
From nobody Thu Nov  7 12:44:31 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A84F120975; Thu,  7 Nov 2019 12:44:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.554
X-Spam-Level: 
X-Spam-Status: No, score=-1.554 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.082, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_MIME_MALF=0.01] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cgf8JItfUOkU; Thu,  7 Nov 2019 12:44:28 -0800 (PST)
Received: from mail-ot1-f46.google.com (mail-ot1-f46.google.com [209.85.210.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D0CD912095E; Thu,  7 Nov 2019 12:44:27 -0800 (PST)
Received: by mail-ot1-f46.google.com with SMTP id z6so3256205otb.2; Thu, 07 Nov 2019 12:44:27 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=Eld5JYuRxwrEWp6DFQ0j6hEMJp8QtGoie15pRJ2KaqI=; b=cVCa4SkvATpJnf1qHUon3dXhsjEox0nh22rGWCcApfwznOnSHDhMd3eNT6IernTYdI IMWGa0pAtVWqqT1HKpNnW+3N4fSyld4wT7sJZe5RILT5z9r1Sp+pl6TXxB5hMHzgaxmB +V5I5FeT5Eal0acG6PUtMi/U+g6/8Crt9qBRX5lhevHARt7gWnXDefIe64HNQoopBm7A XuqAyUFsdc36AzDvVAlyzxkBUiSDLu9nq6Ium83Wto1Vza/Gm/DrpS8YPZYkVRPeiq0D wPV8/bYjqUBVBd6i9XPHD+Vuxk8ffcXV2IBW8zImXkh2OVKp+Mlo0/ONpEOS1EGUVfBx AeUA==
X-Gm-Message-State: APjAAAVGM+4biQ0VK4Ad8tfr7NMcAEzjcWRLNakKWR13eSgkyjADU9FZ 6V8z420o9rtblSYXBvIGYahIvetxAAE0bewamhPlhxRv
X-Google-Smtp-Source: APXvYqyNOsBQAI5EpYIxlpzWRz/NIubVVlhNfNqYoDkCOwK4PG7JdoBRmWxJh6/e+UGFTJcnHrw3FaxUJGzBeodijYw=
X-Received: by 2002:a9d:6b90:: with SMTP id b16mr4865310otq.37.1573159466664;  Thu, 07 Nov 2019 12:44:26 -0800 (PST)
MIME-Version: 1.0
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Thu, 7 Nov 2019 15:44:16 -0500
Message-ID: <CAMm+LwhveTLE0YEW65hZYygBMpX99TOOZSjoeGov8CjKarb3+w@mail.gmail.com>
To: wpack@ietf.org, mathmesh@ietf.org
Content-Type: multipart/alternative; boundary="0000000000002f86870596c7bbe1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/KRM-PsrI6CJ3jNroNkvTBcKW7Zo>
Subject: [Mathmesh] Interaction between MATHMESH and WPACK
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Nov 2019 20:44:29 -0000

--0000000000002f86870596c7bbe1
Content-Type: text/plain; charset="UTF-8"

Given that we have two BOFs that are considering similar technology
proposals, it seems to me that we should consider whether we need to have
two new formats or whether one can do both.

To that end, I would like to encourage some discussion of these issues
prior to Singapore. In particular, I would like to see if a common approach
is feasible. Otherwise, the risk is we end up having to support two new
formats.

Looking at the various WPACK proposals, I can see two possible paths. One
is to work out some way to cram what is wanted into ZIP or MHTML. The
objective being 'code reuse'. Which is great in theory but only if it is
possible to reuse the existing code. Re-use of existing design is
considerably less appealing and especially so if we end up needing to do
backwards compatibility etc.

This also applies to the attempt to reuse parts of HTML. I stopped being
active in HTML when we were still trying to move from 1.0 to 1.1. It was
already clear that RFC822 header syntax was a major constraint but it was
too late to change that decision without a complete redesign. Which we
couldn't even get to in HTTP/2 and are only just starting to look at for
HTTP/3. WPACK should attempt to hit the target where it is going to be in
the future, not where it is now. Some of us have been through signing
headers in the world of DKIM. It was necessary but it certainly wasn't at
all pleasant.

So what I would like to see WPACK do for its own sake even if it is never
taken up in the world of HTTP, is to introduce the structured separation of
headers into functional units that we wanted in HTTP/1.1 (Simon Spero
tried) but couldn't do. In other words instead of

Connection: Keep-Alive
Content-Type: text/html
Date: blah
Content-Encoding: gzip

We should have had (using JSON for clarity but at the time it was
S-expressions being discussed)

Connection: Keep-Alive
Date: blah
Content-Meta {
  "type":"text/html"
  "Content-Encoding" : "gzip" }

If we had had this type of separation, HTTP/1.1 would have been a lot
easier.

The protocol headers can and do change in transit. But if the content
metadata had been collected together in one place it should actually be
unmolested end-to-end unless the content itself had been changed. It does
present the material in a form that allows it to be signed.

I don't think the choice of JSON or CBOR is particularly consequential. But
the browser is going to have a JSON parser which is why I focus on that.

Providing a ZIP like capability does not require us to go any further than
content metadata. But WPACK potentially requires a bit more as we are not
just looking to display the content to the user, we want to push it into
their browser cache. And so it is not just the content and associated
metadata that are at issue here, it is also the binding of that data to the
resource identifier. So what we are looking at is actually something more
like:

Resource {
  "uri" : "http://example.com/fred.html"
  "expires" : "2019-dec-01: blah"
  "Content-Meta" : {
    "type":"text/html"
    "Content-Encoding" : "gzip" }

And this could potentially be signed separately in certain contexts.

--0000000000002f86870596c7bbe1
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">Giv=
en that we have two BOFs that are considering similar technology proposals,=
 it seems to me that we should consider whether we need to have two new for=
mats or whether one can do both.</div><div class=3D"gmail_default" style=3D=
"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size=
:small">To that end, I would like to encourage some discussion of these iss=
ues prior to Singapore. In particular, I would like to see if a common appr=
oach is feasible. Otherwise, the risk is we end up having to support two=C2=
=A0new formats.</div><div class=3D"gmail_default" style=3D"font-size:small"=
><br></div><div class=3D"gmail_default" style=3D"font-size:small">Looking a=
t the various WPACK proposals, I can see two possible paths. One is to work=
 out some way to cram what is wanted into ZIP or MHTML. The objective being=
 &#39;code reuse&#39;. Which is great in theory but only if it is possible =
to reuse the existing code. Re-use of existing design is considerably less =
appealing and especially so if we end up needing to do backwards compatibil=
ity=C2=A0etc.</div><div class=3D"gmail_default" style=3D"font-size:small"><=
br></div><div class=3D"gmail_default" style=3D"font-size:small">This also a=
pplies to the attempt to reuse parts of HTML. I stopped being active in HTM=
L when we were still trying to move from 1.0 to 1.1. It was already clear=
=C2=A0that RFC822 header syntax was a major constraint but it was too late =
to change that decision without a complete redesign. Which we couldn&#39;t =
even get to in HTTP/2 and are only just starting to look at for HTTP/3. WPA=
CK should attempt to hit the target where it is going to be in the future, =
not where it is now. Some of us have been through signing headers in the wo=
rld of DKIM. It was necessary but it certainly wasn&#39;t at all pleasant.<=
/div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div =
class=3D"gmail_default" style=3D"font-size:small">So what I would like to s=
ee WPACK do for its own sake even if it is never taken up in the world of H=
TTP, is to introduce the structured separation of headers into functional u=
nits that we wanted in HTTP/1.1 (Simon Spero tried) but couldn&#39;t do. In=
 other words instead of</div><div class=3D"gmail_default" style=3D"font-siz=
e:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">C=
onnection: Keep-Alive</div><div class=3D"gmail_default" style=3D"font-size:=
small">Content-Type: text/html</div><div class=3D"gmail_default" style=3D"f=
ont-size:small">Date: blah</div><div class=3D"gmail_default" style=3D"font-=
size:small">Content-Encoding: gzip</div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small">We should have had (using JSON for clarity but at the time it wa=
s S-expressions being discussed)</div><div class=3D"gmail_default" style=3D=
"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size=
:small"><div class=3D"gmail_default">Connection: Keep-Alive</div><div class=
=3D"gmail_default">Date: blah=C2=A0=C2=A0<br></div><div class=3D"gmail_defa=
ult">Content-Meta {</div><div class=3D"gmail_default">=C2=A0 &quot;type&quo=
t;:&quot;text/html&quot;</div><div class=3D"gmail_default">=C2=A0 &quot;Con=
tent-Encoding&quot; : &quot;gzip&quot; }</div><div class=3D"gmail_default">=
<br></div><div class=3D"gmail_default">If we had had this type of separatio=
n, HTTP/1.1 would have been a lot easier.=C2=A0 =C2=A0<br></div><div class=
=3D"gmail_default"><br></div><div class=3D"gmail_default">The protocol head=
ers can and do change in transit. But if the content metadata had been coll=
ected together in one place it should actually be unmolested end-to-end unl=
ess the content itself had been changed. It does present the material in a =
form that allows it to be signed.</div><div class=3D"gmail_default"><br></d=
iv><div class=3D"gmail_default">I don&#39;t think the choice of JSON or CBO=
R is particularly consequential. But the browser is going to have a JSON pa=
rser which is why I focus on that.</div><div class=3D"gmail_default"></div>=
</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div=
 class=3D"gmail_default" style=3D"font-size:small">Providing a ZIP like cap=
ability does not require us to go any further than content metadata. But WP=
ACK potentially requires a bit more as we are not just looking to display t=
he content to the user, we want to push it into their browser cache. And so=
 it is not just the content and associated metadata that are at issue here,=
 it is also the binding of that data to the resource identifier. So what we=
 are looking at is actually something more like:</div><div class=3D"gmail_d=
efault" style=3D"font-size:small"><br></div><div class=3D"gmail_default" st=
yle=3D"font-size:small"><div class=3D"gmail_default">Resource {</div><div c=
lass=3D"gmail_default">=C2=A0 &quot;uri&quot; : &quot;<a href=3D"http://exa=
mple.com/fred.html">http://example.com/fred.html</a>&quot;</div><div class=
=3D"gmail_default">=C2=A0 &quot;expires&quot; : &quot;2019-dec-01: blah&quo=
t;=C2=A0=C2=A0<br></div><div class=3D"gmail_default">=C2=A0 &quot;Content-M=
eta&quot; : {</div><div class=3D"gmail_default">=C2=A0 =C2=A0 &quot;type&qu=
ot;:&quot;text/html&quot;</div><div class=3D"gmail_default">=C2=A0 =C2=A0 &=
quot;Content-Encoding&quot; : &quot;gzip&quot; }</div></div><div class=3D"g=
mail_default" style=3D"font-size:small"><br></div><div class=3D"gmail_defau=
lt" style=3D"font-size:small">And this could potentially be signed separate=
ly in certain contexts.</div><div class=3D"gmail_default" style=3D"font-siz=
e:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small"><=
br></div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><=
div class=3D"gmail_default" style=3D"font-size:small"><br></div></div>

--0000000000002f86870596c7bbe1--


From nobody Fri Nov  8 12:33:49 2019
Return-Path: <rsalz@akamai.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2AB7E120CA3 for <mathmesh@ietfa.amsl.com>; Fri,  8 Nov 2019 12:33:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UDaZTG_m-XjV for <mathmesh@ietfa.amsl.com>; Fri,  8 Nov 2019 12:33:46 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DB5B1200E0 for <mathmesh@ietf.org>; Fri,  8 Nov 2019 12:33:45 -0800 (PST)
Received: from pps.filterd (m0050095.ppops.net [127.0.0.1]) by m0050095.ppops.net-00190b01. (8.16.0.42/8.16.0.42) with SMTP id xA8KVtR7029401 for <mathmesh@ietf.org>; Fri, 8 Nov 2019 20:33:43 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=jan2016.eng; bh=bY5uEIknITqP+YFbJZxEUigiu1ZT2el/ZLv2uxBZwOo=; b=gWUz0GEF5pPAqlxcRuHzz/X2WTWPFqgxmz+D+Qvd8BQlY4qVTRHQOkM27Qz/fGyR4EGd ZIcK/wXCWhg2D7oVGToe1KvhySbjaaWIAHtTb26PnQBzQpRhvZfENj2isTFjASIvNh0I xsMBwv4texB6aS5ExrMjnDSepLl7r/uggbUrZM3xgR18QrhlKlucOEJIefFwHc1JGZwP mrUm7KXjP/wZmjxfhlrSSSYLmwhK+G6neIGPyNLCjT171HgBI9cywEJN8X/nrOusV+5E 0MUMOh9nJ3nN7xGhcpl6/0TEBrQ6ScTQEDVHwT00D6Ua+Za7jLJ4Jmk0HexFjJkVuAp0 Iw== 
Received: from prod-mail-ppoint7 (prod-mail-ppoint7.akamai.com [96.6.114.121] (may be forged)) by m0050095.ppops.net-00190b01. with ESMTP id 2w41v44b5h-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Fri, 08 Nov 2019 20:33:43 +0000
Received: from pps.filterd (prod-mail-ppoint7.akamai.com [127.0.0.1]) by prod-mail-ppoint7.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xA8KWk6j027696 for <mathmesh@ietf.org>; Fri, 8 Nov 2019 15:33:42 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.53]) by prod-mail-ppoint7.akamai.com with ESMTP id 2w4210hwhg-5 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Fri, 08 Nov 2019 15:33:41 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb1.msg.corp.akamai.com (172.27.123.101) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Fri, 8 Nov 2019 15:33:31 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Fri, 8 Nov 2019 15:33:31 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "mathmesh@ietf.org" <mathmesh@ietf.org>
Thread-Topic: mathmesh materials
Thread-Index: AQHVlZvACbWXoDujKUiGALT00AxRgqeAiocAgADQWoCAAK+WAP//seKA
Date: Fri, 8 Nov 2019 20:33:30 +0000
Message-ID: <E98C2CBB-04B3-4145-891F-6F909C4D7FC5@akamai.com>
References: <494F3DEE-D8CF-4877-8FA0-6334702CA616@akamai.com> <CAMm+Lwh0UYjW=pJBgxwCX5_Ho+PiziUprJyzrJCMVSLYL5UdpQ@mail.gmail.com> <1443C140-5968-4805-B0C2-4630E329449C@akamai.com> <CAMm+LwgMDXFE6V5B4q4fXxu0Mp5K39MwWvg0S99cELimugDzJA@mail.gmail.com>
In-Reply-To: <CAMm+LwgMDXFE6V5B4q4fXxu0Mp5K39MwWvg0S99cELimugDzJA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/10.1f.0.191103
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.35.243]
Content-Type: multipart/alternative; boundary="_000_E98C2CBB04B34145891F6F909C4D7FC5akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-08_07:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1910280000 definitions=main-1911080198
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-08_07:2019-11-08,2019-11-08 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 lowpriorityscore=0 phishscore=0 impostorscore=0 bulkscore=0 mlxscore=0 malwarescore=0 priorityscore=1501 mlxlogscore=999 adultscore=0 suspectscore=0 spamscore=0 clxscore=1011 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911080198
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/TTA9ojUpRUOzF0tzCA_2R3lffTM>
Subject: [Mathmesh] FW: mathmesh materials
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Nov 2019 20:33:48 -0000

--_000_E98C2CBB04B34145891F6F909C4D7FC5akamaicom_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

R3JlZXRpbmdzIQ0KDQoNCg0KV2VzIEhhcmRha2VyIGFuZCBJIGFyZSBjby1jaGFpcnMgb2YgdGhl
IE1hdGhlbWF0aWNhbCBNZXNoIEJvRiB3aGljaCBpcyBtZWV0aW5nIE1vbmRheSwgZmlyc3Qgc2Vz
c2lvbi4NCg0KDQoNCldlIGFyZSBzdGlsbCB3b3JraW5nIG91dCB0aGUgYWdlbmRhIOKAkyB0aGUg
YmlnZ2VzdCBnb2FsIHdpbGwgYmUgd2hhdCBwYXJ0cyBvZiB0aGUgcHJvYmxlbSB0byBhZGRyZXNz
IOKAkyBidXQgaGVyZSBpcyBhIGxpc3Qgb2YgZHJhZnRzLCBmcm9tIFBoaWxsaXAuIFRob3VnaHRz
IG9uIHRoZSBhZ2VuZGEgYW5kIHByb2Nlc3Mgc2hvdWxkIGJlIHBvc3RlZCBoZXJlLg0KDQoNCg0K
MS4gQXJjaGl0ZWN0dXJlIFtkcmFmdC1oYWxsYW1iYWtlci1tZXNoLWFyY2hpdGVjdHVyZS5odG1s
XQ0KDQpQcm92aWRlcyBhbiBvdmVydmlldyBvZiB0aGUgTWVzaCBhcyBhIHN5c3RlbSBhbmQgdGhl
IHJlbGF0aW9uc2hpcCBiZXR3ZWVuIGl0cw0KDQpjb25zdGl0dWVudCBwYXJ0cy4NCg0KDQoNCjIu
IFVuaWZvcm0gRGF0YSBGaW5nZXJwcmludCBbZHJhZnQtaGFsbGFtYmFrZXItbWVzaC11ZGZdLg0K
DQpEZXNjcmliZXMgdGhlIFVERiBmb3JtYXQgdXNlZCB0byByZXByZXNlbnQgY3J5cHRvZ3JhcGhp
YyBub25jZXMsIGtleXMgYW5kDQoNCmNvbnRlbnQgZGlnZXN0cyBpbiB0aGUgTWVzaCBhbmQgdGhl
IHVzZSBvZiBFbmNyeXB0ZWQgQXV0aGVudGljYXRlZCBSZXNvdXJjZQ0KDQpMb2NhdG9ycyAoRUFS
THMpIGFuZCBTdHJvbmcgSW50ZXJuZXQgTmFtZXMgKFNJTnMpIHRoYXQgYnVpbGQgb24gdGhlIFVE
Rg0KDQpwbGF0Zm9ybS4NCg0KDQoNCjMgRGF0YSBhdCBSZXN0IEVuY3J5cHRpb24gW2RyYWZ0LWhh
bGxhbWJha2VyLW1lc2gtZGFyZV0uDQoNCkRlc2NyaWJlcyB0aGUgY3J5cHRvZ3JhcGhpYyBtZXNz
YWdlIGFuZCBhcHBlbmQtb25seSBzZXF1ZW5jZSBmb3JtYXRzIHVzZWQgaW4NCg0KTWVzaCBhcHBs
aWNhdGlvbnMgYW5kIHRoZSBNZXNoIFNlcnZpY2UgcHJvdG9jb2wuDQoNCg0KDQo0IFNjaGVtYSBS
ZWZlcmVuY2UgW2RyYWZ0LWhhbGxhbWJha2VyLW1lc2gtc2NoZW1hXS4NCg0KRGVzY3JpYmVzIHRo
ZSBzeW50YXggYW5kIHNlbWFudGljcyBvZiBNZXNoIFByb2ZpbGVzLCBDb250YWluZXIgRW50cmll
cyBhbmQNCg0KTWVzaCBNZXNzYWdlcyBhbmQgdGhlaXIgdXNlIGluIE1lc2ggQXBwbGljYXRpb25z
Lg0KDQoNCg0KNSBQcm90b2NvbCBSZWZlcmVuY2UgW2RyYWZ0LWhhbGxhbWJha2VyLW1lc2gtcHJv
dG9jb2xdLg0KDQpEZXNjcmliZXMgdGhlIE1lc2ggU2VydmljZSBQcm90b2NvbC4NCg0KDQoNCjYg
Q3J5cHRvZ3JhcGhpYyBBbGdvcml0aG1zIFtkcmFmdC1oYWxsYW1iYWtlci1tZXNoLWNyeXB0b2dy
YXBoeV0uDQoNCkRlc2NyaWJlcyB0aGUgcmVjb21tZW5kZWQgYW5kIHJlcXVpcmVkIGFsZ29yaXRo
bSBzdWl0ZXMgZm9yIE1lc2ggYXBwbGljYXRpb25zDQoNCmFuZCB0aGUgaW1wbGVtZW50YXRpb24g
b2YgdGhlIG11bHRpLXBhcnR5IGNyeXB0b2dyYXBoeSB0ZWNobmlxdWVzIHVzZWQgaW4gdGhlDQoN
Ck1lc2guDQoNCg0K

