Re: [Anima] Call for agenda items ANIMA @ IETF 111, online

2021-07-12 Thread Michael Richardson
as constrained-join-proxy, but ietf-constrained-voucher still needs more Security Considerations and some Applicability statement. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

Re: [Anima] Call for agenda items ANIMA @ IETF 111, online

2021-07-12 Thread Michael Richardson
Brian E Carpenter wrote: > Although we probably want to produce one more version, I think the > authors of this draft feel it is as complete as seems possible at > present. So is it possible to plan a WG Last Call as soon as the next > version comes out? I concur.

Re: [Anima] FYI: Self-Driving Networks without Self-Crashing Networks

2021-07-10 Thread Michael Richardson
lies are precusors to attacks? If so, assuming that we can even figure out what the network state is, do we have any chance of anonymizing the data? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worl

Re: [Anima] FYI: Self-Driving Networks without Self-Crashing Networks

2021-07-09 Thread Michael Richardson
f-Driving-Network" as a new expansion of SDN :-) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.or

Re: [Anima] New Version Notification for draft-dang-anima-network-service-auto-deployment-00.txt

2021-07-08 Thread Michael Richardson
be regarded as a route discovery JD> process. I also would like to hear more of your thoughts on this JD> point. I don't have the background in traffic engineering to know. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide sig

Re: [Anima] New Version Notification for draft-dang-anima-network-service-auto-deployment-00.txt

2021-07-07 Thread Michael Richardson
to comment, review or contribute it. > Best wishes, > Joanna > ___ > Anima mailing list > Anima@ietf.org > https://www.ietf.org/mailman/listinfo/anima -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman

[Anima] Registrar to MASA connections: SNI required

2021-07-06 Thread Michael Richardson
REQUIRED. TLS 1.3 (or newer) SHOULD be available. I don't know if is worth an errata. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ An

[Anima] discussing EST CSRATTRS specifying the SAN at IETF111

2021-07-06 Thread Michael Richardson
. LAMPS chairs: can we have ten minutes for this discussion on the Thursday Session III meeting at IETF111? The Monday Session II is conflicted with ANIMA. I'm gonna voluntold Eliot to lead this discussion :-) -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman

Re: [Anima] Resending: Call for adoption: draft-richardson-anima-jose-voucher

2021-07-06 Thread Michael Richardson
it wants to merge this work into an RFC8366bis. There are positives and negatives about such a thing. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Descript

Re: [Anima] early allocation for x5bag

2021-07-05 Thread Michael Richardson
Carsten Bormann wrote: > On 2021-07-05, at 20:16, Michael Richardson wrote: >> >> >> https://www.iana.org/assignments/cose/cose.xhtml#header-parameters > Is there a time-warp somewhere? > x5bag (TEMPORARY - registered 2019-08-20, exten

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
ditor to delete the > IANA-maintained module. I think you mean, the RFC-maintained module :-) How do we keep the YANG catalog from latching onto it. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signatu

Re: [Anima] [lamps] EST CSRATTRS specifying the SAN

2021-07-05 Thread Michael Richardson
ce in Cisco's libEST, which > has remained extremely sketchy regarding the csrattrs topic. Are there examples in libest that we can use? Is there unit test code in there that could be exercised to validate other examples? Are we back to redoing this in JSON? -- Michael Richardson

[Anima] early allocation for x5bag

2021-07-05 Thread Michael Richardson
oogle.com/document/d/1T8Rtfk1zia_p05_6eb_WQA2Mmid-eP1-cAgnwdpF9Xk/edit?usp=sharing -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
art of the specification of an enumeration - not in > YANG). yes, it's a text string for XML and JSON, this isn't the case for YANG-CBOR if a value is set. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-05 Thread Michael Richardson
e (usually a guess and usually wrong but it helps to have the tp> assumptions about the requirements spelt out) and such like. tp> As an engineer, I do like to know the requirements before working on the design! We need to be able to write RFCs that extend the voucher types. Not that ofte

Re: [Anima] Secdir early review of draft-ietf-anima-constrained-voucher-11

2021-07-04 Thread Michael Richardson
nit tests. This is quite common for anything involve cryptographic operations. We don't intend to remove it. Our experiences is that people outside of the IETF find protocols without examples to be challenging to implement. Should we merge Appendix A and B? -- Michael Richardson. o O ( IPv6

