Re: [Teep] Genart last call review of draft-ietf-teep-otrp-over-http-13

Dave Thaler <dthaler@microsoft.com> Fri, 14 October 2022 19:17 UTC

Return-Path: <dthaler@microsoft.com>
X-Original-To: teep@ietfa.amsl.com
Delivered-To: teep@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4EFD5C1524D9; Fri, 14 Oct 2022 12:17:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.681
X-Spam-Level:
X-Spam-Status: No, score=-2.681 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3wu1tjCcaMgo; Fri, 14 Oct 2022 12:17:24 -0700 (PDT)
Received: from na01-obe.outbound.protection.outlook.com (mail-eastusazlp170100001.outbound.protection.outlook.com [IPv6:2a01:111:f403:c100::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 34FDBC14F738; Fri, 14 Oct 2022 12:17:23 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QYe/lb4n2rocT/8ZYOV7L/6zx+l3htYzMvt03ackOiOcmZQzCB19E/VgwZIas0om+KS1gTOHmNW8SCyMeW5/Y3PqNz/xXBlZWU0pUQNizvlI6lF69SlXvoamUh92uOhTIEyKpP4PQfJuHF6J+4dghlvbeZeG24wrIyEEmz13mKYDDK71fIAyQfL3r+QNsr+iB+9wpV7bfgjonWUqb3QYlPeQoWzT5nTrr0zqxXFBxPXtUdhGZUM6WVfytWabIC2S59TFMEKFCiYQeVoR/ZcmhtLTSYUgmZIeCUV+86AseqBmyv2ITB7vTX49j73fKJYgxfIWg6BaEF6VdzMrwtrODA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=S69yipeNlO4GBpMAcOgDFLt3NP8L5pGBQ1IOvo074k0=; b=n0c/FdFYTTJxeph9SV4vkKweS0WZdKeba4ThBftOqBX/3LC5KuvIYHSlj9stbXyLac5tK15kZgjIZ8DXP5q6YC13o/flIoimczZuwhydTszXWgo7QWbfMjEiPmyDzwjVZcb8Gy64TdVbt/F+e4exJYEXa7Q6ByOLVdADp6iI6TLFDagL0SWLmrUnj2GL9BSzHDmMLA59cMFQ2+nHttIpyKpiL+/SSrvdFMYSnpxHV5AOX0w05/X3W9jAzzdy8H6IMdSO3DQXasUNefy1rlh/6+RkX/wShX2NBcvX+eAh8VeqVTJO0GIutkacsOpRJtPA3vCiVHuyCEXfmtX2yXoC0Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=S69yipeNlO4GBpMAcOgDFLt3NP8L5pGBQ1IOvo074k0=; b=F8mEp2FRNUvOUk1jGQuqwABJNWcMeXtxF4o7HGlPj5IP2ad65kQYhlwga2N/b7hq156AEMGSlLoeQxq4MjUjJWciAg9wPWT6T8N2nEphxltBccL/gqHAtA/kizYnveVWX6AC9Z+wlrj+A3msTp1ZAVAeuDCGO9fIIohLCCMehD8=
Received: from DM4PR21MB3440.namprd21.prod.outlook.com (2603:10b6:8:ad::14) by CY5PR21MB3543.namprd21.prod.outlook.com (2603:10b6:930:c::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5746.9; Fri, 14 Oct 2022 19:17:20 +0000
Received: from DM4PR21MB3440.namprd21.prod.outlook.com ([fe80::5a88:f55c:9d88:4ac2]) by DM4PR21MB3440.namprd21.prod.outlook.com ([fe80::5a88:f55c:9d88:4ac2%2]) with mapi id 15.20.5746.006; Fri, 14 Oct 2022 19:17:19 +0000
From: Dave Thaler <dthaler@microsoft.com>
To: Russ Housley <housley@vigilsec.com>
CC: "draft-ietf-teep-otrp-over-http.all@ietf.org" <draft-ietf-teep-otrp-over-http.all@ietf.org>, "teep@ietf.org" <teep@ietf.org>
