
From nobody Mon Oct 17 09:44:32 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2566B1298A3 for <6tisch-security@ietfa.amsl.com>; Mon, 17 Oct 2016 09:44:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qjo2CI1WDFYQ for <6tisch-security@ietfa.amsl.com>; Mon, 17 Oct 2016 09:44:28 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32000129972 for <6tisch-security@ietf.org>; Mon, 17 Oct 2016 09:44:26 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id B0DBE2009E for <6tisch-security@ietf.org>; Mon, 17 Oct 2016 12:58:56 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 774E463AFE for <6tisch-security@ietf.org>; Mon, 17 Oct 2016 12:44:24 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Mon, 17 Oct 2016 12:44:24 -0400
Message-ID: <15752.1476722664@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/QI671AgUjY2t4nMKSWc7SPn5PjA>
Subject: [6tisch-security] DRAFT minutes for 2016-09-27 and 2016-10-11 meetings
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Oct 2016 16:44:31 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Reminder next meeting is October 25.

These minutes cover the meetings:
      2016-09-27
      2016-10-11

Note we started trying to use JITSI, but changed to Webex on the 27th.
For meeting reservation information, see:
    https://www.ietf.org/mail-archive/web/6tisch-security/current/msg00603.=
html

Summary of attendance by meeting.
    2016-09-13: mcr, Pascal, Goran, Malisa, Nancy, Thomas, Tero.
    2016-09-27: mcr, Thomas, Mali=C5=A1a, Pascal, Nancy, Tero
    2016-10-11: mcr, Tero, Pascal, Mali=C5=A1a.


To recall, the 2016-09-13 meeting consisted of recap of many activities over
the summer.  I will reply to this email with a summary of activities.

The 2016-09-27 meeting had as agenda:

Agenda for this week:
0) note well.
1) approval of agenda
2) minutes from last week.
   Approved.
3) work to do during meeting:
   time sequence diagram for document
      draft-richardson-6tisch-dtsecurity-secure-join
4) possibility to use GRASP from Join Assistant to JCE, since DAR/DAC is off
   the table.


Our discussion started with how the Pledge gets synchronized to the network,
and whether it needs a Router Advertisement, or if the L2 and L3 address
of the nearest router/join-assistant can be inferrred from the beacon itsel=
f.


PLEDGE(JN)                     JOIN ASSISTANT(JA)                JCE
           <-------- BEACON-L2-----
    hears beacon,
    determines slot offset
    of ALOHA time, get ASN
    uses "K1" key for "encryption"


     ---------"HELLO"----------> YYY
     --------- NS w/ARO +??---->  (for Link-Local address)
     <-------- NA answer-------  ZZZ
                                  -------QUERY-------->  does this node bel=
ong?
                                    DAR/DAC?  GRASP?
                                 <-------acceptable node-----

(device stays more awake to listen to answer, which may be some time)
(device already knows when the answer will arrive, so can sleep according to
schedule)

     <--------PLEASE JOIN-----   QQQ
                    NA answer positive/negative
                    new status code, 6775 update.

    Y<--------------------JOIN PROCESS------------------------>X
    <-- DTLS/EDHOC KMP packets--<PROXY<-----------------------

    <-----/6p over CoAP -------PROXY<---IPIP-/6top-over-CoAP---
    ------------_REPLY_--------------------------------------->


Q: can JN infer link-local address of JA from beacon?  avoiding multicast of
   RS... the NA(line YYY) is there for the JN to announce itself.

Pascal: normally the device multicasts RS, and JA will reply with RA
        (unicast), which establishes LL address of router.

        The beacon is broadcast,  but other options could be included....  =
in
        802.11 there is a task group to expose services in the beacon.

what would we put into the beacon:

    mcr: do we need to have an RA?
    Could the beacon say, "I support IPv6, here is my IPv6 LL address and my
              L2 address", can not be implicit in beacon?  But, some kind of
              RA needs to exist.

    do we have room in the beacon?   How big is a compressed RA?

   Could we put data in the beacon in addition to the IE?

   In a beacon, there is some space for data, but what is in it is not
   defined.

   Yes, can we do it? Does anyone process it, pass it to upper layers?
   Better to add IE?  Could we use the new IETF IE type to put a compressed
   beacon into this IE?
   Tero: it would make perfect sense to put some stuff there.


The 2016-10-11 meeting continued to the topic of RA in IE.

Agenda for this week:
     0) note well
     1) minutes from last time not yet posted; sorry.
     2) recap of time sequence diagram.


    PLEDGE(JN)       JOIN ASSISTANT(JA)        JCE
        <--------------- BEACON-L2                   (1)
        <-------RA ------                            (1B)
        ---- LL NS w/ARO --->                        (2)
                               ------- QUERY---->    (3)
                               <------ REPLY-----    (4)
        <--- LL NA answer----                        (5)
                    some time later
        <-----coaps--------<=3D=3D=3D=3D=3D=3D=3DIPIP-COAPS=3D=3D=3D=3D    =
(6)
                    multiple trips
        ------------------->=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D>    (7)


We noted if RA is contained in Beacon, then it will be visible to all hosts,
both those joined, and those attempting to join, so we must be conservative
and privacy limiting in what we chose to multicast.

Slots in which one can multicast do not occur that often, so sending more
data during this important slot is valuable.

We would send as little as possible in the Beacon-RA, because it needs to
remain as small as possible.

PLAN: Create new IE with minimal RA-equivalent (compressed RA).
      Compressed RA would announce that it is a JA.
      Do not include PIO in RA, but suggest hosts send unicast RS to
      get that information, and unicast are easier to secure.

Could also have hint about network identity (this also helps hosts rejoin
   after a interuption in connectivity).
   [network identity could be DODAGID, or EUI-64 of MESH ROOT?]

We discussed the question as to whether or not all routers were also
Join Assistants, with some dispute as to the cost of that function.
We did however conclude that:

a) Every JA must be a router.
b) A JA may do things a router does not.
c) Every router must be a (802.15.4)  coordinator, and sends beacons.
d) Every beacon must contain a compressed RA in an IE, for the benefit of
   leaf-nodes (hosts!): hosts need to know L3 address of router to send NS,=
 RS,
   etc.

Does this get rid of need for step (1B) in time sequence diagram?

**** Do we ever need broadcast RA in 6tisch? ****

Calculation recorded:
            broadcast slots are rare:  10ms slots, slot-frame length=3D100,=
 so
            1 slot/s for beacon (rare).
            But, some people might have slot-frame length=3D5, so not so ra=
re.

Conclusion: "we want to define a minimal-RA that would be contained in an I=
E"

We discussed how long a pledge would have to listen (and on how many
channels) in order to hear a beacon.... 802.15.4 defines a Beacon Request.

Could Pledge send a Beacon Request?  Yes, in normal 15.4, but in TSCH mode,
this is more difficult.

i.e:
        <--------------- BEACON-L2                   (1)
        --- EBR asking RA or RS ->
        <-------RA ------                            (1B)

(and this is three uses of the shared slot!)

Are we creating an IE to encapsulate an IPv6 packet, or an
    compressed(JA-src.IID)+6loRH(ICMPv6 header+options)?

How big is minimal Beacon anyway?  about 50 bytes (used).

Malisa has complementary draft: which is... XXXX?






=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWAT/5YCLcPvd0N1lAQLoZAf+N3Wy3Aee0l4bB958DV8gEV36mc6YrD8u
bq0Ao9DofxCeOdKobR/gfAkKe65CRloAclb7PHyIaFmbHK651Kyp3C2ZZU8aKijI
Uts+timHpN6MD0fyaocIl8+MQ6OqhK6ZEufV6BtWnxGQhibalX4nimTxHJkLVjz9
oBqizemXHfAQuddUXFfuyEWorCB2YgIiaQwd09gd2YuJt5UjsIJmnrHTTjUq4nXl
8p81sXKlDWekpSJPV13SYlfdelWQXm7Zyhwnv4qoKD6TeGpkRCT6M2ufbpGxp41c
NQzlIIXcoU2ZTW7utwywWrEQn0ZunwjgbnnKM1cSDRYUOYLtbQ+DpA==
=dEbi
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Oct 18 06:27:24 2016
Return-Path: <kivinen@iki.fi>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C29AB12964D for <6tisch-security@ietfa.amsl.com>; Tue, 18 Oct 2016 06:27:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.121
X-Spam-Level: 
X-Spam-Status: No, score=-1.121 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NEUTRAL=0.779] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hHEHa0n9Gqvq for <6tisch-security@ietfa.amsl.com>; Tue, 18 Oct 2016 06:27:22 -0700 (PDT)
Received: from mail.kivinen.iki.fi (fireball.acr.fi [83.145.195.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E13D4129A64 for <6tisch-security@ietf.org>; Tue, 18 Oct 2016 06:27:20 -0700 (PDT)
Received: from fireball.acr.fi (localhost [127.0.0.1]) by mail.kivinen.iki.fi (8.15.2/8.15.2) with ESMTPS id u9IDRIIJ016458 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 18 Oct 2016 16:27:18 +0300 (EEST)
Received: (from kivinen@localhost) by fireball.acr.fi (8.15.2/8.14.8/Submit) id u9IDRIp5023284; Tue, 18 Oct 2016 16:27:18 +0300 (EEST)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <22534.9014.129740.952094@fireball.acr.fi>
Date: Tue, 18 Oct 2016 16:27:18 +0300
From: Tero Kivinen <kivinen@iki.fi>
To: Michael Richardson <mcr+ietf@sandelman.ca>
In-Reply-To: <15752.1476722664@obiwan.sandelman.ca>
References: <15752.1476722664@obiwan.sandelman.ca>
X-Mailer: VM 8.2.0b under 24.5.1 (x86_64--netbsd)
X-Edit-Time: 1 min
X-Total-Time: 1 min
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/HKMklbppb5UACFOq15ko-R1EV0o>
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: [6tisch-security] DRAFT minutes for 2016-09-27 and 2016-10-11 meetings
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2016 13:27:23 -0000

Michael Richardson writes:
> Reminder next meeting is October 25.

