Return-Path: <malisa.vucinic@inria.fr>
X-Original-To: 6tisch@ietfa.amsl.com
Delivered-To: 6tisch@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id C2571120043;
 Fri, 11 Oct 2019 02:18:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.899
X-Spam-Level: 
X-Spam-Status: No, score=-6.899 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5,
 SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id Pl_cffRbG3x5; Fri, 11 Oct 2019 02:18:06 -0700 (PDT)
Received: from mail3-relais-sop.national.inria.fr
 (mail3-relais-sop.national.inria.fr [192.134.164.104])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 3C548120020;
 Fri, 11 Oct 2019 02:18:05 -0700 (PDT)
X-IronPort-AV: E=Sophos;i="5.67,283,1566856800"; 
 d="scan'208,217";a="322384677"
Received: from wifi-pro-82-179.paris.inria.fr ([128.93.82.179])
 by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384;
 11 Oct 2019 11:18:03 +0200
From: =?utf-8?B?TWFsacWhYSBWdcSNaW5pxIc=?= <malisa.vucinic@inria.fr>
Message-Id: <0EEA127F-FA8F-4BA2-8ED5-1614ECAC6566@inria.fr>
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_8B5A299D-355C-4C54-B4E9-59F20B2AAE76"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Date: Fri, 11 Oct 2019 11:18:02 +0200
In-Reply-To: <BN8PR13MB262886B2376BAD2ECBB317D985940@BN8PR13MB2628.namprd13.prod.outlook.com>
Cc: "ops-dir@ietf.org" <ops-dir@ietf.org>, 6tisch <6tisch@ietf.org>,
 "ietf@ietf.org" <ietf@ietf.org>,
 "draft-ietf-6tisch-minimal-security.all@ietf.org"
 <draft-ietf-6tisch-minimal-security.all@ietf.org>
To: Linda Dunbar <linda.dunbar@futurewei.com>
References: <157023324915.1400.10416689027865506912@ietfa.amsl.com>
 <91540EE6-E74D-4ECA-9E54-9B5E35FA5937@inria.fr>
 <BN8PR13MB262886B2376BAD2ECBB317D985940@BN8PR13MB2628.namprd13.prod.outlook.com>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/6tisch/lWkxabBNbepiROMoAxSHXpkwUpg>
Subject: Re: [6tisch] Opsdir last call review of
 draft-ietf-6tisch-minimal-security-12
X-BeenThere: 6tisch@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discuss link layer model for Deterministic IPv6 over the TSCH mode
 of IEEE 802.15.4e,
 and impacts on RPL and 6LoWPAN such as resource allocation" <6tisch.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/6tisch>,
 <mailto:6tisch-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/6tisch/>
List-Post: <mailto:6tisch@ietf.org>
List-Help: <mailto:6tisch-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/6tisch>,
 <mailto:6tisch-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Oct 2019 09:18:09 -0000


--Apple-Mail=_8B5A299D-355C-4C54-B4E9-59F20B2AAE76
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Dear Linda,

After a second look, I noticed that the ASN acronym only had a couple of =
occurrences in the text. To address your comment, I replaced the =
occurrences of =E2=80=9CASN" with the expanded version =E2=80=9Cabsolute =
slot number=E2=80=9D without defining the acronym in our document. The =
changes following your review can be found at:

=
https://bitbucket.org/6tisch/draft-ietf-6tisch-minimal-security/commits/83=
e751fd8c97441e0362df983dec2801b6177300 =
<https://bitbucket.org/6tisch/draft-ietf-6tisch-minimal-security/commits/8=
3e751fd8c97441e0362df983dec2801b6177300>=20

Please let me know whether I should go ahead and upload the new version =
to the datatracker.