--_000_E98C2CBB04B34145891F6F909C4D7FC5akamaicom_
Content-Type: text/html; charset="utf-8"
Content-ID: <472138ACFC4D0948A778CCF41BF3523E@akamai.com>
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6bz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6b2ZmaWNlIiB4
bWxuczp3PSJ1cm46c2NoZW1hcy1taWNyb3NvZnQtY29tOm9mZmljZTp3b3JkIiB4bWxuczptPSJo
dHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL29mZmljZS8yMDA0LzEyL29tbWwiIHhtbG5zPSJo
dHRwOi8vd3d3LnczLm9yZy9UUi9SRUMtaHRtbDQwIj4NCjxoZWFkPg0KPG1ldGEgaHR0cC1lcXVp
dj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiPg0KPG1l
dGEgbmFtZT0iR2VuZXJhdG9yIiBjb250ZW50PSJNaWNyb3NvZnQgV29yZCAxNSAoZmlsdGVyZWQg
bWVkaXVtKSI+DQo8c3R5bGU+PCEtLQ0KLyogRm9udCBEZWZpbml0aW9ucyAqLw0KQGZvbnQtZmFj
ZQ0KCXtmb250LWZhbWlseToiQ2FtYnJpYSBNYXRoIjsNCglwYW5vc2UtMToyIDQgNSAzIDUgNCA2
IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Q2FsaWJyaTsNCglwYW5vc2UtMToy
IDE1IDUgMiAyIDIgNCAzIDIgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0KcC5Nc29Ob3Jt
YWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGluOw0KCW1hcmdpbi1i
b3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTEuMHB0Ow0KCWZvbnQtZmFtaWx5OiJDYWxpYnJp
IixzYW5zLXNlcmlmO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXBy
aW9yaXR5Ojk5Ow0KCWNvbG9yOmJsdWU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQph
OnZpc2l0ZWQsIHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9yaXR5
Ojk5Ow0KCWNvbG9yOnB1cnBsZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCnAuTXNv
UGxhaW5UZXh0LCBsaS5Nc29QbGFpblRleHQsIGRpdi5Nc29QbGFpblRleHQNCgl7bXNvLXN0eWxl
LXByaW9yaXR5Ojk5Ow0KCW1zby1zdHlsZS1saW5rOiJQbGFpbiBUZXh0IENoYXIiOw0KCW1hcmdp
bjowaW47DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMS4wcHQ7DQoJZm9u
dC1mYW1pbHk6IkNhbGlicmkiLHNhbnMtc2VyaWY7fQ0KcC5tc29ub3JtYWwwLCBsaS5tc29ub3Jt
YWwwLCBkaXYubXNvbm9ybWFsMA0KCXttc28tc3R5bGUtbmFtZTptc29ub3JtYWw7DQoJbXNvLW1h
cmdpbi10b3AtYWx0OmF1dG87DQoJbWFyZ2luLXJpZ2h0OjBpbjsNCgltc28tbWFyZ2luLWJvdHRv
bS1hbHQ6YXV0bzsNCgltYXJnaW4tbGVmdDowaW47DQoJZm9udC1zaXplOjExLjBwdDsNCglmb250
LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQpzcGFuLkVtYWlsU3R5bGUxOA0KCXttc28t
c3R5bGUtdHlwZTpwZXJzb25hbDsNCglmb250LWZhbWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjsN
Cgljb2xvcjp3aW5kb3d0ZXh0O30NCnNwYW4uUGxhaW5UZXh0Q2hhcg0KCXttc28tc3R5bGUtbmFt
ZToiUGxhaW4gVGV4dCBDaGFyIjsNCgltc28tc3R5bGUtcHJpb3JpdHk6OTk7DQoJbXNvLXN0eWxl
LWxpbms6IlBsYWluIFRleHQiOw0KCWZvbnQtZmFtaWx5OiJDYWxpYnJpIixzYW5zLXNlcmlmO30N
Ci5Nc29DaHBEZWZhdWx0DQoJe21zby1zdHlsZS10eXBlOmV4cG9ydC1vbmx5Ow0KCWZvbnQtc2l6
ZToxMC4wcHQ7fQ0KQHBhZ2UgV29yZFNlY3Rpb24xDQoJe3NpemU6OC41aW4gMTEuMGluOw0KCW1h
cmdpbjoxLjBpbiAxLjBpbiAxLjBpbiAxLjBpbjt9DQpkaXYuV29yZFNlY3Rpb24xDQoJe3BhZ2U6
V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+DQo8L2hlYWQ+DQo8Ym9keSBsYW5nPSJFTi1VUyIg
bGluaz0iYmx1ZSIgdmxpbms9InB1cnBsZSI+DQo8ZGl2IGNsYXNzPSJXb3JkU2VjdGlvbjEiPg0K
PHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+R3JlZXRpbmdzITxvOnA+PC9vOnA+PC9wPg0KPHAgY2xh
c3M9Ik1zb1BsYWluVGV4dCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxh
aW5UZXh0Ij5XZXMgSGFyZGFrZXIgYW5kIEkgYXJlIGNvLWNoYWlycyBvZiB0aGUgTWF0aGVtYXRp
Y2FsIE1lc2ggQm9GIHdoaWNoIGlzIG1lZXRpbmcgTW9uZGF5LCBmaXJzdCBzZXNzaW9uLjxvOnA+
PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+PG86cD4mbmJzcDs8L286cD48L3A+
DQo8cCBjbGFzcz0iTXNvUGxhaW5UZXh0Ij5XZSBhcmUgc3RpbGwgd29ya2luZyBvdXQgdGhlIGFn
ZW5kYSDigJMgdGhlIGJpZ2dlc3QgZ29hbCB3aWxsIGJlIHdoYXQgcGFydHMgb2YgdGhlIHByb2Js
ZW0gdG8gYWRkcmVzcyDigJMgYnV0IGhlcmUgaXMgYSBsaXN0IG9mIGRyYWZ0cywgZnJvbSBQaGls
bGlwLiBUaG91Z2h0cyBvbiB0aGUgYWdlbmRhIGFuZCBwcm9jZXNzIHNob3VsZCBiZSBwb3N0ZWQg
aGVyZS48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPjxvOnA+Jm5ic3A7
PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+MS4gQXJjaGl0ZWN0dXJlIFtkcmFm
dC1oYWxsYW1iYWtlci1tZXNoLWFyY2hpdGVjdHVyZS5odG1sXTxvOnA+PC9vOnA+PC9wPg0KPHAg
Y2xhc3M9Ik1zb1BsYWluVGV4dCI+UHJvdmlkZXMgYW4gb3ZlcnZpZXcgb2YgdGhlIE1lc2ggYXMg
YSBzeXN0ZW0gYW5kIHRoZSByZWxhdGlvbnNoaXAgYmV0d2VlbiBpdHMNCjxvOnA+PC9vOnA+PC9w
Pg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+Y29uc3RpdHVlbnQgcGFydHMuPG86cD48L286cD48
L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5UZXh0Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxwIGNs
YXNzPSJNc29QbGFpblRleHQiPjIuIFVuaWZvcm0gRGF0YSBGaW5nZXJwcmludCBbZHJhZnQtaGFs
bGFtYmFrZXItbWVzaC11ZGZdLjxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4
dCI+RGVzY3JpYmVzIHRoZSBVREYgZm9ybWF0IHVzZWQgdG8gcmVwcmVzZW50IGNyeXB0b2dyYXBo
aWMgbm9uY2VzLCBrZXlzIGFuZA0KPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5U
ZXh0Ij5jb250ZW50IGRpZ2VzdHMgaW4gdGhlIE1lc2ggYW5kIHRoZSB1c2Ugb2YgRW5jcnlwdGVk
IEF1dGhlbnRpY2F0ZWQgUmVzb3VyY2U8bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFp
blRleHQiPkxvY2F0b3JzIChFQVJMcykgYW5kIFN0cm9uZyBJbnRlcm5ldCBOYW1lcyAoU0lOcykg
dGhhdCBidWlsZCBvbiB0aGUgVURGPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5U
ZXh0Ij5wbGF0Zm9ybS48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPjxv
OnA+Jm5ic3A7PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+MyBEYXRhIGF0IFJl
c3QgRW5jcnlwdGlvbiBbZHJhZnQtaGFsbGFtYmFrZXItbWVzaC1kYXJlXS48bzpwPjwvbzpwPjwv
cD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPkRlc2NyaWJlcyB0aGUgY3J5cHRvZ3JhcGhpYyBt
ZXNzYWdlIGFuZCBhcHBlbmQtb25seSBzZXF1ZW5jZSBmb3JtYXRzIHVzZWQgaW4NCjxvOnA+PC9v
OnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+TWVzaCBhcHBsaWNhdGlvbnMgYW5kIHRo
ZSBNZXNoIFNlcnZpY2UgcHJvdG9jb2wuPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxh
aW5UZXh0Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPjQg
U2NoZW1hIFJlZmVyZW5jZSBbZHJhZnQtaGFsbGFtYmFrZXItbWVzaC1zY2hlbWFdLjxvOnA+PC9v
OnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+RGVzY3JpYmVzIHRoZSBzeW50YXggYW5k
IHNlbWFudGljcyBvZiBNZXNoIFByb2ZpbGVzLCBDb250YWluZXIgRW50cmllcyBhbmQNCjxvOnA+
PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+TWVzaCBNZXNzYWdlcyBhbmQgdGhl
aXIgdXNlIGluIE1lc2ggQXBwbGljYXRpb25zLjxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1z
b1BsYWluVGV4dCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5UZXh0
Ij41IFByb3RvY29sIFJlZmVyZW5jZSBbZHJhZnQtaGFsbGFtYmFrZXItbWVzaC1wcm90b2NvbF0u
PG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5UZXh0Ij5EZXNjcmliZXMgdGhlIE1l
c2ggU2VydmljZSBQcm90b2NvbC48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRl
eHQiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+NiBDcnlw
dG9ncmFwaGljIEFsZ29yaXRobXMgW2RyYWZ0LWhhbGxhbWJha2VyLW1lc2gtY3J5cHRvZ3JhcGh5
XS48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPkRlc2NyaWJlcyB0aGUg
cmVjb21tZW5kZWQgYW5kIHJlcXVpcmVkIGFsZ29yaXRobSBzdWl0ZXMgZm9yIE1lc2ggYXBwbGlj
YXRpb25zDQo8bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29QbGFpblRleHQiPmFuZCB0aGUg
aW1wbGVtZW50YXRpb24gb2YgdGhlIG11bHRpLXBhcnR5IGNyeXB0b2dyYXBoeSB0ZWNobmlxdWVz
IHVzZWQgaW4gdGhlPG86cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvUGxhaW5UZXh0Ij5NZXNo
LjxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb1BsYWluVGV4dCI+PG86cD4mbmJzcDs8L286
cD48L3A+DQo8L2Rpdj4NCjwvYm9keT4NCjwvaHRtbD4NCg==

--_000_E98C2CBB04B34145891F6F909C4D7FC5akamaicom_--


From nobody Fri Nov  8 14:43:35 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CAA73120072 for <mathmesh@ietfa.amsl.com>; Fri,  8 Nov 2019 14:43:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.564
X-Spam-Level: 
X-Spam-Status: No, score=-1.564 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.082, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R0ylmdTkj0qW for <mathmesh@ietfa.amsl.com>; Fri,  8 Nov 2019 14:43:32 -0800 (PST)
Received: from mail-ot1-f41.google.com (mail-ot1-f41.google.com [209.85.210.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA6E5120025 for <mathmesh@ietf.org>; Fri,  8 Nov 2019 14:43:31 -0800 (PST)
Received: by mail-ot1-f41.google.com with SMTP id u13so6601150ote.0 for <mathmesh@ietf.org>; Fri, 08 Nov 2019 14:43:31 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=eI4EJuyfuLKF9HA1Go4hSoq/EkwHaqMbjuJgT4+MiBI=; b=T2UMggvbXlvDIfgZQ4OuL9mN+aObllQemj7Fn7DwRAIsf6r7jiWJ1rHax5AJzOgPtL QGkEfwSiy8FwvDvJnbuSYo13vhPYFLC2nuqEBoycOfu7Ng6C9+YlaBdnSeAcz7JNYQe8 aBS0ZULm+qwxsTLP4v57uibSyL6zCTox3o5DsMki0pYkEwDXLHml6KNgyA18JlbHa7B7 LzkaWUk1zKY9wKavwRVK5nGiRapjKZ8hV6qCrsRdlfspUl315V0pJ+d7tx0F5w9C2e8O GRopnA8IxxaCThVoVyZ8aI8FE2csdZb75g4cHuPBYiAEHc+xIABt7ew9V8pSD1lHBEvc MDdQ==
X-Gm-Message-State: APjAAAWDD+909XPg2nLHLhkE+f0S5L28tBbC4ZCt5gCVv/r0QdJmteDS l/iFc2TD7x9M7I4vWKWCUqMvzw8O1+egUw2ww3I=
X-Google-Smtp-Source: APXvYqwzHIAL8o3Ly5CZRmlCW7uonkwWzlylDJ+qs+vZKKHnWtxzkZDUpbDnjXNhAuSRtKlCXekrlzrLJA92vLlKk5s=
X-Received: by 2002:a05:6830:2001:: with SMTP id e1mr3984886otp.48.1573253010988;  Fri, 08 Nov 2019 14:43:30 -0800 (PST)
MIME-Version: 1.0
References: <494F3DEE-D8CF-4877-8FA0-6334702CA616@akamai.com> <CAMm+Lwh0UYjW=pJBgxwCX5_Ho+PiziUprJyzrJCMVSLYL5UdpQ@mail.gmail.com> <1443C140-5968-4805-B0C2-4630E329449C@akamai.com> <CAMm+LwgMDXFE6V5B4q4fXxu0Mp5K39MwWvg0S99cELimugDzJA@mail.gmail.com> <E98C2CBB-04B3-4145-891F-6F909C4D7FC5@akamai.com>
In-Reply-To: <E98C2CBB-04B3-4145-891F-6F909C4D7FC5@akamai.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Fri, 8 Nov 2019 17:43:21 -0500
Message-ID: <CAMm+LwjphRCSpRVz9mxnq75N5NrSDJcRJ1mOTbqWWmjT2Mtafw@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: "mathmesh@ietf.org" <mathmesh@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000dca5220596dd826b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/ltT6F-0BgljCnaVw9pQjwuuns8g>
Subject: Re: [Mathmesh] FW: mathmesh materials
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Nov 2019 22:43:34 -0000

--000000000000dca5220596dd826b
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

So just to explain the constraints here, the mesh consists of three
technology components and the Mesh itself built on top. The technology
components are:

UDF (part 2)
DARE (part 3)
Meta-Cryptography (part 6)

The Mesh itself is described in parts 1, 4 & 5. Part 1 is the high level
overview and parts 4 and 5 are essentially reference.

So we can do any of UDF, DARE, Meta-Cryptography without doing the Mesh.
But the Mesh is built on top of the three tech components. It is not
possible to do the Mesh without the dependencies.

The Mesh is designed as a platform, it can be used to configure any
application and provision keys for pretty much anything. But I suggest that
we initially focus on just the one application, preferably one that
provides good 'test coverage'.

My preferred test application would be maintaining a password catalog
across connected Mesh devices. This tests out the full Mesh functionality
without requiring consideration of any external specifications. But if we
can do passwords, then the additional work required for SSH, OpenPGP,
S/MIME, etc. will be focused on the issues that are created by those
applications.



On Fri, Nov 8, 2019 at 3:33 PM Salz, Rich <rsalz@akamai.com> wrote:

> Greetings!
>
>
>
> Wes Hardaker and I are co-chairs of the Mathematical Mesh BoF which is
> meeting Monday, first session.
>
>
>
> We are still working out the agenda =E2=80=93 the biggest goal will be wh=
at parts
> of the problem to address =E2=80=93 but here is a list of drafts, from Ph=
illip.
> Thoughts on the agenda and process should be posted here.
>
>
>
> 1. Architecture [draft-hallambaker-mesh-architecture.html]
>
> Provides an overview of the Mesh as a system and the relationship between
> its
>
> constituent parts.
>
>
>
> 2. Uniform Data Fingerprint [draft-hallambaker-mesh-udf].
>
> Describes the UDF format used to represent cryptographic nonces, keys and
>
> content digests in the Mesh and the use of Encrypted Authenticated Resour=
ce
>
> Locators (EARLs) and Strong Internet Names (SINs) that build on the UDF
>
> platform.
>
>
>
> 3 Data at Rest Encryption [draft-hallambaker-mesh-dare].
>
> Describes the cryptographic message and append-only sequence formats used
> in
>
> Mesh applications and the Mesh Service protocol.
>
>
>
> 4 Schema Reference [draft-hallambaker-mesh-schema].
>
> Describes the syntax and semantics of Mesh Profiles, Container Entries an=
d
>
> Mesh Messages and their use in Mesh Applications.
>
>
>
> 5 Protocol Reference [draft-hallambaker-mesh-protocol].
>
> Describes the Mesh Service Protocol.
>
>
>
> 6 Cryptographic Algorithms [draft-hallambaker-mesh-cryptography].
>
> Describes the recommended and required algorithm suites for Mesh
> applications
>
> and the implementation of the multi-party cryptography techniques used in
> the
>
> Mesh.
>
>
> --
> Mathmesh mailing list
> Mathmesh@ietf.org
> https://www.ietf.org/mailman/listinfo/mathmesh
>

--000000000000dca5220596dd826b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">So =
just to explain the constraints here, the mesh consists of three technology=
 components and the Mesh itself built on top. The technology components are=
:</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><di=
v class=3D"gmail_default" style=3D"font-size:small">UDF (part 2)</div><div =
class=3D"gmail_default" style=3D"font-size:small">DARE (part 3)</div><div c=
lass=3D"gmail_default" style=3D"font-size:small">Meta-Cryptography (part 6)=
</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div=
 class=3D"gmail_default" style=3D"font-size:small">The Mesh itself is descr=
ibed in parts=C2=A01, 4 &amp; 5. Part 1 is the high level overview and part=
s 4 and 5 are essentially reference.</div><div class=3D"gmail_default" styl=
e=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-=
size:small">So we can do any of UDF, DARE, Meta-Cryptography without doing =
the Mesh. But the Mesh is built on top of the three tech components. It is =
not possible to do the Mesh without the dependencies.</div><div class=3D"gm=
ail_default" style=3D"font-size:small"><br></div><div class=3D"gmail_defaul=
t" style=3D"font-size:small">The Mesh is designed as a platform, it can be =
used to configure any application and provision keys for pretty much anythi=
ng. But I suggest that we initially focus on just the one application, pref=
erably one that provides good &#39;test coverage&#39;.</div><div class=3D"g=
mail_default" style=3D"font-size:small"><br></div><div class=3D"gmail_defau=
lt" style=3D"font-size:small">My preferred=C2=A0test application would be m=
aintaining a password catalog across connected Mesh devices. This tests out=
 the full Mesh functionality without requiring consideration of any externa=
l specifications. But if we can do passwords, then the additional work requ=
ired for SSH, OpenPGP, S/MIME, etc. will be focused on the issues that are =
created by those applications.</div><div class=3D"gmail_default" style=3D"f=
ont-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:s=
mall"><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Fri, Nov 8, 2019 at 3:33 PM Salz, Rich &lt;<a href=3D"ma=
ilto:rsalz@akamai.com">rsalz@akamai.com</a>&gt; wrote:<br></div><blockquote=
 class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px so=
lid rgb(204,204,204);padding-left:1ex">





