
From ietf-secretariat@ietf.org  Mon Dec  9 09:44:51 2013
Return-Path: <ietf-secretariat@ietf.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C0A771AE3E7; Mon,  9 Dec 2013 09:44:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GVgytPzU71ad; Mon,  9 Dec 2013 09:44:50 -0800 (PST)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 461F01AE3DD; Mon,  9 Dec 2013 09:44:50 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: IETF Secretariat <ietf-secretariat@ietf.org>
To: IETF Announcement List <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 4.83.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20131209174450.21375.35464.idtracker@ietfa.amsl.com>
Date: Mon, 09 Dec 2013 09:44:50 -0800
X-Mailman-Approved-At: Mon, 09 Dec 2013 11:53:11 -0800
Cc: gerdes@tzi.de, Bert.Greevenbosch@huawei.com, ace@ietf.org
Subject: [Ace] New Non-WG Mailing List: Authentication and Authorization for Constrained Environments (ace)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Reply-To: ietf@ietf.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 17:44:52 -0000

A new IETF non-working group email list has been created.

List address: ace@ietf.org
Archive: http://www.ietf.org/mail-archive/web/ace/
To subscribe:https://www.ietf.org/mailman/listinfo/ace

Purpose: BoF and charter planning for work on Authentication and Authorizat=
ion for Constrained Environments.


For additional information, please contact the list administrators.

From ulrich@herberg.name  Mon Dec  9 14:50:10 2013
Return-Path: <ulrich@herberg.name>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 798D51A1F08 for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 14:50:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.377
X-Spam-Level: 
X-Spam-Status: No, score=-1.377 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GFjjZhwQrENg for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 14:50:09 -0800 (PST)
Received: from mail-vc0-x22f.google.com (mail-vc0-x22f.google.com [IPv6:2607:f8b0:400c:c03::22f]) by ietfa.amsl.com (Postfix) with ESMTP id 25F231A1F00 for <ace@ietf.org>; Mon,  9 Dec 2013 14:50:09 -0800 (PST)
Received: by mail-vc0-f175.google.com with SMTP id ld13so4003378vcb.34 for <ace@ietf.org>; Mon, 09 Dec 2013 14:50:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=herberg.name; s=dkim; h=mime-version:date:message-id:subject:from:to:content-type; bh=I9rpuwuNPxl5jEXbJNdtC+M6G01gvGbN9OmtrMf8kpg=; b=KG9sT/G+ExGIpYQ5bqoKUMNMZfFLNBlxNKTX/jFaC+MLjlcLeCd4jK6eyvq440blaC /Vw/bQ2wNZSJmsauCceMCdq4WrU53ZX40SycE+IqqaHbEuN3QLbB7G8+ZuO6kgyzi546 wKEzMoxPMgYlOpL/lg7GBUut5mnGvuHmD2/DY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:date:message-id:subject:from:to :content-type; bh=I9rpuwuNPxl5jEXbJNdtC+M6G01gvGbN9OmtrMf8kpg=; b=Cm2yftYykJ5amGK866btv3sC8DVRvWWNZBiOOzvsrSd4jwfHDNaSeLLGIL/xp+PH3Y SVSUjGxs1aNRvJm1vXItPQgcjl/4T61hjk0SmOUdngiB631qr/4rXUE5kaVW/fYYoPdn b4B/PLc3D7iwWyKn7RK4wROzz89FVmteuA9CNm/ig2fPkjN5nHsuOROU4tcthFdrCZ3g uIdoFOkM64DzafkuMym2Cg1/1zi/+UPHFfxaGtPUbHVVxYV0c3immEm18ZwqDez2sKMC mdilpbDF0E8lsvImLZ5R7tP7L3ZY5LLKzmIDD8bgD+8idGbBaaedpmVPob+0pfpWizHc cJdg==
X-Gm-Message-State: ALoCoQnNujY/dm3g9sv9KTR7MWchYnZk8oylHQ1BI6NOusOlQys6g3Oc16ZQ64lkZxx4UJyllhy9
MIME-Version: 1.0
X-Received: by 10.221.64.17 with SMTP id xg17mr12261615vcb.5.1386629404020; Mon, 09 Dec 2013 14:50:04 -0800 (PST)
Received: by 10.220.253.68 with HTTP; Mon, 9 Dec 2013 14:50:03 -0800 (PST)
Date: Mon, 9 Dec 2013 14:50:03 -0800
Message-ID: <CAK=bVC-SFPtCuB80iM0JKej8eRCBP+X1-cZMNt6vtofrz8J6Hg@mail.gmail.com>
From: Ulrich Herberg <ulrich@herberg.name>
To: ace@ietf.org
Content-Type: multipart/alternative; boundary=001a1133158e0fe3e104ed21d1d5
Subject: [Ace] Purpose for this list?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 22:50:10 -0000

--001a1133158e0fe3e104ed21d1d5
Content-Type: text/plain; charset=ISO-8859-1

Hi,

could one of the list administrators (or anyone else) explain the purpose /
topics / scope of this mailing list?

Thanks
Ulrich

--001a1133158e0fe3e104ed21d1d5
Content-Type: text/html; charset=ISO-8859-1

<div dir="ltr"><div><div>Hi,<br><br></div>could one of the list administrators (or anyone else) explain the purpose / topics / scope of this mailing list?<br><br></div>Thanks<br>Ulrich<br></div>

--001a1133158e0fe3e104ed21d1d5--

From cabo@tzi.org  Mon Dec  9 15:15:30 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C30CE1ADBD4 for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 15:15:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9e1t320SmtY5 for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 15:15:30 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id DA0421ADA74 for <ace@ietf.org>; Mon,  9 Dec 2013 15:15:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rB9NFL1A015031; Tue, 10 Dec 2013 00:15:21 +0100 (CET)
Received: from [192.168.217.105] (p54890261.dip0.t-ipconnect.de [84.137.2.97]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3FF9242; Tue, 10 Dec 2013 00:15:21 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CAK=bVC-SFPtCuB80iM0JKej8eRCBP+X1-cZMNt6vtofrz8J6Hg@mail.gmail.com>
Date: Tue, 10 Dec 2013 00:15:18 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <1D2C8279-A098-49D5-9682-84A04A5E044B@tzi.org>
References: <CAK=bVC-SFPtCuB80iM0JKej8eRCBP+X1-cZMNt6vtofrz8J6Hg@mail.gmail.com>
To: Ulrich Herberg <ulrich@herberg.name>
X-Mailer: Apple Mail (2.1822)
Cc: ace@ietf.org
Subject: Re: [Ace] Purpose for this list?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 23:15:30 -0000

On 09 Dec 2013, at 23:50, Ulrich Herberg <ulrich@herberg.name> wrote:

> Hi,
>=20
> could one of the list administrators (or anyone else) explain the =
purpose / topics / scope of this mailing list?

The list administrators should be sleeping at this point :-), so I=92ll =
jump in with a quick answer:

In Berlin and in Vancouver, the CoRE WG had some discussions about =
authorization (and the related authentication) for CoRE.  There are =
about a dozen I-Ds about this already.  Some of the work may be done in =
CoRE, but some of it would better be done in a Security area WG.  This =
mailing list is for preparing that work (with a view to a BOF possibly =
already in London).  I=92d expect an early charter proposal to be posted =
here this week, which should shed some more light on the potential work =
of that WG.  Until then, search for =93Core-AA=94 in the CoRE minutes =
and slides for IETF87 and IETF88 for an overview.  And welcome to the =
list.

Gr=FC=DFe, Carsten


From ulrich@herberg.name  Mon Dec  9 15:17:55 2013
Return-Path: <ulrich@herberg.name>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 166771ADBD4 for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 15:17:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.377
X-Spam-Level: 
X-Spam-Status: No, score=-1.377 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B4f4nNwROyzJ for <ace@ietfa.amsl.com>; Mon,  9 Dec 2013 15:17:54 -0800 (PST)
Received: from mail-pd0-x235.google.com (mail-pd0-x235.google.com [IPv6:2607:f8b0:400e:c02::235]) by ietfa.amsl.com (Postfix) with ESMTP id 0BD1D1ADA74 for <ace@ietf.org>; Mon,  9 Dec 2013 15:17:53 -0800 (PST)
Received: by mail-pd0-f181.google.com with SMTP id p10so6052502pdj.26 for <ace@ietf.org>; Mon, 09 Dec 2013 15:17:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=herberg.name; s=dkim; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=C10KCREGor70E6J7poiEGPsNXH7512CNXTuBu8GuyZg=; b=krdJUQxBn+syA7sbFfpOnWdGLa0xMQb/N9y3NTampDExspOseO1+6mAWV5MgBkR3uz dwu7qlux7oI0o9Rc7e6bobih96kunCiLSLvM0gjxV+C9Yi95dkXrbfL5CbG4JbXmw/VR vM/kGZWuZnMRe95THlVqlyuGnqQgRXS0JHObI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=C10KCREGor70E6J7poiEGPsNXH7512CNXTuBu8GuyZg=; b=ABhuscmSn+EeO+15z1tSQajo2ZLXqw1ORZ19A96nnauJz5W9z0oLmvJB0ldIWhI6I3 TkdUNtPW97jgBVtNRDu5REj3+MutAtFdLWvGMwMxNxDqOXKwumbLsL6UxB1QIYdqzEl7 zuJovl1BKtyR2Xyb1rOYhB9a1D8DUgu2ZLFn4T4kxTgiBfnIeZ4NQmyvcBrVh5cUS5/u FtalI9G0Nxlwlb7qiMs+8jSz2bv0Mjq1jhmgUxU+vjZosQE6BR7CFpESku2Avdmvwu5o 5gA2ou++D6mKwBDWae6sb7SF2qSyQmAPDQvnvDFccWyaIdTUIir+SIlwnKkGwtxvcUWI 2qxw==
X-Gm-Message-State: ALoCoQnGxAjZfQyJIqCaLS2cp9spolO7iFMZYboDlA0/MjHJco60pEC6w5rE/D+Q/m8QBdtmb9so
MIME-Version: 1.0
X-Received: by 10.66.184.168 with SMTP id ev8mr7400057pac.152.1386631069137; Mon, 09 Dec 2013 15:17:49 -0800 (PST)
Received: by 10.70.13.162 with HTTP; Mon, 9 Dec 2013 15:17:49 -0800 (PST)
In-Reply-To: <1D2C8279-A098-49D5-9682-84A04A5E044B@tzi.org>
References: <CAK=bVC-SFPtCuB80iM0JKej8eRCBP+X1-cZMNt6vtofrz8J6Hg@mail.gmail.com> <1D2C8279-A098-49D5-9682-84A04A5E044B@tzi.org>
Date: Mon, 9 Dec 2013 15:17:49 -0800
Message-ID: <CAK=bVC-AzzAjvr7xr0Gy99gJ+ujNBEhpn=pMvd4i5jQab6Xphw@mail.gmail.com>
From: Ulrich Herberg <ulrich@herberg.name>
To: Carsten Bormann <cabo@tzi.org>
Content-Type: multipart/alternative; boundary=047d7bdc78ea4f9e0b04ed223402
Cc: ace@ietf.org
Subject: Re: [Ace] Purpose for this list?
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 23:17:55 -0000

--047d7bdc78ea4f9e0b04ed223402
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Carsten,

thank you, that is helpful information (shouldn't you be sleeping as well?
;-). I am looking forward to that charter idea, as well as a list of the
drafts you mentioned. I will check the CoRE minutes/slides in the meantime.

Regards
Ulrich


On Mon, Dec 9, 2013 at 3:15 PM, Carsten Bormann <cabo@tzi.org> wrote:

> On 09 Dec 2013, at 23:50, Ulrich Herberg <ulrich@herberg.name> wrote:
>
> > Hi,
> >
> > could one of the list administrators (or anyone else) explain the
> purpose / topics / scope of this mailing list?
>
> The list administrators should be sleeping at this point :-), so I=92ll j=
ump
> in with a quick answer:
>
> In Berlin and in Vancouver, the CoRE WG had some discussions about
> authorization (and the related authentication) for CoRE.  There are about=
 a
> dozen I-Ds about this already.  Some of the work may be done in CoRE, but
> some of it would better be done in a Security area WG.  This mailing list
> is for preparing that work (with a view to a BOF possibly already in
> London).  I=92d expect an early charter proposal to be posted here this w=
eek,
> which should shed some more light on the potential work of that WG.  Unti=
l
> then, search for =93Core-AA=94 in the CoRE minutes and slides for IETF87 =
and
> IETF88 for an overview.  And welcome to the list.
>
> Gr=FC=DFe, Carsten
>
>

--047d7bdc78ea4f9e0b04ed223402
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Carsten,<br><br>thank you, that is helpful information (sh=
ouldn&#39;t you be sleeping as well? ;-). I am looking forward to that char=
ter idea, as well as a list of the drafts you mentioned. I will check the C=
oRE minutes/slides in the meantime.<br>
<br>Regards<br>Ulrich<br></div><div class=3D"gmail_extra"><br><br><div clas=
s=3D"gmail_quote">On Mon, Dec 9, 2013 at 3:15 PM, Carsten Bormann <span dir=
=3D"ltr">&lt;<a href=3D"mailto:cabo@tzi.org" target=3D"_blank">cabo@tzi.org=
</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im">On 09 Dec 2013, at 23:50, =
Ulrich Herberg &lt;<a href=3D"mailto:ulrich@herberg.name">ulrich@herberg.na=
me</a>&gt; wrote:<br>

<br>
&gt; Hi,<br>
&gt;<br>
&gt; could one of the list administrators (or anyone else) explain the purp=
ose / topics / scope of this mailing list?<br>
<br>
</div>The list administrators should be sleeping at this point :-), so I=92=
ll jump in with a quick answer:<br>
<br>
In Berlin and in Vancouver, the CoRE WG had some discussions about authoriz=
ation (and the related authentication) for CoRE. =A0There are about a dozen=
 I-Ds about this already. =A0Some of the work may be done in CoRE, but some=
 of it would better be done in a Security area WG. =A0This mailing list is =
for preparing that work (with a view to a BOF possibly already in London). =
=A0I=92d expect an early charter proposal to be posted here this week, whic=
h should shed some more light on the potential work of that WG. =A0Until th=
en, search for =93Core-AA=94 in the CoRE minutes and slides for IETF87 and =
IETF88 for an overview. =A0And welcome to the list.<br>

<br>
Gr=FC=DFe, Carsten<br>
<br>
</blockquote></div><br></div>

--047d7bdc78ea4f9e0b04ed223402--

From adrian@olddog.co.uk  Tue Dec 10 14:10:57 2013
Return-Path: <adrian@olddog.co.uk>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D060C1AE229 for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 14:10:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6tDxaqz3MzX6 for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 14:10:56 -0800 (PST)
Received: from asmtp5.iomartmail.com (asmtp5.iomartmail.com [62.128.201.176]) by ietfa.amsl.com (Postfix) with ESMTP id 628CC1AE1B1 for <ace@ietf.org>; Tue, 10 Dec 2013 14:10:56 -0800 (PST)
Received: from asmtp5.iomartmail.com (localhost.localdomain [127.0.0.1]) by asmtp5.iomartmail.com (8.13.8/8.13.8) with ESMTP id rBAMAogx013893 for <ace@ietf.org>; Tue, 10 Dec 2013 22:10:50 GMT
Received: from 950129200 (dsl-sp-81-140-15-32.in-addr.broadbandscope.com [81.140.15.32]) (authenticated bits=0) by asmtp5.iomartmail.com (8.13.8/8.13.8) with ESMTP id rBAMAkPj013859 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO) for <ace@ietf.org>; Tue, 10 Dec 2013 22:10:48 GMT
From: "Adrian Farrel" <adrian@olddog.co.uk>
To: <ace@ietf.org>
Date: Tue, 10 Dec 2013 22:10:45 -0000
Message-ID: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Ac719Kxc0dJKVCkBToKVrQ5hQojRJw==
Content-Language: en-gb
Subject: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: adrian@olddog.co.uk
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Dec 2013 22:10:58 -0000

Hi,

I like the name, and I think security is a good thing.

There is clearly some overlap between this proposal and what the DICE working
group is doing.

I would also like to understand whether the intention is to provide security at
a particular layer in constrained networks or across all layers of the
constrained network.

Since the description of the mailing list is both very specific and very vague,
can I call on the proponents of this work to post more explanation as soon as
possible.

Thanks,
Adrian


From gerdes@tzi.de  Tue Dec 10 15:39:35 2013
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F080E1AE2A9 for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 15:39:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yk4BIItfJEYF for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 15:39:33 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 3999A1AE2A7 for <ace@ietf.org>; Tue, 10 Dec 2013 15:39:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBANdMk5025103 for <ace@ietf.org>; Wed, 11 Dec 2013 00:39:22 +0100 (CET)
Received: from [192.168.1.146] (p508A7A36.dip0.t-ipconnect.de [80.138.122.54]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 4E7F47EE for <ace@ietf.org>; Wed, 11 Dec 2013 00:39:22 +0100 (CET)
Message-ID: <52A7A626.5070901@tzi.de>
Date: Wed, 11 Dec 2013 00:39:18 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0.1
MIME-Version: 1.0
To: ace@ietf.org
References: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk>
In-Reply-To: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: Re: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Dec 2013 23:39:35 -0000

Hi Adrian,

I am glad that people are already interested in this discussion group.
The reason for creating this mailing list was a discussion about
authorization in the CoRE WG in Berlin and Vancouver. The feeling in
Vancouver was that only some of this work can be done in CoRE while some
other topics might fit better into the security area.


On 12/10/2013 11:10 PM, Adrian Farrel wrote:
> 
> There is clearly some overlap between this proposal and what the DICE working
> group is doing.

You are correct that some topics are close to the work of the DICE
working group and the DICE chairs were involved in some of the
discussions in Vancouver. DICE is focused on DTLS improvements, though,
and the topics we want to discuss in ACE don't really fit in there.

> 
> I would also like to understand whether the intention is to provide security at
> a particular layer in constrained networks or across all layers of the
> constrained network.
> 
> Since the description of the mailing list is both very specific and very vague,
> can I call on the proponents of this work to post more explanation as soon as
> possible.

We are currently working on a more meaningful proposal which will
hopefully answer a lot of questions.

Best regards,
Steffi


From cabo@tzi.org  Tue Dec 10 15:53:11 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8AB201AE2BC for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 15:53:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id evBIC1WlJLLJ for <ace@ietfa.amsl.com>; Tue, 10 Dec 2013 15:53:10 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id E3C7C1AE2BA for <ace@ietf.org>; Tue, 10 Dec 2013 15:53:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBANqwOG022868; Wed, 11 Dec 2013 00:52:58 +0100 (CET)
Received: from [192.168.217.105] (p54892614.dip0.t-ipconnect.de [84.137.38.20]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 2A6797F6; Wed, 11 Dec 2013 00:52:57 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <52A7A626.5070901@tzi.de>
Date: Wed, 11 Dec 2013 00:53:07 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <48D459D9-2744-4C99-92C5-D1AEF386AA18@tzi.org>
References: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk> <52A7A626.5070901@tzi.de>
To: "<adrian@olddog.co.uk> Farrel" <adrian@olddog.co.uk>
X-Mailer: Apple Mail (2.1822)
Cc: ace@ietf.org
Subject: Re: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Dec 2013 23:53:11 -0000

Adrian,

On 11 Dec 2013, at 00:39, Stefanie Gerdes <gerdes@tzi.de> wrote:

>  The feeling in
> Vancouver was that only some of this work can be done in CoRE while =
some
> other topics might fit better into the security area.

One view of how that might be worked is on slide 105 of=20
	http://www.ietf.org/proceedings/88/slides/slides-88-core-0.pdf

Now this slide takes the view that the work that is closely intertwined =
with the base standard should happen in CoRE and that work with a high =
level of security content should happen in a new SEC area WG (called WGX =
there), with DICE certainly being part of the overall picture where the =
DTLS and related certificate issues dominate.  But, of course, in the =
end we have to make sure we assemble the right constituency in the right =
WGs.  How the division of work should look like in detail will be the =
subject of the discussion now and leading up to IETF89.

Re your question on whether this work might be useful on other layers =
than the application protocol:  Much of what we are trying to to (get =
devices to be verifiably authorized to do something wich each other) is =
often somewhat misleadingly subsumed under =93key management=94.  We =
will try to use CoAP and DTLS to perform operations on authorizations =
and related keying materials, but the authorizations we operate might =
very well cover more than application layer (CoRE) resources.  We need =
to find out how far the technical approaches here can carry us.

Gr=FC=DFe, Carsten


From likepeng@huawei.com  Wed Dec 11 02:11:41 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E7461A8032 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 02:11:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6IHc-2gtGhfA for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 02:11:32 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id A457D1A1F4E for <ace@ietf.org>; Wed, 11 Dec 2013 02:11:31 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id AYW39309; Wed, 11 Dec 2013 10:11:25 +0000 (GMT)
Received: from LHREML406-HUB.china.huawei.com (10.201.5.243) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 11 Dec 2013 10:11:12 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 11 Dec 2013 10:11:21 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Wed, 11 Dec 2013 18:11:17 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: Draft ACE Charter
Thread-Index: Ac72WVT850tgXXxoRT6JXoOa8NAUkA==
Date: Wed, 11 Dec 2013 10:11:17 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CASZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 10:11:41 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CASZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello all,

Welcome to the list!

The purpose of this list is to organize interest in a group to define the c=
harter for work on Authentication and Authorization for Constrained Environ=
ments.

Our mailing list can be found at (1), existing work can be found at (2), an=
d draft charter can be found at (3).

We welcome your feedback!

Thanks,

Kind Regards
Kepeng & Stefanie

(1)Mailing List

https://www.ietf.org/mailman/listinfo/ace

(2)Existing work:

Use Cases:
http://tools.ietf.org/id/draft-garcia-core-security
http://tools.ietf.org/id/draft-greevenbosch-core-authreq
http://tools.ietf.org/id/draft-seitz-core-sec-usecases

Solutions
http://tools.ietf.org/id/draft-gerdes-core-dcaf-authorize
http://tools.ietf.org/id/draft-kang-core-secure-reconfiguration
http://tools.ietf.org/id/draft-selander-core-access-control
http://tools.ietf.org/id/draft-zhu-core-groupauth
http://tools.ietf.org/id/draft-pporamba-dtls-certkey
http://tools.ietf.org/id/draft-schmitt-two-way-authentication-for-iot
http://tools.ietf.org/id/draft-seitz-core-security-modes

(3)Draft Charter - Authentication and Authorization for Constrained Environ=
ment (ACE)

The CoAP (Constrained Application Protocol) is a light-weight application l=
ayer protocol, especially suitable for applications such as smart energy, s=
mart home, building automation, remote patient monitoring etc. Due to the n=
ature of these applications, including a critical, unattended infrastructur=
e and usage in the personal sphere, security and privacy protection are cri=
tical components.

Currently, a problem with constrained devices is the realization of such se=
cure communication. The devices only have limited resources such as memory,=
 storage and transmission capacity. These constraints severely limit the se=
curity functions and communications the device can perform. Missing functio=
nality includes authentication, which provides trust and ensures an entity =
is who it says it is, and authorization, which defines and enforces access =
rights for different clients.

The ACE WG focuses on providing constrained devices with the necessary prer=
equisites to use REST operations in a secure way. Constrained devices will =
thus be enabled to authenticate communications from other (constrained or l=
ess-constrained) devices, to communicate securely with them and to verify t=
heir individual authorization to access specific resources. To achieve this=
, ACE will be able to employ an architecture with one or more trusted less-=
constrained devices which will relieve the constrained nodes from complex s=
ecurity related tasks (e.g. managing authorization policies and a large num=
ber of keys). ACE will use CoAP and employ security properties of DTLS when=
ever possible.

The ACE WG has the following tasks:
- Document the use cases and high-level requirements for secured communicat=
ion between constrained devices.
- Define certificate profiling (what kinds of certificates and which attrib=
utes are to be used).
- Define a mechanism for authenticated and protected transfer of authorizat=
ion information suitable for constrained device to constrained device commu=
nication.
- Define an access ticket and authorization information format suitable for=
 constrained devices.
- Define bootstrapping for authorization information using the Resource Dir=
ectory.


--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CASZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello all,<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Welcome to the list!<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">The purpose of this list is to =
organize interest in a group to define the charter for work on Authenticati=
on and Authorization for Constrained Environments.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Our mailing list can be found a=
t (1), existing work can be found at (2), and draft charter can be found at=
 (3).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">We welcome your feedback!<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thanks,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng &amp; Stefanie<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">(1)Mailing List<o:=
p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"https:/=
/www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/a=
ce</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">(2)Existing work:<=
o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">Use Cases:<o:p></o=
:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-garcia-core-security">http://tools.ietf.org/id/draf=
t-garcia-core-security</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-greevenbosch-core-authreq">http://tools.ietf.org/id=
/draft-greevenbosch-core-authreq</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-seitz-core-sec-usecases">http://tools.ietf.org/id/d=
raft-seitz-core-sec-usecases</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">Solutions<o:p></o:=
p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-gerdes-core-dcaf-authorize">http://tools.ietf.org/i=
d/draft-gerdes-core-dcaf-authorize</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-kang-core-secure-reconfiguration">http://tools.ietf=
.org/id/draft-kang-core-secure-reconfiguration</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-selander-core-access-control">http://tools.ietf.org=
/id/draft-selander-core-access-control</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-zhu-core-groupauth">http://tools.ietf.org/id/draft-=
zhu-core-groupauth</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-pporamba-dtls-certkey">http://tools.ietf.org/id/dra=
ft-pporamba-dtls-certkey</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-schmitt-two-way-authentication-for-iot">http://tool=
s.ietf.org/id/draft-schmitt-two-way-authentication-for-iot</a><o:p></o:p></=
span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><a href=3D"http://=
tools.ietf.org/id/draft-seitz-core-security-modes">http://tools.ietf.org/id=
/draft-seitz-core-security-modes</a><o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">(3)Draft Charter &=
#8211; Authentication and Authorization for Constrained Environment (ACE)<o=
:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">The CoAP (Constrai=
ned Application Protocol) is a light-weight application layer protocol, esp=
ecially suitable for applications such as
 smart energy, smart home, building automation, remote patient monitoring e=
tc. Due to the nature of these applications, including a critical, unattend=
ed infrastructure and usage in the personal sphere, security and privacy pr=
otection are critical components.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">Currently, a probl=
em with constrained devices is the realization of such secure communication=
. The devices only have limited resources
 such as memory, storage and transmission capacity. These constraints sever=
ely limit the security functions and communications the device can perform.=
 Missing functionality includes authentication, which provides trust and en=
sures an entity is who it says it
 is, and authorization, which defines and enforces access rights for differ=
ent clients.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">The ACE WG focuses=
 on providing constrained devices with the necessary prerequisites to use R=
EST operations in a secure way. Constrained
 devices will thus be enabled to authenticate communications from other (co=
nstrained or less-constrained) devices, to communicate securely with them a=
nd to verify their individual authorization to access specific resources. T=
o achieve this, ACE will be able
 to employ an architecture with one or more trusted less-constrained device=
s which will relieve the constrained nodes from complex security related ta=
sks (e.g. managing authorization policies and a large number of keys). ACE =
will use CoAP and employ security
 properties of DTLS whenever possible.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p><=
/span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">The ACE WG has the=
 following tasks:<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">- Document the use=
 cases and high-level requirements for secured communication between constr=
ained devices.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">- Define certifica=
te profiling (what kinds of certificates and which attributes are to be use=
d).<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">- Define a mechani=
sm for authenticated and protected transfer of authorization information su=
itable for constrained device to constrained
 device communication.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">- Define an access=
 ticket and authorization information format suitable for constrained devic=
es.<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left;text-autospa=
ce:none"><span lang=3D"EN-US" style=3D"font-size:10.0pt">- Define bootstrap=
ping for authorization information using the Resource Directory.<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CASZXEMA501MBSchi_--

From ludwig@sics.se  Wed Dec 11 05:33:04 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E59AF1ADDD3 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:33:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.551
X-Spam-Level: 
X-Spam-Status: No, score=-3.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_INVITATION=-2, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mSGw-DTMTY78 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:33:01 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id EA3BD1AD93D for <ace@ietf.org>; Wed, 11 Dec 2013 05:33:00 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBBDWs36021291 for <ace@ietf.org>; Wed, 11 Dec 2013 14:32:54 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asad77c-1 for <ace@ietf.org>; Wed, 11 Dec 2013 14:32:53 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id D1D58400E2 for <ace@ietf.org>; Wed, 11 Dec 2013 14:32:53 +0100 (CET)
Message-ID: <52A86985.50703@sics.se>
Date: Wed, 11 Dec 2013 14:32:53 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.1.1
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms010005030105010805020004"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-11_03:2013-12-11,2013-12-11,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312110055
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 13:33:05 -0000

This is a cryptographically signed message in MIME format.

--------------ms010005030105010805020004
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/11/2013 11:11 AM, Likepeng wrote:
> Hello all,
>
> Welcome to the list!
>
> The purpose of this list is to organize interest in a group to define
> the charter for work on Authentication and Authorization for Constraine=
d
> Environments.
>
> Our mailing list can be found at (1), existing work can be found at (2)=
,
> and draft charter can be found at (3).
>
> We welcome your feedback!
>

Comments inline.

> (3)Draft Charter =96 Authentication and Authorization for Constrained
> Environment (ACE)
> [...]
> Currently, a problem with constrained devices is the realization of suc=
h
> secure communication. The devices only have limited resources such as
> memory, storage and transmission capacity. These constraints severely
> limit the security functions and communications the device can perform.=

> Missing functionality includes authentication,

I would challenge this statement, there is DTLS and it can provide both=20
client and server authentication depending on the mode that is used.=20
Even if you claim that DTLS isn't usable on constrained devices since it =

is too heavyweight (note that I don't claim this, but someone might),=20
profiling DTLS to constrained devices is clearly work that DICE is coveri=
ng.

>[...]
> To achieve this, ACE will be able to employ an architecture
> with one or more trusted less-constrained devices which will relieve th=
e
> constrained nodes from complex security related tasks (e.g. managing
> authorization policies and a large number of keys).

Why should we limit ourselves to this approach? There might very well be =

solutions, that don't require a "big brother"-third-party and that still =

cover several relevant use cases.

> [...]
> The ACE WG has the following tasks:
>
> - Document the use cases and high-level requirements for secured
> communication between constrained devices.
>
It's probably just the wording, but to me this sounds like Ace would=20
only look at CommSec use cases and requirements.

> - Define certificate profiling (what kinds of certificates and which
> attributes are to be used).
For what purpose does Ace intend to use these certs? They seem to come=20
out of nowhere here.

> [...]
> - Define an access ticket and authorization information format suitable=

> for constrained devices.
Do we really want to call those things 'tickets'? Everyone and their=20
grandmother are going to assume Ace does something akin to Kerberos.

Steffanie Gerdes, Olaf Bergmann, G=F6ran Selander and I had agreed to cal=
l=20
those things 'tokens' or 'authorization tokens'. Would that be=20
"consensusable"?

>
> - Define bootstrapping for authorization information using the Resource=

> Directory.
>
What if there is no Resource Directory? Don't we want to define security =

bootstrapping for such cases too?


/Ludwig


PS: I would have appreciated to get an invitation to this list, and I=20
guess the other people who authored the drafts listed as "Existing work" =

would do so too. It would probably also be ok to announce Ace on the=20
CoRE and DICE mailinglists.


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms010005030105010805020004
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTExMzMyNTNaMCMGCSqGSIb3DQEJBDEW
BBScalvl6upLGY55ahhQu82plSooxDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAXKbqqnvv8KnYlcZVWXMegpiJ+E1LhVu+ooia5T/IheFpV/9ODymNJ7Hct11bnAxm1Grn
MHX5bl5Mhcsmjp6SCA48dP7MbXKNFPitPhukky1Y1PJXDccDcQfpKpDpjZtXrRXKsdk1Oq3i
4s/sVKaDoj2AkTMwUF4j+vTWu4tLpiqHwCepJ64oZVg2P1sEgEeNC+I0V3GPB+nUOABP4yPH
/bFBO5QInoIaKvEglgLA5zK5NtCLLzKLm6UO1AOo6h9v0b8kHWjmeZU9udNovgHQ8Dbct7xC
CYSjaGfmB0nr2u/KzQMuK5jEpFGIr/8r7ms0MlRUQQnvbG7IiBcm+m9y4AAAAAAAAA==
--------------ms010005030105010805020004--

From mcr@sandelman.ca  Wed Dec 11 05:42:55 2013
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CFF8F1AD9B8 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:42:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OFn3SR_GU0-K for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:42:54 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id 6DD041AD93D for <ace@ietf.org>; Wed, 11 Dec 2013 05:42:54 -0800 (PST)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id E543D2018D for <ace@ietf.org>; Wed, 11 Dec 2013 09:56:30 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id D2E6C63B8A; Wed, 11 Dec 2013 08:42:39 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id C4D7063848 for <ace@ietf.org>; Wed, 11 Dec 2013 08:42:39 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: ace@ietf.org
In-Reply-To: <52A7A626.5070901@tzi.de>
References: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk> <52A7A626.5070901@tzi.de>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 11 Dec 2013 08:42:39 -0500
Message-ID: <8995.1386769359@sandelman.ca>
Sender: mcr@sandelman.ca
Subject: Re: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 13:42:56 -0000

--=-=-=


I second Adrian's question/confusion.
What about SOLACE?   Michael Behring has a lot of content that he is trying
to get into his behring-homenet-bootstrap document, but really it does not
fit into homenet, dice, roll, 6tisch, 6lo.

I think that we need a workshop, one to follow on from the pre-Paris IETF83
workshop, but this time, with less PPT and more focus on addressing
enrollment and authorization.

I think that we are all in violent agreement about what needds to happen, but
I think that many are scared to admit it, and we need a tygerteam to do a
prototype/spike implementation in order to bring the issues more clearly into
focus.  That is, this is a case running code followed by some rough consensus.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQCVAwUBUqhrz4qHRg3pndX9AQIAPQQA0n/PxzZLqr81c6OWUngX6nDznmiejdKw
ajiXX05d4qvEK7wgIYDlL3SdekcCh4//MqqCou/qwsyQm6+H0kuA3MjSrn18H2Un
N0Mz4ceFFaSHbOBOxCOEOdo2qyXseW9vh7SNu39C+igLB+4MRm4u8awXaJi30/EH
BRgGVlLcGsY=
=Si4d
-----END PGP SIGNATURE-----
--=-=-=--

From mcr@sandelman.ca  Wed Dec 11 05:46:23 2013
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D5991ADEA3 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:46:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VBu7T_cDb8pS for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 05:46:21 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id BE5291ADE7C for <ace@ietf.org>; Wed, 11 Dec 2013 05:46:20 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 26E422018D; Wed, 11 Dec 2013 09:59:57 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 7BDEB63B89; Wed, 11 Dec 2013 08:46:06 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 6D31C63848; Wed, 11 Dec 2013 08:46:06 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <48D459D9-2744-4C99-92C5-D1AEF386AA18@tzi.org>
References: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk> <52A7A626.5070901@tzi.de> <48D459D9-2744-4C99-92C5-D1AEF386AA18@tzi.org>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 11 Dec 2013 08:46:06 -0500
Message-ID: <9716.1386769566@sandelman.ca>
Sender: mcr@sandelman.ca
Cc: "<adrian@olddog.co.uk> Farrel" <adrian@olddog.co.uk>, ace@ietf.org
Subject: Re: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 13:46:23 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Carsten Bormann <cabo@tzi.org> wrote:
    > Re your question on whether this work might be useful on other layers
    > than the application protocol:  Much of what we are trying to to (get
    > devices to be verifiably authorized to do something wich each other) =
is
    > often somewhat misleadingly subsumed under =E2=80=9Ckey management=E2=
=80=9D.  We will
    > try to use CoAP and DTLS to perform operations on authorizations and
    > related keying materials, but the authorizations we operate might very
    > well cover more than application layer (CoRE) resources.  We need to
    > find out how far the technical approaches here can carry us.

I concur completely, and want to +1 that this is not a key managemenet
problem.

Let's solve the problem for light switches acting on light bulbs, and given
that infrastructure/architecture,  extend it later towards motes acting as
router nodes, or joining layer-2 PANs.

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQCVAwUBUqhsnoqHRg3pndX9AQJSowP+J4+E+kcw699gQXPJxyQSiGH6J2HJs2zJ
MKSup0h13BUkqluszamjBqguhEktSGpAFnr+OoYTvQ3UVtsoSpX+WFoM2Ngavo8J
v/ddmE5oIw55j8f+mwdPRBZNGG2l34Xzgf69B9Uar2yE7mDuEwOS+I5hKp/n7gcr
QKomwc7Oupk=
=EP25
-----END PGP SIGNATURE-----
--=-=-=--

From cabo@tzi.org  Wed Dec 11 06:02:17 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EC441ADED6 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 06:02:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KJyymb-MQUa4 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 06:02:16 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id F37991ADBD5 for <ace@ietf.org>; Wed, 11 Dec 2013 06:02:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBBE28TZ020268; Wed, 11 Dec 2013 15:02:08 +0100 (CET)
Received: from [192.168.217.144] (p5489295F.dip0.t-ipconnect.de [84.137.41.95]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 23234C7A; Wed, 11 Dec 2013 15:02:07 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <52A86985.50703@sics.se>
Date: Wed, 11 Dec 2013 15:02:05 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <134000F9-EC41-4B3A-BC67-84F7CF4F7233@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <52A86985.50703@sics.se>
To: Ludwig Seitz <ludwig@sics.se>
X-Mailer: Apple Mail (2.1822)
Cc: ace@ietf.org
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 14:02:17 -0000

Hi Ludwig,

you point out a number of ways in which the proposed text could be =
misread, and I think that is good input.

I would like to make two specific points from a CoRE point of view:

>> To achieve this, ACE will be able to employ an architecture
>> with one or more trusted less-constrained devices which will relieve =
the
>> constrained nodes from complex security related tasks (e.g. managing
>> authorization policies and a large number of keys).
>=20
> Why should we limit ourselves to this approach? There might very well =
be solutions, that don't require a "big brother"-third-party and that =
still cover several relevant use cases.

I read this as a requirement that the approach should *enable* the use =
of less-constrained devices, not to *require* their use.  If your =
devices are powerful enough not to need help, great.  If they aren=92t, =
more than two parties may be needed, and ACE should be flexible enough =
to support that scenario.

>> - Define bootstrapping for authorization information using the =
Resource
>> Directory.
>>=20
> What if there is no Resource Directory? Don't we want to define =
security bootstrapping for such cases too?

If that means that ACE is essentially reinventing another Resource =
Directory so it doesn=92t have to use the existing one, I think my =
answer would be no.   But if you have ways in mind to do authorization =
bootstrapping without such a rendezvous point, please do go ahead and =
tell us more about what needs to be done to make this part of this work.

Gr=FC=DFe, Carsten


From stokcons@xs4all.nl  Wed Dec 11 06:18:15 2013
Return-Path: <stokcons@xs4all.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 409931ADF2F for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 06:18:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.194
X-Spam-Level: 
X-Spam-Status: No, score=0.194 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_NL=0.55, HOST_EQ_NL=1.545, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BX-F0PU_bhnJ for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 06:18:13 -0800 (PST)
Received: from smtp-vbr8.xs4all.nl (smtp-vbr8.xs4all.nl [194.109.24.28]) by ietfa.amsl.com (Postfix) with ESMTP id F15311AD8EB for <ace@ietf.org>; Wed, 11 Dec 2013 06:18:12 -0800 (PST)
Received: from roundcube.xs4all.nl (roundcube10.xs4all.net [194.109.20.208]) by smtp-vbr8.xs4all.nl (8.13.8/8.13.8) with ESMTP id rBBEI624018968 for <ace@ietf.org>; Wed, 11 Dec 2013 15:18:06 +0100 (CET) (envelope-from stokcons@xs4all.nl)
Received: from ineo-y1c.hightechcampus.nl ([80.255.245.239]) by roundcube.xs4all.nl with HTTP (HTTP/1.1 POST); Wed, 11 Dec 2013 15:18:06 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Date: Wed, 11 Dec 2013 15:18:06 +0100
From: peter van der Stok <stokcons@xs4all.nl>
To: ace@ietf.org
Organization: vanderstok consultancy
Mail-Reply-To: consultancy@vanderstok.org
In-Reply-To: <134000F9-EC41-4B3A-BC67-84F7CF4F7233@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <52A86985.50703@sics.se> <134000F9-EC41-4B3A-BC67-84F7CF4F7233@tzi.org>
Message-ID: <dd7c71e804ea5a358ba07db2d2714c3a@xs4all.nl>
X-Sender: stokcons@xs4all.nl (r8NZSM8sJ/ribSRP6Ki8vqfHNBH6O6OA)
User-Agent: XS4ALL Webmail
X-Virus-Scanned: by XS4ALL Virus Scanner
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: consultancy@vanderstok.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 14:18:15 -0000

When there is no resource directory I don't see an immediate need to 
reinvent one.
There is all the work of DNSSD wg which supports service discovery over 
many network topologies.
Introducing that technology into the secure bootstrapping seems viable 
to me.

Peter

>>> 
>> What if there is no Resource Directory? Don't we want to define 
>> security bootstrapping for such cases too?
> 
> If that means that ACE is essentially reinventing another Resource
> Directory so it doesnâ€™t have to use the existing one, I think my
> answer would be no.   But if you have ways in mind to do authorization
> bootstrapping without such a rendezvous point, please do go ahead and
> tell us more about what needs to be done to make this part of this
> work.
> 
> GrÃ¼ÃŸe, Carsten
> 
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace

From thomas.fossati@alcatel-lucent.com  Wed Dec 11 09:06:52 2013
Return-Path: <thomas.fossati@alcatel-lucent.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3318B1ADF2F for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 09:06:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level: 
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ONDRpgY9ofVC for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 09:06:51 -0800 (PST)
Received: from ihemail4.lucent.com (ihemail4.lucent.com [135.245.0.39]) by ietfa.amsl.com (Postfix) with ESMTP id 057921ADF27 for <ace@ietf.org>; Wed, 11 Dec 2013 09:06:50 -0800 (PST)
Received: from fr712usmtp2.zeu.alcatel-lucent.com (h135-239-2-42.lucent.com [135.239.2.42]) by ihemail4.lucent.com (8.13.8/IER-o) with ESMTP id rBBH6fca027069 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL); Wed, 11 Dec 2013 11:06:43 -0600 (CST)
Received: from FR711WXCHHUB01.zeu.alcatel-lucent.com (fr711wxchhub01.zeu.alcatel-lucent.com [135.239.2.111]) by fr712usmtp2.zeu.alcatel-lucent.com (GMO) with ESMTP id rBBH6fxC019714 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 11 Dec 2013 18:06:41 +0100
Received: from FR711WXCHMBA08.zeu.alcatel-lucent.com ([169.254.4.153]) by FR711WXCHHUB01.zeu.alcatel-lucent.com ([135.239.2.111]) with mapi id 14.02.0247.003; Wed, 11 Dec 2013 18:06:40 +0100
From: "FOSSATI, Thomas (Thomas)" <thomas.fossati@alcatel-lucent.com>
To: "consultancy@vanderstok.org" <consultancy@vanderstok.org>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Draft ACE Charter
Thread-Index: Ac72WVT850tgXXxoRT6JXoOa8NAUkAAE8d+AAAEFEoAAAI8zAAAF4s4A
Date: Wed, 11 Dec 2013 17:06:40 +0000
Message-ID: <CECE48B0.E45F%thomas.fossati@alcatel-lucent.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <52A86985.50703@sics.se> <134000F9-EC41-4B3A-BC67-84F7CF4F7233@tzi.org> <dd7c71e804ea5a358ba07db2d2714c3a@xs4all.nl>
In-Reply-To: <dd7c71e804ea5a358ba07db2d2714c3a@xs4all.nl>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [135.239.27.40]
Content-Type: text/plain; charset="utf-8"
Content-ID: <86C15C41E4C4F84AB079E52AEB2362A4@exchange.lucent.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Scanned-By: MIMEDefang 2.57 on 135.245.2.39
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 17:06:52 -0000

SGkgUGV0ZXIsDQoNCk9uIDExLzEyLzIwMTMgMTQ6MTgsICJwZXRlciB2YW4gZGVyIFN0b2siIDxz
dG9rY29uc0B4czRhbGwubmw+IHdyb3RlOg0KPkludHJvZHVjaW5nIHRoYXQgdGVjaG5vbG9neSBp
bnRvIHRoZSBzZWN1cmUgYm9vdHN0cmFwcGluZyBzZWVtcyB2aWFibGUNCj50byBtZS4NCg0KSnVz
dCB0byBjbGFyaWZ5OiBoZXJlIGFyZSB5b3UgaGludGluZyBhdCBjcmVkZW50aWFsIGRpc2NvdmVy
eSBmdWxseSBkb25lDQppbiBETlMgKGUuZy4gdmlhIERBTkUpLCBvciBhdCBzb21lIG90aGVyIG1l
Y2hhbmlzbSB0aGF0IGlzIGJhc2VkIG9uIHRoZQ0KZGV2aWNlLW5hbWUgYXNzb2NpYXRpb25zIGVz
dGFibGlzaGVkIHZpYSBETlMtU0Q/DQoNCkNoZWVycw0KDQo=

From mcr@sandelman.ca  Wed Dec 11 11:54:35 2013
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 447F31AE1C1 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 11:54:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UEMHoYaxarhw for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 11:54:33 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id F09301AE1BE for <ace@ietf.org>; Wed, 11 Dec 2013 11:54:32 -0800 (PST)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 8E46D2018D for <ace@ietf.org>; Wed, 11 Dec 2013 16:08:08 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 8D14C63B89; Wed, 11 Dec 2013 14:54:16 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 7903A63AEF for <ace@ietf.org>; Wed, 11 Dec 2013 14:54:16 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "ace\@ietf.org" <ace@ietf.org>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 11 Dec 2013 14:54:16 -0500
Message-ID: <19752.1386791656@sandelman.ca>
Sender: mcr@sandelman.ca
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 19:54:35 -0000

--=-=-=


Likepeng <likepeng@huawei.com> wrote:
    > (2)Existing work:

I added of the items to my reading list, to discover that half of them were
already on my reading list, and some of them were marked as read :-)
(That's good, it means that this work isn't coming out from nowhere)

    > Currently, a problem with constrained devices is the realization of
    > such secure communication. The devices only have limited resources such
    > as memory, storage and transmission capacity. These constraints
    > severely limit the security functions and communications the device can
    > perform. Missing functionality includes authentication, which provides
    > trust and ensures an entity is who it says it is, and authorization,
    > which defines and enforces access rights for different clients.

I agree with all the words, but I think that many will get caught up on
authentication, and fail to read about authorization.

I suggest, going forward you write:

  The constrained devices while unable to include many sophisticated
  features, such as user interfaces and configuration files, nevertheless
  need to perform authentication and authorization operations.  Two
  items which must be sized to fit include authentication and authorization.
  Authentication is ensuring an entity is who it says it is.  Authentication
  is well understood, and the group must simply agree upon one method that fits.
  Authorization is less well understood, and this group will focus on this
  aspect first.

>  The ACE WG focuses on providing constrained devices with the necessary
>  prerequisites to use REST operations in a secure way. Constrained

I think that examples of prerequisites should be included here.

>  devices will thus be enabled to authenticate communications from other
> (constrained or less-constrained) devices, to communicate securely with
> them and to verify their individual authorization to access specific
> resources. To achieve this, ACE will be able to employ an architecture
> with one or more trusted less-constrained devices which will relieve
> the constrained nodes from complex security related tasks
> (e.g. managing authorization policies and a large number of keys). ACE
> will use CoAP and employ security properties of DTLS whenever possible.

You have made an architectural assumption here which may be appropriate, but
may also be premature.  I'm not objecting to the statement, I just want
everyone to be clear that this statement is being made.

Question:
  - is authorization to make authorization statements in scope?
    (i.e. meta operations)
  - should authorization be expressed in YANG?
  - should authorization to express authorization be expressed in YANG?

(I know little about YANG, but it seems to be what all the cool kids are doing)

    > The ACE WG has the following tasks:

    > - Document the use cases and high-level requirements for secured
    > communication between constrained devices.

Yes, we need use cases, but let's not get bogged down in them.

    > - Define certificate profiling (what kinds of certificates and which
    > attributes are to be used).

I think it's important to understand which parts deal with certificates,
and if we are doing CAs as well as AAs.

    > - Define a mechanism for authenticated and protected transfer of
    > authorization information suitable for constrained device to
    > constrained device communication.

    > - Define an access ticket and authorization information format suitable
    > for constrained devices.

    > - Define bootstrapping for authorization information using the Resource
    > Directory.

Maybe a reference on "Resource Directory" is useful here.
I think it's a CORE/CoAP thing, right?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting for hire =-



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQCVAwUBUqjC6IqHRg3pndX9AQILfwP/Xx1y7pWXfAJEthJwqtjaJGww2gtLwv9p
zcqwGYG3IVzAJDtPcXTztY1YUAkZZ6E63+vWIdsuINWRwi0ElUJWm0qK0WGhpGLN
UJR27mxMW8h5WrLrn+hKwzuDN8TWN1Vepky03ac9n2Rky6yZAc1xcNfHEj3EAEpO
2MX7HTdjDWo=
=LjLa
-----END PGP SIGNATURE-----
--=-=-=--

From cabo@tzi.org  Wed Dec 11 12:50:04 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC26A1AE092 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 12:50:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id krUyOwM-cwMo for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 12:50:03 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 28DE11AE052 for <ace@ietf.org>; Wed, 11 Dec 2013 12:50:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBBKntLZ029841; Wed, 11 Dec 2013 21:49:55 +0100 (CET)
Received: from [192.168.217.144] (p5489295F.dip0.t-ipconnect.de [84.137.41.95]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id CE4C3F19; Wed, 11 Dec 2013 21:49:54 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <19752.1386791656@sandelman.ca>
Date: Wed, 11 Dec 2013 21:49:51 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca>
To: Michael Richardson <mcr+ietf@sandelman.ca>
X-Mailer: Apple Mail (2.1822)
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Dec 2013 20:50:05 -0000

Hi Michael,

here are some viewpoints on some of your questions:

> Question:
>  - is authorization to make authorization statements in scope?
>    (i.e. meta operations)

Absolutely.  That is the cornerstone of pulling in the big brothers.

>  - should authorization be expressed in YANG?
>  - should authorization to express authorization be expressed in YANG?

No.

> (I know little about YANG, but it seems to be what all the cool kids =
are doing)

YANG is a fine data modeling language, but it is currently focused on =
netconf.
I=92m not sure the netconf ecosystem (with XML, SSH over TCP, =85) is a =
good fit right now.
But I=92m sure we=92ll talk to the COMAN people about much of this =
anyway.
There is a very thin line between operations on authorization state and =
other configuration management.

>> - Define certificate profiling (what kinds of certificates and which
>> attributes are to be used).
>=20
> I think it's important to understand which parts deal with =
certificates,
> and if we are doing CAs as well as AAs.

My view here is that (X.509) certificates exist, and people are finding =
uses for them, so we should spend energy in making their use as =
interoperable as possible, even if they aren=92t otherwise a perfect fit =
to the ACE architecture.  There are other cert-like structures such as =
JWTs we should look into.  When thinking about the CAs for the certs, we =
shouldn=92t automatically think PKI.

>> - Define bootstrapping for authorization information using the =
Resource
>> Directory.
>=20
> Maybe a reference on "Resource Directory" is useful here.
> I think it's a CORE/CoAP thing, right?

Yes.

http://tools.ietf.org/html/draft-ietf-core-resource-directory

Gr=FC=DFe, Carsten


From mcr@sandelman.ca  Wed Dec 11 17:38:46 2013
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D419E1AE018 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 17:38:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xvJ2Nd_Sqcjp for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 17:38:44 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id AC0041AE06B for <ace@ietf.org>; Wed, 11 Dec 2013 17:38:44 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 2D4CC20192; Wed, 11 Dec 2013 21:52:21 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 7276063B89; Wed, 11 Dec 2013 20:38:28 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 661CE63AEF; Wed, 11 Dec 2013 20:38:28 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca> <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Wed, 11 Dec 2013 20:38:28 -0500
Message-ID: <26190.1386812308@sandelman.ca>
Sender: mcr@sandelman.ca
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 01:38:47 -0000

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Carsten Bormann <cabo@tzi.org> wrote:
    > My view here is that (X.509) certificates exist, and people are findi=
ng
    > uses for them, so we should spend energy in making their use as
    > interoperable as possible, even if they aren=E2=80=99t otherwise a pe=
rfect fit
    > to the ACE architecture.  There are other cert-like structures such as
    > JWTs we should look into.  When thinking about the CAs for the certs,
    > we shouldn=E2=80=99t automatically think PKI.

I think you mean to write "PKIX", as "PKI" is a generic term.

=2D-
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -=3D IPv6 IoT consulting for hire =3D-



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQCVAwUBUqkTlIqHRg3pndX9AQJMoAQA1D1sRBTojvwxH2L54BUDjngM+xATtcIh
dCZm+L9kX8tdPd+KAJq0YepAPdzNGHfxfM/98127SaTKwPX8eAMJJfW9SB3VPpDn
fgLRuhAkgnUYEIwIsr9QVfifVjeU6wlZ6ginMSY3zhQONyrNYBNj0p77DooJA6Vh
136lEatn4XY=
=ex/f
-----END PGP SIGNATURE-----
--=-=-=--

From twatteyne@gmail.com  Wed Dec 11 18:37:01 2013
Return-Path: <twatteyne@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3736B1AE039 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 18:37:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qekdv8swgk4f for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 18:36:59 -0800 (PST)
Received: from mail-ea0-x235.google.com (mail-ea0-x235.google.com [IPv6:2a00:1450:4013:c01::235]) by ietfa.amsl.com (Postfix) with ESMTP id 4259B1ADFF6 for <ace@ietf.org>; Wed, 11 Dec 2013 18:36:59 -0800 (PST)
Received: by mail-ea0-f181.google.com with SMTP id m10so3245231eaj.26 for <ace@ietf.org>; Wed, 11 Dec 2013 18:36:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=DhW4RcxdwVlL3xfyi8anFzfetc8PBjdGyEOF9LkAXC4=; b=mYgoY1I7nE8Yxz3izuDBQkyRGSP37hkSAnUpI53dJgNzLRhXqute/7KJLCYUISdpw9 nySYFJdKuH5ZjxmFBBKKUgaBjyvpu/jU4EE1dKx4+gsZDi/QBCTpAkOP0iUUllxYpXxl FsdpYhSB9DLDBRpd+kxMY22LAcc/RWkqWXdAeh3UaYhsvcw/V9Q6iMR5EB5c2SQx5DSX +h968VXHXyNhHUlu1vLUK75wI3/9iW4hYiWyl7Ua8yAzl9I1gp8W8FfO0BrIK9++rA7U HLGBAn0YAlipa/ET2qiSwTXv6uazjIWtekp0gv9qUg2t3Bdo/CNuGMm3Jsriu89JX6co cuSw==
X-Received: by 10.15.52.73 with SMTP id o49mr5065519eew.60.1386815812891; Wed, 11 Dec 2013 18:36:52 -0800 (PST)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.14.91.5 with HTTP; Wed, 11 Dec 2013 18:36:32 -0800 (PST)
In-Reply-To: <26190.1386812308@sandelman.ca>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca> <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org> <26190.1386812308@sandelman.ca>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Wed, 11 Dec 2013 18:36:32 -0800
X-Google-Sender-Auth: sTZm-Aw-IN2xD_oJtEgRAKaJbJk
Message-ID: <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Content-Type: multipart/alternative; boundary=001a11c39730e57c2404ed4d3736
Cc: Carsten Bormann <cabo@tzi.org>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 02:37:01 -0000

--001a11c39730e57c2404ed4d3736
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Carsten,

Could you elaborate your argumentation about YANG?

When I read
"There is a very thin line between operations on authorization state and
other configuration management."
I think
"great, so a need to run only a single set of tools on my nodes to enable
both".

Sure, the netconf ecosystem (XML, SSH over TCP, etc.) does not fit, but
maybe this is a good moment to work with COMAN to produce a constrained
version, for example of RESTCONF. In a perfect world, a single protocol
could serve multiple purposes, e.g. by mapping different states to be
managed to different resources.

Thomas


On Wed, Dec 11, 2013 at 5:38 PM, Michael Richardson
<mcr+ietf@sandelman.ca>wrote:

>
> Carsten Bormann <cabo@tzi.org> wrote:
>     > My view here is that (X.509) certificates exist, and people are
> finding
>     > uses for them, so we should spend energy in making their use as
>     > interoperable as possible, even if they aren=92t otherwise a perfec=
t
> fit
>     > to the ACE architecture.  There are other cert-like structures such
> as
>     > JWTs we should look into.  When thinking about the CAs for the cert=
s,
>     > we shouldn=92t automatically think PKI.
>
> I think you mean to write "PKIX", as "PKI" is a generic term.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -=3D IPv6 IoT consulting for hire =3D-
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>

--001a11c39730e57c2404ed4d3736
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Carsten,<div><br></div><div>Could you elaborate your argum=
entation about YANG?</div><div><br></div><div>When I read</div><div>&quot;<=
span style=3D"font-family:arial,sans-serif;font-size:13px">There is a very =
thin line between operations on authorization state and other configuration=
 management.</span>&quot;</div>

<div>I think</div><div>&quot;great, so a need to run only a single set of t=
ools on my nodes to enable both&quot;.</div><div><br></div><div>Sure, the n=
etconf ecosystem (<span style=3D"font-family:arial,sans-serif;font-size:13p=
x">XML, SSH over TCP, etc.) does not fit, but maybe this is a good moment t=
o work with COMAN to produce a constrained version, for example of RESTCONF=
. In a perfect world, a single protocol could serve multiple purposes, e.g.=
 by mapping different states to be managed to different resources.</span></=
div>

<div><span style=3D"font-family:arial,sans-serif;font-size:13px"><br></span=
></div><div><font face=3D"arial, sans-serif">Thomas</font></div></div><div =
class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On Wed, Dec 11, 20=
13 at 5:38 PM, Michael Richardson <span dir=3D"ltr">&lt;<a href=3D"mailto:m=
cr+ietf@sandelman.ca" target=3D"_blank">mcr+ietf@sandelman.ca</a>&gt;</span=
> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im"><br>
Carsten Bormann &lt;<a href=3D"mailto:cabo@tzi.org">cabo@tzi.org</a>&gt; wr=
ote:<br>
=A0 =A0 &gt; My view here is that (X.509) certificates exist, and people ar=
e finding<br>
=A0 =A0 &gt; uses for them, so we should spend energy in making their use a=
s<br>
=A0 =A0 &gt; interoperable as possible, even if they aren=92t otherwise a p=
erfect fit<br>
=A0 =A0 &gt; to the ACE architecture. =A0There are other cert-like structur=
es such as<br>
=A0 =A0 &gt; JWTs we should look into. =A0When thinking about the CAs for t=
he certs,<br>
=A0 =A0 &gt; we shouldn=92t automatically think PKI.<br>
<br>
</div>I think you mean to write &quot;PKIX&quot;, as &quot;PKI&quot; is a g=
eneric term.<br>
<div class=3D"HOEnZb"><div class=3D"h5"><br>
--<br>
Michael Richardson &lt;<a href=3D"mailto:mcr%2BIETF@sandelman.ca">mcr+IETF@=
sandelman.ca</a>&gt;, Sandelman Software Works<br>
=A0-=3D IPv6 IoT consulting for hire =3D-<br>
<br>
<br>
</div></div><br>_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br></div>

--001a11c39730e57c2404ed4d3736--

From likepeng@huawei.com  Wed Dec 11 19:49:36 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 706561AE1CF for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 19:49:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V9zF-NzoxBRK for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 19:49:33 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id CCD1B1AE0EF for <ace@ietf.org>; Wed, 11 Dec 2013 19:49:32 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id AYX06933; Thu, 12 Dec 2013 03:49:26 +0000 (GMT)
Received: from LHREML406-HUB.china.huawei.com (10.201.5.243) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 03:49:14 +0000
Received: from SZXEMA404-HUB.china.huawei.com (10.82.72.36) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 03:49:25 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA404-HUB.china.huawei.com ([10.82.72.36]) with mapi id 14.03.0158.001; Thu, 12 Dec 2013 11:49:19 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: Draft ACE Charter V0.1
Thread-Index: Ac727SJkqYhxD//mT5GYmRIeXquOcw==
Date: Thu, 12 Dec 2013 03:49:19 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2DF8@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD2DF8SZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: [Ace] Draft ACE Charter V0.1
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 03:49:36 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD2DF8SZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello all,

Thanks for your feedback, and they are very helpful.

We made a quick update for the charter (1), and hope it captures some of yo=
ur comments.

I created a wiki page for the charter, so that people can log in the wiki p=
age to improve it:

http://trac.tools.ietf.org/wg/core/trac/wiki/ACE_charter#

Feel free to provide your further comments/suggestions.

Thanks
Kind Regards
Kepeng & Stefanie


(1)    Draft Charter V0.1 - Authentication and Authorization for Constraine=
d Environment (ACE)



The CoAP (Constrained Application Protocol) is a light-weight application l=
ayer protocol, especially suitable for applications such as smart energy, s=
mart home, building automation, remote patient monitoring etc. Due to the n=
ature of these applications, including a critical, unattended infrastructur=
e and usage in the personal sphere, security and privacy protection are cri=
tical components.



Currently, a problem with constrained devices is the realization of such se=
cure operation. Constrained devices are unable to include many sophisticate=
d features, such as user interfaces and configuration files, but neverthele=
ss need to perform authentication and authorization operations. While authe=
ntication is well understood, at least for communication security, there ar=
e only insufficient means for authorization. Authentication is considered i=
n this context as it is needed as a prerequisite to performing authorizatio=
n, including the authorization to change the authorization state.



The ACE WG focuses on providing constrained devices with the necessary prer=
equisites to use REST operations in a secure way such as authorization info=
rmation and the related keying material. Constrained devices will thus be e=
nabled to authenticate operations from other (constrained or less-constrain=
ed) devices, to communicate securely with them and to verify their individu=
al authorization to access specific resources. To achieve this, ACE will be=
 able to employ additional less-constrained devices in order to relieve the=
 constrained nodes from complex security related tasks (e.g. managing autho=
rization policies and a large number of keys). ACE will use CoAP and employ=
 security properties of DTLS whenever possible.



The ACE WG has the following tasks:

- Document the use cases and high-level requirements for secured communicat=
ion between constrained devices. (This task is pursued as a means to the ot=
her ends, not as an end in itself.)

- Flesh out profiles for the certificates that already are part of CoAP's s=
ecurity architecture as well as possibly for any ACE-specific use of certif=
icates.

- Define a mechanism for authenticated and protected transfer of authorizat=
ion information suitable for constrained device to constrained device commu=
nication.

- Define an access token and authorization information format suitable for =
constrained devices.

- Define bootstrapping for authorization information using the Resource Dir=
ectory (see http://tools.ietf.org/html/draft-ietf-core-resource-directory).