Mali=C5=A1a

> On 10 Oct 2019, at 18:42, Linda Dunbar <linda.dunbar@futurewei.com> =
wrote:
>=20
> Malisa,=20
>=20
> Thanks for the changes.=20
>=20
> I didn't realize that IEEE802.15 uses ASN for completely different =
purpose than the IETF's ASN. Maybe add a note stating "this ASN is =
completely different from the BGP's ASN".=20
>=20
> Linda
>=20
> -----Original Message-----
> From: Mali=C5=A1a Vu=C4=8Dini=C4=87 <malisa.vucinic@inria.fr =
<mailto:malisa.vucinic@inria.fr>>=20
> Sent: Monday, October 07, 2019 10:39 AM
> To: Linda Dunbar <linda.dunbar@futurewei.com =
<mailto:linda.dunbar@futurewei.com>>
> Cc: ops-dir@ietf.org <mailto:ops-dir@ietf.org>; 6tisch =
<6tisch@ietf.org <mailto:6tisch@ietf.org>>; ietf@ietf.org =
<mailto:ietf@ietf.org>; draft-ietf-6tisch-minimal-security.all@ietf.org =
<mailto:draft-ietf-6tisch-minimal-security.all@ietf.org>
> Subject: Re: [6tisch] Opsdir last call review of =
draft-ietf-6tisch-minimal-security-12
>=20
> Dear Linda,
>=20
> Many thanks for your review. Please find the responses inline.
>=20
> Kind regards,
> Mali=C5=A1a
>=20
>> On 5 Oct 2019, at 01:54, Linda Dunbar via Datatracker =
<noreply@ietf.org> wrote:
>>=20
>> Reviewer: Linda Dunbar
>> Review result: Has Nits
>>=20
>> Reviewer: Linda Dunbar
>> Review result: Has Nits  & with comment
>>=20
>> I am the assigned Ops area reviewer for this draft. The Ops=20
>> directorate reviews all IETF documents being processed by the IESG =
for=20
>> the IETF Chair.  Please treat these comments just like any other last =
call comments.
>>=20
>> This document is written very clear, specifying a framework for a new=20=

>> device to securely join a 6TiSCH network.
>=20
>>=20
>> One question: the document assumes that there is pre-shared key (PSK)=20=

>> between the device and the controller. The Security Consideration =
does=20
>> describe the common pitfall of  a single PSK shared among a group of=20=

>> devices. Is there any way to prevent it? Is it necessary to require=20=

>> the Key to be periodically changed?
>=20
> Please note that the document mandates unique PSKs between each device =
and the JRC (Section 3, PSK), thus a compromise of a single device does =
not leak the PSK of other devices in the network. The discussion you =
refer to in the Security Consideration section makes an attempt to draw =
attention to the unsafe practices, but beyond mandating the PSK to be =
unique for each pledge, which is already a strong requirement, I am not =
sure we can do much more about it. Requiring the PSK to be periodically =
changed would require periodic in-situ manipulation of devices (by the =
100s or even 1000s), something that is not realistically going to =
happen=E2=80=A6What we could do, however, is to mandate the PSK to be =
changed upon device re-commissioning to a new owner, when it is likely =
that a device needs to be manipulated, so I would propose the following =
sentence be added at the end of Section 3, PSK:
>=20
> NEW:
> In case of device re-commissioning to a new owner, it is REQUIRED to =
change the PSK.
>=20
> Would that work?
>=20
>> Another  suggestion:
>> Section 5.1 introduces an acronym ASN to represent "Absolute slot =
number".
>>=20
>> Can you use a different acronym because ASN has been widely used in=20=

>> networking as the Autonomous System Number.
>=20
> ASN for "Absolute slot number=E2=80=9D was defined in the IEEE =
802.15.4 specification and the acronym is widely used in our community. =
I would refrain from re-defining it as it would cause confusion, given =
that is already used in other documents produced by the 6TiSCH working =
group (RFC8180, RFC7554).
>=20
>> ---
>> An autonomous system number (ASN) is a unique number that's available=20=

>> globally to identify an autonomous system and which enables that=20
>> system to exchange exterior routing information with other =
neighboring autonomous systems.
>>=20
>> Thank you.
>>=20
>> Linda Dunbar
>>=20
>>=20
>> _______________________________________________
>> 6tisch mailing list
>> 6tisch@ietf.org
>> https://nam03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fwww=
 =
<https://nam03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Fwww>.=

>> ietf.org =
<http://ietf.org/>%2Fmailman%2Flistinfo%2F6tisch&amp;data=3D02%7C01%7Clind=
a.dunbar
>> %40futurewei.com =
<http://40futurewei.com/>%7C4b48bea8289a448fc54308d74b3c7064%7C0fee8ff2a3b=
24018
>> =
9c753a1d5591fedc%7C1%7C1%7C637060595293959400&amp;sdata=3DeD9OiaPzigRIqt
>> 66tBC1fANtpgzVzIX2SxldjSYwsq4%3D&amp;reserved=3D0


