
From nobody Sat Dec  9 16:39:06 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 88A36127286; Sat,  9 Dec 2017 16:39:01 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151286634151.21988.5888087854745819212@ietfa.amsl.com>
Date: Sat, 09 Dec 2017 16:39:01 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/qwLe0xd_be3UyhiFRmIKlnu37Sw>
Subject: [stir] I-D Action: draft-ietf-stir-certificates-16.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Dec 2017 00:39:01 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Secure Telephone Identity Revisited WG of the IETF.

        Title           : Secure Telephone Identity Credentials: Certificates
        Authors         : Jon Peterson
                          Sean Turner
	Filename        : draft-ietf-stir-certificates-16.txt
	Pages           : 22
	Date            : 2017-12-09

Abstract:
   In order to prevent the impersonation of telephone numbers on the
   Internet, some kind of credential system needs to exist that
   cryptographically asserts authority over telephone numbers.  This
   document describes the use of certificates in establishing authority
   over telephone numbers, as a component of a broader architecture for
   managing telephone numbers as identities in protocols like SIP.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-stir-certificates-16
https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-16

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-stir-certificates-16


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Sat Dec  9 16:40:31 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B231127005 for <stir@ietfa.amsl.com>; Sat,  9 Dec 2017 16:40:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 16G8pNS8h7gP for <stir@ietfa.amsl.com>; Sat,  9 Dec 2017 16:40:21 -0800 (PST)
Received: from mail-qk0-x229.google.com (mail-qk0-x229.google.com [IPv6:2607:f8b0:400d:c09::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D0AD127337 for <stir@ietf.org>; Sat,  9 Dec 2017 16:40:21 -0800 (PST)
Received: by mail-qk0-x229.google.com with SMTP id 84so3151774qks.8 for <stir@ietf.org>; Sat, 09 Dec 2017 16:40:21 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=3+ChWsBBmfJ/X40v9A2bVSx/m74U6FvZzE7l10vqPCU=; b=EnwpfrEzpuB68DJjGkC14Z0Tkcr0yEXfNe5Zb4NCWGKmHGulplnt554OUTXonD2+c7 +ea+WienULefF4BCeq/1BW68LeNP40jtWKSdxa7VS8it/xDzDqLrNJtqfqaXouE8vxj6 RLsvG1e6pFvexTCYtO33fC+9Xl81zl2SFvUn0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=3+ChWsBBmfJ/X40v9A2bVSx/m74U6FvZzE7l10vqPCU=; b=mdqk+V6BbafwL5orrAZ9EZf+0CdjykaNjW6s+GDNlrU5ip+eNl7m510gc/4BMftWm8 tw0jpgOn7DLO+Hu62yHmvuCuw2fLjbJmGyoPPhaeYJzPudh/v7Ux7csVvsNdRnEdwvt1 rml1IX0GBHLz9gqpvrMjjBGSTkSdIEli/6gaUOg9n4fwVh/oywWDVc8NBiz7lHXAasc2 D/gQeiyB/l/ULhHRHnO1VAbVlLMZHLnY2SVTyQmLjXjjSJiJSIjKCDaYs+sNN7IKEV6D 5nPeY54MZJKdjTGHDsKmFVLiVNaiqkS8EGH2Af6H7QOo1BVjmDf7Bew7BscA2sxtPLOe K62w==
X-Gm-Message-State: AKGB3mK02OM7Gp54FBYzYT5tKL8vsryTcpwzCjQSGeDz07yWFuP10Pw6 gesBPbO4cIlgXV+XkvrMLY7Yf6vt1GA=
X-Google-Smtp-Source: AGs4zMZhxhkAwZ/lRNeQgpd9OEMvPD85WWo6W0G5OKfDLz8wkFnhWfU0JvjEj9aDxRjj9NFupltSXA==
X-Received: by 10.55.6.133 with SMTP id 127mr40245999qkg.219.1512866420051; Sat, 09 Dec 2017 16:40:20 -0800 (PST)
Received: from [172.16.0.18] ([96.231.220.27]) by smtp.gmail.com with ESMTPSA id m22sm2203137qtf.85.2017.12.09.16.40.19 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 09 Dec 2017 16:40:19 -0800 (PST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <151286634151.21988.5888087854745819212@ietfa.amsl.com>
Date: Sat, 9 Dec 2017 19:40:17 -0500
Cc: The IESG <iesg@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <7E4BB0F8-304E-4EDD-B66B-08E54FCE13E5@sn3rd.com>
References: <151286634151.21988.5888087854745819212@ietfa.amsl.com>
To: IETF STIR Mail List <stir@ietf.org>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/x9vMhAqCwUrlsjtvsKei6WcPEYE>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-16.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Dec 2017 00:40:24 -0000

This version addresses the WG/IETFLC comments.

spt

> On Dec 9, 2017, at 19:39, internet-drafts@ietf.org wrote:
>=20
>=20
> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> This draft is a work item of the Secure Telephone Identity Revisited =
WG of the IETF.
>=20
>        Title           : Secure Telephone Identity Credentials: =
Certificates
>        Authors         : Jon Peterson
>                          Sean Turner
> 	Filename        : draft-ietf-stir-certificates-16.txt
> 	Pages           : 22
> 	Date            : 2017-12-09
>=20
> Abstract:
>   In order to prevent the impersonation of telephone numbers on the
>   Internet, some kind of credential system needs to exist that
>   cryptographically asserts authority over telephone numbers.  This
>   document describes the use of certificates in establishing authority
>   over telephone numbers, as a component of a broader architecture for
>   managing telephone numbers as identities in protocols like SIP.
>=20
>=20
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>=20
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-stir-certificates-16
> https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-16
>=20
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-stir-certificates-16
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>=20
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://www.ietf.org/mailman/listinfo/i-d-announce
> Internet-Draft directories: http://www.ietf.org/shadow.html
> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


From nobody Tue Dec 12 11:47:22 2017
Return-Path: <alissa@cooperw.in>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 591CC128656; Tue, 12 Dec 2017 11:47:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cooperw.in header.b=TPtia69U; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=osqq05bZ
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0YM3CRP7UYVN; Tue, 12 Dec 2017 11:47:16 -0800 (PST)
Received: from out3-smtp.messagingengine.com (out3-smtp.messagingengine.com [66.111.4.27]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D96B12952D; Tue, 12 Dec 2017 11:47:16 -0800 (PST)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id A45A32176D; Tue, 12 Dec 2017 14:47:15 -0500 (EST)
Received: from frontend2 ([10.202.2.161]) by compute7.internal (MEProxy); Tue, 12 Dec 2017 14:47:15 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cooperw.in; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; bh=jZyVu4na17y2Q0VcGe6Gdg19fbUwX mY3td61gRUicYk=; b=TPtia69UYbN73WXvNoIi4qUiPw9ir/PWX7Y9WsgXb2CvW 2P0BK6HSPonf0+JH8dbiMC38vYoUeu5sNG3b27ocvOPbu86cp68gaGR8cGzCIqru brqFpZ74ji/rCSFxdmVQMaLA/OQcT7g4e1UzQO6zrrPVJ9HOoKkif4TL4pFL8jJ7 vNj41YU3wiN5TQjRLAuKhk0EstqteCYhlOp3MWagkS4OiSpiEyj/r97HZfOW9Gpq /xGnlUnALeG45Ef67QqgoIjSJrBe0BZc5lDByF0UDasoQAcBuCQqhMMh9UFKkCHw SmydMy5y2Aq22JDoDy3LGZp3iKcAG08Vtl/0PdOFQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=jZyVu4 na17y2Q0VcGe6Gdg19fbUwXmY3td61gRUicYk=; b=osqq05bZvTq7KJ7jBc9teq DvsdAy6mAd3HBdIAIl8jmxErr7UZIlvr9J1TuMH0G5g2qv3Hx5dxGmELRuX/WblQ 9QwxgZUd/Non10krib3sA82maFruwDTliJB9saqPjLJXEZMriCt3udH8kdVWmW66 reUkvNBgiw5O6P9igaSW2zXtJusSaVC1K4frfqnpI1vgL/k2RHuD5UvlXFYShvhA A4cIOZqsjTZyvFyIoiWAszWa//IBlGmIEWphQPVb1q+HTspxt6UzUxEqscPoTQox ArLw6jR+ppRYAkqrEv9rOxfL1/b8L/kmpsMBTDMWY32HkP2KGHLbn4KPWPOIiKVg ==
X-ME-Sender: <xms:QzIwWgheGadpAPHNKl8FHxSowNv2c1e8vFdGlVmDCJSSbXvSnbYW4A>
Received: from sjc-alcoop-8816.cisco.com (unknown [128.107.241.187]) by mail.messagingengine.com (Postfix) with ESMTPA id A5A5F24211; Tue, 12 Dec 2017 14:47:14 -0500 (EST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Alissa Cooper <alissa@cooperw.in>
In-Reply-To: <151090177468.22136.5281729043778955691@ietfa.amsl.com>
Date: Tue, 12 Dec 2017 14:47:12 -0500
Cc: gen-art <gen-art@ietf.org>, draft-ietf-stir-certificates.all@ietf.org, stir@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <7EB81722-50D3-4897-9615-C63EF6F9CD88@cooperw.in>
References: <151090177468.22136.5281729043778955691@ietfa.amsl.com>
To: Joel Halpern <jmh@joelhalpern.com>
X-Mailer: Apple Mail (2.3124)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/EMsa1ps_9zvr4PmjFAJdFjLZraw>
Subject: Re: [stir] [Gen-art] Genart last call review of draft-ietf-stir-certificates-15
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Dec 2017 19:47:18 -0000

Joel, thanks for your review. Sean, thanks for your response. I=E2=80=99m =
keeping my Yes ballot from the last time around. I don=E2=80=99t have a =
strong opinion about the trust anchor issue.

Best,
Alissa

> On Nov 17, 2017, at 1:56 AM, Joel Halpern <jmh@joelhalpern.com> wrote:
>=20
> Reviewer: Joel Halpern
> Review result: Ready
>=20
> I am the assigned Gen-ART reviewer for this draft. The General Area
> Review Team (Gen-ART) reviews all IETF documents being processed
> by the IESG for the IETF Chair.  Please treat these comments just
> like any other last call comments.
>=20
> For more information, please see the FAQ at
>=20
> <https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.
>=20
> Document: draft-ietf-stir-certificates-15
> Reviewer: Joel Halpern
> Review Date: 2017-11-16
> IETF LC End Date: 2017-11-30
> IESG Telechat date: 2017-12-14
>=20
> Summary:
>=20
> Major issues:
>=20
> Minor issues:
>    Section 4 bullet 4 in naming the crypto algorithms refers quite =
clearly to
>    2 algorithms.  It then references one of them as RS256.  I assume =
those
>    versed in the field will know which one is meant.  But it would be =
better
>    if the abbreviation RS256 appeared next to the first reference to =
whichever
>    algorithm it means.
>=20
>    The security considerations section points to RFC 5280 security
>    considerations for most issues.  I presume that the intention is to =
use
>    that section regarding trusting CAs.  However, it seems that there =
is an
>    issue here much like that of classic web CAs.  The number of CAs =
that must
>    be trusted seems to be on the order of the number of countries in =
the
>    world.  That seems to leave a large window for false or misleading
>    certifications, as I can see nothing which restricts what numbers =
for which
>    those top level CAs can provide attestation.  I presume we do not =
want to
>    go down the path of requiring an uber-CA for all national =
authorities.  I
>    would expect some explicit recognition of this issue in this =
document.
>=20
> Nits/editorial comments:
>=20
>=20
> _______________________________________________
> Gen-art mailing list
> Gen-art@ietf.org
> https://www.ietf.org/mailman/listinfo/gen-art


From nobody Tue Dec 12 15:58:14 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 8701C126CBF; Tue, 12 Dec 2017 15:58:12 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Eric Rescorla <ekr@rtfm.com>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-stir-certificates@ietf.org, Robert Sparks <rjsparks@nostrum.com>, stir-chairs@ietf.org, rjsparks@nostrum.com, stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com>
Date: Tue, 12 Dec 2017 15:58:12 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/p9jcQDpNWWjM1g9qEoPgXTt8z8o>
Subject: [stir] Eric Rescorla's Discuss on draft-ietf-stir-certificates-16: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Dec 2017 23:58:12 -0000

Eric Rescorla has entered the following ballot position for
draft-ietf-stir-certificates-16: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

   national policies.  The count field is only applicable to start	
   fields' whose values do not include "*" or "#" (i.e., a	
   TelephoneNumber that does not include "*" or "#").  count never	
   overflows a TelephoneNumber digit boundary (i.e., a	
   TelephoneNumberRange with TelephoneNumber=10 with a count=91 will	
   address numbers 10-99).

This text doesn't seem very clear. When you say "never overflows a digit
boundary" do you mean "doesn't extend the integer to the left"? Because
you sure seem to be overflowing the 1s place here.

Is the algorithm that you are given the input TN, Count, and TN
consists D digits that the range is:

  MIN(TN + Count, 10^D - 1)

That would be consistent with your example here, but I don't think consistent
with your text. Or do you mean something else?





From nobody Wed Dec 13 08:24:50 2017
Return-Path: <adam@nostrum.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8C95D12009C; Wed, 13 Dec 2017 08:24:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.88
X-Spam-Level: 
X-Spam-Status: No, score=-1.88 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_SPF_HELO_PERMERROR=0.01, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zz7DnGLfnBAm; Wed, 13 Dec 2017 08:24:48 -0800 (PST)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0671B128961; Wed, 13 Dec 2017 08:24:45 -0800 (PST)
Received: from Orochi.local (rrcs-97-79-186-2.sw.biz.rr.com [97.79.186.2]) (authenticated bits=0) by nostrum.com (8.15.2/8.15.2) with ESMTPSA id vBDGOhwD039005 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO); Wed, 13 Dec 2017 10:24:44 -0600 (CST) (envelope-from adam@nostrum.com)
X-Authentication-Warning: raven.nostrum.com: Host rrcs-97-79-186-2.sw.biz.rr.com [97.79.186.2] claimed to be Orochi.local
To: Eric Rescorla <ekr@rtfm.com>, The IESG <iesg@ietf.org>
Cc: draft-ietf-stir-certificates@ietf.org, stir-chairs@ietf.org, stir@ietf.org, rjsparks@nostrum.com
References: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com>
From: Adam Roach <adam@nostrum.com>
Message-ID: <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com>
Date: Wed, 13 Dec 2017 10:24:44 -0600
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/8MgowSoGMRxfC8sc8edhtLf4oyQ>
Subject: Re: [stir] Eric Rescorla's Discuss on draft-ietf-stir-certificates-16: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 16:24:49 -0000

On 12/12/17 17:58, Eric Rescorla wrote:
>
>     national policies.  The count field is only applicable to start	
>     fields' whose values do not include "*" or "#" (i.e., a	
>     TelephoneNumber that does not include "*" or "#").  count never	
>     overflows a TelephoneNumber digit boundary (i.e., a	
>     TelephoneNumberRange with TelephoneNumber=10 with a count=91 will	
>     address numbers 10-99).
>
> This text doesn't seem very clear. When you say "never overflows a digit
> boundary" do you mean "doesn't extend the integer to the left"? Because
> you sure seem to be overflowing the 1s place here.

Based on the in-room conversation in Singapore, the notion here seems to 
be that the number does not increase in length.