Re: [Anima] BRSKI design team meeting on Thursday

2021-07-04 Thread Michael Richardson
of above statement, it means that Registrar will operate with any manufacturer, that is, not{3}) > * New issue #122: Use of CoAP 4.03 Forbidden vs 4.01 Unauthorized > - https://github.com/anima-wg/constrained-voucher/issues/122 -- Michael Richardson. o O ( IPv6 IøT consul

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
Michael Richardson wrote: > I propose that the WG adopt this as the -00, and then we change the document > to change this into an RFC7224-style IANA-maintained YANG module. > (In DHC WG, when we did RFC3315bis to make RFC8415 we did a -00 which was > whitespac

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
s updated when IANA revises the module. I think, it mostly doesn't matter because none of are generating code from YANG... AT THIS TIME. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwid

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-07-04 Thread Michael Richardson
//datatracker.ietf.org/doc/draft-richardson-anima-rfc8366bis/ Html: https://www.ietf.org/archive/id/draft-richardson-anima-rfc8366bis-00.html Htmlized: https://datatracker.ietf.org/doc/html/draft-richardson-anima-rfc8366bis -- Michael Richardson. o O ( IPv6 IøT consulting )

Re: [Anima] discussing draft-richardson-anima-jose-voucher

2021-07-04 Thread Michael Richardson
coding > and new privacy considerations). This qualifies exactly what type > of update this RFC will be. Yes, that's what we are obligated to do now anyway. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signat

Re: [Anima] Resending: Call for adoption: draft-richardson-anima-jose-voucher

2021-07-04 Thread Michael Richardson
to say what form of Updates we care about. It is not Amends. It is not quite Extends. It is mostly in the See Also. ps: RFC editor will prefer "artifact" over "artefact" :-) https://github.com/mcr/anima-jose-voucher/commit/66d39393d1d3ccbcb0e74674e10ea6599288eb28 -- Michael Richardson. o

Re: [Anima] on adopting draft-richardson-anima-jose-voucher-01 --- needed for brski-async-enroll

2021-06-30 Thread Michael Richardson
utside my > expertise, but it seems necessary so I would support adoption. Thanks. What parts did you understand? It's just RFC8366 with a different signature. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide si

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-29 Thread Michael Richardson
out that, but others might not. I was basically trying to distill it down into a few words. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelm

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-29 Thread Michael Richardson
t) -> jose-voucher (voucher, voucher-request) and my question was a bit about how we manage all their things inherited. It's really the classic CS multiple inheritance problem. {A Cat is an Mammal A Cat is an Four-legged creature A Cat is Nocturnal.} -- Michael Richardson. o O

[Anima] on adopting draft-richardson-anima-jose-voucher-01 --- needed for brski-async-enroll

2021-06-29 Thread Michael Richardson
ng and > Encryption mechanism described in RFC7515. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@i

[Anima] BRSKI design team meeting on Thursday

2021-06-29 Thread Michael Richardson
Hi, Thursday is July 1, Canada Day. (Not alas, much to celebrate as a nation, now that the "secret" of the thousands of graves is finally public) But, I'll be off from work for the day with other outdoor plans, so I won't attend the 13:30UTC. Please feel free to meet without me.

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-29 Thread Michael Richardson
<#secure method=pgpmime mode=sign> > On Mon, Jun 28, 2021 at 12:39:38PM -0400, Michael Richardson wrote: >> >> Juergen Schoenwaelder wrote: >> >> Juergen Schoenwaelder wrote: > >> > You revise RFC 8366 and do the fo

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-28 Thread Michael Richardson
t make any modifications to the existing enumerations. > - You republish the revised version of RFC 8366. > A couple of month later (and after surviving all the reviews), you > declare success. I fear there is nothing "cheaper". -- Michael Richardson. o O

Re: [Anima] [netmod] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-28 Thread Michael Richardson
Juergen Schoenwaelder wrote: > Note that there is also a middle ground, namely an enumeration type > factored out into an IANA maintained module that is process wise easier > to extend - should extensions be needed more regularly. That would suit me. How do we do that? -

Re: [Anima] a new anima draft on grasp objective ip to group mapping

2021-06-28 Thread Michael Richardson
at the impact of the longer latency to the authoritative source of information is. There is also the question of what happens when policy cache is full, and some entries are expunged. BUT, overall, I think that this is actually a really good document, and a really interesting ASA, thank you for p

Re: [Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-27 Thread Michael Richardson
to see what happens to SID values, etc. But, not before the hackathon, maybe during. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

[Anima] revising RFC8366 -- Re: BRSKI-AE enum issue -> empty, but what's he encoding ?

