Re: [stir] Stephen Farrell's Discuss on draft-ietf-stir-rfc4474bis-15: (with DISCUSS)

"Peterson, Jon" <jon.peterson@neustar.biz> Thu, 03 November 2016 13:20 UTC

Return-Path: <prvs=41151910e3=jon.peterson@neustar.biz>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 47F221295C3; Thu, 3 Nov 2016 06:20:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.701
X-Spam-Level:
X-Spam-Status: No, score=-102.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=neustar.biz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Iag1OrKgNq9; Thu, 3 Nov 2016 06:20:08 -0700 (PDT)
Received: from mx0b-0018ba01.pphosted.com (mx0b-0018ba01.pphosted.com [67.231.157.90]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A0BC31295B6; Thu, 3 Nov 2016 06:20:08 -0700 (PDT)
Received: from pps.filterd (m0049401.ppops.net [127.0.0.1]) by m0049401.ppops.net-0018ba01. (8.16.0.17/8.16.0.17) with SMTP id uA3DFVNn002204; Thu, 3 Nov 2016 09:20:03 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=neustar.biz; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=neustar-biz; bh=VLWWvn7ZCYLNt91BJIveW5fYDgnxz/yTuddTC5Jr19Y=; b=KWnaPT5ja0MLeOi89vJZ2To6S//EN52SpXDW4HjVARMq7mhvXt3j8fwf73SjrOoM2KAP xiDmxD6nCqwetwPxDnX31Esf6ayzSKDX5QQnO8ExSNoKIqgR2XdABxdJPr0DTg2id5CN aso6OihzvZfpzR1KsrS0Sq7EUJCVIYxuONjtpJGjR0I4LQN1HQxwh8u3aMKXOmoVp5pr zMHlWLG/xmmpvWn0iWhJEXdSNgKZnNdDtInQCEV4+tuV/lFbrO6+jeh9jjKGlYkprtHq BSxSe/Vq61EBGkElgpFgPJIW8Zwj3BOci7mX2vE8tzBFXL7gk1a8wcEwvikHUj58WvSH yw==
Received: from stntexhc10.cis.neustar.com ([156.154.17.216]) by m0049401.ppops.net-0018ba01. with ESMTP id 26crj18pkd-1 (version=TLSv1 cipher=ECDHE-RSA-AES256-SHA bits=256 verify=NOT); Thu, 03 Nov 2016 09:20:03 -0400
Received: from STNTEXMB10.cis.neustar.com ([169.254.5.94]) by stntexhc10.cis.neustar.com ([169.254.4.125]) with mapi id 14.03.0279.002; Thu, 3 Nov 2016 09:20:03 -0400
From: "Peterson, Jon" <jon.peterson@neustar.biz>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, The IESG <iesg@ietf.org>
Thread-Topic: Stephen Farrell's Discuss on draft-ietf-stir-rfc4474bis-15: (with DISCUSS)
Thread-Index: AQHSNXPyCK3ORY1edUG/RddTHzG1IKDHPwyA
Date: Thu, 03 Nov 2016 13:20:02 +0000
Message-ID: <D440B031.1C1F85%jon.peterson@neustar.biz>
References: <147813752132.24106.5602048445726889072.idtracker@ietfa.amsl.com>
In-Reply-To: <147813752132.24106.5602048445726889072.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.6.3.160329
x-originating-ip: [10.96.12.147]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <F5AE56F3DED16B4CB9788CA0EC218A01@neustar.biz>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2016-11-03_04:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1609300000 definitions=main-1611030249
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/7qO0Y2gebtwMBwfbYXECGafYPqI>
Cc: "stir@ietf.org" <stir@ietf.org>, "draft-ietf-stir-rfc4474bis@ietf.org" <draft-ietf-stir-rfc4474bis@ietf.org>, "stir-chairs@ietf.org" <stir-chairs@ietf.org>, Robert Sparks <rjsparks@nostrum.com>
Subject: Re: [stir] Stephen Farrell's Discuss on draft-ietf-stir-rfc4474bis-15: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Nov 2016 13:20:10 -0000

>
>
>
>This should be an easy one to fix (or else I'm missing stuff,
>which is quite possible) but if a fix is needed then it'd impact
>on interop...
>
>In 8.3, I think the ABNF conflicts with the E164Number definition
>in the certs draft which disallows "#" and "*" (if I understand
>the "FROM" clause in the ASN.1 module correctly).

The presence of the special keys "#" and "*" in the canonicalizations
allowed in rfc4474bis is a consequence of the fact that the
canonicalization mechanism needs to work over both the origination and
destination numbers. "*" and "#" are used in certain unusual dial strings
for the destination number which resist canonicalization mostly because
they are nationally-specific. The certs in stir-certificates are there to
sign for originating numbers. Hence the usages shouldn't overlap.

Now that much said, out of an abundance of caution for future use cases we
can't anticipate, we could tweak the cert syntax to permit those
characters, but that would end up being a stir-certs fix rather than a
rfc4474bis fix.

Jon Peterson
Neustar, Inc.