[Teep] FW: Restricted operating Environment

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Tue, 19 November 2019 02:51 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: teep@ietfa.amsl.com
Delivered-To: teep@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A3411207FD for <teep@ietfa.amsl.com>; Mon, 18 Nov 2019 18:51:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=zbxAdMjK; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=armh.onmicrosoft.com header.b=gYlJXgX+
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t5evAK_Vi0Xx for <teep@ietfa.amsl.com>; Mon, 18 Nov 2019 18:50:57 -0800 (PST)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-eopbgr130072.outbound.protection.outlook.com [40.107.13.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E91C120236 for <teep@ietf.org>; Mon, 18 Nov 2019 18:50:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fEXC9wy9BgP6yMnluHd1vcqm4k71/7dvTzqInieeOQU=; b=zbxAdMjKxvjGiJ9Wfk6VbMd7bmsuLpe+5GzEZtZP+j5lXxOhq8EUTrHQ41WgUDf6EFjCMTSTEcl24jDvSYBMakeIObDxmUZKePQOu6wmB+dmCCxHTiOJHhQqCxHRUat2Y5RYS5FR2FbiacwQTzT7vzPLmP8QOTiztJdACkvqJgU=
Received: from VI1PR08CA0175.eurprd08.prod.outlook.com (2603:10a6:800:d1::29) by DB8PR08MB4188.eurprd08.prod.outlook.com (2603:10a6:10:b0::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2451.23; Tue, 19 Nov 2019 02:50:54 +0000
Received: from DB5EUR03FT024.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e0a::209) by VI1PR08CA0175.outlook.office365.com (2603:10a6:800:d1::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2451.23 via Frontend Transport; Tue, 19 Nov 2019 02:50:54 +0000
Authentication-Results: spf=fail (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=none action=none header.from=arm.com;
Received-SPF: Fail (protection.outlook.com: domain of arm.com does not designate 63.35.35.123 as permitted sender) receiver=protection.outlook.com; client-ip=63.35.35.123; helo=64aa7808-outbound-1.mta.getcheckrecipient.com;
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by DB5EUR03FT024.mail.protection.outlook.com (10.152.20.67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2451.23 via Frontend Transport; Tue, 19 Nov 2019 02:50:54 +0000
Received: ("Tessian outbound 0cf06bf5c60e:v33"); Tue, 19 Nov 2019 02:50:54 +0000
X-CR-MTA-TID: 64aa7808
Received: from 5fcced3c315d.1 (cr-mta-lb-1.cr-mta-net [104.47.12.54]) by 64aa7808-outbound-1.mta.getcheckrecipient.com id 60385046-139E-42FE-AEA9-4CCB53BD66DB.1; Tue, 19 Nov 2019 02:50:49 +0000
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04lp2054.outbound.protection.outlook.com [104.47.12.54]) by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 5fcced3c315d.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Tue, 19 Nov 2019 02:50:49 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aFAEtkROncNiqLiSDDqDentvJrQDjj7RZynuScogOeMdyGPmATtdHeEzzR/elhVlD59ajeJi2tzERP/i/nxiur36bwrm+osNe1RUgSTRr9cbREEZzpkvFxHO+YorspX0VtYcnsX8yhhWuET26rk1sA9q/RqxgWGdN6lmQUYdwLHFgbVPOeHBDqDXQgYE8cL47HNH0jJbEIlO86kfFFzwGQoFyEMm1c7uiFo5Fp34BiAIWy0Q0KMklbnKpc/T0LZGr9aF6+h+TcemF82jygVOa6yAwh3t5XzEkuGVAbZ1elCPFlNyEW1ve4H9P4xqFZMB8pRd1cAH3hWltPhFbgzWQA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Qh3xoU6EjTL513YjwgCZ1fRquC7KiXLyRu6xor9CYqw=; b=UxkP5PgSfwApPDrZeyt/AysqBDG7Bd4+a9GOG6k0Ifq6L+Drt144UAQiLomRU3ssxoOV7p5fa8sVzBsmtUsFST4sE7UuhmDs659EachJH0oNGzms6qgUbDV4e9OqX1SFVzEOY9XrQs7xgPbEj9GXRdN/ilE1wV72+FCwcvJ9+xT9N3yUVYiimAiuTEQgjc5Ij/2c+qGkIXn9iESK1ex3WN/fkSFM2a+l0wPnY+m7JwERbQw+/qXP4ezvqDU4mxjyD8JN76nPtmeDkJjyLuJ6WpURBrzw/QAMWvdIu00zJ/FQ6sGGZ69He+tNUn4pLRDNN2jVv44TiOcKNMeRC1rdnw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arm.com; dmarc=pass action=none header.from=arm.com; dkim=pass header.d=arm.