Skip to main content

Cryptographic Algorithms for Internet of Things (IoT) Devices
draft-ietf-suit-mti-23

Revision differences

Document history

Date Rev. By Action
2026-05-20
23 (System) RPC status changed to blocked: Reference Not Received (2nd Generation)
2026-05-20
23 (System) RFC Editor state changed to Blocked from MISSREF
2025-07-30
23 (System) IANA Action state changed to RFC-Ed-Ack from Waiting on RFC Editor
2025-07-30
23 (System) IANA Action state changed to Waiting on RFC Editor from In Progress
2025-07-30
23 (System) IANA Action state changed to In Progress from Waiting on Authors
2025-07-24
23 (System) IANA Action state changed to Waiting on Authors from In Progress
2025-07-23
23 (System) RFC Editor state changed to MISSREF
2025-07-23
23 (System) IESG state changed to RFC Ed Queue from Approved-announcement sent
2025-07-23
23 (System) Announcement was received by RFC Editor
2025-07-23
23 (System) IANA Action state changed to In Progress
2025-07-23
23 (System) Removed all action holders (IESG state changed)
2025-07-23
23 Morgan Condie IESG state changed to Approved-announcement sent from Approved-announcement to be sent
2025-07-23
23 Morgan Condie IESG has approved the document
2025-07-23
23 Morgan Condie Closed "Approve" ballot
2025-07-23
23 Morgan Condie Ballot approval text was generated
2025-07-23
23 Morgan Condie Ballot writeup was changed
2025-07-22
23 Deb Cooley IESG state changed to Approved-announcement to be sent from Approved-announcement to be sent::AD Followup
2025-07-22
23 Akira Tsukamoto New version available: draft-ietf-suit-mti-23.txt
2025-07-22
23 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-07-22
23 Akira Tsukamoto Uploaded new revision
2025-07-10
22 Morgan Condie IESG state changed to Approved-announcement to be sent::AD Followup from IESG Evaluation
2025-07-08
22 (System) IANA Review state changed to IANA OK - Actions Needed from Version Changed - Review Needed
2025-07-08
22 Roman Danyliw
[Ballot comment]
Thank you to Linda Dunbar for the GENART review.

** Section 3
  Each profile references specific algorithm identifiers, as defined in
  …
[Ballot comment]
Thank you to Linda Dunbar for the GENART review.

** Section 3
  Each profile references specific algorithm identifiers, as defined in
  [IANA-COSE].

This reference makes [IANA-COSE] a normative reference.  It is currently informative.

** Section 3.
Since these algorithm identifiers are used in the
  context of the IETF SUIT manifest [I-D.ietf-suit-manifest], they are
  represented using CBOR Object Signing and Encryption (COSE)
  structures as defined in [RFC9052] and [RFC9053].

Same as above. [RFC9053] also appears to be normative.

** Section 6
  IANA is requested to create a page for "COSE SUIT Algorithm Profiles"
  within the "Software Update for the Internet of Things (SUIT)"
  registry group.  IANA is also requested to create a registry for
  "COSE SUIT Algorithm Profiles" within that registry group.

What is a “page … within SUIT registry group”?  How is that different than the next sentence’s request for a new registry?

** Section 6.  Can the text explicitly define with inline text or by reference the semantics of the IANA column values.  Perhaps reference Section 3.  Consider if it might be clear to align the column names with the names used in Section 3 and Tables 1-6.
2025-07-08
22 Roman Danyliw [Ballot Position Update] New position, No Objection, has been recorded for Roman Danyliw
2025-07-07
22 Paul Wouters [Ballot comment]
Thanks for this document.

I do think [IANA-COSE] should be a normative reference, not an informative.
2025-07-07
22 Paul Wouters [Ballot Position Update] New position, Yes, has been recorded for Paul Wouters
2025-07-07
22 Orie Steele
[Ballot comment]
# Orie Steele, ART AD, comments for draft-ietf-suit-mti-22
CC @OR13

* line numbers:
  - https://author-tools.ietf.org/api/idnits?url=https://www.ietf.org/archive/id/draft-ietf-suit-mti-22.txt&submitcheck=True

* comment syntax:
  - https://github.com/mnot/ietf-comments/blob/main/format.md

* "Handling Ballot Positions":
  - https://ietf.org/about/groups/iesg/statements/handling-ballot-positions/

## Comments

Thanks to Barry Leiba for the ARTART review.

### OPTIONAL to MANDATORY?

```
492   As time progresses, algorithm profiles may loose their MANDATORY
493   status.  Then, their status will become either OPTIONAL or NOT
494   RECOMMENDED for new implementations.  Likewise, a profile may be
495   transitioned from OPTIONAL to NOT RECOMMENDED.  Since it may be
496   impossible to update certain parts of the IoT device firmware in the
497   field, such as first stage bootloaders, support for all relevant
498   algorithms will almost always be required by authoring tools.
```

I wonder if its worth stating explicitly that suites marked OPTIONAL or NOT RECOMMENDED MUST NOT be transitions to MANDATORY.
Just for the sake of clarity to the DEs.


