[saag] Re: [nasr] Re: Re: NASR BOF Follow-Up

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CABcZeBOwZ3=pz=Xz1D3YwJ6_svTidt5azWDFnTwexsE508rmkA@mail.gmail.com>
On Fri, Apr 11, 2025 at 10:19 AM Henk Birkholz <[email protected]>
wrote:

> On 11.04.25 18:51, Eric Rescorla wrote:
> >      >
> >      >     Would some salt help here (like the salted hashes in sd-cwt)?
> >      >
> >      >
> >      > Probably not very much. What salt does is make it more difficult
> to
> >      > amortize computation
> >      > across multiple hashed values. However, if the total number of
> >     possible
> >      > values
> >      > is low (e.g., you have some configuration setting with 3 values)
> >     then
> >      > you can
> >      > just exhaustively search at query time.
> >
> >     That makes a lot of sense - and might be another good reason not to
> put
> >     these types of Claims into Evidence. I still think it is better to
> >     include software components that provide the conveyance mechanism
> >     (e.g.,
> >     a YANG server with YANG Push capability) in a TCB and then use
> >     successfully appraised software components for trusted telemetry to
> >     convey such values for evaluation.
> >
> >
> > That may be better from some angles but I think brings us back to
> > Richard's question about whether operators are in fact willing to
> > allow counterparties to access their devices to get this configuration
> data.
> >
> > It also doesn't affect--one way or the other--the need to understand
> > which configuration directives are relevant and what acceptable
> > values are.
> >
> > -Ekr
>
> If it is really a requirement that policy must be evaluated on the level
> you describe, my assumption is that a trusted third party that is a kind
> of "policy evaluator", not a counterparty, and also taking on the role
> of an Attester (that can be "RATS approved") could handle such
> operations. But this is now bordering on speculation on my part as there
> are many ways to compose such a system and I am not aware of all the
> requirements.
>

Well, this doesn't matter for the point I'm making. *someone* needs
to do the evaluation and I'm questioning whether it's actually
practical.

My point being here is that RATS is not some kind of smokescreen or some
> kind of solve-it-all. It is just a building block to increase trust in
> the trustworthiness of a remote peer.
>

You may be addressing Richard here? As I said above I'm interested
in the question of whether it's in principal practical to determine
whether a given device's configuration is acceptable even under the
assumption that you have trustworthy access to that configuration.

-Ekr

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.