<div lang=3D"EN-US">
<div class=3D"gmail-m_-6700164660867777525WordSection1">
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Greetings!<u></u><u><=
/u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Wes Hardaker and I ar=
e co-chairs of the Mathematical Mesh BoF which is meeting Monday, first ses=
sion.<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">We are still working =
out the agenda =E2=80=93 the biggest goal will be what parts of the problem=
 to address =E2=80=93 but here is a list of drafts, from Phillip. Thoughts =
on the agenda and process should be posted here.<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">1. Architecture [draf=
t-hallambaker-mesh-architecture.html]<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Provides an overview =
of the Mesh as a system and the relationship between its
<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">constituent parts.<u>=
</u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">2. Uniform Data Finge=
rprint [draft-hallambaker-mesh-udf].<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Describes the UDF for=
mat used to represent cryptographic nonces, keys and
<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">content digests in th=
e Mesh and the use of Encrypted Authenticated Resource<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Locators (EARLs) and =
Strong Internet Names (SINs) that build on the UDF<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">platform.<u></u><u></=
u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">3 Data at Rest Encryp=
tion [draft-hallambaker-mesh-dare].<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Describes the cryptog=
raphic message and append-only sequence formats used in
<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Mesh applications and=
 the Mesh Service protocol.<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">4 Schema Reference [d=
raft-hallambaker-mesh-schema].<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Describes the syntax =
and semantics of Mesh Profiles, Container Entries and
<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Mesh Messages and the=
ir use in Mesh Applications.<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">5 Protocol Reference =
[draft-hallambaker-mesh-protocol].<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Describes the Mesh Se=
rvice Protocol.<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">6 Cryptographic Algor=
ithms [draft-hallambaker-mesh-cryptography].<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Describes the recomme=
nded and required algorithm suites for Mesh applications
<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">and the implementatio=
n of the multi-party cryptography techniques used in the<u></u><u></u></p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText">Mesh.<u></u><u></u></=
p>
<p class=3D"gmail-m_-6700164660867777525MsoPlainText"><u></u>=C2=A0<u></u><=
/p>
</div>
</div>

-- <br>
Mathmesh mailing list<br>
<a href=3D"mailto:Mathmesh@ietf.org" target=3D"_blank">Mathmesh@ietf.org</a=
><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mathmesh" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mathmesh</a><br>
</blockquote></div>

--000000000000dca5220596dd826b--


From nobody Mon Nov 11 09:11:16 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBC24120A44 for <mathmesh@ietfa.amsl.com>; Mon, 11 Nov 2019 09:11:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Avbu2hEOHLQ7 for <mathmesh@ietfa.amsl.com>; Mon, 11 Nov 2019 09:11:11 -0800 (PST)
Received: from mail-oi1-f173.google.com (mail-oi1-f173.google.com [209.85.167.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2686B120A3D for <mathmesh@ietf.org>; Mon, 11 Nov 2019 09:11:11 -0800 (PST)
Received: by mail-oi1-f173.google.com with SMTP id 14so6133269oir.12 for <mathmesh@ietf.org>; Mon, 11 Nov 2019 09:11:11 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=Wqvt6NqFVYFFiuqIKErhifM0Vzx3kp/xHYsIrf0I0vE=; b=q+p6eIjJkB1UN9pHEtF70zzq4NSDHR0aZh5bAIa29QLzkuRGbAthD50txMMOXjYHrR gQWUrxiFDtpETzFP/MX2T9AgRuH0bNakLeWEO/mlR3fJA/r8czW+aOdHB4iGBCzLb7tE MqJ7t4yK+dR+Qc0DICadmoLBKSu+Kr01adtZ9AfYuievnX22nct+su3rFNWNZScgWlaO finYAkmco5LG12XEf5QAv/WjMa+n2yI5iYoeBbtMpXZZnRTVE2VnTHaivmRYPMdWKz/g +BqJ1D55IEe8b7ohnC1XTF9w45Qmwrq5Xba4LIGkiOnCD97olrFCE87k/1nfDAWXCint dEQg==
X-Gm-Message-State: APjAAAWrrv4zpuQWFeWqFq0qQSoUrsvkEVa4TGZpF2NtjnXylcLl39a2 54T+ZcBHLxIOTHvOgrXhOz9mD62Y9q03leGrEOfiNPul
X-Google-Smtp-Source: APXvYqwxRkwTPSsa2uc1xgVzBGxrp6PBm1j9kRHiLIiaTHLGlG1BZ4hZ4yE7KkW+LofINRysLUE0OEEz2eTnnj5X/nY=
X-Received: by 2002:aca:5058:: with SMTP id e85mr51750oib.100.1573492269951; Mon, 11 Nov 2019 09:11:09 -0800 (PST)
MIME-Version: 1.0
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Mon, 11 Nov 2019 12:11:00 -0500
Message-ID: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com>
To: mathmesh@ietf.org
Content-Type: multipart/alternative; boundary="000000000000ceaff205971537be"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/vNkQBUdDd7yG1CPa97MYEBeC9u8>
Subject: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Nov 2019 17:11:15 -0000

--000000000000ceaff205971537be
Content-Type: text/plain; charset="UTF-8"

I am just updating the Web site and upgrading to Bootstrap 4. In the
process, I came across this:

<!-- Latest compiled and minified CSS -->
<link rel="stylesheet" href="
https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css">
Of course downloading bootstrap from a CDN makes every bit of sense and
even better to not have to download it more than once. But lets just step
back and think about what this line of code does.

In effect, bootstrapcdn.com has just become a root of trust for my Web
pages. I have handed a vast degree of trust over to a site that I have no
direct connection to. All I did (or would have done if I wasn't a security
nut) was to cut and paste the code from a Web page giving me instructions.

Replacing the variable uri with a hardened one is much better:

<link rel="stylesheet" href="udf:
maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH4">

Of course we might well require some sort of transition strategy but it
seems we now EOL Web browsers after 8 years (IE 9 is no longer supported by
BS 4).

Content digest of the content provides a link to a fixed static version of
a resource which is exactly what I think is needed here. I do NOT want
anyone making supposed 'bug fixes' to content I am linking to without
testing them on my end.

If a link to dynamic content was required, the way to effect it would be to
provide the content digest of the signature key.

--000000000000ceaff205971537be
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">I a=
m just updating the Web site and upgrading to Bootstrap 4. In the process, =
I came across this:</div><div class=3D"gmail_default" style=3D"font-size:sm=
all"><br></div><div class=3D"gmail_default" style=3D"font-size:small"><span=
 class=3D"gmail-commentcolor" style=3D"box-sizing:inherit;color:green;font-=
family:Consolas,&quot;courier new&quot;;font-size:15px">&lt;!-- Latest comp=
iled and minified CSS --&gt;</span><br style=3D"box-sizing:inherit;color:rg=
b(0,0,0);font-family:Consolas,&quot;courier new&quot;;font-size:15px"><span=
 class=3D"gmail-tagnamecolor" style=3D"box-sizing:inherit;color:brown;font-=
family:Consolas,&quot;courier new&quot;;font-size:15px"><span class=3D"gmai=
l-tagcolor" style=3D"box-sizing:inherit;color:mediumblue">&lt;</span>link<s=
pan class=3D"gmail-attributecolor" style=3D"box-sizing:inherit;color:red">=
=C2=A0rel<span class=3D"gmail-attributevaluecolor" style=3D"box-sizing:inhe=
rit;color:mediumblue">=3D&quot;stylesheet&quot;</span>=C2=A0href<span class=
=3D"gmail-attributevaluecolor" style=3D"box-sizing:inherit;color:mediumblue=
">=3D&quot;<a href=3D"https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/css/b=
ootstrap.min.css">https://maxcdn.bootstrapcdn.com/bootstrap/4.3.1/css/boots=
trap.min.css</a>&quot;</span></span><span class=3D"gmail-tagcolor" style=3D=
"box-sizing:inherit;color:mediumblue">&gt;</span></span>=C2=A0=C2=A0<br></d=
iv><div class=3D"gmail_default" style=3D"font-size:small">Of course downloa=
ding bootstrap from a CDN makes every bit of sense and even better to not h=
ave to download it more than once. But lets just step back and think about =
what this line of code does.</div><div class=3D"gmail_default" style=3D"fon=
t-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:sma=
ll">In effect, <a href=3D"http://bootstrapcdn.com">bootstrapcdn.com</a> has=
 just become a root of trust for my Web pages. I have handed a vast degree =
of trust over to a site that I have no direct connection to. All I did (or =
would have done if I wasn&#39;t a security nut) was to cut and paste the co=
de from a Web page giving me instructions.</div><div class=3D"gmail_default=
" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D=
"font-size:small">Replacing the variable uri with a hardened one is much be=
tter:</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div=
><div class=3D"gmail_default" style=3D"font-size:small"><span class=3D"gmai=
l-tagcolor" style=3D"box-sizing:inherit;color:mediumblue;font-family:Consol=
as,&quot;courier new&quot;;font-size:15px">&lt;</span><span style=3D"color:=
rgb(165,42,42);font-family:Consolas,&quot;courier new&quot;;font-size:15px"=
>link</span><span class=3D"gmail-attributecolor" style=3D"box-sizing:inheri=
t;color:red;font-family:Consolas,&quot;courier new&quot;;font-size:15px">=
=C2=A0rel<span class=3D"gmail-attributevaluecolor" style=3D"box-sizing:inhe=
rit;color:mediumblue">=3D&quot;stylesheet&quot;</span>=C2=A0href<span class=
=3D"gmail-attributevaluecolor" style=3D"box-sizing:inherit;color:mediumblue=
">=3D&quot;udf:<a href=3D"http://maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NH=
O-T26Z-2E6Y-WFH4">maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH=
4</a>&quot;</span></span><span class=3D"gmail-tagcolor" style=3D"box-sizing=
:inherit;color:mediumblue;font-family:Consolas,&quot;courier new&quot;;font=
-size:15px">&gt;</span>=C2=A0=C2=A0</div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small">Of course we might well require some sort of transition strategy=
 but it seems we now EOL Web browsers after 8 years (IE 9 is no longer supp=
orted by BS 4).</div><div class=3D"gmail_default" style=3D"font-size:small"=
><br></div><div class=3D"gmail_default" style=3D"font-size:small">Content d=
igest of the content provides a link to a fixed static version of a resourc=
e which is exactly what I think is needed here. I do NOT want anyone making=
 supposed &#39;bug fixes&#39; to content I am linking to without testing th=
em on my end.</div><div class=3D"gmail_default" style=3D"font-size:small"><=
br></div><div class=3D"gmail_default" style=3D"font-size:small">If a link t=
o dynamic content was required, the way to effect it would be to provide th=
e content digest of the signature key.</div><div class=3D"gmail_default" st=
yle=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"fon=
t-size:small"><br></div></div>

--000000000000ceaff205971537be--


From nobody Mon Nov 11 23:27:52 2019
Return-Path: <mcr@sandelman.ca>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 57D15120168 for <mathmesh@ietfa.amsl.com>; Mon, 11 Nov 2019 23:27:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level: 
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vFwAmzlnwF8Q for <mathmesh@ietfa.amsl.com>; Mon, 11 Nov 2019 23:27:47 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 903311200A4 for <mathmesh@ietf.org>; Mon, 11 Nov 2019 23:27:47 -0800 (PST)
Received: from [192.168.44.20] (unknown [209.52.88.187]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by tuna.sandelman.ca (Postfix) with ESMTPSA id 76D8D3818F for <mathmesh@ietf.org>; Tue, 12 Nov 2019 02:24:16 -0500 (EST)
To: mathmesh@ietf.org
References: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com>
From: Michael Richardson <mcr@sandelman.ca>
Openpgp: preference=signencrypt
Autocrypt: addr=mcr@sandelman.ca; keydata= mQGNBF3EaO8BDADNdcAioLgGWFMLcmR6SuX1ioVH0v1fcprk0Wl1Qc7LCdwqj+QSdv84oNe1 h6lTf+CsmzO+TZtL+2iUzR3WHyXViEJcSHldx2YIfgxGZkzqgqozDj2IoHCU6ezhQz2TwJO7 l6H7fIPBbemIu8qVezwP1azLVq3D+cXZkkOvsFhTiw1bF/WF8lIIAYEbQ4YyYyjk5DS30x59 kxFNSv6om8rqSAKs2epneEWpzybB0J82dBnB4VDDsMmTJWPkszvQoCjCbrvgDAuoRtL5su2V IQWw61O6N5p1mwJ7VQoPDWYyeFH4NrVlL71FwRLueVPle76Oi3ybE2IMUvHZ/e42jVBizlQj 1N/2x7mGk35Zrvz0WHjZLcFJYJkDOnLsMU1smhdRtxNfYf576DTlzQKVcLmNCfOKAWnz4DdQ gRI4pNs24NoxLXl5v5mhDHRX5Me+CuckkFNGSlCXZ5kMXzPPFAV6CwMlm65P1tVJq9td8Uh0 5I5okPcENk5iY+FniqMXamsAEQEAAbQlTWljaGFlbCBSaWNoYXJkc29uIDxtY3JAc2FuZGVs bWFuLmNhPokB1AQTAQgAPhYhBKMP9ag1YAG1i9s8WHACrsLM2IBDBQJdxGjwAhsDBQkB4TOA BQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEHACrsLM2IBDeJ4MAMvUmQjFqXgsg4KhIWQb QBcgNPxrtp9jW/i2m//0zVA2iGxbeTOZD6cmcNDRj153TbSGTEH03oJIeYbdwlOCe5blA6h4 FTEBwt/qX+mjRYKXuA3uvFdEJQJPFcaWFF68rgQMxgLPPUAnTYQ00SqaBEg+Vh4gSh8yOHuU 8VTgenm4JpBdJQx7/7syvIaQilhN2fF25CcA7hArmebkaG691x+cFD60s8ITI9PSf82SVUnp mspJTGptxFxH/GM/kW40iB4tUjZrUSQfTfWIXA/5j005XbVbo1DIYirWWNK0WPVsh51ullzt u37BDVj/SmgbGhvTUXwsBi4b+T2cJHLt+8QT/KM8OA+UA8AlkNPleKtOzxsg5z22m0fzollE Zcw9VIojPKIhTUYU79InmibEUoGfb05MFJM9aXX5BMoJNpKcB92PKI/gMsrxMwH1exs0cY/E K/xYdpFo3rTPw5KSsDkr7ZbqGPgz+QP2H+TLwgLKMFTBlVKpj+oqBnqeEVVrC7kBjQRdxGjv AQwA0T5oxtsQkr3I3FxBi5TkNSh0HZ7ND5xJJkyM6wLAsljLk5KhdcxjTlo6htNjRUuUy1Ld 0bARmezZf5GqKRh6fR7WX9EdYjGm0RbcK3tQ3L61h4p3EOplKgMSoGpGamLSDzRs3SAJu4GF iHfzQ20R0PxBN/CbzWh6ROPcxQ8wwt8G4ZOwU4zXfSmZqZwNp/6xosLCl3TKvFWX6421Vb/L WAOOAz/xSyS0GCUs/grBUfzu95+TTskRk7kkeYSQ//1Oq9srPlIU9lx3Y4jDgPkXIwd9eXOq e7/5y4bQkILGGMIux878DhAED865hPMBuHlkDNzIuo6HhjRkShLBM16yQhK+NJ0WI77+m1FD 7r5QL6iU57zI/B5U03JKZhW0Pm3Bm+RWZPWGVawkPUnvxoMFbw+x1+MnKZgXwRmRmbFsCHhD VmrDKLWXRm9QvTB+k0ZnTdme9ZwSNCn0CXME2rNtOR39Yh6dsWH2nMPvg/G5iUmZyO9Oa01W xhWcXnKA+v+VABEBAAGJAbwEGAEIACYWIQSjD/WoNWABtYvbPFhwAq7CzNiAQwUCXcRo7wIb DAUJAeEzgAAKCRBwAq7CzNiAQwaOC/4olaVHP/npCn2CrtAOstbyytePFmS9NAwdT8A6mA4s +WshPo1DhKEnKnYzW/S0jLf0iqlzT8LUqu2G8f6elGzghRR8WJVn0zH7LVCKMWo/tHE2rWyi Q1zuX9o7ChTodQ8cXx0lM1xdY8v4Amc5fFxyyhJprKZAtiDJ897vv1jP09fWLEBhaDsHqLhg ckQpIoee0Id4FXGt7wxDsPwa64SUUCTYdt98EiLoUY6eAWQnyelgbFU+D/bxkeytmmvWOVr7 UXVMQlEKG7E31G1XQMk6sFATF1dwiH/laLQPLuMYr7owUC+ef/YAWSHMTYeIfwdt/Yd8ngJ8 SFA6Uc+Bjr0i1jdnxS5H3EF4V1FNY2rh4zNPVNj2UrZaShK/XH4hnTJUYL5fo2ygt2ZM98ot 8lIsHGAJQHDl2/EffLsAL85pXDPl8E+nvOUOE1kwmfOgv/oV8z0469qu/hNiEpGp8xKBqGEL NWHd8fH5S9JxVix9Ed34vi9Cyf24iLjiWZBemXw=
Message-ID: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
Date: Tue, 12 Nov 2019 15:21:36 +0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="8TqOexf6aBn3qqSMhBLjordm8Ilkv88jm"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/6tH1KrbQMWxi3rJ8rTDf5tt5eXA>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Nov 2019 07:27:50 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--8TqOexf6aBn3qqSMhBLjordm8Ilkv88jm
Content-Type: multipart/mixed; boundary="rN7ylYVwlfyW4Nm5idaAeGjG3JQX1Hoxk";
 protected-headers="v1"
From: Michael Richardson <mcr@sandelman.ca>
To: mathmesh@ietf.org
Message-ID: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
Subject: Re: [Mathmesh] Using UDF for CDN content
References: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com>
In-Reply-To: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com>

--rN7ylYVwlfyW4Nm5idaAeGjG3JQX1Hoxk
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US



On 2019-11-12 1:11 a.m., Phillip Hallam-Baker wrote:
> I am just updating the Web site and upgrading to Bootstrap 4. In the
> process, I came across this:
>
> <!-- Latest compiled and minified CSS -->
> <link=C2=A0rel=3D"stylesheet"=C2=A0href=3D"https://maxcdn.bootstrapcdn.=
com/bootstrap/4.3.1/css/bootstrap.min.css">=C2=A0=C2=A0
> Of course downloading bootstrap from a CDN makes every bit of sense
> and even better to not have to download it more than once. But lets
> just step back and think about what this line of code does.
>
> In effect, bootstrapcdn.com <http://bootstrapcdn.com> has just become
> a root of trust for my Web pages. I have handed a vast degree of trust
> over to a site that I have no direct connection to. All I did (or
> would have done if I wasn't a security nut) was to cut and paste the
> code from a Web page giving me instructions.

You are completely correct in your assessment.=C2=A0 You could download t=
he
code and put it on your web site, which would improve your threat
surface, but if you did that you would be defeating a great deal of
caching done by browsers of this kind of content.=C2=A0 You might also mi=
ss
out on updates, although if you are linking to a version-numbered
content, then you are not getting any update advantage.
I seem to remember linking to major-version only when pulling in jQuery.

> Replacing the variable uri with a hardened one is much better:
>
> <link=C2=A0rel=3D"stylesheet"=C2=A0href=3D"udf:maxcdn.bootstrapcdn.com/=
MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH4
> <http://maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH4>">=C2=
=A0=C2=A0
>
> Of course we might well require some sort of transition strategy but
> it seems we now EOL Web browsers after 8 years (IE 9 is no longer
> supported by BS 4).

Could we rely on some other (more primitive) bit of javascript to go
through and replace this with the correct one?=C2=A0 That probably means
using something other than href=3D""

> Content digest of the content provides a link to a fixed static
> version of a resource which is exactly what I think is needed here. I
> do NOT want anyone making supposed 'bug fixes' to content I am linking
> to without testing them on my end.
>
> If a link to dynamic content was required, the way to effect it would
> be to provide the content digest of the signature key.

I would like to further remove the hostname from that and just give a hin=
t.
Any content with that hash would satisfy the requirement.


