Re: [OPSAWG] draft-ietf-opsawg-sbom-access and BRSKI ?

2021-05-29 Thread Michael Richardson
Eliot Lear wrote: > So this raises an interesting question, which is probably more > appropriate for RATS.  What information should be shared with whom and > how?  The voucher is shipped in the clear without much prompting.  How so in the clear? It's DNS-ID or pinned TLS from Registr

Re: [OPSAWG] draft-ietf-opsawg-sbom-access and BRSKI ?

2021-05-29 Thread Michael Richardson
Toerless Eckert wrote: > Hah. But thats an even earlier step than what i was thinking of. Yes, > attestation during voucher setup is an interesting option to. It just > would put the pledge into the "even more under control by the > manufacturer" bucket. Which some users will pref

Re: [OPSAWG] draft-ietf-opsawg-sbom-access and BRSKI ?

2021-05-29 Thread Toerless Eckert
On Sat, May 29, 2021 at 04:06:29PM +0200, Eliot Lear wrote: > So this raises an interesting question, which is probably more appropriate > for RATS.  What information should be shared with whom and how?  The voucher > is shipped in the clear without much prompting.  There are different views > abou

Re: [OPSAWG] draft-ietf-opsawg-sbom-access and BRSKI ?

2021-05-29 Thread Eliot Lear
So this raises an interesting question, which is probably more appropriate for RATS.  What information should be shared with whom and how?  The voucher is shipped in the clear without much prompting.  There are different views about how sensitive software inventory is.  This is why the draft do