
From nobody Tue Jun  2 01:53:55 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E3BC1A8AAD for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 01:53:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.1
X-Spam-Level: 
X-Spam-Status: No, score=0.1 tagged_above=-999 required=5 tests=[BAYES_50=0.8,  RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eZdDO_EAaQrP for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 01:53:51 -0700 (PDT)
Received: from mail-la0-f53.google.com (mail-la0-f53.google.com [209.85.215.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 617AF1A8AAC for <ace@ietf.org>; Tue,  2 Jun 2015 01:53:50 -0700 (PDT)
Received: by laei3 with SMTP id i3so32402855lae.3 for <ace@ietf.org>; Tue, 02 Jun 2015 01:53:48 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=o3eDvXTtHAFXpi/L3v7gNCpzWRyzg237JMpz8VsRZoA=; b=LaEkcCKHg3iyXg3yavGgDbXYeY2DgN30zYFF5j+WNo+0vXPzLvEoyQeePTI9HDDN6b y4xQI+47wP8E+xVajzI8guWPiw4U667h1Ze0DAevkTU6SFIoyxTSKrw0vCP63RLn0INV UuWEV1dpfd6ZMJTmGiyzK6lBThNH1NzGFOWk4RK/MMZCKPwNj7CWm5qzuwAa3TdeVm6k jJXfzxLKkjDFzAmlX0SX6lr5C1nTh458iyXM4BvSb1XQ8ZMqkW3N4uvnpT5L8tpVniAm gHiOgj1dilTezLXewDkISYbJ+Xp1WPd/XBErBdgCziX+UwGLJ84D3DorjZmzGamVI5nU 2kUg==
X-Gm-Message-State: ALoCoQmC38rBUGJUDrUgMLxeb+37Uvgt+5t+M9eFS24J6jSA8sHu3Hli7fTI4ua9dt7xgQT5l52Z
X-Received: by 10.152.8.102 with SMTP id q6mr5568450laa.27.1433235228717; Tue, 02 Jun 2015 01:53:48 -0700 (PDT)
Received: from [192.168.0.108] ([85.235.11.178]) by mx.google.com with ESMTPSA id kv1sm4684890lbb.48.2015.06.02.01.53.47 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 02 Jun 2015 01:53:48 -0700 (PDT)
Message-ID: <556D6F11.5000305@sics.se>
Date: Tue, 02 Jun 2015 10:53:37 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: ace@ietf.org, samuel@erdtman.se
References: <CAF2hCbZehwzNKicTJxF7rGGmDVBuhovQgF-EZbdw-EvvQYKxqA@mail.gmail.com>
In-Reply-To: <CAF2hCbZehwzNKicTJxF7rGGmDVBuhovQgF-EZbdw-EvvQYKxqA@mail.gmail.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms000601080404020106010705"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/Qula8m2G1Fy3fnxzqLuKZE2Qbok>
Subject: Re: [Ace] draft-ietf-ace-usecases-03 WGLC review
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jun 2015 08:53:54 -0000

This is a cryptographically signed message in MIME format.

--------------ms000601080404020106010705
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 2015-04-11 18:26, Samuel Erdtman wrote:
> Hi,
>
> Thanks for writing a great document, first time I=B4m sending in review=

> comments so I hope I=B4m doing it the right way.
>

Hello Samuel, thank you for your review. Sorry it took so long to react.

>
> =3D Abstract and Introduction
> Theses sections are mentioning a connections to CoAP for this document
> but there is very limited actual connections to CoAP that I can see whe=
n
> reading is it really needed to mention CoAP since it also says that mos=
t
> concepts are general.
>

Since ACE was created because a need expressed by CoRE, I think it=20
doesn't hurt to mention CoAP, even if the relationship to this specific=20
document is not very pronounced.

>
> =3D Missing use case?
> I see nothing about secure firmware update, could maybe be seen as
> pushing configuration but it would nice to have it spelled out somewher=
e.
>

I'm planning to add this in the Building Automation use case

>
> =3D General comment
> Are the Authorization Problems Summary sections cumulative i.e. if a
> problem has come up in a previous section it will not be mentioned agai=
n
> or are the sections autonomous?
> If sections are autonomous I thing at least
> * 2.3.  Personal Health Monitoring
> Also needs integrity protected data, possible confidentiality too.
>
The sections are autonomous, I will add integrity and confidentiality to =

the Personal Health Monitoring use case.

> =3D General comment about Authorization Problems Summary sections
> Big variation in explanation of why it is a requirement
> For example
> =93U1.3 The container owner requires the integrity of the sensor data t=
hat
> is used for climate control.=94
> Here it is explained, but not here
> =93U1.7 The fruit vendor requires the integrity of the data that is use=
d
> to locate the goods=94
> It just describes the type of data that needs to be integrity protected=

> and nothing about what. We could guess but in U1.3 we did not have to.
>
> It would be super nice if the use case text connected to the
> authorisation problems e.g.
> =93Additionally, the sensor values are used to control the climate with=
in
> the cargo containers.=94
> could add a reference so that it looks like this
> =93Additionally, the sensor values are used to control the climate with=
in
> the cargo containers (U1.3).=94
>

I will put in the references and try to improve the justifications,=20
where necessary. However sometimes the specific location of the=20
reference in the text is somewhat arbitrary, especially if the security=20
problem is quite generic.

Let's see how it looks in the next update (coming soon).

>
>
> What is the differens between
> =93U1.4 The fruit vendor requires the confidentiality of the sensor dat=
a
> that pertains the state of the goods.=94
> and
> =93U1.6 The fruit vendor requires the confidentiality of the data that =
is
> used to locate the goods.=94
>

I agree, I'm planning to merged those


> Is there really a benefit of splitting U1.6 and U1.7

I agree. Merge here too


>
> 2.2.  Home Automation
> There is nothing about transferring ownership of the permeant parts of
> the automated home like air conditioning when selling the home. Further=

> it might be important not to get historical data or it might be
> important to get historical data. e.g. for the heating system it might
> be good to know exactly  how the home behaves during cold periods
> however it might not be interesting to know what groseries that has bee=
n
> in the refrigerator.
>

I am planning to add a new section here


> 2.5.3.  Advanced Metering Infrastructure
> Can also feature remote power off, from what I know (I wrote a bit on
> security for smart meters after seeing a hack at Blackhat Europe last
> https://www.nexusgroup.com/en/blog/smart-meter-security-and-pki/)
>
I am going to add a sentence about power off.

>
> 2.6.1.  Dynamically Connecting Smart Sports Equipment
> Maybe the device, could report fitness data to Jody=B4s fitness account=

> while borrowed. would require Jody to authorise the device to access
> here account for an hour.
>

Nice idea, here the constrained device would be the client towards a=20
more powerful device. I'll add a paragraph about this case.


Regards,

Ludwig Seitz


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms000601080404020106010705
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MDIwODUzMzdaMCMGCSqGSIb3DQEJBDEW
BBRSfj5wyTfPjq0WEJWyrKIajuD1YTBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEAqU0H+WzbITV9ZlvjIALCVupexYKNyrjbkGSAlbZyQM/pz+68mvVSQYs2fotf/Y6ZSxpZ
SyDVw64GbpCn1rkXOE9eSVJWC2huQP/MZWOAN6fLcNDBNiGDd79tbYd0DVof2zrN+maCl8no
pslxym3ZyBh9rqKbvoYedsmUW433hj8MqOJPpaxMsbGnWcpkffM0q9xWZJJFJ083mt0BggHl
PTzq/tCFNZLRFzYiuyT0iH0pnRodED7HfitTf3qzD0gOVrrJXy5qgMZbUUgEgUiHZegxs/9d
AqAI01QOD4QTN3QlqfoHqs1SIWVBnD6DFokLfhrqEIR41wDjyj+0aYDSlAAAAAAAAA==
--------------ms000601080404020106010705--


From nobody Tue Jun  2 01:56:32 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F30C61A8ADC for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 01:56:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zl8WgMNZIFdl for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 01:56:29 -0700 (PDT)
Received: from mail-lb0-f179.google.com (mail-lb0-f179.google.com [209.85.217.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B1B831A8AD6 for <ace@ietf.org>; Tue,  2 Jun 2015 01:56:26 -0700 (PDT)
Received: by lbcue7 with SMTP id ue7so100037711lbc.0 for <ace@ietf.org>; Tue, 02 Jun 2015 01:56:25 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=zshHhoq1SnDNN7RHfH078FDp2AWeGRSyKvR0vbY9Wpc=; b=TwWXWVGwRG9eexAVFcYdLMo5zXFHuOrj5D9+E68Dm9Rm79v5Gz3Q8jL2Hr47qwvOOm 8ZKNIJo71RW1/PDOFjJjzkkOJTNZTIEVoULWI0FnaQ60tm6ABNJ8SVElr64jHd1GcIwC zjW+wlyv+2vbY0bngf2hMHvfmgAh4jgb+YJ6wqPHNJOaLCZsdFeoPdYB2gyZ7XKDPGxQ 17+DSbuz1eYSk4NbfFQDRykOGh0+vHC5p2vh5sRuQ/HYEQVMj0DQqH6hRsLPTn2p0PyT EbM6QnlhMepxVvn/L4XXv5h/cHWI4Y6yZsS1ltkHFQCdBWOQ/bP0DT3io81nu4lkJs0Q faiA==
X-Gm-Message-State: ALoCoQmCLUx16rMg49A40Hd/+uiE1Ln5bTEN0Hebk6T4ooJSAMbkWkD+I1EW9IfMpN0YsecowQfa
X-Received: by 10.152.36.65 with SMTP id o1mr25621147laj.55.1433235385196; Tue, 02 Jun 2015 01:56:25 -0700 (PDT)
Received: from [192.168.0.108] ([85.235.11.178]) by mx.google.com with ESMTPSA id ef5sm2450346lac.30.2015.06.02.01.56.23 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 02 Jun 2015 01:56:24 -0700 (PDT)
Message-ID: <556D6FB6.4030606@sics.se>
Date: Tue, 02 Jun 2015 10:56:22 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: ace@ietf.org, srmoore@mitre.org
References: <CAF2hCbZehwzNKicTJxF7rGGmDVBuhovQgF-EZbdw-EvvQYKxqA@mail.gmail.com> <1428976512246.53294@mitre.org>
In-Reply-To: <1428976512246.53294@mitre.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms030804080002090108050309"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/Bgww-HBoxMhQcHDzaHerGvjMizs>
Subject: Re: [Ace] draft-ietf-ace-usecases-03 WGLC review
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jun 2015 08:56:31 -0000

This is a cryptographically signed message in MIME format.

--------------ms030804080002090108050309
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 2015-04-14 03:55, Moore, Steve wrote:
> I apologize for chiming in so late on the WGLC, but I also don't think =
I
> have any comments that are show stoppers so to speak.
>

Helle Steve,

sorry for being even later in answering your comments. Thank you for=20
reviewing the document.

