
From nobody Wed Feb  1 06:03:05 2017
Return-Path: <rsalz@akamai.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF764129460 for <trans@ietfa.amsl.com>; Wed,  1 Feb 2017 06:03:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.9
X-Spam-Level: 
X-Spam-Status: No, score=-5.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-3.199, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yCmyLyb0FeD4 for <trans@ietfa.amsl.com>; Wed,  1 Feb 2017 06:03:02 -0800 (PST)
Received: from prod-mail-xrelay06.akamai.com (prod-mail-xrelay06.akamai.com [96.6.114.98]) by ietfa.amsl.com (Postfix) with ESMTP id A1E9D12945A for <trans@ietf.org>; Wed,  1 Feb 2017 06:03:02 -0800 (PST)
Received: from prod-mail-xrelay06.akamai.com (localhost.localdomain [127.0.0.1]) by postfix.imss70 (Postfix) with ESMTP id 3584A496C3D; Wed,  1 Feb 2017 14:03:02 +0000 (GMT)
Received: from prod-mail-relay08.akamai.com (prod-mail-relay08.akamai.com [172.27.22.71]) by prod-mail-xrelay06.akamai.com (Postfix) with ESMTP id 1F266496C37; Wed,  1 Feb 2017 14:03:02 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; s=a1; t=1485957782; bh=Fn0iOcQpEnpY5/DXkL8IK0t9nZTDjgHVI13uGyouL0A=; l=596; h=From:To:CC:Date:References:In-Reply-To:From; b=el0cJ/ynoeqOcFwhBPXYd05MaUUQi27RdOUckkibQjmf5B5BdeMA8CdFtvCZKrgab lPiUu0PAVFRbhqdzmutjIgLH6AtE5l7HpBxDQmN435rVMyoh9oIwXAD0Krk8uAMhGl Xfxgfk/Ih8czKjLhxrbJxG+C+beZvIQxZJZ5EnAg=
Received: from email.msg.corp.akamai.com (usma1ex-cas3.msg.corp.akamai.com [172.27.123.32]) by prod-mail-relay08.akamai.com (Postfix) with ESMTP id 04CDF98084; Wed,  1 Feb 2017 14:03:02 +0000 (GMT)
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com (172.27.123.101) by usma1ex-dag1mb6.msg.corp.akamai.com (172.27.123.65) with Microsoft SMTP Server (TLS) id 15.0.1178.4; Wed, 1 Feb 2017 06:03:01 -0800
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com ([172.27.123.101]) by usma1ex-dag1mb1.msg.corp.akamai.com ([172.27.123.101]) with mapi id 15.00.1178.000; Wed, 1 Feb 2017 09:03:01 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Eric Rescorla <ekr@rtfm.com>
Thread-Topic: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
Thread-Index: AQHSe/GW0YKLOLxGL067P4dSkvMytKFS7XNggAEdmgCAACPQgA==
Date: Wed, 1 Feb 2017 14:03:00 +0000
Message-ID: <87964cd08db8405582b5cc7bce7b679d@usma1ex-dag1mb1.msg.corp.akamai.com>
References: <8f6852d8-05ae-5f72-8c09-0437cc963b2c@gmail.com> <CABcZeBObdV8DFDVpsSYO5_Wg=GH3JdhsNJa=-6mUmzaVNmE0TQ@mail.gmail.com> <CABrd9SRJw4t=hQ4wPBPR1rwsmZ08hiUn3MR+fiz6Fg4Y7iQFEg@mail.gmail.com> <CABcZeBPkzDcFUog+36BtNWBYOYmkfTsfQM7RAJ2h_w4Oc7EUXw@mail.gmail.com> <CABrd9SSShNAx8NUXx0NrNC9A8gNbAVJbczxe4aQeRmuUNjw82g@mail.gmail.com> <CABcZeBO1FuD+RmB73EAMSQgPynxOKNDZu_Gpic3P6rzqXi+WCA@mail.gmail.com> <b3ed4ab44d8547eb9922f93c65c1292b@usma1ex-dag1mb1.msg.corp.akamai.com> <4c0baba3-f85a-4154-c8af-10f84540cb12@gmail.com> <f070c7152969457d8ddceeff3d5119d2@usma1ex-dag1mb1.msg.corp.akamai.com> <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com>
In-Reply-To: <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.37.19]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/twCVp4k6NA130TbRTTv-PcbMdSA>
Cc: Richard Barnes <rlb@ipv.sx>, "trans@ietf.org" <trans@ietf.org>, Melinda Shore <melinda.shore@gmail.com>, Ben Laurie <benl@google.com>, Paul Wouters <paul@nohats.ca>
Subject: Re: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Feb 2017 14:03:04 -0000

PiAxLiBDQXMgbWFrZSBtaXN0YWtlcyBidXQgYXJlbid0IG1hbGljaW91cy4NCj4gMi4gQ0FzIGFy
ZSBtYWxpY2lvdXMgYnV0IGxvZ3MgYXJlIG5vdA0KPiAzLiBDQXMgYW5kIGxvZ3MgYXJlIGJvdGgg
bWFsaWNpb3VzDQoNClRoZSBvcmlnaW5hbCBmb2N1cyB3YXMgbWFpbmx5IGFib3V0IGNhdGNoaW5n
IHdyb25nIGNlcnRzLCB3aGljaCB3YXMgcmVhbGx5IGEgZm9jdXMgb24gQ0EgbWlzLWlzc3VhbmNl
LiAgTG9ncyB3ZXJlIGludGVuZGVkIHRvIGJlIGEgY2hlY2sgb24gdGhhdCwgYW5kIG1vbml0b3Jz
IGFuZCBhdWRpdG9ycyB3ZXJlIGxheWVycyBvbiB0b3AgdGhhdCB3b3VsZCBjYXRjaCBlcnJvbmVv
dXMgbG9ncy4NCg0KSGF2ZSB5b3UgcmVhZCB0aGUgdGhyZWF0IG1vZGVsIGRvYz8gIEkgYXNzdW1l
IHllcywgYnV0IGl0IG5ldmVyIGh1cnRzIHRvIGFzay4NCg0K


From nobody Thu Feb  2 07:36:23 2017
Return-Path: <melinda.shore@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0CBB1129468 for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 07:36:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Gk87Gm7Kr2mG for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 07:36:20 -0800 (PST)
Received: from mail-pf0-x234.google.com (mail-pf0-x234.google.com [IPv6:2607:f8b0:400e:c00::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B705F1293EE for <trans@ietf.org>; Thu,  2 Feb 2017 07:36:20 -0800 (PST)
Received: by mail-pf0-x234.google.com with SMTP id y143so6102884pfb.0 for <trans@ietf.org>; Thu, 02 Feb 2017 07:36:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=to:from:subject:message-id:date:user-agent:mime-version; bh=yWHtXpkSaiG+pc1aO6EsdSv1/9bcSFOVyneN51donTI=; b=LUCGILJC7bfQwMNIHB9OEOGlra52xVtEAcqjptymG8hSKMHP7qMAMWeb3Sq1KUYXxe Y7DVv/Zjjs2XuC+ryalpZpSPHoziWM0U+qRRUmcIifc8n250gnTC0Pydgoo5lsNb7YtS qgpzWWfovZFHJRd1SAWiz1X3tZtsdwhXudURCvIDdGpujMXeUmhRapJWF6ZKCyFwG/hm ABNRXaiRt4oA7dyny7zfbNrGDaFbpKOifQW++CgXlvnsQQXtfEtnWr24Vu7xjcKQMY+y u7BoD8QbMCvyTb6v+ZhMW4EjSHs0q3ctTrRZWjkir2ElgexL0mAX+mcWNHaTHE/WvICV cxRg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:message-id:date:user-agent :mime-version; bh=yWHtXpkSaiG+pc1aO6EsdSv1/9bcSFOVyneN51donTI=; b=BBdzNiGIJuZ7ETXXM1Fo5uzBSMY2g/zINHyknqde8y6Fs7+zS7M2wFV5BSiSRyydrW 3SVVisu/luRk+WDeH6ncI9iKlWcVCCLctvYP0IZ9357XlsPkz01Kvnk41JB70U0A/MBW foh5zWH0SSlktQFnjOInbHWP+rmBoiZvf6U7xW75WFvTnWECPIYslZMbDwIGWmdlvuju OpAzZzBd0hSEFS4aPlRsiy+3nzTAJkSPCWvEgqkskogaesgBwfTnTxMOtm8W6kwmoIPY N/8iYZoA5YtyiT9qtSyFJfPw3pCxN9V6bgQ+0XIc9UFCK5aqG47SqJxxXquD9Y/aLQYc RlcQ==
X-Gm-Message-State: AIkVDXIPcON3zTAaWYrr4y3+2FaPOUflEGNFySTKCHSQoouHwyx/DvlCOpK7ZTGVxDoosQ==
X-Received: by 10.99.241.83 with SMTP id o19mr11326366pgk.195.1486049779950; Thu, 02 Feb 2017 07:36:19 -0800 (PST)
Received: from Melindas-MacBook-Pro.local (209-112-217-13-radius.dynamic.acsalaska.net. [209.112.217.13]) by smtp.gmail.com with ESMTPSA id e127sm59412575pfh.89.2017.02.02.07.36.19 for <trans@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 02 Feb 2017 07:36:19 -0800 (PST)
To: "trans@ietf.org" <trans@ietf.org>
From: Melinda Shore <melinda.shore@gmail.com>
Message-ID: <d2a9a76f-0269-eec2-6a37-dd85ec4feb30@gmail.com>
Date: Thu, 2 Feb 2017 06:36:17 -0900
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.6.0
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="xkq7Dlse5W6NwCwjMqWK8j8PnX6pe0RUU"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/Qz9FoGkwPyZWCmHgSUUTRBY92zc>
Subject: [Trans] Completed working group last call for the gossip document
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 15:36:22 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--xkq7Dlse5W6NwCwjMqWK8j8PnX6pe0RUU
Content-Type: multipart/mixed; boundary="bNvBWtWVRe3a8tvO8fVmv19eJmk0Le5pb";
 protected-headers="v1"
From: Melinda Shore <melinda.shore@gmail.com>
To: "trans@ietf.org" <trans@ietf.org>
Message-ID: <d2a9a76f-0269-eec2-6a37-dd85ec4feb30@gmail.com>
Subject: Completed working group last call for the gossip document

--bNvBWtWVRe3a8tvO8fVmv19eJmk0Le5pb
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi, all:

Working group last call for the gossip document
(draft-ietf-trans-gossip) closed with relatively little
comment.  Linus expressed concern that there wasn't
enough implementation experience to be confident in
the correctness of the document, but there was general
agreement that it would still be valuable to publish
it as an experimental RFC, as a starting point for
implementation and experimentation.  So, we're
sending the document along to the IESG for review and
publication.

Many thanks to Linus, DKG, and Tom for their work on
the draft, and to reviewers for their comments.

Melinda and Paul


--bNvBWtWVRe3a8tvO8fVmv19eJmk0Le5pb--

--xkq7Dlse5W6NwCwjMqWK8j8PnX6pe0RUU
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYk1HxAAoJELiGRpM6HoEu+HwP/jjJB+J2Ls1jRwWWZlobLK+o
gxScV7b65yR/2SLf5atFBvkPJeXR3Y55txJnj88b5N/wH9ZwOv86Pg77w6Vo6ww7
4V8gE7cTrX4CkryFA6HUVdOqD5ByMC0pSlfMQ+CUxC/XiXLvel8bPwiNMAiN/YyC
InvZQIdsP/iFkNujdsQEVpIEZfBNniqaa7f9DyetVxnhuknLMVzC2D5cO3HAvU8D
BEWclOyJXfAQndgXbUBJChvh4D7E30jEsqvXV3GMQrx7TGh8icsSzo3MXur0HwWM
anR3oo/00ogkqSv2WzwUuHQCW4N7dq3OICP7mI5zKX9xK5IU76YdU9TCFKOcbGYG
fskcfR+A3/V6TW4+TlcYf5PfTS+30ke6Zi82xDkflepUcJ/4bqaeofUXxQYpSDwD
E6lSEHMDK/KqfjOvU36YCCs17uv+4ej/I+BlUxQz2CzvShZsaX3sI5TAqdKuO+Kv
XX5xMFRbE9pR9yQ1RULJZSoJkFMb5j+x52TURTQAUNv+i9QZf+JpANAPRN/F4ZvV
mZFFgE+3aAgkclJz2uSEJ6wo/tkPif6UGGmaq/J/+k9fEf9f79DSXmMoqp/b83JD
+mk/L8eoq5YsHuqqhilKYYl+reV+JnEcff5lH89Jb9fY/+NLL/v57IS93gMtnksS
CQHrfqieDii+GO+4j01s
=FVxM
-----END PGP SIGNATURE-----

--xkq7Dlse5W6NwCwjMqWK8j8PnX6pe0RUU--


From nobody Thu Feb  2 11:34:27 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 65D2B12998A for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 11:34:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gHQ8nYGlzKHM for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 11:34:21 -0800 (PST)
Received: from mail-yb0-x22a.google.com (mail-yb0-x22a.google.com [IPv6:2607:f8b0:4002:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BEC63129994 for <trans@ietf.org>; Thu,  2 Feb 2017 11:34:20 -0800 (PST)
Received: by mail-yb0-x22a.google.com with SMTP id o65so7897748ybo.2 for <trans@ietf.org>; Thu, 02 Feb 2017 11:34:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=Y7brdvtJN4cLu3b0v38ThmYEd89YXCJQp/JO11C7whQ=; b=wKkYtg8buxQI6GKRQN1L9oyVKUlswZKfKVM9RbfOT9fuDVK0pZ9llIb2Gx+Ixh7hWT Vi9/SwYKhuMUYT+6ZBp/4kiiy7pUu+PDM6sIEbfQNPsuDazZrO3woOFIsegT9F6YwS4e fjUtvgJUHTu3cJqSotXzizd2oTMSOrMhK+Ec+ymLL5WyxDfsxNTpbcMz8rMgIB7jrpmP wBvFft+oUgfk297dyOn3NbvQuDB2RoEnGtk+Y6Tz8Lp+YHxU+fmAGyTdQyTzoqz8aqkI 74EeeHOSCyvXaM4jxSpLl0Hs+0cuI9pgYBSWTOCns8/jxvmsGfJlVj4ygU13dCF+CyB7 fdZQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=Y7brdvtJN4cLu3b0v38ThmYEd89YXCJQp/JO11C7whQ=; b=mOxaPOsSfycR356GVCC+fgQyl9YrolwSpmiMOaZD1bNb5O4u3xFfRH21Xzs/Y5i8er UbP87Saq35psEmnuM1z+TfxKzcx4MsY9dGLSPHzmTTLG0GLQcZHdulaWXk0WrGM/bm07 XHmIlOVVsQQxDDzzU2gpPWEuw99nV9IuVDwcqcTN2oJIH+BQb4LkRBW/k+VjzyFZD5bT B4lQmkgYWnZBKeTIrapkBCO+dziQG/Ef+OV/L6jTJ92BozPsegew8hMIKr3fFx/VZacL 0oIAmuPutR5MUYIbzdFEMvbXnEvB95rwpT2WANCpo7kFvfX9XO03F6FyHVyFYC1VTd2Q 9Sxg==
X-Gm-Message-State: AIkVDXKvqnHJxMBMCnx4vFi+yBFU14zo42xAaOCrUhbiTq6ML5RZiuWzTSIU35bEJG0jhuvzPzR8Ifs2Vk+CJQ==
X-Received: by 10.37.224.77 with SMTP id x74mr3268498ybg.80.1486064059956; Thu, 02 Feb 2017 11:34:19 -0800 (PST)
MIME-Version: 1.0
Received: by 10.13.204.80 with HTTP; Thu, 2 Feb 2017 11:33:39 -0800 (PST)
In-Reply-To: <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com>
References: <8f6852d8-05ae-5f72-8c09-0437cc963b2c@gmail.com> <CABcZeBObdV8DFDVpsSYO5_Wg=GH3JdhsNJa=-6mUmzaVNmE0TQ@mail.gmail.com> <CABrd9SRJw4t=hQ4wPBPR1rwsmZ08hiUn3MR+fiz6Fg4Y7iQFEg@mail.gmail.com> <CABcZeBPkzDcFUog+36BtNWBYOYmkfTsfQM7RAJ2h_w4Oc7EUXw@mail.gmail.com> <CABrd9SSShNAx8NUXx0NrNC9A8gNbAVJbczxe4aQeRmuUNjw82g@mail.gmail.com> <CABcZeBO1FuD+RmB73EAMSQgPynxOKNDZu_Gpic3P6rzqXi+WCA@mail.gmail.com> <b3ed4ab44d8547eb9922f93c65c1292b@usma1ex-dag1mb1.msg.corp.akamai.com> <4c0baba3-f85a-4154-c8af-10f84540cb12@gmail.com> <f070c7152969457d8ddceeff3d5119d2@usma1ex-dag1mb1.msg.corp.akamai.com> <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Thu, 2 Feb 2017 20:33:39 +0100
Message-ID: <CABcZeBOgGs_xsQB6cO0tPFEJdrRbCKOEjZh2uxa2_E8BfcSW6g@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: multipart/alternative; boundary=94eb2c086b34686ff20547914054
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/0YE0iHPiuHAl9RIEltUGHMtZZd4>
Cc: Richard Barnes <rlb@ipv.sx>, "trans@ietf.org" <trans@ietf.org>, Melinda Shore <melinda.shore@gmail.com>, Ben Laurie <benl@google.com>, Paul Wouters <paul@nohats.ca>
Subject: Re: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 19:34:25 -0000

--94eb2c086b34686ff20547914054
Content-Type: text/plain; charset=UTF-8

I thought it might be useful to elaborate on what I meant about
threat model and technology for CT. As I mentioned, I think there
are three primary threat models one might be concerned about:

1. CAs misissue but aren't malicious.
2. CAs are malicious or otherwise fail to log but logs are not
3. CAs and logs are both malicious


In threat model #1, what is mostly required is merely that CAs submit
certificates to logs. As long as every CA submits their certs to a
common log than misissuance can be detected without any client side
behavior at all. This is effectively CT as it is implemented for DV
today and as Ben indicates, it has detected misissuance already.

If CAs do not log (either maliciously or through mistake), then it is
necessary for RPs to refuse to accept certificates which are not
logged. However, as long as we believe that the logs behave correctly
(specifically, they never sign an SCT that they don't then log) then
all that is required is that a certificate contain SCTs from some set
of logs and that RPs check that. This is roughly CT as Chrome
proposes to implement as of end-of-2017.  Note that the Merkle tree
infrastructure is not needed here at all.

The final case is the one where logs are also malicious and collude
with a malicious CA to issue an SCT for a certificate but not to log
it. In order to detect this, you need to ensure that RPs have the same
view of the log structure as auditors do, because otherwise the CA can
issue a certificate which will be acceptable to the RP but will never
be audited [0]. The general notion for current CT is that there is
some notion of getting global consensus on the state of the log and
then the auditors and the RPs can know that they are checking the same
thing. This is where the Merkle tree infrastructure comes in (though
as I indicated previously, Richard and I do not believe it adequately
addresses this case).

Note that these are *all* detection use cases, but just detection
under particular threat models.

So, I think the question is: which threat model is this document
intended to address? It seems to me that the charter pretty clearly
comes down on #3, because it talks about "verifiable" logs and defines
verifiable in a way that seems to include log misissuance. But perhaps
I have misunderstood.

-Ekr


[0] This is just about avoiding TOCTOU bugs.







On Wed, Feb 1, 2017 at 7:51 AM, Eric Rescorla <ekr@rtfm.com> wrote:

>
> On Tue, Jan 31, 2017 at 7:50 PM, Salz, Rich <rsalz@akamai.com> wrote:
>
>> > We don't have consensus.  We're deadlocked and we're not getting
>> > sufficient input from the working group to break the deadlock.
>>
>> Well, yeah, that's why you get paid the big bucks, right? :)
>>
>> > Paul and I can make a decision on the particular question that's a
>> problem but
>> > it probably means an appeal and further delay.
>>
>> That's the process.
>>
>> > Frankly, this working group was chartered under the assumption that the
>> > goal was detection, not prevention.
>>
>> That's my perception as well.  Is there anyone who thinks prevention was
>> part of the scope?
>>
>
> I think this is painting with a bit too broad a brush. One needs to talk
> about
> detection under a specific threat model, as I indicated previously.
> Specifically,
> there seem to be a number of potential threat models:
>
> 1. CAs make mistakes but aren't malicious.
> 2. CAs are malicious but logs are not
> 3. CAs and logs are both malicious
>
> What technological solution is adequate to detect misissuance depends on
> which
> of these three threat models you think applies.
>
> -Ekr
>
>

--94eb2c086b34686ff20547914054
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>I thought it might be useful to elaborate on what I m=
eant about</div><div>threat model and technology for CT. As I mentioned, I =
think there</div><div>are three primary threat models one might be concerne=
d about:</div><div><br></div><div>1. CAs misissue but aren&#39;t malicious.=
</div><div>2. CAs are malicious or otherwise fail to log but logs are not</=
div><div>3. CAs and logs are both malicious</div><div><br></div><div><br></=
div><div>In threat model #1, what is mostly required is merely that CAs sub=
mit</div><div>certificates to logs. As long as every CA submits their certs=
 to a</div><div>common log than misissuance can be detected without any cli=
ent side</div><div>behavior at all. This is effectively CT as it is impleme=
nted for DV</div><div>today and as Ben indicates, it has detected misissuan=
ce already.</div><div><br></div><div>If CAs do not log (either maliciously =
or through mistake), then it is</div><div>necessary for RPs to refuse to ac=
cept certificates which are not</div><div>logged. However, as long as we be=
lieve that the logs behave correctly</div><div>(specifically, they never si=
gn an SCT that they don&#39;t then log) then</div><div>all that is required=
 is that a certificate contain SCTs from some set</div><div>of logs and tha=
t RPs check that. This is roughly CT as Chrome</div><div>proposes to implem=
ent as of end-of-2017.=C2=A0 Note that the Merkle tree</div><div>infrastruc=
ture is not needed here at all.</div><div><br></div><div>The final case is =
the one where logs are also malicious and collude</div><div>with a maliciou=
s CA to issue an SCT for a certificate but not to log</div><div>it. In orde=
r to detect this, you need to ensure that RPs have the same</div><div>view =
of the log structure as auditors do, because otherwise the CA can</div><div=
>issue a certificate which will be acceptable to the RP but will never</div=
><div>be audited [0]. The general notion for current CT is that there is</d=
iv><div>some notion of getting global consensus on the state of the log and=
</div><div>then the auditors and the RPs can know that they are checking th=
e same</div><div>thing. This is where the Merkle tree infrastructure comes =
in (though</div><div>as I indicated previously, Richard and I do not believ=
e it adequately</div><div>addresses this case).</div><div><br></div><div>No=
te that these are *all* detection use cases, but just detection</div><div>u=
nder particular threat models.</div><div><br></div><div>So, I think the que=
stion is: which threat model is this document</div><div>intended to address=
? It seems to me that the charter pretty clearly</div><div>comes down on #3=
, because it talks about &quot;verifiable&quot; logs and defines</div><div>=
verifiable in a way that seems to include log misissuance. But perhaps</div=
><div>I have misunderstood.</div><div><br></div><div>-Ekr</div><div><br></d=
iv><div><br></div><div>[0] This is just about avoiding TOCTOU bugs.</div><d=
iv><br></div><div><br></div><div><br></div><div><br></div><div><br></div><d=
iv><br></div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote=
">On Wed, Feb 1, 2017 at 7:51 AM, Eric Rescorla <span dir=3D"ltr">&lt;<a hr=
ef=3D"mailto:ekr@rtfm.com" target=3D"_blank">ekr@rtfm.com</a>&gt;</span> wr=
ote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border=
-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><div class=3D"=
h5"><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Tue, Jan 3=
1, 2017 at 7:50 PM, Salz, Rich <span dir=3D"ltr">&lt;<a href=3D"mailto:rsal=
z@akamai.com" target=3D"_blank">rsalz@akamai.com</a>&gt;</span> wrote:<br><=
blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px=
 #ccc solid;padding-left:1ex"><span>&gt; We don&#39;t have consensus.=C2=A0=
 We&#39;re deadlocked and we&#39;re not getting<br>
&gt; sufficient input from the working group to break the deadlock.<br>
<br>
</span>Well, yeah, that&#39;s why you get paid the big bucks, right? :)<br>
<span><br>
&gt; Paul and I can make a decision on the particular question that&#39;s a=
 problem but<br>
&gt; it probably means an appeal and further delay.<br>
<br>
</span>That&#39;s the process.<br>
<span><br>
&gt; Frankly, this working group was chartered under the assumption that th=
e<br>
&gt; goal was detection, not prevention.<br>
<br>
</span>That&#39;s my perception as well.=C2=A0 Is there anyone who thinks p=
revention was part of the scope?<br>
</blockquote></div><br></div></div></div><div class=3D"gmail_extra">I think=
 this is painting with a bit too broad a brush. One needs to talk about</di=
v><div class=3D"gmail_extra">detection under a specific threat model, as I =
indicated previously. Specifically,</div><div class=3D"gmail_extra">there s=
eem to be a number of potential threat models:</div><div class=3D"gmail_ext=
ra"><br></div><div class=3D"gmail_extra">1. CAs make mistakes but aren&#39;=
t malicious.</div><div class=3D"gmail_extra">2. CAs are malicious but logs =
are not</div><div class=3D"gmail_extra">3. CAs and logs are both malicious<=
br></div><div class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">Wh=
at technological solution is adequate to detect misissuance depends on whic=
h</div><div class=3D"gmail_extra">of these three threat models you think ap=
plies.</div><div class=3D"gmail_extra"><br></div><div class=3D"gmail_extra"=
>-Ekr<br></div><div class=3D"gmail_extra"><br></div></div>
</blockquote></div><br></div>

--94eb2c086b34686ff20547914054--


From nobody Thu Feb  2 11:34:45 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 265E5129993 for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 11:34:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UTBoqlhCbDxe for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 11:34:43 -0800 (PST)
Received: from mail-yw0-x234.google.com (mail-yw0-x234.google.com [IPv6:2607:f8b0:4002:c05::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 204C712999E for <trans@ietf.org>; Thu,  2 Feb 2017 11:34:39 -0800 (PST)
Received: by mail-yw0-x234.google.com with SMTP id l19so21563049ywc.2 for <trans@ietf.org>; Thu, 02 Feb 2017 11:34:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=SFuTU3Mz9xOJj6Wm29IC799F6kyJutzWErEi8A/pucg=; b=KrhfbUnVqMv84UlU5dGJJT+z6LRAl00YWbVnBCNGDzpFYmE7YsKloih+Ybq8QHBX60 MO+SyJ/QYmoe9H2Hd+tiwoqLDjr0pIq1l/SfgVNfFHJJ428nK+KlRekbiz7sWPt1QQ54 vyDSl5qexqvagINqxwvBe5Cj5DL13o7Y9uMEwYRhx7MO88vjYv2rlwTNg8tzc2zJuuQD 76avK30HJbMqXWRGzIdCPqmY3rtbQlsrauHvZJWSKJth6CaZe2JkO0zqlj4IyKF4yXeI cSQz0Vu4AqQj/bNBCG1CBz3qSBJKmR+w+vKboN1Ovp5u2GAtWert83a+7Rx6EN6pUKfi m4jQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=SFuTU3Mz9xOJj6Wm29IC799F6kyJutzWErEi8A/pucg=; b=E0mMLHzOQbBIQdD9V1BPpcpgW0KEZTN5y6Xc9riN7F6qpvArrqrmlDYci8j8Kj1ZRk LBzGCA3mYCl2/d7qfw2RYbyTAiXpD0Ew4/PwJYtt0Q/pnBmoTfCx4L6pOJvnps738/mA zCPtNCUV2N6pI9H2GaxS9a0E/k1MvoRZHT9Ynk8T8a/2KvGNvFYHsH6YEKschbhVY7mF DbQkonYVN6YZF9gfOijwt8G50EeV4e/06XmqkJsfoGyxtdd9iWHhIGyWJgsA2D7jtMiD 6kasZoBNtd+muq1E9yoLnNDjgCYTPlujHO7HImWJlyjJPBm5AhA0NflOPrEbOyHag8zZ BBrQ==
X-Gm-Message-State: AIkVDXLbiqqjv10gwiQ1h2hTkUfT06Fu/RAcX787T9sjgKqIbQ/Z7Ts4CALhkxrX5GCohzoWMqV8Bg9pcIUguA==
X-Received: by 10.129.137.129 with SMTP id z123mr7720593ywf.327.1486064078439;  Thu, 02 Feb 2017 11:34:38 -0800 (PST)
MIME-Version: 1.0
Received: by 10.13.204.80 with HTTP; Thu, 2 Feb 2017 11:33:57 -0800 (PST)
In-Reply-To: <87964cd08db8405582b5cc7bce7b679d@usma1ex-dag1mb1.msg.corp.akamai.com>
References: <8f6852d8-05ae-5f72-8c09-0437cc963b2c@gmail.com> <CABcZeBObdV8DFDVpsSYO5_Wg=GH3JdhsNJa=-6mUmzaVNmE0TQ@mail.gmail.com> <CABrd9SRJw4t=hQ4wPBPR1rwsmZ08hiUn3MR+fiz6Fg4Y7iQFEg@mail.gmail.com> <CABcZeBPkzDcFUog+36BtNWBYOYmkfTsfQM7RAJ2h_w4Oc7EUXw@mail.gmail.com> <CABrd9SSShNAx8NUXx0NrNC9A8gNbAVJbczxe4aQeRmuUNjw82g@mail.gmail.com> <CABcZeBO1FuD+RmB73EAMSQgPynxOKNDZu_Gpic3P6rzqXi+WCA@mail.gmail.com> <b3ed4ab44d8547eb9922f93c65c1292b@usma1ex-dag1mb1.msg.corp.akamai.com> <4c0baba3-f85a-4154-c8af-10f84540cb12@gmail.com> <f070c7152969457d8ddceeff3d5119d2@usma1ex-dag1mb1.msg.corp.akamai.com> <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com> <87964cd08db8405582b5cc7bce7b679d@usma1ex-dag1mb1.msg.corp.akamai.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Thu, 2 Feb 2017 20:33:57 +0100
Message-ID: <CABcZeBPG3hd5V9wgx3B-CpUP6x=+B0Z75KtU9N84jJHi9Y7Stw@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: multipart/alternative; boundary=94eb2c06bf38827c4c054791414a
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/e-g09WbTiDTYv-igSI-Oge7l_TE>
Cc: Richard Barnes <rlb@ipv.sx>, "trans@ietf.org" <trans@ietf.org>, Melinda Shore <melinda.shore@gmail.com>, Ben Laurie <benl@google.com>, Paul Wouters <paul@nohats.ca>
Subject: Re: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 19:34:44 -0000

--94eb2c06bf38827c4c054791414a
Content-Type: text/plain; charset=UTF-8

On Wed, Feb 1, 2017 at 3:03 PM, Salz, Rich <rsalz@akamai.com> wrote:

> > 1. CAs make mistakes but aren't malicious.
> > 2. CAs are malicious but logs are not
> > 3. CAs and logs are both malicious
>
> The original focus was mainly about catching wrong certs, which was really
> a focus on CA mis-issuance.  Logs were intended to be a check on that, and
> monitors and auditors were layers on top that would catch erroneous logs.
>
> Have you read the threat model doc?  I assume yes, but it never hurts to
> ask.
>

Yes, I have. I think it does a pretty good job of analyzing the various
cases.

-Ekr

--94eb2c06bf38827c4c054791414a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Feb 1, 2017 at 3:03 PM, Salz, Rich <span dir=3D"ltr">&lt;<a hre=
f=3D"mailto:rsalz@akamai.com" target=3D"_blank">rsalz@akamai.com</a>&gt;</s=
pan> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex=
;border-left:1px #ccc solid;padding-left:1ex"><span class=3D"">&gt; 1. CAs =
make mistakes but aren&#39;t malicious.<br>
&gt; 2. CAs are malicious but logs are not<br>
&gt; 3. CAs and logs are both malicious<br>
<br>
</span>The original focus was mainly about catching wrong certs, which was =
really a focus on CA mis-issuance.=C2=A0 Logs were intended to be a check o=
n that, and monitors and auditors were layers on top that would catch erron=
eous logs.<br>
<br>
Have you read the threat model doc?=C2=A0 I assume yes, but it never hurts =
to ask.<br></blockquote><div><br></div><div>Yes, I have. I think it does a =
pretty good job of analyzing the various cases.</div><div><br></div><div>-E=
kr</div><div>=C2=A0</div></div><br></div></div>

--94eb2c06bf38827c4c054791414a--


From nobody Thu Feb  2 14:29:47 2017
Return-Path: <agwa@andrewayer.name>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7D121295A8 for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 14:29:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level: 
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewayer.name
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6DmZWY1wj1PX for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 14:29:46 -0800 (PST)
Received: from alcazar.beanwood.com (alcazar.beanwood.com [IPv6:2600:3c00:e000:6c::1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0518B129574 for <trans@ietf.org>; Thu,  2 Feb 2017 14:29:45 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=andrewayer.name; s=beanwood20160511; t=1486074585; bh=gMhf6qzrFCbrY0vh2LzG7zHmLcqcUhOGM6/bDf46v9o=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=uAPS6pWnsNFcOCxDyPB4+6KVd1PgdZc5pQiNdv/njcJjW4C7FoenPlCjDCK5yPrvU R6OoAMHdH14dWH+PpCZcNgNtyBS9NI5ABjoSNsQ//fR2hDkBfK5DTEULdH1almH/50 fW9Y866Tbyxgq2D75yDKI36h+wEx1GtCLYrNDNmS3odx7/8w+8Kwocjitd7xHTxypH nJVkapx+zqUCQ6Grfs2TF4PzMxUwLtvxqowuD6jAciQq8Z3IdGuBWhH+KR9hxOqm1B 9ddGjAh5/KJdXJrNL0rOzgneyoQtZAz3flUhRM1VydCN9sVZ0auSEbYXxXS059KYRJ q6tqE+S2HtV4g==
Date: Thu, 2 Feb 2017 14:29:44 -0800
From: Andrew Ayer <agwa@andrewayer.name>
To: Richard Barnes <rlb@ipv.sx>
Message-Id: <20170202142944.bb864e58ac412bbd5c7cab87@andrewayer.name>
In-Reply-To: <CAL02cgQ-dYT3o7NWc8JZw7Knuv2ssRAvkhmbLiyMYT8dWX9MfA@mail.gmail.com>
References: <CAL02cgQ-dYT3o7NWc8JZw7Knuv2ssRAvkhmbLiyMYT8dWX9MfA@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/sA7ZrHIsuqWvIkF0B4I8dv8nKsY>
Cc: Eric Rescorla <ekr@rtfm.com>, trans@ietf.org
Subject: Re: [Trans] WGLC comments on draft-ietf-trans-6962-bis-24
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Feb 2017 22:29:47 -0000

On Mon, 16 Jan 2017 17:23:27 -0500
Richard Barnes <rlb@ipv.sx> wrote:

> Clearly in order to be efficient, multiple certs must chain back up
> to the same STH; this is also a privacy requirement because otherwise
> retrieving a given STH leaks which certificate you are verifying.
> For similar privacy reasons, clients need to proactively download and
> validate every STH they might encounter, to avoid making queries for
> STHs (which leak browsing history). 

Hi Richard,

As you point out, the privacy concern with fetching an STH's consistency
proof can be addressed by requiring that multiple certificates "chain
back" to any given STH.  Why then is it necessary for clients to
proactively download and validate every STH?  Could clients not fetch
consistency proofs on demand the first time they see an STH (and then
cache the STH so they don't have to fetch the proof again)?  If so,
that would eliminate your concern with clients having to download 4MB
a month.

Regards,
Andrew


From nobody Thu Feb  2 20:32:42 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F9F5129B80 for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 20:32:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.654
X-Spam-Level: 
X-Spam-Status: No, score=-2.654 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-1.156, RCVD_IN_SORBS_SPAM=0.5, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hwx9Mg6LZipP for <trans@ietfa.amsl.com>; Thu,  2 Feb 2017 20:32:40 -0800 (PST)
Received: from homiemail-a97.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5196F129B7F for <trans@ietf.org>; Thu,  2 Feb 2017 20:32:40 -0800 (PST)
Received: from homiemail-a97.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a97.g.dreamhost.com (Postfix) with ESMTP id B8408A003A07 for <trans@ietf.org>; Thu,  2 Feb 2017 20:32:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=HvHxOy+XOhOItN6wyH8TNRrMECo=; b= j3ZTRZv3RdJlubhAcStbJr9G8/qmQpTOVRAuipRAnuabGv1Rq/1Ms2oQlvcAcPnC m5oOQnff6r3cI9iBWWQ6al9aK9MuPFZvmVvFfqnOdXgQZlht/Kpmx0sAipmO4Fmz VOcQB3esm1GFvl699+h2iB3V7/+XWBr095eY1MVoqZA=
Received: from mail-lf0-f53.google.com (mail-lf0-f53.google.com [209.85.215.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a97.g.dreamhost.com (Postfix) with ESMTPSA id 8550BA000B3C for <trans@ietf.org>; Thu,  2 Feb 2017 20:32:39 -0800 (PST)
Received: by mail-lf0-f53.google.com with SMTP id v186so4036566lfa.1 for <trans@ietf.org>; Thu, 02 Feb 2017 20:32:39 -0800 (PST)
X-Gm-Message-State: AIkVDXIiyidwE/yA5o+mTxqJX1Mb7JQMYmOSsooO5PSoZcSaAfPCW/7jh3WMiGXcnSVdwfzkGBCoNtTRQi/S2Q==
X-Received: by 10.25.171.9 with SMTP id u9mr3687941lfe.151.1486096357714; Thu, 02 Feb 2017 20:32:37 -0800 (PST)
MIME-Version: 1.0
Received: by 10.25.92.154 with HTTP; Thu, 2 Feb 2017 20:32:37 -0800 (PST)
In-Reply-To: <CABcZeBOgGs_xsQB6cO0tPFEJdrRbCKOEjZh2uxa2_E8BfcSW6g@mail.gmail.com>
References: <8f6852d8-05ae-5f72-8c09-0437cc963b2c@gmail.com> <CABcZeBObdV8DFDVpsSYO5_Wg=GH3JdhsNJa=-6mUmzaVNmE0TQ@mail.gmail.com> <CABrd9SRJw4t=hQ4wPBPR1rwsmZ08hiUn3MR+fiz6Fg4Y7iQFEg@mail.gmail.com> <CABcZeBPkzDcFUog+36BtNWBYOYmkfTsfQM7RAJ2h_w4Oc7EUXw@mail.gmail.com> <CABrd9SSShNAx8NUXx0NrNC9A8gNbAVJbczxe4aQeRmuUNjw82g@mail.gmail.com> <CABcZeBO1FuD+RmB73EAMSQgPynxOKNDZu_Gpic3P6rzqXi+WCA@mail.gmail.com> <b3ed4ab44d8547eb9922f93c65c1292b@usma1ex-dag1mb1.msg.corp.akamai.com> <4c0baba3-f85a-4154-c8af-10f84540cb12@gmail.com> <f070c7152969457d8ddceeff3d5119d2@usma1ex-dag1mb1.msg.corp.akamai.com> <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com> <CABcZeBOgGs_xsQB6cO0tPFEJdrRbCKOEjZh2uxa2_E8BfcSW6g@mail.gmail.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Thu, 2 Feb 2017 20:32:37 -0800
X-Gmail-Original-Message-ID: <CAErg=HGNU40Wat9x9b+-xd27MYM11bCHy=Q1p6gHTox6G7vTZA@mail.gmail.com>
Message-ID: <CAErg=HGNU40Wat9x9b+-xd27MYM11bCHy=Q1p6gHTox6G7vTZA@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Content-Type: multipart/alternative; boundary=94eb2c1cc5e680f5ac054798c5b2
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/RbJVE_NLqAV2-cfdk1pUqmHsnTI>
Cc: "trans@ietf.org" <trans@ietf.org>, Richard Barnes <rlb@ipv.sx>, "Salz, Rich" <rsalz@akamai.com>, Melinda Shore <melinda.shore@gmail.com>, Paul Wouters <paul@nohats.ca>, Ben Laurie <benl@google.com>
Subject: Re: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 04:32:41 -0000

--94eb2c1cc5e680f5ac054798c5b2
Content-Type: text/plain; charset=UTF-8

On Thu, Feb 2, 2017 at 11:33 AM, Eric Rescorla <ekr@rtfm.com> wrote:

> If CAs do not log (either maliciously or through mistake), then it is
> necessary for RPs to refuse to accept certificates which are not
> logged. However, as long as we believe that the logs behave correctly
> (specifically, they never sign an SCT that they don't then log) then
> all that is required is that a certificate contain SCTs from some set
> of logs and that RPs check that. This is roughly CT as Chrome
> proposes to implement as of end-of-2017.  Note that the Merkle tree
> infrastructure is not needed here at all.
>

I believe you meant end-of-2016, but given that Chrome hasn't made the
statement you're attributing, it's not fair to say "proposes to implement
as of end-of-2017."


