[stir] Re: AD evaluation: draft-ietf-stir-certificate-transparency-02 (now -03)
"DOLLY, MARTIN C" <md3135@att.com> Thu, 06 August 2026 03:31 UTC
Return-Path: <md3135@att.com>
X-Original-To: stir@mail2.ietf.org
Delivered-To: stir@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 1660412481427; Wed, 5 Aug 2026 20:31:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785987097; bh=acw+kWseRR02eXhzsLhc3UdgV3lhUDqkBOvK67kVafM=; h=From:To:CC:Subject:Date:References:In-Reply-To; b=c3SaVOZRhYYdccNS8ycjNWWQcea/L3UryhoULE0SL5+S4wbHbA2I5zoV8cWIEdVgn E4OH7Uyjm2N7imiP67gij6owBHZFNC5ta7vPoEPZCFiHmAk9ZG1Eif+Fnzl68ZYfNV JGa/lc87Cqq6Umz0E9BIqOsexVP5K1M6dk4SUC9g=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.692
X-Spam-Level:
X-Spam-Status: No, score=-2.692 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=atttest.com header.b="TFj//657"; dkim=pass (2048-bit key) header.d=att.com header.b="K1QwpxTV"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BTsr-mB33bBk; Wed, 5 Aug 2026 20:31:35 -0700 (PDT)
Received: from mx0a-00191d01.pphosted.com (mx0a-00191d01.pphosted.com [67.231.149.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 539E2124813D4; Wed, 5 Aug 2026 20:31:11 -0700 (PDT)
Received: from pps.filterd (m0288872.ppops.net [127.0.0.1]) by m0288872.ppops.net-00191d01. (8.18.1.11/8.18.1.11) with ESMTP id 675Navup3702964; Wed, 5 Aug 2026 23:31:04 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=atttest.com; h= cc:content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=att20260527; bh=FO0CmalGDX0LtrBljfcAYT vWjEDYOrtqqEno6qCUdKI=; b=TFj//657mytAlhkta1U2ivUIpQqE5ppnR6/3fS ydfZ8kAFFf+HVHs+rrGmXteE3DhNag2A86njbPEOX6LGuN3l+jR3HIwe+0nQXwV/ ZiDNPegJ6Ywrh8A/gfbK5STvIkz7hbcyFZ98h5e+uEy2zQQPi7cdE3TQq5jpb/rH JkmXm8NPCEkvm5AEcrKcwdroFNNIbAPppz4WegVcSdA+B4pqBsCChtNfBULi9p34 0u+8tjnSFfdG6W3q+jWi3HthuZ/kaBu/+NVf4v8giVzzHZ7dp7jLVu6/VfvlcW3D LeEydEgDbDBV1R8wuuYrUhoL8A2UrDhSTRVsPRz6oOuvDy0g==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=att.com; h=cc :content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to; s=PP1; bh=FO0CmalGDX0LtrBljfcAYTvWjEDYOr tqqEno6qCUdKI=; b=K1QwpxTVkzeh1NSbQFxo6UwKfPEt5McjoQDBKzhykWHbS1 Grv42Y78+EkF8Y+ThuBP4r/BrkNuRGMx9J6kTShalSBTzeGycJ6hEVEwGtLIaRE1 iLNtea6XMPegRIiWRwGbPC/OyPtgE4dv//WcOo027KMZec4B17dwRt/DRbLuyBzh I/08GXmDZ5CFEnYyWm3zC9nCPVTRcguVbImgFVHIo13pN4Qws5FhpImDd5v8UoXL TxxS1gWaO5dFvNhASHKjVnQDTGK6378E30vJcT+QL+6sdYu09dCzMNEhv85xO6wN KeEJ8giqqwQoHnN1CS/3L2BYDhYLlxdtAW+m72qQ==
Received: from alpi154.enaf.aldc.att.com (sbcsmtp6.sbc.com [144.160.229.23]) by m0288872.ppops.net-00191d01. (PPS) with ESMTPS id 4fvbyrs5g2-1 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Wed, 05 Aug 2026 23:31:03 -0400 (EDT)
Received: from enaf.aldc.att.com (localhost [127.0.0.1]) by alpi154.enaf.aldc.att.com (8.16.1/8.14.5) with ESMTP id 6763V2TU026093; Wed, 5 Aug 2026 23:31:03 -0400
Received: from zlp30486.vci.att.com (zlp30486.vci.att.com [135.47.91.177]) by alpi154.enaf.aldc.att.com (8.16.1/8.14.5) with ESMTPS id 6763Um9P025673 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 5 Aug 2026 23:30:54 -0400