### Why no number assignment for the suite?

```
503 6.1.  Profile: suit-sha256-hmac-a128kw-a128ctr

505   *  Profile: suit-sha256-hmac-a128kw-a128ctr

507   *  Status: MANDATORY

509   *  Digest: -16

511   *  Auth: 5

513   *  Key Exchange: -3

515   *  Encryption: -65534

517   *  Descriptor Array: [-16, 5, -3, -65534]

519   *  Reference: Section 3.1 of THIS_DOCUMENT
```

Given the suites builds on COSE, I was expecting to see a number assigned to the suite.
Given that the registration policy is standards action, there does not seem to be a challenge in requesting the assignment of a new number.
2025-07-07
22 Orie Steele [Ballot Position Update] New position, No Objection, has been recorded for Orie Steele
2025-07-07
22 Brendan Moran New version available: draft-ietf-suit-mti-22.txt
2025-07-07
22 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2025-07-07
22 Brendan Moran Uploaded new revision
2025-07-07
21 Jim Guichard [Ballot Position Update] New position, No Objection, has been recorded for Jim Guichard
2025-07-07
21 Éric Vyncke
[Ballot comment]

# Éric Vyncke, INT AD, comments for draft-ietf-suit-mti-21
CC @evyncke

Thank you for the work put into this document.

Please find below some …
[Ballot comment]

# Éric Vyncke, INT AD, comments for draft-ietf-suit-mti-21
CC @evyncke

Thank you for the work put into this document.

Please find below some non-blocking COMMENT points/nits (replies would be appreciated even if only for my own education).

Special thanks to Russ Housley for the shepherd's write-up (using the old template) including the WG consensus *but it lacks* the justification of the intended status.

Other thanks to Lorenzo Corneo, the IoT directorate reviewer (at my request):
https://datatracker.ietf.org/doc/review-ietf-suit-mti-18-iotdir-telechat-corneo-2025-06-26/ (and I have read the dialog with the authors)

I hope that this review helps to improve the document,

Regards,

-éric

## COMMENTS (non-blocking)

### Abstract

Suggestion: swap the first and second paragraphs.

### Section 1

Should the reference to RFC 9124 be repeated in the introduction?

### Section 3

Suggestion: mention that the profiles will be in a IANA registry (with forward reference to IANA considerations). This could also appear in the introduction.

### Section 4.1

Unsure to understand what is meant by "gadget" in `or use gadgets found in the code will need to first extract the code from the target` ...
2025-07-07
21 Éric Vyncke [Ballot Position Update] New position, No Objection, has been recorded for Éric Vyncke
2025-07-06
21 Akira Tsukamoto New version available: draft-ietf-suit-mti-21.txt
2025-07-06
21 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-07-06
21 Akira Tsukamoto Uploaded new revision
2025-07-04
20 Mahesh Jethanandani [Ballot Position Update] New position, No Objection, has been recorded for Mahesh Jethanandani
2025-07-04
20 Ketan Talaulikar [Ballot Position Update] New position, No Objection, has been recorded for Ketan Talaulikar
2025-07-04
20 Mohamed Boucadair
[Ballot comment]
Hi authors, Hannes, and WG,

Thank you for taking care of my comments.

All the points raised in my previous ballot [1] were …
[Ballot comment]
Hi authors, Hannes, and WG,

Thank you for taking care of my comments.

All the points raised in my previous ballot [1] were adequately addressed in [2].

One comment about -20 though, Section 6.6 has text that is not specific to that section and should be moved out of the subsection.

Cheers,
Med

[1] https://mailarchive.ietf.org/arch/msg/suit/vVFGeoYo3REHWhPQP2rBbGRenHI/

[2] https://author-tools.ietf.org/iddiff?url1=draft-ietf-suit-mti-18&url2=draft-ietf-suit-mti-20&difftype=--html
2025-07-04
20 Mohamed Boucadair [Ballot Position Update] Position for Mohamed Boucadair has been changed to No Objection from Discuss
2025-07-04
20 Akira Tsukamoto New version available: draft-ietf-suit-mti-20.txt
2025-07-04
20 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-07-04
20 Akira Tsukamoto Uploaded new revision
2025-07-03
19 Akira Tsukamoto New version available: draft-ietf-suit-mti-19.txt
2025-07-03
19 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-07-03
19 Akira Tsukamoto Uploaded new revision
2025-07-01
18 Andy Newton [Ballot comment]
I have no object to the publication of this document as an RFC. Many thanks to Barry Leiba for his ARTART review.
2025-07-01
18 Andy Newton [Ballot Position Update] New position, No Objection, has been recorded for Andy Newton
2025-07-01
18 Gorry Fairhurst [Ballot Position Update] New position, No Objection, has been recorded for Gorry Fairhurst
2025-06-30
18 Magnus Nyström Request for Telechat review by SECDIR Completed: Has Issues. Reviewer: Magnus Nyström. Sent review to list.
2025-06-29
18 Mohamed Boucadair
[Ballot discuss]
Hi Brendan, Øyvind, and Akira,

Thanks for the effort put into this document.

Thanks to Jouni Korhonen for the OPSDIR review. I trust …
[Ballot discuss]
Hi Brendan, Øyvind, and Akira,

Thanks for the effort put into this document.

Thanks to Jouni Korhonen for the OPSDIR review. I trust the authors will engage with Jouni to resolve his comments.