Earlier there was email from Thomas:

> From: Thomas Watteyne <thomas.watteyne@inria.fr>
> To: Michael Richardson <mcr+ietf@sandelman.ca>
> Cc: tisch-security <6tisch-security@ietf.org>
> Subject: Re: [6tisch-security] IETF.webex.com for next two meetings
> Date: Wed, 28 Sep 2016 11:07:00 +0200
> 
> I assume that's Oct 11 and Oct 18?

so do we have call today or not?
-- 
kivinen@iki.fi


From nobody Tue Oct 18 07:53:44 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0530312965E for <6tisch-security@ietfa.amsl.com>; Tue, 18 Oct 2016 07:53:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DMQYIYEu4s1M for <6tisch-security@ietfa.amsl.com>; Tue, 18 Oct 2016 07:53:30 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86AE21294A7 for <6tisch-security@ietf.org>; Tue, 18 Oct 2016 07:53:30 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id C99BC203B1; Tue, 18 Oct 2016 11:08:04 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 6714863AFE; Tue, 18 Oct 2016 10:53:29 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Tero Kivinen <kivinen@iki.fi>
In-Reply-To: <22534.9014.129740.952094@fireball.acr.fi>
References: <15752.1476722664@obiwan.sandelman.ca> <22534.9014.129740.952094@fireball.acr.fi>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 18 Oct 2016 10:53:29 -0400
Message-ID: <26581.1476802409@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/SU44Pp9BDO5i7w4X6wCbopD-CLE>
Cc: 6tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] DRAFT minutes for 2016-09-27 and 2016-10-11 meetings
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2016 14:53:43 -0000

--=-=-=
Content-Type: text/plain


Tero Kivinen <kivinen@iki.fi> wrote:
    > Michael Richardson writes:
    >> Reminder next meeting is October 25.

    > Earlier there was email from Thomas:

    >> From: Thomas Watteyne <thomas.watteyne@inria.fr> To: Michael
    >> Richardson <mcr+ietf@sandelman.ca> Cc: tisch-security
    >> <6tisch-security@ietf.org> Subject: Re: [6tisch-security]
    >> IETF.webex.com for next two meetings Date: Wed, 28 Sep 2016 11:07:00
    >> +0200
    >>
    >> I assume that's Oct 11 and Oct 18?

No... every two weeks, and we had one last week, right.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWAY3ZoCLcPvd0N1lAQJfZwf+IcnNM7KZ18naASeJiZF6k3l5KN1SQEz3
hA32UPOafwXWrtCsQffp7/cSJgjzpxsdBt2JLibcFJ3dTzjZO5KO2lxlb0n4AfAq
pjIG1Tr8V9NAee0uHdukpkBTK8tfrsHI5jt26mHvBaLWZs8qaBzAJqV5Lwobh9gc
Rh8ydCys1ghnOF7Gx3dRSFc8gQ2AVzCGyuYvMYSPPaSN4RvNicMR+iXEtwgjcALT
PIdrWOP3PK1D1uIJd0rLGtQYdEUfLMa1OKywByAo3InTwAkx0RPFz+tSwsHEDwUy
10SOwI0Cc5AuOzgfQTPfwTi4Hp9QqcjFbcStqzuJynGzA3McfvpP7Q==
=SdaX
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Oct 18 09:13:11 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F28EE1296BC; Tue, 18 Oct 2016 09:13:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1Yokp7hJ2Dxk; Tue, 18 Oct 2016 09:13:08 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 197371296D2; Tue, 18 Oct 2016 09:13:08 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 5FCF52009E; Tue, 18 Oct 2016 12:27:42 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id C4D5563AFE; Tue, 18 Oct 2016 12:13:06 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch@ietf.org, 6lo@ietf.org
In-Reply-To: <147680041580.30853.17692159482786173917.idtracker@ietfa.amsl.com>
References: <147680041580.30853.17692159482786173917.idtracker@ietfa.amsl.com>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 18 Oct 2016 12:13:06 -0400
Message-ID: <12199.1476807186@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/nY1e4yOajf0PLkAE4iNzjTfm7II>
Cc: 6tisch-security@ietf.org
Subject: [6tisch-security] transporting Router Advertisements in Extended Beacons: draft-richardson-6lo-ra-in-ie
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: 6tisch@ietf.org, 6lo@ietf.org
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2016 16:13:10 -0000

--=-=-=
Content-Type: text/plain


Hi, as detailed in the design team minutes at:
   https://mailarchive.ietf.org/arch/msg/6tisch-security/QI671AgUjY2t4nMKSWc7SPn5PjA

The design team has come to realize that there would be significant time and
energy savings if we could embed an IPv6 Router Advertisement into the
802.15.4 TSCH Enhanced Beacon used by 6tisch to synchronize timing, and
announce the schedule.

I did an initial draft at:
  https://datatracker.ietf.org/doc/draft-richardson-6lo-ra-in-ie/

at the cost of 1-2 bytes, it just uses 6282/6loRH compression to store any
IPv6 packet, but we may want to lock this down more.  The total content is
56 bytes, which just barely fits into a Beacon. (uncompressed it is 80 bytes,
which will not fit)

This is very very much -00!!!  Comments and co-authors welcome, github at:
     https://github.com/ietf-roll/6lo-ra-in-ie

Much more "why" text is needed, and how to use the components is needed.
I don't know if this should be a 6lo or 6tisch work effort; I leave it to the
chairs to think about this.

Unless I mis-read 6282, it provides no compression of ICMPv6 headers,
nor does 6loRH do so at present.  I know that Pascal had talked about coming
back in 6loRH v2, using the new code page space, to compressing RPL (which is
ICMPv6).

I went slightly further afield in this document, and defined a new Router
Advertisement option that I called:
              "Constrained Network Identification"

This will contain a copy of the 16-byte DODAGID so that a very sleepy node
returning to operation would be able to identify which beacon belongs to
which network.  A joining node will have no idea which DODAGID it
wants, and a maliciously sent beacon could have any manner is superfuge here.
Nodes which have already joined the network SHOULD be able to authenticate
the beacons.  However, this is one of the larger objects in the 56 bytes that
I describe, and maybe it is excessive to store so many bytes here.

It could be that the SLLA option (and EUI-64 contained within) is also
unnecessary.

I want to attempt to apply RFC7400 (GHC) to this, the savings will be
probably on the order of ten bytes of zeroes.


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWAZKD4CLcPvd0N1lAQIvQQf+MNzMwrv6EE79p2yTJOL2JyLLkwTmg5Vu
gx9J1cN2FiX1XktOZNB18igU+x+sSmWzO5Cl0OS5p1SVKEPLCZJxsXB1U5h/v63T
FylMlnk3iL2pGO92DUI+mTCmRyB9r+GaQMmQphFbG6+EjDRqupRywqUNikbD2C04
Sa0c+EOIU3Ww64YPzwxIEl6y9IR1ox9K61TBc4XCGVauSa+jGNCG/e448nNw5ibR
vZMn2I2ipCyNBI09FACGSj720+lD7HUb/gBU4227rjGQDsjkSpkkHBDEAk3+pjmB
XDL2dY800LczuU7Vj7xJCCY9WoF6TeNf+Ug/FGE6ejOtJdh9Xw8bHA==
=UmEI
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Oct 19 06:49:35 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 041A212957A; Wed, 19 Oct 2016 06:49:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SBQ7Gld-xYXb; Wed, 19 Oct 2016 06:49:29 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D5AB21295E3; Wed, 19 Oct 2016 06:49:28 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 081C9203B0; Wed, 19 Oct 2016 10:04:06 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 61F6063AFE; Wed, 19 Oct 2016 09:49:27 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch@ietf.org, 6lo@ietf.org
In-Reply-To: <12199.1476807186@obiwan.sandelman.ca>
References: <147680041580.30853.17692159482786173917.idtracker@ietfa.amsl.com> <12199.1476807186@obiwan.sandelman.ca>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 19 Oct 2016 09:49:27 -0400
Message-ID: <11163.1476884967@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/mr1-BXByBYubR-KQKQQjP5K5zWM>
Cc: 6tisch-security@ietf.org
Subject: Re: [6tisch-security] transporting Router Advertisements in Extended Beacons: draft-richardson-6lo-ra-in-ie
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Oct 2016 13:49:31 -0000

--=-=-=
Content-Type: text/plain


to reply to myself

Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > This will contain a copy of the 16-byte DODAGID so that a very sleepy
    > node returning to operation would be able to identify which beacon
    > belongs to which network.  A joining node will have no idea which
    > DODAGID it wants, and a maliciously sent beacon could have any manner
    > is superfuge here.  Nodes which have already joined the network SHOULD
    > be able to authenticate the beacons.  However, this is one of the
    > larger objects in the 56 bytes that I describe, and maybe it is
    > excessive to store so many bytes here.

I realized today that the RA probably also needs to carry the ABRO to be
useful to secured hosts.  Such hosts will still have to unicast as RS to get
the PIO from a router.  I'm sure that we don't want to put the PIO into an
unencrypted EB/RA.

The ARBO has the 6LBR address which is often, but not always the same as the
DODAGID.   It can equally well be used to identify the network.

    > I want to attempt to apply RFC7400 (GHC) to this, the savings will be
    > probably on the order of ten bytes of zeroes.