Received: from zlp30486.vci.att.com (zlp30486.vci.att.com [127.0.0.1]) by zlp30486.vci.att.com (Service) with ESMTP id 7FD324031783; Thu, 6 Aug 2026 03:30:48 +0000 (GMT)
Received: from GAALPA1MSGED5EL.ITServices.sbc.com (unknown [135.147.63.201]) by zlp30486.vci.att.com (Service) with ESMTP id 4AEEE4031781; Thu, 6 Aug 2026 03:30:48 +0000 (GMT)
Received: from GAALPA1MSGED5EL.ITServices.sbc.com (135.147.63.201) by GAALPA1MSGED5EL.ITServices.sbc.com (135.147.63.201) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 5 Aug 2026 23:30:47 -0400
Received: from GAALPA1MSGETA07.tmg.ad.att.com (144.161.121.54) by GAALPA1MSGED5EL.ITServices.sbc.com (135.147.63.201) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45 via Frontend Transport; Wed, 5 Aug 2026 23:30:47 -0400
Received: from PH8PR06CU001.outbound.protection.outlook.com (40.107.209.28) by edgeAL.exch.att.com (144.161.121.54) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 5 Aug 2026 23:30:46 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=DYuEIB2Urosbj+BvaGdMvKnnMxPILmUdL59MB+Gt2HW2Qo/wHmsXJRVo9B8Jz4g1Q1iQloYUSp/Du2+voJvhNd8/z4Vy9pVb/PYLl9R9L1inh0x+FBmBzZKT+SUFQb2ooLj6VI+8JLGCJA+OCIFea5DxXjqSbldW9E5pUADrO5x+1qPnKNq52S4QHwwPDCb2RrDMo3VyaFxiSNaqIxoXLhsR04YUfz3kjhEtgdcPm3flMt0eyzLCZ2iotW2Zs63SZ09Ci9mxTwNaj9NtL1Bv0BoA3l4+KlHABc1STfvTnxTz6ufhjCQd1lbR3fJhqHoCi6I1V0SZYqoSzvO5oE+9QQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=NPFvMsq4/ArqlNlix7kqK/72gTgYrB5I1PLixbYy+AI=; b=wwYfdftpBs7dZ1w/SnMw5w4/C0l/ktFFiMFR4OZ9phs2Ue3PWoISAsf/7bSZMW4kU2bUBuCbD66xSgm3Kfg/MQOIzm165B6dMaL8CfIL+yYmGvaiGNeG/haJd/8GQ4uOTZht3xnb12GCWd2BtmAUjny5YnFbOWOhfKqPCRzZr9UyzUa8yhGn6D08TOuGx/hFChUHuiG+pGtyPAr8ynu6ZA/Mz1suEMM4DG3W4DgypEbeGAoeYCYA9EfOJDRgfgStz6OIvuscVfY29w+ZCMUuDdrSxH0vu0Z3JH/oYkHmcVVyS49JjXISZnfAagZFvFLAmbIJVxvxmsl8jw1CpAARuw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=att.com; dmarc=pass action=none header.from=att.com; dkim=pass header.d=att.com; arc=none
Received: from BN0PR02MB8080.namprd02.prod.outlook.com (2603:10b6:408:16f::21) by DM8PR02MB7990.namprd02.prod.outlook.com (2603:10b6:8:13::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.292.19; Thu, 6 Aug 2026 03:30:37 +0000
Received: from BN0PR02MB8080.namprd02.prod.outlook.com ([fe80::752e:a196:6b37:cf1a]) by BN0PR02MB8080.namprd02.prod.outlook.com ([fe80::752e:a196:6b37:cf1a%5]) with mapi id 15.21.0292.019; Thu, 6 Aug 2026 03:30:37 +0000
From: "DOLLY, MARTIN C" <md3135@att.com>
To: Chris Wendt <chris@appliedbits.com>, "Charles Eckel (eckelcu)" <eckelcu=40cisco.com@dmarc.ietf.org>
Thread-Topic: [stir] Re: AD evaluation: draft-ietf-stir-certificate-transparency-02 (now -03)
Thread-Index: AQHdJT73hL8rHBRG2kStvNQNz3rDbLaQXQKp
Date: Thu, 06 Aug 2026 03:30:37 +0000
Message-ID: <BN0PR02MB80809ED97B776550A31E8461D9D22@BN0PR02MB8080.namprd02.prod.outlook.com>
References: <9E886EE2-4E13-49E6-BBA8-A016BC701761@cisco.com> <253E45CD-0AD1-4D33-A821-4A2EC2107D4D@appliedbits.com>