# DISCUSS

# MTI for authors

We do says in Section 3:

  *  Authors MUST implement all MTI profiles. Authors MAY implement
      any number of additional profiles.

And then in Section 6:

  However, as it may be impossible to update the
  SUIT manifest processor in the field, support for all relevant
  algorithms will almost always be required by authoring tools.

As some profiles may not be recommended in the future, do we really need to impose/hint that authors must always support any MTI profile (including those may not be recommended anymore)?

Rather than imposing the support of MTI defined in this document as an absolute requirement, I suggest we use the IANA registry as the authoritative source for compliance.

OLD:
  *  Authors MUST implement all MTI profiles. Authors MAY implement
      any number of additional profiles.

NEW:

  *  Authors MUST implement all MTI profiles with a status set to “mandatory” (*) in [IANA_REGISTRY]. Authors MAY implement
      any number of additional profiles.

(*) see below for an alternative status approach.

## Manageability and Operational Considerations

CURRENT:
  *  Recipients MAY choose which MTI profile they wish to implement.
      It is RECOMMENDED that they implement the "Future" Asymmetric MTI
      profile.  Recipients MAY implement any number of other profiles
      not defined in this document. Recipients MAY choose not to
      implement encryption and the corresponding key exchange algorithms
      if they do not intend to support encrypted payloads.

How to know what profiles are supported? How to expose that they don’t implement the encryption part? What are the required provisioning for each profile? Is it allowed to control which profile to put into effect when many are supported? If so, how can that be implemented? Under which conditions it isn’t possible to switch to a different profile? Can these events logged and reported?

These are examples of operational considerations that need to be clarified.

I see that Section 4 points to draft-ietf-suit-report but that text focuses more on a behavior vs manifest. I also see that draft-ietf-suit-report describes some capability reporting features, which is good.

I suggest we expand Section 4 to specifically cover these matters. No need to duplicate text if it exists in other documents; adding pointers where to look at would be sufficient. Thanks.

## I-D.ietf-suit-report should be normative

CURRENT:
  When using SUIT reports [I-D.ietf-suit-report] - particularly those
  data structures intended to convey update capabilities, status,
  progress, or success - the same algorithm profile as used in the
  corresponding SUIT manifest SHOULD be applied. 

suggests that [I-D.ietf-suit-report] is normative, not informative as in the current version. Please fix that.

# MANDATORY meaning in IANA section

## Unless I’m mistaken, not all MTI profiles are mandatory to implement. I don’t quite understand how to interpret the “Status” set to MANDATORY in Table 7. The surrounding text does not explain this.

## Transition values

  As time progresses, if entries are removed from mandatory status,
  they will become SHOULD, MAY and then possibly NOT RECOMMENDED for
  new implementation. 

What are the criteria to transition the status? Also, what is the value in having an MTI profile with a “MAY”?

## Given that an MTI profile may not be actually an MTI in the future, you may consider setting the status to “Active” for a currently recommended MTI profile. Then transition to “Inactive” or “Deprecated” when it is not recommended in the future.
2025-06-29
18 Mohamed Boucadair
[Ballot comment]
# Unfortunate naming of profiles

Current/Future choice is unfortunate. Better to use better naming that reflect the technical characterization of the profiles rather …
[Ballot comment]
# Unfortunate naming of profiles

Current/Future choice is unfortunate. Better to use better naming that reflect the technical characterization of the profiles rather than timing.

# Regional requirement

CURRENT:
At least one algorithm in each category must be FIPS-validated.

As someone not familiar with conventions/practices in this filed, some text to explain why a regional requirement is included here would be helpful.

Also, please consider this change:

NEW:
  At least one algorithm in each category must be US FIPS-validated.

# Terminology

CURRENT:
  The abbreviation SUIT stands for Software Updates for the Internet of
  Things and specifically addresses the requirements of constrained
  devices and networks, as described in [RFC9019].

The acronym was already introduced. What would be helpful is to include specific pointers where to find definitions for SUIT authors, recipients, parsers, etc.

# IP: Another unfortunate acronym

CURRENT:
  Payload encryption is often used to protect Intellectual Property
  (IP) and Personally Identifying Information (PII) in transit.  The
  primary function of payload in SUIT is to act as a defense against
  passive IP and PII snooping. 

I would avoid IP here for obvious reasons. Maybe s/IP/IPR or keep the expanded term.

# Missing Registry name

CURRENT:
  IANA is also requested to create a registry for COSE Algorithm
  Profiles within this page. 

Unless I missed where this was provided, I think that we need to provide a name for the new registry.

Also, better to provide the link where to find the registry group.

