Re: [stir] I-D Action: draft-ietf-stir-passport-shaken-02.txt

"Peterson, Jon" <jon.peterson@team.neustar> Thu, 27 September 2018 20:01 UTC

Return-Path: <prvs=68087e1ac2=jon.peterson@team.neustar>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3A13A130ED6 for <stir@ietfa.amsl.com>; Thu, 27 Sep 2018 13:01:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=team.neustar
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PgZ63mzHnD4b for <stir@ietfa.amsl.com>; Thu, 27 Sep 2018 13:01:26 -0700 (PDT)
Received: from mx0b-0018ba01.pphosted.com (mx0a-0018ba01.pphosted.com [67.231.149.94]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E5A38127133 for <stir@ietf.org>; Thu, 27 Sep 2018 13:01:25 -0700 (PDT)
Received: from pps.filterd (m0078666.ppops.net [127.0.0.1]) by mx0a-0018ba01.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w8RJrEFD010712; Thu, 27 Sep 2018 16:01:24 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=team.neustar; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=selector1; bh=LyqWGN7aIMc8/Imqyjhq4GJrnGqS2TXZr7mrN/e5nRo=; b=Ph7nbWXdNycUPZrx8OBefE8Dyx/g+oAgupiwSRCcK0/8ivyimzU0VMhp3tXJWGxdjCZf CxDS4BuW5HdLUOlbmP+cYJKi4ci30YsH+CTBpt1c8uPI/PWASDRMqBjPYgBiGImOsLwn NQaz73+foOWuU4dFcWsP5PFgWUHnMLS5VZoxaJ8MM7v0TDn9KjSehfNc7tM7Npd5TV4t xPZHYNQwsYclXieKLWYsDLYP5Cyd2tzZW8G4WlF+KQMnlQpQmjqLI95GCVAESfdoHJII 7R8aj1fej9h0qai15TWtE/SyMwtUzS9H6dDwDwMpzbLmUlpm3+xDmCaUOm5U2XCqaxex Ww==
Received: from stntexhc12.cis.neustar.com ([156.154.17.216]) by mx0a-0018ba01.pphosted.com with ESMTP id 2mnhutftwr-1 (version=TLSv1 cipher=ECDHE-RSA-AES256-SHA bits=256 verify=NOT); Thu, 27 Sep 2018 16:01:23 -0400
Received: from STNTEXMB101.cis.neustar.com ([fe80::acd4:1667:da41:9938]) by stntexhc12.cis.neustar.com ([::1]) with mapi id 14.03.0279.002; Thu, 27 Sep 2018 16:01:22 -0400
From: "Peterson, Jon" <jon.peterson@team.neustar>
To: Chris Wendt <chris-ietf@chriswendt.net>, Russ Housley <housley@vigilsec.com>
CC: IETF STIR Mail List <stir@ietf.org>
Thread-Topic: [stir] I-D Action: draft-ietf-stir-passport-shaken-02.txt
Thread-Index: AQHUOjGWfakiqJVRaUqdwI460oodGKTwHEuAgBR2uoA=
Date: Thu, 27 Sep 2018 20:01:21 +0000
Message-ID: <8DA2895F-F4FB-4C28-95BC-F29DF9386710@team.neustar>
References: <152147952053.31056.3563220954085220104@ietfa.amsl.com> <B9ED4B68-7DFF-4802-A7EA-4B48CE25772C@chriswendt.net> <E91D3297-FCD7-442B-BEB5-A78357473DFD@vigilsec.com> <1B91A5B6-E016-434F-BEEA-7E5E2A023B56@chriswendt.net>
In-Reply-To: <1B91A5B6-E016-434F-BEEA-7E5E2A023B56@chriswendt.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.e.1.180613
x-originating-ip: [10.96.12.37]
Content-Type: text/plain; charset="utf-8"
Content-ID: <E8E7B813606427429EC582647D26501E@neustar.biz>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-09-27_09:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1807170000 definitions=main-1809270185
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/Pc6RC1YLblcgLKu60wqekkEhV1E>
Subject: Re: [stir] I-D Action: draft-ietf-stir-passport-shaken-02.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Sep 2018 20:01:28 -0000

Chris and I did discuss this at some length, and we're on the same page.

Once we have a bit more deployment experience with all of this, I imagine we'll have a better view of the network requirements for message/header sizes and the possible ways we might tweak STIR down the road to make it more efficient. But we are now, I agree it makes sense to ship SHAKEN full-form only.

Jon Peterson
Neustar, Inc.

On 9/14/18, 5:31 AM, "stir on behalf of Chris Wendt" <stir-bounces@ietf.org on behalf of chris-ietf@chriswendt.net> wrote:

    Thanks Russ, I agree with your edits and will include in a forthcoming update.
    
    I’d also like to update the group on the status of compact form for SHAKEN.
    
    After a little more consideration, while it would be nice to have an approach that can save some bits on the wire, one of the original agreed mandates of SHAKEN was to exclusively use full form of passport.  The reason for this was concern of middle boxes that might change DATE header, for whatever reason right or wrong although mostly the latter, but we could not guarantee this wouldn’t happen.  We felt this was important to make sure we are doing our best to avoid failing the verification of the calling identity inadvertently and potentially causing a blocked call or perception of a spam call or whatever the treatment of failed verification might be.
    
    Therefore, I plan, rather than define compact form, to include text in the new update that states that compact form is not defined for SHAKEN passport extension.
    I have discussed this with Jon directly as well.
    
    Please let me know if you have any comments regarding this, otherwise i will provide an updated document shortly.
    
