[Uta] Genart review of draft-ietf-uta-tls13-iot-profile-21

"Tschofenig, Hannes" <hannes.tschofenig@unibw.de> Tue, 16 June 2026 12:03 UTC

Return-Path: <hannes.tschofenig@unibw.de>
X-Original-To: uta@mail2.ietf.org
Delivered-To: uta@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 59D731021C7B4 for <uta@mail2.ietf.org>; Tue, 16 Jun 2026 05:03:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781611414; bh=myimMoKKc0wSvOUA8IdEelpNzL+Tg0b1RzUIje3KJwo=; h=From:To:Subject:Date; b=yvVAxjoACrD6ZKk4BqvfIYO/gA71JxMTKuyXKJQml+d6lbC++yAz+X+z5HZa+zcv0 kqZm6NVar+otOqyicZKNk+dEj3OVjAJR+9za0iIQSfLsRrFVX6+Dopm0A14li0JWrp /7agtragUsfMaHmrZNX9qLsj9YtskyxatBrqdwi0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=unibw.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k3ChkASm_chm for <uta@mail2.ietf.org>; Tue, 16 Jun 2026 05:03:33 -0700 (PDT)
Received: from gold2srv.rz.unibw-muenchen.de (gold2srv.rz.unibw-muenchen.de [137.193.6.85]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3B02C1021C6FC for <uta@ietf.org>; Tue, 16 Jun 2026 05:03:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=unibw.de; i=@unibw.de; q=dns/txt; s=s2; t=1781611382; x=1813147382; h=from:to:subject:date:message-id:mime-version; bh=myimMoKKc0wSvOUA8IdEelpNzL+Tg0b1RzUIje3KJwo=; b=nEgj/Tqhunxu0ecE2F14QW71YIMX5Pi2SCcAX4tXnxvAXV+36RfDysqC 8AT/NRm4xYtAxLjJnfYgHzxyR4J30GFjcgQd1NUoJVNzUjcOghTGy9Wdq rkUCDWhNQKj+FOgyRacKiCeoNKZ9ggLc5sHFvtHMWpo3xG85I4H//puWN QVABUBS7jYMg8E//Y/fvWlLfQWJq8Zl+xJPiHKKbVPGReSPxqt9DyqtRZ l5oiy1cBOERljO1bx7LbUTVzTul01SO4C5LkYT0UICIFj8fiufwk/X8AX jeVIhqmIyqYvKewn7/7iEzIUNZBo1pHC6oHK8RRhJKTgXy1qs7/9bhJAs g==;
X-CSE-ConnectionGUID: ufyO3rD4RYOcRXZ4x8uYiA==
X-CSE-MsgGUID: TUfKmjh6RUeUaeqBsZxngA==
Authentication-Results: gold2srv.rz.unibw-muenchen.de; dkim=none (message not signed) header.i=none
X-IPAS-Result: A2CCAgDKOjFqjw8EwYlaglmBPYEEgQqCBwECliuSGowEgX4PAQECAQEBAQEIAT0UBAEBkkcoNgcOAQIEAwIDAQEBAQEBAQEBAQELAQEBBQEBAQEBAQYEARQBAQEBAQE5BQ47hglGAQyHUxkBDHMnBBuCegGCHRZAFLFhgTSBAYR92zIGgU2FBYNWASqBNQGEFQE4hlBDgRWGSgKIAyIEgg0VehIbg1iNFCyBGCIDJjMsAQ8RNRMXCwcFgWYDKi8tbjIdgSM+FzRYGwcFgR6CCIEChQYjHwM5f4FwgSVnZhUwNYECER8KOgMLB2Y9FCMUGwQCAYE1i3ddFw+BS3AJXARTIAFkDD80Dx6TMiSPM4F8oXsDBAOCNYFoBYwclUISHBeXYZIkZ5kII41nlTaFVwIEAgQFAhiBbw6CAHGDN1IXAg+OOoNpyCWBNwEHAgcPAoFzkAItMQGBHAEB
IronPort-PHdr: A9a23:HwIXYBX1NNsWGU2m6bRagkhJfrrV8K3JAWYlg6HP6ppBdaCvpY/4I grF97Nwil7DQsDe9v9CgOrbtebsVD9I7ZWAtSUEd5pBH18AhN4NlgMtSMiCFQXgLfHsYiB7V MRPXVNo5Te6ZE5SHsuWWg==
IronPort-Data: A9a23:CrCkUat8n1xCOxM0HuRYDVB7m+fnVAdeMUV32f8akzHdYApBsoF/q tZmKT+HbvqIY2DxKdBxOork9ENU7MTdz9ZhTgJpr3g2QnsT9ZOVVN+UB3mrMnLJJKUvbq7GA +byyDXkBJppJpMJjk71atANi1EihfnQLlbbILedankhLeNcYH5/z0olx6hh29AAbeGRW2ulo cn1r9DUJGir0jt1NnN8w6+YoXuDhtyr0N8jlgJ4P6wjUGP2zSFPUspBfP/pdBMUf6ENdgKEb 7aSpF2G1jODl/sdIovNuqr2dEQMXonTMWCm4lJKW7KviwR1vSc71KA2LpI0MS+7XB3U9zzZ4 IwlWa2YEW/FDIWV8Ague0Aw/xVFAEFz0OSvzU5TESCk5xaun3PEm52CBaytVGES0r4f7Wpmr