So far, the savings I got with GHC was 4 bytes.  I posted an update to the
git repo.  (     https://github.com/ietf-roll/6lo-ra-in-ie )


--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWAd55ICLcPvd0N1lAQKGrQf/TPhhfHyJCcUFRmhq65i2Hi5r2Y0hjwek
dhisrSeC+H9QrSitcAF6p7YUR+stZHZuApdcEqZduOetmTvEFuAHrFv8Y+H6NAPc
EdMdHM/ZGI/unCtdFpyYygP/4tm4/wjVBxliGUkT8D12sH0JSzPI6h6AQob1yDcn
zmRpOJGBWK7agBlCQx0wkeCj8A9TWfUxKbUCw07obHiK/0LzGF14Nz/IXH9b34Ob
yxV3zqXMksLwCk4NOxB2s/PLErZTA66nX8+xeSHZbQpOIHHpOiPgp/9dxDk0GFTO
PSBmTbnw7p72CJwV/R8vGJXQ/TlM6fLnHTJSHGyxVtguSXxlMvjrgw==
=XfNA
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu Oct 20 06:51:18 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8A5C12996A; Thu, 20 Oct 2016 06:51:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q7k7Xp5S_geW; Thu, 20 Oct 2016 06:51:12 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8A91912996C; Thu, 20 Oct 2016 06:51:12 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 5D93C20553; Thu, 20 Oct 2016 10:05:53 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 4A8A5639BA; Thu, 20 Oct 2016 09:51:11 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Thu, 20 Oct 2016 09:51:11 -0400
Message-ID: <20351.1476971471@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/sJfQx3njyutx1v1bTrIvLzAm5nc>
Cc: anima-bootstrap <anima-bootstrap@ietf.org>
Subject: [6tisch-security] 6tisch join -01 documented posted
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Oct 2016 13:51:16 -0000

--=-=-=
Content-Type: text/plain


https://tools.ietf.org/html/draft-richardson-6tisch-dtsecurity-secure-join-01

This has a far more extensive section 2 -- Protocol Description.
Aside from many many details that need to be made more precise, there are
quite a number of major things missing:
  1) reference to draft-ietf-netconf-system-keychain-00, mapped to CBOR,
     along with some additions.
  2) EDHOC/DTLS considerations
  3) reference to ANIMA onwership voucher
  4) references to ANIMA Bootstrap certificate stuff.

In the process of creating this document, I created two other documents.
a) https://datatracker.ietf.org/doc/draft-richardson-6lo-ra-in-ie/
   This describes putting Router Advertisements in 802.15.4 Information Elements.
   Your comments in 6lo and 6tisch ML would be appreciated, and some
   discussion as to if and where this document goes.

b) https://datatracker.ietf.org/doc/draft-richardson-anima-6join-discovery/
   I wrote this document to reference from secure-join to explain the GRASP
   query that the Join Assistant will do to inform the Registrar about a new
   pledge.

   I think that this document goes into draft-ietf-anima-bootstrapping-keyinfra.

   Based upon some feedback on the anima list about how M_NEGOTIATE works,
   there are some major things wrong in this document when it comes to how an
   ANIMA Join Assistant would discover the *EST* port of the Registrar.



--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWAjLzICLcPvd0N1lAQLMFQgAgW1QuD56ZLkFgNdtTIQzDfoFFkgwCepZ
IATEMVAvQg+l/UaRmkNYLpsr88bRZKyHZ9X/0ktRbQ7U2h/73GkhF47SSbaiXqju
HjqgdxXSae2o9xhrKtJQhDimhWJ6iRuAusC6Gnt6L67YQ40YwUOPYRJDPzesbu/x
eEuAIfKwvgb3wC1BP09+DMUjqKOoTC3JWv2Qy3iHTOhy7Uo+dxcjJdKeLTWnE2t6
eQw92c7d7PrFJ2ZvhoDRPMqDcDQ+L0IVF2mOMfUQNCCR1IHETPJH7r9LU83dcotR
19TCrBxi4GiuOOVpTdc4FHIDC2UU7L/XMoW+GJ6WssTchwktwLQRrQ==
=3GpK
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Thu Oct 20 12:38:55 2016
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CFF79129491; Thu, 20 Oct 2016 12:38:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q5TFwSU29nHt; Thu, 20 Oct 2016 12:38:50 -0700 (PDT)
Received: from mail-pf0-x232.google.com (mail-pf0-x232.google.com [IPv6:2607:f8b0:400e:c00::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C36E21296B1; Thu, 20 Oct 2016 12:38:50 -0700 (PDT)
Received: by mail-pf0-x232.google.com with SMTP id s8so42269687pfj.2; Thu, 20 Oct 2016 12:38:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=subject:to:references:cc:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=WtyrhgYboZefnhMzi7Yc3APy5wxDV5e1TnSQKD09aeU=; b=gInxpAOe+9Fh1T/bod4TFuaJtdotMiw1WqGVze7QaI27wwwwlW9ELyMBmbw419igJ4 6JGG4vQjI9aeHrl+1yqys7M+VKjgS8rHuRPLw80/QPmMUrwqINlHe10Ltef2V5zxlUMK ejzmEbpNUrYPejIZa+3VXK2B+OFjVblf8ezcKuMI+LLmFYZYHVdlC/8T0OlAvh0EF88Z Zusue8bg+Z7ItXMkT9WlsyyCxYLuEwMUU2tuzlIH7uFZCLkH77ME4sYxkmxRUMYCGp1l YvLt4optVuEnjUjXUtA5d9u69bIumdZnkbwlVQA3zp3VSis4TgUIHNFvmGwLpEcL1WEf gY8Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-transfer-encoding; bh=WtyrhgYboZefnhMzi7Yc3APy5wxDV5e1TnSQKD09aeU=; b=Lf255utWd/+X0xHBmzvA2XIOshVUKwVPSvGlRbFcmKzUFfEjvhtIwAx1IqAdVJH9Ov kwHWvYiX06gA+O8az8YJye+RKvqBVtDBhf4FNOUzaDZ7B3jAGzn5vkeo+dwEq5u8riR3 dKd5/sKNlNbLTRYjEoYI8+Z8i4vQwK8Hs3NQR2FCTka1ljabKSisGy/O5JN1eX25FZ9z asGp5jjJi/NUDeLoMMSDKGTtsFoYXysZdyS7APbQMzl78Qe25DGGgjaWd2p1yKoOsM3C BjeCOjnIfRm5Ln2bZcVskpYKSwnOwNlWhCMIhz3LR+8Au4AWJKtMX0RllEZFkDwA5Md6 XL1g==
X-Gm-Message-State: AA6/9Rm4bSjDezG5eOzSZ4i823ZnrNafx8+AEAUpDidhgvXCCjQjwLtWbGF2oQPcd86j5A==
X-Received: by 10.98.216.194 with SMTP id e185mr4227291pfg.148.1476992330154;  Thu, 20 Oct 2016 12:38:50 -0700 (PDT)
Received: from [192.168.178.23] (214.218.69.111.dynamic.snap.net.nz. [111.69.218.214]) by smtp.gmail.com with ESMTPSA id y125sm73594570pfg.61.2016.10.20.12.38.47 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 20 Oct 2016 12:38:49 -0700 (PDT)
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security <6tisch-security@ietf.org>
References: <20351.1476971471@obiwan.sandelman.ca>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <0343d14c-5b18-b821-c9ad-d77fb7dae490@gmail.com>
Date: Fri, 21 Oct 2016 08:38:54 +1300
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0
MIME-Version: 1.0
In-Reply-To: <20351.1476971471@obiwan.sandelman.ca>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/2LI3sXlqHzU93DWBA5nMVu_4vFo>
Cc: anima-bootstrap <anima-bootstrap@ietf.org>
Subject: Re: [6tisch-security] [Anima-bootstrap] 6tisch join -01 documented posted
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Oct 2016 19:38:53 -0000

On 21/10/2016 02:51, Michael Richardson wrote:
...
> b) https://datatracker.ietf.org/doc/draft-richardson-anima-6join-discovery/
>    I wrote this document to reference from secure-join to explain the GRASP
>    query that the Join Assistant will do to inform the Registrar about a new
>    pledge.
> 
>    I think that this document goes into draft-ietf-anima-bootstrapping-keyinfra.
> 
>    Based upon some feedback on the anima list about how M_NEGOTIATE works,
>    there are some major things wrong in this document when it comes to how an
>    ANIMA Join Assistant would discover the *EST* port of the Registrar.

TL;DR;WRL (will read later)

I think you could look at my BRSKI toys (in Python) without needing to look at
my actual GRASP code. They express my understanding of the options.

https://www.cs.auckland.ac.nz/~brian/graspy/brski/
start with the README

Regards
   Brian


From nobody Mon Oct 24 15:44:43 2016
Return-Path: <thomas.watteyne@inria.fr>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B459129ADD; Mon, 24 Oct 2016 15:44:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.33
X-Spam-Level: 
X-Spam-Status: No, score=-7.33 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.431] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yVwHM-qCcPY0; Mon, 24 Oct 2016 15:44:39 -0700 (PDT)
Received: from mail2-relais-roc.national.inria.fr (mail2-relais-roc.national.inria.fr [192.134.164.83]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 782AC129ACF; Mon, 24 Oct 2016 15:44:38 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.31,543,1473112800";  d="scan'208,217";a="242167228"
Received: from mail-wm0-f46.google.com ([74.125.82.46]) by mail2-relais-roc.national.inria.fr with ESMTP/TLS/AES128-GCM-SHA256; 25 Oct 2016 00:44:36 +0200
Received: by mail-wm0-f46.google.com with SMTP id d199so14038586wmd.0; Mon, 24 Oct 2016 15:44:37 -0700 (PDT)
X-Gm-Message-State: ABUngvc2grMmHRALBh1xfyf9C7yNGmYjKYhGpxy7f3S3ptuA1INfqj6BFKRbF0WlWrTsEs0E1JG5cRLuv3o14g==
X-Received: by 10.194.78.195 with SMTP id d3mr99384wjx.96.1477349076882; Mon, 24 Oct 2016 15:44:36 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.80.179.19 with HTTP; Mon, 24 Oct 2016 15:44:16 -0700 (PDT)
In-Reply-To: <11163.1476884967@obiwan.sandelman.ca>
References: <147680041580.30853.17692159482786173917.idtracker@ietfa.amsl.com> <12199.1476807186@obiwan.sandelman.ca> <11163.1476884967@obiwan.sandelman.ca>
From: Thomas Watteyne <thomas.watteyne@inria.fr>
Date: Tue, 25 Oct 2016 00:44:16 +0200
X-Gmail-Original-Message-ID: <CADJ9OA8AVTSDvtAg+WqEHcrfi5aGCXR2OGouZuu+W+GQQi3ymA@mail.gmail.com>
Message-ID: <CADJ9OA8AVTSDvtAg+WqEHcrfi5aGCXR2OGouZuu+W+GQQi3ymA@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Content-Type: multipart/alternative; boundary=047d7bfd0010efe04c053fa422c1
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/EYcV4dwYBebSTL6R5n-Et0oiR2s>
Cc: "6tisch@ietf.org" <6tisch@ietf.org>, "6tisch-security@ietf.org" <6tisch-security@ietf.org>, "6lo@ietf.org" <6lo@ietf.org>
Subject: Re: [6tisch-security] [6tisch] transporting Router Advertisements in Extended Beacons: draft-richardson-6lo-ra-in-ie
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Oct 2016 22:44:42 -0000

--047d7bfd0010efe04c053fa422c1
Content-Type: text/plain; charset=UTF-8

Michael,

Cool! Some editorial remarks:

OLD
extended beacon
NEW
enhanced beacon

Could the draft be generic enough to allow for RPL DIOs to be carried in an
EB?