--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD2DF8SZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"\7EAF\6587\672C Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.Char
	{mso-style-name:"\7EAF\6587\672C Char";
	mso-style-priority:99;
	mso-style-link:\7EAF\6587\672C;
	font-family:"Calibri","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1506284149;
	mso-list-type:hybrid;
	mso-list-template-ids:-430507938 -835134942 67698713 67698715 67698703 676=
98713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-text:"\(%1\)";
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:18.0pt;
	text-indent:-18.0pt;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello all,<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thanks for your feedback, and t=
hey are very helpful.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">We made a quick update for the =
charter (1), and hope it captures some of your comments.<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I created a wiki page for the c=
harter, so that people can log in the wiki page to improve it:<o:p></o:p></=
span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><a href=3D"http://trac.tools=
.ietf.org/wg/core/trac/wiki/ACE_charter#">http://trac.tools.ietf.org/wg/cor=
e/trac/wiki/ACE_charter#</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Feel free to provide your furth=
er comments/suggestions.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thanks<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng &amp; Stefanie<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText" style=3D"margin-left:18.0pt;text-indent:-18.0pt;m=
so-list:l0 level1 lfo1">
<![if !supportLists]><span lang=3D"EN-US"><span style=3D"mso-list:Ignore">(=
1)<span style=3D"font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span lang=3D"EN-US">Draft Charter V0.1 - Au=
thentication and Authorization for Constrained Environment (ACE)<o:p></o:p>=
</span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">The CoAP (Constrained Applic=
ation Protocol) is a light-weight application layer protocol, especially su=
itable for applications such as smart energy, smart home, building automati=
on, remote patient monitoring etc. Due
 to the nature of these applications, including a critical, unattended infr=
astructure and usage in the personal sphere, security and privacy protectio=
n are critical components.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">Currently, a problem with co=
nstrained devices is the realization of such secure operation. Constrained =
devices are unable to include many sophisticated features, such as user int=
erfaces and configuration files, but
 nevertheless need to perform authentication and authorization operations. =
While authentication is well understood, at least for communication securit=
y, there are only insufficient means for authorization. Authentication is c=
onsidered in this context as it
 is needed as a prerequisite to performing authorization, including the aut=
horization to change the authorization state.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">The ACE WG focuses on provid=
ing constrained devices with the necessary prerequisites to use REST operat=
ions in a secure way such as authorization information and the related keyi=
ng material. Constrained devices will
 thus be enabled to authenticate operations from other (constrained or less=
-constrained) devices, to communicate securely with them and to verify thei=
r individual authorization to access specific resources. To achieve this, A=
CE will be able to employ additional
 less-constrained devices in order to relieve the constrained nodes from co=
mplex security related tasks (e.g. managing authorization policies and a la=
rge number of keys). ACE will use CoAP and employ security properties of DT=
LS whenever possible.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">The ACE WG has the following=
 tasks:<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">- Document the use cases and=
 high-level requirements for secured communication between constrained devi=
ces. (This task is pursued as a means to the other ends, not as an end in i=
tself.)<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">- Flesh out profiles for the=
 certificates that already are part of CoAP</span><span lang=3D"EN-US" styl=
e=3D"font-family:&quot;Courier New&quot;">&#8217;</span><span lang=3D"EN-US=
">s security architecture as well as possibly for any ACE-specific
 use of certificates.<o:p></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">- Define a mechanism for aut=
henticated and protected transfer of authorization information suitable for=
 constrained device to constrained device communication.<o:p></o:p></span><=
/p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">- Define an access token and=
 authorization information format suitable for constrained devices.<o:p></o=
:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">- Define bootstrapping for a=
uthorization information using the Resource Directory (see
<a href=3D"http://tools.ietf.org/html/draft-ietf-core-resource-directory">h=
ttp://tools.ietf.org/html/draft-ietf-core-resource-directory</a>).<o:p></o:=
p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD2DF8SZXEMA501MBSchi_--

From likepeng@huawei.com  Wed Dec 11 21:43:03 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3D1E1AE00F for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 21:43:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.413
X-Spam-Level: 
X-Spam-Status: No, score=-3.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, GB_I_INVITATION=-2, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1kbRZCOsp50V for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 21:43:00 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 419241A802D for <ace@ietf.org>; Wed, 11 Dec 2013 21:43:00 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBH19038; Thu, 12 Dec 2013 05:42:53 +0000 (GMT)
Received: from LHREML405-HUB.china.huawei.com (10.201.5.242) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 05:42:40 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 05:42:52 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Thu, 12 Dec 2013 13:42:47 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [core] Invitation to New Non-WG Mailing List: Authentication and Authorization for Constrained Environments (ace)
Thread-Index: AQHO9n+6aRw4+VlebU6uU8o/686UippQDGeQ
Date: Thu, 12 Dec 2013 05:42:47 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2E6E@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Cc: Rene Struik <rstruik.ext@gmail.com>
Subject: [Ace] Fw: [core] Invitation to New Non-WG Mailing List: Authentication and Authorization for Constrained Environments (ace)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 05:43:04 -0000

SSBmb3J3YXJkIHRoaXMgZW1haWwgdG8gYWNlIG1haWxpbmcgbGlzdC4NCg0KSXQgd2lsbCBiZSBi
ZXR0ZXIgdG8gZGlzY3VzcyBpdCBpbiBhY2UuDQoNCkBSZW5lLCBwbGVhc2Ugam9pbiBhY2UgbWFp
bGluZyBsaXN0Lg0KDQpUaGFua3MsDQpLaW5kIFJlZ2FyZHMNCktlcGVuZw0KDQotLS0tLdPKvP7U
rbz+LS0tLS0NCreivP7IyzogY29yZSBbbWFpbHRvOmNvcmUtYm91bmNlc0BpZXRmLm9yZ10gtPqx
7SBSZW5lIFN0cnVpaw0Kt6LLzcqxvOQ6IDIwMTPE6jEy1MIxMcjVIDIyOjQ1DQrK1bz+yMs6IFN0
ZWZhbmllIEdlcmRlczsgY29yZUBpZXRmLm9yZw0Ks63LzTogc2FhZ0BpZXRmLm9yZzsgZHRscy1p
b3RAaWV0Zi5vcmc7IGpvc2VAaWV0Zi5vcmc7IG9hdXRoQGlldGYub3JnDQrW98ziOiBSZTogW2Nv
cmVdIEludml0YXRpb24gdG8gTmV3IE5vbi1XRyBNYWlsaW5nIExpc3Q6IEF1dGhlbnRpY2F0aW9u
IGFuZCBBdXRob3JpemF0aW9uIGZvciBDb25zdHJhaW5lZCBFbnZpcm9ubWVudHMgKGFjZSkNCg0K
W2Fwb2xvZ2llcyBmb3IgcmVwbHlpbmcgdG8gYWxsIHRoZSBJRVRGIGxpc3RzIGluIHRoZSBvcmln
aW5hbCBjY10NCg0KRGVhciBjb2xsZWFndWVzOg0KDQpJIGhhdmUgc29tZSBpbml0aWFsIGZlZWRi
YWNrIG9uIHRoZSBwb3RlbnRpYWwgZHJhZnQgY2hhcnRlci4NCg0KSSBiZWxpZXZlIGl0IGlzIHJl
YWxseSBwcmVtYXR1cmUgdG8gd3JpdGUgcG90ZW50aWFsIHBvaW50IHNvbHV0aW9ucyBpbnRvIGEg
ZHJhZnQgY2hhcnRlciwgaW4gY2FzdSBkZWZpbml0aW9uIG9mIGEgbGVzcyBjb25zdHJhaW5lZCBk
ZXZpY2UgdGhhdCBjYW4gYmUgdXNlZCB0byBvdXRzb3VyY2UgY29tcHV0YXRpb25hbCwgc3RvcmFn
ZSwgb3IgbWFuYWdlbWVudCBmdW5jdGlvbmFsaXR5IHRvLiAoRG9lcyB0aGlzIGltcGx5IG9uZSBl
bnZpc2lvbnMgdG8gaGF2ZSB0byBidXkgYSBzZXBhcmF0ZSBib3gvc2luZ2xlIHBvaW50IG9mIGZh
aWx1cmUgdG8gdGFrZSBvbiB0aGlzIHRhc2s/KSBJdCB3b3VsZCBtYWtlIG11Y2ggbW9yZSBzZW5z
ZSB0byBsb29rIGludG8gdGhpcyBwcm9ibGVtIHNwYWNlIGluIHRlcm1zIG9mIHJlcXVpcmVtZW50
cyBmaXJzdCwgd2l0aCBhbiBleWUgdG93YXJkcyBzY2FsYWJpbGl0eSB0b3dhcmRzIGJpbGxpb24r
IGRldmljZXMuIFRoaXMgZG9lcyBub3QgcHJlY2x1ZGUgdGhpcyBwb3RlbnRpYWwgc29sdXRpb24g
ZGlyZWN0aW9uLCBidXQgcXVlc3Rpb25zIGFzIHRvIHdoYXQgdGhpcyBlbnRhaWxzIGluIHRlcm1z
IG9mIHVzYWJpbGl0eSwgc2NhbGFiaWxpdHksIGFuZCBjb21tdW5pY2F0aW9ucyBpbXBhY3QgbmVl
ZCB0byBiZSBjbGVhciBmaXJzdC4gVGhpcyBpcyBhbiBhbWJpdGlvdXMgdW5kZXJ0YWtpbmcgYW5k
IG1hbnkgZWZmb3J0cyBpbiB0aGUgcGFzdCBoYXZlIGJlZW4gZmFyIGxlc3Mgc3VjY2Vzc2Z1bCB0
aGFuIGluaXRpYWxseSB0aG91Z2h0LiBUaGVyZSBpcyBhbHNvIGFuIHVuZGVyY3VycmVudCBpbiB0
aGUgZHJhZnQgY2hhcnRlciB0ZXh0IHRoYXQgdGhlcmUgaXMgYSBuZWVkIGZvciBkaWZmZXJlbnQg
ImRldmljZSB0eXBlcyIsIHdoaWNoIGlzIG5vdCBhIHByaW9yaSBjbGVhci4gVG8gcmVhbGl6ZSB0
aGUgZnVsbCBwb3RlbnRpYWwgb2YgY29uc3RyYWluZWQgbmV0d29ya3MsIG9uZSBzaG91bGQgcmVm
bGUhDQpjdCB1cG9uICINCiB0cnVzdCIgZW5kb3dlZCB1cG9uIHNpbmdsZSBub2Rlcywgb2Ygd2hh
dGV2ZXIgdHlwZSwgYW5kIGNvbnNpZGVyIGxpbWl0aW5nIHRoZSBpbXBhY3Qgb2YgdmlvbGF0aW9u
IG9mIHRoaXMgdHJ1c3QsIHNob3VsZCB0aGlzIG9jY3VyLCBhcyBhbiBleHBsaWNpdCBkZXNpZ24g
Y3JpdGVyaXVtLg0KDQpJbiB0aGUgZW5kLCB0aGlzIG1heSBiZSBhbiB1bmRlcnRha2luZyB0aGF0
IHdvdWxkIGJlIHN1aXRhYmxlIGFzIGFuIElBQiB3b3JrIGl0ZW0sIGNvbnNpZGVyaW5nIHBvdGVu
dGlhbCBzY29wZS4NCg0KQmVzdCByZWdhcmRzLCBSZW5lDQoNCj09DQoNClRvIGFjaGlldmUgdGhp
cywgQUNFIHdpbGwgYmUgYWJsZSB0byBlbXBsb3kgYW4gYXJjaGl0ZWN0dXJlIHdpdGggb25lIG9y
IG1vcmUgdHJ1c3RlZCBsZXNzLWNvbnN0cmFpbmVkIGRldmljZXMgd2hpY2ggd2lsbCByZWxpZXZl
IHRoZSBjb25zdHJhaW5lZCBub2RlcyBmcm9tIGNvbXBsZXggc2VjdXJpdHkgcmVsYXRlZCB0YXNr
cyAoZS5nLiBtYW5hZ2luZyBhdXRob3JpemF0aW9uIHBvbGljaWVzIGFuZCBhIGxhcmdlIG51bWJl
ciBvZiBrZXlzKS4gQUNFIHdpbGwgdXNlIENvQVAgYW5kIGVtcGxveSBzZWN1cml0eSBwcm9wZXJ0
aWVzIG9mIERUTFMgd2hlbmV2ZXIgcG9zc2libGUuDQoNCg0KDQoNCk9uIDEyLzExLzIwMTMgODo0
NiBBTSwgU3RlZmFuaWUgR2VyZGVzIHdyb3RlOg0KPiBIaSBldmVyeWJvZHksDQo+DQo+IEFzIGEg
cmVzdWx0IG9mIGRpc2N1c3Npb25zIGluIHRoZSBDb1JFIFdHIGluIEJlcmxpbiBhbmQgVmFuY291
dmVyIHRoZSANCj4gbmV3IG5vbi1XRyBtYWlsaW5nIGxpc3QgQXV0aGVudGljYXRpb24gYW5kIEF1
dGhvcml6YXRpb24gZm9yIA0KPiBDb25zdHJhaW5lZCBFbnZpcm9ubWVudHMgKGFjZSkgd2FzIGNy
ZWF0ZWQuDQo+DQo+IFRoZSBwdXJwb3NlIG9mIHRoaXMgbGlzdCBpcyB0byBvcmdhbml6ZSBpbnRl
cmVzdCBpbiBhIGdyb3VwIHRvIGRlZmluZSANCj4gdGhlIGNoYXJ0ZXIgZm9yIHdvcmsgb24gQXV0
aGVudGljYXRpb24gYW5kIEF1dGhvcml6YXRpb24gZm9yIA0KPiBDb25zdHJhaW5lZCBFbnZpcm9u
bWVudHMuDQo+DQo+IE91ciBtYWlsaW5nIGxpc3QgY2FuIGJlIGZvdW5kIGF0ICgxKSwgZXhpc3Rp
bmcgd29yayBjYW4gYmUgZm91bmQgYXQgDQo+ICgyKSwgYW5kIHRoZSBkcmFmdCBjaGFydGVyIGNh
biBiZSBmb3VuZCBhdCAoMykuDQo+DQo+IFBsZWFzZSBmZWVsIHdlbGNvbWUgdG8gam9pbiB0aGUg
bGlzdCBhbmQgcHJvdmlkZSB5b3VyIGZlZWRiYWNrIQ0KPg0KPiBUaGFua3MsDQo+DQo+IEtpbmQg
UmVnYXJkcw0KPiBLZXBlbmcgJiBTdGVmYW5pZQ0KPg0KPg0KPiAoMSlNYWlsaW5nIExpc3QNCj4N
Cj4gaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5mby9hY2UNCj4NCj4gKDIpRXhp
c3Rpbmcgd29yazoNCj4NCj4gVXNlIENhc2VzOg0KPiBodHRwOi8vdG9vbHMuaWV0Zi5vcmcvaWQv
ZHJhZnQtZ2FyY2lhLWNvcmUtc2VjdXJpdHkNCj4gaHR0cDovL3Rvb2xzLmlldGYub3JnL2lkL2Ry
YWZ0LWdyZWV2ZW5ib3NjaC1jb3JlLWF1dGhyZXENCj4gaHR0cDovL3Rvb2xzLmlldGYub3JnL2lk
L2RyYWZ0LXNlaXR6LWNvcmUtc2VjLXVzZWNhc2VzDQo+DQo+IFNvbHV0aW9ucw0KPiBodHRwOi8v
dG9vbHMuaWV0Zi5vcmcvaWQvZHJhZnQtZ2VyZGVzLWNvcmUtZGNhZi1hdXRob3JpemUNCj4gaHR0
cDovL3Rvb2xzLmlldGYub3JnL2lkL2RyYWZ0LWthbmctY29yZS1zZWN1cmUtcmVjb25maWd1cmF0
aW9uDQo+IGh0dHA6Ly90b29scy5pZXRmLm9yZy9pZC9kcmFmdC1zZWxhbmRlci1jb3JlLWFjY2Vz
cy1jb250cm9sDQo+IGh0dHA6Ly90b29scy5pZXRmLm9yZy9pZC9kcmFmdC16aHUtY29yZS1ncm91
cGF1dGgNCj4gaHR0cDovL3Rvb2xzLmlldGYub3JnL2lkL2RyYWZ0LXBwb3JhbWJhLWR0bHMtY2Vy
dGtleQ0KPiBodHRwOi8vdG9vbHMuaWV0Zi5vcmcvaWQvZHJhZnQtc2NobWl0dC10d28td2F5LWF1
dGhlbnRpY2F0aW9uLWZvci1pb3QNCj4gaHR0cDovL3Rvb2xzLmlldGYub3JnL2lkL2RyYWZ0LXNl
aXR6LWNvcmUtc2VjdXJpdHktbW9kZXMNCj4NCj4gKDMpRHJhZnQgQ2hhcnRlciAtIEF1dGhlbnRp
Y2F0aW9uIGFuZCBBdXRob3JpemF0aW9uIGZvciBDb25zdHJhaW5lZCANCj4gRW52aXJvbm1lbnQg
KEFDRSkNCj4NCj4gVGhlIENvQVAgKENvbnN0cmFpbmVkIEFwcGxpY2F0aW9uIFByb3RvY29sKSBp
cyBhIGxpZ2h0LXdlaWdodCANCj4gYXBwbGljYXRpb24gbGF5ZXIgcHJvdG9jb2wsIGVzcGVjaWFs
bHkgc3VpdGFibGUgZm9yIGFwcGxpY2F0aW9ucyBzdWNoIA0KPiBhcyBzbWFydCBlbmVyZ3ksIHNt
YXJ0IGhvbWUsIGJ1aWxkaW5nIGF1dG9tYXRpb24sIHJlbW90ZSBwYXRpZW50IA0KPiBtb25pdG9y
aW5nIGV0Yy4gRHVlIHRvIHRoZSBuYXR1cmUgb2YgdGhlc2UgYXBwbGljYXRpb25zLCBpbmNsdWRp
bmcgYSANCj4gY3JpdGljYWwsIHVuYXR0ZW5kZWQgaW5mcmFzdHJ1Y3R1cmUgYW5kIHVzYWdlIGlu
IHRoZSBwZXJzb25hbCBzcGhlcmUsIA0KPiBzZWN1cml0eSBhbmQgcHJpdmFjeSBwcm90ZWN0aW9u
IGFyZSBjcml0aWNhbCBjb21wb25lbnRzLg0KPg0KPiBDdXJyZW50bHksIGEgcHJvYmxlbSB3aXRo
IGNvbnN0cmFpbmVkIGRldmljZXMgaXMgdGhlIHJlYWxpemF0aW9uIG9mIA0KPiBzdWNoIHNlY3Vy
ZSBjb21tdW5pY2F0aW9uLiBUaGUgZGV2aWNlcyBvbmx5IGhhdmUgbGltaXRlZCByZXNvdXJjZXMg
DQo+IHN1Y2ggYXMgbWVtb3J5LCBzdG9yYWdlIGFuZCB0cmFuc21pc3Npb24gY2FwYWNpdHkuIFRo
ZXNlIGNvbnN0cmFpbnRzIA0KPiBzZXZlcmVseSBsaW1pdCB0aGUgc2VjdXJpdHkgZnVuY3Rpb25z
IGFuZCBjb21tdW5pY2F0aW9ucyB0aGUgZGV2aWNlIGNhbiBwZXJmb3JtLg0KPiBNaXNzaW5nIGZ1
bmN0aW9uYWxpdHkgaW5jbHVkZXMgYXV0aGVudGljYXRpb24sIHdoaWNoIHByb3ZpZGVzIHRydXN0
IA0KPiBhbmQgZW5zdXJlcyBhbiBlbnRpdHkgaXMgd2hvIGl0IHNheXMgaXQgaXMsIGFuZCBhdXRo
b3JpemF0aW9uLCB3aGljaCANCj4gZGVmaW5lcyBhbmQgZW5mb3JjZXMgYWNjZXNzIHJpZ2h0cyBm
b3IgZGlmZmVyZW50IGNsaWVudHMuDQo+DQo+IFRoZSBBQ0UgV0cgZm9jdXNlcyBvbiBwcm92aWRp
bmcgY29uc3RyYWluZWQgZGV2aWNlcyB3aXRoIHRoZSBuZWNlc3NhcnkgDQo+IHByZXJlcXVpc2l0
ZXMgdG8gdXNlIFJFU1Qgb3BlcmF0aW9ucyBpbiBhIHNlY3VyZSB3YXkuIENvbnN0cmFpbmVkIA0K
PiBkZXZpY2VzIHdpbGwgdGh1cyBiZSBlbmFibGVkIHRvIGF1dGhlbnRpY2F0ZSBjb21tdW5pY2F0
aW9ucyBmcm9tIG90aGVyIA0KPiAoY29uc3RyYWluZWQgb3IgbGVzcy1jb25zdHJhaW5lZCkgZGV2
aWNlcywgdG8gY29tbXVuaWNhdGUgc2VjdXJlbHkgDQo+IHdpdGggdGhlbSBhbmQgdG8gdmVyaWZ5
IHRoZWlyIGluZGl2aWR1YWwgYXV0aG9yaXphdGlvbiB0byBhY2Nlc3MgDQo+IHNwZWNpZmljIHJl
c291cmNlcy4gVG8gYWNoaWV2ZSB0aGlzLCBBQ0Ugd2lsbCBiZSBhYmxlIHRvIGVtcGxveSBhbiAN
Cj4gYXJjaGl0ZWN0dXJlIHdpdGggb25lIG9yIG1vcmUgdHJ1c3RlZCBsZXNzLWNvbnN0cmFpbmVk
IGRldmljZXMgd2hpY2ggDQo+IHdpbGwgcmVsaWV2ZSB0aGUgY29uc3RyYWluZWQgbm9kZXMgZnJv
bSBjb21wbGV4IHNlY3VyaXR5IHJlbGF0ZWQgdGFza3MgDQo+IChlLmcuIG1hbmFnaW5nIGF1dGhv
cml6YXRpb24gcG9saWNpZXMgYW5kIGEgbGFyZ2UgbnVtYmVyIG9mIGtleXMpLiBBQ0UgDQo+IHdp
bGwgdXNlIENvQVAgYW5kIGVtcGxveSBzZWN1cml0eSBwcm9wZXJ0aWVzIG9mIERUTFMgd2hlbmV2
ZXIgcG9zc2libGUuDQo+DQo+IFRoZSBBQ0UgV0cgaGFzIHRoZSBmb2xsb3dpbmcgdGFza3M6DQo+
IC0gRG9jdW1lbnQgdGhlIHVzZSBjYXNlcyBhbmQgaGlnaC1sZXZlbCByZXF1aXJlbWVudHMgZm9y
IHNlY3VyZWQgDQo+IGNvbW11bmljYXRpb24gYmV0d2VlbiBjb25zdHJhaW5lZCBkZXZpY2VzLg0K
PiAtIERlZmluZSBjZXJ0aWZpY2F0ZSBwcm9maWxpbmcgKHdoYXQga2luZHMgb2YgY2VydGlmaWNh
dGVzIGFuZCB3aGljaCANCj4gYXR0cmlidXRlcyBhcmUgdG8gYmUgdXNlZCkuDQo+IC0gRGVmaW5l
IGEgbWVjaGFuaXNtIGZvciBhdXRoZW50aWNhdGVkIGFuZCBwcm90ZWN0ZWQgdHJhbnNmZXIgb2Yg
DQo+IGF1dGhvcml6YXRpb24gaW5mb3JtYXRpb24gc3VpdGFibGUgZm9yIGNvbnN0cmFpbmVkIGRl
dmljZSB0byANCj4gY29uc3RyYWluZWQgZGV2aWNlIGNvbW11bmljYXRpb24uDQo+IC0gRGVmaW5l
IGFuIGFjY2VzcyB0aWNrZXQgYW5kIGF1dGhvcml6YXRpb24gaW5mb3JtYXRpb24gZm9ybWF0IA0K
PiBzdWl0YWJsZSBmb3IgY29uc3RyYWluZWQgZGV2aWNlcy4NCj4gLSBEZWZpbmUgYm9vdHN0cmFw
cGluZyBmb3IgYXV0aG9yaXphdGlvbiBpbmZvcm1hdGlvbiB1c2luZyB0aGUgDQo+IFJlc291cmNl
IERpcmVjdG9yeS4NCg0KDQotLQ0KZW1haWw6IHJzdHJ1aWsuZXh0QGdtYWlsLmNvbSB8IFNreXBl
OiByc3RydWlrDQpjZWxsOiArMSAoNjQ3KSA4NjctNTY1OCB8IFVTOiArMSAoNDE1KSA2OTAtNzM2
Mw0KDQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fDQpj
b3JlIG1haWxpbmcgbGlzdA0KY29yZUBpZXRmLm9yZw0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFp
bG1hbi9saXN0aW5mby9jb3JlDQo=

From likepeng@huawei.com  Wed Dec 11 22:36:44 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E9BE1AE158 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 22:36:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.202
X-Spam-Level: 
X-Spam-Status: No, score=-6.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_INVITATION=-2, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7-ayBvsg8ILZ for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 22:36:42 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 23CD51AE125 for <ace@ietf.org>; Wed, 11 Dec 2013 22:36:40 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id AYX17484; Thu, 12 Dec 2013 06:36:34 +0000 (GMT)
Received: from LHREML401-HUB.china.huawei.com (10.201.5.240) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 06:36:17 +0000
Received: from SZXEMA403-HUB.china.huawei.com (10.82.72.35) by lhreml401-hub.china.huawei.com (10.201.5.240) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 06:36:29 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA403-HUB.china.huawei.com ([10.82.72.35]) with mapi id 14.03.0158.001; Thu, 12 Dec 2013 14:36:23 +0800
From: Likepeng <likepeng@huawei.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Draft ACE Charter
Thread-Index: Ac72WVT850tgXXxoRT6JXoOa8NAUkP//sjaA//6J0CA=
Date: Thu, 12 Dec 2013 06:36:22 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2EA3@SZXEMA501-MBS.china.huawei.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <52A86985.50703@sics.se>
In-Reply-To: <52A86985.50703@sics.se>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 06:36:44 -0000

SGkgTHVkd2lnLA0KDQpUaGFua3MgZm9yIHlvdXIgZmVlZGJhY2suDQoNCj4+IE1pc3NpbmcgZnVu
Y3Rpb25hbGl0eSBpbmNsdWRlcyBhdXRoZW50aWNhdGlvbiwNCg0KPkkgd291bGQgY2hhbGxlbmdl
IHRoaXMgc3RhdGVtZW50LCB0aGVyZSBpcyBEVExTIGFuZCBpdCBjYW4gcHJvdmlkZSBib3RoIGNs
aWVudCBhbmQgc2VydmVyIGF1dGhlbnRpY2F0aW9uIGRlcGVuZGluZyBvbiB0aGUgbW9kZSB0aGF0
IGlzIHVzZWQuIEV2ZW4gaWYgeW91IGNsYWltIHRoYXQgRFRMUyBpc24ndCB1c2FibGUgb24gY29u
c3RyYWluZWQgZGV2aWNlcyBzaW5jZSBpdCBpcyB0b28gaGVhdnl3ZWlnaHQgKG5vdGUgdGhhdCBJ
IGRvbid0IGNsYWltIHRoaXMsIGJ1dCBzb21lb25lIG1pZ2h0KSwgcHJvZmlsaW5nIERUTFMgdG8g
Y29uc3RyYWluZWQgZGV2aWNlcyBpcyBjbGVhcmx5IHdvcmsgdGhhdCBESUNFIGlzIGNvdmVyaW5n
Lg0KDQpXZSBjaGFuZ2UgdGhlIHN0YXRlbWVudCB0byB0aGUgZm9sbG93aW5nOg0KV2hpbGUgYXV0
aGVudGljYXRpb24gaXMgd2VsbCB1bmRlcnN0b29kLCBhdCBsZWFzdCBmb3IgY29tbXVuaWNhdGlv
biBzZWN1cml0eSwgdGhlcmUgYXJlIG9ubHkgaW5zdWZmaWNpZW50IG1lYW5zIGZvciBhdXRob3Jp
emF0aW9uLiBBdXRoZW50aWNhdGlvbiBpcyBjb25zaWRlcmVkIGluIHRoaXMgY29udGV4dCBhcyBp
dCBpcyBuZWVkZWQgYXMgYSBwcmVyZXF1aXNpdGUgdG8gcGVyZm9ybWluZyBhdXRob3JpemF0aW9u
LCBpbmNsdWRpbmcgdGhlIGF1dGhvcml6YXRpb24gdG8gY2hhbmdlIHRoZSBhdXRob3JpemF0aW9u
IHN0YXRlLg0KDQo+V2h5IHNob3VsZCB3ZSBsaW1pdCBvdXJzZWx2ZXMgdG8gdGhpcyBhcHByb2Fj
aD8gVGhlcmUgbWlnaHQgdmVyeSB3ZWxsIGJlIHNvbHV0aW9ucywgdGhhdCBkb24ndCByZXF1aXJl
IGEgImJpZyBicm90aGVyIi10aGlyZC1wYXJ0eSBhbmQgdGhhdCBzdGlsbCBjb3ZlciBzZXZlcmFs
IHJlbGV2YW50IHVzZSBjYXNlcy4NCg0KQXMgZXhwbGFpbmVkIGJ5IENhcnN0ZW4sIHRoZSBtYWlu
IGludGVudGlvbiBpcyB0byAqZW5hYmxlKiB0aGUgdXNlIG9mIGxlc3MtY29uc3RyYWluZWQgZGV2
aWNlcywgbm90IHRvICpyZXF1aXJlKiB0aGVpciB1c2UuDQoNCj5Gb3Igd2hhdCBwdXJwb3NlIGRv
ZXMgQWNlIGludGVuZCB0byB1c2UgdGhlc2UgY2VydHM/IFRoZXkgc2VlbSB0byBjb21lIG91dCBv
ZiBub3doZXJlIGhlcmUuDQoNCldlIGNoYW5nZSB0aGUgc2VudGVuY2UgdG8gdGhlIGZvbGxvd2lu
ZywgdG8gY2xhcmlmeSB0aGUgcHVycG9zZSB0byB1c2UgY2VydGlmaWNhdGVzLg0KDQpGbGVzaCBv
dXQgcHJvZmlsZXMgZm9yIHRoZSBjZXJ0aWZpY2F0ZXMgdGhhdCBhbHJlYWR5IGFyZSBwYXJ0IG9m
IENvQVDigJlzIHNlY3VyaXR5IGFyY2hpdGVjdHVyZSBhcyB3ZWxsIGFzIHBvc3NpYmx5IGZvciBh
bnkgQUNFLXNwZWNpZmljIHVzZSBvZiBjZXJ0aWZpY2F0ZXMuDQoNCj5EbyB3ZSByZWFsbHkgd2Fu
dCB0byBjYWxsIHRob3NlIHRoaW5ncyAndGlja2V0cyc/IEV2ZXJ5b25lIGFuZCB0aGVpciBncmFu
ZG1vdGhlciBhcmUgZ29pbmcgdG8gYXNzdW1lIEFjZSBkb2VzIHNvbWV0aGluZyBha2luIHRvIEtl
cmJlcm9zLg0KPlN0ZWZmYW5pZSBHZXJkZXMsIE9sYWYgQmVyZ21hbm4sIEfDtnJhbiBTZWxhbmRl
ciBhbmQgSSBoYWQgYWdyZWVkIHRvIGNhbGwgdGhvc2UgdGhpbmdzICd0b2tlbnMnIG9yICdhdXRo
b3JpemF0aW9uIHRva2VucycuIFdvdWxkIHRoYXQgYmUgImNvbnNlbnN1c2FibGUiPw0KDQpXZSBj
aGFuZ2UgaXQgdG8gImFjY2VzcyB0b2tlbiIuIFNlZSB0aGUgZm9sbG93aW5nIHNlbnRlbmNlOg0K
LSBEZWZpbmUgYW4gYWNjZXNzIHRva2VuIGFuZCBhdXRob3JpemF0aW9uIGluZm9ybWF0aW9uIGZv
cm1hdCBzdWl0YWJsZSBmb3IgY29uc3RyYWluZWQgZGV2aWNlcy4NCg0KPldoYXQgaWYgdGhlcmUg
aXMgbm8gUmVzb3VyY2UgRGlyZWN0b3J5PyBEb24ndCB3ZSB3YW50IHRvIGRlZmluZSBzZWN1cml0
eSBib290c3RyYXBwaW5nIGZvciBzdWNoIGNhc2VzIHRvbz8NCg0KU2VlIENhcnN0ZW4ncyByZXNw
b25zZSB0byB0aGlzIG9uZS4gV2UgYWRkIHRoZSByZWZlcmVuY2UgdG8gIlJlc291cmNlIERpcmVj
dG9yeSIuIFBsZWFzZSByZWZlciB0byBhIHNlcGFyYXRlIGVtYWlsIGFib3V0IHRoZSB1cGRhdGVk
IGNoYXJ0ZXIuDQoNCj5JdCB3b3VsZCBwcm9iYWJseSBhbHNvIGJlIG9rIHRvIGFubm91bmNlIEFj
ZSBvbiB0aGUgQ29SRSBhbmQgRElDRSBtYWlsaW5nbGlzdHMuDQoNClllcywgaXQgd2FzIGRvbmUu
IFNvcnJ5IGZvciB0aGUgZGVsYXkuDQoNClRoYW5rcywNCktpbmQgUmVnYXJkcw0KS2VwZW5nDQoN
Ci0tLS0t6YKu5Lu25Y6f5Lu2LS0tLS0NCuWPkeS7tuS6ujogQWNlIFttYWlsdG86YWNlLWJvdW5j
ZXNAaWV0Zi5vcmddIOS7o+ihqCBMdWR3aWcgU2VpdHoNCuWPkemAgeaXtumXtDogMjAxM+W5tDEy
5pyIMTHml6UgMjE6MzMNCuaUtuS7tuS6ujogYWNlQGlldGYub3JnDQrkuLvpopg6IFJlOiBbQWNl
XSBEcmFmdCBBQ0UgQ2hhcnRlcg0KDQpPbiAxMi8xMS8yMDEzIDExOjExIEFNLCBMaWtlcGVuZyB3
cm90ZToNCj4gSGVsbG8gYWxsLA0KPg0KPiBXZWxjb21lIHRvIHRoZSBsaXN0IQ0KPg0KPiBUaGUg
cHVycG9zZSBvZiB0aGlzIGxpc3QgaXMgdG8gb3JnYW5pemUgaW50ZXJlc3QgaW4gYSBncm91cCB0
byBkZWZpbmUgDQo+IHRoZSBjaGFydGVyIGZvciB3b3JrIG9uIEF1dGhlbnRpY2F0aW9uIGFuZCBB
dXRob3JpemF0aW9uIGZvciANCj4gQ29uc3RyYWluZWQgRW52aXJvbm1lbnRzLg0KPg0KPiBPdXIg
bWFpbGluZyBsaXN0IGNhbiBiZSBmb3VuZCBhdCAoMSksIGV4aXN0aW5nIHdvcmsgY2FuIGJlIGZv
dW5kIGF0IA0KPiAoMiksIGFuZCBkcmFmdCBjaGFydGVyIGNhbiBiZSBmb3VuZCBhdCAoMykuDQo+
DQo+IFdlIHdlbGNvbWUgeW91ciBmZWVkYmFjayENCj4NCg0KQ29tbWVudHMgaW5saW5lLg0KDQo+
ICgzKURyYWZ0IENoYXJ0ZXIg4oCTIEF1dGhlbnRpY2F0aW9uIGFuZCBBdXRob3JpemF0aW9uIGZv
ciBDb25zdHJhaW5lZCANCj4gRW52aXJvbm1lbnQgKEFDRSkgWy4uLl0gQ3VycmVudGx5LCBhIHBy
b2JsZW0gd2l0aCBjb25zdHJhaW5lZCBkZXZpY2VzIA0KPiBpcyB0aGUgcmVhbGl6YXRpb24gb2Yg
c3VjaCBzZWN1cmUgY29tbXVuaWNhdGlvbi4gVGhlIGRldmljZXMgb25seSBoYXZlIA0KPiBsaW1p
dGVkIHJlc291cmNlcyBzdWNoIGFzIG1lbW9yeSwgc3RvcmFnZSBhbmQgdHJhbnNtaXNzaW9uIGNh
cGFjaXR5LiANCj4gVGhlc2UgY29uc3RyYWludHMgc2V2ZXJlbHkgbGltaXQgdGhlIHNlY3VyaXR5
IGZ1bmN0aW9ucyBhbmQgDQo+IGNvbW11bmljYXRpb25zIHRoZSBkZXZpY2UgY2FuIHBlcmZvcm0u
DQo+IE1pc3NpbmcgZnVuY3Rpb25hbGl0eSBpbmNsdWRlcyBhdXRoZW50aWNhdGlvbiwNCg0KSSB3
b3VsZCBjaGFsbGVuZ2UgdGhpcyBzdGF0ZW1lbnQsIHRoZXJlIGlzIERUTFMgYW5kIGl0IGNhbiBw
cm92aWRlIGJvdGggY2xpZW50IGFuZCBzZXJ2ZXIgYXV0aGVudGljYXRpb24gZGVwZW5kaW5nIG9u
IHRoZSBtb2RlIHRoYXQgaXMgdXNlZC4gDQpFdmVuIGlmIHlvdSBjbGFpbSB0aGF0IERUTFMgaXNu
J3QgdXNhYmxlIG9uIGNvbnN0cmFpbmVkIGRldmljZXMgc2luY2UgaXQgaXMgdG9vIGhlYXZ5d2Vp
Z2h0IChub3RlIHRoYXQgSSBkb24ndCBjbGFpbSB0aGlzLCBidXQgc29tZW9uZSBtaWdodCksIHBy
b2ZpbGluZyBEVExTIHRvIGNvbnN0cmFpbmVkIGRldmljZXMgaXMgY2xlYXJseSB3b3JrIHRoYXQg
RElDRSBpcyBjb3ZlcmluZy4NCg0KPlsuLi5dDQo+IFRvIGFjaGlldmUgdGhpcywgQUNFIHdpbGwg
YmUgYWJsZSB0byBlbXBsb3kgYW4gYXJjaGl0ZWN0dXJlICB3aXRoIG9uZSANCj5vciBtb3JlIHRy
dXN0ZWQgbGVzcy1jb25zdHJhaW5lZCBkZXZpY2VzIHdoaWNoIHdpbGwgcmVsaWV2ZSB0aGUgIA0K
PmNvbnN0cmFpbmVkIG5vZGVzIGZyb20gY29tcGxleCBzZWN1cml0eSByZWxhdGVkIHRhc2tzIChl
LmcuIG1hbmFnaW5nICANCj5hdXRob3JpemF0aW9uIHBvbGljaWVzIGFuZCBhIGxhcmdlIG51bWJl
ciBvZiBrZXlzKS4NCg0KV2h5IHNob3VsZCB3ZSBsaW1pdCBvdXJzZWx2ZXMgdG8gdGhpcyBhcHBy
b2FjaD8gVGhlcmUgbWlnaHQgdmVyeSB3ZWxsIGJlIHNvbHV0aW9ucywgdGhhdCBkb24ndCByZXF1
aXJlIGEgImJpZyBicm90aGVyIi10aGlyZC1wYXJ0eSBhbmQgdGhhdCBzdGlsbCBjb3ZlciBzZXZl
cmFsIHJlbGV2YW50IHVzZSBjYXNlcy4NCg0KPiBbLi4uXQ0KPiBUaGUgQUNFIFdHIGhhcyB0aGUg
Zm9sbG93aW5nIHRhc2tzOg0KPg0KPiAtIERvY3VtZW50IHRoZSB1c2UgY2FzZXMgYW5kIGhpZ2gt
bGV2ZWwgcmVxdWlyZW1lbnRzIGZvciBzZWN1cmVkIA0KPiBjb21tdW5pY2F0aW9uIGJldHdlZW4g
Y29uc3RyYWluZWQgZGV2aWNlcy4NCj4NCkl0J3MgcHJvYmFibHkganVzdCB0aGUgd29yZGluZywg
YnV0IHRvIG1lIHRoaXMgc291bmRzIGxpa2UgQWNlIHdvdWxkIG9ubHkgbG9vayBhdCBDb21tU2Vj
IHVzZSBjYXNlcyBhbmQgcmVxdWlyZW1lbnRzLg0KDQo+IC0gRGVmaW5lIGNlcnRpZmljYXRlIHBy
b2ZpbGluZyAod2hhdCBraW5kcyBvZiBjZXJ0aWZpY2F0ZXMgYW5kIHdoaWNoIA0KPiBhdHRyaWJ1
dGVzIGFyZSB0byBiZSB1c2VkKS4NCkZvciB3aGF0IHB1cnBvc2UgZG9lcyBBY2UgaW50ZW5kIHRv
IHVzZSB0aGVzZSBjZXJ0cz8gVGhleSBzZWVtIHRvIGNvbWUgb3V0IG9mIG5vd2hlcmUgaGVyZS4N
Cg0KPiBbLi4uXQ0KPiAtIERlZmluZSBhbiBhY2Nlc3MgdGlja2V0IGFuZCBhdXRob3JpemF0aW9u
IGluZm9ybWF0aW9uIGZvcm1hdCANCj4gc3VpdGFibGUgZm9yIGNvbnN0cmFpbmVkIGRldmljZXMu
DQpEbyB3ZSByZWFsbHkgd2FudCB0byBjYWxsIHRob3NlIHRoaW5ncyAndGlja2V0cyc/IEV2ZXJ5
b25lIGFuZCB0aGVpciBncmFuZG1vdGhlciBhcmUgZ29pbmcgdG8gYXNzdW1lIEFjZSBkb2VzIHNv
bWV0aGluZyBha2luIHRvIEtlcmJlcm9zLg0KDQpTdGVmZmFuaWUgR2VyZGVzLCBPbGFmIEJlcmdt
YW5uLCBHw7ZyYW4gU2VsYW5kZXIgYW5kIEkgaGFkIGFncmVlZCB0byBjYWxsIHRob3NlIHRoaW5n
cyAndG9rZW5zJyBvciAnYXV0aG9yaXphdGlvbiB0b2tlbnMnLiBXb3VsZCB0aGF0IGJlICJjb25z
ZW5zdXNhYmxlIj8NCg0KPg0KPiAtIERlZmluZSBib290c3RyYXBwaW5nIGZvciBhdXRob3JpemF0
aW9uIGluZm9ybWF0aW9uIHVzaW5nIHRoZSBSZXNvdXJjZQ0KPiBEaXJlY3RvcnkuDQo+DQpXaGF0
IGlmIHRoZXJlIGlzIG5vIFJlc291cmNlIERpcmVjdG9yeT8gRG9uJ3Qgd2Ugd2FudCB0byBkZWZp
bmUgc2VjdXJpdHkgDQpib290c3RyYXBwaW5nIGZvciBzdWNoIGNhc2VzIHRvbz8NCg0KDQovTHVk
d2lnDQoNCg0KUFM6IEkgd291bGQgaGF2ZSBhcHByZWNpYXRlZCB0byBnZXQgYW4gaW52aXRhdGlv
biB0byB0aGlzIGxpc3QsIGFuZCBJIA0KZ3Vlc3MgdGhlIG90aGVyIHBlb3BsZSB3aG8gYXV0aG9y
ZWQgdGhlIGRyYWZ0cyBsaXN0ZWQgYXMgIkV4aXN0aW5nIHdvcmsiIA0Kd291bGQgZG8gc28gdG9v
LiBJdCB3b3VsZCBwcm9iYWJseSBhbHNvIGJlIG9rIHRvIGFubm91bmNlIEFjZSBvbiB0aGUgDQpD
b1JFIGFuZCBESUNFIG1haWxpbmdsaXN0cy4NCg0KDQotLSANCkx1ZHdpZyBTZWl0eiwgUGhEDQpT
SUNTIFN3ZWRpc2ggSUNUIEFCDQpJZGVvbiBTY2llbmNlIFBhcmsNCkJ1aWxkaW5nIEJldGEgMg0K
U2NoZWVsZXbDpGdlbiAxNw0KU0UtMjIzIDcwIEx1bmQNCg0KUGhvbmUgKzQ2KDApNzAtMzQ5IDky
IDUxDQpodHRwOi8vd3d3LnNpY3Muc2UNCg0K

From likepeng@huawei.com  Wed Dec 11 23:15:09 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CDE1E1AE1BD for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:15:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.413
X-Spam-Level: 
X-Spam-Status: No, score=-1.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B3YcvFDNOv4F for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:15:08 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 064011AE190 for <ace@ietf.org>; Wed, 11 Dec 2013 23:15:06 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBH25928; Thu, 12 Dec 2013 07:15:00 +0000 (GMT)
Received: from LHREML406-HUB.china.huawei.com (10.201.5.243) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 07:14:47 +0000
Received: from SZXEMA405-HUB.china.huawei.com (10.82.72.37) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 07:14:59 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA405-HUB.china.huawei.com ([10.82.72.37]) with mapi id 14.03.0158.001; Thu, 12 Dec 2013 15:14:56 +0800
From: Likepeng <likepeng@huawei.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Purpose of this list
Thread-Index: AQHO9nbucosHSyuDSE+iKeT8DDG8DppQHJuA
Date: Thu, 12 Dec 2013 07:14:55 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2ED5@SZXEMA501-MBS.china.huawei.com>
References: <069d01cef5f4$aea66990$0bf33cb0$@olddog.co.uk> <52A7A626.5070901@tzi.de> <8995.1386769359@sandelman.ca>
In-Reply-To: <8995.1386769359@sandelman.ca>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: Re: [Ace] Purpose of this list
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 07:15:10 -0000

SGkgTWljaGFlbCwNCg0KPldoYXQgYWJvdXQgU09MQUNFPw0KDQpUaGVyZSBpcyBhIG1haWxpbmcg
bGlzdCBmb3IgdGhpcy4gVGhlIGxhc3QgZW1haWwgaW4gdGhpcyBtYWlsaW5nIGxpc3QgaXMgdGhp
cyBvbmU6DQpodHRwOi8vd3d3LmlldGYub3JnL21haWwtYXJjaGl2ZS93ZWIvc29sYWNlL2N1cnJl
bnQvbXNnMDAwNDYuaHRtbA0KDQpJZiBJIHVuZGVyc3RhbmQgY29ycmVjdGx5IGZyb20gdGhlIGRp
c2N1c3Npb24sIHRoZSBncm91cCBpcyBub3Qgc2F0aXNmaWVkIHRvIGNyZWF0ZSBhIElSVEYgZ3Jv
dXAgZm9yIHRoYXQuIEkgdGhpbmsgYWNlIGFjdGl2aXR5IGlzIHBhcnRpYWxseSBiYXNlZCBvbiB0
aGUgcHJldmlvdXMgZGlzY3Vzc2lvbiwgYnV0IHdpdGggYSBmb2N1cyBvbiB0aGUgYXV0aGVudGlj
YXRpb24vYXV0aG9yaXphdGlvbiBwYXJ0Lg0KDQo+SSB0aGluayB0aGF0IHdlIG5lZWQgYSB3b3Jr
c2hvcCwgb25lIHRvIGZvbGxvdyBvbiBmcm9tIHRoZSBwcmUtUGFyaXMgSUVURjgzIHdvcmtzaG9w
LCBidXQgdGhpcyB0aW1lLCB3aXRoIGxlc3MgUFBUIGFuZCBtb3JlIGZvY3VzIG9uIGFkZHJlc3Np
bmcgZW5yb2xsbWVudCBhbmQgYXV0aG9yaXphdGlvbi4NCg0KSSBkb26hr3QgdGhpbmsgd29ya3No
b3AgaGVscHMuIFdlIGhhZCB3b3Jrc2hvcCBiZWZvcmUgaW4gUGFyaXMsIGFuZCB3ZSBoYWQgZ3Jv
dXAgZGlzY3Vzc2lvbiBpbiBCZXJsaW4sIEJhciBCb0YgYW5kIHNldmVyYWwgZ3JvdXAgZGlzY3Vz
c2lvbnMgaW4gVmFuY291dmVyLCBzZXZlcmFsIGRyYWZ0cyBvbiB0aGUgdGFibGUuIFNvIEkgYmVs
aWV2ZSBub3cgaXQgaXMgdGhlIHRpbWUgdG8gdHJ5IHRvIHNldCB1cCBhIG5ldyBXRy4gDQoNCj5J
IHRoaW5rIHRoYXQgd2UgYXJlIGFsbCBpbiB2aW9sZW50IGFncmVlbWVudCBhYm91dCB3aGF0IG5l
ZWRzIHRvIGhhcHBlbiwgYnV0IEkgdGhpbmsgdGhhdCBtYW55IGFyZSBzY2FyZWQgdG8gYWRtaXQg
aXQsIGFuZCB3ZSBuZWVkIGEgdHlnZXJ0ZWFtIHRvIGRvIGEgcHJvdG90eXBlL3NwaWtlIGltcGxl
bWVudGF0aW9uIGluIG9yZGVyIHRvIGJyaW5nIHRoZSBpc3N1ZXMgbW9yZSBjbGVhcmx5IGludG8g
Zm9jdXMuICBUaGF0IGlzLCB0aGlzIGlzIGEgY2FzZSBydW5uaW5nIGNvZGUgZm9sbG93ZWQgYnkg
c29tZSByb3VnaCBjb25zZW5zdXMuDQoNClllcywgaXQgd2lsbCBiZSBnb29kIHRvIGhhdmUgaW1w
bGVtZW50YXRpb25zLg0KDQpUaGFua3MsDQpLaW5kIFJlZ2FyZHMNCktlcGVuZw0KDQotLS0tLdPK
vP7Urbz+LS0tLS0NCreivP7IyzogQWNlIFttYWlsdG86YWNlLWJvdW5jZXNAaWV0Zi5vcmddILT6
se0gTWljaGFlbCBSaWNoYXJkc29uDQq3osvNyrG85DogMjAxM8TqMTLUwjExyNUgMjE6NDMNCsrV
vP7IyzogYWNlQGlldGYub3JnDQrW98ziOiBSZTogW0FjZV0gUHVycG9zZSBvZiB0aGlzIGxpc3QN
Cg0KDQpJIHNlY29uZCBBZHJpYW4ncyBxdWVzdGlvbi9jb25mdXNpb24uDQpXaGF0IGFib3V0IFNP
TEFDRT8gICBNaWNoYWVsIEJlaHJpbmcgaGFzIGEgbG90IG9mIGNvbnRlbnQgdGhhdCBoZSBpcyB0
cnlpbmcNCnRvIGdldCBpbnRvIGhpcyBiZWhyaW5nLWhvbWVuZXQtYm9vdHN0cmFwIGRvY3VtZW50
LCBidXQgcmVhbGx5IGl0IGRvZXMgbm90IGZpdCBpbnRvIGhvbWVuZXQsIGRpY2UsIHJvbGwsIDZ0
aXNjaCwgNmxvLg0KDQpJIHRoaW5rIHRoYXQgd2UgbmVlZCBhIHdvcmtzaG9wLCBvbmUgdG8gZm9s
bG93IG9uIGZyb20gdGhlIHByZS1QYXJpcyBJRVRGODMgd29ya3Nob3AsIGJ1dCB0aGlzIHRpbWUs
IHdpdGggbGVzcyBQUFQgYW5kIG1vcmUgZm9jdXMgb24gYWRkcmVzc2luZyBlbnJvbGxtZW50IGFu
ZCBhdXRob3JpemF0aW9uLg0KDQpJIHRoaW5rIHRoYXQgd2UgYXJlIGFsbCBpbiB2aW9sZW50IGFn
cmVlbWVudCBhYm91dCB3aGF0IG5lZWRzIHRvIGhhcHBlbiwgYnV0IEkgdGhpbmsgdGhhdCBtYW55
IGFyZSBzY2FyZWQgdG8gYWRtaXQgaXQsIGFuZCB3ZSBuZWVkIGEgdHlnZXJ0ZWFtIHRvIGRvIGEg
cHJvdG90eXBlL3NwaWtlIGltcGxlbWVudGF0aW9uIGluIG9yZGVyIHRvIGJyaW5nIHRoZSBpc3N1
ZXMgbW9yZSBjbGVhcmx5IGludG8gZm9jdXMuICBUaGF0IGlzLCB0aGlzIGlzIGEgY2FzZSBydW5u
aW5nIGNvZGUgZm9sbG93ZWQgYnkgc29tZSByb3VnaCBjb25zZW5zdXMuDQoNCi0tDQpNaWNoYWVs
IFJpY2hhcmRzb24gPG1jcitJRVRGQHNhbmRlbG1hbi5jYT4sIFNhbmRlbG1hbiBTb2Z0d2FyZSBX
b3Jrcw0KDQoNCg==

From stokcons@xs4all.nl  Wed Dec 11 23:48:45 2013
Return-Path: <stokcons@xs4all.nl>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EAE3A1ADFD8 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:48:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.194
X-Spam-Level: 
X-Spam-Status: No, score=0.194 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_NL=0.55, HOST_EQ_NL=1.545, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WYG0iITZ12s3 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:48:43 -0800 (PST)
Received: from smtp-vbr10.xs4all.nl (smtp-vbr10.xs4all.nl [194.109.24.30]) by ietfa.amsl.com (Postfix) with ESMTP id 120B51A1F62 for <ace@ietf.org>; Wed, 11 Dec 2013 23:48:42 -0800 (PST)
Received: from roundcube.xs4all.nl (roundcube7.xs4all.net [194.109.20.205]) by smtp-vbr10.xs4all.nl (8.13.8/8.13.8) with ESMTP id rBC7mV73058002; Thu, 12 Dec 2013 08:48:32 +0100 (CET) (envelope-from stokcons@xs4all.nl)
Received: from a82-95-140-48.adsl.xs4all.nl ([82.95.140.48]) by roundcube.xs4all.nl with HTTP (HTTP/1.1 POST); Thu, 12 Dec 2013 08:48:31 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Date: Thu, 12 Dec 2013 08:48:31 +0100
From: peter van der Stok <stokcons@xs4all.nl>
To: ace@ietf.org, bert greevenbosch <bert.greevenbosch@huawei.com>
Organization: vanderstok consultancy
Mail-Reply-To: consultancy@vanderstok.org
In-Reply-To: <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca> <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org> <26190.1386812308@sandelman.ca> <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com>
Message-ID: <161993bf952da3e41a5c4af4842b5057@xs4all.nl>
X-Sender: stokcons@xs4all.nl (1+tYfcOBKcXgF0lZkjX44LcZYCdARVgB)
User-Agent: XS4ALL Webmail
X-Virus-Scanned: by XS4ALL Virus Scanner
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: consultancy@vanderstok.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 07:48:45 -0000

Hi Thomas,

Bert and I started on RESTCONF draft with the subject core management 
interfaces (CoMI).
draft-vanderstok-core-comi-01.
  if I understand you correctly, the draft proposal is a first step to 
your single protocol serving multiple purposes.
After comments by Juergen, we are preparing a second more CBOR, JSON 
focussed version.

Looking forward to your comments,

Peter

Thomas Watteyne schreef op 2013-12-12 03:36:
> Carsten,
> 
> Could you elaborate your argumentation about YANG?
> 
> When I read
> "There is a very thin line between operations on authorization state
> and other configuration management."
> I think
> "great, so a need to run only a single set of tools on my nodes to
> enable both".
> 
> Sure, the netconf ecosystem (XML, SSH over TCP, etc.) does not fit,
> but maybe this is a good moment to work with COMAN to produce a
> constrained version, for example of RESTCONF. In a perfect world, a
> single protocol could serve multiple purposes, e.g. by mapping
> different states to be managed to different resources.
> 
> Thomas
> 


From twatteyne@gmail.com  Wed Dec 11 23:54:34 2013
Return-Path: <twatteyne@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE1121AE0F9 for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:54:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level: 
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F5GlSt39oiMw for <ace@ietfa.amsl.com>; Wed, 11 Dec 2013 23:54:33 -0800 (PST)
Received: from mail-ea0-x22e.google.com (mail-ea0-x22e.google.com [IPv6:2a00:1450:4013:c01::22e]) by ietfa.amsl.com (Postfix) with ESMTP id 03BBB1AE0C2 for <ace@ietf.org>; Wed, 11 Dec 2013 23:54:32 -0800 (PST)
Received: by mail-ea0-f174.google.com with SMTP id b10so20312eae.33 for <ace@ietf.org>; Wed, 11 Dec 2013 23:54:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=4vSjpodaqXBsBbNrtnlO9rVVmNqJEO63X+63PJ/GdzA=; b=FDa1qZTVt3dLuklsFYXu3c/awYDKhBAgeqqnzYLZHm26/AcxM/8rIoddO7WgJRrjzF HrcCNtAa5UwN3Bd2j5oMXbhZJ98gUMMfXkFhjTn2CRZe3Pp5+FP0iudtcZe/nhJJ5wUQ IL+nKfysnUjtM3WbVfxsmMsrgGVYV8k0bzr7FaxCXzYVIpkLqkd/El+OCWFxHJ11AwDD Y8/chlpxSYVteIC8Jiwbwhv3H+ui+lxqnuyjMdpJOnnvcGlxgEhgWjMKlGcrIodFi/Gi G7Rq6sTJmDatFKtx96srZ6hDNl7X4GNQHI67DT/wvwH7FQKR0ifYVFLefg5K26TA4JP/ pJxw==
X-Received: by 10.14.209.129 with SMTP id s1mr6142523eeo.21.1386834866625; Wed, 11 Dec 2013 23:54:26 -0800 (PST)
MIME-Version: 1.0
Sender: twatteyne@gmail.com
Received: by 10.14.91.5 with HTTP; Wed, 11 Dec 2013 23:54:06 -0800 (PST)
In-Reply-To: <161993bf952da3e41a5c4af4842b5057@xs4all.nl>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca> <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org> <26190.1386812308@sandelman.ca> <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com> <161993bf952da3e41a5c4af4842b5057@xs4all.nl>
From: Thomas Watteyne <watteyne@eecs.berkeley.edu>
Date: Wed, 11 Dec 2013 23:54:06 -0800
X-Google-Sender-Auth: LB-UwIBzmTkZrmzPsc2yQmNoVHk
Message-ID: <CADJ9OA91A0AppKq06U=UCm9wSHL38eKPcUM06PkbOnO+9bKC_Q@mail.gmail.com>
To: consultancy@vanderstok.org
Content-Type: multipart/alternative; boundary=047d7b603a7896614904ed51a7cb
Cc: bert greevenbosch <bert.greevenbosch@huawei.com>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 07:54:35 -0000

--047d7b603a7896614904ed51a7cb
Content-Type: text/plain; charset=ISO-8859-1

Peter, Bert,
Thanks for the pointer, this does look exactly like what I was describing.
I will follow-up with comments.
Thomas

On Wed, Dec 11, 2013 at 11:48 PM, peter van der Stok <stokcons@xs4all.nl>wrote:

> Hi Thomas,
>
> Bert and I started on RESTCONF draft with the subject core management
> interfaces (CoMI).
> draft-vanderstok-core-comi-01.
>  if I understand you correctly, the draft proposal is a first step to your
> single protocol serving multiple purposes.
> After comments by Juergen, we are preparing a second more CBOR, JSON
> focussed version.
>
> Looking forward to your comments,
>
> Peter
>
> Thomas Watteyne schreef op 2013-12-12 03:36:
>
>  Carsten,
>>
>> Could you elaborate your argumentation about YANG?
>>
>> When I read
>> "There is a very thin line between operations on authorization state
>> and other configuration management."
>> I think
>> "great, so a need to run only a single set of tools on my nodes to
>> enable both".
>>
>> Sure, the netconf ecosystem (XML, SSH over TCP, etc.) does not fit,
>> but maybe this is a good moment to work with COMAN to produce a
>> constrained version, for example of RESTCONF. In a perfect world, a
>> single protocol could serve multiple purposes, e.g. by mapping
>> different states to be managed to different resources.
>>
>> Thomas
>>
>>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>

--047d7b603a7896614904ed51a7cb
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Peter, Bert,<div style>Thanks for the pointer, this does l=
ook exactly like what I was describing. I will follow-up with comments.</di=
v><div style>Thomas</div><div class=3D"gmail_extra"><br><div class=3D"gmail=
_quote">

On Wed, Dec 11, 2013 at 11:48 PM, peter van der Stok <span dir=3D"ltr">&lt;=
<a href=3D"mailto:stokcons@xs4all.nl" target=3D"_blank">stokcons@xs4all.nl<=
/a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:=
0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

Hi Thomas,<br>
<br>
Bert and I started on RESTCONF draft with the subject core management inter=
faces (CoMI).<br>
draft-vanderstok-core-comi-01.<br>
=A0if I understand you correctly, the draft proposal is a first step to you=
r single protocol serving multiple purposes.<br>
After comments by Juergen, we are preparing a second more CBOR, JSON focuss=
ed version.<br>
<br>
Looking forward to your comments,<br>
<br>
Peter<br>
<br>
Thomas Watteyne schreef op 2013-12-12 03:36:<div class=3D"im HOEnZb"><br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Carsten,<br>
<br>
Could you elaborate your argumentation about YANG?<br>
<br>
When I read<br>
&quot;There is a very thin line between operations on authorization state<b=
r>
and other configuration management.&quot;<br>
I think<br>
&quot;great, so a need to run only a single set of tools on my nodes to<br>
enable both&quot;.<br>
<br>
Sure, the netconf ecosystem (XML, SSH over TCP, etc.) does not fit,<br>
but maybe this is a good moment to work with COMAN to produce a<br>
constrained version, for example of RESTCONF. In a perfect world, a<br>
single protocol could serve multiple purposes, e.g. by mapping<br>
different states to be managed to different resources.<br>
<br>
Thomas<br>
<br>
</blockquote>
<br></div><div class=3D"HOEnZb"><div class=3D"h5">
______________________________<u></u>_________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org" target=3D"_blank">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/<u></u>listinfo/ace</a><br>
</div></div></blockquote></div><br></div></div>

--047d7b603a7896614904ed51a7cb--

From cabo@tzi.org  Thu Dec 12 00:21:50 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E5A01AE0C2 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 00:21:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.101
X-Spam-Level: 
X-Spam-Status: No, score=-1.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_INVITATION=-2, HELO_EQ_DE=0.35, MIME_CHARSET_FARAWAY=2.45, SPF_HELO_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8DM9dwEZcvaP for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 00:21:48 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 019C21AE17F for <ace@ietf.org>; Thu, 12 Dec 2013 00:21:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBC8LcFn005074; Thu, 12 Dec 2013 09:21:38 +0100 (CET)
Received: from [192.168.217.105] (p5489295F.dip0.t-ipconnect.de [84.137.41.95]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id E052336; Thu, 12 Dec 2013 09:21:37 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=gb18030
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2E6E@SZXEMA501-MBS.china.huawei.com>
Date: Thu, 12 Dec 2013 09:21:36 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <FE333CAB-AD0E-43E6-8F71-C6FFA7378497@tzi.org>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2E6E@SZXEMA501-MBS.china.huawei.com>
To: Rene Struik <rstruik.ext@gmail.com>
X-Mailer: Apple Mail (2.1822)
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Fw: [core] Invitation to New Non-WG Mailing List: Authentication and Authorization for Constrained Environments (ace)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 08:21:50 -0000

Indeed, it would be a disaster to cement =A1=B0device types=A1=B1 into =
an architecture.

But, within a specific transaction, devices might have roles (and =
certain devices may be limited to specific ones of these roles, both by =
their constraints and actually by the overall purpose of the device).

The main point here is that the architecture needs to allow (not =
require) more than two systems to be play a role in a single =
authorization operation.
DTLS already provides most of the tools needed to protect two-party =
operations on authorization.
What is needed is a way to protect these operations beyond a single DTLS =
connection.
Certificates are another tool that can be used here, but as used today =
they only have a tenuous link to authorization.

It is not that easy to write this requirement into the charter without =
sounding like a specific solution.