    Thanks
    
    -Chris
    
    
    > On Aug 22, 2018, at 12:02 PM, Russ Housley <housley@vigilsec.com> wrote:
    > 
    > Section 8, Order of Claim Keys, now says:
    > 
    >   The order of the claim keys MUST follow the rules of [RFC8225]
    >   Section 9 and be in lexixgraphic order.  Therefore, the claim keys
    >   MUST appear in the PASSporT Payload in the following order,
    > 
    >   o  attest
    > 
    >   o  dest
    > 
    >   o  iat
    > 
    >   o  orig
    > 
    >   o  origid
    > 
    > I assume that other extensions will be specified in the future,  so I am wondering if it would be better to say:
    > 
    > 8.  Order of Claim Keys
    > 
    >   The order of the claim keys MUST follow the rules of [RFC8225]
    >   Section 9; the claim keys MUST appear in lexicographic order.
    >   Therefore, the claim keys discussed in this document appear in
    >   the PASSporT Payload in the following order:
    > 
    >   o  attest
    > 
    >   o  dest
    > 
    >   o  iat
    > 
    >   o  orig
    > 
    >   o  origid
    > 
    > Russ
    > 
    > 
    >> On Mar 19, 2018, at 1:20 PM, Chris Wendt <chris-ietf@chriswendt.net> wrote:
    >> 
    >> Hi All,
    >> 
    >> I have updated the draft with some fixes based on comments from Christer, both editorial and related to ordering comments.
    >> 
    >> Summary of changes:
    >> 
    >> - addressing Christer’s comments around order of claims adding a brief new section
    >> - clarified the definition of “customer” in the PASSporT ‘attest’ claim section 4
    >> - clarified that it is calling party telephone number that is being attested to in same section
    >> - removed last sentence in section 7, it’s repetitive and not needed.
    >> 
    >> I figured i would include these changes and update document for efficiency, but will review these in meeting on Thursday in either case.
    >> 
    >> -Chris
    >> 
    >> 
    >> 
    >>> On Mar 19, 2018, at 5:12 PM, internet-drafts@ietf.org wrote:
    >>> 
    >>> 
    >>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
    >>> This draft is a work item of the Secure Telephone Identity Revisited WG of the IETF.
    >>> 
    >>>      Title           : PASSporT SHAKEN Extension (SHAKEN)
    >>>      Authors         : Chris Wendt
    >>>                        Mary Barnes
    >>> 	Filename        : draft-ietf-stir-passport-shaken-02.txt
    >>> 	Pages           : 7
    >>> 	Date            : 2018-03-19
    >>> 
    >>> Abstract:
    >>> This document extends PASSporT, which is a token object that conveys
    >>> cryptographically-signed information about the participants involved
    >>> in communications, to include information defined as part of the
    >>> SHAKEN specification from ATIS (Alliance for Telecommunications
    >>> Industry Solutions) and the SIP Forum IP-NNI Joint Task Force.  These
    >>> extensions provide a level of confidence in the correctness of the
    >>> originating identity for a telephone network that has communications
    >>> coming from both STIR participating originating communications as
    >>> well as communications that does not include STIR information.
    >>> 
    >>> 
    >>> The IETF datatracker status page for this draft is:
    >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__datatracker.ietf.org_doc_draft-2Dietf-2Dstir-2Dpassport-2Dshaken_&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=qjlHabC1pKpu2a2pFkNEeqZ9J7vaYjKY4SQ5nSFA1ls&e=
    >>> 
    >>> There are also htmlized versions available at:
    >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__tools.ietf.org_html_draft-2Dietf-2Dstir-2Dpassport-2Dshaken-2D02&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=SCxZ0SyqVgbPBT-G-_feprAQ9X4FY3_RTM5q6Y1oVAY&e=
    >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__datatracker.ietf.org_doc_html_draft-2Dietf-2Dstir-2Dpassport-2Dshaken-2D02&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=TqgXVpiW-_xqz-mfiaWHZ7_sEIzPekjEKGTNYLDCQBQ&e=
    >>> 
    >>> A diff from the previous version is available at:
    >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ietf.org_rfcdiff-3Furl2-3Ddraft-2Dietf-2Dstir-2Dpassport-2Dshaken-2D02&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=Q9Yr0YqYIbhK4t-me9Dw-CH6OlHzX1MKLR9C9zw9SeY&e=
    >>> 
    >>> 
    >>> Please note that it may take a couple of minutes from the time of submission
    >>> until the htmlized version and diff are available at tools.ietf.org.
    >>> 
    >>> Internet-Drafts are also available by anonymous FTP at:
    >>> https://urldefense.proofpoint.com/v2/url?u=ftp-3A__ftp.ietf.org_internet-2Ddrafts_&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=V_dBXH2loc8aqrIpiStEdHQBS4UeARffuW_tyFM8fEo&e=
    >>> 
    >>> _______________________________________________
    >>> stir mailing list
    >>> stir@ietf.org
    >>> https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ietf.org_mailman_listinfo_stir&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=2A5wsjJ663GDHF4Kb2H3iISClAALpDzAi1h2y-NFh9k&e=
    >> 
    >> _______________________________________________
    >> stir mailing list
    >> stir@ietf.org
    >> https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ietf.org_mailman_listinfo_stir&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=2A5wsjJ663GDHF4Kb2H3iISClAALpDzAi1h2y-NFh9k&e=
    > 
    
    _______________________________________________
    stir mailing list
    stir@ietf.org
    https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ietf.org_mailman_listinfo_stir&d=DwIGaQ&c=MOptNlVtIETeDALC_lULrw&r=dQ51tLfoGuuFjanmfeKC0weXHNMl9xZnnsIiwRd6IgY&m=ri4xF2qe2OXWXZ0N4IyxOWzytGeMXyH-W2Zqy0ns9Ss&s=2A5wsjJ663GDHF4Kb2H3iISClAALpDzAi1h2y-NFh9k&e=