On Wed, Oct 19, 2016 at 3:49 PM, Michael Richardson <mcr+ietf@sandelman.ca>
wrote:

>
> to reply to myself
>
> Michael Richardson <mcr+ietf@sandelman.ca> wrote:
>     > This will contain a copy of the 16-byte DODAGID so that a very sleepy
>     > node returning to operation would be able to identify which beacon
>     > belongs to which network.  A joining node will have no idea which
>     > DODAGID it wants, and a maliciously sent beacon could have any manner
>     > is superfuge here.  Nodes which have already joined the network
> SHOULD
>     > be able to authenticate the beacons.  However, this is one of the
>     > larger objects in the 56 bytes that I describe, and maybe it is
>     > excessive to store so many bytes here.
>
> I realized today that the RA probably also needs to carry the ABRO to be
> useful to secured hosts.  Such hosts will still have to unicast as RS to
> get
> the PIO from a router.  I'm sure that we don't want to put the PIO into an
> unencrypted EB/RA.
>
> The ARBO has the 6LBR address which is often, but not always the same as
> the
> DODAGID.   It can equally well be used to identify the network.
>
>     > I want to attempt to apply RFC7400 (GHC) to this, the savings will be
>     > probably on the order of ten bytes of zeroes.
>
> So far, the savings I got with GHC was 4 bytes.  I posted an update to the
> git repo.  (     https://github.com/ietf-roll/6lo-ra-in-ie )
>
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting =-
>
>
>
>
> _______________________________________________
> 6tisch mailing list
> 6tisch@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch
>
>


-- 
_______________________________________

Thomas Watteyne, PhD
Research Scientist & Innovator, Inria
Sr Networking Design Eng, Linear Tech
Founder & co-lead, UC Berkeley OpenWSN
Co-chair, IETF 6TiSCH

www.thomaswatteyne.com
_______________________________________

--047d7bfd0010efe04c053fa422c1
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Michael,<div><br></div><div>Cool! Some editorial remarks:<=
/div><div><br></div><div>OLD</div><div>extended beacon</div><div>NEW</div><=
div>enhanced beacon</div><div><br></div><div>Could the draft be generic eno=
ugh to allow for RPL DIOs to be carried in an EB?</div><div><br></div><div>=
<br></div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">O=
n Wed, Oct 19, 2016 at 3:49 PM, Michael Richardson <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:mcr+ietf@sandelman.ca" target=3D"_blank">mcr+ietf@sandelman=
.ca</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
to reply to myself<br>
<span class=3D""><br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2Bietf@sandelman.ca">mcr+ietf@=
sandelman.ca</a>&gt; wrote:<br>
=C2=A0 =C2=A0 &gt; This will contain a copy of the 16-byte DODAGID so that =
a very sleepy<br>
=C2=A0 =C2=A0 &gt; node returning to operation would be able to identify wh=
ich beacon<br>
=C2=A0 =C2=A0 &gt; belongs to which network.=C2=A0 A joining node will have=
 no idea which<br>
=C2=A0 =C2=A0 &gt; DODAGID it wants, and a maliciously sent beacon could ha=
ve any manner<br>
=C2=A0 =C2=A0 &gt; is superfuge here.=C2=A0 Nodes which have already joined=
 the network SHOULD<br>
=C2=A0 =C2=A0 &gt; be able to authenticate the beacons.=C2=A0 However, this=
 is one of the<br>
=C2=A0 =C2=A0 &gt; larger objects in the 56 bytes that I describe, and mayb=
e it is<br>
=C2=A0 =C2=A0 &gt; excessive to store so many bytes here.<br>
<br>
</span>I realized today that the RA probably also needs to carry the ABRO t=
o be<br>
useful to secured hosts.=C2=A0 Such hosts will still have to unicast as RS =
to get<br>
the PIO from a router.=C2=A0 I&#39;m sure that we don&#39;t want to put the=
 PIO into an<br>
unencrypted EB/RA.<br>
<br>
The ARBO has the 6LBR address which is often, but not always the same as th=
e<br>
DODAGID.=C2=A0 =C2=A0It can equally well be used to identify the network.<b=
r>
<span class=3D""><br>
=C2=A0 =C2=A0 &gt; I want to attempt to apply RFC7400 (GHC) to this, the sa=
vings will be<br>
=C2=A0 =C2=A0 &gt; probably on the order of ten bytes of zeroes.<br>
<br>
</span>So far, the savings I got with GHC was 4 bytes.=C2=A0 I posted an up=
date to the<br>
git repo.=C2=A0 (=C2=A0 =C2=A0 =C2=A0<a href=3D"https://github.com/ietf-rol=
l/6lo-ra-in-ie" rel=3D"noreferrer" target=3D"_blank">https://github.com/iet=
f-roll/<wbr>6lo-ra-in-ie</a> )<br>
<div class=3D"HOEnZb"><div class=3D"h5"><br>
<br>
--<br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2BIETF@sandelman.ca">mcr+IETF@=
sandelman.ca</a>&gt;, Sandelman Software Works<br>
=C2=A0-=3D IPv6 IoT consulting =3D-<br>
<br>
<br>
<br>
</div></div><br>______________________________<wbr>_________________<br>
6tisch mailing list<br>
<a href=3D"mailto:6tisch@ietf.org">6tisch@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/6tisch" rel=3D"noreferrer"=
 target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/6tisch</a><br=
>
<br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br><div cla=
ss=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D"ltr">=
<div><div dir=3D"ltr"><div style=3D"font-size:small"><font face=3D"monospac=
e, monospace">_______________________________________</font></div><div styl=
e=3D"font-size:small"><font face=3D"monospace, monospace"><br></font></div>=
<div style=3D"font-size:small"><font face=3D"monospace, monospace">Thomas W=
atteyne, PhD</font></div><div style=3D"font-size:small"><font face=3D"monos=
pace, monospace">Research Scientist &amp; Innovator, Inria</font></div><div=
 style=3D"font-size:small"><font face=3D"monospace, monospace">Sr Networkin=
g Design Eng, Linear Tech</font></div><div style=3D"font-size:small"><font =
face=3D"monospace, monospace">Founder &amp; co-lead, UC Berkeley OpenWSN</f=
ont></div><div style=3D"font-size:small"><font face=3D"monospace, monospace=
">Co-chair, IETF 6TiSCH</font></div><div style=3D"font-size:small"><font fa=
ce=3D"monospace, monospace"><br></font></div><div style=3D"font-size:small"=
><font face=3D"monospace, monospace"><a href=3D"http://www.thomaswatteyne.c=
om" target=3D"_blank">www.thomaswatteyne.com</a></font></div><div style=3D"=
font-size:small"><font face=3D"monospace, monospace">______________________=
_________________</font></div></div></div></div></div>
</div>

--047d7bfd0010efe04c053fa422c1--


From nobody Tue Oct 25 04:18:36 2016
Return-Path: <malisa.vucinic@inria.fr>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 617A612961C for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 04:18:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.33
X-Spam-Level: 
X-Spam-Status: No, score=-7.33 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.431] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RBOHZGyg6SR9 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 04:18:30 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8381129622 for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 04:18:16 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.31,545,1473112800";  d="scan'208,217";a="198091224"
Received: from unknown (HELO [128.93.85.112]) ([128.93.85.112]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-SHA; 25 Oct 2016 13:18:15 +0200
From: =?utf-8?Q?Mali=C5=A1a_Vu=C4=8Dini=C4=87?= <malisa.vucinic@inria.fr>
Content-Type: multipart/alternative; boundary="Apple-Mail=_72F54BA5-1F49-4E73-9164-F6FBB18F47C3"
Date: Tue, 25 Oct 2016 13:18:15 +0200
References: <147738827207.15142.9664067180872740444.idtracker@ietfa.amsl.com>
To: tisch-security <6tisch-security@ietf.org>
Message-Id: <EBBDD80D-5CDB-4487-AA53-1912F30C9EAB@inria.fr>
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
X-Mailer: Apple Mail (2.3124)
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/dehgRFQfwI7cI-0buS-an0qvB_w>
Subject: [6tisch-security] Fwd: New Version Notification for draft-vucinic-6tisch-minimal-security-00.txt
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 11:18:35 -0000

--Apple-Mail=_72F54BA5-1F49-4E73-9164-F6FBB18F47C3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Dear all,

We have submitted a new draft on the join process in 6TiSCH. The draft =
is quite efficient when it comes to PSKs and requires a single round =
trip for the authenticated key transport from JCE to JN. We use OSCOAP =
for protection of CoAP messages end-to-end (through the proxy) and EDHOC =
for the security handshake when using public keys for joining.=20

It would be great if we could discuss some of the related aspects at the =
meeting this afternoon.

