[Anima] on adopting draft-richardson-anima-jose-voucher-01 --- needed for brski-async-enroll

2021-06-29 Thread Michael Richardson
Signing and > Encryption mechanism described in RFC7515. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list An

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-29 Thread Michael Richardson
her-request) -> jose-voucher (voucher, voucher-request) and my question was a bit about how we manage all their things inherited. It's really the classic CS multiple inheritance problem. {A Cat is an Mammal A Cat is an Four-legged creature A Cat is Nocturnal.} -- Michael Richa

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-29 Thread Michael Richardson
7-10-25.yang&orgtags=&recursion=0&show_rfcs=1&show_subm=1&show_dir=dependents> Yeah, I knew about that, but others might not. I was basically trying to distill it down into a few words. -- ] Never tell me the odds! | ipv6 mesh netw

Re: [Anima] on adopting draft-richardson-anima-jose-voucher-01 --- needed for brski-async-enroll

2021-06-30 Thread Michael Richardson
27;s way outside my > expertise, but it seems necessary so I would support adoption. Thanks. What parts did you understand? It's just RFC8366 with a different signature. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wor

Re: [Anima] Resending: Call for adoption: draft-richardson-anima-jose-voucher

2021-07-04 Thread Michael Richardson
t form of Updates we care about. It is not Amends. It is not quite Extends. It is mostly in the See Also. ps: RFC editor will prefer "artifact" over "artefact" :-) https://github.com/mcr/anima-jose-voucher/commit/66d39393d1d3ccbcb0e74674e10ea6599288eb28 -- Michael Richardson. o

Re: [Anima] discussing draft-richardson-anima-jose-voucher

2021-07-04 Thread Michael Richardson
signing encoding > and new privacy considerations). This qualifies exactly what type > of update this RFC will be. Yes, that's what we are obligated to do now anyway. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wo

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
t Status: https://datatracker.ietf.org/doc/draft-richardson-anima-rfc8366bis/ Html: https://www.ietf.org/archive/id/draft-richardson-anima-rfc8366bis-00.html Htmlized: https://datatracker.ietf.org/doc/html/draft-richardson-anima-rfc8366bis -- Michael Richardson. o O (

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
RFC8366 gets updated when IANA revises the module. I think, it mostly doesn't matter because none of are generating code from YANG... AT THIS TIME. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc,

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
Michael Richardson wrote: > I propose that the WG adopt this as the -00, and then we change the document > to change this into an RFC7224-style IANA-maintained YANG module. > (In DHC WG, when we did RFC3315bis to make RFC8415 we did a -00 which was > whitespace e

Re: [Anima] BRSKI design team meeting on Thursday

2021-07-04 Thread Michael Richardson
trusted. (In the context of above statement, it means that Registrar will operate with any manufacturer, that is, not{3}) > * New issue #122: Use of CoAP 4.03 Forbidden vs 4.01 Unauthorized > - https://github.com/anima-wg/constrained-voucher/issues/122 -- Michael Ri

Re: [Anima] Secdir early review of draft-ietf-anima-constrained-voucher-11

2021-07-04 Thread Michael Richardson
examples are intended to provide meaningful input for unit tests. This is quite common for anything involve cryptographic operations. We don't intend to remove it. Our experiences is that people outside of the IETF find protocols without examples to be challenging to implement. Should we me

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
l be (usually a guess and usually wrong but it helps to have the tp> assumptions about the requirements spelt out) and such like. tp> As an engineer, I do like to know the requirements before working on the design! We need to be able to write RFCs that extend the voucher types. Not

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
to value is part of the specification of an enumeration - not in > YANG). yes, it's a text string for XML and JSON, this isn't the case for YANG-CBOR if a value is set. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa

[Anima] early allocation for x5bag

2021-07-05 Thread Michael Richardson
he interop planning document at: https://docs.google.com/document/d/1T8Rtfk1zia_p05_6eb_WQA2Mmid-eP1-cAgnwdpF9Xk/edit?usp=sharing -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

Re: [Anima] [lamps] EST CSRATTRS specifying the SAN

2021-07-05 Thread Michael Richardson
for instance in Cisco's libEST, which > has remained extremely sketchy regarding the csrattrs topic. Are there examples in libest that we can use? Is there unit test code in there that could be exercised to validate other examples? Are we back to redoing this in JSON? -- Mich

