Re: [Anima] Fwd: I-D Action: draft-carpenter-anima-l2acp-scenarios-00.txt

2019-02-27 Thread Michael Richardson
t that it's not in scope > for this particular draft. In other words, more IPv4-inspired L2-tricks to maintain the illusion there is a big-blue cable with AUI taps on it. And continued inability to see L2 switches, or creatively route around L2 failures :-) -- Michael Richardson , Sandelman

Re: [Anima] Fwd: I-D Action: draft-carpenter-anima-l2acp-scenarios-00.txt

2019-02-27 Thread Michael Richardson
, or does this mean it uses L2 technologies like MACSEC to create a tunnel for L3 packets? i.e. does L3 multicast appear to just work because it more layer-2 tricks? -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP

[Anima] early allocation of MASA URL OID

2019-02-24 Thread Michael Richardson
OID 1.3.6.1.4.1.46930.2, but will check for both in the Registrar for a few months. (This likely means reworking many example/test IDevIDs over time)} -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature

Re: [Anima] Logging vouchers use case

2019-02-19 Thread Michael Richardson
ganathan >> > >> > >> >> -- >> M. Ranganathan >> ___ >> Anima mailing list >> Anima@ietf.org >> https://www.ietf.org/mailman/listinfo/anima > __

Re: [Anima] proposed anima charter (was; Re: New work item proposal / agenda request)

2019-02-19 Thread Michael Richardson
guess the goal is not to forget it, but not to go down a rathole. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman

[Anima] lack of clarity on CSR attributes required for ACP use of BRSKI

2019-01-26 Thread Michael Richardson
r than rfc822Name SANs, and I don't think we ever want more than one. I would strongly suggest that maybe we want to do this with CBOR instead. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___

Re: [Anima] I-D Action: draft-ietf-anima-bootstrapping-keyinfra-18.txt

2019-01-17 Thread Michael Richardson
added the "reviewer-agrees" label (if github allows), or at least a THUMBS UP (which I'm sure github will allow), or you can unicast us. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Descriptio

Re: [Anima] Iotdir telechat review of draft-ietf-anima-bootstrapping-keyinfra-17

2018-12-13 Thread Michael Richardson
> something about the consequences of a poor random source. It does not > need to be a comprehensive as the section dealing with setting time. I've expanded issue #91: https://github.com/anima-wg/anima-bootstrap/issues/91 > > Minor Concerns: next email. -- Michael Richardson ,

Re: [Anima] unsigned voucher requests in BRSKI

2018-12-13 Thread Michael Richardson
Max Pritikin (pritikin) wrote: > > On Dec 11, 2018, at 3:23 PM, Michael Richardson > > wrote: > > > > > > Panos Kampanakis (pkampana) wrote: > >> I was assuming it was mandatory in the current draft, but I was wrong. As > >> you sugges

Re: [Anima] est-coaps clarification on /att and /crts

2018-12-12 Thread Michael Richardson
u agree with the key. You don't know, so you hit ^C. So, that's all. We don't intend to issue certificates... yet. I'm also asking if there is some use case where the client might legitimate need the list of trust anchors (/cacerts request) in order so that it can...? (I couldn't think of a use case

Re: [Anima] est-coaps clarification on /att and /crts

2018-12-12 Thread Michael Richardson
henticated /crt and /att? We can certainly add that. I'd like to add this. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/m

Re: [Anima] unsigned voucher requests in BRSKI

2018-12-11 Thread Michael Richardson
glad that we agree that it should be consistent. I'm not convinced it's worth having unsigned pledge requests at all. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailin

Re: [Anima] est-coaps clarification on /att and /crts

2018-12-11 Thread Michael Richardson
ething in EST-COAPS to explain that we do not see a use case for replying to /crts and /att for clients which are not recognized. Is 401 (4.01) or 403 (4.03) more appropriate do you think? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sa

Re: [Anima] [Ace] est-coaps clarification on /att and /crts

2018-12-11 Thread Michael Richardson
that it should be restricted. Partly, I'm just not sure where the text should go, or if it needs to be said at all. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima maili

[Anima] est-coaps clarification on /att and /crts

2018-12-11 Thread Michael Richardson
w the name of the operator. Note that the later info probably is revealed just by doing the TLS handshake. I think that they should be restricted in general, but I'm concerned that there might be some situation I've missed. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT

Re: [Anima] unsigned voucher requests in BRSKI

2018-12-08 Thread Michael Richardson
document that anything of the pledge requests goes upwards. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Iotdir telechat review of draft-ietf-anima-bootstrapping-keyinfra-17

2018-12-04 Thread Michael Richardson
Thank you Russ! I will turn your comments into issues, attempting to de-duplicate against what we already have. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing

[Anima] adding pledge-voucher-request for unsigned requests

2018-12-03 Thread Michael Richardson
ed artifact +is include in a base64 format. It is not illegal for attributes +unknown to a registrar to be included by the pledge. + + + +-- pledge-voucher-request? binary -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =-

[Anima] underspecification in handling of unsigned voucher requests

2018-12-03 Thread Michael Richardson
ity' + assertion and associated 'proximity-registrar-cert' need to be + verified to be correct. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list An

Re: [Anima] [Gen-art] dealing with many the secdir and genart comments [on draft-ietf-anima-bootstrapping-keyinfra]

2018-12-03 Thread Michael Richardson
ly. My sense in writing the words was that there were more words needed. But I didn't know what else I could nail down scope-wise, so I stopped. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] [Gen-art] dealing with many the secdir and genart comments [on draft-ietf-anima-bootstrapping-keyinfra]

2018-12-02 Thread Michael Richardson
Brian E Carpenter wrote: >> The authors seriously believe that this will result in an attempt to >> boil the ocean. Yes, BRSKI is exciting for many and opens many doors, >> but in the context of the *ANIMA* Charter, we strongly think that this >> document should leave the oceans

Re: [Anima] BRSKI support for asynchronous processing

2018-12-02 Thread Michael Richardson
ams other than what your IT department expects you to use for email.} -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] BRSKI support for asynchronous processing

2018-12-02 Thread Michael Richardson
new protocol in the form of extensions to 8366 processing. I think it also requires the Registrar to contact the OASA (overriding the MASA URL in the IDevID), but maybe you have another idea. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- si

Re: [Anima] BRSKI support for asynchronous processing

2018-12-02 Thread Michael Richardson
, leaving the IDevID also available. This seems mechanically easy, but seems to open many issues. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.s

[Anima] a multiplicity of pinned certificates

2018-12-02 Thread Michael Richardson
f we do it quickly. Destinguishing between arrays of 1-element and single-items isn't that difficult in the serializations we have. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@

[Anima] security review issue 11: what if MASA refuses to provide a voucher #88

2018-11-29 Thread Michael Richardson
t's a bug that the MASA can be used to prevent resale. I'd love to resolve the situation, but I don't know how. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima

[Anima] gen art issue 7: serial-number in voucher issue #95

2018-11-29 Thread Michael Richardson
serial-number is pretty critical. It goes into the certificate and the MASA uses it as it's primary key. So I'm not really sure how to proceed with this comment. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc De

[Anima] dealing with many the secdir and genart comments

2018-11-29 Thread Michael Richardson
the Reply-To. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/ | ruby on rails[ -- Michael Richardson , Sandelma

[Anima] BRSKI use in IoT enrollment

2018-11-29 Thread Michael Richardson
t to renew the liason process from their end. Rüst will be speaking at the https://iotsfconference.com/. I am also presenting, my slides are at: http://www.sandelman.ca/SSW/talks/iotsf2018-brski/ -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael

[Anima] unsigned voucher requests in BRSKI

2018-11-25 Thread Michael Richardson
Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ -- Michael Richardson , Sandelman Software Works -=

Re: [Anima] early allocation for CT for constrained-vouchers

2018-11-20 Thread Michael Richardson
hi, is there any progress on this? Additionally, I thought that I asked for an early allocation of id-mod-MASAURLExtn2016(TBD) from the pkix(7) id-mod(0) Registry. this is for BRSKI, section 7.2. Michael Richardson wrote: > WG chairs, would you please consider asking Ignas and I

Re: [Anima] I-D Action: draft-ietf-anima-bootstrapping-keyinfra-17.txt

2018-11-05 Thread Michael Richardson
ed devices. Supply chain integration ("know your customer") is an additional step that MASA providers and device vendors can explore. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___

Re: [Anima] Conclusions on ACP and BRSKI?

