
From turners@ieca.com  Wed Jul  3 10:12:18 2013
Return-Path: <turners@ieca.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A4C6611E80C5 for <emu@ietfa.amsl.com>; Wed,  3 Jul 2013 10:12:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.047
X-Spam-Level: 
X-Spam-Status: No, score=-102.047 tagged_above=-999 required=5 tests=[AWL=0.218, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 74QvK1Jzfmvm for <emu@ietfa.amsl.com>; Wed,  3 Jul 2013 10:12:12 -0700 (PDT)
Received: from gateway04.websitewelcome.com (gateway04.websitewelcome.com [67.18.55.5]) by ietfa.amsl.com (Postfix) with ESMTP id 6AFBD11E810C for <emu@ietf.org>; Wed,  3 Jul 2013 10:12:12 -0700 (PDT)
Received: by gateway04.websitewelcome.com (Postfix, from userid 5007) id BAB90A8838025; Wed,  3 Jul 2013 12:11:58 -0500 (CDT)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway04.websitewelcome.com (Postfix) with ESMTP id 9C127A8837F53 for <emu@ietf.org>; Wed,  3 Jul 2013 12:11:58 -0500 (CDT)
Received: from [173.73.135.86] (port=52293 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1UuQbD-0005xO-Dp; Wed, 03 Jul 2013 12:12:11 -0500
Message-ID: <51D45B6A.90200@ieca.com>
Date: Wed, 03 Jul 2013 13:12:10 -0400
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: Sean Turner <turners@ieca.com>, jose@ietf.org
References: <20130703051701.22549.85585.idtracker@ietfa.amsl.com>
In-Reply-To: <20130703051701.22549.85585.idtracker@ietfa.amsl.com>
X-Forwarded-Message-Id: <20130703051701.22549.85585.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [173.73.135.86]:52293
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 1
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
X-Mailman-Approved-At: Tue, 09 Jul 2013 08:19:54 -0700
Subject: [Emu] Fwd: Draft submission deadlines change
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Jul 2013 17:12:18 -0000

In case you're not on the IETF announcement list.

spt
-------- Original Message --------
Subject: Draft submission deadlines change
Date: Tue, 02 Jul 2013 22:17:01 -0700
From: IETF Chair <chair@ietf.org>
Reply-To: ietf@ietf.org
To: IETF Announcement List <ietf-announce@ietf.org>

Please note that for IETF 87, there is only one deadline for draft 
submission: Monday 15th July. Previously, there had been two different 
deadlines, one for -00 and another one for other versions. The IESG has 
decided to experiment with just one deadline for now to simplify the set 
of deadlines and enable easier submission of new drafts. While we 
realise that the change comes near the deadline, we hope that you find 
the extra time useful.

But please do note that working group chairs will continue to make smart 
decisions about what topics are worthwhile for discussing in a session 
in the upcoming meeting, and will also set their agendas in a timely 
manner and create deadlines for their working groups that must be 
adhered to. The earlier new drafts are submitted, the more time there is 
to talk about them on the mailing lists and consider them for the 
session agendas. This is particularly important for BoFs.

Jari Arkko for the IESG




From jsalowey@cisco.com  Wed Jul 10 09:53:58 2013
Return-Path: <jsalowey@cisco.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B70621F9FE2 for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 09:53:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.599
X-Spam-Level: 
X-Spam-Status: No, score=-110.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OOAQeaucDT-K for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 09:53:51 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) by ietfa.amsl.com (Postfix) with ESMTP id CFC5421F9FE4 for <emu@ietf.org>; Wed, 10 Jul 2013 09:53:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3086; q=dns/txt; s=iport; t=1373475224; x=1374684824; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=9wkj+oM10hUSujopZMLYqeQH7JVU+En6tZVBH+38ruA=; b=I6K/D/JFD0KXkZi0fr9BickqrreIgep3eFL/NPoXnf4l2gZxxx0uBYyJ LJyic3GXqiH6J25c5X/zC9JDXgGMnVOIXgkpsc0/wsWpu1WSDv+r/XcF5 4V0ulVItWWeptt3KTv1/JFaAeZH+fkwJW5FNhBPvcVAHB0mv7tqcf/3KJ c=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Ai8FAISQ3VGtJXHB/2dsb2JhbABagwkyTcEcgRMWdIIjAQEBAwEBAQE3NAsFCwIBCCIUECcLJQIEDgUIiAEGDLc9BI8wAjEHgwlsA6khgxGCKA
X-IronPort-AV: E=Sophos;i="4.87,1037,1363132800"; d="scan'208";a="233253457"
Received: from rcdn-core2-6.cisco.com ([173.37.113.193]) by rcdn-iport-4.cisco.com with ESMTP; 10 Jul 2013 16:53:33 +0000
Received: from xhc-rcd-x05.cisco.com (xhc-rcd-x05.cisco.com [173.37.183.79]) by rcdn-core2-6.cisco.com (8.14.5/8.14.5) with ESMTP id r6AGrWGu031487 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 10 Jul 2013 16:53:32 GMT
Received: from xmb-rcd-x09.cisco.com ([169.254.9.220]) by xhc-rcd-x05.cisco.com ([173.37.183.79]) with mapi id 14.02.0318.004; Wed, 10 Jul 2013 11:53:32 -0500
From: "Joseph Salowey (jsalowey)" <jsalowey@cisco.com>
To: Sean Turner <turners@ieca.com>
Thread-Topic: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
Thread-Index: AQHOfY4CudEXs+hOLUi20XvAvNxOPg==
Date: Wed, 10 Jul 2013 16:53:32 +0000
Message-ID: <A95B4818FD85874D8F16607F1AC7C628D39D81@xmb-rcd-x09.cisco.com>
References: <645B00545719594A88ADF4221831FD382BAD1D@xmb-rcd-x14.cisco.com> <51CDBC95.10006@ieca.com>
In-Reply-To: <51CDBC95.10006@ieca.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.33.249.19]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <3A096EC810DD5E4A986946A1427F6624@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Jul 2013 16:53:58 -0000

On Jun 28, 2013, at 9:40 AM, Sean Turner <turners@ieca.com> wrote:

> I trimmed this down to the ones that weren't resolved.  Let me know how t=
hose two items end getting resolved.
>=20
>>> 7) s3.2.2: Paque opaque MUST NOT????  What about the other MUSTs in thi=
s
>>> section?
>> [HZ] Not quite understand what you mean. Please explain.
>=20
> Yeah this one got sent out early ;)  Sorry about that.
>=20
> What I meant to write was please add some text about why there are MUST N=
OTs.  If it's just a MUST NOT to make things easier then you'll get push ba=
ck later but if there's a reason for the MUST NOTs and you include it now i=
t'll smooth the way later.
>=20

[Joe] OK

>>> 8) s3.8.2: Couple of questions:
>>>=20
>>> 8.1) How is the pkcs7/10 encoded; is it encapsulated in an media-type
>>> (i.e., does it include the content-type, etc headers)?  The PKCS#10 is
>>> covered in 4.2.17, but what about the PKCS#7.
>> [HZ] We will look into this and get back you.
>=20
> ack

[Joe]   We will add text that the PKCS#10 and PKCS#7 use binary DER encodin=
g . =20

>=20
>>> 8.5) Need some text about verifying the returned certificate back to an
>>> authorized TA.  Don't want the client to willy-nilly accept the returne=
d
>>>  certificate.
>> [HZ] Good suggestion. Do you have any text to suggest or from EST?
>=20
> I was thinking simply "The peer MUST verify the returned certificate to a=
n authorized Trust Anchor."

