Return-Path: <blueroofmusic@gmail.com>
X-Original-To: uta@mail2.ietf.org
Delivered-To: uta@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1])
	by mail2.ietf.org (Postfix) with ESMTP id 28F6510222B54
	for <uta@mail2.ietf.org>; Tue, 16 Jun 2026 05:57:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1;
	t=1781614675; bh=VyCyCIaggYc8+UMl5DnRW62SnkLFJdwkbkEyDFSSHnE=;
	h=References:In-Reply-To:From:Date:Subject:To:Cc;
	b=kzmawX2EGV/InwPveLAUHMk0nE7hrUY7PvJbVHqILEac3M8D+nIW9hfBsItU0DGbX
	 LAB6BBWjqsdSmjW9YplcYG5lxsMfWBNgYKwYYjTiHu/Xr/dVqG0H6qQX3eG7LVLG77
	 hu8wk//B5mxI/M/gqX7qDY+ebz8mud6gGYj4s9e4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level: 
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
	HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,
	SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key)
	header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31])
	by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id wDLu4p7KBDJt for <uta@mail2.ietf.org>;
	Tue, 16 Jun 2026 05:57:54 -0700 (PDT)
Received: from mail-yw1-x112c.google.com (mail-yw1-x112c.google.com
 [IPv6:2607:f8b0:4864:20::112c])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by mail2.ietf.org (Postfix) with ESMTPS id D293810222A38
	for <uta@ietf.org>; Tue, 16 Jun 2026 05:56:24 -0700 (PDT)
Received: by mail-yw1-x112c.google.com with SMTP id
 00721157ae682-7e3b2a435ecso48469107b3.1
        for <uta@ietf.org>; Tue, 16 Jun 2026 05:56:24 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1781614584; cv=none;
        d=google.com; s=arc-20240605;
        b=Sd4paK9RPzHvZ7zhTJLkDzia91poW6VYgb7qtbq1ywoFBLKhwPmcsXhkp+Iz6nACHS
         akT0lNPOeR+5DR8x1kSl3hKEjSJbf1VgdyPxyw1McKmKrKQEVFypo2ey0R/kCYwj1XcT
         M2vtcxh0YzkLMgZK0jF4TgD9aC1IDnwjG+jUc9QkXmDVttMSPf9bW56me7I5t/MPfV2J
         5dfsikMkbvBhPF/sNYYcXukbapkgo8sXESYQAVg315WgAmvJeweeUMMfPnfdqHQXSjpO
         Vq9VHNXAHv84Yfkj2Bh1XrwymqmRbMCZzrLrzLuuFFMKPN1ACL7WhAu8MYzDGVJMqUFa
         AK+w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
 s=arc-20240605;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:dkim-signature;
        bh=GGCpurFnwc+aqi24Pg6GbV4IB1a2x9so0rRaX4AT+a8=;
        fh=Oa9m3D47hD5r+jqB2eXrJLPhoDmVDSokk4aeDGzLRxM=;
        b=TJqkJvPraCnRh6kmfjQrUj20VL0gbVNZVljTOPBOLpDnrKytbvuGbqAPP41RBJdRT9
         ih8Xr1NJpYauOhu/xeN6g44zkzUnu6QZ8hEaO+573ZSwk/o0HB2nEOfoQ7PnLYIA/3K9
         tGghfreP+5amFdnoYxD7MgPCnolV5ySZVvq/Q8y7ZXsHvwbGXqbmAaixJla+djsIygIG
         rpNYs+j8f2PgOSbrEkVNB3+IvNTEROWy9IzbT1HAMXXO4leP/ezI/7mMt0lLrlQp/WcO
         g7BQWsXhHID0eEnl1xDvNCTBhW6fUKBRMfsgDYMWXKiD8e/Ge3uRfsS9AW57Rcvn1FdU
         LSCA==;
        darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20251104; t=1781614584; x=1782219384; darn=ietf.org;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:from:to:cc:subject:date:message-id:reply-to;
        bh=GGCpurFnwc+aqi24Pg6GbV4IB1a2x9so0rRaX4AT+a8=;
        b=CoeDoQ+8g+F5vICIGYv4/vXVW8wVFxQV88E7GGJwS9WcBWgim8EXCvQOItx274Di+g