Gr=A8=B9=810=898e, Carsten


From likepeng@huawei.com  Thu Dec 12 00:22:53 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2BAD1AE17F for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 00:22:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.413
X-Spam-Level: 
X-Spam-Status: No, score=-1.413 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CN_BODY_35=0.339, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dl4Z0eBL9Jlg for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 00:22:51 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 8E70D1AE0C2 for <ace@ietf.org>; Thu, 12 Dec 2013 00:22:50 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBH32393; Thu, 12 Dec 2013 08:22:44 +0000 (GMT)
Received: from LHREML405-HUB.china.huawei.com (10.201.5.242) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 08:22:13 +0000
Received: from SZXEMA404-HUB.china.huawei.com (10.82.72.36) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Thu, 12 Dec 2013 08:22:24 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA404-HUB.china.huawei.com ([10.82.72.36]) with mapi id 14.03.0158.001; Thu, 12 Dec 2013 16:22:19 +0800
From: Likepeng <likepeng@huawei.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Draft ACE Charter
Thread-Index: Ac72WVT850tgXXxoRT6JXoOa8NAUkAADmJ0AACoKTeA=
Date: Thu, 12 Dec 2013 08:22:17 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD2F40@SZXEMA501-MBS.china.huawei.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca>
In-Reply-To: <19752.1386791656@sandelman.ca>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 08:22:53 -0000

SGkgTWljaGFlbCwNCg0KPkkgc3VnZ2VzdCwgZ29pbmcgZm9yd2FyZCB5b3Ugd3JpdGU6DQoNCj4g
VGhlIGNvbnN0cmFpbmVkIGRldmljZXMgd2hpbGUgdW5hYmxlIHRvIGluY2x1ZGUgbWFueSBzb3Bo
aXN0aWNhdGVkDQogIGZlYXR1cmVzLCBzdWNoIGFzIHVzZXIgaW50ZXJmYWNlcyBhbmQgY29uZmln
dXJhdGlvbiBmaWxlcywgbmV2ZXJ0aGVsZXNzDQogIG5lZWQgdG8gcGVyZm9ybSBhdXRoZW50aWNh
dGlvbiBhbmQgYXV0aG9yaXphdGlvbiBvcGVyYXRpb25zLiAgVHdvDQogIGl0ZW1zIHdoaWNoIG11
c3QgYmUgc2l6ZWQgdG8gZml0IGluY2x1ZGUgYXV0aGVudGljYXRpb24gYW5kIGF1dGhvcml6YXRp
b24uDQogIEF1dGhlbnRpY2F0aW9uIGlzIGVuc3VyaW5nIGFuIGVudGl0eSBpcyB3aG8gaXQgc2F5
cyBpdCBpcy4gIEF1dGhlbnRpY2F0aW9uDQogIGlzIHdlbGwgdW5kZXJzdG9vZCwgYW5kIHRoZSBn
cm91cCBtdXN0IHNpbXBseSBhZ3JlZSB1cG9uIG9uZSBtZXRob2QgdGhhdCBmaXRzLg0KICBBdXRo
b3JpemF0aW9uIGlzIGxlc3Mgd2VsbCB1bmRlcnN0b29kLCBhbmQgdGhpcyBncm91cCB3aWxsIGZv
Y3VzIG9uIHRoaXMNCiAgYXNwZWN0IGZpcnN0Lg0KDQpUaGFua3MsIG5vdyB0aGUgbmV3IHRleHQg
aXM6DQoNCkN1cnJlbnRseSwgYSBwcm9ibGVtIHdpdGggY29uc3RyYWluZWQgZGV2aWNlcyBpcyB0
aGUgcmVhbGl6YXRpb24gb2Ygc3VjaCBzZWN1cmUgb3BlcmF0aW9uLiBDb25zdHJhaW5lZCBkZXZp
Y2VzIGFyZSB1bmFibGUgdG8gaW5jbHVkZSBtYW55IHNvcGhpc3RpY2F0ZWQgZmVhdHVyZXMsIHN1
Y2ggYXMgdXNlciBpbnRlcmZhY2VzIGFuZCBjb25maWd1cmF0aW9uIGZpbGVzLCBidXQgbmV2ZXJ0
aGVsZXNzIG5lZWQgdG8gcGVyZm9ybSBhdXRoZW50aWNhdGlvbiBhbmQgYXV0aG9yaXphdGlvbiBv
cGVyYXRpb25zLiBXaGlsZSBhdXRoZW50aWNhdGlvbiBpcyB3ZWxsIHVuZGVyc3Rvb2QsIGF0IGxl
YXN0IGZvciBjb21tdW5pY2F0aW9uIHNlY3VyaXR5LCB0aGVyZSBhcmUgb25seSBpbnN1ZmZpY2ll
bnQgbWVhbnMgZm9yIGF1dGhvcml6YXRpb24uIEF1dGhlbnRpY2F0aW9uIGlzIGNvbnNpZGVyZWQg
aW4gdGhpcyBjb250ZXh0IGFzIGl0IGlzIG5lZWRlZCBhcyBhIHByZXJlcXVpc2l0ZSB0byBwZXJm
b3JtaW5nIGF1dGhvcml6YXRpb24sIGluY2x1ZGluZyB0aGUgYXV0aG9yaXphdGlvbiB0byBjaGFu
Z2UgdGhlIGF1dGhvcml6YXRpb24gc3RhdGUuDQoNCj5JIHRoaW5rIHRoYXQgZXhhbXBsZXMgb2Yg
cHJlcmVxdWlzaXRlcyBzaG91bGQgYmUgaW5jbHVkZWQgaGVyZS4NCg0KT0ssIHdlIGluY2x1ZGUg
c29tZSBleGFtcGxlcy4gSGVyZSBpcyB0aGUgbmV3IHRleHQ6DQpUaGUgQUNFIFdHIGZvY3VzZXMg
b24gcHJvdmlkaW5nIGNvbnN0cmFpbmVkIGRldmljZXMgd2l0aCB0aGUgbmVjZXNzYXJ5IHByZXJl
cXVpc2l0ZXMgdG8gdXNlIFJFU1Qgb3BlcmF0aW9ucyBpbiBhIHNlY3VyZSB3YXkgc3VjaCBhcyBh
dXRob3JpemF0aW9uIGluZm9ybWF0aW9uIGFuZCB0aGUgcmVsYXRlZCBrZXlpbmcgbWF0ZXJpYWwu
DQoNCkkgYmVsaWV2ZSBvdGhlciBjb21tZW50cyBhcmUgY292ZXJlZCBieSBhbm90aGVyIGVtYWls
IGZyb20gQ2Fyc3Rlbi4NCg0KS2luZCBSZWdhcmRzDQpLZXBlbmcNCg0KLS0tLS3Tyrz+1K28/i0t
LS0tDQq3orz+yMs6IEFjZSBbbWFpbHRvOmFjZS1ib3VuY2VzQGlldGYub3JnXSC0+rHtIE1pY2hh
ZWwgUmljaGFyZHNvbg0Kt6LLzcqxvOQ6IDIwMTPE6jEy1MIxMsjVIDM6NTQNCsrVvP7IyzogYWNl
QGlldGYub3JnDQrW98ziOiBSZTogW0FjZV0gRHJhZnQgQUNFIENoYXJ0ZXINCg0KDQpMaWtlcGVu
ZyA8bGlrZXBlbmdAaHVhd2VpLmNvbT4gd3JvdGU6DQogICAgPiAoMilFeGlzdGluZyB3b3JrOg0K
DQpJIGFkZGVkIG9mIHRoZSBpdGVtcyB0byBteSByZWFkaW5nIGxpc3QsIHRvIGRpc2NvdmVyIHRo
YXQgaGFsZiBvZiB0aGVtIHdlcmUgYWxyZWFkeSBvbiBteSByZWFkaW5nIGxpc3QsIGFuZCBzb21l
IG9mIHRoZW0gd2VyZSBtYXJrZWQgYXMgcmVhZCA6LSkgKFRoYXQncyBnb29kLCBpdCBtZWFucyB0
aGF0IHRoaXMgd29yayBpc24ndCBjb21pbmcgb3V0IGZyb20gbm93aGVyZSkNCg0KICAgID4gQ3Vy
cmVudGx5LCBhIHByb2JsZW0gd2l0aCBjb25zdHJhaW5lZCBkZXZpY2VzIGlzIHRoZSByZWFsaXph
dGlvbiBvZg0KICAgID4gc3VjaCBzZWN1cmUgY29tbXVuaWNhdGlvbi4gVGhlIGRldmljZXMgb25s
eSBoYXZlIGxpbWl0ZWQgcmVzb3VyY2VzIHN1Y2gNCiAgICA+IGFzIG1lbW9yeSwgc3RvcmFnZSBh
bmQgdHJhbnNtaXNzaW9uIGNhcGFjaXR5LiBUaGVzZSBjb25zdHJhaW50cw0KICAgID4gc2V2ZXJl
bHkgbGltaXQgdGhlIHNlY3VyaXR5IGZ1bmN0aW9ucyBhbmQgY29tbXVuaWNhdGlvbnMgdGhlIGRl
dmljZSBjYW4NCiAgICA+IHBlcmZvcm0uIE1pc3NpbmcgZnVuY3Rpb25hbGl0eSBpbmNsdWRlcyBh
dXRoZW50aWNhdGlvbiwgd2hpY2ggcHJvdmlkZXMNCiAgICA+IHRydXN0IGFuZCBlbnN1cmVzIGFu
IGVudGl0eSBpcyB3aG8gaXQgc2F5cyBpdCBpcywgYW5kIGF1dGhvcml6YXRpb24sDQogICAgPiB3
aGljaCBkZWZpbmVzIGFuZCBlbmZvcmNlcyBhY2Nlc3MgcmlnaHRzIGZvciBkaWZmZXJlbnQgY2xp
ZW50cy4NCg0KSSBhZ3JlZSB3aXRoIGFsbCB0aGUgd29yZHMsIGJ1dCBJIHRoaW5rIHRoYXQgbWFu
eSB3aWxsIGdldCBjYXVnaHQgdXAgb24gYXV0aGVudGljYXRpb24sIGFuZCBmYWlsIHRvIHJlYWQg
YWJvdXQgYXV0aG9yaXphdGlvbi4NCg0KSSBzdWdnZXN0LCBnb2luZyBmb3J3YXJkIHlvdSB3cml0
ZToNCg0KICBUaGUgY29uc3RyYWluZWQgZGV2aWNlcyB3aGlsZSB1bmFibGUgdG8gaW5jbHVkZSBt
YW55IHNvcGhpc3RpY2F0ZWQNCiAgZmVhdHVyZXMsIHN1Y2ggYXMgdXNlciBpbnRlcmZhY2VzIGFu
ZCBjb25maWd1cmF0aW9uIGZpbGVzLCBuZXZlcnRoZWxlc3MNCiAgbmVlZCB0byBwZXJmb3JtIGF1
dGhlbnRpY2F0aW9uIGFuZCBhdXRob3JpemF0aW9uIG9wZXJhdGlvbnMuICBUd28NCiAgaXRlbXMg
d2hpY2ggbXVzdCBiZSBzaXplZCB0byBmaXQgaW5jbHVkZSBhdXRoZW50aWNhdGlvbiBhbmQgYXV0
aG9yaXphdGlvbi4NCiAgQXV0aGVudGljYXRpb24gaXMgZW5zdXJpbmcgYW4gZW50aXR5IGlzIHdo
byBpdCBzYXlzIGl0IGlzLiAgQXV0aGVudGljYXRpb24NCiAgaXMgd2VsbCB1bmRlcnN0b29kLCBh
bmQgdGhlIGdyb3VwIG11c3Qgc2ltcGx5IGFncmVlIHVwb24gb25lIG1ldGhvZCB0aGF0IGZpdHMu
DQogIEF1dGhvcml6YXRpb24gaXMgbGVzcyB3ZWxsIHVuZGVyc3Rvb2QsIGFuZCB0aGlzIGdyb3Vw
IHdpbGwgZm9jdXMgb24gdGhpcw0KICBhc3BlY3QgZmlyc3QuDQoNCj4gIFRoZSBBQ0UgV0cgZm9j
dXNlcyBvbiBwcm92aWRpbmcgY29uc3RyYWluZWQgZGV2aWNlcyB3aXRoIHRoZSANCj4gbmVjZXNz
YXJ5ICBwcmVyZXF1aXNpdGVzIHRvIHVzZSBSRVNUIG9wZXJhdGlvbnMgaW4gYSBzZWN1cmUgd2F5
LiANCj4gQ29uc3RyYWluZWQNCg0KSSB0aGluayB0aGF0IGV4YW1wbGVzIG9mIHByZXJlcXVpc2l0
ZXMgc2hvdWxkIGJlIGluY2x1ZGVkIGhlcmUuDQoNCj4gIGRldmljZXMgd2lsbCB0aHVzIGJlIGVu
YWJsZWQgdG8gYXV0aGVudGljYXRlIGNvbW11bmljYXRpb25zIGZyb20gDQo+IG90aGVyIChjb25z
dHJhaW5lZCBvciBsZXNzLWNvbnN0cmFpbmVkKSBkZXZpY2VzLCB0byBjb21tdW5pY2F0ZSANCj4g
c2VjdXJlbHkgd2l0aCB0aGVtIGFuZCB0byB2ZXJpZnkgdGhlaXIgaW5kaXZpZHVhbCBhdXRob3Jp
emF0aW9uIHRvIA0KPiBhY2Nlc3Mgc3BlY2lmaWMgcmVzb3VyY2VzLiBUbyBhY2hpZXZlIHRoaXMs
IEFDRSB3aWxsIGJlIGFibGUgdG8gZW1wbG95IA0KPiBhbiBhcmNoaXRlY3R1cmUgd2l0aCBvbmUg
b3IgbW9yZSB0cnVzdGVkIGxlc3MtY29uc3RyYWluZWQgZGV2aWNlcyANCj4gd2hpY2ggd2lsbCBy
ZWxpZXZlIHRoZSBjb25zdHJhaW5lZCBub2RlcyBmcm9tIGNvbXBsZXggc2VjdXJpdHkgcmVsYXRl
ZCANCj4gdGFza3MgKGUuZy4gbWFuYWdpbmcgYXV0aG9yaXphdGlvbiBwb2xpY2llcyBhbmQgYSBs
YXJnZSBudW1iZXIgb2YgDQo+IGtleXMpLiBBQ0Ugd2lsbCB1c2UgQ29BUCBhbmQgZW1wbG95IHNl
Y3VyaXR5IHByb3BlcnRpZXMgb2YgRFRMUyB3aGVuZXZlciBwb3NzaWJsZS4NCg0KWW91IGhhdmUg
bWFkZSBhbiBhcmNoaXRlY3R1cmFsIGFzc3VtcHRpb24gaGVyZSB3aGljaCBtYXkgYmUgYXBwcm9w
cmlhdGUsIGJ1dCBtYXkgYWxzbyBiZSBwcmVtYXR1cmUuIEknbSBub3Qgb2JqZWN0aW5nIHRvIHRo
ZSBzdGF0ZW1lbnQsIEkganVzdCB3YW50IGV2ZXJ5b25lIHRvIGJlIGNsZWFyIHRoYXQgdGhpcyBz
dGF0ZW1lbnQgaXMgYmVpbmcgbWFkZS4NCg0KUXVlc3Rpb246DQogIC0gaXMgYXV0aG9yaXphdGlv
biB0byBtYWtlIGF1dGhvcml6YXRpb24gc3RhdGVtZW50cyBpbiBzY29wZT8NCiAgICAoaS5lLiBt
ZXRhIG9wZXJhdGlvbnMpDQogIC0gc2hvdWxkIGF1dGhvcml6YXRpb24gYmUgZXhwcmVzc2VkIGlu
IFlBTkc/DQogIC0gc2hvdWxkIGF1dGhvcml6YXRpb24gdG8gZXhwcmVzcyBhdXRob3JpemF0aW9u
IGJlIGV4cHJlc3NlZCBpbiBZQU5HPw0KDQooSSBrbm93IGxpdHRsZSBhYm91dCBZQU5HLCBidXQg
aXQgc2VlbXMgdG8gYmUgd2hhdCBhbGwgdGhlIGNvb2wga2lkcyBhcmUgZG9pbmcpDQoNCiAgICA+
IFRoZSBBQ0UgV0cgaGFzIHRoZSBmb2xsb3dpbmcgdGFza3M6DQoNCiAgICA+IC0gRG9jdW1lbnQg
dGhlIHVzZSBjYXNlcyBhbmQgaGlnaC1sZXZlbCByZXF1aXJlbWVudHMgZm9yIHNlY3VyZWQNCiAg
ICA+IGNvbW11bmljYXRpb24gYmV0d2VlbiBjb25zdHJhaW5lZCBkZXZpY2VzLg0KDQpZZXMsIHdl
IG5lZWQgdXNlIGNhc2VzLCBidXQgbGV0J3Mgbm90IGdldCBib2dnZWQgZG93biBpbiB0aGVtLg0K
DQogICAgPiAtIERlZmluZSBjZXJ0aWZpY2F0ZSBwcm9maWxpbmcgKHdoYXQga2luZHMgb2YgY2Vy
dGlmaWNhdGVzIGFuZCB3aGljaA0KICAgID4gYXR0cmlidXRlcyBhcmUgdG8gYmUgdXNlZCkuDQoN
CkkgdGhpbmsgaXQncyBpbXBvcnRhbnQgdG8gdW5kZXJzdGFuZCB3aGljaCBwYXJ0cyBkZWFsIHdp
dGggY2VydGlmaWNhdGVzLCBhbmQgaWYgd2UgYXJlIGRvaW5nIENBcyBhcyB3ZWxsIGFzIEFBcy4N
Cg0KICAgID4gLSBEZWZpbmUgYSBtZWNoYW5pc20gZm9yIGF1dGhlbnRpY2F0ZWQgYW5kIHByb3Rl
Y3RlZCB0cmFuc2ZlciBvZg0KICAgID4gYXV0aG9yaXphdGlvbiBpbmZvcm1hdGlvbiBzdWl0YWJs
ZSBmb3IgY29uc3RyYWluZWQgZGV2aWNlIHRvDQogICAgPiBjb25zdHJhaW5lZCBkZXZpY2UgY29t
bXVuaWNhdGlvbi4NCg0KICAgID4gLSBEZWZpbmUgYW4gYWNjZXNzIHRpY2tldCBhbmQgYXV0aG9y
aXphdGlvbiBpbmZvcm1hdGlvbiBmb3JtYXQgc3VpdGFibGUNCiAgICA+IGZvciBjb25zdHJhaW5l
ZCBkZXZpY2VzLg0KDQogICAgPiAtIERlZmluZSBib290c3RyYXBwaW5nIGZvciBhdXRob3JpemF0
aW9uIGluZm9ybWF0aW9uIHVzaW5nIHRoZSBSZXNvdXJjZQ0KICAgID4gRGlyZWN0b3J5Lg0KDQpN
YXliZSBhIHJlZmVyZW5jZSBvbiAiUmVzb3VyY2UgRGlyZWN0b3J5IiBpcyB1c2VmdWwgaGVyZS4N
CkkgdGhpbmsgaXQncyBhIENPUkUvQ29BUCB0aGluZywgcmlnaHQ/DQoNCi0tDQpNaWNoYWVsIFJp
Y2hhcmRzb24gPG1jcitJRVRGQHNhbmRlbG1hbi5jYT4sIFNhbmRlbG1hbiBTb2Z0d2FyZSBXb3Jr
cyAgLT0gSVB2NiBJb1QgY29uc3VsdGluZyBmb3IgaGlyZSA9LQ0KDQoNCg==

From Hannes.Tschofenig@gmx.net  Thu Dec 12 07:48:13 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D6481AE320 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 07:48:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.722
X-Spam-Level: 
X-Spam-Status: No, score=0.722 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yK38WAcX1kEo for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 07:48:12 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) by ietfa.amsl.com (Postfix) with ESMTP id E6EA11ADF64 for <ace@ietf.org>; Thu, 12 Dec 2013 07:48:11 -0800 (PST)
Received: from 3capp-gmx-bs21.server.lan ([172.19.170.73]) by mrigmx.server.lan (mrigmx001) with ESMTP (Nemesis) id 0ME0kj-1VlvHm0Mj1-00HPof for <ace@ietf.org>; Thu, 12 Dec 2013 16:48:05 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs21.server.lan with HTTP; Thu Dec 12 16:48:05 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-8ef43169-6c2a-4e24-9b41-a8f9102a16fd-1386863284974@3capp-gmx-bs21>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: ace@ietf.org
Content-Type: text/html; charset=UTF-8
Date: Thu, 12 Dec 2013 16:48:05 +0100 (CET)
Importance: normal
Sensitivity: Normal
X-Priority: 3
X-Provags-ID: V03:K0:lflFcjdHuXSpFN8a09weTJb9H8+XdxyvBhoEvSAGbiR LrGJ20ievDo43QofocLzbkqzT2jINIGd/OfHnUYKdkK/3lxw3B Z4fG31pmtv/SY6S6e34yhYnu0hjKZ2HAE9y0HtoyeT+DH3rdn8 rbLCdKeHcBb8rVfoFhlmjleywKADZa42NyBDjAcH0XZvKUod6e JbY3TfN9j+x2SGTcGbkoN1cCcl+tcKbuZhmfFQB2ezZ5lKZ9TY L7wHBcAhaClqz6a2IaFyKeRDRbpFTN51VMibudiECyz5PuxqXC c6zIa0=
Subject: [Ace] draft-seitz-core-sec-usecases-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 15:48:13 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div><span style="font-size:12px;"><span style="font-family:arial,helvetica,sans-serif;"><span style="line-height: 1.6em;">Dear Goeran, Stefanie, Ludwig,&nbsp;</span></span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:arial,helvetica,sans-serif;">I read your document with great interest and I like the description. One basic&nbsp;question did, however, come to my mind.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:arial,helvetica,sans-serif;">Collecting requirements is always a difficult job since it requires you to understand the problem domain and that specific industry sector well enough to know how the&nbsp;stakeholders are planning to deploy their technology.</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:arial,helvetica,sans-serif;">How did you collect these requirements?</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:arial,helvetica,sans-serif;">Ciao<br/>
Hannes</span></span></div>

<div>&nbsp;</div></div></body></html>

From Hannes.Tschofenig@gmx.net  Thu Dec 12 08:47:13 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1344F1AE028 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 08:47:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.722
X-Spam-Level: 
X-Spam-Status: No, score=0.722 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jK30LVdtcgfB for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 08:47:11 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) by ietfa.amsl.com (Postfix) with ESMTP id 98E0E1ADEB6 for <ace@ietf.org>; Thu, 12 Dec 2013 08:47:11 -0800 (PST)
Received: from 3capp-gmx-bs21.server.lan ([172.19.170.73]) by mrigmx.server.lan (mrigmx002) with ESMTP (Nemesis) id 0LrY9r-1VP8Lc1cDt-013MWH for <ace@ietf.org>; Thu, 12 Dec 2013 17:47:05 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs21.server.lan with HTTP; Thu Dec 12 17:47:05 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-e2a1a839-6756-4be5-831d-9ed1927ef217-1386866825278@3capp-gmx-bs21>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: ace@ietf.org
Content-Type: text/html; charset=UTF-8
Date: Thu, 12 Dec 2013 17:47:05 +0100 (CET)
Importance: normal
Sensitivity: Normal
X-Priority: 3
X-Provags-ID: V03:K0:VlrpCiN7Y7dt8iYn9EUqFCKrTtOhey3Cp1r0UqEoEpZ UD/0gRxQjN3Bq67JgG+XruqzpM172UpbeWLDOPuUYrLJogOnEG YpiX8lYFvt5jCSSDtLcaKTg6sZotFPBKeeDsS5vK21HF4pIsa4 Qo0/JbduHcU+RU6uNFWz8j+x4O27ugFYbZVmQYXa+WI6PG4JY8 dhCbDNPq4a3t+AYlLHn4SAQJH+7UNdIxhPckvX4NEEzhT4ozD6 hIbd1m4WFk7vv9msA2XZiPcF3sqPHNVnS/LPT68VDd7uu4swks LCCu0k=
Subject: [Ace] draft-garcia-core-security-06
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 16:47:13 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>
<div>Dear Oscar, Sandeep, Sye Loong, Rene^2,&nbsp;</div>

<div>&nbsp;</div>

<div>thanks for submitting this document. I took a look at the scenario part, which talks about Building Automation and Control (BAC).&nbsp;</div>

<div>&nbsp;</div>

<div>I ran into a few questions: &nbsp;<br/>
&bull;&nbsp;&nbsp; &nbsp;You illustrate the lifecycle of an IoT device and the device identity and the secret keys are provided to the device during the &quot;installation&quot; and &quot;commissioning&quot; phase. You seem to assume that there is no keying material provided to the device during the manufacturing process? Is that correct?&nbsp;<br/>
&bull;&nbsp;&nbsp; &nbsp;I also wasn&rsquo;t quite sure whether you assume that there are different credentials being used for network access, and for access to the different services.&nbsp;<br/>
&bull;&nbsp;&nbsp; &nbsp;How is authorization accomplished in the BAC environment?&nbsp;<br/>
&bull;&nbsp;&nbsp; &nbsp;Why did you pick the BAC environment as an example use for the document? Is it because of your experience with this sector? Or does it have specific characteristics not found in other areas?&nbsp;</div>

<div>&nbsp;</div>

<div>Ciao<br/>
Hannes</div>
</div></div></body></html>

From sarikaya2012@gmail.com  Thu Dec 12 09:31:38 2013
Return-Path: <sarikaya2012@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF4F61ADF6A for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 09:31:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id trJ37myMh9qJ for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 09:31:37 -0800 (PST)
Received: from mail-la0-x22d.google.com (mail-la0-x22d.google.com [IPv6:2a00:1450:4010:c03::22d]) by ietfa.amsl.com (Postfix) with ESMTP id 17A151ADF4E for <ace@ietf.org>; Thu, 12 Dec 2013 09:31:36 -0800 (PST)
Received: by mail-la0-f45.google.com with SMTP id eh20so562566lab.18 for <ace@ietf.org>; Thu, 12 Dec 2013 09:31:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:content-type; bh=++X0kt5MIZI9GLPqLtTgxgIOlW4bs2QxD66u49YHINk=; b=DhLOO0sG7BCHhuf7AmlWA9wyYJxFgCPZxlMoOGUQU7uhxk8vp7YimjAHH+xu9EkOnh /DkHKavQW0qkbod9x28clZqeTMUY+YpxoTRy1AJv3E+qlN2Ae0sUyeq9aNyHJRaG//Zb PP357ABud1OJgvdGNXlFIpi31OVqraSD+5SwnJpW0iKBCJ1Tv6QK4dN0+aUNSRxLptMD aagaeKGPo9vcMV6dcflrA8QPRpB9PII7TubrnZSKDdc4STtud196+KyQEo2IUfhD5ka+ RQ3LuAkDUx3HhhK1i5Iq6Z0+0UDGGNQRiV+Wr7CoIdHnt7H3OZRxRgQ2lGejC/zUFpcX wXiA==
MIME-Version: 1.0
X-Received: by 10.152.120.135 with SMTP id lc7mr4424470lab.38.1386869490153; Thu, 12 Dec 2013 09:31:30 -0800 (PST)
Received: by 10.115.4.165 with HTTP; Thu, 12 Dec 2013 09:31:30 -0800 (PST)
In-Reply-To: <20131211212921.16906.83094.idtracker@ietfa.amsl.com>
References: <20131211212921.16906.83094.idtracker@ietfa.amsl.com>
Date: Thu, 12 Dec 2013 11:31:30 -0600
Message-ID: <CAC8QAcckmyF_1CSGmTKo44Pi2=SgYQnbjcq37hC+W7SuJzvJeQ@mail.gmail.com>
From: Behcet Sarikaya <sarikaya2012@gmail.com>
To: ace@ietf.org
Content-Type: multipart/alternative; boundary=089e012281ac4f7bd104ed59b749
Subject: [Ace] Fwd: New Version Notification for draft-sarikaya-ace-secure-bootstrapping-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: sarikaya@ieee.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 17:31:39 -0000

--089e012281ac4f7bd104ed59b749
Content-Type: text/plain; charset=ISO-8859-1

Hi all,

I submitted a draft as follows. This is coming from the core WG, as many of
the other drafts are.

Kapeng, can you please add this to your list of drafts? I would like to
know how suitable my draft is to the charter?

Regards,

Behcet



A new version of I-D, draft-sarikaya-ace-secure-bootstrapping-00.txt
has been successfully submitted by Behcet Sarikaya and posted to the
IETF repository.

Filename:        draft-sarikaya-ace-secure-bootstrapping
Revision:        00
Title:           Secure Bootstrapping Solution for Constrained Devices
Creation date:   2013-12-11
Group:           Individual Submission
Number of pages: 12
URL:
http://www.ietf.org/internet-drafts/draft-sarikaya-ace-secure-bootstrapping-00.txt
Status:
http://datatracker.ietf.org/doc/draft-sarikaya-ace-secure-bootstrapping
Htmlized:
http://tools.ietf.org/html/draft-sarikaya-ace-secure-bootstrapping-00


Abstract:
   We present a solution to initially configure the network of resource
   constrained nodes securely, a.k.a., secure bootstrapping.  The
   solution is based on EAP-TLS authentication with the use of raw
   public keys as certificates.




Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

--089e012281ac4f7bd104ed59b749
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div>Hi all,<br><br></div>I submitted a dra=
ft as follows. This is coming from the core WG, as many of the other drafts=
 are.<br><br></div>Kapeng, can you please add this to your list of drafts? =
I would like to know how suitable my draft is to the charter?<br>
<br></div>Regards,<br><br></div>Behcet<br><div><div><div><div><div><br><div=
 class=3D"gmail_quote"><br><br>
A new version of I-D, draft-sarikaya-ace-secure-bootstrapping-00.txt<br>
has been successfully submitted by Behcet Sarikaya and posted to the<br>
IETF repository.<br>
<br>
Filename: =A0 =A0 =A0 =A0draft-sarikaya-ace-secure-bootstrapping<br>
Revision: =A0 =A0 =A0 =A000<br>
Title: =A0 =A0 =A0 =A0 =A0 Secure Bootstrapping Solution for Constrained De=
vices<br>
Creation date: =A0 2013-12-11<br>
Group: =A0 =A0 =A0 =A0 =A0 Individual Submission<br>
Number of pages: 12<br>
URL: =A0 =A0 =A0 =A0 =A0 =A0 <a href=3D"http://www.ietf.org/internet-drafts=
/draft-sarikaya-ace-secure-bootstrapping-00.txt" target=3D"_blank">http://w=
ww.ietf.org/internet-drafts/draft-sarikaya-ace-secure-bootstrapping-00.txt<=
/a><br>
Status: =A0 =A0 =A0 =A0 =A0<a href=3D"http://datatracker.ietf.org/doc/draft=
-sarikaya-ace-secure-bootstrapping" target=3D"_blank">http://datatracker.ie=
tf.org/doc/draft-sarikaya-ace-secure-bootstrapping</a><br>
Htmlized: =A0 =A0 =A0 =A0<a href=3D"http://tools.ietf.org/html/draft-sarika=
ya-ace-secure-bootstrapping-00" target=3D"_blank">http://tools.ietf.org/htm=
l/draft-sarikaya-ace-secure-bootstrapping-00</a><br>
<br>
<br>
Abstract:<br>
=A0 =A0We present a solution to initially configure the network of resource=
<br>
=A0 =A0constrained nodes securely, a.k.a., secure bootstrapping. =A0The<br>
=A0 =A0solution is based on EAP-TLS authentication with the use of raw<br>
=A0 =A0public keys as certificates.<br>
<br>
<br>
<br>
<br>
Please note that it may take a couple of minutes from the time of submissio=
n<br>
until the htmlized version and diff are available at <a href=3D"http://tool=
s.ietf.org" target=3D"_blank">tools.ietf.org</a>.<br>
<br>
The IETF Secretariat<br>
<br>
</div><br></div></div></div></div></div></div>

--089e012281ac4f7bd104ed59b749--

From Hannes.Tschofenig@gmx.net  Thu Dec 12 09:36:57 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B16FB1ADF77 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 09:36:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.722
X-Spam-Level: 
X-Spam-Status: No, score=0.722 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UykwgJRgC1jZ for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 09:36:56 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) by ietfa.amsl.com (Postfix) with ESMTP id DA4371ADF12 for <ace@ietf.org>; Thu, 12 Dec 2013 09:36:55 -0800 (PST)
Received: from 3capp-gmx-bs21.server.lan ([172.19.170.73]) by mrigmx.server.lan (mrigmx001) with ESMTP (Nemesis) id 0MBpxx-1VjhfK23sN-00AniR for <ace@ietf.org>; Thu, 12 Dec 2013 18:36:49 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs21.server.lan with HTTP; Thu Dec 12 18:36:49 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-dde6b06c-7592-4afe-976a-64b3c698c738-1386869809257@3capp-gmx-bs21>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: ace@ietf.org
Content-Type: text/html; charset=UTF-8
Date: Thu, 12 Dec 2013 18:36:49 +0100 (CET)
Importance: normal
Sensitivity: Normal
X-Priority: 3
X-Provags-ID: V03:K0:6/Lo0bWVPs46mL/0ay98LCqOW0iQob29ZU4sjTfcssw my0jnL93rBP8xWQqRaalJMEJkSkJ1xK6iAJTiXAOqGsNza6P1C EppW5hKGjZO6APOAuBuc+Vo1zOx8z5/aUZ8hZhCM/5w7LLMUWU Qza63eS2u68b4G9AFT2p4/aT6ZEFN8z+OPck5XUhZxI8Vn6Xwa l4d/ouoz7nxW0ftxuf3YgOfp46BpX1Y5Fjs7uZRzrASfMR5z23 BrcAWk0TiVgUMyvi72DkMWfMakcTOsK/ScSsWamtDjGovQ/BB3 XzOSjc=
Subject: [Ace] draft-greevenbosch-core-authreq-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 17:36:57 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>
<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Dear Bert,&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Thanks for your document. I also ran into questions when I looked at your document.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Your first use case (Section 3.1; maybe also Section 3.8?) with the title &ldquo;authorized and unauthorized devices&rdquo; make an interesting distinction between the two types of devices. You basically draw the line based on whether the device passed certification testing (or not). During the protocol execution you seem to assume that the authentication credentials reveal whether a device passed certification testing or not.&nbsp;<span style="line-height: 1.6em;">While this is clearly possible it is a rather unusual scenario. Is this something you have seen being used or envisioned somewhere or did you create this scenario yourself?&nbsp;</span></span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Many of the scenarios you outline deal with revocation (such as Section 3.3, 3.5, 3.6, 3.7). The scenarios described in Scenarios 3.2 and 3.4 raise the requirements for fine-grained access control. Was this intentional or did I misinterpret something?&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">For the text in Section 3.9 you focus on a small subset of privacy threats, namely surveillance. Maybe you should refer explicitly to surveillance or extend the write-up to also include other privacy threats, see RFC 6973.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Similarly to my comments regarding the other documents I am curious how you came up with these scenarios. It is fine if you came up with them yourself but it would be good to know.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Ciao<br/>
Hannes</span></span></div>
</div></div></body></html>

From Hannes.Tschofenig@gmx.net  Thu Dec 12 10:32:25 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB7071AE3CA for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 10:32:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.722
X-Spam-Level: 
X-Spam-Status: No, score=0.722 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6nt-VhFQJk0a for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 10:32:25 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) by ietfa.amsl.com (Postfix) with ESMTP id F40BF1AE3C9 for <ace@ietf.org>; Thu, 12 Dec 2013 10:32:24 -0800 (PST)
Received: from 3capp-gmx-bs21.server.lan ([172.19.170.73]) by mrigmx.server.lan (mrigmx002) with ESMTP (Nemesis) id 0MOVLv-1VwyLX2bEj-005qt1 for <ace@ietf.org>; Thu, 12 Dec 2013 19:32:18 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs21.server.lan with HTTP; Thu Dec 12 19:32:18 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: ace@ietf.org
Content-Type: text/html; charset=UTF-8
Date: Thu, 12 Dec 2013 19:32:18 +0100 (CET)
Importance: normal
Sensitivity: Normal
X-Priority: 3
X-Provags-ID: V03:K0:oWp2naRAx+/AIpFF1iobWxnzyluU4pkjtxHZXbVroHg 6nZQs5WU0etW2vFlI2pM1VtH5qm8JtekW6vLJsdwIIMo9WVK+w Me217MtO9IJT4xdN0j69PBm791D5Vd+FyTLapu/YmBuhUWrQ8h H8aSUHozP8wUHhFPYLHnDKrUaPeU/bV8kkGDziT+hhwBG7DVXp F/wr4tdp2UJvc5cC9W93OG+JqSCak9BpY+55Fyu0gcPmIG6Hnd 7c6TT54pPiIEkNxhuzASDPn3ddUrQBVpHVQgXwjuQwyiGwvr0H 9Od3KA=
Subject: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 18:32:26 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>Hi all,&nbsp;</div>

<div>&nbsp;</div>

<div>in a couple of drafts I see these pointers to access control lists being described in CoAP. However, the CoAP specification does not really say that much about access control lists and by no means describes how they are supposed to be used in any level of detail.&nbsp;</div>

<div>&nbsp;</div>

<div>I am curious what folks on the list think they do.&nbsp;</div>

<div>&nbsp;</div>

<div>Ciao<br/>
Hannes</div>

<div>&nbsp;</div></div></body></html>

From Hannes.Tschofenig@gmx.net  Thu Dec 12 10:51:35 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1EAD91AE0DD for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 10:51:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.722
X-Spam-Level: 
X-Spam-Status: No, score=0.722 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FfSiGSXwHcH0 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 10:51:33 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) by ietfa.amsl.com (Postfix) with ESMTP id 8CCDC1ADF54 for <ace@ietf.org>; Thu, 12 Dec 2013 10:51:33 -0800 (PST)
Received: from 3capp-gmx-bs21.server.lan ([172.19.170.73]) by mrigmx.server.lan (mrigmx002) with ESMTP (Nemesis) id 0Lrp0S-1VPNei45GQ-013dTH for <ace@ietf.org>; Thu, 12 Dec 2013 19:51:26 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs21.server.lan with HTTP; Thu Dec 12 19:51:26 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: ace@ietf.org
Content-Type: text/html; charset=UTF-8
Date: Thu, 12 Dec 2013 19:51:26 +0100 (CET)
Importance: normal
Sensitivity: Normal
X-Priority: 3
X-Provags-ID: V03:K0:10hrXdhkgcsU6wYhq1Nc0kmacWM2vTL5t9m+m/HBtBP smWkMCX8g8xwyU+E9xqNLD5+ZXYfPj3Vi5VnEC7rpkvcXNqnMJ f9lycTKf95tk30w9rpN89TrBoBvpgW2cprdN7S7nPlgyo80EFH X6UFtW5HZWF3Hhpjeug68lAA+c1d4+MpRLf3hncWIJSNTO1/+x ovtM4d9AqyJzyEmNE8GU8UGabE15pap2GYTX9spsF0Tj5p7zk5 /W+8jIiep6/I2iVk1hYg7OtSDqyvMzLEQV5t0Pk7fw1q7DTvMy aJp9s8=
Subject: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 18:51:35 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Could you guys do me a favor and avoid two terms in your drafts:&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;"><span style="white-space: pre-wrap; line-height: normal;">1) Bootstrapping</span></span></span></div>

<div>
<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">2) Trust</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">The term bootstrapping was created a couple of years ago as a sort of marketing term. It means &quot;key distribution&quot;. Let us use key distribution (or key establishment) instead since we know what it means. There are a number of key distribution protocols out there and we quickly see the relationship to prior work.</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">The term &quot;trust&quot; by itself is extremely vague. So you better avoid it or be a bit more specific by&nbsp;saying &quot;who trust whom to do what&quot;. &nbsp;&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Ciao<br/>
Hannes</span></span></div>

<div>&nbsp;</div>
</div></div></body></html>

From sarikaya2012@gmail.com  Thu Dec 12 12:59:30 2013
Return-Path: <sarikaya2012@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 199E91AE4C9 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 12:59:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ENQagSuJcQo5 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 12:59:28 -0800 (PST)
Received: from mail-la0-x236.google.com (mail-la0-x236.google.com [IPv6:2a00:1450:4010:c03::236]) by ietfa.amsl.com (Postfix) with ESMTP id 831AE1ADFD6 for <ace@ietf.org>; Thu, 12 Dec 2013 12:59:28 -0800 (PST)
Received: by mail-la0-f54.google.com with SMTP id b8so751896lan.13 for <ace@ietf.org>; Thu, 12 Dec 2013 12:59:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=aGt27n3BavN7ssMXZxzXrOLLqJBsXvonwujM8PjLUSI=; b=cgrpcsSKjTCkWsjNIqnCHlxGOAcAZ0hawKmQLXR1EeGni1iyfY5GObNxv+6mRJQLAP NnCGEJE7XeH3LnhqiwMjx6MKtrCwlrTLAgIzixpZqLLHlqrSp0FRcxYj3WtS8JScJCgP mMqAeDAoyatLoIJOVA5HZvWCfdoqMjWOjiVGgy8rWbSSwRefEiQRKD3AqEc0g2sLHslb qlEXROf1hmcOYkECp/JqejMm2R0X1DqssRgOgAsnhvxCNqM5S9kPqUjoJeO1MiI3Br+m vojkAVlB20/knT4h+aQqjEBjJOuNTGgXwMx4favJxtM1I4j3vjuVVgKq10hnC81/ZKp4 OH6A==
MIME-Version: 1.0
X-Received: by 10.152.1.197 with SMTP id 5mr4951190lao.0.1386881961788; Thu, 12 Dec 2013 12:59:21 -0800 (PST)
Received: by 10.115.4.165 with HTTP; Thu, 12 Dec 2013 12:59:21 -0800 (PST)
In-Reply-To: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21>
Date: Thu, 12 Dec 2013 14:59:21 -0600
Message-ID: <CAC8QAcd1mZAEjHMs1LHvGuknOYZSETzfxnVjgu8hW7JO5gH9sA@mail.gmail.com>
From: Behcet Sarikaya <sarikaya2012@gmail.com>
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Content-Type: multipart/alternative; boundary=089e0112bfcead8a1704ed5c9ea8
Cc: ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: sarikaya@ieee.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 20:59:30 -0000

--089e0112bfcead8a1704ed5c9ea8
Content-Type: text/plain; charset=ISO-8859-1

Hi Hannes,


On Thu, Dec 12, 2013 at 12:51 PM, Hannes Tschofenig <
Hannes.Tschofenig@gmx.net> wrote:

> Could you guys do me a favor and avoid two terms in your drafts:
>
> 1) Bootstrapping
>  2) Trust
>
> The term bootstrapping was created a couple of years ago as a sort of
> marketing term. It means "key distribution". Let us use key distribution
> (or key establishment) instead since we know what it means. There are a
> number of key distribution protocols out there and we quickly see the
> relationship to prior work.
>
>

I have this in my draft. It is defined as
Bootstrapping is any processing required before the network can operate.

So following your suggestion, I should change it to key establishment when
the constrained node joins the network?

Regards,

Behcet

> The term "trust" by itself is extremely vague. So you better avoid it or
> be a bit more specific by saying "who trust whom to do what".
>
> Ciao
> Hannes
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>

--089e0112bfcead8a1704ed5c9ea8
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi Hannes,<br><div><div class=3D"gmail_extra"><br><br><div=
 class=3D"gmail_quote">On Thu, Dec 12, 2013 at 12:51 PM, Hannes Tschofenig =
<span dir=3D"ltr">&lt;<a href=3D"mailto:Hannes.Tschofenig@gmx.net" target=
=3D"_blank">Hannes.Tschofenig@gmx.net</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex"><div><div style=3D"font-f=
amily:Verdana;font-size:12px"><div><span style=3D"font-size:12px"><span sty=
le=3D"font-family:verdana,geneva,sans-serif">Could you guys do me a favor a=
nd avoid two terms in your drafts:=A0</span></span></div>


<div>=A0</div>

<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif"><span style=3D"white-space:pre-wrap;line-height:normal">1) B=
ootstrapping</span></span></span></div>

<div>
<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif">2) Trust</span></span></div>

<div>=A0</div>

<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif">The term bootstrapping was created a couple of years ago as =
a sort of marketing term. It means &quot;key distribution&quot;. Let us use=
 key distribution (or key establishment) instead since we know what it mean=
s. There are a number of key distribution protocols out there and we quickl=
y see the relationship to prior work.</span></span></div>


<div>=A0</div></div></div></div></blockquote><div><br></div><div>I have thi=
s in my draft. It is defined as <br>Bootstrapping is any processing require=
d before the network can operate. <br><br></div><div>So following your sugg=
estion, I should change it to key establishment when the constrained node j=
oins the network?<br>
<br></div><div>Regards,<br><br></div><div>Behcet<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex"><div><div style=3D"font-family:Verdana;fon=
t-size:12px">
<div>

<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif">The term &quot;trust&quot; by itself is extremely vague. So =
you better avoid it or be a bit more specific by=A0saying &quot;who trust w=
hom to do what&quot;. =A0=A0</span></span></div>


<div>=A0</div>

<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif">Ciao<span class=3D""><font color=3D"#888888"><br>
Hannes</font></span></span></span></div>

<div>=A0</div>
</div></div></div>
<br>_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br></div></div></div>

--089e0112bfcead8a1704ed5c9ea8--

From prvs=05172c9cc=bora@pnnl.gov  Thu Dec 12 13:20:04 2013
Return-Path: <prvs=05172c9cc=bora@pnnl.gov>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C56651AE4CF for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 13:20:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JRQDe_aiI-lD for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 13:20:01 -0800 (PST)
Received: from Emailgw01.pnnl.gov (emailgw01.pnnl.gov [IPv6:2620:0:50f0:2309:192:101:109:61]) by ietfa.amsl.com (Postfix) with ESMTP id 6F22C1AE4DB for <ace@ietf.org>; Thu, 12 Dec 2013 13:20:01 -0800 (PST)
Received: from ex10cashub01.pnnl.gov ([130.20.128.21]) by Emailgw01.pnnl.gov with ESMTP/TLS/AES128-SHA; 12 Dec 2013 13:19:55 -0800
Received: from EX10MBOX03.pnnl.gov ([169.254.3.40]) by EX10CASHUB01.pnnl.gov ([130.20.128.21]) with mapi id 14.02.0342.003; Thu, 12 Dec 2013 13:19:54 -0800
From: "Akyol, Bora A" <bora@pnnl.gov>
To: "sarikaya@ieee.org" <sarikaya@ieee.org>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: AQHO92s6TcHf6U+ui0iDoRzEoAieFJpRkVSA//9/oYA=
Date: Thu, 12 Dec 2013 21:19:54 +0000
Message-ID: <CECF67DF.14412%bora@pnnl.gov>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <CAC8QAcd1mZAEjHMs1LHvGuknOYZSETzfxnVjgu8hW7JO5gH9sA@mail.gmail.com>
In-Reply-To: <CAC8QAcd1mZAEjHMs1LHvGuknOYZSETzfxnVjgu8hW7JO5gH9sA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.3.9.131030
x-originating-ip: [130.20.128.10]
pnnlmail: 1
Content-Type: multipart/alternative; boundary="_000_CECF67DF14412borapnnlgov_"
MIME-Version: 1.0
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 21:20:05 -0000

--_000_CECF67DF14412borapnnlgov_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Behcet

Is key establishment the only step required?

Usually when I use the word bootstrapping, I include all steps needed to ge=
t an operational environment. This could include key establishment, trust r=
oot provisioning (if required), discovery of network services, etc.

I do agree that we should be specific in what we mean by bootstrapping, but=
 I do not support a regexp-replace to key establishment/distribution.

Thanks

Bora


From: Behcet Sarikaya <sarikaya2012@gmail.com<mailto:sarikaya2012@gmail.com=
>>
Reply-To: "sarikaya@ieee.org<mailto:sarikaya@ieee.org>" <sarikaya@ieee.org<=
mailto:sarikaya@ieee.org>>
Date: Thursday, December 12, 2013 at 12:59 PM
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net<mailto:Hannes.Tschofenig@g=
mx.net>>
Cc: "ace@ietf.org<mailto:ace@ietf.org>" <ace@ietf.org<mailto:ace@ietf.org>>
Subject: Re: [Ace] Terms to avoid

Hi Hannes,


On Thu, Dec 12, 2013 at 12:51 PM, Hannes Tschofenig <Hannes.Tschofenig@gmx.=
net<mailto:Hannes.Tschofenig@gmx.net>> wrote:
Could you guys do me a favor and avoid two terms in your drafts:

1) Bootstrapping
2) Trust

The term bootstrapping was created a couple of years ago as a sort of marke=
ting term. It means "key distribution". Let us use key distribution (or key=
 establishment) instead since we know what it means. There are a number of =
key distribution protocols out there and we quickly see the relationship to=
 prior work.


I have this in my draft. It is defined as
Bootstrapping is any processing required before the network can operate.

So following your suggestion, I should change it to key establishment when =
the constrained node joins the network?

Regards,

Behcet
The term "trust" by itself is extremely vague. So you better avoid it or be=
 a bit more specific by saying "who trust whom to do what".

Ciao
Hannes


_______________________________________________
Ace mailing list
Ace@ietf.org<mailto:Ace@ietf.org>
https://www.ietf.org/mailman/listinfo/ace



--_000_CECF67DF14412borapnnlgov_
Content-Type: text/html; charset="us-ascii"
Content-ID: <6F86E39FB834B848AD8EE19F57C54A22@pnnl.gov>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-lin=
e-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-fami=
ly: Calibri, sans-serif;">
<div>Hi Behcet</div>
<div><br>
</div>
<div>Is key establishment the only step required?</div>
<div><br>
</div>
<div>Usually when I use the word bootstrapping, I include all steps needed =
to get an operational environment. This could include key establishment, tr=
ust root provisioning (if required), discovery of network services, etc.</d=
iv>
<div><br>
</div>
<div>I do agree that we should be specific in what we mean by bootstrapping=
, but I do not support a regexp-replace to key establishment/distribution.<=
/div>
<div><br>
</div>
<div>Thanks</div>
<div><br>
</div>
<div>Bora</div>
<div><br>
</div>
<div><br>
</div>
<span id=3D"OLK_SRC_BODY_SECTION">
<div style=3D"font-family:Calibri; font-size:11pt; text-align:left; color:b=
lack; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM:=
 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid;=
 BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style=3D"font-weight:bold">From: </span>Behcet Sarikaya &lt;<a href=
=3D"mailto:sarikaya2012@gmail.com">sarikaya2012@gmail.com</a>&gt;<br>
<span style=3D"font-weight:bold">Reply-To: </span>&quot;<a href=3D"mailto:s=
arikaya@ieee.org">sarikaya@ieee.org</a>&quot; &lt;<a href=3D"mailto:sarikay=
a@ieee.org">sarikaya@ieee.org</a>&gt;<br>
<span style=3D"font-weight:bold">Date: </span>Thursday, December 12, 2013 a=
t 12:59 PM<br>
<span style=3D"font-weight:bold">To: </span>Hannes Tschofenig &lt;<a href=
=3D"mailto:Hannes.Tschofenig@gmx.net">Hannes.Tschofenig@gmx.net</a>&gt;<br>
<span style=3D"font-weight:bold">Cc: </span>&quot;<a href=3D"mailto:ace@iet=
f.org">ace@ietf.org</a>&quot; &lt;<a href=3D"mailto:ace@ietf.org">ace@ietf.=
org</a>&gt;<br>
<span style=3D"font-weight:bold">Subject: </span>Re: [Ace] Terms to avoid<b=
r>
</div>
<div><br>
</div>
<div>
<div>
<div dir=3D"ltr">Hi Hannes,<br>
<div>
<div class=3D"gmail_extra"><br>
<br>
<div class=3D"gmail_quote">On Thu, Dec 12, 2013 at 12:51 PM, Hannes Tschofe=
nig <span dir=3D"ltr">
&lt;<a href=3D"mailto:Hannes.Tschofenig@gmx.net" target=3D"_blank">Hannes.T=
schofenig@gmx.net</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<div style=3D"font-family:Verdana;font-size:12px">
<div><span style=3D"font-size:12px"><span style=3D"font-family: verdana, ge=
neva, sans-serif;">Could you guys do me a favor and avoid two terms in your=
 drafts:&nbsp;</span></span></div>
<div>&nbsp;</div>
<div><span style=3D"font-size:12px"><span style=3D"font-family:verdana,gene=
va,sans-serif"><span style=3D"white-space:pre-wrap;line-height:normal">1) B=
ootstrapping</span></span></span></div>
<div>
<div><span style=3D"font-size:12px"><span style=3D"font-family: verdana, ge=
neva, sans-serif;">2) Trust</span></span></div>
<div>&nbsp;</div>
<div><span style=3D"font-size:12px"><span style=3D"font-family: verdana, ge=
neva, sans-serif;">The term bootstrapping was created a couple of years ago=
 as a sort of marketing term. It means &quot;key distribution&quot;. Let us=
 use key distribution (or key establishment) instead
 since we know what it means. There are a number of key distribution protoc=
ols out there and we quickly see the relationship to prior work.</span></sp=
an></div>
<div>&nbsp;</div>
</div>
</div>
</div>
</blockquote>
<div><br>
</div>
<div>I have this in my draft. It is defined as <br>
Bootstrapping is any processing required before the network can operate. <b=
r>
<br>
</div>
<div>So following your suggestion, I should change it to key establishment =
when the constrained node joins the network?<br>
<br>
</div>
<div>Regards,<br>
<br>
</div>
<div>Behcet<br>
</div>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<div style=3D"font-family:Verdana;font-size:12px">
<div>
<div><span style=3D"font-size:12px"><span style=3D"font-family: verdana, ge=
neva, sans-serif;">The term &quot;trust&quot; by itself is extremely vague.=
 So you better avoid it or be a bit more specific by&nbsp;saying &quot;who =
trust whom to do what&quot;. &nbsp;&nbsp;</span></span></div>
<div>&nbsp;</div>
<div><span style=3D"font-size:12px"><span style=3D"font-family: verdana, ge=
neva, sans-serif;">Ciao<span class=3D""><font color=3D"#888888"><br>
Hannes</font></span></span></span></div>
<div>&nbsp;</div>
</div>
</div>
</div>
<br>
_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br>
</blockquote>
</div>
<br>
</div>
</div>
</div>
</div>
</div>
</span>
</body>
</html>

--_000_CECF67DF14412borapnnlgov_--

From cabo@tzi.org  Thu Dec 12 14:17:41 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E8C41ADF58 for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 14:17:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0jolWdxW-ClJ for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 14:17:40 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id C5A881AE098 for <ace@ietf.org>; Thu, 12 Dec 2013 14:17:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBCMHVoY001575; Thu, 12 Dec 2013 23:17:31 +0100 (CET)
Received: from [192.168.217.144] (p54890E24.dip0.t-ipconnect.de [84.137.14.36]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id EAEEE628; Thu, 12 Dec 2013 23:17:30 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
X-Priority: 3
In-Reply-To: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21>
Date: Thu, 12 Dec 2013 23:17:29 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21>
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1822)
Cc: ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 22:17:41 -0000

On 12 Dec 2013, at 19:51, Hannes Tschofenig <Hannes.Tschofenig@gmx.net> =
wrote:

> Could you guys do me a favor and avoid two terms in your drafts:=20
> =20
> 1) Bootstrapping
> 2) Trust

I completely agree about the term =93Trust=94.  This is neither an =
objective nor a method.
When people talk about =93trust=94 they usually either talk about the =
ability to authenticate something and/or an authorization relationship, =
but it is rarely fully fleshed out what specifically is meant.
(Some, but not all, of the uses of the term =93certificate=94 are of the =
same kind.)
Device B doesn=92t =93trust=94 device A, but device A is authorized to =
perform certain, well-defined operations on or relevant for device B, =
and that authorization (as well as the origin of the operation and/or =
communication channels) can be authenticated in the course of performing =
the operation.

I don=92t agree about not using bootstrapping.  Bootstrapping is not a =
method, it is an objective, which can be pinpointed pretty precisely in =
the lifecycle of a device.
More specifically, it relates to achieving the transition from a sparse =
or minimal, pre-operational set of authenticated authorizations to a set =
that can be used operationally.
(Key establishment is usually part of what needs to be done there, but =
the keys just serve to authenticate the authorizations, so I=92m not =
even sure they are very important for defining bootstrapping.)

I=92m sorry for this dense terminology attack, but I agree that we need =
to work on some of the terminology now to generate a credible charter.

Gr=FC=DFe, Carsten


From sarikaya2012@gmail.com  Thu Dec 12 14:23:02 2013
Return-Path: <sarikaya2012@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCDA31AE1EE for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 14:23:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.749
X-Spam-Level: 
X-Spam-Status: No, score=-1.749 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M-b50R8jLsOE for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 14:23:01 -0800 (PST)
Received: from mail-la0-x232.google.com (mail-la0-x232.google.com [IPv6:2a00:1450:4010:c03::232]) by ietfa.amsl.com (Postfix) with ESMTP id C274B1AE089 for <ace@ietf.org>; Thu, 12 Dec 2013 14:23:00 -0800 (PST)
Received: by mail-la0-f50.google.com with SMTP id el20so791697lab.37 for <ace@ietf.org>; Thu, 12 Dec 2013 14:22:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:reply-to:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=OaKiKsJHOIWpL6XRms1g21nGFPK61YT9yIyzWi0jSsQ=; b=eRRm+bXhuQiZ3eKjuP3Ys9ddS8EQnHaISuctJCv9hYwFpU4l/Nn7ykgBJBBad4o5Pe A7fLWQBbwwhQh9Vr8RhOrfnVIpJmjOI6vy3TByHhfQfXsRjZXP0+In7JcTCmTDK9mMlU 4a7G186In/7ibCthei8QPBfas1x8h59TXjKGf0pySgGGLZa8Gbp+mgukmYOWR1GQ4HhN Z+vXqy96USNfIiAadNSGUIpuTUQsEJBp0ricLZ5Yye9RQEoTkCSfboVelspUESu4qgiT /MDlQ3h3ZRNOOP8rNM5L5nk0Wkp0tb5EYkGcn8tUO/KgHO3WPQ9M+kLJDkzQXUmEiyTM Mgaw==
MIME-Version: 1.0
X-Received: by 10.152.238.34 with SMTP id vh2mr4996956lac.50.1386886974081; Thu, 12 Dec 2013 14:22:54 -0800 (PST)
Received: by 10.115.4.165 with HTTP; Thu, 12 Dec 2013 14:22:54 -0800 (PST)
In-Reply-To: <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>
Date: Thu, 12 Dec 2013 16:22:54 -0600
Message-ID: <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com>
From: Behcet Sarikaya <sarikaya2012@gmail.com>
To: Carsten Bormann <cabo@tzi.org>
Content-Type: multipart/alternative; boundary=001a1134989c6f0f6b04ed5dc913
Cc: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: sarikaya@ieee.org
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 22:23:03 -0000

--001a1134989c6f0f6b04ed5dc913
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Carsten,

Thanks for the clarification.

I completely agree with you.
I was having nightmares on how to replace bootstrapping.

Regards,

Behcet


On Thu, Dec 12, 2013 at 4:17 PM, Carsten Bormann <cabo@tzi.org> wrote:

> On 12 Dec 2013, at 19:51, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
> wrote:
>
> > Could you guys do me a favor and avoid two terms in your drafts:
> >
> > 1) Bootstrapping
> > 2) Trust
>
> I completely agree about the term =93Trust=94.  This is neither an object=
ive
> nor a method.
> When people talk about =93trust=94 they usually either talk about the abi=
lity
> to authenticate something and/or an authorization relationship, but it is
> rarely fully fleshed out what specifically is meant.
> (Some, but not all, of the uses of the term =93certificate=94 are of the =
same
> kind.)
> Device B doesn=92t =93trust=94 device A, but device A is authorized to pe=
rform
> certain, well-defined operations on or relevant for device B, and that
> authorization (as well as the origin of the operation and/or communicatio=
n
> channels) can be authenticated in the course of performing the operation.
>
> I don=92t agree about not using bootstrapping.  Bootstrapping is not a
> method, it is an objective, which can be pinpointed pretty precisely in t=
he
> lifecycle of a device.
> More specifically, it relates to achieving the transition from a sparse o=
r
> minimal, pre-operational set of authenticated authorizations to a set tha=
t
> can be used operationally.
> (Key establishment is usually part of what needs to be done there, but th=
e
> keys just serve to authenticate the authorizations, so I=92m not even sur=
e
> they are very important for defining bootstrapping.)
>
> I=92m sorry for this dense terminology attack, but I agree that we need t=
o
> work on some of the terminology now to generate a credible charter.
>
> Gr=FC=DFe, Carsten
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>

--001a1134989c6f0f6b04ed5dc913
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div><div><div>Hi Carsten,<br><br></div>Thanks f=
or the clarification.<br><br></div>I completely agree with you.<br></div>I =
was having nightmares on how to replace bootstrapping.<br><br></div>Regards=
,<br>
<br></div>Behcet<br></div><div class=3D"gmail_extra"><br><br><div class=3D"=
gmail_quote">On Thu, Dec 12, 2013 at 4:17 PM, Carsten Bormann <span dir=3D"=
ltr">&lt;<a href=3D"mailto:cabo@tzi.org" target=3D"_blank">cabo@tzi.org</a>=
&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im">On 12 Dec 2013, at 19:51, =
Hannes Tschofenig &lt;<a href=3D"mailto:Hannes.Tschofenig@gmx.net">Hannes.T=
schofenig@gmx.net</a>&gt; wrote:<br>

<br>
&gt; Could you guys do me a favor and avoid two terms in your drafts:<br>
&gt;<br>
&gt; 1) Bootstrapping<br>
&gt; 2) Trust<br>
<br>
</div>I completely agree about the term =93Trust=94. =A0This is neither an =
objective nor a method.<br>
When people talk about =93trust=94 they usually either talk about the abili=
ty to authenticate something and/or an authorization relationship, but it i=
s rarely fully fleshed out what specifically is meant.<br>
(Some, but not all, of the uses of the term =93certificate=94 are of the sa=
me kind.)<br>
Device B doesn=92t =93trust=94 device A, but device A is authorized to perf=
orm certain, well-defined operations on or relevant for device B, and that =
authorization (as well as the origin of the operation and/or communication =
channels) can be authenticated in the course of performing the operation.<b=
r>

<br>
I don=92t agree about not using bootstrapping. =A0Bootstrapping is not a me=
thod, it is an objective, which can be pinpointed pretty precisely in the l=
ifecycle of a device.<br>
More specifically, it relates to achieving the transition from a sparse or =
minimal, pre-operational set of authenticated authorizations to a set that =
can be used operationally.<br>
(Key establishment is usually part of what needs to be done there, but the =
keys just serve to authenticate the authorizations, so I=92m not even sure =
they are very important for defining bootstrapping.)<br>
<br>
I=92m sorry for this dense terminology attack, but I agree that we need to =
work on some of the terminology now to generate a credible charter.<br>
<br>
Gr=FC=DFe, Carsten<br>
<div class=3D"HOEnZb"><div class=3D"h5"><br>
_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
</div></div></blockquote></div><br></div>

--001a1134989c6f0f6b04ed5dc913--

From cabo@tzi.org  Thu Dec 12 15:03:19 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 454011AE1EE for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 15:03:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s_wwlNG2PjpV for <ace@ietfa.amsl.com>; Thu, 12 Dec 2013 15:03:18 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 364B51AE14B for <ace@ietf.org>; Thu, 12 Dec 2013 15:03:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBCN3889003175; Fri, 13 Dec 2013 00:03:08 +0100 (CET)
Received: from [192.168.217.144] (p54890E24.dip0.t-ipconnect.de [84.137.14.36]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 2BD2A63C; Fri, 13 Dec 2013 00:03:06 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
X-Priority: 3
In-Reply-To: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>
Date: Fri, 13 Dec 2013 00:03:03 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1822)
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 12 Dec 2013 23:03:19 -0000

On 12 Dec 2013, at 19:32, Hannes Tschofenig <Hannes.Tschofenig@gmx.net> =
wrote:

> Hi all,=20
> =20
> in a couple of drafts I see these pointers to access control lists =
being described in CoAP. However, the CoAP specification does not really =
say that much about access control lists and by no means describes how =
they are supposed to be used in any level of detail.=20

The CoAP base protocol (draft-ietf-core-coap) does not define ACLs.
It just says you need to have some, because the authentication that we =
get with DTLS is not the complete answer to the security requirements.

The current ACE charter proposal says ACE should define the ACLs for =
CoAP.
(My slide 105 from the CoRE WG at IETF88 says CoRE should define the =
ACLs for CoAP.
Let=92s decide which WG does what *after* deciding what needs to be =
done.)

Gr=FC=DFe, Carsten


From ludwig@sics.se  Fri Dec 13 00:23:07 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B8B71AE1E0 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 00:23:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v7ruTNTr1dLu for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 00:23:03 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 2948E1AE1C6 for <ace@ietf.org>; Fri, 13 Dec 2013 00:23:00 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBD8MrmZ003459 for <ace@ietf.org>; Fri, 13 Dec 2013 09:22:53 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asaecwy-1 for <ace@ietf.org>; Fri, 13 Dec 2013 09:22:53 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 778B9400E2 for <ace@ietf.org>; Fri, 13 Dec 2013 09:22:53 +0100 (CET)
Message-ID: <52AAC3DD.9030802@sics.se>
Date: Fri, 13 Dec 2013 09:22:53 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org>
In-Reply-To: <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020506060403050906010701"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-13_03:2013-12-12,2013-12-13,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312130003
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 08:23:07 -0000

This is a cryptographically signed message in MIME format.