> The final case is the one where logs are also malicious and collude
> with a malicious CA to issue an SCT for a certificate but not to log
> it. In order to detect this, you need to ensure that RPs have the same
> view of the log structure as auditors do, because otherwise the CA can
> issue a certificate which will be acceptable to the RP but will never
> be audited [0]. The general notion for current CT is that there is
> some notion of getting global consensus on the state of the log and
> then the auditors and the RPs can know that they are checking the same
> thing. This is where the Merkle tree infrastructure comes in (though
> as I indicated previously, Richard and I do not believe it adequately
> addresses this case).
>

It's unclear to me, from your remarks and Richard remarks earlier, whether
you believe this goal is explicitly not achieved under the current
proposals. It seems that you accept the current proposal actually does
address this, but that you're unhappy with there being any window between
issuance and global consensus. That is, there's agreement that the current
model provides detection under a certain set of bounded constraints, but
you want to reduce that.

The rest of Richard's message seems to focus on whether the system is
believed to be sufficiently scalable, but I don't know that there's
consensus with Richard's assertion - that is, that CT is too inefficient to
be deployed at scale. Indeed, much of the calculation seems to be based on
an assumption of a design that tightens the detection window, rather than
alternatives; the point being that the inefficiency Richard notes is itself
an issue with Richard's proposal, not an intrinsic property.

--94eb2c1cc5e680f5ac054798c5b2
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Thu, Feb 2, 2017 at 11:33 AM, Eric Rescorla <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:ekr@rtfm.com" target=3D"_blank">ekr@rtfm.com</a>&gt;</span>=
 wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bor=
der-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div>If CAs do n=
ot log (either maliciously or through mistake), then it is<br></div><div>ne=
cessary for RPs to refuse to accept certificates which are not</div><div>lo=
gged. However, as long as we believe that the logs behave correctly</div><d=
iv>(specifically, they never sign an SCT that they don&#39;t then log) then=
</div><div>all that is required is that a certificate contain SCTs from som=
e set</div><div>of logs and that RPs check that. This is roughly CT as Chro=
me</div><div>proposes to implement as of end-of-2017.=C2=A0 Note that the M=
erkle tree</div><div>infrastructure is not needed here at all.</div></div><=
/blockquote><div><br></div><div>I believe you meant end-of-2016, but given =
that Chrome hasn&#39;t made the statement you&#39;re attributing, it&#39;s =
not fair to say &quot;proposes to implement as of end-of-2017.&quot;</div><=
div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e=
x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div>The fi=
nal case is the one where logs are also malicious and collude</div><div>wit=
h a malicious CA to issue an SCT for a certificate but not to log</div><div=
>it. In order to detect this, you need to ensure that RPs have the same</di=
v><div>view of the log structure as auditors do, because otherwise the CA c=
an</div><div>issue a certificate which will be acceptable to the RP but wil=
l never</div><div>be audited [0]. The general notion for current CT is that=
 there is</div><div>some notion of getting global consensus on the state of=
 the log and</div><div>then the auditors and the RPs can know that they are=
 checking the same</div><div>thing. This is where the Merkle tree infrastru=
cture comes in (though</div><div>as I indicated previously, Richard and I d=
o not believe it adequately</div><div>addresses this case).</div></div></bl=
ockquote><div><br></div><div>It&#39;s unclear to me, from your remarks and =
Richard remarks earlier, whether you believe this goal is explicitly not ac=
hieved under the current proposals. It seems that you accept the current pr=
oposal actually does address this, but that you&#39;re unhappy with there b=
eing any window between issuance and global consensus. That is, there&#39;s=
 agreement that the current model provides detection under a certain set of=
 bounded constraints, but you want to reduce that.</div><div><br></div><div=
>The rest of Richard&#39;s message seems to focus on whether the system is =
believed to be sufficiently scalable, but I don&#39;t know that there&#39;s=
 consensus with Richard&#39;s assertion - that is, that CT is too inefficie=
nt to be deployed at scale. Indeed, much of the calculation seems to be bas=
ed on an assumption of a design that tightens the detection window, rather =
than alternatives; the point being that the inefficiency Richard notes is i=
tself an issue with Richard&#39;s proposal, not an intrinsic property.</div=
></div></div></div>

--94eb2c1cc5e680f5ac054798c5b2--


From nobody Fri Feb  3 05:49:52 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7498F129CEF for <trans@ietfa.amsl.com>; Fri,  3 Feb 2017 05:49:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t8pjBkbuOYgS for <trans@ietfa.amsl.com>; Fri,  3 Feb 2017 05:49:48 -0800 (PST)
Received: from mail-yb0-x22f.google.com (mail-yb0-x22f.google.com [IPv6:2607:f8b0:4002:c09::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64146129CFB for <trans@ietf.org>; Fri,  3 Feb 2017 05:49:48 -0800 (PST)
Received: by mail-yb0-x22f.google.com with SMTP id w194so6049477ybe.0 for <trans@ietf.org>; Fri, 03 Feb 2017 05:49:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=FW0OCKGifyfEsuQlywBAr5+hTyNlqEf0/qRcDhotNes=; b=j9VAwHWZMLucEGsSuCkD03mqdG1dmnCTU0ep8mHzOu1OykRgZOcYiGVBJmvYq2NOCG +hbnBk5NdCrsrxY3A9ADBI6O6tsB6Kq2DPcWoBptzg9UUgxm+tUqBOGIF+IpPPRFbXOU dWBPQO+Z36OuUifBWaEYXJqBfikJdw6HTlVPFAyNy2ueFRbg3tdq3X2PIgMP/ZqMiK9z jYBs7C0khzESuJmhHOTurGee02XiAr2Ww41NZnyaEVaA1IciFm4AmJTyjKUMs778ZWnA jykoydw47VCh6GSn9/F8R8BATMdL13IL+6aQduiDitZNAW3YBj+epRc+p17u00Rv/9yW wLDQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=FW0OCKGifyfEsuQlywBAr5+hTyNlqEf0/qRcDhotNes=; b=ebRzE14VWou7I3eBi1J8Jcqn7kfeS806nis6+v3vfrZZopzB8M4S00m8MhjPwmt6RX Ku8aBChX9KmO1ow/jG5dcdzyBnieZdi1uBohEwr3vAVDDRLc7drCxuStvLDhUob3Z/A5 aQdqMK+gdxHu5Z7bAO6Fchz1IhXzYMlEBD1RtAR65z/kpZGIo/gAiDtN+RpLqNbtMICc DKggoqJfpPj+XuzFRimBXc+NVK4nJKD1Dn3cf5VGsiA2yHU4u3XAUt5iQqaDuUh6fv/H bZ0rCvrPeLIh2RmPrTXcO24aC9JbAkuYRDlMfhE9FG7O8pUqjD00pI1IA3u8ZctHxFDC Mr3A==
X-Gm-Message-State: AIkVDXKG2top/vlmZmox6jDX9hZqIuSmZYFttLha0LWIHoNCZA0qF5UW263vIUtgEG+e2fkr21ODEKguRWosSA==
X-Received: by 10.37.124.195 with SMTP id x186mr5899553ybc.105.1486129787467;  Fri, 03 Feb 2017 05:49:47 -0800 (PST)
MIME-Version: 1.0
Received: by 10.13.204.80 with HTTP; Fri, 3 Feb 2017 05:49:06 -0800 (PST)
In-Reply-To: <CAErg=HGNU40Wat9x9b+-xd27MYM11bCHy=Q1p6gHTox6G7vTZA@mail.gmail.com>
References: <8f6852d8-05ae-5f72-8c09-0437cc963b2c@gmail.com> <CABcZeBObdV8DFDVpsSYO5_Wg=GH3JdhsNJa=-6mUmzaVNmE0TQ@mail.gmail.com> <CABrd9SRJw4t=hQ4wPBPR1rwsmZ08hiUn3MR+fiz6Fg4Y7iQFEg@mail.gmail.com> <CABcZeBPkzDcFUog+36BtNWBYOYmkfTsfQM7RAJ2h_w4Oc7EUXw@mail.gmail.com> <CABrd9SSShNAx8NUXx0NrNC9A8gNbAVJbczxe4aQeRmuUNjw82g@mail.gmail.com> <CABcZeBO1FuD+RmB73EAMSQgPynxOKNDZu_Gpic3P6rzqXi+WCA@mail.gmail.com> <b3ed4ab44d8547eb9922f93c65c1292b@usma1ex-dag1mb1.msg.corp.akamai.com> <4c0baba3-f85a-4154-c8af-10f84540cb12@gmail.com> <f070c7152969457d8ddceeff3d5119d2@usma1ex-dag1mb1.msg.corp.akamai.com> <CABcZeBN4VvAbyuyNQhMsQHtDPP8dDzmCCKvOrebmEjxQ5cC-Gw@mail.gmail.com> <CABcZeBOgGs_xsQB6cO0tPFEJdrRbCKOEjZh2uxa2_E8BfcSW6g@mail.gmail.com> <CAErg=HGNU40Wat9x9b+-xd27MYM11bCHy=Q1p6gHTox6G7vTZA@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 3 Feb 2017 05:49:06 -0800
Message-ID: <CABcZeBO8vB3v4eAwhY8c39RWtxN0wqO5d8ZURM2OBy48EU=Qzg@mail.gmail.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
Content-Type: multipart/alternative; boundary=001a114bc39612d2c70547a08e6d
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/vzW1fXM_w1CjcIZ3HclNERXZY6c>
Cc: "trans@ietf.org" <trans@ietf.org>, Richard Barnes <rlb@ipv.sx>, "Salz, Rich" <rsalz@akamai.com>, Melinda Shore <melinda.shore@gmail.com>, Paul Wouters <paul@nohats.ca>, Ben Laurie <benl@google.com>
Subject: Re: [Trans] Update on 6962-bis issues raised by Richard Barnes and EKR
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Feb 2017 13:49:50 -0000

--001a114bc39612d2c70547a08e6d
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Thu, Feb 2, 2017 at 8:32 PM, Ryan Sleevi <ryan-ietf@sleevi.com> wrote:

>
>
> On Thu, Feb 2, 2017 at 11:33 AM, Eric Rescorla <ekr@rtfm.com> wrote:
>
>> If CAs do not log (either maliciously or through mistake), then it is
>> necessary for RPs to refuse to accept certificates which are not
>> logged. However, as long as we believe that the logs behave correctly
>> (specifically, they never sign an SCT that they don't then log) then
>> all that is required is that a certificate contain SCTs from some set
>> of logs and that RPs check that. This is roughly CT as Chrome
>> proposes to implement as of end-of-2017.  Note that the Merkle tree
>> infrastructure is not needed here at all.
>>
>
> I believe you meant end-of-2016, but given that Chrome hasn't made the
> statement you're attributing, it's not fair to say "proposes to implement
> as of end-of-2017."
>

I am referring to this statement:
https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/78N3SMcqUGw/=
ykIwHXuqAQAJ

"This past week at the 39th meeting of the CA/Browser Forum, the Chrome
team announced plans that publicly trusted website certificates issued in
October 2017 or later will be expected to comply with Chrome=E2=80=99s Cert=
ificate
Transparency policy in order to be trusted by Chrome. "

As I understand that policy, certificates will be required to contain SCTs
from some
set of logs and Chrome will check that. I apologize if I have
misrepresented the situation
and I would appreciate any corrections or clarifications you may have.



The final case is the one where logs are also malicious and collude
>> with a malicious CA to issue an SCT for a certificate but not to log
>> it. In order to detect this, you need to ensure that RPs have the same
>> view of the log structure as auditors do, because otherwise the CA can
>> issue a certificate which will be acceptable to the RP but will never
>> be audited [0]. The general notion for current CT is that there is
>> some notion of getting global consensus on the state of the log and
>> then the auditors and the RPs can know that they are checking the same
>> thing. This is where the Merkle tree infrastructure comes in (though
>> as I indicated previously, Richard and I do not believe it adequately
>> addresses this case).
>>
>
> It's unclear to me, from your remarks and Richard remarks earlier, whethe=
r
> you believe this goal is explicitly not achieved under the current
> proposals. It seems that you accept the current proposal actually does
> address this, but that you're unhappy with there being any window between
> issuance and global consensus. That is, there's agreement that the curren=
t
> model provides detection under a certain set of bounded constraints, but
> you want to reduce that.
>
> The rest of Richard's message seems to focus on whether the system is
> believed to be sufficiently scalable, but I don't know that there's
> consensus with Richard's assertion - that is, that CT is too inefficient =
to
> be deployed at scale. Indeed, much of the calculation seems to be based o=
n
> an assumption of a design that tightens the detection window, rather than
> alternatives; the point being that the inefficiency Richard notes is itse=
lf
> an issue with Richard's proposal, not an intrinsic property.
>

It might be better to debate this under the thread where Richard and I
explicitly laid out our concerns
or on the conference call which I understand the chairs to be arranging.
The purpose of this parenthetical
was merely to note those in the context of my understanding of the purpose
of the various components of
the system.

With that said, I don't think that this is quite how I would state my
concern. Even ignoring the question
of detection window, it's not clear to us that there is a scalable story
that actually provides public
verifiability to clients.

-Ekr

--001a114bc39612d2c70547a08e6d
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Thu, Feb 2, 2017 at 8:32 PM, Ryan Sleevi <span dir=3D"ltr">&lt;<a hr=
ef=3D"mailto:ryan-ietf@sleevi.com" target=3D"_blank">ryan-ietf@sleevi.com</=
a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><=
div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quot=
e"><span class=3D"gmail-">On Thu, Feb 2, 2017 at 11:33 AM, Eric Rescorla <s=
pan dir=3D"ltr">&lt;<a href=3D"mailto:ekr@rtfm.com" target=3D"_blank">ekr@r=
tfm.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le=
ft:1ex"><div dir=3D"ltr"><div>If CAs do not log (either maliciously or thro=
ugh mistake), then it is<br></div><div>necessary for RPs to refuse to accep=
t certificates which are not</div><div>logged. However, as long as we belie=
ve that the logs behave correctly</div><div>(specifically, they never sign =
an SCT that they don&#39;t then log) then</div><div>all that is required is=
 that a certificate contain SCTs from some set</div><div>of logs and that R=
Ps check that. This is roughly CT as Chrome</div><div>proposes to implement=
 as of end-of-2017.=C2=A0 Note that the Merkle tree</div><div>infrastructur=
e is not needed here at all.</div></div></blockquote><div><br></div></span>=
<div>I believe you meant end-of-2016, but given that Chrome hasn&#39;t made=
 the statement you&#39;re attributing, it&#39;s not fair to say &quot;propo=
ses to implement as of end-of-2017.&quot;</div></div></div></div></blockquo=
te><div><br></div><div>I am referring to this statement:</div><div><a href=
=3D"https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/78N3SMcq=
UGw/ykIwHXuqAQAJ">https://groups.google.com/a/chromium.org/forum/#!msg/ct-p=
olicy/78N3SMcqUGw/ykIwHXuqAQAJ</a><br></div><div><br></div><div>&quot;This =
past week at the 39th meeting of the CA/Browser Forum, the Chrome=20
team announced plans that publicly trusted website certificates issued=20
in October 2017 or later will be expected to comply with Chrome=E2=80=99s=
=20
Certificate Transparency policy in order to be trusted by Chrome. &quot;</d=
iv><div><br></div><div>As I understand that policy, certificates will be re=
quired to contain SCTs from some</div><div>set of logs and Chrome will chec=
k that. I apologize if I have misrepresented the situation</div><div>and I =
would appreciate any corrections or clarifications you may have.</div><div>=
<br></div><div><br></div><div><br></div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pad=
ding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gm=
ail_quote"><span class=3D"gmail-"><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex"><div dir=3D"ltr"><div>The final case is the one where logs are a=
lso malicious and collude</div><div>with a malicious CA to issue an SCT for=
 a certificate but not to log</div><div>it. In order to detect this, you ne=
ed to ensure that RPs have the same</div><div>view of the log structure as =
auditors do, because otherwise the CA can</div><div>issue a certificate whi=
ch will be acceptable to the RP but will never</div><div>be audited [0]. Th=
e general notion for current CT is that there is</div><div>some notion of g=
etting global consensus on the state of the log and</div><div>then the audi=
tors and the RPs can know that they are checking the same</div><div>thing. =
This is where the Merkle tree infrastructure comes in (though</div><div>as =
I indicated previously, Richard and I do not believe it adequately</div><di=
v>addresses this case).</div></div></blockquote><div><br></div></span><div>=
It&#39;s unclear to me, from your remarks and Richard remarks earlier, whet=
her you believe this goal is explicitly not achieved under the current prop=
osals. It seems that you accept the current proposal actually does address =
this, but that you&#39;re unhappy with there being any window between issua=
nce and global consensus. That is, there&#39;s agreement that the current m=
odel provides detection under a certain set of bounded constraints, but you=
 want to reduce that.</div><div><br></div><div>The rest of Richard&#39;s me=
ssage seems to focus on whether the system is believed to be sufficiently s=
calable, but I don&#39;t know that there&#39;s consensus with Richard&#39;s=
 assertion - that is, that CT is too inefficient to be deployed at scale. I=
ndeed, much of the calculation seems to be based on an assumption of a desi=
gn that tightens the detection window, rather than alternatives; the point =
being that the inefficiency Richard notes is itself an issue with Richard&#=
39;s proposal, not an intrinsic property.</div></div></div></div></blockquo=
te><div><br></div><div>It might be better to debate this under the thread w=
here Richard and I explicitly laid out our concerns<br></div><div>or on the=
 conference call which I understand the chairs to be arranging. The purpose=
 of this parenthetical</div><div>was merely to note those in the context of=
 my understanding of the purpose of the various components of</div><div>the=
 system.</div><div><br></div><div>With that said, I don&#39;t think that th=
is is quite how I would state my concern. Even ignoring the question</div><=
div>of detection window, it&#39;s not clear to us that there is a scalable =
story that actually provides public</div><div>verifiability to clients.</di=
v><div><br></div><div>-Ekr</div><div><br></div><div><br></div></div><br></d=
iv></div>

--001a114bc39612d2c70547a08e6d--


From return-hd6ixwbvxdfrj5jkmhwwarrnz6@temporary-address.scs.stanford.edu  Fri Feb 10 15:12:42 2017
Return-Path: <return-hd6ixwbvxdfrj5jkmhwwarrnz6@temporary-address.scs.stanford.edu>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3831D1295D5; Fri, 10 Feb 2017 15:12:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 44VbmDnoyhRl; Fri, 10 Feb 2017 15:12:40 -0800 (PST)
Received: from market.scs.stanford.edu (www.scs.stanford.edu [IPv6:2001:470:806d:1::9]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C830F129401; Fri, 10 Feb 2017 15:12:37 -0800 (PST)
Received: from market.scs.stanford.edu (localhost [127.0.0.1]) by market.scs.stanford.edu (8.15.2/8.15.2) with ESMTP id v1ANCbnL007884; Fri, 10 Feb 2017 15:12:37 -0800 (PST)
Received: (from dm@localhost) by market.scs.stanford.edu (8.15.2/8.15.2/Submit) id v1ANCb8i010273; Fri, 10 Feb 2017 15:12:37 -0800 (PST)
From: David Mazieres <dm-list-ietf-ilc@scs.stanford.edu>
To: trans@ietf.org, saag@ietf.org, ilc@ietf.org
Date: Fri, 10 Feb 2017 15:12:37 -0800
Message-ID: <87poip3aje.fsf@ta.scs.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/DDd4QOI27xfo33A0XsGlN84EF0M>
X-Mailman-Approved-At: Fri, 10 Feb 2017 15:45:40 -0800
Subject: [Trans] Internet-level Consensus - new list and possible BoF
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: ilc@ietf.org
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Feb 2017 23:23:03 -0000

Several applications depend on Internet-wide consensus to secure an
append-only log, provide tamper-resistant timestamps, and atomically
commit transactions across mutually distrustful parties with no
preexisting relationship. Examples include:

* The IETF trans working group is specifying data structures and
  operational mechanisms for providing secure logging and auditing of
  TLS server certificates, but lacks a mechanism for determining
  consensus among logs (or consensus about whether or not a resource
  should be logged). These functions are currently served by an
  experimental gossip protocol that can potentially be strengthened
  through global consensus.

* The Stellar payment network, is used by remittance companies to trade
  currencies and send payments across the Internet.

* UCSD's SPAM (Secure PAckage Manager) project relies on a secure global
  log both to enable revocation of previously published vulnerable
  software packages and to guarantee that a particular software release
  has been publicly available for audit (somewhat like certificate
  transparency).

* Stellar has an ongoing secure naming project that aims to allow domain
  name owners to assign human-readable names to end-user public keys
  without retaining the ability to lie about those public keys
  undetected.

We have just created a new IETF mailing mailing list to discuss such
applications, the mechanisms that can meet their consensus needs, and a
potential role of the IETF in devising a stable specification for an
Internet-level consensus mechanism.  The home page for the list is here:

        https://www.ietf.org/mailman/listinfo/ilc

If there is interest in the topic, we would like to organize a BoF in
Chicago.  Please join the discussion on the list if you might be
interested in participating.

David


From dm-list-ietf-ilc@scs.stanford.edu  Fri Feb 10 15:33:31 2017
Return-Path: <dm-list-ietf-ilc@scs.stanford.edu>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A9E01295E8 for <trans@ietfa.amsl.com>; Fri, 10 Feb 2017 15:33:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QP6E9vNJ4SKY for <trans@ietfa.amsl.com>; Fri, 10 Feb 2017 15:33:28 -0800 (PST)
Received: from market.scs.stanford.edu (www.scs.stanford.edu [IPv6:2001:470:806d:1::9]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 119491295EB for <trans@ietf.org>; Fri, 10 Feb 2017 15:33:28 -0800 (PST)
Received: from market.scs.stanford.edu (localhost [127.0.0.1]) by market.scs.stanford.edu (8.15.2/8.15.2) with ESMTP id v1ANXRP5039873 for <trans@ietf.org>; Fri, 10 Feb 2017 15:33:27 -0800 (PST)
Received: (from dm@localhost) by market.scs.stanford.edu (8.15.2/8.15.2/Submit) id v1ANXRQF076380; Fri, 10 Feb 2017 15:33:27 -0800 (PST)
From: dm-list-ietf-ilc@scs.stanford.edu
To: trans@ietf.org
Date: Fri, 10 Feb 2017 15:33:27 -0800
Message-ID: <877f4xaaew.fsf@ta.scs.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/1yD5NfiWLEGMEJQsaDpf9BMqb60>
X-Mailman-Approved-At: Fri, 10 Feb 2017 15:45:40 -0800
Subject: [Trans] [Ilc] Internet-level Consensus - new list and possible BoF
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: ilc@ietf.org
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Feb 2017 23:42:39 -0000

Several applications depend on Internet-wide consensus to secure an
append-only log, provide tamper-resistant timestamps, and atomically
commit transactions across mutually distrustful parties with no
preexisting relationship. Examples include:

* The IETF trans working group is specifying data structures and
  operational mechanisms for providing secure logging and auditing of
  TLS server certificates, but lacks a mechanism for determining
  consensus among logs (or consensus about whether or not a resource
  should be logged). These functions are currently served by an
  experimental gossip protocol that can potentially be strengthened
  through global consensus.

* The Stellar payment network, is used by remittance companies to trade
  currencies and send payments across the Internet.

* UCSD's SPAM (Secure PAckage Manager) project relies on a secure global
  log both to enable revocation of previously published vulnerable
  software packages and to guarantee that a particular software release
  has been publicly available for audit (somewhat like certificate
  transparency).

* Stellar has an ongoing secure naming project that aims to allow domain
  name owners to assign human-readable names to end-user public keys
  without retaining the ability to lie about those public keys
  undetected.

We have just created a new IETF mailing mailing list to discuss such
applications, the mechanisms that can meet their consensus needs, and a
potential role of the IETF in devising a stable specification for an
Internet-level consensus mechanism.  The home page for the list is here:

        https://www.ietf.org/mailman/listinfo/ilc

If there is interest in the topic, we would like to organize a BoF in
Chicago.  Please join the discussion on the list if you might be
interested in participating.

David


From nobody Wed Feb 15 12:50:19 2017
Return-Path: <rlb@ipv.sx>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D7A201297CD for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 12:50:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6bHMpVxuZy0b for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 12:50:14 -0800 (PST)
Received: from mail-ua0-x230.google.com (mail-ua0-x230.google.com [IPv6:2607:f8b0:400c:c08::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C88D1297CE for <trans@ietf.org>; Wed, 15 Feb 2017 12:50:14 -0800 (PST)
Received: by mail-ua0-x230.google.com with SMTP id y9so114589495uae.2 for <trans@ietf.org>; Wed, 15 Feb 2017 12:50:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:from:date:message-id:subject:to; bh=9DpmgXYPDj1VNuVFU7nEWJZwVtKime2usGY3v64UI+Q=; b=XGLJ6s4fm9DZRztSPVQsjo+4oMI1jlksYePPB1/WgEQxPuiLQ398fSiOEga0sPmTzm L7Nswo+c5ZoIjKwZUOMMXYkiWr9jvnfBukbpBPFd8870OFT5D2Mi6aVHM6BL/iNAhFVu 7zV2njVzSY/WE203UgeERU81mN85+78MNe3B4Qd6l99HXLwRRhWZL05hZP4vnS4ivc8V DMHKpfTcNzZl8dJ0+pEivyeeAkhfFKEA5v/SWr1Cr0V1AnTj9NSIecmw2AI7KFlCRIsU q/W+9bqxfbNyHQnePlbV/0edB/3jPk1aDtmXLON/svdNU4kxebTpXkJoovqKzHxai6D9 E4oA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=9DpmgXYPDj1VNuVFU7nEWJZwVtKime2usGY3v64UI+Q=; b=tegnXJhGHrni3/VHh9m5lpC1M1/mDUIsCedi+cTZywuQhQ9Yk/2uu8/kvshQME4muL /SCPR/E6mfYzB8GwtX9ynL7UhfO2Ngyif1g+lnOjbPfTNz+ahG1vYfoaziwbuo03Em5e BXAyFL/zPSlZSccrhlyt+x3mPNXudoY3dPeDXnTMn1IsAxvsRG5GnuIhiZf80hmj34q0 6dbCSS+nNby+PLRWYOv4LoP0Wp84qteSGzGJQ2zSDGjepdQ2eAMuOaCj05aw3DHgxTNg kHkk9wjAhRupZZvaZJK6tG+EJzfFZQ9lE8AmEtTzBrUkJPYkRXR0cRryxDfmLnwxQCW3 KomQ==
X-Gm-Message-State: AMke39nD8wU4/SogS6iXOpFHFBOZ9Rbu6tQF2N7rj8VqMmW/kouEXWuzyzMfZfUXJcFom1JZkL0jTU9GGtavvA==
X-Received: by 10.176.2.113 with SMTP id 104mr1108770uas.155.1487191813105; Wed, 15 Feb 2017 12:50:13 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.179.140 with HTTP; Wed, 15 Feb 2017 12:50:12 -0800 (PST)
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 15 Feb 2017 12:50:12 -0800
Message-ID: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
To: trans@ietf.org
Content-Type: multipart/alternative; boundary=001a113e4b92bc362b054897d33f
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/tkzy690WVngXkdhbfveKCdAgiQ8>
Subject: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Feb 2017 20:50:18 -0000

--001a113e4b92bc362b054897d33f
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Dear TRANS,

We had a call between a group of us last week that was helpful in
clarifying my thinking here.  I wanted to follow up to the list with some
more detailed thoughts.

At base, in order to meet this group=E2=80=99s charter deliverables, what w=
e want
to be assured of is that the mechanisms in 6962-bis that are intended to
enable public verifiability can actually do so in practice.  That is, we
need to establish that there is at least one plausible story for how some
substantial fraction of the statements logs provide to clients end up
getting audited.

Part of the issue here is that we don=E2=80=99t have a full story anywhere =
in the
documents for how auditing works at scale, and there are a couple of
incomplete models floating around that lead to different design
requirements for the public verifiability parts of CT, i.e., the part that
is now the Merkle tree.  So let=E2=80=99s consider two straw-man models and=
 look at
the differences they lead to.  Call them =E2=80=9COption G=E2=80=9D and =E2=
=80=9COption M=E2=80=9D :)

In the below, we assume:

- "STH" is a general term for an object that:
  1. represents the state of a log at a given time
  2. is signed by the log
  3. can be verified to fit into a linear sequence with other STHs
- Server cannot be relied upon to take action, so any CT information needs
to come to the client from the CA


Option G: Cache one STH / dynamic inclusion proofs


1. Auditor pulls STHs from logs at some frequency, validates consistency
2. Periodically, the client obtains from the auditor:
  a. The latest validated STH
  b. A proof of consistency from the last STH the client received
3. Client is configured to talk to a log proxy over DNS (for privacy)
4. Client gets SCT from server
5. Client audits by fetching inclusion proof to current STH from log proxy
over DNS


- [PRO] CA can issue immediately due to use of SCTs
- [PRO] Client only has to keep latest SCT
- [PRO] Compatible with existing CA practices w.r.t. SCTs
- [CON] Client has to reveal browsing history to log proxy in queries
- [CON] Audit failure from DNS failure indistinguishable from log
malfeasance
- [CON] Someone needs to operate a log proxy
- [CON] Requirement for audit-time fetches effectively forces audits to be
off-line w.r.t. certificate verification / TLS connection time


Option M: Cache many STHs / static inclusion proofs


1. Auditor pulls STHs from logs at some frequency, validates consistency
2. Periodically, the client obtains from the auditor:
  a. A list of all STHs since the last one the client received
  b. Proofs of consistency along this chain
3. Client caches entire history of STHs that it has received (really just
needs to store tree heads)
4. Client gets inclusion proof to an STH from server (either in the
certificate or in a stapled OCSP response), verifies it
5. Client audits by verifying that the STH provided by the server is in the
validated cache


- [PRO] Client never makes queries that are dependent on browsing history
- [PRO] Auditing can only fail if client state is stale (no live queries)
- [PRO] No need for a log proxy
- [PRO] If inclusion proof is provided at connection / validation time,
then auditing can be done immediately for certificates that are old enough
for their STHs to have propagated
- [CON] CA needs to wait for inclusion proof if inclusion proof is included
in cert
- [CON] Client needs to store entire history of STHs
- [CON] Requires CAs to upgrade to fetch inclusion proofs instead of / in
addition to SCTs


# Requirements for STHs / log structure

Option G requires:

- STHs can be issued relatively infrequently (say daily)
- Inclusion proofs need to be log depth to any STH

Option M requires:

- STHs need to be issued relatively frequently (say ~5-10min)
- Inclusion proofs need to be log depth only to the proximal STH

Option G leads naturally to the current design, with a global Merkle tree.
Option M leads to something like a Haber-Stornetta hash chain of batch
Merkle trees.  And conversely, each of these log structures is unfriendly
to the other operational model.

In general, whatever structure is assigned to the log in 6962-bis will
encode assumptions about the operation of the overall system.  So we need
to discuss the overall system before we decide on the log structure.


# What this means for 6962bis

Whatever we specify in 6962bis will enable some models for auditing and
make other models infeasible.  It=E2=80=99s important that whichever models=
 6962bis
enables not have other features that make them infeasible to deploy.

It seems to me that the two models above stake out roughly the two ends of
the design space.  I believe Option G is pretty much what Google is
planning to deploy right now, though of course I might be mistaken about
that.

Personally, between the two, I find Option M much more appealing, largely
because the failings of Option G seem much more intractable.  Log proxies
seem like a significant addition to the required infrastructure here, and
the analysis required to separate mundane failures in queries to the log
proxy from attacks on auditing seems likely to go awry.   And I have a lot
of difficulty imagining any mechanism for client queries that I would be
comfortable with from a privacy point of view.

Option M is not without problems.  We=E2=80=99ll need to find some way to a=
ddress
the issuance delay problem, whether that entails some OCSP magic to bridge
the gap or just getting the merge delays down to where the delay is
acceptable to CAs.  We=E2=80=99ll need to work out some migration question =
about
how

But in any case, we need to get more alignment among the stakeholders here
on what models for auditing are acceptable before we finalize the public
verification mechanisms in 6962bis.

Obviously, the countersignature-related parts of the document are not tied
up in this discussion at all, so if someone wants to pull those out into a
separate document, I would have no problem advancing that to PS straight
away.

=E2=80=94Richard

--001a113e4b92bc362b054897d33f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Dear TRANS,<br><br>We had a call between a group of us las=
t week that was helpful in clarifying my thinking here.=C2=A0 I wanted to f=
ollow up to the list with some more detailed thoughts.<br><br>At base, in o=
rder to meet this group=E2=80=99s charter deliverables, what we want to be =
assured of is that the mechanisms in 6962-bis that are intended to enable p=
ublic verifiability can actually do so in practice.=C2=A0 That is, we need =
to establish that there is at least one plausible story for how some substa=
ntial fraction of the statements logs provide to clients end up getting aud=
ited.<br><br>Part of the issue here is that we don=E2=80=99t have a full st=
ory anywhere in the documents for how auditing works at scale, and there ar=
e a couple of incomplete models floating around that lead to different desi=
gn requirements for the public verifiability parts of CT, i.e., the part th=
at is now the Merkle tree.=C2=A0 So let=E2=80=99s consider two straw-man mo=
dels and look at the differences they lead to.=C2=A0 Call them =E2=80=9COpt=
ion G=E2=80=9D and =E2=80=9COption M=E2=80=9D :)<br><br>In the below, we as=
sume:<br><br>- &quot;STH&quot; is a general term for an object that:<br>=C2=
=A0 1. represents the state of a log at a given time<br>=C2=A0 2. is signed=
 by the log<br>=C2=A0 3. can be verified to fit into a linear sequence with=
 other STHs<br>- Server cannot be relied upon to take action, so any CT inf=
ormation needs to come to the client from the CA<br><br><br>Option G: Cache=
 one STH / dynamic inclusion proofs<br><br><br>1. Auditor pulls STHs from l=
ogs at some frequency, validates consistency<br>2. Periodically, the client=
 obtains from the auditor:<br>=C2=A0 a. The latest validated STH<br>=C2=A0 =
b. A proof of consistency from the last STH the client received<br>3. Clien=
t is configured to talk to a log proxy over DNS (for privacy)<br>4. Client =
gets SCT from server<br>5. Client audits by fetching inclusion proof to cur=
rent STH from log proxy over DNS<br><br><br>- [PRO] CA can issue immediatel=
y due to use of SCTs<br>- [PRO] Client only has to keep latest SCT<br>- [PR=
O] Compatible with existing CA practices w.r.t. SCTs<br>- [CON] Client has =
to reveal browsing history to log proxy in queries<br>- [CON] Audit failure=
 from DNS failure indistinguishable from log malfeasance<br>- [CON] Someone=
 needs to operate a log proxy<br>- [CON] Requirement for audit-time fetches=
 effectively forces audits to be off-line w.r.t. certificate verification /=
 TLS connection time<br><br><br>Option M: Cache many STHs / static inclusio=
n proofs<br><br><br>1. Auditor pulls STHs from logs at some frequency, vali=
dates consistency<br>2. Periodically, the client obtains from the auditor:<=
br>=C2=A0 a. A list of all STHs since the last one the client received <br>=
=C2=A0 b. Proofs of consistency along this chain<br>3. Client caches entire=
 history of STHs that it has received (really just needs to store tree head=
s)<br>4. Client gets inclusion proof to an STH from server (either in the c=
ertificate or in a stapled OCSP response), verifies it<br>5. Client audits =
by verifying that the STH provided by the server is in the validated cache<=
br><br><br>- [PRO] Client never makes queries that are dependent on browsin=
g history<br>- [PRO] Auditing can only fail if client state is stale (no li=
ve queries)<br>- [PRO] No need for a log proxy<br>- [PRO] If inclusion proo=
f is provided at connection / validation time, then auditing can be done im=
mediately for certificates that are old enough for their STHs to have propa=
gated<br>- [CON] CA needs to wait for inclusion proof if inclusion proof is=
 included in cert<br>- [CON] Client needs to store entire history of STHs<b=
r>- [CON] Requires CAs to upgrade to fetch inclusion proofs instead of / in=
 addition to SCTs<br><br><br># Requirements for STHs / log structure<br><br=
>Option G requires:<br><br>- STHs can be issued relatively infrequently (sa=
y daily)<br>- Inclusion proofs need to be log depth to any STH<br><br>Optio=
n M requires:<br><br>- STHs need to be issued relatively frequently (say ~5=
-10min)<br>- Inclusion proofs need to be log depth only to the proximal STH=
<br><br>Option G leads naturally to the current design, with a global Merkl=
e tree.=C2=A0 Option M leads to something like a Haber-Stornetta hash chain=
 of batch Merkle trees.=C2=A0 And conversely, each of these log structures =
is unfriendly to the other operational model.<br><br>In general, whatever s=
tructure is assigned to the log in 6962-bis will encode assumptions about t=
he operation of the overall system.=C2=A0 So we need to discuss the overall=
 system before we decide on the log structure.<br><br><br># What this means=
 for 6962bis<br><br>Whatever we specify in 6962bis will enable some models =
for auditing and make other models infeasible.=C2=A0 It=E2=80=99s important=
 that whichever models 6962bis enables not have other features that make th=
em infeasible to deploy.<br><br>It seems to me that the two models above st=
ake out roughly the two ends of the design space.=C2=A0 I believe Option G =
is pretty much what Google is planning to deploy right now, though of cours=
e I might be mistaken about that.=C2=A0 <br><br>Personally, between the two=
, I find Option M much more appealing, largely because the failings of Opti=
on G seem much more intractable.=C2=A0 Log proxies seem like a significant =
addition to the required infrastructure here, and the analysis required to =
separate mundane failures in queries to the log proxy from attacks on audit=
ing seems likely to go awry.=C2=A0=C2=A0 And I have a lot of difficulty ima=
gining any mechanism for client queries that I would be comfortable with fr=
om a privacy point of view.<br><br>Option M is not without problems.=C2=A0 =
We=E2=80=99ll need to find some way to address the issuance delay problem, =
whether that entails some OCSP magic to bridge the gap or just getting the =
merge delays down to where the delay is acceptable to CAs.=C2=A0 We=E2=80=
=99ll need to work out some migration question about how <br><br>But in any=
 case, we need to get more alignment among the stakeholders here on what mo=
dels for auditing are acceptable before we finalize the public verification=
 mechanisms in 6962bis.<br><br>Obviously, the countersignature-related part=
s of the document are not tied up in this discussion at all, so if someone =
wants to pull those out into a separate document, I would have no problem a=
dvancing that to PS straight away.<br><br>=E2=80=94Richard<br><br></div>