[Joe] We have some text about this in 4.2.16, is that sufficient?

>=20
>>> 8.6) Are the CRLs for the issuing CA returned as part of the certs-only
>>> message or will the client use the CRLs from the TLS handshake?  Should
>>> we have some kind of guidance about if the client is going to do this
>>> that it SHOULD pull the CRLs/OCSP responses for the CA?
>> [HZ] We are looking into and will get back to you.
>=20
>=20

[Joe]  I think the current text in 4.2.16 about the TEAP server returning C=
RLs is incorrect.  CRLs for the CA certificates is not done within TEAP, th=
ey may be retrieved after TEAP has completed.    =20

Separately, the TEAP server certificate may be checked against OCSP during =
the handshake, but this does not necessarily have anything to do with the C=
A certificate or the certificates described in this section.=20

>=20
>>> 24) s3.7: Assume this throws off an error?  Is there some kind of catch
>>> all sentence someplace that I missed that says all MUST NOTs result in
>>> an error being thrown?
>> [HZ] What is "this?"
>=20
> This bit:
>=20
> The L
> flag is set to indicate the presence of the four-octet TLS Message
> Length field, and MUST be set for the first fragment of a fragmented
> TLS message or set of messages.  It MUST NOT be present for any other
> message.
>=20
> It's back to providing text about the reason for the MUST NOT.
>=20

[Joe] Error handling is described in section 3.6.x =20


> _______________________________________________
> Emu mailing list
> Emu@ietf.org
> https://www.ietf.org/mailman/listinfo/emu


From internet-drafts@ietf.org  Wed Jul 10 19:49:58 2013
Return-Path: <internet-drafts@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E500111E814C; Wed, 10 Jul 2013 19:49:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.522
X-Spam-Level: 
X-Spam-Status: No, score=-102.522 tagged_above=-999 required=5 tests=[AWL=0.078, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wdMNaRF0IQGw; Wed, 10 Jul 2013 19:49:57 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BF9611E813A; Wed, 10 Jul 2013 19:49:57 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.51.p2
Message-ID: <20130711024957.11711.10421.idtracker@ietfa.amsl.com>
Date: Wed, 10 Jul 2013 19:49:57 -0700
Cc: emu@ietf.org
Subject: [Emu] I-D Action: draft-ietf-emu-crypto-bind-04.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 02:49:58 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the EAP Method Update Working Group of the IE=
TF.

	Title           : EAP Mutual Cryptographic Binding
	Author(s)       : Sam Hartman
                          Margaret Wasserman
                          Dacheng Zhang
	Filename        : draft-ietf-emu-crypto-bind-04.txt
	Pages           : 25
	Date            : 2013-07-10

Abstract:
   As the Extensible Authentication Protocol (EAP) evolves, EAP peers
   rely increasingly on information received from the EAP server.  EAP
   extensions such as channel binding or network posture information are
   often carried in tunnel methods; peers are likely to rely on this
   information.  RFC 3748 is a facility that protects tunnel methods
   against man-in-the-middle attacks.  However, cryptographic binding
   focuses on protecting the server rather than the peer.  This memo
   explores attacks possible when the peer is not protected from man-in-
   the-middle attacks and recommends mutual cryptographic binding, a new
   form of cryptographic binding that protects both peer and server
   along with other mitigations.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-emu-crypto-bind

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-emu-crypto-bind-04

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-emu-crypto-bind-04


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From hartmans@mit.edu  Wed Jul 10 19:51:47 2013
Return-Path: <hartmans@mit.edu>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B55C321F8C20 for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 19:51:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.549
X-Spam-Level: 
X-Spam-Status: No, score=-102.549 tagged_above=-999 required=5 tests=[AWL=0.050, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w81F2KBsgMm8 for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 19:51:42 -0700 (PDT)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) by ietfa.amsl.com (Postfix) with ESMTP id 48F6721F9655 for <emu@ietf.org>; Wed, 10 Jul 2013 19:51:34 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.painless-security.com (Postfix) with ESMTP id 6B5F12018A; Wed, 10 Jul 2013 22:46:48 -0400 (EDT)
Received: from mail.painless-security.com ([127.0.0.1]) by localhost (mail.suchdamage.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 196Kl1CKHg3I; Wed, 10 Jul 2013 22:46:48 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org (c-98-216-0-82.hsd1.ma.comcast.net [98.216.0.82]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS; Wed, 10 Jul 2013 22:46:48 -0400 (EDT)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id A1A6988408; Wed, 10 Jul 2013 22:50:47 -0400 (EDT)
From: Sam Hartman <hartmans-ietf@mit.edu>
To: Sean Turner <turners@ieca.com>
References: <51ADC6C1.9000904@ieca.com> <tsltxkoy83n.fsf@mit.edu> <51C83EAC.3040006@ieca.com>
Date: Wed, 10 Jul 2013 22:50:47 -0400
In-Reply-To: <51C83EAC.3040006@ieca.com> (Sean Turner's message of "Mon, 24 Jun 2013 08:42:20 -0400")
Message-ID: <tsltxk1u7w8.fsf@mit.edu>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Cc: Sam Hartman <hartmans-ietf@mit.edu>, emu@ietf.org
Subject: Re: [Emu] AD review of draft-ietf-emu-crypto-bind-03.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 02:51:47 -0000

I believe the version I just posted addresses the comments.
I did not receive any artwork so I removed the figures.