2021-06-25 Thread Michael Richardson
but how much whisky does it cost to bribe an AD? 2) write a formal "Updates" RFC8366 that just does the NEW/OLD version of updates, and that's it. 3) do an entire RFC8366bis. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works

Re: [Anima] Reuse of SZTP-CSR YANG definition in BRSKI-AE

2021-06-25 Thread Michael Richardson
mport dependency on ietf-sztp-csr (and possibly > ietf-sztp-bootstrap-server). > Hence, my suggestion, if you were to do this, would be for a separate > ietf-csr-types.yang module defined as part of the SZTP-CSR draft. That would be very cool. -- Michael Richards

Re: [Anima] GEN-ART review of constrqained-voucher

2021-06-24 Thread Michael Richardson
the activity diagram on Figure 1 in Appendix C. The diagram doesn't explicitly say that I include the sid file. It was stated IANA would be creating and maintaining SID files for anything previously published. -- ] Never tell me the odds! | ipv6 mesh ne

[Anima] GEN-ART review of constrqained-voucher

2021-06-23 Thread Michael Richardson
Section 8.3, Figure 2: Please find fome other way to represent rh> [RPK3]. This looks like a reference, and that is not the intent. okay. rh> Section 8.3, first paragraph after Figure 2: s/certificate-less rh> enrollment/enrollment without certificates/ done. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] Reuse of SZTP-CSR YANG definition in BRSKI-AE

2021-06-23 Thread Michael Richardson
uldn't take more than 30 minutes of real-time discussion, maybe way less. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rail

Re: [Anima] Review of draft-ietf-anima-constrained-join-proxy-02 (part 2/2)

2021-06-23 Thread Michael Richardson
the > Registrar's "join-proxy resource" would have to be discovered also, not > just the port. ) I think another answer is because the server side won't be CoAP, it's DTLS with a bit. -- ] Never tell me the odds! | ipv6 mesh networks [ ] M

Re: [Anima] Review of draft-ietf-anima-constrained-join-proxy-02 (part 2/2)

2021-06-23 Thread Michael Richardson
AP-over-DTLS messages, blockwise transfer can be used to ensure this. do we want to insist that this is the way? It is good that we are figuring this out now. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Wor

Re: [Anima] towards adoption of draft-richardson-anima-jose-voucher

2021-06-23 Thread Michael Richardson
COBOL with J2EE) Having a single format for "everything" is sometimes better than a super-optimized format for a single edge case, which might not even be particularly power constrained now. 3) I haven't made enough time for the running code, although I think I can show something by e

Re: [Anima] Reuse of SZTP-CSR YANG definition in BRSKI-AE

2021-06-19 Thread Michael Richardson
module modeled in a similar. > You can do this. I think that we can have some common mindshare here. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature _

Re: [Anima] [netmod] [anima-wg/anima-brski-async-enroll] Definition of new assertion type (agent-proximity) for the voucher (#18)

2021-06-18 Thread Michael Richardson
d flip "leaf assertion” to “type > identityref”. Yes, okay, so if we have to revise 8366, then this sounds like something we should do. > FWIW, "leaf assertion” is not used by SZTP (RFC 8572). -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelma

Re: [Anima] [netmod] [anima-wg/anima-brski-async-enroll] Definition of new assertion type (agent-proximity) for the voucher (#18)

2021-06-18 Thread Michael Richardson
ble extend it? Can we do this via IANA registry in some way instead? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anim