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
ditor to delete the > IANA-maintained module. I think you mean, the RFC-maintained module :-) How do we keep the YANG catalog from latching onto it. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signatu

Re: [Anima] early allocation for x5bag

2021-07-05 Thread Michael Richardson
Carsten Bormann wrote: > On 2021-07-05, at 20:16, Michael Richardson wrote: >> >> >> https://www.iana.org/assignments/cose/cose.xhtml#header-parameters > Is there a time-warp somewhere? > x5bag (TEMPORARY - registered 2019-08-20, exten

Re: [Anima] Resending: Call for adoption: draft-richardson-anima-jose-voucher

2021-07-06 Thread Michael Richardson
could consider is if it wants to merge this work into an RFC8366bis. There are positives and negatives about such a thing. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide si

[Anima] discussing EST CSRATTRS specifying the SAN at IETF111

2021-07-06 Thread Michael Richardson
bit of code you want to extend. LAMPS chairs: can we have ten minutes for this discussion on the Thursday Session III meeting at IETF111? The Monday Session II is conflicted with ANIMA. I'm gonna voluntold Eliot to lead this discussion :-) -- Michael Richardson. o O ( IPv6 Iø

[Anima] Registrar to MASA connections: SNI required

2021-07-06 Thread Michael Richardson
SNI support) is REQUIRED. TLS 1.3 (or newer) SHOULD be available. I don't know if is worth an errata. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

Re: [Anima] New Version Notification for draft-dang-anima-network-service-auto-deployment-00.txt

2021-07-07 Thread Michael Richardson
nated. > Welcome to comment, review or contribute it. > Best wishes, > Joanna > ___ > Anima mailing list > Anima@ietf.org > https://www.ietf.org/mailman/listinfo/anima -- Michael Richardson. o O ( IPv6 IøT consultin

Re: [Anima] New Version Notification for draft-dang-anima-network-service-auto-deployment-00.txt

2021-07-08 Thread Michael Richardson
route, which I understand should be regarded as a route discovery JD> process. I also would like to hear more of your thoughts on this JD> point. I don't have the background in traffic engineering to know. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman S

Re: [Anima] FYI: Self-Driving Networks without Self-Crashing Networks

2021-07-09 Thread Michael Richardson
like "Self-Driving-Network" as a new expansion of SDN :-) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing lis

Re: [Anima] FYI: Self-Driving Networks without Self-Crashing Networks

2021-07-10 Thread Michael Richardson
are situation, recognizing that many network anomalies are precusors to attacks? If so, assuming that we can even figure out what the network state is, do we have any chance of anonymizing the data? -- Michael Richardson. o O ( IPv6 IøT consulting )

Re: [Anima] Call for agenda items ANIMA @ IETF 111, online

2021-07-12 Thread Michael Richardson
Brian E Carpenter wrote: > Although we probably want to produce one more version, I think the > authors of this draft feel it is as complete as seems possible at > present. So is it possible to plan a WG Last Call as soon as the next > version comes out? I concur. ___

Re: [Anima] Call for agenda items ANIMA @ IETF 111, online

2021-07-12 Thread Michael Richardson
ll as constrained-join-proxy, but ietf-constrained-voucher still needs more Security Considerations and some Applicability statement. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP sign

[Anima] kid in parboiled voucher request

2021-07-14 Thread Michael Richardson
t happened that resulted in the duplication. The sorting is by SID value. Should we invert and present this more as a table? I'm trying to make sure that it's driven by pyang. 4) I have removed the comment in section 8 relating to http://comi.space. -- Michael Richardson , Sa

[Anima] sending SNI to MASA

2021-07-14 Thread Michael Richardson
Peter, Can you tell us what the critical mbedtls operation was that made the SNI communication with my MASA work in the end? Just for the benefit of the archives. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature

Re: [Anima] Adopting draft-richardson-anima-jose-voucher (was Re: Resending: Call for adoption: draft-richardson-anima-jose-voucher)

2021-07-16 Thread Michael Richardson
s a WG group draft. Do you want me to post identical text as -00 (and then -01 with suggestions), or do you want me post richardson-02 with suggestions, and then identical -00? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa a