In-Reply-To: <253E45CD-0AD1-4D33-A821-4A2EC2107D4D@appliedbits.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BN0PR02MB8080:EE_|DM8PR02MB7990:EE_
x-ms-office365-filtering-correlation-id: f2c9aa97-1ecd-43ef-eac9-08def36b14fb
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|23010399003|376014|366016|4022899009|1800799024|38070700021|13003099007|6133799003|10067099003|11063799006|4143699003|56012099006|22082099003|18002099003|8096899003|3023799007;
x-microsoft-antispam-message-info: GP5n2085u1NpvgETEZw9AKUJKSkgjTQSXJgwz5Xw+L1c8M0kjiW6ERPXKNIRz9pNrQUt3EntN5skMQxx68J6rX62xwRZal2eFeFB1/HrtrZgdvtCX18R8npUHBt0BLr9ZDSOok//qgcJqQ/DMFcHWf0opD5nHIEaj4PI0mLS8y7jzR6EJ5gQ2lNhVEnRsk4qA7fvquIp5/YleDsV3gIpGLL6mdnDNxUrrbf0+NC9VDN8nxcogXEAUd9/E6+S0wBinrmLYRW1pb7PQ0uNr3ZvwjDr99Z9bfzoGGCWYUlbFw4ZKFC2MFUock0tMsr5Boyqk7ckivzCEnXNli1UNq3cJV02iJP/oMu7zqDE6Spky9KARqiLzs+Mwnmp2uoPOHjlcoRr905B+s2M1J2VOR8QAy1JXqcR2hwbBGJvzjOgMPl39+9v5veIgUQJT3i3bzKL6NtyYxwg+ZlLLBeHNcIzw4ukuHBxe77y26oWYs8reAaPkrsDlUyyV8xda1DoQdWEunZWpdP9i8wTakDWpCnt+Ly1Pt+rWKf9c94QBFJVw5WM8BZBpMKGylLG79Wl9phYQHgOdu+WThsdQchLS8aFVvSs2X5K8N9rtCEOVB7Z8BhFqrB9/esdvkGN/MLYM+4BbDrC1wDMjY++IFYWg4BN+ST6SUVzAESXUFW3WowMBQE=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:BN0PR02MB8080.namprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(376014)(366016)(4022899009)(1800799024)(38070700021)(13003099007)(6133799003)(10067099003)(11063799006)(4143699003)(56012099006)(22082099003)(18002099003)(8096899003)(3023799007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Ai0bNEq92hYvG1hiIGssOwsvGsWIijKxcAd9aut2jTZS/yVezQZIWipcj0g87qEsmt5gBc0uhP/2ij64zUKv7I3wvNVlcPHy133u5sgJw2sq5Y1d0fjTWsnhm+8IgI7HzF7Rb448S7GQ4s/KzkOsM8vEH062c5SBii6J0Y9au/IB5SGiGRyAgva8n3h10HgmrpZyXoCCGQkgE19Wqr6ZyfNHNcNFRxM7mY22rU8ldYmaEdK5Nyu/dzD7tad7UuVYQTtwFN55sbxbkn97G9XMExs9s+BftzyIcCo8TOA3wpDJ+J3r9yEpJsVQ/IFtBJGKYBGThrdwbbc7Cf2k+4CeWUBygb5HRr2S4BJLCWZOKpIG/u0wLxozSxYcUhcpGHMjv3KYY6iMUWmndQNGJjrFgWvu9p58DLvkmxgp2cvdyEqp9nWfoZD6/KD1iqxQMONfKOcQe8Tb+HvhZxhOthQzS7/9YdIMHpfIHCeVN6Wy0yOvyTHzhS0yyxwburZOqfdRsGJ1wTnSg1dYNNFZCrzchukZD1CzvaGzVTlTEPGaKvKt9DzidvQkHsUuU3ZvdC3MegzRHlQapPbYeWEqSSobT29wjAN2sjbMVggtXsRaijBT2QJ5RmlVYY+O69ETJQG4eXfOhTtxrqtEt+8/DfRJ5yhlTyfyr0zWw6falgLUtgrvm2L7LkUg4gTIOkniQmYePukQ2f6CKHcgbDziQNo0MNuVDuVX2+qI4RoyFaAN5JQU/ZXDJgLZ0SIVn4WwdpAaJeOnAGLOc3JVY2kyuD+6Odk3W9592bMeEQJ2ZqXqq7Hd45QQpcxQIB2LeSLZFdXcs0skmdoXCKdL2eceShUKnyrOI/dCEPKbggky9+U9ynKWqtNDndPy27YK/0/dmljr0VyMVpYe7MMvaNbzfj0ixdhYFD5AG9B/cBtAVAUr/GjlimUsgv2uyaRuCCHc6iQjVayq7bXXjLynqVK5h4WA9VtIsJUIOdglEHdl1SJ2LF6J5jyQi0Y+zFfrqMQP+JF0JdBy3PEVUzdIG9XW7aZqO1ewuvz+d3eQSWsu4pXU/uAtezfch7uW9sprRsgPzA1d3GvSKcBAOg/H5iezLaCOK6VB6jei9nNx7OqixfGjPf9zWmYiVGolkCNINXmHFy1OIlUB/ETAAGu3HwClEWtvEdi5oLiTjpS6ph2A5m1aZTV3Bm6KzM44jmAYlqpD3WqFlOs2W+vZvX66MhxSO9+6oODBnSXHaORqSmxY41JIUzg9uM192b6AqHjXbiZVQnYOf+BI6Rje7mTzDJ0AmIUhWa8tK6IMaUAXKDQprWnGgHtzzToAB2dOfD6JqWcu5SgZrtlxE7Sb8o3RUYsuTOUfiUJINTzpyv2eLCLOEGXdMSNxi2Tol2tcan5Dz0d/LVC6OtAN+/EivV5PVbIK1b1KgUnrbw0Ed0xm8jZ92oxhYlayhlhy3GhnlwdL5TWITrc9jlH2m7qfdpXTesubVCVGM7huP9vSZnnowjUrToEQu/3yNwKWdsvOPu925VeEnjZMemCr7T8+EjSrUy7+O0EK1wjOP11E73muztWTLaFMZ2bbpRCljef93HK4hN05CfXOe1T55p9zF7p9b5VJiC1N3ks7ePe/ry/2wEO/lpRb54a+j8xDeSVlxz81z8pMSkrIRcU+ELGaNOt+Qs8UUtwSVIR38zcGggd2oFUKrnBdGx08wYVdy2Npfc6EapARQE6L
