[stir] Re: Update for STIR CT and new draft Vesper for discussion
Chris Wendt <chris-ietf@chriswendt.net> Mon, 22 July 2024 01:19 UTC
Return-Path: <chris-ietf@chriswendt.net>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45619C151539 for <stir@ietfa.amsl.com>; Sun, 21 Jul 2024 18:19:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=chriswendt.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WrZ2xzlLJ9RQ for <stir@ietfa.amsl.com>; Sun, 21 Jul 2024 18:19:48 -0700 (PDT)
Received: from iguana.tulip.relay.mailchannels.net (iguana.tulip.relay.mailchannels.net [23.83.218.253]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E7E4AC151531 for <stir@ietf.org>; Sun, 21 Jul 2024 18:19:47 -0700 (PDT)
X-Sender-Id: dreamhost|x-authsender|chris-ietf@chriswendt.net
Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id 3C6A05C2F93; Mon, 22 Jul 2024 01:19:47 +0000 (UTC)
Received: from pdx1-sub0-mail-a235.dreamhost.com (unknown [127.0.0.6]) (Authenticated sender: dreamhost) by relay.mailchannels.net (Postfix) with ESMTPA id CC1B35C2EA0; Mon, 22 Jul 2024 01:19:45 +0000 (UTC)
ARC-Seal: i=1; s=arc-2022; d=mailchannels.net; t=1721611185; a=rsa-sha256; cv=none; b=8Ckkj85g3S32kJB/x3f+PrK8wyNhJBCTzLLqHhTOe0ucrZ7/3EcjspZZJurM45FgZ5Gp7V 2zS34TENxTKjfZJGJCABZM7QIG96jv6AO8acYKFydAMC6fRclfAyoqKD3W1jrPFtXr6bxz RsZPpmg1ll7KB7twZuPDQNe2AKj3Mgs8MqxWc8FK3VQWyp+3nq+sAGa2r+Z7cm5rlYbEhs yg/AnuZzMMv0As9Jh3/UW7zYs/05Xf7urDPJhebwh/vZ8wVcxVl6+KQ/IdyxJdJgbUDbov 4wj/SpdXqpbzSA+sIfoj5REWOujJoX3O+Vv+FXbYsBVQbudL7KD1YlELXs6dww==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=mailchannels.net; s=arc-2022; t=1721611185; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=vFQT5df59MFWdcNbPKHrRNdYMa3AS8df9e1ekYXBNLU=; b=fHBlzcRgHwwq/xyD6Ju7JZcop9zAaMwklDQZ9p7ru4AeGZYlxykgcqk8SIAFANYPiv7Cqd ri9l4lkgAJS5bDDUpxYxeuiqDJIPU6ivDJg9ulsR2r00Egk79hCx9qep1TZ/1jcWtc91FX 8P3EzHFZqnP/BAKEDU4vo6VFUZJzj1KlSuAVgu+rPN+l3k0wzaOmEtHoKdnVsZPvtYllmS nCAIGV/vEWkU5r0d0VXuHV+7dMuXJx0w74+sTCboWe8x6ZlrYsRaAYEES0VDUmUyjeyw4U lVqh3xXF1zbyyc0Z3RAXDIucFjdijSXanuAbw3KNMIcma8P41ZMpCrSlVxITbw==
ARC-Authentication-Results: i=1; rspamd-5657f96ff8-c9sj2; auth=pass smtp.auth=dreamhost smtp.mailfrom=chris-ietf@chriswendt.net
X-Sender-Id: dreamhost|x-authsender|chris-ietf@chriswendt.net
X-MC-Relay: Neutral
X-MailChannels-SenderId: dreamhost|x-authsender|chris-ietf@chriswendt.net
X-MailChannels-Auth-Id: dreamhost
X-Occur-Stretch: 23b9372e2bccf3c9_1721611187140_1854901314
X-MC-Loop-Signature: 1721611187140:3252801454
X-MC-Ingress-Time: 1721611187140
Received: from pdx1-sub0-mail-a235.dreamhost.com (pop.dreamhost.com [64.90.62.162]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384) by 100.123.177.230 (trex/7.0.2); Mon, 22 Jul 2024 01:19:47 +0000
Received: from smtpclient.apple (syn-024-043-239-146.biz.spectrum.com [24.43.239.146]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) (Authenticated sender: chris-ietf@chriswendt.net) by pdx1-sub0-mail-a235.dreamhost.com (Postfix) with ESMTPSA id 4WS2WP2h9Tz6h; Sun, 21 Jul 2024 18:19:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chriswendt.net; s=dreamhost; t=1721611185; bh=vFQT5df59MFWdcNbPKHrRNdYMa3AS8df9e1ekYXBNLU=; h=From:Content-Type:Subject:Date:Cc:To; b=FVgINMz5bT6kGdVYB3dyHSA6x1fNbRzVhuBNYIWpzE68zK4Gq+rswvONYsUYuEaWn UIkEWtChqojoFymG3gOVbGslp5gOnlPN8ITPZQlVYK1FoR6WYEB6RuQqGBXZzE5lDb /QkEKF3DlDp0KM99mJK5yudhdAoYWFvHVaTRUihH1X0W7PJql/V+e9j4XohT8NuhoG h25RVBQR52l4KD/ziOJK/tv7RMOQxKnt37ikVVUPC/ahzrGDAYnsOJylq5kAg2ZSBq PPqx6yfWkkjlkbimzqs06HBU47K8pMErYk1VvrpX+m7QW24smYeN+fJjyfy/TKk9WO S3qKoKzOXMp9A==
From: Chris Wendt <chris-ietf@chriswendt.net>
Message-Id: <F7718879-D58F-453D-8C37-B8927A1848AF@chriswendt.net>
Content-Type: multipart/alternative; boundary="Apple-Mail=_23240466-6A67-4F6C-B961-14146558BF2A"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.600.62\))
Date: Sun, 21 Jul 2024 15:19:33 -1000
In-Reply-To: <6bab47b5-ffb3-b937-d268-78ed6a0edd00@ietf.contact>
To: Henk Birkholz <henk.birkholz@ietf.contact>