Re: [Anima] draft-richardson-anima-l2-friendly-acp-02.txt

2021-06-15 Thread Michael Richardson
y thing I knew I needed was the peer's L2 address, and that's already there in the LLDP source address. It could be that it's hard to get at though, so we might want to keep that in mind. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wor

[Anima] draft-richardson-anima-l2-friendly-acp-02.txt

2021-06-15 Thread Michael Richardson
an be deployed easily to layer-two (Ethernet) switched > technologies that are common on Campus/Enterprise network > architectures. > This document leverages the hop-by-hop announcement used in LLDP, but > runs bulk data over normal IPv6 Link-Local unicast ethernet frame

Re: [Anima] [anima-wg/anima-brski-async-enroll] Definition of new assertion type (agent-proximity) for the voucher (#18)

2021-06-15 Thread Michael Richardson
the grouping help us at all? We need to do this for both voucher and voucher-request. > enum agent-proximity { description "Indicates that the voucher has -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.

Re: [Anima] [hackathon] constrained-voucher Hackathon IETF111 efforts

2021-06-14 Thread Michael Richardson
st >> https://datatracker.ietf.org/doc/draft-ietf-anima-constrained-join-proxy/ >> as well, which is also ready for WGLC. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

Re: [Anima] [hackathon] constrained-voucher Hackathon IETF111 efforts

2021-06-14 Thread Michael Richardson
have created a document to capture all the planning into at: >> >> https://docs.google.com/document/d/1T8Rtfk1zia_p05_6eb_WQA2Mmid-eP1-cAgnwdpF9Xk/edit?usp=sharing -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc De

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-14 Thread Michael Richardson
ink this is close.) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] towards adoption of draft-richardson-anima-jose-voucher

2021-06-14 Thread Michael Richardson
pieces. Fries, Steffen wrote: >o Defined call flow and objects for interactions in use case2. > Object format based on draft for JOSE signed voucher artifacts and > aligned the remaining objects with this approach in Section 5.2.3 -- Michael Richardson , Sandelman Softw

Re: [Anima] chain of redirections for Cloud Registrar

2021-06-14 Thread Michael Richardson
.com connection: GET > /.well-known/brski/requestvoucher?brskiredirpath=domain3.com,domain2.com,domain.com Doesn't the HTTP header Referrer include this kind of thing? Or if not, is there another header? -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consult

Re: [Anima] BRSKI redirect Q (was: Re: chain of redirections for Cloud Registrar)

2021-06-14 Thread Michael Richardson
assumes that the pledge has connectivity, so it can go "anywhere" -- Michael Richardson , Sandelman Software Works -= IPv6 IoT consulting =- signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-14 Thread Michael Richardson
ute YANG modules (as pull-requests) to drafts for which I'm not an author, and I don't really want to have to convince them to upgrade. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network archite

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-14 Thread Michael Richardson
Carsten Bormann wrote: > On 14. Jun 2021, at 03:09, Michael Richardson > wrote: >> >> 1) how to process yang files with -DD-MM into XML. 2) how to >> generate yang tree files. 3) how do I get my YANG includes >> downloaded, and do I

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-14 Thread Michael Richardson
Carsten Bormann wrote: > On 14. Jun 2021, at 03:09, Michael Richardson wrote: >> >> 1) how to process yang files with -DD-MM into XML. >> 2) how to generate yang tree files. >> 3) how do I get my YANG includes downloaded, and do I put them i

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-13 Thread Michael Richardson
Michael Richardson wrote: > 3) how do I get my YANG includes downloaded, and do I put them into my repo? The other part of the question is how to manage the various extensions that are occuring. What I know about so far: (ascii art warning. fixed font needed) https://www.yangcatalog.