ZT0JN2RB/yOr7re/V61dgVjrtktPe6wJq9DgEBHxgvpP6o2EY3yQoyfsLe03B9o7ixPNfPXf clELyB9KgnGYhdQf1IKBZQ1nOquwHXyG9FagAvO+uxusjOVkEoojdABM/KMEjCObcVcmECVv STa5G/5BR8XMt2Q4SeD83izwOPC9c/+cNxDSuPkp6ECbFu7+lEdKxgUVQWBnPSEg0OnccltO 0ob0397xUQ13BbyFYGlBUbQTGS/lgMAUvJRHvE0rgaXxcLpDx2xA2EeTWMHcs5gqck3TyNv0 0KEmdjpCDopvLD9pW+hGqm8sD2jHnMPATM4VAgPdzs3v8mzvbAyp0eaJjp8K5JZmOEZDhnc7 li3QMUWgrwJjpNNzbf94FbGiS3po4XESAU16wORUm/NAuJFiGyNOt3ABbvztKgowGOlor+p5 yRsdy+2t7tmMH11vHbRKNjh5Znwjxp/DNEjvbKfN8N4rGz1oSXLkXF4/Td/OkpzKccYcDL1K EPeo0tb+ZlfMWC1YK9tK4esBsIhzaXmfenYugTvRoMWOPBZLVbflAk3PBL49z62yiAEz/pgU ap3hO7wVh72/4w7l2LuH4/wENYDmkgD+I8kbcyhlkz3ieLGOyH9pHVsGALmU93VJZis+G39m +uz/ePXo/mDeIUSuhXqzLM=
IronPort-HdrOrdr: A9a23:jhKhqKrqPVPLc6i4+HroWigaV5oQeYIsimQD101hICG9Kvbo9f xG785rsCMc6QxhIU3I9urhBEDtex7hHP1OkPEs1NWZLWrbUQKTRekIh7cKqAeOJ8SKzI9gPN BbHZSWZuedMbEwt7ef3ODxKadG/DCoytHPudvj
X-Talos-CUID: 9a23:RSJeCmvf5dNYN5jsuT59FKH/6Is4fGz6l238f3WJLm1TeI/JWQ+NyaJNxp8=
X-Talos-MUID: 9a23:wcu5jQrKupc/04mlzZkezw1fOuRt4aTwMn0ArJwLouOfBzx2NB7I2Q==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=McAfee;i="6800,10657,11818"; a="6966497"
X-IronPort-AV: E=Sophos;i="6.24,208,1774306800"; d="scan'208,217";a="6966497"
Received: from mark5.rz.unibw-muenchen.de ([137.193.4.15]) by gold2srv.rz.unibw-muenchen.de with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 16 Jun 2026 14:02:50 +0200
Received: from mark5.rz.unibw-muenchen.de (137.193.4.15) by mark5.rz.unibw-muenchen.de (137.193.4.15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.43; Tue, 16 Jun 2026 14:02:50 +0200
Received: from mark5.rz.unibw-muenchen.de ([fe80::9482:b3d1:6ef3:4ba4]) by mark5.rz.unibw-muenchen.de ([fe80::9482:b3d1:6ef3:4ba4%11]) with mapi id 15.02.2562.043; Tue, 16 Jun 2026 14:02:50 +0200
From: "Tschofenig, Hannes" <hannes.tschofenig@unibw.de>
To: "uta@ietf.org" <uta@ietf.org>
Thread-Topic: Genart review of draft-ietf-uta-tls13-iot-profile-21
Thread-Index: AQHc/YY/fynSV20dZk+8kr5+0QL5hA==
Date: Tue, 16 Jun 2026 12:02:50 +0000
Message-ID: <aaa921f7e971495e9a360e789e5d7b00@unibw.de>
Accept-Language: de-DE, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [137.193.2.50]
Content-Type: multipart/alternative; boundary="_000_aaa921f7e971495e9a360e789e5d7b00unibwde_"
MIME-Version: 1.0
Message-ID-Hash: VHP75FV5OC72VMK7DQC542JK7T74X4Q5
X-Message-ID-Hash: VHP75FV5OC72VMK7DQC542JK7T74X4Q5
X-MailFrom: hannes.tschofenig@unibw.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-uta.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Uta] Genart review of draft-ietf-uta-tls13-iot-profile-21
List-Id: UTA working group mailing list <uta.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/iGm0Z1w-v-1OZLxzhbpjEx5_Xqk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Owner: <mailto:uta-owner@ietf.org>
List-Post: <mailto:uta@ietf.org>
List-Subscribe: <mailto:uta-join@ietf.org>
List-Unsubscribe: <mailto:uta-leave@ietf.org>