--rN7ylYVwlfyW4Nm5idaAeGjG3JQX1Hoxk--

--8TqOexf6aBn3qqSMhBLjordm8Ilkv88jm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEow/1qDVgAbWL2zxYcAKuwszYgEMFAl3KXYAACgkQcAKuwszY
gEPMwwv/fEnlr5vIbOLw0xMDTUqnkU3k3ZDeublJ8EXeyWN+PMssmOxdVOmHL3xu
XKyCx8vb7pdZN25kCGPDqcdO+NDEIszW5q6sCfnETY1ho73VRPWorYhxHhQuznIu
I7vr1KKgHcBME1O+KXpTbIuruGFudKrzXTcL+ScTPPAbyVAOVIsooDxIbPJZGrio
yCz+jRQW91wizK2Ugl/iDPyWZ4k1LgPKbtdgFJxFV3Xo0wUtD5bTRC497i4Z9xEM
cDBe8Ynv5cJ1AOt0f+KQhXtRF43BmNf5TLQJ5rIkaBr0+UngNYwrz81oDypVABxV
iafJeMgM09DscF8nWBKit+OsYTue+YQ25E+d0ZPg3PgRt1oBnWHNGUzjwlVEasaG
Hb1rKv82rpM3/yKCjUtACB8CHz8GLkyg+v9/WJ0TK0uRv8/Ue/V43ZualmQm/l8f
eg8AolmB/RBHL+/jPeguZbo+u00RKtsiOLwUZCXEOUy4vIf5aXZF/gwvoHfSdSuw
Cxp2jDRn
=ZciD
-----END PGP SIGNATURE-----

--8TqOexf6aBn3qqSMhBLjordm8Ilkv88jm--


From nobody Tue Nov 12 05:16:02 2019
Return-Path: <rsalz@akamai.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0CFF01200DB for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 05:16:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bniDQMFINvNm for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 05:15:58 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 559A012011C for <mathmesh@ietf.org>; Tue, 12 Nov 2019 05:15:58 -0800 (PST)
Received: from pps.filterd (m0122331.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id xACDCC13004582; Tue, 12 Nov 2019 13:15:49 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=Myp7TOcQBQn9bCMbJXCcQAI8TfVyMP+3tSyCabKOeD0=; b=aDPe7eOjL/mWbi4UnD3xC1ywDd6rtWxXTYpFMQ1OI9eK8P8vw91Il6FWWIFgpB95F6/k eHuP9Zw+glYAxfA3n92jIkV4ZIL5OAbkp7nK5Ck3U/7ifkqwoQsunRx+d+omVH3RM9U8 HRiKuQcr2DwVpQHmteAn+4QXXWVsUvdzzkpSw7VGVuejpYDLSI5m0bInm0JY2Zi3NEqb atvc00bZ2Gwj3Qd4/0qJChGgx9lrqCHHTWT/HAfhQYTmXN6latJDDBjWlEmZXbL8zAAX Pxe2qAzAHM9q9YGgIe9uUqZIXzwxXYE9OLRNWnAiLVrNC4bHWz/+wWbYQ4l4zVA1CQ0P Mg== 
Received: from prod-mail-ppoint5 (prod-mail-ppoint5.akamai.com [184.51.33.60] (may be forged)) by mx0b-00190b01.pphosted.com with ESMTP id 2w5p6dx00q-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 12 Nov 2019 13:15:49 +0000
Received: from pps.filterd (prod-mail-ppoint5.akamai.com [127.0.0.1]) by prod-mail-ppoint5.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xACD2rbQ011197; Tue, 12 Nov 2019 05:15:48 -0800
Received: from email.msg.corp.akamai.com ([172.27.123.34]) by prod-mail-ppoint5.akamai.com with ESMTP id 2w5vabn25s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Tue, 12 Nov 2019 05:15:48 -0800
Received: from USMA1EX-DAG1MB5.msg.corp.akamai.com (172.27.123.105) by usma1ex-dag3mb2.msg.corp.akamai.com (172.27.123.59) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Tue, 12 Nov 2019 08:15:48 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb5.msg.corp.akamai.com (172.27.123.105) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Tue, 12 Nov 2019 08:15:47 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Tue, 12 Nov 2019 08:15:47 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Michael Richardson <mcr@sandelman.ca>, "mathmesh@ietf.org" <mathmesh@ietf.org>
Thread-Topic: [Mathmesh] Using UDF for CDN content
Thread-Index: AQHVmLMW26fKkMA2hkOClfk6URPvW6eHdg0AgAAPJIA=
Date: Tue, 12 Nov 2019 13:15:47 +0000
Message-ID: <8C1BA78E-3D20-4295-A77B-CCF240137543@akamai.com>
References: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com> <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
In-Reply-To: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/10.1f.0.191110
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.114.73]
Content-Type: text/plain; charset="utf-8"
Content-ID: <606B29F73282804081B03DA172C925CF@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-12_03:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=696 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1910280000 definitions=main-1911120117
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-12_03:2019-11-11,2019-11-12 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 clxscore=1011 adultscore=0 lowpriorityscore=0 bulkscore=0 malwarescore=0 priorityscore=1501 impostorscore=0 phishscore=0 mlxscore=0 mlxlogscore=676 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911120118
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/NIgBY7VnahMq8TcOIt4AbqMoFt0>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Nov 2019 13:16:01 -0000

SXNuJ3Qgc3ViLXJlc291cmNlIGludGVncml0eSBhbHNvIHN1cHBvc2VkIHRvIGFkZHJlc3MgdGhp
cz8NCg0K


From nobody Tue Nov 12 07:31:09 2019
Return-Path: <cabo@tzi.org>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 30A7412006E for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 07:31:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.197
X-Spam-Level: 
X-Spam-Status: No, score=-4.197 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y5sxK_3mmkfz for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 07:31:05 -0800 (PST)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 26DB912000F for <mathmesh@ietf.org>; Tue, 12 Nov 2019 07:31:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost2.informatik.uni-bremen.de [IPv6:2001:638:708:30c8:406a:91ff:fe74:f2b7]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id xACFUuvm004334; Tue, 12 Nov 2019 16:31:01 +0100 (CET)
Received: from [100.76.24.183] (ip-109-41-67-71.web.vodafone.de [109.41.67.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 47CBXb5yyLz1BhL; Tue, 12 Nov 2019 16:30:55 +0100 (CET)
Content-Type: multipart/alternative; boundary=Apple-Mail-FB269721-F000-4606-9385-62B45AC10A22
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (1.0)
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
Date: Tue, 12 Nov 2019 16:30:53 +0100
Cc: mathmesh@ietf.org
Message-Id: <A545E94E-E05C-4DC2-8EEB-2682C8EA8936@tzi.org>
References: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca>
To: Michael Richardson <mcr@sandelman.ca>
X-Mailer: iPhone Mail (17B102)
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/bIyJ-Hi69g6OBMDBgOucVLj4QIo>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Nov 2019 15:31:07 -0000

--Apple-Mail-FB269721-F000-4606-9385-62B45AC10A22
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

RFC 6920

Sent from mobile, sorry for terse

> On 12. Nov 2019, at 08:44, Michael Richardson <mcr@sandelman.ca> wrote:
>=20
> =EF=BB=BF
>=20
>> On 2019-11-12 1:11 a.m., Phillip Hallam-Baker wrote:
>> I am just updating the Web site and upgrading to Bootstrap 4. In the
>> process, I came across this:
>>=20
>> <!-- Latest compiled and minified CSS -->
>> <link rel=3D"stylesheet" href=3D"https://maxcdn.bootstrapcdn.com/bootstra=
p/4.3.1/css/bootstrap.min.css"> =20
>> Of course downloading bootstrap from a CDN makes every bit of sense
>> and even better to not have to download it more than once. But lets
>> just step back and think about what this line of code does.
>>=20
>> In effect, bootstrapcdn.com <http://bootstrapcdn.com> has just become
>> a root of trust for my Web pages. I have handed a vast degree of trust
>> over to a site that I have no direct connection to. All I did (or
>> would have done if I wasn't a security nut) was to cut and paste the
>> code from a Web page giving me instructions.
>=20
> You are completely correct in your assessment.  You could download the
> code and put it on your web site, which would improve your threat
> surface, but if you did that you would be defeating a great deal of
> caching done by browsers of this kind of content.  You might also miss
> out on updates, although if you are linking to a version-numbered
> content, then you are not getting any update advantage.
> I seem to remember linking to major-version only when pulling in jQuery.
>=20
>> Replacing the variable uri with a hardened one is much better:
>>=20
>> <link rel=3D"stylesheet" href=3D"udf:maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FB=
T-7NHO-T26Z-2E6Y-WFH4
>> <http://maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH4>"> =20=

>>=20
>> Of course we might well require some sort of transition strategy but
>> it seems we now EOL Web browsers after 8 years (IE 9 is no longer
>> supported by BS 4).
>=20
> Could we rely on some other (more primitive) bit of javascript to go
> through and replace this with the correct one?  That probably means
> using something other than href=3D""
>=20
>> Content digest of the content provides a link to a fixed static
>> version of a resource which is exactly what I think is needed here. I
>> do NOT want anyone making supposed 'bug fixes' to content I am linking
>> to without testing them on my end.
>>=20
>> If a link to dynamic content was required, the way to effect it would
>> be to provide the content digest of the signature key.
>=20
> I would like to further remove the hostname from that and just give a hint=
.
> Any content with that hash would satisfy the requirement.
>=20
> --=20
> Mathmesh mailing list
> Mathmesh@ietf.org
> https://www.ietf.org/mailman/listinfo/mathmesh

--Apple-Mail-FB269721-F000-4606-9385-62B45AC10A22
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto">RFC 6920<br><br><div dir=3D"ltr">Sent from&=
nbsp;<span style=3D"font-size: 13pt;">mobile, sorry for terse</span></div><d=
iv dir=3D"ltr"><br><blockquote type=3D"cite">On 12. Nov 2019, at 08:44, Mich=
ael Richardson &lt;mcr@sandelman.ca&gt; wrote:<br><br></blockquote></div><bl=
ockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<span></span><br><span></sp=
an><br><span>On 2019-11-12 1:11 a.m., Phillip Hallam-Baker wrote:</span><br>=
<blockquote type=3D"cite"><span>I am just updating the Web site and upgradin=
g to Bootstrap 4. In the</span><br></blockquote><blockquote type=3D"cite"><s=
pan>process, I came across this:</span><br></blockquote><blockquote type=3D"=
cite"><span></span><br></blockquote><blockquote type=3D"cite"><span>&lt;!-- L=
atest compiled and minified CSS --&gt;</span><br></blockquote><blockquote ty=
pe=3D"cite"><span>&lt;link&nbsp;rel=3D"stylesheet"&nbsp;href=3D"https://maxc=
dn.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css"&gt;&nbsp;&nbsp;</=
span><br></blockquote><blockquote type=3D"cite"><span>Of course downloading b=
ootstrap from a CDN makes every bit of sense</span><br></blockquote><blockqu=
ote type=3D"cite"><span>and even better to not have to download it more than=
 once. But lets</span><br></blockquote><blockquote type=3D"cite"><span>just s=
tep back and think about what this line of code does.</span><br></blockquote=
><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=3D=
"cite"><span>In effect, bootstrapcdn.com &lt;http://bootstrapcdn.com&gt; has=
 just become</span><br></blockquote><blockquote type=3D"cite"><span>a root o=
f trust for my Web pages. I have handed a vast degree of trust</span><br></b=
lockquote><blockquote type=3D"cite"><span>over to a site that I have no dire=
ct connection to. All I did (or</span><br></blockquote><blockquote type=3D"c=
ite"><span>would have done if I wasn't a security nut) was to cut and paste t=
he</span><br></blockquote><blockquote type=3D"cite"><span>code from a Web pa=
ge giving me instructions.</span><br></blockquote><span></span><br><span>You=
 are completely correct in your assessment.&nbsp; You could download the</sp=
an><br><span>code and put it on your web site, which would improve your thre=
at</span><br><span>surface, but if you did that you would be defeating a gre=
at deal of</span><br><span>caching done by browsers of this kind of content.=
&nbsp; You might also miss</span><br><span>out on updates, although if you a=
re linking to a version-numbered</span><br><span>content, then you are not g=
etting any update advantage.</span><br><span>I seem to remember linking to m=
ajor-version only when pulling in jQuery.</span><br><span></span><br><blockq=
uote type=3D"cite"><span>Replacing the variable uri with a hardened one is m=
uch better:</span><br></blockquote><blockquote type=3D"cite"><span></span><b=
r></blockquote><blockquote type=3D"cite"><span>&lt;link&nbsp;rel=3D"styleshe=
et"&nbsp;href=3D"udf:maxcdn.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-W=
FH4</span><br></blockquote><blockquote type=3D"cite"><span>&lt;http://maxcdn=
.bootstrapcdn.com/MB5S-R4AJ-3FBT-7NHO-T26Z-2E6Y-WFH4&gt;"&gt;&nbsp;&nbsp;</s=
pan><br></blockquote><blockquote type=3D"cite"><span></span><br></blockquote=
><blockquote type=3D"cite"><span>Of course we might well require some sort o=
f transition strategy but</span><br></blockquote><blockquote type=3D"cite"><=
span>it seems we now EOL Web browsers after 8 years (IE 9 is no longer</span=
><br></blockquote><blockquote type=3D"cite"><span>supported by BS 4).</span>=
<br></blockquote><span></span><br><span>Could we rely on some other (more pr=
imitive) bit of javascript to go</span><br><span>through and replace this wi=
th the correct one?&nbsp; That probably means</span><br><span>using somethin=
g other than href=3D""</span><br><span></span><br><blockquote type=3D"cite">=
<span>Content digest of the content provides a link to a fixed static</span>=
<br></blockquote><blockquote type=3D"cite"><span>version of a resource which=
 is exactly what I think is needed here. I</span><br></blockquote><blockquot=
e type=3D"cite"><span>do NOT want anyone making supposed 'bug fixes' to cont=
ent I am linking</span><br></blockquote><blockquote type=3D"cite"><span>to w=
ithout testing them on my end.</span><br></blockquote><blockquote type=3D"ci=
te"><span></span><br></blockquote><blockquote type=3D"cite"><span>If a link t=
o dynamic content was required, the way to effect it would</span><br></block=
quote><blockquote type=3D"cite"><span>be to provide the content digest of th=
e signature key.</span><br></blockquote><span></span><br><span>I would like t=
o further remove the hostname from that and just give a hint.</span><br><spa=
n>Any content with that hash would satisfy the requirement.</span><br><span>=
</span><br><span>-- </span><br><span>Mathmesh mailing list</span><br><span>M=
athmesh@ietf.org</span><br><span>https://www.ietf.org/mailman/listinfo/mathm=
esh</span><br></div></blockquote></body></html>=

--Apple-Mail-FB269721-F000-4606-9385-62B45AC10A22--


From nobody Tue Nov 12 19:53:03 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC2821200D5 for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 19:53:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.645
X-Spam-Level: 
X-Spam-Status: No, score=-1.645 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UCKA78gkbOA8 for <mathmesh@ietfa.amsl.com>; Tue, 12 Nov 2019 19:52:59 -0800 (PST)
Received: from mail-ot1-f47.google.com (mail-ot1-f47.google.com [209.85.210.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8BA09120041 for <mathmesh@ietf.org>; Tue, 12 Nov 2019 19:52:59 -0800 (PST)
Received: by mail-ot1-f47.google.com with SMTP id d5so435612otp.4 for <mathmesh@ietf.org>; Tue, 12 Nov 2019 19:52:59 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=LKqmmGG15d0pCLWrVt5yYygRZhqoRcYKkzpU0T4rwr4=; b=P4fivd3ZyYb4VGo8L2qPWz4O8eu9fcOa02ow8f1e5V8XlqCEyrNJP7CqgSPFT7qwUz 5iCsXcnpAmWRsiqym4KIi1ooM9tHwaR1Ir3TdkgEhidkP3l5rggk/Ts/9oWNgn3G2+51 k61IO6pb84XC68HR8LGLZ2Fh6GWXK5QF2Q9CrGOpbmYcuv4fYwKMxmhg6woEuXkQmU/5 n/mQip83hXZla6X6uwj+ntI2/NyIPf4A0F9wo74zFRJI6z5WuC6zTw9NGFb4Am4BD8cW NRULI14QBSY9X9FmFEGVUYUPkCmGnxjMBwMVlYvIZHtKhligsnPwkzqCgHLxi8xlvemm 6I1g==
X-Gm-Message-State: APjAAAUInJs1zCAg4bWElKt19m/L9ENtuii+Dcr205flojxTlVhWG0JR 0fDiCKJfqo+YLV25BJYvO1J4Rcs24gSMV5k+pCw=
X-Google-Smtp-Source: APXvYqxberpxovSkbJWCyf/l6p0L5qPIXmSQTNvs/JAl4FDHCURArZ5BI1zGXCwi6jeZRDokbTT/4CSThGBRaVzTCew=
X-Received: by 2002:a05:6830:2001:: with SMTP id e1mr1035820otp.48.1573617178673;  Tue, 12 Nov 2019 19:52:58 -0800 (PST)
MIME-Version: 1.0
References: <CAMm+LwgYiZGFePej6kncJidnKMbPA+4gHtym=MGEKjJrR2wWsw@mail.gmail.com> <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca> <8C1BA78E-3D20-4295-A77B-CCF240137543@akamai.com>
In-Reply-To: <8C1BA78E-3D20-4295-A77B-CCF240137543@akamai.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Tue, 12 Nov 2019 22:52:47 -0500
Message-ID: <CAMm+Lwi+1cwA+jSzAt7_unjprMNg75DV=dseqjrMbTodffyZcQ@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: Michael Richardson <mcr@sandelman.ca>, "mathmesh@ietf.org" <mathmesh@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000f289380597324cb2"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/dfwZZWMXaO5e4fyEHSTITt_sW7g>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2019 03:53:01 -0000

--000000000000f289380597324cb2
Content-Type: text/plain; charset="UTF-8"

On Tue, Nov 12, 2019 at 8:16 AM Salz, Rich <rsalz@akamai.com> wrote:

> Isn't sub-resource integrity also supposed to address this?
>

Wow it actually happened. Larry Masinter only suggested doing this in 1994
after the first Web conference...

Its been one of those things that has been proposed so often since and
never went anywhere.