Re: [Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-13 Thread Michael Richardson
Michael Richardson wrote: > 3) how do I get my YANG includes downloaded, and do I put them into my repo? RFC8995 has been published. It has a YANG module, ietf-voucher-request, which is derived from the RFC8366 ietf-voucher. RFC8366 has: ietf-voucher@2018-05-09 The DT still poi

[Anima] looking for practical advice on managing YANG source in XML format RFCs

2021-06-13 Thread Michael Richardson
with some co-authors which want to stick to XMLv3 rather than kramdown, and whose understanding of Makefiles is poor. I want to stick with the normal stuff so that all the github/etc. tooling works for everyone involved. I'm looking for advice on how do this this? -- Michael Richardson. o O

[Anima] chain of redirections for Cloud Registrar

2021-06-12 Thread Michael Richardson
n EST server? It seems like a good idea to me. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https:/

[Anima] constrained-voucher Hackathon IETF111 efforts

2021-06-11 Thread Michael Richardson
for WGLC. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] CSRATTRS specifying the SAN

2021-06-09 Thread Michael Richardson
ould certainly be happy with that. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] key algorithm in CSR

2021-05-27 Thread Michael Richardson
549 1 1 11 ). It feels odd, because that's not an DN attribute. I am asking this because my ACP implementation has to deal with RSA certificates until everything is ECDSA happy. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Soft

Re: [Anima] BRSKI and IDevID (non-!)issues with draft-ietf-uta-use-san

2021-05-14 Thread Michael Richardson
diff RFC"? If you mean, rfc6125bis, then it seems like it would risk opening wounds. But, wholesale, "replace section X with ...." might be useful. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide si

[Anima] BRSKI and IDevID (non-!)issues with draft-ietf-uta-use-san

2021-05-13 Thread Michael Richardson
e language only. Most of the language is what not to do. I think that this is important to list, but I suggest it be split up into a section "Do this" and a section "Do not do this" -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelma

Re: [Anima] AUTH48 request for CSR example

2021-04-17 Thread Michael Richardson
ubject Alternative Name: email:rfcself+fd739fc23c3440112233445500...@acp.example.com when we are actually settled on otherName. My code has not been updated for that. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Wor

[Anima] AUTH48 request for CSR example

2021-04-13 Thread Michael Richardson
+fd739fc23c3440112233445500...@acp.example.com I don't know if this worth adding. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails

Re: [Anima] GRASP DULL, IPv6 LL scope and multicast and BSD sockets API

2021-04-07 Thread Michael Richardson
ud > of it; in fact I'm frightened to touch it. A few remarks in line below: Yes, it does help. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

[Anima] GRASP DULL, IPv6 LL scope and multicast and BSD sockets API

2021-04-06 Thread Michael Richardson
gh GRASP-15, and I didn't see anything. That is: loop { sleep(60s +- rand(10)); send-M_FLOOD-on-next-interface; } rather than: loop { sleep(60s); for if in interfaces { send-M_FLOOD-on(if) } } -- Michael R

Re: [Anima] Adoption call for draft-richardson-anima-voucher-delegation-03, ends April 19th 2021

2021-04-06 Thread Michael Richardson
lendar year, could the chairs let the WG know about this criteria? -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list An

Re: [Anima] [lamps] Long-lived certificates, but frequently renewed certificates

2021-03-23 Thread Michael Richardson
t's rather more meta data, and it isn't clear it should get shared with peers. > Michael > tells me maybe the CA software gets upgraded and other changes sneak in > that one did not expect. So, I was thinking of a hypothetical that could result in a surprising change in the field

Re: [Anima] [lamps] Long-lived certificates, but frequently renewed certificates

2021-03-21 Thread Michael Richardson
Eliot Lear wrote: >> On 20 Mar 2021, at 19:00, Michael Richardson wrote: >> >> It has to be a three phase commit, and it needs to be initiated from the EST server. > See my answer to Nico. The EST server certainly knows when it wants to > roll the

Re: [Anima] [lamps] Long-lived certificates, but frequently renewed certificates

2021-03-20 Thread Michael Richardson
Eliot Lear wrote: >> On 18 Mar 2021, at 19:58, Michael Richardson wrote: >> >> A pity that EST (and I think SCEP, but I haven't read it all), just returns >> the resulting certificate, and not something more useful, like a JSON dict >>

Re: [Anima] [Acme] Long-lived certificates, but frequently renewed certificates

2021-03-20 Thread Michael Richardson
ed through unicast communications that happen to already be occuring. ("And they tell two friends, and so on, and so on...") I think that a CRL fits within the constraints. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and W

Re: [Anima] [lamps] [Acme] Long-lived certificates, but frequently renewed certificates

