Re: [stir] Proposal for update of erratum #6519

Alec Fenichel <alec.fenichel@transnexus.com> Tue, 20 April 2021 15:31 UTC

Return-Path: <alec.fenichel@transnexus.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C9E8D3A285A for <stir@ietfa.amsl.com>; Tue, 20 Apr 2021 08:31:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=transnexus.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WM5PA7I8-Tzx for <stir@ietfa.amsl.com>; Tue, 20 Apr 2021 08:31:21 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11on2070.outbound.protection.outlook.com [40.107.223.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7AA913A2827 for <stir@ietf.org>; Tue, 20 Apr 2021 08:31:21 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kGPvfGvVYi7nduSvJWxiVGMUnW0bqh2kTCsaD9IjpD6Ty1jF7nEiNtuYcIzgcueF4RzpBMtMJMcfdYOLi0Be9FfBMvbLyUiaAljbZGt964j1H0iQFqbEjgFhFpVoe/a4ymSgXzFdd4n57hmsaf7ZPhdXkOg/irB+gr0Ydyx5fKxwvkouEOA4TlO6k/WwbaWPmGv+8OhO5swViWiqz6Jl/ou6slXfEuUTQsIRx6SIDuay/x9m7e7nx8SqHIivaeBfmOdLdblG3hwKD6bpnz67Bj+Dt11QI+q3L82wwU4C41ozlSsVmtJZCJu05nXFO4vawFGkYTBbOjVprEaHRTs0Zw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eDcld1jzb1ndptCNzPn/SFCMDO6XIYQjQdkD7DnQ+DA=; b=djE4S8jJJkCO3Ehlic2lpu9HZQRJk8dGJ3G181ZpAK6EKR8FF65EvX+dDDAmcN6td/OIWF4yhuHrFYvYO5IHljg8jpUfaQSzmKl9lNtaea0orVZ20lw/t8DGpE3vyErTtsp36WzU3aJ+jS5t4bOioUoLGc/NPdKt0fGYd0OnNNZk0fbNHRiIIGseWk/vlk7xjEZPzRRHAmYwfOwohYWJxXFStfDbqyS3YFHL8IRzhIFrDJw4s7bgISC/OXDHL5rgRVTf7/KZEcaRxl9hQBAMyPhCWjae7M0foa02baUdPSlb1g1r8EoKpxH2HHysazJTyya5uw59svDcn8Fv29girg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=transnexus.com; dmarc=pass action=none header.from=transnexus.com; dkim=pass header.d=transnexus.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=transnexus.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eDcld1jzb1ndptCNzPn/SFCMDO6XIYQjQdkD7DnQ+DA=; b=qq4ypFnq4Mp/9CwtGanxBXcyPTrIprj/oplh6b64MtagmBBlunzHihUEsgx2rVoyX8kfOZlJcZlw97WdBXshJBb4Uub6wIeZwC9VqcvEknzPc9zVDs/ioaVfsMs434s8kw7iBo4SjfZGlJi3L0yzZVSnz+mdIQNCCZfinwHfmrw=
Received: from BN6PR11MB3921.namprd11.prod.outlook.com (2603:10b6:405:81::20) by BN8PR11MB3555.namprd11.prod.outlook.com (2603:10b6:408:82::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4042.16; Tue, 20 Apr 2021 15:31:18 +0000
Received: from BN6PR11MB3921.namprd11.prod.outlook.com ([fe80::848e:acea:1d08:c4a1]) by BN6PR11MB3921.namprd11.prod.outlook.com ([fe80::848e:acea:1d08:c4a1%3]) with mapi id 15.20.4042.024; Tue, 20 Apr 2021 15:31:18 +0000
From: Alec Fenichel <alec.fenichel@transnexus.com>
