Re: [Tls-reg-review] [IANA #1161720] IANA assignments for draft-ietf-tls-subcerts

Sean Turner <sean@sn3rd.com> Thu, 06 February 2020 10:15 UTC

Return-Path: <sean@sn3rd.com>
X-Original-To: tls-reg-review@ietfa.amsl.com
Delivered-To: tls-reg-review@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98055120916 for <tls-reg-review@ietfa.amsl.com>; Thu, 6 Feb 2020 02:15:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id msT8mO5YKcEb for <tls-reg-review@ietfa.amsl.com>; Thu, 6 Feb 2020 02:15:11 -0800 (PST)
Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F256120921 for <tls-reg-review@ietf.org>; Thu, 6 Feb 2020 02:15:11 -0800 (PST)
Received: by mail-qt1-x82d.google.com with SMTP id d9so4007346qte.12 for <tls-reg-review@ietf.org>; Thu, 06 Feb 2020 02:15:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=16H5ye32EFkOy/+adzpmC09UVtnMpccL9tE99c0HsBQ=; b=hWZoKPcap7DKKmci4CvmKfh0z8+1KDT+8G+TH6uMVfwUetALMXLrwo+SVl38gl/Dn5 hp7QxmTLWS8Qbbd315+sbdO3T83rrkdjAzTV0s/uFfjsheEQJ2e4h1PIZfB554diZvRv gmiD3NIPFuFyCsj2drtxNnYzt0YkMrJ6OAxNo=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=16H5ye32EFkOy/+adzpmC09UVtnMpccL9tE99c0HsBQ=; b=SLx7MpSYDCxZcjs3A07wcdPE0q007z3FxGCv1hFpmjawBBQc9cUFGEKGl5wfG45eWe xvs8K7ShtjM2QdZDi2785ZB6tPZZopaUCUCW9wbIcSwoqDPUJDC0X4mk59wYUHjPqZ8y 3AX6oYyiVFN55lZyLBUQUHfTiE2N1sx+MN5aPHflis9ci4fNA8bB3423JhPig1OFhZPp 33sAOTxglw4/BHgbumfPeMWqYK5ihGLcgUSzg11o3GXCX/XdSO79Yp/kZ0VuDF17y8wA DT4k+eVBmCGyn9o2fs7XsRBnGfHumxRiGYtA4YxiY5tf1kOSdqOyVOu3wT59IbvJsKlL 2fVg==
X-Gm-Message-State: APjAAAVD7VjPovAcHMinHDa9zd3B893kLFg2eT1l7LaTSUB8ujT5bNz+ diTIO+DT4Lnv/tJ6qftN7foSCA==
X-Google-Smtp-Source: APXvYqwXt5EGUJeTrKxOLAcStzUwIHRHoyF32xa0o5+7moCAFMQpeL/yWtKIYS29qhvjTVINY/xZ+Q==
X-Received: by 2002:ac8:405a:: with SMTP id j26mr1906213qtl.88.1580984110374; Thu, 06 Feb 2020 02:15:10 -0800 (PST)
Received: from [5.5.33.104] ([204.194.23.17]) by smtp.gmail.com with ESMTPSA id r10sm1186323qkm.23.2020.02.06.02.15.09 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 06 Feb 2020 02:15:09 -0800 (PST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <rt-4.4.3-7673-1580979306-846.1161720-37-0@icann.org>
Date: Thu, 06 Feb 2020 11:15:07 +0100
Cc: tls-reg-review@ietf.org, tls-ads@ietf.org, Russ Housley <housley@vigilsec.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <CBBCA08A-5F09-4D07-801E-9B725DD1BF8E@sn3rd.com>
References: <RT-Ticket-1161720@icann.org> <8AB42A8D-B2E1-40FE-91E2-D16673FAC1C0@sn3rd.com> <rt-4.4.3-7673-1580979306-846.1161720-37-0@icann.org>
To: Amanda Baber via RT <iana-prot-param@iana.org>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls-reg-review/5MJybiSNHEgEKF6ev_UyXk1wMf0>
Subject: Re: [Tls-reg-review] [IANA #1161720] IANA assignments for draft-ietf-tls-subcerts
X-BeenThere: tls-reg-review@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: TLS REVIEW <tls-reg-review.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls-reg-review>, <mailto:tls-reg-review-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls-reg-review/>
List-Post: <mailto:tls-reg-review@ietf.org>
List-Help: <mailto:tls-reg-review-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls-reg-review>, <mailto:tls-reg-review-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Feb 2020 10:15:19 -0000


> On Feb 6, 2020, at 09:55, Amanda Baber via RT <iana-prot-param@iana.org> wrote:
> 
> Hi Sean, all,
> 
> 1) We've already assigned TLS ExtensionType value 34 to delegated_credentials, but with "Recommended" set to "Y":
> 
> https://www.iana.org/assignments/tls-extensiontype-values
> 
> Rich, Nick, Yoav: can you confirm that this should be changed to "N"?
> 
> 2) If Russ approves, how should we fill in the "Description" field for the SMI Security for PKIX Module Identifier registration? Examples here:
> 
> https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.0

From the draft:
id-mod-delegated-credential-extn

> thanks,
> Amanda
> 
> On Thu Feb 06 07:37:21 2020, sean@sn3rd.com wrote:
>> DEs,
>> 
>> On behalf of the TLS WG, I am requesting the following assignments for:
>> https://datatracker.ietf.org/doc/draft-ietf-tls-subcerts/
>> 
>> For convenience I have included them below:
>> 
>> 1. For TLS DEs: Update of the TLS ExtensionType Registry
>> 
>> This document registers the "delegated_credentials" extension in the
>> "TLS ExtensionType Values" registry. The "delegated_credentials"
>> extension has been assigned a code point of TBD. The IANA registry
>> lists this extension as “Not Recommended" (i.e., "N")* and indicates
>> that it may appear in the ClientHello (CH), CertificateRequest (CR),
>> or Certificate (CT) messages in TLS 1.3 [RFC8446].
>> 
>> * The Recommended column will change from “N" to “Y” when the draft
>> is in AUTH48. We cannot request that the TLS DEs set the Recommended
>> to “Y” until this draft, which is a WG draft intended for standards
>> track, has progressed beyond the IESG.
>> 
>> 2. For PKIX DE: Update of the SMI Security for PKIX Registry Request
>> 
>> This document also defines an ASN.1 module for the DelegationUsage
>> certificate extension in Appendix A. IANA is requested to register
>> an Object Identifier (OID) for the ASN.1 in "SMI Security for PKIX
>> Module Identifier" arc. An OID for the DelegationUsage certificate
>> extension is not needed as it is already assigned to the extension
>> from Cloudflare's IANA Private Enterprise Number (PEN) arc. 
>> 
>> Many Thanks!
>> 
>> spt
>