2018-11-05 Thread Michael Richardson
3, where it turned to micromanagement...} -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] early allocation for CT for constrained-vouchers

2018-10-30 Thread Michael Richardson
and while we can use a private CT for now, it would be better if we could sort this out in the next 2 or 3 weeks! -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mai

[Anima] EST (EST-COAP) usage vs BRSKI

2018-10-23 Thread Michael Richardson
operations if we think it's a good idea to let the connection persist. (Caveat, we might actually want to log the telemetry status operation, and perhaps we always return 200 for that) -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =-

[Anima] HTTP codes from JRC to Pledge

2018-10-23 Thread Michael Richardson
a document collecting experiences. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] ship and forget use cases for onboarding

2018-10-22 Thread Michael Richardson
aying, let's not invent a problem before we understand who actually has the problem and make sure that the people who can solve the problem are at our table. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Fwd: New Version Notification for draft-lear-brski-pop-00.txt

2018-10-22 Thread Michael Richardson
ip-to-holding-company. Holding company leases to end user for period of time. End user identity is never communicated back, and might be very much pseudonymous. I'm thinking about car-rentals, hotel rooms (full of devices), ... -- ] Never tell me the odds! | ipv6

[Anima] FYI: EST COAP, and enrollment interop list

2018-10-14 Thread Michael Richardson
a public IPv4 and/or IPv6 so that we can get traffic to you. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman

Re: [Anima] I-D Action: draft-vanderstok-constrained-anima-dtls-join-proxy-00.txt

2018-10-05 Thread Michael Richardson
sed. I guess that extension could go into this document. If 6tisch, then it would use enhanced beacons. If something else, TBD. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-03 Thread Michael Richardson
the APIs that we need to make it deployable. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-02 Thread Michael Richardson
nt could have better text here. At one point we discussed an operational considerations document. Is that really what you are asking for? -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature _

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-02 Thread Michael Richardson
to do it correctly sooner. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-02 Thread Michael Richardson
lain things more? We call the owner's trust controller the "Registrar", or sometimes the Join-Registrar/Coordinator. I don't mind calling it a trust controller, but maybe your term has a different meaning. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =-

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-01 Thread Michael Richardson
. What we are doing is making it clear that the tractor is actually owned, and not p0wned. However, I'm not sure that BRSKI has a value for large devices with real user interfaces. Maybe it has value for implements though. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- s

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-01 Thread Michael Richardson
| ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature ___ Anima mailing l

Re: [Anima] Secdir last call review of draft-ietf-anima-bootstrapping-keyinfra-16

2018-10-01 Thread Michael Richardson
s, we do not say how they are used. >> This is a pretty important question and we have discussed it at >> length. I remain concerned, but as far as I can see, we have this >> problem already. > if i understand correctly, it creates a new problem, nee

Re: [Anima] Fwd: I-D Action: draft-carpenter-limited-domains-03.txt

2018-09-12 Thread Michael Richardson
Brian E Carpenter wrote: > Discussion welcome, perhaps on int-a...@ietf.org. okay, I'll go read the document if it's relevant... but you CC'ed here is the ACP a limited domain? Or does ANIMA make it more practical in some way to support limited domains? -- Michael Richard

Re: [Anima] documenting SID usage in IETF specification

2018-09-11 Thread Michael Richardson
rmative way of doing things — the conventions > we use for this may evolve faster than the rest of the technical > content of draft-ietf-core-sid. I don't want a prescription either, but rather a BCP that evolves. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting

[Anima] documenting SID usage in IETF specification

2018-09-11 Thread Michael Richardson
| | 100,000 | 1,000,000,000 | Specification Required | +-+---++ ^-- seem to be too many zeros -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___

[Anima] explainining pinned-domain-subject-public-key-info

2018-09-11 Thread Michael Richardson
internet-dra...@ietf.org wrote: > A new version of I-D, draft-ietf-anima-constrained-voucher-02.txt has > been successfully submitted by Michael Richardson and posted to the > IETF repository. > Diff: > https://www.ietf.org/rfcdiff?url2=draft-ietf-anima-constra

Re: [Anima] New Version Notification for draft-ietf-anima-constrained-voucher-01.txt

2018-08-28 Thread Michael Richardson
internet-dra...@ietf.org wrote: > A new version of I-D, draft-ietf-anima-constrained-voucher-01.txt > has been successfully submitted by Michael Richardson and posted to the > IETF repository. > Diff: https://www.ietf.org/rfcdiff?url2=draft-ietf-anima

Re: [Anima] draft-ietf-anima-bootstrapping-keyinfra-16: example uses "prior-signed-voucher"

2018-08-23 Thread Michael Richardson
H48 after all IANA actions. (I think some of them are already done in 8366 actually) > (I didn’t find a ticket system active for this draft; so submitting > this one directly to the list. I can collect further remarks in an > email and send at some later time.) it's on github,

Re: [Anima] draft-ietf-anima-bootstrapping-keyinfra: assertions other than "proximity"?