From hartmans@mit.edu  Wed Jul 10 19:58:44 2013
Return-Path: <hartmans@mit.edu>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A921721F99F8 for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 19:58:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.556
X-Spam-Level: 
X-Spam-Status: No, score=-102.556 tagged_above=-999 required=5 tests=[AWL=0.043, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id moAGMcJuvPO2 for <emu@ietfa.amsl.com>; Wed, 10 Jul 2013 19:58:38 -0700 (PDT)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) by ietfa.amsl.com (Postfix) with ESMTP id D0E6721F97E6 for <emu@ietf.org>; Wed, 10 Jul 2013 19:58:38 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.painless-security.com (Postfix) with ESMTP id 816CB20134; Wed, 10 Jul 2013 22:53:52 -0400 (EDT)
Received: from mail.painless-security.com ([127.0.0.1]) by localhost (mail.suchdamage.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W425XbhpLkcI; Wed, 10 Jul 2013 22:53:51 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org (c-98-216-0-82.hsd1.ma.comcast.net [98.216.0.82]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS; Wed, 10 Jul 2013 22:53:51 -0400 (EDT)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id E919988408; Wed, 10 Jul 2013 22:57:50 -0400 (EDT)
From: Sam Hartman <hartmans-ietf@mit.edu>
To: Sean Turner <turners@ieca.com>
References: <645B00545719594A88ADF4221831FD382BAD1D@xmb-rcd-x14.cisco.com> <51CDBC95.10006@ieca.com>
Date: Wed, 10 Jul 2013 22:57:50 -0400
In-Reply-To: <51CDBC95.10006@ieca.com> (Sean Turner's message of "Fri, 28 Jun 2013 12:40:53 -0400")
Message-ID: <tslppupu7kh.fsf@mit.edu>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 02:58:44 -0000

>>>>> "Sean" == Sean Turner <turners@ieca.com> writes:

    >>> 8.5) Need some text about verifying the returned certificate
    >>> back to an authorized TA.  Don't want the client to willy-nilly
    >>> accept the returned certificate.
    >> [HZ] Good suggestion. Do you have any text to suggest or from
    >> EST?

    Sean> I was thinking simply "The peer MUST verify the returned
    Sean> certificate to an authorized Trust Anchor."

Sorry for a late comment, but I cannot understand why this is desirable.
The peer has already authenticated the TEAP server.
Why does the cert need to chain back to a TA?
Requiring cert validation when it's not needed seems undesirable.
I think this should be a MAY rather than MUST.
Or am I confused and there's some attack I am missing?

From turners@ieca.com  Thu Jul 11 04:31:34 2013
Return-Path: <turners@ieca.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1737111E810D for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 04:31:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.391
X-Spam-Level: 
X-Spam-Status: No, score=-101.391 tagged_above=-999 required=5 tests=[AWL=-0.985, BAYES_20=-0.74, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i4jR+P9sYXgr for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 04:31:27 -0700 (PDT)
Received: from gateway08.websitewelcome.com (gateway08.websitewelcome.com [69.56.212.17]) by ietfa.amsl.com (Postfix) with ESMTP id B26AD11E8109 for <emu@ietf.org>; Thu, 11 Jul 2013 04:31:27 -0700 (PDT)
Received: by gateway08.websitewelcome.com (Postfix, from userid 5007) id EE78CBCADE379; Thu, 11 Jul 2013 06:31:26 -0500 (CDT)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway08.websitewelcome.com (Postfix) with ESMTP id E3158BCADE347 for <emu@ietf.org>; Thu, 11 Jul 2013 06:31:26 -0500 (CDT)
Received: from [74.96.0.204] (port=50481 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1UxF5q-0007aG-NB; Thu, 11 Jul 2013 06:31:26 -0500
Message-ID: <51DE978D.8030806@ieca.com>
Date: Thu, 11 Jul 2013 07:31:25 -0400
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: Sam Hartman <hartmans-ietf@mit.edu>
References: <51ADC6C1.9000904@ieca.com> <tsltxkoy83n.fsf@mit.edu> <51C83EAC.3040006@ieca.com> <tsltxk1u7w8.fsf@mit.edu>
In-Reply-To: <tsltxk1u7w8.fsf@mit.edu>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [74.96.0.204]:50481
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 4
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: emu@ietf.org
Subject: Re: [Emu] AD review of draft-ietf-emu-crypto-bind-03.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 11:31:34 -0000

Hitting the buttons now.

spt

On 7/10/13 10:50 PM, Sam Hartman wrote:
> I believe the version I just posted addresses the comments.
> I did not receive any artwork so I removed the figures.
>

From turners@ieca.com  Thu Jul 11 04:35:38 2013
Return-Path: <turners@ieca.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 60A7D21F9A1F for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 04:35:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.412
X-Spam-Level: 
X-Spam-Status: No, score=-102.412 tagged_above=-999 required=5 tests=[AWL=0.187, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5KT116wV1Va6 for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 04:35:32 -0700 (PDT)
Received: from gateway02.websitewelcome.com (gateway02.websitewelcome.com [74.52.222.226]) by ietfa.amsl.com (Postfix) with ESMTP id 21E0C11E80F3 for <emu@ietf.org>; Thu, 11 Jul 2013 04:35:31 -0700 (PDT)
Received: by gateway02.websitewelcome.com (Postfix, from userid 5007) id CEBAEBC2DC6DF; Thu, 11 Jul 2013 06:35:22 -0500 (CDT)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway02.websitewelcome.com (Postfix) with ESMTP id C2F93BC2DC6B0 for <emu@ietf.org>; Thu, 11 Jul 2013 06:35:22 -0500 (CDT)
Received: from [74.96.0.204] (port=50515 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1UxF9m-0000kw-GD; Thu, 11 Jul 2013 06:35:30 -0500
Message-ID: <51DE9881.5050006@ieca.com>
Date: Thu, 11 Jul 2013 07:35:29 -0400
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: "Joseph Salowey (jsalowey)" <jsalowey@cisco.com>
References: <645B00545719594A88ADF4221831FD382BAD1D@xmb-rcd-x14.cisco.com> <51CDBC95.10006@ieca.com> <A95B4818FD85874D8F16607F1AC7C628D39D81@xmb-rcd-x09.cisco.com>
In-Reply-To: <A95B4818FD85874D8F16607F1AC7C628D39D81@xmb-rcd-x09.cisco.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [74.96.0.204]:50515
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 6
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 11:35:38 -0000