To: "Peterson, Jon" <jon.peterson=40team.neustar@dmarc.ietf.org>, "Peterson, Jon" <jon.peterson@team.neustar>, Roman Shpount <roman@telurix.com>, Marc Petit-Huguenin <marc@petit-huguenin.org>
CC: IETF STIR Mail List <stir@ietf.org>, Russ Housley <housley@vigilsec.com>, Christer Holmberg <christer.holmberg@ericsson.com>
Thread-Topic: [stir] Proposal for update of erratum #6519
Thread-Index: AQHXNGtEYP84hmYi3EufgV06U9MN4Kq8DuYAgAAaegCAAAOBgIAADd+AgAAs2wCAAB63AIAAIcUAgADW8oCAAACy7IAABJGAgAAEtec=
Date: Tue, 20 Apr 2021 15:31:18 +0000
Message-ID: <BN6PR11MB3921A7E9996332ED9E057E4C99489@BN6PR11MB3921.namprd11.prod.outlook.com>
References: <42e964d3-2a16-660b-f8b4-fd9daedad115@petit-huguenin.org> <AM0PR07MB38604255784FF9E621257B2D93499@AM0PR07MB3860.eurprd07.prod.outlook.com> <3d8e2fce-d124-99b9-e295-734a36ad564a@petit-huguenin.org> <7558AA11-A7F9-4091-BFD3-F42C742AABAE@vigilsec.com> <167dde10-f242-2b6f-a7ce-96991158589a@petit-huguenin.org> <CAD5OKxvkN+BSY0XuBmfApDDWOLhqCLLFuQgVQryE+yHUftWs4w@mail.gmail.com> <15fc4a20-b5c8-cd27-b30e-76e1f479b4ff@petit-huguenin.org> <CAD5OKxvmvmotpxB8BGJfqRrVTjEGKQkQRow37gmwRMFaBGjEoA@mail.gmail.com> <DF470A3C-6033-48F4-8A61-3442C5DD2239@team.neustar> <BN6PR11MB39216109781BE5DE5C35AB6399489@BN6PR11MB3921.namprd11.prod.outlook.com>, <6F5317AE-44F5-4CAA-82B8-830FF5223179@team.neustar>
In-Reply-To: <6F5317AE-44F5-4CAA-82B8-830FF5223179@team.neustar>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: dmarc.ietf.org; dkim=none (message not signed) header.d=none;dmarc.ietf.org; dmarc=none action=none header.from=transnexus.com;
x-originating-ip: [71.199.144.180]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b4939fd8-0608-4167-c22f-08d9041157f4
x-ms-traffictypediagnostic: BN8PR11MB3555:
x-microsoft-antispam-prvs: <BN8PR11MB35554E7EB3FD05102EC8F9DD99489@BN8PR11MB3555.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: kD6xt1fHoFXXGGvBU10b0vx8/+iweIhb7FKqDZLuwb9F5uZ01k2NCxktVKQ27oEDEwuqyMca5HLE5dI8jD/GEw0x040cBC50fHm35FSK58yi6nQpkZa43yXQ//Ag0kiPQhkFOXqfTlfXre+zX3nGUMJzVpt1i8wQjNE9Ba4kczs94xBakILDkFzNHcwo1uQ5ANP4bSsCAAQwtkTRSrLonj9bYIuPtQVQiQOGo/16pZb2qubG8HXG8aKOlaGVuRSoWoxIsLtklQEfYpgh+cdl6u5bJiaRMjCyOOTG75zDYpddkSYXPcFgNnicvYFA7AfYKRPbUG7PTJNq06FvUWrt686hrX9HofXlnUKOS7fcbVdQZTTboB3QeG68BK5H1wZ2464qD72iEEA4Ilv/w9fUkL48aNT9SFVO++CLAXrKPU04L181hnTO5AGG+NrpH44a5/wKMl4ceg1pTfcEDMPgtpqTYAsZGnDHfz1HJCI8+qfMx7I+GaPBYReU1qd5wV6Ygp5sxXIqQgrZI818EfwD7bB9BoEhnJPQdTOfrx5695xzCtiBPOdRawt8nG96aF31cFzyziYKJ7woucFElXMSD6YpeajkXWU+RqfKUhZ3bCk=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BN6PR11MB3921.