Re: [Anima] Call for adoption: draft-richardson-anima-jose-voucher

2021-07-16 Thread Michael Richardson
; } 172The issues of how [RFC8366] vouchers are used in a [RFC8995] system } 173is addressed in tte> EOUTOFCOFFEE ? yes. Oops. } 388 A.2. Example Parboiled Voucher Request (from Registrar to MASA) tte> (15) If you want to keep "parboiled", please add a refere

[Anima] constrained resources at root for debugging connectivity

2021-07-20 Thread Michael Richardson
3.html#section-2.2 but, this is for the server to validate that the client is really there. Should we recommend that Registrar put something at / that produces a 2.00? (lowercase recommend) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wor

[Anima] Registrar certificate EKU bits

2021-07-20 Thread Michael Richardson
t the certificate was rejected. Perhaps someone else will find this email useful. Mostly, it convinces me to never set any EKU bits. I guess, I need to set serverAuth too, now that I think about it. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software W

Re: [Anima] constrained resources at root for debugging connectivity

2021-07-21 Thread Michael Richardson
3IPrcjkiPVnhoCosUBpTzbqOBhzCBhDAdBgNVHQ4EFgQU/g+KaX9o\nDEKY2K3NGe7Vr/9geDAwCQYDVR0TBAIwADArBgNVHREEJDAioCAGCSsGAQQBgu5S\nAaATDBEwMC1EMC1FNS0wMi0wMC0yRTArBgkrBgEEAYLuUgIEHgwcbWFzYS5ob25l\neWR1a2VzLnNhbmRlbG1hbi5jYTAKBggqhkjOPQQDAgNpADBmAjEAuEwTKPMzS/Xm\nAhR4tFtDo3YHoPoBsaw/6UUYDHot4EoKy2L8AlriFzti/iNmH67/AjEAnRjH2R0T\n98DZjBIhz7W8LM52AeymMdCtsJyuDRjtVuncGEfMO

Re: [Anima] 48h timeout: Constrained BRSKI hackathon / any objections to ask for early allocation

2021-07-21 Thread Michael Richardson
Carsten Bormann wrote: > On 20. Jul 2021, at 23:19, Toerless Eckert wrote: >> >> Optional parameters: cose-type > Ugh. removed from git copy. ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Creating CBOR-based media types and content formats

2021-07-21 Thread Michael Richardson
ld make it the core of the document, explaining each bit of arcana. If it's worth publishing this as a new RFC, then it's worth obsoleting RFC6838. Otherwise, I suggest some nice HTML, maybe in the new-fangled single-hop-over-building wiki. ("Go big, or go home") -- Michael Rich

Re: [Anima] Authors/: IPR poll for draft-richardson-anima-jose-voucher (and others if need be)

2021-07-21 Thread Michael Richardson
Toerless Eckert wrote: > Working on IETF111 chair slides i just stumbled over one process step: > a) Dear authors of draft-richardson-anima-jose-voucher and ANIMA WG: > This is the IPR poll for draft-richardson-anima-jose-voucher > We need for each of you authors to make an IPR

Re: [Anima] draft-ietf-anima-constrained-voucher COSE confusion

2021-07-21 Thread Michael Richardson
indicate the exact media type. Yes! > For example my servers should also accept content-format 18 just as TBD3. Esko, do you think the draft needs to include this option? I prefer not to include. -- Michael Richardson. o O ( IPv6 IøT consulting

Re: [Anima] draft-ietf-anima-constrained-voucher COSE confusion

2021-07-21 Thread Michael Richardson
e protons. They contain YANG-serialized CBOR inside (like quarks) This stuff inside doesn't have an existence: you never get to mess with the quarks without knowing how they are contained. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa a

Re: [Anima] Iotdir early review of draft-ietf-anima-constrained-voucher-12

2021-07-21 Thread Michael Richardson
erly. https://github.com/anima-wg/constrained-voucher/issues/140 > (12) Pinning of Raw Public Keys > "However, if the Pledge is known to also support RPK pinning and the MASA > intends to pin the Registrar's identity (not a CA), then MASA SHOULD pin the > RPK

Re: [Anima] [Cbor] Creating CBOR-based media types and content formats

2021-07-22 Thread Michael Richardson
he new-fangled >> single-hop-over-building wiki. ("Go big, or go home") > I think my parser is failing here. I'm saying that if we aren't going to publish, then it goes into the new wiki. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting

Re: [Anima] Argh?!: Re: draft-ietf-anima-constrained-voucher COSE confusion

2021-07-22 Thread Michael Richardson
cher-cose+cbor in section 13.5.1 We fit voucher-request into the same content. (that's distinguished by the SID values) I think you are overthinking this. And we transport constrained-vouchers with that MIME type over HTTPS between Registrar and MASA. And we use it in the Accept: header. --

Re: [Anima] draft-ietf-anima-constrained-voucher COSE confusion

2021-07-22 Thread Michael Richardson
ak) Anyway, let's ask for an early allocation. We'll be 3-6 months before we get past the IESG and into IANA land to get a number. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature __

Re: [Anima] [Technical Errata Reported] RFC8366 (6646)

2021-07-22 Thread Michael Richardson
0-07T19:31:42Z", > "expires-on": "2016-10-21T19:31:42Z", "assertion": "verified", > "serial-number": "JADA123456789", "idevid-issuer": > "base64encodedvalue==", "pinned-domain-cert"

Re: [Anima] Argh?!: Re: draft-ietf-anima-constrained-voucher COSE confusion

2021-07-23 Thread Michael Richardson
(We had an unsigned voucher request, but we axed it in 2019) -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Argh?!: Re: draft-ietf-anima-constrained-voucher COSE confusion

2021-07-23 Thread Michael Richardson
der "content type" field because the > encoding is never "ambiguous" according to RFC8152 Section 3.1. If a > constrained voucher contains this field, it MUST be ignored by the > processing described in this document. I don't think that this is useful to a

Re: [Anima] Argh?!: Re: draft-ietf-anima-constrained-voucher COSE confusion

2021-07-23 Thread Michael Richardson
ter signatures, because we use CoSESIGN1, and not not CoseSign0. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Slot/Update for draft-ietf-anima-voucher-delegation ?

2021-07-23 Thread Michael Richardson
it until we have something additional to show. (Like code) -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] New Version Notification for draft-dang-anima-network-service-auto-deployment-00.txt

2021-07-23 Thread Michael Richardson
so ask for early allocation if you are trying to do interop. RFC8994 and RFC8994 do GRASP Objective allocations, you could use that as your template. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP sig

Re: [Anima] RFC 8366 / BRSKI / constrained-voucher: what is encoded in the idevid-issuer field?

2021-07-24 Thread Michael Richardson
we need to make sure that we have some examples with idevid-issuer so that we can test all code paths. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___

Re: [Anima] parameters to change pledge certificate

2021-07-24 Thread Michael Richardson
-> device.crt PLEDGE_KEY -> key.pem MASA_SRV_CRT -> masa.crt CA_MASA_CRT -> vendor.crt > Any superfluous ones ? Should this terms go into my masa-considerations document? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelm

Re: [Anima] [core] constrained resources at root for debugging connectivity

2021-07-25 Thread Michael Richardson
Christer Holmberg wrote: > Maybe not exactly what people are looking for, but below is a link to > the thin-ICE presentation from the T2TRG 2019 session in Singapore. No, not what we want. We just want to prove connectivity as part of debugging what's going on. signature.asc Descrip

Re: [Anima] [core] constrained resources at root for debugging connectivity

2021-07-25 Thread Michael Richardson
ditions to coap gem are rough. I guess my changes to OpenSSL are only required by the server side. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

Re: [Anima] IETF111 ANIMA Agenda uploaded - NEED SLIDES

2021-07-25 Thread Michael Richardson
ed slides on jws-voucher (renamed from jose-voucher as requested) I suggest they go after constrained-voucher. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP

[Anima] New Version Notification for draft-richardson-anima-jose-voucher-02, and draft-ietf-anima-jws-voucher

2021-07-25 Thread Michael Richardson
m [RFC8995] to [BRSKI] for references. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://ww

[Anima] draft-ietf-anima-constrained-voucher-13 --- post Hackathon edits

2021-07-25 Thread Michael Richardson
Hackathon are rather minor editorial bits. As the slides say, we did open some 30 new tickets as a result of reviews and the like. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

Re: [Anima] Max/*: Re: RFC 8366 / BRSKI / constrained-voucher: what is encoded in the idevid-issuer field?