Thread-Topic: Genart last call review of draft-ietf-teep-otrp-over-http-13
Thread-Index: AQHYQsw4vjwUFa7aVE6OnhTxH9oooK4PfA+Q
Date: Fri, 14 Oct 2022 19:17:19 +0000
Message-ID: <DM4PR21MB344083982C5476B628BC86BDA3249@DM4PR21MB3440.namprd21.prod.outlook.com>
References: <164848978367.9339.3663967634701398406@ietfa.amsl.com>
In-Reply-To: <164848978367.9339.3663967634701398406@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=f3593fa6-a9f8-4e7f-a0ce-db10fcc155e8; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2022-10-14T19:11:56Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM4PR21MB3440:EE_|CY5PR21MB3543:EE_
x-ms-office365-filtering-correlation-id: 80ac16d4-32cd-4b55-9555-08daae18b6fa
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: oKb16Gi0JMSa9mxq0zxxvFk1QASz0/wPQW7LRzZkCM/4zYPeaBlWljmkGKP6zca+PeA4FkfuG2xQtztovY6guw6V+e6jo+oDOlOV+82KhCXAytrINtd3JFLJ0w9U2DbbA2VPOjQFn+BQss7PMOf7fA5bSued74NCckcNHyG0rzr+ZAQ8gy8HFDi5XBH5019OPDHWIZ6Q0cWZmJa2CDAo3Kr7J6sIoTWLXlKq244gmdPLMeGVjR2mjr8P9oaREZNoIhRACJgk5v7W1fJHM2G9WfHDHiorp2RoqrQltJWdL2euvBtQ9ia+4HyHU7WgXo0Msj0OR+c8d8h/s6fPYblWdkRDk5Td7Y8Gz9O9N8NFBeRDj1eILOL+R+VJiOqyZYrk6VDodUYC0JEFMlo/SoaB8rQ4LojNQeYaju13Ho4YxSIRjfQWFEp7PQnrj97DvV+kyaZ0L+uVBjtIfufh6M+N05CpdOv/i2deZfa6Uz1SE+pDLcE/i0xKOdk9JzvBcbZ23o5MqAan54neMuJxB1rHF5eRUC57XRTZwjL4XV9EjxKBQjOj/icML4IGSniXU2b32SmHSC2PuHWhZIjtzbDplh3+bp4J5YepyS7GxbmBmmDsSEhm9h0fnk+jnRGJZyX9w4w6W/E3XqW2k/ApBgjlC20NpbWvlzpNpVzzpqkOw+upcV0idc1PJ5hhTkHw4qZJ8md8JA4/ym7FgzZwdZBFt5OahLiwdg8q+if6RFuxYLHs0VOkwHNlXNvq5/+i/aL3StUmgcRL/Wm2dnL5sl8CWAz0KO5UDHb0gMfVCRImF43nOiIFmswyjOS/wmXpcV/mSvGf6WnETN+tEbMvExo2d/+uR2VRyQpyh+u/OgYzzFs=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM4PR21MB3440.namprd21.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(39860400002)(136003)(376002)(396003)(346002)(366004)(451199015)(6506007)(9686003)(26005)(53546011)(55016003)(83380400001)(5660300002)(8990500004)(7696005)(186003)(54906003)(66946007)(66476007)(478600001)(8676002)(316002)(6916009)(8936002)(52536014)(71200400001)(76116006)(64756008)(41300700001)(4326008)(66556008)(2906002)(966005)(10290500003)(66446008)(38070700005)(86362001)(38100700002)(122000001)(82960400001)(82950400001)(33656002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Dm5pN7hPoPay+XUNoEXHwXs0LlyCqIOTIDjEGwpwxy4e3qaDRwoz8G0uRzrh8ednQAF9Xr+YF/1p+oAFJic645Mq3s2BHWD82R9YkGC8HZG/SqMxutyqapNKEMjHpkb/pMYAsIZ6pJYl25Twzh219Iyx2t0IOKMVCl0Uhty1ALcagMxdEjMJWbyJAvopJpvSSuzmNGms/xmqQrJGHLvnzZ2yZ0/6YKmAVnrIca6