--------------ms020506060403050906010701
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/13/2013 12:03 AM, Carsten Bormann wrote:
>
> On 12 Dec 2013, at 19:32, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>=
 wrote:
>
>> Hi all,
>>
>> in a couple of drafts I see these pointers to access control lists bei=
ng described in CoAP. However, the CoAP specification does not really say=
 that much about access control lists and by no means describes how they =
are supposed to be used in any level of detail.
>
> The CoAP base protocol (draft-ietf-core-coap) does not define ACLs.
> It just says you need to have some, because the authentication that we =
get with DTLS is not the complete answer to the security requirements.
>
> The current ACE charter proposal says ACE should define the ACLs for Co=
AP.
> (My slide 105 from the CoRE WG at IETF88 says CoRE should define the AC=
Ls for CoAP.
> Let=92s decide which WG does what *after* deciding what needs to be don=
e.)
>
> Gr=FC=DFe, Carsten
>
+1

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms020506060403050906010701
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTMwODIyNTNaMCMGCSqGSIb3DQEJBDEW
BBTJg2Q60vLOsLDLpXPPi6jm95a2kDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEASC3GOhJHpof8kvJ6R5qb7vYH2C9XVqwiq+CKaDmKpm/DnUVS0fR3Yqvw/bmdt1ABZfYx
OQuW25/LdpyZs/f3vY/eEwARq+kwDk3LuAM6jdF2f6ii5i5IJwqHBUpWCQvmtPB9zB4iIW/2
YSu+7nmwUkYVe5F4bdr7Ic0L81HWnAl9ohEeSZnTJvz3tABVEA2HbCGQodqStS2ygp0zjacS
HRw4GN9c9tO3n1jdrFwZpoTg1qQ81SM+KXzHIAAyblhFfUC1IBa6CAi9NPVuMgtSpo9hrB0/
fI5TpvyiQdkVm1chgMwdQS/qZRR7Wc+XEQKAR2jEs7SOJGTx2O776cktBAAAAAAAAA==
--------------ms020506060403050906010701--

From ludwig@sics.se  Fri Dec 13 01:05:47 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3046E1ADBCA for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 01:05:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LPmex4sdIvBJ for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 01:05:46 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 40F041AD937 for <ace@ietf.org>; Fri, 13 Dec 2013 01:05:44 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBD95bZD002921 for <ace@ietf.org>; Fri, 13 Dec 2013 10:05:37 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asaedec-1 for <ace@ietf.org>; Fri, 13 Dec 2013 10:05:37 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 34C58400E2 for <ace@ietf.org>; Fri, 13 Dec 2013 10:05:37 +0100 (CET)
Message-ID: <52AACDE0.1010305@sics.se>
Date: Fri, 13 Dec 2013 10:05:36 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD22CA@SZXEMA501-MBS.china.huawei.com> <19752.1386791656@sandelman.ca> <90BBF9A7-B352-4C63-A8B8-E29D0E035332@tzi.org> <26190.1386812308@sandelman.ca> <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com>
In-Reply-To: <CADJ9OA_PJaFARRfvyECyPjekyzFOYFddcLAyLO1yr+fMugPsnw@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms070800020502070006090906"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-13_03:2013-12-12,2013-12-13,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312130013
Subject: Re: [Ace] Draft ACE Charter
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 09:05:47 -0000

This is a cryptographically signed message in MIME format.

--------------ms070800020502070006090906
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/12/2013 03:36 AM, Thomas Watteyne wrote:
> Carsten,
>
> Could you elaborate your argumentation about YANG?
>
> When I read
> "There is a very thin line between operations on authorization state an=
d
> other configuration management."
> I think
> "great, so a need to run only a single set of tools on my nodes to
> enable both".
>

Reusing the same tool for some other means is mostly frowned upon by=20
crytpo people ;-)

Earnestly: YANG is about data modelling, so you could use it to model=20
authorization data. Has that been done before outside of Netconf?

My preference would be to use the same notation as in relevant other=20
security RFCs e.g. TLS (or perhaps JWT/JWE/JWS if we use JSON) to=20
describe our data structures.

/Ludwig







--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms070800020502070006090906
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTMwOTA1MzZaMCMGCSqGSIb3DQEJBDEW
BBQ9GRJ19UjOznyQKBFF00JCoqIMVzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEALodwfIdPaUpJXqwbtmu6i3z13vjxpT9FCAEEUyjs8CpOWA8hFz+JqX0jCWRTO74riXfV
Rzg4rameX2ntoroVv0ZkuFLqadwXC8ja2VFUqWnpVXH7xMb96rFG1g4BIYYn/0qzp6JDZRtB
xxYTZV4s9OYkPTwPlKUiyvFVRFH0akYoba1QzOkPXY+u8VcNOJUq2aztP+QOCiC75HT2WEEL
zxvW5iyakwj4C+WIzq/eORhAiKhdGAzxsdtzNHbnAfQxs+nqHuz4enLsHB8bD402uh0eWUTw
0CZk69Y1h96STQIlfPKRwgUPzsDFkDZVaItPM/Eyo6w4Tzm9bVqaMl13rAAAAAAAAA==
--------------ms070800020502070006090906--

From likepeng@huawei.com  Fri Dec 13 02:16:43 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E56701ADF5D for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 02:16:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8YuL-H2UgPKv for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 02:16:41 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 86C511ADBC9 for <ace@ietf.org>; Fri, 13 Dec 2013 02:16:40 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBJ06059; Fri, 13 Dec 2013 10:16:33 +0000 (GMT)
Received: from LHREML406-HUB.china.huawei.com (10.201.5.243) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Fri, 13 Dec 2013 10:15:37 +0000
Received: from SZXEMA406-HUB.china.huawei.com (10.82.72.38) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Fri, 13 Dec 2013 10:15:53 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA406-HUB.china.huawei.com ([10.82.72.38]) with mapi id 14.03.0158.001; Fri, 13 Dec 2013 18:15:46 +0800
From: Likepeng <likepeng@huawei.com>
To: Carsten Bormann <cabo@tzi.org>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: AQHO92swut0VGmvey0qAQQLzZcFNrJpQmvCAgADi4iA=
Date: Fri, 13 Dec 2013 10:15:46 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>
In-Reply-To: <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 10:16:43 -0000

PndlIG5lZWQgdG8gd29yayBvbiBzb21lIG9mIHRoZSB0ZXJtaW5vbG9neSBub3cgdG8gZ2VuZXJh
dGUgYSBjcmVkaWJsZSBjaGFydGVyLg0KDQpJIGNoZWNrZWQgUkZDIDQ5NDkgIkludGVybmV0IFNl
Y3VyaXR5IEdsb3NzYXJ5LCBWZXJzaW9uIDIiLCB0aGlzIFJGQyBkZWZpbmVzIGEgbG90IG9mIHNl
Y3VyaXR5IHJlbGF0ZWQgdGVybXMuIFdlIGNhbiByZXVzZSB0aGUgdGVybWlub2xvZ2llcyBkZWZp
bmVkIGluIHRoaXMgZG9jdW1lbnQuIA0KDQpJIGNoZWNrZWQgb3VyIGNoYXJ0ZXIsIGZvciBzb21l
IHRlcm1zLCB3ZSBjYW4gZmluZCBkZWZpbml0aW9ucywgYnV0IHRoZXJlIGFyZSBubyBkZWZpbml0
aW9ucyBmb3IgImJvb3RzdHJhcCIsICJhdXRob3JpemF0aW9uIGluZm9ybWF0aW9uIiBhbmQgImFj
Y2VzcyB0b2tlbiIuDQoNCkZvciAiYm9vdHN0cmFwIiwgdGhlIGRlZmluaXRpb24gZnJvbSBPTUEg
aXM6IHRoZSBwcm9jZXNzIG9mIHByb3Zpc2lvbmluZyB0aGUgY2xpZW50IHRvIGEgc3RhdGUgd2hl
cmUgaXQgaXMgYWJsZSB0byBpbml0aWF0ZSBhIG1hbmFnZW1lbnQgc2Vzc2lvbiB0byBhIG5ldyBz
ZXJ2ZXIuDQpJdCBpcyBxdWl0ZSBzaW1pbGFyIHRvIHdoYXQgQ2Fyc3RlbiBhbmQgQmVoY2V0IGhh
dmUgZGVzY3JpYmVkLiANCg0KRm9yICJhdXRob3JpemF0aW9uIGluZm9ybWF0aW9uIiwgd2UgY2Fu
IGNoYW5nZSBpdCB0byB0aGUgdGVybSBkZWZpbmVkIGluIFJGQyA0OTQ5LCBtYXliZSBhdXRob3Jp
emF0aW9uIGNyZWRlbnRpYWxzPw0KDQpGb3IgImFjY2VzcyB0b2tlbiIsIHRoZXJlIGlzIG5vIGRl
ZmluaXRpb24gaW4gUkZDIDQ5NDksIGJ1dCB0aGVyZSBhcmUgZGVmaW5pdGlvbnMgZm9yICJhY2Nl
c3MiIGFuZCAidG9rZW4iLiBJdCBzaG91bGQgYmUgZmluZSB0byB1c2UgImFjY2VzcyB0b2tlbiIg
b3IganVzdCAidG9rZW4iLg0KDQpLaW5kIFJlZ2FyZHMNCktlcGVuZw0KDQotLS0tLemCruS7tuWO
n+S7ti0tLS0tDQrlj5Hku7bkuro6IEFjZSBbbWFpbHRvOmFjZS1ib3VuY2VzQGlldGYub3JnXSDk
u6PooaggQ2Fyc3RlbiBCb3JtYW5uDQrlj5HpgIHml7bpl7Q6IDIwMTPlubQxMuaciDEz5pelIDY6
MTcNCuaUtuS7tuS6ujogSGFubmVzIFRzY2hvZmVuaWcNCuaKhOmAgTogYWNlQGlldGYub3JnDQrk
uLvpopg6IFJlOiBbQWNlXSBUZXJtcyB0byBhdm9pZA0KDQpPbiAxMiBEZWMgMjAxMywgYXQgMTk6
NTEsIEhhbm5lcyBUc2Nob2ZlbmlnIDxIYW5uZXMuVHNjaG9mZW5pZ0BnbXgubmV0PiB3cm90ZToN
Cg0KPiBDb3VsZCB5b3UgZ3V5cyBkbyBtZSBhIGZhdm9yIGFuZCBhdm9pZCB0d28gdGVybXMgaW4g
eW91ciBkcmFmdHM6IA0KPiAgDQo+IDEpIEJvb3RzdHJhcHBpbmcNCj4gMikgVHJ1c3QNCg0KSSBj
b21wbGV0ZWx5IGFncmVlIGFib3V0IHRoZSB0ZXJtIOKAnFRydXN04oCdLiAgVGhpcyBpcyBuZWl0
aGVyIGFuIG9iamVjdGl2ZSBub3IgYSBtZXRob2QuDQpXaGVuIHBlb3BsZSB0YWxrIGFib3V0IOKA
nHRydXN04oCdIHRoZXkgdXN1YWxseSBlaXRoZXIgdGFsayBhYm91dCB0aGUgYWJpbGl0eSB0byBh
dXRoZW50aWNhdGUgc29tZXRoaW5nIGFuZC9vciBhbiBhdXRob3JpemF0aW9uIHJlbGF0aW9uc2hp
cCwgYnV0IGl0IGlzIHJhcmVseSBmdWxseSBmbGVzaGVkIG91dCB3aGF0IHNwZWNpZmljYWxseSBp
cyBtZWFudC4NCihTb21lLCBidXQgbm90IGFsbCwgb2YgdGhlIHVzZXMgb2YgdGhlIHRlcm0g4oCc
Y2VydGlmaWNhdGXigJ0gYXJlIG9mIHRoZSBzYW1lIGtpbmQuKSBEZXZpY2UgQiBkb2VzbuKAmXQg
4oCcdHJ1c3TigJ0gZGV2aWNlIEEsIGJ1dCBkZXZpY2UgQSBpcyBhdXRob3JpemVkIHRvIHBlcmZv
cm0gY2VydGFpbiwgd2VsbC1kZWZpbmVkIG9wZXJhdGlvbnMgb24gb3IgcmVsZXZhbnQgZm9yIGRl
dmljZSBCLCBhbmQgdGhhdCBhdXRob3JpemF0aW9uIChhcyB3ZWxsIGFzIHRoZSBvcmlnaW4gb2Yg
dGhlIG9wZXJhdGlvbiBhbmQvb3IgY29tbXVuaWNhdGlvbiBjaGFubmVscykgY2FuIGJlIGF1dGhl
bnRpY2F0ZWQgaW4gdGhlIGNvdXJzZSBvZiBwZXJmb3JtaW5nIHRoZSBvcGVyYXRpb24uDQoNCkkg
ZG9u4oCZdCBhZ3JlZSBhYm91dCBub3QgdXNpbmcgYm9vdHN0cmFwcGluZy4gIEJvb3RzdHJhcHBp
bmcgaXMgbm90IGEgbWV0aG9kLCBpdCBpcyBhbiBvYmplY3RpdmUsIHdoaWNoIGNhbiBiZSBwaW5w
b2ludGVkIHByZXR0eSBwcmVjaXNlbHkgaW4gdGhlIGxpZmVjeWNsZSBvZiBhIGRldmljZS4NCk1v
cmUgc3BlY2lmaWNhbGx5LCBpdCByZWxhdGVzIHRvIGFjaGlldmluZyB0aGUgdHJhbnNpdGlvbiBm
cm9tIGEgc3BhcnNlIG9yIG1pbmltYWwsIHByZS1vcGVyYXRpb25hbCBzZXQgb2YgYXV0aGVudGlj
YXRlZCBhdXRob3JpemF0aW9ucyB0byBhIHNldCB0aGF0IGNhbiBiZSB1c2VkIG9wZXJhdGlvbmFs
bHkuDQooS2V5IGVzdGFibGlzaG1lbnQgaXMgdXN1YWxseSBwYXJ0IG9mIHdoYXQgbmVlZHMgdG8g
YmUgZG9uZSB0aGVyZSwgYnV0IHRoZSBrZXlzIGp1c3Qgc2VydmUgdG8gYXV0aGVudGljYXRlIHRo
ZSBhdXRob3JpemF0aW9ucywgc28gSeKAmW0gbm90IGV2ZW4gc3VyZSB0aGV5IGFyZSB2ZXJ5IGlt
cG9ydGFudCBmb3IgZGVmaW5pbmcgYm9vdHN0cmFwcGluZy4pDQoNCknigJltIHNvcnJ5IGZvciB0
aGlzIGRlbnNlIHRlcm1pbm9sb2d5IGF0dGFjaywgYnV0IEkgYWdyZWUgdGhhdCB3ZSBuZWVkIHRv
IHdvcmsgb24gc29tZSBvZiB0aGUgdGVybWlub2xvZ3kgbm93IHRvIGdlbmVyYXRlIGEgY3JlZGli
bGUgY2hhcnRlci4NCg0KR3LDvMOfZSwgQ2Fyc3Rlbg0KDQpfX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fXw0KQWNlIG1haWxpbmcgbGlzdA0KQWNlQGlldGYub3Jn
DQpodHRwczovL3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2FjZQ0K

From ietf@sandeep.de  Fri Dec 13 02:20:53 2013
Return-Path: <ietf@sandeep.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 857281AE1D0 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 02:20:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.027
X-Spam-Level: 
X-Spam-Status: No, score=-1.027 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7Pbqz3udJ3QM for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 02:20:50 -0800 (PST)
Received: from mo6-p00-ob.rzone.de (mo6-p00-ob.rzone.de [IPv6:2a01:238:20a:202:5300::1]) by ietfa.amsl.com (Postfix) with ESMTP id 55C111AE1C5 for <ace@ietf.org>; Fri, 13 Dec 2013 02:20:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; t=1386930041; l=9102; s=domk; d=sandeep.de; h=Content-Type:Cc:To:From:Subject:Date:References:In-Reply-To: MIME-Version:X-RZG-CLASS-ID:X-RZG-AUTH; bh=AUYOE38Zk9EzMtk92EHFBE9gF68=; b=HiVtq88lZfSZfV6QXIx84kCqI31sFKYK4H2xkoF+deP17D5JUB2MYmLtwWckk6BWEJ2 KpYgHrX7/SW3T39+D9mwZgPN38esrxt5v0x0t+NRknfrgdna/LDR2LjxhGSs+K4HPyo10 XVN/L+GzEJKRrbiFp1TyyIwoBJI6pcLcHOc=
X-RZG-AUTH: :JWkQc2C7evFfytIRBe7p82UYMzBqkr+YiXEkNEKLhUifTGQSEYQcmbo=
X-RZG-CLASS-ID: mo00
Received: from mail-bk0-f44.google.com ([209.85.214.44]) by smtp.strato.de (RZmta 32.17 AUTH) with (TLSv1:DHE-RSA-AES256-SHA encrypted) ESMTPSA id Y04d2bpBDAKfcyE for <ace@ietf.org>; Fri, 13 Dec 2013 11:20:41 +0100 (CET)
Received: by mail-bk0-f44.google.com with SMTP id d7so1299786bkh.31 for <ace@ietf.org>; Fri, 13 Dec 2013 02:20:41 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=1LE6MAlaxsRXa4asgngMFLpkMYQGMX0NnS/fLAeMEKk=; b=LMSGrO0thk14RdYyZcnalFKtg4Q824cscutqqioibenWfIDbUPDZ3vVDDFHi06te/m iGJQyuRGIWVKZ+VD4MNVBYt3zGBbWRxVXSgvstP1xXiQ0hFjEnFNwzyFPRY9HqUbZRNa ymKITFRZAuWxjvp/nhJ95XPXCKl4VgQkrZudRgVkXQXi52/zK6LQh2bus8Z090VSaRs2 VN8LLob6n/yJ5hirgawrnTlPYxtgEiqEGdXQTRI4yjhfiaigdZnBz06i7wpKwLgsqpqk QFrVdF0/VVSnzVJiPuxwga+unsbb6TACw1QMbDgI480okPDHN2kiCxZTWZsWcTt7NVdJ gu/A==
MIME-Version: 1.0
X-Received: by 10.205.74.4 with SMTP id yu4mr112889bkb.104.1386930041279; Fri, 13 Dec 2013 02:20:41 -0800 (PST)
Received: by 10.205.25.199 with HTTP; Fri, 13 Dec 2013 02:20:41 -0800 (PST)
In-Reply-To: <trinity-e2a1a839-6756-4be5-831d-9ed1927ef217-1386866825278@3capp-gmx-bs21>
References: <trinity-e2a1a839-6756-4be5-831d-9ed1927ef217-1386866825278@3capp-gmx-bs21>
Date: Fri, 13 Dec 2013 11:20:41 +0100
Message-ID: <CAH51uSfwnMn5YyGM9WNgqsK48iAgH8irb5Vh=tcxiE4C29HVjw@mail.gmail.com>
From: Sandeep Kumar <ietf@sandeep.de>
To: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
Content-Type: multipart/alternative; boundary=f46d0415532c709fd804ed67d0a3
Cc: ace@ietf.org
Subject: Re: [Ace] draft-garcia-core-security-06
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 10:20:53 -0000
X-List-Received-Date: Fri, 13 Dec 2013 10:20:53 -0000

--f46d0415532c709fd804ed67d0a3
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Hannes


On Thu, Dec 12, 2013 at 5:47 PM, Hannes Tschofenig <
Hannes.Tschofenig@gmx.net> wrote:

>  Dear Oscar, Sandeep, Sye Loong, Rene^2,
>
> thanks for submitting this document. I took a look at the scenario part,
> which talks about Building Automation and Control (BAC).
>

This document has been around for quite some years now and gives a general
overview of the security considerations in the constrained environments and
goes beyond authorization.


>
> I ran into a few questions:
> =95    You illustrate the lifecycle of an IoT device and the device ident=
ity
> and the secret keys are provided to the device during the "installation"
> and "commissioning" phase. You seem to assume that there is no keying
> material provided to the device during the manufacturing process? Is that
> correct?
>

We do assume there is some form of security material (device identities,
keys, etc) on the devices after manufacturing that enables a secure
installation and commissioning. However the identities and keys (that you
mention) provided during commissioning are for the operational phase which
in most cases are different from the original manufacturing phase
identities and keys.

"device identity and the secret keys used during *normal operation* are
provided to the device during this phase"




>  =95    I also wasn=92t quite sure whether you assume that there are diff=
erent
> credentials being used for network access, and for access to the differen=
t
> services.
>

Yes, there are a whole bunch of security associations that need to be
created based on what the device intends to do, if it needs just network
access or be part of a secure multicast group or access a particular
backend service, etc. Different credentials need to be then provided during
the commissioning/re-commissioing phase and preferably using a common
protocol.


> =95    How is authorization accomplished in the BAC environment?
>

Presently authorizations in BAC are quite static for obvious reasons,
things don't change much dynamically after the commissioning phase where it
is known before hand which device service needs to be authorized to which
other device service. An ACL at the service layer works pretty well in such
a static environment. In home automation, things may be slightly different
where new devices may need to be added without a professional
installer/commissioner, and then there can be a need for "easier" solutions=
.


> =95    Why did you pick the BAC environment as an example use for the
> document? Is it because of your experience with this sector? Or does it
> have specific characteristics not found in other areas?
>

Professional lighting (in offices, hospitals, malls, etc) is often part of
BAC and we do have a pretty good view of the issues in this domain. There
are very specific characteristics due to the deployment sequence in
buildings for e.g. the BAC is connected to the backend IT infrastructure at
a quite later stage, to name one.

regards
Sandeep


Ciao
Hannes

______________________________
>
> _________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace

--f46d0415532c709fd804ed67d0a3
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div>Hi Hannes<br><br></div><br></div><div class=3D"i=
m">On Thu, Dec 12, 2013 at 5:47 PM, Hannes Tschofenig <span dir=3D"ltr">&lt=
;<a href=3D"mailto:Hannes.Tschofenig@gmx.net" target=3D"_blank">Hannes.Tsch=
ofenig@gmx.net</a>&gt;</span> wrote:<br>

</div><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><=
div><div style=3D"font-family:Verdana;font-size:12px">
<div>
<div>Dear Oscar, Sandeep, Sye Loong, Rene^2,=A0</div>

<div>=A0</div>

<div>thanks for submitting this document. I took a look at the scenario=20
part, which talks about Building Automation and Control (BAC).=A0</div></di=
v></div></div></blockquote></div><div><br>This document has been around for=
 quite some years now and gives a=20
general overview of the security considerations in the constrained=20
environments and goes beyond authorization.<br>=A0</div><div class=3D"im"><=
blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-l=
eft:1px solid rgb(204,204,204);padding-left:1ex"><div><div style=3D"font-fa=
mily:Verdana;font-size:12px">

<div>

<div>=A0</div>

<div>I ran into a few questions: =A0<br>
=95=A0=A0 =A0You illustrate the lifecycle of an IoT device and the device=
=20
identity and the secret keys are provided to the device during the=20
&quot;installation&quot; and &quot;commissioning&quot; phase. You seem to a=
ssume that there=20
is no keying material provided to the device during the manufacturing=20
process? Is that correct?=A0<br>
</div></div></div></div></blockquote></div><div><br>We do assume there=20
is some form of security material (device identities, keys, etc) on the=20
devices after manufacturing that enables a secure installation and=20
commissioning. However the identities and keys (that you mention)=20
provided during commissioning are for the operational phase which in=20
most cases are different from the original manufacturing phase=20
identities and keys.<br>
<pre>&quot;device identity and the secret keys used during <b>normal operat=
ion</b> are <br>provided to the device during this phase&quot;</pre>=A0</di=
v><div class=3D"im"><div>=A0</div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">

<div><div style=3D"font-family:Verdana;font-size:12px"><div><div>
=95=A0=A0 =A0I also wasn=92t quite sure whether you assume that there are=
=20
different credentials being used for network access, and for access to=20
the different services.=A0<br></div></div></div></div></blockquote><div>=A0=
</div></div><div>Yes,
 there are a whole bunch of security associations that need to be=20
created based on what the device intends to do, if it needs just network
 access or be part of a secure multicast group or access a particular=20
backend service, etc. Different credentials need to be then provided=20
during the commissioning/re-commissioing phase and preferably using a=20
common protocol.<br>
</div><div class=3D"im"><div>=A0</div><blockquote class=3D"gmail_quote" sty=
le=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddi=
ng-left:1ex"><div><div style=3D"font-family:Verdana;font-size:12px"><div><d=
iv>
=95=A0=A0 =A0How is authorization accomplished in the BAC environment?=A0<b=
r></div></div></div></div></blockquote><div><br></div></div><div>Presently
 authorizations in BAC are quite static for obvious reasons, things=20
don&#39;t change much dynamically after the commissioning phase where it is=
=20
known before hand which device service needs to be authorized to which=20
other device service. An ACL at the service layer works pretty well in=20
such a static environment. In home automation, things may be slightly=20
different where new devices may need to be added without a professional=20
installer/commissioner, and then there can be a need for &quot;easier&quot;=
=20
solutions.<br>
=A0<br></div><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"m=
argin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left=
:1ex"><div><div style=3D"font-family:Verdana;font-size:12px"><div><div>
=95=A0=A0 =A0Why did you pick the BAC environment as an example use for the=
=20
document? Is it because of your experience with this sector? Or does it=20
have specific characteristics not found in other areas?=A0</div></div></div=
></div>
</blockquote><div><br></div></div><div>Professional lighting (in=20
offices, hospitals, malls, etc) is often part of BAC and we do have a=20
pretty good view of the issues in this domain. There are very specific=20
characteristics due to the deployment sequence in buildings for e.g. the
 BAC is connected to the backend IT infrastructure at a quite later=20
stage, to name one.<br>
</div><div><br></div><div>regards<br></div><div>Sandeep <br></div><div><br>=
</div><div><div style=3D"font-family:Verdana;font-size:12px">
<div>

<div>=A0</div>

<div>Ciao<span><font color=3D"#888888"><br>
Hannes</font></span></div>
</div></div></div>
<br>______________________________<blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">_________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org" target=3D"_blank">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a></blockquote></div>

--f46d0415532c709fd804ed67d0a3--

From ludwig@sics.se  Fri Dec 13 03:32:57 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A88B1AE225 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 03:32:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id odblIdOHZzu5 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 03:32:54 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 1D2801AE063 for <ace@ietf.org>; Fri, 13 Dec 2013 03:32:53 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBDBWkFL013237 for <ace@ietf.org>; Fri, 13 Dec 2013 12:32:46 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asaefeb-1 for <ace@ietf.org>; Fri, 13 Dec 2013 12:32:46 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 48185400E2 for <ace@ietf.org>; Fri, 13 Dec 2013 12:32:46 +0100 (CET)
Message-ID: <52AAF05E.2050305@sics.se>
Date: Fri, 13 Dec 2013 12:32:46 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms080404070100070000020504"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-13_03:2013-12-12,2013-12-13,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312130041
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 11:32:57 -0000

This is a cryptographically signed message in MIME format.

--------------ms080404070100070000020504
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/13/2013 11:15 AM, Likepeng wrote:
>> we need to work on some of the terminology now to generate a credible =
charter.
>
> I checked RFC 4949 "Internet Security Glossary, Version 2", this RFC de=
fines a lot of security related terms. We can reuse the terminologies def=
ined in this document.
>
> I checked our charter, for some terms, we can find definitions, but the=
re are no definitions for "bootstrap", "authorization information" and "a=
ccess token".
>
> For "bootstrap", the definition from OMA is: the process of provisionin=
g the client to a state where it is able to initiate a management session=
 to a new server.
> It is quite similar to what Carsten and Behcet have described.
>
> For "authorization information", we can change it to the term defined i=
n RFC 4949, maybe authorization credentials?
>
> For "access token", there is no definition in RFC 4949, but there are d=
efinitions for "access" and "token". It should be fine to use "access tok=
en" or just "token".


I think the RFC4949 definition of 'token' doesn't quite match what we mea=
n:

"   $ token
	...
       2. (I) /access control/ An object that is used to control access
       and is passed between cooperating entities in a protocol that
       synchronizes use of a shared resource. Usually, the entity that
       currently holds the token has exclusive access to the resource.
       (See: capability token.)
"

The way draft-selander (and draft-gerdes if I'm not mistaken) defines=20
the use of tokens, they don't give _exclusive_ access.

Also if you look at 'capability token':

"	... Possession of the token is accepted by a system as proof
	that the holder has been authorized to access the resource
	 indicated by the token.
"

That also isn't quite in line with draft-selander and draft-gerdes,=20
since both define some subject-binding in the token.

I'd prefer to use "authorization credential" instead of "authorization=20
token".

"Authorization information" is a really vague term, but the analogue=20
"authentication information" is used several times in RFC4949 without=20
being defined, so perhaps we can get away with using it anyway.


/Ludwig









--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=C3=A4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms080404070100070000020504
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTMxMTMyNDZaMCMGCSqGSIb3DQEJBDEW
BBSGBMMY/XOW4RKmr6UQdVv0B/EP9TBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEABqrM/42u/VuPzxZp4LIvQvwFRmNQr8Kj7NnLEphC89PSqXapmmvchdFEVnc0Hka1Y3R+
+lNDTn9VEMsTzMhiheLYZjmUQfgaKYmsPzhP8BVqRMM1qm7QBqbNkex40X7CGLIRQllDDfj5
zNBy6dqYyXeAjUuAjbqBsqY+yo347ohU6fNHM2tk8Hzr/NnDjPnqIxK/d4OlgITPDlPLoNXe
xu97dcpNulrcCKIjtcscWreAu8yOfqXfOO58xWccMpFtIkfOUviIXF2UuDjNrg+mecbb7cpK
Qgfm7g9i5x8IsD5rvrfB9AuFX9NoV1PKQ0eidZKwNQhJ1P5E6YNqOkkW4AAAAAAAAA==
--------------ms080404070100070000020504--

From cabo@tzi.org  Fri Dec 13 03:55:21 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC9AD1AE1F9 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 03:55:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mPrOl5IkZ3Ia for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 03:55:20 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 159F41AE08D for <ace@ietf.org>; Fri, 13 Dec 2013 03:55:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBDBt7ra013866; Fri, 13 Dec 2013 12:55:07 +0100 (CET)
Received: from [192.168.217.22] (p54892442.dip0.t-ipconnect.de [84.137.36.66]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id A4B438B6; Fri, 13 Dec 2013 12:55:05 +0100 (CET)
Message-Id: <41FC64AF-BD75-45B1-AF1E-8738C64CD9E4@tzi.org>
From: Carsten Bormann <cabo@tzi.org>
To: Likepeng <likepeng@huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; delsp=yes
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v936)
Date: Fri, 13 Dec 2013 12:54:51 +0100
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
X-Mailer: Apple Mail (2.936)
Cc: Carsten Bormann <cabo@tzi.org>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 11:55:21 -0000

On Dec 13 2013, at 11:15, Likepeng wrote:

> RFC 4949

I agree that we should use 4949 for everything that's in there.

But we are trying to do new things.
So it is not too surprising that there are gaps.

We shouldn't try to use 4949 terms that don't quite fit what we are =20
doing; here we should be bold enough to make our own terms.

Gr=FC=DFe, Carsten


From Hannes.Tschofenig@gmx.net  Fri Dec 13 04:14:53 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6CCB01A1F7D for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 04:14:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.177
X-Spam-Level: 
X-Spam-Status: No, score=-1.177 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e5CsUAXqElZW for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 04:14:50 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) by ietfa.amsl.com (Postfix) with ESMTP id 370161A1F5E for <ace@ietf.org>; Fri, 13 Dec 2013 04:14:50 -0800 (PST)
Received: from 3capp-gmx-bs24.server.lan ([172.19.170.76]) by mrigmx.server.lan (mrigmx001) with ESMTP (Nemesis) id 0LbfGf-1V6n960Q15-00lEb3 for <ace@ietf.org>; Fri, 13 Dec 2013 13:14:43 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs24.server.lan with HTTP; Fri Dec 13 13:14:43 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: sarikaya@ieee.org
Content-Type: text/html; charset=UTF-8
Date: Fri, 13 Dec 2013 13:14:43 +0100 (CET)
Importance: normal
Sensitivity: Normal
In-Reply-To: <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>, <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com>
X-UI-Message-Type: mail
X-Priority: 3
X-Provags-ID: V03:K0:mnz5SbTIKDFzLxCt8Bo2EYqCsv6+/q/gWUd4bHbaS2Q Bxk4skTw3t4rayD4gHlKPUDcy3lth08LDEX77cZTeDBHXqjA31 cINUOToiEdkWdC1tjZVewStBNGZQONMAho8vzo7LyfqAHzHNgo qTiDdqgSR27E1YpfkUJOiVQkj+dSjF/N/iAuc0OnBNvUtQ6Fhv A3BdQGFsP1JN/jxo2bx7dT44IPtXCDX4osUZxOUE1fyjPM5ori RUmS+a1/65gnL+BDFDADPWLvkkLki0U4sgaXaIIfI8VIaWr/jS gv6TmI=
Cc: Carsten Bormann <cabo@tzi.org>, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 12:14:53 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>The response I get from both of you shows me already that there is a problem.&nbsp;</div>

<div>&nbsp;</div>

<div>Behcet responded that it is &quot;Bootstrapping is any processing required before the network can operate.&quot;&nbsp;</div>

<div>This is obviously incredibly broad although his draft only says that we should leverage the AAA architecture (which is a perfectly fine thing to say as a solution). The AAA framework does not speak about bootstrapping and so one might one why it was possible to get away without that term back on those days.&nbsp;</div>

<div>&nbsp;</div>

<div>Carsten says: &quot;<span style="font-family: Georgia, Times, &#39;Times New Roman&#39;, serif; font-size: 12px; font-style: italic; line-height: 19.1875px;">Bootstrapping is not a method, it is an objective, which can be pinpointed pretty precisely in the lifecycle of a device.</span><br style="font-family: Georgia, Times, &#39;Times New Roman&#39;, serif; font-size: 12px; font-style: italic; line-height: 19.1875px;"/>
<span style="font-family: Georgia, Times, &#39;Times New Roman&#39;, serif; font-size: 12px; font-style: italic; line-height: 19.1875px;">More specifically, it relates to achieving the transition from a sparse or minimal, pre-operational set of authenticated authorizations to a set that can be used operationally.&quot;</span></div>

<div>&nbsp;</div>

<div><font face="Georgia, Times, Times New Roman, serif">Carsten, you are pointing to a lifecycle that seems to be universally agreed. Where is that lifecycle?&nbsp;The definition you offer is also vague and IMHO&nbsp;does not help to guide the work in the group.&nbsp;</font></div>

<div>&nbsp;</div>

<div>Let me try a different approach. There are two basic approaches that I have seen so far in context of security relevant to this debate:&nbsp;</div>

<div>&nbsp;</div>

<div>1) You already have a secret pre-provisioned on the device. You want to leverage that existing secret to access new services. This is what this key distribution / key establishment stuff is all about. This is the typical three party protocol (that some of the referenced documents use). Examples I have seen are <span style="font-family: Verdana; font-size: 12px; line-height: 19.1875px;">Behcet&#39;s AAA proposal, or the OAuth flavor of&nbsp;</span>draft-selander-core-access-control. Kerberos belongs to that category as well and so would models with certificates (where the trusted third party is the CA that issues the certificates).&nbsp;</div>

<div>&nbsp;</div>

<div>2) You have no secret pre-provisioned. The approaches here are sometimes referred as imprinting or pairing. &nbsp;The solutions often make use promitity techniques that require user involvement and their approach varies hugely depending on the hardware&nbsp;capability of the device. You can find a short summary at the smart object security workshop (see http://tools.ietf.org/html/draft-gilger-smart-object-security-workshop-02#section-3.4) and obviously a lot of literature on that subject.&nbsp;</div>

<div>
<div>&nbsp;</div>

<div>It seems that the charter focuses on (1). If that&#39;s the case you should say that.&nbsp;</div>

<div>&nbsp;</div>

<div>Assuming the group wants to go for #1 then&nbsp;the aim&nbsp;of the group is to look at existing key distribution protocols and see which one fits best to the IoT environment. Maybe there are some additional requirements that require extensions (or even a completely new protocol?!?).&nbsp;</div>

<div>&nbsp;</div>

<div>One important implication of going for (1) is that there is obviously this key distribution center (KDC)/AAA server/CA/authorization server that needs to be somewhere (although it does not need to be in the local network). I was wonder whether folks have become aware of that since it may feel a bit foreign in some of the scenarios (just think about having a KDC or a AAA server in your home, for example).&nbsp;</div>

<div>&nbsp;</div>

<div>Ciao</div>

<div>Hannes</div>

<div>&nbsp;</div>

<div name="quote" style="margin:10px 5px 5px 10px; padding: 10px 0 10px 10px; border-left:2px solid #C3D9E5; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div style="margin:0 0 10px 0;"><b>Gesendet:</b>&nbsp;Donnerstag, 12. Dezember 2013 um 22:22 Uhr<br/>
<b>Von:</b>&nbsp;&quot;Behcet Sarikaya&quot; &lt;sarikaya2012@gmail.com&gt;<br/>
<b>An:</b>&nbsp;&quot;Carsten Bormann&quot; &lt;cabo@tzi.org&gt;<br/>
<b>Cc:</b>&nbsp;&quot;Hannes Tschofenig&quot; &lt;Hannes.Tschofenig@gmx.net&gt;, ace@ietf.org<br/>
<b>Betreff:</b>&nbsp;Re: [Ace] Terms to avoid</div>

<div name="quoted-content">
<div>
<div>
<div>
<div>
<div>
<div>Hi Carsten,<br/>
&nbsp;</div>
Thanks for the clarification.<br/>
&nbsp;</div>
I completely agree with you.</div>
I was having nightmares on how to replace bootstrapping.<br/>
&nbsp;</div>
Regards,<br/>
&nbsp;</div>
Behcet</div>

<div class="gmail_extra">&nbsp;
<div class="gmail_quote">On Thu, Dec 12, 2013 at 4:17 PM, Carsten Bormann <span>&lt;<a href="cabo@tzi.org" target="_parent">cabo@tzi.org</a>&gt;</span> wrote:

<blockquote class="gmail_quote" style="margin: 0 0 0 0.8ex;border-left: 1.0px rgb(204,204,204) solid;padding-left: 1.0ex;">
<div class="im">On 12 Dec 2013, at 19:51, Hannes Tschofenig &lt;<a href="Hannes.Tschofenig@gmx.net" target="_parent">Hannes.Tschofenig@gmx.net</a>&gt; wrote:<br/>
<br/>
&gt; Could you guys do me a favor and avoid two terms in your drafts:<br/>
&gt;<br/>
&gt; 1) Bootstrapping<br/>
&gt; 2) Trust<br/>
&nbsp;</div>
I completely agree about the term &ldquo;Trust&rdquo;. &nbsp;This is neither an objective nor a method.<br/>
When people talk about &ldquo;trust&rdquo; they usually either talk about the ability to authenticate something and/or an authorization relationship, but it is rarely fully fleshed out what specifically is meant.<br/>
(Some, but not all, of the uses of the term &ldquo;certificate&rdquo; are of the same kind.)<br/>
Device B doesn&rsquo;t &ldquo;trust&rdquo; device A, but device A is authorized to perform certain, well-defined operations on or relevant for device B, and that authorization (as well as the origin of the operation and/or communication channels) can be authenticated in the course of performing the operation.<br/>
<br/>
I don&rsquo;t agree about not using bootstrapping. &nbsp;Bootstrapping is not a method, it is an objective, which can be pinpointed pretty precisely in the lifecycle of a device.<br/>
More specifically, it relates to achieving the transition from a sparse or minimal, pre-operational set of authenticated authorizations to a set that can be used operationally.<br/>
(Key establishment is usually part of what needs to be done there, but the keys just serve to authenticate the authorizations, so I&rsquo;m not even sure they are very important for defining bootstrapping.)<br/>
<br/>
I&rsquo;m sorry for this dense terminology attack, but I agree that we need to work on some of the terminology now to generate a credible charter.<br/>
<br/>
Gr&uuml;&szlig;e, Carsten
<div class="HOEnZb">
<div class="h5"><br/>
_______________________________________________<br/>
Ace mailing list<br/>
<a href="Ace@ietf.org" target="_parent">Ace@ietf.org</a><br/>
<a href="https://www.ietf.org/mailman/listinfo/ace" target="_blank">https://www.ietf.org/mailman/listinfo/ace</a></div>
</div>
</blockquote>
</div>
</div>
_______________________________________________ Ace mailing list Ace@ietf.org <a href="https://www.ietf.org/mailman/listinfo/ace" target="_blank">https://www.ietf.org/mailman/listinfo/ace</a></div>
</div>
</div></div></body></html>

From gerdes@tzi.de  Fri Dec 13 04:57:21 2013
Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7637F1ACCE4 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 04:57:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kKOWrhAFuRKk for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 04:57:20 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id B422C1A1F48 for <ace@ietf.org>; Fri, 13 Dec 2013 04:57:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBDCv8l2019287 for <ace@ietf.org>; Fri, 13 Dec 2013 13:57:08 +0100 (CET)
Received: from [134.102.218.230] (dynamic-218-c.informatik.uni-bremen.de [134.102.218.230]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 7D070947 for <ace@ietf.org>; Fri, 13 Dec 2013 13:57:08 +0100 (CET)
Message-ID: <52AB0424.8060409@tzi.de>
Date: Fri, 13 Dec 2013 13:57:08 +0100
From: Stefanie Gerdes <gerdes@tzi.de>
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0.1
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com>
X-Enigmail-Version: 1.6
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 12:57:21 -0000

Hi everybody,

On 12/13/2013 11:15 AM, Likepeng wrote:
>> we need to work on some of the terminology now to generate a credible charter.
> 
> I checked RFC 4949 "Internet Security Glossary, Version 2", this RFC defines a lot of security related terms. We can reuse the terminologies defined in this document. 
> 
> I checked our charter, for some terms, we can find definitions, but there are no definitions for "bootstrap", "authorization information" and "access token".
> 
> For "bootstrap", the definition from OMA is: the process of provisioning the client to a state where it is able to initiate a management session to a new server.
> It is quite similar to what Carsten and Behcet have described. 
> 
> For "authorization information", we can change it to the term defined in RFC 4949, maybe authorization credentials?

I assume you refer to this definition of credentials: "A data object
that is a portable representation of the association between an
identifier and one or more access authorizations, and that can be
presented for use in verifying those authorizations for an entity that
attempts such access."

I don't really like the term "credentials" for authorization because  in
my opinion it is too closely connected to authentication. I really want
to avoid getting authentication and authorization even more mixed up
than they are already.

Authorization information is the information that provides the resource
server with the means to know which resources a client might access and
how. Yes, this is a bit vague, but we are not sure at this point what
this information should look like. This is the point of the task "Define
an access token and authorization information format suitable for
constrained devices".

> 
> For "access token", there is no definition in RFC 4949, but there are definitions for "access" and "token". It should be fine to use "access token" or just "token".

I am still in favour of using the term "access ticket". It is intuitive
because a ticket is something you show to someone to get access, even in
the real world. Note that Kerberos didn't invent the term but used it
because it is fitting.


Best regards,
Steffi

From cabo@tzi.org  Fri Dec 13 05:09:39 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C04D91AE263 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 05:09:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3Ok4PVAtfmDF for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 05:09:38 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 548FF1AE262 for <ace@ietf.org>; Fri, 13 Dec 2013 05:09:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBDD9P5s013111; Fri, 13 Dec 2013 14:09:25 +0100 (CET)
Received: from [192.168.217.22] (p54892442.dip0.t-ipconnect.de [84.137.36.66]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 8E24A963; Fri, 13 Dec 2013 14:09:24 +0100 (CET)
From: Carsten Bormann <cabo@tzi.org>
To: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
In-Reply-To: <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>
X-Priority: 3
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>, <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com> <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>
Message-Id: <36D7B1B6-1B55-466F-87E8-92354309DD3B@tzi.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; delsp=yes
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v936)
Date: Fri, 13 Dec 2013 14:07:08 +0100
X-Mailer: Apple Mail (2.936)
Cc: Carsten Bormann <cabo@tzi.org>, sarikaya@ieee.org, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 13:09:40 -0000

On Dec 13 2013, at 13:14, Hannes Tschofenig wrote:

> Carsten says: "Bootstrapping is not a method, it is an objective, =20
> which can be pinpointed pretty precisely in the lifecycle of a device.
> More specifically, it relates to achieving the transition from a =20
> sparse or minimal, pre-operational set of authenticated =20
> authorizations to a set that can be used operationally."
>
> Carsten, you are pointing to a lifecycle that seems to be =20
> universally agreed. Where is that lifecycle?

draft-garcia

> The definition you offer is also vague and IMHO does not help to =20
> guide the work in the group.

It is pretty much as un-vague as it can be.

If that makes you uncomfortable because it doesn't immediately lead to =20=

a separable "bootstrap protocol", I'm with you.
I would be very unhappy if we needed a separate piece of technology =20
for bootstrapping.
Bootstrapping is just one area among the set of requirements this work =20=

needs to meet.
If several good ways to do bootstrapping don't fall naturally out of =20
the ACE work, we have failed.

Re 1 and 2: both, of course.

Maybe it's best to stop thinking about these keys for a moment.
Keys are a means to an end.
What is the end?
Thinking about this might help prevent us from getting another key =20
establishment protocol that only addresses a bizarre subset of the =20
problem.

This is all about authorization.
(Authenticated authorization, specifically.
Not Authentication and authorization as if those were separable.)

Gr=FC=DFe, Carsten


From Hannes.Tschofenig@gmx.net  Fri Dec 13 07:31:20 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E1151ADF60 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:31:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.177
X-Spam-Level: 
X-Spam-Status: No, score=-1.177 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zC8bzgvWr_1p for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:31:18 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) by ietfa.amsl.com (Postfix) with ESMTP id C26321ADDD1 for <ace@ietf.org>; Fri, 13 Dec 2013 07:31:17 -0800 (PST)
Received: from 3capp-gmx-bs07.server.lan ([172.19.170.56]) by mrigmx.server.lan (mrigmx002) with ESMTP (Nemesis) id 0MLDZP-1VrDix2nx3-000N7H for <ace@ietf.org>; Fri, 13 Dec 2013 16:31:10 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs07.server.lan with HTTP; Fri Dec 13 16:31:10 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: "Carsten Bormann" <cabo@tzi.org>
Content-Type: text/html; charset=UTF-8
Date: Fri, 13 Dec 2013 16:31:10 +0100 (CET)
Importance: normal
Sensitivity: Normal
In-Reply-To: <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>,  <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org>
X-UI-Message-Type: mail
X-Priority: 3
X-Provags-ID: V03:K0:IF0W6D/qZohLgBtMErZ0Ki/j2VcVFQ6aW7NKb20S6gb m/9esoKYdu5KITPJpdG2f8iIGvX/vQb5VsF/rlJkZGAYk8mhit 3x401fs1ypGzXpjy3qbX7r0VU88uyXSu7i7JOA1HR90rmbrG67 y8NPq+VQBGTCeM/PbuNZvRtT1ooaqS3nbgelmjgarThKI1ptHo GqJeUfUC0+JSqntkaBWdia211/Uosa/KHVP5woFAUcA6vRG8h9 k595hTC8ZY+al+Dko6/2ZhwLq4pFQsKi36tu30MHZBMa8SLR6R xjmMh8=
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 15:31:20 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Hi Carsten,&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">you are bypassing my question.</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">I am reading through the list of drafts that&nbsp;Kepeng had distributed.</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">For example, when I look at&nbsp;draft-seitz-core-sec-usecases-00.txt I read:&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">&quot;</span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">&nbsp; Currently CoAP proposes to use DTLS<br/>
&nbsp; &nbsp;[RFC6347] for authentication, and access control lists on the<br/>
&nbsp; &nbsp;devices, that specify which clients may initiate a DTLS connection.<br/>
&nbsp; &nbsp;One goal of this document is to point out use cases where this<br/>
&nbsp; &nbsp;approach is not satisfactory.</span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">&quot;&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">I have not closely followed all the CORE work but there seems to be a view of what CoAP does.&nbsp;</span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">When I look at CoAP I don&#39;t see this discussion about&nbsp;access control lists.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">So, I want to hear what folks think it does.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Alternatively, you could just write:&nbsp;</span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;"><span style="line-height: 1.6em;">&quot;</span><span style="line-height: 1.6em;">CoAP does not specify how access control is accomplished and therefore this work introduces these mechanisms.&quot;&nbsp;</span></span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Ciao<br/>
Hannes</span></span></div>

<div>&nbsp;</div>

<div>&nbsp;</div>

<div>&nbsp;
<div name="quote" style="margin:10px 5px 5px 10px; padding: 10px 0 10px 10px; border-left:2px solid #C3D9E5; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div style="margin:0 0 10px 0;"><b>Gesendet:</b>&nbsp;Donnerstag, 12. Dezember 2013 um 23:03 Uhr<br/>
<b>Von:</b>&nbsp;&quot;Carsten Bormann&quot; &lt;cabo@tzi.org&gt;<br/>
<b>An:</b>&nbsp;&quot;Hannes Tschofenig&quot; &lt;Hannes.Tschofenig@gmx.net&gt;<br/>
<b>Cc:</b>&nbsp;ace@ietf.org<br/>
<b>Betreff:</b>&nbsp;Re: [Ace] Access Control Lists in CoAP</div>

<div name="quoted-content"><br/>
On 12 Dec 2013, at 19:32, Hannes Tschofenig &lt;Hannes.Tschofenig@gmx.net&gt; wrote:<br/>
<br/>
&gt; Hi all,<br/>
&gt;<br/>
&gt; in a couple of drafts I see these pointers to access control lists being described in CoAP. However, the CoAP specification does not really say that much about access control lists and by no means describes how they are supposed to be used in any level of detail.<br/>
<br/>
The CoAP base protocol (draft-ietf-core-coap) does not define ACLs.<br/>
It just says you need to have some, because the authentication that we get with DTLS is not the complete answer to the security requirements.<br/>
<br/>
The current ACE charter proposal says ACE should define the ACLs for CoAP.<br/>
(My slide 105 from the CoRE WG at IETF88 says CoRE should define the ACLs for CoAP.<br/>
Let&rsquo;s decide which WG does what *after* deciding what needs to be done.)<br/>
<br/>
Gr&uuml;&szlig;e, Carsten<br/>
<br/>
_______________________________________________<br/>
Ace mailing list<br/>
Ace@ietf.org<br/>
<a href="https://www.ietf.org/mailman/listinfo/ace" target="_blank">https://www.ietf.org/mailman/listinfo/ace</a></div>
</div>
</div></div></body></html>

From ludwig@sics.se  Fri Dec 13 07:51:56 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B60C71ADFC8 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:51:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B-QIOVaqKkAK for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:51:54 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id A7C4F1ADBF7 for <ace@ietf.org>; Fri, 13 Dec 2013 07:51:53 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBDFnlZu007887 for <ace@ietf.org>; Fri, 13 Dec 2013 16:51:46 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asaejqd-1 for <ace@ietf.org>; Fri, 13 Dec 2013 16:51:46 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 2020F400E2 for <ace@ietf.org>; Fri, 13 Dec 2013 16:51:46 +0100 (CET)
Message-ID: <52AB2D11.2080109@sics.se>
Date: Fri, 13 Dec 2013 16:51:45 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>
In-Reply-To: <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms010806080205020303030109"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-13_03:2013-12-12,2013-12-13,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312130101
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 15:51:56 -0000

This is a cryptographically signed message in MIME format.

--------------ms010806080205020303030109
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/13/2013 04:31 PM, Hannes Tschofenig wrote:
> Hi Carsten,
> you are bypassing my question.
> I am reading through the list of drafts that Kepeng had distributed.
> For example, when I look at draft-seitz-core-sec-usecases-00.txt I read=
:
> "
>    Currently CoAP proposes to use DTLS
>     [RFC6347] for authentication, and access control lists on the
>     devices, that specify which clients may initiate a DTLS connection.=

>     One goal of this document is to point out use cases where this
>     approach is not satisfactory.
> "
> I have not closely followed all the CORE work but there seems to be a
> view of what CoAP does.
> When I look at CoAP I don't see this discussion about access control li=
sts.
> So, I want to hear what folks think it does.

What CoAP does (and I don't just think it does, it actually says so in=20
the draft) is that is suggests the use of lists of identifiers that are=20
allowed to start DTLS sessions with the CoAP server.
That makes them access control lists for an "all-or-nothing" access=20
control approach, and currently that's all access control that is in the =

CoAP draft.

Btw. it even says "access control list" for RawPublicKey mode in section =

9.1.3.2.1.:

"During (initial and ongoing) provisioning, an access control list of=20
identifiers the device may start DTLS sessions with SHOULD also be=20
installed and maintained."


Regards,

Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms010806080205020303030109
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTMxNTUxNDVaMCMGCSqGSIb3DQEJBDEW
BBT2JeIKz49R+uCIhWZH7DelK2sTsTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAkOq/Nd1O9L36dF3C4wwG2bVUNOGdwjXNYoleIKuEHgnZLCI5CP2rFpRXtpbsexCbElWd
KLWEmAtfVr6eJqp089SYSGtUp54X1U62Sc6sEXCjlV0zZC9VKurArkEBrz2zd4Lq2Wd1jPGV
+C6iEGXduAN/Jifnno0pPUo2qte2DXURAHx8hJzE9YnwzJBB6I4nKgaBtiz8HpW28E0Oypdn
BYF/g9DoiveK8PmYFzJwUTaM+lJuGGPlloTfuYrg9XaTey7KDK1UPzaCebahkVIs6A4kHWm0
Yua6eCxafC6Ug5At58SEhaan2A+hPIuebvSUDzmxoXAt/ytx2HmnzuPNZQAAAAAAAA==
--------------ms010806080205020303030109--

From ludwig@sics.se  Fri Dec 13 07:54:51 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFA401AE32B for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:54:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id czoyjuqMdtJE for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 07:54:50 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id C94E11AE5F5 for <ace@ietf.org>; Fri, 13 Dec 2013 07:54:46 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBDFscqR011609 for <ace@ietf.org>; Fri, 13 Dec 2013 16:54:39 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asaejra-1 for <ace@ietf.org>; Fri, 13 Dec 2013 16:54:39 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id B98BC400E2 for <ace@ietf.org>; Fri, 13 Dec 2013 16:54:39 +0100 (CET)
Message-ID: <52AB2DBF.9090102@sics.se>
Date: Fri, 13 Dec 2013 16:54:39 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-8ef43169-6c2a-4e24-9b41-a8f9102a16fd-1386863284974@3capp-gmx-bs21>
In-Reply-To: <trinity-8ef43169-6c2a-4e24-9b41-a8f9102a16fd-1386863284974@3capp-gmx-bs21>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms030100070002040406060201"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-13_03:2013-12-12,2013-12-13,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312130102
Subject: Re: [Ace] draft-seitz-core-sec-usecases-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 15:54:51 -0000

This is a cryptographically signed message in MIME format.

--------------ms030100070002040406060201
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/12/2013 04:48 PM, Hannes Tschofenig wrote:
> Dear Goeran, Stefanie, Ludwig,
> I read your document with great interest and I like the description. On=
e
> basic question did, however, come to my mind.
> Collecting requirements is always a difficult job since it requires you=

> to understand the problem domain and that specific industry sector well=

> enough to know how the stakeholders are planning to deploy their techno=
logy.
> How did you collect these requirements?

What we did was to collect somewhat realistic use cases with relevant=20
security issues. Then we made educated guesses as to what security=20
requirements could result from those issues. The main goal (as I=20
understood it) was to get some feedback on whether these could be=20
considered reasonable and important, so actually we are in the process=20
of collection requirements. Those in the draft are mostly meant as a=20
base for discussion.

As for concrete input, I've used some requirements from a company for=20
the Industrial Control Systems use case, and I made some web research on =

Personal Health Monitoring and Home Automation products. Most of these=20
are still at prototype or early-adopter stage, so information on planned =

deployments tend to be pretty vague. The container monitoring scenario=20
is derived from an existing logistics project with the help of members=20
from the project consortium.

Regards,

Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms030100070002040406060201
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTMxNTU0MzlaMCMGCSqGSIb3DQEJBDEW
BBQMxWNDMZRFrU4PykUbZnUFh2OO4TBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAmeCb9DYp+aiTFpkQWqSOz+PqP3rRTxopOvUQ5+btKbqHxOLZ8NYRYTobWdr35m4jyAKV
1rrqawPR9ro+83Q2BETOLnUkZzPM6nJ49xFAXmjlhi5fdeMfvQuPai67M8MYDRQDNJ5PZTA2
q5u0WyVvVmUsNFuV2gtCxbD/vq7UbkhLvr1hytRLxkIxpgO8xw/ZoQK1F0opXA454RwWiEIs
5LcprVAq+PB83mBIsNm0AQ3bKp18/GGKU97vRVHB2rt9bSmy402tPdHVGCh+a8AkArxlMGAy
Hh4JoMMf6S8MBtSjPHmAicj1NaRNg+oRClKaXj5vHB1mKiv1y/7kZSGvhAAAAAAAAA==
--------------ms030100070002040406060201--

From cabo@tzi.org  Fri Dec 13 08:03:22 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B23101AE661 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 08:03:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s-IT454JzQ0L for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 08:03:21 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id BAECF1AE1F5 for <ace@ietf.org>; Fri, 13 Dec 2013 08:03:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBDG38tM001636; Fri, 13 Dec 2013 17:03:08 +0100 (CET)
Received: from [192.168.217.22] (p54892442.dip0.t-ipconnect.de [84.137.36.66]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 650B1A87; Fri, 13 Dec 2013 17:03:07 +0100 (CET)
From: Carsten Bormann <cabo@tzi.org>
To: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
In-Reply-To: <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>
X-Priority: 3
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>
Message-Id: <2207563E-2840-4C0B-B6B4-F8E11EF2D8AC@tzi.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; delsp=yes
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v936)
Date: Fri, 13 Dec 2013 17:03:05 +0100
X-Mailer: Apple Mail (2.936)
Cc: Carsten Bormann <cabo@tzi.org>, ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 16:03:22 -0000

Apparently, I'm not understanding the question, because I thought I =20
had answered it.

On Dec 13 2013, at 16:31, Hannes Tschofenig wrote:

> "CoAP does not specify how access control is accomplished and =20
> therefore this work introduces these mechanisms."

Well, it says that access control is to be performed at the server, =20
using the authentication provided by DTLS.
It does not say
-- what the structure of an ACL or a similar data structure would be, =20=

and, in particular,=20
-- what granularity the access matrix should have, neither on the =20
object nor on the subject side, nor with respect to permissions.
It does not define operations on such a access control matrix.

So my naive expectation of the work here (shared somehow between CoRE =20=

and ACE) is:
-- we are going to define resources ("a Web API") that enable the =20
server to build ACL-like information
-- the subject side can bind to DTLS authentication mechanisms and/or =20=

some object security
-- authorization includes authorization for operations on the =20
information leading to the ACL-like data structure
-- we are using existing CoRE mechanisms (CoAP's REST methods, Web =20
linking, RD, ...) wherever that helps

The combination of all this with existing mechanisms such as DLTS, =20
certs, etc. will be "how access control is accomplished".

Closer to your question?

