Re: [Suit] [suit]: draft-moran-suit-manifest-02

David Brown <david.brown@linaro.org> Mon, 09 July 2018 19:16 UTC

Return-Path: <david.brown@linaro.org>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2807C130E7F for <suit@ietfa.amsl.com>; Mon, 9 Jul 2018 12:16:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=linaro.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SReA7UHVEIJE for <suit@ietfa.amsl.com>; Mon, 9 Jul 2018 12:16:54 -0700 (PDT)
Received: from mail-io0-x229.google.com (mail-io0-x229.google.com [IPv6:2607:f8b0:4001:c06::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D1220130E73 for <suit@ietf.org>; Mon, 9 Jul 2018 12:16:54 -0700 (PDT)
Received: by mail-io0-x229.google.com with SMTP id q9-v6so18071252ioj.8 for <suit@ietf.org>; Mon, 09 Jul 2018 12:16:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:content-transfer-encoding:in-reply-to :user-agent; bh=P1wY8VtdkhIROsMSWTBa6tCd7fr9NacZxiXqSTmKXkw=; b=V9x+NwrwiMbCBKdOwtlhFKAF+LaPQpr2Z9+hXVcyJ8JlpxIVGq27A97O+GqyKw4M+p WSKUvbb5U3G/TY7KOV8NsR+vDsDIY7VM+1s+UYduJ0BqdshirErM0iDSrtShVD9FyqRu /Mdy2dqL097IqJroy5UeufZD6BCXdf37QxPc4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to:user-agent; bh=P1wY8VtdkhIROsMSWTBa6tCd7fr9NacZxiXqSTmKXkw=; b=enjlFEfyku5l6y/sKZlbUXgkOgXunldepDTnS0Ze1LwfjTWDHDL8JJ9Ym/AdzGOOff Iz+5EofgHkP6LDYCF1w32LE1hOb9nRXaAguNTz/no/xzYYAIkXuidEUA1ZGZloxJh9By aVxKx5s/0xY9Psb9qnK3AKat0LP6nTvrYEqsEmZLKXS2sjmIlcRqA/Lf5QNfscgB6nXg RcxOgOn6yqbyTQKNKpb8jocS6r+V9bYyp3rvlJE4j0Luh/TTGb0TBOrGpphjeQ9ylMmU JzDFIeYrKTPihk4pQU7v2hLe8Z+uCnFIQzQl98a2uvUeNkgQFGeT2aA5Ltixh8c8xRG+ BfpA==
X-Gm-Message-State: AOUpUlGt7LLwuDnsW8rs8YS1bvvEZOIUHac1Ci0j77COamVvfjpIFZ62 UlltQdteA/m1y1Lp6u09HYIcz2hIO6I=
X-Google-Smtp-Source: AAOMgpcSLQaGzx+cEg9kzV17RgOxxVnydYw20uH631vqadB4BSjTlNswVqr+nRnS6o59UCmoN1aCzw==
X-Received: by 2002:a6b:3809:: with SMTP id f9-v6mr18803667ioa.105.1531163813784; Mon, 09 Jul 2018 12:16:53 -0700 (PDT)
Received: from davidb.org ([2601:283:4300:987c:6245:cbff:fe6d:5400]) by smtp.gmail.com with ESMTPSA id m203-v6sm7713302ioa.2.2018.07.09.12.16.52 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 09 Jul 2018 12:16:53 -0700 (PDT)
Date: Mon, 09 Jul 2018 13:16:51 -0600
From: David Brown <david.brown@linaro.org>
To: Brendan Moran <Brendan.Moran@arm.com>
Cc: suit <suit@ietf.org>, Hannes Tschofenig <Hannes.Tschofenig@arm.com>
Message-ID: <20180709191651.GA27024@davidb.org>
References: <FDAB87B5-A7CB-4BBC-B7CF-763355B099D8@arm.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <FDAB87B5-A7CB-4BBC-B7CF-763355B099D8@arm.com>
User-Agent: Mutt/1.9.4 (2018-02-28)
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/fhtEMHOdRL4Tyms0CaFUlJvPvFQ>
Subject: Re: [Suit] [suit]: draft-moran-suit-manifest-02
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Jul 2018 19:16:57 -0000

On Tue, Jul 03, 2018 at 09:08:02PM +0000, Brendan Moran wrote:
>This draft is a significant departure from previous drafts, so I think it is
>important to highlight the changes. The draft requires a lot of text that
>hasn’t been written yet, so I will try to put some of that here for discussion.
>
>[1]https://datatracker.ietf.org/doc/draft-moran-suit-manifest/

># Digest info at the top level
>Digests are used in many places in the manifest. The information required to
>interpret digests, therefore, must be a top-level element. All digests in any
>given manifest must use the same digest algorithm.

Is this possibly overly constraining?  For very resource-constrained
devices, it is reasonable to expect the device to only have a single
digest algorithm available in it.  Would we want another digest
algorithm available to allow higher-processing systems to perhaps use
a stronger check.

I think if we want require a single digest format per manifest, there
should at least be motivating text for doing it this way, as well as
why there is only a single digest allowed per entity.

David