Content-Type: multipart/alternative; boundary="_000_BN0PR02MB80809ED97B776550A31E8461D9D22BN0PR02MB8080namp_"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: E0sGYTQSj7yyu/fFFIP1OLCDO3B7RNgTpdm0aTwH+X8g/jzUAcThHa3M/HkIfK4B6fo5VsmI/gWrZmM2Eg28voX+711J1QOFBs/Keclb7rPM68F33LbrZHA9QajSsUHUwGJbQmYK0CzJ4dDgjSZ3wDAWGTS938TrFV0XKpC0b1UVssW10b+4t6uV363OLxVDZGYYkd+q7Uf8+FNLtemfAWGG7WY8hM25oZOAcmPBdE1YfS95GYcr+5iMRJy94SoDOWtYfyGlltG2Jkp0mFgorq7uMlcm59fboKSwHuVPiwIfc0WDN89bEnKUHBSmSZh9FkllPj4xlR5AZPp9owvMKA==
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN0PR02MB8080.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f2c9aa97-1ecd-43ef-eac9-08def36b14fb
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Aug 2026 03:30:37.2153 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: e741d71c-c6b6-47b0-803c-0f3b32b07556
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: lIIHX0oHigfIFAMxKhyOuupHQZk2vrg6GPjAekWdyyiCoLvi1a7WhmKVBRFQ6/gK
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM8PR02MB7990
X-TM-SNTS-SMTP: 78ACB0B5B72223DFA9BF9D0F8B70982B9CBEB6B0A91B986DBDDE5F4EC801C6AC2
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA2MDAyMyBTYWx0ZWRfX8Jqr0wBu4zIA QXQjKx/ckdTGEd39E69yzfo0QJSe1QhNqNwG38g4myaOaTCyHFViYZx+aEwHjbCe5Tv+qQpZetT HI5aCyvf7FwREfIjeuj+n4+5+Gh61qqzORao/Frv2dO/q0BFL1+qaH4pD5e0NyxE8ZF75UsqQSO 4aZVsOqjg+uJbyi3qzAEei2MhFcyJb92zovk2IGI0taaFazRjQ7dA4bBuDu+9fXZRXM8pBhh2SF tA+XjjTIq9ejncdL34Oy6ETC+jAZYVbCsicmKmzvWHgMJhzvfrkGanqtDOwe1yan01ehsjhwafP xpvtQ9QkfnSa46qayk0VlwIXusKKA7tEUCT42hXAOSISR8jIZ3uWcHgR2DvYc8jzTtS6FGT886Y qNGrfANzLG29cYtgkLjgTatnwApgSIHTdoS3F7KIeF2lyObOVQg8eD/7/up/fKO5xmVD5tIeXwC KAMBxxcZmTOwiOJLJUA==
X-Proofpoint-ORIG-GUID: i-bKA1hMKX1XzvKtHrb2DEe1XKXlwzRV
X-Proofpoint-GUID: i-bKA1hMKX1XzvKtHrb2DEe1XKXlwzRV
X-Authority-Analysis: v=2.4 cv=eonvCIpX c=1 sm=1 tr=0 ts=6a73fff8 b=1 cx=c_pps a=VXHOiMMwGAwA+y4G3/O+aw==:117 a=VXHOiMMwGAwA+y4G3/O+aw==:17 a=z/mQ4Ysz8XfWz/Q5cLBRGdckG28=:19 a=lCpzRmAYbLLaTzLvsPZ7Mbvzbb8=:19 a=xqWC_Br6kY4A:10 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=89JvIO0RZVSDRcR4e3eW:22 a=oJl1OpGjQbMzvUC5Zz0t:22 a=48vgC7mUAAAA:8 a=pK79n_WqAAAA:20 a=pMunn2Y3AAAA:8 a=e-XU1k-EVFoCYzqy6woA:9 a=QEXdDO2ut3YA:10 a=ad26MtvDFrzhHo3l9kIA:9 a=2q4O/K3rjNU7EHYdBHB6dYyilSc=:19 a=D81uK7oeIC8x_2mP:21 a=frz4AuCg-hUA:10 a=_W_S_7VecoQA:10 a=WmVTiCyuxqgg3mnwYu6p:22 a=4bI0dLVc9rfSlT54JpQX:22 a=bn7x_FpfJtc3yKQXRW3z:22 a=wGDYQb7OrszqLcoc5sAu:22 a=bA3UWDv6hWIuX7UZL3qL:22
X-Proofpoint-Spam-Info: AW1haW4tMjYwODA2MDAyMyBTYWx0ZWRfX7juUmrAvWiGH yDjdkKDvw08uYggfcWdyDC9K6B22z0zPs+iMiyawLdbwaydT6VdAHympWWO621vMRZv3HkKKAX5 9heHSwhwwLQ1lEZhGPJHUKY8wdCJLKE=
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-05_06,2026-08-05_01,2025-10-01_01