--001a113e4b92bc362b054897d33f--


From nobody Wed Feb 15 14:35:55 2017
Return-Path: <tom@ritter.vg>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0236129880 for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 14:35:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ritter.vg
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 35YcnZjQQBSw for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 14:35:52 -0800 (PST)
Received: from mail-qk0-x22a.google.com (mail-qk0-x22a.google.com [IPv6:2607:f8b0:400d:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BFAE21293EE for <trans@ietf.org>; Wed, 15 Feb 2017 14:35:52 -0800 (PST)
Received: by mail-qk0-x22a.google.com with SMTP id p22so480528qka.0 for <trans@ietf.org>; Wed, 15 Feb 2017 14:35:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ritter.vg; s=vg; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=S3JPkwyRQDRX2FWPM5nMteZV0qpk2JLjE5cijOTiYms=; b=W4z7sRHDWzVKhovO5bidR5zEMK1gPR1AmXC70IoVP+VzAWEhBfU7t+Ze/sa/49bJoX HRDTD05QUCmZTtFGeSWDeE8LLcI51IEgpaeRPoQ1oclm852NtIhWPPjKC57IO1zvONA9 IEk/KiMjLZv+Wj1fJu1Jnn+zMqv6Q635jU8b8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=S3JPkwyRQDRX2FWPM5nMteZV0qpk2JLjE5cijOTiYms=; b=COAEgg8TDBi5ch8i9FQMe+KZa1+aI2B/PmgrhTYCZVgYarh9amHdw0FMufyPcNDamY tE41LF0c9HXnfi4Nmq2/KOypL12pxn+71DhhwQwVscAxP4F6+xkFKsnFQ382RI3EyG6s 4zyg95+QMuBlbz5p9fHClBg2ZgGzuzelrNXhXxXKnuaK5p7wJli5TbVhvdNsbTuLw/SP nI2cjEVAln2ShjFkw1UHDb/clAOTREhsAUxvr9Uad4eZhlJ1S3/wsDu869Ju7bNJy+cH AIstie6vIb8lTUJ1R/mD8HyFneP8IYePc0obnr1ekKsEZedlpI9wP9XZSS+/QCFz2lCY c73g==
X-Gm-Message-State: AMke39kfJah/J8iPC79MEN4ZUDb4s8CJ+ceR/8Yz8v03mja8AX1aWNxoIJ1vfTMZwu9Z1poTBwyUE635uxJBBQIq
X-Received: by 10.55.113.129 with SMTP id m123mr38918156qkc.47.1487198151557;  Wed, 15 Feb 2017 14:35:51 -0800 (PST)
MIME-Version: 1.0
Received: by 10.140.94.244 with HTTP; Wed, 15 Feb 2017 14:35:31 -0800 (PST)
In-Reply-To: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
From: Tom Ritter <tom@ritter.vg>
Date: Wed, 15 Feb 2017 16:35:31 -0600
Message-ID: <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/KaHEMbo1oVIfolLRot-z3VoR4tM>
Cc: "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Feb 2017 22:35:54 -0000

On 15 February 2017 at 14:50, Richard Barnes <rlb@ipv.sx> wrote:
> Dear TRANS,
>
> We had a call between a group of us last week that was helpful in clarify=
ing
> my thinking here.  I wanted to follow up to the list with some more detai=
led
> thoughts.
>
> At base, in order to meet this group=E2=80=99s charter deliverables, what=
 we want to
> be assured of is that the mechanisms in 6962-bis that are intended to ena=
ble
> public verifiability can actually do so in practice.  That is, we need to
> establish that there is at least one plausible story for how some
> substantial fraction of the statements logs provide to clients end up
> getting audited.
>
> Part of the issue here is that we don=E2=80=99t have a full story anywher=
e in the
> documents for how auditing works at scale, and there are a couple of
> incomplete models floating around that lead to different design requireme=
nts
> for the public verifiability parts of CT, i.e., the part that is now the
> Merkle tree.  So let=E2=80=99s consider two straw-man models and look at =
the
> differences they lead to.  Call them =E2=80=9COption G=E2=80=9D and =E2=
=80=9COption M=E2=80=9D :)
>
> In the below, we assume:
>
> - "STH" is a general term for an object that:
>   1. represents the state of a log at a given time
>   2. is signed by the log
>   3. can be verified to fit into a linear sequence with other STHs
> - Server cannot be relied upon to take action, so any CT information need=
s
> to come to the client from the CA
>
>
> Option G: Cache one STH / dynamic inclusion proofs
>
>
> 1. Auditor pulls STHs from logs at some frequency, validates consistency
> 2. Periodically, the client obtains from the auditor:
>   a. The latest validated STH
>   b. A proof of consistency from the last STH the client received
> 3. Client is configured to talk to a log proxy over DNS (for privacy)
> 4. Client gets SCT from server
> 5. Client audits by fetching inclusion proof to current STH from log prox=
y
> over DNS
>
>
> - [PRO] CA can issue immediately due to use of SCTs
> - [PRO] Client only has to keep latest SCT
> - [PRO] Compatible with existing CA practices w.r.t. SCTs
> - [CON] Client has to reveal browsing history to log proxy in queries
> - [CON] Audit failure from DNS failure indistinguishable from log
> malfeasance
> - [CON] Someone needs to operate a log proxy
> - [CON] Requirement for audit-time fetches effectively forces audits to b=
e
> off-line w.r.t. certificate verification / TLS connection time
>
>
> Option M: Cache many STHs / static inclusion proofs
>
>
> 1. Auditor pulls STHs from logs at some frequency, validates consistency
> 2. Periodically, the client obtains from the auditor:
>   a. A list of all STHs since the last one the client received
>   b. Proofs of consistency along this chain
> 3. Client caches entire history of STHs that it has received (really just
> needs to store tree heads)
> 4. Client gets inclusion proof to an STH from server (either in the
> certificate or in a stapled OCSP response), verifies it
> 5. Client audits by verifying that the STH provided by the server is in t=
he
> validated cache
>
>
> - [PRO] Client never makes queries that are dependent on browsing history
> - [PRO] Auditing can only fail if client state is stale (no live queries)
> - [PRO] No need for a log proxy
> - [PRO] If inclusion proof is provided at connection / validation time, t=
hen
> auditing can be done immediately for certificates that are old enough for
> their STHs to have propagated
> - [CON] CA needs to wait for inclusion proof if inclusion proof is includ=
ed
> in cert
> - [CON] Client needs to store entire history of STHs
> - [CON] Requires CAs to upgrade to fetch inclusion proofs instead of / in
> addition to SCTs


Neither option specifies what the client does when it finds some data
suspicious or how it shared said data with an auditor. I'm not sure
you can leave this unspecified while trying to decide the rest of
things. For example, in Option G do you report SCTs you can't resolve
inclusion proofs for after N tries? In Option M what do you do about
STHs you don't have in your verified cache? I'm also unclear if the
log proxy is also an auditor (it seems like it implies it is, but that
doesn't seem right.)

That Option M problem is an additional con I think:
[CON] Client must cache or otherwise handle the situation when the
inclusion proof is to a STH is doesn't know about. This could be
either an attack or just a newly issued certificate. This devolves to
the case of off-line verification in G.

-tom


From nobody Wed Feb 15 15:38:13 2017
Return-Path: <agwa@andrewayer.name>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8CE53129BCB for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 15:38:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewayer.name
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0Xz1CaeQ7zaq for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 15:38:09 -0800 (PST)
Received: from alcazar.beanwood.com (alcazar.beanwood.com [IPv6:2600:3c00:e000:6c::1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6BA1129B9E for <trans@ietf.org>; Wed, 15 Feb 2017 15:38:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=andrewayer.name; s=beanwood20160511; t=1487201889; bh=imCCKfZDYKRnfXwkRSXVwlbNnTTHu28yECQASFB+qHk=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=swWgb2d+IzTolGKU6WAjqiqwvBmGL5KBlMC6TaOENxqP0IfJPTmr/MJgYeafOWrHF FwUI9mTKV/u2FshSwJFgcEGCfsqpL6Kv5wN9ivOozI1d/O7AJRDWnv8ttX0fbzIK39 Nabg8E5q1XG4VV3AbjBLuQCufRv/5KEpY/m0VIHdUetdC6w8BEMk1iiauHrP/V7Uzf 5OarHVquRtJ2r2lMogp77mnbO9Knm0QpvUBjJ+CJxH18SoFoG1U0t0NRmzBxS1ahuR HzVrVXBAXhEQci/WlwWnfGZJGWRR5yYkhGlByoTYMzruh3Nlv1zgCa0sabhiFCA+QC NavUsi55Azi1Q==
Date: Wed, 15 Feb 2017 15:38:08 -0800
From: Andrew Ayer <agwa@andrewayer.name>
To: Richard Barnes <rlb@ipv.sx>
Message-Id: <20170215153808.1d276ae3c7a6a9be3c6b95b3@andrewayer.name>
In-Reply-To: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/vP9cCrCN6etNgHwK4tQCEXwicsM>
Cc: trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Feb 2017 23:38:11 -0000

On Wed, 15 Feb 2017 12:50:12 -0800
Richard Barnes <rlb@ipv.sx> wrote:
>
> [...]
>
> Option M: Cache many STHs / static inclusion proofs
>
> [...]
>
> - [PRO] If inclusion proof is provided at connection / validation
> time, then auditing can be done immediately for certificates that are
> old enough for their STHs to have propagated

Since a client cannot distinguish between a rogue STH and a legitimate
STH that it doesn't know about yet, it has no choice but to accept the
connection if it doesn't know about an STH and audit it later.  Therefore,
option M is no better than option G in this regard: both provide post-hoc
detection rather than prevention.  You can't call this a "pro" for option
M while simultaneously calling it a "con" for Option G.

> [...]
>
> Option M leads to something like a Haber-Stornetta hash chain
> of batch Merkle trees.

Why?  The only justification provided so far is that a client would
need to download 4MB of data a month, which is a "pretty big chunk of
data."[1]  This is a rather extraordinary claim.  Can you explain your
reasoning why 4MB a month is too much?

Even if 4MB/month is deemed excessive, there are other options which
avoid reliance on SCTs, but can be implemented on top of 6962bis'
current design without requiring clients to download 4MB a month.
Let's call them Options A1 and A2.

Option A1: Fetch consistency proofs on demand

1. Client gets an STH and an inclusion proof to the STH from server,
verifies the proof, and adds STH to a cache if not already present.

2. In the background, client audits unverified STHs in the cache
by requesting a consistency proof between the unverified STH and some
other verified STH.

- [PRO] No need to audit SCTs.
- [PRO] Although client makes queries (consistency proofs) that are triggered by
  browsing, the queries do not reveal browsing history because many certificates
  use inclusion proofs to the same STH.
- [PRO] No need for a log proxy.
- [PRO] Client only needs to fetch consistency proofs for STHs it actually sees.
- [PRO] Client only needs to store STHs it actually sees.
- [CON] CA needs to wait for inclusion proof if inclusion proof is included in cert.
- [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in addition to SCTs.

I asked you on-list two weeks ago why this wouldn't work[2], but you
have not replied.


Option A2: Publicly-logged STH batches

1. Auditor pulls STHs from logs at some frequency, validates consistency.

2. Periodically, auditor logs batches of STHs to CT logs.

3. Periodically, the client obtains from the auditor:
  a. Batches of STHs since the last one the client received
  b. Inclusion proofs for each STH batch up to the log's latest STH
  c. Consistency proof between the last STH received by the client and the latest STH

4. The client verifies all proofs received from auditor, but assumes
that the STHs in the batches are legitimate.

5. Client caches entire history of STHs that it has received (really
just needs to store tree heads).

6. Client gets inclusion proof to an STH from server (either in the
certificate or in a stapled OCSP response), verifies it.

7. Client audits by verifying that the STH provided by the server is in
the cache.

8. An ecosystem of auditors monitors logs for STH batches and audits
all contained STHs by requesting consistency proofs. This saves the
client from having to verify every single STH itself.

- [PRO] No need to audit SCTs.
- [PRO] Client never makes queries in response to browsing.
- [PRO] No need for a log proxy.
- [CON] CA needs to wait for inclusion proof if inclusion proof is included in cert.
- [CON] Client needs to store entire history of STHs.
- [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in addition to SCTs.

Option A2 is very similar to Option M, but avoids the need for clients
to do their own STH auditing (except for STHs related to the STH
batches). If you're happy with Option M you should be happy with Option
A2, even when implemented on top of the current Merkle Tree design.

I agree with many of your concerns about SCT auditing, but considering
that Options A1 and A2 can be implemented on top of 6962bis (plus Option
M if 4MB/month can be tolerated), I don't see why these concerns should
hold up publication.

Regards,
Andrew

[1] https://mailarchive.ietf.org/arch/msg/trans/gO_DFW3v9FmBCOek_hifZ6KL368

[2] https://mailarchive.ietf.org/arch/msg/trans/sA7ZrHIsuqWvIkF0B4I8dv8nKsY


From nobody Wed Feb 15 16:01:24 2017
Return-Path: <rlb@ipv.sx>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31052129C02 for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 16:01:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9xVmTlfaHoiT for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 16:01:20 -0800 (PST)
Received: from mail-ua0-x230.google.com (mail-ua0-x230.google.com [IPv6:2607:f8b0:400c:c08::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 82D2D129BFE for <trans@ietf.org>; Wed, 15 Feb 2017 16:01:20 -0800 (PST)
Received: by mail-ua0-x230.google.com with SMTP id 96so1252406uaq.3 for <trans@ietf.org>; Wed, 15 Feb 2017 16:01:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=BKBb0gEOGwGB7e1nq3PNuq5AzIFggSrwf0puBlaBYRU=; b=EWKmSpoHXNeHiDGyC+RJHpCgGhW+MrpKI90yT6lIWW/Ocv9l6F2N85nmNqJbFjFWWq QvUT/TptAu3tH8fpIEjVxvZgExgNFvA0O+HOWzj4G3muuSxNTChfUxpwUDHNtGqrEApv gl679NGlxWscBo5HcutYUiGcU5HBahA04Qs9X221olT73bBXqlYHWlhN++g18l/2c8HO YojrrSKDD1WeQ2douy3FTzlA1BoYNKZdBgYYR2a49elEUv1Q6uihPeNecO4WKNlJLi0L 2elsszUzFXQaXruGEJtJ6kTrKlFTwyIvtMQ/gBhmwIN0yJNmcyfUXYPfHsXTWyPK473J Fuig==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=BKBb0gEOGwGB7e1nq3PNuq5AzIFggSrwf0puBlaBYRU=; b=FaB4VU1WQOUsUZ6pAJRMN10OpxqQdu8dc8GH2pGTtSqgIVrVSjsewLPeL/GCZCuW25 PnJ6540Uc+gQuN08+fWTfTXXmRljYRV6EO3LGpQO3TMjLGPU//HrJAcxxfshn/NLsNR6 gQm9/7d3j0FH+OKvqUNuzPhSs39vSVZMBAPo5L8eCubR739eop0zcxa6iDNE5pWNQv4e xtQxma/88jVAE+4c1FEYPOZZKE+NdBurfzOzNppyewiAUNeXJLGsW8+XuL6DodUzqbrp INxqUc4y1AnRtC5qoYN/LHhpQTBHbxRGD0lZ19OgzF3zQRRb9+2ui60aolaNhUC5jMC4 l6Kg==
X-Gm-Message-State: AMke39nl1WrkdQBY1zoiruem0/+kdfTvVQbsO4iA81p1lDWQQ2lcf2xiKK7mN1zSMFhRnkvJfs3BX2bJnPwXIQ==
X-Received: by 10.159.36.73 with SMTP id 67mr20684497uaq.124.1487203279323; Wed, 15 Feb 2017 16:01:19 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.179.140 with HTTP; Wed, 15 Feb 2017 16:01:18 -0800 (PST)
In-Reply-To: <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 15 Feb 2017 16:01:18 -0800
Message-ID: <CAL02cgRq2pBC3NPuU2YZ+HHecFjVz91U6nOftsa_Z_oKM86-bQ@mail.gmail.com>
To: Tom Ritter <tom@ritter.vg>
Content-Type: multipart/alternative; boundary=001a113e1c9c2ccc5b05489a7f42
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/5Tr5fz2o4K1Z_qaIEJ9wq-BV3n0>
Cc: "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 00:01:22 -0000

--001a113e1c9c2ccc5b05489a7f42
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Wed, Feb 15, 2017 at 2:35 PM, Tom Ritter <tom@ritter.vg> wrote:

> On 15 February 2017 at 14:50, Richard Barnes <rlb@ipv.sx> wrote:
> > Dear TRANS,
> >
> > We had a call between a group of us last week that was helpful in
> clarifying
> > my thinking here.  I wanted to follow up to the list with some more
> detailed
> > thoughts.
> >
> > At base, in order to meet this group=E2=80=99s charter deliverables, wh=
at we
> want to
> > be assured of is that the mechanisms in 6962-bis that are intended to
> enable
> > public verifiability can actually do so in practice.  That is, we need =
to
> > establish that there is at least one plausible story for how some
> > substantial fraction of the statements logs provide to clients end up
> > getting audited.
> >
> > Part of the issue here is that we don=E2=80=99t have a full story anywh=
ere in the
> > documents for how auditing works at scale, and there are a couple of
> > incomplete models floating around that lead to different design
> requirements
> > for the public verifiability parts of CT, i.e., the part that is now th=
e
> > Merkle tree.  So let=E2=80=99s consider two straw-man models and look a=
t the
> > differences they lead to.  Call them =E2=80=9COption G=E2=80=9D and =E2=
=80=9COption M=E2=80=9D :)
> >
> > In the below, we assume:
> >
> > - "STH" is a general term for an object that:
> >   1. represents the state of a log at a given time
> >   2. is signed by the log
> >   3. can be verified to fit into a linear sequence with other STHs
> > - Server cannot be relied upon to take action, so any CT information
> needs
> > to come to the client from the CA
> >
> >
> > Option G: Cache one STH / dynamic inclusion proofs
> >
> >
> > 1. Auditor pulls STHs from logs at some frequency, validates consistenc=
y
> > 2. Periodically, the client obtains from the auditor:
> >   a. The latest validated STH
> >   b. A proof of consistency from the last STH the client received
> > 3. Client is configured to talk to a log proxy over DNS (for privacy)
> > 4. Client gets SCT from server
> > 5. Client audits by fetching inclusion proof to current STH from log
> proxy
> > over DNS
> >
> >
> > - [PRO] CA can issue immediately due to use of SCTs
> > - [PRO] Client only has to keep latest SCT
> > - [PRO] Compatible with existing CA practices w.r.t. SCTs
> > - [CON] Client has to reveal browsing history to log proxy in queries
> > - [CON] Audit failure from DNS failure indistinguishable from log
> > malfeasance
> > - [CON] Someone needs to operate a log proxy
> > - [CON] Requirement for audit-time fetches effectively forces audits to
> be
> > off-line w.r.t. certificate verification / TLS connection time
> >
> >
> > Option M: Cache many STHs / static inclusion proofs
> >
> >
> > 1. Auditor pulls STHs from logs at some frequency, validates consistenc=
y
> > 2. Periodically, the client obtains from the auditor:
> >   a. A list of all STHs since the last one the client received
> >   b. Proofs of consistency along this chain
> > 3. Client caches entire history of STHs that it has received (really ju=
st
> > needs to store tree heads)
> > 4. Client gets inclusion proof to an STH from server (either in the
> > certificate or in a stapled OCSP response), verifies it
> > 5. Client audits by verifying that the STH provided by the server is in
> the
> > validated cache
> >
> >
> > - [PRO] Client never makes queries that are dependent on browsing histo=
ry
> > - [PRO] Auditing can only fail if client state is stale (no live querie=
s)
> > - [PRO] No need for a log proxy
> > - [PRO] If inclusion proof is provided at connection / validation time,
> then
> > auditing can be done immediately for certificates that are old enough f=
or
> > their STHs to have propagated
> > - [CON] CA needs to wait for inclusion proof if inclusion proof is
> included
> > in cert
> > - [CON] Client needs to store entire history of STHs
> > - [CON] Requires CAs to upgrade to fetch inclusion proofs instead of / =
in
> > addition to SCTs
>
>
> Neither option specifies what the client does when it finds some data
> suspicious or how it shared said data with an auditor. I'm not sure
> you can leave this unspecified while trying to decide the rest of
> things. For example, in Option G do you report SCTs you can't resolve
> inclusion proofs for after N tries? In Option M what do you do about
> STHs you don't have in your verified cache? I'm also unclear if the
> log proxy is also an auditor (it seems like it implies it is, but that
> doesn't seem right.)
>

I agree that this is important, but I don't really see a connection to log
structure.  In either case, at this stage, the client has in hand the data
it needs to claim a violation; the only question is how it get reported.


> That Option M problem is an additional con I think:
> [CON] Client must cache or otherwise handle the situation when the
> inclusion proof is to a STH is doesn't know about. This could be
> either an attack or just a newly issued certificate. This devolves to
> the case of off-line verification in G.
>

It's true that if you get a proof to an STH you don't have, then you have
to cache it and see if you get one in a reasonable amount of time.  I
didn't count this as a CON for M because it's the same as G -- the point of
the PRO there was that M can do immediate validation in many cases, but G
never can.

--Richard



> -tom
>

--001a113e1c9c2ccc5b05489a7f42
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Feb 15, 2017 at 2:35 PM, Tom Ritter <span dir=3D"ltr">&lt;<a hr=
ef=3D"mailto:tom@ritter.vg" target=3D"_blank">tom@ritter.vg</a>&gt;</span> =
wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;bord=
er-left:1px #ccc solid;padding-left:1ex"><div class=3D"HOEnZb"><div class=
=3D"h5">On 15 February 2017 at 14:50, Richard Barnes &lt;rlb@ipv.sx&gt; wro=
te:<br>
&gt; Dear TRANS,<br>
&gt;<br>
&gt; We had a call between a group of us last week that was helpful in clar=
ifying<br>
&gt; my thinking here.=C2=A0 I wanted to follow up to the list with some mo=
re detailed<br>
&gt; thoughts.<br>
&gt;<br>
&gt; At base, in order to meet this group=E2=80=99s charter deliverables, w=
hat we want to<br>
&gt; be assured of is that the mechanisms in 6962-bis that are intended to =
enable<br>
&gt; public verifiability can actually do so in practice.=C2=A0 That is, we=
 need to<br>
&gt; establish that there is at least one plausible story for how some<br>
&gt; substantial fraction of the statements logs provide to clients end up<=
br>
&gt; getting audited.<br>
&gt;<br>
&gt; Part of the issue here is that we don=E2=80=99t have a full story anyw=
here in the<br>
&gt; documents for how auditing works at scale, and there are a couple of<b=
r>
&gt; incomplete models floating around that lead to different design requir=
ements<br>
&gt; for the public verifiability parts of CT, i.e., the part that is now t=
he<br>
&gt; Merkle tree.=C2=A0 So let=E2=80=99s consider two straw-man models and =
look at the<br>
&gt; differences they lead to.=C2=A0 Call them =E2=80=9COption G=E2=80=9D a=
nd =E2=80=9COption M=E2=80=9D :)<br>
&gt;<br>
&gt; In the below, we assume:<br>
&gt;<br>
&gt; - &quot;STH&quot; is a general term for an object that:<br>
&gt;=C2=A0 =C2=A01. represents the state of a log at a given time<br>
&gt;=C2=A0 =C2=A02. is signed by the log<br>
&gt;=C2=A0 =C2=A03. can be verified to fit into a linear sequence with othe=
r STHs<br>
&gt; - Server cannot be relied upon to take action, so any CT information n=
eeds<br>
&gt; to come to the client from the CA<br>
&gt;<br>
&gt;<br>
&gt; Option G: Cache one STH / dynamic inclusion proofs<br>
&gt;<br>
&gt;<br>
&gt; 1. Auditor pulls STHs from logs at some frequency, validates consisten=
cy<br>
&gt; 2. Periodically, the client obtains from the auditor:<br>
&gt;=C2=A0 =C2=A0a. The latest validated STH<br>
&gt;=C2=A0 =C2=A0b. A proof of consistency from the last STH the client rec=
eived<br>
&gt; 3. Client is configured to talk to a log proxy over DNS (for privacy)<=
br>
&gt; 4. Client gets SCT from server<br>
&gt; 5. Client audits by fetching inclusion proof to current STH from log p=
roxy<br>
&gt; over DNS<br>
&gt;<br>
&gt;<br>
&gt; - [PRO] CA can issue immediately due to use of SCTs<br>
&gt; - [PRO] Client only has to keep latest SCT<br>
&gt; - [PRO] Compatible with existing CA practices w.r.t. SCTs<br>
&gt; - [CON] Client has to reveal browsing history to log proxy in queries<=
br>
&gt; - [CON] Audit failure from DNS failure indistinguishable from log<br>
&gt; malfeasance<br>
&gt; - [CON] Someone needs to operate a log proxy<br>
&gt; - [CON] Requirement for audit-time fetches effectively forces audits t=
o be<br>
&gt; off-line w.r.t. certificate verification / TLS connection time<br>
&gt;<br>
&gt;<br>
&gt; Option M: Cache many STHs / static inclusion proofs<br>
&gt;<br>
&gt;<br>
&gt; 1. Auditor pulls STHs from logs at some frequency, validates consisten=
cy<br>
&gt; 2. Periodically, the client obtains from the auditor:<br>
&gt;=C2=A0 =C2=A0a. A list of all STHs since the last one the client receiv=
ed<br>
&gt;=C2=A0 =C2=A0b. Proofs of consistency along this chain<br>
&gt; 3. Client caches entire history of STHs that it has received (really j=
ust<br>
&gt; needs to store tree heads)<br>
&gt; 4. Client gets inclusion proof to an STH from server (either in the<br=
>
&gt; certificate or in a stapled OCSP response), verifies it<br>
&gt; 5. Client audits by verifying that the STH provided by the server is i=
n the<br>
&gt; validated cache<br>
&gt;<br>
&gt;<br>
&gt; - [PRO] Client never makes queries that are dependent on browsing hist=
ory<br>
&gt; - [PRO] Auditing can only fail if client state is stale (no live queri=
es)<br>
&gt; - [PRO] No need for a log proxy<br>
&gt; - [PRO] If inclusion proof is provided at connection / validation time=
, then<br>
&gt; auditing can be done immediately for certificates that are old enough =
for<br>
&gt; their STHs to have propagated<br>
&gt; - [CON] CA needs to wait for inclusion proof if inclusion proof is inc=
luded<br>
&gt; in cert<br>
&gt; - [CON] Client needs to store entire history of STHs<br>
&gt; - [CON] Requires CAs to upgrade to fetch inclusion proofs instead of /=
 in<br>
&gt; addition to SCTs<br>
<br>
<br>
</div></div>Neither option specifies what the client does when it finds som=
e data<br>
suspicious or how it shared said data with an auditor. I&#39;m not sure<br>
you can leave this unspecified while trying to decide the rest of<br>
things. For example, in Option G do you report SCTs you can&#39;t resolve<b=
r>
inclusion proofs for after N tries? In Option M what do you do about<br>
STHs you don&#39;t have in your verified cache? I&#39;m also unclear if the=
<br>
log proxy is also an auditor (it seems like it implies it is, but that<br>
doesn&#39;t seem right.)<br></blockquote><div><br></div><div>I agree that t=
his is important, but I don&#39;t really see a connection to log structure.=
=C2=A0 In either case, at this stage, the client has in hand the data it ne=
eds to claim a violation; the only question is how it get reported.<br></di=
v><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex">
That Option M problem is an additional con I think:<br>
[CON] Client must cache or otherwise handle the situation when the<br>
inclusion proof is to a STH is doesn&#39;t know about. This could be<br>
either an attack or just a newly issued certificate. This devolves to<br>
the case of off-line verification in G.<br></blockquote><div><br></div><div=
>It&#39;s true that if you get a proof to an STH you don&#39;t have, then y=
ou have to cache it and see if you get one in a reasonable amount of time.=
=C2=A0 I didn&#39;t count this as a CON for M because it&#39;s the same as =
G -- the point of the PRO there was that M can do immediate validation in m=
any cases, but G never can.=C2=A0 <br></div><div>=C2=A0<br></div><div>--Ric=
hard<br><br></div><div><br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<span class=3D"HOEnZb"><font color=3D"#888888"><br>
-tom<br>
</font></span></blockquote></div><br></div></div>

--001a113e1c9c2ccc5b05489a7f42--


From nobody Wed Feb 15 16:33:48 2017
Return-Path: <rlb@ipv.sx>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E4DE129550 for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 16:33:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ipv-sx.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WBl4T0h6-JWP for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 16:33:42 -0800 (PST)
Received: from mail-vk0-x233.google.com (mail-vk0-x233.google.com [IPv6:2607:f8b0:400c:c05::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 58E6A12953F for <trans@ietf.org>; Wed, 15 Feb 2017 16:33:42 -0800 (PST)
Received: by mail-vk0-x233.google.com with SMTP id r136so1590092vke.1 for <trans@ietf.org>; Wed, 15 Feb 2017 16:33:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipv-sx.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=vNqqR8D3pZ8ipwFM9PaOWG4JcPCVNZ9ZH2xVaWw12dg=; b=XqqscMDFhD4X+4J7+mdkNe8px+JL0xA/P9xs8dxbnDKJ9+7e+/rFRMB/nvlbPmj8sd A7hHu9pjEf6LbqRr20vEF/l9p1/vJhZcyoJR6NiT2+uKVWJFGaQwb2LVK9hKCTcZMwtQ u5H0+ZkQ4ja1SLvY+oOcWgiYRQmMKEqZWpkL+ffRo0FQ8MSLLvBHslFebY9qrvuszrnA mRBBTMi3/8yNVxJH7AU5dWt1DSS6sFMzXi4kwRwVyY7iOUgJih89lawZRsZz/zeUlRwV g0ML5XW6818QQZnqub2RggzibcB8nDq4n2Mc9Z2XH+rE+4VeODDmTf332joRDPwVAnr2 XYOA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=vNqqR8D3pZ8ipwFM9PaOWG4JcPCVNZ9ZH2xVaWw12dg=; b=bAjF0xaCQQzhiqOkmC+yzIADT5QqzhlXCxaoc8WcTenX/J4zx1MYZFnzYG1CxYRf1Y v+uVaUO9G0zscl7YVn86raJsl+WvxRlxEF+yzCNvDCF9anAvxKnJNjBVeNp8xOFw1QTl MyAXbi6th24AFAG0NYS67UuS1O27rL71F1Jes7OLrPp0+yg5BE07zN7lvaXI7Cj2j2Bh l0eQQbkyXGgYeDbsEvf6YwZ8c1uTLDNHZGLT3qoyuKUgkg6+aGoGAxPx4FFr1apZEQe6 YvoHAEijKnzmh+SOq4ThWv2yELL6btsmuZax/QrWLfX1Q2Xg8sJCd8rC/GDU4XVj+yao bgiQ==
X-Gm-Message-State: AMke39nMUIXN8EczhWY8NCLkzOMZAmaqZNgVsAbI/u0vmvgK+LEbSbUpOzj4PV8gj52WDIK+evc8jExntNRuQg==
X-Received: by 10.31.192.204 with SMTP id q195mr18682912vkf.155.1487205221126;  Wed, 15 Feb 2017 16:33:41 -0800 (PST)
MIME-Version: 1.0
Received: by 10.31.179.140 with HTTP; Wed, 15 Feb 2017 16:33:40 -0800 (PST)
In-Reply-To: <20170215153808.1d276ae3c7a6a9be3c6b95b3@andrewayer.name>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <20170215153808.1d276ae3c7a6a9be3c6b95b3@andrewayer.name>
From: Richard Barnes <rlb@ipv.sx>
Date: Wed, 15 Feb 2017 16:33:40 -0800
Message-ID: <CAL02cgQp1AizMcLtPAo6q8WJ-LXwAvQ=d_S-UnKC+kY3MLGGPA@mail.gmail.com>
To: Andrew Ayer <agwa@andrewayer.name>
Content-Type: multipart/alternative; boundary=001a114388ccea3ee405489af255
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/ZMH0eCye9CY4x7KI4RFPPc3LqPA>
Cc: trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 00:33:46 -0000

--001a114388ccea3ee405489af255
Content-Type: text/plain; charset=UTF-8

On Wed, Feb 15, 2017 at 3:38 PM, Andrew Ayer <agwa@andrewayer.name> wrote:

> On Wed, 15 Feb 2017 12:50:12 -0800
> Richard Barnes <rlb@ipv.sx> wrote:
> >
> > [...]
> >
> > Option M: Cache many STHs / static inclusion proofs
> >
> > [...]
> >
> > - [PRO] If inclusion proof is provided at connection / validation
> > time, then auditing can be done immediately for certificates that are
> > old enough for their STHs to have propagated
>
> Since a client cannot distinguish between a rogue STH and a legitimate
> STH that it doesn't know about yet, it has no choice but to accept the
> connection if it doesn't know about an STH and audit it later.  Therefore,
> option M is no better than option G in this regard: both provide post-hoc
> detection rather than prevention.  You can't call this a "pro" for option
> M while simultaneously calling it a "con" for Option G.
>
> > [...]
> >
> > Option M leads to something like a Haber-Stornetta hash chain
> > of batch Merkle trees.
>
> Why?  The only justification provided so far is that a client would
> need to download 4MB of data a month, which is a "pretty big chunk of
> data."[1]  This is a rather extraordinary claim.  Can you explain your
> reasoning why 4MB a month is too much?
>

To be a bit glib -- the folks who manage syncing state out to Firefox
balked when I mentioned it to them.

Basically, that amount might not sound scary from the client side, but if
you're thinking about syncing that data out to 100s of millions of clients,
that's an extra few 100MBps of capacity you have to provision, and it's
only kinda cacheable.



> Even if 4MB/month is deemed excessive, there are other options which
> avoid reliance on SCTs, but can be implemented on top of 6962bis'
> current design without requiring clients to download 4MB a month.
> Let's call them Options A1 and A2.
>

To be clear, I did not mean to imply that these were the only options.  On
the contrary, I would like to have some discussion about the options here
so we can understand what requirements we should be holding 6962bis to.

Can you explain why being implemented on top of the current system is a
requirement?  I can see why it's desireable, e.g., to avoid further delay.
But in general, I would be inclined to change the spec to the web's needs
rather than the other way around.



> Option A1: Fetch consistency proofs on demand
>
> 1. Client gets an STH and an inclusion proof to the STH from server,
> verifies the proof, and adds STH to a cache if not already present.
>
> 2. In the background, client audits unverified STHs in the cache
> by requesting a consistency proof between the unverified STH and some
> other verified STH.
>
> - [PRO] No need to audit SCTs.
> - [PRO] Although client makes queries (consistency proofs) that are
> triggered by
>   browsing, the queries do not reveal browsing history because many
> certificates
>   use inclusion proofs to the same STH.
> - [PRO] No need for a log proxy.
> - [PRO] Client only needs to fetch consistency proofs for STHs it actually
> sees.
> - [PRO] Client only needs to store STHs it actually sees.
> - [CON] CA needs to wait for inclusion proof if inclusion proof is
> included in cert.
> - [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in
> addition to SCTs.
>
> I asked you on-list two weeks ago why this wouldn't work[2], but you
> have not replied.
>

Sorry, that's my fault.  Trying to be more responsible on this thread :)

I think this is better than option G, but there are still a couple of
concerns.  The one that's most critical to me is that you're relying on the
structure of STHs for a privacy property -- if there are too few new certs
under an STH, then your consistency query reveals your browsing history.
That seems like a very fragile assumption to be making, especially given
that we have no STH discipline / schedule in the current system.  And
making logs explicitly trusted for this privacy property seems counter to
the idea that logs are not to be trusted.



>
> Option A2: Publicly-logged STH batches
>
> 1. Auditor pulls STHs from logs at some frequency, validates consistency.
>
> 2. Periodically, auditor logs batches of STHs to CT logs.
>
> 3. Periodically, the client obtains from the auditor:
>   a. Batches of STHs since the last one the client received
>   b. Inclusion proofs for each STH batch up to the log's latest STH
>   c. Consistency proof between the last STH received by the client and the
> latest STH
>
> 4. The client verifies all proofs received from auditor, but assumes
> that the STHs in the batches are legitimate.
>
> 5. Client caches entire history of STHs that it has received (really
> just needs to store tree heads).
>
> 6. Client gets inclusion proof to an STH from server (either in the
> certificate or in a stapled OCSP response), verifies it.
>
> 7. Client audits by verifying that the STH provided by the server is in
> the cache.
>
> 8. An ecosystem of auditors monitors logs for STH batches and audits
> all contained STHs by requesting consistency proofs. This saves the
> client from having to verify every single STH itself.
>
> - [PRO] No need to audit SCTs.
> - [PRO] Client never makes queries in response to browsing.
> - [PRO] No need for a log proxy.
> - [CON] CA needs to wait for inclusion proof if inclusion proof is
> included in cert.
> - [CON] Client needs to store entire history of STHs.
> - [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in
> addition to SCTs.
>
> Option A2 is very similar to Option M, but avoids the need for clients
> to do their own STH auditing (except for STHs related to the STH
> batches). If you're happy with Option M you should be happy with Option
> A2, even when implemented on top of the current Merkle Tree design.
>

What you lose in this design relative to both G and M is the clients direct
assurance that the STHs it's relying on are a valid sequence, as opposed to
something the auditor made up.  That is, the assurance here is like if you
took G or M and removed the part where the auditor sends down the
consistency proofs.

That's not the biggest tragedy in the world, but if that's the best we can
do, we'll need to be clear about this constraint in the document ("Most
clients will need to delegate consistency checking to an auditor, which
means that they will be at risk of the auditor lying to them in the
following ways...").  But given that there are options on the table that
get us to a stranger guarantee at the cost of a spec change and some
adaptation by the small number of logs that exist, I'm not sure why we
should settle here.



> I agree with many of your concerns about SCT auditing, but considering
> that Options A1 and A2 can be implemented on top of 6962bis (plus Option
> M if 4MB/month can be tolerated), I don't see why these concerns should
> hold up publication.
>

As I've noted above, A1 and A2 aren't really meeting my requirements.
(Maybe we should go through a requirements exercise here?)

"It's in the document" is a reason to persist in standardizing a design,
much less implementing it.  If we want to keep the current design, let's
get consensus that there's a plausible auditing story for it.  Otherwise,
let's pick another one.