Cheers,
Med
2025-06-29
18 Mohamed Boucadair [Ballot Position Update] New position, Discuss, has been recorded for Mohamed Boucadair
2025-06-29
18 Jouni Korhonen Request for IETF Last Call review by OPSDIR Completed: Has Nits. Reviewer: Jouni Korhonen. Sent review to list.
2025-06-27
18 Tero Kivinen Request for Telechat review by SECDIR is assigned to Magnus Nyström
2025-06-27
18 Gunter Van de Velde [Ballot Position Update] New position, No Objection, has been recorded for Gunter Van de Velde
2025-06-26
18 Lorenzo Corneo Request for Telechat review by IOTDIR Completed: Ready with Nits. Reviewer: Lorenzo Corneo. Sent review to list.
2025-06-26
18 Ines Robles Request for Telechat review by IOTDIR is assigned to Lorenzo Corneo
2025-06-26
18 Éric Vyncke Requested Telechat review by IOTDIR
2025-06-24
18 Erik Kline [Ballot Position Update] New position, No Objection, has been recorded for Erik Kline
2025-06-23
18 Morgan Condie Placed on agenda for telechat - 2025-07-10
2025-06-22
18 Deb Cooley Ballot has been issued
2025-06-22
18 Deb Cooley [Ballot Position Update] New position, Yes, has been recorded for Deb Cooley
2025-06-22
18 Deb Cooley Created "Approve" ballot
2025-06-22
18 Deb Cooley IESG state changed to IESG Evaluation from Waiting for AD Go-Ahead
2025-06-14
18 (System) IANA Review state changed to Version Changed - Review Needed from IANA OK - Actions Needed
2025-06-14
18 Akira Tsukamoto New version available: draft-ietf-suit-mti-18.txt
2025-06-14
18 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-06-14
18 Akira Tsukamoto Uploaded new revision
2025-06-12
17 Linda Dunbar Request for IETF Last Call review by GENART Completed: Ready with Nits. Reviewer: Linda Dunbar. Sent review to list.
2025-06-12
17 (System) IESG state changed to Waiting for AD Go-Ahead from In Last Call
2025-06-11
17 David Dong
IESG/Authors/WG Chairs:

IANA has completed its review of draft-ietf-suit-mti-17. If any part of this review is inaccurate, please let us know.

IANA understands that, upon …
IESG/Authors/WG Chairs:

IANA has completed its review of draft-ietf-suit-mti-17. If any part of this review is inaccurate, please let us know.

IANA understands that, upon approval of this document, there is a single action which we must complete.

A new registry is to be created called the COSE Algorithm Profiles registry. The new registry will be located in the Software Update for the Internet of Things (SUIT) registry group located at:

https://www.iana.org/assignments/suit/

The registry will be managed via Standards Action as defined in [RFC8126]. The reference for the registry will be [ RFC-to-be ].

There are initial registrations in the new registry as follows:

Profile Status Digest Auth Key Exchange Encryption Descriptor Array Reference
------+------+------+----+-------------+----------+----------------+-----------
suit-sha256-hmac-a128kw-a128ctr      MANDATORY -16    5    -3      -65534 [-16, 5, -3, -65534]    [ RFC-to-be; Section 3.1 ]
suit-sha256-esp256-ecdh-a128ctr      MANDATORY -16    -9  -29      -65534      [-16, -9, -29, -65534]  [ RFC-to-be; Section 3.2 ]
suit-sha256-ed25519-ecdh-a128ctr    MANDATORY -16    -19  -29      -65534      [-16, -19, -29, -65534] [ RFC-to-be; Section 3.3 ]
suit-sha256-esp256-ecdh-a128gcm      MANDATORY -16    -9  -29      1          [-16, -9, -29, 1]      [ RFC-to-be; Section 3.4 ]
suit-sha256-ed25519-ecdh-chacha-poly MANDATORY -16    -19  -29      24          [-16, -19, -29, 24]    [ RFC-to-be; Section 3.5 ]
suit-sha256-hsslms-a256kw-a256ctr    MANDATORY -16    -46  -5      -65532      [-16, -46, -5, -65532]  [ RFC-to-be; Section 3.6 ]

We understand that this is the only action required to be completed upon approval of this document.

NOTE: The action requested in this document will not be completed until the document has been approved for publication as an RFC. This message is meant only to confirm the action that will be performed.

For definitions of IANA review states, please see:

https://datatracker.ietf.org/help/state/draft/iana-review

Thank you,

David Dong
IANA Services Sr. Specialist
2025-06-11
17 (System) IANA Review state changed to IANA OK - Actions Needed from IANA - Review Needed
2025-06-11
17 Jean Mahoney Request for IETF Last Call review by GENART is assigned to Linda Dunbar
2025-06-10
17 Gyan Mishra Assignment of request for IETF Last Call review by GENART to Gyan Mishra was rejected
2025-06-10
17 Bo Wu Request for IETF Last Call review by OPSDIR is assigned to Jouni Korhonen
2025-06-09
17 Akira Tsukamoto New version available: draft-ietf-suit-mti-17.txt
2025-06-09
17 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-06-09
17 Akira Tsukamoto Uploaded new revision
2025-06-07
16 Mohamed Boucadair Requested IETF Last Call review by OPSDIR
2025-06-05
16 Jean Mahoney Request for IETF Last Call review by GENART is assigned to Gyan Mishra
2025-06-03
16 Magnus Nyström Request for IETF Last Call review by SECDIR Completed: Not Ready. Reviewer: Magnus Nyström. Sent review to list.
2025-06-03
16 Barry Leiba Request for IETF Last Call review by ARTART Completed: Ready. Reviewer: Barry Leiba. Sent review to list.
2025-06-02
16 Barry Leiba Request for IETF Last Call review by ARTART is assigned to Barry Leiba
2025-06-02
16 Tero Kivinen Request for IETF Last Call review by SECDIR is assigned to Magnus Nyström
2025-05-30
16 Akira Tsukamoto New version available: draft-ietf-suit-mti-16.txt
2025-05-30
16 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-05-30
16 Akira Tsukamoto Uploaded new revision
2025-05-29
15 Morgan Condie IANA Review state changed to IANA - Review Needed
2025-05-29
15 Morgan Condie
The following Last Call announcement was sent out (ends 2025-06-12):

