS1P1N9Hww3eHo7IdlTmstTjVCRRuwWaOa4udFsxGYKDQy7uOli942a0XTJF08utjRlxPJCDO0bQ+j96oZGouD5WkmdzBrhjntNOTvV6GKPPXhlQI7WjBbTK00YyK4SlxRxNijfYD28Ry48tLwKkg7vIPqJD/knxxfEqr7Apl5oA8+hV4jMV6TnSxuxdXSr8fe/IzmprVADfl1pIm2Na0fhWP/h6Vbzlq9+fG3jP+oC44TiCp3SjZw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=siemens.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kRDkwa5Iv6reM7v3G1dglHnSH9lv8l3n2Y6HPrtxUNw=; b=ikruFBHv1gS/5S9MjExW+Q6nN6LxlJocBarNqcJqfBW4YkGxmgGT9fY6c14WZ6XU8MnEpW2tOTJPg1gwg9b8+GhWvzRSHC2KAI9rGc6imNgCtZQj5rNx4K+ZDwuf2l1kk1j89aqsfRrkNa/CzLBp9W+5W3EK4CNXKuXChTkEmL+QYAN7dEa/UNBYK48zqUgF0HtQh/xX62bKVgFpCDdPIYBI4qJ3dnRRCUvlPExr1U53MFvb59lJAcpXuh4C70cCKKI90EHCihO2lqWsWMpp1plZ/q2SAgwci7sHdasrnQuF5VEjLYLN9j8KZSzos2Oewmk9qTZgBOGuOKBiQtc6AQ==
Received: from GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:150:7d::8) by AS4PR10MB6087.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:582::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6002.13; Fri, 13 Jan 2023 07:50:34 +0000
Received: from GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM ([fe80::cfed:9a7f:2568:206b]) by GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM ([fe80::cfed:9a7f:2568:206b%6]) with mapi id 15.20.5986.018; Fri, 13 Jan 2023 07:50:34 +0000
From: "Brockhaus, Hendrik" <hendrik.brockhaus@siemens.com>
To: "Murray S. Kucherawy" <superuser@gmail.com>, Roman Danyliw <rdd@cert.org>
CC: The IESG <iesg@ietf.org>, "draft-ietf-lamps-lightweight-cmp-profile@ietf.org" <draft-ietf-lamps-lightweight-cmp-profile@ietf.org>, "lamps-chairs@ietf.org" <lamps-chairs@ietf.org>, "spasm@ietf.org" <spasm@ietf.org>, "housley@vigilsec.com" <housley@vigilsec.com>
Thread-Topic: Murray Kucherawy's No Objection on draft-ietf-lamps-lightweight-cmp-profile-18: (with COMMENT)
Thread-Index: AQHZDrZyEaQM8z4lNU+Qq6PTqKsiz65tDJpAgClWxECABN9wAIAA5RzA
Date: Fri, 13 Jan 2023 07:50:34 +0000
Message-ID: <GV2PR10MB62108E6238123AA68F724995FEC29@GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM>
References: <167091047171.45635.975609146244768236@ietfa.amsl.com> <GV2PR10MB62106D9F748CEA4BA9EA638EFEE09@GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM> <GV2PR10MB6210DFE1B688E410B8E1869FFEFE9@GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM> <CAL0qLwZsd_Wwi4QoUBub-7UXJ9QBy+JUM-3z+y5++WVTTOJfeA@mail.gmail.com>
In-Reply-To: <CAL0qLwZsd_Wwi4QoUBub-7UXJ9QBy+JUM-3z+y5++WVTTOJfeA@mail.gmail.com>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Enabled=true; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SetDate=2023-01-13T07:50:32Z; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Method=Standard; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_Name=restricted; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_SiteId=38ae3bcd-9579-4fd4-adda-b42e1495d55a; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ActionId=5b0b5525-cbc9-4f65-b0ba-24e84e81f7c9; MSIP_Label_9d258917-277f-42cd-a3cd-14c4e9ee58bc_ContentBits=0
document_confidentiality: Restricted
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=siemens.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: GV2PR10MB6210:EE_|AS4PR10MB6087:EE_
x-ms-office365-filtering-correlation-id: ec75e0d6-bed3-427b-b6b5-08daf53ada13