X-Proofpoint-Spam-Details: rule=outbound_policy_notspam policy=outbound_policy score=0 malwarescore=0 spamscore=0 clxscore=1011 suspectscore=0 adultscore=0 priorityscore=1501 impostorscore=0 lowpriorityscore=0 bulkscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608060023
Message-ID-Hash: UYRCNYUBPDPAQQ6NOPOQZOH7NUCAEP4P
X-Message-ID-Hash: UYRCNYUBPDPAQQ6NOPOQZOH7NUCAEP4P
X-MailFrom: md3135@att.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-stir.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "stir@ietf.org" <stir@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [stir] Re: AD evaluation: draft-ietf-stir-certificate-transparency-02 (now -03)
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/HoUvZoDnxfzstPMKTRm4EG_bqLc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Owner: <mailto:stir-owner@ietf.org>
List-Post: <mailto:stir@ietf.org>
List-Subscribe: <mailto:stir-join@ietf.org>
List-Unsubscribe: <mailto:stir-leave@ietf.org>
So not to be a PITA, but is this implementable? Martin C Dolly AT&T Expert Member of Technical Staff Government & Services Standards +1 609 903 3360 ________________________________ From: Chris Wendt <chris@appliedbits.com> Sent: Wednesday, August 5, 2026 8:59 PM To: Charles Eckel (eckelcu) <eckelcu=40cisco.com@dmarc.ietf.org> Cc: stir@ietf.org <stir@ietf.org> Subject: [stir] Re: AD evaluation: draft-ietf-stir-certificate-transparency-02 (now -03) Thanks Charles, appreciate the suggestions. All of the changes below are in -03. Responses inline. ### normative language All updated: 363, 379, 417 and 522 to MUST; 507 and 634 to SHOULD. On 627, MUST is right for the Verification Service but Thanks Charles, appreciate the suggestions. All of the changes below are in -03. Responses inline. ### normative language All updated: 363, 379, 417 and 522 to MUST; 507 and 634 to SHOULD. On 627, MUST is right for the Verification Service but not for the Authentication Service, and the original sentence applied one keyword to both. A VS receives the certificate from an untrusted party and the SCT check is what the framework depends on, so that is a MUST. An AS is checking SCTs embedded in its own certificate, obtained through its own issuance process, so that is a local check, and the body of the document already says the AS MAY perform it. The sentence now uses MUST for the VS and MAY for the AS. ### tighten language in security considerations Agreed, and this prompted us to look at the section as a whole. Two of the paragraphs were not saying anything a reader could act on, so they are gone rather than reworded. "must be managed" and "reputable entities" are removed. We could not make "reputable" verifiable, and which logs to accept is a property of the ecosystem's policy rather than something this document specifies. "Performed securely" was meant to refer to the log public keys used to verify SCTs, which is now stated directly. The paragraph beginning "While CT does not prevent mis-issuance" restated the