Regards,
Mali=C5=A1a

> Begin forwarded message:
>=20
> From: internet-drafts@ietf.org
> Subject: New Version Notification for =
draft-vucinic-6tisch-minimal-security-00.txt
> Date: 25 October 2016 at 11:37:52 GMT+2
> To: "Kris Pister" <kpister@eecs.berkeley.edu>, "Malisa Vucinic" =
<malisa.vucinic@inria.fr>, " malisa.vucinic@st.com" =
<malisa.vucinic@inria.fr>, "Jonathan Simon" <jsimon@linear.com>
>=20
>=20
> A new version of I-D, draft-vucinic-6tisch-minimal-security-00.txt
> has been successfully submitted by Malisa Vucinic and posted to the
> IETF repository.
>=20
> Name:		draft-vucinic-6tisch-minimal-security
> Revision:	00
> Title:		Minimal Security Framework for 6TiSCH=20
> Document date:	2016-10-25
> Group:		Individual Submission
> Pages:		17
> URL:            =
https://www.ietf.org/internet-drafts/draft-vucinic-6tisch-minimal-security=
-00.txt
> Status:         =
https://datatracker.ietf.org/doc/draft-vucinic-6tisch-minimal-security/
> Htmlized:       =
https://tools.ietf.org/html/draft-vucinic-6tisch-minimal-security-00
>=20
>=20
> Abstract:
>   This draft describes the minimal mechanisms required to support
>   secure initial configuration in a device being added to a 6TiSCH
>   network.  The goal of this configuration is to set link-layer keys,
>   and to establish a secure session between each joining node and the
>   JCE who may use that to further configure the joining device.
>   Additional security behaviors and mechanisms may be added on top of
>   this minimal framework.
>=20
>=20
>=20
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> The IETF Secretariat
>=20


--Apple-Mail=_72F54BA5-1F49-4E73-9164-F6FBB18F47C3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">Dear all,<div class=3D""><br class=3D""></div><div =
class=3D"">We have submitted a new draft on the join process in 6TiSCH. =
The draft is quite efficient when it comes to PSKs and requires a single =
round trip for the authenticated key transport from JCE to JN. We use =
OSCOAP for protection of CoAP messages end-to-end (through the proxy) =
and EDHOC for the security handshake when using public keys for =
joining.&nbsp;</div><div class=3D""><br class=3D""></div><div =
class=3D"">It would be great if we could discuss some of the related =
aspects at the meeting this afternoon.</div><div class=3D""><br =
class=3D""></div><div class=3D"">Regards,</div><div class=3D"">Mali=C5=A1a=
<br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">Begin forwarded message:</div><br =
class=3D"Apple-interchange-newline"><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span=
 style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">From: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D""><a =
href=3D"mailto:internet-drafts@ietf.org" =
class=3D"">internet-drafts@ietf.org</a><br class=3D""></span></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px;" class=3D""><span style=3D"font-family: =
-webkit-system-font, Helvetica Neue, Helvetica, sans-serif; =
color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">Subject: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D""><b class=3D"">New Version =
Notification for draft-vucinic-6tisch-minimal-security-00.txt</b><br =
class=3D""></span></div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span =
style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">Date: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D"">25 October 2016 at 11:37:52 =
GMT+2<br class=3D""></span></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px;" class=3D""><span=
 style=3D"font-family: -webkit-system-font, Helvetica Neue, Helvetica, =
sans-serif; color:rgba(0, 0, 0, 1.0);" class=3D""><b class=3D"">To: =
</b></span><span style=3D"font-family: -webkit-system-font, Helvetica =
Neue, Helvetica, sans-serif;" class=3D"">"Kris Pister" &lt;<a =
href=3D"mailto:kpister@eecs.berkeley.edu" =
class=3D"">kpister@eecs.berkeley.edu</a>&gt;, "Malisa Vucinic" &lt;<a =
href=3D"mailto:malisa.vucinic@inria.fr" =
class=3D"">malisa.vucinic@inria.fr</a>&gt;, " <a =
href=3D"mailto:malisa.vucinic@st.com" =
class=3D"">malisa.vucinic@st.com</a>" &lt;<a =
href=3D"mailto:malisa.vucinic@inria.fr" =
class=3D"">malisa.vucinic@inria.fr</a>&gt;, "Jonathan Simon" &lt;<a =
href=3D"mailto:jsimon@linear.com" class=3D"">jsimon@linear.com</a>&gt;<br =
class=3D""></span></div><br class=3D""><div class=3D""><div class=3D""><br=
 class=3D"">A new version of I-D, =
draft-vucinic-6tisch-minimal-security-00.txt<br class=3D"">has been =
successfully submitted by Malisa Vucinic and posted to the<br =
class=3D"">IETF repository.<br class=3D""><br class=3D"">Name:<span =
class=3D"Apple-tab-span" style=3D"white-space:pre">	</span><span =
class=3D"Apple-tab-span" style=3D"white-space:pre">	=
</span>draft-vucinic-6tisch-minimal-security<br class=3D"">Revision:<span =
class=3D"Apple-tab-span" style=3D"white-space:pre">	</span>00<br =
class=3D"">Title:<span class=3D"Apple-tab-span" style=3D"white-space:pre">=
	</span><span class=3D"Apple-tab-span" style=3D"white-space:pre">	=
</span>Minimal Security Framework for 6TiSCH <br class=3D"">Document =
date:<span class=3D"Apple-tab-span" style=3D"white-space:pre">	=
</span>2016-10-25<br class=3D"">Group:<span class=3D"Apple-tab-span" =
style=3D"white-space:pre">	</span><span class=3D"Apple-tab-span" =
style=3D"white-space:pre">	</span>Individual Submission<br =
class=3D"">Pages:<span class=3D"Apple-tab-span" style=3D"white-space:pre">=
	</span><span class=3D"Apple-tab-span" style=3D"white-space:pre">	=
</span>17<br class=3D"">URL: =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a =
href=3D"https://www.ietf.org/internet-drafts/draft-vucinic-6tisch-minimal-=
security-00.txt" =
class=3D"">https://www.ietf.org/internet-drafts/draft-vucinic-6tisch-minim=
al-security-00.txt</a><br class=3D"">Status: =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a =
href=3D"https://datatracker.ietf.org/doc/draft-vucinic-6tisch-minimal-secu=
rity/" =
class=3D"">https://datatracker.ietf.org/doc/draft-vucinic-6tisch-minimal-s=
ecurity/</a><br class=3D"">Htmlized: =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a =
href=3D"https://tools.ietf.org/html/draft-vucinic-6tisch-minimal-security-=
00" =
class=3D"">https://tools.ietf.org/html/draft-vucinic-6tisch-minimal-securi=
ty-00</a><br class=3D""><br class=3D""><br class=3D"">Abstract:<br =
class=3D""> &nbsp;&nbsp;This draft describes the minimal mechanisms =
required to support<br class=3D""> &nbsp;&nbsp;secure initial =
configuration in a device being added to a 6TiSCH<br class=3D""> =
&nbsp;&nbsp;network. &nbsp;The goal of this configuration is to set =
link-layer keys,<br class=3D""> &nbsp;&nbsp;and to establish a secure =
session between each joining node and the<br class=3D""> &nbsp;&nbsp;JCE =
who may use that to further configure the joining device.<br class=3D""> =
&nbsp;&nbsp;Additional security behaviors and mechanisms may be added on =
top of<br class=3D""> &nbsp;&nbsp;this minimal framework.<br =
class=3D""><br class=3D""><br class=3D""><br class=3D""><br class=3D""><br=
 class=3D"">Please note that it may take a couple of minutes from the =
time of submission<br class=3D"">until the htmlized version and diff are =
available at <a href=3D"http://tools.ietf.org" =
class=3D"">tools.ietf.org</a>.<br class=3D""><br class=3D"">The IETF =
Secretariat<br class=3D""><br =
class=3D""></div></div></blockquote></div><br =
class=3D""></div></body></html>=

--Apple-Mail=_72F54BA5-1F49-4E73-9164-F6FBB18F47C3--


From nobody Tue Oct 25 04:34:22 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F09C612964F for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 04:34:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.331
X-Spam-Level: 
X-Spam-Status: No, score=-2.331 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RkZYigNS4Kjl for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 04:34:19 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2474B1294AD for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 04:34:19 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 90F26E1D9 for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 07:49:16 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id C4657639BA for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 07:34:17 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: 6tisch-security <6tisch-security@ietf.org>
X-Attribution: mcr
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 25 Oct 2016 07:34:17 -0400
Message-ID: <16693.1477395257@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/oPmAHpCXD-MenGPfccBI8RnZn4k>
Subject: [6tisch-security] reminder -- meeting today - 2016-10-28
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 11:34:21 -0000

--=-=-=
Content-Type: text/plain


(You can now "join in browser" and use WebRTC for audio, but apparently, no
IPv6 support...)

10am EDT, 1400 UTC.

http://etherpad.tools.ietf.org:9000/p/6tischSecurity?useMonospaceFont=true

https://ietf.webex.com/ietf/j.php?MTID=m64b407a7cdbb11b8c41f8ce0cfb3a6d6

Access code: 644 081 620
Meeting password: animalhouse

1-877-668-4493 Call-in toll free number (US/Canada)
1-650-479-3208 Call-in toll number (US/Canada)

Agenda:
0) Note Well
1) draft:
https://tools.ietf.org/html/draft-richardson-6tisch-dtsecurity-secure-join-01

2) things still missing from draft:
   a) EDHOC
   b) DTLS
   c) system-keychain
   d) CoAP POST of ownership voucher, vs DTLS authorization extension
      containing voucher?
   e) more work on privacy considerations