> Is the algorithm that you are given the input TN, Count, and TN
> consists D digits that the range is:
>
>    MIN(TN + Count, 10^D - 1)
>
> That would be consistent with your example here, but I don't think consistent
> with your text. Or do you mean something else?
>

Your formula above matches my understanding, and I think including it in 
the document as the formal definition of how 'count' behaves would be 
the best way to address the lack of clarity you cite.

/a


From nobody Wed Dec 13 08:29:45 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 70CDA127871 for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 08:29:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aqn9_5TiKBiu for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 08:29:41 -0800 (PST)
Received: from mail-yb0-x22b.google.com (mail-yb0-x22b.google.com [IPv6:2607:f8b0:4002:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA5A3127077 for <stir@ietf.org>; Wed, 13 Dec 2017 08:29:41 -0800 (PST)
Received: by mail-yb0-x22b.google.com with SMTP id h28so1208229ybj.5 for <stir@ietf.org>; Wed, 13 Dec 2017 08:29:41 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=6JDErYo/kIM239mHxP40rqSI97AoIPvWsJjDJ7MYhMY=; b=gu4IHN5tuwb2zTqwh84cK0kW+DpBUPA+UGHBN3wxjy5fLkmDn17PfzrVGBjPhl8zCa ioxRfcKmYk2zK/dgFOf1OT89MckPzcOwQYbi0be3oRR828yhRT+SQzYUtk56w9vLXRnY 9KHg1QbEiWC9GxS/koB3si0JWegrX1bAAw0+TYLZRBarIwaHX6YmOm9TiNmwOfsv+RVP Ocnn3ey1zbcrCSyEol5jxo+Ku4CDe4TtKSwTzxFHCTs1gyqK1z3Lx6Ln4Il1v7EqqSwl gBAqbluQkn972RgfCSpuj+ltMJKdw8vhyygPNetdiARewZNN/ETMldbkN5WprnNmpfsr jynw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=6JDErYo/kIM239mHxP40rqSI97AoIPvWsJjDJ7MYhMY=; b=OlOa/bBz6xyepWjj2dyfqh1xzmRh9Un9Vxng8bOko+I4TvGpPe8yWzoWGFQz3rrMwR KViwN7yjhkuiQ5hDe9AFsqF4NVD3mmpwwshoLWehhcSISCOsUn96GWKhG63/Uw3WoqZU 5L83ixd7eaqlMtnHG0+CMPHtNTx1HSMmQ2v/33zgWbFYsI5SVKlgpGBoL7uXAWm+f1ei u+eiFIun4GGe+CUsXgaD1V/4SbPc1LDQK4o+6ZnXr+59Lyw9XmdwMeVn75UrPfQrxpJw xCYlSlw+7z+N7nDkwWFuBYW55gq6WT5eqBdT3YyyQZI6NFT1kBHCRJ81A4IHlTcGyFpC JDdA==
X-Gm-Message-State: AKGB3mL71SHPs2oihcdvPdqZokWJ/nKzDOHswY5MKKc9LCBb8m5Tqh+P 7sb0ZAtEqqkUUjWjjr6jVwv+SO2tQXUovZl5UD+HRw==
X-Google-Smtp-Source: ACJfBoumHaZLROjCy1/NnK03MNfr+blUqPPqZnDVeQdUeMS7Yn1HEDut6LlgPjmmTlyl8UPADaddNGra/GntA+A9MY4=
X-Received: by 10.37.224.215 with SMTP id x206mr2209339ybg.200.1513182580654;  Wed, 13 Dec 2017 08:29:40 -0800 (PST)
MIME-Version: 1.0
Received: by 10.129.123.132 with HTTP; Wed, 13 Dec 2017 08:29:00 -0800 (PST)
In-Reply-To: <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com>
References: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com> <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 13 Dec 2017 08:29:00 -0800
Message-ID: <CABcZeBP3zB02VoxNKSLUTR66LwOrbmEE7WCRWAk6VSEVTCHTzQ@mail.gmail.com>
To: Adam Roach <adam@nostrum.com>
Cc: The IESG <iesg@ietf.org>, draft-ietf-stir-certificates@ietf.org,  stir-chairs@ietf.org, stir@ietf.org, Robert Sparks <rjsparks@nostrum.com>
Content-Type: multipart/alternative; boundary="94eb2c08689633592505603b465a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/ZPL1DvRhiwoHw1jBYCjKclXRot4>
Subject: Re: [stir] Eric Rescorla's Discuss on draft-ietf-stir-certificates-16: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 16:29:44 -0000

--94eb2c08689633592505603b465a
Content-Type: text/plain; charset="UTF-8"

On Wed, Dec 13, 2017 at 8:24 AM, Adam Roach <adam@nostrum.com> wrote:

> On 12/12/17 17:58, Eric Rescorla wrote:
>
>>
>>     national policies.  The count field is only applicable to start
>>     fields' whose values do not include "*" or "#" (i.e., a
>>     TelephoneNumber that does not include "*" or "#").  count never
>>     overflows a TelephoneNumber digit boundary (i.e., a
>>     TelephoneNumberRange with TelephoneNumber=10 with a count=91 will
>>     address numbers 10-99).
>>
>> This text doesn't seem very clear. When you say "never overflows a digit
>> boundary" do you mean "doesn't extend the integer to the left"? Because
>> you sure seem to be overflowing the 1s place here.
>>
>
> Based on the in-room conversation in Singapore, the notion here seems to
> be that the number does not increase in length.
>
> Is the algorithm that you are given the input TN, Count, and TN
>> consists D digits that the range is:
>>
>>    MIN(TN + Count, 10^D - 1)
>>
>> That would be consistent with your example here, but I don't think
>> consistent
>> with your text. Or do you mean something else?
>>
>>
> Your formula above matches my understanding, and I think including it in
> the document as the formal definition of how 'count' behaves would be the
> best way to address the lack of clarity you cite.


That would be fine. As long as people are onboard with this, I'm happy to
withdraw my discuss and let you and the WG handle this.

-Ekr


>
> /a
>
>

--94eb2c08689633592505603b465a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Dec 13, 2017 at 8:24 AM, Adam Roach <span dir=3D"ltr">&lt;<a hr=
ef=3D"mailto:adam@nostrum.com" target=3D"_blank">adam@nostrum.com</a>&gt;</=
span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e=
x;border-left:1px #ccc solid;padding-left:1ex"><span class=3D"">On 12/12/17=
 17:58, Eric Rescorla wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
=C2=A0 =C2=A0 national policies.=C2=A0 The count field is only applicable t=
o start=C2=A0 =C2=A0 =C2=A0<br>
=C2=A0 =C2=A0 fields&#39; whose values do not include &quot;*&quot; or &quo=
t;#&quot; (i.e., a=C2=A0 =C2=A0 =C2=A0<br>
=C2=A0 =C2=A0 TelephoneNumber that does not include &quot;*&quot; or &quot;=
#&quot;).=C2=A0 count never=C2=A0 =C2=A0 =C2=A0<br>
=C2=A0 =C2=A0 overflows a TelephoneNumber digit boundary (i.e., a <br>
=C2=A0 =C2=A0 TelephoneNumberRange with TelephoneNumber=3D10 with a count=
=3D91 will=C2=A0 =C2=A0<br>
=C2=A0 =C2=A0 address numbers 10-99).<br>
<br>
This text doesn&#39;t seem very clear. When you say &quot;never overflows a=
 digit<br>
boundary&quot; do you mean &quot;doesn&#39;t extend the integer to the left=
&quot;? Because<br>
you sure seem to be overflowing the 1s place here.<br>
</blockquote>
<br></span>
Based on the in-room conversation in Singapore, the notion here seems to be=
 that the number does not increase in length.<span class=3D""><br>
<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
Is the algorithm that you are given the input TN, Count, and TN<br>
consists D digits that the range is:<br>
<br>
=C2=A0 =C2=A0MIN(TN + Count, 10^D - 1)<br>
<br>
That would be consistent with your example here, but I don&#39;t think cons=
istent<br>
with your text. Or do you mean something else?<br>
<br>
</blockquote>
<br></span>
Your formula above matches my understanding, and I think including it in th=
e document as the formal definition of how &#39;count&#39; behaves would be=
 the best way to address the lack of clarity you cite.</blockquote><div><br=
></div><div>That would be fine. As long as people are onboard with this, I&=
#39;m happy to withdraw my discuss and let you and the WG handle this.</div=
><div><br></div><div>-Ekr</div><div>=C2=A0</div><blockquote class=3D"gmail_=
quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1=
ex"><span class=3D"HOEnZb"><font color=3D"#888888"><br>
/a<br>
<br>
</font></span></blockquote></div><br></div></div>

--94eb2c08689633592505603b465a--


From nobody Wed Dec 13 08:36:57 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA8FD12895E for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 08:36:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5vfW26jQV-0F for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 08:36:54 -0800 (PST)
Received: from mail-qt0-x22e.google.com (mail-qt0-x22e.google.com [IPv6:2607:f8b0:400d:c0d::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 37993127871 for <stir@ietf.org>; Wed, 13 Dec 2017 08:36:53 -0800 (PST)
Received: by mail-qt0-x22e.google.com with SMTP id i40so4387950qti.8 for <stir@ietf.org>; Wed, 13 Dec 2017 08:36:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=0hfWvVwyvPTAwk7Ek3q0REiNn23ZB5ZlwsFBERXva6Y=; b=PgiNMYGEPxO8BexApetMSvfuw2if8Fjmr504ad73Evn3H1u4ZGOS8cYpo5JgVocCHU ljIYWhHF0mgSXRAiBLM7DOawK496/Koa5tdxw0e1JnN5FmA7oZ0F8EIXwF8HH0Tdj0ZZ vnLLw59fI7Ud1x81Pws39F8ryxZgJbAqk3u9w=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=0hfWvVwyvPTAwk7Ek3q0REiNn23ZB5ZlwsFBERXva6Y=; b=XYM4tubVFWFaErB1LX9dRdLEP7JX7RGOemAc0FCZA9g/3VY5SXgW6Iy/t2D8h6MhaY HtU2Kp6LNcsLfA3znVMJKLZPGjuGav628X7hgCcVfmf4sNBQ0DYaoF/SN+TfMiNJz3Qn oDwYQ0PwryyUbMto1C+QC/txZyqU9bicKq/2MR6/UXg5ZDmu/1xmhsbEDp4Fhnoc7AiH dMlBGUJNNbcK6fuOO9yhGz18WhVM8TnMcc/DH3hy98hyyspSDKIn0mzxoW3RuDgXJJZC 3S4Ax7O7A+N8hSKnyU1LTJuJHYM/QkZXa5TLp5DUddBJWOjnekO7g9P/3m/M4IdAoQVl xZqA==
X-Gm-Message-State: AKGB3mK86SQk4F3+rAuMS1jgYm9BVntduxb2n0tRsVj2TxG8sOAneR/H F9kpNdQEpugsOxnlh9Gh52E3JA==
X-Google-Smtp-Source: ACJfBovM5+EU+d562Eonoh20RU8DP+2LXeM/lT5tQAgK2NFqEslknyBpqv3tR3vEGyn1Ip4vU35zSQ==
X-Received: by 10.200.41.249 with SMTP id 54mr12074437qtt.312.1513183012329; Wed, 13 Dec 2017 08:36:52 -0800 (PST)
Received: from [172.16.0.18] ([96.231.220.27]) by smtp.gmail.com with ESMTPSA id d205sm1218371qke.21.2017.12.13.08.36.51 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 13 Dec 2017 08:36:51 -0800 (PST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com>
Date: Wed, 13 Dec 2017 11:36:50 -0500
Cc: The IESG <iesg@ietf.org>, draft-ietf-stir-certificates@ietf.org, stir-chairs@ietf.org, IETF STIR Mail List <stir@ietf.org>, Robert Sparks <rjsparks@nostrum.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <DB52F922-FAEF-4DBE-8A8B-F0F6EB009CB1@sn3rd.com>
References: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com> <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com>
To: Adam Roach <adam@nostrum.com>, Eric Rescorla <ekr@rtfm.com>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/7fp-FslfDXgROsF6h4D_6cu00OU>
Subject: Re: [stir] Eric Rescorla's Discuss on draft-ietf-stir-certificates-16: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 16:36:56 -0000

> On Dec 13, 2017, at 11:24, Adam Roach <adam@nostrum.com> wrote:
>=20
> On 12/12/17 17:58, Eric Rescorla wrote:
>>=20
>>    national policies.  The count field is only applicable to start=09
>>    fields' whose values do not include "*" or "#" (i.e., a=09
>>    TelephoneNumber that does not include "*" or "#").  count never=09
>>    overflows a TelephoneNumber digit boundary (i.e., a=09
>>    TelephoneNumberRange with TelephoneNumber=3D10 with a count=3D91 =
will=09
>>    address numbers 10-99).
>>=20
>> This text doesn't seem very clear. When you say "never overflows a =
digit
>> boundary" do you mean "doesn't extend the integer to the left"? =
Because
>> you sure seem to be overflowing the 1s place here.
>=20
> Based on the in-room conversation in Singapore, the notion here seems =
to be that the number does not increase in length.

Yep.

>> Is the algorithm that you are given the input TN, Count, and TN
>> consists D digits that the range is:
>>=20
>>   MIN(TN + Count, 10^D - 1)
>>=20
>> That would be consistent with your example here, but I don't think =
consistent
>> with your text. Or do you mean something else?
>>=20
>=20
> Your formula above matches my understanding, and I think including it =
in the document as the formal definition of how 'count' behaves would be =
the best way to address the lack of clarity you cite.

Agreed.  How about this change:

OLD:

    count never overflows a TelephoneNumber digit
    boundary (i.e., a TelephoneNumberRange with
    TelephoneNumber=3D10 with a count=3D91 will address
    numbers 10-99).