--000000000000f289380597324cb2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"fon=
t-size:small"><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"lt=
r" class=3D"gmail_attr">On Tue, Nov 12, 2019 at 8:16 AM Salz, Rich &lt;<a h=
ref=3D"mailto:rsalz@akamai.com">rsalz@akamai.com</a>&gt; wrote:<br></div><b=
lockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-le=
ft:1px solid rgb(204,204,204);padding-left:1ex">Isn&#39;t sub-resource inte=
grity also supposed to address this?<br></blockquote><div><br></div><div cl=
ass=3D"gmail_default" style=3D"font-size:small">Wow it actually happened. L=
arry Masinter only suggested doing this in 1994 after the first Web confere=
nce...</div><div class=3D"gmail_default" style=3D"font-size:small"><br></di=
v><div class=3D"gmail_default" style=3D"font-size:small">Its been one of th=
ose things that has been proposed so often since and never went anywhere.</=
div></div></div>

--000000000000f289380597324cb2--


From nobody Wed Nov 13 20:00:57 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 09C101200F7 for <mathmesh@ietfa.amsl.com>; Wed, 13 Nov 2019 20:00:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.649
X-Spam-Level: 
X-Spam-Status: No, score=-1.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kQwaZjMTXwCS for <mathmesh@ietfa.amsl.com>; Wed, 13 Nov 2019 20:00:54 -0800 (PST)
Received: from mail-oi1-f180.google.com (mail-oi1-f180.google.com [209.85.167.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 436C7120105 for <mathmesh@ietf.org>; Wed, 13 Nov 2019 20:00:54 -0800 (PST)
Received: by mail-oi1-f180.google.com with SMTP id a14so4031498oid.5 for <mathmesh@ietf.org>; Wed, 13 Nov 2019 20:00:54 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=b1O2nNuw9C3XRv9aYStzRirRn75Ma61KvV1kdfjxI6k=; b=bvDExDIZadOVKShMuhwpNYP+oIl482euwg4fB7aHfBDEYKeLQVKicViP0n7xsiEwR2 S0A4eBFbVJ8QTUZpp3RbmboB/fQjg5jKsrsevpmM0nnKrG1kv+5xK3n772SDUYnX6gGt c/4JhqrtF2ozUUNteyphfeVJts4M379QNpnLiaNBgbpNh5itvH8O8i99S5SCoSssF7hj fJqBbeeXtFYS0Ow8rJRSgvjbx7BMVs22hMmLppdIT0QVT2RQGIGRteJCzxr3loTC1RQK H6cCfO9x2pQpFpsGZgxK8sH8cKpkTc5oNPKHquJOMZL6XA+NkqrJgfkVlbfUCSaDP5jd bkHQ==
X-Gm-Message-State: APjAAAXT9hTKNds9ZcNdfmis3m6wHW1vJLNaFYBip7a2fBqRxvnJLfkP x5VHQY+RZ2iWLOyebFm612bspspAc8jW95OOFDkF7cLV
X-Google-Smtp-Source: APXvYqybSpyJoGcqtrzsjtmb3MIdOM0Zo9r3Lki+bPdGore5769/iKGD0Cl0tnhuljDSsSPeR7DqEWo3UzGWY61IBIY=
X-Received: by 2002:aca:484e:: with SMTP id v75mr1802020oia.6.1573704053035; Wed, 13 Nov 2019 20:00:53 -0800 (PST)
MIME-Version: 1.0
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Wed, 13 Nov 2019 23:00:42 -0500
Message-ID: <CAMm+Lwh7t9YgEyGQwQTf9iEmeSt-YO3HaPDgm62fUs-mPJ2jLQ@mail.gmail.com>
To: mathmesh@ietf.org
Content-Type: multipart/alternative; boundary="0000000000001018bd0597468766"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/_15aXEV9b8xZOu8L8tpo2zYMFCY>
Subject: [Mathmesh] New MathMesh Web Site
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Nov 2019 04:00:56 -0000

--0000000000001018bd0597468766
Content-Type: text/plain; charset="UTF-8"

I redid the MathMesh project site. It now has a proper TLS certificate and
the content now matches the specs. There are still some rough edges as the
current focus is still getting the initial cut of the specifications and
code:

https://mathmesh.com/

For those of you with long flights with insufficient in-flight
entertainment. I am hoping that the following directory will provide access
to a downloadable copy of the Mesh introductory videos. These are available
in 4K, HD and compact resolution.

https://mathmesh.com/IETF/

Please note that the server is not exactly well equipped to handle volume
traffic.I was going to move the server but didn't get round to it.

--0000000000001018bd0597468766
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">I r=
edid the MathMesh project site. It now has a proper TLS certificate and the=
 content now matches the specs. There are still some rough edges as the cur=
rent focus is still getting the initial cut of the specifications and code:=
</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div=
 class=3D"gmail_default" style=3D"font-size:small"><a href=3D"https://mathm=
esh.com/">https://mathmesh.com/</a>=C2=A0=C2=A0<br></div><div class=3D"gmai=
l_default" style=3D"font-size:small"><br></div><div class=3D"gmail_default"=
 style=3D"font-size:small">For those of you with long flights with insuffic=
ient in-flight entertainment. I am hoping that the following directory will=
 provide access to a downloadable copy of the Mesh introductory videos. The=
se are available in 4K, HD and compact resolution.</div><div class=3D"gmail=
_default" style=3D"font-size:small"><br></div><div class=3D"gmail_default" =
style=3D"font-size:small"><a href=3D"https://mathmesh.com/IETF/">https://ma=
thmesh.com/IETF/</a>=C2=A0<br></div><div class=3D"gmail_default" style=3D"f=
ont-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:s=
mall">Please note that the server is not exactly well equipped to handle vo=
lume traffic.I was going to move the server but didn&#39;t get round to it.=
</div></div>

--0000000000001018bd0597468766--


From nobody Wed Nov 13 22:10:40 2019
Return-Path: <mcr@sandelman.ca>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6B901200C3 for <mathmesh@ietfa.amsl.com>; Wed, 13 Nov 2019 22:10:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mTnNIr_vXeGf for <mathmesh@ietfa.amsl.com>; Wed, 13 Nov 2019 22:10:36 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E9E2120024 for <mathmesh@ietf.org>; Wed, 13 Nov 2019 22:10:36 -0800 (PST)
Received: from [192.168.41.2] (unknown [58.212.134.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by tuna.sandelman.ca (Postfix) with ESMTPSA id 8FD833818F for <mathmesh@ietf.org>; Thu, 14 Nov 2019 01:07:27 -0500 (EST)
To: mathmesh@ietf.org
References: <CAMm+Lwh7t9YgEyGQwQTf9iEmeSt-YO3HaPDgm62fUs-mPJ2jLQ@mail.gmail.com>
From: Michael Richardson <mcr@sandelman.ca>
Openpgp: preference=signencrypt
Autocrypt: addr=mcr@sandelman.ca; keydata= mQGNBF3EaO8BDADNdcAioLgGWFMLcmR6SuX1ioVH0v1fcprk0Wl1Qc7LCdwqj+QSdv84oNe1 h6lTf+CsmzO+TZtL+2iUzR3WHyXViEJcSHldx2YIfgxGZkzqgqozDj2IoHCU6ezhQz2TwJO7 l6H7fIPBbemIu8qVezwP1azLVq3D+cXZkkOvsFhTiw1bF/WF8lIIAYEbQ4YyYyjk5DS30x59 kxFNSv6om8rqSAKs2epneEWpzybB0J82dBnB4VDDsMmTJWPkszvQoCjCbrvgDAuoRtL5su2V IQWw61O6N5p1mwJ7VQoPDWYyeFH4NrVlL71FwRLueVPle76Oi3ybE2IMUvHZ/e42jVBizlQj 1N/2x7mGk35Zrvz0WHjZLcFJYJkDOnLsMU1smhdRtxNfYf576DTlzQKVcLmNCfOKAWnz4DdQ gRI4pNs24NoxLXl5v5mhDHRX5Me+CuckkFNGSlCXZ5kMXzPPFAV6CwMlm65P1tVJq9td8Uh0 5I5okPcENk5iY+FniqMXamsAEQEAAbQlTWljaGFlbCBSaWNoYXJkc29uIDxtY3JAc2FuZGVs bWFuLmNhPokB1AQTAQgAPhYhBKMP9ag1YAG1i9s8WHACrsLM2IBDBQJdxGjwAhsDBQkB4TOA BQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEHACrsLM2IBDeJ4MAMvUmQjFqXgsg4KhIWQb QBcgNPxrtp9jW/i2m//0zVA2iGxbeTOZD6cmcNDRj153TbSGTEH03oJIeYbdwlOCe5blA6h4 FTEBwt/qX+mjRYKXuA3uvFdEJQJPFcaWFF68rgQMxgLPPUAnTYQ00SqaBEg+Vh4gSh8yOHuU 8VTgenm4JpBdJQx7/7syvIaQilhN2fF25CcA7hArmebkaG691x+cFD60s8ITI9PSf82SVUnp mspJTGptxFxH/GM/kW40iB4tUjZrUSQfTfWIXA/5j005XbVbo1DIYirWWNK0WPVsh51ullzt u37BDVj/SmgbGhvTUXwsBi4b+T2cJHLt+8QT/KM8OA+UA8AlkNPleKtOzxsg5z22m0fzollE Zcw9VIojPKIhTUYU79InmibEUoGfb05MFJM9aXX5BMoJNpKcB92PKI/gMsrxMwH1exs0cY/E K/xYdpFo3rTPw5KSsDkr7ZbqGPgz+QP2H+TLwgLKMFTBlVKpj+oqBnqeEVVrC7kBjQRdxGjv AQwA0T5oxtsQkr3I3FxBi5TkNSh0HZ7ND5xJJkyM6wLAsljLk5KhdcxjTlo6htNjRUuUy1Ld 0bARmezZf5GqKRh6fR7WX9EdYjGm0RbcK3tQ3L61h4p3EOplKgMSoGpGamLSDzRs3SAJu4GF iHfzQ20R0PxBN/CbzWh6ROPcxQ8wwt8G4ZOwU4zXfSmZqZwNp/6xosLCl3TKvFWX6421Vb/L WAOOAz/xSyS0GCUs/grBUfzu95+TTskRk7kkeYSQ//1Oq9srPlIU9lx3Y4jDgPkXIwd9eXOq e7/5y4bQkILGGMIux878DhAED865hPMBuHlkDNzIuo6HhjRkShLBM16yQhK+NJ0WI77+m1FD 7r5QL6iU57zI/B5U03JKZhW0Pm3Bm+RWZPWGVawkPUnvxoMFbw+x1+MnKZgXwRmRmbFsCHhD VmrDKLWXRm9QvTB+k0ZnTdme9ZwSNCn0CXME2rNtOR39Yh6dsWH2nMPvg/G5iUmZyO9Oa01W xhWcXnKA+v+VABEBAAGJAbwEGAEIACYWIQSjD/WoNWABtYvbPFhwAq7CzNiAQwUCXcRo7wIb DAUJAeEzgAAKCRBwAq7CzNiAQwaOC/4olaVHP/npCn2CrtAOstbyytePFmS9NAwdT8A6mA4s +WshPo1DhKEnKnYzW/S0jLf0iqlzT8LUqu2G8f6elGzghRR8WJVn0zH7LVCKMWo/tHE2rWyi Q1zuX9o7ChTodQ8cXx0lM1xdY8v4Amc5fFxyyhJprKZAtiDJ897vv1jP09fWLEBhaDsHqLhg ckQpIoee0Id4FXGt7wxDsPwa64SUUCTYdt98EiLoUY6eAWQnyelgbFU+D/bxkeytmmvWOVr7 UXVMQlEKG7E31G1XQMk6sFATF1dwiH/laLQPLuMYr7owUC+ef/YAWSHMTYeIfwdt/Yd8ngJ8 SFA6Uc+Bjr0i1jdnxS5H3EF4V1FNY2rh4zNPVNj2UrZaShK/XH4hnTJUYL5fo2ygt2ZM98ot 8lIsHGAJQHDl2/EffLsAL85pXDPl8E+nvOUOE1kwmfOgv/oV8z0469qu/hNiEpGp8xKBqGEL NWHd8fH5S9JxVix9Ed34vi9Cyf24iLjiWZBemXw=
Message-ID: <a6ae23f7-0fa8-a5f4-5743-91f4ea8741c9@sandelman.ca>
Date: Thu, 14 Nov 2019 14:10:29 +0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <CAMm+Lwh7t9YgEyGQwQTf9iEmeSt-YO3HaPDgm62fUs-mPJ2jLQ@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="2M9IzcFsZWSU7DbGYO1sbvK1uasQ0IoFV"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/9Zl1LsyTP7LJg__3WA-UmHYuP5c>
Subject: Re: [Mathmesh] New MathMesh Web Site
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Nov 2019 06:10:39 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--2M9IzcFsZWSU7DbGYO1sbvK1uasQ0IoFV
Content-Type: multipart/mixed; boundary="9Hcd6eUgA9n2nAjPXP04OZ5uHme9MCv6P";
 protected-headers="v1"
From: Michael Richardson <mcr@sandelman.ca>
To: mathmesh@ietf.org
Message-ID: <a6ae23f7-0fa8-a5f4-5743-91f4ea8741c9@sandelman.ca>
Subject: Re: [Mathmesh] New MathMesh Web Site
References: <CAMm+Lwh7t9YgEyGQwQTf9iEmeSt-YO3HaPDgm62fUs-mPJ2jLQ@mail.gmail.com>
In-Reply-To: <CAMm+Lwh7t9YgEyGQwQTf9iEmeSt-YO3HaPDgm62fUs-mPJ2jLQ@mail.gmail.com>

--9Hcd6eUgA9n2nAjPXP04OZ5uHme9MCv6P
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US



On 2019-11-14 12:00 p.m., Phillip Hallam-Baker wrote:
> I redid the MathMesh project site. It now has a proper TLS certificate
> and the content now matches the specs. There are still some rough
> edges as the current focus is still getting the initial cut of the
> specifications and code:
>
> https://mathmesh.com/=C2=A0=C2=A0
>
> For those of you with long flights with insufficient in-flight
> entertainment. I am hoping that the following directory will provide
> access to a downloadable copy of the Mesh introductory videos. These
> are available in 4K, HD and compact resolution.
>
> https://mathmesh.com/IETF/
The three resolutions seem to point to the same file?



--9Hcd6eUgA9n2nAjPXP04OZ5uHme9MCv6P--

--2M9IzcFsZWSU7DbGYO1sbvK1uasQ0IoFV
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEow/1qDVgAbWL2zxYcAKuwszYgEMFAl3M79UACgkQcAKuwszY
gEMvYQwArB4rZ+q5K3b06gjY9CZK8FaysWYTP4UokHgexWpyE7+v+TGD2ynwB25D
eS0yZi0+dL0Pmb69eFIdjjNYF65aZLeadYWYChaGqUYgNNAkuyVLc3Cj9OY2bmKG
dgDNr8E0StprSX3p17GCwBSrk53Ly2+2ab6oVIDAeb5FbQ2EkmqaH8YLoHq/1PQg
h0TXRO2QPE/MFDWOQZ4pLY/kPGd4UGP1NCaV9xZRYE3G5mo83ZHorBt2+8V0ALV/
V/kXJKTM8uN9UNoyXKxmBfqOtkg0CAW6w7Yf5dE+fa/ObNaSCCLTNaPYDTnnV2p3
+XCezXuuNykQ+5WEKmheTUGbsKK6dj6DnbYIrJ7K7/9kotZLwVmdiWaHgUeJhLvN
VXHz8/rSIdSMk2y+g6PCAd+a7vE5xMWPDT7phdIZR7GDh5p+jGxCMSqMg7lrNl1j
tVFCsLD3WqMyI7y42SlfGDrzrpze7Q7+vybsAGplTiU0rzQMBlkNFJu1e5anETpj
ZReDS9gB
=dv/o
-----END PGP SIGNATURE-----

--2M9IzcFsZWSU7DbGYO1sbvK1uasQ0IoFV--


From nobody Thu Nov 14 05:41:33 2019
Return-Path: <rsalz@akamai.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDC2F120105 for <mathmesh@ietfa.amsl.com>; Thu, 14 Nov 2019 05:41:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d3Fp0MmcsI6k for <mathmesh@ietfa.amsl.com>; Thu, 14 Nov 2019 05:41:29 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60E5D1208AE for <mathmesh@ietf.org>; Thu, 14 Nov 2019 05:41:29 -0800 (PST)
Received: from pps.filterd (m0050095.ppops.net [127.0.0.1]) by m0050095.ppops.net-00190b01. (8.16.0.42/8.16.0.42) with SMTP id xAEDarff011728 for <mathmesh@ietf.org>; Thu, 14 Nov 2019 13:41:29 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : content-type : mime-version; s=jan2016.eng; bh=/LWVQQVpVYegBL28bxjbW/lpqf1u5Y6Tn2fdGHBXz+w=; b=bsfuvrrzJhh9wUd6BWL50srggv6OmLtaCVxNzUM4PhTS0gEltwDHcaO1C8DckQRIkJt5 +ON/5tZlpiK89tztX/edKk8AAD+eYeQaLXACxFZWmq+mMIWvDh6mxbuyUjYyou4VQWeA /xBk9NUW0j9F4XzrCl8b4b54D/vpBbdtx5TNT8qr2ZqbAyfERGmht13hFPsDMs0j5/8+ nEWClr7cpcp2exym5/CpTuQJpS2+fQ/cVvmwYzslC+X0KQEVsmH9pkIAqun5JxSEVTmL IO8FMg50E2D4kLfOO8OxvM9xh4wAbX65W8XzXsOx0oTEBJpKS1LVINwb2munSoHH58ul TA== 
Received: from prod-mail-ppoint2 (prod-mail-ppoint2.akamai.com [184.51.33.19] (may be forged)) by m0050095.ppops.net-00190b01. with ESMTP id 2w5p6pj3yb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Thu, 14 Nov 2019 13:41:29 +0000
Received: from pps.filterd (prod-mail-ppoint2.akamai.com [127.0.0.1]) by prod-mail-ppoint2.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xAEDGx0r009993 for <mathmesh@ietf.org>; Thu, 14 Nov 2019 08:41:27 -0500
Received: from email.msg.corp.akamai.com ([172.27.123.31]) by prod-mail-ppoint2.akamai.com with ESMTP id 2w5sny9w4e-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Thu, 14 Nov 2019 08:41:27 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb4.msg.corp.akamai.com (172.27.123.104) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Thu, 14 Nov 2019 08:41:26 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Thu, 14 Nov 2019 08:41:26 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "mathmesh@ietf.org" <mathmesh@ietf.org>
Thread-Topic: Slides and agenda uploaded
Thread-Index: AQHVmvE1Cpw1bNw3JEGitQb4TwWiLw==
Date: Thu, 14 Nov 2019 13:41:25 +0000
Message-ID: <55BF9280-DAA3-495F-B005-EA3BF13A32A2@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/10.1f.0.191110
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.114.75]
Content-Type: multipart/alternative; boundary="_000_55BF9280DAA3495FB005EA3BF13A32A2akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-14_03:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=551 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1910280000 definitions=main-1911140125
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-14_03:2019-11-14,2019-11-14 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 clxscore=1015 impostorscore=0 mlxscore=0 bulkscore=0 suspectscore=0 mlxlogscore=541 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911140126
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/pC-oEwCXLGOKglnCTlyfuOhVrpU>
Subject: [Mathmesh] Slides and agenda uploaded
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Nov 2019 13:41:32 -0000

--_000_55BF9280DAA3495FB005EA3BF13A32A2akamaicom_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

UGxlYXNlIHZpc2l0IGh0dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvbWVldGluZy8xMDYvc2Vz
c2lvbi9tYXRobWVzaCB0byBzZWUgdGhlIGFnZW5kYSBhbmQgc2xpZGVzLiAgUGxlYXNlIHBvc3Qg
Y29ycmVjdGlvbnMgdG8gdGhlIGxpc3Qgb3IgbWF0aG1lc2gtY2hhaXJzQGlldGYub3JnPG1haWx0
bzptYXRobWVzaC1jaGFpcnNAaWV0Zi5vcmc+ICBUaGFuayB5b3UuDQo=

