[saag] Re: [nasr] Re: Re: NASR BOF Follow-Up
Henk Birkholz <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 11.04.25 18:51, Eric Rescorla wrote: > > > > Would some salt help here (like the salted hashes in sd-cwt)? > > > > > > Probably not very much. What salt does is make it more difficult to > > amortize computation > > across multiple hashed values. However, if the total number of > possible > > values > > is low (e.g., you have some configuration setting with 3 values) > then > > you can > > just exhaustively search at query time. > > That makes a lot of sense - and might be another good reason not to put > these types of Claims into Evidence. I still think it is better to > include software components that provide the conveyance mechanism > (e.g., > a YANG server with YANG Push capability) in a TCB and then use > successfully appraised software components for trusted telemetry to > convey such values for evaluation. > > > That may be better from some angles but I think brings us back to > Richard's question about whether operators are in fact willing to > allow counterparties to access their devices to get this configuration data. > > It also doesn't affect--one way or the other--the need to understand > which configuration directives are relevant and what acceptable > values are. > > -Ekr If it is really a requirement that policy must be evaluated on the level you describe, my assumption is that a trusted third party that is a kind of "policy evaluator", not a counterparty, and also taking on the role of an Attester (that can be "RATS approved") could handle such operations. But this is now bordering on speculation on my part as there are many ways to compose such a system and I am not aware of all the requirements. My point being here is that RATS is not some kind of smokescreen or some kind of solve-it-all. It is just a building block to increase trust in the trustworthiness of a remote peer. Different building blocks have to be combined here to take all requirements into account. As long as trustworthy policy evaluations can be conducted inside a trust domain, maybe the missing piece here is a viable mechanism to convey believable policy evaluation results to counterparties. Maybe these can be based on approaches similar to draft-ietf-rats-ar4si, maybe something different is needed. Currently, that is hard to tell, but some indirection seems to be in order. As a general rule, I'd also not expect that operators are willing to allow counterparties blank access to configuration, policy, or operational state. I would be surprised, if that was actually intended. Viele Grüße, Henk _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]