NEW:

    count never makes the number increase in length
    (i.e., a TelephoneNumberRange with TelephoneNumber=3D10
    with a count=3D91 will address numbers 10-99); formally,
    given the inputs count and TelephoneNumber of length D
    the end of the TelephoneNumberRange is:
    MIN(TelephoneNumber + count, 10^D - 1)

spt=


From nobody Wed Dec 13 09:06:48 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 90A7F12895E for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 09:06:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CxFk9r4AAE_q for <stir@ietfa.amsl.com>; Wed, 13 Dec 2017 09:06:16 -0800 (PST)
Received: from mail-yb0-x22b.google.com (mail-yb0-x22b.google.com [IPv6:2607:f8b0:4002:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6CC84128D2E for <stir@ietf.org>; Wed, 13 Dec 2017 09:06:12 -0800 (PST)
Received: by mail-yb0-x22b.google.com with SMTP id t127so1301416ybf.9 for <stir@ietf.org>; Wed, 13 Dec 2017 09:06:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=0mc/L98NkCEdS2gIyq3eBJJePs80Jl2s9fp9q1CQEDM=; b=fDFVdlH/IhTOkhTRJhigI5EZdDYGbwatSCqCWl+ummBCP9bYvOdzzbj5zQrMcm37PC w9jp1A2/llI/h6Q/cSMAqcFglThkS+tdnvAsHJYvF1CmVsqzpcF3cJe1i8gWZUDR6I95 3kRNm8FuMbK4+zyv1VxTrbeOubrGPWSIEi7sdCWqV0CrUn1bWetngAHDnYOR2iRV2WwA mimXtD7VrKm53Yh0jr8l9qXGI2EqZP/zEGKZ+BwaMvglBgPdra87t+aVTPLEEo997cPe a9kYicGlaOGvydiea4F7GlzgpxmK3VGl17WnbdTZNgLzob0SnsSYcsT5uoQQfcV8JZHP NeZw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=0mc/L98NkCEdS2gIyq3eBJJePs80Jl2s9fp9q1CQEDM=; b=MYWcnnadTCRP2bZbB/hsBDAicXUDzbUSIYSNUW2gNEzzbAJixsOFicXrCyIrfDrKH/ HSudDahZV0YjG1CxDA3x5CXrH/ssdOUwUKCJCygVDRUuUCesnPo6Gnm3Y9lVTn27ssc4 7qK90hulKKgC11NhC1aqAfUrkw1Q8Kq8acuh2COpFY2R5YrYl0C1hpi7/umETQ1jC++9 Yk4UpDXTP/5NVkbXHG5BmGeO5s65ydE7GatcpqmY3t6PZEcnfIwLt/reus+KiolGY9Rt A51ddx0oFwU2Muv9qdoMQp1SmFCOS9WwUqhqT/PhDY2pzc6uuPiYXJrjhhEG23/bF/My oZhw==
X-Gm-Message-State: AKGB3mLORCTltjIhaD+3QQkvRGP6RSEf8gtHrJfSjxj9tVZICDANjTRI u8bE+eAm6L9L2bNzMVKoIVtjuQa1Cp/u/z8hkSjEbw==
X-Google-Smtp-Source: ACJfBosOSm8Bzps2rCgjxjLj4Gn2/3t9VRsenDfLq2zvHjrpKhkszRBVfn0I/FfpZe3IHcFArAguWQctamUzrcocVJM=
X-Received: by 10.129.222.9 with SMTP id k9mr2259997ywj.47.1513184771593; Wed, 13 Dec 2017 09:06:11 -0800 (PST)
MIME-Version: 1.0
Received: by 10.129.123.132 with HTTP; Wed, 13 Dec 2017 09:05:30 -0800 (PST)
In-Reply-To: <DB52F922-FAEF-4DBE-8A8B-F0F6EB009CB1@sn3rd.com>
References: <151312309254.29995.11111198641956884169.idtracker@ietfa.amsl.com> <1e300ca0-f9fd-0079-ea1f-851fe30283cd@nostrum.com> <DB52F922-FAEF-4DBE-8A8B-F0F6EB009CB1@sn3rd.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 13 Dec 2017 09:05:30 -0800
Message-ID: <CABcZeBNM_rQpRJEPC_LNai2FoC13k8a1VHNk8KKpc5gV_riWug@mail.gmail.com>
To: Sean Turner <sean@sn3rd.com>
Cc: Adam Roach <adam@nostrum.com>, The IESG <iesg@ietf.org>,  draft-ietf-stir-certificates@ietf.org, stir-chairs@ietf.org,  IETF STIR Mail List <stir@ietf.org>, Robert Sparks <rjsparks@nostrum.com>
Content-Type: multipart/alternative; boundary="f403043d0488ca759105603bc874"
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/UmxLXZEmuNm8jocf7-erzMRnNWY>
Subject: Re: [stir] Eric Rescorla's Discuss on draft-ietf-stir-certificates-16: (with DISCUSS)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 17:06:43 -0000

--f403043d0488ca759105603bc874
Content-Type: text/plain; charset="UTF-8"

On Wed, Dec 13, 2017 at 8:36 AM, Sean Turner <sean@sn3rd.com> wrote:

>
>
> > On Dec 13, 2017, at 11:24, Adam Roach <adam@nostrum.com> wrote:
> >
> > On 12/12/17 17:58, Eric Rescorla wrote:
> >>
> >>    national policies.  The count field is only applicable to start
> >>    fields' whose values do not include "*" or "#" (i.e., a
> >>    TelephoneNumber that does not include "*" or "#").  count never
> >>    overflows a TelephoneNumber digit boundary (i.e., a
> >>    TelephoneNumberRange with TelephoneNumber=10 with a count=91 will
> >>    address numbers 10-99).
> >>
> >> This text doesn't seem very clear. When you say "never overflows a digit
> >> boundary" do you mean "doesn't extend the integer to the left"? Because
> >> you sure seem to be overflowing the 1s place here.
> >
> > Based on the in-room conversation in Singapore, the notion here seems to
> be that the number does not increase in length.
>
> Yep.
>
> >> Is the algorithm that you are given the input TN, Count, and TN
> >> consists D digits that the range is:
> >>
> >>   MIN(TN + Count, 10^D - 1)
> >>
> >> That would be consistent with your example here, but I don't think
> consistent
> >> with your text. Or do you mean something else?
> >>
> >
> > Your formula above matches my understanding, and I think including it in
> the document as the formal definition of how 'count' behaves would be the
> best way to address the lack of clarity you cite.
>
> Agreed.  How about this change:
>
> OLD:
>
>     count never overflows a TelephoneNumber digit
>     boundary (i.e., a TelephoneNumberRange with
>     TelephoneNumber=10 with a count=91 will address
>     numbers 10-99).
>
> NEW:
>
>     count never makes the number increase in length
>     (i.e., a TelephoneNumberRange with TelephoneNumber=10
>     with a count=91 will address numbers 10-99); formally,
>     given the inputs count and TelephoneNumber of length D
>     the end of the TelephoneNumberRange is:
>     MIN(TelephoneNumber + count, 10^D - 1)
>


This seems fine.

-Ekr

--f403043d0488ca759105603bc874
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Dec 13, 2017 at 8:36 AM, Sean Turner <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:sean@sn3rd.com" target=3D"_blank">sean@sn3rd.com</a>&gt;</spa=
n> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;b=
order-left:1px #ccc solid;padding-left:1ex"><span class=3D""><br>
<br>
&gt; On Dec 13, 2017, at 11:24, Adam Roach &lt;<a href=3D"mailto:adam@nostr=
um.com">adam@nostrum.com</a>&gt; wrote:<br>
&gt;<br>
&gt; On 12/12/17 17:58, Eric Rescorla wrote:<br>
&gt;&gt;<br>
&gt;&gt;=C2=A0 =C2=A0 national policies.=C2=A0 The count field is only appl=
icable to start<br>
&gt;&gt;=C2=A0 =C2=A0 fields&#39; whose values do not include &quot;*&quot;=
 or &quot;#&quot; (i.e., a<br>
&gt;&gt;=C2=A0 =C2=A0 TelephoneNumber that does not include &quot;*&quot; o=
r &quot;#&quot;).=C2=A0 count never<br>
&gt;&gt;=C2=A0 =C2=A0 overflows a TelephoneNumber digit boundary (i.e., a<b=
r>
&gt;&gt;=C2=A0 =C2=A0 TelephoneNumberRange with TelephoneNumber=3D10 with a=
 count=3D91 will<br>
&gt;&gt;=C2=A0 =C2=A0 address numbers 10-99).<br>
&gt;&gt;<br>
&gt;&gt; This text doesn&#39;t seem very clear. When you say &quot;never ov=
erflows a digit<br>
&gt;&gt; boundary&quot; do you mean &quot;doesn&#39;t extend the integer to=
 the left&quot;? Because<br>
&gt;&gt; you sure seem to be overflowing the 1s place here.<br>
&gt;<br>
&gt; Based on the in-room conversation in Singapore, the notion here seems =
to be that the number does not increase in length.<br>
<br>
</span>Yep.<br>
<span class=3D""><br>
&gt;&gt; Is the algorithm that you are given the input TN, Count, and TN<br=
>
&gt;&gt; consists D digits that the range is:<br>
&gt;&gt;<br>
&gt;&gt;=C2=A0 =C2=A0MIN(TN + Count, 10^D - 1)<br>
&gt;&gt;<br>
&gt;&gt; That would be consistent with your example here, but I don&#39;t t=
hink consistent<br>
&gt;&gt; with your text. Or do you mean something else?<br>
&gt;&gt;<br>
&gt;<br>
&gt; Your formula above matches my understanding, and I think including it =
in the document as the formal definition of how &#39;count&#39; behaves wou=
ld be the best way to address the lack of clarity you cite.<br>
<br>
</span>Agreed.=C2=A0 How about this change:<br>
<br>
OLD:<br>
<span class=3D""><br>
=C2=A0 =C2=A0 count never overflows a TelephoneNumber digit<br>
=C2=A0 =C2=A0 boundary (i.e., a TelephoneNumberRange with<br>
=C2=A0 =C2=A0 TelephoneNumber=3D10 with a count=3D91 will address<br>
=C2=A0 =C2=A0 numbers 10-99).<br>
<br>
</span>NEW:<br>
<br>
=C2=A0 =C2=A0 count never makes the number increase in length<br>
<span class=3D"">=C2=A0 =C2=A0 (i.e., a TelephoneNumberRange with Telephone=
Number=3D10<br>
</span>=C2=A0 =C2=A0 with a count=3D91 will address numbers 10-99); formall=
y,<br>
=C2=A0 =C2=A0 given the inputs count and TelephoneNumber of length D<br>
=C2=A0 =C2=A0 the end of the TelephoneNumberRange is:<br>
=C2=A0 =C2=A0 MIN(TelephoneNumber + count, 10^D - 1)<br></blockquote><div><=
br></div><div><br></div><div>This seems fine.</div><div><br></div><div>-Ekr=
</div><div>=C2=A0</div></div></div></div>

--f403043d0488ca759105603bc874--


From nobody Wed Dec 13 13:45:54 2017
Return-Path: <Kathleen.Moriarty.ietf@gmail.com>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 12BA81201F8; Wed, 13 Dec 2017 13:45:49 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Kathleen Moriarty <Kathleen.Moriarty.ietf@gmail.com>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-stir-certificates@ietf.org, Robert Sparks <rjsparks@nostrum.com>, stir-chairs@ietf.org, rjsparks@nostrum.com, stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151320154906.30089.14763553746343335688.idtracker@ietfa.amsl.com>
Date: Wed, 13 Dec 2017 13:45:49 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/CEUn9aEbZK-XDhWa4LjZMlVaw4g>
Subject: [stir] Kathleen Moriarty's Yes on draft-ietf-stir-certificates-16: (with COMMENT)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 21:45:49 -0000

Kathleen Moriarty has entered the following ballot position for
draft-ietf-stir-certificates-16: Yes

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks for your work on this draft!

NIT: Section 4, bullet 4, RFC8017 is PKCS #1 v2.2, not v1.5.
There are some other mentions of v1.5, did you mean that or 2.2?  2.2 fixes a
few problems, so I was glad to see that reference.



From nobody Wed Dec 13 15:50:41 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id E06931201F8; Wed, 13 Dec 2017 15:50:35 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Eric Rescorla <ekr@rtfm.com>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-stir-certificates@ietf.org, Robert Sparks <rjsparks@nostrum.com>, stir-chairs@ietf.org, rjsparks@nostrum.com, stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151320903591.6112.4151980256252015377.idtracker@ietfa.amsl.com>
Date: Wed, 13 Dec 2017 15:50:35 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/0loRtk-2c1vKwJLcCC_stxs66cw>
Subject: [stir] Eric Rescorla's No Objection on draft-ietf-stir-certificates-16: (with COMMENT)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 23:50:36 -0000

Eric Rescorla has entered the following ballot position for
draft-ietf-stir-certificates-16: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Removing my discuss based on conversations with the authors



From nobody Thu Dec 14 04:12:22 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02739128D64 for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 04:12:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WhCuVKYOSV3m for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 04:12:16 -0800 (PST)
Received: from mail-qt0-x22d.google.com (mail-qt0-x22d.google.com [IPv6:2607:f8b0:400d:c0d::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AABAD128BC8 for <stir@ietf.org>; Thu, 14 Dec 2017 04:12:13 -0800 (PST)
Received: by mail-qt0-x22d.google.com with SMTP id a16so7639822qtj.3 for <stir@ietf.org>; Thu, 14 Dec 2017 04:12:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=Vdwmje4S0Ei/4aH0CHStJYsyvpX7ejIlo1TtazwKF1Y=; b=Io961vp8nSV7VO4L+uOVaCTwjkb7liFHMQ5aB6FaFVPtz15B7yGBQ7fh5FOCV5S0f8 hRaCmVY1iqIak71Ag4uQqAHmApQb7MAh2CJoM4CxGnXTwRUbhvfc3ToE2Et7BBaUUcU+ U9jSG5d52NMHxrIU21g6GRSwKuDjL6q/rIRPw=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=Vdwmje4S0Ei/4aH0CHStJYsyvpX7ejIlo1TtazwKF1Y=; b=olgsFdIUE4q2EdLYfY1IKwB2LIyh6h2e4QkuNcRnKS5ZI0nmlPGZ+Ehgy9SjN69S2m Y+KFtsjfsi5nF2mDlaVDfkmqVM3JQONiA4d0CTqj0WXtzNSW7kCM/ddBI4bpR6kXjU5E 2/NuRTeym5RIcHbNTTDp8dlTRd1DkITsTgj1Zs9s8Ebwuhqq2V0nXKjdNzTnVS3VNThP CBF7hbsWb5FkiMLYI8Cgm7ifAuBIDEPVOYSlK8pUVwcPBQWrhVywTFQRxaPGLG26ukbh gqvyZAwk0Pk4wWEAH1GQZVynM9XYPrflIuCKPIppu7FoFqV2syrBdYeW4TdrGuvtF4kW vgHQ==
X-Gm-Message-State: AKGB3mIm4vtnIipW4nJmxoYUkAoT8ZPdv13tBODT9bOV3TpbTw/qSJ1T 75nzN8bLet3LtzUR+NwcDA+GEQ==
X-Google-Smtp-Source: ACJfBouirBBqZksBBzHxrqakjO2e8DyemMwa2LSpOkr41QHKHehmP3c7OWiPUzxc01rx5TFf1ecyoQ==
X-Received: by 10.237.53.174 with SMTP id c43mr16602379qte.273.1513253532845;  Thu, 14 Dec 2017 04:12:12 -0800 (PST)
Received: from [172.16.0.18] ([96.231.220.27]) by smtp.gmail.com with ESMTPSA id m5sm2612834qkh.90.2017.12.14.04.12.11 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 14 Dec 2017 04:12:12 -0800 (PST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <151320154906.30089.14763553746343335688.idtracker@ietfa.amsl.com>
Date: Thu, 14 Dec 2017 07:12:11 -0500
Cc: The IESG <iesg@ietf.org>, draft-ietf-stir-certificates@ietf.org, Robert Sparks <rjsparks@nostrum.com>, stir-chairs@ietf.org, stir@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <8D806052-A27A-41C4-8C2C-5000F0F8796A@sn3rd.com>
References: <151320154906.30089.14763553746343335688.idtracker@ietfa.amsl.com>
To: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/EPgKqfvQZwhz4WY7IappIulEU54>
Subject: Re: [stir] Kathleen Moriarty's Yes on draft-ietf-stir-certificates-16: (with COMMENT)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 12:12:21 -0000

> On Dec 13, 2017, at 16:45, Kathleen Moriarty =
<kathleen.moriarty.ietf@gmail.com> wrote:
>=20
> Kathleen Moriarty has entered the following ballot position for
> draft-ietf-stir-certificates-16: Yes
>=20
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut =
this
> introductory paragraph, however.)
>=20
>=20
> Please refer to =
https://www.ietf.org/iesg/statement/discuss-criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
>=20
>=20
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>=20
>=20
>=20
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>=20
> Thanks for your work on this draft!
>=20
> NIT: Section 4, bullet 4, RFC8017 is PKCS #1 v2.2, not v1.5.
> There are some other mentions of v1.5, did you mean that or 2.2?  2.2 =
fixes a
> few problems, so I was glad to see that reference.