>
>  >=3D Missing use case?
>  >I see nothing about secure firmware update, could maybe be seen as
> pushing configuration but it would nice to have it spelled out somewher=
e.
>
> I agree that this is important, but I'm not really sure that the
> Authentication and Authorization part applies to it. (Although you coul=
d
> make the case that the firmware is another resource on the device maybe=
?)
>

I am planning to add a paragraph on this in the building automation use=20
case. The device needs to make sure the update is authorized, so it is=20
definitely in scope of this document.


>  > 2.2.  Home Automation
>  > There is nothing about transferring ownership of the permeant parts
> of the automated home like air conditioning when selling the home.
> Further it might be important not to get > historical data or it might
> be important to get historical data. e.g. for the heating system it
> might be good to know exactly  how the home behaves during cold periods=

> however it might > not be interesting to know what groseries that has
> been in the refrigerator.
>
> This thought also crossed my mind it is touched upon with the
> re-provisioning that is mentioned in U4.2 under the building automation=
=2E
> Handing over the permanent parts of the house would probably be part of=

> the authorization/authentication server for the house, but the
> historical data might be more of a feature of the home
> gateway/aggregation service (Or a cloud based home management system).
>

I'm planning to add a paragraph describing that scenario.


Regards,

Ludwig Seitz


--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms030804080002090108050309
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MDIwODU2MjJaMCMGCSqGSIb3DQEJBDEW
BBRy9Cam/WkkME2jYkVGNlXcqF825DBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEAWzutDiWWXeuFjZKMnzctdnSUACD0Zwo+4pDcJqN/4gJKuAuS4c+6RpzbYj3LsdbC3WZ7
1p22l8ORNX8jK6i0RaPn6h1Iyb9c3pXGxCrIDfSYL4V6kSEgf53PF9brbuDfgo0T35HPlc3P
PhNCWlp5ZsSQ1aea2RKwosNxv4SkEUzC6h8YkGH4GZ9bkQhRVq7zVwj/9zojIg6x7uF87USx
Jushps2gMRkTYe0zTT5I5tEyVqpfZj7fShQ7HTL3SR2JeVIvE0M0co9fmwJr20dN/By+HUFb
qISTqTKOgrBjVqmMGncsbNH0rhBKishvM+W+q+qTqJpz7NwqGWnmN5TVXwAAAAAAAA==
--------------ms030804080002090108050309--


From nobody Tue Jun  2 02:38:29 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE2581A9097 for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 02:38:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 26qkOIgJKuhb for <ace@ietfa.amsl.com>; Tue,  2 Jun 2015 02:38:22 -0700 (PDT)
Received: from mail-lb0-f172.google.com (mail-lb0-f172.google.com [209.85.217.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B0051A90B0 for <ace@ietf.org>; Tue,  2 Jun 2015 02:38:22 -0700 (PDT)
Received: by lbcmx3 with SMTP id mx3so100639570lbc.1 for <ace@ietf.org>; Tue, 02 Jun 2015 02:38:20 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=OQWYqJxJO+1P7tLnb8TD+YCMNASezdN/pJ8xxCE+hsk=; b=TU9cWVMx60op4E+AGDp9MZCXVyyrl85fbrSTdfbEZqJfAceRPcUMIv5XTvo6sFbUL4 98mgCVDYMEQLEirMKYCbwX8kefAr/8AI6d9pjVfLc6c+b2kqfhuO0qRoWG9uba8Jsehb K9WTg7z+9KkQA3FgFGyh9yEn2wlFUxRVsrUBB4JZyGxNoDpQZlDipFaMOCeaQmuU9Ys1 LZKchrMAGnAQeWsVhlZdv99utoYWEjsJsR+JdrHG6vYAQFSynhOoRgNzCFeBZHelMQll Bp8a9hti49A5ylZP1DSf8fx4wwMOIQ3yZAMWCQ0xsdiua7Qi0iGmaHs2SQHbLVQYTjYs Deig==
X-Gm-Message-State: ALoCoQl97HfLsiUVLZ+7PPqxDk7Ape2HicV+rpcK5aF3uH8c3DSxzXetNvdzXR1K+UaZwlI8qMdn
X-Received: by 10.152.37.37 with SMTP id v5mr24675805laj.11.1433237900760; Tue, 02 Jun 2015 02:38:20 -0700 (PDT)
Received: from [192.168.0.108] ([85.235.11.178]) by mx.google.com with ESMTPSA id bn2sm4812630lbc.47.2015.06.02.02.38.18 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 02 Jun 2015 02:38:19 -0700 (PDT)
Message-ID: <556D7989.50003@sics.se>
Date: Tue, 02 Jun 2015 11:38:17 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: ace@ietf.org, hardjono@mit.edu
References: <5E393DF26B791A428E5F003BB6C5342A92D08CE4@OC11EXPO24.exchange.mit.edu>
In-Reply-To: <5E393DF26B791A428E5F003BB6C5342A92D08CE4@OC11EXPO24.exchange.mit.edu>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020703070905080502000801"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/xnZNmJJ-uhqbB5GN7xs-AZGAEhM>
Subject: Re: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jun 2015 09:38:28 -0000

This is a cryptographically signed message in MIME format.

--------------ms020703070905080502000801
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: quoted-printable

On 2015-05-29 23:07, Thomas Hardjono wrote:
>
> Hannes, Kepeng, Folks,
>
> As promised, here is a review of the use cases draft (draft-ietf-ace-us=
ecases-03). I also checked against the stated goals of the ACE Charter.
>
> I apologize upfront if some of my comments may offend folks in the ACE =
WG. However, the field of Constrained Environments and Devices (IoT) is a=

 >huge deal, so I believe getting the architecture/protocols right is an =

important contribution that IETF can make.

On a first glance I can not find anything offensive with your comments.=20
Thank you for contributing this review.

>
> General comments:
>
> (a) On the positive side:
>
> - I think this is a pretty good and reasonable set of use-cases from th=
e ACE WG. Congrats!
>
> - The majority of use-cases here have been written in a technology-agno=
stic manner, as they should. And so perhaps the draft doesn't really need=
 to call out specific
> technologies/protocols like REST and CoAP (Section 1, Parag 4 & 5) sinc=
e these are already called out in the ACE Charter. However, leaving these=
 in is also ok and does
 > not detract from value of the use-cases draft.
>

As I answered to Samuel, I am planning to leave the reference to CoAP in =

the document. I gather from your comment that you are ok with that.

>
> (b) On the (somewhat) negative side:
>
> - IoT is the other side of the coin of Big Data.  This is particularly =
true for the Home Automation (Smart Home) scenarios.
 > The most valuable asset here is the *data* that these devices collect =

and report.
>
> - As such I was kind of surprise that there was no use-case covering th=
e Home Personal Data Store (Home-PDS).
 > Many smart-home owners would potentially prefer the model where all=20
their home-data (e.g. from AC, refrigerator, thermostat, etc)
 > gets collected into one data-store or container that they control=20
(call it what you will: the home PC, the "home server", the
 > "home gateway", etc). In this way the home-owner then has=20
owner-centric control over which data-sets get sent out of the home.
>

Since ACE responds to a need by CoRE, the focus of this document is more =

on constrained devices. The Home-PDS is not what we would call=20
constrained and one can use regular security protocols to protect it.=20
ACE mechanisms may apply to the smaller devices communicating with the=20
Home-PDS. Do you think this warrants a specific description in the docume=
nt?


> PS. If the ACE WG is open, I can write a short use-case on the Home-PDS=
=2E
>

I'll read your contribution ASAP.


>
> (c) Weak Privacy Considerations section (Sect 4):
>
> - The privacy consideration section (Sect 4) is weak IMHO. Perhaps a pr=
ivacy expert should be invited to contribute better text to that section.=

>

Could you elaborate on that? What aspects do you think are missing?


> - May I suggest the addition of some references in Sect 4 that indicate=
 awareness of privacy issues around personal/home/health data:
>
> [ref#1] World Economic Forum, "Personal Data: The Emergence of a New As=
set Class," 2011, available on http://www.weforum.org/reports/ personal-d=
ata-emergence-new-asset-class.
>
> [ref#2] Meglena Kuneva, European Consumer Commissioner, Keynote Speech,=
 Roundtable on Online Data Collection, Targeting and Profiling, Brussels,=
 31 March 2009. Available at: http://europa.eu/rapid/press-release_SPEECH=
-09-156_en.htm
>

I do not think that these particular references would be helpful in this =

document. The awareness should be obvious by the text itself, if it=20
isn't then the text needs to be improved. Throwing in web references=20
that might become dead links by the time the document is published=20
doesn't really make it better.

>
>
> Specific comments on certain lines on the draft:
>
> (d) Section 2, parag.2 :
>
>>>> The definition of the function of a
>>>> device in a certain use case is not
>>>> in scope of this document.
>
> This line seems redundant. I think a good use-case ("use-case scenario"=
) should always be written in a high level and
> thus avoid defining functions to begin with.

If I recall correctly we have had request to do exactly that (define=20
functions), therefore we felt it necessary to add this sentence.

>
> (e) Section 2.2, parag. 1:
>
>>>> A home automation system connects
>>>> devices in a house to the Internet
>>>> and thus makes them accessible and
>>>> manageable remotely.
>
> To the non-technical reader, this line seems to confine/limit the poten=
tial scope of Home Automation or the Smart Home.
> IoT in the home promises far more than provide remote accessibility and=
 remote manageability to devices in the home.
>

I'll rewrite this sentence to clarify that remote access is only one of=20
many functions.


>
> (f) Section 2.3.2:
>
>>>> o U3.7 The device provides a service
>>>> that can be fatal for the wearer if it fails.
>>>> Accordingly, the wearer wants a security
>>>> mechanism to provide a high level of security.
>
> I think I understand the intent of this line (related to U3.6), but the=
 sentence could be improved.
 > More specifically, a device failing may have nothing to do with the=20
level of security implemented in
 > the device. For example, a heart monitor may fail simply because it=20
was a faulty device coming out of the factory.
>
> So perhaps something like:
>
> "The device provides a service that can be fatal for the wearer if it f=
ails. Accordingly, the wearer wants the
 > device to have a high degree of resistance against attacks that may=20
cause the device to fail to operate partially or completely".

Agree. I'll use your suggestion.

>
>
> (g) 2.5.3. Advanced Metering Infrastructure:
>
> - This subsection perhaps contains too much technical detail about the =
Head-End and the Data Collection Units. (Most home owners
> who have cable TV or cable modem don't know that there is a head end CM=
TS server that talks to their cable box).
> - I would suggest rewriting these two bullets into a softer explanation=
 using the entities involved (home-owner, utility company, smart meter, e=
tc).
>

I'll give it a try.


