Re: [AVTCORE] Roman Danyliw's Abstain on draft-ietf-avtcore-rtp-scip-05: (with COMMENT)

"Dan.Hanson@gd-ms.com" <Dan.Hanson@gd-ms.com> Wed, 26 July 2023 21:27 UTC

Return-Path: <Dan.Hanson@gd-ms.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 747F7C14F74A; Wed, 26 Jul 2023 14:27:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.106
X-Spam-Level:
X-Spam-Status: No, score=-7.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gd-ms.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iatAmP0PA3xg; Wed, 26 Jul 2023 14:27:36 -0700 (PDT)
Received: from vadc01-egs01.gd-ms.com (vadc01-egs01.gd-ms.com [137.100.132.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E6688C14F736; Wed, 26 Jul 2023 14:27:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=gd-ms.com; i=@gd-ms.com; q=dns/txt; s=esa; t=1690406847; x=1721942847; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=AqeheO6eZefferOKeFri9X7H3imyiSb6gAMy00PiovE=; b=T6bURdgHhb6cyxv/iZ3J10Rj9iYQTSjVkMFHTteHIa70XmR7w2/uSjJn NjS3FxVCglWg3WUFiYEeLSjd4HOkCkCkJMZkz+Wg7nbD2u5efuo+m9C+N ro5htE9GiX3n0bZxXbiIS7jbpgSi5OsHP7+6QARmcWAyBcn8CGjSJJvjB 6SmqcUXsyutbNSLzxZ8b+c7T/JT/neHiHsiNcd1/q8Eri+qYCpOCIqyBU ZmzFQNNPdrAKO6e7TnozMU+Dg3AYlEKe8sIki5CaCpbdRFNphg18VTNYO ePYZkU3/A0uRj80G2CjNBI08Yt+Ny/ZBJNfAlAryteVyBwMxf+aUXdwVL A==;
X-IronPort-AV: E=Sophos; i="6.01,233,1684814400"; d="scan'208,217"; a="53908844"
Received: from unknown (HELO eadc-e-fmsprd01.eadc-e.gd-ais.com) ([10.96.30.97]) by vadc01-egs01.gd-ms.com with ESMTP; 26 Jul 2023 17:27:23 -0400
Received: from azr-v-mbx02.GD-MS.US (azr-v-mbx02.gd-ms.us [10.144.20.53]) by eadc-e-fmsprd01.eadc-e.gd-ais.com (Postfix) with ESMTP id EEEF5FB04FC; Wed, 26 Jul 2023 21:27:22 +0000 (UTC)
Received: from azr-v-mbx02.GD-MS.US (10.144.20.53) by azr-v-mbx02.GD-MS.US (10.144.20.53) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.27; Wed, 26 Jul 2023 17:27:21 -0400
Received: from USG02-BN3-obe.outbound.protection.office365.us (137.100.132.86) by smtp-relay.gd-ms.us (10.144.20.60) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.27 via Frontend Transport; Wed, 26 Jul 2023 17:27:21 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=K8j1atU/AZqCDMjJcWt3T9//ZDws7H31pXOOt7Y32HR7GO/ry65+xCB0Lc9NVJbsN5LO1Dpu5SxYlg8AVNc5aWyL7nclJ8ftvIoc9ajWzoQ4GrJLUi/CgEAHMc0wJj947Tn4rDWEGI6VDxYdgWEF0UHsUeD36i53yH1LTwUvEYpZglQfck99fSRIDGG6Yg6Wvty5GKiTCOc3EGfXN8QKAIMmtC0lTB/PuuM9HQrw5ZKwKI2PgE9sRYWKF0UPbocU67ASsecPsc2H7GAha6zGICIwqX0nI/ZMPyW7ABnNBLbTZrhakJ8x7+75xaL1mvPVUsiihmJFHc2YMCgvVBfEIA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=oteCV4WQ8YKjNhGyYN8lVpweu+sol4VLOkxIfr3wbVk=; b=t3mNGBldp5PYPMpJekydZcL0Ep9H3yoJYdZq2Xfl5AxQiy6GFJztoi/gyCrBRFj9H4Z4uHIYVwrlNLEn0Q20GezjCzCROwq1sN+BP2DUS1e4xx5MF6aIyGnx2w8Axq7qXxVcXM1c0IKplZVqEFgMjxqJVKt+/n76b5rh8yfEvupiU5o3WDZmfNFceY9czCtNPscLRxsfDOUzd/j5rOfmqP5ShsCmtpQ3sjJ7SYvp1LGfehGFY+STUSCm/UFIAIrmmVT7+wDsEk6bm1Y9YcOhtSxqjjzV5zyqzWas6C6w1lnEBY18pnHUdZg6YK+GlZcIrhg8c/F3c+5IJ2Co8NIfNQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=gd-ms.com; dmarc=pass action=none header.from=gd-ms.com; dkim=pass header.d=gd-ms.com; arc=none
