Re: [Suit] Surprising push back on the need for a customer to verify the trust relationship between a software supplier and software signer during digital signature validation on signed code

Dick Brooks <dick@reliableenergyanalytics.com> Fri, 11 June 2021 11:14 UTC

Return-Path: <dick@reliableenergyanalytics.com>
X-Original-To: suit@ietfa.amsl.com
Delivered-To: suit@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 86A563A33D4 for <suit@ietfa.amsl.com>; Fri, 11 Jun 2021 04:14:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level:
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=messagingengine.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yZ0-1OfwG-Hs for <suit@ietfa.amsl.com>; Fri, 11 Jun 2021 04:14:27 -0700 (PDT)
Received: from forward4-smtp.messagingengine.com (forward4-smtp.messagingengine.com [66.111.4.238]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 822CF3A33C9 for <suit@ietf.org>; Fri, 11 Jun 2021 04:14:24 -0700 (PDT)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailforward.nyi.internal (Postfix) with ESMTP id 206F81940435; Fri, 11 Jun 2021 07:14:21 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162]) by compute6.internal (MEProxy); Fri, 11 Jun 2021 07:14:21 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:reply-to:subject:to :x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; bh=IemFSagydLbecYcfAVd603KvqxYtPq5KcRjnkakZve4=; b=r5uXwJ+b AFKVBR4/Klp1Wm/LLDtU/PQYB1qLsMZf4d7qagOaIxJDuvRpqpmEzEEMT/mah7q4 tlGvaeR6z6xmvGrWduy+cKjKWJmybKtTNfWpcsyzOnHPsK7KUlGRgVcOLHdj7PO1 XmMiz+xqRXGAF+8go0vmQw/3/bBnXZ7k9VU7favAsNpdyTWYSPvwr1XLFlM7J7UD CGQp0mTu/9KlZiNfx5bL5qCqtkVsNuGfhcBGLnx69qehdBhXyAZyp7AJCs6yBsmE +os0DXoFdVtkYh5zhlJSUpXc/3h+86P22/ZanQHiSSmPehclixcYiRnr897B2gqZ F0SYBNQXKOlHBg==
X-ME-Sender: <xms:jEXDYFUe702QpFPtuhFw5lnwi6R01o_cWrrNZG0DF0zf0gZ7UVl2gA> <xme:jEXDYFlkYvjx0qW7AcAmfyFiHoJonMvbT9XVFweREjf09K8bAStiVFF3z5PTJ9Kpo AR9TfYVA22MDujomg>
X-ME-Received: <xmr:jEXDYBYIec-0wKdaz5M_0lLgpl45f9gaCQR_7KkIMO4CbQRCiEPng8g>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrfedujedgfeeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurheprhfhvfhfjgfuffhokfggtgfothesrhdtghepvddtvdenucfhrhhomhepfdff ihgtkhcuuehrohhokhhsfdcuoeguihgtkhesrhgvlhhirggslhgvvghnvghrghihrghnrg hlhihtihgtshdrtghomheqnecuggftrfgrthhtvghrnhepvefgteetffeuuefhvedvtdeh vdfgfffgfedvvdeujeevtefhgeetieegjedttddtnecuffhomhgrihhnpehgihhthhhusg drtghomhdprhgvlhhirggslhgvvghnvghrghihrghnrghlhihtihgtshdrtghomhenucev lhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhmpeguihgtkhesrh gvlhhirggslhgvvghnvghrghihrghnrghlhihtihgtshdrtghomh
X-ME-Proxy: <xmx:jEXDYIWh9-CBOAepRKG7T5aNZzYoox6UCey5z7uwsbu1WQjjWerQog> <xmx:jEXDYPkHbb2-Y17tCVkp8e0PGof49e2ruJhDAq7Fk27rqHS94MZPYg> <xmx:jEXDYFe3CGUPLhfCgev-NHm5qr5R7XUYNgLNPqyw27bfdhrrgZgj-w> <xmx:jUXDYFRpo1iWcBP9Xbsb9Evl7JRrvdUe5fD7qJqtIo3dF5b0J9itxQ>
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 11 Jun 2021 07:14:20 -0400 (EDT)
Reply-To: dick@reliableenergyanalytics.com
From: Dick Brooks <dick@reliableenergyanalytics.com>
To: 'Russ Housley' <housley@vigilsec.com>
Cc: 'suit' <suit@ietf.org>
References: <0f9601d75adf$5856cf50$09046df0$@reliableenergyanalytics.com> <DBBPR08MB59155DB5DBE123F55B25894BFA359@DBBPR08MB5915.eurprd08.prod.outlook.com> <068401d75df6$d8e0d430$8aa27c90$@reliableenergyanalytics.com> <10E26450-1218-456E-AFD7-2D434A5A2CBB@vigilsec.com>
In-Reply-To: <10E26450-1218-456E-AFD7-2D434A5A2CBB@vigilsec.com>
Date: Fri, 11 Jun 2021 07:14:17 -0400
Organization: Reliable Energy Analytics LLC
Message-ID: <1d8701d75eb2$ed720060$c8560120$@reliableenergyanalytics.com>
MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_000_1D88_01D75E91.6660AE80"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQGWV7HWN1UFe48pVCqNOvWTpeLidgI50GCWALrHFY8B+fo1a6tpQXmQ
Content-Language: en-us
Archived-At: <https://mailarchive.ietf.org/arch/msg/suit/pOfDkEM9escudk9zktHBlGe8ZTk>
Subject: Re: [Suit] Surprising push back on the need for a customer to verify the trust relationship between a software supplier and software signer during digital signature validation on signed code
X-BeenThere: suit@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Software Updates for Internet of Things <suit.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/suit>, <mailto:suit-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/suit/>
List-Post: <mailto:suit@ietf.org>
List-Help: <mailto:suit-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/suit>, <mailto:suit-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jun 2021 11:14:32 -0000

Done.

https://github.com/rjb4standards/REA-Products/blob/master/20210608-NTIAFiled
Comments.pdf

 

 

Thanks,

 

Dick Brooks



 <https://reliableenergyanalytics.com/products> Never trust software, always
verify and report! T

 <http://www.reliableenergyanalytics.com/>
http://www.reliableenergyanalytics.com

Email:  <mailto:dick@reliableenergyanalytics.com>
dick@reliableenergyanalytics.com

Tel: +1 978-696-1788

 

From: Russ Housley <housley@vigilsec.com> 
Sent: Thursday, June 10, 2021 5:41 PM
To: Dick Brooks <dick@reliableenergyanalytics.com>
Cc: suit <suit@ietf.org>
Subject: Re: [Suit] Surprising push back on the need for a customer to
verify the trust relationship between a software supplier and software
signer during digital signature validation on signed code

 

Dick:

 

Russ, I'll share my NTIA comment filing here, if you give me the green light
to do so (about 6 pages in length).

 

Can you post it on a website, and then post a pointer here?

 

Russ