--Apple-Mail=_8B5A299D-355C-4C54-B4E9-59F20B2AAE76
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Dear =
Linda,<div class=3D""><br class=3D""></div><div class=3D"">After a =
second look, I noticed that the ASN acronym only had a couple of =
occurrences in the text. To address your comment, I replaced the =
occurrences of =E2=80=9CASN" with the expanded version =E2=80=9Cabsolute =
slot number=E2=80=9D without defining the acronym in our document. The =
changes following your review can be found at:</div><div class=3D""><br =
class=3D""></div><div class=3D""><a =
href=3D"https://bitbucket.org/6tisch/draft-ietf-6tisch-minimal-security/co=
mmits/83e751fd8c97441e0362df983dec2801b6177300" =
class=3D"">https://bitbucket.org/6tisch/draft-ietf-6tisch-minimal-security=
/commits/83e751fd8c97441e0362df983dec2801b6177300</a>&nbsp;</div><div =
class=3D""><br class=3D""></div><div class=3D"">Please let me know =
whether I should go ahead and upload the new version to the =
datatracker.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Mali=C5=A1a<br class=3D""><div><br class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D"">On 10 Oct 2019, at 18:42, Linda =
Dunbar &lt;<a href=3D"mailto:linda.dunbar@futurewei.com" =
class=3D"">linda.dunbar@futurewei.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Malisa,<span =
class=3D"Apple-converted-space">&nbsp;</span></span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Thanks for the changes.<span =
class=3D"Apple-converted-space">&nbsp;</span></span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">I didn't realize that IEEE802.15 =
uses ASN for completely different purpose than the IETF's ASN. Maybe add =
a note stating "this ASN is completely different from the BGP's =
ASN".<span class=3D"Apple-converted-space">&nbsp;</span></span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Linda</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">-----Original =
Message-----</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">From: Mali=C5=A1=
a Vu=C4=8Dini=C4=87 &lt;</span><a href=3D"mailto:malisa.vucinic@inria.fr" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D"">malisa.vucinic@inria.fr</a><span style=3D"caret-color: rgb(0, =
0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">&gt;<span =
class=3D"Apple-converted-space">&nbsp;</span></span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Sent: Monday, October 07, 2019 =
10:39 AM</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">To: Linda =
Dunbar &lt;</span><a href=3D"mailto:linda.dunbar@futurewei.com" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D"">linda.dunbar@futurewei.com</a><span style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">&gt;</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Cc:<span class=3D"Apple-converted-space">&nbsp;</span></span><a=
 href=3D"mailto:ops-dir@ietf.org" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">ops-dir@ietf.org</a><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">; 6tisch &lt;</span><a =
href=3D"mailto:6tisch@ietf.org" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">6tisch@ietf.org</a><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">&gt;;<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"mailto:ietf@ietf.org" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">ietf@ietf.org</a><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">;<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"mailto:draft-ietf-6tisch-minimal-security.all@ietf.org" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D"">draft-ietf-6tisch-minimal-security.all@ietf.org</a><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Subject: Re: [6tisch] Opsdir =
last call review of draft-ietf-6tisch-minimal-security-12</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Dear Linda,</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">Many thanks for your review. =
Please find the responses inline.</span><br style=3D"caret-color: rgb(0, =
0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Kind regards,</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Mali=C5=A1a</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><blockquote type=3D"cite" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D"">On 5 Oct 2019, at 01:54, Linda Dunbar =
via Datatracker &lt;<a href=3D"mailto:noreply@ietf.org" =
class=3D"">noreply@ietf.org</a>&gt; wrote:<br class=3D""><br =
class=3D"">Reviewer: Linda Dunbar<br class=3D"">Review result: Has =
Nits<br class=3D""><br class=3D"">Reviewer: Linda Dunbar<br =
class=3D"">Review result: Has Nits &nbsp;&amp; with comment<br =
class=3D""><br class=3D"">I am the assigned Ops area reviewer for this =
draft. The Ops<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">directorate reviews all IETF documents being processed by the =