Received: from PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:189::10) by PH1P110MB1457.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:18a::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6609.33; Wed, 26 Jul 2023 21:27:19 +0000
Received: from PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM ([fe80::4cb0:e196:9217:d020]) by PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM ([fe80::4cb0:e196:9217:d020%6]) with mapi id 15.20.6609.035; Wed, 26 Jul 2023 21:27:19 +0000
From: "Dan.Hanson@gd-ms.com" <Dan.Hanson@gd-ms.com>
To: Roman Danyliw <rdd@cert.org>, The IESG <iesg@ietf.org>
CC: "draft-ietf-avtcore-rtp-scip@ietf.org" <draft-ietf-avtcore-rtp-scip@ietf.org>, "avtcore-chairs@ietf.org" <avtcore-chairs@ietf.org>, "avt@ietf.org" <avt@ietf.org>, "jonathan.lennox@8x8.com" <jonathan.lennox@8x8.com>, "bernard.aboba@gmail.com" <bernard.aboba@gmail.com>
Thread-Topic: Roman Danyliw's Abstain on draft-ietf-avtcore-rtp-scip-05: (with COMMENT)
Thread-Index: AQHZv+2AlRhYQp9yokSuyc73UpW8Z6/MjV3g
Date: Wed, 26 Jul 2023 21:27:19 +0000
Message-ID: <PH1P110MB1172854C3B66738930314E12D500A@PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM>
References: <169039547056.3183.16209480963216260492@ietfa.amsl.com>
In-Reply-To: <169039547056.3183.16209480963216260492@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=gd-ms.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH1P110MB1172:EE_|PH1P110MB1457:EE_
x-ms-office365-filtering-correlation-id: 23b0675b-f520-4e93-27db-08db8e1f1789
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: B4Avd9LEYSrFmz76kKcT/0UXHfbzn+/jTsz8vgJPX7Sl1187/PcEL7IelRKTv5GG8Lhtl6h3na/IkLvQW7QNwAkixk+1eJt4A+rDJ/kMeo+9J2fvJrnhYnGgCf6h8hqLiqvkpgPmjviFD3lRNoaBBMYnPd7RIguiKbTKwvXcNj+qXtshz+3tfX+r6+jCAj/N8iSBA/0sQ6TOX2dQ6knZI56lrraFP51Xn+LcLaQ8LKxTvhYcqAgyKJvw2kxa18BOEUDUyc2ZwpHrmxT1V28CzDovSDfG6TVIqtY5odHtH1AeghNG7sAsDbWRljwLJzbfHJdv4WD3Gwb57ea+sG1PipGpY9uFZJSJ0CqmI2c6l1D6iBpWVoRcNFiD3+vqwRjOjzQvLtWIrDfG9xAW+d36rtC4i8cOgSrneNmxGwfEP9nRqRP6jsDdu/yCCDKt5WXwoZY+u4sc7TQwwuK6btfqo/+Xq0yM3mgONN88h3xnAeyi3Z6KqI6Zj5RCPUxLRw2EgZ+zjCgeif8jImHARll3T96NQ4fMaAF6P++/AVHlHM+FK0O8nwEj9f2ogRUWF/9t5I1c9kzDmOF9pbgvCze29BsanVcQOAxzANhg/r/RwTn6Wr9ZH66IIGR3cFPp3lXH