introduction. It now says that an SCT proves a certificate was logged and not that it was legitimately issued, which is the consideration a reader needs, and it carries the SHOULD from 634. On privacy, the original asked implementers to "consider" something without saying what could be done about it, and redaction would remove the detection the log exists to provide. The text now identifies what is disclosed and the one thing a deployment controls, which is whether the TNAuthList enumerates individual numbers or uses a service provider code or a range. Line 642, on rate limiting and redundant storage, is removed. It applies to any network service, and the section already inherits the security considerations of RFC 6962. Note that two of these are longer than the text they replace. The original phrasings were short because they did not say what they meant. ### Comments All fixed as suggested: both abstract rewrites taken as written, "its" to "their", "certificate change" to "certificate chains", "role" used consistently for all three, your wording for the third parties sentence and for the extra "in" and "that", and "asking" to "checking". The trust anchors sentence is reworded to say that each chain is required to end in a trust anchor the log accepts, and that the accepted set is the authorized set or a subset of it. ### Nits All applied: eco-system to ecosystem, stir to STIR, pre-certificate to precertificate, provides to provide, and "There is three" to "There are three". The "a established" instance was in the abstract sentence rewritten above. On the formatting issue, yes, that was meant to be a list. The blank line after the introducing colon was missing, so kramdown treated the items as a continuation of the paragraph. Fixed. On Jul 13, 2026, at 8:14 PM, Charles Eckel (eckelcu) <eckelcu=40cisco.com@dmarc.ietf.org> wrote: # Charles Eckel, ART AD, AD evaluation: draft-ietf-stir-certificate-transparency-02 CC @eckelcu * line numbers: - https://author-tools.ietf.org/api/idnits?url=https://www.ietf.org/archive/id/draft-ietf-stir-certificate-transparency-02.txt&submitcheck=True<https://urldefense.com/v3/__https://author-tools.ietf.org/api/idnits?url=https:**Awww.ietf.org*archive*id*draft-ietf-stir-certificate-transparency-02.txt&submitcheck=True__;Ly8vLy8!!BhdT!gBXO4ip4QbXF40pzXjxZWeXJ8mqZ44Pi8afnPZcwWnq9FFshaaCYox_rwvMk2Ioy3qTJriqE2ccVZlWJ$> * comment syntax: - https://github.com/mnot/ietf-comments/blob/main/format.md<https://urldefense.com/v3/__https://github.com/mnot/ietf-comments/blob/main/format.md__;!!BhdT!gBXO4ip4QbXF40pzXjxZWeXJ8mqZ44Pi8afnPZcwWnq9FFshaaCYox_rwvMk2Ioy3qTJriqE2ZsPTC5k$> ## Discuss ### normative language ``` 363 must include all necessary intermediate certificates to validate the 379 Logs must publish a list of accepted root certificates, which aligns 417 Logs must produce an STH within the Maximum Merge Delay (MMD) to 507 * Key caching - Log public keys are static and should be loaded at 522 transparency logs for new entries. The