Gr=FC=DFe, Carsten


From Hannes.Tschofenig@gmx.net  Fri Dec 13 08:41:41 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D7681ADF9B for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 08:41:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.177
X-Spam-Level: 
X-Spam-Status: No, score=-1.177 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L11fxWbeFnFr for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 08:41:39 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) by ietfa.amsl.com (Postfix) with ESMTP id 14B471ADEB7 for <ace@ietf.org>; Fri, 13 Dec 2013 08:41:39 -0800 (PST)
Received: from 3capp-gmx-bs07.server.lan ([172.19.170.56]) by mrigmx.server.lan (mrigmx002) with ESMTP (Nemesis) id 0MSomp-1W1AzO2LTR-00RpgC for <ace@ietf.org>; Fri, 13 Dec 2013 17:41:31 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs07.server.lan with HTTP; Fri Dec 13 17:41:31 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-ec0b4747-a0cc-44af-8494-8ece42e581e8-1386952891304@3capp-gmx-bs07>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: "Carsten Bormann" <cabo@tzi.org>
Content-Type: text/html; charset=UTF-8
Date: Fri, 13 Dec 2013 17:41:31 +0100 (CET)
Importance: normal
Sensitivity: Normal
In-Reply-To: <36D7B1B6-1B55-466F-87E8-92354309DD3B@tzi.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>, <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com> <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>, <36D7B1B6-1B55-466F-87E8-92354309DD3B@tzi.org>
X-UI-Message-Type: mail
X-Priority: 3
X-Provags-ID: V03:K0:g8bNGML05Y9UyfpbssHyFdONEAajzQrXp+aZEtGLcv2 oT/5YSbQEzXTmHZ6IPmREr5XU2MC//K0DDJPIaZFuvLMhdTgYL kZqmj2uRfGQWjISXTZQaBWN1JJ1sAijTPt3SoFKCOLb9p0WhUL iFU2MD1myhNmSctPRxQQ1m4npbH92O7FwBFXGJZ0gISEUR9EkB GKdS7UsL6qxAQmgvaKJR0c2szJ9VYTDm1EebK8HoQepLC9hsUK zmbLokSy1L0PyIxKrJdzXdLc5ttXEKnhJrp5z3y4yc3ndJEcC0 Q/nxdI=
Cc: Carsten Bormann <cabo@tzi.org>, sarikaya@ieee.org, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 16:41:41 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>Carsten,&nbsp;</div>

<div>&nbsp;</div>

<div>I always get worried when new terminology is introduced because it somehow prevents people to see the connection to earlier work anymore. I am not saying that without some experience. I have seen EU funded projects (with good people) working in different working groups (who use different terminology) to find out after two years that they have been actually working on the same problem and came up with the same solution (but just called it differently).&nbsp;</div>

<div>&nbsp;</div>

<div>Just to give you an example in this conversation about terminology for access token. Where does that term come from? Hmmm. It comes from OAuth since the write-up offered in&nbsp;draft-selander-core-access-control-01.txt is essentially OAuth. (Of course, one has to say that the OAuth group also &quot;re-invented&quot; Kerberos to a large extend.) The terminology defined in the base OAuth 2.0 spec is &quot;access token -- a string denoting a specific scope, lifetime, and other access attributes&quot;. Access token was OAuth specific and one could as well look at the Kerberos terminology for a very similar concept (the ticket) --&nbsp;&nbsp; Ticket:&nbsp;A record that helps a client authenticate itself to a server; it&nbsp;contains the client&#39;s identity, a session key, a timestamp, and&nbsp;other formation, all sealed using the server&#39;s secret key. &nbsp;It&nbsp;only serves to authenticate a client when presented along with a&nbsp;fresh Authenticator.&quot;&nbsp;</div>

<div>&nbsp;</div>

<div>If you acknowledge that it has something to do with OAuth one can start differently, namely by saying the following: &quot;Here is OAuth and it has the features we like in the IoT context. There are a few things we do not like (and we profile them away) and here are some additional features we need, which are X, Y, and Z.&quot; That would save us a lot of time.&nbsp;</div>

<div>&nbsp;</div>

<div>Regarding your reference to the lifecycle in&nbsp;<a href="http://tools.ietf.org/html/draft-garcia-core-security-01">http://tools.ietf.org/html/draft-garcia-core-security-01</a>&nbsp;concerning&nbsp;bootstrapping. It shows that bootstrapping consists of the phases &quot;installed&quot; and &quot;commissioned&quot; but unfortunately&nbsp;it does not define them in detail. I would much more comfortable if the authors had explained it, which I raised in my review&nbsp;http://www.ietf.org/mail-archive/web/ace/current/msg00027.html.&nbsp;</div>

<div>&nbsp;</div>

<div>Regarding your remark about not looking at the keys. Of course, key establishment protocols are not only about keys. There is more to them and&nbsp;authorization is part of the story. It turns out that&nbsp;you cannot separate all these different phases into distinct pieces. As an example, I can point to a good description about the&nbsp;AAA framework:&nbsp;<a href="http://tools.ietf.org/search/rfc5247">http://tools.ietf.org/search/rfc5247</a>&nbsp;(Of course it has the AAA alike communication framework underneath, which you may or may not like.)</div>

<div>&nbsp;</div>

<div>I think I am really not asking for too much here, I believe. All I am looking for is for the group to take existing IETF work (terminology, and concepts) <span style="font-family: Verdana; font-size: 12px; line-height: 19.1875px;">into account and if it cannot be used then to describe it clearly what the new things does.</span>&nbsp;Am I asking for too much?</div>

<div>&nbsp;</div>

<div>Ciao<br/>
Hannes</div>

<div>&nbsp;</div>

<div>
<div name="quote" style="margin:10px 5px 5px 10px; padding: 10px 0 10px 10px; border-left:2px solid #C3D9E5; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div style="margin:0 0 10px 0;"><b>Gesendet:</b>&nbsp;Freitag, 13. Dezember 2013 um 13:07 Uhr<br/>
<b>Von:</b>&nbsp;&quot;Carsten Bormann&quot; &lt;cabo@tzi.org&gt;<br/>
<b>An:</b>&nbsp;&quot;Hannes Tschofenig&quot; &lt;Hannes.Tschofenig@gmx.net&gt;<br/>
<b>Cc:</b>&nbsp;&quot;Carsten Bormann&quot; &lt;cabo@tzi.org&gt;, sarikaya@ieee.org, ace@ietf.org<br/>
<b>Betreff:</b>&nbsp;Re: [Ace] Terms to avoid</div>

<div name="quoted-content">On Dec 13 2013, at 13:14, Hannes Tschofenig wrote:<br/>
<br/>
&gt; Carsten says: &quot;Bootstrapping is not a method, it is an objective,<br/>
&gt; which can be pinpointed pretty precisely in the lifecycle of a device.<br/>
&gt; More specifically, it relates to achieving the transition from a<br/>
&gt; sparse or minimal, pre-operational set of authenticated<br/>
&gt; authorizations to a set that can be used operationally.&quot;<br/>
&gt;<br/>
&gt; Carsten, you are pointing to a lifecycle that seems to be<br/>
&gt; universally agreed. Where is that lifecycle?<br/>
<br/>
draft-garcia<br/>
<br/>
&gt; The definition you offer is also vague and IMHO does not help to<br/>
&gt; guide the work in the group.<br/>
<br/>
It is pretty much as un-vague as it can be.<br/>
<br/>
If that makes you uncomfortable because it doesn&#39;t immediately lead to<br/>
a separable &quot;bootstrap protocol&quot;, I&#39;m with you.<br/>
I would be very unhappy if we needed a separate piece of technology<br/>
for bootstrapping.<br/>
Bootstrapping is just one area among the set of requirements this work<br/>
needs to meet.<br/>
If several good ways to do bootstrapping don&#39;t fall naturally out of<br/>
the ACE work, we have failed.<br/>
<br/>
Re 1 and 2: both, of course.<br/>
<br/>
Maybe it&#39;s best to stop thinking about these keys for a moment.<br/>
Keys are a means to an end.<br/>
What is the end?<br/>
Thinking about this might help prevent us from getting another key<br/>
establishment protocol that only addresses a bizarre subset of the<br/>
problem.<br/>
<br/>
This is all about authorization.<br/>
(Authenticated authorization, specifically.<br/>
Not Authentication and authorization as if those were separable.)<br/>
<br/>
Gr&uuml;&szlig;e, Carsten<br/>
&nbsp;</div>
</div>
</div></div></body></html>

From Hannes.Tschofenig@gmx.net  Fri Dec 13 09:10:29 2013
Return-Path: <Hannes.Tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 629C91AE347 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 09:10:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.177
X-Spam-Level: 
X-Spam-Status: No, score=-1.177 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 623fkFhWQXEj for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 09:10:27 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) by ietfa.amsl.com (Postfix) with ESMTP id 8AA6E1AE341 for <ace@ietf.org>; Fri, 13 Dec 2013 09:10:27 -0800 (PST)
Received: from 3capp-gmx-bs07.server.lan ([172.19.170.56]) by mrigmx.server.lan (mrigmx001) with ESMTP (Nemesis) id 0MSXbW-1W1Rqy3aaq-00RVi7 for <ace@ietf.org>; Fri, 13 Dec 2013 18:10:20 +0100
Received: from [217.140.96.21] by 3capp-gmx-bs07.server.lan with HTTP; Fri Dec 13 18:10:20 CET 2013
MIME-Version: 1.0
Message-ID: <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07>
From: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
To: "Ludwig Seitz" <ludwig@sics.se>
Content-Type: text/html; charset=UTF-8
Date: Fri, 13 Dec 2013 18:10:20 +0100 (CET)
Importance: normal
Sensitivity: Normal
In-Reply-To: <52AB2D11.2080109@sics.se>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>,  <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se>
X-UI-Message-Type: mail
X-Priority: 3
X-Provags-ID: V03:K0:qYtB17Tzl7SbF6Td/57DCwEcRrkSdIdF2VgoK9f3pMx pw2boR5b7QUN6u76Icsxft4QDjuSbOlO++52b6+6aTMDbjs+ok /5b5utWzpF7xf0zD8X5hIgAiOJw/uJRqKVNR1rphTZ+BtSgAkJ lrQFcTR8uQJFhBjmS1edEGgB3mTtLnHsNEXW8v26lWSg7NSyln QvwMySlcq9F5unDieV9uhvBg2mYb1qdQ20FpaKZT2C/zqQPQsU dE5tJ+8jfWryde3aHwqslrgg2nR0DW7/LpNSJCpTECXHdhej12 lMuh0o=
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Dec 2013 17:10:29 -0000

<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Hi Ludwig,&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">thanks for the response.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">I think the concept of access control had gotten wrong there a bit.&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;"><span style="line-height: 1.6em;">Many devices may need to have some information (like an IP address, FQDN, or URIs) for the services they have to interact with.&nbsp;</span></span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;"><span style="line-height: 20.796875px;">I would have not called this an access control list. The access control list is either on the server side or on a third party that makes the decision about accessing the server.&nbsp;</span></span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;"><span style="line-height: 20.796875px;">For the use of raw public keys from the server to the client you actually have to do some out-of-band validation of the public key of the server. The specification is explicit about the need for it.&nbsp;There is no identifier that comes along with the public key as such since the idea was to stripped off everything from a certificate except for the public key.&nbsp;&nbsp;</span></span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Does this make sense?&nbsp;</span></span></div>

<div>&nbsp;</div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Ciao</span></span></div>

<div><span style="font-size:12px;"><span style="font-family:verdana,geneva,sans-serif;">Hannes</span></span></div>

<div>&nbsp;</div>

<div>&nbsp;</div>

<div>&nbsp;</div>

<div>&nbsp;
<div name="quote" style="margin:10px 5px 5px 10px; padding: 10px 0 10px 10px; border-left:2px solid #C3D9E5; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div style="margin:0 0 10px 0;"><b>Gesendet:</b>&nbsp;Freitag, 13. Dezember 2013 um 15:51 Uhr<br/>
<b>Von:</b>&nbsp;&quot;Ludwig Seitz&quot; &lt;ludwig@sics.se&gt;<br/>
<b>An:</b>&nbsp;ace@ietf.org<br/>
<b>Betreff:</b>&nbsp;Re: [Ace] Access Control Lists in CoAP</div>

<div name="quoted-content">On 12/13/2013 04:31 PM, Hannes Tschofenig wrote:<br/>
&gt; Hi Carsten,<br/>
&gt; you are bypassing my question.<br/>
&gt; I am reading through the list of drafts that Kepeng had distributed.<br/>
&gt; For example, when I look at draft-seitz-core-sec-usecases-00.txt I read:<br/>
&gt; &quot;<br/>
&gt; Currently CoAP proposes to use DTLS<br/>
&gt; [RFC6347] for authentication, and access control lists on the<br/>
&gt; devices, that specify which clients may initiate a DTLS connection.<br/>
&gt; One goal of this document is to point out use cases where this<br/>
&gt; approach is not satisfactory.<br/>
&gt; &quot;<br/>
&gt; I have not closely followed all the CORE work but there seems to be a<br/>
&gt; view of what CoAP does.<br/>
&gt; When I look at CoAP I don&#39;t see this discussion about access control lists.<br/>
&gt; So, I want to hear what folks think it does.<br/>
<br/>
What CoAP does (and I don&#39;t just think it does, it actually says so in<br/>
the draft) is that is suggests the use of lists of identifiers that are<br/>
allowed to start DTLS sessions with the CoAP server.<br/>
That makes them access control lists for an &quot;all-or-nothing&quot; access<br/>
control approach, and currently that&#39;s all access control that is in the<br/>
CoAP draft.<br/>
<br/>
Btw. it even says &quot;access control list&quot; for RawPublicKey mode in section<br/>
9.1.3.2.1.:<br/>
<br/>
&quot;During (initial and ongoing) provisioning, an access control list of<br/>
identifiers the device may start DTLS sessions with SHOULD also be<br/>
installed and maintained.&quot;<br/>
<br/>
<br/>
Regards,<br/>
<br/>
Ludwig<br/>
<br/>
<br/>
--<br/>
Ludwig Seitz, PhD<br/>
SICS Swedish ICT AB<br/>
Ideon Science Park<br/>
Building Beta 2<br/>
Scheelev&auml;gen 17<br/>
SE-223 70 Lund<br/>
<br/>
Phone +46(0)70-349 92 51<br/>
<a href="http://www.sics.se" target="_blank">http://www.sics.se</a><br/>
<br/>
_______________________________________________<br/>
Ace mailing list<br/>
Ace@ietf.org<br/>
<a href="https://www.ietf.org/mailman/listinfo/ace" target="_blank">https://www.ietf.org/mailman/listinfo/ace</a></div>
</div>
</div></div></body></html>

From goran.selander@ericsson.com  Fri Dec 13 16:33:39 2013
Return-Path: <goran.selander@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BDA21AE0F3 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 16:33:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.551
X-Spam-Level: 
X-Spam-Status: No, score=-3.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id isregB28wxT2 for <ace@ietfa.amsl.com>; Fri, 13 Dec 2013 16:33:35 -0800 (PST)
Received: from mailgw2.ericsson.se (mailgw2.ericsson.se [193.180.251.37]) by ietfa.amsl.com (Postfix) with ESMTP id 419B71AE055 for <ace@ietf.org>; Fri, 13 Dec 2013 16:33:35 -0800 (PST)
X-AuditID: c1b4fb25-b7eff8e000000eda-ce-52aba7570b72
Received: from ESESSHC019.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw2.ericsson.se (Symantec Mail Security) with SMTP id D8.83.03802.757ABA25; Sat, 14 Dec 2013 01:33:28 +0100 (CET)
Received: from ESESSMB302.ericsson.se ([169.254.2.133]) by ESESSHC019.ericsson.se ([153.88.183.75]) with mapi id 14.02.0347.000; Sat, 14 Dec 2013 01:33:23 +0100
From: =?iso-8859-1?Q?G=F6ran_Selander?= <goran.selander@ericsson.com>
To: "Hannes.Tschofenig@gmx.net" <Hannes.Tschofenig@gmx.net>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: Ac74ZBh8lrvW1Ev0L0O2VT6QHuQUfw==
Date: Sat, 14 Dec 2013 00:33:23 +0000
Message-ID: <F3AD00FA8C16C24298F85A1A14F03E433CBB45F5@ESESSMB302.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [153.88.183.153]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrDLMWRmVeSWpSXmKPExsUyM+JvrW7E8tVBBmc2cFt8/9bDbHFkyl1W i6U777E6MHss3rSfzWPJkp9MHtMWZQYwR3HZpKTmZJalFunbJXBlPPq6irngsWlF63flBsbX 2l2MnBwSAiYSF27+Y4ewxSQu3FvP1sXIxSEkcIhR4svx12wgCSGBJYwSF+4Gg9hsAq4SBx68 YwKxRQSsJS53LGMGsZkFHCS+PbwJFhcWUJTYueYhI0SNksTKd6uhbD2Jhy17WEBsFgFViYdb H4HV8wr4SnRuPAtmMwId8f3UGiaImeISt57MZ4I4TkBiyZ7zzBC2qMTLx/9YIWwlib3HrrNA 1OtJ3Jg6hQ3C1pZYtvA1M8R8QYmTM5+wTGAUmYVk7CwkLbOQtMxC0rKAkWUVI3tuYmZOernR JkZgDBzc8lt1B+OdcyKHGKU5WJTEeT+8dQ4SEkhPLEnNTk0tSC2KLyrNSS0+xMjEwSnVwKi1 besbjU8bu9eYTeH5kfR9x4ufJxm8BDaf+hC+rmHLtvNq676dXj1vjuBa7gO5c5adX+zG8TFC edOXhiYTO23z96qTlZZV+vTb3Z6tX/Pk7GmLqSIlSmuLE1b2eHb8irVUM6o2YHlkdztcPovT J09PsVntVHTfu3T12cWbEh8XladEzSs3O6/EUpyRaKjFXFScCAB/ySSATwIAAA==
Cc: "cabo@tzi.org" <cabo@tzi.org>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Dec 2013 00:33:39 -0000

Hi Hannes,=0A=
=0A=
Just stepping in briefly in this thread (will not be able to keep as prompt=
 dialogue as I would like).=0A=
=0A=
On terminology in general: I agree, in part based on the same experience, o=
n the importance of aligning terms. =0A=
=0A=
On terminology in draft-selander-core-access-control-01.txt in particular: =
yes some terminology is aligned with OAuth, and for exactly that reason. =
=0A=
=0A=
Having said that, the main part of the job is still to be done. The alignme=
nt is on names of nodes in the architecture and on the central object (acce=
ss token). We have not yet tried to understand the exact dependency. Neithe=
r are we claiming that OAuth is the only means to acquire access tokens in =
constrained environments. And vice versa except for a few comments in Berli=
n, no one with deep insights in OAuth have commented on this draft. IIRC fr=
om Carsten's presentation at the OAuth meeting in Berlin, there was an agre=
ement to coordinate between OAuth and CoRE on this topic. (This is at least=
 one of the reasons this missing analysis has slipped down on my todo list =
- I thought it ended up also on someone elses ;-)=0A=
=0A=
I think this is a good reminder for some of us to pick up this again in pre=
paration for London. =0A=
=0A=
Best regards,=0A=
G=F6ran=0A=
=0A=
=0A=
--Original message---=0A=
Sender: "Ace" <ace-bounces@ietf.org>=0A=
Sent time: 13 dec 2013 17:41=0A=
To: cabo@tzi.org=0A=
Cc: cabo@tzi.org, sarikaya@ieee.org, ace@ietf.org=0A=
Subject: Re: [Ace] Terms to avoid=0A=
=0A=
Carsten,    I always get worried when new terminology is introduced because=
 =0A=
it somehow prevents people to see the connection to earlier work anymore. I=
 =0A=
am not saying that without some experience. I have seen EU funded projects =
=0A=
(with good people) working in different working groups (who use different =
=0A=
terminology) to find out after two years that they have been actually =0A=
working on the same problem and came up with the same solution (but just =
=0A=
called it differently).    Just to give you an example in this conversation=
 =0A=
about terminology for access token. Where does that term come from? Hmmm. =
=0A=
It comes from OAuth since the write-up offered in =0A=
draft-selander-core-access-control-01.txt is essentially OAuth. (Of course,=
 =0A=
one has to say that the OAuth group also "re-invented" Kerberos to a large =
=0A=
extend.) The terminology defined in the base OAuth 2.0 spec is "access =0A=
token -- a string denoting a specific scope, lifetime, and other access =0A=
attributes". Access token was OAuth specific and one could as well look at =
=0A=
the Kerberos terminology for a very similar concept (the ticket) --   =0A=
Ticket: A record that helps a client authenticate itself to a server; it =
=0A=
contains the client's identity, a session key, a timestamp, and other =0A=
formation, all sealed using the server's secret key.  It only serves to =0A=
authenticate a client when presented along with a fresh Authenticator."    =
=0A=
If you acknowledge that it has something to do with OAuth one can start =0A=
differently, namely by saying the following: "Here is OAuth and it has the =
=0A=
features we like in the IoT context. There are a few things we do not like =
=0A=
(and we profile them away) and here are some additional features we need, =
=0A=
which are X, Y, and Z." That would save us a lot of time.    Regarding your=
 =0A=
reference to the lifecycle in  =0A=
http://tools.ietf.org/html/draft-garcia-core-security-01=0A=
<http://tools.ietf.org/html/draft-garcia-core-security-01>  concerning =0A=
bootstrapping. It shows that bootstrapping consists of the phases =0A=
"installed" and "commissioned" but unfortunately it does not define them in=
 =0A=
detail. I would much more comfortable if the authors had explained it, =0A=
which I raised in my review =0A=
http://www.ietf.org/mail-archive/web/ace/current/msg00027.html.    =0A=
Regarding your remark about not looking at the keys. Of course, key =0A=
establishment protocols are not only about keys. There is more to them and =
=0A=
authorization is part of the story. It turns out that you cannot separate =
=0A=
all these different phases into distinct pieces. As an example, I can point=
 =0A=
to a good description about the AAA framework:  =0A=
http://tools.ietf.org/search/rfc5247 <http://tools.ietf.org/search/rfc5247>=
 =0A=
 (Of course it has the AAA alike communication framework underneath, which =
=0A=
you may or may not like.)   I think I am really not asking for too much =0A=
here, I believe. All I am looking for is for the group to take existing =0A=
IETF work (terminology, and concepts) into account and if it cannot be used=
 =0A=
then to describe it clearly what the new things does. Am I asking for too =
=0A=
much?   Ciao=0A=
Hannes   Gesendet: Freitag, 13. Dezember 2013 um 13:07 Uhr=0A=
Von: "Carsten Bormann" <cabo@tzi.org>=0A=
An: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>=0A=
Cc: "Carsten Bormann" <cabo@tzi.org>, sarikaya@ieee.org, ace@ietf.org=0A=
Betreff: Re: [Ace] Terms to avoid On Dec 13 2013, at 13:14, Hannes =0A=
Tschofenig wrote:=0A=
=0A=
> Carsten says: "Bootstrapping is not a method, it is an objective,=0A=
> which can be pinpointed pretty precisely in the lifecycle of a device.=0A=
> More specifically, it relates to achieving the transition from a=0A=
> sparse or minimal, pre-operational set of authenticated=0A=
> authorizations to a set that can be used operationally."=0A=
>=0A=
> Carsten, you are pointing to a lifecycle that seems to be=0A=
> universally agreed. Where is that lifecycle?=0A=
=0A=
draft-garcia=0A=
=0A=
> The definition you offer is also vague and IMHO does not help to=0A=
> guide the work in the group.=0A=
=0A=
It is pretty much as un-vague as it can be.=0A=
=0A=
If that makes you uncomfortable because it doesn't immediately lead to=0A=
a separable "bootstrap protocol", I'm with you.=0A=
I would be very unhappy if we needed a separate piece of technology=0A=
for bootstrapping.=0A=
Bootstrapping is just one area among the set of requirements this work=0A=
needs to meet.=0A=
If several good ways to do bootstrapping don't fall naturally out of=0A=
the ACE work, we have failed.=0A=
=0A=
Re 1 and 2: both, of course.=0A=
=0A=
Maybe it's best to stop thinking about these keys for a moment.=0A=
Keys are a means to an end.=0A=
What is the end?=0A=
Thinking about this might help prevent us from getting another key=0A=
establishment protocol that only addresses a bizarre subset of the=0A=
problem.=0A=
=0A=
This is all about authorization.=0A=
(Authenticated authorization, specifically.=0A=
Not Authentication and authorization as if those were separable.)=0A=
=0A=
Gr=FC=DFe, Carsten=

From mcr@sandelman.ca  Sat Dec 14 16:37:36 2013
Return-Path: <mcr@sandelman.ca>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1712E1ADF7B for <ace@ietfa.amsl.com>; Sat, 14 Dec 2013 16:37:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.892
X-Spam-Level: 
X-Spam-Status: No, score=-1.892 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_TVD_MIME_NO_HEADERS=0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dWrdFJ6LmoIt for <ace@ietfa.amsl.com>; Sat, 14 Dec 2013 16:37:31 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3::184]) by ietfa.amsl.com (Postfix) with ESMTP id 575371ADF73 for <ace@ietf.org>; Sat, 14 Dec 2013 16:37:31 -0800 (PST)
Received: from sandelman.ca (desk.marajade.sandelman.ca [209.87.252.247]) by tuna.sandelman.ca (Postfix) with ESMTP id 5284B2003B; Sat, 14 Dec 2013 20:51:19 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 8CA4F63B89; Sat, 14 Dec 2013 19:37:14 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 75DFF63848; Sat, 14 Dec 2013 19:37:14 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Hannes Tschofenig" <Hannes.Tschofenig@gmx.net>
In-Reply-To: <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>, <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com> <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Sat, 14 Dec 2013 19:37:14 -0500
Message-ID: <7932.1387067834@sandelman.ca>
Sender: mcr@sandelman.ca
Cc: sarikaya@ieee.org, Carsten Bormann <cabo@tzi.org>, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Dec 2013 00:37:36 -0000

--=-=-=


> 1) You already have a secret pre-provisioned on the device. You want to
> leverage that existing secret to access new services. This is what this key
> distribution / key establishment stuff is all about. This is the typical
> three party protocol (that some of the referenced documents use). Examples
> I have seen are Behcet's AAA proposal, or the OAuth flavor of
> draft-selander-core-access-control. Kerberos belongs to that category as
> well and so would models with certificates (where the trusted third party
> is the CA that issues the certificates).

Would you include situations where the "secret" is imprinted upon a bar/QR
code on the packaging under (1)?

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting for hire =-



--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQCVAwUBUqz5t4qHRg3pndX9AQJ/iQQAyoiDUCnZzQn9z9NbMm0rM4+F+qfBIRL5
Z5HgVjl5ST4yhGZRvx6TAmONYyx8EtTUprHzUbJhdB1Aw1kYrpzA16ueVuqvHBSL
iIAZ5bSBpdHa1JWXxXDShsrv+8jgSOe2MS07o67Pg7M98vbhaCxhq6ktTrJrPwX3
lpO73aAGVgU=
=XfHO
-----END PGP SIGNATURE-----
--=-=-=--

From cabo@tzi.org  Sun Dec 15 07:34:37 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE1331AE05C for <ace@ietfa.amsl.com>; Sun, 15 Dec 2013 07:34:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HBXfBTUGQoSA for <ace@ietfa.amsl.com>; Sun, 15 Dec 2013 07:34:36 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id A11DB1ADF54 for <ace@ietf.org>; Sun, 15 Dec 2013 07:34:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBFFYNvB005226; Sun, 15 Dec 2013 16:34:23 +0100 (CET)
Received: from [192.168.217.144] (p54893F11.dip0.t-ipconnect.de [84.137.63.17]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 97699DE7; Sun, 15 Dec 2013 16:34:22 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
X-Priority: 3
In-Reply-To: <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07>
Date: Sun, 15 Dec 2013 16:34:19 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <546917AC-CFE6-464A-8E27-9403A6318896@tzi.org>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se> <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1822)
Cc: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 15 Dec 2013 15:34:37 -0000

Hi Hannes,

device identifiers aren=92t access control lists, but they can be used =
to index an ACL (i.e., as the subject key into an access matrix).
This works well when you have a way to authenticate a claim that a =
requested operation comes from the device with a given device identifier =
(=93speaks for=94 the identifier).
Associating a device identifier with an RPK is a way to authorize the =
holder of the associated private key to speak for the identifier, i.e., =
to make use of all ACL entries that give the identifier some permission.
You might as well use the RPK as a device identifier, removing the need =
for maintaining that association, but there may also be benefits to an =
indirection through the device identifier.

One important thing to remember here is that the =93servers=94 in CoAP =
are the most constrained devices.
They also can=92t reasonably talk to a big brother (cf. EAP=92s =
authentication server) for each enforcement decision.
So the constrained devices really need a (simple form) of ACL/C-list, =
one which is set up to enable authenticated authorization.  We already =
have the authentication part for using that ACL/C-list via DTLS.

Delegating the onus of communication with the big brother to the client =
is one of the ideas behind several of the proposals here, including =
DCAF.
Now that needs a way to authenticate the input from the big brother to =
the server via multiple DTLS hops (item 3 on slide 105 from =
core@IETF88).
It also would benefit from some standardized form of ACL/C-list (item 2 =
on that slide).

G=F6ran is right that there is a lot of work that still needs to be =
done, and I want to thank you for asking good questions here.  There are =
often three phases of dealing with complexity:
1) when you don=92t understand things, everything seems simple;
2) when you start to understand things, everything appears to become =
more and more complex;
3) when you really understand things, you discover the structure =
relevant to making things simple again.
We are in the middle of phase 2, and your input will help us get to =
phase 3; I=92m confident that this will all be much simpler when we are =
done with that.

Gr=FC=DFe, Carsten


From likepeng@huawei.com  Sun Dec 15 19:28:51 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68DE21AE222 for <ace@ietfa.amsl.com>; Sun, 15 Dec 2013 19:28:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.739
X-Spam-Level: 
X-Spam-Status: No, score=-4.739 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0IcNtqeGU_h0 for <ace@ietfa.amsl.com>; Sun, 15 Dec 2013 19:28:44 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 512D51AE219 for <ace@ietf.org>; Sun, 15 Dec 2013 19:28:44 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBK83721; Mon, 16 Dec 2013 03:28:43 +0000 (GMT)
Received: from LHREML404-HUB.china.huawei.com (10.201.5.218) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 16 Dec 2013 03:28:18 +0000
Received: from SZXEMA406-HUB.china.huawei.com (10.82.72.38) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 16 Dec 2013 03:28:42 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA406-HUB.china.huawei.com ([10.82.72.38]) with mapi id 14.03.0158.001; Mon, 16 Dec 2013 11:28:38 +0800
From: Likepeng <likepeng@huawei.com>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: AQHO92swut0VGmvey0qAQQLzZcFNrJpQmvCAgADi4iD///tSAIAEq9rg
Date: Mon, 16 Dec 2013 03:28:37 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se>
In-Reply-To: <52AAF05E.2050305@sics.se>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 03:28:51 -0000

RnJvbSBMdWR3aWc6IA0KPkknZCBwcmVmZXIgdG8gdXNlICJhdXRob3JpemF0aW9uIGNyZWRlbnRp
YWwiIGluc3RlYWQgb2YgImF1dGhvcml6YXRpb24gdG9rZW4iLg0KDQpGcm9tIFN0ZWZhbmllOg0K
PkkgYW0gc3RpbGwgaW4gZmF2b3Igb2YgdXNpbmcgdGhlIHRlcm0gImFjY2VzcyB0aWNrZXQiLiBJ
dCBpcyBpbnR1aXRpdmUgYmVjYXVzZSBhIHRpY2tldCBpcyBzb21ldGhpbmcgeW91IHNob3cgdG8g
c29tZW9uZSB0byBnZXQgYWNjZXNzLCBldmVuIGluIHRoZSByZWFsIHdvcmxkLiBOb3RlIHRoYXQg
S2VyYmVyb3MgZGlkbid0IGludmVudCB0aGUgdGVybSBidXQgdXNlZCBpdCBiZWNhdXNlIGl0IGlz
IGZpdHRpbmcuDQo+SSBkb24ndCByZWFsbHkgbGlrZSB0aGUgdGVybSAiY3JlZGVudGlhbHMiIGZv
ciBhdXRob3JpemF0aW9uIGJlY2F1c2UgaW4gbXkgb3BpbmlvbiBpdCBpcyB0b28gY2xvc2VseSBj
b25uZWN0ZWQgdG8gYXV0aGVudGljYXRpb24uIEkgcmVhbGx5IHdhbnQgdG8gYXZvaWQgZ2V0dGlu
ZyBhdXRoZW50aWNhdGlvbiBhbmQgYXV0aG9yaXphdGlvbiBldmVuIG1vcmUgbWl4ZWQgdXAgdGhh
biB0aGV5IGFyZSBhbHJlYWR5Lg0KDQpGcm9tIFJGQyA0OTQ5Og0KDQogICAkIHRpY2tldA0KICAg
ICAgKEkpIFN5bm9ueW0gZm9yICJjYXBhYmlsaXR5IHRva2VuIi4NCg0KICAgICAgVHV0b3JpYWw6
IEEgdGlja2V0IGlzIHVzdWFsbHkgZ3JhbnRlZCBieSBhIGNlbnRyYWxpemVkIGFjY2Vzcw0KICAg
ICAgY29udHJvbCBzZXJ2ZXIgKHRpY2tldC1ncmFudGluZyBhZ2VudCkgdG8gYXV0aG9yaXplIGFj
Y2VzcyB0byBhDQogICAgICBzeXN0ZW0gcmVzb3VyY2UgZm9yIGEgbGltaXRlZCB0aW1lLiBUaWNr
ZXRzIGNhbiBiZSBpbXBsZW1lbnRlZA0KICAgICAgd2l0aCBlaXRoZXIgc3ltbWV0cmljIGNyeXB0
b2dyYXBoeSAoc2VlOiBLZXJiZXJvcykgb3IgYXN5bW1ldHJpYw0KICAgICAgY3J5cHRvZ3JhcGh5
IChzZWU6IGF0dHJpYnV0ZSBjZXJ0aWZpY2F0ZSkuDQoNCiAgICQgY3JlZGVudGlhbA0KMi4gKEkp
IC9hY2Nlc3MgY29udHJvbC8gImF1dGhvcml6YXRpb24gY3JlZGVudGlhbCI6IEEgZGF0YSBvYmpl
Y3QNCiAgICAgIHRoYXQgaXMgYSBwb3J0YWJsZSByZXByZXNlbnRhdGlvbiBvZiB0aGUgYXNzb2Np
YXRpb24gYmV0d2VlbiBhbg0KICAgICAgaWRlbnRpZmllciBhbmQgb25lIG9yIG1vcmUgYWNjZXNz
IGF1dGhvcml6YXRpb25zLCBhbmQgdGhhdCBjYW4gYmUNCiAgICAgIHByZXNlbnRlZCBmb3IgdXNl
IGluIHZlcmlmeWluZyB0aG9zZSBhdXRob3JpemF0aW9ucyBmb3IgYW4gZW50aXR5DQogICAgICB0
aGF0IGF0dGVtcHRzIHN1Y2ggYWNjZXNzLiBFeGFtcGxlOiBYLjUwOSBhdHRyaWJ1dGUgY2VydGlm
aWNhdGUuDQogICAgICAoU2VlOiBjYXBhYmlsaXR5IHRva2VuLCB0aWNrZXQuKQ0KDQpGcm9tIHRo
ZSBleHBsYW5hdGlvbnMgYWJvdmUsICJ0aWNrZXQiIGFuZCAiY3JlZGVudGlhbCIgYXJlIHF1aXRl
IHNpbWlsYXIgaW4gdGVybXMgb2YgYXV0aG9yaXphdGlvbi4gQnV0IGNyZWRlbnRpYWwgaGFzIG1v
cmUgdXNhZ2VzLCBmb3IgZXhhbXBsZSwgYXV0aGVudGljYXRpb24uDQoNCklmIHdlIHdhbnQgdG8g
YXZvaWQgY29uZnVzaW9uLCAidGlja2V0IiBpcyBiZXR0ZXIgdGhhbiAiY3JlZGVudGlhbCIgaW4g
b3VyIGNvbnRleHQuDQoNCktpbmQgUmVnYXJkcw0KS2VwZW5nDQoNCi0tLS0t6YKu5Lu25Y6f5Lu2
LS0tLS0NCuWPkeS7tuS6ujogQWNlIFttYWlsdG86YWNlLWJvdW5jZXNAaWV0Zi5vcmddIOS7o+ih
qCBMdWR3aWcgU2VpdHoNCuWPkemAgeaXtumXtDogMjAxM+W5tDEy5pyIMTPml6UgMTk6MzMNCuaU
tuS7tuS6ujogYWNlQGlldGYub3JnDQrkuLvpopg6IFJlOiBbQWNlXSBUZXJtcyB0byBhdm9pZA0K
DQpPbiAxMi8xMy8yMDEzIDExOjE1IEFNLCBMaWtlcGVuZyB3cm90ZToNCj4+IHdlIG5lZWQgdG8g
d29yayBvbiBzb21lIG9mIHRoZSB0ZXJtaW5vbG9neSBub3cgdG8gZ2VuZXJhdGUgYSBjcmVkaWJs
ZSBjaGFydGVyLg0KPg0KPiBJIGNoZWNrZWQgUkZDIDQ5NDkgIkludGVybmV0IFNlY3VyaXR5IEds
b3NzYXJ5LCBWZXJzaW9uIDIiLCB0aGlzIFJGQyBkZWZpbmVzIGEgbG90IG9mIHNlY3VyaXR5IHJl
bGF0ZWQgdGVybXMuIFdlIGNhbiByZXVzZSB0aGUgdGVybWlub2xvZ2llcyBkZWZpbmVkIGluIHRo
aXMgZG9jdW1lbnQuDQo+DQo+IEkgY2hlY2tlZCBvdXIgY2hhcnRlciwgZm9yIHNvbWUgdGVybXMs
IHdlIGNhbiBmaW5kIGRlZmluaXRpb25zLCBidXQgdGhlcmUgYXJlIG5vIGRlZmluaXRpb25zIGZv
ciAiYm9vdHN0cmFwIiwgImF1dGhvcml6YXRpb24gaW5mb3JtYXRpb24iIGFuZCAiYWNjZXNzIHRv
a2VuIi4NCj4NCj4gRm9yICJib290c3RyYXAiLCB0aGUgZGVmaW5pdGlvbiBmcm9tIE9NQSBpczog
dGhlIHByb2Nlc3Mgb2YgcHJvdmlzaW9uaW5nIHRoZSBjbGllbnQgdG8gYSBzdGF0ZSB3aGVyZSBp
dCBpcyBhYmxlIHRvIGluaXRpYXRlIGEgbWFuYWdlbWVudCBzZXNzaW9uIHRvIGEgbmV3IHNlcnZl
ci4NCj4gSXQgaXMgcXVpdGUgc2ltaWxhciB0byB3aGF0IENhcnN0ZW4gYW5kIEJlaGNldCBoYXZl
IGRlc2NyaWJlZC4NCj4NCj4gRm9yICJhdXRob3JpemF0aW9uIGluZm9ybWF0aW9uIiwgd2UgY2Fu
IGNoYW5nZSBpdCB0byB0aGUgdGVybSBkZWZpbmVkIGluIFJGQyA0OTQ5LCBtYXliZSBhdXRob3Jp
emF0aW9uIGNyZWRlbnRpYWxzPw0KPg0KPiBGb3IgImFjY2VzcyB0b2tlbiIsIHRoZXJlIGlzIG5v
IGRlZmluaXRpb24gaW4gUkZDIDQ5NDksIGJ1dCB0aGVyZSBhcmUgZGVmaW5pdGlvbnMgZm9yICJh
Y2Nlc3MiIGFuZCAidG9rZW4iLiBJdCBzaG91bGQgYmUgZmluZSB0byB1c2UgImFjY2VzcyB0b2tl
biIgb3IganVzdCAidG9rZW4iLg0KDQoNCkkgdGhpbmsgdGhlIFJGQzQ5NDkgZGVmaW5pdGlvbiBv
ZiAndG9rZW4nIGRvZXNuJ3QgcXVpdGUgbWF0Y2ggd2hhdCB3ZSBtZWFuOg0KDQoiICAgJCB0b2tl
bg0KCS4uLg0KICAgICAgIDIuIChJKSAvYWNjZXNzIGNvbnRyb2wvIEFuIG9iamVjdCB0aGF0IGlz
IHVzZWQgdG8gY29udHJvbCBhY2Nlc3MNCiAgICAgICBhbmQgaXMgcGFzc2VkIGJldHdlZW4gY29v
cGVyYXRpbmcgZW50aXRpZXMgaW4gYSBwcm90b2NvbCB0aGF0DQogICAgICAgc3luY2hyb25pemVz
IHVzZSBvZiBhIHNoYXJlZCByZXNvdXJjZS4gVXN1YWxseSwgdGhlIGVudGl0eSB0aGF0DQogICAg
ICAgY3VycmVudGx5IGhvbGRzIHRoZSB0b2tlbiBoYXMgZXhjbHVzaXZlIGFjY2VzcyB0byB0aGUg
cmVzb3VyY2UuDQogICAgICAgKFNlZTogY2FwYWJpbGl0eSB0b2tlbi4pDQoiDQoNClRoZSB3YXkg
ZHJhZnQtc2VsYW5kZXIgKGFuZCBkcmFmdC1nZXJkZXMgaWYgSSdtIG5vdCBtaXN0YWtlbikgZGVm
aW5lcyB0aGUgdXNlIG9mIHRva2VucywgdGhleSBkb24ndCBnaXZlIF9leGNsdXNpdmVfIGFjY2Vz
cy4NCg0KQWxzbyBpZiB5b3UgbG9vayBhdCAnY2FwYWJpbGl0eSB0b2tlbic6DQoNCiIJLi4uIFBv
c3Nlc3Npb24gb2YgdGhlIHRva2VuIGlzIGFjY2VwdGVkIGJ5IGEgc3lzdGVtIGFzIHByb29mDQoJ
dGhhdCB0aGUgaG9sZGVyIGhhcyBiZWVuIGF1dGhvcml6ZWQgdG8gYWNjZXNzIHRoZSByZXNvdXJj
ZQ0KCSBpbmRpY2F0ZWQgYnkgdGhlIHRva2VuLg0KIg0KDQpUaGF0IGFsc28gaXNuJ3QgcXVpdGUg
aW4gbGluZSB3aXRoIGRyYWZ0LXNlbGFuZGVyIGFuZCBkcmFmdC1nZXJkZXMsIHNpbmNlIGJvdGgg
ZGVmaW5lIHNvbWUgc3ViamVjdC1iaW5kaW5nIGluIHRoZSB0b2tlbi4NCg0KSSdkIHByZWZlciB0
byB1c2UgImF1dGhvcml6YXRpb24gY3JlZGVudGlhbCIgaW5zdGVhZCBvZiAiYXV0aG9yaXphdGlv
biB0b2tlbiIuDQoNCiJBdXRob3JpemF0aW9uIGluZm9ybWF0aW9uIiBpcyBhIHJlYWxseSB2YWd1
ZSB0ZXJtLCBidXQgdGhlIGFuYWxvZ3VlICJhdXRoZW50aWNhdGlvbiBpbmZvcm1hdGlvbiIgaXMg
dXNlZCBzZXZlcmFsIHRpbWVzIGluIFJGQzQ5NDkgd2l0aG91dCBiZWluZyBkZWZpbmVkLCBzbyBw
ZXJoYXBzIHdlIGNhbiBnZXQgYXdheSB3aXRoIHVzaW5nIGl0IGFueXdheS4NCg0KDQovTHVkd2ln
DQoNCi0tDQpMdWR3aWcgU2VpdHosIFBoRA0KU0lDUyBTd2VkaXNoIElDVCBBQg0KSWRlb24gU2Np
ZW5jZSBQYXJrDQpCdWlsZGluZyBCZXRhIDINClNjaGVlbGV2w6RnZW4gMTcNClNFLTIyMyA3MCBM
dW5kDQoNClBob25lICs0NigwKTcwLTM0OSA5MiA1MQ0KaHR0cDovL3d3dy5zaWNzLnNlDQoNCg==

From ludwig@sics.se  Mon Dec 16 01:05:45 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8ADCC1AE160 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:05:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level: 
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.538] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7dsc1jvj17EU for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:05:38 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 87F561AE0A8 for <ace@ietf.org>; Mon, 16 Dec 2013 01:05:37 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBG95VW1030908 for <ace@ietf.org>; Mon, 16 Dec 2013 10:05:35 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asag8qt-1 for <ace@ietf.org>; Mon, 16 Dec 2013 10:05:35 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id B6B76400E2 for <ace@ietf.org>; Mon, 16 Dec 2013 10:05:35 +0100 (CET)
Message-ID: <52AEC257.4060503@sics.se>
Date: Mon, 16 Dec 2013 10:05:27 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020008090100060904050701"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-15_01:2013-12-12,2013-12-15,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312160014
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 09:05:45 -0000

This is a cryptographically signed message in MIME format.

--------------ms020008090100060904050701
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/16/2013 04:28 AM, Likepeng wrote:
>  From Ludwig:
>> I'd prefer to use "authorization credential" instead of "authorization=
 token".
>
>  From Stefanie:
>> I am still in favor of using the term "access ticket".
[...]

> If we want to avoid confusion, "ticket" is better than "credential" in =
our context.
>
> Kind Regards
> Kepeng
>
>

Why not just have a poll? I don't want to drag this discussion on more=20
than necessary and I'm willing to accept a majority consensus (as long=20
as the majority is more than 3 people).

Would this format be acceptable?
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Question: Which is the best (as in "creating the least confusion") term=20
for a data object carrying authorization information (See RFC4949 for=20
definitions of the suggested terms):


[ ] access ticket, short: ticket
[ ] authorization credential, short: credential
[ ] authorization token, short: token
[ ] other (please state why):

/Ludwig
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=C3=A4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms020008090100060904050701
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTYwOTA1MjdaMCMGCSqGSIb3DQEJBDEW
BBSdS/o18T3UbE10fNDGXTO8Ex5fsDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAVdY76btfTSdV9GTnnXtPY5SloOGaWCMXSv6EhsmZssRMtxhaB/Xw0wMPs4UI2Zp9dNUS
7v1Hs2+L84J+2KZOEWoKap8gybsag74IRcA96Ky2WiLKBYMcWNaaN0T57PyNyYuySvC8+JWK
z2+/JRjPLuHD+ePrt0lUrT2rGQGKpSw86WRiPSYHbUT2cCC/xyryXm4uo27QyPdA9eMQyRPJ
82FZzgeXI7ryckPtM2+aXkYWKrovfc0W90N+BGkiaIU9fBI35SmNbK9c5Jb8GjPpZpTY2HJy
/S3+efMZHgGJLHIoNTNpe4i6+r4l++7u7dCQ/JXIy93bGwVuZXnlRKwPaAAAAAAAAA==
--------------ms020008090100060904050701--

From cabo@tzi.org  Mon Dec 16 01:18:16 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 440911AD2EC for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:18:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qYP6weSRs-7q for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:18:12 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id CC1BB1A1F61 for <ace@ietf.org>; Mon, 16 Dec 2013 01:18:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBG9I3HS028430; Mon, 16 Dec 2013 10:18:03 +0100 (CET)
Received: from [192.168.217.105] (p54893F11.dip0.t-ipconnect.de [84.137.63.17]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 9F35171; Mon, 16 Dec 2013 10:18:02 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1822\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <52AEC257.4060503@sics.se>
Date: Mon, 16 Dec 2013 10:18:00 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com> <52AEC257.4060503@sics.se>
To: Ludwig Seitz <ludwig@sics.se>
X-Mailer: Apple Mail (2.1822)
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 09:18:16 -0000

On 16 Dec 2013, at 10:05, Ludwig Seitz <ludwig@sics.se> wrote:

> Why not just have a poll?=20

Do we know what it is the name of which we are deciding?
I haven=92t seen a discussion of a definition.

Gr=FC=DFe, Carsten


From ludwig@sics.se  Mon Dec 16 01:39:02 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 036451AE147 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:39:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.067
X-Spam-Level: 
X-Spam-Status: No, score=-1.067 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, MISSING_HEADERS=1.021, RP_MATCHES_RCVD=-0.538] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pu4apWqUFKNy for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 01:38:57 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 3270F1AD2EC for <ace@ietf.org>; Mon, 16 Dec 2013 01:38:55 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBG9crGf022689 for <ace@ietf.org>; Mon, 16 Dec 2013 10:38:53 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asagaab-1 for <ace@ietf.org>; Mon, 16 Dec 2013 10:38:53 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 2C456400E2 for <ace@ietf.org>; Mon, 16 Dec 2013 10:38:53 +0100 (CET)
Message-ID: <52AECA2C.7010806@sics.se>
Date: Mon, 16 Dec 2013 10:38:52 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
CC: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se> <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07>
In-Reply-To: <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms080802060300050000050802"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-15_01:2013-12-12,2013-12-15,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312160019
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 09:39:02 -0000

This is a cryptographically signed message in MIME format.

--------------ms080802060300050000050802
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/13/2013 06:10 PM, Hannes Tschofenig wrote:
> Hi Ludwig,
> thanks for the response.
> I think the concept of access control had gotten wrong there a bit.
> Many devices may need to have some information (like an IP address,
> FQDN, or URIs) for the services they have to interact with.
> I would have not called this an access control list. The access control=

> list is either on the server side or on a third party that makes the
> decision about accessing the server.

Just to make sure we don't misunderstand each other: when I say=20
(resource) server I mean the device. So yes, the list is on the server=20
side according to my understanding of the CoAP spec.

Furthermore: It's a list that is used to decide who gets to make a DTLS=20
connection to the device. With no other access controls present I'd call =

this an "access control list", and apparently so does the CoAP spec.

Could you elaborate on why you think this gets the concept of access=20
control wrong?

> For the use of raw public keys from the server to the client you
> actually have to do some out-of-band validation of the public key of th=
e
> server. The specification is explicit about the need for it. There is n=
o
> identifier that comes along with the public key as such since the idea
> was to stripped off everything from a certificate except for the public=

> key.

Right, isn't that exactly what the CoAP spec says? I hope I didn't give=20
the impression I was questioning that.

 From the CoAP spec:

    RawPublicKey:  DTLS is enabled and the device has an asymmetric key
       pair without a certificate (a raw public key) that is validated
       using an out-of-band mechanism [I-D.ietf-tls-oob-pubkey] as
       described in Section 9.1.3.2.  The device also has an identity
       calculated from the public key and a list of identities of the
       nodes it can communicate with.



--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=C3=A4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms080802060300050000050802
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTYwOTM4NTJaMCMGCSqGSIb3DQEJBDEW
BBQM8UpSyS2lZehQ3XZnd5LH3WfvCTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEATFkEX6cUgjwn8b23WI60ThI3Jjgast77RdxmRyIsMxUXZ20reQLn4RMzXbMOO0dwkBro
8B8gZ3MroNHtECrLNSjSIqH+nFP2MCK0f3p/sdbI7xB//69RZ0InDJcW8YlHSBTDP5k80rXw
GTHZoGVVPyf+Avl+b1OwhRn69EPzW7f9x2PqpLxRoNUUHq53KQ8RRRvxAKExSQX92AZ1No8G
B5F+l33gvC9xfmQ9Xza3g3QiBsbaH5lzV6TRE+3mTZfwMedVL7kzfck/3ix0fRIpIIxSlaY2
RLj8CTMVMkjF+jS30nxQ3/3gHbr7UpcFI3hb3y45llZw34Mhnth1UooakAAAAAAAAA==
--------------ms080802060300050000050802--

From paul.madsen@gmail.com  Mon Dec 16 03:41:25 2013
Return-Path: <paul.madsen@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 544871AE1F6 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 03:41:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tJY_cwU3JnsE for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 03:41:20 -0800 (PST)
Received: from mail-qa0-x22d.google.com (mail-qa0-x22d.google.com [IPv6:2607:f8b0:400d:c00::22d]) by ietfa.amsl.com (Postfix) with ESMTP id D08231AE1D4 for <ace@ietf.org>; Mon, 16 Dec 2013 03:41:19 -0800 (PST)
Received: by mail-qa0-f45.google.com with SMTP id o15so1416935qap.11 for <ace@ietf.org>; Mon, 16 Dec 2013 03:41:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=5cXJGMsSE58miYAg/GEHOw5rkf6StuR80849ZoqxeJ4=; b=Q10qPGtqtZSpdvgpOlIGduQtDlO+Jr09x4cdamD8cC/SWnbc+vWNbhq//piLj9zi7f rwEFgP8jBK7Cg7GPub1cMAXcs7GcaCi4PI615IO/FRw9CxSk9AMvsas+h5i5lwOcSM9W 37kPGldgQh9pCm/J6URmQ0Q3VumKf7/9hxCES9UcLLXLMGcMa04ivRAR4L/HMdBvpDG8 7ZREImEQzi7wQfL9zCFvrAnE69ghar6GeEb7pyJ5betf7rdbv67bysMqFJzR/kjj5vIw 2/Ycbrb7sbS4/mm2M8ziAm10r15C3qduCiquHo9Ok5vwAyPrdg7P9gHVxWWDakvsVVLI V/Sw==
MIME-Version: 1.0
X-Received: by 10.49.120.8 with SMTP id ky8mr31633236qeb.29.1387194078867; Mon, 16 Dec 2013 03:41:18 -0800 (PST)
Received: by 10.140.83.232 with HTTP; Mon, 16 Dec 2013 03:41:18 -0800 (PST)
In-Reply-To: <52AAC3DD.9030802@sics.se>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se>
Date: Mon, 16 Dec 2013 03:41:18 -0800
Message-ID: <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com>
From: Paul Madsen <paul.madsen@gmail.com>
To: Ludwig Seitz <ludwig@sics.se>
Content-Type: multipart/alternative; boundary=047d7bb04e944e34e804eda54a2b
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 11:41:25 -0000

--047d7bb04e944e34e804eda54a2b
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

what does it mean to define the ACLs? define a format?

and, if so, what is the motivation for a standard format? not interchange
presumably?

paul


On Fri, Dec 13, 2013 at 12:22 AM, Ludwig Seitz <ludwig@sics.se> wrote:

> On 12/13/2013 12:03 AM, Carsten Bormann wrote:
>
>>
>> On 12 Dec 2013, at 19:32, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
>> wrote:
>>
>>  Hi all,
>>>
>>> in a couple of drafts I see these pointers to access control lists bein=
g
>>> described in CoAP. However, the CoAP specification does not really say =
that
>>> much about access control lists and by no means describes how they are
>>> supposed to be used in any level of detail.
>>>
>>
>> The CoAP base protocol (draft-ietf-core-coap) does not define ACLs.
>> It just says you need to have some, because the authentication that we
>> get with DTLS is not the complete answer to the security requirements.
>>
>> The current ACE charter proposal says ACE should define the ACLs for CoA=
P.
>> (My slide 105 from the CoRE WG at IETF88 says CoRE should define the ACL=
s
>> for CoAP.
>> Let=92s decide which WG does what *after* deciding what needs to be done=
.)
>>
>> Gr=FC=DFe, Carsten
>>
>>  +1
>
> --
> Ludwig Seitz, PhD
> SICS Swedish ICT AB
> Ideon Science Park
> Building Beta 2
> Scheelev=E4gen 17
> SE-223 70 Lund
>
> Phone +46(0)70-349 92 51
> http://www.sics.se
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>


--=20
Paul Madsen

--047d7bb04e944e34e804eda54a2b
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">what does it mean to define the ACLs? define a format?=A0<=
div><br></div><div style>and, if so, what is the motivation for a standard =
format? not interchange presumably?=A0</div><div style><br></div><div style=
>paul =A0<br>
</div></div><div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">O=
n Fri, Dec 13, 2013 at 12:22 AM, Ludwig Seitz <span dir=3D"ltr">&lt;<a href=
=3D"mailto:ludwig@sics.se" target=3D"_blank">ludwig@sics.se</a>&gt;</span> =
wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im">On 12/13/2013 12:03 AM, Ca=
rsten Bormann wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
On 12 Dec 2013, at 19:32, Hannes Tschofenig &lt;<a href=3D"mailto:Hannes.Ts=
chofenig@gmx.net" target=3D"_blank">Hannes.Tschofenig@gmx.net</a>&gt; wrote=
:<br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Hi all,<br>
<br>
in a couple of drafts I see these pointers to access control lists being de=
scribed in CoAP. However, the CoAP specification does not really say that m=
uch about access control lists and by no means describes how they are suppo=
sed to be used in any level of detail.<br>

</blockquote>
<br>
The CoAP base protocol (draft-ietf-core-coap) does not define ACLs.<br>
It just says you need to have some, because the authentication that we get =
with DTLS is not the complete answer to the security requirements.<br>
<br>
The current ACE charter proposal says ACE should define the ACLs for CoAP.<=
br>
(My slide 105 from the CoRE WG at IETF88 says CoRE should define the ACLs f=
or CoAP.<br>
Let=92s decide which WG does what *after* deciding what needs to be done.)<=
br>
<br>
Gr=FC=DFe, Carsten<br>
<br>
</blockquote></div>
+1<span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
-- <br>
Ludwig Seitz, PhD<br>
SICS Swedish ICT AB<br>
Ideon Science Park<br>
Building Beta 2<br>
Scheelev=E4gen 17<br>
SE-223 70 Lund<br>
<br>
Phone <a href=3D"tel:%2B46%280%2970-349%2092%2051" value=3D"+46703499251" t=
arget=3D"_blank">+46(0)70-349 92 51</a><br>
<a href=3D"http://www.sics.se" target=3D"_blank">http://www.sics.se</a><br>
<br>
</font></span><br>_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>Paul Mad=
sen<br>
</div>

--047d7bb04e944e34e804eda54a2b--

From ludwig@sics.se  Mon Dec 16 03:45:13 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE6A71AE241 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 03:45:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level: 
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.538] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ghIanuzAieK4 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 03:45:09 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 4FA3C1AE1D4 for <ace@ietf.org>; Mon, 16 Dec 2013 03:45:09 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBGBeN9l014679 for <ace@ietf.org>; Mon, 16 Dec 2013 12:45:06 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asagkyn-1 for <ace@ietf.org>; Mon, 16 Dec 2013 12:45:06 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 86EA8400E2 for <ace@ietf.org>; Mon, 16 Dec 2013 12:45:06 +0100 (CET)
Message-ID: <52AEE7C2.6090401@sics.se>
Date: Mon, 16 Dec 2013 12:45:06 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se> <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com>
In-Reply-To: <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050905000000010006060005"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-15_01:2013-12-12,2013-12-15,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312160038
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 11:45:13 -0000

This is a cryptographically signed message in MIME format.

--------------ms050905000000010006060005
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/16/2013 12:41 PM, Paul Madsen wrote:
> what does it mean to define the ACLs? define a format?
>

That's how I understood it.

> and, if so, what is the motivation for a standard format? not
> interchange presumably?
>
> paul
>

If different manufacturers agree on a single ACL format, you can=20
centrally manage ACLs and provision them to devices from both=20
manufacturers using the same set of tools.

/Ludwig


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms050905000000010006060005
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTYxMTQ1MDZaMCMGCSqGSIb3DQEJBDEW
BBTm4dkycs1LpY3w3H5ecnPD/8owTDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAc5n4IWPBZG/uBqBaxg6aeH1iU/wBazGKQlqLlNsULMVaxKL1MBS5PMLN0gEkvav48xBE
6yn7TgZumxOHpTyxgJZe69zHrFPcc5JGVn1n+xFuiCqNp2tfBxN6yBWqjQODFljxu96RbRgZ
zHnPEuj9xUdp6ILFdJBlhMKxX1j1fL3RKiRFpkLYyBWs3mRzUQ/o059CvUxlddtTn8O6jNuX
58vNe5SUkRpIDWtJfEhgTQKR4JCVNPR3Ld00KaNgjJOxuf6XHcWHRRzP0oaACSjVj4sTT9z6
iTxiszvm+jUSlskOB0UvoYN+tYUv/BNqMXklO3of6m/dVZShsLH7jN0XdQAAAAAAAA==
--------------ms050905000000010006060005--

From paul.madsen@gmail.com  Mon Dec 16 04:01:55 2013
Return-Path: <paul.madsen@gmail.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD0951ADF60 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 04:01:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BgQijxS9jctj for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 04:01:53 -0800 (PST)
Received: from mail-qe0-x22b.google.com (mail-qe0-x22b.google.com [IPv6:2607:f8b0:400d:c02::22b]) by ietfa.amsl.com (Postfix) with ESMTP id AC7551ADF23 for <ace@ietf.org>; Mon, 16 Dec 2013 04:01:53 -0800 (PST)
Received: by mail-qe0-f43.google.com with SMTP id 2so3729619qeb.2 for <ace@ietf.org>; Mon, 16 Dec 2013 04:01:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=dfJYEjLv/Cbfsb1iwa4tXa+Mdbhm9mwTUgc/0oAORKE=; b=hIuW7/X8bWPxiA5J2r1OgrGqu/nzcozCaPPfM1M4wVrzbXwO/oOQyMrxRx/ON8jnzC PIEp81j4qO8jVXfdjCS8JLKQ9Z6fsMJZ+wUN/R7yv7caJwU13sFcYnZHlmWmRnnP+R+Y yrDW08JApQmZDE1Zpv9z/bhEPP+L+qu6QSutg3gj1ZsjbbWGg1cJuiWhCBJ3Lz7kXvv9 ez/1Jr1acA5uV5wby9MQTbHJskbklfhf4TJLIsNVT3H0X5PA/9n5F1uurVR+tGSJb+JK y8Tu5HbLosgAbGNEi15ZvBDN8lIWN7dSx0ojpmRv27C8mx2yUJoMJJBexlvNrNV9bEiM G5gw==
MIME-Version: 1.0
X-Received: by 10.224.94.8 with SMTP id x8mr32292230qam.1.1387195312874; Mon, 16 Dec 2013 04:01:52 -0800 (PST)
Received: by 10.140.83.232 with HTTP; Mon, 16 Dec 2013 04:01:52 -0800 (PST)
In-Reply-To: <52AEE7C2.6090401@sics.se>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se> <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com> <52AEE7C2.6090401@sics.se>
Date: Mon, 16 Dec 2013 04:01:52 -0800
Message-ID: <CA+bqkgG2uy5EO6omB7aNpj_YLL7G5uBwEcKGuypy_H--BHv6Og@mail.gmail.com>
From: Paul Madsen <paul.madsen@gmail.com>
To: Ludwig Seitz <ludwig@sics.se>
Content-Type: multipart/alternative; boundary=047d7b6761f6dba97a04eda593b9
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 12:01:56 -0000

--047d7b6761f6dba97a04eda593b9
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

thanks Ludwig, I wasnt aware of the need for the provisioning use case

paul


On Mon, Dec 16, 2013 at 3:45 AM, Ludwig Seitz <ludwig@sics.se> wrote:

> On 12/16/2013 12:41 PM, Paul Madsen wrote:
>
>> what does it mean to define the ACLs? define a format?
>>
>>
> That's how I understood it.
>
>
>  and, if so, what is the motivation for a standard format? not
>> interchange presumably?
>>
>> paul
>>
>>
> If different manufacturers agree on a single ACL format, you can centrall=
y
> manage ACLs and provision them to devices from both manufacturers using t=
he
> same set of tools.
>
> /Ludwig
>
>
>
> --
> Ludwig Seitz, PhD
> SICS Swedish ICT AB
> Ideon Science Park
> Building Beta 2
> Scheelev=E4gen 17
> SE-223 70 Lund
>
> Phone +46(0)70-349 92 51
> http://www.sics.se
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>
>


--=20
Paul Madsen

--047d7b6761f6dba97a04eda593b9
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">thanks Ludwig, I wasnt aware of the need for the provision=
ing use case<div><br></div><div style>paul</div></div><div class=3D"gmail_e=
xtra"><br><br><div class=3D"gmail_quote">On Mon, Dec 16, 2013 at 3:45 AM, L=
udwig Seitz <span dir=3D"ltr">&lt;<a href=3D"mailto:ludwig@sics.se" target=
=3D"_blank">ludwig@sics.se</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex"><div class=3D"im">On 12/16/2013 12:41 PM, Pa=
ul Madsen wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
what does it mean to define the ACLs? define a format?<br>
<br>
</blockquote>
<br></div>
That&#39;s how I understood it.<div class=3D"im"><br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
and, if so, what is the motivation for a standard format? not<br>
interchange presumably?<br>
<br>
paul<br>
<br>
</blockquote>
<br></div>
If different manufacturers agree on a single ACL format, you can centrally =
manage ACLs and provision them to devices from both manufacturers using the=
 same set of tools.<span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
/Ludwig</font></span><div class=3D"HOEnZb"><div class=3D"h5"><br>
<br>
<br>
-- <br>
Ludwig Seitz, PhD<br>
SICS Swedish ICT AB<br>
Ideon Science Park<br>
Building Beta 2<br>
Scheelev=E4gen 17<br>
SE-223 70 Lund<br>
<br>
Phone <a href=3D"tel:%2B46%280%2970-349%2092%2051" value=3D"+46703499251" t=
arget=3D"_blank">+46(0)70-349 92 51</a><br>
<a href=3D"http://www.sics.se" target=3D"_blank">http://www.sics.se</a><br>
<br>
</div></div><br>_______________________________________________<br>
Ace mailing list<br>
<a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/ace" target=3D"_blank">htt=
ps://www.ietf.org/mailman/listinfo/ace</a><br>
<br></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>Paul Mad=
sen<br>
</div>

--047d7b6761f6dba97a04eda593b9--

From ludwig@sics.se  Mon Dec 16 04:09:27 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02EFA1AE2F5 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 04:09:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level: 
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.538] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bof_Jz9ptn5F for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 04:09:18 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id AF9471AE2F3 for <ace@ietf.org>; Mon, 16 Dec 2013 04:09:17 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBGC7NQI001816 for <ace@ietf.org>; Mon, 16 Dec 2013 13:09:16 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asagnf8-1 for <ace@ietf.org>; Mon, 16 Dec 2013 13:09:16 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 4A386400E2 for <ace@ietf.org>; Mon, 16 Dec 2013 13:09:16 +0100 (CET)
Message-ID: <52AEED6B.4070507@sics.se>
Date: Mon, 16 Dec 2013 13:09:15 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se> <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com> <52AEE7C2.6090401@sics.se> <CA+bqkgG2uy5EO6omB7aNpj_YLL7G5uBwEcKGuypy_H--BHv6Og@mail.gmail.com>
In-Reply-To: <CA+bqkgG2uy5EO6omB7aNpj_YLL7G5uBwEcKGuypy_H--BHv6Og@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms060102010503070203000504"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-15_01:2013-12-12,2013-12-15,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312160044
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 12:09:27 -0000

This is a cryptographically signed message in MIME format.

--------------ms060102010503070203000504
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/16/2013 01:01 PM, Paul Madsen wrote:
> thanks Ludwig, I wasnt aware of the need for the provisioning use case
>
> paul
>
>
> On Mon, Dec 16, 2013 at 3:45 AM, Ludwig Seitz <ludwig@sics.se
> <mailto:ludwig@sics.se>> wrote:
>
>     On 12/16/2013 12:41 PM, Paul Madsen wrote:
>
>         what does it mean to define the ACLs? define a format?
>
>
>     That's how I understood it.
>
>
>         and, if so, what is the motivation for a standard format? not
>         interchange presumably?
>
>         paul
>
>
>     If different manufacturers agree on a single ACL format, you can
>     centrally manage ACLs and provision them to devices from both
>     manufacturers using the same set of tools.
>
>     /Ludwig
>


BTW as was pointed out to me by Zach Shelby, a lot of work on=20
provisioning in general and ACLs specifically, has been done in=20
OMA-Lightweight M2M [1].

Does anyone see a compelling reason to reinvent that stuff for use cases =

where provisioning ACLs works to cover access control?

