[stir] draft-peterson-stir-mls-00

"Peterson, Jon" <Jon.Peterson@transunion.com> Tue, 24 October 2023 14:07 UTC

Return-Path: <Jon.Peterson@transunion.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B5AB0C15154E for <stir@ietfa.amsl.com>; Tue, 24 Oct 2023 07:07:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.106
X-Spam-Level:
X-Spam-Status: No, score=-7.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=transunion.com header.b="lD85iz4J"; dkim=pass (1024-bit key) header.d=transunion.onmicrosoft.com header.b="rToHYoxb"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qJfP0_luHtmI for <stir@ietfa.amsl.com>; Tue, 24 Oct 2023 07:07:35 -0700 (PDT)
Received: from mx0a-00030c01.pphosted.com (mx0a-00030c01.pphosted.com [148.163.156.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3BA2EC15199B for <stir@ietf.org>; Tue, 24 Oct 2023 07:06:51 -0700 (PDT)
Received: from pps.filterd (m0216095.ppops.net [127.0.0.1]) by mx0a-00030c01.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 39O4ZpHe025709 for <stir@ietf.org>; Tue, 24 Oct 2023 09:06:50 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=transunion.com; h=from : to : subject : date : message-id : content-type : mime-version; s=tuppdkim; bh=yQ+Pqtt7D3MiA2sMY5fm0M2JDJb8lzGmpUPmmuiPTfo=; b=lD85iz4JIBrWHidNpqFTKMcfSx9EBKL8uAnZ5BJNyng4vFxoJVBD/fS6P468ASGAnyQK UiXKdWpG9dYTFeNpt0553df+ELUHHfTLXWPBA0+v4uukFfhsQGpifHKnE5mFeZyMpNB8 7Nccxm4fUWNZApPaAocxWi6YwaChLGAEjL8vsLVEQrT6ildOzC8l5xTZq69wSBQ3ulME ZXx9oRAB5YpxAezovjEnZtn5Ia4iT1IMUaOLFG9ooXCJnaRqsDnuYRwJRDy3fzcCa3OV 5z0WoqOXGF//TeJT4rBPMFP7hDQDhG9NS+99+iG8rqVjadMmAuN8tB8uNB2tFZZn70Jp Zw==
Received: from nam12-bn8-obe.outbound.protection.outlook.com (mail-bn8nam12lp2169.outbound.protection.outlook.com [104.47.55.169]) by mx0a-00030c01.pphosted.com (PPS) with ESMTPS id 3twxn14f8k-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <stir@ietf.org>; Tue, 24 Oct 2023 09:06:50 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=E8XFIWni+Xv/3LKfiVvOQIJevtJqxVNO5LqwMPh6Eg/WwWstQUn+RBeUUTuKlIqPDon8BjeWZUZdfhYsOB5d9mMX8duMHueRgmsjjTIy63oiBU4XApLAG9e/EDTka1HF+jX8/tnOVNQI4eZfdrNihozQYEMhpqHcKlEbNDgE7pInffqb5pksHusAdaA0h31TvppAzAUsL4hRNjs434ISZcqxujeudH6iKNhgdTJivVgS7s7cCNnNfBTmTy+YrqwNYuTZ6GWuHXzqSZdgRLvyRJEf+Qfx7nVDxfnhD09n7rRzNHt4hJ0Zza+oa4K5BHtJ7ykcDg8Zw0tu208zcrKzXA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=yQ+Pqtt7D3MiA2sMY5fm0M2JDJb8lzGmpUPmmuiPTfo=; b=KOdz85E5f6TkcwycBtG/MuPrhOvOQ/OQioEJ9EucKyz92J7SLNxgvDMaDy3EmVbJGSoab9sC79gKIRdCfXiX7WU43ueCzIX85ASTNnRZhWXolG7qgtMbQVYjgcfHlPvnkv1fTRwIZhwFac0/tY3uVlaYfZsUbI11xbEIVYPzdsne6AmZVV5W5b5b1p889hyx1RXaybr3G408qcm9/maIEhwV/2xThgI0LyDghaGtSzFTTExOl5YSC9ZOvXfodluCJygSs9ndlZYvin1Z6GGmnOuXmhaec5LeJIkmVKJAVS4xSwAskbAuTFJmBhrsVi7LtLDqc6MhFAtOI0154ex/6Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=transunion.com; dmarc=pass action=none header.from=transunion.com; dkim=pass header.d=transunion.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=transunion.onmicrosoft.com; s=selector2-transunion-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=yQ+Pqtt7D3MiA2sMY5fm0M2JDJb8lzGmpUPmmuiPTfo=; b=rToHYoxb4Cbx9uQ1GrK8wGcUg+rGvwKet5M15qSpHg29Q2LL9xcwbHFYSIAEX+Uvw0Hspc/zYeT2FhecrcN02iuEGpYLEM0iDAEzDpn9jsnRXmsupPMCKUf/K2SlM8Pyno1/kq221y/nbZQi4kqmgRpmhIkKgG+SJvj/F4RyXOU=