2021-07-26 Thread Michael Richardson
ve. I agree that we could clarify the use of this field. One thing that I don't like is that it's hard to write/edit/revise the "description" field in the YANG, and more and more, I'd like to just say, "See RFC section Y.Z" in the description. That might not

[Anima] x5bag in pledge->registrar

2021-07-26 Thread Michael Richardson
uff in that doesn't belong, but it will get ignored. https://github.com/anima-wg/constrained-voucher/issues/145 -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP s

Re: [Anima] Registrar certificate EKU bits

2021-07-26 Thread Michael Richardson
ep this for considerations for a BRSKI-bis document. So, I've opened https://github.com/anima-wg/constrained-voucher/issues/146. I agree that we should put it constrained-voucher. It sounds like you also think it deserves an errata. -- Michael Richardson. o O ( IPv6 IøT consulting )

Re: [Anima] Bulk transfer in draft-ietf-anima-grasp-distribution-03

2021-07-26 Thread Michael Richardson
he F_NEG or something like that? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Registrar certificate EKU bits

2021-07-27 Thread Michael Richardson
te issues: what about draft-richardson-masa-operational-considerations and draft-richardson-registrar-operational-considerations? (yes, I think one needs to be reposted) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and

Re: [Anima] x5bag in pledge->registrar

2021-07-28 Thread Michael Richardson
we introduce new things. If we say that anything new causes the VR to be dropped, then we can never add new things, because it causes interoperation issues if the pledge starts adding them before the Registrar is ready. -- ] Never tell me the odds! | ipv6 mes

[Anima] freshness in the background check interaction model

2021-07-28 Thread Michael Richardson
7;t get to insert entropy into the nonce? All of this coming to a draft near you. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://ww

[Anima] RFC8366bis proceedure

2021-07-30 Thread Michael Richardson
eel that perhaps we need an entire virtual interim on this. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@

Re: [Anima] ANIMA thursday: slides missing?, agenda item order change

2021-07-30 Thread Michael Richardson
clearly we need more. Perhaps you'd like to declare one of the Thursday BRSKI design meetings as a virtual-interim (maybe at the very end of August?) and we could go through them. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa

Re: [Anima] I-D Action: draft-ietf-anima-jws-voucher-00.txt

2021-07-30 Thread Michael Richardson
strapping Protocols > Authors : Michael Richardson > Thomas Werner > Filename: draft-ietf-anima-jws-voucher-00.txt > Pages : 16 > Date: 2021-07-25 > Abstract: > RFC8366 defines a digital artifact called vouche

Re: [Anima] RFC8366bis proceedure

2021-08-01 Thread Michael Richardson
ound. Also, BTW, LAMPS thread says that the way that RFC8994 uses CSRATTRS is wrong. I've suggested a virtual interim for LAMPS for this subject around September 2 in that slot as well. This might also affect SZTP's CSR YANG spec too! -- Michael Richardson. o O ( IPv6 IøT consult

Re: [Anima] BRSKI-AE document split discussion

2021-08-02 Thread Michael Richardson
would proceed as WG documents. Are there common parts that would argue for three documents (B--referencing-->A, and C--referencing-->A) "A" could also be RFC8366bis. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Softw

Re: [Anima] BRSKI-AE document split discussion

2021-08-02 Thread Michael Richardson
ircular. We do get clusters with the relationship is a DAG, but they aren't as much of a problem, and just represent the RPC being overworked, I think. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc

Re: [Anima] BRSKI-AE document split discussion

2021-08-03 Thread Michael Richardson
strar > is kept as close as possible to BRSKI by relying on an enhanced voucher > and utilizing EST with enhanced objects for enrollment. Based on that, > use case 2 document would not reference use case 1 document. I thought that the enrollment objects in use case 2 cou

Re: [Anima] BRSKI-AE document split discussion

2021-08-05 Thread Michael Richardson
into RFC8366bis. Plus: fewer documents. Negative: potentially opens up RFC8366bis to new semantics? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

[Anima] Doodle poll to find a date for the LAMPS Virtual Interim Focused on CSRATTRS

