[Suit] Follow-up AD review on draft-ietf-suit-manifest-24

Roman Danyliw <rdd@cert.org> Sun, 29 October 2023 00:12 UTC

Return-Path: <rdd@cert.org>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF1D4C14F73F for <suit@ietfa.amsl.com>; Sat, 28 Oct 2023 17:12:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cert.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ECqb9P-zxLRd for <suit@ietfa.amsl.com>; Sat, 28 Oct 2023 17:12:04 -0700 (PDT)
Received: from USG02-CY1-obe.outbound.protection.office365.us (mail-cy1usg02on0133.outbound.protection.office365.us [23.103.209.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6F6BBC14F726 for <suit@ietf.org>; Sat, 28 Oct 2023 17:12:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=hSgXz+oImkGlC0tLSPq9fGnXTIMb7VCkuUprvNpX40CxrtG7l+HHeMXMK6NyssGyjTmRattwEPMXL2VFHvBzt+IHqKfVkmOCS1+n7qSsefr4tOWQUj7E6APOX0Q/YAE+HBMhLBMpoHVovvIV3G9RVnr1JZR3hjHNmv6G+LeMd19FKaqnHZssi9fRDR/NPglIYdEJQnsK8x7MdyDz6Vvl30T55cihqV7KZB6XYK2LGMpi+QGiJhJ8kvA7Ac4xZPOL3DTopRUsGsArzcxFzFVdoRTm7+HN2gXLTE82i8P+epkDbL4uqmYwFliLDnQN7GpTN8gcDB09azeU/lvfJo7gRw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=VdgqteXAsKAgF/u+4BfvSHkTGpNvD9741AzxXssR04c=; b=xNqKSNgVEYfHQbwIqMQox/7XixRFglfPzBsNittl66MKatH7MCuH02NjfKuclAwyznu6p+1XOAsUWIK+fyxxoDEWPNwu6ELtUMowjO+GJU8b06MEVwVgmeIitqxIMAG3VqB+2eHgIIbdXLJt/CVFMjfZeXRcZU5rjlP4m5ji7PWv3J1zvYchS3AY1ftQZ//nAqDptmQ0T4cJ45SCOAQ82pXnPAuq91hG9u1Kg9uOvNQ33g2+lVhVTGna8gTmQOsIFPDMoOkOjTMKGRr0pyB5j/5UlhNzQPv73iRUv8BJsGVjlZBd8viyBVEY4jd5UPd97e+/U+Lzkaf1oAf9gUF4pw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cert.org; dmarc=pass action=none header.from=cert.org; dkim=pass header.d=cert.org; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cert.org; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=VdgqteXAsKAgF/u+4BfvSHkTGpNvD9741AzxXssR04c=; b=DDMBtIN6bHtpojtBIOgGijIM/9DBAz88R4ry1S36XbKr/wiO5CE5Q2FzaERkd9vWuxg5LlNKI5DaAp+9fzXoVGXJQfea4kCSs0gsUFb4oluN9W/P4PDfSb95dnSdbTvYVH+et8omORY83O8wNrz0GNEtcZiHRIBKM9MnqQnSmxo=
Received: from BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:168::11) by BN2P110MB1732.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:169::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6863.51; Sun, 29 Oct 2023 00:12:00 +0000
Received: from BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM ([fe80::44ae:335c:4fd2:ea74]) by BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM ([fe80::44ae:335c:4fd2:ea74%6]) with mapi id 15.20.6863.051; Sun, 29 Oct 2023 00:12:00 +0000
From: Roman Danyliw <rdd@cert.org>
To: "suit@ietf.org" <suit@ietf.org>
Thread-Topic: Follow-up AD review on draft-ietf-suit-manifest-24
Thread-Index: AdoJ++6dvEzpnWQCSPWY5QTaTbOuuA==
Date: Sun, 29 Oct 2023 00:12:00 +0000
Message-ID: <BN2P110MB110702374844312296933A93DCA2A@BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cert.org;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BN2P110MB1107:EE_|BN2P110MB1732:EE_
x-ms-office365-filtering-correlation-id: e0dace2a-b60c-43b5-1574-08dbd813abec