> (h) 2.5.4: U5.1
>
>>>> U5.1 Devices are installed in hostile
>>>> environments where they are physically
>>>> accessible by attackers. The service
>>>> operator and the utility company want
>>>> to make sure that an attacker cannot use a
>>>> captured device to attack other parts
>>>> of their infrastructure.
>
> - This bullet item does not sound like it is an authorization problem b=
ut rather a device-physical-security problem, caused by placing
 > the devices (e.g. smart meter) outside the house or premises. This=20
problem could be remedied (e.g. in the future drive-by metering)
 > if in the smart-meter was placed inside the house (e.g. windows=20
panel) or placed on high on the wall or the roof.

Actually this text was referring to the inside of the building as=20
hostile environment. Some of the tenants can be expected to try and=20
manipulate or sabotage metering devices in an attempt to avoid paying=20
for their consumption, or just for the pure fun of vandalism (e.g if the =

device is on the roof, where the vandalism cannot be pinpointed on a=20
specific person or household).

It is indeed also a physical security problem, but the intent here was=20
to indicate that attacking one device physically should not lead to=20
opportunities of attacking other devices remotely (e.g. by using=20
captured credentials).

>
>
> (i) 2.5.4: U5.2
>
>>> U5.2 The utility company wants to restrict
>>> which entities are allowed to send data to
>>> their endpoints and to ensure the
>>> integrity of the data on their endpoints.
>
> This sentence is a bit confusing and needs fixing (maybe it was 2 sente=
nces joined into one).
 > We know that the utility company wants both of these features=20
(authorization to send data
 > with source-authentication; and integrity-protection of data/messages)=
=2E
 > Perhaps rewriting this into separate lines would help.
>

I'll try to improve that sentence


>
> (j) 2.5.4: U5.2
>
>>>> o U5.3 The utility company wants to
>>>> control which entities are allowed to
>>>> read data on their endpoints and protect
>>>> such data in transfer.
>
> This sentence could also be improved as it seems to merge together two =
different needs (authorization
 > to read data once it arrives at the side of the utility company; and=20
integrity-protection of data/messages in transit to the utility end-point=
).
>

Ok, I'll split that up

>
> (k) Section 3: Parag. 1
>
>>> Therefore, the devices will be entrusted with vast
>>> amounts of valuable data or even control functions,
>>> that need to be protected from unauthorized
>>> access. Moreover, the aggregation of data must be
>>> considered: attackers might not only collect
>>> data from a single device but from
>>> many devices, thus increasing the potential damage.
>
> - This paragraph does not read to be consistent.  Most IoT devices will=
 have a limited storage resource, which is why they need to periodically
 > "dump" (somewhere) the data they have gathered so far. So over time=20
an IoT device will see large amounts of raw data pass-through but an=20
attacker
 > may not necessarily have access to all of this data.
>

A persistent attack would allow an attacker to see all this raw data=20
passing through. Of course attacking the "Dump" would be more efficient, =

give equivalent protection measures, but I strongly suspect that=20
currently the protection of the IoT devices is comparatively weak.

> - The second sentence is unclear. If an attacker can read data from lar=
ge amounts of distributed IoT devices on an on-going basis,
 > that means they have successfully compromised these devices on an=20
almost permanent basis which means the game is up).
> Perhaps that second line could be re-written/improved.
>

The sentence was written to motivate why protecting even seemingly=20
innocuous functions and data on IoT devices is necessary. Perhaps the=20
sentence does not quite drive that point home. I'll think about how to=20
improve this, but I'll gladly accept suggestions.



Regards,

Ludwig



--=20
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelev=E4gen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se


--------------ms020703070905080502000801
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MDIwOTM4MTdaMCMGCSqGSIb3DQEJBDEW
BBSfqYj3V3KkS7ljfuVxjStiJ/30EDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEAZ+RJn3WbcFe+pkGly2mwiMMqd8qc7GnO/fmfNK9LiFjdakYIoZ5QIBrHiWaIR/3Ah77P
U+EXdLM4zgqgjqg1JrBrKsfHNL0VTPLMtT2uA4w0JSHsMQ7D/xm6hd5aYBC8/8u0bzMMm+TL
iK2qxXXapQ3mCnAcMPszm4xxRBrvfWZSAsF2m+c72PO34/pfTzXLAUHSS0TI/kZp7hhmGDjI
cbxRQfI2/IIOPUTvsr9u00xO11iLmMVYptsXX85a5qyHTmwlOb2TH8se9ofdRT24iWUc9PTK
4YhCO9tObdtHF+C/+YZUGM25mSZ43XejFYFWGPw07qYF1JcKaSVGFYaE7QAAAAAAAA==
--------------ms020703070905080502000801--


From nobody Wed Jun  3 08:43:04 2015
Return-Path: <hardjono@mit.edu>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59B581A1BB1 for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 08:43:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gjDsZvRBFZcG for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 08:43:01 -0700 (PDT)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BE07D1A9089 for <ace@ietf.org>; Wed,  3 Jun 2015 08:43:00 -0700 (PDT)
X-AuditID: 1209190f-f79936d000000d16-28-556f2083873d
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-4.mit.edu (Symantec Messaging Gateway) with SMTP id 7D.51.03350.3802F655; Wed,  3 Jun 2015 11:42:59 -0400 (EDT)
Received: from outgoing-exchange-3.mit.edu (outgoing-exchange-3.mit.edu [18.9.28.13]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t53Fgwaj003614; Wed, 3 Jun 2015 11:42:59 -0400
Received: from w92exedge3.EXCHANGE.MIT.EDU (w92exedge3.exchange.mit.edu [18.7.73.15]) by outgoing-exchange-3.mit.edu (8.13.8/8.12.4) with ESMTP id t53Fgdi9032105; Wed, 3 Jun 2015 11:42:58 -0400
Received: from OC11EXCAS21.exchange.mit.edu (18.9.1.46) by w92exedge3.exchange.mit.edu (18.7.73.15) with Microsoft SMTP Server (TLS) id 8.2.255.0; Wed, 3 Jun 2015 11:42:33 -0400
Received: from OC11EXPO24.exchange.mit.edu ([169.254.1.2]) by OC11EXCAS21.exchange.mit.edu ([18.9.1.46]) with mapi id 14.03.0158.001; Wed, 3 Jun 2015 11:42:54 -0400
From: Thomas Hardjono <hardjono@mit.edu>
To: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
Thread-Index: AdCaU4H4IgyXLJNNQXyNSS9QjRBkrQC5d+iAADYhgEA=
Date: Wed, 3 Jun 2015 15:42:53 +0000
Message-ID: <5E393DF26B791A428E5F003BB6C5342A92D13F46@OC11EXPO24.exchange.mit.edu>
References: <5E393DF26B791A428E5F003BB6C5342A92D08CE4@OC11EXPO24.exchange.mit.edu> <556D7989.50003@sics.se>
In-Reply-To: <556D7989.50003@sics.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [192.160.73.254]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrJKsWRmVeSWpSXmKPExsUixG6nrtuskB9qcOCnpMX3bz3MFq9a7zA7 MHksWfKTyaP32G+2AKYoLpuU1JzMstQifbsErozFq76zFtzlr1j1awpzA+Mcni5GTg4JAROJ F1vPM0HYYhIX7q1nA7GFBBYzSbz87dXFyAVk72eUaJ6ygxHCOcooce3vHWYIZyujxMHlc6Cc FYwSdxe/ZQXpZxPQkGj70csOYosIOEi8W3gGbIewQIBEc/9TJoh4oMSnaWegbCuJVe9fgdks AioSNztWgvXyCgRJtKybwdLFyAG0IFeiab4cSJhTQFVi6+zLzCA2I9DZ30+tAWtlFhCXuPVk PtQ7ghKLZu9hhnnt366HbBC2ksSdR62sEPU6Egt2f2KDsLUlli18zQyxVlDi5MwnLBMYJWYh GTsLScssJC2zkLQsYGRZxSibklulm5uYmVOcmqxbnJyYl5dapGuil5tZopeaUrqJERSDnJL8 Oxi/HVQ6xCjAwajEw+sQlhcqxJpYVlyZe4hRkoNJSZT3mmh+qBBfUn5KZUZicUZ8UWlOavEh RgkOZiUR3gOyQDnelMTKqtSifJiUNAeLkjjvph98IUIC6YklqdmpqQWpRTBZGQ4OJQnee3JA jYJFqempFWmZOSUIaSYOTpDhPEDDTeVBhhcXJOYWZ6ZD5E8xKkqJ8xqBJARAEhmleXC9sBT5 ilEc6BVhXneQKh5geoXrfgU0mAlocLtADsjgkkSElFQDY1wqu6JJfrtNThBXjsidrb9Vlxk/ MjrWce79S3OVLq0A2wZ/j4xjvvfS/KRuP5f6yPLW7krW6Q8hkz6LqZ+fevut2Y+XP8pCzztb nF0RuDSdvd7HpiNjW/uS/mWHipgXBjHW/zkfJF4W/HaZLteWHRUVc78xxItU+b291tgTFFyZ FhFrZPVPiaU4I9FQi7moOBEA8/Q2smwDAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/XhiM8gJN8EaL_ctY5BKQh3Clabw>
Subject: Re: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Jun 2015 15:43:02 -0000

Hi Ludwig,

> -----Original Message-----
> From: Ludwig Seitz [mailto:ludwig@sics.se]
> Sent: Tuesday, June 02, 2015 5:38 AM
> To: ace@ietf.org; Thomas Hardjono
> Subject: Re: [Ace] Review of ACE Uses Cases
> draft (draft-ietf-ace-usecases-03)
>=20
> As I answered to Samuel, I am planning to
> leave the reference to CoAP in
> the document. I gather from your comment that
> you are ok with that.
>=20
> >
> > (b) On the (somewhat) negative side:
> >
> > - IoT is the other side of the coin of Big
> Data.  This is particularly true for the Home
> Automation (Smart Home) scenarios.
>  > The most valuable asset here is the *data*
> that these devices collect
> and report.
> >
> > - As such I was kind of surprise that there
> was no use-case covering the Home Personal
> Data Store (Home-PDS).
>  > Many smart-home owners would potentially
> prefer the model where all
> their home-data (e.g. from AC, refrigerator,
> thermostat, etc)
>  > gets collected into one data-store or
> container that they control
> (call it what you will: the home PC, the "home
> server", the
>  > "home gateway", etc). In this way the home-
> owner then has
> owner-centric control over which data-sets get
> sent out of the home.
> >
>=20
> Since ACE responds to a need by CoRE, the
> focus of this document is more
> on constrained devices. The Home-PDS is not
> what we would call
> constrained and one can use regular security
> protocols to protect it.
> ACE mechanisms may apply to the smaller
> devices communicating with the
> Home-PDS. Do you think this warrants a
> specific description in the document?


