Re: [6tisch] Intelligent JP / validating the MASA

"Pascal Thubert (pthubert)" <pthubert@cisco.com> Fri, 23 August 2019 07:39 UTC

Return-Path: <pthubert@cisco.com>
X-Original-To: 6tisch@ietfa.amsl.com
Delivered-To: 6tisch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DCCB9120C4E for <6tisch@ietfa.amsl.com>; Fri, 23 Aug 2019 00:39:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.5
X-Spam-Level:
X-Spam-Status: No, score=-14.5 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=MjZ+64OE; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=s+ZOETSN
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u4crVAtjPABH for <6tisch@ietfa.amsl.com>; Fri, 23 Aug 2019 00:39:27 -0700 (PDT)
Received: from alln-iport-5.cisco.com (alln-iport-5.cisco.com [173.37.142.92]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A62C12006F for <6tisch@ietf.org>; Fri, 23 Aug 2019 00:39:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1992; q=dns/txt; s=iport; t=1566545967; x=1567755567; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=rWXStNFcCoVnUrkejCEqoaUHQHrxeQAOSmbUW78zsb8=; b=MjZ+64OEj2tzsqRduIi90ZGidJicH9daJw2iGvMNTqu2W4AvTLC6Zl7z JFswpZmZL6A5s0DNh9DZC8nSt/XOxn4krDhOMhhl8lvcPtH+JKH5mcSdU 893kibFTaBUkg2JUyOnTX09rAF+kypapVPFye13pi3d48Ev2QFMZnhpVI M=;
IronPort-PHdr: 9a23:/C+i2R3AFxTWxr9tsmDT+zVfbzU7u7jyIg8e44YmjLQLaKm44pD+JxKGt+51ggrPWoPWo7JfhuzavrqoeFRI4I3J8RVgOIdJSwdDjMwXmwI6B8vQEVH7MfTndTASF8VZX1gj9Ha+YgBY
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0B7AABjl19d/5hdJa1kDgsBAQEBAQEBAQEBAQEHAQEBAQEBgWeBRVADgUMgBAsqhCCDRwOKboJcl2eCUgNUCQEBAQwBAS0CAQGEPwIXgkojOBMCCQEBBAEBAwEGBG2FLQyFSgEBAQEDEhERDAEBNwELBAIBCBEBAwEBAQICJgICAjAVAgYIAQEEAQ0FCBqEawMdAQKgOgKBOIhhc4EygnsBAQWFJhiCFgmBDCiJJoJJGIFAP4ERRoJMPoRGgwkygiaML4JqnEwJAoIdlFqYTI1jmBkCBAIEBQIOAQEFgWchgVhwFYMngkKDcooYO3KBKYhQK4IlAQE
X-IronPort-AV: E=Sophos;i="5.64,420,1559520000"; d="scan'208";a="316884336"
Received: from rcdn-core-1.cisco.com ([173.37.93.152]) by alln-iport-5.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 23 Aug 2019 07:39:26 +0000
Received: from XCH-RCD-009.cisco.com (xch-rcd-009.cisco.com [173.37.102.19]) by rcdn-core-1.cisco.com (8.15.2/8.15.2) with ESMTPS id x7N7dQHk031748 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Fri, 23 Aug 2019 07:39:26 GMT
Received: from xhs-aln-001.cisco.com (173.37.135.118) by XCH-RCD-009.cisco.com (173.37.102.19) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Fri, 23 Aug 2019 02:39:25 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Fri, 23 Aug 2019 02:39:24 -0500
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Fri, 23 Aug 2019 02:39:24 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ia80hna0noLDRb+2KOrXEtu19uG6Gdfaf6PX+GoXYKfbGH0s0/y2K5bqFRatgJ3SEBwl31Yii0FmWuTCSpgqgf8xE6ipXeLQMI9Bof45O7Hk3LGzQJpaJA0nhvrsGWOi/0G7vg7Q8z+vD6FGmAa35/9kj1vZtgu9DLVcVQG+/4QafcejTGycT93uQOMTlICTiva0UShkz8x8zeDLzeIgy51HPM5OGUG7kfHGqyvuXmqZY0AYNpLnS+Fe4UUCGraCeJ65s+HbMoc/RMAdtfn/jbk7HTMSiHT7CUs9v9aymat9AVijqtUIysHiN/YXB8deT5+EgzBk190HjFWOBLtscA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rWXStNFcCoVnUrkejCEqoaUHQHrxeQAOSmbUW78zsb8=; b=jBS0VEkjSg3oCK3rL1KPiDrM4ENwMFH79hxhiJ2dGuGEaZDNSDx1LhfY39B3dcomYpxMCUYAurF9vkN0b/2G44Pl1VcNskGN/rUoPiM+gFIplsVZScH023PSnSTK/8E92xzbbNO/6iNc9l+0qLrqjw167759bpVvKKSXLl/Jui9ssONyScM96nPeZDoJKqLVXo3e9nsduXZoAgTSlUwvczQT6V6whTtCFgPdKVLTycsKfZLpyVzRNgDDOpNnwXi4VIny/Zx29A01cxP2JRHJ5mgasin/OpSny3FeB8tEIGBFWsQHK64DR4rYwb1pVpNAcApg5xOF10cOXv93yzNsNQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rWXStNFcCoVnUrkejCEqoaUHQHrxeQAOSmbUW78zsb8=; b=s+ZOETSNYgWiJtXZx91zoKkefx8EO7NOFEzchk4WqkjBYOl34LfoKakxZVysYGqrYwF13+KDkLRVzvAnAc7eqc6NnLfcpJ0ExWRzlcwOf+pCo0IBRqFNa1HBjvt+fj3+R2UeZ1KOB5H2OP8PP/GmFyEpiHlGAC96ipQIA1KET+o=
Received: from MN2PR11MB3565.namprd11.prod.outlook.com (20.178.250.159) by MN2PR11MB3774.namprd11.prod.outlook.com (20.178.254.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2157.22; Fri, 23 Aug 2019 07:39:23 +0000