WfT9f3ixuAdJc2l9pHNL+czA3bPR253KWghKcZbrYE1Cf1kAetH7Wu7FEifQxnd+D4B8w2H2psxO6F9zaeHtbzOSdEpGkr11AqbQwKI7zcW6UBBtp9GqS6lJKW92hUwG2JmVWHv5JNe8d0mt+dq2Cn79+Bcc8j/QfO3eub4eyllKrp4xIv0ndzS8s+bkaMnP7ydmcNdfPeuFSCSKl8Bf3BTCvol+TlJgxevCTlmGqBd5Q8WzZKcPdh2A9Al1zNbjTfyxelP43UgBuvWUYKIj1nT0c92R2VIwAJMv1aFnThYQKaQMZ3lekbZuJslk1I4KCCBPEp6oTAjxGqqHiq3YtWSrxgLy1m6nPWe6VqP3inImDMHiQAdXHOq8/SpbqBHZ9ktk9siTSboWlExf3YLpLhfpMYQNqiqub1RZ4jv7DdBzHMbbVX+sQm/I4zN67Ng0/rnIbJoCKgO3nIG5b3Rmz3nBBRkQNwNPqUV39+CtJfjHnAVmGuA/SOEA8we4nmphIApqLvCYyzKUpRWdpxPflzwdv0voeN81gG2cRLLPcWnGWQOkGr9/nGp/LM8kSzJg2+UAuwQIXP3jeiMRkelcGInrbNeW+6477UdwM1yuBVNjtKBk/IxWyMjX1Uv2jBo398umLaZVOS/cgH+P3RxvF2BCUnt0udm0Hky5r5ZP4E5feCdHd/+MHlIlrY/hGjx0dDu955y6qgJgqvCEtXtZYgUxAc3nkd/NYTCvkVXRVbGAOWaBQuAtAuP/Ep4HW5w2EngOsTPjjb/TsO7Jbsme+YG35fDnIOOlyAkezwCj/UTokBIuxOyZUEklcAHMT6XENWIJAyFEmyEPW32G06otJTcwEfXzWUX/rTDvXSVuGBaJewJ/byaJyiGY7OqwdCQE8Easa43l5kmM6kfR5iCkWkZfNIlasrMn+BT9pqbBrcrWkDONYxsmqCGct7EfRWWQjSZvot/fIH+XaP/KrRyaFYcnWio1YiAaJrEJtE4FnXjvjzO6sCpipAya4zDSPSsnrDL1bnX2baxeG1iUCVkZC79zDMDvRkWRY4xzP591i0SaAx6Fn0ahUvGD0eYK9OacW6NP53whmGVORcRsstA0lgS2+jng1DfwU5qBlWHJcPRBpRxDIZSK/JAWbCrSNBzWBtjV1UM/w8+4wffTK9bMgA8oi/r9tBdEvCGxqpVDM6Cg+CdOsc/Ex4N3tHDX3yQQKzvH89BoQtE/nCRntU8STd5sYQwWOsoVxOLLfmXc4urHLM2cBBjrSxAkqZN3h4V9mLsfnBjuzz9IPXuj1X+FivH+9ekPxRN3B4OBhaLoLNEf/JRYpADA8V1t2kRiwlaKBmEjB8KmrbxjsS8jD2kEps0dxMg5wUrfLCsVJlETECr7DJg==
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM4PR21MB3440.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 80ac16d4-32cd-4b55-9555-08daae18b6fa
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Oct 2022 19:17:19.8513 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 2w8mDNOJj/9ZU4fRiCG1mkaLlRv1K9CWd3jFTjMCsvEhuz7EpR/P8Td5hy458KqhZ0tdeunCXUmFfFCwAqOsF3t0X6F1K6vklSrIyainTUk=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY5PR21MB3543
Archived-At: <https://mailarchive.ietf.org/arch/msg/teep/3_LHny0vZShkFvWSFkiY-OodJAU>
Subject: Re: [Teep] Genart last call review of draft-ietf-teep-otrp-over-http-13
X-BeenThere: teep@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A Protocol for Dynamic Trusted Execution Environment Enablement <teep.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/teep>, <mailto:teep-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/teep/>
List-Post: <mailto:teep@ietf.org>
List-Help: <mailto:teep-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/teep>, <mailto:teep-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 14 Oct 2022 19:17:25 -0000