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Qh3xoU6EjTL513YjwgCZ1fRquC7KiXLyRu6xor9CYqw=; b=gYlJXgX+vZWlASbX0owhfmfaI20wSoaYQjYgcwEoMRI5xmVWU1GcY4AKAxcA/4UbQ9FtitRwEUJ6TnpH73Mqn4hdxTAEHs1nbJRoaOU2+sxTFGsTQ2rhlx85+GK9MaReU7RJMHHurQVDx6hOZxluskZX9ckkGplYc4VkhvD6lM4=
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com (52.133.245.74) by VI1PR08MB2640.eurprd08.prod.outlook.com (10.170.237.32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2451.23; Tue, 19 Nov 2019 02:50:48 +0000
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d]) by VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::4044:55a8:a969:fd1d%7]) with mapi id 15.20.2451.029; Tue, 19 Nov 2019 02:50:48 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: teep <teep@ietf.org>
Thread-Topic: Restricted operating Environment
Thread-Index: AQHVnoNMav82afLHy0OTCrVYd4prqaeRyv9A
Date: Tue, 19 Nov 2019 02:50:47 +0000
Message-ID: <VI1PR08MB53604591D9233FA71A30E3A8FA4C0@VI1PR08MB5360.eurprd08.prod.outlook.com>
References: <EC895C5D-69F2-419A-A71A-04FFFE77DF45@island-resort.com>
In-Reply-To: <EC895C5D-69F2-419A-A71A-04FFFE77DF45@island-resort.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: 5d7cfdfe-1b82-43e2-8022-e5188eedc407.0
x-checkrecipientchecked: true
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
x-originating-ip: [31.133.155.170]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-HT: Tenant
X-MS-Office365-Filtering-Correlation-Id: a8d56bf6-1be5-4593-1e25-08d76c9b4be3
X-MS-TrafficTypeDiagnostic: VI1PR08MB2640:|DB8PR08MB4188:
X-Microsoft-Antispam-PRVS: <DB8PR08MB4188A12A3F53D2D54BF45C11FA4C0@DB8PR08MB4188.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
x-ms-oob-tlc-oobclassifiers: OLM:6790;OLM:6790;
x-forefront-prvs: 022649CC2C
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(396003)(39860400002)(136003)(346002)(376002)(366004)(199004)(189003)(13464003)(74316002)(71200400001)(8936002)(71190400001)(316002)(76176011)(7696005)(25786009)(6916009)(6436002)(3846002)(9686003)(2473003)(6306002)(55016002)(76116006)(476003)(52536014)(66446008)(64756008)(66556008)(66476007)(66946007)(7736002)(6506007)(14454004)(102836004)(305945005)(26005)(53546011)(33656002)(4744005)(99286004)(186003)(86362001)(966005)(229853002)(478600001)(2906002)(446003)(7116003)(11346002)(5660300002)(6116002)(81156014)(81166006)(8676002)(66066001)(256004)(14444005)(486006); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR08MB2640; H:VI1PR08MB5360.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: eMQ7z8v2VkRAUuve26GSnTd2huLXPHLvQJS2f7cvTHLDDfV9nXzPLkUPoFB7JnxDQ3Qq/1VaTuYKBmgL7oqdwM/fUjlQKlcuQoYGhkldwXDcQzS7SQcgnQP7z4rpI+MTQiwVEmi7K9x64jrwKYwLmPOq/pFBR8sQ4mhuprvrOi1b3k2GdEA3oymgcW33IGjT9PSmSxrtnua04g8/hiWGtN+P9lXRWsV5dyWBEWj4CPux9tk7SHkslV5SaJ0LFkSiI7YjB9Ae5dRAnLNU4vKsa2zn5BbHnO2Kd/UNvPgfwKQ5krUBFK5RwGMyqGmOUCnVDjwXPQSwFjadfnwzXsagO6Ro664SwMaROCUwi1u2L7PShThb/UKY1b9U5XP3VL7K5ilagJp2eycsp+RyE+Wi6Q89W6tCE7rmsIrWrrVRc0YJR0MyWjCTozCuCRCRxWsw
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB2640