Received: from MN2PR11MB3565.namprd11.prod.outlook.com ([fe80::89cf:9d:8a75:266e]) by MN2PR11MB3565.namprd11.prod.outlook.com ([fe80::89cf:9d:8a75:266e%3]) with mapi id 15.20.2178.020; Fri, 23 Aug 2019 07:39:23 +0000
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Benjamin Kaduk <kaduk@mit.edu>, Michael Richardson <mcr+ietf@sandelman.ca>
CC: Mališa Vučinić <malisa.vucinic@inria.fr>, Tero Kivinen <kivinen@iki.fi>, "6tisch@ietf.org" <6tisch@ietf.org>
Thread-Topic: Intelligent JP / validating the MASA
Thread-Index: AdVXcq2WhsWuyF3LQK+d3r69CIYQ2wBX2JKAAALfqIcAE8YWgAAF440AABBR3OA=
Date: Fri, 23 Aug 2019 07:39:11 +0000
Deferred-Delivery: Fri, 23 Aug 2019 07:38:52 +0000
Message-ID: <MN2PR11MB35659FAA7959F89EBDDBB7E3D8A40@MN2PR11MB3565.namprd11.prod.outlook.com>
References: <MN2PR11MB356593FEE789835AC61E7589D8AB0@MN2PR11MB3565.namprd11.prod.outlook.com> <92FD98F1-B503-4549-B940-9426C5B4841B@inria.fr> <70982E11-9DD0-4239-9DBD-061BDB5E834B@cisco.com> <26540.1566507639@dooku.sandelman.ca> <20190822234916.GW60855@kduck.mit.edu>
In-Reply-To: <20190822234916.GW60855@kduck.mit.edu>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=pthubert@cisco.com;
x-originating-ip: [2001:420:c0c0:1007::143]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1c94b8e6-6645-4e53-29a2-08d7279d04aa
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(5600166)(711020)(4605104)(1401327)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7193020); SRVR:MN2PR11MB3774;
x-ms-traffictypediagnostic: MN2PR11MB3774:
x-microsoft-antispam-prvs: <MN2PR11MB3774597C0E0E0B401F8C328FD8A40@MN2PR11MB3774.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0138CD935C
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(376002)(346002)(366004)(39860400002)(396003)(136003)(189003)(199004)(13464003)(66446008)(7736002)(25786009)(33656002)(74316002)(316002)(71200400001)(99286004)(81156014)(71190400001)(256004)(6506007)(86362001)(66946007)(53546011)(54906003)(229853002)(66476007)(76176011)(81166006)(55016002)(6436002)(46003)(14454004)(9686003)(7696005)(53936002)(110136005)(478600001)(486006)(66556008)(446003)(14444005)(11346002)(6116002)(305945005)(66574012)(64756008)(186003)(476003)(4326008)(6666004)(5660300002)(8936002)(76116006)(2171002)(52536014)(2906002)(8676002)(102836004)(6246003); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR11MB3774; H:MN2PR11MB3565.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: cdSjxJpCMvzxjW7a7ZoZ2c0tuIJXX/5qC89liuNAhMNfEgI+p5ufhwAclcxfoRPwElsm/pGxFg9MES+BwqvPTyQ6hiMqn4mOBSp33qryuIVLfx8Uu4XhVuMrSrvUfv1isNLKYmIkU/iLnjld4WFmWbltnrvfNMFw9cFezViba2ecNJwWmjAaSp22unmGhWbM8fPtVhjgo4PxT2xnpr4sqkgCkWvcBl4A2TGgbkg09iANX/h1P3pxXCAuZ9a3skeU1MKYYzKDwJus7EK0BwGxmco6pyFD2MZ2YloN0EYgNVJXalii2ZlV6SDwElXRlvBzrvnM7G5VG8ty1BB2XtxSm5oV0+L/7WCiXfe758nXZMfUUz7awurRJje1/pZRrZDXpoknf3vt6Bug+5rMYH/o8j/jNXAvPQYz4HX40BiLIQA=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 1c94b8e6-6645-4e53-29a2-08d7279d04aa
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Aug 2019 07:39:23.7494 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: I05inlqenRgYa6RzhXHhsDtFU1nyzj0Ps4Lbmq3CgJEJH3vAQArNTNziEgymuzt5ZIQJ22xCIpfzNFSvdb6wlw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB3774
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.19, xch-rcd-009.cisco.com
X-Outbound-Node: rcdn-core-1.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch/jhyHvVsGROxHE_iYxDCfw-Savnk>
Subject: Re: [6tisch] Intelligent JP / validating the MASA
X-BeenThere: 6tisch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discuss link layer model for Deterministic IPv6 over the TSCH mode of IEEE 802.15.4e, and impacts on RPL and 6LoWPAN such as resource allocation" <6tisch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch>, <mailto:6tisch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch/>
List-Post: <mailto:6tisch@ietf.org>
List-Help: <mailto:6tisch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch>, <mailto:6tisch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Aug 2019 07:39:29 -0000