From: The IESG
To: IETF-Announce
CC: debcooley1@gmail.com, draft-ietf-suit-mti@ietf.org, housley@vigilsec.com, suit-chairs@ietf.org, suit@ietf.org …
The following Last Call announcement was sent out (ends 2025-06-12):

From: The IESG
To: IETF-Announce
CC: debcooley1@gmail.com, draft-ietf-suit-mti@ietf.org, housley@vigilsec.com, suit-chairs@ietf.org, suit@ietf.org
Reply-To: last-call@ietf.org
Sender:
Subject: Last Call:  (Mandatory-to-Implement Algorithms for Authors and Recipients of Software Update for the Internet of Things manifests) to Proposed Standard


The IESG has received a request from the Software Updates for Internet of
Things WG (suit) to consider the following document: -
'Mandatory-to-Implement Algorithms for Authors and Recipients of
  Software Update for the Internet of Things manifests'
  as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
last-call@ietf.org mailing lists by 2025-06-12. Exceptionally, comments may
be sent to iesg@ietf.org instead. In either case, please retain the beginning
of the Subject line to allow automated sorting.

Abstract


  This document specifies cryptographic algorithm profiles to be used
  with the Software Updates for Internet of Things (suit) manifest.
  These profiles define mandatory-to-implement algorithms to ensure
  interoperability.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-suit-mti/



No IPR declarations have been submitted directly on this I-D.




2025-05-29
15 Morgan Condie IESG state changed to In Last Call from Last Call Requested
2025-05-29
15 Deb Cooley Last call was requested
2025-05-29
15 Deb Cooley Last call announcement was generated
2025-05-29
15 Deb Cooley Ballot approval text was generated
2025-05-29
15 Deb Cooley IESG state changed to Last Call Requested from AD Evaluation::AD Followup
2025-05-26
15 Akira Tsukamoto New version available: draft-ietf-suit-mti-15.txt
2025-05-26
15 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-05-26
15 Akira Tsukamoto Uploaded new revision
2025-04-30
14 (System) Changed action holders to Deb Cooley (IESG state changed)
2025-04-30
14 (System) Sub state has been changed to AD Followup from Revised I-D Needed
2025-04-30
14 Brendan Moran New version available: draft-ietf-suit-mti-14.txt
2025-04-30
14 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2025-04-30
14 Brendan Moran Uploaded new revision
2025-03-24
13 Deb Cooley 1.  https://mailarchive.ietf.org/arch/msg/suit/R_hqwiJqLjlz-mcWQWuwPugfmqE/
2.  IANA early comments
3.  My IANA query re:  https://mailarchive.ietf.org/arch/msg/suit/_gBtTa6ecqmTQ5ep9bUNN5wTSRk/
2025-03-24
13 (System) Changed action holders to Brendan Moran, Øyvind Rønningstad, Akira Tsukamoto (IESG state changed)
2025-03-24
13 Deb Cooley IESG state changed to AD Evaluation::Revised I-D Needed from AD Evaluation::AD Followup
2025-03-17
13 Brendan Moran New version available: draft-ietf-suit-mti-13.txt
2025-03-17
13 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2025-03-17
13 Brendan Moran Uploaded new revision
2025-03-16
12 Akira Tsukamoto New version available: draft-ietf-suit-mti-12.txt
2025-03-16
12 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-03-16
12 Akira Tsukamoto Uploaded new revision
2025-03-16
11 Akira Tsukamoto New version available: draft-ietf-suit-mti-11.txt
2025-03-16
11 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-03-16
11 Akira Tsukamoto Uploaded new revision
2025-03-16
10 (System) Changed action holders to Deb Cooley (IESG state changed)
2025-03-16
10 (System) Sub state has been changed to AD Followup from Revised I-D Needed
2025-03-16
10 Akira Tsukamoto New version available: draft-ietf-suit-mti-10.txt
2025-03-16
10 Akira Tsukamoto New version accepted (logged-in submitter: Akira Tsukamoto)
2025-03-16
10 Akira Tsukamoto Uploaded new revision
2025-03-10
09 Deb Cooley Notification list changed to housley@vigilsec.com from housley@vigilsec.com, davewaltermire@gmail.com
2025-03-05
09 Deb Cooley https://mailarchive.ietf.org/arch/msg/suit/_J6pMYOLnzEVoEkTJwhtqI3wUt8/
2025-03-05
09 (System) Changed action holders to Brendan Moran, Øyvind Rønningstad, Akira Tsukamoto (IESG state changed)
2025-03-05
09 Deb Cooley IESG state changed to AD Evaluation::Revised I-D Needed from AD Evaluation::AD Followup
2025-03-05
09 Deb Cooley https://mailarchive.ietf.org/arch/msg/suit/_J6pMYOLnzEVoEkTJwhtqI3wUt8/
2025-03-03
09 (System) Changed action holders to Deb Cooley (IESG state changed)
2025-03-03
09 (System) Sub state has been changed to AD Followup from Revised I-D Needed
2025-03-03
09 Brendan Moran New version available: draft-ietf-suit-mti-09.txt
2025-03-03
09 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2025-03-03
09 Brendan Moran Uploaded new revision
2025-02-23
08 Deb Cooley For comments, see:  https://mailarchive.ietf.org/arch/msg/suit/CCIujeIb0gzvpDjRQWpaLsScjJw/
2025-02-23
08 (System) Changed action holders to Brendan Moran, Øyvind Rønningstad, Akira Tsukamoto (IESG state changed)
2025-02-23
08 Deb Cooley IESG state changed to AD Evaluation::Revised I-D Needed from AD Evaluation
2025-02-21
08 Deb Cooley IESG state changed to AD Evaluation from Publication Requested
2025-02-21
08 Deb Cooley Ballot writeup was changed
2024-11-26
08 Akira Tsukamoto
Shepherd Write-up for draft-ietf-suit-mti-08