--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWA9DNoCLcPvd0N1lAQICJAf/Roi9iKbNr3cW1ZNR/v6PeJEpIhFM9JB9
EKDJh1YHBbq4I1wOCt8FSQTQgHkYSwSygHRJECHJsKQXVZhB9qVXoudeadZd+gHX
yZMfSfHU+2q8+7kJRGjIhkjp4slNH9xM9fBeEk1LlPTplDyHqR9Ep58gOyP9Z8iu
ROsizEU9Nd8ibo0ZnMSr3WtEd2L1bpQTMDlsLv1p4RzAie34nDPsX4As/ioVUoIT
P3BR5KQgmDQumA/CKuOXFCQofTH1RDJaq7w8wWOk2WHBA1prpFGWRTtQXTi4mzWr
QTLsgiiM3Bp+sn3qZLkNMzBn8iJ6amLtQyFcFHkP/Vdab2Czs7Wnfg==
=0Vg9
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Tue Oct 25 05:45:04 2016
Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C1121295E6 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 05:45:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.952
X-Spam-Level: 
X-Spam-Status: No, score=-14.952 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.431, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, WEIRD_PORT=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SR1O2j0uWxEu for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 05:44:57 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64CDB12954B for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 05:44:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1227; q=dns/txt; s=iport; t=1477399497; x=1478609097; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=QlILYvutYBUrPqMMAmrFlpFqGnOvT94Zn48Bv5ClnZ8=; b=R9r+zKUqQGn3mtBQoDAKC/Yxy96f81pkthfHbUZm7JGYSweXJTK4pZv4 uQH4CDcy+n0+3bpyY+p9W+aauykxCUpUqalfdTZ77nmjE8Mr0yHzpflvA B6MVW5PbOrAuf2jwbs3gxcbOtbAdKXgsKfMKv1swNxdTR2cr4YoB2A20j s=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0B/AAA7Uw9Y/4UNJK1CFwMaAQEBAQIBA?= =?us-ascii?q?QEBCAEBAQGDMAEBAQEBHVh9B40uln6UP4EfBWMpgkKCV18CgXs/FAECAQEBAQE?= =?us-ascii?q?BAWIohGIBAQEEOiwfBAIBCBEEAQEVBAYGAwcyFAkHAQIBAwESCIhLDi25W4dnA?= =?us-ascii?q?QEBAQEBAQEBAQEBAQEBAQEBAQEBHIY9hFWBPAGCezAmB4URBXeZHwGGKYlmgkO?= =?us-ascii?q?NR40IhAABHjZegxQcgQdLcgGHEIEAAQEB?=
X-IronPort-AV: E=Sophos;i="5.31,545,1473120000"; d="scan'208";a="340035884"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by alln-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 25 Oct 2016 12:44:56 +0000
Received: from XCH-RCD-004.cisco.com (xch-rcd-004.cisco.com [173.37.102.14]) by alln-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id u9PCiuOT001921 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 25 Oct 2016 12:44:56 GMT
Received: from xch-rcd-001.cisco.com (173.37.102.11) by XCH-RCD-004.cisco.com (173.37.102.14) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Tue, 25 Oct 2016 07:44:55 -0500
Received: from xch-rcd-001.cisco.com ([173.37.102.11]) by XCH-RCD-001.cisco.com ([173.37.102.11]) with mapi id 15.00.1210.000; Tue, 25 Oct 2016 07:44:56 -0500
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] reminder -- meeting today - 2016-10-28
Thread-Index: AQHSLrO+Eq4Z4J8f80mUx1eN4l81qaC5HQ5Q
Date: Tue, 25 Oct 2016 12:44:34 +0000
Deferred-Delivery: Tue, 25 Oct 2016 12:43:41 +0000
Message-ID: <7be4b63514504a538978e58de37ab871@XCH-RCD-001.cisco.com>
References: <16693.1477395257@obiwan.sandelman.ca>
In-Reply-To: <16693.1477395257@obiwan.sandelman.ca>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.55.22.4]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/Frpow7unjRpF-uSzv4E_lYNAS3o>
Subject: Re: [6tisch-security] reminder -- meeting today - 2016-10-28
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 12:45:03 -0000

Hello Michael: Today or 10/28?

-----Original Message-----
From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf O=
f Michael Richardson
Sent: mardi 25 octobre 2016 13:34
To: 6tisch-security <6tisch-security@ietf.org>
Subject: [6tisch-security] reminder -- meeting today - 2016-10-28


(You can now "join in browser" and use WebRTC for audio, but apparently, no
IPv6 support...)

10am EDT, 1400 UTC.

http://etherpad.tools.ietf.org:9000/p/6tischSecurity?useMonospaceFont=3Dtru=
e

https://ietf.webex.com/ietf/j.php?MTID=3Dm64b407a7cdbb11b8c41f8ce0cfb3a6d6

Access code: 644 081 620
Meeting password: animalhouse

1-877-668-4493 Call-in toll free number (US/Canada)
1-650-479-3208 Call-in toll number (US/Canada)

Agenda:
0) Note Well
1) draft:
https://tools.ietf.org/html/draft-richardson-6tisch-dtsecurity-secure-join-=
01

2) things still missing from draft:
   a) EDHOC
   b) DTLS
   c) system-keychain
   d) CoAP POST of ownership voucher, vs DTLS authorization extension
      containing voucher?
   e) more work on privacy considerations








--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works  -=3D =
IPv6 IoT consulting =3D-




From nobody Tue Oct 25 07:05:15 2016
Return-Path: <francesca.palombini@ericsson.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3FA78129563 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 07:05:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level: 
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QB7qzgP9SGP6 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 07:05:10 -0700 (PDT)
Received: from sessmg22.ericsson.net (sessmg22.ericsson.net [193.180.251.58]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 81398129570 for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 07:04:57 -0700 (PDT)
X-AuditID: c1b4fb3a-aa3ff7000000099a-0a-580f66862f6d
Received: from ESESSHC008.ericsson.se (Unknown_Domain [153.88.183.42]) by  (Symantec Mail Security) with SMTP id F9.96.02458.6866F085; Tue, 25 Oct 2016 16:04:55 +0200 (CEST)
Received: from EUR02-VE1-obe.outbound.protection.outlook.com (153.88.183.145) by oa.msg.ericsson.com (153.88.183.42) with Microsoft SMTP Server (TLS) id 14.3.319.2; Tue, 25 Oct 2016 16:04:52 +0200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.onmicrosoft.com; s=selector1-ericsson-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=h6gSw28w1BUVNXUrH+AAJtVqnPvyxNQztjUeijqpV04=; b=mGlEK3/WgKuvbq7x1SS8TMJLzB6T1Syen6HwZ9DEXdgMyFz/QkLS7qnCiOF1pFufxdV2lgt2i2qXdveWmm6a5033doF8b7BLjIzOK9tEkgLGp9bhC3ksxbLeroE9ZZQCwspWmGxeDCQby8s/05SwxoDleT1RIcMAXymEYD5Q5oM=
Received: from HE1PR0701MB2539.eurprd07.prod.outlook.com (10.168.129.17) by HE1PR0701MB2538.eurprd07.prod.outlook.com (10.168.129.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.679.5; Tue, 25 Oct 2016 14:04:53 +0000
Received: from HE1PR0701MB2539.eurprd07.prod.outlook.com ([10.168.129.17]) by HE1PR0701MB2539.eurprd07.prod.outlook.com ([10.168.129.17]) with mapi id 15.01.0679.015; Tue, 25 Oct 2016 14:04:53 +0000
From: Francesca Palombini <francesca.palombini@ericsson.com>
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>, Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security <6tisch-security@ietf.org>
Thread-Topic: [6tisch-security] reminder -- meeting today - 2016-10-28
Thread-Index: AQHSLrPNIAM6yPE1Lk287yUYYO5/KaC5HasAgAAWNcA=
Date: Tue, 25 Oct 2016 14:04:52 +0000
Message-ID: <HE1PR0701MB25394162FC0296D809EFC45398A80@HE1PR0701MB2539.eurprd07.prod.outlook.com>
References: <16693.1477395257@obiwan.sandelman.ca> <7be4b63514504a538978e58de37ab871@XCH-RCD-001.cisco.com>
In-Reply-To: <7be4b63514504a538978e58de37ab871@XCH-RCD-001.cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=francesca.palombini@ericsson.com; 
x-originating-ip: [80.216.62.213]
x-ms-office365-filtering-correlation-id: 5ed2922d-3162-488b-b64d-08d3fcdfe495
x-microsoft-exchange-diagnostics: 1; HE1PR0701MB2538; 6:PmpsFvdgoCwlkJ2k2W34FOM+749kFFe1p0El8XnRBDe5ta4rKOV2SRwYrpfueAytRY+Qt9Fv5avv3xS7+tiZdQk9yvwsQTMAWVR08Nofe5NQy7lSdJZq+xNGQhnxFU6g04wh6L+WKRvwj7ywzlZJUhLk6bYyeg0FJJNXOpun+fEosBF/WOdV1bJWlDkiao2L3YhI2lqpj0JcKPhWesUQYzDAw7Mu12/Ke1L6nux9ygDiCf4zVmFx8dsk9LwvIAjlvL75Uz00WkMGkCV31EaCYPBMele4m+KwPsAR9UyFtwiPGb6APkI0UbwUe5veuOS3; 5:Z/BKnE+nHc7X4qr4CZSbOQ6jgE0zSne6+zP6MGtv3GPz91TMapU290cxdZFnf+75LPaOUKyDaBTuq6avp9+J/C1y0N98z9Smbg2hARfAlxfKV3jL5W+gyD/asYGfP6f5Y3MZYviTujqe8qaFVBmEpQ==; 24:pM1diyZ6FXwDwMBa0rLobQeuuiEDCl3K9kW4Mom0AUHkVhbjTXYhl/G/+43pj1kfAoweAgJU6opYlfjdfKtT63P3FKOTM1gNAOxwT2W4uV0=; 7:GcrWmMjDX0XG69WASJlZTSq/d8riecqsUkfTOY357ttB9nJmDGJncspT1lFbHOUxftAvTJHzim3wAJ4eXRkTb+8XhEu16n3czHd64ukcNIWTw+wR9BjI1vPIkC4ttvr5Jmum57y7j7EJm6VyV0uzXcPMPGNVoPl2CjN9nKo96odbGBPqS7odnW/QaxpBjyg8tM2iFuTlb8rH7TlSGW9T7eYcTktQ4KhVK0XkJXFhvzztzGSUo4ZHyX++DA6us+evJW5/OupkzllQZjuGc+0Tgbq+yEgiI6Ohk8PztVsSpDUjX5spW1Rtb6eSqdL4bo/KM6TzRxMV3Rin27bNzuhEUunVp5+3h3nNi2Ka3DDUlg8=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:HE1PR0701MB2538;
x-microsoft-antispam-prvs: <HE1PR0701MB2538AE4ED245E10F78103B9C98A80@HE1PR0701MB2538.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(60795455431006)(94707916325470);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040176)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001);  SRVR:HE1PR0701MB2538; BCL:0; PCL:0; RULEID:; SRVR:HE1PR0701MB2538; 
x-forefront-prvs: 01068D0A20
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(7916002)(279900001)(199003)(5423002)(12213003)(189002)(13464003)(497574002)(377424004)(122556002)(2420400007)(15650500001)(4001150100001)(107886002)(5001770100001)(189998001)(97736004)(230783001)(7110500001)(3660700001)(9686002)(3280700002)(5002640100001)(66066001)(551544002)(77096005)(19625305001)(15975445007)(10400500002)(16799955002)(305945005)(68736007)(33656002)(2950100002)(575784001)(19580395003)(74316002)(19580405001)(11100500001)(92566002)(2900100001)(86362001)(7736002)(81156014)(81166006)(8676002)(7696004)(2906002)(10710500007)(54356999)(101416001)(76576001)(586003)(7846002)(76176999)(50986999)(102836003)(3846002)(6116002)(5660300001)(106116001)(105586002)(106356001)(8936002)(87936001); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR0701MB2538; H:HE1PR0701MB2539.eurprd07.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en; 
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Oct 2016 14:04:52.9703 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2538
X-OriginatorOrg: ericsson.com
X-Brightmail-Tracker: H4sIAAAAAAAAA02Se0hTYRjG+XbOtuPY8mtNfDEjG0RozVLGGmZiRCZiJRU0hMihJx3tYjtm KUleG16mWQa5VpmtRLsaooKXcJROCS+llOWK0EwpL4wsbKBtOwb993vf5/neGx9FiKu4QZRG n0Ub9WqtlCcga1VtYTLTaX/VLseETFnUWM9XVtir+MobNfMoloivcTdz4222ZU58sbWTSCKS BdFptFaTTRt3xqQIMsbLrbzMRv8LlulHnHw0JixDfhRgOQwMWvllSECJ8VMEz5xDa4HDE9zq QV4Xic0EmOckrFDLAfflFsQGAwh6zfWE18XD0TD8ZYHrFSS4EsGrrimfsAEfgGuF8x6B8ghx YOoQedMSHAWuDgfJdtgKN5dXfd1EOAXy3Q0+FmMdjI/Wcbzs5ylT3ObwMcKb4GfBQ195AgfC h6k7HHYfDLbOIYLlAJidXOGy/lQY/VjJZ/NbYKmgi+cdB/AhqHgv9o4M2MUHV/UfkvXEw48y 21pNA7QuFSGWE6C69jpiH3QiKJmbXzMFw9XyWZIVTHywDbt57AY0NDwuQewhgsA5WrrGwTAz 0cW9gkIt/y3B8g6o63DxWN4OD+5+Jyy+w6yH/topsg6RTSiAoRlGlx4ZGU4bNakMY9CH6+ms 58jzTXpa3FHtqOfbPjvCFJIKRSGJ61RirjqbydHZEVCEVCLqTvNXiUVp6pxc2mg4ZTynpRk7 2kiR0kCRovHzCTFOV2fRZ2g6kzb+UzmUX1A+Smr99dbyQt6+d2q8ZX/OyHl7X9Zq3lestQvl Mr9MpWzYsLjVeq+wpjsmVnIpwSoPzZ0+DkeEm5uJd5aQ/pMvjzW/+bR49PXIdJx/pL307BOF dbAqWZ83qZgZMzUvKJzbVobMe+4PhI3/dt4+uJTe0ueacVQfdmp6dYlpFyOadktJJkMdEUYY GfVfQyiFZiIDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/0S9EqbiG15U8CgDEAGDL76URmk0>
Subject: Re: [6tisch-security] reminder -- meeting today - 2016-10-28
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 14:05:14 -0000

