Skip to main content

Early Review of draft-ietf-scitt-receipts-ccf-profile-01
review-ietf-scitt-receipts-ccf-profile-01-secdir-early-sheffer-2026-04-19-00

Request Review of draft-ietf-scitt-receipts-ccf-profile
Requested revision No specific revision (document currently at 04)
Type Early Review
Team Security Area Directorate (secdir)
Deadline 2026-05-15
Requested 2026-03-30
Requested by Nicole Bates
Authors Henk Birkholz , Antoine Delignat-Lavaud , Cedric Fournet , Amaury Chamayou
I-D last updated 2026-07-01 (Latest revision 2026-06-24)
Completed reviews Genart Early review of -01 by Christer Holmberg (diff)
Secdir Early review of -01 by Yaron Sheffer (diff)
Comments
This document was adopted by the Working Group during IETF 124 and is a profile for COSE Receipts (https://datatracker.ietf.org/doc/draft-ietf-cose-merkle-tree-proofs/) currently in AUTH48. It has been reviewed by several community members and there is no outstanding feedback from the SCITT Working Group. This document would benefit from an early review beyond the SCITT Working Group before proceeding to WGLC.
Assignment Reviewer Yaron Sheffer
State Completed
Request Early review on draft-ietf-scitt-receipts-ccf-profile by Security Area Directorate Assigned
Posted at https://mailarchive.ietf.org/arch/msg/secdir/-38iA-exckQP9UXtVBRKIpLb2kM
Reviewed revision 01 (document currently at 04)
Result Ready
Completed 2026-04-19
review-ietf-scitt-receipts-ccf-profile-01-secdir-early-sheffer-2026-04-19-00
This document defines a new Verifiable Data Structure for SCITT, one based on
CCF ledgers.

I am not an expert on either SCITT or CCF. However the draft seems simple
enough (it's basically formalizing the structures into CDDL), that I believe
the Security Considerations are appropriate.