/Ludwig

[1] http://openmobilealliance.org/about-oma/work-program/m2m-enablers/

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms060102010503070203000504
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTYxMjA5MTVaMCMGCSqGSIb3DQEJBDEW
BBQqLX76qQ4pRop55hh28xzJBJl5xDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEANlAXvf5sCvXqL0qDhyrtgLUBsdItT4Z1m9PensD/n885/cTqFekXcftsU6mCcKkEjimg
NZv/ZJGVW+nVrTHwq7KZuUzo9ba0+Nj3wCkSQTvjHFeSE1FjoxEakUml94dQvMpLxpEo0BOO
pJ5nvXjLRRTdqx6BhULoRvDx8z22DDsmjq84LYn7T0m7jnsjb8HKtI961rgtsMpd6ILNNALB
Du76MCrDO9+CdfxFadX9gvaIYyFab4eCejDnRGjslqLsq7Kvb62f+qKkdDoeLZY4zvlmtwsY
C3gsf5MK8QbppYvsT9eVdsjmC+vzLQsrlZiLTcLLKUQSfq3jHHYvTzXP/QAAAAAAAA==
--------------ms060102010503070203000504--

From hannes.tschofenig@gmx.net  Mon Dec 16 12:58:31 2013
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B8651ADBCD for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 12:58:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.437
X-Spam-Level: 
X-Spam-Status: No, score=-2.437 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fBASsW32kyRY for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 12:58:24 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.19]) by ietfa.amsl.com (Postfix) with ESMTP id D45C71ADE88 for <ace@ietf.org>; Mon, 16 Dec 2013 12:58:23 -0800 (PST)
Received: from [192.168.10.155] ([2.102.217.110]) by mail.gmx.com (mrgmx002) with ESMTPSA (Nemesis) id 0Lbuo0-1V9fuE0uBQ-00jIJG for <ace@ietf.org>; Mon, 16 Dec 2013 21:58:22 +0100
Message-ID: <52AF6968.1050303@gmx.net>
Date: Mon, 16 Dec 2013 20:58:16 +0000
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Paul Madsen <paul.madsen@gmail.com>, Ludwig Seitz <ludwig@sics.se>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se> <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com>
In-Reply-To: <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------090701020507050802000704"
X-Provags-ID: V03:K0:eiVpzuPeOnkFpWjL5bbyrbRmWGwjr3xLDNoa4YTQDwIBd81AM3J agW2hCwTCQCw6LyWunyn+cHLkqkN9LIyCN+7W6c0qRu8JQXd+m/VSvNBNWC7aHZ4XtBvAZ3 wVIMX7XKavF1V9oilLiZUn3xQvZTKVK3DXgT0e171Lwfa8N1H14UchyQCUWuwibjccMoqfz YSIoB/34hF67Od8Ct26uw==
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 20:58:31 -0000

This is a multi-part message in MIME format.
--------------090701020507050802000704
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit

Very good question, Paul.

Historically, standardizing access control policies has not been very
successful (neither in the IETF nor in other organizations). Most
deployments either use proprietary extensions (because it provides
companies the glue they need to hold their different components together
and to provide a competitive advantage) or handle authorization at a
dedicated server (which requires a different type of standardization).
An example for the former: Kerberos authorization extension by
Microsoft. An example of the latter: AAA.

Now, the argument is that you want to have interoperability of
authorization decisions and maybe the outsourcing of the authorization
decision to a central server does not work.

Ciao
Hannes

On 12/16/2013 11:41 AM, Paul Madsen wrote:
> what does it mean to define the ACLs? define a format? 
>
> and, if so, what is the motivation for a standard format? not
> interchange presumably? 
>
> paul  
>
>
> On Fri, Dec 13, 2013 at 12:22 AM, Ludwig Seitz <ludwig@sics.se
> <mailto:ludwig@sics.se>> wrote:
>
>     On 12/13/2013 12:03 AM, Carsten Bormann wrote:
>
>
>         On 12 Dec 2013, at 19:32, Hannes Tschofenig
>         <Hannes.Tschofenig@gmx.net <mailto:Hannes.Tschofenig@gmx.net>>
>         wrote:
>
>             Hi all,
>
>             in a couple of drafts I see these pointers to access
>             control lists being described in CoAP. However, the CoAP
>             specification does not really say that much about access
>             control lists and by no means describes how they are
>             supposed to be used in any level of detail.
>
>
>         The CoAP base protocol (draft-ietf-core-coap) does not define
>         ACLs.
>         It just says you need to have some, because the authentication
>         that we get with DTLS is not the complete answer to the
>         security requirements.
>
>         The current ACE charter proposal says ACE should define the
>         ACLs for CoAP.
>         (My slide 105 from the CoRE WG at IETF88 says CoRE should
>         define the ACLs for CoAP.
>         Let's decide which WG does what *after* deciding what needs to
>         be done.)
>
>         Grüße, Carsten
>
>     +1
>
>     -- 
>     Ludwig Seitz, PhD
>     SICS Swedish ICT AB
>     Ideon Science Park
>     Building Beta 2
>     Scheelevägen 17
>     SE-223 70 Lund
>
>     Phone +46(0)70-349 92 51 <tel:%2B46%280%2970-349%2092%2051>
>     http://www.sics.se
>
>
>     _______________________________________________
>     Ace mailing list
>     Ace@ietf.org <mailto:Ace@ietf.org>
>     https://www.ietf.org/mailman/listinfo/ace
>
>
>
>
> -- 
> Paul Madsen
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------090701020507050802000704
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Very good question, Paul. <br>
    <br>
    Historically, standardizing access control policies has not been
    very successful (neither in the IETF nor in other organizations).
    Most deployments either use proprietary extensions (because it
    provides companies the glue they need to hold their different
    components together and to provide a competitive advantage) or
    handle authorization at a dedicated server (which requires a
    different type of standardization). An example for the former:
    Kerberos authorization extension by Microsoft. An example of the
    latter: AAA.<br>
    <br>
    Now, the argument is that you want to have interoperability of
    authorization decisions and maybe the outsourcing of the
    authorization decision to a central server does not work. <br>
    <br>
    Ciao<br>
    Hannes<br>
    <br>
    <div class="moz-cite-prefix">On 12/16/2013 11:41 AM, Paul Madsen
      wrote:<br>
    </div>
    <blockquote
cite="mid:CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">what does it mean to define the ACLs? define a
        format?&nbsp;
        <div><br>
        </div>
        <div style="">and, if so, what is the motivation for a standard
          format? not interchange presumably?&nbsp;</div>
        <div style=""><br>
        </div>
        <div style="">paul &nbsp;<br>
        </div>
      </div>
      <div class="gmail_extra"><br>
        <br>
        <div class="gmail_quote">On Fri, Dec 13, 2013 at 12:22 AM,
          Ludwig Seitz <span dir="ltr">&lt;<a moz-do-not-send="true"
              href="mailto:ludwig@sics.se" target="_blank">ludwig@sics.se</a>&gt;</span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div class="im">On 12/13/2013 12:03 AM, Carsten Bormann
              wrote:<br>
              <blockquote class="gmail_quote" style="margin:0 0 0
                .8ex;border-left:1px #ccc solid;padding-left:1ex">
                <br>
                On 12 Dec 2013, at 19:32, Hannes Tschofenig &lt;<a
                  moz-do-not-send="true"
                  href="mailto:Hannes.Tschofenig@gmx.net"
                  target="_blank">Hannes.Tschofenig@gmx.net</a>&gt;
                wrote:<br>
                <br>
                <blockquote class="gmail_quote" style="margin:0 0 0
                  .8ex;border-left:1px #ccc solid;padding-left:1ex">
                  Hi all,<br>
                  <br>
                  in a couple of drafts I see these pointers to access
                  control lists being described in CoAP. However, the
                  CoAP specification does not really say that much about
                  access control lists and by no means describes how
                  they are supposed to be used in any level of detail.<br>
                </blockquote>
                <br>
                The CoAP base protocol (draft-ietf-core-coap) does not
                define ACLs.<br>
                It just says you need to have some, because the
                authentication that we get with DTLS is not the complete
                answer to the security requirements.<br>
                <br>
                The current ACE charter proposal says ACE should define
                the ACLs for CoAP.<br>
                (My slide 105 from the CoRE WG at IETF88 says CoRE
                should define the ACLs for CoAP.<br>
                Let&#8217;s decide which WG does what *after* deciding what
                needs to be done.)<br>
                <br>
                Gr&uuml;&szlig;e, Carsten<br>
                <br>
              </blockquote>
            </div>
            +1<span class="HOEnZb"><font color="#888888"><br>
                <br>
                -- <br>
                Ludwig Seitz, PhD<br>
                SICS Swedish ICT AB<br>
                Ideon Science Park<br>
                Building Beta 2<br>
                Scheelev&auml;gen 17<br>
                SE-223 70 Lund<br>
                <br>
                Phone <a moz-do-not-send="true"
                  href="tel:%2B46%280%2970-349%2092%2051"
                  value="+46703499251" target="_blank">+46(0)70-349 92
                  51</a><br>
                <a moz-do-not-send="true" href="http://www.sics.se"
                  target="_blank">http://www.sics.se</a><br>
                <br>
              </font></span><br>
            _______________________________________________<br>
            Ace mailing list<br>
            <a moz-do-not-send="true" href="mailto:Ace@ietf.org">Ace@ietf.org</a><br>
            <a moz-do-not-send="true"
              href="https://www.ietf.org/mailman/listinfo/ace"
              target="_blank">https://www.ietf.org/mailman/listinfo/ace</a><br>
            <br>
          </blockquote>
        </div>
        <br>
        <br clear="all">
        <div><br>
        </div>
        -- <br>
        Paul Madsen<br>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------090701020507050802000704--

From hannes.tschofenig@gmx.net  Mon Dec 16 13:17:47 2013
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CBCC1A1F6F for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:17:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.438
X-Spam-Level: 
X-Spam-Status: No, score=-4.438 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, GB_I_LETTER=-2, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K-qNSnMN7uBa for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:17:42 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) by ietfa.amsl.com (Postfix) with ESMTP id E6AD41AC3DD for <ace@ietf.org>; Mon, 16 Dec 2013 13:17:41 -0800 (PST)
Received: from [192.168.10.155] ([2.102.217.110]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0M54L0-1Vbh7d39Be-00zBto for <ace@ietf.org>; Mon, 16 Dec 2013 22:17:40 +0100
Message-ID: <52AF6DF1.90203@gmx.net>
Date: Mon, 16 Dec 2013 21:17:37 +0000
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Michael Richardson <mcr+ietf@sandelman.ca>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org>, <CAC8QAcfbYjBrWO8pitHUYr=oq9WD6vkkjJ69vfiK+1oTjW7Uig@mail.gmail.com> <trinity-9d582751-d593-4ef3-a062-e03bdf2a63de-1386936882917@3capp-gmx-bs24> <7932.1387067834@sandelman.ca>
In-Reply-To: <7932.1387067834@sandelman.ca>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:R0sGUyPIdTYWjfOCN/J5+6Erb5zLh+xou6dS+8ElAjxtdDTqF+E 58cP9b6IHcB3KCmo0POVVr6Su5ADFg9Xr2WRTwJFH7NTOUVJ8mscsKTwXu+btYMp9P5bGDo yxM6669bubqNwm4SjbwVAdqKS8wwItFPtO9t24c2r/PlQCy0oSy31hoHRj58+OY0Fiaamr3 7LWcVr6stQpnItr6fxcvg==
Cc: sarikaya@ieee.org, Carsten Bormann <cabo@tzi.org>, ace@ietf.org
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 21:17:47 -0000

Hi Michael,

On 12/15/2013 12:37 AM, Michael Richardson wrote:
>> 1) You already have a secret pre-provisioned on the device. You want to
>> leverage that existing secret to access new services. This is what this key
>> distribution / key establishment stuff is all about. This is the typical
>> three party protocol (that some of the referenced documents use). Examples
>> I have seen are Behcet's AAA proposal, or the OAuth flavor of
>> draft-selander-core-access-control. Kerberos belongs to that category as
>> well and so would models with certificates (where the trusted third party
>> is the CA that issues the certificates).
> Would you include situations where the "secret" is imprinted upon a bar/QR
> code on the packaging under (1)?

Good question as well. 

The issue is that you can actually mix the different models together in
a single deployment because there is more than one credential.

For example, think about your WLAN access point (which most likely has
the secret printed on the bottom of the box). There you will most likely
use the secret for actually configuring the device. Instead of sending
you a letter with the password the manufacturer decided to print the
secret directly onto the box (which makes a lot of sense since you are
less likely to find they key later.

So, in that case this is just a regular out-of-band key provisioning
between two parties. The difference to the imprinting case is (if I
understood the terminology correctly) that the two devices do not have
anything provisioned prior to the exchange.

That's my understanding.

Ciao
Hannes

> --
> Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
>  -= IPv6 IoT consulting for hire =-
>
>


From hannes.tschofenig@gmx.net  Mon Dec 16 13:33:12 2013
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5974F1ADED5 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:33:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.438
X-Spam-Level: 
X-Spam-Status: No, score=-2.438 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U9tDmld3SGqS for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:33:10 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) by ietfa.amsl.com (Postfix) with ESMTP id 060631A1F1B for <ace@ietf.org>; Mon, 16 Dec 2013 13:33:10 -0800 (PST)
Received: from [192.168.10.155] ([2.102.217.110]) by mail.gmx.com (mrgmx001) with ESMTPSA (Nemesis) id 0MAxyW-1VikAS2E8C-009xr4 for <ace@ietf.org>; Mon, 16 Dec 2013 22:33:08 +0100
Message-ID: <52AF7193.2030908@gmx.net>
Date: Mon, 16 Dec 2013 21:33:07 +0000
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Carsten Bormann <cabo@tzi.org>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se> <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07> <546917AC-CFE6-464A-8E27-9403A6318896@tzi.org>
In-Reply-To: <546917AC-CFE6-464A-8E27-9403A6318896@tzi.org>
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: 8bit
X-Provags-ID: V03:K0:wAMQ5SnVx5ZRvT9UUVbj6ZeeSFr7ubDfqGwlHDoY0p14NB208NJ 5neYMJccrBh2W39RFZp+FvUNChl9lfu8NMk6ym1vEdHuRn0QkY0DIJpy6hK09AkrPADo4eM SZI9mydb+Jud+tVZcLPpw2Ap7Y5cYvBFv5ba/twLh1Wcu3M/QErBxeRWZlNr5POoKWKSlNY 1ekPdIPYCse6qtOG9i8FA==
Cc: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 21:33:12 -0000

Hi Carsten,


On 12/15/2013 03:34 PM, Carsten Bormann wrote:
> Hi Hannes,
>
> device identifiers aren’t access control lists, but they can be used to index an ACL (i.e., as the subject key into an access matrix).

This is pretty much how AAA servers work (in the simplistic case).  You
have a list of identifiers and their credentials. If authentication
works then you get network access or access to some other service.

Identity-based authorization is extremely common on the Internet in general.
> This works well when you have a way to authenticate a claim that a requested operation comes from the device with a given device identifier (“speaks for” the identifier).
> Associating a device identifier with an RPK is a way to authorize the holder of the associated private key to speak for the identifier, i.e., to make use of all ACL entries that give the identifier some permission.
> You might as well use the RPK as a device identifier, removing the need for maintaining that association, but there may also be benefits to an indirection through the device identifier.
>
> One important thing to remember here is that the “servers” in CoAP are the most constrained devices.
Let's see how the deployment reality works out. It is a bit premature to
tell that at this point in time.
> They also can’t reasonably talk to a big brother (cf. EAP’s authentication server) for each enforcement decision.

Maybe. I am also not so sure about that.

> So the constrained devices really need a (simple form) of ACL/C-list, one which is set up to enable authenticated authorization.  We already have the authentication part for using that ACL/C-list via DTLS.
>
> Delegating the onus of communication with the big brother to the client is one of the ideas behind several of the proposals here, including DCAF.
> Now that needs a way to authenticate the input from the big brother to the server via multiple DTLS hops (item 3 on slide 105 from core@IETF88).
> It also would benefit from some standardized form of ACL/C-list (item 2 on that slide).

Got that for the three party model.

>
> Göran is right that there is a lot of work that still needs to be done, and I want to thank you for asking good questions here.  There are often three phases of dealing with complexity:
> 1) when you don’t understand things, everything seems simple;
> 2) when you start to understand things, everything appears to become more and more complex;
> 3) when you really understand things, you discover the structure relevant to making things simple again.
> We are in the middle of phase 2, and your input will help us get to phase 3; I’m confident that this will all be much simpler when we are done with that.
The challenge for me is to find the right assumptions. From the
discussions I can see that you make certain assumptions about the
expected deployment environment. From the answer about the use case
gathering we are sort of guessing a bit (and that's fine) but there is
also the risk that we get it completely wrong.

Ciao
Hannes

>
> Grüße, Carsten
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


From hannes.tschofenig@gmx.net  Mon Dec 16 13:35:47 2013
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B91E31ADD02 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:35:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.437
X-Spam-Level: 
X-Spam-Status: No, score=-2.437 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ze8ItS7wMaER for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:35:45 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.20]) by ietfa.amsl.com (Postfix) with ESMTP id 79BE91A1F1B for <ace@ietf.org>; Mon, 16 Dec 2013 13:35:45 -0800 (PST)
Received: from [192.168.10.155] ([2.102.217.110]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0MCLx3-1VjZ8j0ZAf-009CiI for <ace@ietf.org>; Mon, 16 Dec 2013 22:35:44 +0100
Message-ID: <52AF722E.2000307@gmx.net>
Date: Mon, 16 Dec 2013 21:35:42 +0000
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
References: <trinity-8ef43169-6c2a-4e24-9b41-a8f9102a16fd-1386863284974@3capp-gmx-bs21> <52AB2DBF.9090102@sics.se>
In-Reply-To: <52AB2DBF.9090102@sics.se>
Content-Type: multipart/alternative; boundary="------------070201040205080208050603"
X-Provags-ID: V03:K0:OKAuRoc+3G9FVTw1ZcIvcYjcdvsoBlIu1Av5upIW3nXV05K3W4e 3Jkg8hXfZzoc1yWokxwVZN8sz7D7blHmhT7M/N36LItxzvWg1g+L0wMcP5DiYScAFiNRxqD 1JErum344f96FO/qJYSNh8GWPfrPS+oqsBvIheyBmbNPo6StFzHdOpUbWl4ocpdGY/f6WXy A5v5/gH4ueD58gbqKt4bw==
Subject: Re: [Ace] draft-seitz-core-sec-usecases-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 21:35:47 -0000

This is a multi-part message in MIME format.
--------------070201040205080208050603
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

Hi Ludwig,

thanks for the honest response. Of course it would be good to have more
real-world deployment data but if we don't have that information then
that's the best we can do.

The use case draft was in any case well written and it was fun to read it.
Normally, use case documents are boring but this one wasn't.

Ciao
Hannes

On 12/13/2013 03:54 PM, Ludwig Seitz wrote:
> On 12/12/2013 04:48 PM, Hannes Tschofenig wrote:
>> Dear Goeran, Stefanie, Ludwig,
>> I read your document with great interest and I like the description. One
>> basic question did, however, come to my mind.
>> Collecting requirements is always a difficult job since it requires you
>> to understand the problem domain and that specific industry sector well
>> enough to know how the stakeholders are planning to deploy their
>> technology.
>> How did you collect these requirements?
>
> What we did was to collect somewhat realistic use cases with relevant
> security issues. Then we made educated guesses as to what security
> requirements could result from those issues. The main goal (as I
> understood it) was to get some feedback on whether these could be
> considered reasonable and important, so actually we are in the process
> of collection requirements. Those in the draft are mostly meant as a
> base for discussion.
>
> As for concrete input, I've used some requirements from a company for
> the Industrial Control Systems use case, and I made some web research
> on Personal Health Monitoring and Home Automation products. Most of
> these are still at prototype or early-adopter stage, so information on
> planned deployments tend to be pretty vague. The container monitoring
> scenario is derived from an existing logistics project with the help
> of members from the project consortium.
>
> Regards,
>
> Ludwig
>
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------070201040205080208050603
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hi Ludwig, <br>
    <br>
    thanks for the honest response. Of course it would be good to have
    more real-world deployment data but if we don't have that
    information then that's the best we can do. <br>
    <br>
    The use case draft was in any case well written and it was fun to
    read it. <br>
    Normally, use case documents are boring but this one wasn't. <br>
    <br>
    Ciao<br>
    Hannes<br>
    <br>
    <div class="moz-cite-prefix">On 12/13/2013 03:54 PM, Ludwig Seitz
      wrote:<br>
    </div>
    <blockquote cite="mid:52AB2DBF.9090102@sics.se" type="cite">On
      12/12/2013 04:48 PM, Hannes Tschofenig wrote:
      <br>
      <blockquote type="cite">Dear Goeran, Stefanie, Ludwig,
        <br>
        I read your document with great interest and I like the
        description. One
        <br>
        basic question did, however, come to my mind.
        <br>
        Collecting requirements is always a difficult job since it
        requires you
        <br>
        to understand the problem domain and that specific industry
        sector well
        <br>
        enough to know how the stakeholders are planning to deploy their
        technology.
        <br>
        How did you collect these requirements?
        <br>
      </blockquote>
      <br>
      What we did was to collect somewhat realistic use cases with
      relevant security issues. Then we made educated guesses as to what
      security requirements could result from those issues. The main
      goal (as I understood it) was to get some feedback on whether
      these could be considered reasonable and important, so actually we
      are in the process of collection requirements. Those in the draft
      are mostly meant as a base for discussion.
      <br>
      <br>
      As for concrete input, I've used some requirements from a company
      for the Industrial Control Systems use case, and I made some web
      research on Personal Health Monitoring and Home Automation
      products. Most of these are still at prototype or early-adopter
      stage, so information on planned deployments tend to be pretty
      vague. The container monitoring scenario is derived from an
      existing logistics project with the help of members from the
      project consortium.
      <br>
      <br>
      Regards,
      <br>
      <br>
      Ludwig
      <br>
      <br>
      <br>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------070201040205080208050603--

From hannes.tschofenig@gmx.net  Mon Dec 16 13:40:07 2013
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A67B61A82E2 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:40:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.437
X-Spam-Level: 
X-Spam-Status: No, score=-2.437 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MZZpsDT2UD0U for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 13:40:05 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.18]) by ietfa.amsl.com (Postfix) with ESMTP id EFB561A1F1B for <ace@ietf.org>; Mon, 16 Dec 2013 13:40:04 -0800 (PST)
Received: from [192.168.10.155] ([2.102.217.110]) by mail.gmx.com (mrgmx003) with ESMTPSA (Nemesis) id 0Lj1Cw-1VFmAv1qFa-00dHJq for <ace@ietf.org>; Mon, 16 Dec 2013 22:40:03 +0100
Message-ID: <52AF7332.8050607@gmx.net>
Date: Mon, 16 Dec 2013 21:40:02 +0000
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Ludwig Seitz <ludwig@sics.se>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se> <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07> <52AECA2C.7010806@sics.se>
In-Reply-To: <52AECA2C.7010806@sics.se>
Content-Type: multipart/alternative; boundary="------------000705080103030807020303"
X-Provags-ID: V03:K0:GLN8CaAQduZxF9Bgd3+RiMhQPDxFEQtGKnDDhw0ZNmTNjkr+lSR ONxMMzXnqrhI6EOaSxhHNlatYfTbEbnIyqB4csYizST/u2wqhKY77i0E4xoTuoi9UKZDng9 oYYq2u7+rCZfah/qzTFw3lgi3T66L31tbXvF1J4jBLvHEzwqYWbbRQzAFcTJo//I/H14kbF K1s+sj/5z0im0YeX8zqxA==
Cc: ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 21:40:07 -0000

This is a multi-part message in MIME format.
--------------000705080103030807020303
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

Hi Ludwig,

thanks for the feedback and pointing me to the right places in the document

I think the following wording confused me:

"
   During the provisioning phase, a CoAP device is provided with the
   security information that it needs, including keying materials and
   access control lists.
"

I think the text should either say:


"
   During the provisioning phase, a CoAP server is provided with the
   security information that it needs, including keying materials and
   access control lists.
"

or


"
   During the provisioning phase, a CoAP client is provided with the
   security information that it needs, including keying materials and
   information about the CoAP servers it needs to interact.
"

Maybe there is still a chance to clarify this in AUTH48.

Ciao
Hannes

On 12/16/2013 09:38 AM, Ludwig Seitz wrote:
> On 12/13/2013 06:10 PM, Hannes Tschofenig wrote:
>> Hi Ludwig,
>> thanks for the response.
>> I think the concept of access control had gotten wrong there a bit.
>> Many devices may need to have some information (like an IP address,
>> FQDN, or URIs) for the services they have to interact with.
>> I would have not called this an access control list. The access control
>> list is either on the server side or on a third party that makes the
>> decision about accessing the server.
>
> Just to make sure we don't misunderstand each other: when I say
> (resource) server I mean the device. So yes, the list is on the server
> side according to my understanding of the CoAP spec.
>
> Furthermore: It's a list that is used to decide who gets to make a
> DTLS connection to the device. With no other access controls present
> I'd call this an "access control list", and apparently so does the
> CoAP spec.
>
> Could you elaborate on why you think this gets the concept of access
> control wrong?
>
>> For the use of raw public keys from the server to the client you
>> actually have to do some out-of-band validation of the public key of the
>> server. The specification is explicit about the need for it. There is no
>> identifier that comes along with the public key as such since the idea
>> was to stripped off everything from a certificate except for the public
>> key.
>
> Right, isn't that exactly what the CoAP spec says? I hope I didn't
> give the impression I was questioning that.
>
> From the CoAP spec:
>
>    RawPublicKey:  DTLS is enabled and the device has an asymmetric key
>       pair without a certificate (a raw public key) that is validated
>       using an out-of-band mechanism [I-D.ietf-tls-oob-pubkey] as
>       described in Section 9.1.3.2.  The device also has an identity
>       calculated from the public key and a list of identities of the
>       nodes it can communicate with.
>
>
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


--------------000705080103030807020303
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Hi Ludwig, <br>
    <br>
    thanks for the feedback and pointing me to the right places in the
    document <br>
    <br>
    I think the following wording confused me: <br>
    <br>
    " <br>
    &nbsp;&nbsp; During the provisioning phase, a CoAP device is provided with the<br>
    &nbsp;&nbsp; security information that it needs, including keying materials
    and<br>
    &nbsp;&nbsp; access control lists.<br>
    " <br>
    <br>
    I think the text should either say:<br>
    <br>
    <br>
    " <br>
    &nbsp;&nbsp; During the provisioning phase, a CoAP server is provided with the<br>
    &nbsp;&nbsp; security information that it needs, including keying materials
    and<br>
    &nbsp;&nbsp; access control lists.<br>
    " <br>
    <br>
    or<br>
    <br>
    <br>
    " <br>
    &nbsp;&nbsp; During the provisioning phase, a CoAP client is provided with the<br>
    &nbsp;&nbsp; security information that it needs, including keying materials
    and<br>
    &nbsp;&nbsp; information about the CoAP servers it needs to interact.<br>
    " <br>
    <br>
    Maybe there is still a chance to clarify this in AUTH48. <br>
    <br>
    Ciao<br>
    Hannes<br>
    <br>
    <div class="moz-cite-prefix">On 12/16/2013 09:38 AM, Ludwig Seitz
      wrote:<br>
    </div>
    <blockquote cite="mid:52AECA2C.7010806@sics.se" type="cite">On
      12/13/2013 06:10 PM, Hannes Tschofenig wrote:
      <br>
      <blockquote type="cite">Hi Ludwig,
        <br>
        thanks for the response.
        <br>
        I think the concept of access control had gotten wrong there a
        bit.
        <br>
        Many devices may need to have some information (like an IP
        address,
        <br>
        FQDN, or URIs) for the services they have to interact with.
        <br>
        I would have not called this an access control list. The access
        control
        <br>
        list is either on the server side or on a third party that makes
        the
        <br>
        decision about accessing the server.
        <br>
      </blockquote>
      <br>
      Just to make sure we don't misunderstand each other: when I say
      (resource) server I mean the device. So yes, the list is on the
      server side according to my understanding of the CoAP spec.
      <br>
      <br>
      Furthermore: It's a list that is used to decide who gets to make a
      DTLS connection to the device. With no other access controls
      present I'd call this an "access control list", and apparently so
      does the CoAP spec.
      <br>
      <br>
      Could you elaborate on why you think this gets the concept of
      access control wrong?
      <br>
      <br>
      <blockquote type="cite">For the use of raw public keys from the
        server to the client you
        <br>
        actually have to do some out-of-band validation of the public
        key of the
        <br>
        server. The specification is explicit about the need for it.
        There is no
        <br>
        identifier that comes along with the public key as such since
        the idea
        <br>
        was to stripped off everything from a certificate except for the
        public
        <br>
        key.
        <br>
      </blockquote>
      <br>
      Right, isn't that exactly what the CoAP spec says? I hope I didn't
      give the impression I was questioning that.
      <br>
      <br>
      From the CoAP spec:
      <br>
      <br>
      &nbsp;&nbsp; RawPublicKey:&nbsp; DTLS is enabled and the device has an asymmetric
      key
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; pair without a certificate (a raw public key) that is
      validated
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; using an out-of-band mechanism [I-D.ietf-tls-oob-pubkey] as
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; described in Section 9.1.3.2.&nbsp; The device also has an
      identity
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; calculated from the public key and a list of identities of
      the
      <br>
      &nbsp;&nbsp;&nbsp;&nbsp;&nbsp; nodes it can communicate with.
      <br>
      <br>
      <br>
      <br>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------000705080103030807020303--

From likepeng@huawei.com  Mon Dec 16 17:03:13 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 96E1C1ADFB0 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 17:03:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.739
X-Spam-Level: 
X-Spam-Status: No, score=-4.739 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FfSpthM6HQp8 for <ace@ietfa.amsl.com>; Mon, 16 Dec 2013 17:03:12 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 036EA1ADFCF for <ace@ietf.org>; Mon, 16 Dec 2013 17:03:10 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBM65993; Tue, 17 Dec 2013 01:03:09 +0000 (GMT)
Received: from LHREML402-HUB.china.huawei.com (10.201.5.241) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 17 Dec 2013 01:02:44 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml402-hub.china.huawei.com (10.201.5.241) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 17 Dec 2013 01:03:09 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Tue, 17 Dec 2013 09:03:02 +0800
From: Likepeng <likepeng@huawei.com>
To: Carsten Bormann <cabo@tzi.org>, Ludwig Seitz <ludwig@sics.se>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: AQHO92swut0VGmvey0qAQQLzZcFNrJpQmvCAgADi4iD///tSAIAEq9rg///h+4CAAAOCAIABjGOg
Date: Tue, 17 Dec 2013 01:03:00 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD4CFE@SZXEMA501-MBS.china.huawei.com>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com> <52AEC257.4060503@sics.se> <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org>
In-Reply-To: <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Dec 2013 01:03:13 -0000

PkRvIHdlIGtub3cgd2hhdCBpdCBpcyB0aGUgbmFtZSBvZiB3aGljaCB3ZSBhcmUgZGVjaWRpbmc/
DQoNCkl0IGlzIGFib3V0IHRoZSAiYWNjZXNzIHRva2VuIiBpbiB0aGUgY2hhcnRlci4NCi0gRGVm
aW5lIGFuIGFjY2VzcyB0b2tlbiBhbmQgYXV0aG9yaXphdGlvbiBpbmZvcm1hdGlvbiBmb3JtYXQg
c3VpdGFibGUgZm9yIGNvbnN0cmFpbmVkIGRldmljZXMuDQoNClR3byBwcm9wb3NhbHMgc28gZmFy
OiANClsxXSBhY2Nlc3MgdGlja2V0LCBzaG9ydDogdGlja2V0DQpbMl0gYXV0aG9yaXphdGlvbiBj
cmVkZW50aWFsLCBzaG9ydDogY3JlZGVudGlhbCBbIF0gYXV0aG9yaXphdGlvbiB0b2tlbiwgc2hv
cnQ6IHRva2VuIFsgXSBvdGhlcg0KDQo+SSBoYXZlbuKAmXQgc2VlbiBhIGRpc2N1c3Npb24gb2Yg
YSBkZWZpbml0aW9uLg0KDQpEZWZpbml0aW9ucyBmcm9tIFJGQzQ5NDk6DQoNCiAgICQgdGlja2V0
OiBBIHRpY2tldCBpcyB1c3VhbGx5IGdyYW50ZWQgYnkgYSBjZW50cmFsaXplZCBhY2Nlc3MNCiAg
ICAgIGNvbnRyb2wgc2VydmVyICh0aWNrZXQtZ3JhbnRpbmcgYWdlbnQpIHRvIGF1dGhvcml6ZSBh
Y2Nlc3MgdG8gYQ0KICAgICAgc3lzdGVtIHJlc291cmNlIGZvciBhIGxpbWl0ZWQgdGltZS4gDQoN
CiAgICQgY3JlZGVudGlhbA0KMi4gKEkpIC9hY2Nlc3MgY29udHJvbC8gImF1dGhvcml6YXRpb24g
Y3JlZGVudGlhbCI6IEEgZGF0YSBvYmplY3QNCiAgICAgIHRoYXQgaXMgYSBwb3J0YWJsZSByZXBy
ZXNlbnRhdGlvbiBvZiB0aGUgYXNzb2NpYXRpb24gYmV0d2VlbiBhbg0KICAgICAgaWRlbnRpZmll
ciBhbmQgb25lIG9yIG1vcmUgYWNjZXNzIGF1dGhvcml6YXRpb25zLCBhbmQgdGhhdCBjYW4gYmUN
CiAgICAgIHByZXNlbnRlZCBmb3IgdXNlIGluIHZlcmlmeWluZyB0aG9zZSBhdXRob3JpemF0aW9u
cyBmb3IgYW4gZW50aXR5DQogICAgICB0aGF0IGF0dGVtcHRzIHN1Y2ggYWNjZXNzLiBFeGFtcGxl
OiBYLjUwOSBhdHRyaWJ1dGUgY2VydGlmaWNhdGUuDQogICAgICAoU2VlOiBjYXBhYmlsaXR5IHRv
a2VuLCB0aWNrZXQuKQ0KDQpLaW5kIFJlZ2FyZHMNCmtlcGVuZw0KDQotLS0tLemCruS7tuWOn+S7
ti0tLS0tDQrlj5Hku7bkuro6IEFjZSBbbWFpbHRvOmFjZS1ib3VuY2VzQGlldGYub3JnXSDku6Po
oaggQ2Fyc3RlbiBCb3JtYW5uDQrlj5HpgIHml7bpl7Q6IDIwMTPlubQxMuaciDE25pelIDE3OjE4
DQrmlLbku7bkuro6IEx1ZHdpZyBTZWl0eg0K5oqE6YCBOiBhY2VAaWV0Zi5vcmcNCuS4u+mimDog
UmU6IFtBY2VdIFRlcm1zIHRvIGF2b2lkDQoNCk9uIDE2IERlYyAyMDEzLCBhdCAxMDowNSwgTHVk
d2lnIFNlaXR6IDxsdWR3aWdAc2ljcy5zZT4gd3JvdGU6DQoNCj4gV2h5IG5vdCBqdXN0IGhhdmUg
YSBwb2xsPyANCg0KRG8gd2Uga25vdyB3aGF0IGl0IGlzIHRoZSBuYW1lIG9mIHdoaWNoIHdlIGFy
ZSBkZWNpZGluZz8NCkkgaGF2ZW7igJl0IHNlZW4gYSBkaXNjdXNzaW9uIG9mIGEgZGVmaW5pdGlv
bi4NCg0KR3LDvMOfZSwgQ2Fyc3Rlbg0KDQpfX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fXw0KQWNlIG1haWxpbmcgbGlzdA0KQWNlQGlldGYub3JnDQpodHRwczov
L3d3dy5pZXRmLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2FjZQ0K

From ludwig@sics.se  Tue Dec 17 02:09:05 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D1871ADFBE for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:09:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.067
X-Spam-Level: 
X-Spam-Status: No, score=-1.067 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, MISSING_HEADERS=1.021, RP_MATCHES_RCVD=-0.538] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2jvy1AUTOyzG for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:09:02 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id 9A3431AE13B for <ace@ietf.org>; Tue, 17 Dec 2013 02:08:47 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBHA6lnW023887 for <ace@ietf.org>; Tue, 17 Dec 2013 11:08:45 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asahrhk-1 for <ace@ietf.org>; Tue, 17 Dec 2013 11:08:45 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id 902AE400E2 for <ace@ietf.org>; Tue, 17 Dec 2013 11:08:45 +0100 (CET)
Message-ID: <52B022AD.4040306@sics.se>
Date: Tue, 17 Dec 2013 11:08:45 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
CC: ace@ietf.org
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21> <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <52AAC3DD.9030802@sics.se> <CA+bqkgFUtgu1o2LghDKbJSYCtzPM9v79nmVOfotpNy2vOJDQiQ@mail.gmail.com> <52AF6968.1050303@gmx.net>
In-Reply-To: <52AF6968.1050303@gmx.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms050601040009020409060602"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-17_01:2013-12-17,2013-12-17,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312170021
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Dec 2013 10:09:05 -0000

This is a cryptographically signed message in MIME format.

--------------ms050601040009020409060602
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/16/2013 09:58 PM, Hannes Tschofenig wrote:
> Very good question, Paul.
>
> Historically, standardizing access control policies has not been very
> successful (neither in the IETF nor in other organizations).

Sorry, but this is just wrong.

Just have a look at XACML and the list of companies using it [1] (and=20
that list is hardly up to date).
There are several companies selling XACML products (including Oracle,=20
IBM, Quest, NextLabs, and Axiomatics).
If you look at e.g. the Axiomatics customer list [2] a lot of companies=20
are buying these products (e.g. Bank of America, PayPal, Bell=20
Helicopter, Boeing, the Swedish Public Employment Service, DATEV, Swiss R=
e).

Identity and Access Management is a very small market and it takes a lot =

of convincing to make companies buy anything new in that sector (since=20
it doesn't affect sales immediately), but I'd claim that
XACML has been very successful as far as standardizing access control=20
policies goes.

/Ludwig


[1]=20
https://www.oasis-open.org/committees/download.php/42588/xacmlRefs-V1-85.=
html#Products

[2] https://axiomatics.com/customers.html

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms050601040009020409060602
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTcxMDA4NDVaMCMGCSqGSIb3DQEJBDEW
BBSmAM9V4h33w+4vbvf0jfmHYa6fJTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAQmbUO9/XMmAYS3ARkV353xApJ83vbGjuRKLFzRak5jBmwfqq1Ey71T4qDJXX9ox5Fevp
Jvu3u8pnetByEVbifdfmfO4/YIfmUqCLX6jFZ8yldir6WepgU59A1WBs3wB2wKF0i3qtvkN+
8NnTqKDkrN67mxMsEP4/+m3jfK61+uWEwDAjG28foJ8DjmGFBjd6lOfUaoQ5sMziO/BEDtMc
ryWgteFfnenT+MIM1nPAzT0SYmwlPYuQOwVKfng2LArdjittTNPCRtU5ZneALjAG9fdAK+t7
x00i2tWZyLZ3HWIJnOn0t2xCf9oATVzRgw4fY9cCdiiN/cywEPS7s/o7UwAAAAAAAA==
--------------ms050601040009020409060602--

From cabo@tzi.org  Tue Dec 17 02:10:39 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B7191AE143 for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:10:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pG85zeKbXezR for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:10:37 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 2DA101AE13C for <ace@ietf.org>; Tue, 17 Dec 2013 02:10:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBHAANED015541; Tue, 17 Dec 2013 11:10:23 +0100 (CET)
Received: from [10.0.1.4] (reingewinn.informatik.uni-bremen.de [134.102.218.123]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 05B217F9; Tue, 17 Dec 2013 11:10:22 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.1 \(1827\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD4CFE@SZXEMA501-MBS.china.huawei.com>
Date: Tue, 17 Dec 2013 11:10:22 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <F4257D7D-8B1F-4D90-B258-9BD155E72F6C@tzi.org>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com> <52AEC257.4060503@sics.se> <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD4CFE@SZXEMA501-MBS.china.huawei.com>
To: Likepeng <likepeng@huawei.com>
X-Mailer: Apple Mail (2.1827)
Cc: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Dec 2013 10:10:39 -0000

On 17 Dec 2013, at 02:03, Likepeng <likepeng@huawei.com> wrote:

>> Do we know what it is the name of which we are deciding?
>=20
> It is about the "access token" in the charter.
> - Define an access token and authorization information format suitable =
for constrained devices.

Yes.  What I was (tersely) trying to say was that we should define what =
that is before we decide on a name for it.
For that discussion, both =93token=94 and =93ticket=94 are fine.
(I=92m not a big fan of =93credential=94, but that is because I have a =
mental image of what that thing should be.)

Gr=FC=DFe, Carsten


From ludwig@sics.se  Tue Dec 17 02:21:56 2013
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA8531AE13B for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:21:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level: 
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_SE=0.35, RP_MATCHES_RCVD=-0.538] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JII12rJlTdcJ for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:21:55 -0800 (PST)
Received: from fsmsg2.sics.se (fsmsg2.sics.se [IPv6:2001:6b0:3a:1:250:56ff:fea9:52ad]) by ietfa.amsl.com (Postfix) with ESMTP id C9EB21AE12B for <ace@ietf.org>; Tue, 17 Dec 2013 02:21:54 -0800 (PST)
Received: from pps.filterd (fsmsg2 [127.0.0.1]) by fsmsg2.sics.se (8.14.5/8.14.5) with SMTP id rBHAINib032350 for <ace@ietf.org>; Tue, 17 Dec 2013 11:21:53 +0100
Received: from letter.sics.se (letter.sics.se [193.10.64.6]) by fsmsg2.sics.se with ESMTP id 1g7asahrs3-1 for <ace@ietf.org>; Tue, 17 Dec 2013 11:21:52 +0100
Received: from [192.168.0.103] (unknown [85.235.11.178]) (Authenticated sender: ludwig@sics.se) by letter.sics.se (Postfix) with ESMTPSA id C81B2400E2 for <ace@ietf.org>; Tue, 17 Dec 2013 11:21:52 +0100 (CET)
Message-ID: <52B025C0.5050800@sics.se>
Date: Tue, 17 Dec 2013 11:21:52 +0100
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com> <52AEC257.4060503@sics.se> <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD4CFE@SZXEMA501-MBS.china.huawei.com> <F4257D7D-8B1F-4D90-B258-9BD155E72F6C@tzi.org>
In-Reply-To: <F4257D7D-8B1F-4D90-B258-9BD155E72F6C@tzi.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms070809010707060105080206"
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87, 1.0.14, 0.0.0000 definitions=2013-12-17_01:2013-12-17,2013-12-17,1970-01-01 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=1 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1305240000 definitions=main-1312170022
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Dec 2013 10:21:56 -0000

This is a cryptographically signed message in MIME format.

--------------ms070809010707060105080206
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 12/17/2013 11:10 AM, Carsten Bormann wrote:
> On 17 Dec 2013, at 02:03, Likepeng <likepeng@huawei.com> wrote:
>
>>> Do we know what it is the name of which we are deciding?
>>
>> It is about the "access token" in the charter.
>> - Define an access token and authorization information format suitable=
 for constrained devices.
>
> Yes.  What I was (tersely) trying to say was that we should define what=
 that is before we decide on a name for it.
> For that discussion, both =93token=94 and =93ticket=94 are fine.
> (I=92m not a big fan of =93credential=94, but that is because I have a =
mental image of what that thing should be.)
>
> Gr=FC=DFe, Carsten
>

Perhaps my attempt to define it was too unspecific:

  "a data object carrying authorization information"

But if I may expand on this and suggest the following:

"a data object carrying information about an authorization decision"


/Ludwig

--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms070809010707060105080206
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwW1izANBgkqhkiG9w0BAQsFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTEzMDExNTAyMDUwNloXDTE0MDExNTE0Mzc0OFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqm5Fq+vazAJCxhLsrE6yZ4Fcjf22HECMhhoH
QAVWMuk61UnFAxiiKnsGb2iRrw9fFD2ZZP+VVKiojuMaNzlnyrULh84UwJhmkm6Ab2olLQ4x
XZqNDvFe7djMtMMgqD8Erf35WuK8mrRjqHPX/imDEw4Ub6XvL5+rnhBKQozCm5FoIHOcol5H
EbAO+F4XZA3pgQFyUWpWGlyIMZ3na9fkCBspupWZ68ytytxgB0poqbqJMSZtge6bkP/gZo6e
dnbAydjkSkqHHGbpKzMJVI12TyJlJTN70Zg/OF4EMgcwN0tmJvrNqhH3oXlkKkTWk94ojP8M
J3eQv6del7mB1tJcuwIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTAO/qDJzu5Icr9AFUhmI3z
qGMpbjAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQELBQADggEBADhtqCPIvc8t6La1swQso5U7FF3Is5txWrQWPzcttJMyPo1LzdNT/jHEKF93
nOqiKm50NISmDFkBSxKOTTYPFJ4thgFcTZf+K57ucvxL/c+MLj3PlmCMNmtciCa8gxpldYz4
aob7CT02KQZvX+yGUmOTdHkoLd9FaxRq0ei43EAxjGIsU7vliaAoKCSO0pRsdtSrOYNV3fSd
ZB6xd8KBjAJsC8P/Q2BfeMT5+fJPvX5pfj8h+qyGkJCPx2RHhkf5tSIrnOAoYkvrUZFk1JJx
H+v1KrX2QRCu3fx7L9D3S1QNSCD3d3nDcM2sXdtGg6/KynBtw31O4YqQWgU9XQp+NoYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwW1izAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMzEyMTcxMDIxNTJaMCMGCSqGSIb3DQEJBDEW
BBT/U1KqCg2e/jxb3vKKcEdY8DdCOzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDBbWLMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMFtYswDQYJKoZIhvcNAQEBBQAE
ggEAGbpmWf0McM5ABVvA5rcuvmwRTh+h3fCJ/47S3e6B1VEa8j9L9JJXs1AZCMlLdjQgbnvg
QwQtiOJr9Eh6ijIpzZ6zvEFsfFj0XzIBbVU7jX1qD6/F9qNEJhlFJYfNO4GrYCXO7gN3cP3V
NrOEN/2wf5ZGzlRJO+lRQ+gdh3X7isBOfg/c+dErBC22mvKoMcDTZmB7mb0PGXzZhP8mRokk
x+DNoBRjlZJJHlEL//tyvgJQiC1D0xcGKpS0LWGQ7sMhjJYVNP2UD2lv6eaygEzsHdQkMjul
ivAQwEL2vkwzMfu2aye015uwI16QYgLBLMZsAJ6l2u3e64Tvktf5fCUEpAAAAAAAAA==
--------------ms070809010707060105080206--

From cabo@tzi.org  Tue Dec 17 02:25:59 2013
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DED881ADBC7 for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:25:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.551
X-Spam-Level: 
X-Spam-Status: No, score=-1.551 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Hn3EPW2yonH for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 02:25:58 -0800 (PST)
Received: from informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) by ietfa.amsl.com (Postfix) with ESMTP id 88B7C1ADBCF for <ace@ietf.org>; Tue, 17 Dec 2013 02:25:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from smtp-fb3.informatik.uni-bremen.de (smtp-fb3.informatik.uni-bremen.de [134.102.224.120]) by informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id rBHAPsx9016092; Tue, 17 Dec 2013 11:25:54 +0100 (CET)
Received: from [10.0.1.4] (reingewinn.informatik.uni-bremen.de [134.102.218.123]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp-fb3.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3DFF6822; Tue, 17 Dec 2013 11:25:54 +0100 (CET)
Mime-Version: 1.0 (Mac OS X Mail 7.1 \(1827\))
Content-Type: text/plain; charset=windows-1252
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <52AF7193.2030908@gmx.net>
Date: Tue, 17 Dec 2013 11:25:53 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <5C5672A5-3209-4904-87A1-2F3C3FD2BB3A@tzi.org>
References: <trinity-92d72b3f-d1c9-41d9-a39f-dae288360cfa-1386873138484@3capp-gmx-bs21>, <5CAF87B9-7312-4AB6-A7BE-E4C66ADEC2CA@tzi.org> <trinity-da014ff3-b20a-40f1-b0df-1c6274b954c2-1386948670533@3capp-gmx-bs07>, <52AB2D11.2080109@sics.se> <trinity-42664287-5f4e-4998-a5a0-bd6923465c49-1386954620756@3capp-gmx-bs07> <546917AC-CFE6-464A-8E27-9403A6318896@tzi.org> <52AF7193.2030908@gmx.net>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
X-Mailer: Apple Mail (2.1827)
Cc: Ludwig Seitz <ludwig@sics.se>, ace@ietf.org
Subject: Re: [Ace] Access Control Lists in CoAP
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Dec 2013 10:26:00 -0000

On 16 Dec 2013, at 22:33, Hannes Tschofenig <hannes.tschofenig@gmx.net> =
wrote:

> Hi Carsten,
>=20
>=20
> On 12/15/2013 03:34 PM, Carsten Bormann wrote:
>> Hi Hannes,
>>=20
>> device identifiers aren=92t access control lists, but they can be =
used to index an ACL (i.e., as the subject key into an access matrix).
>=20
> This is pretty much how AAA servers work (in the simplistic case).  =
You
> have a list of identifiers and their credentials. If authentication
> works then you get network access or access to some other service.
>=20
> Identity-based authorization is extremely common on the Internet in =
general.

Certainly.
One of the embryonic results of the Paris workshop was that maybe the =
importance of identity will be different for constrained devices.
So I would like to be prepared for a world where not everything needs to =
go through naming authorities.

>> This works well when you have a way to authenticate a claim that a =
requested operation comes from the device with a given device identifier =
(=93speaks for=94 the identifier).
>> Associating a device identifier with an RPK is a way to authorize the =
holder of the associated private key to speak for the identifier, i.e., =
to make use of all ACL entries that give the identifier some permission.
>> You might as well use the RPK as a device identifier, removing the =
need for maintaining that association, but there may also be benefits to =
an indirection through the device identifier.
>>=20
>> One important thing to remember here is that the =93servers=94 in =
CoAP are the most constrained devices.
> Let's see how the deployment reality works out. It is a bit premature =
to
> tell that at this point in time.

The deployment reality right now is dominated by IPv4 concerns. =20
In IPv4, servers are useless, so everything is a client, and you need to =
put everything else in the cloud.
I=92m not sure we want to continue to emulate this world.

But yes, we want to make sure that what we do works for both constrained =
clients and constrained servers.
That=92s one reason why delegation is such an important function here.

>> They also can=92t reasonably talk to a big brother (cf. EAP=92s =
authentication server) for each enforcement decision.
>=20
> Maybe. I am also not so sure about that.

Each resource access needs an enforcement decision.  So I=92m pretty =
sure about that :-)

[=85]
> The challenge for me is to find the right assumptions. =46rom the
> discussions I can see that you make certain assumptions about the
> expected deployment environment. =46rom the answer about the use case
> gathering we are sort of guessing a bit (and that's fine) but there is
> also the risk that we get it completely wrong.

Absolutely.  We may be =93flexible=94 in some things, but will have to =
make assumptions in other things.
That set of assumptions is what is usually called an =93architecture=94=85=

I=92d like this work to stay within the CoRE architecture instead of =
trying to solve all possible problems.

Gr=FC=DFe, Carsten


From likepeng@huawei.com  Tue Dec 17 16:59:28 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EDE21ADF77 for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 16:59:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.739
X-Spam-Level: 
X-Spam-Status: No, score=-4.739 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K72N3zzydrZL for <ace@ietfa.amsl.com>; Tue, 17 Dec 2013 16:59:27 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id C36871ADE8B for <ace@ietf.org>; Tue, 17 Dec 2013 16:59:26 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBN68960; Wed, 18 Dec 2013 00:59:24 +0000 (GMT)
Received: from LHREML404-HUB.china.huawei.com (10.201.5.218) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 18 Dec 2013 00:58:56 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 18 Dec 2013 00:59:23 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Wed, 18 Dec 2013 08:59:16 +0800
From: Likepeng <likepeng@huawei.com>
To: Carsten Bormann <cabo@tzi.org>
Thread-Topic: [Ace] Terms to avoid
Thread-Index: AQHO92swut0VGmvey0qAQQLzZcFNrJpQmvCAgADi4iD///tSAIAEq9rg///h+4CAAAOCAIABjGOggAAUkwCAAXxxAA==
Date: Wed, 18 Dec 2013 00:59:16 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD5534@SZXEMA501-MBS.china.huawei.com>
References: <trinity-8553dce2-e064-4ed4-8774-fe3a04fc2bb7-1386874286879@3capp-gmx-bs21> <B9A7B5DA-ED8E-4507-8424-FC093C029D19@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD3EA2@SZXEMA501-MBS.china.huawei.com> <52AAF05E.2050305@sics.se> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD46D0@SZXEMA501-MBS.china.huawei.com> <52AEC257.4060503@sics.se> <BD021B0A-DE1C-4C9F-BCC6-376F9ECC305E@tzi.org> <34966E97BE8AD64EAE9D3D6E4DEE36F252AD4CFE@SZXEMA501-MBS.china.huawei.com> <F4257D7D-8B1F-4D90-B258-9BD155E72F6C@tzi.org>
In-Reply-To: <F4257D7D-8B1F-4D90-B258-9BD155E72F6C@tzi.org>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Cc: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Terms to avoid
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Dec 2013 00:59:28 -0000

RnJvbSBDYXJzdGVuOg0KPkZvciB0aGF0IGRpc2N1c3Npb24sIGJvdGgg4oCcdG9rZW7igJ0gYW5k
IOKAnHRpY2tldOKAnSBhcmUgZmluZS4NCg0KRnJvbSBMdWR3aWc6DQo+U3RlZmZhbmllIEdlcmRl
cywgT2xhZiBCZXJnbWFubiwgR8O2cmFuIFNlbGFuZGVyIGFuZCBJIGhhZCBhZ3JlZWQgdG8gY2Fs
bCB0aG9zZSB0aGluZ3MgJ3Rva2Vucycgb3IgJ2F1dGhvcml6YXRpb24gdG9rZW5zJy4gV291bGQg
dGhhdCBiZSAiY29uc2Vuc3VzYWJsZSI/DQoNClRvIG1ha2UgYSBzdW1tYXJ5IG9mIHRoZSBkaXNj
dXNzaW9uLCBsZXQncyBrZWVwICJ0b2tlbiIgZm9yIG5vdyBpbiB0aGUgY2hhcnRlci4gDQoNCldl
IGNhbiBjaGFuZ2UgbGF0ZXIgaWYgd2UgaGF2ZSBiZXR0ZXIgcHJvcG9zYWxzLg0KDQpUaGFua3Ms
DQoNCktpbmQgUmVnYXJkcw0KS2VwZW5nDQoNCi0tLS0t6YKu5Lu25Y6f5Lu2LS0tLS0NCuWPkeS7
tuS6ujogQ2Fyc3RlbiBCb3JtYW5uIFttYWlsdG86Y2Fib0B0emkub3JnXSANCuWPkemAgeaXtumX
tDogMjAxM+W5tDEy5pyIMTfml6UgMTg6MTANCuaUtuS7tuS6ujogTGlrZXBlbmcNCuaKhOmAgTog
THVkd2lnIFNlaXR6OyBhY2VAaWV0Zi5vcmcNCuS4u+mimDogUmU6IFtBY2VdIFRlcm1zIHRvIGF2
b2lkDQoNCk9uIDE3IERlYyAyMDEzLCBhdCAwMjowMywgTGlrZXBlbmcgPGxpa2VwZW5nQGh1YXdl
aS5jb20+IHdyb3RlOg0KDQo+PiBEbyB3ZSBrbm93IHdoYXQgaXQgaXMgdGhlIG5hbWUgb2Ygd2hp
Y2ggd2UgYXJlIGRlY2lkaW5nPw0KPiANCj4gSXQgaXMgYWJvdXQgdGhlICJhY2Nlc3MgdG9rZW4i
IGluIHRoZSBjaGFydGVyLg0KPiAtIERlZmluZSBhbiBhY2Nlc3MgdG9rZW4gYW5kIGF1dGhvcml6
YXRpb24gaW5mb3JtYXRpb24gZm9ybWF0IHN1aXRhYmxlIGZvciBjb25zdHJhaW5lZCBkZXZpY2Vz
Lg0KDQpZZXMuICBXaGF0IEkgd2FzICh0ZXJzZWx5KSB0cnlpbmcgdG8gc2F5IHdhcyB0aGF0IHdl
IHNob3VsZCBkZWZpbmUgd2hhdCB0aGF0IGlzIGJlZm9yZSB3ZSBkZWNpZGUgb24gYSBuYW1lIGZv
ciBpdC4NCkZvciB0aGF0IGRpc2N1c3Npb24sIGJvdGgg4oCcdG9rZW7igJ0gYW5kIOKAnHRpY2tl
dOKAnSBhcmUgZmluZS4NCihJ4oCZbSBub3QgYSBiaWcgZmFuIG9mIOKAnGNyZWRlbnRpYWzigJ0s
IGJ1dCB0aGF0IGlzIGJlY2F1c2UgSSBoYXZlIGEgbWVudGFsIGltYWdlIG9mIHdoYXQgdGhhdCB0
aGluZyBzaG91bGQgYmUuKQ0KDQpHcsO8w59lLCBDYXJzdGVuDQoNCg==

From likepeng@huawei.com  Tue Dec 24 22:18:58 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 801561AE21A for <ace@ietfa.amsl.com>; Tue, 24 Dec 2013 22:18:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.738
X-Spam-Level: 
X-Spam-Status: No, score=-4.738 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5aQx-kQVnQ14 for <ace@ietfa.amsl.com>; Tue, 24 Dec 2013 22:18:56 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 3BF0E1AE232 for <ace@ietf.org>; Tue, 24 Dec 2013 22:18:56 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBV48753; Wed, 25 Dec 2013 06:18:51 +0000 (GMT)
Received: from LHREML405-HUB.china.huawei.com (10.201.5.242) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 25 Dec 2013 06:18:03 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 25 Dec 2013 06:18:49 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Wed, 25 Dec 2013 14:18:45 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: BoF in London 
Thread-Index: Ac8BOSnwwd7J1lE5QYiWqWURGkJePg==
Date: Wed, 25 Dec 2013 06:18:43 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8SZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: [Ace] BoF in London
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Dec 2013 06:18:58 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8SZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello all,

Just FYI that Stefanie and I submitted a BoF request for London F2F meeting=
.

The request can be found at:
http://trac.tools.ietf.org/bof/trac/wiki#

It is pending for approval by IESG and IAB joint meeting in January, 2014.

Merry Christmas! :)

Thanks,
Kind Regards
Kepeng

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8SZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello all,<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Just FYI that Stefanie and I su=
bmitted a BoF request for London F2F meeting.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">The request can be found at:<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><a href=3D"http://trac.tools.ie=
tf.org/bof/trac/wiki#">http://trac.tools.ietf.org/bof/trac/wiki#</a><o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">It is pending for approval by I=
ESG and IAB joint meeting in January, 2014.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Merry Christmas! </span><span l=
ang=3D"EN-US" style=3D"font-family:Wingdings">J</span><span lang=3D"EN-US">=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thanks,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng<o:p></o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8SZXEMA501MBSchi_--

From likepeng@huawei.com  Tue Dec 24 22:53:38 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 968A01AE255 for <ace@ietfa.amsl.com>; Tue, 24 Dec 2013 22:53:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.738
X-Spam-Level: 
X-Spam-Status: No, score=-4.738 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tAQhH6qZU1ja for <ace@ietfa.amsl.com>; Tue, 24 Dec 2013 22:53:37 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id 097881A1F19 for <ace@ietf.org>; Tue, 24 Dec 2013 22:53:36 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml203-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBV50813; Wed, 25 Dec 2013 06:53:31 +0000 (GMT)
Received: from LHREML405-HUB.china.huawei.com (10.201.5.242) by lhreml203-edg.huawei.com (172.18.7.221) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 25 Dec 2013 06:52:39 +0000
Received: from SZXEMA404-HUB.china.huawei.com (10.82.72.36) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 25 Dec 2013 06:53:29 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA404-HUB.china.huawei.com ([10.82.72.36]) with mapi id 14.03.0158.001; Wed, 25 Dec 2013 14:53:25 +0800
From: Likepeng <likepeng@huawei.com>
To: "ace@ietf.org" <ace@ietf.org>
Thread-Topic: Relationship and difference with DICE
Thread-Index: Ac8BPgK3+lKjWCqZQJiuZKIBQ1XXGQ==
Date: Wed, 25 Dec 2013 06:53:25 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD792B@SZXEMA501-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/alternative; boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD792BSZXEMA501MBSchi_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: [Ace] Relationship and difference with DICE
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Dec 2013 06:53:38 -0000

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD792BSZXEMA501MBSchi_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello all,

I received offline question about how this work (ACE) relates to DICE, and =
how it's different.

My answer is the following:

DICE (DTLS In Constrained Environments) WG aims to define a DTLS profile th=
at is suitable for constrained environment, and define how DTLS record laye=
r can be used to transmit multicast messages securely. The objective is to =
secure message exchanges at the transport layer, and it does not address th=
e authenticated authorization issue. ACE aims to enable authenticated commu=
nication between constrained devices, and enable authorization verification=
 to access specific resources. ACE will employ security properties of DTLS =
whenever possible.

Does this address the question?

Kind Regards
Kepeng

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD792BSZXEMA501MBSchi_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"\7EAF\6587\672C Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
span.Char
	{mso-style-name:"\7EAF\6587\672C Char";
	mso-style-priority:99;
	mso-style-link:\7EAF\6587\672C;
	font-family:"Calibri","sans-serif";}
span.EmailStyle19
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple" style=3D"text-justify-t=
rim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello all,<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I received offline question abo=
ut how this work (ACE) relates to DICE, and how it's different.<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">My answer is the following:<o:p=
></o:p></span></p>
<p class=3D"MsoPlainText"><span lang=3D"EN-US">DICE (DTLS In Constrained En=
vironments) WG aims to define a DTLS profile that is suitable for constrain=
ed environment, and define how DTLS record layer can be used to transmit mu=
lticast messages securely. The objective
 is to secure message exchanges at the transport layer, and it does not add=
ress the authenticated authorization issue. ACE aims to enable authenticate=
d communication between constrained devices, and enable authorization verif=
ication to access specific resources.
 ACE will employ security properties of DTLS whenever possible.<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Does this address the question?=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng<o:p></o:p></span></p>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD792BSZXEMA501MBSchi_--

From schmitt@ifi.uzh.ch  Wed Dec 25 00:20:11 2013
Return-Path: <schmitt@ifi.uzh.ch>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 26EEE1AE203 for <ace@ietfa.amsl.com>; Wed, 25 Dec 2013 00:20:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.426
X-Spam-Level: 
X-Spam-Status: No, score=-2.426 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.538, T_HK_NAME_DR=0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KHZyiUGkhKR2 for <ace@ietfa.amsl.com>; Wed, 25 Dec 2013 00:20:08 -0800 (PST)
Received: from bohuslav.ifi.uzh.ch (bohuslav.ifi.uzh.ch [130.60.155.10]) by ietfa.amsl.com (Postfix) with ESMTP id A7D1C1AD73E for <ace@ietf.org>; Wed, 25 Dec 2013 00:20:07 -0800 (PST)
Received: from authenticated sender schmitt by bohuslav.ifi.uzh.ch (postfix) with ESMTPSA id SA for <01ACF7FC76>; ace@ietf.org
Message-ID: <52BA9531.9090803@ifi.uzh.ch>
Date: Wed, 25 Dec 2013 09:20:01 +0100
From: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------090800060801090301070100"
X-Virus-Scanned: clamav-milter 0.97.8 at bohuslav
X-Virus-Status: Clean
Subject: Re: [Ace] BoF in London
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Dec 2013 08:20:11 -0000

This is a multi-part message in MIME format.
--------------090800060801090301070100
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear Kepeng and Stefanie,

thanks for the information. Let`s have fingers crossed.

