Re: [stir] draft-housley-stir-enhance-rfc8226-00

Sean Turner <sean@sn3rd.com> Thu, 04 February 2021 20:26 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 936AB3A17E7 for <stir@ietfa.amsl.com>; Thu, 4 Feb 2021 12:26:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ofmywA2SKemm for <stir@ietfa.amsl.com>; Thu, 4 Feb 2021 12:26:53 -0800 (PST)
Received: from mail-qt1-x835.google.com (mail-qt1-x835.google.com [IPv6:2607:f8b0:4864:20::835]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BD4283A17DD for <stir@ietf.org>; Thu, 4 Feb 2021 12:26:53 -0800 (PST)
Received: by mail-qt1-x835.google.com with SMTP id h16so3380013qth.11 for <stir@ietf.org>; Thu, 04 Feb 2021 12:26:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=TUu3ZhFOvHYgoLi9Bf8wkDUeihV5RHmkiDWOxlMyrZc=; b=cgSmIBTOgVxwC36AAEOFGnAVc8FakI++qdpPKmWjDB7RJkQapfO6zVdQBYAPfsVus+ CfKoObQ/gCLkTlyPVMbZxb3ah/sTkGpjxAkmaoslGyesBgB1mBxyyy3EqI+yCLbEyZgU 8PaFiI737+sGHdrSp0ywr4xoYkVT23STrq790=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=TUu3ZhFOvHYgoLi9Bf8wkDUeihV5RHmkiDWOxlMyrZc=; b=PZ1qfBq8IrrCjwLTbpGmp0CpxbpEwczIAtZOUr0YQEYrRgF6pIlYxRq3RuPmSGLebw jQGsnNcKmV6hxgV5X+U0AmV23AJkmcFEEOIXC1bvxnjDxRvlfqrIYoAC1SULCxcyHj4j V3HiQBO7kXAA3VO3xLd0zJGJSqJUC5jt4kGLZJq+uak3VxLmKhRB6uFV+hPslpjketp7 O+nnvhpV7rF0dGiqS88GIhCKU6BiNoCchFoH4TrJQi7QSCGPlQHGJL47bL93cywb54J0 1cW3hHLHdrfPwD6ckZPWE0YAkfzjxrBNl25wa4ulYAigHEDs7ZpH4H+bnA+EJo6QH8W3 34Hw==
X-Gm-Message-State: AOAM530NxXS+gTTiXDv3ZFI+L4kn+MgmzlPUpKbw2+44zxHWhIo5m9S+ WctglKMpK0++yXTtjK4bGwo/VgamzMyprFnS
X-Google-Smtp-Source: ABdhPJytnQ8E4KEofuxYNwStm3CzTpD+8T1vigOcGfW5QHfMCg/Vz565+yFxr2AEhIrOcGlllY9xsA==
X-Received: by 2002:ac8:1094:: with SMTP id a20mr1381058qtj.248.1612470412740; Thu, 04 Feb 2021 12:26:52 -0800 (PST)
Received: from [192.168.1.152] (pool-108-31-39-252.washdc.fios.verizon.net. [108.31.39.252]) by smtp.gmail.com with ESMTPSA id b72sm6090365qkc.60.2021.02.04.12.26.50 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 04 Feb 2021 12:26:51 -0800 (PST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <6515CC12-1A12-4524-9EB9-5C46D01855CF@vigilsec.com>
Date: Thu, 04 Feb 2021 15:26:50 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <95BB2CB1-B149-40A9-9B6E-CD6EADF5FBD9@sn3rd.com>
References: <161126455434.3362.14572023954174036871@ietfa.amsl.com> <6515CC12-1A12-4524-9EB9-5C46D01855CF@vigilsec.com>
To: Russ Housley <housley@vigilsec.com>
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/pdZ_1NqjqiGQVi9TkIE4pMapqmU>
Subject: Re: [stir] draft-housley-stir-enhance-rfc8226-00
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Feb 2021 20:27:02 -0000

I knew we should have added this at the time ;) Let’s do it.

spt

> On Jan 21, 2021, at 16:32, Russ Housley <housley@vigilsec.com> wrote:
> 
> Please review and comment.  Christ Wendt has found some use cases where the JWT Claims Constraints in RFC 8226 are not adequate.  This I-D proposes an enhancement to make the constraints more rich.
> 
> Russ
> 
> 
>> From: internet-drafts@ietf.org
>> Subject: New Version Notification for draft-housley-stir-enhance-rfc8226-00.txt
>> Date: January 21, 2021 at 4:29:14 PM EST
>> To: "Russ Housley" <housley@vigilsec.com>
>> 
>> 
>> A new version of I-D, draft-housley-stir-enhance-rfc8226-00.txt
>> has been successfully submitted by Russ Housley and posted to the
>> IETF repository.
>> 
>> Name:		draft-housley-stir-enhance-rfc8226
>> Revision:	00
>> Title:		Enhanced JWT Claim Constraints for STIR Certificates
>> Document date:	2021-01-21
>> Group:		Individual Submission
>> Pages:		8
>> URL:            https://www.ietf.org/archive/id/draft-housley-stir-enhance-rfc8226-00.txt
>> Status:         https://datatracker.ietf.org/doc/draft-housley-stir-enhance-rfc8226/
>> Htmlized:       https://datatracker.ietf.org/doc/html/draft-housley-stir-enhance-rfc8226
>> Htmlized:       https://tools.ietf.org/html/draft-housley-stir-enhance-rfc8226-00
>> 
>> 
>> Abstract:
>>   RFC 8226 provides a certificate extension to constrain the JWT claims
>>   that can be included in the PASSporT as defined in RFC 8225.  If the
>>   signer includes a JWT claim outside the constraint boundaries, then
>>   the recipient will reject the entire PASSporT.  This document defines
>>   additional ways that the JWT claims can be constrained.
>> 
>> 
>> 
>> 
>> Please note that it may take a couple of minutes from the time of submission
>> until the htmlized version and diff are available at tools.ietf.org.
>> 
>> The IETF Secretariat
>> 
>> 
> 
> _______________________________________________
> stir mailing list
> stir@ietf.org
> https://www.ietf.org/mailman/listinfo/stir