         Eukw9YXm7GkavTE/BLok+2S7nwRPNpGZp3R2GNWgMt9+Z8MXu+eFABaC6P+ODcS9ATpn
         +foJRXIWXZ8IUlZjyrF3XraoJjffnlgAc8M7/2o37WcSS5CY97RioZfnx/2mrXg0Pfcf
         J2Kk6WKkkNTNz+nB4YuBXKCtpe0akrLVE77PukivNoB7soNPRn7B0MyJPL8e47cRygZ5
         fK76+1TH/sUDvUF348VmwpdUonGXMi5gnG2roLkeP52RF2ZXql98NtzTJAf0aaNfvUsw
         BC2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20251104; t=1781614584; x=1782219384;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date
         :message-id:reply-to;
        bh=GGCpurFnwc+aqi24Pg6GbV4IB1a2x9so0rRaX4AT+a8=;
        b=krbR7UgLMNZqqW93OBMQVJ9R4tGN3eGVbW5iGjtNUaZeBnl1TxEc1APLI07L5/1XH+
         ssRGPtM8PL1g9ukrjDnfTAoiG5cBOKd+5F306oJq6BVbrhIQ1WkgLdjHghR5hChfzOIU
         0UrPRjlLnZ3WWQvG2jjPYKMKvsLbJbxEP+RnGhUlXIHRiots58Jbjbafk3uFZr4k19m7
         CzF6Brr3CaE8yEZoF++vifS7meDeNBeiEFrSxDfc4Mb5jPPPfQugyQg3UILpAXfxz2WN
         YVtQl9sDoQWNecC4Ua1tsj2v0xVPINClaxDuPLt2dEJlktUl0ouJqRhNnCmTufsQPY7y
         waZA==
X-Gm-Message-State: AOJu0Yxs9wj044jefS6Mx10q1qF1aFquvJGr8uoc+1DPqUQkfFMX5Ema
	Z4NfkFlXPUsvmhd+EmEvwfpImkg9TDHQaYNL4OAU9yRpt+KDc0sHw7RAuIq65ITgUjvboKbm+8h
	dvZO9vgJ8HpRcCXOgxkc8uhfDuJjkn2M=
X-Gm-Gg: Acq92OEtDRk0ZmFLT1OW/VST5cNyWLTyQKp0ZjzEiRI0kzc+AxkFlGdObXYL/tF3zyp
	EslsnYcWb8NaLnCxmagbxIl1EkhkT7KR/W6irg5KcIS91phjKHpDTyrfPIfp6FGsmvPNXjsobVn
	8o49gNaUMSktJWTJHaoycx663C0rVCxNkUIerEKQcY9CA9iC6l9S/5e/jdnYV2FzFKJDNHCxIKH
	Q0YXZX3+7uTKhHFtpMHvviHGZGrC4Er/OrvNOHsfiynE4wMfpU64M2jtVMmEVHJ5wdCV7Ac5Dhv
	g9Hs0KmjUq6JkuTspgbd/YYeVvA/PkYvSk5oWtZpjAj+EpPaxlJX3go9/hXyXN/4wboS
X-Received: by 2002:a05:690c:4902:b0:7a3:7ad3:3e9e with SMTP id
 00721157ae682-7f8c37d34b1mr136852517b3.32.1781614583994; Tue, 16 Jun 2026
 05:56:23 -0700 (PDT)
MIME-Version: 1.0
References: <aaa921f7e971495e9a360e789e5d7b00@unibw.de>
In-Reply-To: <aaa921f7e971495e9a360e789e5d7b00@unibw.de>
From: Ira McDonald <blueroofmusic@gmail.com>
Date: Tue, 16 Jun 2026 08:56:13 -0400
X-Gm-Features: AVVi8CcRrTBF0rGyvqllJMRKub0fzGbI53r2NSE4kmivpL_xJuCx6SdVDAJrTlY
Message-ID: 
 <CAN40gSuGSL-QSJVgMwJgGLEkiP0AGPqh5=B2yiUUOexvhPkZZQ@mail.gmail.com>
To: "Tschofenig, Hannes" <hannes.tschofenig=40unibw.de@dmarc.ietf.org>,
	Ira McDonald <blueroofmusic@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000067df3606545e78cd"
Message-ID-Hash: 4BTJQ3QZHQP7T5RYQKTFXLWHZRLCYWKC
X-Message-ID-Hash: 4BTJQ3QZHQP7T5RYQKTFXLWHZRLCYWKC
X-MailFrom: blueroofmusic@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-uta.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: uta@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BUta=5D_Re=3A_Genart_review_of_draft-ietf-uta-tls13-iot-profile-?=
	=?utf-8?q?21?=
List-Id: UTA working group mailing list <uta.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/uta/coRviakbFU7WxfDUX7JJm3WHmP8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Owner: <mailto:uta-owner@ietf.org>
List-Post: <mailto:uta@ietf.org>
List-Subscribe: <mailto:uta-join@ietf.org>
List-Unsubscribe: <mailto:uta-leave@ietf.org>