Hi Pascal,

Today, it is starting.

Francesca

> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf=
 Of
> Pascal Thubert (pthubert)
> Sent: den 25 oktober 2016 14:45
> To: Michael Richardson <mcr+ietf@sandelman.ca>; 6tisch-security <6tisch-
> security@ietf.org>
> Subject: Re: [6tisch-security] reminder -- meeting today - 2016-10-28
>=20
> Hello Michael: Today or 10/28?
>=20
> -----Original Message-----
> From: 6tisch-security [mailto:6tisch-security-bounces@ietf.org] On Behalf=
 Of
> Michael Richardson
> Sent: mardi 25 octobre 2016 13:34
> To: 6tisch-security <6tisch-security@ietf.org>
> Subject: [6tisch-security] reminder -- meeting today - 2016-10-28
>=20
>=20
> (You can now "join in browser" and use WebRTC for audio, but apparently,
> no
> IPv6 support...)
>=20
> 10am EDT, 1400 UTC.
>=20
> http://etherpad.tools.ietf.org:9000/p/6tischSecurity?useMonospaceFont=3Dt=
r
> ue
>=20
> https://ietf.webex.com/ietf/j.php?MTID=3Dm64b407a7cdbb11b8c41f8ce0cfb3
> a6d6
>=20
> Access code: 644 081 620
> Meeting password: animalhouse
>=20
> 1-877-668-4493 Call-in toll free number (US/Canada)
> 1-650-479-3208 Call-in toll number (US/Canada)
>=20
> Agenda:
> 0) Note Well
> 1) draft:
> https://tools.ietf.org/html/draft-richardson-6tisch-dtsecurity-secure-joi=
n-01
>=20
> 2) things still missing from draft:
>    a) EDHOC
>    b) DTLS
>    c) system-keychain
>    d) CoAP POST of ownership voucher, vs DTLS authorization extension
>       containing voucher?
>    e) more work on privacy considerations
>=20
>=20
>=20
>=20
>=20
>=20
>=20
>=20
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -=3D IPv6 IoT consulting =3D-
>=20
>=20
>=20
> _______________________________________________
> 6tisch-security mailing list
> 6tisch-security@ietf.org
> https://www.ietf.org/mailman/listinfo/6tisch-security


From nobody Tue Oct 25 07:06:58 2016
Return-Path: <mcr@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B0AA91294EE for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 07:06:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P3TtpklrGvt0 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 07:06:53 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4009E129570 for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 07:06:49 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 71C9EE007 for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 10:21:47 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 419F0639BA for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 10:06:48 -0400 (EDT)
From: Michael Richardson <mcr@sandelman.ca>
to: 6tisch-security <6tisch-security@ietf.org>
In-Reply-To: <16693.1477395257@obiwan.sandelman.ca>
References: <16693.1477395257@obiwan.sandelman.ca>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-ID: <19318.1477404408.1@obiwan.sandelman.ca>
Content-Transfer-Encoding: quoted-printable
Date: Tue, 25 Oct 2016 10:06:48 -0400
Message-ID: <19319.1477404408@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/74XgepO3IpKXBrlPUvSO605034Y>
Subject: Re: [6tisch-security] reminder -- meeting today - 2016-10-25
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 14:06:58 -0000

Michael Richardson <mcr+ietf@sandelman.ca> wrote:
    > (You can now "join in browser" and use WebRTC for audio, but apparen=
tly, no
    > IPv6 support...)
    > 10am EDT, 1400 UTC.

Sorry, but this was a typo in the  subject, it should be TODAY, the 25th.




--
]               Never tell me the odds!                 | ipv6 mesh networ=
ks [
]   Michael Richardson, Sandelman Software Works        | network architec=
t  [
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails =
   [


From nobody Tue Oct 25 09:14:32 2016
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 072D71297C2 for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 09:14:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.332
X-Spam-Level: 
X-Spam-Status: No, score=-2.332 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.431, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mR70R1qukCBh for <6tisch-security@ietfa.amsl.com>; Tue, 25 Oct 2016 09:14:26 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24EDC1297CB for <6tisch-security@ietf.org>; Tue, 25 Oct 2016 09:14:26 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id CFEF8200A3; Tue, 25 Oct 2016 12:29:24 -0400 (EDT)
Received: from obiwan.sandelman.ca (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 5AF61639BA; Tue, 25 Oct 2016 12:14:25 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: =?us-ascii?Q?=3D=3Futf-8=3FQ=3FMali=3DC5=3DA1a=5FVu=3DC4=3D8Dini=3DC4?= =?us-ascii?Q?=3D87=3F=3D?= <malisa.vucinic@inria.fr>
In-Reply-To: <EBBDD80D-5CDB-4487-AA53-1912F30C9EAB@inria.fr>
References: <147738827207.15142.9664067180872740444.idtracker@ietfa.amsl.com> <EBBDD80D-5CDB-4487-AA53-1912F30C9EAB@inria.fr>
X-Mailer: MH-E 8.6; nmh 1.6+dev; GNU Emacs 24.5.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 25 Oct 2016 12:14:25 -0400
Message-ID: <15617.1477412065@obiwan.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/m8BAknQ6T3bGl65eUuUZTTbwens>
Cc: tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] Fwd: New Version Notification for draft-vucinic-6tisch-minimal-security-00.txt
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Oct 2016 16:14:31 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Mali=C5=A1a Vu=C4=8Dini=C4=87 <malisa.vucinic@inria.fr> wrote:
    > We have submitted a new draft on the join process in 6TiSCH. The draf=
t is
    > quite efficient when it comes to PSKs and requires a single round trip
    > for the authenticated key transport from JCE to JN. We use OSCOAP for
    > protection of CoAP messages end-to-end (through the proxy) and EDHOC
    > for the security
    > handshake when using public keys for joining.

    > It would be great if we could discuss some of the related aspects at =
the
    > meeting this afternoon.

Give us a day to read the document ... :-)
Is 30 minutes on Nov. 8 meeting okay for you?

