[TLS] I-D on TLS authentication with VC

Andrea Vesco <andrea.vesco@linksfoundation.com> Thu, 04 April 2024 08:53 UTC

Return-Path: <andrea.vesco@linksfoundation.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E238C14F609 for <tls@ietfa.amsl.com>; Thu, 4 Apr 2024 01:53:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=istitutoboella.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jkR9XkSbN3K9 for <tls@ietfa.amsl.com>; Thu, 4 Apr 2024 01:53:31 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2131.outbound.protection.outlook.com [40.107.20.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 25821C14F5FA for <tls@ietf.org>; Thu, 4 Apr 2024 01:53:30 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=g342ENzoiIuXZjqd7dc0aywt0gxFFLYq9FX4q3VmvZcCgTGlrKMyHeuhtKbdvC3cHuhfgrOhka4wSL0l1o4mU0cVkgm4Zz51KaDWjwq82jaQTXYQLh9pP7oPwJHXY2Xwg+XGSCbY+Ga/zkGSh7VD5h1boZjphKSrX2Cl70xg5smB35G0cQ1dZUiNDjjA9pBQu8p2xroiXTIrtyKPxISkH28fZsbStlXa3WAEgElprrzivfnZwTpp3n5CUL7I5r/5zKEU5qEk9dLondqJcpw8FfIGvk6StcqaZ8HkP/n+T1lLMmyJOh3cl9ll04QOnQfKx3UVINnSQp2zw5KEV82IBA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=33h4wB1WQsEA/TXSLP7zWZQ/Qqd0ZuHKSuqKfdFHJTY=; b=cZK6U6GpuA1uC3MGwpSiTj2l/SyySi4h9piIscUiCBT3OJG1+tg5/MEeGqKTX0OP6rQI8Bf2XCqnzA50Opm5WkCCVvCGv5oaY0uB5LwfcvHC+qGclAn4NkrMXOiEyZo99F+bNuFISoZxNNvhbjbP67g6wMEl2RTKMNDaCAV0jXQ8ABq6rO7wNMSgzfmM5zVCOQtC36Trq2BnhbRFZcvQhiKz/tU4guqOhhgY8tIRvPD+AQ50i/TJnVLmVfX8K4Bocmxh4UK7yO2sWU/q9z6LdwKfnV3OByiuN9xqtEYypfT6+Gvudtaysc/tlsXUV6JYlbviXZ03keN4YP5t7BLYjQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=linksfoundation.com; dmarc=pass action=none header.from=linksfoundation.com; dkim=pass header.d=linksfoundation.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=istitutoboella.onmicrosoft.com; s=selector2-istitutoboella-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=33h4wB1WQsEA/TXSLP7zWZQ/Qqd0ZuHKSuqKfdFHJTY=; b=EygZkyDXHd2qO6LJUiiMnnKTVIdZuLFGepEmtFbFNyDxOrRFdEcpx9esoCNQT75TsZc6dk8wjGTEfyzkA/rp6AtU2MJLH/8FlJB4HjF2M5fovaMuZ8aqjAi5sJIoe8D2a9vjkLG9EqCGWYmoaGa04kTMAZUClZL0/Xal7F542LA=
Received: from DB9P195MB1130.EURP195.PROD.OUTLOOK.COM (2603:10a6:10:268::18) by AM9P195MB1172.EURP195.PROD.OUTLOOK.COM (2603:10a6:20b:3ac::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.46; Thu, 4 Apr 2024 08:53:27 +0000
Received: from DB9P195MB1130.EURP195.PROD.OUTLOOK.COM ([fe80::8fe7:f255:db56:97af]) by DB9P195MB1130.EURP195.PROD.OUTLOOK.COM ([fe80::8fe7:f255:db56:97af%7]) with mapi id 15.20.7409.042; Thu, 4 Apr 2024 08:53:27 +0000