--00000000000067df3606545e78cd
Content-Type: text/plain; charset="UTF-8"

Hi Hannes,

BTW - That MAC address draft is already approved and in the RFC Editor
queue, so not a blocking reference for you.

Cheers,
- Ira

*Ira McDonald (Musician / Software Architect)*
*Co-Chair - TCG Mobile Platform WG*








*Chair - Linux Foundation Open Printing WGSecretary - ISTO Printer Working
GroupCo-Chair - ISTO PWG Internet Printing Protocol WGIETF Designated
Expert - IPP & Printer MIBBlue Roof Music / High North
Inchttp://sites.google.com/site/blueroofmusic
<http://sites.google.com/site/blueroofmusic>http://sites.google.com/site/highnorthinc
<http://sites.google.com/site/highnorthinc>mailto: blueroofmusic@gmail.com
<blueroofmusic@gmail.com>(permanent) PO Box 221  Grand Marais, MI 49839
906-494-2434*

On Tue, Jun 16, 2026, 8:03 AM Tschofenig, Hannes <hannes.tschofenig=
40unibw.de@dmarc.ietf.org> wrote:

> Hi Russ,
>
> Thank you for the careful review and the helpful suggestions.
>
> We have updated the draft to address your comments. In particular:
>
> * We clarified the certificate serial number generation. The draft now says
> that CAs SHOULD generate serial numbers containing at least eight octets of
> unpredictable output, and that this random value MAY be combined with a
> counter or other information that ensures uniqueness.
>
> * We clarified the discussion of the PKI hierarchy and device credentials,
> including the relationship between IDevIDs, LDevIDs, manufacturer CAs,
> operator-issued certificates, and application instance certificates.
>
> * We clarified that this document borrows selected terminology and
> certificate
> fields from IEEE 802.1AR, but does not claim conformance to IEEE 802.1AR.
>
> * We clarified that CA certificates and end-entity certificates are not
> required
> to use the same signature algorithm, while noting that CAs should select
> algorithms that constrained relying devices can actually validate.
>
> * We added text explaining that TLS 1.3 certificate-based authentication
> uses
> signature-capable end-entity certificates, and that static DH/ECDH
> certificate-based key exchange modes from TLS 1.2 are prohibited by this
> profile.
>
> * We expanded the certificate lifetime discussion to point out that an
> IDevID
> with an effectively unlimited lifetime is only useful if the relevant
> certification path remains usable for the intended device lifetime.
>
> * We have made many editorial fixes.
>
> Here is the PR:
>
> <https://github.com/thomas-fossati/draft-tls13-iot/pull/202>
> https://github.com/thomas-fossati/draft-tls13-iot/pull/201
>
> There is an open issue from your review, namely:
> "
> Section 17.4.1: Why prohibit the use of MACAddress otherName as specified
> in draft-ietf-lamps-macaddress-on, which is in the RFC Editor's queue.
> "
>
> I had not realized that this draft already existed; we need to brainstorm
> how to address this issue.
>
> Ciao
> Hannes
>
>
> _______________________________________________
> Uta mailing list -- uta@ietf.org
> To unsubscribe send an email to uta-leave@ietf.org
>

--00000000000067df3606545e78cd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto"><div>Hi Hannes,</div><div dir=3D"auto"><br></div><div dir=
=3D"auto">BTW - That MAC address draft is already approved and in the RFC E=
ditor queue, so not a blocking reference for you.</div><div dir=3D"auto"><b=
r></div><div dir=3D"auto">Cheers,</div><div dir=3D"auto">- Ira</div><div><b=
r></div><div data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div =
dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"lt=
r"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><=
div dir=3D"ltr"><i><font size=3D"1">Ira McDonald (Musician / Software Archi=
tect)</font></i></div><div><i><font size=3D"1"></font></i></div><div dir=3D=
"ltr"><i><font size=3D"1">Co-Chair - TCG Mobile Platform WG</font></i></div=
><div><i><font size=3D"1"></font></i></div><div dir=3D"ltr"><i><font size=
=3D"1">Chair - Linux Foundation Open Printing WG<br>Secretary - ISTO Printe=
r Working Group<br>Co-Chair - ISTO PWG Internet Printing Protocol WG<br>IET=
F Designated Expert - IPP &amp; Printer MIB<br>Blue Roof Music / High North=
 Inc<br><a style=3D"color:rgb(51,51,255)" href=3D"http://sites.google.com/s=
ite/blueroofmusic" target=3D"_blank">http://sites.google.com/site/blueroofm=
usic</a><br><a style=3D"color:rgb(102,0,204)" href=3D"http://sites.google.c=
om/site/highnorthinc" target=3D"_blank">http://sites.google.com/site/highno=
rthinc</a><br>mailto: <a href=3D"mailto:blueroofmusic@gmail.com" target=3D"=
_blank">blueroofmusic@gmail.com</a><br>(permanent) PO Box 221=C2=A0 Grand M=
arais, MI 49839=C2=A0 906-494-2434</font></i></div></div></div></div></div>=
</div></div></div></div></div></div></div></div></div></div></div></div></d=
iv></div><br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"l=
tr" class=3D"gmail_attr">On Tue, Jun 16, 2026, 8:03 AM Tschofenig, Hannes &=
lt;hannes.tschofenig=3D<a href=3D"mailto:40unibw.de@dmarc.ietf.org">40unibw=
.de@dmarc.ietf.org</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote=
" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">