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(366004)(7696005)(86362001)(9686003)(99936003)(26005)(66476007)(122000001)(53546011)(2906002)(55016002)(186003)(52536014)(15650500001)(44832011)(5660300002)(38100700002)(8936002)(110136005)(83380400001)(508600001)(54906003)(4326008)(66446008)(76116006)(71200400001)(66946007)(66616009)(8676002)(33656002)(66556008)(6506007)(64756008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: bKLR3UhZ/t5K2uLQ7OEDdxoxKWJaZWJtxaWfNZaSlyR92UQPS4H7XnnRTGnrU55jXorFYFbLE0moH5KovWaQ/Fe2xYvAIbxo1MvhWIxkvzTcuHUNcQ8brEm7DdFE32FAb0pTzLjNGjS4gX+AS/rP7yB25CnxJHPtCevQ6royUsMi5snsHUYwuORlMdnVoo+gmCHFF9fjkujc4s5chkreE6frFFPuVg1J1QTDwNsbbqYL82S+5XqCfkfNg8yfug97uscRNSNH7mdIOgPdO6Mrr7XSq3o98++18OXJkbE3wBRXxEC+Gxecy35e4CSrTvwnrMI4l5HNZDdqSiaDTa790JOZA3nWl3o/ok/IzljshkxXnpUvZ34InEhhqgPmWN6coYkc3wCQvFdXCfpGTYmn/7lnxR9QxdIS6NBG1py+XgWYt7DbFaOQtAW3RKXwXQeWczV8Icb2Vd32sgorTiAO2jpiwZ8YNOax7uOqBXAtoZ1qfV+w7mAoN79zyC0L2atwmp2rco4er+uvcgSzkEHUscOHJ5Zf/JAny8Cn6IdqE3tO/arnygNgXLiYrQrJm6TbhRCUjVBA7TvLANscjbBzE5m0wsatQfoXmQQtgssuDOh1ii9BLbL0Mbummgrogbtuy2tXRxEhk74KIGUzABpiX4YsCVL4oqO3uuYjGrwm34H6OkemUEn2hnNN60n/7ecyw6fb0U2b/w7pxEut6gw2ppMhQLffis1J8vuaQ6f3NQ3f2A8qt7bvislZq9u7NE6o0SYlE+VdCIHYRlGXUb2LlYtHXydd2gicoHeOj9swkTJhRjDVRiOE1YM9keLg+MEG7OEh/HPluCquNpSsXBfSyDYT0MWuoFvP4Di5svAp5PI4NLlzApZnNgaDlqfoUJqRgC4Zvla6CrRE8XJI6ZUWHfO2AZxi8kFc6FqSNfIP0dpcI5vATUJLOt9ilkzPJjevHfAPIlQlkQDk9yMIxQesVZ/R6E102J/Zs9sX5eUmth05mfuQ9fIc0bEjEjtDVbNYjUDoCRRFyOdV96L7Avnfy7Wcc38GEZoyjtQD6pyAGWmAarsH7Oi5cIoNrbtf84A28PqsBM6llpL+K9HdFkdu2Eq9cSqM+8O3RL9hILBq+OpLhFTp5SVLQf26gtcn85915CLEWv+JkoEYzUbRZMGXdGhaOOyD4sXum8HDx1iG/wDOIHrK92BqsEYRy69Hk0V7nJnFA+Ha9yV2ZXtgREobfXpKAOzEMvaao6M4+iM/sOuEoB0X+lZ34nip1csG8aXJcjU2A6NtZnY8hTXUjOy7xaX03qwDDpc3QUVar+CApqQQHwv9xoAJA0oQ1/4P5dUSNhcYAwMxzlsuDmRYVfoV6w==
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha256"; boundary="_AFB8A91B-4819-3643-A98D-8BD8DD262051_"
MIME-Version: 1.0
X-OriginatorOrg: transnexus.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN6PR11MB3921.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b4939fd8-0608-4167-c22f-08d9041157f4
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Apr 2021 15:31:18.4760 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 8e2972a2-d21d-49ac-b005-18e8ceaadee3
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: XwF9CqzXHeQgO3FnWeINCBjpv6BdJmcZPQCTzIx5VqGvMhb17VJ664kFn5aYkdldlerLxTUtAEWXzq5nKH7l5lwYZy/fJ8iPo2L4doxGgAo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN8PR11MB3555
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/Z8TaqdpclXhobaQmi451qXTAQbo>
Subject: Re: [stir] Proposal for update of erratum #6519
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Apr 2021 15:31:31 -0000