2018-08-23 Thread Michael Richardson
Thanks for careful read that revealed this point. I've popped your email into an issue: https://github.com/anima-wg/anima-bootstrap/issues/71 -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature

Re: [Anima] Genart last call review of draft-ietf-anima-reference-model-06

2018-08-17 Thread Michael Richardson
em. We don't need the > sentence as grounding for that.) I think that the intent is to say that the ASA will have a model of itself. I think that it would be better to say that. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sande

Re: [Anima] Alissa Cooper's Discuss on draft-ietf-anima-autonomic-control-plane-16: (with DISCUSS and COMMENT)

2018-08-01 Thread Michael Richardson
on, then they probably meant to do something very specific. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sande

Re: [Anima] limited domain

2018-07-26 Thread Michael Richardson
SKI to bootstrap the other LDevIDs, but rather the ACP for the physical devices would provide a mechanism by which virtual routers would be created for customers) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Softwa

[Anima] limited domain

2018-07-25 Thread Michael Richardson
the domain, I think you mean to say, "which interface on a node" is a member of the domain... ?) -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list

[Anima] functional differences for constrained voucher

2018-07-24 Thread Michael Richardson
key, while constrained vouchers are (optionally) pinned to a Raw Public Key. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca

Re: [Anima] Yangdoctors early review of draft-ietf-anima-constrained-voucher-00

2018-07-20 Thread Michael Richardson
ut for clarity. okay, I'll add a note about that. https://github.com/anima-wg/constrained-voucher/commit/6d274f13e3c553efc714c0f06c195f924ad880ff -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-18 Thread Michael Richardson
a datacenter to find their partners in adjacent cabinet B. Yes, there might be a 100G fiber between them... but it might be mis-installed, and/or the lambdas might be wrong, etc. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelma

[Anima] "Rogue" Domains vs audit-only MASA policies

2018-07-16 Thread Michael Richardson
ins registrar. E.g: verify some > domains email, credit-card number, ... something easily > automated and good enough to track back the bad guy with enough > likelihood. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, S

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-16 Thread Michael Richardson
I should post under correct name) How to pick the PANID is not specified yet. Mostly the same as picking an SSID. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@san

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-16 Thread Michael Richardson
| ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature ___ Anima maili

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-16 Thread Michael Richardson
odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature ___

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-16 Thread Michael Richardson
etwork. So please explain. > On 12.07.18 17:12, Michael Richardson wrote: > Eliot Lear wrote: >> involved. What a manufacturer wants to avoid is a pledge joining a >> network where the MASA just does the logging and does no validation, >> withou

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-16 Thread Michael Richardson
and other protocols don't just use a certificate, but they use the related private key to sign part of the transaction. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@san

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-12 Thread Michael Richardson
") that is different from the MASA's desire. The MASA *is* the expression manufacturer's desire. If the manufacturer has sales channel information that indicates the Pledge is on the wrong network, it should not issue a voucher. So the situation you describe makes no sense to me. -- Michael Ri

Re: [Anima] Revision of scope of MASA in the BRSKI - Reg

2018-07-07 Thread Michael Richardson
the device a second time. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ -- Michael Richardson , Sandelman Software

Re: [Anima] GRASP details - WGLC draft-ietf-anima-bootstrapping-keyinfra-15

2018-06-20 Thread Michael Richardson
This announcement can be within the same message as the ACP > | announcement detailed in [I-D.ietf-anima-autonomic-control-plane]. > The optional IPinIP proxy as described in Appendix C requires > the following extension to the syntax of [GRASP]: We are removing Appendix C.

