[Anima] MACsec as an alternative to L3-tunnels

Michael Richardson <mcr+ietf@sandelman.ca> Wed, 24 July 2019 23:03 UTC

Return-Path: <mcr@sandelman.ca>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EFB28120103 for <anima@ietfa.amsl.com>; Wed, 24 Jul 2019 16:03:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FzTs-w7dj90z for <anima@ietfa.amsl.com>; Wed, 24 Jul 2019 16:03:22 -0700 (PDT)
Received: from relay.sandelman.ca (relay.cooperix.net [IPv6:2a01:7e00::f03c:91ff:feae:de77]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B31F1200FD for <anima@ietf.org>; Wed, 24 Jul 2019 16:03:21 -0700 (PDT)
Received: from dooku.sandelman.ca (unknown [IPv6:2001:67c:370:128:6e88:14ff:fe34:93bc]) by relay.sandelman.ca (Postfix) with ESMTPS id 186581F44B for <anima@ietf.org>; Wed, 24 Jul 2019 23:03:20 +0000 (UTC)
Received: by dooku.sandelman.ca (Postfix, from userid 179) id 07D831B00; Wed, 24 Jul 2019 19:03:42 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: anima@ietf.org
In-reply-to: <20190724220015.sfzqxcozq4khc6ut@faui48f.informatik.uni-erlangen.de>
References: <DM6PR11MB3385255D58A133B186AA547EDBC60@DM6PR11MB3385.namprd11.prod.outlook.com> <20190724214603.llrersvrcgb4hy7p@faui48f.informatik.uni-erlangen.de> <20190724220015.sfzqxcozq4khc6ut@faui48f.informatik.uni-erlangen.de>
Comments: In-reply-to Toerless Eckert <tte@cs.fau.de> message dated "Thu, 25 Jul 2019 00:00:15 +0200."
X-Mailer: MH-E 8.6; nmh 1.6; GNU Emacs 24.5.1
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha256"; protocol="application/pgp-signature"
Date: Wed, 24 Jul 2019 19:03:42 -0400
Message-ID: <6709.1564009422@dooku.sandelman.ca>
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/hpGKE4v2pZYzW3Jvkoos2aqxWJY>
Subject: [Anima] MACsec as an alternative to L3-tunnels
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2019 23:03:24 -0000

I was asked to decode words mangled at the mic at Tuesday morning's ANIMA
meeting.
The word was "MACsec", and 
    https://en.wikipedia.org/wiki/IEEE_802.1AE
    https://1.ieee802.org/security/802-1ae/        

provides a reasonable description, and probably the getieee mechanism
might get you a copy for free, but IEEE doesn't have a URL that
leads to the actual document.  I did read it once.
(One of the URLs in the wikipedia page leads to 404)

    https://ieeexplore.ieee.org/document/8585421
might get you the document if you have a valid password, which
I used to, but apparently not anymore.

Given my newly acquired understanding that MACsec applies on a per-port
basis, not on a per-VLAN basis, this means that it would be rather difficult
to do peer discovery and security for a L2-bridged LAN.

-- 
]               Never tell me the odds!                 | ipv6 mesh networks [ 
]   Michael Richardson, Sandelman Software Works        | network architect  [ 
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails    [