--Richard





>
> Regards,
> Andrew
>
> [1] https://mailarchive.ietf.org/arch/msg/trans/gO_
> DFW3v9FmBCOek_hifZ6KL368
>
> [2] https://mailarchive.ietf.org/arch/msg/trans/
> sA7ZrHIsuqWvIkF0B4I8dv8nKsY
>

--001a114388ccea3ee405489af255
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Feb 15, 2017 at 3:38 PM, Andrew Ayer <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:agwa@andrewayer.name" target=3D"_blank">agwa@andrewayer.name<=
/a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:=
0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">=
On Wed, 15 Feb 2017 12:50:12 -0800<br>
Richard Barnes &lt;rlb@ipv.sx&gt; wrote:<br>
&gt;<br>
&gt; [...]<br>
<span class=3D"gmail-">&gt;<br>
&gt; Option M: Cache many STHs / static inclusion proofs<br>
&gt;<br>
</span>&gt; [...]<br>
<span class=3D"gmail-">&gt;<br>
&gt; - [PRO] If inclusion proof is provided at connection / validation<br>
&gt; time, then auditing can be done immediately for certificates that are<=
br>
&gt; old enough for their STHs to have propagated<br>
<br>
</span>Since a client cannot distinguish between a rogue STH and a legitima=
te<br>
STH that it doesn&#39;t know about yet, it has no choice but to accept the<=
br>
connection if it doesn&#39;t know about an STH and audit it later.=C2=A0 Th=
erefore,<br>
option M is no better than option G in this regard: both provide post-hoc<b=
r>
detection rather than prevention.=C2=A0 You can&#39;t call this a &quot;pro=
&quot; for option<br>
M while simultaneously calling it a &quot;con&quot; for Option G.<br>
<br>
&gt; [...]<br>
<span class=3D"gmail-">&gt;<br>
&gt; Option M leads to something like a Haber-Stornetta hash chain<br>
&gt; of batch Merkle trees.<br>
<br>
</span>Why?=C2=A0 The only justification provided so far is that a client w=
ould<br>
need to download 4MB of data a month, which is a &quot;pretty big chunk of<=
br>
data.&quot;[1]=C2=A0 This is a rather extraordinary claim.=C2=A0 Can you ex=
plain your<br>
reasoning why 4MB a month is too much?<br></blockquote><div><br></div><div>=
To be a bit glib -- the folks who manage syncing state out to Firefox balke=
d when I mentioned it to them.<br><br></div><div>Basically, that amount mig=
ht not sound scary from the client side, but if you&#39;re thinking about s=
yncing that data out to 100s of millions of clients, that&#39;s an extra fe=
w 100MBps of capacity you have to provision, and it&#39;s only kinda cachea=
ble.<br></div><div><br>=C2=A0</div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">
Even if 4MB/month is deemed excessive, there are other options which<br>
avoid reliance on SCTs, but can be implemented on top of 6962bis&#39;<br>
current design without requiring clients to download 4MB a month.<br>
Let&#39;s call them Options A1 and A2.<br></blockquote><div><br></div><div>=
To be clear, I did not mean to imply that these were the only options.=C2=
=A0 On the contrary, I would like to have some discussion about the options=
 here so we can understand what requirements we should be holding 6962bis t=
o.<br><br></div><div>Can you explain why being implemented on top of the cu=
rrent system is a requirement?=C2=A0 I can see why it&#39;s desireable, e.g=
., to avoid further delay.=C2=A0 But in general, I would be inclined to cha=
nge the spec to the web&#39;s needs rather than the other way around.<br></=
div><div><br>=C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1=
ex">
Option A1: Fetch consistency proofs on demand<br>
<br>
1. Client gets an STH and an inclusion proof to the STH from server,<br>
verifies the proof, and adds STH to a cache if not already present.<br>
<br>
2. In the background, client audits unverified STHs in the cache<br>
by requesting a consistency proof between the unverified STH and some<br>
other verified STH.<br>
<br>
- [PRO] No need to audit SCTs.<br>
- [PRO] Although client makes queries (consistency proofs) that are trigger=
ed by<br>
=C2=A0 browsing, the queries do not reveal browsing history because many ce=
rtificates<br>
=C2=A0 use inclusion proofs to the same STH.<br>
- [PRO] No need for a log proxy.<br>
- [PRO] Client only needs to fetch consistency proofs for STHs it actually =
sees.<br>
- [PRO] Client only needs to store STHs it actually sees.<br>
- [CON] CA needs to wait for inclusion proof if inclusion proof is included=
 in cert.<br>
- [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in ad=
dition to SCTs.<br>
<br>
I asked you on-list two weeks ago why this wouldn&#39;t work[2], but you<br=
>
have not replied.<br></blockquote><div><br></div><div>Sorry, that&#39;s my =
fault.=C2=A0 Trying to be more responsible on this thread :)<br><br></div><=
div>I think this is better than option G, but there are still a couple of c=
oncerns.=C2=A0 The one that&#39;s most critical to me is that you&#39;re re=
lying on the structure of STHs for a privacy property -- if there are too f=
ew new certs under an STH, then your consistency query reveals your browsin=
g history.=C2=A0 That seems like a very fragile assumption to be making, es=
pecially given that we have no STH discipline / schedule in the current sys=
tem.=C2=A0 And making logs explicitly trusted for this privacy property see=
ms counter to the idea that logs are not to be trusted.<br></div><div><br>=
=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0=
.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
Option A2: Publicly-logged STH batches<br>
<br>
1. Auditor pulls STHs from logs at some frequency, validates consistency.<b=
r>
<br>
2. Periodically, auditor logs batches of STHs to CT logs.<br>
<br>
3. Periodically, the client obtains from the auditor:<br>
=C2=A0 a. Batches of STHs since the last one the client received<br>
=C2=A0 b. Inclusion proofs for each STH batch up to the log&#39;s latest ST=
H<br>
=C2=A0 c. Consistency proof between the last STH received by the client and=
 the latest STH<br>
<br>
4. The client verifies all proofs received from auditor, but assumes<br>
that the STHs in the batches are legitimate.<br>
<br>
5. Client caches entire history of STHs that it has received (really<br>
just needs to store tree heads).<br>
<br>
6. Client gets inclusion proof to an STH from server (either in the<br>
certificate or in a stapled OCSP response), verifies it.<br>
<br>
7. Client audits by verifying that the STH provided by the server is in<br>
the cache.<br>
<br>
8. An ecosystem of auditors monitors logs for STH batches and audits<br>
all contained STHs by requesting consistency proofs. This saves the<br>
client from having to verify every single STH itself.<br>
<br>
- [PRO] No need to audit SCTs.<br>
- [PRO] Client never makes queries in response to browsing.<br>
- [PRO] No need for a log proxy.<br>
- [CON] CA needs to wait for inclusion proof if inclusion proof is included=
 in cert.<br>
- [CON] Client needs to store entire history of STHs.<br>
- [CON] Requires CA to upgrade to fetch inclusion proofs instead of / in ad=
dition to SCTs.<br>
<br>
Option A2 is very similar to Option M, but avoids the need for clients<br>
to do their own STH auditing (except for STHs related to the STH<br>
batches). If you&#39;re happy with Option M you should be happy with Option=
<br>
A2, even when implemented on top of the current Merkle Tree design.<br></bl=
ockquote><div><br></div><div>What you lose in this design relative to both =
G and M is the clients direct assurance that the STHs it&#39;s relying on a=
re a valid sequence, as opposed to something the auditor made up.=C2=A0 Tha=
t is, the assurance here is like if you took G or M and removed the part wh=
ere the auditor sends down the consistency proofs.<br></div><div><br></div>=
<div>That&#39;s not the biggest tragedy in the world, but if that&#39;s the=
 best we can do, we&#39;ll need to be clear about this constraint in the do=
cument (&quot;Most clients will need to delegate consistency checking to an=
 auditor, which means that they will be at risk of the auditor lying to the=
m in the following ways...&quot;).=C2=A0 But given that there are options o=
n the table that get us to a stranger guarantee at the cost of a spec chang=
e and some adaptation by the small number of logs that exist, I&#39;m not s=
ure why we should settle here.<br><br></div><div>=C2=A0</div><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid=
 rgb(204,204,204);padding-left:1ex">
I agree with many of your concerns about SCT auditing, but considering<br>
that Options A1 and A2 can be implemented on top of 6962bis (plus Option<br=
>
M if 4MB/month can be tolerated), I don&#39;t see why these concerns should=
<br>
hold up publication.<br></blockquote><div><br></div><div>As I&#39;ve noted =
above, A1 and A2 aren&#39;t really meeting my requirements.=C2=A0 (Maybe we=
 should go through a requirements exercise here?)<br><br></div><div>&quot;I=
t&#39;s in the document&quot; is a reason to persist in standardizing a des=
ign, much less implementing it.=C2=A0 If we want to keep the current design=
, let&#39;s get consensus that there&#39;s a plausible auditing story for i=
t.=C2=A0 Otherwise, let&#39;s pick another one.<br><br></div><div>--Richard=
<br></div><div><br><br></div><div><br>=C2=A0</div><blockquote class=3D"gmai=
l_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,20=
4,204);padding-left:1ex">
<br>
Regards,<br>
Andrew<br>
<br>
[1] <a href=3D"https://mailarchive.ietf.org/arch/msg/trans/gO_DFW3v9FmBCOek=
_hifZ6KL368" rel=3D"noreferrer" target=3D"_blank">https://mailarchive.ietf.=
org/<wbr>arch/msg/trans/gO_<wbr>DFW3v9FmBCOek_hifZ6KL368</a><br>
<br>
[2] <a href=3D"https://mailarchive.ietf.org/arch/msg/trans/sA7ZrHIsuqWvIkF0=
B4I8dv8nKsY" rel=3D"noreferrer" target=3D"_blank">https://mailarchive.ietf.=
org/<wbr>arch/msg/trans/<wbr>sA7ZrHIsuqWvIkF0B4I8dv8nKsY</a><br>
</blockquote></div><br></div></div>

--001a114388ccea3ee405489af255--


From nobody Wed Feb 15 17:19:14 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B5C2C12946E for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 17:19:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id apX-7BRXwMaN for <trans@ietfa.amsl.com>; Wed, 15 Feb 2017 17:19:10 -0800 (PST)
Received: from homiemail-a107.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 43C53129461 for <trans@ietf.org>; Wed, 15 Feb 2017 17:19:10 -0800 (PST)
Received: from homiemail-a107.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a107.g.dreamhost.com (Postfix) with ESMTP id C57B620051C23 for <trans@ietf.org>; Wed, 15 Feb 2017 17:19:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=qtd4g9ERs+6Us5EBqq8e5EkXMIs=; b= TUkK0TSAZKmyBUCCwyExNCeurrM+/6/OHkzBs3mYzWptujxfubl+1bUUjqMtuq7i iqiQ37ijjDM5E6/5d8+9/Q9OA6cvERF8q/0Is0yw3MFSw4EwK5ZcPla/VapABhZQ T7tazMMRNilHSJ5QZ+0LzxW1fisImrqFpsZHLDd7JM8=
Received: from mail-lf0-f43.google.com (mail-lf0-f43.google.com [209.85.215.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a107.g.dreamhost.com (Postfix) with ESMTPSA id 98A2520051C22 for <trans@ietf.org>; Wed, 15 Feb 2017 17:19:09 -0800 (PST)
Received: by mail-lf0-f43.google.com with SMTP id v186so1363899lfa.1 for <trans@ietf.org>; Wed, 15 Feb 2017 17:19:09 -0800 (PST)
X-Gm-Message-State: AMke39lVCmOcTkXO87BOatDpXUrHS4jbI6vbPcqzJMuxfEWIV77jUTRCzemS1l5CxA9kWGATBXm/Ut2cf1tJYQ==
X-Received: by 10.25.156.144 with SMTP id f138mr13504954lfe.80.1487207947775;  Wed, 15 Feb 2017 17:19:07 -0800 (PST)
MIME-Version: 1.0
Received: by 10.25.92.154 with HTTP; Wed, 15 Feb 2017 17:19:07 -0800 (PST)
In-Reply-To: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Wed, 15 Feb 2017 17:19:07 -0800
X-Gmail-Original-Message-ID: <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com>
Message-ID: <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Content-Type: multipart/alternative; boundary=001a11410e7c6f395105489b955f
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/MFcZJCiKZxlIkIvqu3JqOpop4WQ>
Cc: trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 01:19:13 -0000

--001a11410e7c6f395105489b955f
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Wed, Feb 15, 2017 at 12:50 PM, Richard Barnes <rlb@ipv.sx> wrote:

> At base, in order to meet this group=E2=80=99s charter deliverables, what=
 we want
> to be assured of is that the mechanisms in 6962-bis that are intended to
> enable public verifiability can actually do so in practice.  That is, we
> need to establish that there is at least one plausible story for how some
> substantial fraction of the statements logs provide to clients end up
> getting audited.
>

If I may, it seems like you're stating two (different) goals as equivalent;
the subtlety here at least deserves calling out. For recap, the charter is
https://datatracker.ietf.org/wg/trans/charter/ , with the work item being
"Publish an update to RFC 6962 as a standards-track mechanism to apply
verifiable logs to HTTP over TLS."

The subtlety here I'm calling out is that you're implicitly treating
"clients" to mean "common Web browsers". While I certainly agree that's an
important use case to consider (and certainly one we at Google have been
considering), your interpretation is much more narrower than what's
chartered, and your concerns much more specific to individual products (on
particular platforms), rather than to either the general case of "Web
browsers" or even "TLS clients".

The danger in this approach is that it bleeds dangerously close to
specifying implementation policy, when the current draft provides
infrastructure to support a variety of policies for a variety of consumers
and clients. Notable here is that you can have CT clients that may decide
to 'hard-fail' - whether browser or otherwise - and so some of the
'pragmatic' cons you highlight aren't exactly relevant to the chartered
objective, or refer to implementation details and product decisions rather
than generalized problems.

I think perhaps if we can agree on the scope and its relevance to the
charter - which you're highlighting as the key concern - we can better work
through these issues. For example, if you imagine a command-line TLS client
(such as wget or curl), neither Option M nor Option G, as you've defined
them, may be suitable. Does that mean it's necessarily to fundamentally
alter how 6962-bis works? Maybe, maybe not. Does that mean it's necessary
for such a "guidance document" to consider wget and curl's needs as
equivalent to the presumed consumers of Option M or Option G? Maybe, maybe
not.

--001a11410e7c6f395105489b955f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Wed, Feb 15, 2017 at 12:50 PM, Richard Barnes <span dir=3D"ltr">&lt;=
<a href=3D"mailto:rlb@ipv.sx" target=3D"_blank">rlb@ipv.sx</a>&gt;</span> w=
rote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8e=
x;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"ltr"=
>At base, in order to meet this group=E2=80=99s charter deliverables, what =
we want to be assured of is that the mechanisms in 6962-bis that are intend=
ed to enable public verifiability can actually do so in practice.=C2=A0 Tha=
t is, we need to establish that there is at least one plausible story for h=
ow some substantial fraction of the statements logs provide to clients end =
up getting audited.<br></div></blockquote><div><br></div><div>If I may, it =
seems like you&#39;re stating two (different) goals as equivalent; the subt=
lety here at least deserves calling out. For recap, the charter is=C2=A0<a =
href=3D"https://datatracker.ietf.org/wg/trans/charter/">https://datatracker=
.ietf.org/wg/trans/charter/</a> , with the work item being &quot;Publish an=
 update to RFC 6962 as a standards-track mechanism to apply verifiable logs=
 to HTTP over TLS.&quot;</div><div><br></div><div>The subtlety here I&#39;m=
 calling out is that you&#39;re implicitly treating &quot;clients&quot; to =
mean &quot;common Web browsers&quot;. While I certainly agree that&#39;s an=
 important use case to consider (and certainly one we at Google have been c=
onsidering), your interpretation is much more narrower than what&#39;s char=
tered, and your concerns much more specific to individual products (on part=
icular platforms), rather than to either the general case of &quot;Web brow=
sers&quot; or even &quot;TLS clients&quot;.</div><div><br></div><div>The da=
nger in this approach is that it bleeds dangerously close to specifying imp=
lementation policy, when the current draft provides infrastructure to suppo=
rt a variety of policies for a variety of consumers and clients. Notable he=
re is that you can have CT clients that may decide to &#39;hard-fail&#39; -=
 whether browser or otherwise - and so some of the &#39;pragmatic&#39; cons=
 you highlight aren&#39;t exactly relevant to the chartered objective, or r=
efer to implementation details and product decisions rather than generalize=
d problems.</div><div><br></div><div>I think perhaps if we can agree on the=
 scope and its relevance to the charter - which you&#39;re highlighting as =
the key concern - we can better work through these issues. For example, if =
you imagine a command-line TLS client (such as wget or curl), neither Optio=
n M nor Option G, as you&#39;ve defined them, may be suitable. Does that me=
an it&#39;s necessarily to fundamentally alter how 6962-bis works? Maybe, m=
aybe not. Does that mean it&#39;s necessary for such a &quot;guidance docum=
ent&quot; to consider wget and curl&#39;s needs as equivalent to the presum=
ed consumers of Option M or Option G? Maybe, maybe not.</div></div></div></=
div>

--001a11410e7c6f395105489b955f--


From nobody Thu Feb 16 11:38:05 2017
Return-Path: <agwa@andrewayer.name>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D5021295EE for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 11:38:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level: 
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewayer.name
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YL-WuXoujrkH for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 11:38:02 -0800 (PST)
Received: from alcazar.beanwood.com (alcazar.beanwood.com [IPv6:2600:3c00:e000:6c::1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C885D1294C3 for <trans@ietf.org>; Thu, 16 Feb 2017 11:38:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=andrewayer.name; s=beanwood20160511; t=1487273882; bh=rM/7Rl302DlO7G09c7X61SvJC0Da+t5odmA6s1MtxD8=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=n6gA0UWc9IPHYiJ2TWN5OziT5XLfsik3FS553ID968TKQ+Oe0h7XhkFhqzhRIPmPZ dN0/UCNxpeGm86UxYucAMgkUUCXeZ92HLP3Zxm4Uku3819Mqz64oS+z3I/lDg6Jv9/ 9mPR+0Li9+pTMOgbPEHOzyRsAqsJfWE+24+B3dxPB1plbw1B+x47+hDEhwPiFYvnaU H3ZQRV8ExUIpmmoGiC52hzBYrv78SrZFFWCX5OsKYyg8a4mxIk7z2E7gtmyBH4DOkI EUyjgwYE4LKC53iKkx4hzP6J5c2NYdhoRLlugKTKc+QNzqAK6sMASTvOOg9FJfkY76 clTPt3Dqtb43g==
Date: Thu, 16 Feb 2017 11:38:01 -0800
From: Andrew Ayer <agwa@andrewayer.name>
To: Richard Barnes <rlb@ipv.sx>
Message-Id: <20170216113801.359d3eb906dc4c9e141f9073@andrewayer.name>
In-Reply-To: <CAL02cgQp1AizMcLtPAo6q8WJ-LXwAvQ=d_S-UnKC+kY3MLGGPA@mail.gmail.com>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <20170215153808.1d276ae3c7a6a9be3c6b95b3@andrewayer.name> <CAL02cgQp1AizMcLtPAo6q8WJ-LXwAvQ=d_S-UnKC+kY3MLGGPA@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/hmkHteU0snLk94UBf2EVYZfURwg>
Cc: trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 19:38:04 -0000

On Wed, 15 Feb 2017 16:33:40 -0800
Richard Barnes <rlb@ipv.sx> wrote:

> [...]
>
> >
> > > [...]
> > >
> > > Option M leads to something like a Haber-Stornetta hash chain
> > > of batch Merkle trees.
> >
> > Why?  The only justification provided so far is that a client would
> > need to download 4MB of data a month, which is a "pretty big chunk
> > of data."[1]  This is a rather extraordinary claim.  Can you
> > explain your reasoning why 4MB a month is too much?
> >
> 
> To be a bit glib -- the folks who manage syncing state out to Firefox
> balked when I mentioned it to them.
> 
> Basically, that amount might not sound scary from the client side,
> but if you're thinking about syncing that data out to 100s of
> millions of clients, that's an extra few 100MBps of capacity you have
> to provision, and it's only kinda cacheable.

Ah, it's a server-side constraint. Thanks for clarifying.

Would an effective caching strategy make this implementable by Mozilla?
What if every STH and its consistency proof to the previous STH was
a separate resource?  That's trivially cacheable, and HTTP/2 makes
it cheap for the client to request lots of resources at once.

> > Even if 4MB/month is deemed excessive, there are other options which
> > avoid reliance on SCTs, but can be implemented on top of 6962bis'
> > current design without requiring clients to download 4MB a month.
> > Let's call them Options A1 and A2.
> >
> 
> To be clear, I did not mean to imply that these were the only
> options.  On the contrary, I would like to have some discussion about
> the options here so we can understand what requirements we should be
> holding 6962bis to.
> 
> Can you explain why being implemented on top of the current system is
> a requirement?  I can see why it's desireable, e.g., to avoid further
> delay. But in general, I would be inclined to change the spec to the
> web's needs rather than the other way around.

Does the desirability of a new design outweigh the desirability of moving
forward with the current one?  Tradeoffs always have to be made, or one
could spend forever in quest of the perfect solution.  Consider:

1. The delay would likely be significant.  RFC6962bis would need major
changes.  The gossip and threat analysis documents would need revision.
This would hold up other work.

2. We'd forgo much of the running code and implementation experience
from RFC6962.

3. There's no guarantee that a Haber-Stornetta chain is the right
solution - what if we uncover unforeseen problems in a year?

> > Option A1: Fetch consistency proofs on demand
> >
> > 1. Client gets an STH and an inclusion proof to the STH from server,
> > verifies the proof, and adds STH to a cache if not already present.
> >
> > 2. In the background, client audits unverified STHs in the cache
> > by requesting a consistency proof between the unverified STH and
> > some other verified STH.
> >
> > - [PRO] No need to audit SCTs.
> > - [PRO] Although client makes queries (consistency proofs) that are
> > triggered by
> >   browsing, the queries do not reveal browsing history because many
> > certificates
> >   use inclusion proofs to the same STH.
> > - [PRO] No need for a log proxy.
> > - [PRO] Client only needs to fetch consistency proofs for STHs it
> > actually sees.
> > - [PRO] Client only needs to store STHs it actually sees.
> > - [CON] CA needs to wait for inclusion proof if inclusion proof is
> > included in cert.
> > - [CON] Requires CA to upgrade to fetch inclusion proofs instead
> > of / in addition to SCTs.
> >
> > I asked you on-list two weeks ago why this wouldn't work[2], but you
> > have not replied.
> >
> 
> Sorry, that's my fault.  Trying to be more responsible on this
> thread :)
> 
> I think this is better than option G, but there are still a couple of
> concerns.  The one that's most critical to me is that you're relying
> on the structure of STHs for a privacy property -- if there are too
> few new certs under an STH, then your consistency query reveals your
> browsing history. That seems like a very fragile assumption to be
> making, especially given that we have no STH discipline / schedule in
> the current system.  And making logs explicitly trusted for this
> privacy property seems counter to the idea that logs are not to be
> trusted.

6962bis could require a minimum number of log entries between STHs,
much like it requires a minimum amount of time.  Monitors could
detect it if logs violated this requirement.

However, one could stuff the log with certificates that it knows will
never be used on the public Internet, so you're right that this option
has privacy problems which makes it inferior to options M and A2.

> > Option A2: Publicly-logged STH batches
> >
> > 1. Auditor pulls STHs from logs at some frequency, validates
> > consistency.
> >
> > 2. Periodically, auditor logs batches of STHs to CT logs.
> >
> > 3. Periodically, the client obtains from the auditor:
> >   a. Batches of STHs since the last one the client received
> >   b. Inclusion proofs for each STH batch up to the log's latest STH
> >   c. Consistency proof between the last STH received by the client
> > and the latest STH
> >
> > 4. The client verifies all proofs received from auditor, but assumes
> > that the STHs in the batches are legitimate.
> >
> > 5. Client caches entire history of STHs that it has received (really
> > just needs to store tree heads).
> >
> > 6. Client gets inclusion proof to an STH from server (either in the
> > certificate or in a stapled OCSP response), verifies it.
> >
> > 7. Client audits by verifying that the STH provided by the server
> > is in the cache.
> >
> > 8. An ecosystem of auditors monitors logs for STH batches and audits
> > all contained STHs by requesting consistency proofs. This saves the
> > client from having to verify every single STH itself.
> >
> > - [PRO] No need to audit SCTs.
> > - [PRO] Client never makes queries in response to browsing.
> > - [PRO] No need for a log proxy.
> > - [CON] CA needs to wait for inclusion proof if inclusion proof is
> > included in cert.
> > - [CON] Client needs to store entire history of STHs.
> > - [CON] Requires CA to upgrade to fetch inclusion proofs instead
> > of / in addition to SCTs.
> >
> > Option A2 is very similar to Option M, but avoids the need for
> > clients to do their own STH auditing (except for STHs related to
> > the STH batches). If you're happy with Option M you should be happy
> > with Option A2, even when implemented on top of the current Merkle
> > Tree design.
> >
> 
> What you lose in this design relative to both G and M is the clients
> direct assurance that the STHs it's relying on are a valid sequence,
> as opposed to something the auditor made up.  That is, the assurance
> here is like if you took G or M and removed the part where the
> auditor sends down the consistency proofs.

Not quite, because in option A2, the client has assurance that every
STH it relies upon has been published for the world to see.  If a
log misbehaves and signs an inconsistent STH, and the auditor passes
that STH through to the client, someone is certain to notice and detect
the log's misbehavior.

> That's not the biggest tragedy in the world, but if that's the best
> we can do, we'll need to be clear about this constraint in the
> document ("Most clients will need to delegate consistency checking to
> an auditor, which means that they will be at risk of the auditor
> lying to them in the following ways...").

It's true that clients have to assume that someone else does the
auditing faithfully, but since the STHs are logged for anyone to
audit, this is a very safe assumption.

> But given that there are
> options on the table that get us to a stranger guarantee at the cost
> of a spec change and some adaptation by the small number of logs that
> exist, I'm not sure why we should settle here.
> 
> > I agree with many of your concerns about SCT auditing, but
> > considering that Options A1 and A2 can be implemented on top of
> > 6962bis (plus Option M if 4MB/month can be tolerated), I don't see
> > why these concerns should hold up publication.
> >
> 
> As I've noted above, A1 and A2 aren't really meeting my requirements.
> (Maybe we should go through a requirements exercise here?)

I would like to convince you that A2 meets your requirements.  I contend
that its auditing guarantees are as strong as M's.  In particular, having
proof that the STHs are publicly-logged is just as good as the client
auditing them itself.  If you disagree, I'm curious why.

Regards,
Andrew


From nobody Thu Feb 16 12:02:34 2017
Return-Path: <prvs=12200ef3e2=steve.kent@raytheon.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 550851296E9 for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:02:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OjnH4aKtiSxx for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:02:30 -0800 (PST)
Received: from dfw-mailout20.raytheon.com (dfw-mailout20.raytheon.com [199.46.199.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72726129A5F for <trans@ietf.org>; Thu, 16 Feb 2017 12:02:11 -0800 (PST)
Received: from ma-mailout10.rtnmail.ray.com (ma-mailout10.rtnmail.ray.com [147.25.130.27]) by dfw-mailout20.ext.ray.com (8.15.0.59/8.15.0.59) with ESMTPS id v1GK29Ia004985 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Thu, 16 Feb 2017 20:02:09 GMT
Received: from 008-smtp-out.ray.com ([23.103.8.213]) by ma-mailout10.rtnmail.ray.com (8.15.0.59/8.15.0.59) with ESMTPS id v1GK28nM018955 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Thu, 16 Feb 2017 20:02:09 GMT
Received: from CY1PR0601MB023.008f.mgd2.msft.net (23.103.8.215) by CY1PR0601MB021.008f.mgd2.msft.net (23.103.8.213) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.860.16; Thu, 16 Feb 2017 20:02:07 +0000
Received: from CY1PR0601MB023.008f.mgd2.msft.net ([23.103.8.215]) by CY1PR0601MB023.008f.mgd2.msft.net ([23.103.8.215]) with mapi id 15.01.0860.012; Thu, 16 Feb 2017 20:02:07 +0000
From: Steve KENT <steve.kent@raytheon.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>, Richard Barnes <rlb@ipv.sx>
Thread-Topic: [Trans] The importance of understanding auditing
Thread-Index: AQHSh80kfExfXtOnuUCmL0vHQ+8Ec6Fq1buAgAE0jKA=
Date: Thu, 16 Feb 2017 20:02:07 +0000
Message-ID: <f4d0dcfb88a04b9b9c074d321cfc8b53@CY1PR0601MB023.008f.mgd2.msft.net>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>,  <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com>
In-Reply-To: <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [23.103.8.133]
Content-Type: multipart/alternative; boundary="_000_f4d0dcfb88a04b9b9c074d321cfc8b53CY1PR0601MB023008fmgd2m_"
MIME-Version: 1.0
X-CC: ryan-ietf@sleevi.com, rlb@ipv.sx, trans@ietf.org
X-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-02-16_14:, , signatures=0
X-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-02-16_14:, , signatures=0
X-DMZ-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1612050000 definitions=main-1702160188
X-DMZ-Spam-Reason: mlx
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/sS13RrQTXLurGDP2bWAKki-7qHA>
Cc: "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 20:02:32 -0000

--_000_f4d0dcfb88a04b9b9c074d321cfc8b53CY1PR0601MB023008fmgd2m_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Ryan,


I agree that the charter for TRANS refers to TLS client in general, but the=
 WG has long focused primarily (if not exclusively) on browsers as the TLS =
clients of interest for CT. For example, the gossip document talks extensiv=
ely in terms of browsers and HTTPS clients, not generic TLS clients. The th=
reat model also talks in terms of browsers as clients of TLS servers, and h=
as done so for a very long time. For browsers we have a model of how trust =
anchor stores are managed and thus how info about logs could be promulgated=
 (even though these mechanisms are not IETF standards.) For generic TLS cli=
ents I don't believe there are similar models, which would suggest gaps in =
the architecture.


Steve

________________________________
From: Trans <trans-bounces@ietf.org> on behalf of Ryan Sleevi <ryan-ietf@sl=
eevi.com>
Sent: Wednesday, February 15, 2017 8:19:07 PM
To: Richard Barnes
Cc: trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing



On Wed, Feb 15, 2017 at 12:50 PM, Richard Barnes <rlb@ipv.sx<mailto:rlb@ipv=
.sx>> wrote:
At base, in order to meet this group's charter deliverables, what we want t=
o be assured of is that the mechanisms in 6962-bis that are intended to ena=
ble public verifiability can actually do so in practice.  That is, we need =
to establish that there is at least one plausible story for how some substa=
ntial fraction of the statements logs provide to clients end up getting aud=
ited.

If I may, it seems like you're stating two (different) goals as equivalent;=
 the subtlety here at least deserves calling out. For recap, the charter is=
 https://datatracker.ietf.org/wg/trans/charter/ , with the work item being =
"Publish an update to RFC 6962 as a standards-track mechanism to apply veri=
fiable logs to HTTP over TLS."

The subtlety here I'm calling out is that you're implicitly treating "clien=
ts" to mean "common Web browsers". While I certainly agree that's an import=
ant use case to consider (and certainly one we at Google have been consider=
ing), your interpretation is much more narrower than what's chartered, and =
your concerns much more specific to individual products (on particular plat=
forms), rather than to either the general case of "Web browsers" or even "T=
LS clients".

The danger in this approach is that it bleeds dangerously close to specifyi=
ng implementation policy, when the current draft provides infrastructure to=
 support a variety of policies for a variety of consumers and clients. Nota=
ble here is that you can have CT clients that may decide to 'hard-fail' - w=
hether browser or otherwise - and so some of the 'pragmatic' cons you highl=
ight aren't exactly relevant to the chartered objective, or refer to implem=
entation details and product decisions rather than generalized problems.

I think perhaps if we can agree on the scope and its relevance to the chart=
er - which you're highlighting as the key concern - we can better work thro=
ugh these issues. For example, if you imagine a command-line TLS client (su=
ch as wget or curl), neither Option M nor Option G, as you've defined them,=
 may be suitable. Does that mean it's necessarily to fundamentally alter ho=
w 6962-bis works? Maybe, maybe not. Does that mean it's necessary for such =
a "guidance document" to consider wget and curl's needs as equivalent to th=
e presumed consumers of Option M or Option G? Maybe, maybe not.

--_000_f4d0dcfb88a04b9b9c074d321cfc8b53CY1PR0601MB023008fmgd2m_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body>
<style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi=
n-bottom:0;} --></style>
<div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt;color:#000000;font=
-family:Calibri,Arial,Helvetica,sans-serif;" dir=3D"ltr">
<p>Ryan,</p>
<p><br>
</p>
<p>I agree that the charter for TRANS refers to TLS client in general, but =
the WG has long focused primarily (if not exclusively) on browsers as the T=
LS clients of interest for CT. For example, the gossip document talks exten=
sively in terms of browsers and
 HTTPS clients, not generic TLS clients. The threat model also talks in ter=
ms of browsers as clients of TLS servers, and has done so for a very long t=
ime. For browsers we have a model of how trust anchor stores are managed an=
d thus how info about logs could
 be promulgated (even though these mechanisms are not IETF standards.) For =
generic TLS clients I don't believe there are similar models, which would s=
uggest gaps in the architecture.</p>
<p><br>
</p>
<p>Steve<br>
</p>
<br>
</div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Trans &lt;trans-bounc=
es@ietf.org&gt; on behalf of Ryan Sleevi &lt;ryan-ietf@sleevi.com&gt;<br>
<b>Sent:</b> Wednesday, February 15, 2017 8:19:07 PM<br>
<b>To:</b> Richard Barnes<br>
<b>Cc:</b> trans@ietf.org<br>
<b>Subject:</b> Re: [Trans] The importance of understanding auditing</font>
<div>&nbsp;</div>
</div>
<div>
<div dir=3D"ltr"><br>
<div class=3D"gmail_extra"><br>
<div class=3D"gmail_quote">On Wed, Feb 15, 2017 at 12:50 PM, Richard Barnes=
 <span dir=3D"ltr">
&lt;<a href=3D"mailto:rlb@ipv.sx" target=3D"_blank">rlb@ipv.sx</a>&gt;</spa=
n> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir=3D"ltr">At base, in order to meet this group&#8217;s charter deliv=
erables, what we want to be assured of is that the mechanisms in 6962-bis t=
hat are intended to enable public verifiability can actually do so in pract=
ice.&nbsp; That is, we need to establish that
 there is at least one plausible story for how some substantial fraction of=
 the statements logs provide to clients end up getting audited.<br>
</div>
</blockquote>
<div><br>
</div>
<div>If I may, it seems like you're stating two (different) goals as equiva=
lent; the subtlety here at least deserves calling out. For recap, the chart=
er is&nbsp;<a href=3D"https://datatracker.ietf.org/wg/trans/charter/">https=
://datatracker.ietf.org/wg/trans/charter/</a>
 , with the work item being &quot;Publish an update to RFC 6962 as a standa=
rds-track mechanism to apply verifiable logs to HTTP over TLS.&quot;</div>
<div><br>
</div>
<div>The subtlety here I'm calling out is that you're implicitly treating &=
quot;clients&quot; to mean &quot;common Web browsers&quot;. While I certain=
ly agree that's an important use case to consider (and certainly one we at =
Google have been considering), your interpretation is
 much more narrower than what's chartered, and your concerns much more spec=
ific to individual products (on particular platforms), rather than to eithe=
r the general case of &quot;Web browsers&quot; or even &quot;TLS clients&qu=
ot;.</div>
<div><br>
</div>
<div>The danger in this approach is that it bleeds dangerously close to spe=
cifying implementation policy, when the current draft provides infrastructu=
re to support a variety of policies for a variety of consumers and clients.=
 Notable here is that you can have
 CT clients that may decide to 'hard-fail' - whether browser or otherwise -=
 and so some of the 'pragmatic' cons you highlight aren't exactly relevant =
to the chartered objective, or refer to implementation details and product =
decisions rather than generalized
 problems.</div>
<div><br>
</div>
<div>I think perhaps if we can agree on the scope and its relevance to the =
charter - which you're highlighting as the key concern - we can better work=
 through these issues. For example, if you imagine a command-line TLS clien=
t (such as wget or curl), neither
 Option M nor Option G, as you've defined them, may be suitable. Does that =
mean it's necessarily to fundamentally alter how 6962-bis works? Maybe, may=
be not. Does that mean it's necessary for such a &quot;guidance document&qu=
ot; to consider wget and curl's needs as equivalent
 to the presumed consumers of Option M or Option G? Maybe, maybe not.</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_f4d0dcfb88a04b9b9c074d321cfc8b53CY1PR0601MB023008fmgd2m_--


From nobody Thu Feb 16 12:41:52 2017
Return-Path: <ryan-ietf@sleevi.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CDF1129698 for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:41:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.886
X-Spam-Level: 
X-Spam-Status: No, score=-3.886 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-1.887] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=sleevi.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WjhnKuHicQpg for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:41:49 -0800 (PST)
Received: from homiemail-a25.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 31EE5129689 for <trans@ietf.org>; Thu, 16 Feb 2017 12:41:49 -0800 (PST)
Received: from homiemail-a25.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a25.g.dreamhost.com (Postfix) with ESMTP id A45636000507 for <trans@ietf.org>; Thu, 16 Feb 2017 12:41:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sleevi.com; h=mime-version :in-reply-to:references:from:date:message-id:subject:to:cc :content-type; s=sleevi.com; bh=At7AmFk92BnLxnKVSK3ou4DFoRw=; b= twmQtnrBkNNlIOCl3nrAeq3QJZyPptFRIq6ErUS7KfD69mnEIolCRoz9qtzuw/xd CnSQ//RIe+OZCuPR1uQxbiG91IZf+YpKqv8g/RCI4tmu97JdKrmoOQvbZ5Ul6Vq3 gcKb61k3jtYirYJVYDZ+Dsag3M9IqV1jvveO3YhT+AA=
Received: from mail-lf0-f52.google.com (mail-lf0-f52.google.com [209.85.215.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: ryan@sleevi.com) by homiemail-a25.g.dreamhost.com (Postfix) with ESMTPSA id 7283E6000503 for <trans@ietf.org>; Thu, 16 Feb 2017 12:41:48 -0800 (PST)
Received: by mail-lf0-f52.google.com with SMTP id x1so13890121lff.0 for <trans@ietf.org>; Thu, 16 Feb 2017 12:41:48 -0800 (PST)
X-Gm-Message-State: AMke39l+v/D+5ojqAlgjLkSYuP8Aa2TjLpxAR1k4DU4KYyBs0TiGgBm00nD4zOgdWPG5arUfX2nCY2dlOfEfFg==
X-Received: by 10.46.20.93 with SMTP id 29mr1106475lju.10.1487277706563; Thu, 16 Feb 2017 12:41:46 -0800 (PST)
MIME-Version: 1.0
Received: by 10.25.92.154 with HTTP; Thu, 16 Feb 2017 12:41:45 -0800 (PST)
In-Reply-To: <f4d0dcfb88a04b9b9c074d321cfc8b53@CY1PR0601MB023.008f.mgd2.msft.net>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com> <f4d0dcfb88a04b9b9c074d321cfc8b53@CY1PR0601MB023.008f.mgd2.msft.net>
From: Ryan Sleevi <ryan-ietf@sleevi.com>
Date: Thu, 16 Feb 2017 12:41:45 -0800
X-Gmail-Original-Message-ID: <CAErg=HHPUp7Mf2zvx631XSCaaGqytBMzExXFRfnsjp9imYfDLA@mail.gmail.com>
Message-ID: <CAErg=HHPUp7Mf2zvx631XSCaaGqytBMzExXFRfnsjp9imYfDLA@mail.gmail.com>
To: Steve KENT <steve.kent@raytheon.com>
Content-Type: multipart/alternative; boundary=f403045fb5d461ddc30548abd3ff
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/n9MXVbFwl_HET2lPkrtt1A2-894>
Cc: Ryan Sleevi <ryan-ietf@sleevi.com>, Richard Barnes <rlb@ipv.sx>, "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 20:41:50 -0000

--f403045fb5d461ddc30548abd3ff
Content-Type: text/plain; charset=UTF-8

On Thu, Feb 16, 2017 at 12:02 PM, Steve KENT <steve.kent@raytheon.com>
wrote:

> Ryan,
>
>
> I agree that the charter for TRANS refers to TLS client in general, but
> the WG has long focused primarily (if not exclusively) on browsers as the
> TLS clients of interest for CT. For example, the gossip document talks
> extensively in terms of browsers and HTTPS clients, not generic TLS
> clients. The threat model also talks in terms of browsers as clients of TLS
> servers, and has done so for a very long time. For browsers we have a model
> of how trust anchor stores are managed and thus how info about logs could
> be promulgated (even though these mechanisms are not IETF standards.) For
> generic TLS clients I don't believe there are similar models, which would
> suggest gaps in the architecture.
>
Thanks for clarifying Steve.

I highlight this concern/divergence because I think it's important to
understand whether the disagreements are architectural or political. I
think the good comparison here is OCSP, OCSP Stapling, and client policy.
For a number of TLS clients (including S2S scenarios or automated tooling),
OCSP (with hardfail) is a totally viable scenario. However, we know
browsers have raised a variety of concerns with OCSP's deployment in that
model, which is where OCSP Stapling serves as a useful bridge for that.
However, even with OCSP Stapling, we cannot suggest that it's addressed the
revocation threat model unless and until OCSP stapling is mandatory for
connections - otherwise, we're back to the same problem. OCSP Stapling
being mandatory for connections is more a question of policy than of
technology.