IESG for<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">the IETF Chair. &nbsp;Please treat these comments just like =
any other last call comments.<br class=3D""><br class=3D"">This document =
is written very clear, specifying a framework for a new<span =
class=3D"Apple-converted-space">&nbsp;</span><br class=3D"">device to =
securely join a 6TiSCH network.<br class=3D""></blockquote><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" =
class=3D""><blockquote type=3D"cite" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
class=3D"">One question: the document assumes that there is pre-shared =
key (PSK)<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">between the device and the controller. The Security =
Consideration does<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">describe the common pitfall of &nbsp;a single PSK shared =
among a group of<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">devices. Is there any way to prevent it? Is it necessary to =
require<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">the Key to be periodically changed?<br =
class=3D""></blockquote><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Please note that the document mandates unique PSKs between =
each device and the JRC (Section 3, PSK), thus a compromise of a single =
device does not leak the PSK of other devices in the network. The =
discussion you refer to in the Security Consideration section makes an =
attempt to draw attention to the unsafe practices, but beyond mandating =
the PSK to be unique for each pledge, which is already a strong =
requirement, I am not sure we can do much more about it. Requiring the =
PSK to be periodically changed would require periodic in-situ =
manipulation of devices (by the 100s or even 1000s), something that is =
not realistically going to happen=E2=80=A6What we could do, however, is =
to mandate the PSK to be changed upon device re-commissioning to a new =
owner, when it is likely that a device needs to be manipulated, so I =
would propose the following sentence be added at the end of Section 3, =
PSK:</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">NEW:</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">In case of device =
re-commissioning to a new owner, it is REQUIRED to change the =
PSK.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" class=3D"">Would that =
work?</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><blockquote type=3D"cite" style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D"">Another=
 &nbsp;suggestion:<br class=3D"">Section 5.1 introduces an acronym ASN =
to represent "Absolute slot number".<br class=3D""><br class=3D"">Can =
you use a different acronym because ASN has been widely used in<span =
class=3D"Apple-converted-space">&nbsp;</span><br class=3D"">networking =
as the Autonomous System Number.<br class=3D""></blockquote><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">ASN for "Absolute slot number=E2=80=
=9D was defined in the IEEE 802.15.4 specification and the acronym is =
widely used in our community. I would refrain from re-defining it as it =
would cause confusion, given that is already used in other documents =
produced by the 6TiSCH working group (RFC8180, RFC7554).</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" =
class=3D""><blockquote type=3D"cite" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; orphans: auto; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D"">---<br =
class=3D"">An autonomous system number (ASN) is a unique number that's =
available<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">globally to identify an autonomous system and which enables =
that<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">system to exchange exterior routing information with other =
neighboring autonomous systems.<br class=3D""><br class=3D"">Thank =
you.<br class=3D""><br class=3D"">Linda Dunbar<br class=3D""><br =
class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">6tisch mailing list<br class=3D""><a =
href=3D"mailto:6tisch@ietf.org" class=3D"">6tisch@ietf.org</a><br =
class=3D""><a =
href=3D"https://nam03.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%=
2Fwww" =
class=3D"">https://nam03.safelinks.protection.outlook.com/?url=3Dhttps%3A%=
2F%2Fwww</a>.<br class=3D""><a href=3D"http://ietf.org/" =
class=3D"">ietf.org</a>%2Fmailman%2Flistinfo%2F6tisch&amp;amp;data=3D02%7C=
01%7Clinda.dunbar<br class=3D"">%<a href=3D"http://40futurewei.com/" =
class=3D"">40futurewei.com</a>%7C4b48bea8289a448fc54308d74b3c7064%7C0fee8f=
f2a3b24018<br =
class=3D"">9c753a1d5591fedc%7C1%7C1%7C637060595293959400&amp;amp;sdata=3De=
D9OiaPzigRIqt<br =
class=3D"">66tBC1fANtpgzVzIX2SxldjSYwsq4%3D&amp;amp;reserved=3D0</blockquo=
te></div></blockquote></div><br class=3D""></div></body></html>=

--Apple-Mail=_8B5A299D-355C-4C54-B4E9-59F20B2AAE76--