From: Andrea Vesco <andrea.vesco@linksfoundation.com>
To: "tls@ietf.org" <tls@ietf.org>
Thread-Topic: I-D on TLS authentication with VC
Thread-Index: AQHahm2P+aVw5CVAbU+Se6suZ/Y3/A==
Date: Thu, 04 Apr 2024 08:53:27 +0000
Message-ID: <F515427B-EE5A-4514-9787-8BB3F95FC380@linksfoundation.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3731.700.6)
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DB9P195MB1130:EE_|AM9P195MB1172:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: VkjBbF9SRlI6+uqPDbd/H3bNwdacHejeWkRpZcjO4jyD4p99PFpDjAUNe1VCwwZAJ3m6iJBQJkg4HY8gAPC0V1folqq89ZDRRYO+McBpVxa4Fw1WUTCpCnuHKYSJst/bAvRFMrFOXhws93jG80exb6fI4fX1URe7rxzELjq+xh0GodlLNPaXd3y06Qkfwt/1d+HEsL83PReG3nGszaMlfJCa3TDIRunYf1fuZqodqmVQILpEgrkk0hdHDzon+1ddk8EdB8xLwY4i/+4haQe4f9L/htythLjSipP3huc0ogtXiM7bpqgzkOC5pFQcVltnk1CLEzUFrB58tD+q37jD0Kv86edBl+fv3tryw4DYwJrkwegjQV411mDXN8qxgbiGuKvI92wEI/ax+pqVWfz3PUpRFoS/SphNKGOc7r4rqbzB/DergQmWzaErl8xacfGhPBVwl/GDZfgReYw5Y3sByNiFM9h3kupN/BEty9iGWV/rdxiRRSRbcWywIEGF0BnwOKwwGhuOqlb2rrzGhFf+47qkBFfBy/1UDQdGWcgL/qmMcnk5uxKiYbuRXNhCwogPsdS2V6rPIy///bj6SMvTEENDLnNX72G0u0M8n8kH3E8=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB9P195MB1130.EURP195.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(41320700004)(376005)(366007)(1800799015); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: uF3R3eKUbbVKFzAcU7ZCccDqnEEc3pd4gv0fImWvrbWWcHXBO91sRZzBSSF3z91E/L1U7UZPm0NTpKiRJjsl4i6bt1A0v2gKfiNK/09oA9zO1nNIqtT/lM7S7mbvxkjSN4CaJAFOSjIejq9ONlGVhwE8P/cW/wtLOHLmmK+eJTQDWK7yNXZTpr3RS/vVsurIEf19OZbnCB/9U/DWoUbzUTudq2ogc1xKQSoKP76w4xknXiJCBvSccwI8ExOG2/5v9JOp0h2/E20J5rcjEL2Gocx/TvlTj+C158p3MagaYZNAZlkD+cfRV7m2Ef2hji1wZfKFXpi6RvYaC61KEkWrsh2DRLv4eThTsfj2MuRn39AY2Py9yXnSMlLcfurJpR+dafsMGOFEO4+KevpZ2MURBUop50Yet5JL1ViFmR2wg7SBx/RjjOfQ1IWg8s2Au2eFmcSmPmH5DzcZ8vRp5e3JRR3UmfG6gGYr7HJXpmMo9Spzq3fvu9q+Xll2jtJjpGks+X40TpkgYG6YAu5kc4gbe0TIY5ZwyOKSJEraQf6I5vLiOYtZhdJQP6NuKIfTGV8Rj1El59nkBBvFDGYczVrlMoSrbDNWXMVh8onGXf6YOrbQgg1IXtOe9TyOM9ANSN2ZW6wjvzXSdPcy64CIXWerCyYJ23C5zLxMWhgyg8IX6RCuXAsvN+vq06w8DmsGlV/xjJnEGfFfwflPWHy3Qud6TNyX6avRCJXrpz57+RWO5Cw7Cu4q/zeh6dt0zvcdrOBZ+hBqFEmrSjsKu7He9LRRF/WP8P7YuyM1TdA/Voe89B9nNhqRbIt6g5HO5QjnM9ivkO5n9LKlaQiuRjIqVIREnX3eCyowoBgjYjz8FfA2W/ZlNL+0lqqJIrPzWuEfvSX++kP3+z9PalCXA69VQZ/SKImJ1DSRhS0eT7pUjpYyNR6onLsZt89LN6rw9PyN1qbbooPt52MKLvzNSllJWfBv4pbt9Y0BJtayAfh3q565XrnC0b6HZeLBz8622jQqE+z8s+gOTfZEQldZ/NPiXXvm1dWf+3xAPUimByHoKivlCFimlU8vpYv0ynglZt5r6EKoGeN3422bRiITxALBvhcGVlAFSj7qc2II9rhzUB7JLSmVJPkcIWJNk8O6V7C7mXUt1Sb4wvBRJbV5YKclLy70g9GOjT5xqXRr0SeLUQi2lVYlGEPuz3F81t+TLncmr1UuhbDMG3QEYm7QOIVquJ8gJn320UJEj/qg4bF2y/TkW7yd03p7xa2f7pl79e5lYmZxS4P/g5xIYzIFLtw+0sae17uHNYx0Fxw5L/HOrf/f0NlnH9HaVaruwgpyWWev3OxwcqgO67XQE5x9ECJhhpIANYWlPprs97LClsiAAiWirhRYKZNiTuHp0Tv7kfKVp//sUoMzO3noRBiGqgo9z21IMR1ZrXnAabELtepZrssH3gAKxhwYHzfZlu11LD8qGkGChgZZeaj6TsvGb8m6h2PdlozCaBNEaHO4Ca9pGKU1UiBRSuIxtQlJ227aN7InR6nFZX8UGsiiJu9/Obif/zhq+KTLfycvuYBo3qOkO4wqcGl3pMuOLDfzJs0TziuCbYCdc6cTHmmDsELpIv+2UWxCn74LwouOiFE0o+i8SWjB9uA=
Content-Type: text/plain; charset="us-ascii"
Content-ID: <1E1A5D9B2937BF4A88815F159F9EA4D4@EURP195.PROD.OUTLOOK.COM>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: linksfoundation.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB9P195MB1130.EURP195.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 6c651940-8845-4b79-d38e-08dc5484b1b0
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Apr 2024 08:53:27.2880 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 46a5eda7-5583-400d-805d-330f6efe08bd
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 2ysP+IrNcRdZYAnKe5jRNR6DccRnq7HdMAZk9bZWaIKsEE5PPpTS4XGRl+yK5m41UWEhCXqX9MUwle5cUp2RgLHZ+HDc/VNjE+fdcFw1Ropa0t3/0oHK/LK91a8CTWQp
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9P195MB1172
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/McseJJgvrUmX9S5neAuXvRKq0rs>
Subject: [TLS] I-D on TLS authentication with VC
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Apr 2024 08:53:35 -0000

L. Perugini and I have written an I-D on the use of Verifiable Credentials [1][2] as an additional authentication mode in TLS.  We presented the I-D to the ALLDISPATCH WG during IETF119 and the outcome was to explore the potential interest of the TLS WG. The I-D proposes to add (i) a new Certificate Type called VC in addition to X509 and RawPublicKey to the existing client_certificate_type and server_certificate_type extensions and (ii) a new extension called did_methods to carry the list of DID Methods supported by the endpoint to resolve the peer's DID during the validation of the Verifiable Credential. The I-D focuses on the IoT use case.

We are aware of the current discussion in the working group about new code points and would like to know your opinion in the case of this I-D and to explore the possible interest. Thank you in advance for your feedback.

I-D: https://datatracker.ietf.org/doc/draft-vesco-vcauthtls/ 
Code:
 - Provider https://github.com/Cybersecurity-LINKS/openssl-ssi-provider
 - OpenSSL https://github.com/Cybersecurity-LINKS/openssl

[1] https://www.w3.org/TR/vc-data-model-2.0/
[2] https://www.w3.org/TR/did-core/