Similarly, I think it's important to understand where our disagreements
exist on technology and whether the perspectives of concerns are things
that are true and generic, or if they are specific to certain deployment
and trust scenarios. For example, it's quite trivial and easy to imagine a
CT deployment scenario in which the client directly communicated with an
Auditor/Monitor who could fulfill all the roles necessary for the
assurances here - at a certain cost of client privacy (in their
communications with the Auditor/Monitor).

Richard's discussion highlights things in terms of "pros" and "cons", but
evaluating whether something is a pro, con, or neutral implies with it a
specific set of requirements and objectives, and I believe those
requirements and objectives may differ between potential clients - those
both active in TRANS and those absent. That's why I wanted to get a better
clarification here about the particular objective set as the WG sees it (vs
as Google, Mozilla, or other implementors may see it), and then better
articulate the requirements.

As an example, imagine a proposal which proposed that for clients, after
some period of time, an OCSP response MUST be stapled and the OCSP response
MUST include an inclusion proof to an STH within some delta of the OCSP
responses' validity period. That is a solution which is effectively coupled
to policy - such as whether OCSP responses must be stapled - and to
implementation - such as whether OCSP stapled responses should be preferred.

--f403045fb5d461ddc30548abd3ff
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Thu, Feb 16, 2017 at 12:02 PM, Steve KENT <span dir=3D"ltr">&lt;<a h=
ref=3D"mailto:steve.kent@raytheon.com" target=3D"_blank">steve.kent@raytheo=
n.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"m=
argin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left=
:1ex">



<div>

<div id=3D"gmail-m_7571789902778186865divtagdefaultwrapper" style=3D"font-s=
ize:12pt;color:rgb(0,0,0);font-family:calibri,arial,helvetica,sans-serif" d=
ir=3D"ltr">
<p>Ryan,</p>
<p><br>
</p>
<p>I agree that the charter for TRANS refers to TLS client in general, but =
the WG has long focused primarily (if not exclusively) on browsers as the T=
LS clients of interest for CT. For example, the gossip document talks exten=
sively in terms of browsers and
 HTTPS clients, not generic TLS clients. The threat model also talks in ter=
ms of browsers as clients of TLS servers, and has done so for a very long t=
ime. For browsers we have a model of how trust anchor stores are managed an=
d thus how info about logs could
 be promulgated (even though these mechanisms are not IETF standards.) For =
generic TLS clients I don&#39;t believe there are similar models, which wou=
ld suggest gaps in the architecture.</p></div></div></blockquote>Thanks for=
 clarifying Steve.<div><br></div><div>I highlight this concern/divergence b=
ecause I think it&#39;s important to understand whether the disagreements a=
re architectural or political. I think the good comparison here is OCSP, OC=
SP Stapling, and client policy. For a number of TLS clients (including S2S =
scenarios or automated tooling), OCSP (with hardfail) is a totally viable s=
cenario. However, we know browsers have raised a variety of concerns with O=
CSP&#39;s deployment in that model, which is where OCSP Stapling serves as =
a useful bridge for that. However, even with OCSP Stapling, we cannot sugge=
st that it&#39;s addressed the revocation threat model unless and until OCS=
P stapling is mandatory for connections - otherwise, we&#39;re back to the =
same problem. OCSP Stapling being mandatory for connections is more a quest=
ion of policy than of technology.</div><div><br></div><div>Similarly, I thi=
nk it&#39;s important to understand where our disagreements exist on techno=
logy and whether the perspectives of concerns are things that are true and =
generic, or if they are specific to certain deployment and trust scenarios.=
 For example, it&#39;s quite trivial and easy to imagine a CT deployment sc=
enario in which the client directly communicated with an Auditor/Monitor wh=
o could fulfill all the roles necessary for the assurances here - at a cert=
ain cost of client privacy (in their communications with the Auditor/Monito=
r).</div><div><br></div><div>Richard&#39;s discussion highlights things in =
terms of &quot;pros&quot; and &quot;cons&quot;, but evaluating whether some=
thing is a pro, con, or neutral implies with it a specific set of requireme=
nts and objectives, and I believe those requirements and objectives may dif=
fer between potential clients - those both active in TRANS and those absent=
. That&#39;s why I wanted to get a better clarification here about the part=
icular objective set as the WG sees it (vs as Google, Mozilla, or other imp=
lementors may see it), and then better articulate the requirements.</div><d=
iv><br></div><div>As an example, imagine a proposal which proposed that for=
 clients, after some period of time, an OCSP response MUST be stapled and t=
he OCSP response MUST include an inclusion proof to an STH within some delt=
a of the OCSP responses&#39; validity period. That is a solution which is e=
ffectively coupled to policy - such as whether OCSP responses must be stapl=
ed - and to implementation - such as whether OCSP stapled responses should =
be preferred.</div></div></div></div>

--f403045fb5d461ddc30548abd3ff--


From nobody Thu Feb 16 12:43:19 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D280B12969F for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:43:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.691
X-Spam-Level: 
X-Spam-Status: No, score=-2.691 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Veo7VTe5eytS for <trans@ietfa.amsl.com>; Thu, 16 Feb 2017 12:43:10 -0800 (PST)
Received: from mail-it0-x22f.google.com (mail-it0-x22f.google.com [IPv6:2607:f8b0:4001:c0b::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79A1A1296A6 for <trans@ietf.org>; Thu, 16 Feb 2017 12:43:10 -0800 (PST)
Received: by mail-it0-x22f.google.com with SMTP id g67so4736828itb.1 for <trans@ietf.org>; Thu, 16 Feb 2017 12:43:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=upBR329oNYnXJSlQO2iDH9EhZRlHoW8CNorFbbVwtQ4=; b=Wcwrcujdgj8EjTA6NS/kfvKcOkAsxetob28R99akMYq+FX4g4vq1GnhWlJG3lHDrKP B59WwcdD+Y7hp0kt4C5ogkVz/SdSWKpZ20DBcErCGF7M40grZM6KRlrR2BeFSb/XetQS afjbUQN/mG44s+lyVqaEI/ELxXJ9mucSQriH4jQpI4Pa+5ki/k+yoDPo+AOqC2yehMhS UmILFRhVAAh7finLXoarW5meOMXNvxy+dcP56C4ZK4nu1Zg7/3Q6ZZY3tFaprjJwG1++ Z+8B5m27TQZGDezc9DVZLXsfBoyuNnlnhdu4k01D6SKiIZ9fnbHyAgf9RD4FV5ny+IVR NUYQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=upBR329oNYnXJSlQO2iDH9EhZRlHoW8CNorFbbVwtQ4=; b=tFPKxwQNxqEcsZTSFkwToVmH/t9J/SwJeJxaR0KzisTp1mmv+FpB5CdjZJjRlh+CiC yur/7gAVTXeWAgVed/sn9y4KyqsdFuUYMCyMLwRxElX4OWkHYXeVtsgToYN8EmqfzfP7 zVbbgYbHxZUHIoxhVtb/H4/TOtMdTeHEypn+TpQKQCXCGcWZOk1T78mIzCAoYA+FahpH 8ySP0+1HlGNDiC8RFHmKeRFTFiZsVHmRN/Wt31bxTK0ij0mHpWiN1UnLj0Ur8Xlh2n2t hGr5GSCWbaOHdgw4v4h//cuN5ewFBlncxtRidT5B4LKvFRGT17bQo+S38gLbxqqEqNYY S7hw==
X-Gm-Message-State: AMke39miApF9p/dM1mj2yW4y+Nv+luSP0WrbW9KL/Enyr0yHuFi0GgPh0XwEs2XrtDyKASkO+PRXgxc9hKccu03c
X-Received: by 10.107.7.78 with SMTP id 75mr4809628ioh.165.1487277789321; Thu, 16 Feb 2017 12:43:09 -0800 (PST)
MIME-Version: 1.0
Received: by 10.107.178.23 with HTTP; Thu, 16 Feb 2017 12:42:38 -0800 (PST)
In-Reply-To: <CAKexNNMGtROWamVuM=Wtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ@mail.gmail.com>
References: <CAKexNNMGtROWamVuM=Wtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ@mail.gmail.com>
From: Eran Messeri <eranm@google.com>
Date: Thu, 16 Feb 2017 20:42:38 +0000
Message-ID: <CALzYgEfcFo=hi2tEP1de-XN4XFGfdXLWjJWgJtC+wKHJfTCQ+g@mail.gmail.com>
To: "trans@ietf.org" <trans@ietf.org>,  "certificate-transparency@googlegroups.com" <certificate-transparency@googlegroups.com>
Content-Type: multipart/alternative; boundary=001a113f98d250f9370548abd873
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/fOFRys5bz84QD2XVKhW0XncG7cU>
Subject: [Trans] Fwd: [ct-policy] CT Policy Days Location
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2017 20:43:18 -0000

--001a113f98d250f9370548abd873
Content-Type: text/plain; charset=UTF-8

Cross-post from the Chromium ct-policy list.
tl;dr:
- There are free spaces if any of you would like to attend in-person.
- You can attend remotely via https://hangouts.google.
com/hangouts/_/google.com/ctpolicydays
<https://hangouts.google.com/hangouts/_/google.com/ctpolicydays> (if you
can only use PSTN and would like to dial in, let me know).

---------- Forwarded message ----------
From: 'Ryan Hurst' via Certificate Transparency Policy <
ct-policy@chromium.org>
Date: Thu, Feb 16, 2017 at 2:56 AM
Subject: [ct-policy] CT Policy Days Location

All,

I am looking forward to seeing you all next week at Google, we will be
located in Google Tech Corners II on the Third Floor in Quinn Mallory.

I will have people in the lobby to help get you to the right location.

The address is:

Google, Inc.

Tech Corners 2

807 11th Ave

Sunnyvale, CA 94089

We have the room from 8am - 5pm (PST) but the event will not start until
9am.

Agenda wise, I received some feedback for ideas on working group sessions
from others but otherwise it seems the agenda has the right structure.

State of the Union and Warming Up

Time

Start

Stop

Slot

Description

Discussion Leader / Notes

0:15

9:00

9:15

Check-in, badging, get situated in room

All

0:30

9:00

9:30

Breakfast - Continental

All

0:05

9:30

9:35

Welcome and Logistics

Ryan Hurst

0:45

9:35

10:20

1

Presentation: Operating CT Logs at Scale

CT Team

0:45

10:20

11:05

2

Presentation: CT Standardization Roadmap

CT Team

0:15

11:05

11:20

Break

All

0:45

11:20

12:05

3

Presentation: Current Chrome Policy

Chrome Team

1:00

12:05

13:05

Lunch

All

0:45

13:05

13:50

4

Discussion: Concerns with Current Policy

Ryan Hurst

0:30

13:50

14:20

Pick Break-Out Sessions

Ryan Hurst

0:45

14:20

15:05

5.1

Break-Out Sessions - 1

TBD*

0:30

15:05

15:35

Coffee/Beverage Service Break

All

0:45

15:35

16:20

5.2

Break-Out Sessions - 1 Presentations

TBD

0:45

16:20

17:05

6.1

Break-Out Sessions - 2

TBD*

0:45

17:05

17:50

6.2

Break-Out Sessions - 2 Presentations

All

15

17:50


Adjourn for the Day

All

2:40

17:50

20:30

Casual Dinner - @ - On your own or informal group

All



Break Out Sessions and Next Steps

Start

Stop

Slot

Description

Discussion Leader / Notes

9:00

9:15

Check-in, badging, get situated in room

All

9:00

9:45

Breakfast - Continental

All

9:45

10:15

Kick-Off and Check-point

Ryan Hurst

10:15

10:45

7.1

Break-Out Sessions - 3

TBD*

10:45

11:30

Break

All

11:30

12:30

7.2

Break-Out Sessions - 3 Presentations

TBD*

12:30

13:30

Lunch

All

13:30

14:15

8.1

Break-Out Sessions - 4

TBD*

14:15

15:15

Break

All

15:15

16:00

8.2

Break-Out Sessions - 4 Presentations

TBD*

16:00

16:30

Coffee/Beverage Service Break

All

16:30

17:30

9

Next Steps Summary

Ryan Hurst

17:30


Adjourn

All

17:30

20:00

Casual Dinner - @ - On your own or informal group

All


For the remote attendees we will have a Google Video Chat here:
https://hangouts.google.com/hangouts/_/google.com/ctpolicydays
<https://hangouts.google.com/hangouts/_/google.com/ctpolicydays>

There is still more room so don't be shy if you want to attend, just let me
know.

Ryan



-- 
You received this message because you are subscribed to the Google Groups
"Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to ct-policy+unsubscribe@chromium.org.
To post to this group, send email to ct-policy@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/
chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZKnQZD_
LNSqWwyQ%40mail.gmail.com
<https://groups.google.com/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=email&utm_source=footer>
.

--001a113f98d250f9370548abd873
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Cross-post from the Chromium ct-policy list.</div><di=
v>tl;dr:</div><div>- There are free spaces if any of you would like to atte=
nd in-person.</div><div>- You can attend remotely via=C2=A0<a href=3D"https=
://hangouts.google.com/hangouts/_/google.com/ctpolicydays" target=3D"_blank=
" style=3D"font-size:12.8px">https://hangouts.google.<wbr>com/hangouts/_/go=
ogle.com/<wbr>ctpolicydays=C2=A0</a>=C2=A0(if you can only use PSTN and wou=
ld like to dial in, let me know).</div><br><div class=3D"gmail_quote">-----=
----- Forwarded message ----------<br>From: <b class=3D"gmail_sendername">&=
#39;Ryan Hurst&#39; via Certificate Transparency Policy</b> <span dir=3D"lt=
r">&lt;<a href=3D"mailto:ct-policy@chromium.org">ct-policy@chromium.org</a>=
&gt;</span><br>Date: Thu, Feb 16, 2017 at 2:56 AM<br>Subject: [ct-policy] C=
T Policy Days Location<br><br><div dir=3D"ltr">All,<div><br></div><div>I am=
 looking forward to seeing you all next week at Google, we will be located =
in Google Tech Corners II on the Third Floor in <span style=3D"color:rgb(68=
,68,68)">Quinn Mallory. =C2=A0</span></div><div><p>I will have people in th=
e lobby to help get you to the right location.</p><p><span style=3D"color:r=
gb(68,68,68)">The address is: =C2=A0</span></p></div><blockquote style=3D"m=
argin:0px 0px 0px 40px;border:none;padding:0px"><div><p>Google, Inc.</p></d=
iv><div><p>Tech Corners 2</p></div><div><p>807 11th Ave</p></div><div><p>Su=
nnyvale, CA 94089</p></div></blockquote><div><p>We have the room from <span=
 style=3D"color:rgb(51,51,51)">8am - 5pm (PST) but the event will not start=
 until 9am.</span></p><p><font color=3D"#333333">Agenda wise, I received=C2=
=A0some feedback for ideas on working group sessions from others but otherw=
ise it seems the agenda has the right structure.</font></p><p dir=3D"ltr" s=
tyle=3D"font-size:12.8px;line-height:1.38;margin-top:0pt;margin-bottom:0pt"=
><span style=3D"font-size:11pt;font-family:arial;color:rgb(0,0,0);backgroun=
d-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre=
-wrap">State of the Union and Warming Up</span></p><div dir=3D"ltr" style=
=3D"font-size:12.8px;margin-left:0pt"><table style=3D"border:none;border-co=
llapse:collapse"><colgroup><col width=3D"55"><col width=3D"58"><col width=
=3D"58"><col width=3D"51"><col width=3D"230"><col width=3D"156"></colgroup>=
<tbody><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;=
vertical-align:baseline;white-space:pre-wrap">Time</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wr=
ap">Start</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical=
-align:baseline;white-space:pre-wrap">Stop</span></p></td><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">Slot=
</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-align:ba=
seline;white-space:pre-wrap">Description</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">Discus=
sion Leader / Notes</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">0:15</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:righ=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">9:00</span></p></td><td style=3D"bor=
der-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:=
bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt=
;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fam=
ily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:=
15</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Check-in, badgi=
ng, get situated in room</span></p></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"h=
eight:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">0:30</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:00</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">9:30</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
br></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">Breakfast - Continental</span></p></td><td style=3D"border-width:0.75p=
t;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:=
2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:=
0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);verti=
cal-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=
=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">0:05</span></p></td><td style=3D"border-width=
:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pa=
dding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-b=
ottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial=
;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:30</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">9:35</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"=
line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spac=
e:pre-wrap">Welcome and Logistics</span></p></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);=
vertical-align:baseline;white-space:pre-wrap">Ryan Hurst</span></p></td></t=
r><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:so=
lid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"lt=
r" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:ri=
ght"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);verti=
cal-align:baseline;white-space:pre-wrap">0:45</span></p></td><td style=3D"b=
order-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-alig=
n:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0=
pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-f=
amily:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:ba=
seline;white-space:pre-wrap">9:35</span></p></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white=
-space:pre-wrap">10:20</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;te=
xt-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0=
,0,0);background-color:transparent;vertical-align:baseline;white-space:pre-=
wrap">1</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"f=
ont-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transpare=
nt;vertical-align:baseline;white-space:pre-wrap">Presentation: Operating CT=
 Logs at Scale</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:base=
line;white-space:pre-wrap">CT Team</span></p></td></tr><tr style=3D"height:=
0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whi=
te-space:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;t=
ext-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre=
-wrap">10:20</span></p></td><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"l=
tr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:r=
ight"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);back=
ground-color:transparent;vertical-align:baseline;white-space:pre-wrap">11:0=
5</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">2</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:b=
aseline;white-space:pre-wrap">Presentation: CT Standardization Roadmap</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pr=
e-wrap">CT Team</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"b=
order-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-alig=
n:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0=
pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-f=
amily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">=
0:15</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-c=
olor:transparent;vertical-align:baseline;white-space:pre-wrap">11:05</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">11:20</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);back=
ground-color:transparent;vertical-align:baseline;white-space:pre-wrap">Brea=
k</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:righ=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgro=
und-color:transparent;vertical-align:baseline;white-space:pre-wrap">11:20</=
span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-co=
lor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"l=
ine-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span st=
yle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:t=
ransparent;vertical-align:baseline;white-space:pre-wrap">12:05</span></p></=
td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0=
,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:=
1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;=
vertical-align:baseline;white-space:pre-wrap">3</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">Presentation: Current Chrome Policy</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Chrome Team<=
/span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">1:00</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent=
;vertical-align:baseline;white-space:pre-wrap">12:05</span></p></td><td sty=
le=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertic=
al-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margi=
n-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-a=
lign:baseline;white-space:pre-wrap">13:05</span></p></td><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:so=
lid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"lt=
r" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">Lunch</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All=
</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</span></p>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparen=
t;vertical-align:baseline;white-space:pre-wrap">13:05</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-=
align:baseline;white-space:pre-wrap">13:50</span></p></td><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:basel=
ine;white-space:pre-wrap">4</span></p></td><td style=3D"border-width:0.75pt=
;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2=
pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0=
pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">Discus=
sion: Concerns with Current Policy</span></p></td><td style=3D"border-width=
:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pa=
dding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-b=
ottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">Ryan Hurst</span></p></td></=
tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"l=
tr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:r=
ight"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vert=
ical-align:baseline;white-space:pre-wrap">0:30</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:b=
aseline;white-space:pre-wrap">13:50</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:aria=
l;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;whi=
te-space:pre-wrap">14:20</span></p></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><br></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:=
rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-=
height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-a=
lign:baseline;white-space:pre-wrap">Pick Break-Out Sessions</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Rya=
n Hurst</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">14:20</span></p></td=
><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0=
);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.=
38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-s=
ize:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;ve=
rtical-align:baseline;white-space:pre-wrap">15:05</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-ali=
gn:baseline;white-space:pre-wrap">5.1</span></p></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0=
,0);background-color:transparent;vertical-align:baseline;white-space:pre-wr=
ap">Break-Out Sessions - 1</span></p></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">TBD*</span></p></td></tr><tr style=
=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">0:30</span></p></td><td style=3D"border-width=
:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pa=
dding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-b=
ottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial=
;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;whit=
e-space:pre-wrap">15:05</span></p></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;t=
ext-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre=
-wrap">15:35</span></p></td><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baselin=
e;white-space:pre-wrap">Coffee/Beverage Service Break</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</span=
></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;=
text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</span></p></td><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vert=
ical-align:baseline;white-space:pre-wrap">15:35</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font=
-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:=
baseline;white-space:pre-wrap">16:20</span></p></td><td style=3D"border-wid=
th:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;=
padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin=
-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;wh=
ite-space:pre-wrap">5.2</span></p></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background=
-color:transparent;vertical-align:baseline;white-space:pre-wrap">Break-Out =
Sessions - 1 Presentations</span></p></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">TBD</span></p></td></tr><tr style=3D=
"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-col=
or:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"li=
ne-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:base=
line;white-space:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;co=
lor:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-s=
pace:pre-wrap">16:20</span></p></td><td style=3D"border-width:0.75pt;border=
-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p =
dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text=
-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0=
,0);vertical-align:baseline;white-space:pre-wrap">17:05</span></p></td><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;ma=
rgin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:1=
2pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:=
pre-wrap">6.1</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions -=
 2</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:righ=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgro=
und-color:transparent;vertical-align:baseline;white-space:pre-wrap">17:05</=
span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-co=
lor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"l=
ine-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span st=
yle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:bas=
eline;white-space:pre-wrap">17:50</span></p></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">6.2</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;fo=
nt-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-alig=
n:baseline;white-space:pre-wrap">Break-Out Sessions - 2 Presentations</span=
></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:=
rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-=
height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre=
-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">15</s=
pan></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-col=
or:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"li=
ne-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tr=
ansparent;vertical-align:baseline;white-space:pre-wrap">17:50</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">Adjourn for the Day</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr=
 style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap">2:40</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">17:50=
</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">20:30</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">Casual Dinner - @ - On your own or informal group</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">All</span></p></td></tr></tbody></table></div><p><br style=3D"font-siz=
e:12.8px"><br style=3D"font-size:12.8px"></p><p dir=3D"ltr" style=3D"font-s=
ize:12.8px;line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=
=3D"font-size:11pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap">Break=
 Out Sessions and Next Steps</span></p><div dir=3D"ltr" style=3D"font-size:=
12.8px;margin-left:0pt"><table style=3D"border:none;border-collapse:collaps=
e"><colgroup><col width=3D"61"><col width=3D"61"><col width=3D"54"><col wid=
th=3D"259"><col width=3D"173"></colgroup><tbody><tr style=3D"height:0pt"><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Start=
</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spa=
ce:pre-wrap">Stop</span></p></td><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">Slot</span></p></td><td style=3D"border-width=
:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pa=
dding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-b=
ottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">Description</span></p></td><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-famil=
y:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Disc=
ussion Leader / Notes</span></p></td></tr><tr style=3D"height:0pt"><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-=
wrap">9:00</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertic=
al-align:baseline;white-space:pre-wrap">9:15</span></p></td><td style=3D"bo=
rder-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align=
:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:base=
line;white-space:pre-wrap">Check-in, badging, get situated in room</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;fo=
nt-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wr=
ap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:00</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">9:45</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spa=
ce:pre-wrap">Breakfast - Continental</span></p></td><td style=3D"border-wid=
th:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;=
padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin=
-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);vertical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><t=
r style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">9:45</span></p></td><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;m=
argin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-famil=
y:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">10:1=
5</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Kick-Off and Che=
ck-point</span></p></td><td style=3D"border-width:0.75pt;border-style:solid=
;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" =
style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"=
font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;w=
hite-space:pre-wrap">Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt=
"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">10:15</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;tex=
t-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);background-color:transparent;vertical-align:baseline;white-space:pre-w=
rap">10:45</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">7.1</s=
pan></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-col=
or:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"li=
ne-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:1=
2pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertica=
l-align:baseline;white-space:pre-wrap">Break-Out Sessions - 3</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fa=
mily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">T=
BD*</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">10:45</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">11:30</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);back=
ground-color:transparent;vertical-align:baseline;white-space:pre-wrap">Brea=
k</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">11:30</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">12:30<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"=
line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span s=
tyle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:=
transparent;vertical-align:baseline;white-space:pre-wrap">7.2</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fa=
mily:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:bas=
eline;white-space:pre-wrap">Break-Out Sessions - 3 Presentations</span></p>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font=
-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap=
">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wid=
th:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;=
padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin=
-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">12:30</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">13:30</span></p></td=
><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0=
);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);bac=
kground-color:transparent;vertical-align:baseline;white-space:pre-wrap">Lun=
ch</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">13:30</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">14:15<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"=
line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span s=
tyle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:=
transparent;vertical-align:baseline;white-space:pre-wrap">8.1</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fa=
mily:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:bas=
eline;white-space:pre-wrap">Break-Out Sessions - 4</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD*</span><=
/p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;te=
xt-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0=
,0,0);vertical-align:baseline;white-space:pre-wrap">14:15</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;verti=
cal-align:baseline;white-space:pre-wrap">15:15</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color=
:transparent;vertical-align:baseline;white-space:pre-wrap">Break</span></p>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font=
-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap=
">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:aria=
l;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">15:15</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">16:00</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;ver=
tical-align:baseline;white-space:pre-wrap">8.2</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spa=
ce:pre-wrap">Break-Out Sessions - 4 Presentations</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD*</span><=
/p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;te=
xt-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0=
,0,0);vertical-align:baseline;white-space:pre-wrap">16:00</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;verti=
cal-align:baseline;white-space:pre-wrap">16:30</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color=
:transparent;vertical-align:baseline;white-space:pre-wrap">Coffee/Beverage =
Service Break</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt">=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-sp=
ace:pre-wrap">16:30</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-=
align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);background-color:transparent;vertical-align:baseline;white-space:pre-wra=
p">17:30</span></p></td><td style=3D"border-width:0.75pt;border-style:solid=
;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" =
style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right=
"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgrou=
nd-color:transparent;vertical-align:baseline;white-space:pre-wrap">9</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-al=
ign:baseline;white-space:pre-wrap">Next Steps Summary</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Ryan Hurs=
t</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;co=
lor:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">17:30</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-wid=
th:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;=
padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whi=
te-space:pre-wrap">Adjourn</span></p></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D=
"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-col=
or:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"li=
ne-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:base=
line;white-space:pre-wrap">17:30</span></p></td><td style=3D"border-width:0=
.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padd=
ing:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bot=
tom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;c=
olor:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">20:00</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt"><span style=3D"color:rgb(0,0,0);font-family:arial;font-size:1=
6px;white-space:pre-wrap">Casual Dinner - @ - On your own or informal group=
</span><br></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">All</span></p></td></tr></tbody></table></div><p><br style=
=3D"font-size:12.8px"></p><p>For the remote attendees we will have a Google=
 Video Chat here:=C2=A0<a href=3D"https://hangouts.google.com/hangouts/_/go=
ogle.com/ctpolicydays" target=3D"_blank">https://hangouts.google.<wbr>com/h=
angouts/_/google.com/<wbr>ctpolicydays=C2=A0</a></p><p>There is still more =
room so don&#39;t be shy if you want to attend, just let me know.</p><span =
class=3D"gmail-HOEnZb"><font color=3D"#888888"><p>Ryan</p><p><font color=3D=
"#333333"><br></font></p><p><font color=3D"#333333"><br></font></p></font><=
/span></div></div><span class=3D"gmail-HOEnZb"><font color=3D"#888888">

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;Certificate Transparency Policy&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:ct-policy+unsubscribe@chromium.org" target=3D"_bl=
ank">ct-policy+unsubscribe@<wbr>chromium.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:ct-policy@chromium.o=
rg" target=3D"_blank">ct-policy@chromium.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZ=
KnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=3Demail&amp;utm_source=3Dfooter"=
 target=3D"_blank">https://groups.google.com/a/<wbr>chromium.org/d/msgid/ct=
-<wbr>policy/CAKexNNMGtROWamVuM%<wbr>3DWtvz8HACcSOTNLuXiZKnQZD_<wbr>LNSqWwy=
Q%40mail.gmail.com</a>.<br>
</font></span></div><br></div>

--001a113f98d250f9370548abd873--


From nobody Fri Feb 17 09:19:24 2017
Return-Path: <prvs=1221f82071=steve.kent@raytheon.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C49212959A for <trans@ietfa.amsl.com>; Fri, 17 Feb 2017 09:19:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.759
X-Spam-Level: 
X-Spam-Status: No, score=-1.759 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_SBL=0.141, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QhCryz1yzS8b for <trans@ietfa.amsl.com>; Fri, 17 Feb 2017 09:19:21 -0800 (PST)
Received: from dfw-mailout10.raytheon.com (dfw-mailout10.raytheon.com [199.46.199.220]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 54BDB129562 for <trans@ietf.org>; Fri, 17 Feb 2017 09:19:21 -0800 (PST)
Received: from tx-mailout10.rtnmail.ray.com (tx-mailout10.rtnmail.ray.com [138.126.127.234]) by dfw-mailout10.ext.ray.com (8.15.0.59/8.15.0.59) with ESMTPS id v1HHJIN7048629 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Fri, 17 Feb 2017 17:19:18 GMT
Received: from 008-smtp-out.ray.com ([23.103.8.213]) by tx-mailout10.rtnmail.ray.com (8.15.0.59/8.15.0.59) with ESMTPS id v1HHJHga007877 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Fri, 17 Feb 2017 17:19:18 GMT
Received: from CY1PR0601MB023.008f.mgd2.msft.net (23.103.8.215) by CY1PR0601MB021.008f.mgd2.msft.net (23.103.8.213) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.860.16; Fri, 17 Feb 2017 17:19:16 +0000
Received: from CY1PR0601MB023.008f.mgd2.msft.net ([23.103.8.215]) by CY1PR0601MB023.008f.mgd2.msft.net ([23.103.8.215]) with mapi id 15.01.0860.012; Fri, 17 Feb 2017 17:19:16 +0000
From: Steve KENT <steve.kent@raytheon.com>
To: Ryan Sleevi <ryan-ietf@sleevi.com>
Thread-Topic: [Trans] The importance of understanding auditing
Thread-Index: AQHSh80kfExfXtOnuUCmL0vHQ+8Ec6Fq1buAgAE0jKCAABBKgIABVate
Date: Fri, 17 Feb 2017 17:19:16 +0000
Message-ID: <6521151207624ec3bc74a2e88992b872@CY1PR0601MB023.008f.mgd2.msft.net>
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <CAErg=HEP2+2J=CHRbc-LPbCqKBZsytSiyKkk71LbQuTtTYTw7w@mail.gmail.com> <f4d0dcfb88a04b9b9c074d321cfc8b53@CY1PR0601MB023.008f.mgd2.msft.net>, <CAErg=HHPUp7Mf2zvx631XSCaaGqytBMzExXFRfnsjp9imYfDLA@mail.gmail.com>
In-Reply-To: <CAErg=HHPUp7Mf2zvx631XSCaaGqytBMzExXFRfnsjp9imYfDLA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [23.103.8.4]
Content-Type: multipart/alternative; boundary="_000_6521151207624ec3bc74a2e88992b872CY1PR0601MB023008fmgd2m_"
MIME-Version: 1.0
X-CC: ryan-ietf@sleevi.com, rlb@ipv.sx, trans@ietf.org
X-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-02-17_14:, , signatures=0
X-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-02-17_14:, , signatures=0
X-DMZ-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1612050000 definitions=main-1702170159
X-DMZ-Spam-Reason: mlx
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/Gv_5ZeIj1nqJ1QdXTAhi2xgPwj8>
Cc: Richard Barnes <rlb@ipv.sx>, "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Feb 2017 17:19:23 -0000

--_000_6521151207624ec3bc74a2e88992b872CY1PR0601MB023008fmgd2m_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Ryan,


Thanks for the thoughtful reply and further explanation of your concerns. I=
 agree that what constitutes a pro or con is very much a function of the pe=
rceived use context, which is why IETF WGs often (but not always) develop a=
 set of requirements before pursuing the design of solutions. Unfortunately=
, that was not the case for TRANS. The charter asserts that verifiable logs=
 are the solution for the problem of mis-issuance in the context of HTTP ov=
er TLS, but mis-issuance is not defined in the charter or in 6962-bis (alth=
ough the threat doc does define the term).


If we adopt the very general context of any use of HTTP/TLS then it's harde=
r to establish firm requirements based on uniform assumptions, because of t=
he wide range of scenarios that are encompassed. Your discussion of OCSP st=
apling illustrates the problem, I believe. I support Richard's assumption t=
hat browser use of CT is a useful scope for the current doc. Also, as I not=
ed, that context has been the focus of WG discussions since the beginning, =
as reflected in the two other active WG docs.


Steve

________________________________
From: Trans <trans-bounces@ietf.org> on behalf of Ryan Sleevi <ryan-ietf@sl=
eevi.com>
Sent: Thursday, February 16, 2017 3:41:45 PM
To: Steve KENT
Cc: Ryan Sleevi; Richard Barnes; trans@ietf.org
Subject: Re: [Trans] The importance of understanding auditing



On Thu, Feb 16, 2017 at 12:02 PM, Steve KENT <steve.kent@raytheon.com<mailt=
o:steve.kent@raytheon.com>> wrote:

Ryan,


I agree that the charter for TRANS refers to TLS client in general, but the=
 WG has long focused primarily (if not exclusively) on browsers as the TLS =
clients of interest for CT. For example, the gossip document talks extensiv=
ely in terms of browsers and HTTPS clients, not generic TLS clients. The th=
reat model also talks in terms of browsers as clients of TLS servers, and h=
as done so for a very long time. For browsers we have a model of how trust =
anchor stores are managed and thus how info about logs could be promulgated=
 (even though these mechanisms are not IETF standards.) For generic TLS cli=
ents I don't believe there are similar models, which would suggest gaps in =
the architecture.

Thanks for clarifying Steve.

I highlight this concern/divergence because I think it's important to under=
stand whether the disagreements are architectural or political. I think the=
 good comparison here is OCSP, OCSP Stapling, and client policy. For a numb=
er of TLS clients (including S2S scenarios or automated tooling), OCSP (wit=
h hardfail) is a totally viable scenario. However, we know browsers have ra=
ised a variety of concerns with OCSP's deployment in that model, which is w=
here OCSP Stapling serves as a useful bridge for that. However, even with O=
CSP Stapling, we cannot suggest that it's addressed the revocation threat m=
odel unless and until OCSP stapling is mandatory for connections - otherwis=
e, we're back to the same problem. OCSP Stapling being mandatory for connec=
tions is more a question of policy than of technology.

Similarly, I think it's important to understand where our disagreements exi=
st on technology and whether the perspectives of concerns are things that a=
re true and generic, or if they are specific to certain deployment and trus=
t scenarios. For example, it's quite trivial and easy to imagine a CT deplo=
yment scenario in which the client directly communicated with an Auditor/Mo=
nitor who could fulfill all the roles necessary for the assurances here - a=
t a certain cost of client privacy (in their communications with the Audito=
r/Monitor).

Richard's discussion highlights things in terms of "pros" and "cons", but e=
valuating whether something is a pro, con, or neutral implies with it a spe=
cific set of requirements and objectives, and I believe those requirements =
and objectives may differ between potential clients - those both active in =
TRANS and those absent. That's why I wanted to get a better clarification h=
ere about the particular objective set as the WG sees it (vs as Google, Moz=
illa, or other implementors may see it), and then better articulate the req=
uirements.

As an example, imagine a proposal which proposed that for clients, after so=
me period of time, an OCSP response MUST be stapled and the OCSP response M=
UST include an inclusion proof to an STH within some delta of the OCSP resp=
onses' validity period. That is a solution which is effectively coupled to =
policy - such as whether OCSP responses must be stapled - and to implementa=
tion - such as whether OCSP stapled responses should be preferred.