Re: [Anima] WG Last Call on draft-ietf-anima-bootstrapping-keyinfra-15

2018-06-20 Thread Michael Richardson
l references to IPPROTO_IPV6 from the normative text, and also the IPPROTO_UDP, since CoAP version is another draft. 2) We used the //= notation to make it clear that transport-proto was an extension point. We also threw in the $... -- Michael Richardson , Sandelman Software Works -= IPv6 Io

Re: [Anima] [Cbor] CDDL-02 section 2.2.2 choices

2018-06-19 Thread Michael Richardson
Brian E Carpenter wrote: > On 20/06/2018 05:53, Michael Richardson wrote: >> >> Carsten Bormann wrote: >> > 2.2.2 says: >> >> >> It is not an error if a name is first used with a "/=&q

Re: [Anima] CDDL-02 section 2.2.2 choices

2018-06-19 Thread Michael Richardson
d be done) to mark an extension point with a dollar > sign: > $transport-proto /= IPPROTO_TCP > (See section 3.9 for more about that convention.) Ah, interesting. thank you. -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-06-19 Thread Michael Richardson
On 31/05/18 04:23 PM, Brian E Carpenter wrote: On 01/06/2018 07:31, Michael Richardson wrote: Toerless Eckert wrote: > On Thu, May 31, 2018 at 03:07:15PM -0400, Michael Richardson wrote: >> > I would prefer to have the simple definition "ANI == systems that suppo

Re: [Anima] references to code ?

2018-06-19 Thread Michael Richardson
On 31/05/18 02:43 PM, Toerless Eckert wrote: Thanks, Eliot Good point, forgot to ask/mention this point in my previous emails. As an ANIMA contributor, i would love for a draft/->RFC like BRSKI to mention known existing implementations, especially open source, even if just PoC. I did not

[Anima] transport-proto IANA considerations

2018-06-19 Thread Michael Richardson
On 19/06/18 11:08 AM, Michael Richardson wrote: From our document: transport-proto /= IPPROTO_TCP ; note this is an extensible CDDL choice ; and can be added to in subsequent ; specifications using the /= and //= In further

[Anima] CDDL-02 section 2.2.2 choices

2018-06-19 Thread Michael Richardson
ifications using the /= and //= It is unclear in section 2.2.2 if we can say foo /= without having said foo = 1 / 2 / 3 previously, but it seems like it should be reasonable to do in order to indicate that implementations should expect future values. -- Michael Richardson , Sandelman Soft

Re: [Anima] getting the constrained MASA voucher signing public key to JRC

2018-06-18 Thread Michael Richardson
2.3 or at > https://www.iana.org/assignments/core-parameters/core-parameters.xhtml#content-formats > . Can you provide a pointer to explain what this would look like? This is between the Registrar and MASA, which is unconstrained HTTPS, not CoAP, even in the constrained situation. -- Mi

Re: [Anima] naming of constrained voucher YANG model

2018-06-05 Thread Michael Richardson
or so ago. I hear your suggestion for ietf-voucher-constrained{,-request}, and unless there is a groundswell against that, another rename will occur. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network

Re: [Anima] GRASP details - WGLC draft-ietf-anima-bootstrapping-keyinfra-15

2018-06-01 Thread Michael Richardson
ative" would be the same as > for IPinIP. Maybe its different code-paths == different ports. I'm sorry, I don't even understand the problem. Maybe someone else can translate for me. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Ri

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-05-31 Thread Michael Richardson
ASP". > Possibly both, because GRASP already defines > transport-proto = IPPROTO_TCP / IPPROTO_UDP > IPPROTO_TCP = 6 > IPPROTO_UDP = 17 Ah right. I just don't care... someone else decide and tell me what. -- ] Never tell me the odds!

Re: [Anima] references to code ?

2018-05-31 Thread Michael Richardson
it might sit in mis-ref for a few more months, which might help someone. Is it that useful to the IESG? Having said that, I don't have any problem adding it, I just don't want to do much work on it :-) -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.a

Re: [Anima] references to code ? (was: Re: WG Last Call on draft-ietf-anima-bootstrapping-keyinfra-15)

2018-05-31 Thread Michael Richardson
CoAP code to have DTLS underneath it was not easy, as the OpenSSL DTLS code has some problems in it's DTLS API. (At least, I say it does, and I did patches for it. I can't get my patches upstream until I find a VAX to test compile them on though...) -- ] Never tell me the o

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-05-31 Thread Michael Richardson
BRSKI rather than "update of GRASP". -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-05-31 Thread Michael Richardson
Toerless Eckert wrote: > On Thu, May 31, 2018 at 03:07:15PM -0400, Michael Richardson wrote: >> > I would prefer to have the simple definition "ANI == systems that support >> > both BRSKI and ACP" in the doc itself. Threre is really no single a