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEVAwUBWA+E3oCLcPvd0N1lAQKWTwgAvvZX4W71O/XNm4PesvrxcodSMxTa7D4p
TEsFlu0E00r6HDIJV0bF6RynLxQm6yZRzIbZD18dVk78pRih+giV9G3uKHZsh3M2
jpnFoEtxZht4SRNpikRSONQ6rT0PCc7f7jh115Ds3OPf8L+i7fbrDJoKdORFqAVk
VyUlzC+rBOStqKBMv63vxnlaQoPsB/bnAmIp0SEsNXjmCzswXPUsTixFine4jPtk
xwEIn2BlFXelxDWVIzEHGfwV/r6GvicmBChpTcZfGWLKOFwKnqJJZlx7Q6Pw86lE
7Zr9zTvqUgQc3OqdNDyDyTNRHjsncCinxexbDPIu0x86Y9hCXTuKbw==
=A45e
-----END PGP SIGNATURE-----
--=-=-=--


From nobody Wed Oct 26 04:10:16 2016
Return-Path: <malisa.vucinic@inria.fr>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A29F312952C for <6tisch-security@ietfa.amsl.com>; Wed, 26 Oct 2016 04:10:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.33
X-Spam-Level: 
X-Spam-Status: No, score=-7.33 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.431] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f5ynRCky6meS for <6tisch-security@ietfa.amsl.com>; Wed, 26 Oct 2016 04:10:12 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr (mail3-relais-sop.national.inria.fr [192.134.164.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B73FE12943C for <6tisch-security@ietf.org>; Wed, 26 Oct 2016 04:10:11 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.31,550,1473112800";  d="scan'208,217";a="198225295"
Received: from unknown (HELO [128.93.85.112]) ([128.93.85.112]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-SHA; 26 Oct 2016 13:10:10 +0200
Content-Type: multipart/alternative; boundary="Apple-Mail=_0DE64AF7-339E-4560-8862-882668C6CD49"
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: =?utf-8?Q?Mali=C5=A1a_Vu=C4=8Dini=C4=87?= <malisa.vucinic@inria.fr>
In-Reply-To: <15617.1477412065@obiwan.sandelman.ca>
Date: Wed, 26 Oct 2016 13:10:11 +0200
Message-Id: <8833E8D9-C502-4C61-B34D-15AFA311C02C@inria.fr>
References: <147738827207.15142.9664067180872740444.idtracker@ietfa.amsl.com> <EBBDD80D-5CDB-4487-AA53-1912F30C9EAB@inria.fr> <15617.1477412065@obiwan.sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.3124)
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/dZgk8CbzutjkhQP_3o6RXKHej24>
Cc: tisch-security <6tisch-security@ietf.org>
Subject: Re: [6tisch-security] New Version Notification for draft-vucinic-6tisch-minimal-security-00.txt
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Oct 2016 11:10:15 -0000

--Apple-Mail=_0DE64AF7-339E-4560-8862-882668C6CD49
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=us-ascii

Yes, that would be great!

> On 25 Oct 2016, at 18:14, Michael Richardson <mcr+ietf@sandelman.ca> wrote:
> 
> 
> Give us a day to read the document ... :-)
> Is 30 minutes on Nov. 8 meeting okay for you?


--Apple-Mail=_0DE64AF7-339E-4560-8862-882668C6CD49
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">Yes, that would be great!<div class=3D""><br =
class=3D""><div><blockquote type=3D"cite" class=3D""><div class=3D"">On =
25 Oct 2016, at 18:14, Michael Richardson &lt;<a =
href=3D"mailto:mcr+ietf@sandelman.ca" =
class=3D"">mcr+ietf@sandelman.ca</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><br =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><span style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">Give us a day to =
read the document ... :-)</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; orphans: auto; text-align: start; text-indent: =
0px; text-transform: none; white-space: normal; widows: auto; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">Is 30 minutes on Nov. 8 meeting okay for =
you?</span></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_0DE64AF7-339E-4560-8862-882668C6CD49--


From nobody Wed Oct 26 18:00:49 2016
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: 6tisch-security@ietfa.amsl.com
Delivered-To: 6tisch-security@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 894731294FE; Wed, 26 Oct 2016 18:00:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jv_19cUvHK-W; Wed, 26 Oct 2016 18:00:42 -0700 (PDT)
Received: from mail-pf0-x22f.google.com (mail-pf0-x22f.google.com [IPv6:2607:f8b0:400e:c00::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 83C7F1294C0; Wed, 26 Oct 2016 18:00:42 -0700 (PDT)
Received: by mail-pf0-x22f.google.com with SMTP id 197so6144619pfu.0; Wed, 26 Oct 2016 18:00:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;  h=subject:to:references:cc:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=jCdbdd+87KlKiabV7KaJYtUCDrJdpsa8O1zpbHByetU=; b=z2MT5ND65YpOCLBJ1g5VWZdE2nf7n9znf7rJBeOLOLT7w8HcWrrciBAIOFbt/3be92 7zautEphB+9houXGSDRSje4ipmBw9qo9tY+Fg/NZ8tdAE/lPzNvOp2o27WB2OkLc+sEC T0Rh35IhYPvZ9oQHdp/3/jaLsMDFODXJnKK3a21zodv8Cu8sogYoRyH+BkPhE88FpLbY H3hfVEnPppzIhhQSRrZL83sJJyro4G3V/I3dc6RuwDIi+hMndBHopZbYEqgrJj6IffyV o2PsQX82KVcB4gSopmkiURtG0FaSOWarf/jjXquG7liNF5seQfXQJMJCAWxIwyxk4aX+ R9YA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-transfer-encoding; bh=jCdbdd+87KlKiabV7KaJYtUCDrJdpsa8O1zpbHByetU=; b=mfUynDselkymJTNwr5pNYgCosEHBaOyjcprLIBg1vh3KVNiV225iVHw6JyAVPeiVBs aoPN1YcNinGuk+/Anyv97WwSQIjJpcRFe8WjMKkNY9xKIVr8P6NmGYZCf99w8JqhiJTI oYgcvAGW1JVkiqAYCDcqltF9gJfq+n1Q30mBphuRfHqI9w+RjheSZhn3ptj6fMryw+Hq GGQ47As5xQMLCbCHJAfNBUfKsEdSLw98mJGBBuiUjjmMSj3BCCw0xyHGmIBSt/lN3wAT RmyGZo7uBAy5LoVgYs0I/+Sl6c9gUwmjiza0FfIgahGckRafpTlHRBBSCvrl+uWJIffb sefA==
X-Gm-Message-State: ABUngvcTM0vWklwoSf/pzOGKxz7BlS5EXTAQPbkpAqCeM5PnmJcjSfn/tsWxkoYTt34d8Q==
X-Received: by 10.99.188.1 with SMTP id q1mr7587672pge.145.1477530041873; Wed, 26 Oct 2016 18:00:41 -0700 (PDT)
Received: from ?IPv6:2406:e007:44d7:1:28cc:dc4c:9703:6781? ([2406:e007:44d7:1:28cc:dc4c:9703:6781]) by smtp.gmail.com with ESMTPSA id yz6sm6732590pab.35.2016.10.26.18.00.38 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 26 Oct 2016 18:00:40 -0700 (PDT)
To: Michael Richardson <mcr+ietf@sandelman.ca>, 6tisch-security <6tisch-security@ietf.org>
References: <20351.1476971471@obiwan.sandelman.ca> <0343d14c-5b18-b821-c9ad-d77fb7dae490@gmail.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <12808a8a-5de1-c6cb-3f96-945573041ee4@gmail.com>
Date: Thu, 27 Oct 2016 14:00:44 +1300
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0
MIME-Version: 1.0
In-Reply-To: <0343d14c-5b18-b821-c9ad-d77fb7dae490@gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch-security/DLIL0EWQhUJhzTcFAdRfCkk-yZA>
Cc: anima-bootstrap <anima-bootstrap@ietf.org>
Subject: Re: [6tisch-security] [Anima-bootstrap] 6tisch join -01 documented posted
X-BeenThere: 6tisch-security@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Extended Design Team for 6TiSCH security architecture <6tisch-security.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch-security/>
List-Post: <mailto:6tisch-security@ietf.org>
List-Help: <mailto:6tisch-security-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch-security>, <mailto:6tisch-security-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Oct 2016 01:00:44 -0000

Hi Michael,

I said: TL;DR;WRL (will read later)

Well, now is "later". Two comments:

1. I seemed to recall from various corridor discussions in Berlin that
the anima-bootstrap preference was for a GRASP flooding model. However,
I have no strong preference; and in fact your approach could make more use
of GRASP than the flooding approach. But for discussion, here's the way
a flooded objective would look (i.e. the registrar floods it out to all
potential proxies (= Join Assistants).

objective = ["AN_Registrar", objective-flags, loop-count, [radius, priority, weight, method]]

method /= "BRSKI_TLS"
method /= "BRSKI_COAP"

radius = 0..255 ; the initial loop-count, so that the recipient can calculate
                ; the distance by subtraction

priority =      ; same semantics as mDNS priority
weight =        ; same semantics as mDNS weight

The IP address, protocol and port are supplied as part of the M_FLOOD message
(sorry, people who aren't familiar with draft-ietf-anima-grasp-07
won't get that).

My model was that the proxy would get all the floods available and choose
the one it liked best, based on the available method and distance, using the
weight and priority as for mDNS. (Personally I think the mDNS stuff is overkill,
but Toerless suggested we should be feature-equivalent.)

That's what is coded in Python at https://www.cs.auckland.ac.nz/~brian/graspy/brski/

Of course, since it's flooded there is no response, so I was assuming that
the pledge's IID would be part of the first actual BRSKI message.

2. Your CDDL looks OK to me. The format and semantics of the value field of
a GRASP objective are completely flexible, so I don't see a problem with
the first "request" to the Registrar being [IID, join-method]. The reply
from the registrar could be [IID, another-join-method] if it didn't like
the first one proposed. Once either side receives a join-method it likes,
it would send [M_END,,[O_ACCEPT]] and we're done.

3. Mini-question, is this really IPv6-specific? If not I'd prefer a name
that flags it as an AN infrastructure objective, e.g. "AN_Join"

Regards
   Brian

On 21/10/2016 08:38, Brian E Carpenter wrote:
> On 21/10/2016 02:51, Michael Richardson wrote:
> ...
>> b) https://datatracker.ietf.org/doc/draft-richardson-anima-6join-discovery/
>>    I wrote this document to reference from secure-join to explain the GRASP
>>    query that the Join Assistant will do to inform the Registrar about a new
>>    pledge.
>>
>>    I think that this document goes into draft-ietf-anima-bootstrapping-keyinfra.
>>
>>    Based upon some feedback on the anima list about how M_NEGOTIATE works,
>>    there are some major things wrong in this document when it comes to how an
>>    ANIMA Join Assistant would discover the *EST* port of the Registrar.
> 
> TL;DR;WRL (will read later)
> 
> I think you could look at my BRSKI toys (in Python) without needing to look at
> my actual GRASP code. They express my understanding of the options.
> 
> https://www.cs.auckland.ac.nz/~brian/graspy/brski/
> start with the README
> 
> Regards
>    Brian
> 

