[saag] Re: Interests on Initiating the standardization work related to "Zero Trust"
Muhammad Usama Sardar <[email protected]> Fri, 26 Dec 2025 10:14:25 +0100
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hi Aijun,
Your response is unsatisfactory and unacceptable. In fact, you actually
did not answer any of my questions. I asked you three questions:
1. I provided you feedback at side meeting at 123. What did you do with
my feedback? Both of your documents are neither refuting my claims
nor addressing my concerns shared at side meeting.
2. What exactly is the protocol work in your proposal beyond the scope
of SEAT? Reading Sec. 5.3 of draft-liu-saag-zt-problem-statement, it
is unclear to me which of your requirements cannot be met by the
protocol specified in [2*] or at least why it cannot be used as a basis?
3. Do you have a real use case that is not covered in [1*]?
Please avoid any jargon and answer my questions precisely and concisely.
Also see inline.
On 26.12.25 09:16, Aijun Wang wrote:
> As indicated inhttps://datatracker.ietf.org/doc/html/draft-liu-saag-zt-problem-statement-00#section-5.2, although "zero trust" is mainly used as the marketing buzzword, it also reflects the necessity for the standardization body to define and identify how to achieve this goal and how to interoperate among the different components of the "zero trust" system.
I strongly object to the word "necessity". I believe it is not
"necessary" for IETF to define every marketing term out there.
> The use cases defined in this document are just general descriptions.
so what? General descriptions are not acceptable. My question 2 above is
asking you to be specific.
> For the potential works in "zero trust" WG, I think you should refer to section 5.3 "Gap Analysis" and section 6 "Proposed Scope of Work for the IETF" of this document.
> These are not covered by the SEAT WG, and should be developed in one new WG.
Did you read my previous email carefully? I already mentioned 5.3 in my
email. My question 2 above is unanswered.
> Actually, I think the work within SEAT, and also your referred draft documents can be seen as the cases that enhance the "trustworthiness" in transport layer(specially TLS protocol), which can be also clarified as one part of solution for "zero trust", but not all of them.
Protocol in [2*] is beyond the transport layer! Please read the drafts
deeply and carefully before sending any further casual responses.
> There will be others documents to describe the necessary of the new solutions for "zero trust" in these days.
I would like to see answers to 3 questions above in those documents.
> We encourage also others experts to contribute some documents/thoughts on this topic, to make the "zero trust" concept more touchable, implementable and deployable.
I already spent some time with you at meeting 123. To see a proof of
your seriousness, I need answer to question 1 first.
-Usama
> [1]
> https://tls-attestation.github.io/use-cases-and-properties/draft-mihalcea-seat-use-cases.html
>
> [2]
> https://tls-attestation.github.io/exported-attestation/draft-fossati-seat-expat.html
>
>
> * Apologies for mentioning the editors' drafts. We will roll out the updates in the corresponding drafts early next year.
_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.7 KB) - not displayed