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-05-31 Thread Michael Richardson
re is so that implementations actually check the value. > One option in this case is to include "/ IPPROTO_UDP / IPPROTO_IPV6" > in the syntax with a specific note that they are not currently > defined and MUST be treated as errors if received. I prefer this to the not li

Re: [Anima] [Closed] Re: Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-05-31 Thread Michael Richardson
l (just working through that in ACP doc because > of the ongoing review of it). okay. > 4.1.1: >> transport-proto = IPPROTO_TCP / IPPROTO_UDP / IPPROTO_IPV6 > The way i see it, the normative approach with TCP circuit proxy would > always only have TCP, right, e.g.: the

[Anima] getting the constrained MASA voucher signing public key to JRC

2018-05-29 Thread Michael Richardson
Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc

[Anima] recording the need for a document on Operational security for ACP

2018-05-29 Thread Michael Richardson
need some clarification, if only so that they are automated correctly. This is just a note for later on; I think we need some operating ACPs before we can describe issues with them. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman

Re: [Anima] Adoption call for draft-richardson-anima-ace-constrained-voucher (ends 05/12/2018)

2018-05-23 Thread Michael Richardson
6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ signature.asc Description: PGP signature ___ Anima mailing list Anima

Re: [Anima] draft-richardson-anima-ace-constrained-voucher

2018-04-30 Thread Michael Richardson
In other words: to not be PKCS7 compatible, but require CMS processing. I think this is reasonable from a specification point of view, but there has been pushback from people who have FIPS-140 libraries that they have hard times getting updated. -- ] Never tell me the odds!

Re: [Anima] I-D Action: draft-ietf-anima-bootstrapping-keyinfra-13.txt

2018-03-27 Thread Michael Richardson
> So I think the "SHOULD NOT" clause has to go. Perhaps you > mean: > This value MUST NOT be used for any future Registration attempt. Edited as you suggest! -- Michael Richardson <mcr+i...@sandelman.ca>, Sandelman Software Works -= IPv6 IoT consulting

Re: [Anima] dns-sd [was Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09]

2018-03-26 Thread Michael Richardson
Brian E Carpenter <brian.e.carpen...@gmail.com> wrote: > On 27/03/2018 08:11, Michael Richardson wrote: > ... >> >> > d) Add section to request brksi-proxy and brski-registrar to >> > IANA service name registry. >> >> I

Re: [Anima] Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-03-26 Thread Michael Richardson
Brian E Carpenter <brian.e.carpen...@gmail.com> wrote: > I definitely recommend replacing lower-case "may" in a case like > the one below. Agreed. > Perhaps: >>> , and MUST NOT be >>> enabled unless the JRC indicates support for th

Re: [Anima] Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-03-26 Thread Michael Richardson
two in an appropriate section > of BRSKI as a very explicit example how BRSKI can be reused outside the > complete ANIMA scope (also add draft-ietf-netconf-zerotouch as an > informational > reference). I would prefer to let ietf-netconf-zerotouch do tha

Re: [Anima] Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09

2018-03-26 Thread Michael Richardson
ntries in that list? > b) It would be good to create subsections for each registray mentioned so > that one can see from the table of content what registries are impacted. Don't we already have that? We are only creating one registry. > c) Probably need a summary of updates this

[Anima] constrained voucher

2018-03-21 Thread Michael Richardson
uchers may be transported in the [I-D.vanderstok-ace-coap-est] protocol. -- Michael Richardson <mcr+i...@sandelman.ca>, Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anim

Re: [Anima] Shepherd review draft-ietf-anima-bootstrapping-keyinfra-09 (part 4?)

2018-03-20 Thread Michael Richardson
e really want people to read 6125, not just guess. > Aka: for the less PKIX/Websecurity initiated readers like me, writing out > what is actually implied could make the sentence easier to parse > (instead of having to read more of RFC6125. But, I want you to read 6

Re: [Anima] BRSKI pledge cert/key/script stuff

2018-03-18 Thread Michael Richardson
should be not be signed in any way. -- Michael Richardson <mcr+i...@sandelman.ca>, Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] BRSKI pledge cert/key/script stuff

2018-03-18 Thread Michael Richardson
ns the > encoded (signed form) of the Pledge voucher-request. > What is the correct behavior? I've opened this as issue: https://github.com/anima-wg/anima-bootstrap/issues/48 -- Michael Richardson <mcr+i...@sandelman.ca>, Sandelman Software Wo

<    4   5   6   7   8   9   10   11   >