--_000_55BF9280DAA3495FB005EA3BF13A32A2akamaicom_
Content-Type: text/html; charset="utf-8"
Content-ID: <59F0F0F2E9957F4EBB095025EA79020D@akamai.com>
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6bz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6b2ZmaWNlIiB4
bWxuczp3PSJ1cm46c2NoZW1hcy1taWNyb3NvZnQtY29tOm9mZmljZTp3b3JkIiB4bWxuczptPSJo
dHRwOi8vc2NoZW1hcy5taWNyb3NvZnQuY29tL29mZmljZS8yMDA0LzEyL29tbWwiIHhtbG5zPSJo
dHRwOi8vd3d3LnczLm9yZy9UUi9SRUMtaHRtbDQwIj4NCjxoZWFkPg0KPG1ldGEgaHR0cC1lcXVp
dj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiPg0KPG1l
dGEgbmFtZT0iR2VuZXJhdG9yIiBjb250ZW50PSJNaWNyb3NvZnQgV29yZCAxNSAoZmlsdGVyZWQg
bWVkaXVtKSI+DQo8c3R5bGU+PCEtLQ0KLyogRm9udCBEZWZpbml0aW9ucyAqLw0KQGZvbnQtZmFj
ZQ0KCXtmb250LWZhbWlseToiQ2FtYnJpYSBNYXRoIjsNCglwYW5vc2UtMToyIDQgNSAzIDUgNCA2
IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Q2FsaWJyaTsNCglwYW5vc2UtMToy
IDE1IDUgMiAyIDIgNCAzIDIgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0KcC5Nc29Ob3Jt
YWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGluOw0KCW1hcmdpbi1i
b3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5OiJDYWxpYnJp
IixzYW5zLXNlcmlmO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXBy
aW9yaXR5Ojk5Ow0KCWNvbG9yOiMwNTYzQzE7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9
DQphOnZpc2l0ZWQsIHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9y
aXR5Ojk5Ow0KCWNvbG9yOiM5NTRGNzI7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQpz
cGFuLkVtYWlsU3R5bGUxNw0KCXttc28tc3R5bGUtdHlwZTpwZXJzb25hbC1jb21wb3NlOw0KCWZv
bnQtZmFtaWx5OiJDYWxpYnJpIixzYW5zLXNlcmlmOw0KCWNvbG9yOndpbmRvd3RleHQ7fQ0KLk1z
b0NocERlZmF1bHQNCgl7bXNvLXN0eWxlLXR5cGU6ZXhwb3J0LW9ubHk7DQoJZm9udC1mYW1pbHk6
IkNhbGlicmkiLHNhbnMtc2VyaWY7fQ0KQHBhZ2UgV29yZFNlY3Rpb24xDQoJe3NpemU6OC41aW4g
MTEuMGluOw0KCW1hcmdpbjoxLjBpbiAxLjBpbiAxLjBpbiAxLjBpbjt9DQpkaXYuV29yZFNlY3Rp
b24xDQoJe3BhZ2U6V29yZFNlY3Rpb24xO30NCi0tPjwvc3R5bGU+DQo8L2hlYWQ+DQo8Ym9keSBs
YW5nPSJFTi1VUyIgbGluaz0iIzA1NjNDMSIgdmxpbms9IiM5NTRGNzIiPg0KPGRpdiBjbGFzcz0i
V29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6MTEuMHB0Ij5QbGVhc2UgdmlzaXQgPGEgaHJlZj0iaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRm
Lm9yZy9tZWV0aW5nLzEwNi9zZXNzaW9uL21hdGhtZXNoIj4NCmh0dHBzOi8vZGF0YXRyYWNrZXIu
aWV0Zi5vcmcvbWVldGluZy8xMDYvc2Vzc2lvbi9tYXRobWVzaDwvYT4gdG8gc2VlIHRoZSBhZ2Vu
ZGEgYW5kIHNsaWRlcy4mbmJzcDsgUGxlYXNlIHBvc3QgY29ycmVjdGlvbnMgdG8gdGhlIGxpc3Qg
b3INCjxhIGhyZWY9Im1haWx0bzptYXRobWVzaC1jaGFpcnNAaWV0Zi5vcmciPm1hdGhtZXNoLWNo
YWlyc0BpZXRmLm9yZzwvYT4mbmJzcDsgVGhhbmsgeW91LjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4N
CjwvZGl2Pg0KPC9ib2R5Pg0KPC9odG1sPg0K

--_000_55BF9280DAA3495FB005EA3BF13A32A2akamaicom_--


From nobody Fri Nov 15 00:35:49 2019
Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0BFDC120119 for <mathmesh@ietfa.amsl.com>; Fri, 15 Nov 2019 00:35:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VdIK5y9HdoJB for <mathmesh@ietfa.amsl.com>; Fri, 15 Nov 2019 00:35:45 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5629412008B for <mathmesh@ietf.org>; Fri, 15 Nov 2019 00:35:44 -0800 (PST)
Received: from [192.168.41.2] (unknown [49.77.183.152]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by tuna.sandelman.ca (Postfix) with ESMTPSA id 5868F3897C for <mathmesh@ietf.org>; Fri, 15 Nov 2019 03:32:33 -0500 (EST)
To: mathmesh@ietf.org
References: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca> <A545E94E-E05C-4DC2-8EEB-2682C8EA8936@tzi.org>
From: Michael Richardson <mcr+ietf@sandelman.ca>
Message-ID: <a88be414-104e-498d-2ad3-3ddd04f813d4@sandelman.ca>
Date: Fri, 15 Nov 2019 16:35:37 +0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <A545E94E-E05C-4DC2-8EEB-2682C8EA8936@tzi.org>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/1HF-xaxPeXtQqyLUASvBX4NvRvQ>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Nov 2019 08:35:47 -0000

On 2019-11-12 11:30 p.m., Carsten Bormann wrote:
> RFC 6920


  which is: Naming Things with Hashes

while it provides for retrieving things via a /.well-known interface,
and it provides for human readable (nih), it just feels too hard to use
in practice.  I think that I can build a udf:// server with any stock
static web server by just putting the things into a flat directory, with
the files named for the encrypted/hashed items.

ni:// supports fixing the content, but not encrypting it.

So I agree that there is significant overlap, and maybe we can make
udf:// an extension of ni://.  We should explore that.



From nobody Sun Nov 17 22:26:08 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3BFF612089E for <mathmesh@ietfa.amsl.com>; Sun, 17 Nov 2019 22:26:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.406
X-Spam-Level: 
X-Spam-Status: No, score=-1.406 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.244, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id swNX112K2E0r for <mathmesh@ietfa.amsl.com>; Sun, 17 Nov 2019 22:26:05 -0800 (PST)
Received: from mail-oi1-f169.google.com (mail-oi1-f169.google.com [209.85.167.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9AA851200B3 for <mathmesh@ietf.org>; Sun, 17 Nov 2019 22:26:05 -0800 (PST)
Received: by mail-oi1-f169.google.com with SMTP id l202so14324941oig.1 for <mathmesh@ietf.org>; Sun, 17 Nov 2019 22:26:05 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=nOjabwOnXAEFnOqUUtSRisxMKG03aVI/FGMZm1E1+j4=; b=rHnckr3IZfFff+tjjG5RlYqpWgzCJUvvOHAE35+nYJpDnXDin8gmla1EDt7XZ3KcSC upaM9J7YQFPl8Nrzf4zPsm+r90hWHtfE3EIsYdXyMAjDsd7wSFunpJDV0Ihy7ZyUO9kD AW8YOaOuvcu7azHhG1lR72gRd4G6nyjw+nbRLafGlDqboHS2EyjjjKd8esAO6M+DrvnW IlSen1FHrZi+gXiNkHVMIiafJq5ej2e3SMQyn17kbjfTBFOP+m01QgM9nB3DQId+EfFI U+XuTSe3MPRktd53JnLiFVerIwIjRP7P8c2YX+ioMnS0nIMnFRvofSLi44DQZJtwQmcR M6BQ==
X-Gm-Message-State: APjAAAWPVCYIq5h2N2lS6CNNhMtt/In4WW3+j9IGlFoBzt4gi0vjyC+t 770o784I5Nypgclk4gA3yqHZWlXa07Rpo2ABXi6vzTsQil0=
X-Google-Smtp-Source: APXvYqz0KNXQYJCy/Okb8pMgu1loIDXDED9Z6X8LJGeouryEupoqlRfAuzhm1jJp1/YQwQfcEuxARuzyWNr//LwAlNY=
X-Received: by 2002:aca:484e:: with SMTP id v75mr19180605oia.6.1574058364791;  Sun, 17 Nov 2019 22:26:04 -0800 (PST)
MIME-Version: 1.0
References: <2301212a-ebea-7c8d-f52a-83e2988df71e@sandelman.ca> <A545E94E-E05C-4DC2-8EEB-2682C8EA8936@tzi.org> <a88be414-104e-498d-2ad3-3ddd04f813d4@sandelman.ca>
In-Reply-To: <a88be414-104e-498d-2ad3-3ddd04f813d4@sandelman.ca>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Mon, 18 Nov 2019 14:25:53 +0800
Message-ID: <CAMm+LwgkNjig6gHkjyffoi+_rwFgHLj0dRYEsL3p1oN6qhG=fA@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Cc: mathmesh@ietf.org
Content-Type: multipart/alternative; boundary="000000000000b070750597990557"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/wcGA0G1bhGNMBg0Qm0z_0yyVzEE>
Subject: Re: [Mathmesh] Using UDF for CDN content
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Nov 2019 06:26:07 -0000

--000000000000b070750597990557
Content-Type: text/plain; charset="UTF-8"

The encryption piece was dropped from the main document. But it is in the
draft:

https://tools.ietf.org/html/draft-hallambaker-decade-ni-params-03

If there was a ni userbase, I would have resurrected this already. But I
don't think there is.



On Fri, Nov 15, 2019 at 4:35 PM Michael Richardson <mcr+ietf@sandelman.ca>
wrote:

>
>
> On 2019-11-12 11:30 p.m., Carsten Bormann wrote:
> > RFC 6920
>
>
>   which is: Naming Things with Hashes
>
> while it provides for retrieving things via a /.well-known interface,
> and it provides for human readable (nih), it just feels too hard to use
> in practice.  I think that I can build a udf:// server with any stock
> static web server by just putting the things into a flat directory, with
> the files named for the encrypted/hashed items.
>
> ni:// supports fixing the content, but not encrypting it.
>
> So I agree that there is significant overlap, and maybe we can make
> udf:// an extension of ni://.  We should explore that.
>
>
> --
> Mathmesh mailing list
> Mathmesh@ietf.org
> https://www.ietf.org/mailman/listinfo/mathmesh
>

--000000000000b070750597990557
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">The=
 encryption=C2=A0piece was dropped from the main document. But it is in the=
 draft:</div><div class=3D"gmail_default" style=3D"font-size:small"><br></d=
iv><div class=3D"gmail_default" style=3D"font-size:small"><a href=3D"https:=
//tools.ietf.org/html/draft-hallambaker-decade-ni-params-03">https://tools.=
ietf.org/html/draft-hallambaker-decade-ni-params-03</a><br></div><div class=
=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"gmail_=
default" style=3D"font-size:small">If there was a ni userbase, I would have=
 resurrected this already. But I don&#39;t think there is.=C2=A0</div><div =
class=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"g=
mail_default" style=3D"font-size:small"><br></div></div><br><div class=3D"g=
mail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Nov 15, 2019 at 4=
:35 PM Michael Richardson &lt;<a href=3D"mailto:mcr%2Bietf@sandelman.ca">mc=
r+ietf@sandelman.ca</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex"><br>
<br>
On 2019-11-12 11:30 p.m., Carsten Bormann wrote:<br>
&gt; RFC 6920<br>
<br>
<br>
=C2=A0 which is: Naming Things with Hashes<br>
<br>
while it provides for retrieving things via a /.well-known interface,<br>
and it provides for human readable (nih), it just feels too hard to use<br>
in practice.=C2=A0 I think that I can build a udf:// server with any stock<=
br>
static web server by just putting the things into a flat directory, with<br=
>
the files named for the encrypted/hashed items.<br>
<br>
ni:// supports fixing the content, but not encrypting it.<br>
<br>
So I agree that there is significant overlap, and maybe we can make<br>
udf:// an extension of ni://.=C2=A0 We should explore that.<br>
<br>
<br>
-- <br>
Mathmesh mailing list<br>
<a href=3D"mailto:Mathmesh@ietf.org" target=3D"_blank">Mathmesh@ietf.org</a=
><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mathmesh" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mathmesh</a><br>
</blockquote></div>

--000000000000b070750597990557--


From nobody Mon Nov 18 17:04:36 2019
Return-Path: <rsalz@akamai.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 443521200F7 for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 17:04:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QDfKPwFPxLiq for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 17:04:32 -0800 (PST)
Received: from mx0a-00190b01.pphosted.com (mx0a-00190b01.pphosted.com [IPv6:2620:100:9001:583::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EDFCB12000F for <mathmesh@ietf.org>; Mon, 18 Nov 2019 17:04:31 -0800 (PST)
Received: from pps.filterd (m0050095.ppops.net [127.0.0.1]) by m0050095.ppops.net-00190b01. (8.16.0.42/8.16.0.42) with SMTP id xAJ0vGDr011162 for <mathmesh@ietf.org>; Tue, 19 Nov 2019 01:04:31 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : content-type : mime-version; s=jan2016.eng; bh=b3avlQf+ErF2/ZZFx8YFpa6lHsRDILMIPAH3QHI//eE=; b=FxNGecA2OvzQG06DH2FKuYYXjRnac2fEBBNQ6G+jxd5ROAMmekWSFpYDWLamIw3jUX4g bLqA6ItEsbwfJeDumlTWe01F392bomt01YWFzI+/cBnUT+msy/t+QQcw6B8g7bhbYv8F 3as7fcWfFsGpNc7FzjMvBwaFMbErcIobYdbgJZsCuusZ0bpxn9EHVjwF06iU40QxWtkv BVlr+0e84dFVpPY2Chm2aGY1wkMnqffyj1QZ6VPZEebfxyELPDe0RsCkIyzlDLLn8oOM hlG0aMwmSeJ/FN7XF69S+yEKZUgSZyJuVXDDv/r2zPdAB+6Kz2S+EGiQbHxE0BNOybOO gg== 
Received: from prod-mail-ppoint5 (prod-mail-ppoint5.akamai.com [184.51.33.60] (may be forged)) by m0050095.ppops.net-00190b01. with ESMTP id 2wafwvba38-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Tue, 19 Nov 2019 01:04:31 +0000
Received: from pps.filterd (prod-mail-ppoint5.akamai.com [127.0.0.1]) by prod-mail-ppoint5.akamai.com (8.16.0.27/8.16.0.27) with SMTP id xAJ134SJ024355 for <mathmesh@ietf.org>; Mon, 18 Nov 2019 17:04:30 -0800
Received: from email.msg.corp.akamai.com ([172.27.123.34]) by prod-mail-ppoint5.akamai.com with ESMTP id 2wafybks6x-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT) for <mathmesh@ietf.org>; Mon, 18 Nov 2019 17:04:30 -0800
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com (172.27.123.103) by usma1ex-dag1mb3.msg.corp.akamai.com (172.27.123.103) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 18 Nov 2019 20:04:29 -0500
Received: from USMA1EX-DAG1MB3.msg.corp.akamai.com ([172.27.123.103]) by usma1ex-dag1mb3.msg.corp.akamai.com ([172.27.123.103]) with mapi id 15.00.1473.005; Mon, 18 Nov 2019 20:04:29 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: "mathmesh@ietf.org" <mathmesh@ietf.org>
Thread-Topic: Draft minutes
Thread-Index: AQHVnnVK9QjLdJd2u0q21JiTzcUbwQ==
Date: Tue, 19 Nov 2019 01:04:27 +0000
Message-ID: <CDE69C84-50BE-45C6-A1CA-7E3961FDA913@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/10.1f.0.191110
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.19.216.123]
Content-Type: multipart/mixed; boundary="_002_CDE69C8450BE45C6A1CA7E3961FDA913akamaicom_"
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-11-18_08:, , signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1911140001 definitions=main-1911190006
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.95,18.0.572 definitions=2019-11-18_08:2019-11-15,2019-11-18 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 lowpriorityscore=0 priorityscore=1501 phishscore=0 clxscore=1015 mlxlogscore=999 impostorscore=0 suspectscore=0 bulkscore=0 malwarescore=0 adultscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-1911190005
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/Ke1P8THUvOezT0AJkh8GU1vq4_c>
Subject: [Mathmesh] Draft minutes
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Nov 2019 01:04:34 -0000

--_002_CDE69C8450BE45C6A1CA7E3961FDA913akamaicom_
Content-Type: text/plain; charset="utf-8"
Content-ID: <00C26DEED9C16D4398966B90283CE3CC@akamai.com>
Content-Transfer-Encoding: base64

VGhhbmtzIHZlcnkgbXVjaCB0byBNZWxpbmRhIGZvciB0YWtpbmcgcXVpdGUgZGV0YWlsZWQgbWlu
dXRlcy4gIFBsZWFzZSBwb3N0IGNvcnJlY3Rpb25zIHRvIHRoZSBsaXN0Lg0KKEkga25vdyBXZXMg
aGFzIG1hbnkgbm90ZXMgdG8gYWRkLCBqdWRnaW5nIGJ5IGhpcyB0eXBpbmcgYXQgdGhlIGNoYWly
cyBkZXNrIDopIA0KDQo=

--_002_CDE69C8450BE45C6A1CA7E3961FDA913akamaicom_
Content-Type: text/plain; name="mathmesh.txt"
Content-Description: mathmesh.txt
Content-Disposition: attachment; filename="mathmesh.txt"; size=7623;
 creation-date="Tue, 19 Nov 2019 01:04:27 GMT";
 modification-date="Tue, 19 Nov 2019 01:04:27 GMT"
Content-ID: <441377CD0D355747A452F04FF3C55809@akamai.com>
Content-Transfer-Encoding: base64