(1) What type of RFC is being requested (BCP, Proposed Standard, Internet
Standard, Informational, Experimental, or Historic)?  Why is this the …
Shepherd Write-up for draft-ietf-suit-mti-08


(1) What type of RFC is being requested (BCP, Proposed Standard, Internet
Standard, Informational, Experimental, or Historic)?  Why is this the
proper type of RFC?  Is this type of RFC indicated in the title page
header?

  Proposed Standard.  Yes, the header calls for a Standards Track RFC.


(2) The IESG approval announcement includes a Document Announcement
Write-Up.  Please provide such a Document Announcement Write-Up.  Recent
examples can be found in the "Action" announcements for approved
documents.  The approval announcement contains the following sections:

  Technical Summary:

  This document specifies cryptographic algorithms to be used with
  the SUIT manifest (see draft-ietf-suit-manifest).  These are the
  mandatory-to-implement algorithms to ensure interoperability.

  Working Group Summary:

  There is consensus for this document in the SUIT WG.

  Document Quality:

  Projects at the IETF Hackathon have informed this document.
   
  Personnel:

  Russ Housley is the document shepherd.
  Deb Cooley is the responsible area director.


(3) Briefly describe the review of this document that was performed by
the Document Shepherd.  If this version of the document is not ready for
publication, please explain why the document is being forwarded to the
IESG.

  The document shepherd did a thorough review of the document during
  WG Last Call.  All issues that were raised during WG Last Call have
  been resolved.


(4) Does the document Shepherd have any concerns about the depth or
breadth of the reviews that have been performed?

  No concerns.


(5) Do portions of the document need review from a particular or from
broader perspective, e.g., security, operational complexity, AAA, DNS,
DHCP, XML, or internationalization?  If so, describe the review that took
place.

  No concerns.


(6) Describe any specific concerns or issues that the Document Shepherd
has with this document that the Responsible Area Director and/or the IESG
should be aware of?  For example, perhaps he or she is uncomfortable with
certain parts of the document, or has concerns whether there really is a
need for it.  In any event, if the WG has discussed those issues and has
indicated that it still wishes to advance the document, detail those
concerns here.

  No concerns.


(7) Has each author confirmed that any and all appropriate IPR
disclosures required for full conformance with the provisions of BCP 78
and BCP 79 have already been filed.  If not, explain why?

The authors have explicitly stated that all known IPR has been
disclosed.


(8) Has an IPR disclosure been filed that references this document?  If
so, summarize any WG discussion and conclusion regarding the IPR
disclosures.

  No IPR disclosures have been filed.


(9) How solid is the WG consensus behind this document?  Does it
represent the strong concurrence of a few individuals, with others being
silent, or does the WG as a whole understand and agree with it?

  There is consensus for this document in the SUIT WG.


(10) Has anyone threatened an appeal or otherwise indicated extreme
discontent?  If so, please summarise the areas of conflict in separate
email messages to the Responsible Area Director.  (It should be in a
separate email because this questionnaire is publicly available.)

  No one has threatened an appeal.


(11) Identify any ID nits the Document Shepherd has found in this
document.  (See http://www.ietf.org/tools/idnits/ and the Internet-Drafts
Checklist).  Boilerplate checks are not enough; this check needs to be
thorough.

  IDnits gets really confused processing the CCDL in Appendix A.  It
  seems to think thet things in square brackets are missing references.


(12) Describe how the document meets any required formal review criteria,
such as the MIB Doctor, media type, and URI type reviews.

  No special reviews are needed.  CBOR experts have looked at
  Appendix A.


(13) Have all references within this document been identified as either
normative or informative?

  Yes.


(14) Are there normative references to documents that are not ready for
advancement or are otherwise in an unclear state?  If such normative
references exist, what is the plan for their completion?

  No.


(15) Are there downward normative references references (see RFC 3967)?
If so, list these downward references to support the Area Director in the
Last Call procedure.

  There are no downward normative references.


(16) Will publication of this document change the status of any existing
RFCs?  Are those RFCs listed on the title page header, listed in the
abstract, and discussed in the introduction?  If the RFCs are not listed
in the Abstract and Introduction, explain why, and point to the part of
the document where the relationship of this document to the other RFCs is
discussed.  If this information is not in the document, explain why the
WG considers it unnecessary.