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR03FT024.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(396003)(346002)(376002)(136003)(39860400002)(1110001)(339900001)(13464003)(189003)(199004)(40434004)(476003)(70586007)(486006)(126002)(6916009)(966005)(14454004)(52536014)(7696005)(26826003)(2486003)(336012)(23676004)(436003)(5024004)(14444005)(8676002)(102836004)(50466002)(25786009)(6506007)(305945005)(446003)(478600001)(356004)(7116003)(11346002)(26005)(186003)(81166006)(81156014)(8936002)(7736002)(55016002)(229853002)(66066001)(2906002)(76130400001)(47776003)(74316002)(53546011)(76176011)(9686003)(2473003)(6306002)(3846002)(6116002)(86362001)(105606002)(5660300002)(99286004)(316002)(22756006)(33656002)(70206006); DIR:OUT; SFP:1101; SCL:1; SRVR:DB8PR08MB4188; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:Fail; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; MX:1; A:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: b2d9076e-3c08-462b-b50d-08d76c9b4806
X-MS-Exchange-PUrlCount: 1
X-Forefront-PRVS: 022649CC2C
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 7reiCQQN+LatziCCwVVmLClOEF8hCTISv1y5s1tpkFaC448w2uUzPHrVFVCJnU6DnlaXliw4+XdV23ijqgsiCbYN3MOchkyGiBNqk4KK2PY9zFlEF2qKo7W80ObXEKxYv6mOxf2QH4SrrQztHpCtZKiJ1KFhROt8SVWCmDOyf4Yx5bXqslOBgrohHAV7xRZaAn7M5J6mr4uZfJWY7YYQjaNkTJ0gJ2pcFz0D7y8M6czesxc2dNu32AOpC9rXBlq/CcEt85jNyS9V77wHKZWRMQ6sKXJ/miNkD7oVN1PNBctyRg4bY7J2UF82EY5NAJ9pxtILq7707NNdX40T3xDayUucSQozc1pfajaqSPjLsQpm7q5vhAaCIY2OZEVqOI0J01bUDJkVw42pz0p2k3bKdnBZp88+v4gs+sX5Z9v10HvNYyT76aavK+e25VL8Z1JHDp8WJ24XOxeGiYMe6i4jezT4/Yo3LKDQfyRMUcol9bw=
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Nov 2019 02:50:54.4600 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: a8d56bf6-1be5-4593-1e25-08d76c9b4be3
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB8PR08MB4188
Archived-At: <https://mailarchive.ietf.org/arch/msg/teep/HgolBCKeSZjvkStBPivGbzSWiLY>
Subject: [Teep] FW: Restricted operating Environment
X-BeenThere: teep@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A Protocol for Dynamic Trusted Execution Environment Enablement <teep.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/teep>, <mailto:teep-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/teep/>
List-Post: <mailto:teep@ietf.org>
List-Help: <mailto:teep-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/teep>, <mailto:teep-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Nov 2019 02:51:03 -0000

Forward from Laurence on a terminology issue discussed at the meeting today.

-----Original Message-----
From: Laurence Lundblade <lgl@island-resort.com>
Sent: Tuesday, November 19, 2019 10:45 AM
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>; Ben Kaduk <kaduk@mit.edu>; Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com>; Dave Thaler <dthaler=40microsoft.com@dmarc.ietf.org>
Subject: Restricted operating Environment

I’m not on the TEEP list so just sending to you. Please forward.

Keep in mind that this is part of a formal certification program who’s mission is to actually evaluate the security in a precise and well-defined way, and has the legal, financial and policy basis. This is very different from a protocol definition.

https://fidoalliance.org/specs/fido-security-requirements-v1.0-fd-20170524/fido-authenticator-allowed-restricted-operating-environments-list_20170524.pdf

LL

IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.