I'm aware of some folks who want to create an "IoT Gateway" in the home. Th=
ey categorize this as a constrained device. So it really depends on the def=
inition of "constrained". We could rename Home-PDS as a "Home-Gateway".

Alternatively, I could collect all my home-data into my mobile phone.  Woul=
d this sound better?


/thomas/









From nobody Wed Jun  3 09:05:12 2015
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F28D1A9163 for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 09:05:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X2WmVcvNpljj for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 09:05:08 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EF2AB1A9149 for <ace@ietf.org>; Wed,  3 Jun 2015 09:05:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id t53G50ns015830; Wed, 3 Jun 2015 18:05:00 +0200 (CEST)
Received: from alma.local (p5DCCC91B.dip0.t-ipconnect.de [93.204.201.27]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3m1w701XQXz2bth; Wed,  3 Jun 2015 18:05:00 +0200 (CEST)
Message-ID: <556F25AA.2030604@tzi.org>
Date: Wed, 03 Jun 2015 18:04:58 +0200
From: Carsten Bormann <cabo@tzi.org>
User-Agent: Postbox 3.0.11 (Macintosh/20140602)
MIME-Version: 1.0
To: Thomas Hardjono <hardjono@mit.edu>
References: <5E393DF26B791A428E5F003BB6C5342A92D08CE4@OC11EXPO24.exchange.mit.edu> <556D7989.50003@sics.se> <5E393DF26B791A428E5F003BB6C5342A92D13F46@OC11EXPO24.exchange.mit.edu>
In-Reply-To: <5E393DF26B791A428E5F003BB6C5342A92D13F46@OC11EXPO24.exchange.mit.edu>
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/TMMLUxb4EoKlTFZMnwCLB3KerhY>
Cc: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Jun 2015 16:05:10 -0000

Thomas Hardjono wrote:
> the definition of "constrained".

Everything has constraints, so "constrained" on its own is not very well
defined.

That's why we wrote RFC 7228, which is trying to put the term on a
quantitative footing.

I would consider it not so likely that a home central will be designed
as a class-1 device.  Both class-2+ and Linux-level devices (as in the
Belkin WeMo switch) are conceivable, though, so there may still be some
constrainedness.

Grüße, Carsten


From nobody Wed Jun  3 09:24:20 2015
Return-Path: <hardjono@mit.edu>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E5A921AC3F2 for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 09:24:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level: 
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id auk6tSO_jvZy for <ace@ietfa.amsl.com>; Wed,  3 Jun 2015 09:24:17 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id 544EA1AC3F0 for <ace@ietf.org>; Wed,  3 Jun 2015 09:24:17 -0700 (PDT)
X-AuditID: 12074422-f79c36d000000db3-00-556f2a306815
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id 08.80.03507.03A2F655; Wed,  3 Jun 2015 12:24:16 -0400 (EDT)
Received: from outgoing-exchange-3.mit.edu (outgoing-exchange-3.mit.edu [18.9.28.13]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t53GOFdg028408; Wed, 3 Jun 2015 12:24:16 -0400
Received: from W92EXEDGE6.EXCHANGE.MIT.EDU (w92exedge6.exchange.mit.edu [18.7.73.28]) by outgoing-exchange-3.mit.edu (8.13.8/8.12.4) with ESMTP id t53GOEEv019630; Wed, 3 Jun 2015 12:24:15 -0400
Received: from W92EXHUB11.exchange.mit.edu (18.7.73.20) by W92EXEDGE6.EXCHANGE.MIT.EDU (18.7.73.28) with Microsoft SMTP Server (TLS) id 14.3.158.1; Wed, 3 Jun 2015 12:24:03 -0400
Received: from OC11EXPO24.exchange.mit.edu ([169.254.1.2]) by W92EXHUB11.exchange.mit.edu ([18.7.73.20]) with mapi id 14.03.0158.001; Wed, 3 Jun 2015 12:24:14 -0400
From: Thomas Hardjono <hardjono@mit.edu>
To: Carsten Bormann <cabo@tzi.org>
Thread-Topic: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
Thread-Index: AdCaU4H4IgyXLJNNQXyNSS9QjRBkrQC5d+iAADYhgEAACapTAAAH3p5Q
Date: Wed, 3 Jun 2015 16:24:13 +0000
Message-ID: <5E393DF26B791A428E5F003BB6C5342A92D142EE@OC11EXPO24.exchange.mit.edu>
References: <5E393DF26B791A428E5F003BB6C5342A92D08CE4@OC11EXPO24.exchange.mit.edu> <556D7989.50003@sics.se> <5E393DF26B791A428E5F003BB6C5342A92D13F46@OC11EXPO24.exchange.mit.edu> <556F25AA.2030604@tzi.org>
In-Reply-To: <556F25AA.2030604@tzi.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [192.160.73.254]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrNKsWRmVeSWpSXmKPExsUixCmqrWuglR9q8P61msX3bz3MFkem3GW1 eNV6h9mB2WPJkp9MHr3HfrN5TFuUGcAcxWWTkpqTWZZapG+XwJVx6cpVloJ3nBVXznawNjCe 4exi5OSQEDCReHzjCSOELSZx4d56ti5GLg4hgcVMEqf6+9hBEkIC+xklOvZWQySOMkqc3LaF EcLZxijx7Mt05i5GdiBnBaNEDUg9m4CGRNuPXrBeEQEliQsX17CB2MwCDhIH9k8AWyYsECDR 3P+UCaImUOLTtDNQtpvEyYfzwGpYBFQkznasYAGxeQWCJHacng913GVGid1/voAt4BRQl9j6 4ytYESPQB99PrWGCWCYucevJfCaIzwQlFs3ewwzz5b9dD9kgbCWJO49aWbsYOYDqNSXW79KH aFWUmNL9kB1ir6DEyZlPWCYwSs5CMnUWQscsJB2zkHQsYGRZxSibklulm5uYmVOcmqxbnJyY l5dapGuql5tZopeaUrqJERSn7C5KOxh/HlQ6xCjAwajEw+sQlhcqxJpYVlyZe4hRkoNJSZR3 lUZ+qBBfUn5KZUZicUZ8UWlOavEhRgkOZiUR3gOyQDnelMTKqtSifJiUNAeLkjjvph98IUIC 6YklqdmpqQWpRTBZGQ4OJQnefSBDBYtS01Mr0jJzShDSTBycIMN5gIZfBanhLS5IzC3OTIfI n2JUlBLnnQeSEABJZJTmwfXC0ugrRnGgV4R5NTWBqniAKRiu+xXQYCagwe0COSCDSxIRUlIN jHFvjBca+aWypd5WbWG9ULHeqJZ5r0K87QYu69WnZi1hNisVzvg2odRrWbX8QkHrei/Hsjf3 jm7bcCxw2/oewYCnN/7efbY0/uEVOzvPY5WTEgKu55o/uN+Td2L5yp/Zv7eF1C/7OzW4U7nX SmdqZBzjz631+uueuHTXv5p74m6Ox8OFshPcbJVYijMSDbWYi4oTAQTA7y9+AwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/rTa3KfjKKWjbP24jUlSNY1bxLCY>
Cc: Ludwig Seitz <ludwig@sics.se>, "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Review of ACE Uses Cases draft (draft-ietf-ace-usecases-03)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Jun 2015 16:24:19 -0000

DQpUaGFua3MgQ2Fyc3RlbiwNCg0KPiAtLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KPiBGcm9t
OiBDYXJzdGVuIEJvcm1hbm4gW21haWx0bzpjYWJvQHR6aS5vcmddDQo+IFNlbnQ6IFdlZG5lc2Rh
eSwgSnVuZSAwMywgMjAxNSAxMjowNSBQTQ0KPiBUbzogVGhvbWFzIEhhcmRqb25vDQo+IENjOiBM
dWR3aWcgU2VpdHo7IGFjZUBpZXRmLm9yZw0KPiBTdWJqZWN0OiBSZTogW0FjZV0gUmV2aWV3IG9m
IEFDRSBVc2VzIENhc2VzDQo+IGRyYWZ0IChkcmFmdC1pZXRmLWFjZS11c2VjYXNlcy0wMykNCj4N
Cj4gVGhvbWFzIEhhcmRqb25vIHdyb3RlOg0KPiA+IHRoZSBkZWZpbml0aW9uIG9mICJjb25zdHJh
aW5lZCIuDQo+DQo+IEV2ZXJ5dGhpbmcgaGFzIGNvbnN0cmFpbnRzLCBzbyAiY29uc3RyYWluZWQi
DQo+IG9uIGl0cyBvd24gaXMgbm90IHZlcnkgd2VsbCBkZWZpbmVkLg0KPg0KPiBUaGF0J3Mgd2h5
IHdlIHdyb3RlIFJGQyA3MjI4LCB3aGljaCBpcyB0cnlpbmcNCj4gdG8gcHV0IHRoZSB0ZXJtIG9u
IGEgcXVhbnRpdGF0aXZlIGZvb3RpbmcuDQo+DQo+IEkgd291bGQgY29uc2lkZXIgaXQgbm90IHNv
IGxpa2VseSB0aGF0IGEgaG9tZQ0KPiBjZW50cmFsIHdpbGwgYmUgZGVzaWduZWQgYXMgYSBjbGFz
cy0xIGRldmljZS4NCj4gQm90aCBjbGFzcy0yKyBhbmQgTGludXgtbGV2ZWwgZGV2aWNlcyAoYXMg
aW4NCj4gdGhlIEJlbGtpbiBXZU1vIHN3aXRjaCkgYXJlIGNvbmNlaXZhYmxlLA0KPiB0aG91Z2gs
IHNvIHRoZXJlIG1heSBzdGlsbCBiZSBzb21lDQo+IGNvbnN0cmFpbmVkbmVzcy4NCj4NCj4gR3LD
vMOfZSwgQ2Fyc3Rlbg0KDQoNCkknbSBvayBpZiB5b3Ugd2FudCB0byBkcm9wIHRoZSBIb21lLVBE
UyB1c2UgY2FzZS4gSSdsbCBsZWF2ZSB0aGUgQUNFIFdHIHRvIGRlY2lkZS4NCg0KDQovdGhvbWFz
Lw0KDQoNCg==


