Return-Path: <denis.ietf@free.fr>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 4B849130EB1
 for <suit@ietfa.amsl.com>; Wed,  4 Jul 2018 01:18:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.587
X-Spam-Level: 
X-Spam-Status: No, score=-2.587 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001,
 RCVD_IN_DNSWL_LOW=-0.7, T_KAM_HTML_FONT_INVALID=0.01,
 URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id GNlckT7LLaRk for <suit@ietfa.amsl.com>;
 Wed,  4 Jul 2018 01:18:38 -0700 (PDT)
Received: from smtp6-g21.free.fr (smtp6-g21.free.fr [IPv6:2a01:e0c:1:1599::15])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 5F2FF130E2F
 for <suit@ietf.org>; Wed,  4 Jul 2018 01:18:38 -0700 (PDT)
Received: from [192.168.0.13] (unknown [88.182.125.39])
 by smtp6-g21.free.fr (Postfix) with ESMTP id 1BF2078031A;
 Wed,  4 Jul 2018 10:18:36 +0200 (CEST)
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>,
 "suit@ietf.org" <suit@ietf.org>
References: <VI1PR0801MB2112A08944328EE625D4DE5CFA430@VI1PR0801MB2112.eurprd08.prod.outlook.com>
 <ec04d5da-0b76-f4d7-c548-e69579530856@free.fr>
 <VI1PR0801MB21127B3F43736CA592FD52B5FA420@VI1PR0801MB2112.eurprd08.prod.outlook.com>
From: Denis <denis.ietf@free.fr>
Message-ID: <fb5f56bb-9779-2ac6-8211-58947c7e0ae4@free.fr>
Date: Wed, 4 Jul 2018 10:18:36 +0200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101
 Thunderbird/52.8.0
MIME-Version: 1.0
In-Reply-To: <VI1PR0801MB21127B3F43736CA592FD52B5FA420@VI1PR0801MB2112.eurprd08.prod.outlook.com>
Content-Type: multipart/alternative;
 boundary="------------11A70F2A6E0906D0581F8B26"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/NWC0k01sULOiVbsA3_Z5jjVVzUk>
Subject: Re: [Suit] draft-ietf-suit-architecture-01
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>,
 <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>,
 <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Jul 2018 08:18:53 -0000

This is a multi-part message in MIME format.
--------------11A70F2A6E0906D0581F8B26
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit

Hannes,

In the security considerations section, it would be worthwhile to 
indicate that the threats are addressed in details
in section 3.2 (Threat Descriptions) from [I-D.ietf-suit-information-model].

Denis

> Hi Denis,
>
> I think the risk of installing an old firmware version is covered in 
> the information model document, which goes into the details of what a 
> manifest has to contain. See Section 3.2.1 of 
> https://tools.ietf.org/html/draft-ietf-suit-information-model-01
>
> There are essentially three types of documents the working group is 
> aiming to produce: an architecture document, the information model for 
> the manifest and one or multiple serialization formats. You have been 
> looking at the architecture but the appropriate document to read is 
> the information model spec.
>
> Ciao
>
> Hannes
>
> *From:*Suit [mailto:suit-bounces@ietf.org] *On Behalf Of *Denis
> *Sent:* 03 July 2018 11:59
> *To:* suit@ietf.org
> *Subject:* Re: [Suit] draft-ietf-suit-architecture-01
>
> Hannes,
>
> It is well known that software updates are often done to address a 
> security issue. The same applies
> to firmware updates. The current draft is lacking to address 
> protections against the downloading of
> an old firmware version. The threat should be mentioned in the 
> security considerations section.
>
> The main body of the document should mention mechanisms to prevent the 
> replay of an old version
> of the firmware.
>
> Denis
>
>     Hi all,
>
>     I have just submitted version -01 of the architecture document. I
>     have incorporate feedback from the working group, such as
>
>     ·New terminology,
>
>     ·Updates on the operating modes
>
>     ·New architecture figures,
>
>     ·New use cases (by David Brown)
>
>     Here is the new version:
>
>     https://tools.ietf.org/html/draft-ietf-suit-architecture-01
>
>     Here is the diff:
>
>     https://tools.ietf.org/rfcdiff?url2=draft-ietf-suit-architecture-01.txt
>
>     Feedback is appreciated.
>
>     Ciao
>
>     Hannes
>
>     IMPORTANT NOTICE: The contents of this email and any attachments
>     are confidential and may also be privileged. If you are not the
>     intended recipient, please notify the sender immediately and do
>     not disclose the contents to any other person, use it for any
>     purpose, or store or copy the information in any medium. Thank you.
>
>
>     _______________________________________________
>
>     Suit mailing list
>
>     Suit@ietf.org <mailto:Suit@ietf.org>
>
>     https://www.ietf.org/mailman/listinfo/suit
>
> IMPORTANT NOTICE: The contents of this email and any attachments are 
> confidential and may also be privileged. If you are not the intended 
> recipient, please notify the sender immediately and do not disclose 
> the contents to any other person, use it for any purpose, or store or 
> copy the information in any medium. Thank you. 



