Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace-usecases-09: (with COMMENT)

Stefanie Gerdes <gerdes@tzi.de> Fri, 23 October 2015 14:58 UTC

Return-Path: <gerdes@tzi.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 474B41A1BEC for <ace@ietfa.amsl.com>; Fri, 23 Oct 2015 07:58:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.55
X-Spam-Level:
X-Spam-Status: No, score=-1.55 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Wc86EztJCbYP for <ace@ietfa.amsl.com>; Fri, 23 Oct 2015 07:58:21 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB09E1A1BE9 for <ace@ietf.org>; Fri, 23 Oct 2015 07:58:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id t9NEwFdD013702; Fri, 23 Oct 2015 16:58:15 +0200 (CEST)
Received: from [192.168.1.109] (pD9F6184A.dip0.t-ipconnect.de [217.246.24.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3nj7wR3VdszHy06; Fri, 23 Oct 2015 16:58:15 +0200 (CEST)
To: Ludwig Seitz <ludwig@sics.se>, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
References: <20151022132903.23826.2689.idtracker@ietfa.amsl.com> <5629EA01.6020506@sics.se> <5629EED2.5080005@cs.tcd.ie> <CAHbuEH6LNA6XaY8kUkZZ20A+Jc2V4SWriDajuZOkxq2JFuZX0Q@mail.gmail.com> <562A3647.3030101@sics.se>
From: Stefanie Gerdes <gerdes@tzi.de>
X-Enigmail-Draft-Status: N1110
Message-ID: <562A4B07.9080305@tzi.de>
Date: Fri, 23 Oct 2015 16:58:15 +0200
User-Agent: Mozilla/5.0 (X11; Linux i686 on x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <562A3647.3030101@sics.se>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/JbjxK6shYCu1KI9NCsbPDnYzhLc>
Cc: "ace@ietf.org" <ace@ietf.org>
Subject: Re: [Ace] Stephen Farrell's Yes on draft-ietf-ace-usecases-09: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Oct 2015 14:58:22 -0000

Hi all,

>>> 1. Software update is really needed and often missing and
>>> usually hard. There's at least a need to authenticate and
>>> authorize new firmware, when there is any update. That may not
>>> be the same as authorizing a new config.
> 
> 
> Isn't this covered in section 2.4.1.3. ?
> 
> "At some point the facility management company wants to update the
> firmware of lighting devices in order to eliminate software bugs.
> Before accepting the new firmware, each device checks the
> authorization of the facility management company to perform this
> update."
> 
> There is simply not a specific authorization problem listed for this, I
> could argue that it is subsumed under U4.4 but if you think it deserves
> specific mention under the problems section I can live with adding a point.
> 

I think adding a point in 2.4.3 is a good idea. We could also add an
item to 3.3 that emphasizes the problem.

Thanks,
Steffi