<div dir=3D"ltr">
<div id=3D"m_-28581994037812676divtagdefaultwrapper" dir=3D"ltr" style=3D"f=
ont-size:12pt;color:rgb(0,0,0);font-family:Calibri,Helvetica,sans-serif,&qu=
ot;EmojiFont&quot;,&quot;Apple Color Emoji&quot;,&quot;Segoe UI Emoji&quot;=
,NotoColorEmoji,&quot;Segoe UI Symbol&quot;,&quot;Android Emoji&quot;,Emoji=
Symbols">
<p></p>
<div>Hi Russ,<br>
<br>
Thank you for the careful review and the helpful suggestions.<br>
<br>
We have updated the draft to address your comments. In particular:<br>
<br>
* We clarified the certificate serial number generation. The draft now says=
<br>
that CAs SHOULD generate serial numbers containing at least eight octets of=
<br>
unpredictable output, and that this random value MAY be combined with a<br>
counter or other information that ensures uniqueness.<br>
<br>
* We clarified the discussion of the PKI hierarchy and device credentials,<=
br>
including the relationship between IDevIDs, LDevIDs, manufacturer CAs,<br>
operator-issued certificates, and application instance certificates.<br>
<br>
* We clarified that this document borrows selected terminology and certific=
ate<br>
fields from IEEE 802.1AR, but does not claim conformance to IEEE 802.1AR.<b=
r>
<br>
* We clarified that CA certificates and end-entity certificates are not req=
uired<br>
to use the same signature algorithm, while noting that CAs should select<br=
>
algorithms that constrained relying devices can actually validate.<br>
<br>
* We added text explaining that TLS 1.3 certificate-based authentication us=
es<br>
signature-capable end-entity certificates, and that static DH/ECDH<br>
certificate-based key exchange modes from TLS 1.2 are prohibited by this<br=
>
profile.<br>
<br>
* We expanded the certificate lifetime discussion to point out that an IDev=
ID<br>
with an effectively unlimited lifetime is only useful if the relevant</div>
<div>certification path remains usable for the intended device lifetime.<br=
>
<br>
* We have made many editorial fixes.</div>
<br>
Here is the PR:=C2=A0
<p></p>
<p><a href=3D"https://github.com/thomas-fossati/draft-tls13-iot/pull/202" t=
arget=3D"_blank" rel=3D"noreferrer"></a><a href=3D"https://github.com/thoma=
s-fossati/draft-tls13-iot/pull/201" target=3D"_blank" rel=3D"noreferrer">ht=
tps://github.com/thomas-fossati/draft-tls13-iot/pull/201</a><br>
</p>
<br>
<p>There is an open issue from your review, namely:<br>
&quot;</p>
<div>Section 17.4.1: Why prohibit the use of MACAddress otherName as specif=
ied<br>
in draft-ietf-lamps-macaddress-on, which is in the RFC Editor&#39;s queue.<=
/div>
&quot;<br>
<p><span style=3D"white-space:pre-wrap">I had not realized that this draft =
already existed; we need to brainstorm how to address this issue.</span></p=
>
<br>
<p></p>
<p>Ciao<br>
Hannes</p>
<p><br>
</p>
</div>
</div>

_______________________________________________<br>
Uta mailing list -- <a href=3D"mailto:uta@ietf.org" target=3D"_blank" rel=
=3D"noreferrer">uta@ietf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:uta-leave@ietf.org" targe=
t=3D"_blank" rel=3D"noreferrer">uta-leave@ietf.org</a><br>
</blockquote></div>

--00000000000067df3606545e78cd--