Hi Russ,

Thank you for the careful review and the helpful suggestions.

We have updated the draft to address your comments. In particular:

* We clarified the certificate serial number generation. The draft now says
that CAs SHOULD generate serial numbers containing at least eight octets of
unpredictable output, and that this random value MAY be combined with a
counter or other information that ensures uniqueness.

* We clarified the discussion of the PKI hierarchy and device credentials,
including the relationship between IDevIDs, LDevIDs, manufacturer CAs,
operator-issued certificates, and application instance certificates.

* We clarified that this document borrows selected terminology and certificate
fields from IEEE 802.1AR, but does not claim conformance to IEEE 802.1AR.

* We clarified that CA certificates and end-entity certificates are not required
to use the same signature algorithm, while noting that CAs should select
algorithms that constrained relying devices can actually validate.

* We added text explaining that TLS 1.3 certificate-based authentication uses
signature-capable end-entity certificates, and that static DH/ECDH
certificate-based key exchange modes from TLS 1.2 are prohibited by this
profile.

* We expanded the certificate lifetime discussion to point out that an IDevID
with an effectively unlimited lifetime is only useful if the relevant
certification path remains usable for the intended device lifetime.

* We have made many editorial fixes.

Here is the PR:

<https://github.com/thomas-fossati/draft-tls13-iot/pull/202>https://github.com/thomas-fossati/draft-tls13-iot/pull/201


There is an open issue from your review, namely:
"

Section 17.4.1: Why prohibit the use of MACAddress otherName as specified
in draft-ietf-lamps-macaddress-on, which is in the RFC Editor's queue.
"

I had not realized that this draft already existed; we need to brainstorm how to address this issue.


Ciao
Hannes