Happy holidays,
Corinna

Am 25.12.13 07:18, schrieb Likepeng:
>
> Hello all,
>
> Just FYI that Stefanie and I submitted a BoF request for London F2F 
> meeting.
>
> The request can be found at:
>
> http://trac.tools.ietf.org/bof/trac/wiki#
>
> It is pending for approval by IESG and IAB joint meeting in January, 2014.
>
> Merry Christmas! J
>
> Thanks,
>
> Kind Regards
>
> Kepeng
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


-- 

--------------090800060801090301070100
Content-Type: multipart/related;
 boundary="------------020202040503060802010301"


--------------020202040503060802010301
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear Kepeng and Stefanie,<br>
      <br>
      thanks for the information. Let`s have fingers crossed.<br>
      <br>
      Happy holidays,<br>
      Corinna<br>
      <br>
      Am 25.12.13 07:18, schrieb Likepeng:<br>
    </div>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 12 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span lang="EN-US">Hello all,<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Just FYI that Stefanie
            and I submitted a BoF request for London F2F meeting.<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">The request can be found
            at:<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><a
              moz-do-not-send="true"
              href="http://trac.tools.ietf.org/bof/trac/wiki#">http://trac.tools.ietf.org/bof/trac/wiki#</a><o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">It is pending for
            approval by IESG and IAB joint meeting in January, 2014.<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Merry Christmas! </span><span
            style="font-family:Wingdings" lang="EN-US">J</span><span
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Thanks,<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Kind Regards<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Kepeng<o:p></o:p></span></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
    <br>
    <div class="moz-signature">-- <br>
      <img src="cid:part2.07030502.00000104@ifi.uzh.ch" border="0"></div>
  </body>
</html>

--------------020202040503060802010301
Content-Type: image/png; x-mac-type="0"; x-mac-creator="0";
 name="visitenkarte.png"
Content-Transfer-Encoding: base64
Content-ID: <part2.07030502.00000104@ifi.uzh.ch>
Content-Disposition: inline;
 filename="visitenkarte.png"

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------020202040503060802010301--

--------------090800060801090301070100--


From schmitt@ifi.uzh.ch  Sun Dec 29 02:18:29 2013
Return-Path: <schmitt@ifi.uzh.ch>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1256F1ADF60 for <ace@ietfa.amsl.com>; Sun, 29 Dec 2013 02:18:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.827
X-Spam-Level: 
X-Spam-Status: No, score=-2.827 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, T_HK_NAME_DR=0.01, UNPARSEABLE_RELAY=0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p1rCi1RYvtii for <ace@ietfa.amsl.com>; Sun, 29 Dec 2013 02:18:26 -0800 (PST)
Received: from ladislav.ifi.uzh.ch (ladislav.ifi.uzh.ch [130.60.156.19]) by ietfa.amsl.com (Postfix) with ESMTP id 0ED761ADF5B for <ace@ietf.org>; Sun, 29 Dec 2013 02:18:25 -0800 (PST)
Received: from authenticated sender schmitt by ladislav.ifi.uzh.ch (postfix) with ESMTPSA id SA for <28A5276057>; ace@ietf.org
Message-ID: <52BFF6E7.4040904@ifi.uzh.ch>
Date: Sun, 29 Dec 2013 11:18:15 +0100
From: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: ace@ietf.org
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com>
In-Reply-To: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------020404010103070407010707"
X-Virus-Scanned: clamav-milter 0.97.8 at ladislav
X-Virus-Status: Clean
Subject: Re: [Ace] BoF in London
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Dec 2013 10:18:29 -0000

This is a multi-part message in MIME format.
--------------020404010103070407010707
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

Dear Kepeng,

I just browsed your mentioned link.
Perhaps it might be useful to avoid a parallel schedule with 6tisch as well.

Regards,
Corinna

Am 25.12.13 07:18, schrieb Likepeng:
>
> Hello all,
>
> Just FYI that Stefanie and I submitted a BoF request for London F2F 
> meeting.
>
> The request can be found at:
>
> http://trac.tools.ietf.org/bof/trac/wiki#
>
> It is pending for approval by IESG and IAB joint meeting in January, 2014.
>
> Merry Christmas! J
>
> Thanks,
>
> Kind Regards
>
> Kepeng
>
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace


-- 

--------------020404010103070407010707
Content-Type: multipart/related;
 boundary="------------050502000909080207010602"


--------------050502000909080207010602
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Dear Kepeng,<br>
      <br>
      I just browsed your mentioned link.<br>
      Perhaps it might be useful to avoid a parallel schedule with
      6tisch as well.<br>
      <br>
      Regards,<br>
      Corinna<br>
      <br>
      Am 25.12.13 07:18, schrieb Likepeng:<br>
    </div>
    <blockquote
cite="mid:34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 12 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
/* Page Definitions */
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span lang="EN-US">Hello all,<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Just FYI that Stefanie
            and I submitted a BoF request for London F2F meeting.<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">The request can be found
            at:<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><a
              moz-do-not-send="true"
              href="http://trac.tools.ietf.org/bof/trac/wiki#">http://trac.tools.ietf.org/bof/trac/wiki#</a><o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">It is pending for
            approval by IESG and IAB joint meeting in January, 2014.<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Merry Christmas! </span><span
            style="font-family:Wingdings" lang="EN-US">J</span><span
            lang="EN-US"><o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Thanks,<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Kind Regards<o:p></o:p></span></p>
        <p class="MsoNormal"><span lang="EN-US">Kepeng<o:p></o:p></span></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Ace mailing list
<a class="moz-txt-link-abbreviated" href="mailto:Ace@ietf.org">Ace@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/ace">https://www.ietf.org/mailman/listinfo/ace</a>
</pre>
    </blockquote>
    <br>
    <br>
    <div class="moz-signature">-- <br>
      <img src="cid:part2.02050108.00050302@ifi.uzh.ch" border="0"></div>
  </body>
</html>

--------------050502000909080207010602
Content-Type: image/png; x-mac-type="0"; x-mac-creator="0";
 name="visitenkarte.png"
Content-Transfer-Encoding: base64
Content-ID: <part2.02050108.00050302@ifi.uzh.ch>
Content-Disposition: inline;
 filename="visitenkarte.png"

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1B
AACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAA
buNJREFUeF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9I
R0CahSqCgtJBQKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm
5cqVWq1atWr//v3v1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSR
q666Skd14s/o0aOdTH/SM5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9
+/ad4/r0T+kZSM9A9hnAdTjopptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMze
MivjVa1alax866233rXTdIP0DKRn4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNP
nz40z1QuPc14NEx86bc0412KCU/3kZ6BaAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhU
M5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxx
xx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp02JAh/jmYOmUyifrGG28kzU6eyBmzlh5l
egYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZNatyoYY1q1apXq1anVq0G9eo1rFu3
ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/DGRhvJdffpnQixiP4INNSbV1
no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsyeNXvO7NnTp00bNnRoj27d
WjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsWLboiMWa+J4kXGGb0
qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW2dKl+/fre/jw
YY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf74Xnn8c8
zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgxrXam
SfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi
5enSKclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57
du/R47/vvPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69
e7do1qxYkaKB984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZ
aV/QjdIXva8zkJ3xgn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK
5cunTJ78VMGCRQsXLl60qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8
/kbMe81Lliix5eWXw9Yxu63l2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZN
m+Z54vF169ZdQjrW1fLlyx95ODeJ/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//c
nDlz0ur3+8of/7WbXSzjRULm5Ek806RxEzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q
379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWrVX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs
3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8
LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhnmjZpqtsfXn/9gQMHjr711r3/vucr
X/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0bLoyHQ1cXdu1/jfbesePsmsI7
jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1q1a3atmyc8eOc2bNInwi
Ujt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJN97ApdOnTp01c2bb
1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH58NJLEeNl/3jg
48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/97OZYYqcS
U1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXagyH37
9x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL
3H7bbfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdk
ed/uTnH91S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379
XMU52aN791q1a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1W
tOjAAf1LlSzlV2cGDhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGF
Cxfu0rmLnr2fiRMnPvXUU8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+
8H+PPfaYTa+Rv1e20X79uvXlypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxx
Ea/Sr3716+B/Mn6zWqVKlddefTXLuvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLE
HSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZJ+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kT
Jgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N
2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH/V/60hc/9alPfe5zn/vaV79KYSMJly5Z
ao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQb50nTn/60586sINFA40bN3aMl/wl
5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf/cxn3Vr7W//ylzGjR/vp61//
OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+S2aSeKT67f/4x6HDkVHq
PVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6WT/n1hpcsn79+rxP
PHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxEbzdeIF++l154
ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWVXTjjedp9
e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zUskWL
B+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx
9bGPfezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmz
iHliNZXW/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN
/PTYo4/ywcycMfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2
baR0o0aNyA2moA4dOljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611On
Th0zekzXLl3r16/ft29feweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPl
ypazGw+i4PChw927dStXrvzokSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrX
qt2nV6+XN7/M4/W1r32NimFuF8xfULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165d
u3//fnQMQrJevegBJ0+afOjNQ7ZCn/70p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJy
NlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kzvvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9v
Xs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWeeOzxhfPnFy1cqFTxElTNxx99ZN68eanj
8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6QZiIAwcO/uynP2Nc2bRxE7fEtddc
861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499/OMfR08jRowgJ6+++ms/+P73
se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt2L/+1a8w3sYYCeDTqVMn
7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZWorO+v3eVfq7CeD/+
0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpmMKtUsSLSIf//
9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/9pjO/3n7
7XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7f778
mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy
5cv36dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+
1IxnUlq2bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6c
udAtlhOYsjq1a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rv
mcRXXtmC8a757ncxD1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tF
vXevXkOGDLEussdoSVC4yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/
S9H9zGc+E7TrsOdElJ/8xCdmTJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/
+x3z1be+8Y3q1asRgN/51rc2rN/wk5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19
/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8
rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clPpkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0
+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRnty5db/7dzQ6KFStaqlQpBz/76U+s4wcP
HJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6mwLzhkd3rB9ddZ80KLOeVEQx5Hn+c
HiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXErZED+/c/cvjIGVvJmPEG9OvH
X3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK139m9pxXX3112bPP2gKx
x9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR37dplwKVLl4kYr3v3
LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgsDvCbd+a8NXLK
pMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr1syvfvWr
FNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS40FOF
xo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/t
mtUYj2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40
GF8xoowbN55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiP
Yd80/uJnP7eg6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKz
DbUXomHmfeLx+++55+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkP
VGtl/fGPf+yAAAxKmhWBpkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvO
aP/2zW9886+33oqSbM8MqWmTyLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/
cdttvtqxMI1SuV1Cif30p690I8SdPIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++q
ZcYNXEXaXPWF/6tRowat8qc/+TGf/ltHjtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvv
bdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8SmJw6P/zh9XCGzlAR1730Em7MlStXv379vYXF
ixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0OHnKevrLm36h/x98/3vDhgy1xuknvMEw
/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x8MMP79u3n6pJrLmWfmg5sI1kFi5e
vDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJokVI9Jvf+EaFCuXJTLLOpvHv
f/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6BxxS3ZAJh9Md7G9etNk72s
dTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjUpnNnIayYc9bPmTnr
1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1gJC3tCiypqJCk
kujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHSeRSQoAW1
RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu7dun
L/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcq
jb6Z3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT
4ydMwPyWLZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7Ky
YsWK7dq2a9q0mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh
2Jm4o5cvX4ZaQD4YKfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/u
S5csYSgfO2Yswg3nWVCQfhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXw
Nfzk48WEg6AuZsdYnnFh7BqJrzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aV
KBpqpgNdJ8k4Q4vw9UK57mTq06VOTnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQ
aXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jq
e2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryh
Q4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtxgnmDJ501zBJr09+hfcSrZ9wiepWR3yKF
QDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946/JTKAKk3DbfMaKCnTIdK8s7sdkDG
f/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QGP33ezpxxclkmHj1pk9F7ZsvM
Z8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiEjDd4+sKMyYxXtvCM8WsO
RynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbuQ1PasX171oX51Enb
6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT165ebXfets3Z
GO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+zcDFMN4o
sqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zNsseL
hJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTv
qZ2vvzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smep
alUqVZaeLGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8Z
N7UTO3Vq5vTpDRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdf
tGGjZLKckntVK1WGLcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyq
Jqai+SyYP09L1iHBdazD3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoD
z816TgPs0L79GZfEu8ED+w/w7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2r
Vjf/9ndQS4zXwXvx4aab9NNd5AxcIOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQ
wVatXp3anTq0nzVj+qwZM8SniwmaOmnStMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4
W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPUp3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SR
nRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKN
Mkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/CxYEOtG/Tlpth3JgxrNhdO3cJ+Npk
rh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQcAyUjDMN1/3zn/90hhWUX5GM
1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHeeXxV4JUBPOHO576iRTViA
ZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10FzwDF8V406dOg9Vi
q+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fvXszTulVLTmeQ
P7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38ZWpIL+9NX
fgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo92l/u
3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lH
OGDAAF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga
61zyeVApfYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/a
AUbyH1SqUKFzhw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo
115wQ3auCxIPCAhL/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILH
AtzUJaVKlEwYiWYKF0sGBldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZ
alStWrJYcdgUdsiSJYqTV+wiUoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJap
fNmyMtuKCxbhDvgXAo5SZy+IRKBHGHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYV
ivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIGHirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpN
zPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJNxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYS
zFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3YyW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx
/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6Yhkv5r1TjRs1Jgrq1a3HrMevBRVF
HEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnEi+4HPoYnwcapdrff9neARior
BmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uog8DDbiTQTiiKZAc8H1/5
ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlRtqJX/Er8piXeZUzP
OWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W+MY3vl63Vi0h
RXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhrX/uquFtG
mqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmyRMk3
3zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9Nc
SQYvLdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAM
DCeBzjkJPCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQ
woKgBQLLsCBHC1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3Emb
yDNxZs3opJPgHkhtmbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqo
RpLniTyMnPIOLJgXGet95JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIH
DlNFBF4v6BNGS0Dn3Xv2+NuwXv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0D
l8cMXGLGS0DJ9k7SYJJd0kKxpjSoX89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YX
cmCmue7yII/0KP5bM3CJGc8wQxR9YB6aJy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIc
lwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTHSQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZb
XE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ01n68bLMwH+X8dLTnZ6B9AycdQbSjJcm
jPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+mZ/zmfX31PhdO0y9eXbkZzgTRWOk
ZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WXFqgZYOXJJwvvqScQygBHjBRV
s36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k95oJVgLR7tipk7ydIhIC
DPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jxElteeeW8bnfqpIrN
hvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZJXgcJEIgZIuQ
4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNOuntSR+WM
WhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvYLWGh
XqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy
87hFbbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMD
m7sEXtW/TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0a
XeoHRRQ6deoo64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZU
JlL6sxUrlovKFeCLGYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqD
Fi9WLMTmxlLq5JEjb/38pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYy
d5LkkkpJhJEvTx55QQUZlyhWTP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR
9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn
1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmiSPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197
zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCkaL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMr
HmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpKgla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5Jf
Bd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XGW7RoIaY+bXc5D454n5p8mBjvP2qs
KyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPProI6ovBKVOaW+UunHDevJHnukg
lDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK41VXXdWkcZQGNxJ48Rpw
7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHKEjnTrl27r3z5SwKv
rA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAWmlZ73gIvhYQg
9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZTuzyD8fr1
y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+++77
8he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y
5817w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZX
trwsXyCKPyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUk
QreyHhqMjEw1alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2
SWU8aRaxuiVAyy1btmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUq
aHn7ZNGcOmVqEDiB94TCf+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hU
gY89+kjgBNYUN1q0cFHY49kKOkmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1
a4YBUDTfOnpU1m2bwwceeMBmjFDl+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tb
IUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xdOnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnno
sqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJhoTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdk
yRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k1gMHDoom6NSpRYsWlStXzsZJ/s9y5crL
FoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbNmxmXHNgMnqHPsMezFRQK7KcCBQr2
6N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVlpqEvsr5UrVKN319hzWrVqqki
ZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAvvK+PnoMZLwvwKoim4DtP
jsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOTKWPOejK6XVzMPdtd
Mu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RUOPdVSedJJ6kd
huPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5ls49s7Ek
OXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lHFeT5
eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5
i5Ljv8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJ
QcI4M3bM2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZ
qWOnpNlZNcwst05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvp
nrgsWXhMZiR2I3lMzd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLy
qswT6HGb00tA/MoybhIdXerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdX
F8VPQeVKbcNEmdRIQQ4lixd/KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39W
m0pQa8MnlSKV5gRDcRICUywSg+2Lz78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLP
uXPnrl+/HtLgrFOUejI1BiI5HwaQxZATfuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccac
ZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoHEF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55
htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFBk5PFihThxHPVwAEDXeK+Rw4dIiGbNWuu
OBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0GWaLw2PbtO/r169+sWTM98+D79O7Z
S4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9VdDB7MTb0xGG6xF9DhilhzpZBy
XO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546dVrTpk1HjBjBf6j8k3ir
nj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevWrT2vmoRmHgZ9/Ljx
O19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2PdpCXipqP4y6CeH
M16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+cPiNQ4YRx
413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX26hR
o/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN
0UNI099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5ol
K8uDDzwAzlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocW
l7x58ryyZYvGvKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29Jrgf
RUsVG9W5laVooUKehVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9P
r17oA61079o1YTyiaVG8fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOe
dgv4LMoVE0uNaAe42r0wXpvWrYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+cc
VzJJjaTFixZFEql58xXLl6cwXjWi28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zg
wU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9
Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVpGuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTR
EsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+OnboGJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZ
HYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouKQI/kXUQoTYT8OOjTp09c46Hl889H
dTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsMxpscM17/ARaC5cuXr1m7lh2V
ukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5Yzp5VblSZbqfZPj169XT
Zt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP3LF9h4DwDh86ZFC8
RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24iq2rdMkStsTl
SpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ9rHxy/Jy
K5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeuLVu2
7IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgz
ADi7dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7b
t21H4tE2d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYl
ihWn1EGWkdgUh9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZw
wULMbxMrWMmiYAJ6dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8
Bw0Y4OmETRbMn4+4jhnvQ6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aN
FlBDY6RrhU0XKUT+MGYKnGOnmz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRI
wIrdunbDdSLfhPkISF+37qUgEl2Ojok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjg
IMF77CUqchqAreabhw5ZGt4+dgxSFFc7iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3
atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RGNW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8r
CFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm69ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0d
ynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9CUD7z2gVjLyCaca7NFruxfZyNhzj
acRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFyngZwRs0yP8mFp3vIhJVmsdpn
ONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6F7Iv52cdW+pkJpdk91KE
7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM/hKMMAMReib67Hxf
17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5nWc4cvhIAApe
SlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2Ans5ySUaw
VZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4CBWec
jMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F
7R6Njy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/Zs
tjKZS84EQJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSk
dp6p8sX6WCa78kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboO
xsUgmfJ2U0N44+CjTANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at
7psYjd+V+D7KDXIw43nfDOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3M
cICcXc2aN2fdrlql6jPPzMUwjPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+
JmEQfG4w+ERcseLF//WvO3E+vziQNN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZX
Ne+WA64tcrtJk6Zt2rR9Ye3zd999N+Al2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4
EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMs
YmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzw
rkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyTNZs/2n6Ok7pr5058g8CNWKhK5SpL
Fi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icHF6xww/r1YankJuKnKl2ylFCA
RMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5zmaQrV66M1qGN9UnMQoE8
PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe84YSYrE3AAIQYn57L
9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9T9L8cDfL2YyH
Vp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pgm+XLlFa9
AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQqTGpF
AMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLj
oG+fvqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa
4om6dumapFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW
/iRVYD6gojAevnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCP
gPwEkRgCE8qiiCKHPj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawB
OLNK5UrSh23dtk3RH1wEo+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPA
SAc0zxnTpoO/gNFE4M+KFa0drVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ
/Tlgr23zwMqTh71I6vwQX56DGc+6Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+e
zJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/Ony+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSp
UsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpyS4AskmrihImdOnTUj3BvgwkEjSswqruDO9tb
zpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73dncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5S
uPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ94dGo3/aQ1atWE0aQdBVYK5C+kZtq
wFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xImS8HM17AFqlZ1a9fX2YMUdi+
KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8+5nVq1d16NCBGAQRtPvC
J6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFKaiAsdeXKVZhEEKBq
dcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJeKf+RXB7cBuz
lSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PYrP8Vylc0
5kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFyMOMl
pJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtq
zLtNXefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo
9+8lpBnv/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/f
Mj0DacZL00B6Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABm
IM14H8Ckp2+ZnoEczHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSl
IVDg3J8kniCjcQhNCBkv40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1
eIfohIxHzoyWOOszhnGeT3xD8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+Lo
JIOQux9QWIidIL04LewJGUfE1L1T6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1Ip
QfomyQX90YnAQtmZMugvypwbLUzCC50PS5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7
jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rP
HDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2whzMeN6KkiCFCxcpX768mjvmRSEuQdln
ov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd2nVioZqZqTqOxQ5SMdBxdJz5axLz
FjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kdk35Sk0z6oxrVqklmMWTw4Pnz
5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T7LmvIoNKlyotq8XmzS+H
B1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2DqY2al1xMnhSM3adRY
foCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJy3jvyd39pNRu
wwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3zcS7naJmX
EkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0gvzqJ
evQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslI
SdNCD+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q1
53oIExjl84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsb
K9sIIJreAwf2hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY
1H0Ki1etVk3qFOWOK1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eq
z+lNTgdZfVSQrFatuvSYbVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3
vybZniRIJJWsE15/RGsxN0pRERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFS
TdbQ2EdmJDUDpSSUr0VWmKaNm4Q8ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1Yi
I6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzCh
rKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERi
JSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKeiqVSpcolixcx/SO59scR30dfnbIknKdgT
jz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseoTQlLqY1e3rzl3rvvlgTJu5w+daqc
JbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXgSbLIvkKbGtVrWEddSNkjHCSH
xhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mwafwouE6t2mR1tSqVSYNA
H74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlqJ0RqcMkSJf/fb35D
vURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAOqH/9+kVZKnCm
CntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/krd8uTBQvK
oSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+Kukb
SViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp5
40aqqWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbz
XraRyDOp6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWF
IFAMc0iF8hVcHudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvF
n4MUOnb8mOxpshjGtZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4k
ssuWKW3XJ0116HDNmjVkjgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJn
B/bvp8w19Vj604h1T5zUZt2LL9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJep
h2VzkiLR17pxweeN6zeEEtNpxrtYxkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IAC
vKeqFSsxYsppOX7cWGqkjF00N/obxtOPVJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9
JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcXjG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um
7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XU
tdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3bu0+oEe9DZ+vff4CDMqVKrd+wgagk
1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PIVKZUaZk5ZWcsX6YsPqGTV65Y
ycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWlVLXAUV9NjvRNqtWSvQS4
bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOWQvj4Y4/LZCklprIK
FmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq3IMGIg70pLFc
sfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6Gh4gxZsyU
4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsULqLW
NLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQex
ajxZoGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjx
mq5eufLAwQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3
hg8fMXnylI0bqX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ER
Ak25Dx2+eehNQ6d5yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wl
EmwmcxHl+Vy1yvbpbPQRmf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTI
kbt2RuXEJH72UDNnzjIhhBLzCTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+
bsUK+gLiHjt2rLoRJs2qpzG3xGvbtgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfi
xEkyoCqDYdiS1StJz/eowAMlxcbPezRLVlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdI
nblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5Krj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7R
PsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHtU0abJQ3m6WycyeVZKIOim/I4mbXHYqUx
Ow0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4uEeNcbDc5m/Eu9unT16dn4AOagRzM
eBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Esrk0VO6niNFEss8jYLG0iQGnS
W1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PIQKWeqUecgYzNuCS+PExd
xtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0HDhxUEOHSTrqXGpAT
sQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7avuhyMGGjRtY
U5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzne1SyyxgS
pMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudftM5l4
wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5
tOGLZ0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQR
r06dOmXKlKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUs
QXaAeEKxsWha4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061
BMMtNN7+2nYGZC+rR7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZ
dIlnZyKGEIAo0nLRosWKGbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB
+EFEYmo+xueDaKK3EpePVXkHXDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcb
tB1m6wL58sVglIhW+KYfffhhjuCEppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4X
Ip+BS/Ati2tykjfZsRKtHhlqhA09/HRW8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOT
oSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifzAOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEd
J5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgfaXTy2DFOF04Lx1FVtvETeGUxeVRbs0oV
r4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16DLbtA/ny1atYCwmShZmeP5EyFCtxK
bx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOetaLxicivvBSbKOeAp8kvAqMATg
RQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r370qVLUjknNIM+4zcH91WC
jz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdAFsLKs4tRgLHi4Nqz
ew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ3Bgtm7ckIWdn
egWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM4OLHaSbc
JDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLeapAO
OgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrder
oIGBAweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hx
RERQIHm0Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw
/jF4zgQXpta5KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB
4/bt248DKedQRDz+bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICO
Pv9w880BqHR58lsyqhzPeDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GL
FlMnTwKVUBQOzYnKCeQO0QurlS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMX
TkW19IIFCgBM5H7oIVqQJRk+m/pkli3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxA
DRU2HSQxaQplUi89jnEK/rXkI7hAo6HzZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/x
Pnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCfbtvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly
5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07aMfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qM
Dx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfPE8xI4cEv50/OZjwY6UBePiB5ETWw
uAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnhLQirunXrQUELlmFJGzNmTFQV
uUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59ehcrVgzFJOEFkPIQzy5n
PEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQbx40dg3UTksXqNjm+
Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWLl6BtstzQZgd4
qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blkyZK0DA9I
/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApqHtwr
dcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnR
O3ToWKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2B
diSAzuG5Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO
0f7NBzbVGpekWkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAw
W3GaNW4irI51F9SOUs1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzM
eKj21ddeQ0+BYmDWoxQpJ07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqC
LXPH9h0Qj8G6Gc6Tb9Sz8NUL1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQS
ZpWvhpdCLicobzwHBuVyEQDMKoLiUGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4k
m8gJC5PIJmZAV3GgGXMiJTws76idYWJn9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAh
vYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXowBpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r1
68yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwxWX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZG
kvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3BmsxYlgFn0daS6T091TGiIPtjvtM8
pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRnIEe7E876+s4qtc4io86mkATn
+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/zmHXOvrWW7bmGcn54n18
0FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLbmJofNhmwQdrC2WVd
/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Qnj2aoa9xo4YM
bsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj0OkGHywV
pO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17MN1e
TgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLl
ypWHHfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1
bNni9zf/XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuT
GdYRcJkERDxyNWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyY
UxnPuNHrUwUKBlAIoAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3
ChIpb7E2OpHoVnJleaxs88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8
Y9p0OZdopFHeruPHuKrlUwqN9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJ
FNHgVLBUgb4BxKLceBE8ql4E4GzcGD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9Pk
gcM2sqqCwsAHSwoowSOAYuu4BwBrGXXCvcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthp
U6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYLT5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWM
B7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5RQbUXgikAh2pKTI0fO44SmPeJJwCa2rRt
K/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91XIRAHjuBambZjhRqXjhpcN9rKSWZ
A7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWVLBkKmdTq2LEjbbN71279+/WX
MNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX4C6cIMEjeKRiA5C44FGY
Z+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZOnRKCaOSulKFdRoOn
nx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslTjPhEDd8A6HME
vNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql9ObYLAKI
viqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu377D
lvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KY
voZ3ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQW
GGoPFkfuvR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWX
N6uywJcYb1Zfj/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JU
IcW/g7h2+elPwJSFp4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2
mUnLhEwDh5y5zTu9I+W3UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv
3r0HV6dEZkp/GKp8M+r1hV8Dj4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR
52zGU3VNcishycePvQ2DIv+U5Hxy4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCAB
GQKKQJfHjqmJB4epJDrz4yG5igUl7NoVYTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5D
o0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovp
VoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJKVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ
1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q1KM3hm+w1aefHhzVOr8Myhp/cOxz
4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj/MT1uRMgUVCpnLZ8dzhBklaV
2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9CjqNHjxoSZ/gy8T169ChX
tpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7fpGkT2VflIDEGGACZ
nsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/ECQ5fhBZQh10e
Md6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1Vq1YpQKmu
rdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYutyk2
NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMp
m4r96GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxg
n+avx1RqPGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+R
h6TLBw7sl2aTDJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54
NKCbbrrpiqpVqwL+XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPi
qIING9SXT5LWhIvgXYQSYUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIk
DnJ56Pm1ba/Cdnbu2Im0UcnZmTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3o
DbmHxKwYT0QFvVcaNfEWBq9SsfNMMmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOna
k2x8/ThfAV05wmTgVrs43ItOThrj/HnPPEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k
/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUvc8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgc
ATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLFi8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORT
UgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrEK1tabfG3jTBUAnCJVJz6sUwApilR
4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZkNrw2m668efJs2fKyXK6ygHk0
WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcrl9mZPWumNcjKMmTQYJEZ
AjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3mjCcv+nPLlrEcEHFY
TpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqVq7ZqFSGbyTGp
pnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fErOqJlyhW
nJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7ZgXB
xpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i
5bYBuXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1
dkchpSSDJFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYi
PfLWGzsjNKb5YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSL
IKbHjslFaYemE4MJedfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/y
q0+cJ+aE/wkLJMPDa2Ud4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6
YbpLFsbzpq666ip/I8aTzJxp7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3
S9pkX7pwvs1bq1atK1aoGDaZqb2lKhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLl
eVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/Hj
FHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEixvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa
+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxLNkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p
9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8lin1PnaYbp2cgPQPnmAGyDlvhvdQ2
pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2GmyrqsqmbqDYDI2Dldk2a/i5n39LUf5RmA
Z7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A7FuabadGZ7zyyiuFH2RR
L8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9BckHFTJneYAAAAASUVO
RK5CYII=
--------------050502000909080207010602--

--------------020404010103070407010707--


From likepeng@huawei.com  Sun Dec 29 16:09:10 2013
Return-Path: <likepeng@huawei.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C4E7C1AE33A for <ace@ietfa.amsl.com>; Sun, 29 Dec 2013 16:09:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.288
X-Spam-Level: 
X-Spam-Status: No, score=-2.288 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.538, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FnSPlzmw6LR8 for <ace@ietfa.amsl.com>; Sun, 29 Dec 2013 16:09:08 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) by ietfa.amsl.com (Postfix) with ESMTP id D572A1AE292 for <ace@ietf.org>; Sun, 29 Dec 2013 16:09:06 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml204-edg.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BBZ11744; Mon, 30 Dec 2013 00:09:00 +0000 (GMT)
Received: from LHREML406-HUB.china.huawei.com (10.201.5.243) by lhreml204-edg.china.huawei.com (172.18.7.223) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 30 Dec 2013 00:07:59 +0000
Received: from SZXEMA401-HUB.china.huawei.com (10.82.72.33) by lhreml406-hub.china.huawei.com (10.201.5.243) with Microsoft SMTP Server (TLS) id 14.3.158.1; Mon, 30 Dec 2013 00:08:57 +0000
Received: from SZXEMA501-MBS.china.huawei.com ([169.254.2.66]) by SZXEMA401-HUB.china.huawei.com ([10.82.72.33]) with mapi id 14.03.0158.001; Mon, 30 Dec 2013 08:08:54 +0800
From: Likepeng <likepeng@huawei.com>
To: "Dr. Corinna Schmitt" <schmitt@ifi.uzh.ch>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] BoF in London
Thread-Index: AQHPBH9TNfnVLvli20ux2n/ivDD6zZpr3QJA
Date: Mon, 30 Dec 2013 00:08:54 +0000
Message-ID: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD886F@SZXEMA501-MBS.china.huawei.com>
References: <34966E97BE8AD64EAE9D3D6E4DEE36F252AD78E8@SZXEMA501-MBS.china.huawei.com> <52BFF6E7.4040904@ifi.uzh.ch>
In-Reply-To: <52BFF6E7.4040904@ifi.uzh.ch>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
x-originating-ip: [10.66.167.122]
Content-Type: multipart/related; boundary="_004_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_"; type="multipart/alternative"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Subject: Re: [Ace] BoF in London
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Dec 2013 00:09:11 -0000

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_
Content-Type: multipart/alternative;
	boundary="_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_"

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: base64

PlBlcmhhcHMgaXQgbWlnaHQgYmUgdXNlZnVsIHRvIGF2b2lkIGEgcGFyYWxsZWwgc2NoZWR1bGUg
d2l0aCA2dGlzY2ggYXMgd2VsbC4NCg0KT0ssIEkgd2lsbCByZW1pbmQgb3VyIEFEIGFib3V0IHRo
aXMsIGlmIG91ciBCb0YgcmVxdWVzdCBpcyBhcHByb3ZlZC4NCg0KVGhhbmtzLA0KDQpLaW5kIFJl
Z2FyZHMNCktlcGVuZw0KDQq3orz+yMs6IEFjZSBbbWFpbHRvOmFjZS1ib3VuY2VzQGlldGYub3Jn
XSC0+rHtIERyLiBDb3Jpbm5hIFNjaG1pdHQNCreiy83KsbzkOiAyMDEzxOoxMtTCMjnI1SAxODox
OA0KytW8/sjLOiBhY2VAaWV0Zi5vcmcNCtb3zOI6IFJlOiBbQWNlXSBCb0YgaW4gTG9uZG9uDQoN
CkRlYXIgS2VwZW5nLA0KDQpJIGp1c3QgYnJvd3NlZCB5b3VyIG1lbnRpb25lZCBsaW5rLg0KUGVy
aGFwcyBpdCBtaWdodCBiZSB1c2VmdWwgdG8gYXZvaWQgYSBwYXJhbGxlbCBzY2hlZHVsZSB3aXRo
IDZ0aXNjaCBhcyB3ZWxsLg0KDQpSZWdhcmRzLA0KQ29yaW5uYQ0KDQpBbSAyNS4xMi4xMyAwNzox
OCwgc2NocmllYiBMaWtlcGVuZzoNCkhlbGxvIGFsbCwNCg0KSnVzdCBGWUkgdGhhdCBTdGVmYW5p
ZSBhbmQgSSBzdWJtaXR0ZWQgYSBCb0YgcmVxdWVzdCBmb3IgTG9uZG9uIEYyRiBtZWV0aW5nLg0K
DQpUaGUgcmVxdWVzdCBjYW4gYmUgZm91bmQgYXQ6DQpodHRwOi8vdHJhYy50b29scy5pZXRmLm9y
Zy9ib2YvdHJhYy93aWtpIzxodHRwOi8vdHJhYy50b29scy5pZXRmLm9yZy9ib2YvdHJhYy93aWtp
Pg0KDQpJdCBpcyBwZW5kaW5nIGZvciBhcHByb3ZhbCBieSBJRVNHIGFuZCBJQUIgam9pbnQgbWVl
dGluZyBpbiBKYW51YXJ5LCAyMDE0Lg0KDQpNZXJyeSBDaHJpc3RtYXMhIDopDQoNClRoYW5rcywN
CktpbmQgUmVnYXJkcw0KS2VwZW5nDQoNCg0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX18NCg0KQWNlIG1haWxpbmcgbGlzdA0KDQpBY2VAaWV0Zi5vcmc8bWFp
bHRvOkFjZUBpZXRmLm9yZz4NCg0KaHR0cHM6Ly93d3cuaWV0Zi5vcmcvbWFpbG1hbi9saXN0aW5m
by9hY2UNCg0KLS0NCltjaWQ6aW1hZ2UwMDEucG5nQDAxQ0YwNTM2LjYxOEQ4MDcwXQ0K

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_
Content-Type: text/html; charset="gb2312"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dgb2312">
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:SimSun;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	text-align:justify;
	text-justify:inter-ideograph;
	font-size:10.5pt;
	font-family:"Calibri","sans-serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML \9884\8BBE\683C\5F0F Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";
	color:black;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.HTMLChar
	{mso-style-name:"HTML \9884\8BBE\683C\5F0F Char";
	mso-style-priority:99;
	mso-style-link:"HTML \9884\8BBE\683C\5F0F";
	font-family:"Courier New";
	color:black;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=3D"white" lang=3D"ZH-CN" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">&gt;</span><span lang=3D"EN-US"=
>Perhaps it might be useful to avoid a parallel schedule with 6tisch as wel=
l.</span><span lang=3D"EN-US" style=3D"color:#1F497D"><o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D"><o:p>&n=
bsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D">OK, I w=
ill remind our AD about this, if our BoF request is approved.<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D"><o:p>&n=
bsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D">Thanks,=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D"><o:p>&n=
bsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D">Kind Re=
gards<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D">Kepeng<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"color:#1F497D"><o:p>&n=
bsp;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><b><span st=
yle=3D"font-size:10.0pt;font-family:SimSun;color:windowtext">=B7=A2=BC=FE=
=C8=CB<span lang=3D"EN-US">:</span></span></b><span lang=3D"EN-US" style=3D=
"font-size:10.0pt;font-family:SimSun;color:windowtext"> Ace [mailto:ace-bou=
nces@ietf.org]
</span><b><span style=3D"font-size:10.0pt;font-family:SimSun;color:windowte=
xt">=B4=FA=B1=ED </span>
</b><span lang=3D"EN-US" style=3D"font-size:10.0pt;font-family:SimSun;color=
:windowtext">Dr. Corinna Schmitt<br>
</span><b><span style=3D"font-size:10.0pt;font-family:SimSun;color:windowte=
xt">=B7=A2=CB=CD=CA=B1=BC=E4<span lang=3D"EN-US">:</span></span></b><span l=
ang=3D"EN-US" style=3D"font-size:10.0pt;font-family:SimSun;color:windowtext=
"> 2013</span><span style=3D"font-size:10.0pt;font-family:SimSun;color:wind=
owtext">=C4=EA<span lang=3D"EN-US">12</span>=D4=C2<span lang=3D"EN-US">29</=
span>=C8=D5<span lang=3D"EN-US">
 18:18<br>
</span><b>=CA=D5=BC=FE=C8=CB<span lang=3D"EN-US">:</span></b><span lang=3D"=
EN-US"> ace@ietf.org<br>
</span><b>=D6=F7=CC=E2<span lang=3D"EN-US">:</span></b><span lang=3D"EN-US"=
> Re: [Ace] BoF in London<o:p></o:p></span></span></p>
</div>
</div>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<div>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Dear Kepeng,<br>
<br>
I just browsed your mentioned link.<br>
Perhaps it might be useful to avoid a parallel schedule with 6tisch as well=
.<br>
<br>
Regards,<br>
Corinna<br>
<br>
Am 25.12.13 07:18, schrieb Likepeng:<o:p></o:p></span></p>
</div>
<blockquote style=3D"margin-top:5.0pt;margin-bottom:5.0pt">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello all,<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Just FYI that Stefanie and I su=
bmitted a BoF request for London F2F meeting.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">The request can be found at:<o:=
p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><a href=3D"http://trac.tools.ie=
tf.org/bof/trac/wiki">http://trac.tools.ietf.org/bof/trac/wiki#</a><o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">It is pending for approval by I=
ESG and IAB joint meeting in January, 2014.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Merry Christmas! </span><span l=
ang=3D"EN-US" style=3D"font-family:Wingdings">J</span><span lang=3D"EN-US">=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Thanks,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kind Regards<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">Kepeng<o:p></o:p></span></p>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot=
;,&quot;serif&quot;"><o:p>&nbsp;</o:p></span></p>
<pre><span lang=3D"EN-US">_______________________________________________<o=
:p></o:p></span></pre>
<pre><span lang=3D"EN-US">Ace mailing list<o:p></o:p></span></pre>
<pre><span lang=3D"EN-US"><a href=3D"mailto:Ace@ietf.org">Ace@ietf.org</a><=
o:p></o:p></span></pre>
<pre><span lang=3D"EN-US"><a href=3D"https://www.ietf.org/mailman/listinfo/=
ace">https://www.ietf.org/mailman/listinfo/ace</a><o:p></o:p></span></pre>
</blockquote>
<p class=3D"MsoNormal" align=3D"left" style=3D"margin-bottom:12.0pt;text-al=
ign:left"><span lang=3D"EN-US" style=3D"font-size:12.0pt;font-family:&quot;=
Times New Roman&quot;,&quot;serif&quot;"><o:p>&nbsp;</o:p></span></p>
<div>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span lang=
=3D"EN-US" style=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot=
;,&quot;serif&quot;">--
<br>
<img border=3D"0" width=3D"296" height=3D"160" id=3D"_x0000_i1025" src=3D"c=
id:image001.png@01CF0536.618D8070"><o:p></o:p></span></p>
</div>
</div>
</body>
</html>

--_000_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_--

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_
Content-Type: image/png; name="image001.png"
Content-Description: image001.png
Content-Disposition: inline; filename="image001.png"; size=28517;
	creation-date="Mon, 30 Dec 2013 00:08:54 GMT";
	modification-date="Mon, 30 Dec 2013 00:08:54 GMT"
Content-ID: <image001.png@01CF0536.618D8070>
Content-Transfer-Encoding: base64