On 7/10/13 12:53 PM, Joseph Salowey (jsalowey) wrote:
>
> On Jun 28, 2013, at 9:40 AM, Sean Turner <turners@ieca.com> wrote:
>
>> I trimmed this down to the ones that weren't resolved.  Let me know how those two items end getting resolved.
>>
>>>> 7) s3.2.2: Paque opaque MUST NOT????  What about the other MUSTs in this
>>>> section?
>>> [HZ] Not quite understand what you mean. Please explain.
>>
>> Yeah this one got sent out early ;)  Sorry about that.
>>
>> What I meant to write was please add some text about why there are MUST NOTs.  If it's just a MUST NOT to make things easier then you'll get push back later but if there's a reason for the MUST NOTs and you include it now it'll smooth the way later.
>>
>
> [Joe] OK
>
>>>> 8) s3.8.2: Couple of questions:
>>>>
>>>> 8.1) How is the pkcs7/10 encoded; is it encapsulated in an media-type
>>>> (i.e., does it include the content-type, etc headers)?  The PKCS#10 is
>>>> covered in 4.2.17, but what about the PKCS#7.
>>> [HZ] We will look into this and get back you.
>>
>> ack
>
> [Joe]   We will add text that the PKCS#10 and PKCS#7 use binary DER encoding .
>
>>
>>>> 8.5) Need some text about verifying the returned certificate back to an
>>>> authorized TA.  Don't want the client to willy-nilly accept the returned
>>>>   certificate.
>>> [HZ] Good suggestion. Do you have any text to suggest or from EST?
>>
>> I was thinking simply "The peer MUST verify the returned certificate to an authorized Trust Anchor."
>
> [Joe] We have some text about this in 4.2.16, is that sufficient?

After further review it seems fine.


>>>> 8.6) Are the CRLs for the issuing CA returned as part of the certs-only
>>>> message or will the client use the CRLs from the TLS handshake?  Should
>>>> we have some kind of guidance about if the client is going to do this
>>>> that it SHOULD pull the CRLs/OCSP responses for the CA?
>>> [HZ] We are looking into and will get back to you.
>>
>>
>
> [Joe]  I think the current text in 4.2.16 about the TEAP server returning CRLs is incorrect.  CRLs for the CA certificates is not done within TEAP, they may be retrieved after TEAP has completed.
>
> Separately, the TEAP server certificate may be checked against OCSP during the handshake, but this does not necessarily have anything to do with the CA certificate or the certificates described in this section.

roger that

>>
>>>> 24) s3.7: Assume this throws off an error?  Is there some kind of catch
>>>> all sentence someplace that I missed that says all MUST NOTs result in
>>>> an error being thrown?
>>> [HZ] What is "this?"
>>
>> This bit:
>>
>> The L
>> flag is set to indicate the presence of the four-octet TLS Message
>> Length field, and MUST be set for the first fragment of a fragmented
>> TLS message or set of messages.  It MUST NOT be present for any other
>> message.
>>
>> It's back to providing text about the reason for the MUST NOT.
>>
>
> [Joe] Error handling is described in section 3.6.x

ack

looking forward to the next version.

spt

From turners@ieca.com  Thu Jul 11 05:02:04 2013
Return-Path: <turners@ieca.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DDE3E21F977A for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 05:02:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.258
X-Spam-Level: 
X-Spam-Status: No, score=-102.258 tagged_above=-999 required=5 tests=[AWL=0.007, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id veh7L6rR++yk for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 05:01:58 -0700 (PDT)
Received: from gateway05.websitewelcome.com (gateway05.websitewelcome.com [67.18.1.3]) by ietfa.amsl.com (Postfix) with ESMTP id ADD1821F9F58 for <emu@ietf.org>; Thu, 11 Jul 2013 05:01:58 -0700 (PDT)
Received: by gateway05.websitewelcome.com (Postfix, from userid 5007) id 099F9CC5C6D3D; Thu, 11 Jul 2013 07:01:56 -0500 (CDT)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway05.websitewelcome.com (Postfix) with ESMTP id EF8DFCC5C6CE9 for <emu@ietf.org>; Thu, 11 Jul 2013 07:01:55 -0500 (CDT)
Received: from [74.96.0.204] (port=50538 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1UxFZL-0003Dv-NT; Thu, 11 Jul 2013 07:01:55 -0500
Message-ID: <51DE9EB2.2060205@ieca.com>
Date: Thu, 11 Jul 2013 08:01:54 -0400
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: Sam Hartman <hartmans-ietf@mit.edu>
References: <645B00545719594A88ADF4221831FD382BAD1D@xmb-rcd-x14.cisco.com> <51CDBC95.10006@ieca.com> <tslppupu7kh.fsf@mit.edu>
In-Reply-To: <tslppupu7kh.fsf@mit.edu>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [74.96.0.204]:50538
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 1
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 12:02:05 -0000

On 7/10/13 10:57 PM, Sam Hartman wrote:
>>>>>> "Sean" == Sean Turner <turners@ieca.com> writes:
>
>      >>> 8.5) Need some text about verifying the returned certificate
>      >>> back to an authorized TA.  Don't want the client to willy-nilly
>      >>> accept the returned certificate.
>      >> [HZ] Good suggestion. Do you have any text to suggest or from
>      >> EST?
>
>      Sean> I was thinking simply "The peer MUST verify the returned
>      Sean> certificate to an authorized Trust Anchor."
>
> Sorry for a late comment, but I cannot understand why this is desirable.
> The peer has already authenticated the TEAP server.
> Why does the cert need to chain back to a TA?
> Requiring cert validation when it's not needed seems undesirable.
> I think this should be a MAY rather than MUST.
> Or am I confused and there's some attack I am missing?

The certificate here is one that is new provisioned.  If a client is 
given a certificate that it will use to sign and or encrypt and it 
cannot validate that back to an installed TA, then it seems like maybe 
there's something wrong?  At least, that's where I was going.  After 
re-reading it, I think they're good with the text they've got.

spt

spt

From hartmans@mit.edu  Thu Jul 11 05:45:03 2013
Return-Path: <hartmans@mit.edu>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3032111E8159 for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 05:45:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.562
X-Spam-Level: 
X-Spam-Status: No, score=-102.562 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id szSYZxRG7D6c for <emu@ietfa.amsl.com>; Thu, 11 Jul 2013 05:44:49 -0700 (PDT)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) by ietfa.amsl.com (Postfix) with ESMTP id A0D4D11E811A for <emu@ietf.org>; Thu, 11 Jul 2013 05:44:48 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mail.painless-security.com (Postfix) with ESMTP id 7B1772010D; Thu, 11 Jul 2013 08:40:00 -0400 (EDT)
Received: from mail.painless-security.com ([127.0.0.1]) by localhost (mail.suchdamage.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5bfmfFBwInOM; Thu, 11 Jul 2013 08:39:59 -0400 (EDT)
Received: from carter-zimmerman.suchdamage.org (c-98-216-0-82.hsd1.ma.comcast.net [98.216.0.82]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS; Thu, 11 Jul 2013 08:39:59 -0400 (EDT)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id 6661080AE9; Thu, 11 Jul 2013 08:43:59 -0400 (EDT)
From: Sam Hartman <hartmans-ietf@mit.edu>
To: Sean Turner <turners@ieca.com>
References: <645B00545719594A88ADF4221831FD382BAD1D@xmb-rcd-x14.cisco.com> <51CDBC95.10006@ieca.com> <tslppupu7kh.fsf@mit.edu> <51DE9EB2.2060205@ieca.com>
Date: Thu, 11 Jul 2013 08:43:59 -0400
In-Reply-To: <51DE9EB2.2060205@ieca.com> (Sean Turner's message of "Thu, 11 Jul 2013 08:01:54 -0400")
Message-ID: <tslzjtts1v4.fsf@mit.edu>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.4 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Cc: Sam Hartman <hartmans-ietf@mit.edu>, "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] AD review of draft-ietf-emu-eap-tunnel-method
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 12:45:03 -0000