We do point to the 2.2 specification, but we=E2=80=99re still using the =
RSASSA-PKCS1-v1_5 scheme.  Basically, we=E2=80=99re still using the 1.5 =
scheme though it=E2=80=99s documented in the 2.2 spec ;)

spt=


From nobody Thu Dec 14 07:55:21 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id BA032126CD8; Thu, 14 Dec 2017 07:55:19 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151326691971.6099.4107849780973461328@ietfa.amsl.com>
Date: Thu, 14 Dec 2017 07:55:19 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/aDtlNBOzBH66fsgpF0hteULvLuA>
Subject: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 15:55:20 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Secure Telephone Identity Revisited WG of the IETF.

        Title           : Secure Telephone Identity Credentials: Certificates
        Authors         : Jon Peterson
                          Sean Turner
	Filename        : draft-ietf-stir-certificates-17.txt
	Pages           : 22
	Date            : 2017-12-14

Abstract:
   In order to prevent the impersonation of telephone numbers on the
   Internet, some kind of credential system needs to exist that
   cryptographically asserts authority over telephone numbers.  This
   document describes the use of certificates in establishing authority
   over telephone numbers, as a component of a broader architecture for
   managing telephone numbers as identities in protocols like SIP.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-stir-certificates-17
https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-17

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-stir-certificates-17


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Thu Dec 14 07:57:18 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD77C1293D6 for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 07:57:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L6pULaR42u6T for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 07:57:16 -0800 (PST)
Received: from mail-qt0-x22c.google.com (mail-qt0-x22c.google.com [IPv6:2607:f8b0:400d:c0d::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C9AE8120227 for <stir@ietf.org>; Thu, 14 Dec 2017 07:57:15 -0800 (PST)
Received: by mail-qt0-x22c.google.com with SMTP id u10so8527796qtg.2 for <stir@ietf.org>; Thu, 14 Dec 2017 07:57:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=from:content-transfer-encoding:mime-version:subject:date:references :to:in-reply-to:message-id; bh=y6vf4oRXV2cj9mIcPFh0oE4+Fk/y84WnP5i7sy87izg=; b=XJdPAapEBjgCOGeHh51wBHZPUcSpT0sOjtfB9iIEhQxc4qMEtfXDhxaQ2SbsCGPv+W 2jv3vXVw/RZbWLIEi0nNQfOj1uysLdP0WBsaIeW/r4dpgyqQ7W9MqMPfNgK343th33o7 36sxKQonu5cnArz5ymG5BARWQngPA7Afd1sno=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:content-transfer-encoding:mime-version :subject:date:references:to:in-reply-to:message-id; bh=y6vf4oRXV2cj9mIcPFh0oE4+Fk/y84WnP5i7sy87izg=; b=D41sA2HPI8l+pSO73PzIAFJCkbY79bOJyUb0gtQrkpiPwVJPo/NiSAGQWsYCyokqzN Al4r7K3JFn8gZNBbfoRzLolkLYUi7CBZJcdNjIFaAH6oPclFJSrn2Rnd/OZLIbU70FzS Q+EG+hS2N9y3zrvQXbzDGW1oPF2fVDA3R2BuJhwusL6MhRPzIdE7aClunHX5NRswdTI0 4mXdBY5vPDqPavvO5lJq8UQ1dUmudGsQsYP7t9Z+QflNrLQ4xXT0DOU0Qcu3t/c2M0v6 x3DRmqxvio71v2WyNxmjjFkQxPY5SXbD1YKy5TLsWF1eB7fBsU4wNB0lpKOkrbGvl9Sr ivfA==
X-Gm-Message-State: AKGB3mI6WuBWKQLWLgo5nPp8NwWmmd4Mcxfjln02hcpT++ORgNw/2ytN xd3zsY9oWtxa9aFtMTd8OlL0icDKR/I=
X-Google-Smtp-Source: ACJfBos9U7C3xEXIngVnUaWxqtd0+A9ydT3RZaMdz45JIo6I90Z+n+dfkK0EtPjgBwkqG70j5mGHLw==
X-Received: by 10.200.37.97 with SMTP id 30mr17318572qtn.318.1513267034813; Thu, 14 Dec 2017 07:57:14 -0800 (PST)
Received: from [172.16.0.18] ([96.231.220.27]) by smtp.gmail.com with ESMTPSA id p7sm2709922qkd.14.2017.12.14.07.57.13 for <stir@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 14 Dec 2017 07:57:14 -0800 (PST)
From: Sean Turner <sean@sn3rd.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
Date: Thu, 14 Dec 2017 10:57:13 -0500
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com>
To: IETF STIR Mail List <stir@ietf.org>
In-Reply-To: <151326691971.6099.4107849780973461328@ietfa.amsl.com>
Message-Id: <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/KNGhHevc7WSeHjpsQBmUHlrcyO4>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 15:57:18 -0000

This version addresses ekr=E2=80=99s discuss and IANA=E2=80=99s request =
to include additional fields (which I forgot).

spt

> On Dec 14, 2017, at 10:55, internet-drafts@ietf.org wrote:
>=20
>=20
> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
> This draft is a work item of the Secure Telephone Identity Revisited =
WG of the IETF.
>=20
>        Title           : Secure Telephone Identity Credentials: =
Certificates
>        Authors         : Jon Peterson
>                          Sean Turner
> 	Filename        : draft-ietf-stir-certificates-17.txt
> 	Pages           : 22
> 	Date            : 2017-12-14
>=20
> Abstract:
>   In order to prevent the impersonation of telephone numbers on the
>   Internet, some kind of credential system needs to exist that
>   cryptographically asserts authority over telephone numbers.  This
>   document describes the use of certificates in establishing authority
>   over telephone numbers, as a component of a broader architecture for
>   managing telephone numbers as identities in protocols like SIP.
>=20
>=20
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>=20
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-stir-certificates-17
> https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-17
>=20
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-stir-certificates-17
>=20
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>=20
> _______________________________________________
> stir mailing list
> stir@ietf.org
> https://www.ietf.org/mailman/listinfo/stir


From nobody Thu Dec 14 08:42:28 2017
Return-Path: <martin.thomson@gmail.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2B351127F0E for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 08:42:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lr-QcwQ_grCG for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 08:42:25 -0800 (PST)
Received: from mail-ot0-x230.google.com (mail-ot0-x230.google.com [IPv6:2607:f8b0:4003:c0f::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 188741273B1 for <stir@ietf.org>; Thu, 14 Dec 2017 08:42:24 -0800 (PST)
Received: by mail-ot0-x230.google.com with SMTP id e74so5439428ote.7 for <stir@ietf.org>; Thu, 14 Dec 2017 08:42:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=4TYY6svVso70cMXTcNlO3/4pz+HsRA5wQlYBA4k3yQc=; b=FdqzFPH+TzARPR0O00XF31FfvCjAB/X0w4b0PLU4moya60YldOD5CJviUPOIqlBfO3 ikiyYzI/wq9Ns1ec74ezACwke6xlpALDv+AypFLxQq30i96vQcBtOasOkNPlKJVp8zQX n7VeKsBd6mqkmYtspWei3+723Ixvya4uF6alvQpdaeWl26/ECxxNIjpyn1qEth+jW680 72hrgdb+17gkeS6M9Goyjsd9tbTJNQsoJ8+IWeb3By79GrtT4KunVTtMQ1i6SpsxnvDv XAwS/FnB4RA6NEUaTx8TqKCZ0/Zt7Qop7+ZriyPiSECkMqGA65OZ4uFwdCLy4YeoGjzs YtRw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=4TYY6svVso70cMXTcNlO3/4pz+HsRA5wQlYBA4k3yQc=; b=UFbd0gj6v6wMlI3jg6l9bBEUdV9aj0V4qpgfVVdh/ZJDd0wvZWBonMr08NfatceVBL dsyqIKr1wfrQG/j0UdeYAxbHVRpwGX/EJPOptN686J+q7xUUfhmaXJcFG3LP2227mOTB 2/+VfhvNNH7nrHahbWLrlPMJYZIlwInbAEpuHqfZIQ+8G6bSM/dwqMtQb+CjrmBZVg6y d2kHEkjufl7o0L8o7acEdr3k8iLmcTxd8d98zIiogk/Uopu6oIAD2mxCePI2QBJP/aFi 0qY6FnPGj4N6A/xFfmhKYjS5hGmx+GYZhE3HbjfxC0f+FknxqPjMyVX6I8zEVSvIkDMV UGHw==
X-Gm-Message-State: AKGB3mLQ1z03HtWRB3QkWvEQgw765d1H2GCCFzeCVUocsEJNKaalX4Ae r7UwJYAPAbUoNAaH0mgXV5IksUzWs1CNkp4gkfNGNw==
X-Google-Smtp-Source: ACJfBovnk6Yz463xbkblkOvPgpP49WdxdTb08VA71khcwBq1XKJoJzt2frfWmR1LDRZGVMRCft+qJnNJvoTh2goW4WM=
X-Received: by 10.157.67.146 with SMTP id t18mr5537581ote.103.1513269744331; Thu, 14 Dec 2017 08:42:24 -0800 (PST)
MIME-Version: 1.0
Received: by 10.157.8.11 with HTTP; Thu, 14 Dec 2017 08:42:23 -0800 (PST)
In-Reply-To: <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Thu, 14 Dec 2017 10:42:23 -0600
Message-ID: <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com>
To: Sean Turner <sean@sn3rd.com>
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/WINhhTF6VyD_plCkavUknxVOvEc>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 16:42:27 -0000

Hey Sean, why did you choose to allow capped ranges rather than making
them invalid?

"123"+900 is now equivalent to "123"+876, which means that you have
two ways to represent the same thing.  Don't we try to avoid that in
certificates?  (I mean otherwise we'd use BER...)

On Thu, Dec 14, 2017 at 9:57 AM, Sean Turner <sean@sn3rd.com> wrote:
> This version addresses ekr=E2=80=99s discuss and IANA=E2=80=99s request t=
o include additional fields (which I forgot).
>
> spt
>
>> On Dec 14, 2017, at 10:55, internet-drafts@ietf.org wrote:
>>
>>
>> A New Internet-Draft is available from the on-line Internet-Drafts direc=
tories.
>> This draft is a work item of the Secure Telephone Identity Revisited WG =
of the IETF.
>>
>>        Title           : Secure Telephone Identity Credentials: Certific=
ates
>>        Authors         : Jon Peterson
>>                          Sean Turner
>>       Filename        : draft-ietf-stir-certificates-17.txt
>>       Pages           : 22
>>       Date            : 2017-12-14
>>
>> Abstract:
>>   In order to prevent the impersonation of telephone numbers on the
>>   Internet, some kind of credential system needs to exist that
>>   cryptographically asserts authority over telephone numbers.  This
>>   document describes the use of certificates in establishing authority
>>   over telephone numbers, as a component of a broader architecture for
>>   managing telephone numbers as identities in protocols like SIP.
>>
>>
>> The IETF datatracker status page for this draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>>
>> There are also htmlized versions available at:
>> https://tools.ietf.org/html/draft-ietf-stir-certificates-17
>> https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-17
>>
>> A diff from the previous version is available at:
>> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-stir-certificates-17
>>
>>
>> Please note that it may take a couple of minutes from the time of submis=
sion
>> until the htmlized version and diff are available at tools.ietf.org.
>>
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/
>>
>> _______________________________________________
>> stir mailing list
>> stir@ietf.org
>> https://www.ietf.org/mailman/listinfo/stir
>
> _______________________________________________
> stir mailing list
> stir@ietf.org
> https://www.ietf.org/mailman/listinfo/stir


From nobody Thu Dec 14 09:40:57 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2F42C128616 for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:40:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H4v2lFl4uOQj for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:40:53 -0800 (PST)
Received: from mail-pf0-x22a.google.com (mail-pf0-x22a.google.com [IPv6:2607:f8b0:400e:c00::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A5E5129431 for <stir@ietf.org>; Thu, 14 Dec 2017 09:40:53 -0800 (PST)
Received: by mail-pf0-x22a.google.com with SMTP id u25so4111337pfg.5 for <stir@ietf.org>; Thu, 14 Dec 2017 09:40:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=M5vW1rSFSKlpPqQHBTqIu9G5BA/ceYoGBY/+FqGoqbs=; b=W2TnP4IC2iaikn+cZy+E/Oof3wzZIJgux7IEi+08AWLAMVrZ6yinFv6V9sNTC8z4iH Y/nrzJgnXviD8b6P+jIsv9c2iyuOJI7cZFtdsh0N9ZeLi1HQpjLjS+fEHOHrHwAoZEKi kydFofconmU0X1kU8pWUoi/jEYA1EC06pXv7I=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=M5vW1rSFSKlpPqQHBTqIu9G5BA/ceYoGBY/+FqGoqbs=; b=tJ11OJZU8/EMlYGbeDHyPqYxc/ruD3gBFm+KegPXulGtVU2HQckp44ul430flo3cXT 87kOEEyM/3OPmyJIDJvDBlmHRH+RlqJJXI2FBXILMllhxBrsnR0up7KlhbbykuFLQEXs nFAXpqqnZfkHvP/qWsy+RGlTv+2PPbnHAw+IqWwq5DJnQNAfbM68W6PwxJSKOZ4fQ7BK fZiEft2JqqWd3HrUx4QDRVjP/ZBLHknOIForv6iv8cv5vBbA8xPRm707GyzupjS9zh8l SI398CHAJAdrTApNBhBUKIawwiRszEqxTKPkjB0dy+cqeJT5QTj40q1BsUTfjneMpQC4 ESfQ==
X-Gm-Message-State: AKGB3mL0plzdrXQ0EGxg7C0D+cLvpIR16R12H+OlQ0C2qcCdD1GYLJn9 QOufKOH4LeegXfRF1J7BprFHcg==
X-Google-Smtp-Source: ACJfBoulxbIHbVkp++OhdMNiZcE88Mx1aZzIsBGAzTe1Nm6/D73FwNABS3Itk++CbOPWtZY+KuAwfA==
X-Received: by 10.98.224.200 with SMTP id d69mr10562455pfm.100.1513273252711;  Thu, 14 Dec 2017 09:40:52 -0800 (PST)
Received: from [5.5.33.190] (vpn.snozzages.com. [204.42.252.17]) by smtp.gmail.com with ESMTPSA id g17sm9162785pfj.66.2017.12.14.09.40.49 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 14 Dec 2017 09:40:51 -0800 (PST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com>
Date: Thu, 14 Dec 2017 12:40:43 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <10D3E501-E18D-43E3-A864-431329D7AA77@sn3rd.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/JS1F3Ij0Gh-QyfDAduWH4zrnhdY>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 17:40:55 -0000

The only reason I can come up with is to allow laziness.

