Re: [Suit] RFC 9124 on A Manifest Information Model for Firmware Updates in Internet of Things (IoT) Devices

Russ Housley <housley@vigilsec.com> Fri, 14 January 2022 20:06 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EAD93A094A for <suit@ietfa.amsl.com>; Fri, 14 Jan 2022 12:06:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wz2ZTQF4LSgU for <suit@ietfa.amsl.com>; Fri, 14 Jan 2022 12:06:00 -0800 (PST)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E83423A0920 for <suit@ietf.org>; Fri, 14 Jan 2022 12:05:59 -0800 (PST)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 8B735112839; Fri, 14 Jan 2022 15:05:58 -0500 (EST)
Received: from a860b60074bd.fios-router.home (pool-141-156-161-153.washdc.fios.verizon.net [141.156.161.153]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 78FE1112838; Fri, 14 Jan 2022 15:05:58 -0500 (EST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.21\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <20220114195258.AD7CE20D6A0@rfc-editor.org>
Date: Fri, 14 Jan 2022 15:05:58 -0500
Cc: suit <suit@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <827E644D-2E42-4FE4-97A7-B7CE4222D973@vigilsec.com>
References: <20220114195258.AD7CE20D6A0@rfc-editor.org>
To: Brendan Moran <Brendan.Moran@arm.com>, Hannes Tschofenig <Hannes.Tschofenig@arm.com>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>
X-Mailer: Apple Mail (2.3445.104.21)
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/dJJYeIxa7fOgOpe64hDxfMz6S3c>
Subject: Re: [Suit] RFC 9124 on A Manifest Information Model for Firmware Updates in Internet of Things (IoT) Devices
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 14 Jan 2022 20:06:04 -0000

Congratulations for finally getting this across the finish line!

Russ


> On Jan 14, 2022, at 2:52 PM, rfc-editor@rfc-editor.org wrote:
> 
> A new Request for Comments is now available in online RFC libraries.
> 
> 
>        RFC 9124
> 
>        Title:      A Manifest Information Model for Firmware Updates
>                    in Internet of Things (IoT) Devices
>        Author:     B. Moran,
>                    H. Tschofenig,
>                    H. Birkholz
>        Status:     Informational
>        Stream:     IETF
>        Date:       January 2022
>        Mailbox:    Brendan.Moran@arm.com,
>                    hannes.tschofenig@gmx.net,
>                    henk.birkholz@sit.fraunhofer.de
>        Pages:      40
>        Updates/Obsoletes/SeeAlso:   None
> 
>        I-D Tag:    draft-ietf-suit-information-model-13.txt
> 
>        URL:        https://www.rfc-editor.org/info/rfc9124
> 
>        DOI:        10.17487/RFC9124
> 
> Vulnerabilities with Internet of Things (IoT) devices have raised the
> need for a reliable and secure firmware update mechanism that is also
> suitable for constrained devices. Ensuring that devices function and
> remain secure over their service lifetime requires such an update
> mechanism to fix vulnerabilities, update configuration settings, and
> add new functionality.
> 
> One component of such a firmware update is a concise and
> machine-processable metadata document, or manifest, that describes
> the firmware image(s) and offers appropriate protection. This
> document describes the information that must be present in the
> manifest.
> 
> This document is a product of the Software Updates for Internet of Things Working Group of the IETF.
> 
> 
> INFORMATIONAL: This memo provides information for the Internet community.
> It does not specify an Internet standard of any kind. Distribution of
> this memo is unlimited.
> 
> This announcement is sent to the IETF-Announce and rfc-dist lists.
> To subscribe or unsubscribe, see
>  https://www.ietf.org/mailman/listinfo/ietf-announce
>  https://mailman.rfc-editor.org/mailman/listinfo/rfc-dist
> 
> For searching the RFC series, see https://www.rfc-editor.org/search
> For downloading RFCs, see https://www.rfc-editor.org/retrieve/bulk
> 
> Requests for special distribution should be addressed to either the
> author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
> specifically noted otherwise on the RFC itself, all RFCs are for
> unlimited distribution.
> 
> 
> The RFC Editor Team
> Association Management Solutions, LLC
> 
> _______________________________________________
> IETF-Announce mailing list
> IETF-Announce@ietf.org
> https://www.ietf.org/mailman/listinfo/ietf-announce