  No.


(17) Describe the Document Shepherd's review of the IANA considerations
section, especially with regard to its consistency with the body of the
document.  Confirm that all protocol extensions that the document makes
are associated with the appropriate reservations in IANA registries.
Confirm that any referenced IANA registries have been clearly identified.
Confirm that newly created IANA registries include a detailed
specification of the initial contents for the registry, that allocations
procedures for future registrations are defined, and a reasonable name
for the new registry has been suggested (see RFC 5226).

  Section 6 describes a new registry to be created by IANA.


(18) List any new IANA registries that require Expert Review for future
allocations.  Provide any public guidance that the IESG would find useful
in selecting the IANA Experts for these new registries.

  No Expert Review registries are talked about in this document.


(19) Describe reviews and automated checks performed by the Document
Shepherd to validate sections of the document written in a formal
language, such as XML code, BNF rules, MIB definitions, etc.

  None are needed.
2024-11-26
08 Akira Tsukamoto IETF WG state changed to Submitted to IESG for Publication from WG Consensus: Waiting for Write-Up
2024-11-26
08 Akira Tsukamoto IESG state changed to Publication Requested from I-D Exists
2024-11-26
08 (System) Changed action holders to Deb Cooley (IESG state changed)
2024-11-26
08 Akira Tsukamoto Responsible AD changed to Deb Cooley
2024-11-26
08 Akira Tsukamoto Document is now in IESG state Publication Requested
2024-11-26
08 Akira Tsukamoto
Shepherd Write-up for draft-ietf-suit-mti-08


(1) What type of RFC is being requested (BCP, Proposed Standard, Internet
Standard, Informational, Experimental, or Historic)?  Why is this the …
Shepherd Write-up for draft-ietf-suit-mti-08


(1) What type of RFC is being requested (BCP, Proposed Standard, Internet
Standard, Informational, Experimental, or Historic)?  Why is this the
proper type of RFC?  Is this type of RFC indicated in the title page
header?

  Proposed Standard.  Yes, the header calls for a Standards Track RFC.


(2) The IESG approval announcement includes a Document Announcement
Write-Up.  Please provide such a Document Announcement Write-Up.  Recent
examples can be found in the "Action" announcements for approved
documents.  The approval announcement contains the following sections:

  Technical Summary:

  This document specifies cryptographic algorithms to be used with
  the SUIT manifest (see draft-ietf-suit-manifest).  These are the
  mandatory-to-implement algorithms to ensure interoperability.

  Working Group Summary:

  There is consensus for this document in the SUIT WG.

  Document Quality:

  Projects at the IETF Hackathon have informed this document.
   
  Personnel:

  Russ Housley is the document shepherd.
  Deb Cooley is the responsible area director.


(3) Briefly describe the review of this document that was performed by
the Document Shepherd.  If this version of the document is not ready for
publication, please explain why the document is being forwarded to the
IESG.

  The document shepherd did a thorough review of the document during
  WG Last Call.  All issues that were raised during WG Last Call have
  been resolved.


(4) Does the document Shepherd have any concerns about the depth or
breadth of the reviews that have been performed?

  No concerns.


(5) Do portions of the document need review from a particular or from
broader perspective, e.g., security, operational complexity, AAA, DNS,
DHCP, XML, or internationalization?  If so, describe the review that took
place.

  No concerns.


(6) Describe any specific concerns or issues that the Document Shepherd
has with this document that the Responsible Area Director and/or the IESG
should be aware of?  For example, perhaps he or she is uncomfortable with
certain parts of the document, or has concerns whether there really is a
need for it.  In any event, if the WG has discussed those issues and has
indicated that it still wishes to advance the document, detail those
concerns here.

  No concerns.


(7) Has each author confirmed that any and all appropriate IPR
disclosures required for full conformance with the provisions of BCP 78
and BCP 79 have already been filed.  If not, explain why?

The authors have explicitly stated that all known IPR has been
disclosed.


(8) Has an IPR disclosure been filed that references this document?  If
so, summarize any WG discussion and conclusion regarding the IPR
disclosures.

  No IPR disclosures have been filed.


(9) How solid is the WG consensus behind this document?  Does it
represent the strong concurrence of a few individuals, with others being
silent, or does the WG as a whole understand and agree with it?

  There is consensus for this document in the SUIT WG.


(10) Has anyone threatened an appeal or otherwise indicated extreme
discontent?  If so, please summarise the areas of conflict in separate
email messages to the Responsible Area Director.  (It should be in a
separate email because this questionnaire is publicly available.)

  No one has threatened an appeal.


(11) Identify any ID nits the Document Shepherd has found in this
document.  (See http://www.ietf.org/tools/idnits/ and the Internet-Drafts
Checklist).  Boilerplate checks are not enough; this check needs to be
thorough.

  IDnits gets really confused processing the CCDL in Appendix A.  It
  seems to think thet things in square brackets are missing references.


(12) Describe how the document meets any required formal review criteria,
such as the MIB Doctor, media type, and URI type reviews.

  No special reviews are needed.  CBOR experts have looked at
  Appendix A.


(13) Have all references within this document been identified as either
normative or informative?