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(366004)(451199021)(966005)(7696005)(110136005)(9686003)(54906003)(498600001)(71200400001)(6506007)(83380400001)(33656002)(86362001)(38070700005)(55016003)(30864003)(2906002)(186003)(26005)(38100700002)(82960400001)(122000001)(4326008)(76116006)(66556008)(64756008)(66946007)(5660300002)(66446008)(66476007)(8676002)(8936002)(52536014)(579004); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 4B0150DyW/+Woxuf9W3SiaPk80YMS6vMkIiUZ3ydqyEjwxOApYzHX2grTGObcdfbTTrdrgG1h6IXWTJ+DtX+aJ1jRaXTHVjmecwjxOaYAIihlsnTUFv29FkzGDM6CnHMu3Pn9bKzi1P6GTGBPodRvYlLjRod5+tYoxe+HFiTMA4apeL4KkxcxuuK07mN9XBY7Iz6OHsDpodJuXMfDeouwclMZatu8lF0lFZw4vLlUjnRS3Hf3meLE0Ub+FKc+/NZ25/NUAeRblCTuR6vfopjzCPGpTSIozeelj/tuv/Y3YUQ0aFAFOBI2pbg3gUpVH8/dRI0fHKJTNzFg5tell5FH9CvMzI0//tjXC7R7E1lySnrrBWz/oIjcyNOwB5H82hrbQmvTA5lDvnkjop/bQJFZRZ/A8cMBoN1FOC38ZExJtqfiA8EeeqpX+hRzmCFsQYz2tfJVGM4KWX7cD5SVsJLMg/pMuDi2s51VVrJNiBwB7qNaTo6F3VAhxjwEyvPHHpOSb4hSQ+qUdAkO1H0gmYieYiUNTC2x0IxZBIqsCOOgnfzM47hozQV4VSm7bg6dv8HBqbSsxPcXwNWFFCdCsqL78hFTDBgX+TFeNY1YuGrfrHNCCGgQ3vGwkTrriOKX/n4u5Lwr7lfjRQpK5cxhb9ka0zPeM86dEKcsVX8wPJOWJEVYSUU+8FJImU2PWFS8uvErLUYlGJ1sg2FU7CXXUJLVZhYyRO+9iXClNAa7xJnp9dWrKJWrwxTsnq5MF2NnElqPZUtn1p3w8KchBlUBUQwSdIpmxwQc/PzvsL78oBbMWl2blW30nQH/YUuxfedSYMA8efXmVmToJJyFbUNrNCFrC3MpYCb9c4GHyTOCutbnrLCuhtdADQWBGGYWVjX9Ni/BmZICyoniF4FA6GUrYlRLkYvEhNAa+nMNmjAnaSOs988khBqhGUQELOJf/LltG9B0TUQrIap8zOPC8x4oYhDoRQLy9DFkKiCYzDhmH2WNZYS/zA26AXd3oGHKL4EyIMNwrg/anmLX52+NBPipWBX9mV0jHB/oviXaX6JHySF43wtanYCFDmzUbgK3He6FcbblgQHSBEZiF0SOpQ6+XWwzb2UX3F/8Pi+i/h1EY4ZmbPAVzSe/8UMMBJ61d+kK/AWWBg0n+4G341uDg2E5EMZI0d2Agc2a8d7Rxa2c/6RIpOuGLCI+M+RGp7NWoT3MTKPy+EwiOZdZpv4lXjjAQzsaOaXinep814VoFZqltjxn3oA6D2CXwAbgrgudwxxI1xp0OfgMccZvLId3wBmwJnGfSyEy9zdqxsFna548B0u5Xh58h9AHoIMehJY4bg9WxlfVi3nGxFSl3aUohSOCfkgSODXcLUOXdWC7gC9UZ90esN2FC4e/CBMxESL5rAJQ2yIaAWYLdYgl5g5RqGdG6uncPNeI+s6gq2aF/I74EmYeznqS9yDRmZqEV8RGBVFhZgmyXI40OSiTZGl5Kh/fu5vQdEZpdkrHPswOhlQ9r7kZjs=
Content-Type: multipart/alternative; boundary="_000_PH1P110MB1172854C3B66738930314E12D500APH1P110MB1172NAMP_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 23b0675b-f520-4e93-27db-08db8e1f1789
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jul 2023 21:27:19.2864 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 7c5a26cf-ddf0-400c-9703-4070b4e3a54d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH1P110MB1457
X-OriginatorOrg: gd-ms.com
X-TM-SNTS-SMTP: 55679F7AD2DFED1CCEAF4443241B2ADA4A8C64F935F70929B5138B090FDB94402000:8
X-Content-Scanned: Fidelis Mail
Archived-At: <https://mailarchive.ietf.org/arch/msg/avt/-JPlqe9uXb92EqS674SsU4idMBs>
Subject: Re: [AVTCORE] Roman Danyliw's Abstain on draft-ietf-avtcore-rtp-scip-05: (with COMMENT)
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/avt/>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Jul 2023 21:27:40 -0000