From nobody Fri Jun  5 06:48:35 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73A3C1B2FAA for <ace@ietfa.amsl.com>; Fri,  5 Jun 2015 06:48:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b0tR9De7LsHE for <ace@ietfa.amsl.com>; Fri,  5 Jun 2015 06:48:31 -0700 (PDT)
Received: from mail-la0-f51.google.com (mail-la0-f51.google.com [209.85.215.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3404B1B2FA4 for <ace@ietf.org>; Fri,  5 Jun 2015 06:48:31 -0700 (PDT)
Received: by labpy14 with SMTP id py14so54773988lab.0 for <ace@ietf.org>; Fri, 05 Jun 2015 06:48:29 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=8WuPml+kMVQTFkjSa0eZhPdy/AcE0c36tOeD0U3CyW4=; b=i2OW+DEDFiU+2e82ijghj/pc4Y0DhTm9osz5iE402Qd8hm3y4g3E8gYnJ+tCbhbBWt Uuu/LRIjiXMguof+dyf60v5UXk906j+3XHHDh+iDsYGKtCkf4lnqfYKCO/+hUCt2+zra ke6JHo30zxBhb5F+FbaQ62SLhOGlRpb/xLlRYZIBw30XckHfkUFLHh0BnR/xCBeJrtS+ lJLCdLe9Uh0f3RMdZKefeyuaM5b6OWy6liy5mFMUYl04ZUecrguiTg2VC5vMHyx9CzLD wFHZqobQLRiVbTAKJAzo+RRoSV+Zt9jtDPngl9phMMFH6/P4dzMp2iRCH9o4dw5swElZ oCRw==
X-Gm-Message-State: ALoCoQlpVTfAz0zucLL+nWVey5BcFWr/vKoZmnC6kogunbhHq0CL4Qe+UoEPCn8ZkouiofonLlJy
X-Received: by 10.112.137.232 with SMTP id ql8mr3433863lbb.121.1433512109725;  Fri, 05 Jun 2015 06:48:29 -0700 (PDT)
Received: from [192.168.0.102] ([89.253.76.185]) by mx.google.com with ESMTPSA id ew11sm1787886lac.31.2015.06.05.06.48.28 for <ace@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 05 Jun 2015 06:48:28 -0700 (PDT)
Message-ID: <5571A8AA.3030306@sics.se>
Date: Fri, 05 Jun 2015 15:48:26 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20150605134553.10725.60484.idtracker@ietfa.amsl.com>
In-Reply-To: <20150605134553.10725.60484.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20150605134553.10725.60484.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020603050106020405090805"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/mtglDoiGn4HWkpP3QklKunpMQZA>
Subject: [Ace] Fwd: New Version Notification for draft-ietf-ace-usecases-04.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Jun 2015 13:48:33 -0000

This is a cryptographically signed message in MIME format.

--------------ms020603050106020405090805
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable

Hello ACE,

I have just submitted an update of draft-ietf-ace-usecases-04.txt=20
addressing most of the review comments.

What I have not yet done is to rewrite/improve the privacy=20
considerations section as suggested by Thomas Hardjono. Perhaps our=20
resident privacy expert Hannes can give it a look?

Regards,

Ludwig Seitz


-------- Forwarded Message --------
Subject: New Version Notification for draft-ietf-ace-usecases-04.txt
Date: Fri, 05 Jun 2015 06:45:53 -0700
From: internet-drafts@ietf.org
To: Mehdi Mani <mehdi.mani@itron.com>, Sandeep Kumar=20
<sandeep.kumar@philips.com>, Goeran Selander=20
<goran.selander@ericsson.com>, Sandeep S. Kumar=20
<sandeep.kumar@philips.com>, Ludwig Seitz <ludwig@sics.se>, Goran=20
Selander <goran.selander@ericsson.com>, Stefanie Gerdes=20
<gerdes@tzi.org>, Stefanie Gerdes <gerdes@tzi.org>, Ludwig Seitz=20
<ludwig@sics.se>, Mehdi Mani <mehdi.mani@itron.com>


A new version of I-D, draft-ietf-ace-usecases-04.txt
has been successfully submitted by Ludwig Seitz and posted to the
IETF repository.

Name:		draft-ietf-ace-usecases
Revision:	04
Title:		ACE use cases
Document date:	2015-06-04
Group:		ace
Pages:		25
URL:=20
https://www.ietf.org/internet-drafts/draft-ietf-ace-usecases-04.txt
Status:         https://datatracker.ietf.org/doc/draft-ietf-ace-usecases/=

Htmlized:       https://tools.ietf.org/html/draft-ietf-ace-usecases-04
Diff:           https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-ace-usecas=
es-04

Abstract:
    Constrained devices are nodes with limited processing power, storage
    space and transmission capacities.  These devices in many cases do
    not provide user interfaces and are often intended to interact
    without human intervention.

    This document comprises a collection of representative use cases for
    the application of authentication and authorization in constrained
    environments.  These use cases aim at identifying authorization
    problems that arise during the lifecylce of a constrained device and
    are intended to provide a guideline for developing a comprehensive
    authentication and authorization solution for this class of
    scenarios.

    Where specific details are relevant, it is assumed that the devices
    use the Constrained Application Protocol (CoAP) as communication
    protocol, however most conclusions apply generally.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms020603050106020405090805
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MDUxMzQ4MjZaMCMGCSqGSIb3DQEJBDEW
BBTEmU28vWpBzya5Dc+dexFpdocICjBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEASRmQYZfoM3cRsFw4YH6PewszUNO8B8X96JIMcfZHI5AgaNay/D28IESukE36KW7jU7p+
PuMoPcQKmZ//QMX5ddtGGsb3rn6WJoj4amfTy3ZyTJvQp0V2BHwpMeMwZEzgUIpmAM69p6+w
Gpmro7KLbfMXA3netx/vlgPswIpRM0q/e/pE2AXByoWTsmd96tZLAmtIsNCIXVTg9ZjuE/xz
uNCiS9dTk+Au+A2YAkZcn6psax92W8nOsgtGOcFPIUOeW2tqq0eeaClmp6oUUZrQFXRoQryN
HcYkTZ5PnU1sHtd/L6DNADXUfrgkXNhfEZvsginxfjvQ/sjQmDhDf6U4IAAAAAAAAA==
--------------ms020603050106020405090805--


From nobody Fri Jun  5 07:26:56 2015
Return-Path: <internet-drafts@ietf.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ECA7C1B2F91; Fri,  5 Jun 2015 06:45:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bQu7GcyCa4mV; Fri,  5 Jun 2015 06:45:53 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 790321B2F94; Fri,  5 Jun 2015 06:45:53 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.0.3.p2
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150605134553.10725.97902.idtracker@ietfa.amsl.com>
Date: Fri, 05 Jun 2015 06:45:53 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/35m-g_2jWFLTrWpqp-lW-QTiBWU>
X-Mailman-Approved-At: Fri, 05 Jun 2015 07:26:55 -0700
Cc: ace@ietf.org
Subject: [Ace] I-D Action: draft-ietf-ace-usecases-04.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Jun 2015 13:45:55 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
 This draft is a work item of the Authentication and Authorization for Constrained Environments Working Group of the IETF.

        Title           : ACE use cases
        Authors         : Ludwig Seitz
                          Stefanie Gerdes
                          Goeran Selander
                          Mehdi Mani
                          Sandeep S. Kumar
	Filename        : draft-ietf-ace-usecases-04.txt
	Pages           : 25
	Date            : 2015-06-05

Abstract:
   Constrained devices are nodes with limited processing power, storage
   space and transmission capacities.  These devices in many cases do
   not provide user interfaces and are often intended to interact
   without human intervention.

   This document comprises a collection of representative use cases for
   the application of authentication and authorization in constrained
   environments.  These use cases aim at identifying authorization
   problems that arise during the lifecylce of a constrained device and
   are intended to provide a guideline for developing a comprehensive
   authentication and authorization solution for this class of
   scenarios.

   Where specific details are relevant, it is assumed that the devices
   use the Constrained Application Protocol (CoAP) as communication
   protocol, however most conclusions apply generally.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-ace-usecases/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-ace-usecases-04

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-usecases-04


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Jun 19 17:12:53 2015
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CEBFD1A9045; Fri, 19 Jun 2015 17:12:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wjdzfq8U-Pec; Fri, 19 Jun 2015 17:12:49 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6BAA61A9076; Fri, 19 Jun 2015 17:12:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id t5K0Cjhh001196; Sat, 20 Jun 2015 02:12:45 +0200 (CEST)
Received: from alma.local (p5DC7EA60.dip0.t-ipconnect.de [93.199.234.96]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3mCyBP02qJz99ST; Sat, 20 Jun 2015 02:12:44 +0200 (CEST)
Message-ID: <5584AFFA.7030507@tzi.org>
Date: Sat, 20 Jun 2015 02:12:42 +0200
From: Carsten Bormann <cabo@tzi.org>
User-Agent: Postbox 4.0.1 (Macintosh/20150514)
MIME-Version: 1.0
To: dtls-iot@ietf.org, core@ietf.org, ace@ietf.org, cose@ietf.org, t2trg@irtf.org
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/E1FwaVdzSdYQuKCNcqZ0EhlL4KM>
Subject: [Ace] Constrained Node/Network Cluster @ IETF93, early draft version
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 20 Jun 2015 00:12:52 -0000

A first draft version of the IETF93 agenda is out.
** THIS IS GOING TO CHANGE ** for conflict resolution,
so please don't make travel arrangements based on it.

Here is my usual eclectic condensed agenda built from that.
(Bye, bye, appsawg.  lwig over roll is interesting; at least we do
have a roll meeting at all.)
Note that the t2trg meeting on Monday is a "summary" meeting for those
who haven't been able to join during the weekend (conflicts with
Hackathon, ICNRG, etc.)

All times are CEST (UTC+0200) (the browser timezone function appears
to have vanished from https://datatracker.ietf.org/meeting/agenda-utc,
but maybe we can reinstate that for those who want to listen from
remote).

Sorry for the duplicate posting, the IETF mail system does not allow
sending to all 9 mailing lists at the same time.