Monitor must be 627 Signed Certificate Timestamps (SCTs) should be verified by 634 and monitors should track Telephone Number (TN) and Service Provider ``` Should each of these be MUST/SHOULD? And in case of line 627, why not MUST? ### tighten language in security considerations ``` 620 The use of Certificate Transparency (CT) within the STIR ecosystem 621 enhances accountability but also introduces operational and security 622 risks that must be managed. Trust in the system depends on the 623 integrity of CT logs and therefore, logs should be operated by 624 reputable entities and monitored to detect mis-issuance or 625 inconsistent Signed Tree Heads (STHs). 642 CT logs and Certification Authorities (CAs) should implement ``` What does "must be managed" imply and is there a way to verify that logs are operated by "reputable entities"? ``` 630 keys to prevent forgery or replay. Key rotation and distribution 631 should be performed securely. ``` What is meant to be performed securely? ``` 639 and entities, implementers should consider privacy implications and ``` How can this be done? ## Comments ### Abstract, establishment of trust ``` 22 logs themselves. The intent is for the establishment of a level of 23 trust in the STI eco-system that depends on the verification of 24 telephone numbers requiring and refusing to honor STI certificates 25 that do not appear in a established log. This effectively ... ``` I find this sentence difficult to parse. s/numbers requiring/numbers by requiring Or break the sentence in two, e.g., "The intent is to establish a level of trust within the STI ecosystem that relies on the verification of telephone numbers. This involves requiring and refusing to honor STI certificates that are not listed in an established log." ### Abstract, avoidance of issuance ``` 29 number resource. The primary role of CT in the STI ecosystem is for 30 verifiable trust in the avoidance of issuance of unauthorized 31 duplicate telephone number level delegate certificates or provider 32 level certificates. This provides a robust auditable mechanism for ``` The phrase "avoidance of issuance of" is clunky, and if I understand correctly, CT does not prevent or avoid issuance; rather, it ensures that issuance is publicly detectable, which is what creates the "verifiable trust." How about something like the following: "In the STI ecosystem, the primary role of CT is to provide verifiable trust by detecting the unauthorized issuance of duplicate telephone number level delegate certificates or provider level certificates." ### unclear who/what is meant by "its" ``` 150 system (DNS). This document describes a conceptually similar 151 framework that directly borrows concepts like transparency receipts 152 in the form of SCTs and how they are used in certificates and its 153 specific use as part of the larger STIR framework for call 154 authentication. This framework is defined for the specific use with ``` ### certificate change ``` 168 issuance of