>>>>> "Sean" == Sean Turner <turners@ieca.com> writes:

    Sean> On 7/10/13 10:57 PM, Sam Hartman wrote:
    >>>>>>> "Sean" == Sean Turner <turners@ieca.com> writes:
    >> 
    >> >>> 8.5) Need some text about verifying the returned certificate
    >> >>> back to an authorized TA.  Don't want the client to
    >> willy-nilly >>> accept the returned certificate.  >> [HZ] Good
    >> suggestion. Do you have any text to suggest or from >> EST?
    >> 
    Sean> I was thinking simply "The peer MUST verify the returned
    Sean> certificate to an authorized Trust Anchor."
    >> 
    >> Sorry for a late comment, but I cannot understand why this is
    >> desirable.  The peer has already authenticated the TEAP server.
    >> Why does the cert need to chain back to a TA?  Requiring cert
    >> validation when it's not needed seems undesirable.  I think this
    >> should be a MAY rather than MUST.  Or am I confused and there's
    >> some attack I am missing?

    Sean> The certificate here is one that is new provisioned.  If a
    Sean> client is given a certificate that it will use to sign and or
    Sean> encrypt and it cannot validate that back to an installed TA,
    Sean> then it seems like maybe there's something wrong?  At least,
    Sean> that's where I was going.  After re-reading it, I think
    Sean> they're good with the text they've got.

OK.  If I'm remembering correctly this is a cert I might use for EAP
authentication; I guess I could use it for other purposes although is
somewhat unspecified.

If you require TA validation, then you require that I keep my clients in
sync with my EAP server's idea of what trust anchors it trusts.  It may
want to use an online CA that's less trusted than the offline CA I use
for EAP server certificates, etc, so there's no reason to assume that
just because I can validate the server cert I can validate the newly
issued client certificate.

If I'm using EAP because it's a convenient way to do authenticated cert
provisioning, then I may well have some other mechanism like AD group
policy to push out trust anchors.

However if I'm using EAP because this is a new machine that is first
appearing on the network, I probably don't have a good opportunity to
push out new trust anchors.  Although, hmm, I had to either push out a
fingerprint of the EAP server cert or push out a trust anchor for that.

So, I don't think TA validation is necessary, but given that you need to
provision for the server cert, I don't think it creates significant
deployment problems either.
So, I don't really care one way or the other.

From iesg-secretary@ietf.org  Thu Jul 11 06:22:04 2013
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81A4611E812E; Thu, 11 Jul 2013 06:22:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.477
X-Spam-Level: 
X-Spam-Status: No, score=-102.477 tagged_above=-999 required=5 tests=[AWL=0.123, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id quYoYk+ElB-L; Thu, 11 Jul 2013 06:22:02 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7046E21F9C05; Thu, 11 Jul 2013 06:22:02 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 4.51.p2
Sender: <iesg-secretary@ietf.org>
Message-ID: <20130711132158.24163.16922.idtracker@ietfa.amsl.com>
Date: Thu, 11 Jul 2013 06:21:58 -0700
Cc: emu@ietf.org
Subject: [Emu] Last Call: <draft-ietf-emu-crypto-bind-04.txt> (EAP Mutual	Cryptographic Binding) to Informational RFC
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: ietf@ietf.org
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jul 2013 13:22:04 -0000

The IESG has received a request from the EAP Method Update WG (emu) to
consider the following document:
- 'EAP Mutual Cryptographic Binding'
  <draft-ietf-emu-crypto-bind-04.txt> as Informational RFC

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2013-07-25. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

Abstract


   As the Extensible Authentication Protocol (EAP) evolves, EAP peers
   rely increasingly on information received from the EAP server.  EAP
   extensions such as channel binding or network posture information are
   often carried in tunnel methods; peers are likely to rely on this
   information.  RFC 3748 is a facility that protects tunnel methods
   against man-in-the-middle attacks.  However, cryptographic binding
   focuses on protecting the server rather than the peer.  This memo
   explores attacks possible when the peer is not protected from man-in-
   the-middle attacks and recommends mutual cryptographic binding, a new
   form of cryptographic binding that protects both peer and server
   along with other mitigations.




The file can be obtained via
http://datatracker.ietf.org/doc/draft-ietf-emu-crypto-bind/

IESG discussion can be tracked via
http://datatracker.ietf.org/doc/draft-ietf-emu-crypto-bind/ballot/


No IPR declarations have been submitted directly on this I-D.



From internet-drafts@ietf.org  Sun Jul 14 20:54:35 2013
Return-Path: <internet-drafts@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 071D121F9C85; Sun, 14 Jul 2013 20:54:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.539
X-Spam-Level: 
X-Spam-Status: No, score=-102.539 tagged_above=-999 required=5 tests=[AWL=0.061, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MmlC6iSaGjZb; Sun, 14 Jul 2013 20:54:34 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C0A721F89C3; Sun, 14 Jul 2013 20:54:34 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.51.p2
Message-ID: <20130715035434.15145.89400.idtracker@ietfa.amsl.com>
Date: Sun, 14 Jul 2013 20:54:34 -0700
Cc: emu@ietf.org
Subject: [Emu] I-D Action: draft-ietf-emu-eap-tunnel-method-07.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Jul 2013 03:54:35 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the EAP Method Update Working Group of the IE=
TF.