--_000_6521151207624ec3bc74a2e88992b872CY1PR0601MB023008fmgd2m_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body>
<style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi=
n-bottom:0;} --></style>
<div id=3D"divtagdefaultwrapper" style=3D"font-size:12pt;color:#000000;font=
-family:Calibri,Arial,Helvetica,sans-serif;" dir=3D"ltr">
<p>Ryan,</p>
<p><br>
</p>
<p>Thanks for the thoughtful reply and further explanation of your concerns=
. I agree that what constitutes a pro or con is very much a function of the=
 perceived use context, which is why IETF WGs often (but not always) develo=
p a set of requirements before pursuing
 the design of solutions. Unfortunately, that was not the case for TRANS. T=
he charter asserts that verifiable logs are the solution for the problem of=
 mis-issuance in the context of HTTP over TLS, but mis-issuance is not defi=
ned in the charter or in 6962-bis
 (although the threat doc does define the term). <br>
</p>
<p><br>
</p>
<p>If we adopt the very general context of any use of HTTP/TLS then it's ha=
rder to establish firm requirements based on uniform assumptions, because o=
f the wide range of scenarios that are encompassed. Your discussion of OCSP=
 stapling illustrates the problem,
 I believe. I support Richard's assumption that browser use of CT is a usef=
ul scope for the current doc. Also, as I noted, that context has been the f=
ocus of WG discussions since the beginning, as reflected in the two other a=
ctive WG docs.</p>
<p><br>
</p>
<p>Steve<br>
</p>
</div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Trans &lt;trans-bounc=
es@ietf.org&gt; on behalf of Ryan Sleevi &lt;ryan-ietf@sleevi.com&gt;<br>
<b>Sent:</b> Thursday, February 16, 2017 3:41:45 PM<br>
<b>To:</b> Steve KENT<br>
<b>Cc:</b> Ryan Sleevi; Richard Barnes; trans@ietf.org<br>
<b>Subject:</b> Re: [Trans] The importance of understanding auditing</font>
<div>&nbsp;</div>
</div>
<div>
<div dir=3D"ltr"><br>
<div class=3D"gmail_extra"><br>
<div class=3D"gmail_quote">On Thu, Feb 16, 2017 at 12:02 PM, Steve KENT <sp=
an dir=3D"ltr">
&lt;<a href=3D"mailto:steve.kent@raytheon.com" target=3D"_blank">steve.kent=
@raytheon.com</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">
<div>
<div id=3D"gmail-m_7571789902778186865divtagdefaultwrapper" style=3D"font-s=
ize:12pt;color:rgb(0,0,0);font-family:calibri,arial,helvetica,sans-serif" d=
ir=3D"ltr">
<p>Ryan,</p>
<p><br>
</p>
<p>I agree that the charter for TRANS refers to TLS client in general, but =
the WG has long focused primarily (if not exclusively) on browsers as the T=
LS clients of interest for CT. For example, the gossip document talks exten=
sively in terms of browsers and
 HTTPS clients, not generic TLS clients. The threat model also talks in ter=
ms of browsers as clients of TLS servers, and has done so for a very long t=
ime. For browsers we have a model of how trust anchor stores are managed an=
d thus how info about logs could
 be promulgated (even though these mechanisms are not IETF standards.) For =
generic TLS clients I don't believe there are similar models, which would s=
uggest gaps in the architecture.</p>
</div>
</div>
</blockquote>
Thanks for clarifying Steve.
<div><br>
</div>
<div>I highlight this concern/divergence because I think it's important to =
understand whether the disagreements are architectural or political. I thin=
k the good comparison here is OCSP, OCSP Stapling, and client policy. For a=
 number of TLS clients (including
 S2S scenarios or automated tooling), OCSP (with hardfail) is a totally via=
ble scenario. However, we know browsers have raised a variety of concerns w=
ith OCSP's deployment in that model, which is where OCSP Stapling serves as=
 a useful bridge for that. However,
 even with OCSP Stapling, we cannot suggest that it's addressed the revocat=
ion threat model unless and until OCSP stapling is mandatory for connection=
s - otherwise, we're back to the same problem. OCSP Stapling being mandator=
y for connections is more a question
 of policy than of technology.</div>
<div><br>
</div>
<div>Similarly, I think it's important to understand where our disagreement=
s exist on technology and whether the perspectives of concerns are things t=
hat are true and generic, or if they are specific to certain deployment and=
 trust scenarios. For example, it's
 quite trivial and easy to imagine a CT deployment scenario in which the cl=
ient directly communicated with an Auditor/Monitor who could fulfill all th=
e roles necessary for the assurances here - at a certain cost of client pri=
vacy (in their communications with
 the Auditor/Monitor).</div>
<div><br>
</div>
<div>Richard's discussion highlights things in terms of &quot;pros&quot; an=
d &quot;cons&quot;, but evaluating whether something is a pro, con, or neut=
ral implies with it a specific set of requirements and objectives, and I be=
lieve those requirements and objectives may differ between
 potential clients - those both active in TRANS and those absent. That's wh=
y I wanted to get a better clarification here about the particular objectiv=
e set as the WG sees it (vs as Google, Mozilla, or other implementors may s=
ee it), and then better articulate
 the requirements.</div>
<div><br>
</div>
<div>As an example, imagine a proposal which proposed that for clients, aft=
er some period of time, an OCSP response MUST be stapled and the OCSP respo=
nse MUST include an inclusion proof to an STH within some delta of the OCSP=
 responses' validity period. That
 is a solution which is effectively coupled to policy - such as whether OCS=
P responses must be stapled - and to implementation - such as whether OCSP =
stapled responses should be preferred.</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_6521151207624ec3bc74a2e88992b872CY1PR0601MB023008fmgd2m_--


From nobody Tue Feb 21 05:33:23 2017
Return-Path: <debcooley1@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5250E129BB1 for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 05:33:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.738
X-Spam-Level: 
X-Spam-Status: No, score=-1.738 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aBn17YqnEbvt for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 05:33:16 -0800 (PST)
Received: from mail-wr0-x22e.google.com (mail-wr0-x22e.google.com [IPv6:2a00:1450:400c:c0c::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 17F47129BB6 for <trans@ietf.org>; Tue, 21 Feb 2017 05:33:15 -0800 (PST)
Received: by mail-wr0-x22e.google.com with SMTP id z61so81936551wrc.1 for <trans@ietf.org>; Tue, 21 Feb 2017 05:33:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=VZiHp40HUwC9/yNKI9/aZtHuvA0SJbhWZlR19GWnTZI=; b=HikU71rNq5rRXXco8j9LL74hgKeQmVAYeJpJw74zm8IFr6BcXVkod1TPdwuChnAnw9 VN/kuJmmkn0S26GFcQ84bUJ6YtH+z09EVgHb1DZ6cogjUP8eNk1xdhOmFkxmwPuqFRW8 ovnoL2MV9o++znWS46RjGmHyETerBrhSVLhJdHGxA7y6QOqpYcESVvUkKcQxx/PvzOLD 0cnRdUhNobmw0rFwJ7e3x8fiH4j8V9rKVnL3R/3isqmqx30DgAdGa9X2ykfSRsK9T7H0 PqWIeXvx8qjTcxWLyUyRIQZ2aqAnzT8bTT307hBJCA5uCRfcIR1A0D2JpFAEsj9a/rcN 3vPQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=VZiHp40HUwC9/yNKI9/aZtHuvA0SJbhWZlR19GWnTZI=; b=JOtqaffdtYQBL9Ba5Gc0XaS8k2WMz4IjETpu4wp8WLZfdaURaFHThN4QfLUwdXmwRp 5YNVQWb61wi4LJ+fkDV/8dMVaiUuNyEDF3zNp+D3PJ5mjCBHMsqApwN4GKrrUOXteAxk I6hP4s0DCqj9kxEeBub2W4BMhmb2UbpdGO4GZ1CjRhNe+0/xKHNTc8zXB+lRAvHN9VZT eVScSOZQdQE6MELFRjrHHAfD8QIqjIuCbVZ6QNGTfsBghmDhFiBcoI2K9vzNmQYl9lBu HCYcG3/3joVItTZi34QRx+xYAqPa+zx7VTeHK9YqentUoQw5V8quaPmql6UxbQAVK/ey manQ==
X-Gm-Message-State: AMke39lCVZnxuPVFzwI63XTRDoOO4nywo31pZ99/5xRFeCaWNU8ZWOc1k1Eobh24hW99v+bce8J1Ly9T9AWBJA==
X-Received: by 10.223.138.9 with SMTP id w9mr19625442wrw.50.1487683993507; Tue, 21 Feb 2017 05:33:13 -0800 (PST)
MIME-Version: 1.0
Received: by 10.80.153.2 with HTTP; Tue, 21 Feb 2017 05:33:12 -0800 (PST)
In-Reply-To: <CALzYgEfcFo=hi2tEP1de-XN4XFGfdXLWjJWgJtC+wKHJfTCQ+g@mail.gmail.com>
References: <CAKexNNMGtROWamVuM=Wtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ@mail.gmail.com> <CALzYgEfcFo=hi2tEP1de-XN4XFGfdXLWjJWgJtC+wKHJfTCQ+g@mail.gmail.com>
From: Deb Cooley <debcooley1@gmail.com>
Date: Tue, 21 Feb 2017 08:33:12 -0500
Message-ID: <CAGgd1Od-gHccYuGKRnQf+mb27rrQ+jtCvUEAOf5SqQG+Kr=BFg@mail.gmail.com>
To: Eran Messeri <eranm@google.com>
Content-Type: multipart/alternative; boundary=f403045e447cf8a43305490a6b8c
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/8K5jRPIyFMjXbZDgRUKhb2u1IHk>
Cc: "trans@ietf.org" <trans@ietf.org>, "certificate-transparency@googlegroups.com" <certificate-transparency@googlegroups.com>
Subject: Re: [Trans] Fwd: [ct-policy] CT Policy Days Location
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Feb 2017 13:33:17 -0000

--f403045e447cf8a43305490a6b8c
Content-Type: text/plain; charset=UTF-8

Can you post the PSTN information?


TY,
Deb Cooley


On Thu, Feb 16, 2017 at 3:42 PM, Eran Messeri <eranm@google.com> wrote:

> Cross-post from the Chromium ct-policy list.
> tl;dr:
> - There are free spaces if any of you would like to attend in-person.
> - You can attend remotely via https://hangouts.google.co
> m/hangouts/_/google.com/ctpolicydays
> <https://hangouts.google.com/hangouts/_/google.com/ctpolicydays> (if you
> can only use PSTN and would like to dial in, let me know).
>
> ---------- Forwarded message ----------
> From: 'Ryan Hurst' via Certificate Transparency Policy <
> ct-policy@chromium.org>
> Date: Thu, Feb 16, 2017 at 2:56 AM
> Subject: [ct-policy] CT Policy Days Location
>
> All,
>
> I am looking forward to seeing you all next week at Google, we will be
> located in Google Tech Corners II on the Third Floor in Quinn Mallory.
>
> I will have people in the lobby to help get you to the right location.
>
> The address is:
>
> Google, Inc.
>
> Tech Corners 2
>
> 807 11th Ave
>
> Sunnyvale, CA 94089
>
> We have the room from 8am - 5pm (PST) but the event will not start until
> 9am.
>
> Agenda wise, I received some feedback for ideas on working group sessions
> from others but otherwise it seems the agenda has the right structure.
>
> State of the Union and Warming Up
>
> Time
>
> Start
>
> Stop
>
> Slot
>
> Description
>
> Discussion Leader / Notes
>
> 0:15
>
> 9:00
>
> 9:15
>
> Check-in, badging, get situated in room
>
> All
>
> 0:30
>
> 9:00
>
> 9:30
>
> Breakfast - Continental
>
> All
>
> 0:05
>
> 9:30
>
> 9:35
>
> Welcome and Logistics
>
> Ryan Hurst
>
> 0:45
>
> 9:35
>
> 10:20
>
> 1
>
> Presentation: Operating CT Logs at Scale
>
> CT Team
>
> 0:45
>
> 10:20
>
> 11:05
>
> 2
>
> Presentation: CT Standardization Roadmap
>
> CT Team
>
> 0:15
>
> 11:05
>
> 11:20
>
> Break
>
> All
>
> 0:45
>
> 11:20
>
> 12:05
>
> 3
>
> Presentation: Current Chrome Policy
>
> Chrome Team
>
> 1:00
>
> 12:05
>
> 13:05
>
> Lunch
>
> All
>
> 0:45
>
> 13:05
>
> 13:50
>
> 4
>
> Discussion: Concerns with Current Policy
>
> Ryan Hurst
>
> 0:30
>
> 13:50
>
> 14:20
>
> Pick Break-Out Sessions
>
> Ryan Hurst
>
> 0:45
>
> 14:20
>
> 15:05
>
> 5.1
>
> Break-Out Sessions - 1
>
> TBD*
>
> 0:30
>
> 15:05
>
> 15:35
>
> Coffee/Beverage Service Break
>
> All
>
> 0:45
>
> 15:35
>
> 16:20
>
> 5.2
>
> Break-Out Sessions - 1 Presentations
>
> TBD
>
> 0:45
>
> 16:20
>
> 17:05
>
> 6.1
>
> Break-Out Sessions - 2
>
> TBD*
>
> 0:45
>
> 17:05
>
> 17:50
>
> 6.2
>
> Break-Out Sessions - 2 Presentations
>
> All
>
> 15
>
> 17:50
>
>
> Adjourn for the Day
>
> All
>
> 2:40
>
> 17:50
>
> 20:30
>
> Casual Dinner - @ - On your own or informal group
>
> All
>
>
>
> Break Out Sessions and Next Steps
>
> Start
>
> Stop
>
> Slot
>
> Description
>
> Discussion Leader / Notes
>
> 9:00
>
> 9:15
>
> Check-in, badging, get situated in room
>
> All
>
> 9:00
>
> 9:45
>
> Breakfast - Continental
>
> All
>
> 9:45
>
> 10:15
>
> Kick-Off and Check-point
>
> Ryan Hurst
>
> 10:15
>
> 10:45
>
> 7.1
>
> Break-Out Sessions - 3
>
> TBD*
>
> 10:45
>
> 11:30
>
> Break
>
> All
>
> 11:30
>
> 12:30
>
> 7.2
>
> Break-Out Sessions - 3 Presentations
>
> TBD*
>
> 12:30
>
> 13:30
>
> Lunch
>
> All
>
> 13:30
>
> 14:15
>
> 8.1
>
> Break-Out Sessions - 4
>
> TBD*
>
> 14:15
>
> 15:15
>
> Break
>
> All
>
> 15:15
>
> 16:00
>
> 8.2
>
> Break-Out Sessions - 4 Presentations
>
> TBD*
>
> 16:00
>
> 16:30
>
> Coffee/Beverage Service Break
>
> All
>
> 16:30
>
> 17:30
>
> 9
>
> Next Steps Summary
>
> Ryan Hurst
>
> 17:30
>
>
> Adjourn
>
> All
>
> 17:30
>
> 20:00
>
> Casual Dinner - @ - On your own or informal group
>
> All
>
>
> For the remote attendees we will have a Google Video Chat here:
> https://hangouts.google.com/hangouts/_/google.com/ctpolicydays
> <https://hangouts.google.com/hangouts/_/google.com/ctpolicydays>
>
> There is still more room so don't be shy if you want to attend, just let
> me know.
>
> Ryan
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "Certificate Transparency Policy" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ct-policy+unsubscribe@chromium.org.
> To post to this group, send email to ct-policy@chromium.org.
> To view this discussion on the web visit https://groups.google.com/a/ch
> romium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACc
> SOTNLuXiZKnQZD_LNSqWwyQ%40mail.gmail.com
> <https://groups.google.com/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>
>

--f403045e447cf8a43305490a6b8c
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Can you post the PSTN information?=C2=A0 <br><br><br>=
</div><div>TY, <br></div><div>Deb Cooley<br></div><div><br></div></div><div=
 class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Thu, Feb 16, 2017 =
at 3:42 PM, Eran Messeri <span dir=3D"ltr">&lt;<a href=3D"mailto:eranm@goog=
le.com" target=3D"_blank">eranm@google.com</a>&gt;</span> wrote:<br><blockq=
uote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr"><div>Cross-post from the Chromium =
ct-policy list.</div><div>tl;dr:</div><div>- There are free spaces if any o=
f you would like to attend in-person.</div><div>- You can attend remotely v=
ia=C2=A0<a href=3D"https://hangouts.google.com/hangouts/_/google.com/ctpoli=
cydays" style=3D"font-size:12.8px" target=3D"_blank">https://hangouts.googl=
e.co<wbr>m/hangouts/_/google.com/ctpoli<wbr>cydays=C2=A0</a>=C2=A0(if you c=
an only use PSTN and would like to dial in, let me know).</div><br><div cla=
ss=3D"gmail_quote">---------- Forwarded message ----------<br>From: <b clas=
s=3D"gmail_sendername">&#39;Ryan Hurst&#39; via Certificate Transparency Po=
licy</b> <span dir=3D"ltr">&lt;<a href=3D"mailto:ct-policy@chromium.org" ta=
rget=3D"_blank">ct-policy@chromium.org</a>&gt;</span><br>Date: Thu, Feb 16,=
 2017 at 2:56 AM<br>Subject: [ct-policy] CT Policy Days Location<br><br><di=
v dir=3D"ltr">All,<div><br></div><div>I am looking forward to seeing you al=
l next week at Google, we will be located in Google Tech Corners II on the =
Third Floor in <span style=3D"color:rgb(68,68,68)">Quinn Mallory. =C2=A0</s=
pan></div><div><p>I will have people in the lobby to help get you to the ri=
ght location.</p><p><span style=3D"color:rgb(68,68,68)">The address is: =C2=
=A0</span></p></div><blockquote style=3D"margin:0px 0px 0px 40px;border:non=
e;padding:0px"><div><p>Google, Inc.</p></div><div><p>Tech Corners 2</p></di=
v><div><p>807 11th Ave</p></div><div><p>Sunnyvale, CA 94089</p></div></bloc=
kquote><div><p>We have the room from <span style=3D"color:rgb(51,51,51)">8a=
m - 5pm (PST) but the event will not start until 9am.</span></p><p><font co=
lor=3D"#333333">Agenda wise, I received=C2=A0some feedback for ideas on wor=
king group sessions from others but otherwise it seems the agenda has the r=
ight structure.</font></p><p dir=3D"ltr" style=3D"font-size:12.8px;line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:11pt;fo=
nt-family:arial;color:rgb(0,0,0);background-color:transparent;font-weight:7=
00;vertical-align:baseline;white-space:pre-wrap">State of the Union and War=
ming Up</span></p><div dir=3D"ltr" style=3D"font-size:12.8px;margin-left:0p=
t"><table style=3D"border:none;border-collapse:collapse"><colgroup><col wid=
th=3D"55"><col width=3D"58"><col width=3D"58"><col width=3D"51"><col width=
=3D"230"><col width=3D"156"></colgroup><tbody><tr style=3D"height:0pt"><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;ma=
rgin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:a=
rial;color:rgb(0,0,0);font-weight:700;vertical-align:baseline;white-space:p=
re-wrap">Time</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vert=
ical-align:baseline;white-space:pre-wrap">Start</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap"=
>Stop</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-ali=
gn:baseline;white-space:pre-wrap">Slot</span></p></td><td style=3D"border-w=
idth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:botto=
m;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;marg=
in-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">Descript=
ion</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-align=
:baseline;white-space:pre-wrap">Discussion Leader / Notes</span></p></td></=
tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"l=
tr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:r=
ight"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vert=
ical-align:baseline;white-space:pre-wrap">0:15</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap"=
>9:00</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><=
span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-al=
ign:baseline;white-space:pre-wrap">9:15</span></p></td><td style=3D"border-=
width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bott=
om;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;=
white-space:pre-wrap">Check-in, badging, get situated in room</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fa=
mily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">A=
ll</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0=
.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padd=
ing:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bot=
tom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;c=
olor:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:30</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"=
font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;w=
hite-space:pre-wrap">9:00</span></p></td><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:30</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vert=
ical-align:baseline;white-space:pre-wrap">Breakfast - Continental</span></p=
></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(=
0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heig=
ht:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;fon=
t-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wra=
p">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wid=
th:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;=
padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin=
-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:05</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">9:30</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:35</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);=
vertical-align:baseline;white-space:pre-wrap">Welcome and Logistics</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"b=
order-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-alig=
n:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0=
pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-f=
amily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">=
0:45</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-c=
olor:transparent;vertical-align:baseline;white-space:pre-wrap">9:35</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transpa=
rent;vertical-align:baseline;white-space:pre-wrap">10:20</span></p></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;m=
argin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:=
12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertic=
al-align:baseline;white-space:pre-wrap">1</span></p></td><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;m=
argin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);background-color:transparent;vertical-align:baseline;white-space:pr=
e-wrap">Presentation: Operating CT Logs at Scale</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">CT Team</spa=
n></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;ver=
tical-align:baseline;white-space:pre-wrap">10:20</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-ali=
gn:baseline;white-space:pre-wrap">11:05</span></p></td><td style=3D"border-=
width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bott=
om;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;mar=
gin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:=
arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline=
;white-space:pre-wrap">2</span></p></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgroun=
d-color:transparent;vertical-align:baseline;white-space:pre-wrap">Presentat=
ion: CT Standardization Roadmap</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ve=
rtical-align:baseline;white-space:pre-wrap">CT Team</span></p></td></tr><tr=
 style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap">0:15</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baselin=
e;white-space:pre-wrap">11:05</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spa=
ce:pre-wrap">11:20</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:b=
aseline;white-space:pre-wrap">Break</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr=
 style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap">0:45</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baselin=
e;white-space:pre-wrap">11:20</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spa=
ce:pre-wrap">12:05</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);background-color:transparent;vertical-align:baseline;white-space:pre-wrap=
">3</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;v=
ertical-align:baseline;white-space:pre-wrap">Presentation: Current Chrome P=
olicy</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">Chrome Team</span></p></td></tr><tr style=3D"height:0pt">=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-sp=
ace:pre-wrap">1:00</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);background-color:transparent;vertical-align:baseline;white-space:pre-wrap=
">12:05</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgroun=
d-color:transparent;vertical-align:baseline;white-space:pre-wrap">13:05</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;m=
argin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);background-color:transparent;vertical-align:baseline;white-space:pr=
e-wrap">Lunch</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt">=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-sp=
ace:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);background-color:transparent;vertical-align:baseline;white-space:pre-wrap=
">13:05</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgroun=
d-color:transparent;vertical-align:baseline;white-space:pre-wrap">13:50</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">4</span></p></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;m=
argin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:=
arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline=
;white-space:pre-wrap">Discussion: Concerns with Current Policy</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap"=
>Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;m=
argin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-famil=
y:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:30=
</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color=
:transparent;vertical-align:baseline;white-space:pre-wrap">13:50</span></p>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparen=
t;vertical-align:baseline;white-space:pre-wrap">14:20</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background=
-color:transparent;vertical-align:baseline;white-space:pre-wrap">Pick Break=
-Out Sessions</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">Ryan Hurst</span></p></td></tr><tr style=3D"heigh=
t:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"=
font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;w=
hite-space:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);background-color:transparent;vertical-align:baseline;white-space:p=
re-wrap">14:20</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align=
:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ba=
ckground-color:transparent;vertical-align:baseline;white-space:pre-wrap">15=
:05</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">5.1</span></p=
></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(=
0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heig=
ht:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;fon=
t-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align=
:baseline;white-space:pre-wrap">Break-Out Sessions - 1</span></p></td><td s=
tyle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vert=
ical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;mar=
gin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD*</sp=
an></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:r=
gb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:30</span></p></td=
><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0=
);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.=
38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-s=
ize:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;ve=
rtical-align:baseline;white-space:pre-wrap">15:05</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-ali=
gn:baseline;white-space:pre-wrap">15:35</span></p></td><td style=3D"border-=
width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bott=
om;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transpa=
rent;vertical-align:baseline;white-space:pre-wrap">Coffee/Beverage Service =
Break</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-=
wrap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">15:35<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"=
line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span s=
tyle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:=
transparent;vertical-align:baseline;white-space:pre-wrap">16:20</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent=
;vertical-align:baseline;white-space:pre-wrap">5.2</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white=
-space:pre-wrap">Break-Out Sessions - 1 Presentations</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD</span=
></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;=
text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</span></p></td><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vert=
ical-align:baseline;white-space:pre-wrap">16:20</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font=
-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap=
">17:05</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">6.1</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre=
-wrap">Break-Out Sessions - 2</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vert=
ical-align:baseline;white-space:pre-wrap">TBD*</span></p></td></tr><tr styl=
e=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-alig=
n:baseline;white-space:pre-wrap">0:45</span></p></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;w=
hite-space:pre-wrap">17:05</span></p></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:r=
gb(0,0,0);vertical-align:baseline;white-space:pre-wrap">17:50</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">6.2</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><spa=
n style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-col=
or:transparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sess=
ions - 2 Presentations</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><=
span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-al=
ign:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"hei=
ght:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">15</span></p></td><td style=3D"border-width:0.75pt=
;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2=
pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0=
pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space=
:pre-wrap">17:50</span></p></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ve=
rtical-align:baseline;white-space:pre-wrap">Adjourn for the Day</span></p><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap"=
>All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width=
:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pa=
dding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-b=
ottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial=
;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">2:40</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">17:50</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">20:30</span></p=
></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(=
0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">Casual Dinner - @ - On your=
 own or informal group</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><=
span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-al=
ign:baseline;white-space:pre-wrap">All</span></p></td></tr></tbody></table>=
</div><p><br style=3D"font-size:12.8px"><br style=3D"font-size:12.8px"></p>=
<p dir=3D"ltr" style=3D"font-size:12.8px;line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt"><span style=3D"font-size:11pt;font-family:arial;color:rgb(=
0,0,0);background-color:transparent;font-weight:700;vertical-align:baseline=
;white-space:pre-wrap">Break Out Sessions and Next Steps</span></p><div dir=
=3D"ltr" style=3D"font-size:12.8px;margin-left:0pt"><table style=3D"border:=
none;border-collapse:collapse"><colgroup><col width=3D"61"><col width=3D"61=
"><col width=3D"54"><col width=3D"259"><col width=3D"173"></colgroup><tbody=
><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">Start</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ver=
tical-align:baseline;white-space:pre-wrap">Stop</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Slot</span></p>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font=
-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap=
">Description</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">Discussion Leader / Notes</span></p></td></tr><tr=
 style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap">9:00</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:15<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"bo=
rder-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align=
:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0p=
t;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Check-in, badging,=
 get situated in room</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"heig=
ht:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;=
white-space:pre-wrap">9:00</span></p></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:r=
gb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:45</span></p></td=
><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0=
);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ver=
tical-align:baseline;white-space:pre-wrap">Breakfast - Continental</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;fo=
nt-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wr=
ap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:45</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">10:15</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">Kick-Off and Check-point</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);vertical-align:baseline;white-space:pre-wrap">Ryan Hurst</span></p><=
/td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">10:15</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-=
align:baseline;white-space:pre-wrap">10:45</span></p></td><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:basel=
ine;white-space:pre-wrap">7.1</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);back=
ground-color:transparent;vertical-align:baseline;white-space:pre-wrap">Brea=
k-Out Sessions - 3</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span=
 style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:=
baseline;white-space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height=
:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(=
0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heig=
ht:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"f=
ont-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;wh=
ite-space:pre-wrap">10:45</span></p></td><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);background-color:transparent;vertical-align:baseline;white-space:p=
re-wrap">11:30</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:basel=
ine;white-space:pre-wrap">Break</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ve=
rtical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr sty=
le=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-alig=
n:baseline;white-space:pre-wrap">11:30</span></p></td><td style=3D"border-w=
idth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:botto=
m;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;marg=
in-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:a=
rial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;=
white-space:pre-wrap">12:30</span></p></td><td style=3D"border-width:0.75pt=
;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2=
pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0=
pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space=
:pre-wrap">7.2</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tr=
ansparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions =
- 3 Presentations</span></p></td><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:=
0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whi=
te-space:pre-wrap">12:30</span></p></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;=
text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);background-color:transparent;vertical-align:baseline;white-space:pr=
e-wrap">13:30</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-famil=
y:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseli=
ne;white-space:pre-wrap">Lunch</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ver=
tical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr styl=
e=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-alig=
n:baseline;white-space:pre-wrap">13:30</span></p></td><td style=3D"border-w=
idth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:botto=
m;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;marg=
in-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:a=
rial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;=
white-space:pre-wrap">14:15</span></p></td><td style=3D"border-width:0.75pt=
;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2=
pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0=
pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space=
:pre-wrap">8.1</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tr=
ansparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions =
- 4</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">14:15</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">15:15<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"bo=
rder-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align=
:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0p=
t;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space=
:pre-wrap">Break</span></p></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0=
pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">15:15</span></p></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;t=
ext-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre=
-wrap">16:00</span></p></td><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"l=
tr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:r=
ight"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);back=
ground-color:transparent;vertical-align:baseline;white-space:pre-wrap">8.2<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"=
line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;verti=
cal-align:baseline;white-space:pre-wrap">Break-Out Sessions - 4 Presentatio=
ns</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">16:00</span></p></td><td style=3D"border-width:0.75pt;border-style:sol=
id;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr=
" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:rig=
ht"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgr=
ound-color:transparent;vertical-align:baseline;white-space:pre-wrap">16:30<=
/span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-c=
olor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"bo=
rder-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align=
:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0p=
t;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space=
:pre-wrap">Coffee/Beverage Service Break</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);vertical-align:baseline;white-space:pre-wrap">All</span></p></td></t=
r><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:so=
lid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"lt=
r" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:ri=
ght"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);verti=
cal-align:baseline;white-space:pre-wrap">16:30</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-=
family:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:b=
aseline;white-space:pre-wrap">17:30</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:aria=
l;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;whi=
te-space:pre-wrap">9</span></p></td><td style=3D"border-width:0.75pt;border=
-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p =
dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">Next Steps Su=
mmary</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bo=
rder-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" sty=
le=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt"><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spa=
ce:pre-wrap">17:30</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br><=
/td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);=
vertical-align:baseline;white-space:pre-wrap">Adjourn</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</span=
></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;=
text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb=
(0,0,0);vertical-align:baseline;white-space:pre-wrap">17:30</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-sp=
ace:pre-wrap">20:00</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br>=
</td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0=
,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-heigh=
t:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"color:rgb(0,0,0);fo=
nt-family:arial;font-size:16px;white-space:pre-wrap">Casual Dinner - @ - On=
 your own or informal group</span><br></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ve=
rtical-align:baseline;white-space:pre-wrap">All</span></p></td></tr></tbody=
></table></div><p><br style=3D"font-size:12.8px"></p><p>For the remote atte=
ndees we will have a Google Video Chat here:=C2=A0<a href=3D"https://hangou=
ts.google.com/hangouts/_/google.com/ctpolicydays" target=3D"_blank">https:/=
/hangouts.google.<wbr>com/hangouts/_/google.com/ctpo<wbr>licydays=C2=A0</a>=
</p><p>There is still more room so don&#39;t be shy if you want to attend, =
just let me know.</p><span class=3D"m_-8939327824327879671gmail-HOEnZb"><fo=
nt color=3D"#888888"><p>Ryan</p><span class=3D"HOEnZb"><font color=3D"#8888=
88"><p><font color=3D"#333333"><br></font></p><p><font color=3D"#333333"><b=
r></font></p></font></span></font></span></div></div><span class=3D"HOEnZb"=
><font color=3D"#888888"><span class=3D"m_-8939327824327879671gmail-HOEnZb"=
><font color=3D"#888888">

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;Certificate Transparency Policy&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:ct-policy+unsubscribe@chromium.org" target=3D"_bl=
ank">ct-policy+unsubscribe@chromium<wbr>.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:ct-policy@chromium.o=
rg" target=3D"_blank">ct-policy@chromium.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZ=
KnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=3Demail&amp;utm_source=3Dfooter"=
 target=3D"_blank">https://groups.google.com/a/ch<wbr>romium.org/d/msgid/ct=
-policy/<wbr>CAKexNNMGtROWamVuM%3DWtvz8HACc<wbr>SOTNLuXiZKnQZD_LNSqWwyQ%<wb=
r>40mail.gmail.com</a>.<br>
</font></span></font></span></div><br></div>
<br>______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/trans</a><br>
<br></blockquote></div><br></div>

--f403045e447cf8a43305490a6b8c--


From nobody Tue Feb 21 06:06:42 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B244E129BA3 for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 06:06:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.69
X-Spam-Level: 
X-Spam-Status: No, score=-2.69 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cMjVKX9mVAkK for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 06:06:39 -0800 (PST)
Received: from mail-it0-x22c.google.com (mail-it0-x22c.google.com [IPv6:2607:f8b0:4001:c0b::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CEFF8129BC9 for <trans@ietf.org>; Tue, 21 Feb 2017 06:06:38 -0800 (PST)
Received: by mail-it0-x22c.google.com with SMTP id y135so50973310itc.1 for <trans@ietf.org>; Tue, 21 Feb 2017 06:06:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=ZGFget3TnJJq3QPhkdVyC+jl5lYn8I3MantAyEk88Yo=; b=fTIqrJ9bZ3bCqALbwoTKIRFqtlReuoxT8UnkDf1poCotK2nvsJcUE6t7mumk7lb1jn YVEdChpmggf96N0umj7gAnUQ1IvsUiAVoGDRi5zbdow4DoyxtlU7Jay6/RhPN3kBmy/1 Be96vZ+L708gUzKWoxKvjzMFJOUMCKMJsCChsduOP2VSSuTlLY7THzzPA3nk4KMwKGma zNAMSn/g+jHDdbnQn9Nn/m36MZNGG9DoYL56++q5utcT4Mu1fqUVdPfzOBKya05BQSsX gC3hs0kxxEzOnGNrRYEQoGbqoMbxq99xDrXve8ZEtIT0R29d09kL9t+tBMNlbHJnndma 2Vig==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=ZGFget3TnJJq3QPhkdVyC+jl5lYn8I3MantAyEk88Yo=; b=e4OGzwz3sMlMwncH4563DTTFLksCc88fCBbO807SPra1R2iqKPaS4HmQppU4r8rjLK Bit0+9mddqM7qcySDWxzGH+7LLHqTpSGrq8JChoW7R6iePYk1eA35Am2TQL4YDkVnsXu rlIyp9jfgtyW9EmQgvcbYiNFmHzxXeoLbTyc+akY4HhzStUvAXyMtz0z2ZUzorFrIMF2 Q6mmOE5uI+/4S9kkEmQM6NwTWPu1HR3PDsqkcdXQCLCotL1A+aT5T87fLPgBjoq0w7Cl 3ecTqDaYq4hnIIVvD6HfRuX5vFVVKOkKn7Y6Iz+xF165kDMZFSKqQ+mHX4yAewfeFYcb u/bA==
X-Gm-Message-State: AMke39nDguuNSuMG5Ijef9W14K464sI2zOM3dd68l/1C7XF0ZjZE1lZjMt8A5HMPtQv+STnO9QMKCfcU842ohb4c
X-Received: by 10.107.7.78 with SMTP id 75mr24047959ioh.165.1487685997795; Tue, 21 Feb 2017 06:06:37 -0800 (PST)
MIME-Version: 1.0
Received: by 10.107.178.23 with HTTP; Tue, 21 Feb 2017 06:06:07 -0800 (PST)
In-Reply-To: <CAGgd1Od-gHccYuGKRnQf+mb27rrQ+jtCvUEAOf5SqQG+Kr=BFg@mail.gmail.com>
References: <CAKexNNMGtROWamVuM=Wtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ@mail.gmail.com> <CALzYgEfcFo=hi2tEP1de-XN4XFGfdXLWjJWgJtC+wKHJfTCQ+g@mail.gmail.com> <CAGgd1Od-gHccYuGKRnQf+mb27rrQ+jtCvUEAOf5SqQG+Kr=BFg@mail.gmail.com>
From: Eran Messeri <eranm@google.com>
Date: Tue, 21 Feb 2017 06:06:07 -0800
Message-ID: <CALzYgEdB0r68O=oYSebNyMQk2eK7Di=GkPUVURnOaG=wSzfhBg@mail.gmail.com>
To: Deb Cooley <debcooley1@gmail.com>
Content-Type: multipart/alternative; boundary=001a113f98d26fe38605490ae3a5
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/YhSPWBdNgGd5EK-D5fBdALts3Nw>
Cc: "trans@ietf.org" <trans@ietf.org>, "certificate-transparency@googlegroups.com" <certificate-transparency@googlegroups.com>
Subject: Re: [Trans] Fwd: [ct-policy] CT Policy Days Location
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Feb 2017 14:06:40 -0000

--001a113f98d26fe38605490ae3a5
Content-Type: text/plain; charset=UTF-8

Hi,

I'll have to dial individual participants up.
If you'd like to participate via PSTN, please reply privately with your
phone number and I'll connect you around 9:30 AM PST.

Eran

On Tue, Feb 21, 2017 at 5:33 AM, Deb Cooley <debcooley1@gmail.com> wrote:

> Can you post the PSTN information?
>
>
> TY,
> Deb Cooley
>
>
> On Thu, Feb 16, 2017 at 3:42 PM, Eran Messeri <eranm@google.com> wrote:
>
>> Cross-post from the Chromium ct-policy list.
>> tl;dr:
>> - There are free spaces if any of you would like to attend in-person.
>> - You can attend remotely via https://hangouts.google.co
>> m/hangouts/_/google.com/ctpolicydays
>> <https://hangouts.google.com/hangouts/_/google.com/ctpolicydays> (if you
>> can only use PSTN and would like to dial in, let me know).
>>
>> ---------- Forwarded message ----------
>> From: 'Ryan Hurst' via Certificate Transparency Policy <
>> ct-policy@chromium.org>
>> Date: Thu, Feb 16, 2017 at 2:56 AM
>> Subject: [ct-policy] CT Policy Days Location
>>
>> All,
>>
>> I am looking forward to seeing you all next week at Google, we will be
>> located in Google Tech Corners II on the Third Floor in Quinn Mallory.
>>
>> I will have people in the lobby to help get you to the right location.
>>
>> The address is:
>>
>> Google, Inc.
>>
>> Tech Corners 2
>>
>> 807 11th Ave
>>
>> Sunnyvale, CA 94089
>>
>> We have the room from 8am - 5pm (PST) but the event will not start until
>> 9am.
>>
>> Agenda wise, I received some feedback for ideas on working group sessions
>> from others but otherwise it seems the agenda has the right structure.
>>
>> State of the Union and Warming Up
>>
>> Time
>>
>> Start
>>
>> Stop
>>
>> Slot
>>
>> Description
>>
>> Discussion Leader / Notes
>>
>> 0:15
>>
>> 9:00
>>
>> 9:15
>>
>> Check-in, badging, get situated in room
>>
>> All
>>
>> 0:30
>>
>> 9:00
>>
>> 9:30
>>
>> Breakfast - Continental
>>
>> All
>>
>> 0:05
>>
>> 9:30
>>
>> 9:35
>>
>> Welcome and Logistics
>>
>> Ryan Hurst
>>
>> 0:45
>>
>> 9:35
>>
>> 10:20
>>
>> 1
>>
>> Presentation: Operating CT Logs at Scale
>>
>> CT Team
>>
>> 0:45
>>
>> 10:20
>>
>> 11:05
>>
>> 2
>>
>> Presentation: CT Standardization Roadmap
>>
>> CT Team
>>
>> 0:15
>>
>> 11:05
>>
>> 11:20
>>
>> Break
>>
>> All
>>
>> 0:45
>>
>> 11:20
>>
>> 12:05
>>
>> 3
>>
>> Presentation: Current Chrome Policy
>>
>> Chrome Team
>>
>> 1:00
>>
>> 12:05
>>
>> 13:05
>>
>> Lunch
>>
>> All
>>
>> 0:45
>>
>> 13:05
>>
>> 13:50
>>
>> 4
>>
>> Discussion: Concerns with Current Policy
>>
>> Ryan Hurst
>>
>> 0:30
>>
>> 13:50
>>
>> 14:20
>>
>> Pick Break-Out Sessions
>>
>> Ryan Hurst
>>
>> 0:45
>>
>> 14:20
>>
>> 15:05
>>
>> 5.1
>>
>> Break-Out Sessions - 1
>>
>> TBD*
>>
>> 0:30
>>
>> 15:05
>>
>> 15:35
>>
>> Coffee/Beverage Service Break
>>
>> All
>>
>> 0:45
>>
>> 15:35
>>
>> 16:20
>>
>> 5.2
>>
>> Break-Out Sessions - 1 Presentations
>>
>> TBD
>>
>> 0:45
>>
>> 16:20
>>
>> 17:05
>>
>> 6.1
>>
>> Break-Out Sessions - 2
>>
>> TBD*
>>
>> 0:45
>>
>> 17:05
>>
>> 17:50
>>
>> 6.2
>>
>> Break-Out Sessions - 2 Presentations
>>
>> All
>>
>> 15
>>
>> 17:50
>>
>>
>> Adjourn for the Day
>>
>> All
>>
>> 2:40
>>
>> 17:50
>>
>> 20:30
>>
>> Casual Dinner - @ - On your own or informal group
>>
>> All
>>
>>
>>
>> Break Out Sessions and Next Steps
>>
>> Start
>>
>> Stop
>>
>> Slot
>>
>> Description
>>
>> Discussion Leader / Notes
>>
>> 9:00
>>
>> 9:15
>>
>> Check-in, badging, get situated in room
>>
>> All
>>
>> 9:00
>>
>> 9:45
>>
>> Breakfast - Continental
>>
>> All
>>
>> 9:45
>>
>> 10:15
>>
>> Kick-Off and Check-point
>>
>> Ryan Hurst
>>
>> 10:15
>>
>> 10:45
>>
>> 7.1
>>
>> Break-Out Sessions - 3
>>
>> TBD*
>>
>> 10:45
>>
>> 11:30
>>
>> Break
>>
>> All
>>
>> 11:30
>>
>> 12:30
>>
>> 7.2
>>
>> Break-Out Sessions - 3 Presentations
>>
>> TBD*
>>
>> 12:30
>>
>> 13:30
>>
>> Lunch
>>
>> All
>>
>> 13:30
>>
>> 14:15
>>
>> 8.1
>>
>> Break-Out Sessions - 4
>>
>> TBD*
>>
>> 14:15
>>
>> 15:15
>>
>> Break
>>
>> All
>>
>> 15:15
>>
>> 16:00
>>
>> 8.2
>>
>> Break-Out Sessions - 4 Presentations
>>
>> TBD*
>>
>> 16:00
>>
>> 16:30
>>
>> Coffee/Beverage Service Break
>>
>> All
>>
>> 16:30
>>
>> 17:30
>>
>> 9
>>
>> Next Steps Summary
>>
>> Ryan Hurst
>>
>> 17:30
>>
>>
>> Adjourn
>>
>> All
>>
>> 17:30
>>
>> 20:00
>>
>> Casual Dinner - @ - On your own or informal group
>>
>> All
>>
>>
>> For the remote attendees we will have a Google Video Chat here:
>> https://hangouts.google.com/hangouts/_/google.com/ctpolicydays
>> <https://hangouts.google.com/hangouts/_/google.com/ctpolicydays>
>>
>> There is still more room so don't be shy if you want to attend, just let
>> me know.
>>
>> Ryan
>>
>>
>>
>> --
>> You received this message because you are subscribed to the Google Groups
>> "Certificate Transparency Policy" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to ct-policy+unsubscribe@chromium.org.
>> To post to this group, send email to ct-policy@chromium.org.
>> To view this discussion on the web visit https://groups.google.com/a/ch
>> romium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcS
>> OTNLuXiZKnQZD_LNSqWwyQ%40mail.gmail.com
>> <https://groups.google.com/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZKnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>>
>> _______________________________________________
>> Trans mailing list
>> Trans@ietf.org
>> https://www.ietf.org/mailman/listinfo/trans
>>
>>
>

