Re: [Suit] Information model updates

Dick Brooks <dick@reliableenergyanalytics.com> Mon, 24 May 2021 14:01 UTC

Return-Path: <dick@reliableenergyanalytics.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBA833A29FF for <suit@ietfa.amsl.com>; Mon, 24 May 2021 07:01:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level:
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=messagingengine.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ty2cKofn5Lvj for <suit@ietfa.amsl.com>; Mon, 24 May 2021 07:01:19 -0700 (PDT)
Received: from forward4-smtp.messagingengine.com (forward4-smtp.messagingengine.com [66.111.4.238]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86F2D3A29FC for <suit@ietf.org>; Mon, 24 May 2021 07:01:19 -0700 (PDT)
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailforward.nyi.internal (Postfix) with ESMTP id 7759C19403A1; Mon, 24 May 2021 10:01:16 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute3.internal (MEProxy); Mon, 24 May 2021 10:01:16 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:reply-to:subject:to :x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm2; bh=PjhC6G4h5U9HSBi/lQlxU4DfnDcpgWbssXAggPj8+ig=; b=bxYlZEG+ 9wORHVI2WcBfH/CtNJBkXdVYG/Pv6lVhgWvgzY8Vq6gDgKA4yL0mlkC1KXawXNN7 iC1vCbot9A9rOaA4+dAZDuh7nmc+zvGFXZUzWxypPfRFKVolsfHDsCrPNlTr8+YI /jkPlBq5letZgkwwvEl+lgxhY0nGVxd0Kq+0MGP6ovHFWSHjAy8ghc2+iJ70SEe+ K/0fwUjfwo9jEHi9xsjelNlw2xVhzdihGIhuuan+KaCdarSB9jHVNTaD9zUnadkw gEKAEc+UYB5foAJ4teGIm0pnaSNFIaqb8wv7vd/NbLXHW/QpAbkSZqEopYwGx7WK GfRgCN1JJ1djHA==
X-ME-Sender: <xms:q7GrYCyNUnqb_Wskl-eFBiM2z_glWYjyTaIFHuquVj9peLCqZPaG5A> <xme:q7GrYOS_gdSEXNuSwKN74y8I_DLBLNBUHOZKSiUVJOzQKLdJVZK5fx1n2t6Z9TlAO yDYxyOhPFKXicJ4uQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrvdejledgjeefucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurheprhfhvfhfjgfuffhokfggtgfothesrhdtghepvddtjeenucfhrhhomhepfdff ihgtkhcuuehrohhokhhsfdcuoeguihgtkhesrhgvlhhirggslhgvvghnvghrghihrghnrg hlhihtihgtshdrtghomheqnecuggftrfgrthhtvghrnhepiefgvedvffeuleejudfgledt tdelfeeigefhtdegheeghfegfffgvdffteetvdeknecuffhomhgrihhnpegvnhgvrhhghi gtvghnthhrrghlrdgtohhmpdhrvghlihgrsghlvggvnhgvrhhghigrnhgrlhihthhitghs rdgtohhmpdhgihhthhhusgdrtghomhdpihgvthhfrdhorhhgnecukfhppedvudeirddule efrddugedvrddvvdenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhl fhhrohhmpeguihgtkhesrhgvlhhirggslhgvvghnvghrghihrghnrghlhihtihgtshdrtg homh
X-ME-Proxy: <xmx:q7GrYEXkNaM9Gy56B2u85kbUoBMWd9bPuzj258seUdhHTvyS1iH27w> <xmx:q7GrYIibh3NbI9DY5BmQhMjmcK5Ml1fAdz3MqnRnuj-ZQ3oGqgWwhQ> <xmx:q7GrYEAtHZShKDfyB_DrxMBkCUsDVqt3EwhQxNA-dkyNtuIdpXbQaQ> <xmx:rLGrYD-LoMJ5RJwKPWkP1rHoZk0PpO6iFf9EyT8LpQSo-A33UBFw7w>
Received: from Warp9 (unknown [216.193.142.22]) by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 24 May 2021 10:01:15 -0400 (EDT)
Reply-To: dick@reliableenergyanalytics.com
From: Dick Brooks <dick@reliableenergyanalytics.com>
To: 'Russ Housley' <housley@vigilsec.com>, 'Brendan Moran' <Brendan.Moran@arm.com>
Cc: 'suit' <suit@ietf.org>
References: <953A0DFE-D8C3-41B3-8AE3-53729378E00F@arm.com> <44670387-088C-4992-88FC-94B6F15752EE@vigilsec.com>
In-Reply-To: <44670387-088C-4992-88FC-94B6F15752EE@vigilsec.com>
Date: Mon, 24 May 2021 10:01:13 -0400
Organization: Reliable Energy Analytics LLC
Message-ID: <933f01d750a5$4393bae0$cabb30a0$@reliableenergyanalytics.com>
MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_000_9340_01D75083.BC821AE0"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQDJ8Y05KEazaG0vQhpq6KAnOITvNwLfWPqlrPZri2A=
Content-Language: en-us
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/4imUXNrV7GNIXWbi6GCgVENSGr8>
Subject: Re: [Suit] Information model updates
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 May 2021 14:01:25 -0000

Russ, et al,

 

               I’ve raised an issue with regard to software supplier identification and verification as part of a software supply chain verification. I haven’t been paying much attention to the SUIT and MUD work, so I would be curious to know if this issue also effects your work in this area. 

 

https://energycentral.com/c/ec/we-cannot-secure-software-supply-chain-without-sbom 

 

Thanks,

 

Dick Brooks



 <https://reliableenergyanalytics.com/products> Never trust software, always verify and report! ™

 <http://www.reliableenergyanalytics.com/> http://www.reliableenergyanalytics.com

Email:  <mailto:dick@reliableenergyanalytics.com> dick@reliableenergyanalytics.com

Tel: +1 978-696-1788

 

From: Suit <suit-bounces@ietf.org> On Behalf Of Russ Housley
Sent: Monday, May 24, 2021 9:55 AM
To: Brendan Moran <Brendan.Moran@arm.com>
Cc: suit <suit@ietf.org>
Subject: Re: [Suit] Information model updates

 

The IESG is waiting for a revised Internet-Draft to be posted.

 

Russ





On May 13, 2021, at 6:06 AM, Brendan Moran <Brendan.Moran@arm.com <mailto:Brendan.Moran@arm.com> > wrote:

 

I’ve made a number of pull requests to the information model. These should address the issues raised by IESG review. 

 

See here for more information: https://github.com/suit-wg/information-model/pulls

 

Brendan

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you. 

_______________________________________________
Suit mailing list
Suit@ietf.org <mailto:Suit@ietf.org> 
https://www.ietf.org/mailman/listinfo/suit