[Ace] PoA based Device Registration (draft-vattaparambil-ace-wg-poa-device-reg): Support, suggestions

2024-05-17 Thread Christian Amsüss
Hello Sreelakshmi, authors, ACE, I've read draft-vattaparambil-ace-wg-poa-device-reg-00 and think it provides a valuable contribution to ACE, especially if it grows to actually propose an interface to the client registration problem. I am not sure that the proposed solution has the ideal work flow

[Ace] Re: PoA based Device Registration (draft-vattaparambil-ace-wg-poa-device-reg): Support, suggestions

2024-05-17 Thread sree lakshmi
Hi Christian, Thank you for your input. I like your idea on Figure 5, to make the DO talk to the AS directly rather than sending a large payload to the client. In this draft, we have assumed a pre-established mutual authentication step between the DO and the AS. We haven’t explained it in detail b

[Ace] Re: PoA based Device Registration (draft-vattaparambil-ace-wg-poa-device-reg): Support, suggestions

2024-05-17 Thread Christian Amsüss
Hello Sree, On Fri, May 17, 2024 at 02:57:24PM +0200, sree lakshmi wrote: > In this draft, we have assumed a pre-established mutual authentication > step between the DO and the AS. We haven’t explained it in detail > because it is an assumption. The assumption I've been working on is that DO is e

[Ace] Re: Secdir last call review of draft-ietf-ace-revoked-token-notification-06

2024-05-17 Thread Marco Tiloca
Hello Kyle, Thanks for your additional comments! Please find our replies inline below. Best, /Marco On 2024-05-13 22:47, Kyle Rose wrote: On Fri, May 10, 2024 at 9:12 AM Marco Tiloca wrote: * The security issue outlined in section 13.5 ("Dishonest clients") adequately justifies mai