2021-03-20 Thread Michael Richardson
John Gardiner Myers wrote: > On 3/18/21 11:15 AM, Michael Richardson wrote: >> As far as I know, the only signal for when to renew is notAfter. >> Generally, one should renew sometimes after the half-way point. >> (LetsEncrypt policy of 90 days, but discoura

Re: [Anima] [lamps] Long-lived certificates, but frequently renewed certificates

2021-03-20 Thread Michael Richardson
r being in some distant reliable future, that a higher frequency of renewal attempts is desired. These seem like things we should have put into draft-ietf-ace-est-coaps! Some of this is also already worked out for symmetric network keys in draft-ietf-6tisch-minimal-security. -- Michael Richardson

Re: [Anima] [lamps] Long-lived certificates, but frequently renewed certificates

2021-03-18 Thread Michael Richardson
Nico Williams wrote: > On Thu, Mar 18, 2021 at 05:54:55PM +0100, Toerless Eckert wrote: >> On Thu, Mar 18, 2021 at 08:57:04AM -0400, Michael Richardson wrote: >> > It seems that a CA ought to be able to express some other kind of renewal >> > period di

[Anima] Long-lived certificates, but frequently renewed certificates

2021-03-18 Thread Michael Richardson
ch is good in theory, but not in practice. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

[Anima] Long-lived certificates, but frequently renewed certificates

2021-03-18 Thread Michael Richardson
this area? I think that a smooth transition from one CA anchor to another can be accomplished by signing of the old CA by the new CA, and VV. I don't know how successful this has been in reality: I sense that it's a practice which is good in theory, but not in practice. -- Michael Richardson. o O (

[Anima] L2 friendly ACP work

2021-03-12 Thread Michael Richardson
will abandon this document for now. I think that we can do ACP DULL discovery (only) over LLDP, as the AN_ACP M_FLOOD is essentially static information, thus appropriate for LLDP. The rest of the code ACP can occur over normal unicast, whether that's IKEv2/v6-LL or some MACsec as Toerless prefers.

Re: [Anima] [Acme] ACME integrations with BRSKI and the cmcRA EKU

2021-03-05 Thread Michael Richardson
On 2020-12-21 5:54 a.m., Deb Cooley wrote: I don't post often, so go easy. And I've not read up on the current state of BRSKI or MASA.  This response is based only on the original post. The BRSKI Registrar is expected, like all RFC7030 Registrars, to have the cmcRA bit set. The conclusion is

Re: [Anima] draft-ietf-acme-star-delegation-05.txt and BRSKI-AE

2021-03-03 Thread Michael Richardson
pledge-server (UC2). Would you have further suggestions for a > naming? We could also discuss this in the next design team meeting. I suggest we refer to it as "pledge-initiated onboarding" (PULL), or "registrar (or pledge-agent) initiated onboarding". Also, it is a Pledg

Re: [Anima] ANIMA when there is a system-wide issue

2021-02-23 Thread Michael Richardson
of 802.1X-2020. Table 11-3 lists the 9 EAPOL >> types used. No equivalent to IANA Consideratons exist, so I think >> that it would require a revision by the IEEE to allocate a code. That >> would really be enough. > Right. I didn't mean to use EAPOL. I me

[Anima] changes in draft-ietf-anima-constrained-voucher-10.txt

2021-02-21 Thread Michael Richardson
Sub"ordinate CA. Figure 2 gets that right. internet-dra...@ietf.org wrote: > Title : Constrained Voucher Artifacts for Bootstrapping > Protocols Authors : Michael Richardson Peter van der Stok Panos > Kampanakis Esko Dijk Filename : > draft-ietf-anima-constraine

[Anima] draft-ietf-acme-star-delegation-05.txt and BRSKI-AE

2021-02-21 Thread Michael Richardson
iated STAR certificate renewal with the ACME CA. Another key > property of this mechanism is it does not require any modification to > the deployed TLS ecosystem. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide

Re: [Anima] ANIMA when there is a system-wide issue

2021-02-12 Thread Michael Richardson
he device that would be providing that native multicast in the ACP... -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing lis

Re: [Anima] ANIMA when there is a system-wide issue

2021-02-11 Thread Michael Richardson
l me if that you think this is within the ANIMA WG's charter. > Forget using multicast MAC destinations. Maybe i can find the time > trying to remember all the horrible things that could go wrong with it. okay. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Softwa