--001a113f98d26fe38605490ae3a5
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>I&#39;ll have to dial individual pa=
rticipants up.</div><div>If you&#39;d like to participate via PSTN, please =
reply privately with your phone number and I&#39;ll connect you around 9:30=
 AM PST.</div><div><br></div><div>Eran</div></div><div class=3D"gmail_extra=
"><br><div class=3D"gmail_quote">On Tue, Feb 21, 2017 at 5:33 AM, Deb Coole=
y <span dir=3D"ltr">&lt;<a href=3D"mailto:debcooley1@gmail.com" target=3D"_=
blank">debcooley1@gmail.com</a>&gt;</span> wrote:<br><blockquote class=3D"g=
mail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-l=
eft:1ex"><div dir=3D"ltr"><div>Can you post the PSTN information?=C2=A0 <br=
><br><br></div><div>TY, <br></div><div>Deb Cooley<br></div><div><br></div><=
/div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote"><div><div cl=
ass=3D"h5">On Thu, Feb 16, 2017 at 3:42 PM, Eran Messeri <span dir=3D"ltr">=
&lt;<a href=3D"mailto:eranm@google.com" target=3D"_blank">eranm@google.com<=
/a>&gt;</span> wrote:<br></div></div><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><d=
iv class=3D"h5"><div dir=3D"ltr"><div>Cross-post from the Chromium ct-polic=
y list.</div><div>tl;dr:</div><div>- There are free spaces if any of you wo=
uld like to attend in-person.</div><div>- You can attend remotely via=C2=A0=
<a href=3D"https://hangouts.google.com/hangouts/_/google.com/ctpolicydays" =
style=3D"font-size:12.8px" target=3D"_blank">https://hangouts.google.co<wbr=
>m/hangouts/_/google.com/ctpoli<wbr>cydays=C2=A0</a>=C2=A0(if you can only =
use PSTN and would like to dial in, let me know).</div><br><div class=3D"gm=
ail_quote">---------- Forwarded message ----------<br>From: <b class=3D"gma=
il_sendername">&#39;Ryan Hurst&#39; via Certificate Transparency Policy</b>=
 <span dir=3D"ltr">&lt;<a href=3D"mailto:ct-policy@chromium.org" target=3D"=
_blank">ct-policy@chromium.org</a>&gt;</span><br>Date: Thu, Feb 16, 2017 at=
 2:56 AM<br>Subject: [ct-policy] CT Policy Days Location<br><br><div dir=3D=
"ltr">All,<div><br></div><div>I am looking forward to seeing you all next w=
eek at Google, we will be located in Google Tech Corners II on the Third Fl=
oor in <span style=3D"color:rgb(68,68,68)">Quinn Mallory. =C2=A0</span></di=
v><div><p>I will have people in the lobby to help get you to the right loca=
tion.</p><p><span style=3D"color:rgb(68,68,68)">The address is: =C2=A0</spa=
n></p></div><blockquote style=3D"margin:0px 0px 0px 40px;border:none;paddin=
g:0px"><div><p>Google, Inc.</p></div><div><p>Tech Corners 2</p></div><div><=
p>807 11th Ave</p></div><div><p>Sunnyvale, CA 94089</p></div></blockquote><=
div><p>We have the room from <span style=3D"color:rgb(51,51,51)">8am - 5pm =
(PST) but the event will not start until 9am.</span></p><p><font color=3D"#=
333333">Agenda wise, I received=C2=A0some feedback for ideas on working gro=
up sessions from others but otherwise it seems the agenda has the right str=
ucture.</font></p><p dir=3D"ltr" style=3D"font-size:12.8px;line-height:1.38=
;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:11pt;font-famil=
y:arial;color:rgb(0,0,0);background-color:transparent;font-weight:700;verti=
cal-align:baseline;white-space:pre-wrap">State of the Union and Warming Up<=
/span></p><div dir=3D"ltr" style=3D"font-size:12.8px;margin-left:0pt"><tabl=
e style=3D"border:none;border-collapse:collapse"><colgroup><col width=3D"55=
"><col width=3D"58"><col width=3D"58"><col width=3D"51"><col width=3D"230">=
<col width=3D"156"></colgroup><tbody><tr style=3D"height:0pt"><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">=
Time</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-alig=
n:baseline;white-space:pre-wrap">Start</span></p></td><td style=3D"border-w=
idth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:botto=
m;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;marg=
in-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);font-weight:700;vertical-align:baseline;white-space:pre-wrap">Stop</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12=
pt;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-align:baseli=
ne;white-space:pre-wrap">Slot</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);font=
-weight:700;vertical-align:baseline;white-space:pre-wrap">Description</span=
></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:=
rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-=
height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);font-weight:700;vertical-align:baseline=
;white-space:pre-wrap">Discussion Leader / Notes</span></p></td></tr><tr st=
yle=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-alig=
n:baseline;white-space:pre-wrap">0:15</span></p></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:00</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">9:15</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spa=
ce:pre-wrap">Check-in, badging, get situated in room</span></p></td><td sty=
le=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertic=
al-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margi=
n-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:aria=
l;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</span>=
</p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;t=
ext-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(=
0,0,0);vertical-align:baseline;white-space:pre-wrap">0:30</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spac=
e:pre-wrap">9:00</span></p></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">9:30</span></p></td><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">Breakfast - Continental</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</=
span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75p=
t;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:=
2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:=
0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color=
:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:05</span></p></=
td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0=
,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:=
1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">9:30</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;tex=
t-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);vertical-align:baseline;white-space:pre-wrap">9:35</span></p></td><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical=
-align:baseline;white-space:pre-wrap">Welcome and Logistics</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Rya=
n Hurst</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:45</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">9:35</span></p></td>=
<td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0)=
;vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.3=
8;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-si=
ze:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;ver=
tical-align:baseline;white-space:pre-wrap">10:20</span></p></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-ali=
gn:baseline;white-space:pre-wrap">1</span></p></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);background-color:transparent;vertical-align:baseline;white-space:pre-wrap=
">Presentation: Operating CT Logs at Scale</span></p></td><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rg=
b(0,0,0);vertical-align:baseline;white-space:pre-wrap">CT Team</span></p></=
td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">0:45</span></p></td><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-al=
ign:baseline;white-space:pre-wrap">10:20</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baselin=
e;white-space:pre-wrap">11:05</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spa=
ce:pre-wrap">2</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tr=
ansparent;vertical-align:baseline;white-space:pre-wrap">Presentation: CT St=
andardization Roadmap</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">CT Team</span></p></td></tr><tr style=3D"=
height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">0:15</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">11:05</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-=
align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);background-color:transparent;vertical-align:baseline;white-space:pre-wra=
p">11:20</span></p></td><td style=3D"border-width:0.75pt;border-style:solid=
;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ari=
al;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;wh=
ite-space:pre-wrap">Break</span></p></td><td style=3D"border-width:0.75pt;b=
order-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt=
"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt=
"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical=
-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"=
height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">11:20</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-=
align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);background-color:transparent;vertical-align:baseline;white-space:pre-wra=
p">12:05</span></p></td><td style=3D"border-width:0.75pt;border-style:solid=
;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" =
style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right=
"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgrou=
nd-color:transparent;vertical-align:baseline;white-space:pre-wrap">3</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-al=
ign:baseline;white-space:pre-wrap">Presentation: Current Chrome Policy</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pr=
e-wrap">Chrome Team</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">1:00</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:righ=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgro=
und-color:transparent;vertical-align:baseline;white-space:pre-wrap">12:05</=
span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-co=
lor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"l=
ine-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span st=
yle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:t=
ransparent;vertical-align:baseline;white-space:pre-wrap">13:05</span></p></=
td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0=
,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0=
.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padd=
ing:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bot=
tom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);b=
ackground-color:transparent;vertical-align:baseline;white-space:pre-wrap">L=
unch</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:righ=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);backgro=
und-color:transparent;vertical-align:baseline;white-space:pre-wrap">13:05</=
span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-co=
lor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"l=
ine-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span st=
yle=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:t=
ransparent;vertical-align:baseline;white-space:pre-wrap">13:50</span></p></=
td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0=
,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:=
1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;=
vertical-align:baseline;white-space:pre-wrap">4</span></p></td><td style=3D=
"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-al=
ign:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top=
:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">Discussion: Concerns with Current Policy</span></p></td><td s=
tyle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vert=
ical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;mar=
gin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:ar=
ial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Ryan Hur=
st</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0=
.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padd=
ing:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bot=
tom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;c=
olor:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:30</span></=
p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb=
(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-hei=
ght:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"=
font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transpar=
ent;vertical-align:baseline;white-space:pre-wrap">13:50</span></p></td><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;ma=
rgin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:1=
2pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertica=
l-align:baseline;white-space:pre-wrap">14:20</span></p></td><td style=3D"bo=
rder-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align=
:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tr=
ansparent;vertical-align:baseline;white-space:pre-wrap">Pick Break-Out Sess=
ions</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt"><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size=
:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spac=
e:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;background-color:transparent;vertical-align:baseline;white-space:pre-wrap"=
>14:20</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background=
-color:transparent;vertical-align:baseline;white-space:pre-wrap">15:05</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">5.1</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baselin=
e;white-space:pre-wrap">Break-Out Sessions - 1</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD*</span></p><=
/td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">0:30</span></p></td><td sty=
le=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertic=
al-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margi=
n-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-a=
lign:baseline;white-space:pre-wrap">15:05</span></p></td><td style=3D"borde=
r-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bo=
ttom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;m=
argin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-famil=
y:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseli=
ne;white-space:pre-wrap">15:35</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><br></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vert=
ical-align:baseline;white-space:pre-wrap">Coffee/Beverage Service Break</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12=
pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:p=
re-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">0:4=
5</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">15:35</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transpa=
rent;vertical-align:baseline;white-space:pre-wrap">16:20</span></p></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;m=
argin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:=
12pt;font-family:arial;color:rgb(0,0,0);background-color:transparent;vertic=
al-align:baseline;white-space:pre-wrap">5.2</span></p></td><td style=3D"bor=
der-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:=
bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt=
;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:r=
gb(0,0,0);background-color:transparent;vertical-align:baseline;white-space:=
pre-wrap">Break-Out Sessions - 1 Presentations</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">TBD</span></p></=
td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">0:45</span></p></td><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-al=
ign:baseline;white-space:pre-wrap">16:20</span></p></td><td style=3D"border=
-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bot=
tom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;ma=
rgin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">17:05=
</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-=
color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D=
"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">6.1</span></p></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);=
background-color:transparent;vertical-align:baseline;white-space:pre-wrap">=
Break-Out Sessions - 2</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><=
span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-al=
ign:baseline;white-space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"he=
ight:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:=
rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-=
height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">0:45</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spa=
ce:pre-wrap">17:05</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-a=
lign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">17:50</span></p></td><td st=
yle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);verti=
cal-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;marg=
in-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pr=
e-wrap">6.2</span></p></td><td style=3D"border-width:0.75pt;border-style:so=
lid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"lt=
r" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tran=
sparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions - =
2 Presentations</span></p></td><td style=3D"border-width:0.75pt;border-styl=
e:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span =
style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:b=
aseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0=
pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,=
0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height=
:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"fon=
t-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;whit=
e-space:pre-wrap">15</span></p></td><td style=3D"border-width:0.75pt;border=
-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p =
dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text=
-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0=
,0);background-color:transparent;vertical-align:baseline;white-space:pre-wr=
ap">17:50</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td s=
tyle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vert=
ical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">Adjourn for the Day</span></p></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;m=
argin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:=
arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</s=
pan></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt=
;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2=
pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0=
pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color:=
rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">2:40</span></p></t=
d><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,=
0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1=
.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">17:50</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;tex=
t-align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);vertical-align:baseline;white-space:pre-wrap">20:30</span></p></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">Casual Dinner - @ - On your own or i=
nformal group</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:basel=
ine;white-space:pre-wrap">All</span></p></td></tr></tbody></table></div><p>=
<br style=3D"font-size:12.8px"><br style=3D"font-size:12.8px"></p><p dir=3D=
"ltr" style=3D"font-size:12.8px;line-height:1.38;margin-top:0pt;margin-bott=
om:0pt"><span style=3D"font-size:11pt;font-family:arial;color:rgb(0,0,0);ba=
ckground-color:transparent;font-weight:700;vertical-align:baseline;white-sp=
ace:pre-wrap">Break Out Sessions and Next Steps</span></p><div dir=3D"ltr" =
style=3D"font-size:12.8px;margin-left:0pt"><table style=3D"border:none;bord=
er-collapse:collapse"><colgroup><col width=3D"61"><col width=3D"61"><col wi=
dth=3D"54"><col width=3D"259"><col width=3D"173"></colgroup><tbody><tr styl=
e=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border=
-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-=
size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-=
space:pre-wrap">Start</span></p></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">Stop</span></p></td><td style=3D"border-w=
idth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:botto=
m;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;marg=
in-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,=
0,0);vertical-align:baseline;white-space:pre-wrap">Slot</span></p></td><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;ma=
rgin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:a=
rial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">Descrip=
tion</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">Discussion Leader / Notes</span></p></td></tr><tr style=3D=
"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-col=
or:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"li=
ne-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span sty=
le=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:base=
line;white-space:pre-wrap">9:00</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;co=
lor:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:15</span></p=
></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(=
0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-widt=
h:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;p=
adding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-=
bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0=
);vertical-align:baseline;white-space:pre-wrap">Check-in, badging, get situ=
ated in room</span></p></td><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"l=
tr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><=
td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);=
vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38=
;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-siz=
e:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-spa=
ce:pre-wrap">9:00</span></p></td><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">9:45</span></p></td><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;borde=
r-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p=
 dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">Breakfast - Continental</span></p></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family=
:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</=
span></p></td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75p=
t;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:=
2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:=
0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color=
:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">9:45</span></p></=
td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0=
,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:=
1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font=
-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white=
-space:pre-wrap">10:15</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
br></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-he=
ight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;f=
ont-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-w=
rap">Kick-Off and Check-point</span></p></td><td style=3D"border-width:0.75=
pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding=
:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom=
:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vert=
ical-align:baseline;white-space:pre-wrap">Ryan Hurst</span></p></td></tr><t=
r style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">10:15</span></p></td><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);background-color:transparent;vertical-align:basel=
ine;white-space:pre-wrap">10:45</span></p></td><td style=3D"border-width:0.=
75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddi=
ng:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bott=
om:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;co=
lor:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-s=
pace:pre-wrap">7.1</span></p></td><td style=3D"border-width:0.75pt;border-s=
tyle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p di=
r=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span=
 style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-colo=
r:transparent;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessi=
ons - 3</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;=
border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" s=
tyle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"f=
ont-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;wh=
ite-space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td s=
tyle=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vert=
ical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;mar=
gin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12=
pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:p=
re-wrap">10:45</span></p></td><td style=3D"border-width:0.75pt;border-style=
:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D=
"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align=
:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);ba=
ckground-color:transparent;vertical-align:baseline;white-space:pre-wrap">11=
:30</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=
=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical=
-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-=
top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;=
color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white=
-space:pre-wrap">Break</span></p></td><td style=3D"border-width:0.75pt;bord=
er-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><=
p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><=
span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-al=
ign:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"hei=
ght:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">11:30</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">12:30</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-=
align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);background-color:transparent;vertical-align:baseline;white-space:pre-wra=
p">7.2</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparen=
t;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions - 3 Pres=
entations</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;=
white-space:pre-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;m=
argin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:=
12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space=
:pre-wrap">12:30</span></p></td><td style=3D"border-width:0.75pt;border-sty=
le:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;background-color:transparent;vertical-align:baseline;white-space:pre-wrap"=
>13:30</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial=
;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;whit=
e-space:pre-wrap">Lunch</span></p></td><td style=3D"border-width:0.75pt;bor=
der-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt">=
<p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-a=
lign:baseline;white-space:pre-wrap">All</span></p></td></tr><tr style=3D"he=
ight:0pt"><td style=3D"border-width:0.75pt;border-style:solid;border-color:=
rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-=
height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><span style=
=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseli=
ne;white-space:pre-wrap">13:30</span></p></td><td style=3D"border-width:0.7=
5pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;paddin=
g:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-botto=
m:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;col=
or:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-sp=
ace:pre-wrap">14:15</span></p></td><td style=3D"border-width:0.75pt;border-=
style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p d=
ir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-=
align:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,=
0);background-color:transparent;vertical-align:baseline;white-space:pre-wra=
p">8.1</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"fo=
nt-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:transparen=
t;vertical-align:baseline;white-space:pre-wrap">Break-Out Sessions - 4</spa=
n></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color=
:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line=
-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12p=
t;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pr=
e-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"bord=
er-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:b=
ottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;=
margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fami=
ly:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">14:=
15</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;borde=
r-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">15:15</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0=
,0);background-color:transparent;vertical-align:baseline;white-space:pre-wr=
ap">Break</span></p></td><td style=3D"border-width:0.75pt;border-style:soli=
d;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr"=
 style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D=
"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;=
white-space:pre-wrap">All</span></p></td></tr><tr style=3D"height:0pt"><td =
style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ver=
tical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;ma=
rgin-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:1=
2pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:=
pre-wrap">15:15</span></p></td><td style=3D"border-width:0.75pt;border-styl=
e:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;background-color:transparent;vertical-align:baseline;white-space:pre-wrap"=
>16:00</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;b=
order-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" st=
yle=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right">=
<span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background=
-color:transparent;vertical-align:baseline;white-space:pre-wrap">8.2</span>=
</p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:r=
gb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-h=
eight:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);background-color:transparent;vertical-al=
ign:baseline;white-space:pre-wrap">Break-Out Sessions - 4 Presentations</sp=
an></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-colo=
r:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"lin=
e-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:12=
pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:p=
re-wrap">TBD*</span></p></td></tr><tr style=3D"height:0pt"><td style=3D"bor=
der-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:=
bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt=
;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-fam=
ily:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">16=
:00</span></p></td><td style=3D"border-width:0.75pt;border-style:solid;bord=
er-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=
=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><sp=
an style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-co=
lor:transparent;vertical-align:baseline;white-space:pre-wrap">16:30</span><=
/p></td><td style=3D"border-width:0.75pt;border-style:solid;border-color:rg=
b(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td style=3D"border-wi=
dth:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom=
;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margi=
n-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0=
,0);background-color:transparent;vertical-align:baseline;white-space:pre-wr=
ap">Coffee/Beverage Service Break</span></p></td><td style=3D"border-width:=
0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;pad=
ding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bo=
ttom:0pt"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);=
vertical-align:baseline;white-space:pre-wrap">All</span></p></td></tr><tr s=
tyle=3D"height:0pt"><td style=3D"border-width:0.75pt;border-style:solid;bor=
der-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" styl=
e=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-align:right"><s=
pan style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-ali=
gn:baseline;white-space:pre-wrap">16:30</span></p></td><td style=3D"border-=
width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-align:bott=
om;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;mar=
gin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;font-family:=
arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline=
;white-space:pre-wrap">17:30</span></p></td><td style=3D"border-width:0.75p=
t;border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:=
2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:=
0pt;text-align:right"><span style=3D"font-size:12pt;font-family:arial;color=
:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-spac=
e:pre-wrap">9</span></p></td><td style=3D"border-width:0.75pt;border-style:=
solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"=
ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span styl=
e=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);background-color:tra=
nsparent;vertical-align:baseline;white-space:pre-wrap">Next Steps Summary</=
span></p></td><td style=3D"border-width:0.75pt;border-style:solid;border-co=
lor:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"l=
ine-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style=3D"font-size:=
12pt;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space=
:pre-wrap">Ryan Hurst</span></p></td></tr><tr style=3D"height:0pt"><td styl=
e=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertica=
l-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin=
-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt;=
font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre-=
wrap">17:30</span></p></td><td style=3D"border-width:0.75pt;border-style:so=
lid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><td=
 style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);ve=
rtical-align:bottom;padding:2pt"><br></td><td style=3D"border-width:0.75pt;=
border-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2p=
t"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0p=
t"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertica=
l-align:baseline;white-space:pre-wrap">Adjourn</span></p></td><td style=3D"=
border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertical-ali=
gn:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:=
0pt;margin-bottom:0pt"><span style=3D"font-size:12pt;font-family:arial;colo=
r:rgb(0,0,0);vertical-align:baseline;white-space:pre-wrap">All</span></p></=
td></tr><tr style=3D"height:0pt"><td style=3D"border-width:0.75pt;border-st=
yle:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><p dir=
=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt;text-al=
ign:right"><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0)=
;vertical-align:baseline;white-space:pre-wrap">17:30</span></p></td><td sty=
le=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);vertic=
al-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;margi=
n-top:0pt;margin-bottom:0pt;text-align:right"><span style=3D"font-size:12pt=
;font-family:arial;color:rgb(0,0,0);vertical-align:baseline;white-space:pre=
-wrap">20:00</span></p></td><td style=3D"border-width:0.75pt;border-style:s=
olid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"><br></td><t=
d style=3D"border-width:0.75pt;border-style:solid;border-color:rgb(0,0,0);v=
ertical-align:bottom;padding:2pt"><p dir=3D"ltr" style=3D"line-height:1.38;=
margin-top:0pt;margin-bottom:0pt"><span style=3D"color:rgb(0,0,0);font-fami=
ly:arial;font-size:16px;white-space:pre-wrap">Casual Dinner - @ - On your o=
wn or informal group</span><br></p></td><td style=3D"border-width:0.75pt;bo=
rder-style:solid;border-color:rgb(0,0,0);vertical-align:bottom;padding:2pt"=
><p dir=3D"ltr" style=3D"line-height:1.38;margin-top:0pt;margin-bottom:0pt"=
><span style=3D"font-size:12pt;font-family:arial;color:rgb(0,0,0);vertical-=
align:baseline;white-space:pre-wrap">All</span></p></td></tr></tbody></tabl=
e></div><p><br style=3D"font-size:12.8px"></p><p>For the remote attendees w=
e will have a Google Video Chat here:=C2=A0<a href=3D"https://hangouts.goog=
le.com/hangouts/_/google.com/ctpolicydays" target=3D"_blank">https://hangou=
ts.google.<wbr>com/hangouts/_/google.com/ctpo<wbr>licydays=C2=A0</a></p><p>=
There is still more room so don&#39;t be shy if you want to attend, just le=
t me know.</p><span class=3D"m_670361230948755989m_-8939327824327879671gmai=
l-HOEnZb"><font color=3D"#888888"><p>Ryan</p><span class=3D"m_6703612309487=
55989HOEnZb"><font color=3D"#888888"><p><font color=3D"#333333"><br></font>=
</p><p><font color=3D"#333333"><br></font></p></font></span></font></span><=
/div></div><span class=3D"m_670361230948755989HOEnZb"><font color=3D"#88888=
8"><span class=3D"m_670361230948755989m_-8939327824327879671gmail-HOEnZb"><=
font color=3D"#888888">

<p></p>

-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;Certificate Transparency Policy&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:ct-policy+unsubscribe@chromium.org" target=3D"_bl=
ank">ct-policy+unsubscribe@chromium<wbr>.org</a>.<br>
To post to this group, send email to <a href=3D"mailto:ct-policy@chromium.o=
rg" target=3D"_blank">ct-policy@chromium.org</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/chromium.org/d/msgid/ct-policy/CAKexNNMGtROWamVuM%3DWtvz8HACcSOTNLuXiZ=
KnQZD_LNSqWwyQ%40mail.gmail.com?utm_medium=3Demail&amp;utm_source=3Dfooter"=
 target=3D"_blank">https://groups.google.com/a/ch<wbr>romium.org/d/msgid/ct=
-policy/C<wbr>AKexNNMGtROWamVuM%3DWtvz8HACcS<wbr>OTNLuXiZKnQZD_LNSqWwyQ%40m=
ail.<wbr>gmail.com</a>.<br>
</font></span></font></span></div><br></div>
<br></div></div>______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org" target=3D"_blank">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/l<wbr>istinfo/trans</a><br>
<br></blockquote></div><br></div>
</blockquote></div><br></div>

--001a113f98d26fe38605490ae3a5--


From nobody Tue Feb 21 09:42:51 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15587129485 for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 09:42:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3JKKspxoQytM for <trans@ietfa.amsl.com>; Tue, 21 Feb 2017 09:42:49 -0800 (PST)
Received: from mail-it0-x234.google.com (mail-it0-x234.google.com [IPv6:2607:f8b0:4001:c0b::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D757D12943D for <trans@ietf.org>; Tue, 21 Feb 2017 09:42:48 -0800 (PST)
Received: by mail-it0-x234.google.com with SMTP id h10so112673962ith.1 for <trans@ietf.org>; Tue, 21 Feb 2017 09:42:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=LjoFIXT/kIKLNGWRP7TCQT2qNoZGC31n/XEbVjkegYg=; b=JkFVHBxW6ES19lg0+QMFOd3Dej8M/mwE8KtqwiCQlmZOYZ+72oIUF3BpctLX9hZ+Zu vvH4laC2u/3kpx2ifrbvAvJlbwrz2RKzIMCc5OY6pKNCXLGjO4SX8mwPqjCIA/J8haAJ sKZzfRXHuVsV5CkKa9KfLa34lHLOU/0cKTObuBonSoHTSpzPj/31DmNxuOz319+UseeM Cxe8KdrdP312mydArZlomX73dj4ThkI06cADX3wBhV+/GFtiiSjVM5geaFWMJrIElwtq CbSNGWgJ2wSslxbprMVuwNTikuMJrUsfKE5FFvAWg2a1rK6MNdczbX909NvSdkzA81M6 wnTw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=LjoFIXT/kIKLNGWRP7TCQT2qNoZGC31n/XEbVjkegYg=; b=KHdn6676XGTpRfT2ksdl0F2QcGz1VTYVgace6rDEhl1EtVBRnGmUHBghP71VvthTcq JiX2OI6xiUfF+D0YE1c8gWxgIRYK0meOlWyqq8ZM9Mv6+o6knpWeFrmNiGd6uVj03HU4 9j94j2xYBf4R3M4EV4Q0D0DfSixtW+tjXGAaElNoMCvaMW+FqRiQ2Sb/2t6EGEZuU55s DnhvV48fQcq+Hf811FDg/FEJxYxA3bdOpRAWyOjllMohcttXeL5Up8ZzQ97xHtLm6jfq bCxwzNNixJj2trze44FoYe4xTbqmbZIEZ0ZIn/PmU8D/m8ynCcbONXgdmrR0/tskcQdE CN7g==
X-Gm-Message-State: AMke39khwcfdD7yWTg/JMxbgECMSifolsX7TL8Rr3Pl5EGetKE797xcn56tx4Zbb9zAShYuz0zIq/aFqRGL9DNfA
X-Received: by 10.36.93.213 with SMTP id w204mr31276518ita.60.1487698965660; Tue, 21 Feb 2017 09:42:45 -0800 (PST)
MIME-Version: 1.0
Received: by 10.107.178.23 with HTTP; Tue, 21 Feb 2017 09:42:15 -0800 (PST)
In-Reply-To: <CALzYgEeQYQ+CB2LOrPEFdqaZd7Z4O_jRfP-4duQdr4VkOiZzRw@mail.gmail.com>
References: <CALzYgEeQYQ+CB2LOrPEFdqaZd7Z4O_jRfP-4duQdr4VkOiZzRw@mail.gmail.com>
From: Eran Messeri <eranm@google.com>
Date: Tue, 21 Feb 2017 09:42:15 -0800
Message-ID: <CALzYgEfaCp+9J_SBM7ED5OUe9w9+B8nrrzEp_R0VH5O6+T2hYA@mail.gmail.com>
To: "trans@ietf.org" <trans@ietf.org>
Content-Type: multipart/alternative; boundary=001a113a629661fd8e05490de8fb
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/orxlPrhu-nJVSYJ0wE7appexPSc>
Subject: [Trans] Fwd: CT policy days remote participation link
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Feb 2017 17:42:50 -0000

--001a113a629661fd8e05490de8fb
Content-Type: text/plain; charset=UTF-8

FYI.

---------- Forwarded message ----------
From: Eran Messeri <eranm@chromium.org>
Date: Tue, Feb 21, 2017 at 9:39 AM
Subject: CT policy days remote participation link
To: "ct-policy@chromium.org" <ct-policy@chromium.org>


For those participating remotely, please join via:
https://hangouts.google.com/hangouts/_/google.com/ctpolicy-days

Regards,
Eran

--001a113a629661fd8e05490de8fb
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">FYI.<div><br><div class=3D"gmail_quote">---------- Forward=
ed message ----------<br>From: <b class=3D"gmail_sendername">Eran Messeri</=
b> <span dir=3D"ltr">&lt;<a href=3D"mailto:eranm@chromium.org">eranm@chromi=
um.org</a>&gt;</span><br>Date: Tue, Feb 21, 2017 at 9:39 AM<br>Subject: CT =
policy days remote participation link<br>To: &quot;<a href=3D"mailto:ct-pol=
icy@chromium.org">ct-policy@chromium.org</a>&quot; &lt;<a href=3D"mailto:ct=
-policy@chromium.org">ct-policy@chromium.org</a>&gt;<br><br><br><div dir=3D=
"ltr">For those participating remotely, please join via:<div><a href=3D"htt=
ps://hangouts.google.com/hangouts/_/google.com/ctpolicy-days" target=3D"_bl=
ank">https://hangouts.google.com/<wbr>hangouts/_/google.com/<wbr>ctpolicy-d=
ays</a><br></div><div><br></div><div>Regards,</div><div>Eran</div></div>
</div><br></div></div>

--001a113a629661fd8e05490de8fb--


From nobody Thu Feb 23 11:18:51 2017
Return-Path: <melinda.shore@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E6E7C1296C8 for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:18:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0dEzlevRukeD for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:18:48 -0800 (PST)
Received: from mail-pg0-x233.google.com (mail-pg0-x233.google.com [IPv6:2607:f8b0:400e:c05::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8E6331296A6 for <trans@ietf.org>; Thu, 23 Feb 2017 11:18:48 -0800 (PST)
Received: by mail-pg0-x233.google.com with SMTP id b129so186825pgc.2 for <trans@ietf.org>; Thu, 23 Feb 2017 11:18:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to; bh=NZ+X9rv/EQR89VPGVSwQ5UMTyVCgvQkqTF7soQdPyHM=; b=BTPkaUHEarqiHyvk+XAaXm8rWjE8KaFINUuql7jikfoRuzMHA6m8T5TBT8F2OtnR1g mPpAGQKFwkn68yCgqgbVXXp/hZwf6mgSAPV+Jpk/AGJCGuriiAHVQxO0V5+ChajrG7/z JHYWO/4cDkKHSk2v8lqxFfrkiCUeGXqn8jU6d9+Pk1aRxkm3Ep+7PVhTgooXMzbznwUG zpw4PfIXwRuFH/fPpd4b/YdxNapZVOBo/Gn110GExIzW+HJNzlekufOnGlD0VEnC99Ea M2zLhWx0h1U92oklyCtFWv2rt8i4qSWfSHVwvztF9x55aZUMty5EtAaDwulBo/GasnLt G2/A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to; bh=NZ+X9rv/EQR89VPGVSwQ5UMTyVCgvQkqTF7soQdPyHM=; b=o7UaZF6JFh9JyJz6fN+54KN1O0SItfNcY0JEh2o8bqXaLGuXaQmEwKUne4L+m2fAf8 dUXFlKjlInrYt82aBtvJjhsB54eBr7JHEFZGN2YMYF4KLWJkKY0pVU6JcgM4sK5M2NV3 lHrGIUg8eCOTlUHucbzwClr8in9yqb6iKKKGk7at7aBvzorf1UF0iFbiq7OjJQKCJ/G1 YlaagDRGR7Ti7AptGzWh4sxfu1DYIfxsmLPXkJjbLVx5/1ZuC8zDY94n3rdrGxDkQUSm yKjVGNjHYX/YGfFgtFnq+bQgKfoHSLIlJq7XhJmTx91GUysx6ewF/69+fvwA1XD3XMgm QGEw==
X-Gm-Message-State: AMke39lJVz1zTZ6gykvM41Zl+74jUB9oFMVAdascNK6xKMzTxFyI2BYxv0q3GYJSpWPsSg==
X-Received: by 10.98.87.142 with SMTP id i14mr47831754pfj.85.1487877527492; Thu, 23 Feb 2017 11:18:47 -0800 (PST)
Received: from Melindas-MacBook-Pro.local (209-112-145-158-radius.dynamic.acsalaska.net. [209.112.145.158]) by smtp.gmail.com with ESMTPSA id e2sm11216381pga.61.2017.02.23.11.18.46 for <trans@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 23 Feb 2017 11:18:46 -0800 (PST)
To: trans@ietf.org
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com> <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
From: Melinda Shore <melinda.shore@gmail.com>
Message-ID: <a3685057-d094-e78b-7c02-cbf9b1254262@gmail.com>
Date: Thu, 23 Feb 2017 10:18:42 -0900
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="nddN1Pg3rWfODwLLSqiWkF0FoSP5cvnxh"
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/-zcxqtMJ_Hjy5nlZHM5Vr7ZdqH4>
Subject: Re: [Trans] The importance of understanding auditing
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Feb 2017 19:18:50 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--nddN1Pg3rWfODwLLSqiWkF0FoSP5cvnxh
Content-Type: multipart/mixed; boundary="6BrT5cmtQ0O3OBSsTlk5pJltM5AsRMOMd";
 protected-headers="v1"
From: Melinda Shore <melinda.shore@gmail.com>
To: trans@ietf.org
Message-ID: <a3685057-d094-e78b-7c02-cbf9b1254262@gmail.com>
Subject: Re: [Trans] The importance of understanding auditing
References: <CAL02cgSitACqqYG1NCoc=QS-bG+13uax=_YxrQ0yTcq8KhHiyQ@mail.gmail.com>
 <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>
In-Reply-To: <CA+cU71k1st5Hr_63NSVqh6=2DSV6WseChpeAYiQvwpcG3Fhx4w@mail.gmail.com>

--6BrT5cmtQ0O3OBSsTlk5pJltM5AsRMOMd
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi, all:

The discussion seems to have settled out, and this is a
check to see where we stand.  First, in general it sounds
like there's a need for a client behavior document regardless,
and we'll take the mechanics of that to a separate discussion.
Second, Richard proposed two auditing models (one STH and
dynamic inclusion proofs, and many STHs and static inclusion
proofs), which in turn led to a discussion of what sort of
TLS client we're targeting, in the first place.  That we're
covering browsers seems uncontroversial but there's not
agreement on clients beyond that (for example, command-line
or batching tools like curl and wget).  I think this is where
I need to point out that our current deliverables specify
HTTP over TLS but not browsers, even though our documents
tend to focus on browsers, and the charter discusses the
possibility of addressing other, non-HTTP applications.

I think it would be probably be useful to have another call.
Would people involved in this discussion be up for a call
next week?

Melinda



--6BrT5cmtQ0O3OBSsTlk5pJltM5AsRMOMd--

--nddN1Pg3rWfODwLLSqiWkF0FoSP5cvnxh
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYrzWTAAoJELiGRpM6HoEu8p4P/3ejNBHrKmYrP13YKXzILaSs
+ScAR7dBQNSUzZFsYcqKFN6rfd2sLmSZTPHfLSpZ31HcnrR+yi8QyQhXke6nWIb1
WLR3kVDwbHsBdGpKVeAhjgA30YkwF3KwZlpf6/odKrU1GmCseHkuLtnGyBgckVYi
DdNHgXC3tY2k8q2DnMRN2P0YVjrHD0CJV/bsCMqLuruOZWgjGwDvGTeZYYgACR8e
yVXGhMbjnyZRtE+wtt84OiHoRWzeMDh3yBKTI94FYERvz+5eM7scc/jEpjgvQQov
LcaEnFg7NBi7fRUbI9GUlIk2nqxhiD1CWz9YtIzmpDlHLIUHlSEqux46CSYdzAdB
lhxGx8dVvf6THlc/c7GFV66pi6xVTkG+61KHmazBYOUQDATbLn1LpXPjzF5ySbkR
6cBo/roi2j8LAlSfx+nki4Bwj1NUgVFWI1ZxEOindeUHxMncFnCmiyeUJHZArh/l
Q5xoV6e4XeKQR5BvbgJbkUi0x4ISuI/xcg08Aecswk89LV5g5nzMGpLAsQVtXoYQ
fn+ILYCca7By4mZcLJ9hGR109abUEQGCBiZolHtzVhMMOUnFFGxDijMtena6+FO3
UZ55zij7lIFOAFvysK9Wn+5BHc1/j2SOwWeg8v/cXZ8xD6RL/j+COi+OrRHpxnaL
kYszpMrgVJVJjUzN+/W/
=g1LG
-----END PGP SIGNATURE-----

--nddN1Pg3rWfODwLLSqiWkF0FoSP5cvnxh--


From nobody Thu Feb 23 11:32:28 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7113512A1F4 for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:32:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pKtukw84EiwC for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:32:24 -0800 (PST)
Received: from mail-it0-x22b.google.com (mail-it0-x22b.google.com [IPv6:2607:f8b0:4001:c0b::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2195B12A135 for <trans@ietf.org>; Thu, 23 Feb 2017 11:32:24 -0800 (PST)
Received: by mail-it0-x22b.google.com with SMTP id d9so6191546itc.0 for <trans@ietf.org>; Thu, 23 Feb 2017 11:32:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=ogUhut4Act2d4IKYoBx9cp3toAaODQEhPmnhrafhL2M=; b=OGb7VeamNFs955KkzLZ1Y6QUaJQz4s+Zk+v81u3H38vLkPz4vSiq9W+9zw/zcA8lIX hYNyNqIju/XQqBqoyeKKCADpAe0K4ngimmuhz/uLuzFoGXWfg3iRldtzSThzATpAj87F mTY+eV5pt6eli/mVIaViE5JboHQmc6eOnO1MNIho9E8INDwJbMO9IOm+ub+SuI+yFUHN /ZvvW+wfXMyK6vU+gozUXKItHES6myQGtJPy9dHfIu03MrGMpGkr0R3SJwBk9NmyV+Ac m6Qx4SQYdURpDL/4IaUEBzDAimgFFPJn9mzehY4+rG00ESMrjurXe3n0D+sNqeumZVeg irpQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=ogUhut4Act2d4IKYoBx9cp3toAaODQEhPmnhrafhL2M=; b=VgPqTUoiOcflgE3/xbzEPoJc2TEQvXzzpWcVj+v9gSTTgQwQNHWB2LLL6RLaewkBTU I75OV611nrALCSNwFefq05pGuIGdrI5LolIASXe+WBcpfNV95td4LfTRpM2SBY+vK0zd G27PEmbjwvvEbkWFRZgsPlK0/kMEnrUcBgOdXzooVSCiN0Hk3w+XwrDjq9v3Vj4O1h/9 Jfif3u73b2zKnJNdxQ4UJLk2irdGyQXLMvMJ46PSiOda3l+5wfjuqvsM3fUAGRQubFk+ 8HcHVUWkGcJpyjudIIsptmruyBSxPIOgb+XyF3cJQHa09CaUXKg38TjA66T/NCOBv9Jg Rb2A==
X-Gm-Message-State: AMke39nVirSTouvZIz4Y9QHAb2rbFAOf1bCxxaMKYWkOXaKmA1WItN5GHmGa7QDg/LI5jYgdNDRbZhdRwXYT1SVG
X-Received: by 10.107.7.78 with SMTP id 75mr35667282ioh.165.1487878342900; Thu, 23 Feb 2017 11:32:22 -0800 (PST)
MIME-Version: 1.0
Received: by 10.107.178.23 with HTTP; Thu, 23 Feb 2017 11:31:52 -0800 (PST)
From: Eran Messeri <eranm@google.com>
Date: Thu, 23 Feb 2017 11:31:52 -0800
Message-ID: <CALzYgEcKpA3fPcE_TkG=FKSxpMiGFp1f=66WG6jPXd1rODW3Bw@mail.gmail.com>
To: "trans@ietf.org" <trans@ietf.org>,  "certificate-transparency@googlegroups.com" <certificate-transparency@googlegroups.com>
Content-Type: multipart/alternative; boundary=001a113f98d2196c62054937ac89
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/VBHQynZYsK0MxFNzllxMkfbjUhI>
Subject: [Trans] Public verification of log behaviour - obtaining proofs
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Feb 2017 19:32:26 -0000

--001a113f98d2196c62054937ac89
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I=E2=80=99d like to overview a few options for clients to obtain inclusion =
proofs
of log entries (each comprising of the corresponding SCT=E2=80=99s timestam=
p +
certificate) in a privacy-preserving manner.