: )

I used the heavy weaponry in -25;  madi minimal a normative reference and added:

"
6.7.  Deeper Considerations

   The reader is encouraged to review the security section of
   [I-D.ietf-6tisch-minimal-security], which discusses 6TiSCH security
   issues in more details.

"

Works?

Pascal

> -----Original Message-----
> From: Benjamin Kaduk <kaduk@mit.edu>
> Sent: vendredi 23 août 2019 01:49
> To: Michael Richardson <mcr+ietf@sandelman.ca>
> Cc: Pascal Thubert (pthubert) <pthubert@cisco.com>; =?utf-
> 8?B?TWFsacWhYSBWdcSNaW5pxIc=?= <malisa.vucinic@inria.fr>; Tero Kivinen
> <kivinen@iki.fi>; 6tisch@ietf.org
> Subject: Re: Intelligent JP / validating the MASA
> 
> On Thu, Aug 22, 2019 at 05:00:39PM -0400, Michael Richardson wrote:
> >
> > Pascal Thubert (pthubert) <pthubert@cisco.com> wrote:
> >     > I’m reading a question of possibility multiple JRC whereby the pledge
> >     > would indicate which JRC to use and possibly leverage that for an
> >     > attack on anyone outside.
> >
> > No, the pledge intentionally has no way to signal alternate destinations.
> 
> Cool; I think I had missed that or confused myself.
> Combined with the defenses in minimal-security that Mališa pointed out, it
> sounds like we're in pretty good shape.  Now Pascal just has to figure out how
> to point to the text in minimal-security without bloating -architecture too
> much!
> 
> Thanks,
> 
> Ben