Re: [TLS] 2nd WGLC for Delegated Credentials for TLS

Jonathan Hoyland <jonathan.hoyland@gmail.com> Thu, 02 July 2020 14:20 UTC

Return-Path: <jonathan.hoyland@gmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0A8AF3A0874 for <tls@ietfa.amsl.com>; Thu, 2 Jul 2020 07:20:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7WVEbBT_tZF1 for <tls@ietfa.amsl.com>; Thu, 2 Jul 2020 07:20:39 -0700 (PDT)
Received: from mail-ua1-x92e.google.com (mail-ua1-x92e.google.com [IPv6:2607:f8b0:4864:20::92e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72FDD3A0867 for <tls@ietf.org>; Thu, 2 Jul 2020 07:20:39 -0700 (PDT)
Received: by mail-ua1-x92e.google.com with SMTP id q15so8760728uap.4 for <tls@ietf.org>; Thu, 02 Jul 2020 07:20:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=yRPPOL3HO5fiqowwFHi7HjpDHHTiSkGqpCaYZABvRoQ=; b=rfMe+stzapYCBvPS3T6+W09PwvyGtjRBHgDGMeHHYtD2yohsSMrdxXheuxK86g9sFw G2OvskxqByUrlrarmdIB32xFISG6YFB6nzLzQHKiwV0uM56Cv5/0Ob2fSOaUpa2YoUmM neZLcxVMoH5NDFD5TJnEpgTPXuaExjLZ6v1Wj8rpTtMukz3nSgsPuAKxjDd9MsgpUqHb xjrGWuFXRof86AspiczdvA4FxFLcH6E84R+4nFbpi5Z1wAW/9wQaJ4t6K3VzH063iCTP 0dW0GpZ48NffGjMrljHlzW479tHKu+6RYnNz0h77m7aMmbrRAYxfDzV5c8c2J8aKdSzl QrHA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=yRPPOL3HO5fiqowwFHi7HjpDHHTiSkGqpCaYZABvRoQ=; b=YR4kdcio2aL26gcp3cJ8nNLbgjxeqCYK8QIW978WTrKg/358rUEHQRWxPCrsDkScMl oFfC3x24ZS08mizs7F3ehDIzlCWvvNpuQKlDTPoeibL/68zTQKsXm5Bn6MIhm5sHllVP 76jtxPej4lbt4nrjOA5WVpSoTiv1PM+oHPpVrWOoZbP4RyEN/MGWl+mNDsmhL3O7ibOZ msZFNTA1Vc/bnmhkAnzqUYoqoVBZW60Vd0Xk/I8P8CG8fAsExzHjvRT8x+6K/zitxnCK KQsgYn9YkqlASOZbA0xIbBM48NHv4MgiPlBFHpZ3hM3Htm3tVbRBKnOYG5gLgtla5p8s H0ww==
X-Gm-Message-State: AOAM531CWlejgCYtc2fD6btjf2lBO7+tqqLcTJAyY059cpEzJrz8QGZ2 TAPVunQyBpGno4WAzyOaUtZDosNg1gMIC3RFDG+phc5Pgv4=
X-Google-Smtp-Source: ABdhPJzwQFY94bWX9bLMk0JUwo/dqMcnUtFOSatC/n2GFDaqePR+/nS1dKeBgrUIDu7UHg60bDSVC3XRutcj7hY2r6w=
X-Received: by 2002:a9f:36e5:: with SMTP id p92mr1783077uap.27.1593699638403; Thu, 02 Jul 2020 07:20:38 -0700 (PDT)
MIME-Version: 1.0
References: <CAOgPGoB3LDZ2uMJkMyDxMbbWy6yScYuURVB7GqTiwVS0f2UkTw@mail.gmail.com>
In-Reply-To: <CAOgPGoB3LDZ2uMJkMyDxMbbWy6yScYuURVB7GqTiwVS0f2UkTw@mail.gmail.com>
From: Jonathan Hoyland <jonathan.hoyland@gmail.com>
Date: Thu, 02 Jul 2020 15:20:25 +0100
Message-ID: <CACykbs1zgLW5RS3pH34DjBDz8ap14AmAb4NL1NMrpWc6Octq1A@mail.gmail.com>
To: Joseph Salowey <joe@salowey.net>
Cc: "<tls@ietf.org>" <tls@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d395f305a9761c69"
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/qyKrEZ-medpT011I5FtT6a6cjNU>
Subject: Re: [TLS] 2nd WGLC for Delegated Credentials for TLS
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Jul 2020 14:20:41 -0000

Hi All,

For those interested, I've been working on a formal analysis of DCs the
results of which should appear online in the next few days.
I'll post to the list when it's up.

In summary I managed to prove a server only version of DCs secure (i.e.
does not violate any of the properties in Appendix E.1) under the Dolev-Yao
model without resumption, and work on a more general result is ongoing.

Regards,

Jonathan

On Mon, 29 Jun 2020 at 16:59, Joseph Salowey <joe@salowey.net> wrote:

> This is the second working group last call for Delegated Credentials for
> TLS.  The latest draft can be found here:
> https://tools.ietf.org/html/draft-ietf-tls-subcerts-09.  There have been
> 2 revisions since the last review.  Draft 8 contains changes that were not
> committed in time for draft 7 and draft 9 contains revisions from the
> previous WGLC.  Links to the Diffs between the draft 9 and draft 7 can be
> found at the end of this message.   Please focus your review on the changes
> between draft 7 and draft 9.  Please send your comments to the list by July
> 13, 2020.
>
> Thanks,
>
> Sean and Joe
>
> [Inline Diff]
> https://tools.ietf.org/rfcdiff?difftype=--hwdiff&url2=draft-ietf-tls-subcerts-09.txt&url1=draft-ietf-tls-subcerts-07.txt
> [Side-by-side Diff]
> https://tools.ietf.org/rfcdiff?url2=draft-ietf-tls-subcerts-09.txt&url1=draft-ietf-tls-subcerts-07.txt
>
> _______________________________________________
> TLS mailing list
> TLS@ietf.org
> https://www.ietf.org/mailman/listinfo/tls
>