The naive approach, of contacting the CT log itself (or a proxy), discloses
to the operator of the service the certificates each client (as defined by
IP) observed.

Option 1: DNS-based protocol [1].
Clients perform two types of queries, under this protocol:
* Getting the index of an entry.
* Getting an inclusion proof for entry with the given index.

This protocol preserves the client=E2=80=99s privacy by using the client=E2=
=80=99s
recursive resolver to proxy the request (rather than directly connecting to
a service) - full privacy analysis is at [2].

An upside of this protocol is that responses to queries generated under
this protocol are constant and can be cached infinitely - an entry=E2=80=99=
s index
will never change, as well as the inclusion proof from a particular index
for a particular tree size.

This is the approach the CT team and Chrome team at Google are working on
implementing - currently DNS queries are authoritatively resolved by a DNS
front-end of the CT log mirror operated by Google. The intent is to measure
success rates and validate correct operation under most scenarios, then
standardize the protocol.

Option 2: SSL Proxy for log traffic.
Clients connect to a proxy that will relay the TCP connection to the log
(much like SOCKS5), but perform an SSL handshake with the log. Since the
connection is coming from the proxy, the log will not learn which clients
observed which certificate. As the connection is encrypted, the proxy will
not learn which clients observed which certificates.

One downside of the protocol is that responses are not cacheable by the log
/ proxy (at least not with a naive implementation). It should be noted that
clients only need to fetch an inclusion proof once per observed
certificate, not once per connection, and that information can be cached on
the client.

The other downside, and the reason we didn=E2=80=99t implement this approac=
h at
Google, is that collusion between the proxy operator and the log operator
could easily correlate requests to the proxy with requests to the log and
de-cloak clients.

Note the underlying assumption of clients having up-to-date Signed Tree
Heads, provided to them by the UA vendor. While the original design called
for clients obtaining STHs themselves, having UA vendors push down STHs
improves the scalability aspect and does not change the threat model (since
clients already trust the UA vendor). If anything, it serves to guarantee
all clients have the same view of the tree, making it harder for the log to
present split views.

I=E2=80=99ll post separately about dealing with the result of an inclusion =
proof
check.

Eran

[1]
https://github.com/google/certificate-transparency-rfcs/blob/master/dns/dra=
ft-ct-over-dns.md
[2] https://www.ietf.org/mail-archive/web/trans/current/msg02617.html

--001a113f98d2196c62054937ac89
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>I=E2=80=99d like to overview a few options for client=
s to obtain inclusion proofs of log entries (each comprising of the corresp=
onding SCT=E2=80=99s timestamp + certificate) in a privacy-preserving manne=
r.</div><div><br></div><div>The naive approach, of contacting the CT log it=
self (or a proxy), discloses to the operator of the service the certificate=
s each client (as defined by IP) observed.</div><div><br></div><div>Option =
1: DNS-based protocol [1].</div><div>Clients perform two types of queries, =
under this protocol:</div><div>* Getting the index of an entry.</div><div>*=
 Getting an inclusion proof for entry with the given index.</div><div><br><=
/div><div>This protocol preserves the client=E2=80=99s privacy by using the=
 client=E2=80=99s recursive resolver to proxy the request (rather than dire=
ctly connecting to a service) - full privacy analysis is at [2].</div><div>=
<br></div><div>An upside of this protocol is that responses to queries gene=
rated under this protocol are constant and can be cached infinitely - an en=
try=E2=80=99s index will never change, as well as the inclusion proof from =
a particular index for a particular tree size.</div><div><br></div><div>Thi=
s is the approach the CT team and Chrome team at Google are working on impl=
ementing - currently DNS queries are authoritatively resolved by a DNS fron=
t-end of the CT log mirror operated by Google. The intent is to measure suc=
cess rates and validate correct operation under most scenarios, then standa=
rdize the protocol.</div><div><br></div><div>Option 2: SSL Proxy for log tr=
affic.</div><div>Clients connect to a proxy that will relay the TCP connect=
ion to the log (much like SOCKS5), but perform an SSL handshake with the lo=
g. Since the connection is coming from the proxy, the log will not learn wh=
ich clients observed which certificate. As the connection is encrypted, the=
 proxy will not learn which clients observed which certificates.</div><div>=
<br></div><div>One downside of the protocol is that responses are not cache=
able by the log / proxy (at least not with a naive implementation). It shou=
ld be noted that clients only need to fetch an inclusion proof once per obs=
erved certificate, not once per connection, and that information can be cac=
hed on the client.</div><div><br></div><div>The other downside, and the rea=
son we didn=E2=80=99t implement this approach at Google, is that collusion =
between the proxy operator and the log operator could easily correlate requ=
ests to the proxy with requests to the log and de-cloak clients.</div><div>=
<br></div><div>Note the underlying assumption of clients having up-to-date =
Signed Tree Heads, provided to them by the UA vendor. While the original de=
sign called for clients obtaining STHs themselves, having UA vendors push d=
own STHs improves the scalability aspect and does not change the threat mod=
el (since clients already trust the UA vendor). If anything, it serves to g=
uarantee all clients have the same view of the tree, making it harder for t=
he log to present split views.</div><div><br></div><div>I=E2=80=99ll post s=
eparately about dealing with the result of an inclusion proof check.</div><=
div><br></div><div>Eran</div><div><br></div><div>[1] <a href=3D"https://git=
hub.com/google/certificate-transparency-rfcs/blob/master/dns/draft-ct-over-=
dns.md">https://github.com/google/certificate-transparency-rfcs/blob/master=
/dns/draft-ct-over-dns.md</a></div><div>[2]=C2=A0<a href=3D"https://www.iet=
f.org/mail-archive/web/trans/current/msg02617.html">https://www.ietf.org/ma=
il-archive/web/trans/current/msg02617.html</a></div><div><br></div></div>

--001a113f98d2196c62054937ac89--


From nobody Thu Feb 23 11:45:07 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9122312A2AC for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:45:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cwfxS6ChH_vH for <trans@ietfa.amsl.com>; Thu, 23 Feb 2017 11:45:01 -0800 (PST)
Received: from mail-it0-x22d.google.com (mail-it0-x22d.google.com [IPv6:2607:f8b0:4001:c0b::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38918129A8F for <trans@ietf.org>; Thu, 23 Feb 2017 11:45:01 -0800 (PST)
Received: by mail-it0-x22d.google.com with SMTP id h10so178068224ith.1 for <trans@ietf.org>; Thu, 23 Feb 2017 11:45:01 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=qPjpo7uiNalVUCNKJpYCadgoIMfoju7GSf9+IFpJie8=; b=ND1JaByeujqIaUe3BCicSnIVrIVO+DFCyJDHByUgXgdfUrw71VczOK4x9PD3wMLrt8 BI5Mk9q9PfacIrc3XibgKiLChSB9wQ/G4293WqXw5NZXrXk+zs1RbYYdHdNoAKpE19Sc BfeG7l5u7D2OAfVRquWKVbUqzvJmRli/ljKGAVA4qQb0Wda00QkuSUuuH/XjZULdyakv UQQR9OI3MijjUNNFXtMeSlGuo6EasFol0D9YE9IIxDxaog6PWCaKIfVTQ6DjM4CfEfiV 6V9b96jjdfxjwANwuXzPHapeiYPmngOYg5XJ5NYRAW9g9Jl52vh8jePH42L7TrHsLUdq FH/g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=qPjpo7uiNalVUCNKJpYCadgoIMfoju7GSf9+IFpJie8=; b=EHJW0LAoQUZE7Xygj3Z6tBw3JhPwQrqkLBizohuFJxwqFx1KZYcTbBVMw/EuI6x3m6 Zwx3yxyK57CmvBjf+eB7afpigmP3BYG9K7ra5Za92ePrG1Jl+kbCjoH5sgbXTefVAPzr 9QxCYGYVbL3f8sO7l+h0WU4uTIIdKgU8JO2SVMk22OLGHc1z57LFAeUsndgtGpRY9E6P E79TBwnoi6pBTTh1HdEshARkUnzS1wpHM3L1LFvRumaB4q2xzxHO/wRq1y2TbxIkEHnu j4XGRhcbafUz0qR9k8TD2c3fkwNz9rRsj+PaPcneobjp8VPmAX4e7JI+JfTmDwAOgfEg 2wVQ==
X-Gm-Message-State: AMke39nO1tEK4dZUlndKY0+kyWBD44Q0xHF9Ib1wGGb2kO/mYE82NiBVekowo4Q6dYsCSI4QE8glx3LTT/n3dngq
X-Received: by 10.36.116.71 with SMTP id o68mr4587009itc.60.1487879100179; Thu, 23 Feb 2017 11:45:00 -0800 (PST)
MIME-Version: 1.0
Received: by 10.107.178.23 with HTTP; Thu, 23 Feb 2017 11:44:29 -0800 (PST)
From: Eran Messeri <eranm@google.com>
Date: Thu, 23 Feb 2017 11:44:29 -0800
Message-ID: <CALzYgEf6r1n6jTAf96qFNqgxNEqBuR_Uzj058R1cYwYadzGeKQ@mail.gmail.com>
To: "trans@ietf.org" <trans@ietf.org>,  "certificate-transparency@googlegroups.com" <certificate-transparency@googlegroups.com>
Content-Type: multipart/alternative; boundary=001a114aad2c3c6e68054937d965
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/yWB_PVExN3jWatxMPYI3KxMf9-A>
Subject: [Trans] Reporting evidence of potential log misbehaviour
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Feb 2017 19:45:04 -0000

--001a114aad2c3c6e68054937d965
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

To complement my other post about methods for obtaining inclusion proofs,
I've listed some thoughts about coping with failure to obtain an inclusion
proof. Note that this is not a concrete work plan, and does not represent
conclusions reached with the broader CT & Chrome teams.
Feedback is most welcome.

Under the assumption of the current deployment of 6962, in particular:
- Clients get SCTs (without inclusion proofs).
- Clients periodically receive STHs from a the UA vendor (which acts as a
trusted auditor).

The problem is:
How can log misbehaviour, observed by some clients, can be published to
other parties? More concretely, how can clients, in possession of a
suspicious log promise, make other parties aware of this promise?
Particularly, SCTs that could not be audited successfully (=E2=80=9Csuspici=
ous=E2=80=9D
SCTs).

Assumptions:
* The client trusts the UA software vendor (which is already the case).
* Same incident response model as for misbehaving CAs: Clients can only
disclose evidence, but not take local action, and rely on the managers of
the root store program for remediation.

Approaches for solution:
(1) Disclose =E2=80=9Csuspicious=E2=80=9D SCTs to the UA vendor.
(2) Disclose =E2=80=9Csuspicious=E2=80=9D SCTs to the website owner (or a c=
hosen collection
service).
(3) Privacy-preserving proof of log misbehaviour.

(1) Is the most trivial action for a client to take, but has to be balanced
against privacy implications (of disclosing part of the browsing history).
For example, a client could only disclose SCTs from a certain log for which
it failed to get an inclusion proof, while at the same time being able to
obtain inclusion proofs for other SCTs from the same log. The heuristics
for determining when to disclose SCTs to the trusted auditor, or when to
suggest so to the user, should be based on real-world data of success rates
for obtaining inclusion proofs, which is the motivation behind deployment
of the DNS-based protocol.

Option (2), of reporting SCTs to the originating website or a collection
service nominated by the website has better privacy properties, as
information about observed certificates + SCTs is only reported to the site
from which it originated. This method is specified in the Gossip document.
It does require website participation, but does not require websites to
make security decisions (as observed SCTs can be passed along to monitoring
services).

A third option is a privacy-preserving proof of log misbehaviour - there's
academic work in the area which I hope to be able to share soon, but can be
implemented on top of RFC6962 (and would be simpler to implement on top of
6962-bis). In this option, there would be a proof, signed by the log, that
it cannot fulfil a commitment to incorporate an SCT. One variant would not
disclose the SCT at all, and another one would disclose the timestamp from
the SCT, allowing black-listing of bad entries.

Note, that all of these options would work if clients receive embedded
inclusion proofs + STHs.

Reporting back to the UA vendor implies trust in the UA vendor to take
action. To add transparency to the system and prevent the option of a UA
vendor denying having received potential evidence of log misbehaviour, all
such evidence (as well as the view of logs the UA vendor sends to its
users) can be logged in a verifiable data structure.

The problem of global consensus on the state of CT logs (i.e. among UA
vendors, for example), is a much broader one that may be tackled by the
=E2=80=9CInternet-level Consensus=E2=80=9D list.

Eran

--001a114aad2c3c6e68054937d965
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>To complement my other post about methods for obtaini=
ng inclusion proofs, I&#39;ve listed some thoughts about coping with failur=
e to obtain an inclusion proof. Note that this is not a concrete work plan,=
 and does not represent conclusions reached with the broader CT &amp; Chrom=
e teams.</div><div>Feedback is most welcome.</div><div><br></div><div>Under=
 the assumption of the current deployment of 6962, in particular:</div><div=
>- Clients get SCTs (without inclusion proofs).</div><div>- Clients periodi=
cally receive STHs from a the UA vendor (which acts as a trusted auditor).<=
/div><div><br></div><div>The problem is:</div><div>How can log misbehaviour=
, observed by some clients, can be published to other parties? More concret=
ely, how can clients, in possession of a suspicious log promise, make other=
 parties aware of this promise? Particularly, SCTs that could not be audite=
d successfully (=E2=80=9Csuspicious=E2=80=9D SCTs).</div><div><br></div><di=
v>Assumptions:</div><div>* The client trusts the UA software vendor (which =
is already the case).</div><div>* Same incident response model as for misbe=
having CAs: Clients can only disclose evidence, but not take local action, =
and rely on the managers of the root store program for remediation.</div><d=
iv><br></div><div>Approaches for solution:</div><div>(1) Disclose =E2=80=9C=
suspicious=E2=80=9D SCTs to the UA vendor.</div><div>(2) Disclose =E2=80=9C=
suspicious=E2=80=9D SCTs to the website owner (or a chosen collection servi=
ce).</div><div>(3) Privacy-preserving proof of log misbehaviour.</div><div>=
<br></div><div>(1) Is the most trivial action for a client to take, but has=
 to be balanced against privacy implications (of disclosing part of the bro=
wsing history). For example, a client could only disclose SCTs from a certa=
in log for which it failed to get an inclusion proof, while at the same tim=
e being able to obtain inclusion proofs for other SCTs from the same log. T=
he heuristics for determining when to disclose SCTs to the trusted auditor,=
 or when to suggest so to the user, should be based on real-world data of s=
uccess rates for obtaining inclusion proofs, which is the motivation behind=
 deployment of the DNS-based protocol.</div><div><br></div><div>Option (2),=
 of reporting SCTs to the originating website or a collection service nomin=
ated by the website has better privacy properties, as information about obs=
erved certificates + SCTs is only reported to the site from which it origin=
ated. This method is specified in the Gossip document. It does require webs=
ite participation, but does not require websites to make security decisions=
 (as observed SCTs can be passed along to monitoring services).</div><div><=
br></div><div>A third option is a privacy-preserving proof of log misbehavi=
our - there&#39;s academic work in the area which I hope to be able to shar=
e soon, but can be implemented on top of RFC6962 (and would be simpler to i=
mplement on top of 6962-bis). In this option, there would be a proof, signe=
d by the log, that it cannot fulfil a commitment to incorporate an SCT. One=
 variant would not disclose the SCT at all, and another one would disclose =
the timestamp from the SCT, allowing black-listing of bad entries.</div><di=
v><br></div><div>Note, that all of these options would work if clients rece=
ive embedded inclusion proofs + STHs.</div><div><br></div><div>Reporting ba=
ck to the UA vendor implies trust in the UA vendor to take action. To add t=
ransparency to the system and prevent the option of a UA vendor denying hav=
ing received potential evidence of log misbehaviour, all such evidence (as =
well as the view of logs the UA vendor sends to its users) can be logged in=
 a verifiable data structure.</div><div><br></div><div>The problem of globa=
l consensus on the state of CT logs (i.e. among UA vendors, for example), i=
s a much broader one that may be tackled by the =E2=80=9CInternet-level Con=
sensus=E2=80=9D list.</div><div><br></div><div>Eran</div></div>

--001a114aad2c3c6e68054937d965--


From nobody Fri Feb 24 11:22:29 2017
Return-Path: <eranm@google.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 942681294DC for <trans@ietfa.amsl.com>; Fri, 24 Feb 2017 11:22:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gwJkl9BlvPZW for <trans@ietfa.amsl.com>; Fri, 24 Feb 2017 11:22:25 -0800 (PST)
Received: from mail-wr0-x231.google.com (mail-wr0-x231.google.com [IPv6:2a00:1450:400c:c0c::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 034041294D4 for <trans@ietf.org>; Fri, 24 Feb 2017 11:22:24 -0800 (PST)
Received: by mail-wr0-x231.google.com with SMTP id 89so19225757wrr.3 for <trans@ietf.org>; Fri, 24 Feb 2017 11:22:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=jEEtcxJGhLU7gyTYWeKyT8hfTm2g7rMGTL29qEnS86A=; b=ediCMGZ/wKClZVnmUtceVve7icCatlPzW2FkqltmpeFyDJp3pNuKA/opJUgHEFDuhM 5KkWvDZIYfhJsf733puOeDQe16kf0oTDT4IWXhdiygI95e3StzroSPnQpmJyhvpmppKA kFGVmc6upPY92QxIZvd/lGLVKXe+83K9k6I5Ec2kDLWRCCsBPHhvcSb8+H9FiMbrJzzD /Ej2tsGgpJ+OyJc4W2rUaJY03tbrniK4nzlmrHfy1LL+e/rESQ+yTYvDI2DyXMpA32Nt tXNV3xd4RxeH91cYkSqbBAOpAaQssfRs/p1LLnCOF+w7LqMKZkZazdjC3BNsAAc2d0cb HbbA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=jEEtcxJGhLU7gyTYWeKyT8hfTm2g7rMGTL29qEnS86A=; b=j+p67LMKoztKysuM1q719uSYjqCuo7MR4zVaH0PpfyHZWUecwFH5BcbIDcyShXDKLB ZoLOC343zRyPezcb6touAiaqNsYfPuk8aSuWYxgvWdsTaglWznne9WdgTcdIdvpkNlUt GZRJMmGoG+wIBOLt1MeSU88Klm2TW7pLm1z3ItN5ILlWAjyLYWNcawEnj9aNAJyZwVFi 7/hNCvNAnsRDZL2GJ3aoyF+o4ygcUlFc6lFZ92SsGvPJLDey0S+MmQOUyjrMZNlAVrl9 Sr92MuMxSMgBMQ/Q06L82mOF5b0g937yVi7PAcbNUfwV/2+VpSoakTQ0o68+C/OalTgf lKVw==
X-Gm-Message-State: AMke39mHmAwcYRl4hwqPDKRsdrdL39i49RqX1sqqa91/P12RFdhe93Xq7YiRM/ocxKiQFsIHE750tCfzwmLD1hnJ
X-Received: by 10.223.134.52 with SMTP id 49mr3934856wrv.50.1487964143348; Fri, 24 Feb 2017 11:22:23 -0800 (PST)
MIME-Version: 1.0
Received: by 10.28.158.15 with HTTP; Fri, 24 Feb 2017 11:21:52 -0800 (PST)
In-Reply-To: <CAMm+Lwim3NDovHGp62UBKhGc4ewYQQkq2=qH9ssAOFk=JTF=Cw@mail.gmail.com>
References: <CABrd9SSeePrsNq8ERjxpbEvUAdyb=yQOGAom0qh9SZMoP=nsMw@mail.gmail.com> <CAMm+LwiZUw+JpEanY5vkxGBOtdrs9HfYzp34cBtwDv34uJCjKw@mail.gmail.com> <4E665C5B-BC28-428E-9BFB-626D3364E05B@nohats.ca> <CABrd9STPBWt=p-eAW5t=QSw2oexuSeW5tbtcbczagA0jx77gQA@mail.gmail.com> <alpine.LRH.2.20.1611160636020.4488@bofh.nohats.ca> <CABrd9SQjMkWCOv1jPky+DiOE61qCTXej2Ovy9nRVAKs66OtEGA@mail.gmail.com> <CAMm+Lwim3NDovHGp62UBKhGc4ewYQQkq2=qH9ssAOFk=JTF=Cw@mail.gmail.com>
From: Eran Messeri <eranm@google.com>
Date: Fri, 24 Feb 2017 11:21:52 -0800
Message-ID: <CALzYgEcQZb-Yc_b2Mp+dd9hFKAAj5o4Wg9suH6Nq5J03EMz-=A@mail.gmail.com>
To: Phillip Hallam-Baker <ietf@hallambaker.com>
Content-Type: multipart/alternative; boundary=001a1146c03c34361305494ba632
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/wPfUd4VtBNmPbI5TEEUhzunvQcg>
Cc: "trans@ietf.org" <trans@ietf.org>, Paul Wouters <paul@nohats.ca>, Ben Laurie <benl@google.com>
Subject: Re: [Trans] How to redact an entry
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Feb 2017 19:22:27 -0000

--001a1146c03c34361305494ba632
Content-Type: text/plain; charset=UTF-8

Following up on this thread, after a few discussions about it in online &
offline forums:
- It is necessary to have the "Redaction reason" entry in the log to commit
the log to the redaction of a particular entry and avoid allowing the log
to present redacted/unredacted view at will.
- A few have echoed Phillip's sentiment that once an entry is suppressed
then the suppression reason can't be effectively audited for correctness.
- There was a strong push-back against this mechanism on the basis that it
weakens the basic properties we get from the Merkle tree right now.
Potential problems: What if the "Redaction reason" entry itself was
redacted?
- A suggestion by Peter Bowen was to simply not serve the redacted entry:
The only API method by which a suppressed entry can be obtain is
'get-entries', it's possible to return an error when the range specified
includes a suppressed entry. That suffers from the same drawback of the log
being able to selectively presenting redacted/unredacted view.
- An approach many see as superior is to reduce the chances of having
entries with undesirable content in the log by restricting the certificates
that may be logged (e.g. forbidding certificates with embedded images).

Eran

On Wed, Nov 16, 2016 at 6:20 AM, Phillip Hallam-Baker <ietf@hallambaker.com>
wrote:

> Lets break this down.
>
> In what way is suppression of a previously enrolled certificate different
> to not enrolling the certificate at all?
>
> The only ones I can see is that it means that 1) the CA is off the hook,
> they fulfilled their duties and 2) the fact that suppression has occurred
> is visible.
>
>
> CT relies on there being some feedback mechanism to detect unenrolled
> certs, the same would apply to suppressed certs.
>
> So let us imagine that a government coerces a CA to issue a bogus cert and
> then coerces a notary to suppress it. What next?
>
> Well first off anyone who has a copy of that cert taken from the
> repository before the suppression is going to hard look at it. So the
> chance of people being aware of the suppression and working out the reason
> for it is essentially 99%.
>
>
> A person formerly very senior in NSA told me that the governing paradigm
> post Snowden was 'NOBUS': Nobody but us. Sure they might want to perform
> this type of attack if they think they can get away with it but they won't
> do things that are liable to get caught.
>
>
>
>
> On Wed, Nov 16, 2016 at 6:48 AM, Ben Laurie <benl@google.com> wrote:
>
>> On 16 November 2016 at 11:39, Paul Wouters <paul@nohats.ca> wrote:
>> > On Wed, 16 Nov 2016, Ben Laurie wrote:
>> >
>> > (no hats on)
>> >
>> >> On 16 November 2016 at 03:46, Paul Wouters <paul@nohats.ca> wrote:
>> >>>
>> >>> How can I as log consumer detect the difference between the log
>> removing
>> >>> illegal content and the log being compelled by a government to hide a
>> >>> rogue
>> >>> certificate?
>> >>
>> >>
>> >> Court orders are court orders. That issue is not in the log's domain.
>> >
>> >
>> > It was an example. the core isuse is, how can a consumer determine the
>> > log censored itself with a valid reason, versus an attack, compromise,
>> > having been compelled, or for financial gain or any other invalid
>> reason?
>> >
>> > Using a hash of a removed cert won't allow anyone to verify the reason
>> > for removal. And clearly the content cannot remain their either. It's
>> > a catch22.
>>
>> This is why the redaction reason entry exists, so that there _is_
>> something to reason about. If you (a consumer) are unconvinced by the
>> reason, well, there are public fora where you can voice your concerns.
>>
>
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>
>

--001a1146c03c34361305494ba632
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Following up on this thread, after a few discussions about=
 it in online &amp; offline forums:<div>- It is necessary to have the &quot=
;Redaction reason&quot; entry in the log to commit the log to the redaction=
 of a particular entry and avoid allowing the log to present redacted/unred=
acted view at will.</div><div><div>- A few have echoed Phillip&#39;s sentim=
ent that once an entry is suppressed then the suppression reason can&#39;t =
be effectively audited for correctness.</div><div>- There was a strong push=
-back against this mechanism on the basis that it weakens the basic propert=
ies we get from the Merkle tree right now. Potential problems: What if the =
&quot;Redaction reason&quot; entry itself was redacted?</div><div>- A sugge=
stion by Peter Bowen was to simply not serve the redacted entry: The only A=
PI method by which a suppressed entry can be obtain is &#39;get-entries&#39=
;, it&#39;s possible to return an error when the range specified includes a=
 suppressed entry. That suffers from the same drawback of the log being abl=
e to selectively presenting redacted/unredacted view.</div></div><div>- An =
approach many see as superior is to reduce the chances of having entries wi=
th undesirable content in the log by restricting the certificates that may =
be logged (e.g. forbidding certificates with embedded images).</div><div><b=
r></div><div>Eran</div></div><div class=3D"gmail_extra"><br><div class=3D"g=
mail_quote">On Wed, Nov 16, 2016 at 6:20 AM, Phillip Hallam-Baker <span dir=
=3D"ltr">&lt;<a href=3D"mailto:ietf@hallambaker.com" target=3D"_blank">ietf=
@hallambaker.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote"=
 style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><d=
iv dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">Lets =
break this down.</div><div class=3D"gmail_default" style=3D"font-size:small=
"><br></div><div class=3D"gmail_default" style=3D"font-size:small">In what =
way is suppression of a previously enrolled certificate different to not en=
rolling the certificate at all?</div><div class=3D"gmail_default" style=3D"=
font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:=
small">The only ones I can see is that it means that 1) the CA is off the h=
ook, they fulfilled their duties and 2) the fact that suppression has occur=
red is visible.</div><div class=3D"gmail_default" style=3D"font-size:small"=
><br></div><div class=3D"gmail_default" style=3D"font-size:small"><br></div=
><div class=3D"gmail_default" style=3D"font-size:small">CT relies on there =
being some feedback mechanism to detect unenrolled certs, the same would ap=
ply to suppressed certs.</div><div class=3D"gmail_default" style=3D"font-si=
ze:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">=
So let us imagine that a government coerces a CA to issue a bogus cert and =
then coerces a notary to suppress it. What next?</div><div class=3D"gmail_d=
efault" style=3D"font-size:small"><br></div><div class=3D"gmail_default" st=
yle=3D"font-size:small">Well first off anyone who has a copy of that cert t=
aken from the repository before the suppression is going to hard look at it=
. So the chance of people being aware of the suppression and working out th=
e reason for it is essentially 99%.</div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small"=
>A person formerly very senior in NSA told me that the governing paradigm p=
ost Snowden was &#39;NOBUS&#39;: Nobody but us. Sure they might want to per=
form this type of attack if they think they can get away with it but they w=
on&#39;t do things that are liable to get caught.</div><div class=3D"gmail_=
default" style=3D"font-size:small"><br></div><div class=3D"gmail_default" s=
tyle=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"fo=
nt-size:small"><br></div></div><div class=3D"HOEnZb"><div class=3D"h5"><div=
 class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Wed, Nov 16, 2016 =
at 6:48 AM, Ben Laurie <span dir=3D"ltr">&lt;<a href=3D"mailto:benl@google.=
com" target=3D"_blank">benl@google.com</a>&gt;</span> wrote:<br><blockquote=
 class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc soli=
d;padding-left:1ex"><span>On 16 November 2016 at 11:39, Paul Wouters &lt;<a=
 href=3D"mailto:paul@nohats.ca" target=3D"_blank">paul@nohats.ca</a>&gt; wr=
ote:<br>
&gt; On Wed, 16 Nov 2016, Ben Laurie wrote:<br>
&gt;<br>
&gt; (no hats on)<br>
&gt;<br>
&gt;&gt; On 16 November 2016 at 03:46, Paul Wouters &lt;<a href=3D"mailto:p=
aul@nohats.ca" target=3D"_blank">paul@nohats.ca</a>&gt; wrote:<br>
&gt;&gt;&gt;<br>
&gt;&gt;&gt; How can I as log consumer detect the difference between the lo=
g removing<br>
&gt;&gt;&gt; illegal content and the log being compelled by a government to=
 hide a<br>
&gt;&gt;&gt; rogue<br>
&gt;&gt;&gt; certificate?<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; Court orders are court orders. That issue is not in the log&#39;s =
domain.<br>
&gt;<br>
&gt;<br>
&gt; It was an example. the core isuse is, how can a consumer determine the=
<br>
&gt; log censored itself with a valid reason, versus an attack, compromise,=
<br>
&gt; having been compelled, or for financial gain or any other invalid reas=
on?<br>
&gt;<br>
&gt; Using a hash of a removed cert won&#39;t allow anyone to verify the re=
ason<br>
&gt; for removal. And clearly the content cannot remain their either. It&#3=
9;s<br>
&gt; a catch22.<br>
<br>
</span>This is why the redaction reason entry exists, so that there _is_<br=
>
something to reason about. If you (a consumer) are unconvinced by the<br>
reason, well, there are public fora where you can voice your concerns.<br>
</blockquote></div><br></div>
</div></div><br>______________________________<wbr>_________________<br>
Trans mailing list<br>
<a href=3D"mailto:Trans@ietf.org">Trans@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/trans" rel=3D"noreferrer" =
target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/trans</a><br>
<br></blockquote></div><br></div>

--001a1146c03c34361305494ba632--


From nobody Fri Feb 24 12:00:07 2017
Return-Path: <pzbowen@gmail.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 988C1129508 for <trans@ietfa.amsl.com>; Fri, 24 Feb 2017 12:00:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C6A3JfqlFS6o for <trans@ietfa.amsl.com>; Fri, 24 Feb 2017 12:00:02 -0800 (PST)
Received: from mail-ot0-x22b.google.com (mail-ot0-x22b.google.com [IPv6:2607:f8b0:4003:c0f::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 101181294EE for <trans@ietf.org>; Fri, 24 Feb 2017 12:00:02 -0800 (PST)
Received: by mail-ot0-x22b.google.com with SMTP id k4so21154100otc.0 for <trans@ietf.org>; Fri, 24 Feb 2017 12:00:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=Vu06i5WxdCZ3+cY2+L9dA7IsNC/A+Nwwb68cwknSI0w=; b=Vt6mZ0Si9KZQbcFiNQXal6KAUioxwHnEsfR7Kk3LPtLDAGETyBgHfNpAGUyM2Fhe0w RlkeEKwum31KP+nV5LqszyhDcIBfHv4Kxzee5+1/Vb8hYBIZTna3NS5Ibnq2cIYke7Ps pUx37qMTjJZFpPjhZqUdpEdU8F4ntwT5Z9Ihmf+lgp2xCtwD45Ep47DMT+VeOBNyOWf5 CoVUrY7gIfHm3AL1PLVHGArUFA9447LY+QXASdDncdRtPWd/QvQrZw8dVo7DfKvlKyDc dkNGV/TyzcHEVJUrkQAsCOaqrXN1sDq39Ls6+Ldy1sUIze9ruWnwERmowGG5kpuZttS1 InnA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=Vu06i5WxdCZ3+cY2+L9dA7IsNC/A+Nwwb68cwknSI0w=; b=FCnrkiDNXWE8+Ee8G+ve4uunVmxB8JZDu0VmHSZqgFsnNASQg+YnZ+2+EssOQ18PjQ oY7VjS7Jabm83Flht72hsaCwkI46AGRvrfGTDsPkquhQXZI8tm8a+OioN0eKzoIBaDcZ oCenY2uebAgVxoTZBwCVcozmMFcRtwiKOXfBzOqClAwv+wwOZuCNrIs39mouUDKTzcYw FNS0NHY8pFphdp+Un2pAuDfhLElgCN8kei5FUikCrPI0JobnrsTV75sZlMpLwAuVGjsi WEGmBc48drFAbOy601LT4zNOrTOv0m8qqhgHetZwbYqrwugOJvHWggNTam4Vb/hP6SgQ Vwxg==
X-Gm-Message-State: AMke39nhiqh8MVdVlnzcWVATj32jXjCN/ZwYIWaFrwK9lXgEKmlIIgmoCzyxQJQK0+x4uMVLFEETRcGeTEYreA==
X-Received: by 10.157.25.14 with SMTP id j14mr2096564ota.178.1487966401370; Fri, 24 Feb 2017 12:00:01 -0800 (PST)
MIME-Version: 1.0
Received: by 10.157.1.228 with HTTP; Fri, 24 Feb 2017 12:00:00 -0800 (PST)
In-Reply-To: <CALzYgEcQZb-Yc_b2Mp+dd9hFKAAj5o4Wg9suH6Nq5J03EMz-=A@mail.gmail.com>
References: <CABrd9SSeePrsNq8ERjxpbEvUAdyb=yQOGAom0qh9SZMoP=nsMw@mail.gmail.com> <CAMm+LwiZUw+JpEanY5vkxGBOtdrs9HfYzp34cBtwDv34uJCjKw@mail.gmail.com> <4E665C5B-BC28-428E-9BFB-626D3364E05B@nohats.ca> <CABrd9STPBWt=p-eAW5t=QSw2oexuSeW5tbtcbczagA0jx77gQA@mail.gmail.com> <alpine.LRH.2.20.1611160636020.4488@bofh.nohats.ca> <CABrd9SQjMkWCOv1jPky+DiOE61qCTXej2Ovy9nRVAKs66OtEGA@mail.gmail.com> <CAMm+Lwim3NDovHGp62UBKhGc4ewYQQkq2=qH9ssAOFk=JTF=Cw@mail.gmail.com> <CALzYgEcQZb-Yc_b2Mp+dd9hFKAAj5o4Wg9suH6Nq5J03EMz-=A@mail.gmail.com>
From: Peter Bowen <pzbowen@gmail.com>
Date: Fri, 24 Feb 2017 12:00:00 -0800
Message-ID: <CAK6vND8sSDtsgvsrtD7L2zCo2SCxZ8sTQz0+QEkXp5UU8+Nenw@mail.gmail.com>
To: Eran Messeri <eranm@google.com>
Content-Type: text/plain; charset=UTF-8
Archived-At: <https://mailarchive.ietf.org/arch/msg/trans/IUrBKfUKifYTFETFsBKpw5026X0>
Cc: Ben Laurie <benl@google.com>, Paul Wouters <paul@nohats.ca>, Phillip Hallam-Baker <ietf@hallambaker.com>, "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] How to redact an entry
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Feb 2017 20:00:05 -0000

On Fri, Feb 24, 2017 at 11:21 AM, Eran Messeri <eranm@google.com> wrote:
> Following up on this thread, after a few discussions about it in online &
> offline forums:
> - It is necessary to have the "Redaction reason" entry in the log to commit
> the log to the redaction of a particular entry and avoid allowing the log to
> present redacted/unredacted view at will.
> - A few have echoed Phillip's sentiment that once an entry is suppressed
> then the suppression reason can't be effectively audited for correctness.
> - There was a strong push-back against this mechanism on the basis that it
> weakens the basic properties we get from the Merkle tree right now.
> Potential problems: What if the "Redaction reason" entry itself was
> redacted?
> - A suggestion by Peter Bowen was to simply not serve the redacted entry:
> The only API method by which a suppressed entry can be obtain is
> 'get-entries', it's possible to return an error when the range specified
> includes a suppressed entry. That suffers from the same drawback of the log
> being able to selectively presenting redacted/unredacted view.

Another option would be to return something other than "leaf_input"
and "extra_data" in the object.  For example the log could return the
hash of the MerkleTreeLeaf that was there along with a reference to
the leaf that has the redaction reason entry.

> - An approach many see as superior is to reduce the chances of having
> entries with undesirable content in the log by restricting the certificates
> that may be logged (e.g. forbidding certificates with embedded images).
>
> Eran
>
> On Wed, Nov 16, 2016 at 6:20 AM, Phillip Hallam-Baker <ietf@hallambaker.com>
> wrote:
>>
>> Lets break this down.
>>
>> In what way is suppression of a previously enrolled certificate different
>> to not enrolling the certificate at all?
>>
>> The only ones I can see is that it means that 1) the CA is off the hook,
>> they fulfilled their duties and 2) the fact that suppression has occurred is
>> visible.
>>
>>
>> CT relies on there being some feedback mechanism to detect unenrolled
>> certs, the same would apply to suppressed certs.
>>
>> So let us imagine that a government coerces a CA to issue a bogus cert and
>> then coerces a notary to suppress it. What next?
>>
>> Well first off anyone who has a copy of that cert taken from the
>> repository before the suppression is going to hard look at it. So the chance
>> of people being aware of the suppression and working out the reason for it
>> is essentially 99%.
>>
>>
>> A person formerly very senior in NSA told me that the governing paradigm
>> post Snowden was 'NOBUS': Nobody but us. Sure they might want to perform
>> this type of attack if they think they can get away with it but they won't
>> do things that are liable to get caught.
>>
>>
>>
>>
>> On Wed, Nov 16, 2016 at 6:48 AM, Ben Laurie <benl@google.com> wrote:
>>>
>>> On 16 November 2016 at 11:39, Paul Wouters <paul@nohats.ca> wrote:
>>> > On Wed, 16 Nov 2016, Ben Laurie wrote:
>>> >
>>> > (no hats on)
>>> >
>>> >> On 16 November 2016 at 03:46, Paul Wouters <paul@nohats.ca> wrote:
>>> >>>
>>> >>> How can I as log consumer detect the difference between the log
>>> >>> removing
>>> >>> illegal content and the log being compelled by a government to hide a
>>> >>> rogue
>>> >>> certificate?
>>> >>
>>> >>
>>> >> Court orders are court orders. That issue is not in the log's domain.
>>> >
>>> >
>>> > It was an example. the core isuse is, how can a consumer determine the
>>> > log censored itself with a valid reason, versus an attack, compromise,
>>> > having been compelled, or for financial gain or any other invalid
>>> > reason?
>>> >
>>> > Using a hash of a removed cert won't allow anyone to verify the reason
>>> > for removal. And clearly the content cannot remain their either. It's
>>> > a catch22.
>>>
>>> This is why the redaction reason entry exists, so that there _is_
>>> something to reason about. If you (a consumer) are unconvinced by the
>>> reason, well, there are public fora where you can voice your concerns.
>>
>>
>>
>> _______________________________________________
>> Trans mailing list
>> Trans@ietf.org
>> https://www.ietf.org/mailman/listinfo/trans
>>
>
>
> _______________________________________________
> Trans mailing list
> Trans@ietf.org
> https://www.ietf.org/mailman/listinfo/trans
>