References: <171777283560.40072.6690714429117933871@ietfa.amsl.com> <B9B0F9D5-57B8-493F-A5FB-DA5B30F7E18C@nostrum.com> <1E971FAB-02C1-4C18-88DB-EFB87C061E1D@chriswendt.net> <6bab47b5-ffb3-b937-d268-78ed6a0edd00@ietf.contact>
X-Mailer: Apple Mail (2.3774.600.62)
Message-ID-Hash: 4FVQUQ6OMZBAZIGKTZCRBXN3KSFE6VAT
X-Message-ID-Hash: 4FVQUQ6OMZBAZIGKTZCRBXN3KSFE6VAT
X-MailFrom: chris-ietf@chriswendt.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-stir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF STIR Mail List <stir@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [stir] Re: Update for STIR CT and new draft Vesper for discussion
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/37aXWnMmQ83LtfQkciafBeZb3ws>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Owner: <mailto:stir-owner@ietf.org>
List-Post: <mailto:stir@ietf.org>
List-Subscribe: <mailto:stir-join@ietf.org>
List-Unsubscribe: <mailto:stir-leave@ietf.org>
Hi Henk, I think there may be a path for including CWT, but to be honest the SIP/telecom community in general is used to text based payloads in general and is now just getting conceptually comfortable with JWT in PASSporTs, so adding binary encoding and CWT may or may not be a big conceptual ask to swollow. But I think it’s a fair question, and would love to hear others opinions on this. Size of payload had had a bit of a debate early on in STIR, but at the end has become mostly tolerable in most implementations and not a big concern. -Chris > On Jul 16, 2024, at 10:08 PM, Henk Birkholz <henk.birkholz@ietf.contact> wrote: > > Dear authors, > > I followed a trail of shiny crumbs to this I-D action. I skimmed the I-D and I am wondering, is it in the scope of the STIR charter to register CWT and JWT Claims in one swoop? That would eliminate the need to do a parallel I-D, just for the CWT equivalent. > > > Viele Grüße, > > Henk > > On 15.07.24 20:04, Chris Wendt wrote: >> Hello STIR WG, >> Just wanted to let everyone know about two document updates that we plan to discuss at the meeting next week. >> First, we have created an 03 latest update of draft-wendt-stir-certiifcate-transparency. We took some of the feedback received at the meeting at 119 and rather than try to align with the webpki certificate transparency RFC too closely, we moved to be more opinionated about what certificate transparency scheme would match current practices of STIR eco-systems. Please let us know if you have any comments and join the discussion at the 120 meeting. >> Name: draft-wendt-stir-certificate-transparency >> Revision: 03 >> Title: STI Certificate Transparency >> Date: 2024-07-08 >> Group: Individual Submission >> Pages: 13 >> URL: https://www.ietf.org/archive/id/draft-wendt-stir-certificate-transparency-03.txt <https://www.ietf.org/archive/id/draft-wendt-stir-certificate-transparency-03.txt> >> Status: https://datatracker.ietf.org/doc/draft-wendt-stir-certificate-transparency/ <https://datatracker.ietf.org/doc/draft-wendt-stir-certificate-transparency/> >> HTML: https://www.ietf.org/archive/id/draft-wendt-stir-certificate-transparency-03.html <https://www.ietf.org/archive/id/draft-wendt-stir-certificate-transparency-03.html> >> HTMLized: https://datatracker.ietf.org/doc/html/draft-wendt-stir-certificate-transparency <https://datatracker.ietf.org/doc/html/draft-wendt-stir-certificate-transparency> >> Diff: https://author-tools.ietf.org/iddiff?url2=draft-wendt-stir-certificate-transparency-03 <https://author-tools.ietf.org/iddiff?url2=draft-wendt-stir-certificate-transparency-03> >> Abstract: >> This document describes a framework for the use of the Certificate >> Transparency (CT) protocol for publicly logging the existence of >> Secure Telephone Identity (STI) certificates as they are issued or >> observed. This allows any interested party that is part of the STI >> eco-system to audit STI certification authority (CA) activity and >> audit both the issuance of