Grüße, Carsten

SATURDAY, July 18, 2015

1000-1800  Session I
(TBD)   	IRTF*** t2trg   Proposed Thing-to-thing Research Group
0900-2100  IETF Hackathon - Chez Louis

SUNDAY, July 19, 2015

0900-1600  Session II
(TBD)   	IRTF*** t2trg   Proposed Thing-to-thing Research Group
1000-1800  IETF Hackathon - Chez Louis
1600-1700  Newcomers' Meet and Greet (open to Newcomers and WG chairs
only) - Garden Terrace
1700-1900  Welcome Reception - Grand Hilton Ballroom

MONDAY, July 20, 2015

0900-1130  Morning Session I
Grand Hilton BR	ART	appsawg	Applications Area Working Group WG
Karlin I/II	OPS	anima	Autonomic Networking Integrated Model and Approach WG
Berlin/Brussels	SEC ***	cose	CBOR Object Signing and Encryption WG
Congress H II	TSV	rmcat	RTP Media Congestion Avoidance Techniques WG

1300-1500  Afternoon Session I
Congress H III	INT	6man	IPv6 Maintenance WG
Grand Hilton BR	RTG	detnet	Deterministic Networking BOF

1520-1720  Afternoon Session II
Berlin/Brussels	IRTF***	t2trg	Proposed Thing-to-Thing Research Group
Congress H III	TSV	tcpinc	TCP Increased Security WG

1740-1840  Afternoon Session III
Congress H II	INT ***	6lo	IPv6 over Networks of Resource-constrained
Nodes WG
Karlin I/II	SEC	httpauth	Hypertext Transfer Protocol Authentication WG

1850-1950  Afternoon Session IV
Congress H I	INT	intarea	Internet Area Working Group WG

TUESDAY, July 21, 2015

1300-1500  Afternoon Session I
Karlin I/II	ART	httpbis	Hypertext Transfer Protocol WG
Congress H II	INT ***	6lo	IPv6 over Networks of Resource-constrained
Nodes WG
Grand Hilton BR	OPS	v6ops	IPv6 Operations WG

1520-1720  Afternoon Session II
Karlin I/II	ART ***	core	Constrained RESTful Environments WG
Congress H II	RTG	rtgarea	Routing Area Open Meeting
Congress H III	SEC	tls	Transport Layer Security WG

1740-1840  Afternoon Session III
Congress H III	ART	uta	Using TLS in Applications WG
Berlin/Brussels	INT ***	lwig	Light-Weight Implementation Guidance WG
Congress H I	RTG ***	roll	Routing Over Low power and Lossy networks WG

WEDNESDAY, July 22, 2015

0900-1130  Morning Session I
Athens/Barcel.	INT	dnssd	Extensions for Scalable DNS Service Discovery  WG
Karlin I/II	SEC ***	ace	Authentication and Authorization for Constrained
Environments WG
Grand Hilton BR	SEC	tls	Transport Layer Security WG

1300-1530  Afternoon Session I
Grand Hilton BR	INT	homenet	Home Networking WG
Berlin/Brussels	RTG	bier	Bit Indexed Explicit Replication WG

1740-1940  Afternoon Session III
Athens/Barcel.	SEC	oauth	Web Authorization Protocol WG
Congress H III	TSV	tsvwg	Transport Area Working Group WG

THURSDAY, July 23, 2015

1300-1500  Afternoon Session I
Congress H II	SEC	saag	Security Area Open Meeting
Karlin I/II	TSV	taps	Transport Services WG

1520-1720  Afternoon Session II
Athens/Barcel.	INT ***	6tisch	IPv6 over the TSCH mode of IEEE 802.15.4e WG
Congress H III	SEC	acme	Automated Certificate Management Environment WG
Grand Hilton BR	TSV	tsvwg	Transport Area Working Group WG

1740-1910  Afternoon Session III
Athens/Barcel.	ART	webpush	Web-Based Push Notifications WG
Karlin I/II	OPS	anima	Autonomic Networking Integrated Model and Approach WG
Grand Hilton BR	TSV	tsvarea	Transport Area Open Meeting

FRIDAY, July 24, 2015

0900-1130  Morning Session I
Grand Hilton BR	OPS	v6ops	IPv6 Operations WG
Karlin I/II	SEC	openpgp	Open Specification for Pretty Good Privacy WG

1150-1320  Afternoon Session I
Karlin I/II	ART ***	core	Constrained RESTful Environments WG
Congress H I	SEC	tokbind	Token Binding WG


From nobody Sat Jun 27 03:53:32 2015
Return-Path: <cabo@tzi.org>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7929C1AC3CB; Sat, 27 Jun 2015 03:53:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level: 
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 634rlL_i3j3K; Sat, 27 Jun 2015 03:53:30 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C45AA1AC428; Sat, 27 Jun 2015 03:53:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::b]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id t5RArISQ024756; Sat, 27 Jun 2015 12:53:18 +0200 (CEST)
Received: from alma.local (p5DC7EA60.dip0.t-ipconnect.de [93.199.234.96]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3mJX4G3DZbz9905; Sat, 27 Jun 2015 12:53:18 +0200 (CEST)
Message-ID: <558E809C.5020409@tzi.org>
Date: Sat, 27 Jun 2015 12:53:16 +0200
From: Carsten Bormann <cabo@tzi.org>
User-Agent: Postbox 4.0.1 (Macintosh/20150514)
MIME-Version: 1.0
To: dtls-iot@ietf.org, core@ietf.org, ace@ietf.org, cose@ietf.org, t2trg@irtf.org
X-Enigmail-Version: 1.2.3
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/_IKq8SsalFzH2jEZywYkdC9PnW0>
Subject: [Ace] Constrained Node/Network Cluster @ IETF93, "final" version
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 27 Jun 2015 10:53:31 -0000

Below is the "final" version of the eclectic IoT agenda (I have filled
in the T2TRG Sat/Sun meeting, which is waiting for its room
assignment).  Again, there is still some potential for changes.

Apart from a dozen room changes, the main difference from the early
version is that the second 6lo and 6tisch meetings were swapped.

Grüße, Carsten


Carsten Bormann wrote:
> A first draft version of the IETF93 agenda is out.
> ** THIS IS GOING TO CHANGE ** for conflict resolution,
> so please don't make travel arrangements based on it.
>
> Here is my usual eclectic condensed agenda built from that.
> (Bye, bye, appsawg.  lwig over roll is interesting; at least we do
> have a roll meeting at all.)
> Note that the t2trg meeting on Monday is a "summary" meeting for those
> who haven't been able to join during the weekend (conflicts with
> Hackathon, ICNRG, etc.)
>
> All times are CEST (UTC+0200) (the browser timezone function appears
> to have vanished from https://datatracker.ietf.org/meeting/agenda-utc,
> but maybe we can reinstate that for those who want to listen from
> remote).
>
> Sorry for the duplicate posting, the IETF mail system does not allow
> sending to all 9 mailing lists at the same time.

SATURDAY, July 18, 2015

1000-1800  Session I
(TBD)   	IRTF*** t2trg   Proposed Thing-to-thing Research Group
0900-2100  IETF Hackathon - Chez Louis

SUNDAY, July 19, 2015

0900-1600  Session II
(TBD)   	IRTF*** t2trg   Proposed Thing-to-thing Research Group
0900-1800  IETF Hackathon - Chez Louis
1600-1700  Newcomers' Meet and Greet (open to Newcomers and WG chairs
only) - Garden Terrace
1700-1900  Welcome Reception - Grand Hilton Ballroom

MONDAY, July 20, 2015

0900-1130  Morning Session I
Grand Hilton BR	ART	appsawg	ART Area General Applications Working Group WG
Karlin I/II	OPS	anima	Autonomic Networking Integrated Model and Approach WG
Berlin/Brussels	SEC ***	cose	CBOR Object Signing and Encryption WG -
10:00 - 11:30
Congress H II	TSV	rmcat	RTP Media Congestion Avoidance Techniques WG

1300-1500  Afternoon Session I
Congress H III	INT	6man	IPv6 Maintenance WG
Grand Hilton BR	RTG	detnet	Deterministic Networking BOF

1520-1720  Afternoon Session II
Berlin/Brussels	IRTF***	t2trg	Proposed Thing-to-Thing Research Group
Congress H III	TSV	tcpinc	TCP Increased Security WG

1740-1840  Afternoon Session III
Congress H II	INT ***	6lo	IPv6 over Networks of Resource-constrained
Nodes WG
Congress H I	OPS	opsarea	Operations & Management Area Open Meeting
Karlin I/II	SEC	httpauth	Hypertext Transfer Protocol Authentication WG

1850-1950  Afternoon Session IV
Congress H III	INT	intarea	Internet Area Working Group WG

TUESDAY, July 21, 2015

1300-1500  Afternoon Session I
Congress H I	ART	httpbis	Hypertext Transfer Protocol WG
Athens/Barcel.	INT ***	6tisch	IPv6 over the TSCH mode of IEEE 802.15.4e WG
Congress H II	OPS	v6ops	IPv6 Operations WG - Joint Session with SUNSET4

1520-1720  Afternoon Session II
Karlin I/II	ART ***	core	Constrained RESTful Environments WG
Congress H II	RTG	rtgarea	Routing Area Open Meeting
Congress H III	SEC	tls	Transport Layer Security WG

1740-1840  Afternoon Session III
Congress H III	ART	uta	Using TLS in Applications WG
Berlin/Brussels	INT ***	lwig	Light-Weight Implementation Guidance WG
Congress H I	RTG ***	roll	Routing Over Low power and Lossy networks WG

WEDNESDAY, July 22, 2015

0900-1130  Morning Session I
Athens/Barcel.	INT	dnssd	Extensions for Scalable DNS Service Discovery  WG
Karlin I/II	SEC ***	ace	Authentication and Authorization for Constrained
Environments WG
Grand Hilton BR	SEC	tls	Transport Layer Security WG

1300-1530  Afternoon Session I
Grand Hilton BR	INT	homenet	Home Networking WG
Berlin/Brussels	RTG	bier	Bit Indexed Explicit Replication WG

1740-1940  Afternoon Session III
Athens/Barcel.	SEC	oauth	Web Authorization Protocol WG
Congress H III	TSV	tsvwg	Transport Area Working Group WG

THURSDAY, July 23, 2015

1300-1500  Afternoon Session I
Congress H II	SEC	saag	Security Area Open Meeting
Karlin I/II	TSV	taps	Transport Services WG

1520-1720  Afternoon Session II
Congress H I	INT ***	6lo	IPv6 over Networks of Resource-constrained Nodes WG
Congress H III	SEC	acme	Automated Certificate Management Environment WG
Karlin I/II	TSV	tsvwg	Transport Area Working Group WG

1740-1910  Afternoon Session III
Karlin I/II	ART	webpush	Web-Based Push Notifications WG
Congress H I	OPS	anima	Autonomic Networking Integrated Model and Approach WG
Grand Hilton BR	TSV	tsvarea	Transport Area Open Meeting

FRIDAY, July 24, 2015

0900-1130  Morning Session I
Grand Hilton BR	OPS	v6ops	IPv6 Operations WG - Joint Session with SUNSET4
Congress H I	SEC	openpgp	Open Specification for Pretty Good Privacy WG

1150-1320  Afternoon Session I
Karlin I/II	ART ***	core	Constrained RESTful Environments WG
Congress H I	SEC	tokbind	Token Binding WG


