Re: [Anima] I-D Action: draft-vanderstok-constrained-anima-dtls-join-proxy-00.txt

Brian E Carpenter <brian.e.carpenter@gmail.com> Fri, 05 October 2018 19:42 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A6AA130EB2 for <anima@ietfa.amsl.com>; Fri, 5 Oct 2018 12:42:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RMp28uvvoEeA for <anima@ietfa.amsl.com>; Fri, 5 Oct 2018 12:42:01 -0700 (PDT)
Received: from mail-pl1-x632.google.com (mail-pl1-x632.google.com [IPv6:2607:f8b0:4864:20::632]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8D65130EC8 for <anima@ietf.org>; Fri, 5 Oct 2018 12:42:01 -0700 (PDT)
Received: by mail-pl1-x632.google.com with SMTP id v5-v6so7270700plz.13 for <anima@ietf.org>; Fri, 05 Oct 2018 12:42:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=cevDjOj2vprYHW6YXcIzKDoagWAsvhaQoMdCPEYnoQs=; b=m3n+AiwCD6wx657Tx1xB2mEWAsfGPMC878ta2MYn/L3y3Mwtfu10kk/QroXhErgzFE pxwlcvbWutBwBGjjk0xITTRRNnw/VFoymQe+fsaKpdC9WzxpyCGVOSZOLTQJ1HnYUiw4 eJ3P9JfcdzeDCjb3tGbdaadtKcdScyw3j3XZWDYwLoRjxqQjugejGwHgqbCeedCAbyOk G2+YqdrHgumQh18x2QEzQAkBLZNuqJkBXf8fk8JdYpmbr+GtkAqxQeIWLVFb8hINaUYm eLKCqWzCUZsns4fWQsdINsxtBh6cet4GmGwYvi9sPqZ8nfEkGP/ySDTL/7wtO1iHHtDe BqjA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=cevDjOj2vprYHW6YXcIzKDoagWAsvhaQoMdCPEYnoQs=; b=m502Mr5soZrTRxgElMajs7rvHXIvWgQswTlRI0387Yjr2aqOiLpHxgT3mv2fzcfbV/ Z/c24L+DXzRd1T7Ah6kZVxEOTIXoPd3hUxlqWILt1Mc3KCRNapxRTPSRoCgeTA0b7MLo tf/6tW2UBB2uovvMjOBiSua0JaGvkivIl7ueyLpBVv7dAdDthnUNvh5/XHYaj9taTFvC viS1Kqi58esemdvBmW70qdp58pyIvwL45FwKDALPoKUrKDEGJ+5tIsxhbJtveKA46Mp0 MvwuziDqE69BuEcITZRcX4WEY7iHgotvKBDkjdOcEsuEKCdRK18qGHlgXYR8R7GUbFar aYxw==
X-Gm-Message-State: ABuFfoi6vLO5ER0zppWn2eK0Gf1OL773FK9cijUIi/LXcmbzyPtM4uH2 nZOWeFjCneI1q71n2hNdXZc++/Ib
X-Google-Smtp-Source: ACcGV61UJV2TzDQECbzQzC7bNTwznJu/UwakxlotDCQFncm2y+hu4T83QcDkXe3j9RKGa1tA/Js/ow==
X-Received: by 2002:a17:902:7b84:: with SMTP id w4-v6mr12642130pll.32.1538768521084; Fri, 05 Oct 2018 12:42:01 -0700 (PDT)
Received: from [192.168.178.30] ([118.148.76.40]) by smtp.gmail.com with ESMTPSA id m27-v6sm14091173pff.187.2018.10.05.12.41.58 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 05 Oct 2018 12:42:00 -0700 (PDT)
To: consultancy@vanderstok.org
Cc: anima@ietf.org
References: <153825200726.18811.5817453433918930845@ietfa.amsl.com> <659e84c2-551c-4b7c-1002-b156337a92ac@gmail.com> <a0af8e7d7e164946f6c864f499e08160@bbhmail.nl>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Message-ID: <eeb3ca6e-103d-d328-a2ba-b337638f2743@gmail.com>
Date: Sat, 06 Oct 2018 08:41:53 +1300
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1
MIME-Version: 1.0
In-Reply-To: <a0af8e7d7e164946f6c864f499e08160@bbhmail.nl>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/rYmmOTyIgs9EyaEg4ar-dRwlt8k>
Subject: Re: [Anima] I-D Action: draft-vanderstok-constrained-anima-dtls-join-proxy-00.txt
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Oct 2018 19:42:14 -0000

Peter,
On 2018-10-05 20:24, Peter van der Stok wrote:
> Hi Brian.
> 
> The answer consists of a selection of text of section 7 of the draft.