iVBORw0KGgoAAAANSUhEUgAAASgAAACgCAIAAAAw8WZPAAAAAXNSR0IArs4c6QAAAARnQU1BAACx
jwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAbuNJREFU
eF7t3Qe8FtXRP3CT901i2htTTVeTGE035Z+YZkxijFFjQcVKVXrvvffee6/Se+9IR0CahSqCgtJB
QKTl/9099y4P9yIiEOXq83zwus8+Z8+ePTtzZs7Mb2Y+9p///OeKd/uMGTNm5cqVWq1atWr//v3v
1jz9e3oGPnIzcOWVV/7ud7/z2DfeeON9993n67tMAcZ7p8/s2bMfeeSRq666Skd14s/o0aOdTH/S
M5CegSwzMHny5MAjWAbXYRnMcg7muuKsvz333HOuvPXWW59++ul9+/ad4/r0T+kZSM9A9hnAdTjo
pptuwp9nnZ+zMB5mu/nmm8/Nr+m5Ts9AegbedQYIMNKLGMzeMivjVa1alax866233rXTdIP0DKRn
4HxmIOifWXjqDMbDdRqdOnXqZPqTnoH0DFyKGcBNmLNPnz40z1QuPc14NEx86bc0412KCU/3kZ6B
aAYC4/k0adKEYEt4L4PxKKP2dUEaphkvTTLpGbhUM5AwHs4i2Ii3wHsZjJdq/bxgxsvk7XPovWkl
9lK90HQ/OWMGUhlvx44d1157bRBvEeNxQdxxxx0Ju7wnxjtx4sTJEyeSa/fs2b1mzZrp06YPHzp0
2JAh/jmYOmUyifrGG28kzU6eyBmzlh5legYucgZSGQ/9ly1btk2bNhmMh+vw3oUxXrhq586dkyZN
atyoYY1q1apXq1anVq0G9eo1rFu3ob/16tWrU6d61arVq1WvX6/+6FGjt219NVx1kY+Uvjw9A5f/
DGRhvJdffpnQixiP4INNSbV1no/EI+hsBl2/ffuOnj17li9XrmrlKhivaZMmXTt3fnrwoKlTpsye
NXvO7NnTp00bNnRoj27dWjRv3rhhw+pVq5cuWbpTx46bN28K7KerSGymP+kZ+DDOQBbGQ/CMKYsW
LboiMWa+J4kXGGb0qFHlypatVrVqy+YtunbpsnDBgtkzZo4bOzb7Jm/evGecX75sWa+ePTWuXatW
2dKl+/fre/jwYY2PH08z3oeR6NLPlGLVTJgiIMuuCP9LZZVzSzwsovGunTsbN2pUsUKF5k2bDujf
74Xnn8c8zg8cMLBCuXKv79hhzhM5dvTo2y2bN2/YoMHxY8e12bhhw/BhQ1s0bVa1cuWaNWps2rgx
rXamSfTDOgPZJV5Ak12RP39+3r3zZzwtX968mW5Zr27dNq3bLFiwYPOmTXv37Hb+hRdeaFCvfptW
rVu1aJnwkoO5s+c4o/3gQQN9XfbssmeXLiX9Onbo0KhRw9IlSzr+b8i9YPi55IbU49aY4yfi5enS
KclRT8czPD5pj86HiAuzMx49k7Z5RRbLCgY4h8Tz6ytbtpQpXTrs5ba8vMWZwQMHkn57du/R47/v
vPPfd92FLZ0/cuTI4UOHHIwaOfLef//7zjvuaNWyha99+vRt3qz59te2b33llT69e7do1qxYkaKB
984x4cnSENqkPs/5X3VJXijGyzKYLF8v6C6RvvD228defOGFtWvWHHrzzfPZaV/QjdIXva8zkJ3x
gn3lCiDOLADqs77y2JryH5EKNnXNmzXr3Knj/v37aJj169WbMX0GY+bK5cunTJ78VMGCRQsXLl60
qM3bcyuemzljhqt6dutWMH/+J/PntxvkynDJvr372rZp88zcuW+8/kbMe81Lliix5eWXw9Yxu63l
2LHjSxYvNs6DBw8ans+xt48tXrSI8ebNN98860Rqc/To0WZNm+Z54vF169ZdQjrW1fLlyx95ODeJ
/fbbb7u7UZHhe/fuveC7RPrC88/f8+9/f+H//u/zn//cnDlz0ur3+8of/7WbXSzjRULm5Ek806Rx
EzZJTNK5c+eXXnypdMlSFM6li5doMGHcuP59+w3q379mjeq7du3EVBs2rHfjwQMGdOvSuX/v3jWr
VX/z4MG9+/Y9u2RJm9athw8btmDe/Igze/Zs3bKVHeORw4dTN4cZwu3kyTffPPSrm276whe+sHbN
2iBe9u8/8LOf/vSLX/wipgpSOhB9+DU8LSfHN77+dfGIvXr0SG2TCMxwSTI1CdtEfcVdht6yCFhn
mjZpqtsfXn/9gQMHjr711r3/vucrX/7y2rXR2MJVZ3QV95X6ZrPcMQy+YIEC+rzt73+rVq3qhg0b
LoyHQ1cXdu1/jfbesePsmsI7jTx5rZdwkBc8S8mFyajO0VXyrpOHfW8Sz2Vjx4whslq3arV169Y1
q1a3atmyc8eOc2bNInwiUjt5EkNWrVK1ZvXq+fPmxZlUphnTp1PMGjdswOJSrXLlgvny7969J2KJ
N97ApdOnTp01c2bb1m22b9/eoV077r4e3bpHhH6md+HUyVOHDh36xc9//vnPfU6fmYy3/yc//jH5
8NJLEeNl/3jg48feHjt6NA5n7EkaBHF61kvCSfvC1F+1T7ZeCR/a5TZv3oKEj9ofP/HTn/7ks5/9
7OZYYqcSU1ATMroNojzlTJYx/PmPf/z85z+/efPm6PwF4dSzdHjBhBUT9wljiN7FRXzi53jHLXag
yH379x858lbGHTMfIPWeYcYgLvbu3Xfs2LGLGE7GpfFDnX6lnvQ99RnGGAZ//Ngxo0rOvJPmleW9
nC/jRZR36hQzZrkyZVq1aLFkyeIN69e3b9vu9dffGDVixBtv7Iyf5MT+ffuKFylSqkSJ8mXL3H7b
bfx4M6ZNw0779u3Ndd99LCj8B84vmB+JuPBZtHDRYw8/XKRQ4SOHDlO0WjVv7vL16zdked/uTnH9
1S9vuuqqLwSp4rP/wIGf/exnX/rSlzZu2Lh39+4qVau0bNmCCM11/3333ntP/379XMU52aN791q1
a7GjEstFixV1d+dPHD9OSyxUqBDLELZp367dnf/61x3//CdPo02pBtOmTS1WtOjAAf1LlSzlV2cG
DhjwQK5ct/7lFiYi82u0NarXGPL009aXEiVKkKsUxNy5czdu0mTcuHGFCxfu0rmLnr2fiRMnPvXU
U8xXpihsDnfseB2Q4K4777rvnnt5Vg4dPvzKK6+UKF7i29/+1he+8H+PPfaYTa+Rv1e20X79uvXl
ypUrUqRI2TJlFi9afDFsE+xSR986+p6IMkvjt98+ijTfiRxxEa/Sr3716+B/Mn6zWqVKlddefTXL
uvP6668/kvvhv9zyl02bIt/vxQzJteSEV/PSSy8VLVLEHSN6OG/W03j1qlVVqlTdtXMX/rnrzjvZ
J+2ngEN2vrHzrK/swiVeWHL43+rWrt2zRw/W/0kTJgzo15/EM61+Oha74Xbv2tm+bZsmjRsVL1KU
0Js0aSK6rFK58p7du/kMKlUoX71K5SqVKs5N2b34SbfPPbdy8qRJWzZvfnrQ4LatW9uVvSfG44hH
/V/60hc/9alPfe5zn/vaV79KYSMJly5Zao/32//3/3y1GwQMd/DUk0/pnF3nq1/56qc++ckVK1bQ
b50nTn/60586sINFA40bN3aMl/wl5Ht07/Hxj30Md/36l78qXqyYHkYMH+Gnf99993MrVlxzzTWf
/cxn3Vr7W//ylzGjR/vp61//OsuTSb/9H7f72r170HVPbtu69ZY//9mZL171RQNwULRoUUP97ne+
S2aSeKT67f/4x6HDkVHqPVGY9rNmzvrSF7/YpHHjMqVKXfPda6ZNm5Zlrc0i6rN8zUIiDerXDyr6
WT/n1hpcsn79+rxPPHFg//7kQbL0w/b2veuus0JFciymMWTg8VetXJml5cL5C0y+peTc488+zuxE
bzdeIF++l154ccf2HTVq1CRCAg4k++esklCzMaNGf/5zn31126vWi+98+9tbt24bOWK4YdsdnPWV
XTjjedp9e/dWrVyJL47DAJXXrlmT6HtlyytBbQsikfb49KBBxYoUQXwMJ+PHje3SqXPRwkU2b9zU
skWLB+6/P+/jjzdt1IhBJfVNWOybN23WsWOHl1560Z6Q2aZyxYpbtkTG0sTEgmAPHz70q1/+8qpo
j5epah7YHyQe3WzrK1u9wv/5n//B2mYk1/33h30dLedvf/3rlZ/6FPfFiuXLceP1P/gByCjx9bGP
fezRRx5hSkXuv/rVr55fu3b5s8u+/73vfeMb39i9a1e7tm01+OY3vwlzQw0mD3XYrGmziHliNZXW
/Yn//d+HHngAb6Own//sZ/afkDomgXB2U+179+q9Yd26r3z5K9ddey0pF15tgwYN/PTYo4/ywcyc
MfNb3/qmUS1auNBk/u63/w83mh/KxQVAeXTuWur3ju2vOc6fL999993rYNu2baR0o0aNyA2moA4d
OljsKlWsNH78eL+aPQxWoWLFCRMmWEb7+/Tt1759+759+qD13/z611OnTh0zekzXLl3r16/ft29f
eweT7EldK+1VyxYtrarI9403XgdB7Na1K5EFR/HG66+b3s9+5jPlypazGw+i4PChw927dStXrvzo
kSMJ/0YNG331K1955OFHwoZWhzOmT0PKq1etHjpsWLeu3WrXqt2nV6+XN7/M4/W1r32NimFuF8xf
ULlSJauz9/j2sbcZGgy1d+/e8+fPN+zWrVozmLOu165du3//fnQMQrJevegBJ0+afOjNQ7ZCn/70
p5944gnaVvfu3V/dts19bRkqVKjYuWMncqxbNMJyNlCJjhxeXLJDmThhwnXXXkOhe+CBB1CLm9Kz
vvud79h9XGLGi5aiyZOrVanct3dvE2pZmj9vXs/uPRgVkiXZxBFfdWvXKl2iBN4rWCA/bHTtGjWe
eOzxhfPnFy1cqFTxElTNxx99ZN68eanj8wLwkvfXrk1b74+QbNywkYmM22RoAIHxfnnTTV+86iq6
QZiIAwcO/uynP2Nc2bRxE7fEtddc861vfSvMY4Xy5RE3kJq3/feY8RZRKU+cuOOfd2AnXPf44499
/OMfR08jRowgJ6+++ms/+P73se6nr7ySyFm/bl37du31QNsM96pZvYavhEm+vHkxcMJ4D+bK5cEt
2L/+1a8w3sYYCeDTqVMn7b1dmqQDil+w1Wh5+23/+N///d+pk6eElsyYH7viiqcHD3Z8y5//5BZW
orO+v3eVfq7CeD/+0Y3r173k2GMa1fbXXnvwgQdKly6NDRhvmIK+fvXX/3LLn8uXL2/GVj73HDpm
MKtUsSLSIf//9te/0R2KFyuKmH584423/f3v3pdrv//97wPhMiA98fjjjzz88E0///mePXtoB48/
9pjO/3n77XT4z332s3nz5OFM+v3NN1tWSpUs8fWvX61zQsbg0bHjm37xi2rVql1//fVDhwxF93g7
f778mD+T8aYbxuqVq+jhN97ww6pVqnztq18Z0H+A4V199dWYbf78BT/+0Y95s/7+178ZCRv7d77z
bbxqOaMrff6zn9X5jTfeYCbDJYTkvGeeiVaW+Hk5kO1Hrv7a14x85IgRX/7SlxYvXITrvPpy5cv3
6dW7Vo2aP/3xT9q2aQvnGI04/jAH7tu7J1CjiaXu6Wr2rJkF8hf49je/2aNHjxGB8V6+1IxnUlq2
bNmsSZNpU6fOnjWrQL78hZ58avOm6DanF+Z4E2jBo4K21rhp0+FDhloL8z6RZ+6cudAtlhOYsjq1
a82de4ahXCe4ZdCAAVga3VAz3Kh+3bpvHz29u4j2eIcOeWfUuUQPsdx+77rvmcRXXtmC8a757ncx
D1+iDpECcqcVZzDelVdivIgfOnZ03j7zuuuuu/GHN9iU2gqSk7RBK6tFvXevXkOGDLEussdoSVC4
yt2ZdpiUCEYnTTrl3rJH4sWM58W8GUnjq64KyoYP6f31q6/+7ne/S9H9zGc+E7TrsOdElJ/8xCdm
TJseWt59190f//jHRg4fbtfxpz/+0TpCfl4s470UMR440c2/+x3z1be+8Y3q1asRgN/51rc2rN/w
k5/8JISE/b9f/waxejSbAjveb3/725jtnnvuKVuGsh19/n3nXcC3DpB4sVjBxsl2sLSeG274oZf1
oxtvLFKoEBFHsg0aOJA2sW7dehTyg+99nwCc/8w8rLt7d4SsoBQdPHDA5W7kq/UrX958NpA//clP
pkyaFJ7XX+IUBa9ZvcpiUalSJWd+8Yufe4/0+R//6Edert3NH3//B+fnzpn9/eu+x8LHrNWhfdRn
ty5db/7dzQ6KFStaqlQpBz/76U+s4wcPHJw0cSK59K1vftMBU/uNN9yw6rmVa9aspoksXby4QH6m
wLzhkd3rB9ddZ80KLOeVEQx5Hn+cHiHsJrTBeFh9x47t48aOY2nXDDE4c4kZz51wfO1aNQkBhIXE
rZED+/c/cvjIGVvJmPEG9OvHX3fLH/8oIqFVq1b0GS9m5PARsNF33XFH7vvvb1Cv7jPPnFY1g5pK
139m9pxXX3112bPP2gKxx9SqWdNXUiJZ5smKe/59D7q3CmK5I2+9xQNBdPzpD384fPgI1RTjURR3
7dplwKVLl4kYr3v3LIxHInmvn/zkJzEbQ5GWtsX/8z8f/8Pv/0DHCNO6d89ef1u1aqkHARaBJmgs
DvCbd+a8NXLKpMmB8fhYvFpbxM9+9jMzZ8586+hRQ/VQeZ54gnS1M7zlT382gYm1wDvWAxsS4TNr
1syvfvWrFNpNmzYee/voJWG8SNWMTbhUuHz58nF+WpuEokTaY9++r732Ggq2uGjw29/8Bh0XLlS4
0FOFxo8bT6ZhvHvvucci69djb79929/+1qhBzHiPPVayZElbod/+9rd0H4IRw8yZNfuGH/7Q47Rr
165bt+5Urx9eHzEeje5HN9zw+o7tkyZOuuGH16OKTMY7aHnq1DFikvzYLm9eKr3BkDxZGG/tmtUY
j2LpjtScXj17zJ8/z8xDbjA7sf1qz8/pdbNzSOM1NrbNWDdN4FtH3ipSuIi1wBnXDh40GF8xoowb
N55YmzB+PDObBZqoF7x23XXXLlm0mJvXJ7x9HwqdJZ5QDZYwBGrPXLBgweBAThiPYd80/uJnP7eg
6Pa/wnicdZUqVOzfty/RRJR5+LlxxrIzlJ9Tp6KtUes2jz/yCFNPoSefZLKzDbUXomHmfeLx+++5
5+EHHyhVongWVRNOSle8eeXLlitbqvTLmzaNGDacO962J7lFsO7QDEkPVGtl/fGPf+yAAAxKmhWB
pkcR4rjz9amnCvm1U4cOGA95OZ4XbywjGnr8CV/pmfNj/yEevuvOaP/2zW9886+33oqSbM8MqWmT
yLjCrBKuMvV/+P3v//ynPzn585/93F2gwx3f8c/bI9Pf0bf/cdttvtqxMI1SuV1Cif30p690I8Sd
PIiDCRMm2ohrHGm2n/50tHVsEhmT7F5wL15lbcs6t++qZcYNXEXaXPWF/6tRowat8qc/+TGf/ltH
jtx9513snLiOZ4V8u+GGG/51xx3aWIOsoZ733nvvbdSwodEOHjTI17qxnCeBWYft8ZYsWfLQgw8S
mJw6P/zh9XCGzlAR1730Em7MlStXv379vYXFixfT3J5f+/zY0WO+8bWrX3t1m/0IzblunXp8sJH0
OHnKevrLm36h/x98/3vDhgy1xuknvMEw/kzjynN01zKly7iEUIpcVnNm2w6w6onq5DtlD/vHP/7x
8MMP79u3n6pJrLmWfmg5sI1kFi5evDgWcS0VhsXBIBs2aGjHMWrkKHa1a7/73WJFi8nR/OUvfXHJ
okVI9Jvf+EaFCuXJTLLOpvHvf/ubBciON4iWQAPJMaqmVFvr+/Xrd813vst6BJjlzMZNZ4ccX6Bx
xS3ZAJh9Md7G9etNk72sdTSb5fTU3j17atWoQdvs368/QUdjHD923LgxY7t37fbEo4/16tnLDpjU
pnNnIayYc9bPmTnr1a1bEcrkiROrValii5jaLIwe7z36yKM0qN/f/DtK7MQJE6MZOXmS6YLW7n1g
JC3tCiypqJCkkujCcsXOHhlFTv0H0gUNiRikT4Y+Ga8xmLn+/e9+h23sNo8fP0am5c2Td9SokWHS
eRSQoAW1RPHiwYPPKmMppQVYF/XDfkhJ++Mf/mBxpXlqsPWVLV48gYYWkwcJkpPZ84FcD+jt3nvu
7dunL/Jykt7VsH59BEFeZZvb8+O8k6dsd2vWqFmmTBnvi0IY6AWJoHVCb8yoUXjg5z//ueelyJFv
brRi+YqKFSsxhjVv3gwcp1evXjNmzAz384y2RowrWo6MzSFt2rTlzrELbdq0KdXLbNNrSpcqjb6Z
3CxPFDANoAvsAL3KLp0716hZ004s2SzR9umBQ4cMiZTPgwebNWuGl8Lz+mvRsR/zRiwT4ydMwPyW
LZYSYkqfNiMeiOOX8QPgnvT2pnhTV65cpQOLSPv2Hdgdhg0bzt5o9SS6Vz5na7KyYsWK7dq2a9q0
mS+nTp4YNmxo5cqV586d26RJ02ARwUulSpVs2aI5FjJ7xhC2nYnCmbxBJ9nh2Jm4o5cvX4ZaQD4Y
KfiHdu7cddYXd+GMN2rkCM9pO2TG+/XpQzcI+JIsH9qzrVqgVK+qZ4/uS5csYSgfO2Yswg3nWVCQ
fhbGMzKq4+yZszp16EiVJbgtwEwj2ZuFTuyUCJlwHCGLjx9PlqXwNfzk48WEg6AuZsdYnnFh7BqJ
rzrt9c6Yej6tlMspk4Fb4saZ3Ub++miNDOexPVMNs0TcQ4aVKBpqpgNdJ8k4Q4vw9UK57mTq06VO
TnIXB5Re3kJrfGaD03OV2syDhDiSM06mTGY0pbGqknxQaXwy4yniB8qYRi/Fw3oXqSSYiiXIJKSM
9kmz5InCGV1mecbk/SYHJzIHGRxd2T/ZZyk1f0Jqe2/8bAve6YfKmMNMensnxPyFM97oUSObNGw4
aOCANatXYyFCL9ipsjLe668PHjjA4rRg3ryhQ4dWLF/e1q5e3ToWcraKFcuWPb92DRGRnfEisjtx
gnmDJ501zBJr09+hfcSrZ9wiepWR3yKFQDOwIGG9DCQb+zair5nH0fnIG5wZphS3cybTaXoiK946
/JTKAKk3DbfMaKCnTIdK8s7sdkDGf/Ob3/zPxz8ePGkp98q4NpXlkmdMHuFs7/t8zp3hBs4YZ+QG
P33ezpxxclkmHj1pk9F7ZsvMZ8zwFWUAieKOwin/S+YhzHP0Y+bf1DPJcWr7cDJz6s71aPFbzHiE
jDd4+sKMyYxXtvCM8WsORynPknqD0/fNPJs8Vvxc5+tKT52qcNMwK9kf5mIYb0STBg1sABg/+vbu
Q1PasX171oX51Enb6B7du61du2bJ4iV0D1av4sWK534oN92M089+w1aYNynVgR5GqSsrIhvM1MmT
165ebXfets3ZGO98aO+cbc4hTM4qbcKUZZ+45GTWu8XtOSHs3Ig7bqjwdBc98EvWQdhRx+p5+vM+
zcDFMN4osqtf374vb9o8fOgwaiToY3Z6YlRo3KD++LFjJk2YaBNFarEWCH+gNDLiUbvpkFx8z8zN
sseLhJgOqZqCD2wbJowf53bAIqkSL2gyWT6xKHv3JSqs08m1Z7kkFqRZnyhDrGUsDUGlJCoTXora
x4tw6gt0jl4wfuzYZUuXXjzW8ZKTRliUz2fSLvmtP7IdXjjjzZo1i0fO7o6Jn1zCVCReNhTvqZ2v
vzH06aeZJWV5GD9u3HPPrWCoFezHz8bzvmTxInFmAVR9pg4ZEf3uXbsF+DVt3Hj5smepalUqVZae
LGmGUN566whQKLACRJx/0f9ff8NW0xJ+Pm/Utg0yo0XzFnrI3p6tr3jRYpCWYJ8ZN7UTO3Vq5vTp
DRvU50WwdWbCejh3boYZXgoGJCsFW47gpuyyI3V1OJ+xpdt8uGfgwhnvpRdftGGjZLKckntVK1WG
Lcimap7avXNnm9atGJHZLZk07QnFH4wYPnzqlEnMaM/MmQPCUrlChSyqJqai+SyYP09L1iHBdazD
3AlgRwnjOXj22We5azm+v/+979/wwxt++hPW8p+wPmfdB57tHWoDz816TgPs0L79GZfEu8ED+w/w
7TA3c9QGPSwe1X969+x19113Pf/883//298pzLkffIiVuU2rVjf/9ndQS4zXwXvx4aab9NNd5Axc
IOPZtRAIsGAd2rWN4NETJ/bt1WvksGEg3ll4jx8PQgUQwVatXp3anTq0nzVj+qwZM8SniwmaOmnS
tMmTy5YqlYrVjLekkcmLnXfixEmECfNuuzZtuCX4W1IZD1CLP5S/FSry+ut/wOuNi8ZPiNCG4RPU
p3DM4JYchzMEJgt7rvtzrVq5KiiHqXKJD5SRnRvQEpN6vl+fvgBQrOr/uO0f856ZB3ixcOHC3j17
Yjnu6V/8/BfBX3+RLyZ9+Yd7Bi6Q8QKNMkvy0tDWGC25E3r16EmyZaE5+h/n2/wFCwYNGkQWsX/C
xYEOtG/Tlpth3JgxrNhdO3cJ+Npkrh2/+MKLTRs3nT59OifysqXPRpCxevXejhDrGa0i5nz7bcIQ
cAyUjDMN1/3zn/90hhWUX5GM1fTwkUP82pHR9QDZvA+wYMaM6Ry7RiKGCMNjpNdf3xFQzgsWzHee
XxV4JUBPOHO576iRTViAZkcgL+VvwRpvu+22alWr0YS5vAsXKgTnTYCDlYJZ7ty1K0H0fbipJ/10
FzwDF8V406dOg9Viq+QlB03gN0wiwRMRQeJhMHEMUPDQJ3yRi+3rnn8eAA9Kk1bmQxcNEi/1s2fv
XszTulVLTmeQP7Z4PsNEiMVSMXrqcAlNVYwCkMRS1ov//IfqG8D+jnfv3oU3YAi2bttmt/blL38Z
WpIL+9NXfgrAh5aoZfC589sKSvDVBzrp0KHDv/zlLwU6XHvtNeGk2KJFcTwbvzAMDe824QZ8LNo9
2l/u3MlRy88bocMu+IWkL/xozMCFM575sQsSWQdrv3DBQqSPjnUnxiR8jsrRc+zY9ldf4zSHwo/5
oQ/XeWAVYTUCTMMxYRLhvk+eDFfF/44GnyZLyboXX6SsVixfAWIzizh1iX7hG/9yyy0YI8lHOGDA
AF/hVLS3KED04UlGIJLQpg4CS0YZ64ULBSx+/H8+PmvGTKoj5gTvgquIIi3mz+eWxHga61zyeVAp
fYK8ZFkgsn+9rFwFHw0yznlPeeGMFywNZAvjXpVKlbgHunfp2kUIXdu2Hdu3jw/aAUbyH1SqUKFz
hw7du3QRU2eb17VTpy6dOrVs1kxcpgP/BA3Vr1vHgWtdqLEDpk6XQ8oBKHVo115wQ3auCxIPCAhL
/O63v2MFDWwwcOBAZ4SWOBa7ASKMozIZ79uEHkSSn/D2vffe94lPfILHAtzUJaVKlEwYiWYKF0sG
BldHk0YRUDOEJuS895we8WU2AxfOeIHoyROM0axxYzF1AszBncFZalStWrJYcdgUdsiSJYqTV+wi
UoxxxLVo1hSXVqxQ3p4NrlrqB9wovV+F8uVEo8vCAjztwJapfNmyMtuKCxbhDvgXAo5SZy+IRKBH
GHAIY3HWCc9AtWKSggUKOmNrx/KZMJ4wEPbPkOKFQBYVivHIW+nMXAKV5nyYFPKQpcSFIdhPUJIG
HirNeJcZDefI4VwU4wXeY9IUEsrMwJjO9gjNLEpNzPi0KVMdkCQTxk9wnsSgjjKW3HfPPYLBxRAJ
NxRiSLUTAFq3Th0ijspXl+WzY0cxfngAZzYSzFi/PvuHG2X18J44CZ4pegM/PFmwIMuJVWDXrt3Y
yW7QSeGYrqI3iuYWBRMkHsZjBQ3xYIHx/vcT/wtC2bB+FAPONBJyfjLb4NjAeHzfacbLkdR9GQ/6
Yhkv5r1TjRs1Jgrq1a3HrMevBRVFHEWwzMaN+bKLFC4s8teBXH033nCj8BPmeDEX4tA3btwApSnE
i+4HPoYnwcapdrff9neARiorBmYtlEkhOx4FMzCifupTnxRl873rrrWRu1702HXXiR9l5Rdf97Uo
g8DDbiTQTiiKZAc8H1/5ylfiCL0Mxrvrrjvxm+Xg2aXP/t///Z9jO7q77767RrXqkaj88Y9lTAlR
tqJX/Er8piXeZUzPOWZol4DxdCHEA2JDkIHkFrAsQoDhbhkwJ44bB8zRo2vXIYMHyXriQIRbrH+W
+MY3vl63Vi0hRXJptmjalK+MRte+TRueCciPAX37yWUiaqNkyRJCE95pd4dp+bgF2tA2JbqQSuhr
X/uquFtGmqJFikoJwV5SoEAB2YfkPhAwwhopPYGgSRKPNkniiQoVqC+oxC369O4jJyet9cpPXVmy
RMk33zwoQwTx+EKcwkyGGFbNd9pq5pgXnh7o5TEDl4DxgpWFIle2dJnmzZsjX3Aqhkr1Ejq1b1+m
ZKmunbrI605vnD51CiVT2pnyZcpiBtksbJzq162HY/3jKO/TsydoGBu9/EhqLURxbjHRv9NcSQYv
LdTpj+Pt2wW5eCoBLMRvCKySzUGzYGt9fcfrYGU0yeNxrBAOZF8NAU1hy2ozKdAJPEAMDCeBzjkJ
PCNbi2eEGk1jGi8P0s3Zo7gEjBcmIOK9ba8KJcRLHHpt2rQWB2R3JIpRRL1/XNJQwoKgBQLLsCBH
C1w1kWV/JcUFBJYNGKEnmR+/vA2eXNROnluvS6wpWQ7CeLJ8AuI5nEwc3EmbyDNxZs3opJPgHkht
mbPfeXr0l8EMXDLGC2HUZAtZx1ApE96A/v1BsZIb0DzlgChfpsyTBQqoRpLniTyMnPIOLJgXGet9
5JKQb4cuV61K1Tq1a2/bGqUGuwymKD2E9Axc+hm4ZIyXyD3cItIHDlNFBF4v6BNGS0Dn3Xv2+Nuw
Xv0QF8MKKlWE8jcRimXaNJ43fMiAoaIQeFeI/730j5vuMT0Dl8cMXGLGS0DJ9k7SYJJd0kKxpjSo
X89XyWSLFy0yacL4qZMnVShXntuAVGzauBEHoH8ay/YXcmCmue7yII/0KP5bM3CJGc8wQxR9YB6a
Jy8f/zhnQ/Wq1TgY+MS5B2r4r3JlTvOqVSqrSaIclwwuIuoyWC4leP+/9dzpftMz8IHOwKVnvNTH
SQwSUJ2SK4p2le5TZJ0SsIIS4EXomcrHnbZbXE4JET7Q95K++Yd8Bv67jJeksnkn82OmiEvnHfiQ
01n68bLMwH+X8dLTnZ6B9AycdQbSjJcmjPQMfAAzkGa8D2DS07dMz0Ca8dI0kJ6BD2AGPpKMF2w+
mZ/zmfX31PhdO0y9eXbkZzgTRWOkZD4+V5+Z+Zsv7SDf9SnSDS5mBnI242VHY57PXCDULBe+61WX
FqgZYOXJJwvvqScQygBHjBRVs36XD7R3AjJVGyCN4X63Cbssfs/BjGfoEpCJJFDDxUeKlMT/fu5k
95oJVgLR7tipk7ydIhICDPqdPn5dvWZNz569xDGcu+V5vlIDWLN6jVwZ3bt1X71qZZY+fVVnr3jx
ElteeeW8bnfqpIrNhvf88y8YQMoacbqkxHkOLN3sfZuBHMx4KEwAqwKOii0LxpPWUshcVAg6qFyZ
JXgcJEIgZIuQ4EwyCFnJfvXrX//gB98XOBsQaoFkIx0vviTjZCxNVFFWhW9BnE43yKLkwHGYxDNO
untSR+WMWhnRANSjEkAo0k8JVaWJw02TSkO+CtuXSDcpc5tUPgoqaBhYUnbHVxVdRB7iPceyYsvY
LWGhXqU5DWWHo/7T4IT3javO40Y5m/EmTpz46U9/pkOHjmKO7vxXVEoS9jr1kYjBKNleZmklxA0L
qoghupdmQq22lzdvUhA8cNHevXtCEuhUPsSD5OquXTvXrn1exs5Enkj+Jy1nKr85Vv8tFLIy87hF
bbTdu/YEvTF5F9JVSMJ7y5/+BCAu6yGJnSDsDr75piSBcoS2adNGVC9MuQhj5cdSxyMDm7sEXtW/
TG6ORQkKXAxh9YraWVNCugqRh4Lyk6Lt50EP6Sbv0wzkbMZTAfiqL1wV6qdLMi0aXeoHRRQ6deoo
64TUg+o0pJZN10w9a/wp5C9hIQc4UCDS9773vWu+e43KktgMyrRixQq9evZUJlL6sxUrlovKFeCL
GYoUKdy9e/e//vWvxKZKLC6H9q5Vq5a6hJLJ537oIdyC4nPdd79q7IqDFi9WLMTmxlLq5JEjb/38
pz8V6r569ZrTYvP48c6dOunwW9/6drkypQ3v61+7OveDD6ru4kYyd5LkkkpJhJEvTx55QQUZlyhW
TP4YgcUwd5s2bVLYUZZeqXu///3vKT4uf+GggYOUQZUlTVpR9d+tGmmZ9z5x1Xnc5sPAeKHcHBnw
6KOPUgiVDZMB6ZOf/MQd/7yjR48eGC8p3aORDLyf/MQn1CVPpJCDfn37OVm3Tl3JNr/whf+rXKmi
SPZrr/nu16++WtXyBfPnhwy5KJtodfBArlwSY197zTWqr7BnPPrIw5/8xCeFIFavVv3jH/+YMoCk
aL06dWfOnKXqqqroI4ZnVPQOeqngep1IAwMrHmSsYoNXfvJTTxV8UuXuaVOnafCpT35SNaUuXbpK
gla7dm3Z5tVzJ6uxk+f62BVXVK9eQ5JfBd+HDx9uYPJ/eljppG6++feSO+XJk2fK5CmVKlV2F0XG
W7RoIaY+bXc5D454n5p8mBjvP2qsKyA+/5l5aj5ffbWK25EOqSxoQnC+ivdD06rUZzBeJAVOPPro
I6ovBKVOaW+UunHDevJHnukglDCeXCxKN6qy4kCKNCextxzvbx48IKyesMWBG+NkSnZofnVepRZK
41VXXdWkcZQGNxJ48Rpw7NjbzCo33vBD7KcT8vbJgk/qYf++DLy4pGxqNrwYB+Cr7S6HmtxnNrHK
EjnTrl27r3z5SwKvrA62uPICW2vcpWfPnn4lLV3L2uRY9hqrg7ymqXd/nygrfZtzzsCHgfGYWBAW
mlZ73gIvhYQg9x/dcOOBffsz9MlTGVusQJfIXXhuJCIzjSKqnP/5z3+Wy8zJwk899aMf3Sj3EsZT
uzyD8fr1y2S8ufKOKccZGO+mm26SEwnj/eRHP4qDel/A8HL4CryQRRffyu1px2XnmZB+YoORWub+
++778he/+NILL+bO/fBvf/tbwjncDuMRtspq40kGmEJPPRUYz4LiV0kTv/XNb0iJv2nTxm9945tN
mzSWoA3jqVTuV1U+pc1evSra48ntfc13viNxcHjYNC9cPjPwYWC8efPmI6xhQ4dR6iRaJ0/y5817
w/U/3LN7DyqP0hYpdRJ/NGPHJxBQuaRjEY3LOX/0aJlSpSXefHnzywTSH/7w+7/+9dZXtrwsXyCK
PyvjqeXgvLydzCSB8X584402cljl61+/WqVbumgkA48fW7Vq5Re/+MWmKRLPSfUkQreyHhqMjEw1
alT/3Oc+F1JWR4zXurXx2E8eOXLkhz+8PmE8i4JfW7Vs+c1vfF0WpsB4zZo2SWU8aRaxuiVAyy1b
tmhQpnSa8S4fjssYSc5mPDsi4uuvf/ubRJ0sCtgAsSK4B+6//+qvfVUqaHn7ZNGcOmVqEDiB94TC
f+ELX7jh+uvt3277+9+nTJqocAIr4q9/9evb/n7b5z73WXwlv5hUgY89+kjgBNYUN1q0cFHY49kK
Okmgsce4S+7cD3FoOOAAkM+ziZj6GjVtGnPlyvWnP/5R+9o1a4YBUDTfOnpU1m2bwwceeMBmjFDl
+mCTNE7M9uCDD1WrUkXCqOBOOHT4kAd5/NFHidNvf/tbIUVvwwYNlHRWHWXd+nWf+fSnpfpUJ8xd
OnXqHD1dr16Ob/nzLSqHSvL7y5t+oe6KwkZvvnnosqO+j/CAcjDjRX7t1avLly//1JNP2iMxLXJh
oTx03LdvX5aSw4cPod1ixUvIlptpVMwogrdkyRKZJvLlzVumTJmQoX3pkiWly5QhWzjBfN2/b7/k
1gMHDoom6NSpRYsWlStXzsZJ/s9y5crLFoOJevfu3ahRY0qgBBb16tU/fOiwnLlVqlRRBkwy3BbN
mxmXHNgMnqHPsMezFRQK7KcCBQr26N6dwyNTFK9ma3niiTzdu3aTSLtq1ap6s+1knlGDRQJCObVl
pqEvsr5UrVKN319hzWrVqqkiZmDlK1ScN3++rrgWWrVspX9Zfd1UGaZiRYs1atgoLpT77jiYjzAv
vK+PnoMZLwvwKoim4DtPjsNBIu7iqWVXzJr8L0tXiWxMlZOOQ82jjM5jX3y4Y3KQfTazDCD49pOT
KWPOejK6XVzMPdtdMu6LiVNulzGwgBA4PciUeyWmnfeVvtI3e4cZyMGM54kCICP5JM8YzoSv72RU
OPdVSedJJ6kdhuPkLllud8avmbfJMv/Z736Wx3mHu5zrdpmPnPrUqe3TjHCZzEDOZrzMScyE88d5
ls49s7EkOXviwFAUNsiZiA1SOzpxdgY+U5ZGl4QJvbC3G+RbKt8GGXthvSVXpfYQS9ywZFxst9lH
FeT5eRpPo3m+yAfLyZfnYMYLalXMJxnFzVNddmd9KciCnVAi97MSDaZl6oTw0HOis6WSLzY4gxmh
yQ4dCkBKn5DS9+jRt0DMLmA3hR/Azdhgjx59O1Bwklz0+LsFKZxDpgW7bpZBBlY0d5eWdJN5i5Lj
v8MKmDHUeInxXJd2ADmotxzMeIYu/bsqPw5e27Zt5MiRGStuCj1loUgvm9Fvfpy7OnlJQcI4M3bM
2LJlynAqRILr5MlevXoqmB54+9CbB2vWqLEmNpkmOiFoJQxXEhWhKkP//v1nz5rZqWOnpNlZNcws
t05t075t29WrVrmcfaV69erlyparUaPmwhicfVaqSgafNIjQ1plNiTWrABvpnrgsWXhMZiR2I3lM
zd5Zx5mI3NN3jKYoQ7s++zD8GkmwE6Bt3bt1MxWhWap+Hs6E/ScLsLLyqswT6HGb00tA/MoybhId
XerV4TJhzhzMeN4fFOWwYcMcrF29mjkxxazwH2rMGV8zzQwd2rdXF8VPQeVKbcNEmdRIQQ4lixd/
KNcDwavO38BTFy5MPvsP7GeHJD/DGX48BlI2RgX9UpvFq39Wm0pQa8MnlSKV5gRDcRICUywSg+2L
z78AL5baONFmk5PPPPPMCy9EjrvsHzRdpnTpBPzN3aLPuXPnrl+/HtLgrFOUejI1BiI5HwaQxZAT
fuUyZUNOFqPs42FP5tv0yM8tXx6gQhmTQPU9ccacZJmfy4RhLtUwcjbjATEHZti6ZUsokrx27RoH
EF4onS9B4T4FjJT88ZxDnh4CzIXspPcM5G55htKEhLT245l//ON2QOdDh4CJT1HzlLYtVrjIizFB
k5PFihThxHPVwAEDXeK+Rw4dIiGbNWuuOBmfOAwXMSUdfdPGjV0yccIEjgTgSb3Fmt6pdevWqT0G
WaLw2PbtO/r169+sWTM98+D79O7ZS4F1qLckGogDoGbNmkYCitm7V2+IcEU2ZSilD/MouESue9Vd
DB7MTb0xGG6xF9DhilhzpZByXO2G91SBAkHi+bRs0Tx1+bBqqJ7rcaZMnkT2zJgxs0uXLk0aN546
dVrTpk1HjBjBf6j8k3irnj17jBo5yvysX7/hjTdeBwQ1FRz3oS6Np2ioEsaYsaIlxowZy5uiTevW
rT2vmoRmHgZ9/LjxO19/49FHHgHdduHE8RN4VlauWKGUd9u2bT2Xik5eh/cFgkPfBtCrV68e2Pdp
CXipqP4y6CeHM16PHhxxFDz0V6N6dZuZmjWqL126lMyZO2f22jWrVSnqipQ6d/YWoftR8MO5c8+c
PiNQ4YRx413F+6wi9IplyytUqICybRTDm27epInqYoMHDrRjaVCvXtu2bZC4gs9g1oLcSpUsaWnX
26hRo/jxlPJbv2FDsaJFpk6Z3LJ5c5KTgrdi+Yry5crjk9Dh2tVrli97dvCgwfh/1apV4pjokGTm
ooULJ0+ajDQXLlx0/733GXO8LpzikYO6tr/DLerAvPzylnJlyr7x+uuulX57wfwF4h6sC5gN0UNI
099g06wOHdp3oAh07NABt4wfPz7XffeFrMH4X83QLS9vCeuOvwL5pPQGDADIVtUMB5olK8uDDzwA
zlr4qULLly2/9S9/GTd2bNHCRejVVjRTQWxWr1YtWo969hTN6NdHcudetHixsocWl7x58ryyZYvG
vKkrn1u5bcuWObNnqZgtOmnDunWtW7cSh4Eb8z7++I7XtoOzzZhuwO29JrgfRUsVG9W5laVooUKe
hVj+UNpgcjrjdcc5EydN4j1HuC+9+MJDDzyABIXwwDELz1F+CCwLir9Pr17oA61079o1YTyiaVG8
fVK62RIuvGD9+nW+hl2HIipCSJX1e27Fii5xmQegUChKQkybIUOedgv4LMoVE0uNaAe42r0wXpvW
rYiRpwoWhFp+5OFH4mJjERR7z569cG21a9dRBX41aRzXW+ccVzJJjaTFixZFEql58xXLl6cwXjWi
28Ixa0a0WACg7Nq5U6Q5BrMXjW8XgXKQOEf53j17H3zgwU6dO4uHsvRUqVgxCDq3c5UDXcHQIPqE
8dxu7uzZvpooSb7bt2urHwjPRvUbOFmnZk2kryq9Y8vX4oULYdAUuLeiQc84CbNqVmnXVA9fmzVp
GuEQSpZc/uwy/JzQlqXNSzG2DRs2KBplzHTREsWKLlqw0AriwmiJqV5j+fJloVvIoeHDhls+Onbo
GJaMJKLyMpBVl2YIOZ3xeii57sVs2bwZHYPzI3cUbBexbdurVStXUbeoV4+ezZs2xVpjRo/REouK
QI/kXUQoTYT8OOjTp09c46Hl889HdTAD4ylstH7dOu3xtj5Rw/Rp05FmYDzhORivdu1aGI8hVJsM
xpscM17/ARaC5cuXr1m7lh2VukipU5hFvomhQ4ay06xa+Zy7h1tPGDcOPwcLCjVvxbJlWRiPNJg5
Yzp5VblSZbqfZPj169XTZt/+/YSneHYYmvnz52G8fHnzzJkzd8WKFQBlFcqWjRjv1KmK5cqJMAyP
3LF9h4DwDh86ZFC8RTnFjNeOVCf6LEmmgPoAc1eubFk6uQr1JDPgTq0aNaSrSBhPKv6pU6d4Cp24
iq2rdMkStsTlSpdW/dNJJRCB4BYvXkJXN59DBj89bep0ANfiRYsuWbS4Tq1a2hi5NWXF8mUe31cQ
9rHxy/JyK5YvB/j24bOw5GzG69ShA7LzhtauXmWZP3L4kIrQY8eOmzNn9tZXtqrCZ9OCRqtbpNeu
LVu27IwZM/55++30yUB2djIVCY2pU9lRtmx5GcosWBRjxjtRvUoVYT5UtVtvuQW5d+3WbdLESRiV
MjZt2lS6mQiAu++6i/Ylao5eR1oWK1x4wrixlDEaoOKbtCb/mBDYcWzkShYvMWH8BMTtdkgzADi7
dOo8dtQosbyRfjVt2t9uvXXZ0qUx451EjuwiMN842bpgVJUrVcLSipm5+7atVLjZQn7bt21H4tE2
d+/ehR/69+s/b94zIoawa/v27QcPHqTEvP1neK6tW7fBqhmzqaDaPfPMPHFStqYlihWn1EGWkdgU
h9o1a5gBxQynTJla+MknBUlAfs+bO4eSSQCSe+Da5u3BXLlEA5oiMln/BrZwwULMbxMrWMmiYAJ6
dO9mxZk/f/6/77rTRprMr1O7Di0gz+OP7XzjdcqzXZyWdolUaOuXfhg8Bw0Y4OmETRbMn4+4jhnv
Q6Vy5mDG8yps53CUA+YTlISyrNYtmregpciqYLPEQgDfGCwco0aNFlBDY6RrhU0XKUT+MGYKnGOn
mz17Djt4+IlWNnPGTK9cLDnCcvLZZ5996aV13j5SYyBhGGRIwIrdunbDdSLfhPkISF+37qUgEl2O
jok4VhDCSqcvvvCiMtQDBgw01Fdf3Yaw3IcNEwNoMHjgIMF77CUqchqAreabhw5ZGt4+dgxSFFc7
iSXQqBxJrvUULVu2tDti15HsqEWLlhs2bIRWpTC3atXKGYKCqta5c5cRw4YdOhhbjOJ93Yb1G8RG
NW3SFOLUyfA4OjQDwiNog0L4bWbNgOAmSw8rCFMHcaeCvFgkthn9WCMYThTTtsS8tG4dY4n2Otm6
9ZWxY8dQHQ8ePEA7ZXbasH4dZcE4hw0dynwiSNLwbJLhV60pONBusFu3bpCufsVqfBI0BTrLwAH9
CUD7z2gVjLyCaca7NFruxfZyNhzjacRjlhUlC0IyZq0zai/7GsRgGFZG+0x3Q3J5oN3wyeKxSAFy
ngZwRs0yP8mFp3vIhJVmsdpnONDjeyV3yfII2Xs7x5nEMJh9HlIGkzF7wcmS2jLJCpM5RWdBlqZ6
F7Iv52cdW+pkJpdk91KE7FUXSy6X2fU5W+JdZpOZHk56Bs53BnI244WlMDyDv/+NdfG8nEjvgOTM
/hKMMAMReib67Hxf17u1o6clYiQW25dOUMT5qoMwjKc6gqWE40QipaoM7zbSj/rvOZjxImTgsSi5
nWc4cvhIAApeSlIL4XMAlJlozOzE4tY+4dbnRUoxgIad8xwpn0Of59XbmY3CTlL/zDkh7V8MXr2A
ns5ySUawVZxEmCE3mvaTMqYd0f2xY8cxYvxconwjS+alueWHupcczHgBlGxbz5gmHlQmr8R+EA4C
BWecjMD4Z5yMfsgkkYTQkwszcsyePMkAGNIohJkKxJCx0mceMJ8wHjCuhPMZvUUwwwBFPM1FbJvA
GdBtsgwi3+R2qaPN6OJsMUEBpZ3cInNIp/tnfhRcW6tWTaCZZc8uCyDIlIfKGH/2543Dfc/F7R6N
jy6a6qpVx4we/eqrrzVu2Ei0LjOmK3kO1LiHs6lZs4Zmad5710UjBzOeoUNISIk3e/ZstjKZS84E
QJ6BwwxaEBRI9l0+MRkLh+NhLlIrKyDFjRs2nC4WHRN+zF0Z3fCYAXIxq0iORBSkdp6p8sX6WCa7
8kZwasGy6DbcNwnbTa6dMGHCypUrU7six7MPO+PNRewSc2PMj107dwFzEboOxsUgmfJ2U0N44+Cj
TANSKmDVc51VdOtH5l9wNu51YLfXXnuVvZEbAGhG6he99ezenbN029at7psYjd+V+D7KDXIw43nf
DOuSWCZEiWgGDRhYpWrV3r37HH377aefHgLhIWPCqBEjYa840y3McICcXc2aN2fdrlql6jPPzMUw
jPi0MokkeAIgs6Smrle3Hm8SdPLokchr6759e1u0bFGrVm2+JmEQfG4w+ERcseLF//WvO3E+vziQ
NN8G1JVkDbyCL7zwYrt27bnRIdpwV5hoRvmypcsEGyZXNe+WA64tcrtJk6Zt2rR9Ye3zd999N+Al
2z1HWeUqVYYNG+7K0aPHcJPobeTIUXXq1DVgcBl4EYiZkLrChx+iQrnyQQ8MH+tRl85denTvsWPH
6zzgnpcj0Ug4SPRPUXRrDhjhFJ4XkitSHUMsYmYPiYQ3G+pMJD0DAwG7hK98DOXKlnFt8utHmaPO
89lzNuNhKlnDYrmBlE/xDpUvWxbFYwzwrkKFCtG7+HaLFi4Mc8hxDOj477vvHj92HLAvyCVvFXyT
NZs/2n6Ok7pr5058g8CNWKhK5SpLFi/hXwawhF8BziBDZKpdumQpkQKECc4CRgzvAh8t1R9S1icH
F6xww/r1YankJuKnKl2ylFCARMh07tTZ7dQ/AVXhsufyMmYAK5UPeL2xE5TzyBEjXFizeg1eNU5z
maQrV66M1qGN9UnMQoE8PWhw6VIljYTHMkhX4+Gdc2DwHGikK6aSahrcxIVgJc57XoPx+Dz4ADe8
4YSYrE3AAIQYn57L9cbDKdxB4plEVjds0PD5taejoghtqVy6du2q/arnVsLKOjBmrsjZs2afW2s9
T9L8cDfL2YyHVp59NgPn4cVDPwyPBSBHMEhHvbp16J8L5y/o1qWLkyWLF/NVPAHUv8zNI0cMf/Pg
m+XLlFa9AJoR40lSBPW7bNmzUBra8+pOmzKldq0oHK5i+fJJqAuEIfRJ7ty5582dC5gClmkSixQq
TGpFAMW4aoIIicGDBgYEI7h9iPSJfcCRrLMdhbDhLyaCpkyZ0qFdO7gtTAuo7VeLBeCVWz/84EO2
jlKhLVq0MGStxYEtmjXXpnKFiuDaoGc4n8pK3YwYYOWqgOR6bfv2jh07YoaNGzcEMKSFwNLjoG+f
vqCVXNjQBWRUtapVwFwAXPwEMSOeIEgt0ljaX0tA4EN/HYen8DW4+PbvP2AAAGh0yxAa4om6duma
pFT7cHPORT5dzmY82wxbi0TDGdCvX8h4CQMFMIUa1r30EjgFxsMMJYsVI5QwHigW/iRVYD6gojAe
vnLV9OnTevXoQRSgS19VCALdYE4gScqWKqWyl5PPrXgOdtGODriJXgrKGKCPgPwEkRgCE8qiiCKH
Pj0kpHZu0gT8MuCeMwwzjjEerVI8IY6dNjWKbNq2bWvZMmVF2UgyLawBOLNK5UrSh23dtk3RH1wE
o+zXls1bIHxISLAsWiGciicNMwAUTrp6HMe2ZDHmez2hGo2hUSPASAc0zxnTpoO/gNFE4M+KFa0d
rVtGz2t9oW068AjgY8IvILaC7HKSug5ikkx1OLCQlS9bThAQ/Tlgr23zwMqTh71I6vwQX56DGc+6
Kw4I2M/mR6wXzSpCSxYtKmyMQkX+UNIYJKOok3btAK+ezJ9fcQ9qJ+Ai/oTWlTzTV0GiwJODBw/O
ny+/JNBUTUod0rH8Q3VCZgLv2klWqlDRBgnErHSpUsTUww/lxqgLFiwsXqz42jVr8z2RBy4Z9kpy
S4AskmrihImdOnTUj3BvgwkEjSswqruDO9tbzpg+TdkgLI3oGWkMHnga4llsgQgAjya2TVwfM73d
ncD5WKlr4MFJb2OzaxXWoDxQIHR/NS5SuPBo4Q6t2xCSJCSkuPNw4bZ/IP+lSpSkb7OFkI1AniJ9
4dGo3/aQ1atWE0aQdBVYK5C+kZtqwFGg6nHjxi1cYCzP2OtaDlh9NbMdtYKYeboAqGp84SXyY3xI
mS8HM17AFqlZ1a9fX2YMUdi+KpwgqjJKanDq1Lxn5gpPhVoUFcZ2ggPZJ2logkRffPFFOx+bHNs8
+5nVq1d16NCBGAQRtPvCJ6QKsbNl88u6xRiWfVYNbZCySBlCxoZQYBty7NWrN7aBzHQM2ElRpPFK
aiAsdeXKVZhEEKBqdcEHsHvXbtB7Ymfzps1GawtHAut8/vwFbdu2U3VMG/BuDYgOGE7PhVvkcdEJ
eKf+RXB7cBuzlSufAxPt06c3QRfkUtAAlyxaRFZ369ZVnmmTYz2KvJHHjsFG4gpD0obMpwaDU5PY
rP8Vylc05kmTJodOEmZLpfloqnfvxmYqNwgFZGSKZmzYcA6MYJ59dslS97XrE5KX2s+HlHEu9rFy
MOMlpJboP6mQwiABsvwUnjb5KRycFQOZ5WTYRGX/pE5flkQSoXEqyDO6XYqPQ6g7AcKtl9ptAhk9
Y/DvkMbi9NPFZBB4JvsgA7onOZ/l0UClGVTDr+dgmHMgRWP80BkOj3DmYmnzQ319zma8nPtqzLtN
XefOnXfv2nlmIsH3+5nYReWcjtj2PME37/cAP5z3SzPeB/Zes8irD2QciWs+QtsdT8uo9+8lpBnv
/Zvr9J3SM5DMQJrx0sSQnoEPYAbSjPcBTHr6lukZSDNemgbSM/ABzECa8T6ASU/fMj0DacZL00B6
Bj6AGUgz3gcw6elbpmcgzXhpGkjPwAcwA2nG+wAmPX3L9AykGS9NA+kZ+ABmIM14H8Ckp2+ZnoEc
zHhxmscMMH5I7hhCb97rS4WZDLMQgIuOU+H277W3828f7hINOyOO4fSlIVDg3J8kniCjcQhNCBkv
40+YkPiJMrJZJ8EZyU9JCEVSFDI1ju7MsImMyQkhF8ktUoeadBs1eIfohIxHzoyWOOszhnGeT3xD
8qbC857njL3b1L4fv+doxjsugaRMOwoehPcktDQqzfMeP+LoJIOQux9QWIidIL04LewJGUfE1L1T
6EBCxO/xbqebG3AIKfQ3yTLkZyvHoWgw70hGgR/kL1IpQfomyQX90YnAQtmZMugvypwbLUzCC50P
S5IDl8R3PPHWkWjqhCbs2bM7JErcs3uvZ08YSdj7jtdff3Xbq8IRpb2QXdRESQkTzU9mHIObRj9l
1pR3awUbBPueIywoZHPzV4LAqBTz2RbKI6rPHDoUErqde3rdyPOLAIwm8JwgbzdSP1C5lQt+X5f2
whzMeN6KkiCFCxcpX768mjvmRSEuQdlnov5Px6Elj5p6gAIkhhg3Zkwo6dy8aZP1L70Ueli6eHHd
2nVioZqZqTqOxQ5SMdBxdJz5axLzFjFPyoqeiKZIIsWfRFxYo5VFkU9JHGo476/g1Hx58qKSs5Kd
k35Sk0z6oxrVqklmMWTw4Pnz5rujNCoSioWrYu49JEGLHBOK9QiWlQRNLgwJHUJ2DPHjhQsXln9T
7LmvIoNKlyotq8XmzS+HB1RJS+2X2nXqlChRQj4YZ6Q2Gz92rIygoorDg8ho5hYh2UT4KLckv2Dq
Y2al1xMnhSM3adRYfoCe3Xsk61d007ipg0mTJgmxdZyljkKsz2Smr86czEOHolJ7wurDTSPxHmVJ
y3jvyd39pNRuwwb1w7u7tFx0Ab3lbMYLOeeIK7m3vH605aVaBRFEyE0kdlu0NbKTalptGhOuio3z
cS7naJmXEkKWPqm+oguPH1ezTra8kKlOqhW14MK6G9ggfFSl079mqhxbm8PqLhDbT/v37Uu4S/0g
vzqJevQfsu6RTqFlLO2itV8AePWqVTrG6YZcK/+SxJsPP/RQKKyV5Y0GaabmkdQS+MqodCv1g1QU
0YAXLmwYF5TMYOAZM2vXrOUWEq5MnKh82Fi50qSZqVi+whtv7JR/dvLEqFyZgXhezC+4XslISdNC
D+5ltP6akwH9+jspnp1AM11uahyRgD1yBMWHUuYmXz9SV+jBGwlBydnVPyeV1FMQk9Q153oIExjl
84z0jKiQ4N69+6gbo0eNxn6+xm9nj+eVsjp5F5HUlUj32DGZF4sWLqTCkZ/27tsbK9sIIJreAwf2
hzGEN67iZ4P69dKMdwHLxBmXmE35C6QeMbOWZNXhlFaUXESevFo1a6urLNeY1H0Ki1etVk3qFOWO
K1WsJNlJqxYtJUeRztkbVU1WZjuqZs8ePWlRsnFpQ0qowuU91aldS+eqz+lNTgdZfVSQrFatuvSY
bVq1/sMf/oA4QqJOmQUlcZHQWvE3SVz69elrRVfRynIg54ocKtu3vybZniRIJJWsE15/RGsxN0pR
ERjPZ9SIEf379lXQTycJC4WfgiClK6q8l5o8V5EwCSw0UNFSTdbQ2EdmJDUDpSSUr0VWmKaNm4Q8
ufILyq0iA0WD+g0krUDrMlyE0sqknPRHFqkgE5yRu1YiI6wlHYb0FmHOlYyVRUJ9eckpLAFS11A0
ypevgLFNmhTD7qgs4e7dewIDJ0MKfbq7BIcmPzChrKS4i1yVf0lqDPM5YcLEAf0HFCxYUBHZpc8+
a3klq/M8kWf9upeGPP10hQoVpcawQjVp3ERiJSl0S5coIfWTZlKqCuo/8tYRiVUVnY5qa0s3HKei
qVSpcolixcx/SO59scR30dfnbIknKdgTjz/x5JNPNmsSZbZq07pNvz59LN5UUDm/VCr2RjGVcseo
TQlLqY1e3rzl3rvvlgTJu5w+daqcJbNnziI6MJu/UdHWoUPkyUOyVE2aiaRjRJAstxUrlKdrPVXg
SbLIvkKbGtVrWEddSNkjHCSHxhV66N2zR8F8+W0nsJZ8gZhZs2NH30aO8rXIfSLlHiZKDANy+6mw
afwouE6t2mR1tSqVSYNAH74qE42BQ+72TZs216xZK17Io0IRDtq1aZsnTx6FKQsWKFi/Xn2XHIlq
J0RqcMkSJf/fb35DvURrmPmlFyMt2pDGjBqFQ3AsQmzbuo1nlKEoqJdlS5ci2SI+jzvv2qWzTDAO
qH/9+kVZKnCmCntPFsj/zNw5tpSFCz2Fc0yC/bAMn1RN+UtlH5UwSh7BaJwnT3quSZMmWhnDE/kr
d8uTBQvKoSYHXKsWzTdt3HDHP26nvCycPx/34u2e3bpT/vv37xfeoIQuMhpa7yxnJtYyKjna448+
KukbSViiaFF7UfMvMWmp4sXVpldfVvFtSdaktLHLxefyXHl98jgaUprxLmrdiFZf5Ua7dpN6VeYv
mpIcRCqJSuq65eXNqEeWS6RJF6JxeT1jxoxWAN3uR6lXKopMW7Z2gwYOkM6ImiR7LD3KCrp540aq
qWoMC+fPsxVR1TH3Q7mbNm1WuFAhRRLpdWQdBpOtCK0bg0xbJFggTYmrH3n4YTk7EZbzXraRyDOp
6KQslI8+/EjtWrXUHmgoU1hmfRUXSs2E2hy0bdO2atVqhC1VU1KjIB+sDldccYWFIFAMc0iF8hVc
Hudgjxp0aNe+b99+iHhklIEvSr9ZrVpV2fgIfyPctHGT7KOSiNKyQs5pOyvFn4MUOnb8mOxpshjG
tZ2lEjtcoVyUri/6Lb5X9WpVg248beq0wYOj1NG1atRcv36DdKO7d+4kssuWKW3XJ0116HDNmjVk
jgMZqCRfDCc9nUfo27t3xM+ZezNZp3DF5s2baMKG59WYW3J42dJnB/bvp8w19Vj604h1T5zUZt2L
L9FuHnzgAVkGZVKTetAW14pmybPHw3gjRgwnAx+4PxfhLJeph2VzkiLR17pxweeN6zeEEtNpxrtY
xkNDiMacyq4Z8md6YWafUkfJrFq5UmQ76drVrlob/IACvKeqFSsxYsppOX7cWGqkjF00N/obxtOP
VJxv7NxZQzmO+fMaNWgwYfw4RPnmm4cOxkVV9UO9JLJY0uSx9tW2SlXUtavXlCxRwg4K71GfnJcX
jG4TLrH8Y0V0tmr1qsM0uSgzV/RJrClKk2um7rG0fOq8/uWWW9wl2HAYFSWcJaAsGWHfZdl+Ji46
Gz6SF6JCB1jOoqNz+iHpLb2f3KHO+5XUtdAQtr7Wr1sXe4RryZMK5ctZODz+sbeP4l5LQxBKfu3b
u0+oEe9DZ+vff4CDMqVKrd+wgagk1mybCRP6BR4IzVavWa0EswNSS20TBzpT+hxTydUZKdjRJ8PI
VKZUaZk5ZWcsX6YsPqGTV65Yycj79O5F37ZQhpkk8IcNifIUW0qsj8yqllEagc3qgf0HPG+ZUiWl
VLXAUV9NjvRNqtWSvQS4bYOnsxOJ52dZtGlPG1cuiu3ihVPuV6nUbc/oHl6YysNegL2HN03BkHOW
Qvj4Y4/LZCklprIKFmbWDUqLNyd565hRo627pCWZwDxDqWNIWPfii6+/sZNiJnlk3dq1WR3Z+qKq
3IMGIg70pLFcsfrPlzcvC2SDevWdl41PyXXcpZ/evXrTyuyC6I0SUBIINDELBIlE3EkFL5Ulug6G
h4gxZsyU4jJhJAdVK1UKxqFEPjiOWsfqn61agXz5KYoeH/V36tB+aqzU0cQ8e9KPgsaFnnrKgIsU
LqLWNLovUbwEg1CdWrVw7zNz5lIWlExo37YtUrRm2Z3KqDtz5ozQA6lu6iQvpKiTyXaMZL6Huutf
/6Lu1qheTRZ3/dDeLXOutQzhwCWLF4WEtj169AwSL8seD08/v/Z59lL8Zj3yq+LYD+TKRQexajxZ
oGB0bfcexKORFC9aTIp+Sqkq87LQSwFM0bXBk5rNg5PVrFk8D9RL2RatHfJk57rv/pjxmq5eufLA
wQMVypbDqHazkhRbGW1D9J+WeBfJeiet0CNGjLQuBlMEFUj9ILttTIi1qKCUfsV3hg8fMXnylI0b
qX6bvWDrPdcTQqRKIeVZs2exgqgr8NZbR5Xz3r9/H3cg4tCnv7qVqdZ+Q4ERAk25Dx2+eehNQ6d5
yodp48SAqdkLz6+VSRZXUJ+wmeyuVFbjkQyXuT961LhKOCmEaJJ3H+wlEmwmcxHl+Vy1yvbpbPQR
mf/ci3mDP0AaX5TnqVhuULAkogaT9KMZ48eQIUNtdwMvrVmzdsTIkbt2RuXEJH72UDNnzjIhhBLz
CTvTM1G6segT7fcOHpRp0/RqRvvVP51NNls7KJZh02WG5cx+bsUK+gLiHjt2rLoRJs2qpzG3xGvb
tgX5lvrx1XThEzMZKxEnvaOQXt4uMVS091pf3vwyFXfixEkyoCqDYdiS1StJz/eowAMlxcbPezRL
VlJjsAQsW7bMhFhq2V3pI5HJ9OhR6wV92DFXkzdInblYmrtE1+dg40qqNMiyssZrWkoKyxRpEq5K
rj2zslesAmUa9MJFqQt2SjcZtofkzFnzYZ7RPsW5Fw0ghR5Dsyxn3tHwdmbyzOT9JeNMJYxkAIHt
U0abJQ3m6WycyeVZKIOim/I4mbXHYqUxOw0lg8nuToi4OqWj1JZZJjx7t6nzmepeP+sYkrechU4u
EeNcbDc5m/Eu9unT16dn4AOagRzMeBbLZPRBOwoC6lLOZOYtguk/rLJZbhCt2SnFYrNInowLM4Es
rk0VO6niNFEss8jYLG0iQGnSW1yJ/Ayxlu3howk5w5OWkez9vc5SIo6S580+1Umb0HmQOUGSx6PI
QKWeqUecgYzNuCS+PExdxtPFVplU8Z78FCpsJhpH7IS/pDTwXmfq/NrnZMY7fpxxcssWxRG2ej0H
DhxUEOHSTrqXGpATsQUyep1gK1lqptIJbTDsKjOoTZVwu59Dh8LXBJpoJ7bjte0xnOKg3SZkhjH7
avuhyMGGjRtYU5JLbOE2bNjI4geWoQ3XCD+4j32XF+Z2Nqs2OTjQ3mzbtlc3bFivOOtZnz1GyBzn
e1SyyxgSpMj5kUdGK0NVOMVGLjx7BAw6cCAq457Sizb2xgyOYRjhjRheJuNFLGQ36CnswWxVudft
M5l4wzzYHJoFM2OEoddQKzce+UZmEvMMPrpp8+bDbx6KqDae54ALDcgyW2VTcekX3/c0U+fdOAcz
nilmqCxQoACsCazjunUvhepwyaoZjkmEQAepP6WKytS5ymJrdgksCNe58wiCAZBlLwJ2pIC5tOGL
Z0EN/b999K08jz/OPZg5jKikEeM7uytfBXplZgRe4dTmxEdMjgEs9PB8XGndYI6+fZQRr06dOmXK
lKlapTLjQblyZSFu6tevhzIxKkc8MynPHuMNFEjevHlq166lxhBTx1nsMXFNJYUsQXaAeEKxsWha
4k+4Y/T3zD1laj/hF2WG2HK13LtnjzEbQ2ob/WGApwoW7NGtW+jfje6+8061BMMtNN7+2nYGZC+r
R7fuVpAWzZt5BP4DDIMhlWoyh0yj/EChZxeqjlKkUCHNmG2xPb8O2IqZdIlnZyKGEIAo0nLRosWK
GbHfqj2YEMB5c8EH0DBnM556yEyall44abYvrlXIzEgURNrYKedB+EFEYmo+xueDaKK3EpePVXkH
XDPWTML6Gq+cQb+JpYSWjGBPFSjA4a6BGIg+vftwWwErhVcbtB1m6wL58sVglIhW+KYfffhhjuCE
ppVibtUy8inrMwYiRmOAseKWcEmtWrWA9AMnJO8/0C4XIp+BS/Ati2tykjfZsRKtHhlqhA09/HRW
8tEtaczUHiBabkO0sg1akAio0C3RQTQlAtOsRDOToSJGz6gSYJ5HH2vXJipbCQ4CjRlVoowrwifz
AOf5+COPdOvcOQyGizXXvfc+M3t2Mg9gesEdJ5ri6FtH98NVxvg1dcswlRqd4cIgVONhHyxetCgf
aXTy2DFOF04Lx1FVtvETeGUxeVRbs0oVr4mnbu2aNdtffY3v4aww1w+At855y5zNeKRHcKBXr16D
LbtA/ny1atYCwmShZmeP5EyFCtxKbx48wDmrUhwX9sJ4DSYh8SpGpUEFig+KzYwZylYtdQbtOeta
LxicivvBSbKOeAp8kvAqMATgRQSJOHWKpZ6rmi+R6zkm8ij+BU1wJXNeE1YJbXFgQDBpYJ3u3r37
0qVLUjknNIM+4zcH91WCjz+NX85JhcSqVKqs8BjAGvs7lGapUqVZ+XftysB2ZhHvboHTVN4MHhdA
FsLKs4tRgLHi4Nqzew9NwTKUcL4DZQBVBQuPQEo3atBQnc0O7TOcjZwf0KfJUqGN9U5XADrd4yqZ
3Bgtm7ckIWdnegWxfdmyZUBPpkyZZM6jQcbhHcFJyNOdN29eJQq5ExJG5QUh3HhKleNzkqfE2+TM
4OLHaSbcJDhP4sGaQagErDaVRNG11Mm83FgujCeHM16PHqWjaoktOUxfevGFwk89ZTvUqWMnPiLe
apAOOgxZBPFQIF9e72zunLla8sMiRE68ShUqzJsXvdRkpz5s+PA5szNAIZzOMGj2TlGlxZgqufgq
la/A+5QQh57xGJcgwIqTsKMLFixQjxaAJuqWpH3r6EMPPIDhjYpqRMKAGloa/nXHHevXrderoIGB
AweWKF4c80TdZm6QOAA5fMkiG6rRI0ciUGUrLS7aAEz97re/LV+uLJFjm9S/Xz8162hxRERQIHm0
Bw0cZCsVhwedNAlPPPYYqlUxE4DOP15paiGOov268OlBg1yVaoYB++IfD/w/bOgw/jF4zgQXpta5
KuoJ42kD0wyGCnwXqk+bDY44LLFg3rzQCdfl7X//O7CBn1q2bOV2XkeRIoWB4/bt248DKedQRDz+
bhQumTFt2q233NKlSxfaKfyDMwKXbv7tb82VZRFWRl1eJ7naoXA9CICOPv9w880BqHR58lsyqhzP
eDVr1qRu2QhZv4MONnTokJHDh9uPzZsblapE0JDQ9WrXpmpGK3GLFlMnTwKVUBQOzYnKCeQO0Qur
lS9/vmLFiou7EdngQBktQBNUy6VrpiLGq1AhqJq+gkrnzZMXTkW19IIFCgBM5H7oIVqQJRk+m/pk
li3DDz34IIe4S4gaVIWRoF4QKPBkYm/k66cyhSUgiCxADRU2HSQxaQplUi89jnEK/rXkI7hAo6Hz
ZXE5eB+AG9hIkPxAf0ailDRmo2F6EIoiafn4o4/xPnv8m37xC0IvuvXxEyJqBw8aDORx/3331YCf
btvWQz2cOzcfOgBa8WLFAn4a4yUSz1chObly5YJxIzltPufMmQPdakkqWqQIHGmIh8J4ue6/H07a
MfgIaCUtkWlEYGGIRQwf8U1hJxkdT5qMDx2wCVFeQGHtUe0dDI+4BoUNwDfAIC1FMFN26tdvkDfP
E8xI4cEv50/OZjwY6UBePiB5ETWwuAwcOGrkCLssaAdfMQ8oE5Cetw5WInATjIvwQRDEEUNZWOnh
LQirunXrQUELlmFJGzNmTFQVuUGDu+++O6hA9CUlvyPTYhy1ybo4bNhwberUqY2qFi9eMnDAwN59
ehcrVgzFJOEFkPIQzy5nPEiWc2AL28UQFuRDAQY7jqg/7KxOnoRTiwo4xyFnoQ2lC/W3Ugx5bCQb
x40dg3UTksXqNjm+Ghi8OAlJ4kER6M0eD60LHfAroCblmTRjtCDxdFi0cJFhQ6OtVwhTMkVMGsWL
l6BtstzQZgd4qN69WTUee/QxS4aW1i97vNB5vB7tJ6ysbqVKlbIAqWXta+/evXLnzq2ZWdKG/blk
yZK0DA9I/qsNGEYOj0JHTZ5C1I99e/hqd0fERQcvvqASPXEdxjl92nT6vP02DdPX2lHQUwb0lApq
HtwrdcN8ebJfzma8Xj17jB0zOrwnaK9Qu9yajbZodHQzWigwJ+t8zWrVAb5QFZ3Ei8EDUIt4EjmG
lxQ6oaAmqmY4s3XrKxbXcEwpgg+0ZcowK2T60yiNtosJ9YDVU958Dd2CUJIVjRo2omjZaFnRO3To
WKhQIbApVGi9V9O4VKmS6DW6JCreesomqljRIqxEemCTJFHhpMlnazwiwyp0SyBJ+z2BdiSAzuG5
Q4qHLHu8iPH2G3aFsMezKgm9o28XyC+uZy5IKv4sVbIUiZF6LVmHSZInip9iUbfO0f7NBzbVGpek
WkiaUfYE4yRfgSotYck8AH2VK1OO7AJ8hSZjLnYX4ExbNc8IrWpmPKOY+qAwW3GaNW4irI51F9SO
Us1oqWB14UKFCepXX32VZdhCCZ7qwWkxwLelS5acMSPCml6ezJY6qhzMeKj21ddeQ0+BYmDWoxQp
J07s2LH9jTeiRADIl34Cx4iWvTZaH20zorC4CPjkKVMIIpEjYTqCLXPH9h0Qj8G6Gc6Tb9Sz8NUL
1qe/Wd6rbqNbZ35sooiUMKqQQGn16jWsKThWz4gG2jNE6MQSZpWvhpdCLicobzwHBuVyEQDMKoLi
UGSgaY3Jeaq1Y3XJp02bTrsL9snsBBebUt8Kj+9XEl4km8gJC5PIJmZAV3GgGXMiJTws76idYWJn
9ZMbKc4e1gVTDU1JPmahJLalCP4afzSz3oVY2PAhvYULG6ox0DPtt6M68ps3G4ApJV1BQ4NETXow
BpZbQXfhwe0bx0+YCIubOQ+bpk6dRp671/r168yJZchPOcF/npONKymJseL3Gn+SXVMqeDL8mqwx
WX5KKCMxsaTSUyoqJfSTnbhDgo/TFBZGkvIJYwsnU4+zf40vyoBrZHo6znVJ0ttZB5Y6pAyBlg3B
msxYlgFn0daS6T091TGiIPtjvtM8pK7xqccZbJn5JKlskzxdWALOMXWnW0bzl0auZCfS9Jn0DKRn
IEe7E876+s4qtc4io86mkATn+RkyJEYYhjOpP1EUQuN3IqHkkosZZJo+P8QzkIP3eGd9K1QSWxf/
zmHXOvrWW7bmGcn54n180FEDa7HCrX3+ed5bEKegv9m6MKPbAs6YPoPrwh4yoBbfifF0yJDDCmLb
mJofNhmwQdrC2WVd/sa3DzHpf7CPlrMZL2Xbdhqn//TTTwe7c8xOpzcGSWOmF5462MuQC1Azlr3Q
nj2aoa9xo4YMbsAuTI6YBO6EV4oFnJlUtGW3rl1eBLOMWSqDac/cQ+pHFgYG1WRfl+w6kjFI4yPj
0OkGHywVpO/+vs9ADma8iGdi0xk8brAQbHt1Gx/xsCFDnh78tLBxDm7cAZEo5Jm5TBuNiTt2wt17
MN1eTgXJMzmvubm279jBssdCPf+ZeTiNKRwaA8SRI5v7wWfylKmSJsGOuTDOWxzJPKZCljfH7nLo
8GEeYSbQ3Xt261b2LrbNKINDDBzzZsNcGwOMr6RMI4YNjwXv0Q8+19z7TnbpG+ZgxkOv0FLlypWH
HfEiBw4YwIErzaOTeZ/IU7VqFeikyBfUrBlJVbx4cRlQgI/gvzZu2sixK5vlX2+9Fe+1bNni9zf/
XoIGPi7/eCCkypk4YeL9997L7ydjUpfOnSQO4Em//fbbpUtp2iTKJxkJq1P/ASuTGdYRcJkERDxy
NWrWBONgKBejoPOKFStyeERcFzOexpzCXTp37t2zl5Qt0Plc2AaZ1jk/aqyYUxnPuNHrUwUKBlAI
oAmpFXLxQ7s3b9rMDqxSpUpbt2yRlgfWkRe7dKmSXNIA7zKIyP8FMMX3ChIpb7E2OpHoVnJleaxs
88TCgXqSk9WqVMVpoDAEY+sYnl+2dGnJ0oOWSAWV/8cBNNOi2Fk8Y9p0OZdopFHeruPHuKrlUwqN
9QBXEVUFOHUK0AMUAwBaqiwyMGwm05+PzgzkVMYLMoQjWDiJFNHgVLBUgb4BxKLceBE8ql4E4Gzc
GD6LqQOhO1mhbNk5c2djHjpnzHivUB2rx4xH3EmJi9PkgcM2sqqCwsAHSwoowSOAYuu4BwBrGXXC
vcSqdI0DYVq3ar1s6VLgKeBdQa7u2L5dlBxaQthpU6P86j4ghe3btAnHVocA/JXzC8Y6zXgfHZYL
T5qDGS+ghwkxsEOSqnSJkiG3PugwQL0DYGWMB7m7dPESMqpl8xYeWA5Glkk4SRfWrVP3tde22+5R
QbUXgikAh2pKTI0fO44SmPeJJwCa2rRtK/BHviqRYJrhyZUrngvTh/F0G/FzhQoyTwtKCGhMEq91
XIRAHjuBambZjhRqXjhpcN9rKSWZA7E/bLBpxkszHvDTtddee8Wtt96KQMPyHD6X1T7EYEDpJaWV
LBkKmdTq2LEjbbN71279+/WXMNOAYflBpaLkykuXCleV6hz1V6lUUeQBqcX0Iic09K3AH8hJqGKX
4C6cIMEjeKRiA5C44FGYZ+zo0WvWrpXpmX1EgmqAr9mz59jgMZPA4LvR3XfdBbIklTpjZteu3aZO
nRKCaOSulKFdRoOnnx7CCkqiijETmtCrZ69JEybojVjmV0gzXprxcgbjeU+AjIIjxYABXkbrwslT
jPhEDd8A6HMEvNyxg1gTSCLOUkESRkvbQtZOqHzmRJdjV1vEkLpD5E6IA1Aoz0n7QDGjYbkRJKql
9ObYLAKIviqkJToOFWrs0BYtWoh7FZojHl24YOFCv8aZRU6wrEBy+mzdGoEYiTtgaE5C5wUZgTtu
377DlvKjRnbp583BqqaXl0jj+PgMGGL4NXm8VIdbuCq5PGkTqCGLkE8AK2d12WVpn3ptfIvTSbJS
73jmsC8vVSLNEu/PDORsxnt/5ih9l/QMXPIZyMGMd56wzOxTFm9YMyK7L4eNaxCA7wRAy/KYvoZ3
ltRDPjtNnAk6Df0HFeCsKNN33WSee5CXnC4/9B3mYMbzbpYtWy6vUcI8iQUoOcj+/jQWGGoPFkfu
vR6Fk3+gL9l4hNvZN77TKGBKhYTbpkaPGYO2wWVgYqK0lpkg7ezP66HUalQ55OWXN6uywJcYb1Zf
j/JhZkOZAuLYKvOvvNMy5LxtsL1uFi39A525nH3zHMx4iKBZ0yZRfoTMj/JUIcW/g7h2+elPwJSF
p4XknD51GmMMt4GkfdH5zEC7ZDoyY/ZOB3R7zxmiJlPmRMaSk6nZrDM2mUnLhEwDh5y5zTu9I+W3
UEU5yOHTci8TZcrkw7UYJeTL3JfCo6m5lfp0MppED5gZER9+4tnv3r0HV6dEZkp/GKp8M+r1hV8D
j4Vj7scK5cpivDNHmHoHNdNHuC87kDXLD2pNhoLVOZv8P7jR52zGU3VNcishycePvQ2DIv+U5Hxy
4xQvXkzCPLZEpsXVa9ZESTgkxoyqdUcVt9XiYsEXcCABGQKKQJfHjqmJB4epJDrz4yG5igUl7NoV
YTJPnFAfWGQ6OSFHy062yrhouISqfnIlAlabJi5Do0TOZoPRj58UFla7izMd54SMmu7omKFVOjC5
H6XE4pZg3pT1QGIyFxJlADeJjUeGwlWrVovpVoKPTz+OSY9YRfrAkOCAT9+v7iKdCd8GDKrjUAuJ
KVU6CZnzpE6RlcSA9+7Z7Xk5UdTc4TUJ1SfNlXEaAyeK3oTnO3mQBfiNndJym65169dp76TBw52q
1KM3hm+w1aefHhzVOr8Myhp/cOxz4XfO2YwHrSIBifLWXTt3ARC55Za/cLUpaHjLLbeEBGFAm9Wj
/MT1uRMgUVCpnLZ8dzhBklaV2WSMlRcE/cFh+lUmr/vuuUeZO7Qr8xxwCWkg52yUDnDrVkWbpd9C
jqNHjxoSZ/gy8T169ChXtpwkKMDZfHTWAv4JiLCyZctyl1euVNG9otSA+/Yjbn6IRQsXkFdr1z7f
pGkT2VflIDEGGACZnsmoqHH8oXzCl0n1JSFn+bJlIcsgUSdMGO8nydQsHIBplStXIb2hdv7yl7/E
CQ5fhBZQh10eMd6RO+64Q+Yy2ZnuvfdeTPXs0iUywEoPY7TyC4HLSFgGOOrCjRvWgwpUr1ZdAb1V
q1YpQKmurdybUVKTOnXAXC09JnbihPGm4p577sH55kHVctrs5bBJvnDy/+CufEfGy58/P8JN1TYu
tyk2NimGZJImpmhTXG1y/vB3m0y5vgkjnAZvqZmVfuHCRSFXCroPBcf9BNglozMyIhlyP/jgnNmz
nh48qG3r1nLOyeEhPzSwGFHTplWrXj16Eq0YMs9jjxFTZGZAqBBxvPa41LF0Q/37RlXCBeMpm4r9
6GalS5biMDR1SjHjH7FIdlM6DBMLU0ogG4l8hFguPEX4SUag4XFwEymsN6kyn3/hBWxgn+avx1Rq
PGR0pWRKOEsiEbkyqamjkC9PHntXEDlZUlaufE6dR8147WU3mjZlqjLikXq5b7+Rh6TLBw7sl2aT
DJ8xY6YM0PJhmgQ7OreQH0ViMnVhZROcOWM6AFDPnlFv1jWLVFrVvGDOzc54NKCbbrrpiqpVqwL+
XuaMR7ysWPEcCIsCvDRJ9U0RLoUQWIwWJKnrvLlzPYJ4BVlxwrMIsSPiqIING9SXT5LWhIvgXYQS
YUiJruCtmzRuBEs5eOBAVYXJrihT6vLl7dq0AcvEWoIhZJgO2fIkDnJ56Pm1ba/Cdnbu2Im0UcnZ
mTgZbv0AZONFV80U89t0yfnpDFEmJ6SD9u3bcf1TFKFqMG3oDbmHxKwYT0QFvVcaNfEWBq9SsfNM
MmQUw4m9Wf26Uf4yCq+MmrVq1yarqakGuWH9Biq3NOnak2x8/ThfAV05wmTgVrs43ItOThrj/HnP
PEMaW18sBDLf1qsjT/spD+i83mbNmCFTU7euUW8k/JLFZ2S/vmAS/GhemJ3xFLumpFwhg2/RokUv
c8aT2hUpSAlesVx52zDYMcv2kbeOUNuwnxgcATgegUBApgwDTtLTGFRgo6mp2M+mS+o7mqS48pLF
i8u3aeNmyS+YL7/U1IhVSnBKJjYr/ORTUgOKbn/iscfJKM1syeS9kkIzlCUI9nr64fBhQ/2VcJrE
K1tabfG3jTBUAnCJVJz6sUwApilR4BKiiXFFmrAKRNCu3YapK3FG3bp09atr6caGR+IRxX169ZZk
Nrw2m668efJs2fKyXK6ygHk0WDn1ekg8GjV0uASb4pjIbUH0+EfPAZ0zsP8AS0OZ0qVkE/NVOQcr
l9mZPWumNcjKMmTQYJEZAjU8ZqMG9a1fJJ7UzoI8BF65pEXLlhL+Ofhoss3FP3V2xgscd0VAjl3m
jCcv+nPLlrEcEHFYTpSd1OLibiz79jlq7lj7baLwGIrv1bM3/VBouaXdvmh4DKSOFu+2bUNx+qqV
q7ZqFSGbyTGppnUrSK9gwYKRyDp1Cn+iYDOO1iWTtSHs3iNKV96vbx85p7Foz+7dataoKREtD4fE
rOqJlyhWnJa4bes2iE28JOxdks98efJaDkaNGvXE4483btzIMCSEJPEwHouFyKahQ4fRgXfu3GV7
ZgXBxpLwYlTWlyaNGotdAlUjOYkgkRlgop6XJJRJmtosV6xtWMECBUl+T6rAyNKlz9oysP2SY0aL
c+gyZUqXkb1X2maZKsUZCi+kJ9u7UoNpBzQFYVDuiJNZj9q0aknM6g3oVLSUxzd7xi+TvI3i5bYB
uXiWeH96yM54xB2hd4WXdPPNN1svE9673KYYKdOR6E5WcTF1NnUkwPoNG3x1nkyzq0G1dkchpSSD
JFMe6cQJwOgXWeTi2CI2TFXv4t4OImL9RKa/3XvYF0kbPUdugxMnXCjVioOouDYiPfLWGzsjNKb5
YZthtECpLIohyTnepvup0SF1vN5wkZa4RVJkmzSWHssERlq1ehWZaTCYnPSLIKbHjslFaYemE4MJ
edfd2rVUSrfWf1zL6Di9kYWGePdePDg902aS0SXq8ODBuKzfgWich9/yq0+cJ+aE/wkLJMPDa2Ud
4WkwFXL1unVczTxqSWzqwSDdSD+GZ0rDjLH6CunwK65Oavq9P8T6YbpLFsbzpq666ip/I8aTzJxp
7rJlvGBbT/xRiVcqOWC0nD49Y2uXnAzaUXioxHCf5WSYlHM3S9pkX7pwvs1bq1atK1aoGDaZqb2l
KhFZ5jal2RkJocP55Eapw07tOXUkyeSkOvdSM9CkdpLleVMHnDEJmR7CZE6yDObDxBLvz7NkIZuE
1yLGw3+0TRj/8CYuN4l37gkK/rdIvr2/nyj38/HjFHVxQ2SCeSNC3wXe9f6OMH23y2EGUhkvldEi
xvMRrHnfffflUMYLw34nDOR/a/ZjKGQiyoKa+n6P4b/1bOl+L9kMpDJeqmqZwXgIiKWFvSXHSbxL
NkPpjtIz8F+YgYTxmFEEnYeqmj6nGc8p9pYs0ehn3aikT6ZnID0D72kGbEmYMJPd3BmM5wvrlp8l
in1PnaYbp2cgPQPnmAGyDlvhvdQ2pyVeOEvuPfLII1xAmDA9m+kZSM/AxcwAbrKvo2Gmyrqsqmbq
DYDI2Dldk2a/i5n39LUf5RmAZ7jxxhs56pJ93bkkXvIblnMNZx9rJ6OLvR8P7Ed5HtPPnp6Bc89A
7FuabadGZ7zyyiuFH2RRL8+L8ZJGPA0MnsQl9lXqPv1Jz0B6Bs46A5REbILr8N5ZpVwq4/1/9Bck
HFTJneYAAAAASUVORK5CYII=

--_004_34966E97BE8AD64EAE9D3D6E4DEE36F252AD886FSZXEMA501MBSchi_--