From nobody Mon Jun 29 09:34:13 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C31FF1AD356 for <ace@ietfa.amsl.com>; Mon, 29 Jun 2015 09:34:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bNlykY_XfmdS for <ace@ietfa.amsl.com>; Mon, 29 Jun 2015 09:34:06 -0700 (PDT)
Received: from mail-la0-f47.google.com (mail-la0-f47.google.com [209.85.215.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 486A51AD36E for <ace@ietf.org>; Mon, 29 Jun 2015 09:34:06 -0700 (PDT)
Received: by lagx9 with SMTP id x9so132388614lag.1 for <ace@ietf.org>; Mon, 29 Jun 2015 09:34:04 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=osEvK3ZlEVXfP61NxTc1XHW1SwQbDaGzkN2hqQkGQNM=; b=nHXklQ0g+LSUiCeGU52Hrz2k1sEy5QhJFUH1psriXcagSKpSYte1fsIjB+0SaIAT5i 6SrqjHBaINscRLTnkF2/Dr6leR1/ldxlJhf6sk+NWP70o/TQR7/HbAeGFI7E4jbmMoeB aZ8Z5dPeHizoeRsj8EmIgECJqHfHtI1XsMzL5Ui9duD7kYzhQyBRJWGAKSdLhDLjb+9Q mbEfxfxEnJ4kJh1iY6PGNirNTTdwnyXYf8EAGR/AcCfAhraUkFYhOwZrj5L+avbl1G8z L0zaGYSAvHaPnvNp+cnGaCtNQKcA2WabPFkRnLwMgnCpzuLMf+tu1HlyOeC7L5VJMSfC 9fSw==
X-Gm-Message-State: ALoCoQlRESse8VG/cOsn91EFQBNCaD4TCv1Kc1YsstGDFslFtfHCcCFX/SltWQv8ORYWy9ZLFBZb
X-Received: by 10.112.151.178 with SMTP id ur18mr15152181lbb.59.1435595644831;  Mon, 29 Jun 2015 09:34:04 -0700 (PDT)
Received: from [192.168.0.102] (89-253-76-185.customers.ownit.se. [89.253.76.185]) by mx.google.com with ESMTPSA id le5sm10919227lab.34.2015.06.29.09.34.03 for <ace@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 29 Jun 2015 09:34:04 -0700 (PDT)
Message-ID: <55917372.2010001@sics.se>
Date: Mon, 29 Jun 2015 18:33:54 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20150629162754.30862.72458.idtracker@ietfa.amsl.com>
In-Reply-To: <20150629162754.30862.72458.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20150629162754.30862.72458.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020104090906060302090404"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/YwkSLdIj1CjP_w-ZyL-L2TPwHHE>
Subject: [Ace] Fwd: New Version Notification for draft-seitz-ace-core-authz-00.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Jun 2015 16:34:11 -0000

This is a cryptographically signed message in MIME format.

--------------ms020104090906060302090404
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable

We have submitted a new draft describing an authorization scheme for=20
CoRE using RESTful authorization resources.

@Chairs: We would like a slot to present this draft in Prague at the ACE =

session.

Regards,

Ludwig

-------- Forwarded Message --------
Subject: New Version Notification for draft-seitz-ace-core-authz-00.txt
Date: Mon, 29 Jun 2015 09:27:54 -0700
From: internet-drafts@ietf.org
To: Goeran Selander <goran.selander@ericsson.com>, Ludwig Seitz=20
<ludwig@sics.se>, Goran Selander <goran.selander@ericsson.com>, Ludwig=20
Seitz <ludwig@sics.se>, malisa.vucinic@st.com <malisa.vucinic@st.com>,=20
Malisa Vucinic <malisa.vucinic@st.com>


A new version of I-D, draft-seitz-ace-core-authz-00.txt
has been successfully submitted by Ludwig Seitz and posted to the
IETF repository.

Name:		draft-seitz-ace-core-authz
Revision:	00
Title:		Authorization for Constrained RESTful Environments
Document date:	2015-06-29
Group:		Individual Submission
Pages:		28
URL:=20
https://www.ietf.org/internet-drafts/draft-seitz-ace-core-authz-00.txt
Status:         https://datatracker.ietf.org/doc/draft-seitz-ace-core-aut=
hz/
Htmlized:       https://tools.ietf.org/html/draft-seitz-ace-core-authz-00=



Abstract:
    This memo defines a framework for authorization in constrained-node
    networks, i.e. networks where some devices have severe constraints on=

    memory, processing, power and communication bandwidth.  The main goal=

    is to offload constrained devices by providing them access control
    support from trusted parties that are less constrained.  The approach=

    is based on RESTful requests to dedicated access management
    resources, supporting different authorization schemes and
    communication security paradigms.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms020104090906060302090404
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MjkxNjMzNTRaMCMGCSqGSIb3DQEJBDEW
BBQ9/xMVC6BfDRRk3+mbVrhZ90rzszBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEAumyh3T9MhNp4B6F90Mk+5StAk19+6H7Ot2nuoE66HWLgiIIHG4tSzcF0uPlpf7bHAtV+
uWInt1tXSxoNDEwpq4h2TFbqHwHGBUl6kyiiL/XOtNYHjlBdThozWxu+zcSP/QJdIGRFLDgT
WNcM0SZ02nZdqBnCuOAMIdUW5NP7REV6rQ587M5zBq5HOSZROCbQPd/7Yj2SZIqcOtQXau7M
ebhfXwEQ0NVFdhgp1lTDnGvDBeMu593EP6R/y9ZZRNNwexzTZBy/Cn2XOkTO/zjLAwsSypXQ
5J7wgBLIgzZh1r9HXzJ8lwJaQSivtziFkZSgC6eLfzti5YzP2qL0ZtgIaQAAAAAAAA==
--------------ms020104090906060302090404--


From nobody Mon Jun 29 09:37:08 2015
Return-Path: <ludwig@sics.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31C761B2A13 for <ace@ietfa.amsl.com>; Mon, 29 Jun 2015 09:37:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p_Tk_EtKvW3J for <ace@ietfa.amsl.com>; Mon, 29 Jun 2015 09:37:05 -0700 (PDT)
Received: from mail-la0-f41.google.com (mail-la0-f41.google.com [209.85.215.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 58B341B29FB for <ace@ietf.org>; Mon, 29 Jun 2015 09:37:04 -0700 (PDT)
Received: by laar3 with SMTP id r3so70473613laa.0 for <ace@ietf.org>; Mon, 29 Jun 2015 09:37:02 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type; bh=H2W3+Za3QD1Paerk9K6WjfBp7pQ4dpZc140WuEABqJE=; b=YMx8aRlUE6IWfUN9+CYwGZruXGN9Rdc4e9Stz6XVxIJHhQr6I+MSw+TArB6yGz/tG7 p2gTv6m4pdcOgzxe8vv5cNC92ayhlr4n+ipec4VCeofqjiK4stcovSKEh0IUq8Pnquvg ua3FaDGXZ3aNebdU8kI8vYZAHwNLO/4VHwxokkGpjA7uqK70vqULJOQ/KsFfv60hNL4A 7pT8u5woSWTRS82fAVHegNuF1Jq40TfBN5BbFPTaH3TAcVnUIFgzWDeZjIQXIE6rsZDS 4FM9O8tq+YygkbOT/fFr3lzqhCF2MEDhHnOYPFUh18NUFk7dvXB1OyMSduiZ5hbSIOoE W1Aw==
X-Gm-Message-State: ALoCoQnpxmbo7XH56WfiI/Fq6b69FXW79slNkePSPY74vWg+1+4CjeBHAufF8/cC773RVY0n9qFf
X-Received: by 10.112.85.204 with SMTP id j12mr14614038lbz.47.1435595822803; Mon, 29 Jun 2015 09:37:02 -0700 (PDT)
Received: from [192.168.0.102] (89-253-76-185.customers.ownit.se. [89.253.76.185]) by mx.google.com with ESMTPSA id w9sm10887484laj.21.2015.06.29.09.37.01 for <ace@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 29 Jun 2015 09:37:01 -0700 (PDT)
Message-ID: <5591742B.8070105@sics.se>
Date: Mon, 29 Jun 2015 18:36:59 +0200
From: Ludwig Seitz <ludwig@sics.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: "ace@ietf.org" <ace@ietf.org>
References: <20150629135808.16942.95770.idtracker@ietfa.amsl.com>
In-Reply-To: <20150629135808.16942.95770.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20150629135808.16942.95770.idtracker@ietfa.amsl.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha1; boundary="------------ms020803040109050105020409"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/UfLM5LCljKIqeN9flZezBEVy7o0>
Subject: [Ace] Fwd: New Version Notification for draft-selander-ace-object-security-02.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Jun 2015 16:37:07 -0000

This is a cryptographically signed message in MIME format.

--------------ms020803040109050105020409
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable

We have uploaded an update of our object security draft, taking into=20
consideration the developments around COSE and including considerations=20
on Blockwise Transfer (as requested at IETF 92).

This might be relevant for CoRE as well.  We are therefore unsure where=20
to present this at IETF 93. What do the chairs think?

Regards,

Ludwig

-------- Forwarded Message --------
Subject: New Version Notification for=20
draft-selander-ace-object-security-02.txt
Date: Mon, 29 Jun 2015 06:58:08 -0700
From: internet-drafts@ietf.org
To: John Mattsson <john.mattsson@ericsson.com>, Francesca Palombini=20
<francesca.palombini@ericsson.com>, John Mattsson=20
<john.mattsson@ericsson.com>, Ludwig Seitz <ludwig@sics.se>, Goran=20
Selander <goran.selander@ericsson.com>, Goeran Selander=20
<goran.selander@ericsson.com>, Francesca Palombini=20
<francesca.palombini@ericsson.com>, Ludwig Seitz <ludwig@sics.se>


A new version of I-D, draft-selander-ace-object-security-02.txt
has been successfully submitted by Francesca Palombini and posted to the
IETF repository.

Name:		draft-selander-ace-object-security
Revision:	02
Title:		June 29, 2015
Document date:	2015-06-29
Group:		Individual Submission
Pages:		43
URL:=20
https://www.ietf.org/internet-drafts/draft-selander-ace-object-security-0=
2.txt
Status:=20
https://datatracker.ietf.org/doc/draft-selander-ace-object-security/
Htmlized:=20
https://tools.ietf.org/html/draft-selander-ace-object-security-02
Diff:=20
https://www.ietf.org/rfcdiff?url2=3Ddraft-selander-ace-object-security-02=


Abstract:
    This memo presents OSCOAP, a scheme for protection of request and
    response messages of the Constrained Application Protocol (CoAP),
    using data object security.