Received: from CO6PR17MB4978.namprd17.prod.outlook.com (2603:10b6:303:139::23) by SJ0PR17MB4382.namprd17.prod.outlook.com (2603:10b6:a03:296::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6933.11; Tue, 24 Oct 2023 14:06:46 +0000
Received: from CO6PR17MB4978.namprd17.prod.outlook.com ([fe80::3dbf:226d:4592:f872]) by CO6PR17MB4978.namprd17.prod.outlook.com ([fe80::3dbf:226d:4592:f872%6]) with mapi id 15.20.6933.014; Tue, 24 Oct 2023 14:06:46 +0000
From: "Peterson, Jon" <Jon.Peterson@transunion.com>
To: "stir@ietf.org" <stir@ietf.org>
Thread-Topic: draft-peterson-stir-mls-00
Thread-Index: AQHaBoKP+86B/OJWs0m8yw5OiBMGww==
Date: Tue, 24 Oct 2023 14:06:46 +0000
Message-ID: <CO6PR17MB4978C6E0F9C70E9B915C5F31FDDFA@CO6PR17MB4978.namprd17.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CO6PR17MB4978:EE_|SJ0PR17MB4382:EE_
x-ms-office365-filtering-correlation-id: 4e235fb3-4582-415f-f796-08dbd49a75c2
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: O0DzLaRIoklpPPPHRygc+VSleLHG1YegfHrQWKcKS7IWa5c6HScLtlMv+DY/RbAouSTqyK3wiA7kVbGfa/n7hRrR+5LTq/ig3/5EGEiNtNOiJfQsXAvixkyycSjU4nLis2CjjJLtwJOhWhXDtgplnuTAxU7i1fEXh5vVSh7OhTfPIEV8MTw6yBKuHOZ2w5A4W4OFPtEpJtIl7fdr8HMhO6Th+R5NQj4yzAkUC5cUKxFkpS/R2hCyf/nguZXVPQeRKdxbg9i7Gt5Jq/XGCypRizim09fpQ/IUzRI2LwZA2+FQZvV0jQifKUSGID95hLApJSUM9N3Z/xkE7MsoXtcfvnT3kbtUeg11dEbTIflFvu5rc24YqWJ7XMFYRDjQzz8qtwmirxPBo/q4OiPgRWalC+VSLuBF2TalJIP3/wzs00PNBxzz9UqNBeMlqATH/VpWGvfgi+bAVC8KLx/hNimBTMnzXWbUO/g2JLEqozGjvVF4gZGXHBLWsnTjdwrIcJb9x0m+VvbJqGMGBLvGBSzYKnhbPKlUA7S2CXL0Eya81BIN3ePW/WPJ+L4sPVNdGGmAm/DaBJkwIICakZ6PPBp/Naq1Bhk/uN1WLdo4ZqK/p6I=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO6PR17MB4978.namprd17.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(346002)(39860400002)(136003)(396003)(366004)(376002)(230922051799003)(451199024)(64100799003)(1800799009)(186009)(66899024)(55016003)(7696005)(76116006)(66446008)(41300700001)(66476007)(64756008)(66556008)(66946007)(86362001)(6916009)(316002)(478600001)(6506007)(9686003)(5660300002)(966005)(33656002)(8936002)(52536014)(2906002)(4744005)(166002)(8676002)(38100700002)(26005)(122000001)(71200400001)(38070700009); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 01G9uENUZ5TdwapzV3R0lLdt03iWegmA72RUz4fU9WqTgnknQl9R90HR9jOyKB79M//ghJnVpsFiv9T7XxME4xRx4ofxRT/187BGnPROZFGaJ1DCpdohwupma9Hq9Av2iJDZzGFTo2LgWssVCDIVFBJduVXWC1mFZBNA1irAQvSYIR6hPdxyd4QtOkwPxbbCP7V+dGcOHNz96nDgr5hYbO3bv/yi38BTFF3+FF2rvWnOKV/LRxFSpAdCa2O9ShdamdvdbGfNq/ZEGlBxNXN9oegOEvkMNwG1w2ifK2ZGn2AoodUGjKghKY21TVCf7dAs3w7Amx8rbLW2eC4AYJYam0pdAS3z+B3nwCAwDdQSXW8563S/RbWZ0BPjZ0nzHCQKKUWtMBFIlruhBgpFYl/6bvCGjVP0nSERAnVfcLDe/HHA1AkcYzfQDrwIORnIJjiFO+o+HugcA5FiH8JVWbWz2yqATdy9oxn4IYTsh1KYUFFRVLq+NC80GjiEwHpcI4nNC9PuMfWycWz6JE/PYJsXzLX99u/I4gdkppWSK1qEYKj6DREQQcLv2Tvhc2FHNCDacd5kPgnqgM0T6bPVvVoD0eJOoichF/fikIwZQmdy87nbUwVl5SyOPugo23lMFDTmESeaoqWWrLsKdUmBmDoxmPr/4oMhvEGJxGhg0jeTlHl3gSHo5vSAY9dmFEDGp7K8PnuKAwjim0toN3nlH1PGPSl+AzORUzq0nvXueGteUwVsKEZvUYNa4rIwewQyhhsFwf74sY8nqwrzAaMvMSnW7SbDTnDW/So51Yz0Uz3RjHgNzmkIxQ6X+ogCJxXArgXJdDlqRilgip1S4S6lxK+QzZUeKq6Wsauyu5tRTuEABH5FcJ3iZ5d/gCbKngsfP/Drb40AHChaIS/KKbeJGtWLoLS5x8ncA0k8Ew3Ui6Z8f/KN9Qy3y0kET53l/5TNMXgGGbv9YKshuZTrZDyx0sdtrWTbhG+2hQad4ZKj/3Kl+ipTJ4XweHRWAZtM1MvJ2QbG7N3+EriCAOt0RXnysKrDhNGqCl/uwvTC2enZKKKt3/pbYfmZKTiHMrHkzGbUsTMhwormUrX8Z5Z0wWeAi+lL/zSthHTeJwCON3ZdSM4eym0To7WQpvWzLVtR/vEoJ6coot8PNlqBjU05UldUJ5gqv6NOB6k8BxRDUES1g9kKjiOd23B2rF6vaKg1nhkXo2FsbCJyiSP5+QE/a2OfH1PWFOikbzUT90IBtgK920Gfm8Kt4aP3TpAdnv0NPJ5VgYmq0mGvUDdwRxpN7uRW7XSgwlPhkFwSGqB/ZPTKzjlaCzbY4HolYCY6lF6oub6VlVuxCl+60tN9BC7d7QNrx/ObRNxzlLY5RM8OzObMMAos5NRQX5YOD1a2svuhl0/d/Oxp+Mge+ToCJKla/5U9DUm/NKauazfcxsJ+kaaGdIdErCvh+61YMQL43v3hH0kgJIrMy0fuVS+ljGj47tSGQAws2TKa6LPVcEP+Zk9H3nF1Nwku529AL7lTETMlp0Y6pf2mExLj/KBYrAR3WqqCJzdmM5HoMLkRhd+K2nmciKxT4+8NhFFsYHPiljbNhFdQfQ9QsY93vRRwK2TOZ+EMMuMh4ZJwa5Kc5fms1Wb9o3S5ZAw=
Content-Type: multipart/alternative; boundary="_000_CO6PR17MB4978C6E0F9C70E9B915C5F31FDDFACO6PR17MB4978namp_"
MIME-Version: 1.0
X-OriginatorOrg: transunion.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO6PR17MB4978.namprd17.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4e235fb3-4582-415f-f796-08dbd49a75c2
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Oct 2023 14:06:46.8314 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0685d760-4332-4f24-b2ea-ffbbc2383f15
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 9yi5Z0Vmmua6NXi7oEkXrd0AoJJAWIacxFnbY5qyE9ySjKtnqxHQStsE23kp134KYalm4F7axB3FAUmN+1QukD+dfetDB8cpy98oeQtYZC8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR17MB4382
X-Proofpoint-GUID: 0p4ieJaZscnCeGNX_WV6trO0zoutcpmy
X-Proofpoint-ORIG-GUID: 0p4ieJaZscnCeGNX_WV6trO0zoutcpmy
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.980,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2023-10-24_14,2023-10-24_01,2023-05-22_02
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 lowpriorityscore=0 priorityscore=1501 suspectscore=0 mlxscore=0 mlxlogscore=417 adultscore=0 bulkscore=0 phishscore=0 spamscore=0 clxscore=1015 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2310170001 definitions=main-2310240121
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/0d1tIyCq_SZWPZwZxBfozhod2L4>
Subject: [stir] draft-peterson-stir-mls-00
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Oct 2023 14:07:38 -0000

At the last IETF I took an action item to put together a draft about how we might leverage STIR credentials for MLS. A -00 of that document is now here:

https://datatracker.ietf.org/doc/draft-peterson-stir-mls/

It outlines basically two approaches: using STIR certificates (including SPC certs and delegate certs) as MLS credentials, or using PASSporTs. These approaches have their pluses and minuses, and it might make sense to ultimately allow all of these options. Comments, alternatives, and so on welcome – we should discuss in Prague.

Jon Peterson
TransUnion