	Title           : Tunnel EAP Method (TEAP) Version 1
	Author(s)       : Hao Zhou
                          Nancy Cam-Winget
                          Joseph Salowey
                          Stephen Hanna
	Filename        : draft-ietf-emu-eap-tunnel-method-07.txt
	Pages           : 105
	Date            : 2013-07-14

Abstract:
   This document defines the Tunnel Extensible Authentication Protocol
   (TEAP) version 1.  TEAP is a tunnel based EAP method that enables
   secure communication between a peer and a server by using the
   Transport Layer Security (TLS) protocol to establish a mutually
   authenticated tunnel.  Within the tunnel, Type-Length-Value (TLV)
   objects are used to convey authentication related data between the
   EAP peer and the EAP server.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-emu-eap-tunnel-method-07

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-emu-eap-tunnel-method-07


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From iesg-secretary@ietf.org  Tue Jul 16 07:19:51 2013
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D759321F9E94; Tue, 16 Jul 2013 07:19:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.495
X-Spam-Level: 
X-Spam-Status: No, score=-102.495 tagged_above=-999 required=5 tests=[AWL=0.105, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WN7yQj5yatqt; Tue, 16 Jul 2013 07:19:51 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 546A021F9CAC; Tue, 16 Jul 2013 07:19:51 -0700 (PDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 4.51.p2
Sender: <iesg-secretary@ietf.org>
Message-ID: <20130716141951.26241.35307.idtracker@ietfa.amsl.com>
Date: Tue, 16 Jul 2013 07:19:51 -0700
Cc: emu@ietf.org
Subject: [Emu] Last Call: <draft-ietf-emu-eap-tunnel-method-07.txt> (Tunnel EAP	Method (TEAP) Version 1) to Proposed Standard
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: ietf@ietf.org
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Jul 2013 14:19:52 -0000

The IESG has received a request from the EAP Method Update WG (emu) to
consider the following document:
- 'Tunnel EAP Method (TEAP) Version 1'
  <draft-ietf-emu-eap-tunnel-method-07.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2013-07-30. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

Abstract


   This document defines the Tunnel Extensible Authentication Protocol
   (TEAP) version 1.  TEAP is a tunnel based EAP method that enables
   secure communication between a peer and a server by using the
   Transport Layer Security (TLS) protocol to establish a mutually
   authenticated tunnel.  Within the tunnel, Type-Length-Value (TLV)
   objects are used to convey authentication related data between the
   EAP peer and the EAP server.




The file can be obtained via
http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/

IESG discussion can be tracked via
http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/ballot/


The following IPR Declarations may be related to this I-D:

   http://datatracker.ietf.org/ipr/1902/




From ietf-secretariat-reply@ietf.org  Mon Jul 22 15:04:53 2013
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B58C221F99F6 for <emu@ietfa.amsl.com>; Mon, 22 Jul 2013 15:04:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.974
X-Spam-Level: 
X-Spam-Status: No, score=-101.974 tagged_above=-999 required=5 tests=[AWL=0.626, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id w6z2JHfeI2E3; Mon, 22 Jul 2013 15:04:53 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 47B5621F9814; Mon, 22 Jul 2013 15:04:53 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
To: emu-chairs@tools.ietf.org, draft-ietf-emu-eap-tunnel-method@tools.ietf.org, emu@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.53
Message-ID: <20130722220453.5331.46258.idtracker@ietfa.amsl.com>
Date: Mon, 22 Jul 2013 15:04:53 -0700
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
X-Mailman-Approved-At: Mon, 22 Jul 2013 15:32:13 -0700
Subject: [Emu] ID Tracker State Update Notice:	<draft-ietf-emu-eap-tunnel-method-07.txt>
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jul 2013 22:04:53 -0000

IANA review state changed to IANA - Not OK
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-m=
ethod/


From ietf-secretariat-reply@ietf.org  Tue Jul 23 19:53:55 2013
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6FF6811E81CA for <emu@ietfa.amsl.com>; Tue, 23 Jul 2013 19:53:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.428
X-Spam-Level: 
X-Spam-Status: No, score=-102.428 tagged_above=-999 required=5 tests=[AWL=0.172, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PK+P3ssb5lyj; Tue, 23 Jul 2013 19:53:55 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F8CA11E81C0; Tue, 23 Jul 2013 19:53:55 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
To: emu-chairs@tools.ietf.org, draft-ietf-emu-eap-tunnel-method@tools.ietf.org, emu@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.60p1
Message-ID: <20130724025355.29837.84409.idtracker@ietfa.amsl.com>
Date: Tue, 23 Jul 2013 19:53:55 -0700
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Subject: [Emu] ID Tracker State Update Notice:	<draft-ietf-emu-eap-tunnel-method-07.txt>
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2013 02:53:55 -0000

IANA review state changed to IANA OK - Actions Needed
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-m=
ethod/


From iesg-secretary@ietf.org  Thu Jul 25 00:10:01 2013
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D92221F9A0C; Thu, 25 Jul 2013 00:10:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.453
X-Spam-Level: 
X-Spam-Status: No, score=-102.453 tagged_above=-999 required=5 tests=[AWL=0.147, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AFF-l+uEGHWn; Thu, 25 Jul 2013 00:10:01 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 094AA21F99A0; Thu, 25 Jul 2013 00:10:01 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: DraftTracker Mail System <iesg-secretary@ietf.org>
To: iesg@ietf.org, emu-chairs@tools.ietf.org, draft-ietf-emu-crypto-bind@tools.ietf.org, emu@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.60p1
Message-ID: <20130725071000.17436.52213.idtracker@ietfa.amsl.com>
Date: Thu, 25 Jul 2013 00:10:00 -0700
Cc: iesg-secretary@ietf.org
Subject: [Emu] Last Call Expired: <draft-ietf-emu-crypto-bind-04.txt>
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2013 07:10:01 -0000

Please DO NOT reply to this email.

I-D: <draft-ietf-emu-crypto-bind-04.txt>
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-emu-crypto-bind/

IETF Last Call has ended, and the state has been changed to
Waiting for AD Go-Ahead.


From Josh.Howlett@ja.net  Thu Jul 25 06:27:05 2013
Return-Path: <Josh.Howlett@ja.net>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0EE7F21F9AFE; Thu, 25 Jul 2013 06:27:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0DrUoeoljHjo; Thu, 25 Jul 2013 06:26:59 -0700 (PDT)
Received: from egw001.ukerna.ac.uk (egw001.ukerna.ac.uk [194.82.140.74]) by ietfa.amsl.com (Postfix) with ESMTP id 188E821F9AFA; Thu, 25 Jul 2013 06:26:58 -0700 (PDT)
Received: from egw001.ukerna.ac.uk (localhost.localdomain [127.0.0.1]) by localhost (Email Security Appliance) with SMTP id 9CD2E1AC595A_1F127A1B; Thu, 25 Jul 2013 13:26:57 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk (exc001.atlas.ukerna.ac.uk [193.62.83.37]) by egw001.ukerna.ac.uk (Sophos Email Appliance) with ESMTP id 5AC1E1AC5959_1F127A1F; Thu, 25 Jul 2013 13:26:57 +0000 (GMT)
Received: from EXC001.atlas.ukerna.ac.uk ([193.62.83.37]) by EXC001 ([193.62.83.37]) with mapi id 14.02.0247.003; Thu, 25 Jul 2013 14:26:56 +0100
From: Josh Howlett <Josh.Howlett@ja.net>
To: "ietf@ietf.org" <ietf@ietf.org>
Thread-Topic: [Emu] Last Call: <draft-ietf-emu-eap-tunnel-method-07.txt> (Tunnel EAP Method (TEAP) Version 1) to Proposed Standard
Thread-Index: AQHOiTqho2f1WzAyiUaQlrNJcTfyFQ==
Date: Thu, 25 Jul 2013 13:26:55 +0000
Message-ID: <CE16DCB4.22F46%Josh.Howlett@ja.net>
In-Reply-To: <20130716141951.26241.35307.idtracker@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.3.6.130613
x-originating-ip: [194.82.140.76]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <55201231F1AD6242A0CF31AFD074FD77@ukerna.ac.uk>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] Last Call: <draft-ietf-emu-eap-tunnel-method-07.txt> (Tunnel EAP Method (TEAP) Version 1) to Proposed Standard
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2013 13:27:05 -0000