2021-08-05 Thread Michael Richardson
On 2021-08-01 5:36 p.m., Russ Housley wrote: Due to a schedule conflict, we did not talk about the ESR CSR Attr topics at IETF 111. This topic is getting more urgent, so we want to virtual interim for it, but we do not want to take away from the separate virtual interim for PQC. For this rea

[Anima] IANA managed YANG modules

2021-08-05 Thread Michael Richardson
IANA managed YANG module. Can someone point me at some specific text/explanation? Maybe there is a PHB version? Maybe just an email from the dawn of YANG-time. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc

Re: [Anima] ipv4-only network

2021-08-05 Thread Michael Richardson
ne can point them > out. Conceivably, you might have an L2 network which is opaque to etherype 0x86DD then there might be an issue. Is that really the case? In which case we could discuss running over IPv4-Link-Local. -- Michael Richardson. o O ( IPv6 IøT consulting ) San

Re: [Anima] MichaelR/Rob/*: RFC8995 errata concerns

2021-08-05 Thread Michael Richardson
ons.Pledges ought to not send it, since they don't really know what to put. (Is that a SHOULD NOT, or a MUST NOT, or what, I am not sure. The requirement is on the receiver to ignore it) That's a second errata. -- ] Never tell me the odds! | ipv6 me

Re: [Anima] MichaelR/Rob/*: RFC8995 errata concerns

2021-08-07 Thread Michael Richardson
know, the pledge did a mDNS discovery to find a join proxy and that's why it's using the wrong name. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___

[Anima] Limited Additional Mechanisms for PKIX and SMIME (lamps) WG Virtual Meeting: 2021-08-30

2021-08-09 Thread Michael Richardson
This matters to RFC8994. --- Begin Message --- The Limited Additional Mechanisms for PKIX and SMIME (lamps) WG will hold a virtual interim meeting on 2021-08-30 from 13:30 to 15:00 America/New_York (17:30 to 19:00 UTC). Agenda: Discuss issues with EST CSR Attrs Information about remote partici

Re: [Anima] [anima-wg/constrained-join-proxy] new protocol (#4)

2021-08-10 Thread Michael Richardson
eeds to go into the Applicability statement, I think. We included that in RFC9031, see section 8.4.2, "JRC address", but your application does not run 6tisch. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signatur

Re: [Anima] Yangdoctors early review of draft-ietf-anima-brski-async-enroll-03

2021-08-18 Thread Michael Richardson
reshad> "vcr". While this is valid, I am curious why. I didn't think the prefix had relevance outside of the module, but I don't know a lot here. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Sof

[Anima] terms parboiled and raw, but instead RVR and PVR

2021-08-19 Thread Michael Richardson
close visually, and we condsidered: PdVR and ReVR, but did not go that way. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing

Re: [Anima] Yangdoctors early review of draft-ietf-anima-brski-async-enroll-03

2021-08-19 Thread Michael Richardson
On 2021-08-15 11:22 a.m., Reshad Rahman via Datatracker wrote: It was correctly pointed out that the enumeration for "leaf assertion" in RFC8366 can not be augmented. If my understanding is correct, there is a suggestion to do a IANA-maintained module for the assertion and republish a new YANG mo

Re: [Anima] Review of draft-ietf-anima-constrained-join-proxy-02 (part 2/2)

2021-08-19 Thread Michael Richardson
5.3.1. Pledge Extensions . . . . . . . . . . . . . . . . . . 9 5.3.2. Registrar Extensions . . . . . . . . . . . . . . . . 10 ** 5.4 DTLS Considerations Peter, we can't use Blockwise on the DTLS handshake, because that part is outside of the CoAP header. We can only blockwise

Re: [Anima] terms parboiled and raw, but instead RVR and PVR

2021-08-20 Thread Michael Richardson
omeone getting confused, but probably that's not the only thing that they'd have trouble with. We were trying to get to PvdS, as the TLA, but we failed. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signat

Re: [Anima] GRASP maximum message size considerations

2021-08-21 Thread Michael Richardson
don't know yet. It's not clear me that we need to do this network-wide, but we could do that. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

Re: [Anima] GRASP maximum message size considerations

2021-08-22 Thread Michael Richardson
ragment before encrypt. Reassemble after decrypt. 2) encrypt and then fragment the ESP. Depends upon ESP assembly buffer being big enough. Both tend to work, up to some ill-defined limit which is not always 64K. (1) is likely easier to fix if it's broken, since re-assembly happens in the co