77u/TWF0aGVtYXRpY2FsIE1lc2ggQk9GCjE4IG5vdiAyMDE5CgpBZG1pbmlzdHJpdmlhIC4uLgot
LS0tLS0tLS0tLS0tLS0tLQoKCk92ZXJ2aWV3Ci0tLS0tLS0tCgpUaGUgb2JqZWN0aXZlIGlzIHRv
IG1ha2UgY29tcHV0ZXJzIGVhc2llciB0byB1c2UgYnkgbWFraW5nCnRoZW0gbW9yZSBzZWN1cmUu
ICBDcnlwdG9ncmFwaGljYWxseSBjb25uZWN0IGV2ZXJ5IGRldmljZQpBbGljZSBvd25zIHRvIGVh
Y2ggb3RoZXIgLSBwZXJzb25hbCBtZXNoLiAgRW5hYmxlIHVzZSBvZgpzdHJvbmcgZW5kLXRvLWVu
ZCBlbmNyeXB0aW9uLgoKVGhyZWUgY29yZSBwcm9ibGVtczoKLiBwcm92aXNpb24gcHJpdmF0ZSBr
ZXlzIHRvIGFsbCBkZXZpY2VzCi4gcHJvdmlkZSB0aGUgbWVhbnMgdG8gb2J0YWluIGFuZCB2YWxp
ZGF0ZSBwcml2YXRlIGtleXMKLiBzZWN1cmUgZGF0YSBhdCByZXN0CgpUb2RheSB3ZSBoYXZlIHNp
bG9lZCBhcHBsaWNhdGlvbnMgJiBzZXBhcmF0ZSBjb25maWd1cmF0aW9ucywKc2VjdXJpdHkgZmFs
bHMgYmV0d2VlbiB0aGUgY3JhY2tzLgoKTWVzaCBDb3JlIGRlcGVuZHMgb24gVURGIChuYW1pbmcg
aW5mcmFzdHJ1Y3R1cmUpLCBEQVJFCihjcnlwdG9ncmFwaGljIGVudmVsb3BlcyksIGFuZCBNZXRh
LUNyeXB0b2dyYXBoeSAobmV3IGNyeXB0bwpwcmltaXRpdmVzKS4gIE1lc2ggQ29yZSBwcm92aWRl
cyBuYXJyb3cgd2Fpc3QgaW4gdGhlIE1lc2gKYXJjaGl0ZWN0dXJlLgoKUHJvcG9zaW5nIHRoYXQg
Zm9yIHBoYXNlIDEsIHBpY2sgb25lIG9yIHR3byBhcHBsaWNhdGlvbnMsCnByb3ZpZGUgcHJvb2Yg
b2YgY29uY2VwdC4gIFByb3Bvc2VzIGZvY3VzIG9uIHBhc3N3b3Jkcy4KCk1lc2ggcGFzc3dvcmQg
Y2F0YWxvZyBwcm92aWRlcyA5MCUgY292ZXJhZ2Ugb2YgbWVzaApmdW5jdGlvbmFsaXR5LiAgRG9l
cyBub3QgcmVseSBvbiBuZXR3b3JrIGVmZmVjdCwgYWRkcmVzc2VzCmZuY3Rpb25hbCBwYXNzd29y
ZCBwcm9ibGVtLiAgQW4gb3BlbiBzdGFuZGFyZCBmb3IgYSBwYXNzd29yZAp2YXVsdC4KCk1ha2Ug
QWxpY2UgaGVyIG93biByb290IG9mIHRydXN0LiAgU2hlIGNyZWF0ZXMgYSBwZXJzb25hbApNZXNo
IHByb2Zpa2xlLiAgTWFzdGVyIHNpZ25hdHVyZSBrZXksIGFkbWluaXN0cmF0aW9uIGtleXMuCklu
c3RhbGxzIGFwcCBvbiBoZXIgbW9iaWxlIHBob25lLCBhZGQgbW9yZSBkZXZpY2VzIGJ5CnNjYW5u
aW5nIFFSIGNvZGUsIG9yIGluc3RhbGxpbmcgYW4gYXBwIGFuZCByZXF1ZXN0aW5nCmNvbm5lY3Rp
b24uCgpFdmVyeSBjb25uZWN0ZWQgZGV2aWNlIGhhcyB0aGUgc2FtZSB3b3JsZCB2aWV3LiAgRXZl
cnkKY29ubmVjdGVkIGRldmljZSBjYW4gYXV0aGVudGljYXRlIG1lc3NhZ2VzIG9mIGJlaW5nICJv
ZgpBbGljZSIKCk1lc2ggY29tcG9uZW50cwouIE1lc2ggc2NoZW1hCi4gTWVzaCBhY2NvdW50Ci4g
TWVzaCBzZXJ2aWNlCgpFS1I6IGhvdyBkb2VzIHRoaXMgY29ubmVjdCB0byBwYXNzd29yZCB2YXVs
dD8gIFBIQjogaWYgdGhpcwppcyBvbiBvbmUgbWFjaGluZSwgc3RvcmVkIGxvY2FsbHkuICBJZiB5
b3UndmUgZ290IDIwCm1hY2hpbmVzLCBwYXNzd29yZCBjaGFuZ2UgaXMgcmVwbGljYXRlZCBhY3Jv
c3MgYWxsIG1hY2hpbmVzCncvbyBjZW50cmFsaXplZCBwYXNzd29yZCB2YXVsdC4KCkRpbm86ICBo
b3cgdG8gbWFuYWdlIHBhc3N3b3JkcyBmb3Igd2ViLWJhc2VkIHNlcnZpY2VzPyAgUEhCOgphcyBt
YW55IHBhc3N3b3JkcyBhcyB5b3Ugd2FudAoKTWljaGFlbCBSaWNoYXJkc29uOiAgSG93IGRvZXMg
dGhpcyBzdG9wIGEgdGhpZWYgd2hvIGhhcyB5b3VyCnBob25lIGZyb20gZ2V0dGluZyB5b3VyIHBh
c3N3b3Jkcz8gIFlvdSBjYW4gdGVsbCB0aGUgc2VydmljZQpub3QgdG8gcHJvdmlkZSBkZWNyeXB0
aW9uIGtleXMuICBJZiB0aGllZiBnZXRzIHRoZXJlIGZpcnN0CnRoZXJlJ3Mgbm90aGluZyB5b3Ug
Y2FuIGRvLiAgUTogY2FuIEkgZG8gc2VsZWN0aXZlIHBhc3N3b3JkCnNoYXJpbmc/ICBBOiB5ZXMK
ClVERgotLS0KCmJhc2UtMzIgZW5jb2Rpbmcgb2YgY3J5cHRvZ3JhcGhpYyBkYXRhIChkaWdlc3Rz
LCBNQUNzLApzeW1tZXRyaWMga2V5cywgZXRjLikuICBBbGwgTWVzaCBrZXktaWRzIGFyZSBDb250
ZW50LURpZ2VzdApVREZzLgoKCkRBUkUgKGRhdGEgYXQgcmVzdCBlbnZlbG9wZSkKLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLS0tLQoKQmxvY2tjaGFpbiBpbiBKU09OLiAgUEtDUyM3IGZvciBKU09O
IFNpZ25hdHVyZSBhbmQKRW5jcnlwdGlvbi4gIE1lc2ggdXNlcyBzdGFuZGFyZCBlbmNyeXB0aW9u
LCBzaWduYXR1cmUgYW5kCnZlcmlmaWNhdGlvbi4gIFVzZXMgS0RGICg8bWFzdGVyIHNlY3JldD4s
PG5vbmNlPikgdG8gZGVyaXZlCklWIGFuZCBlbmNyeXB0aW9uLCBNQUMga2V5IChpZiBuZWVkZWQp
LCBzaWduYXR1cmUgd2l0bmVzcwp2YWx1ZS4KCkFwcGVuZC1vbmx5IGxvZyBmb3JtYXQgKHVzZXMg
TWVya2xlIHRyZWUpIHByb3ZpZGVzCmluY3JlbWVudGFsIGF1dGhlbnRpY2F0aW9uLCBpbmNyZW1l
bnRhbCBlbmNyeXB0aW9uLiAgQ2FuCnN1cHBvcnQgYW4gYXJjaGl2ZSBmb3JtYXQuCgpEQVJFIGNh
dGFsb2cgLSBwZXJzaXN0ZW5jZSBzdG9yZSBiYXNlZCBvbiBEQVJFIHNlcXVlbmNlLgoKRGlubzog
IGRvIHlvdSB0aGluayB0aGUgTWVzaCBzZXJ2aWNlIGlzIGRlY2VudHJhbGl6ZWQ/ICBBOgp5ZXMK
Ck1ldGEtQ3J5cHRvZ3JhcGh5Ci0tLS0tLS0tLS0tLS0tLS0tCgpyZWJyYW5kaW5nIHRocmVzaG9s
ZCBjcnlwdG8sIGV0Yy4KCktleSBjb21iaW5hdGlvbjoKICAgIFByaXZhdGUga2V5IFggLT4gUHVi
bGljIGtleSBYID0geC5QCiAgICBQcml2YXRlIEtleSBZIC0+IFB1YmxpYyBrZXkgWSAtIHkuUAog
ICAgUHJpdmF0ZSBLZXkgeiA9IHggKyB5IC0+IHogPSAoeCArIHkpLlAgPSBYICsgWQoKQ2FuIGRv
IGF3YXkgd2l0aCBwcm9vZi1vZi1wb3NzZXNzaW9uIGFzIGEgcmVzdWx0LgoKS2V5IHNwbGl0dGlu
ZwoKU25vd2Rlbi1wcm9vZiBrZXkgbWFuYWdlbWVudDogIENsb3VkIHNlcnZpY2UgY2FuIGNvbnRy
b2wKZGVjcnlwdGlvbiBidXQgY2Fubm90IGRlY3J5cHQuICBDbG91ZCBvbmx5IGtub3dzIGEgcmFu
ZG9tCm51bWJlciB0aGF0IGNhbiBiZSBnZW5lcmF0ZWQgd2l0aG91dCBrbm93bGVkZ2Ugb2YgcHJp
dmF0ZQprZXkuCgpTdGVwaGVuOiAgaXQncyB1bmNsZWFyIHRvIG1lIHRoYXQgd2hhdCB5b3UncmUg
cHJlc2VudGluZwpzdGF5cyBhcyBzaW1wbGUgYXMgaXQgaXMgd2l0aG91dCB0dXJuaW5nIGludG8g
c29tZXRoaW5nIGFzCmNvbXBsaWNhdGVkIGFzIE1MUy4KCkplZmZyZXkgWWFzc2tpbjogaG93IGFy
ZSB5b3UgaGFuZGxpbmcgdHJ1c3QgLSBpbmZvcm1hdGlvbiBpcwpoaWRkZW4gZnJvbSBzZXJ2aWNl
IGJ1dCBpdCdzIGJlaW5nIHRydXN0ZWQgdG8gbWFuYWdlIHVzZXJzPwpBOiBzZXBhcmF0aW9uIG9m
IGR1dGllcyBjYW4gYmUgYXBwbGllZC4gIEJlbjogIHRoZSBzdGFydGluZwpwcmVtaXNlIGlzIHRo
YXQgd2Ugd2FudCBzb21ldGhpbmcgdGhhdCBpcyBlYXN5IHRvIHVzZSwgYW5kCnRoYXQgY2FuIGlt
cGFjdCBzZWN1cml0eSBjb25zdHJhaW50cwoKCkRpc2N1c3Npb24KLS0tLS0tLS0tLQoKRXJpayBO
b3JkbWFyazogIGNhbiB3ZSBkbyB0aGlzIGZvciBkZXZpY2VzIHRoYXQgZG9uJ3QgaGF2ZQp1c2Vy
IGludGVyZmFjZXM/CgpSb21hbjogSXMgdGhlIGZvY3VzIG9uIHNvbHZpbmcgdGhlIHBhc3N3b3Jk
IHByb2JsZW0sIG9yIGlzCnRoZSBwYXNzd29yZCBwcm9ibGVtIGEgdXNlIGNhc2UgZm9yIGEgYnJv
YWRlciBlZmZvcnQuICBQSEI6CndvdWxkIHByZWZlciB0aGUgbGF0dGVyCgpSb21hbjogSSBzdHJ1
Z2dsZSB3aXRoIGhvdyB0byBtZWFzdXJlIHN1Y2Nlc3MgZm9yIHRoZQpicm9hZGVyIGVmZm9ydAoK
TWljaGFlbCBSaWNoYXJkc29uOiAgSSBhbSB3aXRoIFBoaWxsIGluIHRoYXQgSSB3b3VsZCBsaWtl
IHRvCnNvbHZlIHBhc3N3b3JkIHByb2JsZW0gYXMgYSBzdGVwIGFsb25nIHRoZSB3YXkgZm9yIHRo
ZQpicm9hZGVyIHByb2JsZW0KCkJlbjogIHdpdGggbm8gaGF0LCBJJ20gcHJldHR5IGV4Y2l0ZWQg
YWJvdXQgd29ya2luZyBvbiB0aGUKYnJvYWRlciB0ZWNobm9sb2d5IHF1ZXN0aW9ucy4KCkVLUjog
dGhlcmUgYXJlIHF1aXRlIGEgZmV3IHBlb3BsZSBhbHJlYWR5IGRvaW5nIHBhc3N3b3JkCnN5bmMu
ICBXaGljaCBjb21wYW5pZXMgd291bGQgdXNlIHRoaXM/ICBXZXM6IHNvbWV0aGluZyB0aGF0Cndv
dWxkIGNvbWUgb3V0IG9mIHRoaXMgd291bGQgYmUgaW50ZXJvcGVyYWJsZSBwYXNzd29yZAptYW5h
Z2VtZW50LgoKTGF1cmVuY2UgTHVuZGJsYWRlOiBzdWJzdGFudGlhbCBvdmVybGFwIHdpdGggd29y
ayBiZWluZyBkb25lCmluIHRoZSBGSURPIEFsbGlhbmNlCgpCZW4gS2FkdWs6ICBUaGVyZSBhcmUg
b3RoZXIgcG90ZW50aWFsIHVzZSBjYXNlcyBpbiBhZGRpdGlvbgp0byBwYXNzd29yZCBtYW5hZ2Vt
ZW50L3N5bmMuCgpFcmlrOiAgSSB3b3VsZCBhcHBseSBwaWVjZXMgb2YgdGhpcyB0byBJb1Qgb3Ig
ZWRnZQpjb21wdXRpbmcuCgpBbGV4OiB0aGlzIHNlZW1zIHJlbGF0ZWQgdG8gZGVjZW50cmFsaXpl
ZCBpZGVudGl0eSB3b3JrIGF0CnRoZSBXM0MuICBUaGUgbWFpbiBnb2FsIG9mIHRoaXMgd29yayBp
cyB0byBnZXQgcmlkIG9mCnBhc3N3b3Jkcy4KCldlczogIHlvdSdyZSBub3QgYWN0dWFsbHkgZ2V0
dGluZyByaWQgb2YgcGFzc3dvcmRzLCByaWdodD8KSXQncyBhIHBhc3N3b3JkIHN0b3JhZ2Ugc3lz
dGVtPyAgUEhCOiAgeW91J3JlIHVzaW5nIGtleXMsIHNvCnlvdSdyZSBtb3ZpbmcgYXdheSBmcm9t
IHBhc3N3b3JkcyBidXQgbm90IGdldHRpbmcgcmlkIG9mCnRoZW0gZW50aXJlbHkKCkJlbjogIGlz
bid0IHRoaXMgYSBrZXkgc3luYyBwcm90b2NvbCByYXRoZXIgdGhhbiBhIHBhc3N3b3JkCnN5bmMg
cHJvdG9jb2w/ICBQSEI6ICB5ZXMKCkRhdmlkIFNjaGluYXppOiB0aGlzIGZlZWxzIGxpa2UgYSBn
cmFuZCB1bmlmaWVkIHRoZW9yeSBvZgpjcnlwdG9ncmFwaHksIGEgd2F5IHRvIHRpZSBhIGxvdCBv
ZiB0aGluZ3MgdG9nZXRoZXIuICBUaGlzCmlzIG5vdCB3aGF0IHRoZSBJRVRGIGRvZXMgd2VsbC4g
IFRoZSBJRVRGIHNvbHZlcyBzcGVjaWZpYwpwcm9ibGVtcy4gIFNvLCBwaWNrIGEgdXNlIGNhc2Uu
ICBUaGlzIGlzIGN1cnJlbnRseSB3YXkgdG9vCnZhZ3VlIHRvIGJlIHRyYWN0YWJsZS4KCkVLUjog
RGF2aWQgc2FpZCB0aGUgdGhpbmdzIEknZCBoYXZlIHNhaWQuICBJcyB0aGVyZSBhIHVzZXIKY29t
bXVuaXR5IHRoYXQgd2FudHMgdGhhdCBib3ggc29sdmVkPyAgTGV0J3MgZmluZCBhIGN1c3RvbWVy
CmZvciB0aGlzIHdobydzIGV4Y2l0ZWQgYWJvdXQgaXQ/CgpNaWNoYWVsOiAgZWNob2VzIEVLUi4g
IEdhdmUgZXhhbXBsZSBvZiBtYW5hZ2VtZW50IG9mIGJlYXJlcgp0b2tlbnMKCkNocmlzIFdvb2Q6
ICBBcyBhbiBvcGVyYXRpbmcgc3lzdGVtIHZlbmRvciwgd2Ugd291bGQgbm90IGJlCmludGVyZXN0
ZWQgaW4gaW50ZXJvcGVyYWJsZSBhbnkgb2YgdGhpcwoKV2VzOiAgVGhlcmUncyBhIGZhaXIgYW1v
dW50IG9mIHJlc2lzdGFuY2UgdG8gdGhlIHBhc3N3b3JkCnByb2JsZW0sIGJ1dCB0aGVyZSBpcyBp
bnRlcmVzdCBpbiBvdGhlciBwaWVjZXMuICBSb21hbjogIHdlCmRpZG4ndCBkaXZlIGludG8gYW55
IG9mIHRoZSBibHVlIGJveGVzIGluZGl2aWR1YWxseS4KCk1pY2hhZWw6ICBVREYgcHJvdmlkZXMg
YSB3YXkgdG8gcGFzcyBjZXJ0aWZpY2F0ZXMgYnkKcmVmZXJlbmNlIHJhdGhlciB0aGFuIGJ5IHZh
bHVlLiAgV2FudHMgdG8gcmVpdGVyYXRlIElvVApiYWNrdXAvcmVzdG9yZSBwcm9ibGVtIGhhcyBu
byBzb2x1dGlvbiBjdXJyZW50bHkuCgpCZW46ICBEb2VzIE1pY2hhZWwgdGhpbmsgdGhlcmUgYXJl
IHBlb3BsZSBpbiB0aGUgcm9vbSBvciBpbgpJRVRGIHdobydkIGJlIGludGVyZXN0ZWQgaW4gdXNp
bmcgdGhpcz8gIE1pY2hhZWw6ICBUaGVyZSBhcmUKcGVvcGxlIGluIHRoZSByb29tIHdvcmtpbmcg
Zm9yIHRob3NlIGNvbXBhbmllcywgYWx0aG91Z2ggdGhlCnBlb3BsZSBwcmVzZW50IGFyZW4ndCB3
b3JraW5nIG9uIHRob3NlIHByb2R1Y3RzCgpKb25hdGhhbiBIYW1pbDogIEkgZG9uJ3Qgc2VlIGEg
cGF0aCB0byBxdWFudHVtIHJlc2lzdGFuY2U/Ck15IG1haW4gY29uY2VybiBpcyB0aGF0IGJ5IHRo
ZSB0aW1lIHRoaXMgaXMgZGVwbG95ZWQgaXQKd29uJ3QgYmUgc2VjdXJlLiAgUEhCOiBkb2Vzbid0
IHRoaW5rIHdlJ3JlIGNsb3NlIHRvIGhhdmluZwphY3R1YWwgcXVhbnR1bSBjb21wdXRlcnMuICBF
c2NhcGUgaG9sZSB3b3VsZCBiZSBiYXNlZCBvbgpLZXJiZXJvcyBvciBMYW1wb3J0IGhhc2ggc2ln
bmF0dXJlcy4KClJpY2hhcmQgQmFybmVzOiAgQ2lzY28gaXMgd29ya2luZyBvbiBJb1QgYnV0IHRo
aXMgZG9lc24ndAptYXAgd2VsbCB0byB3aGF0IENpc2NvIGlzIGRvaW5nLgoKQmVuOiAgeW91J3Zl
IHN1bW1hcml6ZWQgY29ycmVjdGx5IHdoYXQgd2UndmUgaGVhcmQgaW4gdGhlCnJvb20uICBUaGVy
ZSdzIHBvdGVudGlhbCBoZXJlIGJ1dCBub3QgYSBsb3Qgb2YgaW50ZXJlc3QgaW4KdGhlIHJvb20g
aW4gc3BlY2lmaWMgdXNlIGNhc2VzLiAgV291bGQgbGlrZSB0byBzdWdnZXN0CnRoZXJlJ3MgcG90
ZW50aWFsIGluIHRoZSBibHVlIGJveGVzLiAgV2lsbCB0YWtlIGh1bXMKCkVLUjogIHdlIHJlYWxs
eSBkaWRuJ3QgaGF2ZSBtdWNoIGRpc2N1c3Npb24gb2YgdGhlIG1lcml0cyBvZgp0aGVzZSBwaWVj
ZXMgb2Ygd29yawoKQmVuOiAgYXNrZWQgd2hvIHJlYWQgaW5kaXZpZHVhbCBkb2N1bWVudHM/ICBB
Ym91dCAxMCBpbiBlYWNoCmNhc2UKCkRhdmlkOiAgcHJvY2VzcyBxdWVzdGlvbiAtIHRoZXJlJ3Mg
bm8gcHJvYmxlbSBzdGF0ZW1lbnQgZm9yCnRoZSBibHVlIGJveGVzLiAgQmVuOiAgVGhhdCdzIGEg
ZmFpciBwb2ludC4KCk1pY2hhZWw6ICBXZSdyZSBhbGxvd2VkIHRvIGhhdmUgYSBzZWNvbmQgQk9G
LCBhbmQgbWF5YmUKeW91J3JlIGFza2luZyB5b3VyIHF1ZXN0aW9ucyBwcmVtYXR1cmVseS4gIFNo
b3VsZCB3ZSBhc2sgaWYKdGhlcmUgc2hvdWxkIGJlIGEgc2Vjb25kIEJPRj8KCldlczogIENhbiBJ
IHJlcGhyYXNlIHRoaXMgYXMgYSBtb3JlIHBvc2l0aXZlIHBvaW50PyAgRG8KcGVvcGxlIGJlbGll
dmUgdGhlcmUgYXJlIHByb2JsZW0gc3BhY2VzIHRoYXQgdGhlc2UKdGVjaG5vbG9naWVzIG1pZ2h0
IGJlIHJlbGV2YW50IHRvCgpNYXJ0aW4gVGhvbXNvbjogIGlzIHRoZXJlIGEgY29uc3RpdHVlbmN5
IGZvciB0aGlzIHdvcmsgaW4KdGhlIElFVEY/CgpSb21hbjogIHdlIGRpZG4ndCBmaW5kIGEgY29u
c3RpdHVlbmN5IGZvciBhbnkgb2YgdGhlIG9yYW5nZQpib3hlcywgYnV0IHdoYXQgYWJvdXQgYmx1
ZT8KCkJlbjogSXMgdGhlcmUgYW55IHRlY2hub2xvZ3kgaGVyZSB0aGF0IGFueWJvZHkgd291bGQg
bGlrZSB0bwprbm93IG1vcmUgYWJvdXQ/CgpSb21hbjogIEdpdmVuIHRoZSBzbWFsbCBudW1iZXIg
b2YgcGVvcGxlIHdobyd2ZSByZWFkIHRoZQpkb2N1bWVudHMsIGJhc2VkIG9uIHRoZSBkaXNjdXNz
aW9uIHNvIGZhciB0aGVyZSdzIGludGVyZXN0CmluIHJlYWRpbmcgdGhlIGRvY3VtZW50cyBhbmQg
ZmluZGluZyBvdXQgbW9yZT8gIEh1bSByZXN1bHRlZAppbiAieWVzLiIK