Section 3.2 of draft-wierenga-ietf-eduroam describes the issues presented
by EAP's spartan support for error condition handling. Although these are
described in the context of a particular roaming operator's experiences, I
believe this is also likely to be true for other non-trivial deployments.

To its credit this document (draft-ietf-emu-eap-tunnel-method) does
address error handling more comprehensively than previous EAP methods, but
I am not confident that it will yield error handling outcomes that could
be understood and corrected by an end user. For example, from my
understanding of the document, the most common failure modes (e.g.,
incorrect password; account locked; backend database offline, etc) will
all yield an "Inner_Method_Error". The other error messages are equally
vague ("General_PKI_Error") or cryptic from an end user's perspective.

Is this something that could be discussed in Berlin next week?

Josh.

On 16/07/2013 15:19, "The IESG" <iesg-secretary@ietf.org> wrote:

>
>The IESG has received a request from the EAP Method Update WG (emu) to
>consider the following document:
>- 'Tunnel EAP Method (TEAP) Version 1'
>  <draft-ietf-emu-eap-tunnel-method-07.txt> as Proposed Standard
>
>The IESG plans to make a decision in the next few weeks, and solicits
>final comments on this action. Please send substantive comments to the
>ietf@ietf.org mailing lists by 2013-07-30. Exceptionally, comments may be
>sent to iesg@ietf.org instead. In either case, please retain the
>beginning of the Subject line to allow automated sorting.
>
>Abstract
>
>
>   This document defines the Tunnel Extensible Authentication Protocol
>   (TEAP) version 1.  TEAP is a tunnel based EAP method that enables
>   secure communication between a peer and a server by using the
>   Transport Layer Security (TLS) protocol to establish a mutually
>   authenticated tunnel.  Within the tunnel, Type-Length-Value (TLV)
>   objects are used to convey authentication related data between the
>   EAP peer and the EAP server.
>
>
>
>
>The file can be obtained via
>http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/
>
>IESG discussion can be tracked via
>http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/ballot/
>
>
>The following IPR Declarations may be related to this I-D:
>
>   http://datatracker.ietf.org/ipr/1902/
>
>
>
>_______________________________________________
>Emu mailing list
>Emu@ietf.org
>https://www.ietf.org/mailman/listinfo/emu


Janet(UK) is a trading name of Jisc Collections and Janet Limited, a=20
not-for-profit company which is registered in England under No. 2881024=20
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238


From jsalowey@cisco.com  Thu Jul 25 09:07:47 2013
Return-Path: <jsalowey@cisco.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10FF121F84D9; Thu, 25 Jul 2013 09:07:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.599
X-Spam-Level: 
X-Spam-Status: No, score=-110.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1aMCuAFFERSJ; Thu, 25 Jul 2013 09:07:42 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) by ietfa.amsl.com (Postfix) with ESMTP id EEE5121F84E3; Thu, 25 Jul 2013 09:07:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3271; q=dns/txt; s=iport; t=1374768462; x=1375978062; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=1ncK8hSQ2QLE2uRb5yw9BMPjKAY1V1gKkWiLMb32FWs=; b=b1j/JZYolf2vo0KuopK853JZnrYg9JIst/AI9oXJfMHvzOsyyJAYiLlH ah/vHdWi5pQECWlcwTKS2sgDWzZrs5iSfeL9F8FlT8kTsEB0BqfvtT/yK oRSbgUwCN2btigxf2C6ysHA3myEMoe99c2Fea4DPhmbwDJIUB6kW7QIq6 o=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhMFAH5M8VGtJV2d/2dsb2JhbABSCIMGNVC9XYEWFnSCJAEBAQMBAQEBNzQLBQsCAQgYCgsDBgULJwslAgQOBQiIAgYMuVmOSAKBAAIxBwoOgnpuA5kIkCSBW4E5gWhC
X-IronPort-AV: E=Sophos;i="4.89,744,1367971200"; d="scan'208";a="239245149"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-1.cisco.com with ESMTP; 25 Jul 2013 16:07:41 +0000
Received: from xhc-aln-x01.cisco.com (xhc-aln-x01.cisco.com [173.36.12.75]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id r6PG7fiu029955 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Thu, 25 Jul 2013 16:07:41 GMT
Received: from xmb-rcd-x09.cisco.com ([169.254.9.235]) by xhc-aln-x01.cisco.com ([173.36.12.75]) with mapi id 14.02.0318.004; Thu, 25 Jul 2013 11:07:41 -0500
From: "Joseph Salowey (jsalowey)" <jsalowey@cisco.com>
To: Josh Howlett <Josh.Howlett@ja.net>
Thread-Topic: [Emu] Last Call: <draft-ietf-emu-eap-tunnel-method-07.txt> (Tunnel EAP Method (TEAP) Version 1) to Proposed Standard
Thread-Index: AQHOiTqho2f1WzAyiUaQlrNJcTfyFZl144eA
Date: Thu, 25 Jul 2013 16:07:40 +0000
Message-ID: <A95B4818FD85874D8F16607F1AC7C628D856D1@xmb-rcd-x09.cisco.com>
References: <CE16DCB4.22F46%Josh.Howlett@ja.net>
In-Reply-To: <CE16DCB4.22F46%Josh.Howlett@ja.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.33.249.159]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <8ADA0080ED726B458C1AAADA932B4DED@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "ietf@ietf.org" <ietf@ietf.org>, "emu@ietf.org" <emu@ietf.org>
Subject: Re: [Emu] Last Call: <draft-ietf-emu-eap-tunnel-method-07.txt> (Tunnel EAP Method (TEAP) Version 1) to Proposed Standard
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2013 16:07:47 -0000