spt

> On Dec 14, 2017, at 11:42, Martin Thomson <martin.thomson@gmail.com> =
wrote:
>=20
> Hey Sean, why did you choose to allow capped ranges rather than making
> them invalid?
>=20
> "123"+900 is now equivalent to "123"+876, which means that you have
> two ways to represent the same thing.  Don't we try to avoid that in
> certificates?  (I mean otherwise we'd use BER...)
>=20
> On Thu, Dec 14, 2017 at 9:57 AM, Sean Turner <sean@sn3rd.com> wrote:
>> This version addresses ekr=E2=80=99s discuss and IANA=E2=80=99s =
request to include additional fields (which I forgot).
>>=20
>> spt
>>=20
>>> On Dec 14, 2017, at 10:55, internet-drafts@ietf.org wrote:
>>>=20
>>>=20
>>> A New Internet-Draft is available from the on-line Internet-Drafts =
directories.
>>> This draft is a work item of the Secure Telephone Identity Revisited =
WG of the IETF.
>>>=20
>>>       Title           : Secure Telephone Identity Credentials: =
Certificates
>>>       Authors         : Jon Peterson
>>>                         Sean Turner
>>>      Filename        : draft-ietf-stir-certificates-17.txt
>>>      Pages           : 22
>>>      Date            : 2017-12-14
>>>=20
>>> Abstract:
>>>  In order to prevent the impersonation of telephone numbers on the
>>>  Internet, some kind of credential system needs to exist that
>>>  cryptographically asserts authority over telephone numbers.  This
>>>  document describes the use of certificates in establishing =
authority
>>>  over telephone numbers, as a component of a broader architecture =
for
>>>  managing telephone numbers as identities in protocols like SIP.
>>>=20
>>>=20
>>> The IETF datatracker status page for this draft is:
>>> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>>>=20
>>> There are also htmlized versions available at:
>>> https://tools.ietf.org/html/draft-ietf-stir-certificates-17
>>> =
https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-17
>>>=20
>>> A diff from the previous version is available at:
>>> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-stir-certificates-17
>>>=20
>>>=20
>>> Please note that it may take a couple of minutes from the time of =
submission
>>> until the htmlized version and diff are available at tools.ietf.org.
>>>=20
>>> Internet-Drafts are also available by anonymous FTP at:
>>> ftp://ftp.ietf.org/internet-drafts/
>>>=20
>>> _______________________________________________
>>> stir mailing list
>>> stir@ietf.org
>>> https://www.ietf.org/mailman/listinfo/stir
>>=20
>> _______________________________________________
>> stir mailing list
>> stir@ietf.org
>> https://www.ietf.org/mailman/listinfo/stir


From nobody Thu Dec 14 09:42:18 2017
Return-Path: <martin.thomson@gmail.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B51C129431 for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:42:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1bB12q31P_XI for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:42:15 -0800 (PST)
Received: from mail-ot0-x232.google.com (mail-ot0-x232.google.com [IPv6:2607:f8b0:4003:c0f::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E949128616 for <stir@ietf.org>; Thu, 14 Dec 2017 09:42:15 -0800 (PST)
Received: by mail-ot0-x232.google.com with SMTP id s4so5611979ote.4 for <stir@ietf.org>; Thu, 14 Dec 2017 09:42:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=40ZdKR59TXcIV/f1ViVHfrh59caJBQq+3CRFadvdk84=; b=gsIwJzem/SGat8LxtJoKX2eqoA8Ibie8vPFXexG2A124PDcSqhWNsjYcFDzPWraoKa /767iPWdz82MAyaBG+WaNj3bi9GYl9+loqo0PlccuB6fCDIgmsr5rFmZa6SxV5MUTT+d kczLE1Sro+4XxfVkLdTvwkz1Dw94hB3aZQCFoiD+XiBggnkEaDLKqXyiQ0GFGltUh3Wk wsGy7bfls6qhteX2KGv1+SFUfgds6jLgdIAoBIY8T6uPWqKQO79iMm9SPGV+eMAY1vcG SCt4t3MaojHsaw0C4okwCKvRh4pL8qFTIrG/UWeq7S3qcPt9OshDxsMu6JSpFj6pZXCh mOKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=40ZdKR59TXcIV/f1ViVHfrh59caJBQq+3CRFadvdk84=; b=BeGb9lF8XZut75VqfPweboqGQP1LIgBLua+9ez1cghRD+ZPdGISmTc+mR/IE1Yrj5a 5hVKfzl2PWuAZ/D7J5OtRbnLLmCzlaKVeXOs4oiMTTcheKK8lnaMFVsdJycOqzJ+iZg8 laWVVXM28N/z4SgSA3I2SRsOE0ObY9rEi6N7V0YYFtlIsWFO8ZGo0YcEtET3Go0xMKQG dnY4iH38EM7yS39BI9ZY8xczkTAOEu4mOgJsfcdCeLXFStCuBgDXBwKmDDAexrKQks89 UKG8aZFtAJd+A95zxvseF1t5m9v/HqirsBFPBhBD/4td/rNmEl8qD+xf95kdp/kP2FtC U2yg==
X-Gm-Message-State: AKGB3mJ/jnz37yIeKO4e5mjSpMvL606WdLb+6MPf7iVht3Bp671GMjTf FI9M3JYVDz3Ux+1sPweYVi8kcIe18tg+7uVlczs=
X-Google-Smtp-Source: ACJfBoukbuuvhnThOlVdm9F1wocReLNwYDcsOMH29kyEDBKvo85Pf3h4J8we+emKYNiTOJ87GEj1IuttTGtZ/VYOZDk=
X-Received: by 10.157.32.19 with SMTP id n19mr5743423ota.133.1513273334563; Thu, 14 Dec 2017 09:42:14 -0800 (PST)
MIME-Version: 1.0
Received: by 10.157.8.11 with HTTP; Thu, 14 Dec 2017 09:42:14 -0800 (PST)
In-Reply-To: <10D3E501-E18D-43E3-A864-431329D7AA77@sn3rd.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <10D3E501-E18D-43E3-A864-431329D7AA77@sn3rd.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Thu, 14 Dec 2017 11:42:14 -0600
Message-ID: <CABkgnnU+hisTEx3sAC7ur9K_0M3w1f4tQ+s1Wu9=xu2xTvHtdg@mail.gmail.com>
To: Sean Turner <sean@sn3rd.com>
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/K-eUq_LA07yOnmshQXQ8tKC8_qU>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 17:42:17 -0000

That doesn't sound like a good reason.

On Thu, Dec 14, 2017 at 11:40 AM, Sean Turner <sean@sn3rd.com> wrote:
> The only reason I can come up with is to allow laziness.
>
> spt
>
>> On Dec 14, 2017, at 11:42, Martin Thomson <martin.thomson@gmail.com> wro=
te:
>>
>> Hey Sean, why did you choose to allow capped ranges rather than making
>> them invalid?
>>
>> "123"+900 is now equivalent to "123"+876, which means that you have
>> two ways to represent the same thing.  Don't we try to avoid that in
>> certificates?  (I mean otherwise we'd use BER...)
>>
>> On Thu, Dec 14, 2017 at 9:57 AM, Sean Turner <sean@sn3rd.com> wrote:
>>> This version addresses ekr=E2=80=99s discuss and IANA=E2=80=99s request=
 to include additional fields (which I forgot).
>>>
>>> spt
>>>
>>>> On Dec 14, 2017, at 10:55, internet-drafts@ietf.org wrote:
>>>>
>>>>
>>>> A New Internet-Draft is available from the on-line Internet-Drafts dir=
ectories.
>>>> This draft is a work item of the Secure Telephone Identity Revisited W=
G of the IETF.
>>>>
>>>>       Title           : Secure Telephone Identity Credentials: Certifi=
cates
>>>>       Authors         : Jon Peterson
>>>>                         Sean Turner
>>>>      Filename        : draft-ietf-stir-certificates-17.txt
>>>>      Pages           : 22
>>>>      Date            : 2017-12-14
>>>>
>>>> Abstract:
>>>>  In order to prevent the impersonation of telephone numbers on the
>>>>  Internet, some kind of credential system needs to exist that
>>>>  cryptographically asserts authority over telephone numbers.  This
>>>>  document describes the use of certificates in establishing authority
>>>>  over telephone numbers, as a component of a broader architecture for
>>>>  managing telephone numbers as identities in protocols like SIP.
>>>>
>>>>
>>>> The IETF datatracker status page for this draft is:
>>>> https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/
>>>>
>>>> There are also htmlized versions available at:
>>>> https://tools.ietf.org/html/draft-ietf-stir-certificates-17
>>>> https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-17
>>>>
>>>> A diff from the previous version is available at:
>>>> https://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-stir-certificates-17
>>>>
>>>>
>>>> Please note that it may take a couple of minutes from the time of subm=
ission
>>>> until the htmlized version and diff are available at tools.ietf.org.
>>>>
>>>> Internet-Drafts are also available by anonymous FTP at:
>>>> ftp://ftp.ietf.org/internet-drafts/
>>>>
>>>> _______________________________________________
>>>> stir mailing list
>>>> stir@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/stir
>>>
>>> _______________________________________________
>>> stir mailing list
>>> stir@ietf.org
>>> https://www.ietf.org/mailman/listinfo/stir
>


From nobody Thu Dec 14 09:59:10 2017
Return-Path: <sean@sn3rd.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF242126DFF for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:59:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sn3rd.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KGzhMBfIsoEU for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 09:59:07 -0800 (PST)
Received: from mail-pf0-x234.google.com (mail-pf0-x234.google.com [IPv6:2607:f8b0:400e:c00::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8905A124BAC for <stir@ietf.org>; Thu, 14 Dec 2017 09:59:07 -0800 (PST)
Received: by mail-pf0-x234.google.com with SMTP id y89so4161921pfk.0 for <stir@ietf.org>; Thu, 14 Dec 2017 09:59:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sn3rd.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=CRaMswTRrguag7xDREMSeWuNvrbXY0BsJV8mpf6ZtTg=; b=kICS5qajfZanbFckNJIRUJFvY5o743WiIr9Drf/tcspQ22RQOwwfkhFibpXsDeLJNh h9c18rizWrNGe6KP7Yk61TkiLfc7WxKvVfXkIoKVNjHj1jpwjT6j8F4wkBdrDcKdbB3G gNh2IAmwn2BbX99PNtIFa7nRjiiawGJ4Udnfc=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=CRaMswTRrguag7xDREMSeWuNvrbXY0BsJV8mpf6ZtTg=; b=dgtt2yWumEuWs31I6TzO3Au7XRu65bC4qhJj8DES4ZcQkZdUYP77QBabIETqrAAi1W 5PAD8qYmtrXUSQe+QLFHkNQz3Dn4+4P4eXKpMVLW4DBRVY3Q0OUcUxuw61NhtduMNUvu 30QREcJidV2u9ztDdm6kSDfsVQolKgpbkfnM/1hDHR8dqdm6AzZVuhZVJgUbbYGKA7rz Im03r2vhTOZCLORGG6jLbjAblO/ck3MtblBALSaZY3GBWUKywfmAaIEpx5prZz7cTkaU QFVH2KRq2grPC4WufMKKrOuHb0eDFc0MfQgxod2lo2+8LPCDAqkwZ0N9Ws3hPEKZoZ5t jSYg==
X-Gm-Message-State: AKGB3mKFtrLEDcqoMf5KL8Jeq+is/L5vBIeDEuhqLcc3HJXIGMttxD8l Ws59kIr5b6cFspYL502aAoXz9g==
X-Google-Smtp-Source: ACJfBouogpHs3fYF0M/ORNlL6q2TgJURZVTFyfToLHf1reJFVMrEHNby3g9ev65AXJbh+qdEAthFHw==
X-Received: by 10.98.95.68 with SMTP id t65mr10502529pfb.45.1513274347186; Thu, 14 Dec 2017 09:59:07 -0800 (PST)
Received: from [5.5.33.190] (vpn.snozzages.com. [204.42.252.17]) by smtp.gmail.com with ESMTPSA id j17sm7730933pgv.40.2017.12.14.09.59.04 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 14 Dec 2017 09:59:06 -0800 (PST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 11.2 \(3445.5.20\))
From: Sean Turner <sean@sn3rd.com>
In-Reply-To: <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com>
Date: Thu, 14 Dec 2017 12:59:01 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
X-Mailer: Apple Mail (2.3445.5.20)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/sOVoU8tgiIgiWPEFrGbdiHfFQQ8>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 17:59:09 -0000

Bit to quick in my response, to address the 2nd point:

> On Dec 14, 2017, at 11:42, Martin Thomson <martin.thomson@gmail.com> =
wrote:
>=20
> "123"+900 is now equivalent to "123"+876, which means that you have
> two ways to represent the same thing.  Don't we try to avoid that in
> certificates?  (I mean otherwise we'd use BER...)

As far encoding something the same way: I=E2=80=99d be worried if =
=E2=80=9C123=E2=80=9D+900 and =E2=80=9C123=E2=80=9D+876 resulted in the =
same DER code, but it doesn=E2=80=99t.

spt=


From nobody Thu Dec 14 13:20:04 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F9E91270A3 for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 13:20:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HD_sxkx_I2xY for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 13:20:01 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BE5FF1200C1 for <stir@ietf.org>; Thu, 14 Dec 2017 13:20:01 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 2051D300681 for <stir@ietf.org>; Thu, 14 Dec 2017 16:20:01 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id ZX04wDGuKy9W for <stir@ietf.org>; Thu, 14 Dec 2017 16:19:59 -0500 (EST)
Received: from new-host.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 9E73230029C; Thu, 14 Dec 2017 16:19:59 -0500 (EST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com>
Date: Thu, 14 Dec 2017 16:19:59 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com>
To: Sean Turner <sean@sn3rd.com>, Martin Thomson <martin.thomson@gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/gYKXTT_G6X1pXVmGTG8EgAGiG8I>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 21:20:03 -0000

> On Dec 14, 2017, at 12:59 PM, Sean Turner <sean@sn3rd.com> wrote:
>=20
> Bit to quick in my response, to address the 2nd point:
>=20
>> On Dec 14, 2017, at 11:42, Martin Thomson <martin.thomson@gmail.com> =
wrote:
>>=20
>> "123"+900 is now equivalent to "123"+876, which means that you have
>> two ways to represent the same thing.  Don't we try to avoid that in
>> certificates?  (I mean otherwise we'd use BER...)
>=20
> As far encoding something the same way: I=E2=80=99d be worried if =
=E2=80=9C123=E2=80=9D+900 and =E2=80=9C123=E2=80=9D+876 resulted in the =
same DER code, but it doesn=E2=80=99t.

No, this bits on the wire are different, but they specify the same block =
of telephone numbers.  Why do we want more than one way to specify the =
same block of numbers?

