Re: [stir] For the sake of implementers, please verify errata in a timely manner: ppt= with/without quotes

Marc Petit-Huguenin <marc@petit-huguenin.org> Thu, 08 April 2021 19:55 UTC

Return-Path: <marc@petit-huguenin.org>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36E0C3A1960 for <stir@ietfa.amsl.com>; Thu, 8 Apr 2021 12:55:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oCfaJubVnQnn for <stir@ietfa.amsl.com>; Thu, 8 Apr 2021 12:54:58 -0700 (PDT)
Received: from implementers.org (implementers.org [IPv6:2001:4b98:dc0:45:216:3eff:fe7f:7abd]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 822A03A195F for <stir@ietf.org>; Thu, 8 Apr 2021 12:54:58 -0700 (PDT)
Received: from [IPv6:2601:648:8400:8e7d:d250:99ff:fedf:93cd] (unknown [IPv6:2601:648:8400:8e7d:d250:99ff:fedf:93cd]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "Marc Petit-Huguenin", Issuer "implementers.org" (verified OK)) by implementers.org (Postfix) with ESMTPS id 042A2AE255; Thu, 8 Apr 2021 21:54:54 +0200 (CEST)
From: Marc Petit-Huguenin <marc@petit-huguenin.org>
To: Christer Holmberg <christer.holmberg@ericsson.com>, "stir@ietf.org Mail List" <stir@ietf.org>
References: <AM0PR07MB38609E8F69EBD4516A0DC86893749@AM0PR07MB3860.eurprd07.prod.outlook.com> <65247929-dd31-ccbf-ab3b-ef2a64b0de99@petit-huguenin.org> <AM0PR07MB3860F044E886F39B6990259293749@AM0PR07MB3860.eurprd07.prod.outlook.com>
Message-ID: <2695c31e-9040-3d9d-b30e-41bb8c6fa89b@petit-huguenin.org>
Date: Thu, 08 Apr 2021 12:54:53 -0700
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.9.0
MIME-Version: 1.0
In-Reply-To: <AM0PR07MB3860F044E886F39B6990259293749@AM0PR07MB3860.eurprd07.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/_yGZ9vXge6xv5Eqpr_c51Tyh3w4>
Subject: Re: [stir] For the sake of implementers, please verify errata in a timely manner: ppt= with/without quotes
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Apr 2021 19:55:01 -0000

On 4/8/21 12:44 PM, Christer Holmberg wrote:
> Hi,
> 
>>>> 5. https://protect2.fireeye.com/v1/url?k=7fd536e0-204e0fdc-7fd5767b-86b1886cfa64-26b897891e272008&q=1&e=dcc3cd11-966a-4e58-8216-7894ec032d39&u=https%3A%2F%2Fwww.rfc-editor.org%2Ferrata%2Feid6499
>>>>
>>>> I disagree with that -- wrong examples, especially from another SDO, should not change normative text.   In itself adding quotes around a token is puzzling.  An additional
>>>> unintended consequence is that quoted strings are case-sensitive, whereas tokens are case >insensitive, so that may create an additional interop issue.
>>>
>>> Note that ppt= is used with quotes also in RFC 8443 and RFC 8946, so it is not just "from another SDO".
>>
>> Right.  Still, that's changing the normative part (ABNF) because the informative part (examples) is wrong.  Should that be the other way around?
> 
> There is the perfect world, and there is the real world :)
> 
> I think the question is: what (if any) has been deployed?

Well, people at my $dayjob are currently testing a STIR/SHAKEN solution, and the value of the ppt parameter is not quoted.  My (separate) implementation does not quote either, but it will never be deployed in production, so I suppose that does not count.

-- 
Marc Petit-Huguenin
Email: marc@petit-huguenin.org
Blog: https://marc.petit-huguenin.org
Profile: https://www.linkedin.com/in/petithug