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: QJFlPhyFX+5ywT2GpaIpeBhNPa84Ys0GoLOPQVO7saqo0epURbgeIb1FKxH1SkIgk/aQhIhxY+lOCtdD6HzrPOMSKwDD6YRE8jLJX1rPgicrHjcz9rywPfH9pPmCiMrRkv8sfwfvie7a5CiyO3Llwa8i59WRSUElQpQPAwTcu5cYmX1EexUARxyafgY6JsWU9UUAelfUPx0RGGcJ0pfEM+FzeAbw0nZJj3/f2fnIpMYreLLrGp8Vf/tMQe56IBMovRSd8lBrh8USVS82k3yUBW5P2/Jv3tfdBzPP4TXxFeJ7RAjbf0X9BUzOmSgLN7swnuK/CqKJyoNJpNfpKnBLaq/mQ66bGUzs1Dt0nR9mKNNnXayQkx/m89M1a5f/MzZtqvW7xRUDW/+o4pLmwHhmfbrgY7WZtVk87Leb1W/gzWKoRzX3w+P+8NYV0IRoO7tDfuIXal2QBw0b8D6agxUlzea+BIv/4jllBo/HMu7Vv0bXY9m4V74xib/SDSErGGvFxWBGA/aotHZBYrlMgipoMWS3QiNMmZkCH7hCW+INlFtBQ2j1qFBMLy9bwIkAAp2lGQVulW9jY4SDqBNgGSFmbI8KdcrjOyr6aa7y1cC7vKqYjgD/MUHj6ckpFttXSOnK+kV5Hj6uau526lCpIsEMbE2CNKIwdPZZo5KNNHrsH+W72H8ZIpAs+kV0Rno2SXlglkv9te5q7cWDkQT7vkijQg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230022)(4636009)(376002)(366004)(136003)(396003)(39860400002)(346002)(451199015)(9686003)(4326008)(38070700005)(82960400001)(33656002)(478600001)(38100700002)(41300700001)(86362001)(110136005)(54906003)(316002)(26005)(71200400001)(7696005)(55016003)(66946007)(66556008)(186003)(76116006)(66899015)(64756008)(53546011)(66446008)(6506007)(5660300002)(2906002)(8676002)(66476007)(52536014)(8936002)(83380400001)(122000001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: LcO/irpHHpX4J9KPo4bGwH9cYLgaFO2hX/OFjfZCCR/Aduio738PTMoHwIxtqQ4C51S3SRsFrm2ih70bdO6+sBOeYkipxoy/iIaAthYlvgo15NVKQPauUT32poUCBoQFs8ek6Oxjy7Pj2tkalB1lkP9RYn96sk0C0s3IDbCrWEOKd1Uh+QzZlm3McaSkGw/TEjwTG8Vv3KcqhX7tJiBo09Id5s94hRcCNb+yGExxUFIj8sDAT95QQiNOmkNT6AQjU/nsQl0WuhFaWTzrmMx1OjYoVIh4ftdW+kVcLqf7jeH7jwdKYbr9I+JtUeXvgIYfyC9p+l5y7HU/TmtdFuJl3/V6BTpfWTCk0xdItpONJkhwmVj8I7LGlWlu73U+2+6vWZSTWU5tOYooEetMbr1hezmgCDeP6V1fbHmcw9VT//wRS7C6rLx6E7iDhwjToYJ9zIBiHAr4vwUIwxiQ9hySkL060xQ0gmm+gPZwdItq7VYg4aLWZd+oKwcwxdITPwtFGSTxHzOOyQi4wug+BkcktzTJ2lvufWiMC4B6mmSB8buLrWti4n5ewQkte6qxxyqU0rgjZHeN8KVVG3owH08Hjk319aoWf12954LspaFR6Tg6FQZmJY3VqUYemibuaSpXvkyJuBaxiqurLWFpAr/exq//n7ZTuE3TtYFbcZrUJ0qVfl46NqQTk3hRCetXkzdgVAtda8GxK57DJS3gNRSRBRz/d8Jk5bO6f0YWrdLtWiK7Nijrwj4qXSe1zIDYzZ4av3EaNJjWgxuCE75MupV7wZ4LOrapw1KIymme16Z1FYK/sgTOZwft3yO+CjZOxtmj8MkltcviTad3Go3FCI5jumz7dECN5e44Ao1PoiqnZOdxPgDIkAKHQdf7Q4yP3E4OiBSfJR4gHPp5i/6hg22/9acvWHEKNeami05KlRYUoRTNUfRQALQOsq0i76g8tIOPZN3lyO0wbQuTRNPehB2dchCwsrghfqzwhRDqRxWSalgiMf8vK+CbVA2Rx/0bRUXkZN0FUpY7+jx5fGqjx+hGcDREF9I5Kp7H3Rhs2E6lyOoPQ+IYS1/uvOfRjo3eABm0SyLRBc+npXdh9yyRsECjWFB0UVuhg6CB+DhgUDLdZ5KQTCNol7Ju/+Ij7P/SI0LrxrXaskYmoXKsU+Y4kIwln+l93+z5BrHpuBKAXRqBTv2T1PkWehu+RXXRmPamlK1Q5yWuINubd9nVujEx7EnG+RYFPefz6D9gvccxEMOVPVFzBHW3Q1x2b9m1HukjK27L00SebuY1dntT7whgrf11jK38YW+KdXVpfLWVCtBCk6jOQ3mCYjPso+Lg7tKsI8SKijcu8xo4MReuTy4/tDiPZcDzbYovq4WXFZCvw6aFpV0j7aIsoJsJRg8oBk8iB3b31sRCeHUzl9PO1PnfXsDiti/aJE5kWogwpLpBYJwBXkhyCQQ2dJJ6O3qPt1C1GKKR6bMUeGqrK/H6RjcV7+vMxxZ7F29gtNgvVHjBSACTLuoLFjvV81Gj82ufXOEsU3LevmQvXYBbxBGpjbEwrWnndQM7QiQ1Cs/vnCUJBvq7WakJiEv9h5EM5VUIRHqbBViRegZNIq31Ak5fZMweBKdsQA==
Content-Type: multipart/alternative; boundary="_000_GV2PR10MB62108E6238123AA68F724995FEC29GV2PR10MB6210EURP_"
MIME-Version: 1.0
X-OriginatorOrg: siemens.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: GV2PR10MB6210.EURPRD10.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: ec75e0d6-bed3-427b-b6b5-08daf53ada13
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Jan 2023 07:50:34.1511 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: mslaTF3Cm2NzNv+DbGkXXlYtuLB9F2jCBtBTRUZb7vxxKFvqQ29rU95eq+uxy2tNusQj8loJCnNrtNMRRa5llTHqGLQ0KlyzR6taDsBW1YY=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4PR10MB6087
Archived-At: <https://mailarchive.ietf.org/arch/msg/spasm/ucotr_b2BQkkLf5liUlN0vZbgNY>
Subject: Re: [lamps] Murray Kucherawy's No Objection on draft-ietf-lamps-lightweight-cmp-profile-18: (with COMMENT)
X-BeenThere: spasm@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is a venue for discussion of doing Some Pkix And SMime \(spasm\) work." <spasm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spasm>, <mailto:spasm-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spasm/>
List-Post: <mailto:spasm@ietf.org>
List-Help: <mailto:spasm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spasm>, <mailto:spasm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Jan 2023 07:50:43 -0000

