SanKumar2015 / EST-coaps

EST over CoAPs IETF draft
1 stars 1 forks source link

Alissa C.'s IESG COMMENT #157

Open csosto-pk opened 4 years ago

csosto-pk commented 4 years ago

COMMENT:

Section 10.1:

"It is also RECOMMENDED that the Implicit Trust Anchor database used for EST server authentication is carefully managed to reduce the chance of a third-party CA with poor certification practices jeopardizing authentication."

This strikes me as a slightly odd use of normative language (what are the exception cases when the trust anchor database should not be carefully managed?).

csosto-pk commented 4 years ago

From Peter:

Suggestion" "The actionswith respect to the Trust Anchor database, cited below, reduce the chance of a third-party CA with poor certification practices to jeopardize authentication."

csosto-pk commented 4 years ago

"It is also RECOMMENDED that the Implicit Trust Anchor database used for EST server authentication is carefully managed to reduce the chance of a third-party CA with poor certification practices jeopardizing authentication."

This strikes me as a slightly odd use of normative language (what are the exception cases when the trust anchor database should not be carefully managed?).

The blurb

   It is also RECOMMENDED that the Implicit Trust Anchor database used
   for EST server authentication is carefully managed to reduce the
   chance of a third-party CA with poor certification practices
   jeopardizing authentication.  Disabling the Implicit Trust Anchor
   database after successfully receiving the Distribution of CA
   certificates response (Section 4.1.3 of [RFC7030]) limits any risk to
   the first DTLS exchange.

is directly from RFC7030. We reiterate it here to point it out as a best practice and then we present a potential deviation from it for constrained environments.

To avoid this confusion we can rephrase it as

    As discussed in Section 6 of [RFC7030], it is 
   "RECOMMENDED that the Implicit Trust Anchor database used
   for EST server authentication is carefully managed to reduce the
   chance of a third-party CA with poor certification practices
   jeopardizing authentication.  Disabling the Implicit Trust Anchor
   database after successfully receiving the Distribution of CA
   certificates response (Section 4.1.3 of [RFC7030]) limits any risk to
   the first DTLS exchange." [...]
csosto-pk commented 4 years ago

Changes committed in https://github.com/SanKumar2015/EST-coaps/commit/a45eda375f4b228b4bcb29e142e393cddbaa4e6a

csosto-pk commented 4 years ago

Text now reads

   As discussed in Section 6 of [RFC7030], it is "RECOMMENDED that the
   Implicit Trust Anchor database used for EST server authentication is
   carefully managed to reduce the chance of a third-party CA with poor
   certification practices jeopardizing authentication.  Disabling the
   Implicit Trust Anchor database after successfuly receiving the
   Distribution of CA certificates response (Section 4.1.3) limits any
   risk to the first TLS exchange".  Alternatively, in a case where a [...]
csosto-pk commented 4 years ago

Uploaded in v-18