--------------11A70F2A6E0906D0581F8B26
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">Hannes,<br>
      <br>
      In the security considerations section, it would be worthwhile to
      indicate that the threats are addressed in details<br>
      in section 3.2 (Threat Descriptions) from <span class="insert">[I-D.ietf-suit-information-model].<br>
        <br>
        Denis</span><br>
      <br>
    </div>
    <blockquote type="cite"
cite="mid:VI1PR0801MB21127B3F43736CA592FD52B5FA420@VI1PR0801MB2112.eurprd08.prod.outlook.com">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	color:black;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New","serif";
	color:black;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0cm;
	margin-right:0cm;
	margin-bottom:0cm;
	margin-left:36.0pt;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	color:black;
	mso-fareast-language:EN-US;}
span.EmailStyle18
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;
	color:black;
	mso-fareast-language:EN-US;}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:599023614;
	mso-list-type:hybrid;
	mso-list-template-ids:1503316698 1632670534 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}
@list l0:level1
	{mso-level-start-at:0;
	mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Symbol;
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:"Courier New","serif";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Symbol;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:"Courier New","serif";}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Symbol;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:"Courier New","serif";}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span style="color:#1F497D">Hi Denis, <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I think the
            risk of installing an old firmware version is covered in the
            information model document, which goes into the details of
            what a manifest has to contain. See Section 3.2.1 of
            <a
              href="https://tools.ietf.org/html/draft-ietf-suit-information-model-01"
              moz-do-not-send="true">https://tools.ietf.org/html/draft-ietf-suit-information-model-01</a><o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">There are
            essentially three types of documents the working group is
            aiming to produce: an architecture document, the information
            model for the manifest and one or multiple serialization
            formats. You have been looking at the architecture but the
            appropriate document to read is the information model spec.
            <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Ciao<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Hannes<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #B5C4DF
            1.0pt;padding:3.0pt 0cm 0cm 0cm">
            <p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext;mso-fareast-language:EN-GB"
                  lang="EN-US">From:</span></b><span
style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:windowtext;mso-fareast-language:EN-GB"
                lang="EN-US"> Suit [<a class="moz-txt-link-freetext" href="mailto:suit-bounces@ietf.org">mailto:suit-bounces@ietf.org</a>] <b>On
                  Behalf Of </b>Denis<br>
                <b>Sent:</b> 03 July 2018 11:59<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:suit@ietf.org">suit@ietf.org</a><br>
                <b>Subject:</b> Re: [Suit]
                draft-ietf-suit-architecture-01<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <div>
          <p class="MsoNormal"><span
              style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">Hannes,</span><br>
            <br>
            <span
              style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;"
              lang="EN-US">It is well known that software updates are
              often done to address a security issue. The same applies
              <br>
              to firmware updates. The current draft is lacking to
              address protections against the downloading of
              <br>
              an old firmware version. The threat should be mentioned in
              the security considerations section.<br>
              <br>
              The main body of the document should mention mechanisms to
              prevent the replay of an old version
              <br>
              of the firmware.<br>
              <br>
              Denis<br>