Russ


From nobody Thu Dec 14 14:03:31 2017
Return-Path: <pkyzivat@alum.mit.edu>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 39B2A126B7E for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 14:03:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fu6Xpf7H6nqr for <stir@ietfa.amsl.com>; Thu, 14 Dec 2017 14:03:27 -0800 (PST)
Received: from alum-mailsec-scanner-6.mit.edu (alum-mailsec-scanner-6.mit.edu [18.7.68.18]) by ietfa.amsl.com (Postfix) with ESMTP id B9016126DEE for <stir@ietf.org>; Thu, 14 Dec 2017 14:03:26 -0800 (PST)
X-AuditID: 12074412-1fdff7000000748d-71-5a32f52d1ca3
Received: from outgoing-alum.mit.edu (OUTGOING-ALUM.MIT.EDU [18.7.68.33]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by alum-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id D3.DF.29837.D25F23A5; Thu, 14 Dec 2017 17:03:26 -0500 (EST)
Received: from PaulKyzivatsMBP.localdomain (c-24-62-227-142.hsd1.ma.comcast.net [24.62.227.142]) (authenticated bits=0) (User authenticated as pkyzivat@ALUM.MIT.EDU) by outgoing-alum.mit.edu (8.13.8/8.12.4) with ESMTP id vBEM3P0k027359 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT) for <stir@ietf.org>; Thu, 14 Dec 2017 17:03:25 -0500
To: stir@ietf.org
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com> <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com>
From: Paul Kyzivat <pkyzivat@alum.mit.edu>
Message-ID: <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu>
Date: Thu, 14 Dec 2017 17:03:25 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrNIsWRmVeSWpSXmKPExsUixO6iqKv31SjK4MpCQYvla7cxOTB6LFny kymAMYrLJiU1J7MstUjfLoEr42bfHpaCjRwVP/csZWxgvMzWxcjJISFgIjH3bydjFyMXh5DA DiaJL5ufskI4X5kkWk/PYwSpEhZwlrjc3ckOYosICErcm3GaCaJoKZPEivu/mUESbAJaEnMO /WfpYuTg4BWwl1h8IRokzCKgKvH21nkWEFtUIE1iz4UOMJsXaM7JmU/AbE4BB4l7p/ewgtjM AmYS8zY/ZIawxSVuPZnPBGHLSzRvnc08gZF/FpL2WUhaZiFpmYWkZQEjyypGucSc0lzd3MTM nOLUZN3i5MS8vNQiXTO93MwSvdSU0k2MkLAU2sG4/qTcIUYBDkYlHl6LNqMoIdbEsuLK3EOM khxMSqK8JZuAQnxJ+SmVGYnFGfFFpTmpxYcYJTiYlUR4r7QC5XhTEiurUovyYVLSHCxK4rw/ F6v7CQmkJ5akZqemFqQWwWRlODiUJHgvfgFqFCxKTU+tSMvMKUFIM3FwggznARp+G6SGt7gg Mbc4Mx0if4rRkqOn58YfJo5nM183MHP0zPrRwizEkpeflyolzssI0iAA0pBRmgc3E5ZmXjGK A70ozMsCUsUDTFFwU18BLWQCWvi8RR9kYUkiQkqqgZHnxsad+3sjjU8efquj39vy6lm/Xht/ nOHVv/E1b08uOPrQoWfuVrOdMu67q5LKiv8skFaKyTpo5LBzX+Xy7d25kxK9gwOvzJy/qu7T mjOK1bvefm3I6NTSXy9/pCpwwnWxBatfpS7ndjrCVHh5x0Y3pbrVfbKzjoWWykhbzfN+tNL/ oecWCy4lluKMREMt5qLiRAD0HdssDgMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/f-FPQg3QxBlGzE07YfFvReKM7C0>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 22:03:29 -0000

On 12/14/17 4:19 PM, Russ Housley wrote:
> 
>> On Dec 14, 2017, at 12:59 PM, Sean Turner <sean@sn3rd.com> wrote:
>>
>> Bit to quick in my response, to address the 2nd point:
>>
>>> On Dec 14, 2017, at 11:42, Martin Thomson <martin.thomson@gmail.com> wrote:
>>>
>>> "123"+900 is now equivalent to "123"+876, which means that you have
>>> two ways to represent the same thing.  Don't we try to avoid that in
>>> certificates?  (I mean otherwise we'd use BER...)
>>
>> As far encoding something the same way: I’d be worried if “123”+900 and “123”+876 resulted in the same DER code, but it doesn’t.
> 
> No, this bits on the wire are different, but they specify the same block of telephone numbers.  Why do we want more than one way to specify the same block of numbers?

I agree that "123"+900 seems like a bad idea.

But even without that there are multiple ways to specify the same range 
of numbers: a single range, two or more smaller ranges that collectively 
cover the range, or a complete list of individual numbers.

	Thanks,
	Paul


From nobody Fri Dec 15 09:32:29 2017
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B1A791200CF; Fri, 15 Dec 2017 09:32:11 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.67.1
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, adam@nostrum.com, stir@ietf.org, Robert Sparks <rjsparks@nostrum.com>, draft-ietf-stir-certificates@ietf.org, rfc-editor@rfc-editor.org, stir-chairs@ietf.org, rjsparks@nostrum.com
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <151335913172.30532.8816104333594546549.idtracker@ietfa.amsl.com>
Date: Fri, 15 Dec 2017 09:32:11 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/oFP8vl6BsSLVGGiqI07DI3c790c>
Subject: [stir] Protocol Action: 'Secure Telephone Identity Credentials: Certificates' to Proposed Standard (draft-ietf-stir-certificates-17.txt)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Dec 2017 17:32:13 -0000

The IESG has approved the following document:
- 'Secure Telephone Identity Credentials: Certificates'
  (draft-ietf-stir-certificates-17.txt) as Proposed Standard

This document is the product of the Secure Telephone Identity Revisited
Working Group.

The IESG contact persons are Adam Roach, Alexey Melnikov and Ben Campbell.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/




Technical Summary

 In order to prevent the impersonation of telephone numbers on the
   Internet, some kind of credential system needs to exist that
   cryptographically asserts authority over telephone numbers.  This
   document describes the use of certificates in establishing authority
   over telephone numbers, as a component of a broader architecture for
   managing telephone numbers as identities in protocols like SIP.

Working Group Summary

This document has undergone heavy review. Interoperability testing at the SIPit
in September identified issues leading to the introduction of the JWT Claim
Constraints, shifting where LOA assertions are made.

The document suite has been through three working group last calls, the third
of which was abbreviated to one week. The first last call stimulated
significant discussion, some of which was heated. 

Document Quality
This document is a component of a toolset for combating robocalling. In the
US, the FCC is applying significant pressure to the industry to deter
robocalling (with deadlines in the last part of 2016). An industry-led strike
force is moving towards deployment of a solution that uses that toolset. The
ATIS/SIP Forum IPNNI Task Force's SHAKEN solution relies on the toolset defined
by STIR and profiles it for deployment in the North American market.

Personnel

The document shepherd is Robert Sparks. The responsible AD is Adam Roach.


RFC Editor Note

This document contains several IANA-registered values in formal ASN.1
definitions. The definitions speculatively assumed values prior to official
assignment, and two of these presumed values have subsequently been assigned.
As a consequence, the final published ASN.1 syntax will need to be modified to
match actually assigned values. The areas to take note of are listed below.

These two definitions, which each appear _twice_ in the document, will need to
be updated to match the assigned entries in
https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.1
(these are known to need adjustment, as id-pe 25 has been assigned for another
purpose)

     id-pe-JWTClaimConstraints OBJECT IDENTIFIER ::= { id-pe 25 }

     id-pe-TNAuthList OBJECT IDENTIFIER ::= { id-pe 26 }

This definition, which appears _twice_ in the document, should match the
assigned value in
https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.48
(as the codepoint 14 remains unallocated, this may not need adjustment)

     id-ad-stirTNList  OBJECT IDENTIFIER ::= { id-ad 14 }

Finally, the (88) in the following definition from Appendix A needs to be
replaced with the actually assigned value from
https://www.iana.org/assignments/smi-numbers/smi-numbers.xhtml#smi-numbers-1.3.6.1.5.5.7.0
(the current value of 88 has already been assigned for another purpose, so
this will require adjustment):

   TN-Module-2016
     { iso(1) identified-organization(3) dod(6) internet(1) security(5)
       mechanisms(5) pkix(7) id-mod(0) id-mod-tn-module(88) }


From nobody Fri Dec 15 13:45:07 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BFAF127011 for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 13:45:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ERIz0Z_JI10e for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 13:45:04 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EBE9F1241FC for <stir@ietf.org>; Fri, 15 Dec 2017 13:45:03 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 62BF93005D8 for <stir@ietf.org>; Fri, 15 Dec 2017 16:45:03 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id KGeDPTYzz2nB for <stir@ietf.org>; Fri, 15 Dec 2017 16:45:02 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 4E854300293; Fri, 15 Dec 2017 16:45:02 -0500 (EST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu>
Date: Fri, 15 Dec 2017 16:45:01 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <333F2A6D-6CAF-4480-A448-06B76E1B397E@vigilsec.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com> <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com> <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu>
To: Paul Kyzivat <pkyzivat@alum.mit.edu>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/RX7T3No9V3Zq0HRLZEVSE1cdzrU>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Dec 2017 21:45:06 -0000

> On Dec 14, 2017, at 5:03 PM, Paul Kyzivat <pkyzivat@alum.mit.edu> =
wrote:
>=20
> On 12/14/17 4:19 PM, Russ Housley wrote:
>>> On Dec 14, 2017, at 12:59 PM, Sean Turner <sean@sn3rd.com> wrote:
>>>=20
>>> Bit to quick in my response, to address the 2nd point:
>>>=20
>>>> On Dec 14, 2017, at 11:42, Martin Thomson =
<martin.thomson@gmail.com> wrote:
>>>>=20
>>>> "123"+900 is now equivalent to "123"+876, which means that you have
>>>> two ways to represent the same thing.  Don't we try to avoid that =
in
>>>> certificates?  (I mean otherwise we'd use BER...)
>>>=20
>>> As far encoding something the same way: I=E2=80=99d be worried if =
=E2=80=9C123=E2=80=9D+900 and =E2=80=9C123=E2=80=9D+876 resulted in the =
same DER code, but it doesn=E2=80=99t.
>> No, this bits on the wire are different, but they specify the same =
block of telephone numbers.  Why do we want more than one way to specify =
the same block of numbers?
>=20
> I agree that "123"+900 seems like a bad idea.
>=20
> But even without that there are multiple ways to specify the same =
range of numbers: a single range, two or more smaller ranges that =
collectively cover the range, or a complete list of individual numbers.

To be clear, there is not a security issue here.  "123" + 900 and "123" =
+ 876 specify the same block of numbers.  If a certificate issuer says =
"123" + 900, do we really want to reject the certificate as badly =
formed?

Does anyone have language to make "123" + 876 the preferred encoding?

Russ


From nobody Fri Dec 15 15:08:36 2017
Return-Path: <martin.thomson@gmail.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D669E1242EA for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 15:08:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3drTL2VCSZTN for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 15:08:33 -0800 (PST)
Received: from mail-ot0-x232.google.com (mail-ot0-x232.google.com [IPv6:2607:f8b0:4003:c0f::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7F9FF1241FC for <stir@ietf.org>; Fri, 15 Dec 2017 15:08:33 -0800 (PST)
Received: by mail-ot0-x232.google.com with SMTP id d27so9105501ote.11 for <stir@ietf.org>; Fri, 15 Dec 2017 15:08:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=S6AFDww2YfRQE7z8nFWVryyuZg9GvuFdWDzcJ2PIsZE=; b=OdbDWsZ7A3CBGsar/obN2srMyl8cBqWUFrL5xNi1ydxbHZN7uC7pCjwXLeBZcnChY1 35tjUHp7dJmPHqyePz1V/eNZ6i8o2kLFdKGNbRRDio0RQb9AxHwFhe3RvgRoWvbabQrz GHlU5kwYDhI2pQajLBVE5AKg8hbv6R5nYuNtJaRhfRRfFnDcaSvBiDuxKV+XwjRKSa06 YpAd8IG6HrUIiYnZYSGumYCr3Yd54kM3gZLAmoPMZuML9/I86zfapS9IqJS031HmV8bz CwRm/uhRPlJUErh/yHJQVs/3uoATkiC+SHptq+TrAftLiokzzmDycGOZn4W7iImU5nNh rcKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=S6AFDww2YfRQE7z8nFWVryyuZg9GvuFdWDzcJ2PIsZE=; b=mwm5/GfRhvc4Fl+kwHEmtv0MPBiP1DoltLuOoSVWRmQMzFgrn5cIi0MVwaURAV+mbq EXEbgY0xqI3P/xipf+7f16jNURzqi9823XpsHhrWay8PteYuNGW4RKFVyiv5LEt86JjO n0uPzr4QLgMOX/wWb/h+SBGyXUg46vOAPYjKivU9m4xA5lHWfiljBTdAMkOtJrTFmRqJ k0ZYvW4VRjAFF75VA4qAQllNlXV5Jiqu33GZ7OxrjEz+309NyF7uTLOY9IgEdfONI7f/ tcuYXNZv2aoivCg7TC0IV/4+fhlmAOVOEZi896YyTZJez34jDo+g/K0bpd+ME70c09Y6 N9zg==
X-Gm-Message-State: AKGB3mKGLBCGq4eUy+C9EjB84g+FkBrhtYz3/lQ0n3U+t48k33NyOP1Y YXu6x4U+yrCtGOtqjVpYjPoA/rzJwdmvYz9i/Dj1yTf+
X-Google-Smtp-Source: ACJfBotSV0sibTCwqrC2QZwHLzPd5CAtDrGtI4Ke+sNiMI3Ox1IZrg6MKSQ5kqj5DAIt78zVmLwWbQgjwLgz2Jt7ROU=
X-Received: by 10.157.32.19 with SMTP id n19mr9580310ota.133.1513379312804; Fri, 15 Dec 2017 15:08:32 -0800 (PST)
MIME-Version: 1.0
Received: by 10.157.8.11 with HTTP; Fri, 15 Dec 2017 15:08:31 -0800 (PST)
In-Reply-To: <333F2A6D-6CAF-4480-A448-06B76E1B397E@vigilsec.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com> <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com> <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu> <333F2A6D-6CAF-4480-A448-06B76E1B397E@vigilsec.com>
From: Martin Thomson <martin.thomson@gmail.com>
Date: Fri, 15 Dec 2017 17:08:31 -0600
Message-ID: <CABkgnnXf01yfh2pfo+RqTjAfEr0KUGm1U=WFt0vHAZ=ScrWYHA@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Cc: Paul Kyzivat <pkyzivat@alum.mit.edu>, IETF STIR Mail List <stir@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/6aCW1FnTc6O3K4zdthiiA88FL6E>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Dec 2017 23:08:35 -0000

On Fri, Dec 15, 2017 at 3:45 PM, Russ Housley <housley@vigilsec.com> wrote:
> To be clear, there is not a security issue here.  "123" + 900 and "123" + 876 specify the same block of numbers.  If a certificate issuer says "123" + 900, do we really want to reject the certificate as badly formed?

Yup.

> Does anyone have language to make "123" + 876 the preferred encoding?

OLD:
   count never
   makes the number increase in length (i.e., a TelephoneNumberRange
   with TelephoneNumber=10 with a count=91 will address numbers
   10-99); formally, given the inputs count and TelephoneNumber of
   length D the end of the TelephoneNumberRange is:
   MIN(TelephoneNumber + count, 10^D - 1).
NEW:
   count MUST NOT make the number increase in length (i.e., a
TelephoneNumberRange
   with TelephoneNumber=10 with a count=91 is invalid); formally,
given the inputs count and TelephoneNumber of
   length D TelephoneNumber + count MUST be less than 10^D.

That is, treat "123"+900 the same way you would a range with a
negative count "123"+(-10).


