On Jun 15, 2018, at 8:38 PM, Michael Richardson 
<[email protected]<mailto:[email protected]>> wrote:


Michael Richardson <[email protected]<mailto:[email protected]>> wrote:
5) use the existing /voucherrequest, but define the result (when an
application/cbor+cose voucher request is presented) to be a multipart
result, with the second piece being the public key "bag".

I've been convinced to return a multipart/related.
(I think it's related I want).

This is HTTP not CoAP, to be clear.

The next 6tisch-dtsecurity-zerotouch-join will say;

In order to do this, the MASA MAY return a multipart/related return, within that
body, two items SHOULD be returned:

1. An application/voucher-cose+cbor body.
2. An application/pkcs7-mime; smime-type=certs-only, or an
application/SOMETHING containing a Raw Public Key.

It seems weird to combine the cwt style body with such an unconstrained value 
such as a pkcs7-smime blob.
Even if it makes sense to use the http layer multipart instead of x5c 
(unprotected header fields) wouldn’t the more optimized message format make 
sense?

I can’t seem to find a definition of multipart (or “related”?) for CoAP. If its 
handled anything like https://tools.ietf.org/html/rfc2046#section-5.1.1 I’d 
expect to find it in here https://tools.ietf.org/html/rfc7252#section-12.3 or 
at 
https://www.iana.org/assignments/core-parameters/core-parameters.xhtml#content-formats
 . Can you provide a pointer to explain what this would look like?

- max



(See other email wherein I ask for opinions)


--
Michael Richardson <[email protected]<mailto:[email protected]>>, 
Sandelman Software Works
-= IPv6 IoT consulting =-



_______________________________________________
Anima mailing list
[email protected]<mailto:[email protected]>
https://www.ietf.org/mailman/listinfo/anima

_______________________________________________
Anima mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/anima

Reply via email to