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: LfruacUSjweLkQXBYLYLbESXI+0H8JUbF3PY7z71bQPnnOAy2hM87QsIhv0WCihwaapvMPGCNo8KaOSYCSmPUZcevJE5o2FN8ytMoRCz4YbhlSts7NoQqSknT1mAB+HsZOwXyZxGuml9tJYovPztJ9AgkuFzR6w6NJa0OKLvjQ8POAH0adFTErwASVZhwJXG8dgskED3Jt43QHWz1JdsH1T30C0lTrdJSXw9lKyuJZPaeL/IPvSYkRbwsTw7ifvsMnrFenFsyYcWKRxzmaE0wUo77cQ5tfDk6I/AsJNrE3TmU7NwMl9A0F3YLurU5ejsOQ6rjHOyOcf1sVJ4JiuX1VLwQ+6MBwKpn02q1xn1rcHvh3smFs+v6bR38t8T1W+UD40gpFE7lMD8RbXOgDe3dsK9R4rbwGlpETxNmNlb1rfDCgWYOiC1uZw/Y6t3REYGm1P/dhNFSI4S0nfCMq6YixUs2Z+IF8YjsgQXWN8CpQFk/d27hZ/Vup5VFhTrJaAVXXaBLzSbMm3kDjJE1WFZYFtcT2bpe0ELQeL3RAU7MBI427oc2d86esXVjTGi/0GsExqU88KN9vy9S4/dJs3FuIxxABuvCfz44tXVYBVPeGRpxCDJp4c9+iRZEtG3lskowyKfdIBxPaGV3EQA/3Ogvw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(396003)(39830400003)(136003)(366004)(230373577357003)(230473577357003)(230922051799003)(64100799003)(451199024)(186009)(1800799009)(55016003)(7696005)(2906002)(5660300002)(38100700002)(82960400001)(76116006)(66446008)(66476007)(66556008)(71200400001)(6916009)(508600001)(64756008)(9686003)(966005)(6506007)(66946007)(86362001)(41300700001)(52536014)(8936002)(33656002)(122000001)(8676002)(41320700001)(38070700009)(26005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: OWNqKmMXQ6PoQOXthSXx8ZzONy3oK1HPXmjzAZONySMvj5W8XoD4i9FvrwUWD3cHfa9Z8cmc3KDpuxv5z5XkvtqNH3K7ZPo5pHPTqYpcNJvhiibtUWfbjQxy3Z5+OjH+ZFB/6XxZaz7teQN93hmYem5tgb0Vo+c9b2TjcfOl/N9oOhMlZ2s/A1AkQHgHtcjnPRQn/nAkKih6vRmg4liQVFHfhL2as5JAEGiIRLLzqWde54sm6Dz+XMhWnaE/Sgx+LvYUYy63mpGv17Pvj56fnfzedf3o7fDQUtcWmq0/zUHpOZlLw9llkjFSk+vZagB4e7/0UsGuRS1YerYJn7CO3e/ZvNrIU9ROHHUQlmlKgiPpyINh9STwAAbk5oEWefkOFzPs/ZPIJ7eS/KcdPkY5KDY6m6zLmwAtYeaE0d9paUy9XzCDQ3Z3TSw5G9HdzgpPrmvrmyNULeEiKjafgDyfP3ek9KGc1g6PaIf4JE/wlsOaMY7hp2MtfMbdOkDB9tVoAABNvFCE50IX0GyvwEDOdk0No9GjcqHU6iJ/CMVejfI7dP5srD/WP5ozNzyJQirpBa2VtYMX08fofhsmJdu2mX9Wft9da8bMnMU8EqVDQyrhGofBm7XzX6kta/TB7UQuUr0SkGpYE3GvhSwAyOJkS/42J7wtc6PZtnNogW0+AmIQAL8UJYP24ybWV65iT1+Um6h9vKY1M1Vo5wyfdeTOWIyaRSTQ/dcFsgL7DVCr9KlhpZakevSmVeQGdBuxpxVtg1oUTIUpsRR90xjB1VpV3fUY1pNLfLCXEGkX/Xp+RP+QA0MFwEPmiiPf3DNJHrb2LIfAFJ/CVC7+5fzO15kk3sm5hcv6cbOu8mfpYGuo54naZKSeeajsQt3NUEnzcU8psrubagPQqVKT0smsAkFF/WA61dCaiT+wYFq4cdsZfsm7cZhZWz9+bEOqZHcJl3l174gFyy28Z7d15FLm21fHaR38/WEr3iVE4WuLE6Br1bTtG29H/IheGAGj5M8pVEcSi8JxQbGZcUeJWFEhlI9iR641r5KXDy191X1vGOEzq6uNhBXE9oDE8+VJTp3ohAWJ434hz/KqEEmWFNM0z3NgW3GQsofvKbyk11Idsn8q6qUZIAKQQNWE6G+pEdB+NUz6WybBRedPb8xll4WR+ovskpek6FV63/zyOceA1xIL8kh+Ac1SW/zZXdeeAH0vrTsv8otKKa2Vz2XkxeEO8KL1oYR8ZztaZrCVWcQzRe7a+1v/z2zi6i39ZxYLmM11ih5R2wSQus251BpmbujfatgyTHJJV7ZmlDRm1wPurJQp58rll1miahXhDXUKvyA6qSSin/6l+jevwIREtd65BOEG4xDGs2Bm6msNOnXAtenG+geAqT5WKq4j3TzNL7HvMq+K4PxgRHWM5nYqRG2NxT3FWPTE4G0p5AaJ27UKPNiWIAinfvRzIpYBCjpm0ts5CEwKzs0g3OKFTVfuC2t9ODUpxa6gC1+BTYTKg+ihVb8w0mk=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: cert.org
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BN2P110MB1107.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: e0dace2a-b60c-43b5-1574-08dbd813abec
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Oct 2023 00:12:00.3174 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 95a9dce2-04f2-4043-995d-1ec3861911c6
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN2P110MB1732
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/Vy44OGqjnN_58zA_2jnupPGTcOk>
Subject: [Suit] Follow-up AD review on draft-ietf-suit-manifest-24
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Oct 2023 00:12:09 -0000