Yes, this document is the main thing on the agenda.=20
On Jul 25, 2013, at 6:26 AM, Josh Howlett <Josh.Howlett@ja.net>
 wrote:

> Section 3.2 of draft-wierenga-ietf-eduroam describes the issues presented
> by EAP's spartan support for error condition handling. Although these are
> described in the context of a particular roaming operator's experiences, =
I
> believe this is also likely to be true for other non-trivial deployments.
>=20
> To its credit this document (draft-ietf-emu-eap-tunnel-method) does
> address error handling more comprehensively than previous EAP methods, bu=
t
> I am not confident that it will yield error handling outcomes that could
> be understood and corrected by an end user. For example, from my
> understanding of the document, the most common failure modes (e.g.,
> incorrect password; account locked; backend database offline, etc) will
> all yield an "Inner_Method_Error". The other error messages are equally
> vague ("General_PKI_Error") or cryptic from an end user's perspective.
>=20
> Is this something that could be discussed in Berlin next week?
>=20
> Josh.
>=20
> On 16/07/2013 15:19, "The IESG" <iesg-secretary@ietf.org> wrote:
>=20
>>=20
>> The IESG has received a request from the EAP Method Update WG (emu) to
>> consider the following document:
>> - 'Tunnel EAP Method (TEAP) Version 1'
>> <draft-ietf-emu-eap-tunnel-method-07.txt> as Proposed Standard
>>=20
>> The IESG plans to make a decision in the next few weeks, and solicits
>> final comments on this action. Please send substantive comments to the
>> ietf@ietf.org mailing lists by 2013-07-30. Exceptionally, comments may b=
e
>> sent to iesg@ietf.org instead. In either case, please retain the
>> beginning of the Subject line to allow automated sorting.
>>=20
>> Abstract
>>=20
>>=20
>>  This document defines the Tunnel Extensible Authentication Protocol
>>  (TEAP) version 1.  TEAP is a tunnel based EAP method that enables
>>  secure communication between a peer and a server by using the
>>  Transport Layer Security (TLS) protocol to establish a mutually
>>  authenticated tunnel.  Within the tunnel, Type-Length-Value (TLV)
>>  objects are used to convey authentication related data between the
>>  EAP peer and the EAP server.
>>=20
>>=20
>>=20
>>=20
>> The file can be obtained via
>> http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/
>>=20
>> IESG discussion can be tracked via
>> http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-method/ballot/
>>=20
>>=20
>> The following IPR Declarations may be related to this I-D:
>>=20
>>  http://datatracker.ietf.org/ipr/1902/
>>=20
>>=20
>>=20
>> _______________________________________________
>> Emu mailing list
>> Emu@ietf.org
>> https://www.ietf.org/mailman/listinfo/emu
>=20
>=20
> Janet(UK) is a trading name of Jisc Collections and Janet Limited, a=20
> not-for-profit company which is registered in England under No. 2881024=20
> and whose Registered Office is at Lumen House, Library Avenue,
> Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238
>=20
> _______________________________________________
> Emu mailing list
> Emu@ietf.org
> https://www.ietf.org/mailman/listinfo/emu


From turners@ieca.com  Sun Jul 28 02:20:16 2013
Return-Path: <turners@ieca.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E761B21F9C72 for <emu@ietfa.amsl.com>; Sun, 28 Jul 2013 02:20:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.748
X-Spam-Level: 
X-Spam-Status: No, score=-100.748 tagged_above=-999 required=5 tests=[AWL=-0.897, BAYES_40=-0.185, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qMPbIzwB--yx for <emu@ietfa.amsl.com>; Sun, 28 Jul 2013 02:20:09 -0700 (PDT)
Received: from gateway09.websitewelcome.com (gateway09.websitewelcome.com [67.18.10.7]) by ietfa.amsl.com (Postfix) with ESMTP id A7EA421F9C70 for <emu@ietf.org>; Sun, 28 Jul 2013 02:20:09 -0700 (PDT)
Received: by gateway09.websitewelcome.com (Postfix, from userid 507) id A52F3D64074E0; Sun, 28 Jul 2013 04:19:21 -0500 (CDT)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway09.websitewelcome.com (Postfix) with ESMTP id 72820D640748D for <emu@ietf.org>; Sun, 28 Jul 2013 04:19:21 -0500 (CDT)
Received: from [198.180.150.142] (port=49845 helo=dhcp-119e.meeting.ietf.org) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1V3N94-0000rX-WD for emu@ietf.org; Sun, 28 Jul 2013 04:20:07 -0500
Message-ID: <51F4E245.6050501@ieca.com>
Date: Sun, 28 Jul 2013 11:20:05 +0200
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
MIME-Version: 1.0
To: emu@ietf.org
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (dhcp-119e.meeting.ietf.org) [198.180.150.142]:49845
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 1
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Subject: [Emu] heads up
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 Jul 2013 09:20:16 -0000

Just wanted to let the wg know that I've added the wg to the send 
notices to field in the datatracker for the remaining two wg drafts. 
What that means is that the WG will get copied on the status changes and 
ballot positions as well as the emails to resolve the ballot positions. 
  The purpose is to make sure the WG is more aware of the IESG 
discusses/comments.  Let me know if you think this is helpful or not.

spt

From iesg-secretary@ietf.org  Tue Jul 30 00:09:56 2013
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1469F21E80B7; Tue, 30 Jul 2013 00:09:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.504
X-Spam-Level: 
X-Spam-Status: No, score=-102.504 tagged_above=-999 required=5 tests=[AWL=0.096, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mRjR2hrussV5; Tue, 30 Jul 2013 00:09:55 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B2DFC11E81BC; Tue, 30 Jul 2013 00:09:54 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: DraftTracker Mail System <iesg-secretary@ietf.org>
To: iesg@ietf.org, emu-chairs@tools.ietf.org, draft-ietf-emu-eap-tunnel-method@tools.ietf.org, emu@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.60p1
Message-ID: <20130730070954.10760.87776.idtracker@ietfa.amsl.com>
Date: Tue, 30 Jul 2013 00:09:54 -0700
Cc: iesg-secretary@ietf.org
Subject: [Emu] Last Call Expired: <draft-ietf-emu-eap-tunnel-method-07.txt>
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/emu>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Jul 2013 07:09:56 -0000

Please DO NOT reply to this email.

I-D: <draft-ietf-emu-eap-tunnel-method-07.txt>
ID Tracker URL: http://datatracker.ietf.org/doc/draft-ietf-emu-eap-tunnel-m=
ethod/

IETF Last Call has ended, and the state has been changed to
Waiting for AD Go-Ahead.