STI certificates and certificate change that are intended ``` Is this supposed to be certificate chains? ### actor vs role vs actor role ``` 177 There is three primary actors in the certificate transparency ``` In the text that follows, all three variations are used. Use one consistently. ### interested third parties ``` 223 logs. Note, in [RFC6962] it is possible for certificate holders to 224 directly contribute their own certificate chains or interested third 225 parties, ``` Should this instead read as follows: "Note, in [RFC6962] it is possible for certificate holders and interested third parties to contribute certificate chains, ..." ### extra "in" and "that" ``` 225 parties, however because in stir eco-systems that generally consist ``` s/because in stir eco-systems that generally consist/because STIR ecosystems generally consist ### trust anchors ``` 229 authorized to participate as valid trust anchors. It is required 230 that each chain ends with a trust anchor that is accepted by the log 231 which would include those authorized trust anchors or a subset of 232 them. ``` I am not sure what this is saying. I believe it should be reworded. ### asking a log file? ``` 239 the logs, asking them regularly for all new entries, and can thus ``` s/asking/checking ## Nits ### global replace ``` s/eco-system/ecosystem s/stir/STIR s/pre-certificate/precertificate ``` ### typos ``` 201 web PKI environments, but provides a specific framework designed for ``` s/provides/provide ``` 25 that do not appear in a established log. This effectively ... ``` s/a established/an established ``` 177 There is three primary actors in the certificate transparency ``` s/There is three/There are three ### formatting issue ``` 606 The main differences are: - The expected certificate types are STI 607 certificates as defined in [RFC8226] and [RFC9060], with TNAuthList 608 extensions. - Submitters are limited to STI Certification Authorities 609 and Subordinate Certification Authorities. - Monitoring and auditing 610 are focused on detection of mis-issued telephone number or service 611 provider codes (SPCs). - The client roles (e.g., VS, AS) interact 612 with certificates and logs in ways specific to SIP call 613 authentication. ``` It seems this was meant to be formatted as a list? --- _______________________________________________ stir mailing list -- stir@ietf.org To unsubscribe send an email to stir-leave@ietf.org
- [stir] AD evaluation: draft-ietf-stir-certificate… Charles Eckel (eckelcu)
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Chris Wendt
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… DOLLY, MARTIN C
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Alec Fenichel
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Chris Wendt
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Charles Eckel (eckelcu)
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Chris Wendt
- [stir] Re: AD evaluation: draft-ietf-stir-certifi… Charles Eckel (eckelcu)