> -----Original Message-----
> From: Russ Housley via Datatracker <noreply@ietf.org>
> Sent: Monday, March 28, 2022 10:50 AM
> To: gen-art@ietf.org
> Cc: draft-ietf-teep-otrp-over-http.all@ietf.org; last-call@ietf.org;
> teep@ietf.org
> Subject: Genart last call review of draft-ietf-teep-otrp-over-http-13
> 
> Reviewer: Russ Housley
> Review result: Almost Ready
> 
> I am the assigned Gen-ART reviewer for this draft. The General Area Review
> Team (Gen-ART) reviews all IETF documents being processed by the IESG for
> the IETF Chair.  Please treat these comments just like any other last call
> comments.

Thanks Russ for the review!

[...]
> Major Concerns:
> 
> Section 1 says:
> 
>    This document specifies the middle layer (TEEP-over-HTTP), whereas
>    the top layer (TEEP) is specified in [I-D.ietf-teep-protocol].
> 
> I think this should be expanded to provide a reference for the HTTP layer as
> well.  Something like:
> 
>    TEEP implementations MUST support HTTP [RFC9110].

Section 4 already stated: "This document uses HTTP [I-D.ietf-httpbis-semantics] as a transport." which reference is now RFC 9110 so it was already explicit there. However, I have updated section 1 to say:

+ This document specifies the middle layer (TEEP-over-HTTP), whereas
+ the top layer (TEEP) is specified in {{I-D.ietf-teep-protocol}}
+ and the bottom layer (HTTP) is specified in {{!RFC9110}}.

> I realize that this document references I-D.ietf-httpbis-semantics, which talks
> about HTTP/1.0, HTTP/1.1, HTTP/2, and HTTP/3, and it says:
> 
>    All three major versions of HTTP rely on the semantics defined by
>    this document.  They have not obsoleted each other because each one
>    has specific benefits and limitations depending on the context of
>    use.  Implementations are expected to choose the most appropriate
>    transport and messaging syntax for their particular context.
> 
> Therefore, it might appropriate for this document to select a version of HTTP
> for interoperability.

RFC 9205 section 4.1 states:

> Because HTTP is a hop-by-hop protocol, a connection can be handled by
> implementations that are not controlled by the application; for example, proxies,
> CDNs, firewalls, and so on. Requiring a particular version of HTTP makes it difficult
> to use in these situations and harms interoperability. Therefore, it is NOT
> RECOMMENDED that applications using HTTP specify a minimum version of HTTP
> to be used.
>
> However, if an application's deployment benefits from the use of a particular
> version of HTTP (for example, HTTP/2's multiplexing), this ought be noted.
>
> Applications using HTTP MUST NOT specify a maximum version, to preserve the
> protocol's ability to evolve.

Since the middle paragraph case does not apply to TEEP, we follow the RFC guidance above to NOT specify a minimum or maximum version.

[Russ continues:] 
> Minor Concerns:
> 
> The Abstract says: "An implementation of this document can (if desired) run
> outside of any TEE, but interacts with a TEEP implementation that runs inside
> a TEE."  This is a little bit confusing.  I think that it is trying to say that one oc
> the TEEP implementations must be running inside the TEE that is being
> managed by the TAM, but the TAM side on the protocol does not need to be
> implemented in a separate TEE of its own.  I hope that I got that right.  The
> most straightforward clarification might be to add a sentence about the client
> side of the protocol, TEEP "Agent", runs in the TEE that is being managed by
> the TAM.  Please clarify.

I removed the sentence from the abstract since it is not essential in the abstract. The second paragraph of the introduction already gave a better explanation, and to that paragraph I have appended the new sentence:

+ See section 6.2 of [I-D.ietf-teep-architecture] for a depiction of various
+ implementation models.

since that has a figure that is highly relevant here.

> Section 8 should be expanded.  In Section 4, the document says:
> 
>    However, there may be constrained nodes where code space is an issue.
>    [RFC7925] provides TLS profiles that can be used in many constrained
>    nodes, but in rare cases the most constrained nodes might need to use
>    HTTP without a TLS stack, relying on the end-to-end security provided
>    by the TEEP protocol.
> 
> Section 8 ought to discuss this a bit more.  That is, when TLS is not used, what
> are the additional security considerations?

Added:

+ See Sections 4.4.2 and 6 of {{RFC9205}} for more discussion of additional security
+ considerations that apply in this case.

> Nits:
> 
> Section 1, s/A fuller discussion of/A more complete discussion of/

Done.
 
> IDnits reports:
> 
>   -- Possible downref: Normative reference to a draft: ref.
>      'I-D.ietf-httpbis-semantics'
> 
> This document will be published on the standards track, so it will not be a
> downref.

Updated to point to RFC 9110 since the ref is now an RFC.

Latest copy with the above changes is visible at
https://github.com/ietf-teep/teep-over-http/blob/master/draft-ietf-teep-otrp-over-http.md
and I will submit as an updated I-D shortly.

Dave