=20



Please note that it may take a couple of minutes from the time of submiss=
ion
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat





--------------ms020803040109050105020409
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIMVDCC
BhgwggUAoAMCAQICAwyGmDANBgkqhkiG9w0BAQUFADCBjDELMAkGA1UEBhMCSUwxFjAUBgNV
BAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFsIENlcnRpZmljYXRl
IFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNzIDEgUHJpbWFyeSBJbnRlcm1lZGlh
dGUgQ2xpZW50IENBMB4XDTE1MDEwODA4MzkwNloXDTE2MDEwOTIyNDEzMFowODEXMBUGA1UE
AwwObHVkd2lnQHNpY3Muc2UxHTAbBgkqhkiG9w0BCQEWDmx1ZHdpZ0BzaWNzLnNlMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUHisC6rgXFsBHHBGo8ulz/cLX3gX5Ufhcwo
rp+7djzMMuKPM1KOHq0bjWhmFe8ly8CzWdk2NS600t7IEBQWJiHLsdc12UqmNswQUpD7oqkR
1nRGT6leAHYTWapkR+nczZ2NxD+H7u4ZWVIZg0DFiTqtY8ghYHHYYy8BBoc/jHG78X4+JJAg
s5XOa0gVl7W38vDvVpo14xhWEBGjzPk9WxWirqAF66PF+JEu2JD9LzFbpEq829SRXJMFB9wp
oQNlH0UQ01/2sWCIBxPpHuEjxEF/V3Z/F2VsNTy4zvYrd+/MYO3w30F+bWQNZsMHEkTW1pEh
iz7rQPWTBXoO8Fv0wQIDAQABo4IC1DCCAtAwCQYDVR0TBAIwADALBgNVHQ8EBAMCBLAwHQYD
VR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMB0GA1UdDgQWBBTqvKspqEm0E4R1sgsABYKk
6xDJqDAfBgNVHSMEGDAWgBRTcu2SnODaywFcfH6WNU7y1LhRgjAZBgNVHREEEjAQgQ5sdWR3
aWdAc2ljcy5zZTCCAUwGA1UdIASCAUMwggE/MIIBOwYLKwYBBAGBtTcBAgMwggEqMC4GCCsG
AQUFBwIBFiJodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMIH3BggrBgEFBQcC
AjCB6jAnFiBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTADAgEBGoG+VGhpcyBj
ZXJ0aWZpY2F0ZSB3YXMgaXNzdWVkIGFjY29yZGluZyB0byB0aGUgQ2xhc3MgMSBWYWxpZGF0
aW9uIHJlcXVpcmVtZW50cyBvZiB0aGUgU3RhcnRDb20gQ0EgcG9saWN5LCByZWxpYW5jZSBv
bmx5IGZvciB0aGUgaW50ZW5kZWQgcHVycG9zZSBpbiBjb21wbGlhbmNlIG9mIHRoZSByZWx5
aW5nIHBhcnR5IG9ibGlnYXRpb25zLjA2BgNVHR8ELzAtMCugKaAnhiVodHRwOi8vY3JsLnN0
YXJ0c3NsLmNvbS9jcnR1MS1jcmwuY3JsMIGOBggrBgEFBQcBAQSBgTB/MDkGCCsGAQUFBzAB
hi1odHRwOi8vb2NzcC5zdGFydHNzbC5jb20vc3ViL2NsYXNzMS9jbGllbnQvY2EwQgYIKwYB
BQUHMAKGNmh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL3N1Yi5jbGFzczEuY2xpZW50
LmNhLmNydDAjBgNVHRIEHDAahhhodHRwOi8vd3d3LnN0YXJ0c3NsLmNvbS8wDQYJKoZIhvcN
AQEFBQADggEBAGXwFsbSfv4mMWqIk64CoxuR6ozo7J37igca7d9tpKIzVIp6xp7Zt+a+J9X3
1r4zgMRFnZJWQ5hy82W/fVDeG9i3NGMM6p7DNUrGjTbVHd11BQtbUOG9MSlyWKQbmt3Q1ElC
f4SRLAQot5SPryLR2FTxQuFkMOrcDzVxNxnMgatOM2fAO8KS0H+wX+I7gC3pEnbg/eMqNgU+
Ktbc2y9naDNmLNLN65s8TT9xZyoQEn9S1oU8Xnh596OMu49Eccws8Ny+vAGESIHG4bqhMSjj
rmDilL1Wj9nQahmBnID5oZD5g9s9KyqxiZIGNnowYYOpCrSeITZ1b7wg50dC8ySojnYwggY0
MIIEHKADAgECAgEeMA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNVBAYTAklMMRYwFAYDVQQKEw1T
dGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRhbCBDZXJ0aWZpY2F0ZSBTaWdu
aW5nMSkwJwYDVQQDEyBTdGFydENvbSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNzEw
MjQyMTAxNTVaFw0xNzEwMjQyMTAxNTVaMIGMMQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3Rh
cnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlmaWNhdGUgU2lnbmlu
ZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVybWVkaWF0ZSBDbGll
bnQgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDHCYPMzi3YGrEppC4Tq5a+
ijKDjKaIQZZVR63UbxIP6uq/I0fhCu+cQhoUfE6ERKKnu8zPf1Jwuk0tsvVCk6U9b+0UjM0d
Lep3ZdE1gblK/1FwYT5Pipsu2yOMluLqwvsuz9/9f1+1PKHG/FaR/wpbfuIqu54qzHDYeqiU
fsYzoVflR80DAC7hmJ+SmZnNTWyUGHJbBpA8Q89lGxahNvuryGaC/o2/ceD2uYDX9U8Eg5Dp
IpGQdcbQeGarV04WgAUjjXX5r/2dabmtxWMZwhZna//jdiSyrrSMTGKkDiXm6/3/4ebfeZuC
YKzN2P8O2F/Xe2AC/Y7zeEsnR7FOp+uXAgMBAAGjggGtMIIBqTAPBgNVHRMBAf8EBTADAQH/
MA4GA1UdDwEB/wQEAwIBBjAdBgNVHQ4EFgQUU3Ltkpzg2ssBXHx+ljVO8tS4UYIwHwYDVR0j
BBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwZgYIKwYBBQUHAQEEWjBYMCcGCCsGAQUFBzAB
hhtodHRwOi8vb2NzcC5zdGFydHNzbC5jb20vY2EwLQYIKwYBBQUHMAKGIWh0dHA6Ly93d3cu
c3RhcnRzc2wuY29tL3Nmc2NhLmNydDBbBgNVHR8EVDBSMCegJaAjhiFodHRwOi8vd3d3LnN0
YXJ0c3NsLmNvbS9zZnNjYS5jcmwwJ6AloCOGIWh0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3Nm
c2NhLmNybDCBgAYDVR0gBHkwdzB1BgsrBgEEAYG1NwECATBmMC4GCCsGAQUFBwIBFiJodHRw
Oi8vd3d3LnN0YXJ0c3NsLmNvbS9wb2xpY3kucGRmMDQGCCsGAQUFBwIBFihodHRwOi8vd3d3
LnN0YXJ0c3NsLmNvbS9pbnRlcm1lZGlhdGUucGRmMA0GCSqGSIb3DQEBBQUAA4ICAQAKgwh9
eKssBly4Y4xerhy5I3dNoXHYfYa8PlVLL/qtXnkFgdtY1o95CfegFJTwqBBmf8pyTUnFsukD
FUI22zF5bVHzuJ+GxhnSqN2sD1qetbYwBYK2iyYA5Pg7Er1A+hKMIzEzcduRkIMmCeUTyMyi
kfbUFvIBivtvkR8ZFAk22BZy+pJfAoedO61HTz4qSfQoCRcLN5A0t4DkuVhTMXIzuQ8Cnykh
ExD6x4e6ebIbrjZLb7L+ocR0y4YjCl/Pd4MXU91y0vTipgr/O75CDUHDRHCCKBVmz/Rzkc/b
970MEeHt5LC3NiWTgBSvrLEuVzBKM586YoRD9Dy3OHQgWI270g+5MYA8GfgI/EPT5G7xPbCD
z+zjdH89PeR3U4So4lSXur6H6vp+m9TQXPF3a0LwZrp8MQ+Z77U1uL7TelWO5lApsbAonrqA
SfTpaprFVkL4nyGH+NHST2ZJPWIBk81i6Vw0ny0qZW2Niy/QvVNKbb43A43ny076khXO7cNb
BIRdJ/6qQNq9Bqb5C0Q5nEsFcj75oxQRqlKf6TcvGbjxkJh8BYtv9ePsXklAxtm8J7GCUBth
HSQgepbkOexhJ0wP8imUkyiPHQ0GvEnd83129fZjoEhdGwXV27ioRKbj/cIq7JRXun0NbeY+
UdMYu9jGfIpDLtUUGSgsg2zMGs5R4jGCA90wggPZAgEBMIGUMIGMMQswCQYDVQQGEwJJTDEW
MBQGA1UEChMNU3RhcnRDb20gTHRkLjErMCkGA1UECxMiU2VjdXJlIERpZ2l0YWwgQ2VydGlm
aWNhdGUgU2lnbmluZzE4MDYGA1UEAxMvU3RhcnRDb20gQ2xhc3MgMSBQcmltYXJ5IEludGVy
bWVkaWF0ZSBDbGllbnQgQ0ECAwyGmDAJBgUrDgMCGgUAoIICHTAYBgkqhkiG9w0BCQMxCwYJ
KoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNTA2MjkxNjM2NTlaMCMGCSqGSIb3DQEJBDEW
BBRSrUJWKB85xebuM/Wq6F90c8UolzBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjAL
BglghkgBZQMEAQIwCgYIKoZIhvcNAwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFA
MAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMIGlBgkrBgEEAYI3EAQxgZcwgZQwgYwxCzAJBgNV
BAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSswKQYDVQQLEyJTZWN1cmUgRGlnaXRh
bCBDZXJ0aWZpY2F0ZSBTaWduaW5nMTgwNgYDVQQDEy9TdGFydENvbSBDbGFzcyAxIFByaW1h
cnkgSW50ZXJtZWRpYXRlIENsaWVudCBDQQIDDIaYMIGnBgsqhkiG9w0BCRACCzGBl6CBlDCB
jDELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3Vy
ZSBEaWdpdGFsIENlcnRpZmljYXRlIFNpZ25pbmcxODA2BgNVBAMTL1N0YXJ0Q29tIENsYXNz
IDEgUHJpbWFyeSBJbnRlcm1lZGlhdGUgQ2xpZW50IENBAgMMhpgwDQYJKoZIhvcNAQEBBQAE
ggEARJZMdxBPB213eoSRJKSrTDf7+IZwfkd268fG/wphlsEIaXj4/eQNTYMM2AWMIUc65uA+
yu4JIz64Q+PQAGyuNAh8gn0N/t0raX4oOFHKVUXidgfc9soO2J4Gmu27EquwCotOZmnZY0+g
GfF5aJDk326qZ2EeFaAdfmb8vSeZIwLwV2TNRL/sXB2ftFTL9ZoUZmr3D6oM5afxtkEkpTED
H3lJDpZoqWxt6TFRuWpjoV2xNjR6j0owKUNFviKhYUwYfFvyQKl/FX5vt27PycPCZDLp/dye
31lMOTn9lpKt1LQumaUsx2ShV7BLgqZIRpMj4vuy4dpUBElv+tity/dMQQAAAAAAAA==
--------------ms020803040109050105020409--