  Yes.


(14) Are there normative references to documents that are not ready for
advancement or are otherwise in an unclear state?  If such normative
references exist, what is the plan for their completion?

  No.


(15) Are there downward normative references references (see RFC 3967)?
If so, list these downward references to support the Area Director in the
Last Call procedure.

  There are no downward normative references.


(16) Will publication of this document change the status of any existing
RFCs?  Are those RFCs listed on the title page header, listed in the
abstract, and discussed in the introduction?  If the RFCs are not listed
in the Abstract and Introduction, explain why, and point to the part of
the document where the relationship of this document to the other RFCs is
discussed.  If this information is not in the document, explain why the
WG considers it unnecessary.

  No.


(17) Describe the Document Shepherd's review of the IANA considerations
section, especially with regard to its consistency with the body of the
document.  Confirm that all protocol extensions that the document makes
are associated with the appropriate reservations in IANA registries.
Confirm that any referenced IANA registries have been clearly identified.
Confirm that newly created IANA registries include a detailed
specification of the initial contents for the registry, that allocations
procedures for future registrations are defined, and a reasonable name
for the new registry has been suggested (see RFC 5226).

  Section 6 describes a new registry to be created by IANA.


(18) List any new IANA registries that require Expert Review for future
allocations.  Provide any public guidance that the IESG would find useful
in selecting the IANA Experts for these new registries.

  No Expert Review registries are talked about in this document.


(19) Describe reviews and automated checks performed by the Document
Shepherd to validate sections of the document written in a formal
language, such as XML code, BNF rules, MIB definitions, etc.

  None are needed.
2024-11-07
08 David Waltermire Document shepherd changed to Russ Housley
2024-11-04
08 David Waltermire Document shepherd changed to (None)
2024-10-21
08 Brendan Moran New version available: draft-ietf-suit-mti-08.txt
2024-10-21
08 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2024-10-21
08 Brendan Moran Uploaded new revision
2024-10-21
07 Brendan Moran New version available: draft-ietf-suit-mti-07.txt
2024-10-21
07 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2024-10-21
07 Brendan Moran Uploaded new revision
2024-07-08
06 Brendan Moran New version available: draft-ietf-suit-mti-06.txt
2024-07-08
06 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2024-07-08
06 Brendan Moran Uploaded new revision
2024-06-04
05 Akira Tsukamoto Changed document external resources from:

github_repo https://github.com/bremoran/suit-mti

to:

github_repo https://github.com/suit-wg/suit-mti
2024-03-20
05 David Waltermire Notification list changed to housley@vigilsec.com, davewaltermire@gmail.com from housley@vigilsec.com because the document shepherd was set
2024-03-20
05 David Waltermire Document shepherd changed to David Waltermire
2024-02-12
05 Brendan Moran New version available: draft-ietf-suit-mti-05.txt
2024-02-12
05 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2024-02-12
05 Brendan Moran Uploaded new revision
2024-01-23
04 Brendan Moran New version available: draft-ietf-suit-mti-04.txt
2024-01-23
04 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2024-01-23
04 Brendan Moran Uploaded new revision
2023-11-09
03 David Waltermire IETF WG state changed to WG Consensus: Waiting for Write-Up from In WG Last Call
2023-11-04
03 David Waltermire Added to session: IETF-118: suit  Tue-1600
2023-10-23
03 Brendan Moran New version available: draft-ietf-suit-mti-03.txt
2023-10-23
03 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2023-10-23
03 Brendan Moran Uploaded new revision
2023-09-11
02 Dave Thaler Added to session: interim-2023-suit-01
2023-09-05
02 Russ Housley IETF WG state changed to In WG Last Call from WG Document
2023-09-01
02 Brendan Moran New version available: draft-ietf-suit-mti-02.txt
2023-09-01
02 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2023-09-01
02 Brendan Moran Uploaded new revision
2023-07-24
01 Dave Thaler Changed consensus to Yes from Unknown
2023-07-24
01 Dave Thaler Intended Status changed to Proposed Standard from None
2023-07-24
01 Dave Thaler Notification list changed to housley@vigilsec.com because the document shepherd was set
2023-07-24
01 Dave Thaler Document shepherd changed to Russ Housley
2023-07-24
01 Dave Thaler Added to session: IETF-117: suit  Mon-2230
2023-07-05
01 Brendan Moran New version available: draft-ietf-suit-mti-01.txt
2023-07-05
01 Brendan Moran New version accepted (logged-in submitter: Brendan Moran)
2023-07-05
01 Brendan Moran Uploaded new revision
2023-03-29
00 Dave Thaler Changed document external resources from: None to:

github_repo https://github.com/bremoran/suit-mti
2023-03-14
00 Russ Housley Added to session: IETF-116: suit  Thu-0400
2023-03-13
00 Russ Housley This document now replaces draft-moran-suit-mti instead of None
2023-03-13
00 Brendan Moran New version available: draft-ietf-suit-mti-00.txt
2023-03-13
00 Russ Housley WG -00 approved
2023-03-13
00 Brendan Moran Set submitter to "Brendan Moran ", replaces to draft-moran-suit-mti and sent approval email to group chairs: suit-chairs@ietf.org
2023-03-13
00 Brendan Moran Uploaded new revision