suspect certificates and the certificate >> logs themselves. The intent is for the establishment of a level of >> trust in the STI eco-system that depends on the verification of >> telephone numbers requiring and refusing to honor STI certificates >> that do not appear in a established log. This effectively >> establishes the precedent that STI CAs must add all issued >> certificates to the logs and thus establishes unique association of >> STI certificates to an authorized provider or assignee of a telephone >> number resource. The primary role of CT in the STI ecosystem is for >> verifiable trust in the avoidance of issuance of unauthorized >> duplicate telephone number level delegate certificates or provider >> level certificates. This provides a robust auditable mechanism for >> the detection of unauthorized creation of certificate credentials for >> illegitimate spoofing of telephone numbers or service provider codes >> (SPC). >> I’d also like to let everyone know about a new draft we also want to discuss related to certificate transparency, but more aligned with ways of representing entity vetting and right-to-use (RTU) of telephone numbers in the form of a “vesper” token. It incorporates some of the ideas and technologies being discussed in SCITT and SPICE and we think is also relevant in particular for RCD and VCON as well. The draft is linked below, and will plan to spend some time to introduce this at 120 meeting. >> Name: draft-wendt-stir-vesper >> Revision: 00 >> Title: VESPER - VErifiable STI Personas >> Date: 2024-06-25 >> Group: Individual Submission >> Pages: 17 >> URL: https://www.ietf.org/archive/id/draft-wendt-stir-vesper-00.txt <https://www.ietf.org/archive/id/draft-wendt-stir-vesper-00.txt> >> Status: https://datatracker.ietf.org/doc/draft-wendt-stir-vesper/ <https://datatracker.ietf.org/doc/draft-wendt-stir-vesper/> >> HTML: https://www.ietf.org/archive/id/draft-wendt-stir-vesper-00.html <https://www.ietf.org/archive/id/draft-wendt-stir-vesper-00.html> >> HTMLized: https://datatracker.ietf.org/doc/html/draft-wendt-stir-vesper <https://datatracker.ietf.org/doc/html/draft-wendt-stir-vesper> >> Abstract: >> This document extends the STIR architecture by specifying the use of >> JSON Web Tokens (JWT) and Selective Disclosure JWT (SD-JWT) for >> representing persona related information intended to be the output of >> a Know Your Customer (KYC) or Know Your Business (KYB) type of >> vetting process. It defines entities called Vetting Agents (VA) that >> perform a vetting of persona related information and can issue a >> verifiable token bearing the VA signature, containing information >> that can be disclosed or selectively disclosed to an interested >> party. The Vetted Entity (VE) can hold this token in selectively >> disclosable forms to disclose specific information to the third >> parties. The vesper token enables the delivery and verification of >> information with privacy protecting mechanism in a complete, >> selective or zero knowledge manner specifically supported by the SD- >> JWT. This document also describes an API standard to be supported/ >> hosted by a Vetting Agent (VA), which allow vetted parties to present >> tokens proving their KYC/KYB conformance, and incorporates proof of >> possession to ensure the legitimacy of the entity presenting the >> token. >> Thanks!! >> -Chris > > _______________________________________________ > stir mailing list -- stir@ietf.org <mailto:stir@ietf.org> > To unsubscribe send an email to stir-leave@ietf.org <mailto:stir-leave@ietf.org>
- [stir] Re: [sipcore] I-D Action: draft-ietf-sipco… Ben Campbell
- [stir] Update for STIR CT and new draft Vesper fo… Chris Wendt
- [stir] Re: Update for STIR CT and new draft Vespe… Henk Birkholz
- [stir] Re: [sipcore] Re: I-D Action: draft-ietf-s… Richard Shockey
- [stir] Re: Update for STIR CT and new draft Vespe… Chris Wendt
- [stir] Re: [sipcore] Re: I-D Action: draft-ietf-s… Paul Kyzivat