[Anima] ANIMA constrained-voucher mime type registration

2021-08-26 Thread Michael Richardson
Group (anima@ietf.org) or IETF Operations and Management Area Working Group (ops...@ietf.org) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

[Anima] “idevid-issuer” value from voucher (request) payload

2021-08-26 Thread Michael Richardson
o that's all redundant. I think that we will say this (voucher-requests do not need idevid-issuer) in the constrained-voucher document. Since we extend the YANG, we can refine the constrained-voucher part. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Sof

[Anima] async-enroll and CSR grouping introduced in draft-ietf-netconf-sztp-csr-06

2021-08-26 Thread Michael Richardson
w YANG module to add to async -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mai

Re: [Anima] “idevid-issuer” value from voucher (request) payload

2021-08-28 Thread Michael Richardson
alas.) > "do not need idevid-issuer" is mostly true for the Voucher. I do see a > particular corner case where idevid-issuer is needed in the Voucher to > avoid identity confusion, > I can write that down some other time. Thank you. My other idea is to obsolet

[Anima] RFC8994/8995 requirements for CSRattr

2021-08-29 Thread Michael Richardson
sm to specify SAN (new document in ANIMA) Perhaps you can think of others. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing

Re: [Anima] [lamps] RFC8994/8995 requirements for CSRattr

2021-08-30 Thread Michael Richardson
n't you want to define _that_ signalling instead of overloading > a different protocol? I'd love to define that protocol. But, we thought CSRattrs was that protocol. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worl

Re: [Anima] [lamps] RFC8994/8995 requirements for CSRattr

2021-09-01 Thread Michael Richardson
I started a github/kramdown for this work and invited Toerless and Dan. I think that having a 6-10 examples would be helpful for the document. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description

Re: [Anima] [lamps] RFC8994/8995 requirements for CSRattr

2021-09-03 Thread Michael Richardson
Anyway, we are going to enhance the CSRattr description to support all the requirements. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___

Re: [Anima] BRSKI-AE document split discussion

2021-09-03 Thread Michael Richardson
/architecture" document that > we keep alive and extend with whatever we need to keep in common, > and then 2 or maybe over time more protocol specification parts of > the pieces we are adding. I would call the third document the applicability statement for uses in industry

Re: [Anima] [lamps] rollover of CA

2021-09-03 Thread Michael Richardson
DTLS between nodes rekeys. {My reading of MATTER spec didn't reveal any rollover support. Hmm} -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sa

[Anima] kinds of trust relationships in IoT networks (was Re: [lamps] rollover of CA)

2021-09-03 Thread Michael Richardson
some networks do a combination of these for different purposes. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] [lamps] RFC8994/8995 requirements for CSRattr

2021-09-03 Thread Michael Richardson
ugmented CSRs that have goo and there are practical considerations to > rolling out a solution here that compel the use of CSRAttrs. I agree. I'd like to see a RA->CA protocol that augments rather than replaces. I agree that this takes time, but -- Michael Richardson. o O ( IPv

Re: [Anima] BRSKI-AE document split discussion

2021-09-03 Thread Michael Richardson
te above is the same as forgetting how documents 1/2 relate. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima

Re: [Anima] [lamps] RFC8994/8995 requirements for CSRattr

2021-09-07 Thread Michael Richardson
using some sort of REST API. There > is no standard for this of course, perhaps ACME is the closest to a > standardized REST API you get today? Yes, I'd say so. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wor

Re: [Anima] Max/*: Re: RFC 8366 / BRSKI / constrained-voucher: what is encoded in the idevid-issuer field?

2021-09-08 Thread Michael Richardson
m. > So this seems what was meant with "Authority Key Identifier OCTET > STRING" in RFC 8366 -> "Authority Key Identifier extension OCTET STRING > (i.e. the extnValue)" Worthwhile clarifying in constrained-voucher. Should it also be an errata against

[Anima] RFC 8366 / BRSKI / constrained-voucher: what is encoded in the idevid-issuer field?

2021-09-08 Thread Michael Richardson
Identifier (20 bytes). We think this consistent with other users of Authority Key Identifier. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.s

  1   2   3   4   5   6   7   8   9   10   >