              <br>
            </span><o:p></o:p></p>
        </div>
        <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
          <p class="MsoNormal">Hi all, <o:p></o:p></p>
          <p class="MsoNormal"> <o:p></o:p></p>
          <p class="MsoNormal">I have just submitted version -01 of the
            architecture document. I have incorporate feedback from the
            working group, such as
            <o:p></o:p></p>
          <p class="MsoListParagraph"
            style="text-indent:-18.0pt;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
              style="font-family:Symbol"><span style="mso-list:Ignore">·<span
                  style="font:7.0pt &quot;Times New Roman&quot;">        
                </span></span></span><!--[endif]-->New terminology, <o:p></o:p></p>
          <p class="MsoListParagraph"
            style="text-indent:-18.0pt;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
              style="font-family:Symbol"><span style="mso-list:Ignore">·<span
                  style="font:7.0pt &quot;Times New Roman&quot;">        
                </span></span></span><!--[endif]-->Updates on the
            operating modes <o:p></o:p></p>
          <p class="MsoListParagraph"
            style="text-indent:-18.0pt;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
              style="font-family:Symbol"><span style="mso-list:Ignore">·<span
                  style="font:7.0pt &quot;Times New Roman&quot;">        
                </span></span></span><!--[endif]-->New architecture
            figures, <o:p></o:p></p>
          <p class="MsoListParagraph"
            style="text-indent:-18.0pt;mso-list:l0 level1 lfo2"><!--[if !supportLists]--><span
              style="font-family:Symbol"><span style="mso-list:Ignore">·<span
                  style="font:7.0pt &quot;Times New Roman&quot;">        
                </span></span></span><!--[endif]-->New use cases (by
            David Brown)<o:p></o:p></p>
          <p class="MsoNormal"> <o:p></o:p></p>
          <p class="MsoNormal">Here is the new version: <o:p></o:p></p>
          <p class="MsoNormal"><a
              href="https://tools.ietf.org/html/draft-ietf-suit-architecture-01"
              moz-do-not-send="true">https://tools.ietf.org/html/draft-ietf-suit-architecture-01</a><o:p></o:p></p>
          <p class="MsoNormal"> <o:p></o:p></p>
          <p class="MsoNormal">Here is the diff: <o:p></o:p></p>
          <p class="MsoNormal"><a
href="https://tools.ietf.org/rfcdiff?url2=draft-ietf-suit-architecture-01.txt"
              moz-do-not-send="true">https://tools.ietf.org/rfcdiff?url2=draft-ietf-suit-architecture-01.txt</a><o:p></o:p></p>
          <p class="MsoNormal"> <o:p></o:p></p>
          <p class="MsoNormal">Feedback is appreciated. <o:p></o:p></p>
          <p class="MsoNormal"> <o:p></o:p></p>
          <p class="MsoNormal">Ciao<o:p></o:p></p>
          <p class="MsoNormal">Hannes<o:p></o:p></p>
          <p class="MsoNormal"><span
              style="font-size:12.0pt;font-family:&quot;Times New
              Roman&quot;,&quot;serif&quot;;mso-fareast-language:EN-GB">IMPORTANT
              NOTICE: The contents of this email and any attachments are
              confidential and may also be privileged. If you are not
              the intended recipient, please notify the sender
              immediately and do not disclose the contents to any other
              person, use it for any purpose, or store or copy the
              information in any medium. Thank you.
              <br>
              <br>
              <br>
              <o:p></o:p></span></p>
          <pre>_______________________________________________<o:p></o:p></pre>
          <pre>Suit mailing list<o:p></o:p></pre>
          <pre><a href="mailto:Suit@ietf.org" moz-do-not-send="true">Suit@ietf.org</a><o:p></o:p></pre>
          <pre><a href="https://www.ietf.org/mailman/listinfo/suit" moz-do-not-send="true">https://www.ietf.org/mailman/listinfo/suit</a><o:p></o:p></pre>
        </blockquote>
        <p><o:p> </o:p></p>
      </div>
      IMPORTANT NOTICE: The contents of this email and any attachments
      are confidential and may also be privileged. If you are not the
      intended recipient, please notify the sender immediately and do
      not disclose the contents to any other person, use it for any
      purpose, or store or copy the information in any medium. Thank
      you.
    </blockquote>
    <p><br>
    </p>
  </body>
</html>

--------------11A70F2A6E0906D0581F8B26--