From nobody Fri Dec 15 16:59:23 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC4FC128896 for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 16:59:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qlL46jXAEZ_p for <stir@ietfa.amsl.com>; Fri, 15 Dec 2017 16:59:20 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 311321201FA for <stir@ietf.org>; Fri, 15 Dec 2017 16:59:20 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 9157D3005D9 for <stir@ietf.org>; Fri, 15 Dec 2017 19:59:19 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id kk1Sh3P30jtP for <stir@ietf.org>; Fri, 15 Dec 2017 19:59:18 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 890AA300293; Fri, 15 Dec 2017 19:59:18 -0500 (EST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <CABkgnnXf01yfh2pfo+RqTjAfEr0KUGm1U=WFt0vHAZ=ScrWYHA@mail.gmail.com>
Date: Fri, 15 Dec 2017 19:59:17 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <C0CFC6CC-3BE1-4F3A-924E-BA1017941A17@vigilsec.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com> <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com> <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu> <333F2A6D-6CAF-4480-A448-06B76E1B397E@vigilsec.com> <CABkgnnXf01yfh2pfo+RqTjAfEr0KUGm1U=WFt0vHAZ=ScrWYHA@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/zG5vOenEyeh2m5PUKAroYMkBgwI>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Dec 2017 00:59:22 -0000

> On Dec 15, 2017, at 6:08 PM, Martin Thomson <martin.thomson@gmail.com> =
wrote:
>=20
> On Fri, Dec 15, 2017 at 3:45 PM, Russ Housley <housley@vigilsec.com> =
wrote:
>> To be clear, there is not a security issue here.  "123" + 900 and =
"123" + 876 specify the same block of numbers.  If a certificate issuer =
says "123" + 900, do we really want to reject the certificate as badly =
formed?
>=20
> Yup.
>=20
>> Does anyone have language to make "123" + 876 the preferred encoding?
>=20
> OLD:
>   count never
>   makes the number increase in length (i.e., a TelephoneNumberRange
>   with TelephoneNumber=3D10 with a count=3D91 will address numbers
>   10-99); formally, given the inputs count and TelephoneNumber of
>   length D the end of the TelephoneNumberRange is:
>   MIN(TelephoneNumber + count, 10^D - 1).
> NEW:
>   count MUST NOT make the number increase in length (i.e., a
> TelephoneNumberRange
>   with TelephoneNumber=3D10 with a count=3D91 is invalid); formally,
> given the inputs count and TelephoneNumber of
>   length D TelephoneNumber + count MUST be less than 10^D.
>=20
> That is, treat "123"+900 the same way you would a range with a
> negative count "123"+(-10).

Note, the ASN.1 syntax requires the count to be an INTEGER greater than =
2.

Russ




From nobody Mon Dec 18 11:28:15 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F51712D855 for <stir@ietfa.amsl.com>; Mon, 18 Dec 2017 11:28:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0
X-Spam-Level: 
X-Spam-Status: No, score=0 tagged_above=-999 required=5 tests=[none] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AgX3VQZyHBFL for <stir@ietfa.amsl.com>; Mon, 18 Dec 2017 11:28:13 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C6BBF120454 for <stir@ietf.org>; Mon, 18 Dec 2017 11:28:13 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id ECB2E300670 for <stir@ietf.org>; Mon, 18 Dec 2017 14:28:12 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id Tt06G-Dl3q2D for <stir@ietf.org>; Mon, 18 Dec 2017 14:28:12 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 1238A300447; Mon, 18 Dec 2017 14:28:12 -0500 (EST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <CABkgnnXf01yfh2pfo+RqTjAfEr0KUGm1U=WFt0vHAZ=ScrWYHA@mail.gmail.com>
Date: Mon, 18 Dec 2017 14:28:11 -0500
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <F61E7B29-AABA-41C8-A305-3E4D57C32470@vigilsec.com>
References: <151326691971.6099.4107849780973461328@ietfa.amsl.com> <7E30739D-C21C-466E-8C3A-8395171C253D@sn3rd.com> <CABkgnnXCizOyLkJzSR-MHo97O2feOiGXfOVFZeQPoNzj4m452g@mail.gmail.com> <07AB7CB1-E5A2-45EE-B90E-B11E6A04C018@sn3rd.com> <1AF855C9-7129-4098-A137-2CF6099A3A1C@vigilsec.com> <c03d5092-5646-0807-3e16-864aeeb3e413@alum.mit.edu> <333F2A6D-6CAF-4480-A448-06B76E1B397E@vigilsec.com> <CABkgnnXf01yfh2pfo+RqTjAfEr0KUGm1U=WFt0vHAZ=ScrWYHA@mail.gmail.com>
To: Martin Thomson <martin.thomson@gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/8NtHqD2VMEKmVWOZTwLxfZVYtJQ>
Subject: Re: [stir] I-D Action: draft-ietf-stir-certificates-17.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 19:28:15 -0000

{STIR WG Chair Hat ON}

> OLD:
>   count never
>   makes the number increase in length (i.e., a TelephoneNumberRange
>   with TelephoneNumber=3D10 with a count=3D91 will address numbers
>   10-99); formally, given the inputs count and TelephoneNumber of
>   length D the end of the TelephoneNumberRange is:
>   MIN(TelephoneNumber + count, 10^D - 1).
> NEW:
>   count MUST NOT make the number increase in length (i.e., a
> TelephoneNumberRange
>   with TelephoneNumber=3D10 with a count=3D91 is invalid); formally,
> given the inputs count and TelephoneNumber of
>   length D TelephoneNumber + count MUST be less than 10^D.

I have not heard anyone object to this text, so I'm asking the authors =
to add it to the document.

Russ


From nobody Mon Dec 18 14:24:13 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D4FF112D88F; Mon, 18 Dec 2017 14:24:11 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: stir@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.68.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151363585182.7367.10367939088814255731@ietfa.amsl.com>
Date: Mon, 18 Dec 2017 14:24:11 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/tG0HqIVu4mGZ1_xpuoJHczPKCSc>
Subject: [stir] I-D Action: draft-ietf-stir-certificates-18.txt
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Dec 2017 22:24:12 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Secure Telephone Identity Revisited WG of the IETF.

        Title           : Secure Telephone Identity Credentials: Certificates
        Authors         : Jon Peterson
                          Sean Turner
	Filename        : draft-ietf-stir-certificates-18.txt
	Pages           : 22
	Date            : 2017-12-18

Abstract:
   In order to prevent the impersonation of telephone numbers on the
   Internet, some kind of credential system needs to exist that
   cryptographically asserts authority over telephone numbers.  This
   document describes the use of certificates in establishing authority
   over telephone numbers, as a component of a broader architecture for
   managing telephone numbers as identities in protocols like SIP.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-stir-certificates/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-stir-certificates-18
https://datatracker.ietf.org/doc/html/draft-ietf-stir-certificates-18

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-stir-certificates-18


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Tue Dec 19 14:14:49 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA49F1200FC for <stir@ietfa.amsl.com>; Tue, 19 Dec 2017 14:14:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Aei3iUUeYK3l for <stir@ietfa.amsl.com>; Tue, 19 Dec 2017 14:14:45 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 94D6712D848 for <stir@ietf.org>; Tue, 19 Dec 2017 14:14:45 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 0A1B63005D7 for <stir@ietf.org>; Tue, 19 Dec 2017 17:14:45 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id FUPjND--1Xb6 for <stir@ietf.org>; Tue, 19 Dec 2017 17:14:44 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id 39B03300447 for <stir@ietf.org>; Tue, 19 Dec 2017 17:14:44 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 19 Dec 2017 17:14:43 -0500
References: <D419A386-9CBB-4F35-8042-41B2C3CAFF72@vigilsec.com>
To: IETF STIR Mail List <stir@ietf.org>
In-Reply-To: <D419A386-9CBB-4F35-8042-41B2C3CAFF72@vigilsec.com>
Message-Id: <D3F7CC05-E7B5-444C-94BD-CA989610E8B9@vigilsec.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/gIOzYL-dQ1okEOq8gmJk6-QkyhA>
Subject: Re: [stir] WG Last Call for draft-ietf-stir-rph-01
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 22:14:48 -0000

I have reviewed the postings on this WG Last Call.  Many people spoke =
for publication, and no one spoke against publication.  A few editorial =
errors were pointed out.  Will the authors please correct those.  Once =
the updated I-D is posted, we will ask the IESG for publication.

In addition to the comments on the mail list, IDnits reports that  7 =
lines in the document are too long lines in the document, the longest =
one being 4 characters in excess of 72.  Please correct them.

IDnits also reports that three RFCs are included in the references =
section, but they are not  references in the body of the document.  =
Please remove these references, or add a reference in the document body.

I think that the Abstract can be shortened considerably.  I suggest:

   This document extends the STIR PASSporT specification to allow the
   inclusion of cryptographically-signed assertions of authorization
   for values that might appear in the SIP 'Resource-Priority' header
   field, which is used for communications resource prioritization.

Russ


> On Oct 23, 2017, at 9:29 AM, Russ Housley <housley@vigilsec.com> =
wrote:
>=20
> This is the STIR WG Last Call for "PASSporT Extension for =
Resource-Priority Authorization=E2=80=9D <draft-ietf-stri-rph-01>.  =
Please review the document and send your comments to the list by 6 =
November 2017.=20
>=20
> Thanks,
> Russ & Robert


From nobody Tue Dec 19 14:37:17 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB7FA126E64 for <stir@ietfa.amsl.com>; Tue, 19 Dec 2017 14:37:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xQD7njHiGfrI for <stir@ietfa.amsl.com>; Tue, 19 Dec 2017 14:37:13 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 172481242F5 for <stir@ietf.org>; Tue, 19 Dec 2017 14:37:13 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 8303B300670 for <stir@ietf.org>; Tue, 19 Dec 2017 17:37:12 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id UP1g097XxGb8 for <stir@ietf.org>; Tue, 19 Dec 2017 17:37:10 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id C2C3C300447 for <stir@ietf.org>; Tue, 19 Dec 2017 17:37:10 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 19 Dec 2017 17:37:09 -0500
References: <D419A386-9CBB-4F35-8042-41B2C3CAFF72@vigilsec.com> <D3F7CC05-E7B5-444C-94BD-CA989610E8B9@vigilsec.com>
To: IETF STIR Mail List <stir@ietf.org>
In-Reply-To: <D3F7CC05-E7B5-444C-94BD-CA989610E8B9@vigilsec.com>
Message-Id: <4E836B7C-B349-47C4-9A40-A13D99367204@vigilsec.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/4bq0KsN34BbiR6POgxBEjGueM9s>
Subject: [stir] Draft Document Shepherd Write-up for draft-ietf-stir-rph
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Dec 2017 22:37:15 -0000

Please speak up now if you have any disagreement with this write-up.
The sections with *** will be updated as the authors respond.

Russ

= = = = = = = = =

(1) What type of RFC is being requested (BCP, Proposed Standard,
Internet Standard, Informational, Experimental, or Historic)?  Why
is this the proper type of RFC?  Is this type of RFC indicated in the
title page header?

  Standards track RFC is requested.  Yes, this appears on the
  title page of the Internet-Draft.

(2) The IESG approval announcement includes a Document Announcement
Write-Up. Please provide such a Document Announcement Write-Up. Recent
examples can be found in the "Action" announcements for approved
documents. The approval announcement contains the following sections:

Technical Summary

  This document extends the STIR PASSporT specification to allow the
  inclusion of cryptographically-signed assertions of authorization
  for values that might appear in the SIP 'Resource-Priority' header
  field, which is used for communications resource prioritization.

Working Group Summary

  The STIR WG reached consensus, and there is strong support for
  publication of this document.

Document Quality

  Several people have expressed interest in implementing this
  specification.

Personnel

  Russ Housley is the Document Shepherd.
  Adam Roach is the Responsible Area Director.

(3) Briefly describe the review of this document that was performed by
the Document Shepherd.  If this version of the document is not ready
for publication, please explain why the document is being forwarded to
the IESG.

   *** Asked authors to fix.

(4) Does the document Shepherd have any concerns about the depth or
breadth of the reviews that have been performed?

  No concerns at all.

(5) Do portions of the document need review from a particular or from
broader perspective, e.g., security, operational complexity, AAA, DNS,
DHCP, XML, or internationalization? If so, describe the review that
took place.

  No additional review is needed.

(6) Describe any specific concerns or issues that the Document Shepherd
has with this document that the Responsible Area Director and/or the
IESG should be aware of? For example, perhaps he or she is uncomfortable
with certain parts of the document, or has concerns whether there really
is a need for it. In any event, if the WG has discussed those issues and
has indicated that it still wishes to advance the document, detail those
concerns here.

  No concerns at all.

(7) Has each author confirmed that any and all appropriate IPR
disclosures required for full conformance with the provisions of BCP 78
and BCP 79 have already been filed. If not, explain why.

   *** Asked authors to confirm.

(8) Has an IPR disclosure been filed that references this document?
If so, summarize any WG discussion and conclusion regarding the IPR
disclosures.

  No IPR disclosures have been submitted against this document.

(9) How solid is the WG consensus behind this document? Does it 
represent the strong concurrence of a few individuals, with others
being silent, or does the WG as a whole understand and agree with it?   

  The STIR WG reached consensus, and there is strong support for
  publication of this document.

(10) Has anyone threatened an appeal or otherwise indicated extreme 
discontent? If so, please summarise the areas of conflict in separate
email messages to the Responsible Area Director. (It should be in a
separate email because this questionnaire is publicly available.) 

  No one has threatened to appeal or expressed discontent.

(11) Identify any ID nits the Document Shepherd has found in this
document. (See https://www.ietf.org/tools/idnits/ and the Internet-Drafts
Checklist). Boilerplate checks are not enough; this check needs to be
thorough.

   *** Asked authors to fix.

(12) Describe how the document meets any required formal review
criteria, such as the MIB Doctor, media type, and URI type reviews.

  No additional formal review is needed for this document.

(13) Have all references within this document been identified as
either normative or informative?

  Yes, informative and normative references appear is separate
  sections in the document.

(14) Are there normative references to documents that are not ready for
advancement or are otherwise in an unclear state? If such normative
references exist, what is the plan for their completion?

  Two normative references are in the RFC Editor queue.

(15) Are there downward normative references references (see RFC 3967)?
If so, list these downward references to support the Area Director in 
the Last Call procedure. 

  There are no downrefs.

(16) Will publication of this document change the status of any
existing RFCs? Are those RFCs listed on the title page header, listed
in the abstract, and discussed in the introduction? If the RFCs are not
listed in the Abstract and Introduction, explain why, and point to the
part of the document where the relationship of this document to the
other RFCs is discussed. If this information is not in the document,
explain why the WG considers it unnecessary.

  No, publication of this document will not change the status of
  any other documents.

(17) Describe the Document Shepherd's review of the IANA considerations
section, especially with regard to its consistency with the body of the
document. Confirm that all protocol extensions that the document makes
are associated with the appropriate reservations in IANA registries.
Confirm that any referenced IANA registries have been clearly
identified. Confirm that newly created IANA registries include a
detailed specification of the initial contents for the registry, that
allocations procedures for future registrations are defined, and a
reasonable name for the new registry has been suggested (see RFC 5226).

  The IANA considerations appear to be complete.

(18) List any new IANA registries that require Expert Review for future
allocations. Provide any public guidance that the IESG would find
useful in selecting the IANA Experts for these new registries.

  No new IANA registries are created.  Two entries are added to
  existing IANA registries.

(19) Describe reviews and automated checks performed by the Document
Shepherd to validate sections of the document written in a formal
language, such as XML code, BNF rules, MIB definitions, etc.