Hi!

Thanks for all of the work to produce -24.  In the spirit of tracking where things stand, the following residual AD review feedback remains from the original on -22 (https://mailarchive.ietf.org/arch/msg/suit/Ak_sFp1PaZcIRSol5Ge_xH2FN-w/) or -23 (https://mailarchive.ietf.org/arch/msg/suit/MJNk7-SBiRrEPRugmZKTlwkQ9jA/).

** Section 5.3.4.  Editorial and introduced in -23: Per “see {#ovr-integrated}, are integrity-checked …”, there is misspelled Markdown reference.

** This document referenced RFC4122.  The bis for it, draft-ietf-uuidrev-rfc4122bis, is in IESG review.  Consider if there is a reason why it could not be used instead.  This feedback come during other IESG reviews of documents referencing RFC4122.

** https://github.com/suit-wg/manifest-spec/issues/108 and 

https://github.com/suit-wg/manifest-spec/issues/107 and


-- REQ.SEC.IMG.CONFIDENTIALITY (Section 4.3.12 of RFC9124)

The manifest information model MUST enable encrypted payloads.

...

Implemented by:  Encryption Wrapper (Section 3.20)

This document does not describe any mechanism to encrypt a payload.  Section 3 says:

This specification covers the core features of SUIT.  Additional
   specifications describe functionality of advanced use cases, such as:

   *  Firmware Encryption is covered in
      [I-D.ietf-suit-firmware-encryption]

However, this reference is not normative and isn't consider a core feature.