Jon,

 

Understood. Then maybe we could just leave it as is until RFC 8224 is updated? Is there any implementation out there that doesn’t support receiving with or without quotes?

 

Sincerely,

 

Alec Fenichel

Senior Software Architect

alec.fenichel@transnexus.com

+1 (407) 760-0036

TransNexus

 

From: Peterson, Jon <jon.peterson=40team.neustar@dmarc.ietf.org>
Date: Tuesday, April 20, 2021 at 11:05
To: Alec Fenichel <alec.fenichel@transnexus.com>, Peterson, Jon <jon.peterson@team.neustar>, Roman Shpount <roman@telurix.com>, Marc Petit-Huguenin <marc@petit-huguenin.org>
Cc: IETF STIR Mail List <stir@ietf.org>, Russ Housley <housley@vigilsec.com>, Christer Holmberg <christer.holmberg@ericsson.com>
Subject: Re: [stir] Proposal for update of erratum #6519

 

I mean, no, it’s just pushy. It’s the same reason we don’t propose that you MUST only accept quoted. Given that it was the ambiguity in the original spec that caused this problem, I’m a little hesitant to be that pushy.

 

Maybe for the errata we could be less pushy, but when we (inevitably, someday) do an actual update or bis to RFC8224, we could be more pushy about it.

 

Jon Peterson

Neustar, Inc.

 

From: stir <stir-bounces@ietf.org> on behalf of Alec Fenichel <alec.fenichel=40transnexus.com@dmarc.ietf.org>
Date: Tuesday, April 20, 2021 at 7:59 AM
To: "Peterson, Jon" <jon.peterson=40team.neustar@dmarc.ietf.org>, Roman Shpount <roman@telurix.com>, Marc Petit-Huguenin <marc@petit-huguenin.org>
Cc: IETF STIR Mail List <stir@ietf.org>, Russ Housley <housley@vigilsec.com>, Christer Holmberg <christer.holmberg@ericsson.com>
Subject: Re: [stir] Proposal for update of erratum #6519

 

Is it really a problem to just say that you must (or must not, either way) include quotes and be done? STI-AS and STI-VS implementations will need to be updated frequently over the next few years due to all of the new PASSporT extensions, so expecting implementations to add/remove quotes seems reasonable. Implementations could accept both values at their discretion, even if it violates the standard.

 

Sincerely,

 

Alec Fenichel

Senior Software Architect

alec.fenichel@transnexus.com

+1 (407) 760-0036

TransNexus

 

From: stir <stir-bounces@ietf.org> on behalf of Peterson, Jon <jon.peterson=40team.neustar@dmarc.ietf.org>
Date: Tuesday, April 20, 2021 at 10:47
To: Roman Shpount <roman@telurix.com>, Marc Petit-Huguenin <marc@petit-huguenin.org>
Cc: IETF STIR Mail List <stir@ietf.org>, Russ Housley <housley@vigilsec.com>, Christer Holmberg <christer.holmberg@ericsson.com>
Subject: Re: [stir] Proposal for update of erratum #6519

 

Inline.

 

From: stir <stir-bounces@ietf.org> on behalf of Roman Shpount <roman@telurix.com>
Date: Monday, April 19, 2021 at 6:57 PM
To: Marc Petit-Huguenin <marc@petit-huguenin.org>
Cc: IETF STIR Mail List <stir@ietf.org>, Russ Housley <housley@vigilsec.com>, Christer Holmberg <christer.holmberg@ericsson.com>
Subject: Re: [stir] Proposal for update of erratum #6519

 

On Mon, Apr 19, 2021 at 7:56 PM Marc Petit-Huguenin <marc@petit-huguenin.org> wrote:

A literalist.  Fantastic.



That was not my understanding.

 

We can go back to the recording to check on the decision.

 

More importantly, what is the normative strength of "be tolerant to the absence of quotes when receiving"? Is this MUST accept quotes? SHOULD accept quotes?

 

In the sentence "Implementations SHOULD use quotes around the token when sending", what would be the valid use cases when implementations are allowed not to use quotes?

 

My understanding is that SHOULD implies well know exceptions.

 

The exception we are aware of is that implementations exhibiting this behavior exist. It is, in other words, for backwards compatibility reasons.

 

Regardless of what the recording says (we were kinda all over the place, if I recall), I think I agree that the right semantics are that you MUST accept quoted and unquoted, and SHOUD send quotes (the exception to the SHOULD being backwards compatibility). If we said you MUST send quotes, well, then implementations that don’t are violating the spec. As you pointed out, it’s kind of a mixed bag at the moment out there in terms of where implementations are.

 

Jon Peterson

Neustar, Inc.