Huh? Section 7 is "security considerations" and the text you quote below
is nowhere in the draft. Maybe it's time for version -01 already?

Also, ff01::fd confuses me. It is not a link-local address - it is node-local.
I think you mean ff02::fd, which is link-local and belongs to COAP.

Regards
    Brian

> The discovery follows the standard coap discovery.
> ________________________________________________________________
> The discovery of the Join-Proxy by the
>    Pledge is an extension to the discovery described in section 4 of
>    [I-D.ietf-anima-bootstrapping-keyinfra].  In particular this section
>    replaces section 4.2 of [I-D.ietf-anima-bootstrapping-keyinfra].
> 
>    The Pledge can discover a Join-Proxy by sending a link-local
>    multicast message to ALL CoAP Nodes with address FF01::FD.  Multiple
>    or no nodes may respond.  The handling of multiple responses and the
>    absence of responses follow section 4 of
>    [I-D.ietf-anima-bootstrapping-keyinfra].
> 
> The presence and location of (path to) the join-proxy resource are
>    discovered by sending a MC GET request to "/.well-known/core"
> including
>    a resource type (RT) parameter with the value "brski-proxy"
>    [RFC6690].  Upon success, the return payload will contain the root
>    resource of the Join-Proxy resources.
> 
> ____________________________________________________________ Looking
> forward to your comments and suggestions,
> 
> Peter
> Brian E Carpenter schreef op 2018-10-05 04:03:
> 
>> How does the constrained pledge discover the LL address of the constrained proxy?
>>
>> Regards
>> Brian Carpenter
>>
>> On 2018-09-30 09:13, internet-drafts@ietf.org wrote: 
>>
>>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>>>
>>> Title           : Constrained Join Proxy for Bootstrapping Protocols
>>> Authors         : Michael Richardson
>>> Peter van der Stok
>>> Panos Kampanakis
>>> Filename        : draft-vanderstok-constrained-anima-dtls-join-proxy-00.txt
>>> Pages           : 10
>>> Date            : 2018-09-29
>>>
>>> Abstract:
>>> This document defines a protocol to securely assign a pledge to an
>>> owner, using an intermediary node between pledge and owner.  This
>>> intermediary node is known as a "constrained-join-proxy".
>>>
>>> This document extends the work of
>>> [I-D.ietf-anima-bootstrapping-keyinfra] by replacing the Circuit-
>>> proxy by a stateless constrained join-proxy, that uses IP
>>> encapsulation.
>>>
>>> The IETF datatracker status page for this draft is:
>>> https://datatracker.ietf.org/doc/draft-vanderstok-constrained-anima-dtls-join-proxy/
>>>
>>> There are also htmlized versions available at:
>>> https://tools.ietf.org/html/draft-vanderstok-constrained-anima-dtls-join-proxy-00
>>> https://datatracker.ietf.org/doc/html/draft-vanderstok-constrained-anima-dtls-join-proxy-00
>>>
>>> Please note that it may take a couple of minutes from the time of submission
>>> until the htmlized version and diff are available at tools.ietf.org.
>>>
>>> Internet-Drafts are also available by anonymous FTP at:
>>> ftp://ftp.ietf.org/internet-drafts/
>>>
>>> _______________________________________________
>>> I-D-Announce mailing list
>>> I-D-Announce@ietf.org
>>> https://www.ietf.org/mailman/listinfo/i-d-announce
>>> Internet-Draft directories: http://www.ietf.org/shadow.html
>>> or ftp://ftp.ietf.org/ietf/1shadow-sites.txt
>>
>> _______________________________________________
>> Anima mailing list
>> Anima@ietf.org
>> https://www.ietf.org/mailman/listinfo/anima