--_002_CDE69C8450BE45C6A1CA7E3961FDA913akamaicom_--


From nobody Mon Nov 18 18:08:56 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 029A8120232 for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 18:08:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.405
X-Spam-Level: 
X-Spam-Status: No, score=-1.405 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.244, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LFvHMy1EifvI for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 18:08:50 -0800 (PST)
Received: from mail-oi1-f181.google.com (mail-oi1-f181.google.com [209.85.167.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C748A12004E for <mathmesh@ietf.org>; Mon, 18 Nov 2019 18:08:50 -0800 (PST)
Received: by mail-oi1-f181.google.com with SMTP id s71so17383533oih.11 for <mathmesh@ietf.org>; Mon, 18 Nov 2019 18:08:50 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=40CLUqmapbVMgzjmu/pzRn+8e0jcr+AcNM+h8Rav/xc=; b=BfDHYKzptDii6O8gTdNe8MaNWZ+HMvSy8+TFbbt63r2/FsRuz4GZ5hn1PZsw3I/vZ/ z+qQExiLGd3oThSTgk4Lqd9PulZxjp69NECPtNBD4F+TWQxRmLXs39Noe7amdhuE9Yws q5W0nxH0hcQ4PRS/+rMdug63/bK9WE6ziFTLg7pA7ha8Tx0hRTMwFn4ZZ4OocawiKRy4 jYSnaQCeEQwiAfpWtTfIMxG3iGBDbJ2XhdpwLpjqU6juDetuTMJ2HGh7fyacEGBVvPrj 6wiHXyEDrOYzVGmx69Z86Xqqhj/5e/GeDOl+BC6Moff0fPZpqtbvq7IcFKQxVGLsWxfA hU7Q==
X-Gm-Message-State: APjAAAUTbAFpmXxv9HK1J5kpupQIQ9csbxWCsRyWcw77GzVEdQtq8rEX fxffMMiXbLbeKd2VjsW1iPM4sjVADepT5NbBWnY=
X-Google-Smtp-Source: APXvYqxNRjvACN1sSlXKe97kjL28aJXvRwPauos9wKBJbbuwR38615ksK91mAWRFLLbBv4s7/jUycNtv08Xv6/MiIwM=
X-Received: by 2002:aca:484e:: with SMTP id v75mr1869758oia.6.1574129329943; Mon, 18 Nov 2019 18:08:49 -0800 (PST)
MIME-Version: 1.0
References: <CDE69C84-50BE-45C6-A1CA-7E3961FDA913@akamai.com>
In-Reply-To: <CDE69C84-50BE-45C6-A1CA-7E3961FDA913@akamai.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Tue, 19 Nov 2019 10:08:38 +0800
Message-ID: <CAMm+LwgiUzyfvM8=e=eRgUJE4xiAtjiPs8H0R0jUn-rm=njuCw@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: "mathmesh@ietf.org" <mathmesh@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000008abb4d0597a98bb6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/5cehrJ_Wv5HcbNLCOIiWvXuks9o>
Subject: Re: [Mathmesh] Draft minutes
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Nov 2019 02:08:55 -0000

--0000000000008abb4d0597a98bb6
Content-Type: text/plain; charset="UTF-8"

Thank you to everyone for making this event happen.

On Tue, Nov 19, 2019 at 9:04 AM Salz, Rich <rsalz@akamai.com> wrote:

> Thanks very much to Melinda for taking quite detailed minutes.  Please
> post corrections to the list.
> (I know Wes has many notes to add, judging by his typing at the chairs
> desk :)
>
> --
> Mathmesh mailing list
> Mathmesh@ietf.org
> https://www.ietf.org/mailman/listinfo/mathmesh
>

--0000000000008abb4d0597a98bb6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">Tha=
nk you to everyone for making this event happen.=C2=A0</div></div><br><div =
class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Nov 19,=
 2019 at 9:04 AM Salz, Rich &lt;<a href=3D"mailto:rsalz@akamai.com">rsalz@a=
kamai.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">Thanks very much to Melinda for taking quite detailed minutes.=
=C2=A0 Please post corrections to the list.<br>
(I know Wes has many notes to add, judging by his typing at the chairs desk=
 :) <br>
<br>
-- <br>
Mathmesh mailing list<br>
<a href=3D"mailto:Mathmesh@ietf.org" target=3D"_blank">Mathmesh@ietf.org</a=
><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/mathmesh" rel=3D"noreferre=
r" target=3D"_blank">https://www.ietf.org/mailman/listinfo/mathmesh</a><br>
</blockquote></div>

--0000000000008abb4d0597a98bb6--


From nobody Mon Nov 18 18:38:23 2019
Return-Path: <hallam@gmail.com>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 70DA6120BBB for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 18:38:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.406
X-Spam-Level: 
X-Spam-Status: No, score=-1.406 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.244, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ix9aBAHk0zdS for <mathmesh@ietfa.amsl.com>; Mon, 18 Nov 2019 18:38:20 -0800 (PST)
Received: from mail-oi1-f196.google.com (mail-oi1-f196.google.com [209.85.167.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F974120800 for <mathmesh@ietf.org>; Mon, 18 Nov 2019 18:38:20 -0800 (PST)
Received: by mail-oi1-f196.google.com with SMTP id n16so17473921oig.2 for <mathmesh@ietf.org>; Mon, 18 Nov 2019 18:38:20 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=AvIyTsBn1JLF2W3+2q2S3+7hPxzG2dbjM9mNj7wLYcc=; b=Rz8MoOc4UFQHY2ycikD5/PN/YvYcSmAdYXhxYzLdMke1aAxqAetN7/1Rppp10/tzRq 2/3llx2/Gu8pQs9W3hT8rvMfNJ14pFkB5yuOMfWIbnX1AD2QJzXLQtiaveHc+hzmr0UA Nt8dXOEEAMNsBMcKd9V1kFCkxNgJP8j8PwTYIHXW17lnLPkoVK97C4baEb6i3U0ISImn joJcPYZUEb8G36GmkHCxTUd7PkDxIdBCEZItiU4RM8ofrjRsN6Ftk5AoFDsZ2KLZFe1h /Qx1Ta0xsBMn+U+iTptvUpTe0GPD1neUGpdtz9/bair0gDgHIW4bNGdo0dQxRiBkQDOT zvqA==
X-Gm-Message-State: APjAAAUCkGz3KHs2zDVkSryMR2gNoNMoFmLEvZNMExdzQCM6y02+S6Av ZCNHp/iRpxIceJhou0lrezI+N1vKEgBYKyyKNvaG9rDxWlc=
X-Google-Smtp-Source: APXvYqzABRQF4o0IhWuiGuwZse1NuugCZ8VPwkHbRWyA7evNMmLcL156oPSWtK5TwMmpJXQjqQLiPWR3iOUrVsz5Yh8=
X-Received: by 2002:aca:1a03:: with SMTP id a3mr1976430oia.58.1574131098846; Mon, 18 Nov 2019 18:38:18 -0800 (PST)
MIME-Version: 1.0
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Tue, 19 Nov 2019 10:38:06 +0800
Message-ID: <CAMm+LwhaxoWqONv6neYYzf+7=R3hkbuTwR52y9kz57WG==U+Vg@mail.gmail.com>
To: mathmesh@ietf.org
Content-Type: multipart/alternative; boundary="000000000000fa09c00597a9f4ae"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/-diOh8AX4CWJ53qQ61g7oG7Nt3M>
Subject: [Mathmesh] Alternative approaches to Web passwords
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Nov 2019 02:38:21 -0000

--000000000000fa09c00597a9f4ae
Content-Type: text/plain; charset="UTF-8"

1) The Mesh Password Manager is not intended to be limited to the Web
Browser application and that is probably not the early adopter area.

2) Early adopter might well be SSH key management + functional passwords
for scripting etc.

That said, I began thinking through the issues of Web password security in
isolation last night and I think there is actually another approach that
doesn't involve the Mesh infrastructure that is a really low hanging fruit.

The core problem of Web passwords is that users have too many of them. 250
in my case (I just checked). So of course they are often repeated, that is
inevitable. And they are also horribly weak.

So my idea is a combination of HTTP Digest auth and the ideas in Russ
Housley's draft on Quantum security hardening of CMS.

Each user has at least one password salt that is generated with a decent
amount of randomness. It might look like this:

NCE2-VJXS-X5AR-BVRI-73HO-POOA-STAA

This is short enough to be typed in by the user when they change machines.
It is not quite a password though. It is a salt that we are going to add in
to every password the user enters.

So now we change the password dialogue so that when the user enters a
password in a particular form, a KDF with the supplied password as the IKM,
salted with the user nonce and then salted with the host domain is used.

So Alice goes to example.com, enters #password into the password box. The #
is recognized as meaning 'use the KDF scheme'

We then calculate the PRK:

PRK = KDF1('password'.UTF8(),
'NCE2-VJXS-X5AR-BVRI-73HO-POOA-STAA'.UDFData());

The password used is:

Password = Passwordify ( KDF2(PRK, 'example.com'.UTF8());

Where 'Passwordify' is a function that ensures the generated password meets
a generic profile (e.g. 16 chars, at least one upper, lower and symbol
character)

This approach is essentially password hardening for transport. There is
abundant prior art.

This approach can be used in combination with traditional password managers
but we now store the scope across which the password is used and the
constraints on the password generation profile rather than the password
itself.

What I like about this approach is that it allows me to divide my passwords
into two buckets, the ones that protect my assets and the ones that don't.
I make absolutely no apologies for not wasting my brain space remembering a
password for anyone else's benefit.

So NYT, the password I enter might be #, same for WaPo, etc. etc.

But for Fidelity it would probably be #mysecret which is giving an
additional bit of security above and beyond the embedded secret.

The main limitation of this approach is that it makes password sharing
between users very very hard. Which is quite possible a feature rather than
a bug.

--000000000000fa09c00597a9f4ae
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">1) =
The Mesh Password Manager is not intended to be limited to the Web Browser =
application and that is probably not the early adopter area.=C2=A0</div><di=
v class=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D=
"gmail_default" style=3D"font-size:small">2) Early adopter might well be SS=
H key management=C2=A0+ functional passwords for scripting etc.</div><div c=
lass=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"gm=
ail_default" style=3D"font-size:small">That said, I began thinking through =
the issues of Web password security in isolation last night and I think the=
re is actually another approach that doesn&#39;t involve the Mesh infrastru=
cture that is a really low hanging fruit.</div><div class=3D"gmail_default"=
 style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"=
font-size:small">The core problem of Web passwords is that users have too m=
any of them. 250 in my case (I just checked). So of course they are often r=
epeated, that is inevitable. And they are also horribly weak.</div><div cla=
ss=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"gmai=
l_default" style=3D"font-size:small">So my idea is a combination of HTTP Di=
gest auth and the ideas in Russ Housley&#39;s draft on Quantum security har=
dening of CMS.</div><div class=3D"gmail_default" style=3D"font-size:small">=
<br></div><div class=3D"gmail_default" style=3D"font-size:small">Each user =
has at least one password salt that is generated with a decent amount of ra=
ndomness. It might look like this:</div><div class=3D"gmail_default" style=
=3D"font-size:small"><pre id=3D"gmail-s-1_1-5" style=3D"background-color:rg=
b(249,249,249);font-family:&quot;Roboto Mono&quot;,monospace;border:1px sol=
id rgb(238,238,238);margin-top:0px;margin-bottom:0px;padding:1em;overflow-x=
:auto;font-size:14px">NCE2-VJXS-X5AR-BVRI-73HO-POOA-STAA</pre></div><div cl=
ass=3D"gmail_default" style=3D"font-size:small">This is short enough to be =
typed in by the user when they change machines. It is not quite a password =
though. It is a salt that we are going to add in to every password the user=
 enters.</div><div class=3D"gmail_default" style=3D"font-size:small"><br></=
div><div class=3D"gmail_default" style=3D"font-size:small">So now we change=
 the password dialogue so that when the user enters a password in a particu=
lar form, a KDF with the supplied password as the IKM, salted with the user=
 nonce and then salted with the host domain is used.</div><div class=3D"gma=
il_default" style=3D"font-size:small"><br></div><div class=3D"gmail_default=
" style=3D"font-size:small">So Alice goes to <a href=3D"http://example.com"=
>example.com</a>, enters #password into the password box. The # is recogniz=
ed as meaning &#39;use the KDF scheme&#39;</div><div class=3D"gmail_default=
" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D=
"font-size:small">We then calculate the PRK:</div><div class=3D"gmail_defau=
lt" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=
=3D"font-size:small">PRK =3D KDF1(&#39;password&#39;.UTF8(), &#39;NCE2-VJXS=
-X5AR-BVRI-73HO-POOA-STAA&#39;.UDFData());</div><div class=3D"gmail_default=
" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D=
"font-size:small">The password used is:</div><div class=3D"gmail_default" s=
tyle=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"fo=
nt-size:small">Password =3D Passwordify ( KDF2(PRK, &#39;<a href=3D"http://=
example.com">example.com</a>&#39;.UTF8());</div><div class=3D"gmail_default=
" style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D=
"font-size:small">Where &#39;Passwordify&#39; is a function that ensures th=
e generated password meets a generic profile (e.g. 16 chars, at least one u=
pper, lower and symbol character)</div><div class=3D"gmail_default" style=
=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-s=
ize:small">This approach is essentially password hardening for transport. T=
here is abundant prior art.</div><div class=3D"gmail_default" style=3D"font=
-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size:smal=
l">This approach can be used in combination with traditional password manag=
ers but we now store the scope across which the password is used and the co=
nstraints on the password generation profile rather than the password itsel=
f.</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div><d=
iv class=3D"gmail_default" style=3D"font-size:small">What I like about this=
 approach is that it allows me to divide my passwords into two buckets, the=
 ones that protect my assets and the ones that don&#39;t. I make absolutely=
 no apologies for not wasting my brain space remembering a password for any=
one else&#39;s benefit.</div><div class=3D"gmail_default" style=3D"font-siz=
e:small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">S=
o NYT, the password I enter might be #, same for WaPo, etc. etc.</div><div =
class=3D"gmail_default" style=3D"font-size:small"><br></div><div class=3D"g=
mail_default" style=3D"font-size:small">But for Fidelity it would probably =
be #mysecret which is giving an additional bit of security above and beyond=
 the embedded secret.</div><div class=3D"gmail_default" style=3D"font-size:=
small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">The=
 main limitation of this approach is that it makes password sharing between=
 users very very hard. Which is quite possible a feature rather than a bug.=
</div></div>

--000000000000fa09c00597a9f4ae--


From nobody Thu Nov 21 00:06:02 2019
Return-Path: <mcr@sandelman.ca>
X-Original-To: mathmesh@ietfa.amsl.com
Delivered-To: mathmesh@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6100120822 for <mathmesh@ietfa.amsl.com>; Thu, 21 Nov 2019 00:06:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IlDWgDgeiHu3 for <mathmesh@ietfa.amsl.com>; Thu, 21 Nov 2019 00:05:59 -0800 (PST)
Received: from relay.sandelman.ca (relay.cooperix.net [176.58.120.209]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3609A120048 for <mathmesh@ietf.org>; Thu, 21 Nov 2019 00:05:59 -0800 (PST)
Received: from dooku.sandelman.ca (unknown [IPv6:2001:67c:370:128:8c67:35ff:fe03:4a21]) by relay.sandelman.ca (Postfix) with ESMTPS id 9C2F51F450; Thu, 21 Nov 2019 08:05:57 +0000 (UTC)
Received: by dooku.sandelman.ca (Postfix, from userid 179) id E0EEE1142; Thu, 21 Nov 2019 16:05:57 +0800 (+08)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Phillip Hallam-Baker <phill@hallambaker.com>, mathmesh@ietf.org
In-reply-to: <CAMm+LwhaxoWqONv6neYYzf+7=R3hkbuTwR52y9kz57WG==U+Vg@mail.gmail.com>
References: <CAMm+LwhaxoWqONv6neYYzf+7=R3hkbuTwR52y9kz57WG==U+Vg@mail.gmail.com>
Comments: In-reply-to Phillip Hallam-Baker <phill@hallambaker.com> message dated "Tue, 19 Nov 2019 10:38:06 +0800."
X-Mailer: MH-E 8.6; nmh 1.6; GNU Emacs 24.5.1
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature"
Date: Thu, 21 Nov 2019 16:05:57 +0800
Message-ID: <5487.1574323557@dooku.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/mathmesh/wh0zs5Tkraa7rPNXb9yPkrVFWFc>
Subject: Re: [Mathmesh] Alternative approaches to Web passwords
X-BeenThere: mathmesh@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <mathmesh.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mathmesh/>
List-Post: <mailto:mathmesh@ietf.org>
List-Help: <mailto:mathmesh-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mathmesh>, <mailto:mathmesh-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Nov 2019 08:06:02 -0000

--=-=-=
Content-Type: text/plain


Do you mean:
   Alternative approaches to Web passwords
or:
   Alternative use cases than Web passwords
   ??

Phillip Hallam-Baker <phill@hallambaker.com> wrote:
    > 1) The Mesh Password Manager is not intended to be limited to the Web
    > Browser application and that is probably not the early adopter area.

I think that it's worth recasting this slightly.
The problem is not about synchronizing passwords between browsers on
different devices, but between enabling access between devices with full user
interfaces, and those with limited user interfaces.

I write access rather than passwords, because I believe that more and more
the "login with X" is really important.

My TV's netflix would like to login with facebook, but I really don't want my
facebook password to be simple enough that I'd be willing to type it in with
the TV's <->^V remote control keypad.

While netflix could (and maybe they do) solve this by having me login to
facebook and connect my account up from my laptop or phone, and then store
the resulting OAUTH token in their cloud, (and there are dozens of reasons
why this model is less desireable), the problem is that it does not
generalize to arbitrary services and arbitrary devices.

There are extensions (plugins) to many browsers that will let you send a URL
to your phone.  This usually uses the infrastructure of the phone makers. I
don't know if it works cross-browser/phone. (So Chrome->Android works, and I
imagine Safari->iPhone works, but I don't know about the other combinatorics)

I am imaging a system where it could be common to be able to send
authorization to your TV/fridge,ec.  We need to this in a standard way
because we don't expect all our IoT devices to run the same browser as our
desktop, nor for every member of the household who wants to do this to have
to run the same browser.

As a simple and direct use case, if I had a fridge with an LCD
display (I think you have one Phill) then it would be nice if the detailed
(not just public) calendars for all the members of the household were visible
on the LCD.

--
Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEERK+9HEcJHTJ9UqTMlUzhVv38QpAFAl3WRWUACgkQlUzhVv38
QpDKjAf/UjCjpiYrPm/ZpeKDRmTkeaUx7NhoBK98Kk0BXdYv9JHxiQRPoUQAPFr8
PQ/EEGurAzLNhKqmQO5HOhZMyS9Q2CUS4I6eG3aFG4w2apmgntiCmCtirOYR6cM+
Og2tHtkDh6uYnbhvs058m1YPAoLNSlYKfbD2MBUwBScaOH6VWh86yAFBiTch4394
7Uw05s517Dl0f2nHtG+2rvZcEze4raxC+T+ZSgl7I7PYeWMlHG+JGbAdzBbgQ5O6
yq4JBRzRTdzsXlLQvAlu2quf0Iq8x5PX27ttCjRAdw6Xl3df/ZkjNhK8FyoLulX9
VVKoVUbYVTZSu3kobYvXUFZHXY3AkA==
=kjMz
-----END PGP SIGNATURE-----
--=-=-=--