Re: [Anima] ANIMA when there is a system-wide issue

2021-01-28 Thread Michael Richardson
t details a number of possibilities, and what it would take to standardize each possibility. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature __

[Anima] subordinate vs intermediate certification authorities

2021-01-28 Thread Michael Richardson
ed-voucher, in which we have a number of choices on which certificate (or public key) to pin our constrained-RFC8366 voucher. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___

[Anima] [IANA #1186632] S/MIME CMS Content-Type -- constrained voucher (fwd) "Michelle Cotton via RT": [IANA #1186632] S/MIME CMS Content-Type -- constrained voucher

2021-01-08 Thread Michael Richardson
to wrap CBOR objects with CMS. > > The authors of the document suggest that this early allocation not be > renewed. > Thank you. > > -- > Michael Richardson. o O ( IPv6 I�T > consulting ) >Sandelman Software Works Inc, Ottawa and Worldwide

[Anima] continuing BRSKI design team calls

2021-01-07 Thread Michael Richardson
* Peter van der Stok * Ejko Dijk * Thomas Werner * Aurelio Schellenbaum * Steffen Fries * Michael Richardson * Wei Pan * Hendrik Brockhaus * Eliot Lear We are working on the following documents/repositories: https://github.com/

[Anima] S/MIME CMS Content-Type -- constrained voucher

2021-01-06 Thread Michael Richardson
testing has revealed that we really do not need/want to wrap CBOR objects with CMS. The authors of the document suggest that this early allocation not be renewed. Thank you. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide

Re: [Anima] ANIMA when there is a system-wide issue

2020-12-19 Thread Michael Richardson
the aforementioned circular dependencies. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list Anima@ietf.org https://www.ietf.org/mailman/listinfo/anima

Re: [Anima] GRASP M_FLOOD captured from Reggie.py -- could it be wrong?

2020-12-13 Thread Michael Richardson
Carsten Bormann wrote: > You forced me to get a bigger screen... > I don’t know what you are trying to say here: >> On 13. Dec 2020, at 20:43, Michael Richardson >> wrote: >> >> I guess I'm still confused by why this is: [ &g

[Anima] GRASP M_FLOOD captured from Reggie.py -- could it be wrong?

2020-12-13 Thread Michael Richardson
84 # array(4) 18 67 # unsigned(103) 50 # bytes(16) 2607F0BF000205F7 # "&\a\xF0\xB0\x00\x0F\x00\x02\x00\x00\x00\x00\x00\x00\x05\xF7" 06

[Anima] ACME integrations with BRSKI and the cmcRA EKU

2020-12-04 Thread Michael Richardson
ACME. ofriel> Seems like mixing two sort of orthogonal things - subdomains and cmcRA.. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature

Re: [Anima] ANIMA when there is a system-wide issue

2020-11-30 Thread Michael Richardson
know what we could write into the specification to make this happen. It seems that we really just need smart implementers. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: P

Re: [Anima] WARREN: PLS reply: another fix to BRSKI in RFC editor queue.

2020-11-10 Thread Michael Richardson
tting them know > that we are doing something unusual... Yes. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide signature.asc Description: PGP signature ___ Anima mailing list An

Re: [Anima] Michael: IANA request for GRASP registry missing from BRSKI text

2020-11-06 Thread Michael Richardson
On Fri, Nov 06, 2020 at 04:15:21PM -0500, Michael Richardson wrote: >> >> Toerless Eckert wrote: >> > Am i completeley confused, or did we miss until now the IANA request in BRSKI for >> > the new entries AN_Proxy and AN_join_registrar ? >>

Re: [Anima] Michael: IANA request for GRASP registry missing from BRSKI text

2020-11-06 Thread Michael Richardson
wg-chair). -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

Re: [Anima] Michael: IANA request for GRASP registry missing from BRSKI text

2020-11-06 Thread Michael Richardson
rcontent.com/anima-wg/anima-bootstrap/master/dtbootstrap-anima-keyinfra.txt -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/ | rub

<    1   2   3   4   5   6   7   8   9   10   >