Murray

Thank you for commenting again on our approach addressing your feedback from December.
Thank you for providing the quote from RFC 2119. This makes it much clearer to us and shows that we tried to kind of redefine the usage of “SHOULD” which seams not appropriate.

We offer to revise the SHOULDs and decide to either add explanatory text, change to “MUST” or “MAY”, or use “should” instead.
This will take some time, but the authors are willing to do this. :-)

@Roman, if you think this is not the right way forward, please let us know.

Hendrik

Von: Murray S. Kucherawy <superuser@gmail.com>
Gesendet: Donnerstag, 12. Januar 2023 19:03
An: Brockhaus, Hendrik (T CST SEA-DE) <hendrik.brockhaus@siemens.com>
Cc: Roman Danyliw <rdd@cert.org>; The IESG <iesg@ietf.org>; draft-ietf-lamps-lightweight-cmp-profile@ietf.org; lamps-chairs@ietf.org; spasm@ietf.org; housley@vigilsec.com
Betreff: Re: Murray Kucherawy's No Objection on draft-ietf-lamps-lightweight-cmp-profile-18: (with COMMENT)

On Mon, Jan 9, 2023 at 8:07 AM Brockhaus, Hendrik <hendrik.brockhaus@siemens.com<mailto:hendrik.brockhaus@siemens.com>> wrote:
Murray

Last week the co-authors and I managed to align on how to address your
comments. Please see our proposal for an updated version of the draft below.
I hope these generic changes sufficiently addresses your comment
sufficiently. Changing the entire document instead, will be a mayor effort.

@Roman, I hope these changes are appropriate after IESG review. If you have
any concerns, please let me know.

[...]

Hi Hendrik,

I appreciate the attention you're giving to this, especially since this isn't a DISCUSS position.

Succinctly, it seems like you're trying to widen the definition of SHOULD as defined in BCP 14, and I'm having trouble understanding what you're seeking to achieve by doing so.  It seems to me like it might be simpler to just say "should" instead of "SHOULD"; that would be an easy way to avoid this sort of friction.

Section 6 of RFC 2119 says in its entirety:

   Imperatives of the type defined in this memo must be used with care

   and sparingly.  In particular, they MUST only be used where it is

   actually required for interoperation or to limit behavior which has

   potential for causing harm (e.g., limiting retransmisssions)  For

   example, they must not be used to try to impose a particular method

   on implementors where the method is not required for

   interoperability.
We have come to also allow use of BCP 14 key words around security and operations.  For instance, "you MUST encrypt data in transit" has become a security best practice generally; "you SHOULD log this when it happens" is sound operational advice.  However, the text of your abstract reads a lot like an Applicability Statement (Section 3.2 of RFC 2026), though, so I don't feel that it falls under those sorts of exceptions.

SHOULD isn't intended to allow general mush around the requirement to do something; it's meant to say, in effect, "You really need to do this.  Doing anything else threatens interoperability, so you need to be sure of what you're doing if you deviate."  This is why we encourage, along with SHOULD, some kind of guidance around when one might decide not to do what the SHOULD says.

I think your best options are either to revisit the SHOULDs you have and see about either adding some of the supporting text I'm suggesting, change them to MUSTs or MAYs, or just use "should" instead of "SHOULD".

Again, I'm not holding a DISCUSS on this, and hence not making a demand.  It's up to you and your AD to decide where you go from here.

Thanks again for your consideration.

-MSK