  None is needed for this document.


From nobody Wed Dec 20 10:14:15 2017
Return-Path: <subirdas21@gmail.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DE70129511 for <stir@ietfa.amsl.com>; Wed, 20 Dec 2017 10:14:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.449
X-Spam-Level: 
X-Spam-Status: No, score=-2.449 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zQA8XuI1fJuD for <stir@ietfa.amsl.com>; Wed, 20 Dec 2017 10:14:11 -0800 (PST)
Received: from mail-wm0-x231.google.com (mail-wm0-x231.google.com [IPv6:2a00:1450:400c:c09::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 035A31241FC for <stir@ietf.org>; Wed, 20 Dec 2017 10:14:11 -0800 (PST)
Received: by mail-wm0-x231.google.com with SMTP id n138so11560723wmg.2 for <stir@ietf.org>; Wed, 20 Dec 2017 10:14:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=EdTZiOLHWoipdVtYlJxdUEczAtKXiCz48Vs4QgOffOA=; b=kmFjB9IdBm1K6chwTz7xXrgpLp+HRB6ucgTUTHseMZC/fE4ausS81aKUt0akuoNuuj O71NiifjejboXdH+Lq5Ro1zhswY7zA7Q+jOcNlebA+2spYe4w7bFKh8x+/JVYEqb/bDf Eb27sjKheBRp/QsPwZ+9VBeZsp6yd5rUthIXFc7LzFaviVSnEe/E3gNmBz+mJ+Si1/g3 mrohwlqwsisA87TQonhvY9L8qsezHJ0jRmHVGNZLdmMBKh7ilY/MftOjK6e9PpkXc57B Weg6RJzMB786V57LAhdXqO7N6PgRlhxcukkQY4Sx/TjrzO3neT3f6VG8+UJvJ0m+EaW4 4i6g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=EdTZiOLHWoipdVtYlJxdUEczAtKXiCz48Vs4QgOffOA=; b=aLmLb70CmfhPtlNA4hOCOScmdZ8yTphsDoapZro/Hr5lW5gJukYeKg54dDY3EBh+ZO aOnM6b7gMdYT9usU3nTBlskCW5oJoFcrCyG6MdB84B4TqRfPFb3ic+R6rjswwc2Tr4So tMbaZ/KpLZDMR/37CskI9iyxCzyZ6cvbtK5oBVFYgTvqvJJLh8sVcsuPhDytZeZKVhCd ZCpqRz9wOzt/B+jPMxxbpqLs0uD2VCtbddYIhgbsWMkgvaiZpMox1BnU+XxvEsmM11+q WOYn+2tFRn48+ZrJVD350uca+1PAoqLS2YwmmE6wkAUUIhi5AOByR1IgJv1qmpnhXoZp L2Vw==
X-Gm-Message-State: AKGB3mIHh+07pdXHWgCiSnI2RIzYLeEOQGOVj7NTu/1gQCxBYQhofros xAqWPCB9yaiMMfFuFoemSGehJpja6OjzcXZ0qbs=
X-Google-Smtp-Source: ACJfBosjoglrzohUWz45cNEX04MYOjDgPyGQnBiKxqoDr5oLSHQ15T2+8V44jweVj+bBBJ2z9hd+h7S10jeEbujzuRc=
X-Received: by 10.28.125.11 with SMTP id y11mr7420820wmc.115.1513793649512; Wed, 20 Dec 2017 10:14:09 -0800 (PST)
MIME-Version: 1.0
Received: by 10.28.70.132 with HTTP; Wed, 20 Dec 2017 10:14:08 -0800 (PST)
In-Reply-To: <D3F7CC05-E7B5-444C-94BD-CA989610E8B9@vigilsec.com>
References: <D419A386-9CBB-4F35-8042-41B2C3CAFF72@vigilsec.com> <D3F7CC05-E7B5-444C-94BD-CA989610E8B9@vigilsec.com>
From: Subir Das <subirdas21@gmail.com>
Date: Wed, 20 Dec 2017 13:14:08 -0500
Message-ID: <CAFb8J8oY1j3J5QOoSo1aF-tdwDAXtx9QyuRSwjoQu76XdHUrOw@mail.gmail.com>
To: Russ Housley <housley@vigilsec.com>
Cc: IETF STIR Mail List <stir@ietf.org>
Content-Type: multipart/alternative; boundary="001a1141922cbe15c60560c98c55"
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/CpasEn7BAsf-Nql1ZPIYokIKlAg>
Subject: Re: [stir] WG Last Call for draft-ietf-stir-rph-01
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 18:14:13 -0000

--001a1141922cbe15c60560c98c55
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Russ,
Thanks for your review and comments. Your suggested abstract looks good to
me.
We will address  other editorial comments and submit another version of the
draft.

-Subir

On Tue, Dec 19, 2017 at 5:14 PM, Russ Housley <housley@vigilsec.com> wrote:

> I have reviewed the postings on this WG Last Call.  Many people spoke for
> publication, and no one spoke against publication.  A few editorial error=
s
> were pointed out.  Will the authors please correct those.  Once the updat=
ed
> I-D is posted, we will ask the IESG for publication.
>
> In addition to the comments on the mail list, IDnits reports that  7 line=
s
> in the document are too long lines in the document, the longest one being=
 4
> characters in excess of 72.  Please correct them.
>
> IDnits also reports that three RFCs are included in the references
> section, but they are not  references in the body of the document.  Pleas=
e
> remove these references, or add a reference in the document body.
>
> I think that the Abstract can be shortened considerably.  I suggest:
>
>    This document extends the STIR PASSporT specification to allow the
>    inclusion of cryptographically-signed assertions of authorization
>    for values that might appear in the SIP 'Resource-Priority' header
>    field, which is used for communications resource prioritization.
>
> Russ
>
>
> > On Oct 23, 2017, at 9:29 AM, Russ Housley <housley@vigilsec.com> wrote:
> >
> > This is the STIR WG Last Call for "PASSporT Extension for
> Resource-Priority Authorization=E2=80=9D <draft-ietf-stri-rph-01>.  Pleas=
e review
> the document and send your comments to the list by 6 November 2017.
> >
> > Thanks,
> > Russ & Robert
>
> _______________________________________________
> stir mailing list
> stir@ietf.org
> https://www.ietf.org/mailman/listinfo/stir
>

--001a1141922cbe15c60560c98c55
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div>Hi Russ,<br></div>Thanks for your review an=
d comments. Your suggested abstract looks good to me. <br></div>We will add=
ress=C2=A0 other editorial comments and submit another version of the draft=
. <br><br></div>-Subir <br></div><div class=3D"gmail_extra"><br><div class=
=3D"gmail_quote">On Tue, Dec 19, 2017 at 5:14 PM, Russ Housley <span dir=3D=
"ltr">&lt;<a href=3D"mailto:housley@vigilsec.com" target=3D"_blank">housley=
@vigilsec.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I hav=
e reviewed the postings on this WG Last Call.=C2=A0 Many people spoke for p=
ublication, and no one spoke against publication.=C2=A0 A few editorial err=
ors were pointed out.=C2=A0 Will the authors please correct those.=C2=A0 On=
ce the updated I-D is posted, we will ask the IESG for publication.<br>
<br>
In addition to the comments on the mail list, IDnits reports that=C2=A0 7 l=
ines in the document are too long lines in the document, the longest one be=
ing 4 characters in excess of 72.=C2=A0 Please correct them.<br>
<br>
IDnits also reports that three RFCs are included in the references section,=
 but they are not=C2=A0 references in the body of the document.=C2=A0 Pleas=
e remove these references, or add a reference in the document body.<br>
<br>
I think that the Abstract can be shortened considerably.=C2=A0 I suggest:<b=
r>
<br>
=C2=A0 =C2=A0This document extends the STIR PASSporT specification to allow=
 the<br>
=C2=A0 =C2=A0inclusion of cryptographically-signed assertions of authorizat=
ion<br>
=C2=A0 =C2=A0for values that might appear in the SIP &#39;Resource-Priority=
&#39; header<br>
=C2=A0 =C2=A0field, which is used for communications resource prioritizatio=
n.<br>
<span class=3D"HOEnZb"><font color=3D"#888888"><br>
Russ<br>
</font></span><div class=3D"HOEnZb"><div class=3D"h5"><br>
<br>
&gt; On Oct 23, 2017, at 9:29 AM, Russ Housley &lt;<a href=3D"mailto:housle=
y@vigilsec.com">housley@vigilsec.com</a>&gt; wrote:<br>
&gt;<br>
&gt; This is the STIR WG Last Call for &quot;PASSporT Extension for Resourc=
e-Priority Authorization=E2=80=9D &lt;draft-ietf-stri-rph-01&gt;.=C2=A0 Ple=
ase review the document and send your comments to the list by 6 November 20=
17.<br>
&gt;<br>
&gt; Thanks,<br>
&gt; Russ &amp; Robert<br>
<br>
______________________________<wbr>_________________<br>
stir mailing list<br>
<a href=3D"mailto:stir@ietf.org">stir@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/stir" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/stir</a><br>
</div></div></blockquote></div><br></div>

--001a1141922cbe15c60560c98c55--


From nobody Wed Dec 20 11:17:04 2017
Return-Path: <session-request@ietf.org>
X-Original-To: stir@ietf.org
Delivered-To: stir@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 77AB91205F1; Wed, 20 Dec 2017 11:17:02 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: IETF Meeting Session Request Tool <session-request@ietf.org>
To: <session-request@ietf.org>
Cc: stir@ietf.org, housley@vigilsec.com, adam@nostrum.com, stir-chairs@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.68.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151379742244.2637.2996254565339060782.idtracker@ietfa.amsl.com>
Date: Wed, 20 Dec 2017 11:17:02 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/VWJ8gdJWfVCBrGzTEHlbuHKVVPw>
Subject: [stir] stir - New Meeting Session Request for IETF 101
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 19:17:02 -0000

A new meeting session request has just been submitted by Russ Housley, a Chair of the stir working group.


---------------------------------------------------------
Working Group Name: Secure Telephone Identity Revisited
Area Name: Applications and Real-Time Area
Session Requester: Russ Housley

Number of Sessions: 1
Length of Session(s):  1 Hour
Number of Attendees: 60
Conflicts to Avoid: 
 First Priority: curdle sipbrandy ipwave modern ice dispatch sipcore mmusic rtcweb avtcore ecrit tls acme lamps suit saag
 Second Priority: perc slim netvc clue tcpinc uta ace oauth



People who must be present:
  Russ Housley
  Sean Turner
  Adam Roach
  Robert Sparks
  Jon Peterson
  Chris Wendt

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Wed Dec 20 11:35:29 2017
Return-Path: <housley@vigilsec.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B90E212422F for <stir@ietfa.amsl.com>; Wed, 20 Dec 2017 11:35:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nNzk9ju-liLQ for <stir@ietfa.amsl.com>; Wed, 20 Dec 2017 11:35:26 -0800 (PST)
Received: from mail.smeinc.net (mail.smeinc.net [209.135.209.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44BD01205F1 for <stir@ietf.org>; Wed, 20 Dec 2017 11:35:26 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.smeinc.net (Postfix) with ESMTP id 8E9553005AB for <stir@ietf.org>; Wed, 20 Dec 2017 14:35:25 -0500 (EST)
X-Virus-Scanned: amavisd-new at mail.smeinc.net
Received: from mail.smeinc.net ([127.0.0.1]) by localhost (mail.smeinc.net [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id Ulm2k02vFXQT for <stir@ietf.org>; Wed, 20 Dec 2017 14:35:24 -0500 (EST)
Received: from a860b60074bd.home (pool-108-45-101-150.washdc.fios.verizon.net [108.45.101.150]) by mail.smeinc.net (Postfix) with ESMTPSA id C298030041E for <stir@ietf.org>; Wed, 20 Dec 2017 14:35:24 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <B62DC317-C3C3-41C0-8EB5-150C64ECC1E3@vigilsec.com>
Date: Wed, 20 Dec 2017 14:35:24 -0500
To: IETF STIR Mail List <stir@ietf.org>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/8OeUKjW5zSj1tVvpVhfGVxt4XeU>
Subject: [stir] Should the STIR WG Adopt draft-wendt-stir-passport-shaken?
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Dec 2017 19:35:28 -0000

draft-wendt-stir-passport-shaken was discussed in the recent meeting in =
Singapore.  Please indicate whether or not you believe the STIR WG =
should adopt this document.  Please respond no later than 3 January =
2018.

For the STIR WG Chairs,
  Russ=


From nobody Thu Dec 21 10:59:14 2017
Return-Path: <rjsparks@nostrum.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45AB512D958 for <stir@ietfa.amsl.com>; Thu, 21 Dec 2017 10:59:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.889
X-Spam-Level: 
X-Spam-Status: No, score=-1.889 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, T_RP_MATCHES_RCVD=-0.01, T_SPF_HELO_PERMERROR=0.01, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wsh7oyfyFHgd for <stir@ietfa.amsl.com>; Thu, 21 Dec 2017 10:59:11 -0800 (PST)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D46712D93F for <stir@ietf.org>; Thu, 21 Dec 2017 10:59:11 -0800 (PST)
Received: from unescapeable.local ([47.186.15.50]) (authenticated bits=0) by nostrum.com (8.15.2/8.15.2) with ESMTPSA id vBLIx9C4058642 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO) for <stir@ietf.org>; Thu, 21 Dec 2017 12:59:10 -0600 (CST) (envelope-from rjsparks@nostrum.com)
X-Authentication-Warning: raven.nostrum.com: Host [47.186.15.50] claimed to be unescapeable.local
To: "stir@ietf.org" <stir@ietf.org>
From: Robert Sparks <rjsparks@nostrum.com>
Message-ID: <1c415a2e-0842-2b55-478c-e76999f2c69a@nostrum.com>
Date: Thu, 21 Dec 2017 12:59:09 -0600
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/qvQK2Hx4SnkksVi8YClze_76c-8>
Subject: [stir] Minutes for STIR @ IETF100
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Dec 2017 18:59:13 -0000

With apologies to the original notetaker, whose notes were lost somehow, 
I created minutes by listening to the meetecho recording.

Please provide any necessary additions or corrections to the list or the 
chairs ASAP.

-------

Minutes - STIR - IETF 100 - Tue Nov 14 2017

Summary

- The agenda was bashed to remove discussion of 
draft-ietf-stir-passport-rcd,
   and to provide an update on the documents that are already in IESG 
processing.

- draft-ietf-stir-rph is in WGLC and the editor is addressing comments.

- The proposed changes to draft-ietf-stir-certificates were discussed, minor
   tweaks were suggested, but no issues or objections were raised. The 
changes
   will go through a new last-call.

- The room expressed strong support for adopting
   draft-wendt-stir-passport-shaken. The editor believes it is ready for 
WGLC.

- The core elements of the current architecture of draft-ietf-stir-oob were
   discussed. There were no concerns expressed with the direction the 
draft is
   heading. The editors will move forward with defining concrete protocols.

- Open issues in draft-ietf-passport-divert were discussed. The core of the
   discussion was the tradeoff of nesting vs re-encrypting when retargeting
   happens. The room landed on pursuing nesting. Optionally including 
the index
   from History-Info was discussed.

See the session recording at 
<https://play.conf.meetecho.com/Playout/?session=IETF100-STIR-20171114-1330> 
for more detail.