Roman,

We feel it is important to follow up with your recent comments.  The following responses were in the slide deck from IETF 117 but were not presented or discussed due to time constraints.

*       ... However, unlike all of the other recent "RTP Payload Format" document I could find, the text here avoids making a normative reference to a document formally describing a payload.
o       There is precedence: RFC 8817 TSVCIS has an informative reference to the TSVCIS specification
*       It wasn't clear which text in this document was intended to inform the definition of security policies.
o       Rev. 05 shifted the focus so that the SCIP payload should be supported by network devices - stated in the Introduction and Background
*       ... the stated "Intended usage" of "Common, Government and Military" doesn't seem consistent with the guidance in RFC6838 ...
o       The IANA Media Type submission form allows 'Additional Information' in the Intended Usage field.  We can remove "Government and Military" to avoid confusion.
*       Section 5.1. and 5.2.  I concur with Francesca's ballot which wonders why the IETF is registering a media type for which it has no change control and the challenges it might create.
*       There is precedence: RFC 8817 TSVCIS is a government/military-only Media Type (and RTP payload) over which the IETF does not have change control authority
*       SCIP is requesting the same consideration
*       ... The underlying codec is proprietary, neither available or intended for users outside of a closed consortium; and the need for standardization isn't clear since this is intended for this closed consortium.
*       Again there is precedence: RFC 8817 TSVCIS is proprietary, neither available to or intended for users outside of a closed consortium
*       Based on non-public TSVCIS and SCIP specifications
*       RFC 8817 presents only a small portion of the RTP traffic - only the Narrowband MELP voice.  There are other payloads such as Wideband voice and NB/WB Data that are not presented.  And there are several control messages (e.g., preamble, EOM, etc.) that are transmitted that are not presented in RFC 8817.
*       Our main purpose is for network devices to support SCIP


Respectfully,
Dan Hanson
General Dynamics Mission Systems

This message and/or attachments may include information subject to GD Corporate Policies 07-103 and 07-105 and is intended to be accessed only by authorized recipients.  Use, storage and transmission are governed by General Dynamics and its policies. Contractual restrictions apply to third parties.  Recipients should refer to the policies or contract to determine proper handling.  Unauthorized review, use, disclosure or distribution is prohibited.  If you are not an intended recipient, please contact the sender and destroy all copies of the original message.

-----Original Message-----
From: Roman Danyliw via Datatracker <noreply@ietf.org<mailto:noreply@ietf.org>>
Sent: Wednesday, July 26, 2023 2:18 PM
To: The IESG <iesg@ietf.org<mailto:iesg@ietf.org>>
Cc: draft-ietf-avtcore-rtp-scip@ietf.org<mailto:draft-ietf-avtcore-rtp-scip@ietf.org>; avtcore-chairs@ietf.org<mailto:avtcore-chairs@ietf.org>; avt@ietf.org<mailto:avt@ietf.org>; jonathan.lennox@8x8.com<mailto:jonathan.lennox@8x8.com>; bernard.aboba@gmail.com<mailto:bernard.aboba@gmail.com>; bernard.aboba@gmail.com<mailto:bernard.aboba@gmail.com>
Subject: Roman Danyliw's Abstain on draft-ietf-avtcore-rtp-scip-05: (with COMMENT)

----
External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.

Roman Danyliw has entered the following ballot position for
draft-ietf-avtcore-rtp-scip-05: Abstain

When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-avtcore-rtp-scip/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

(Revised position)

Thank you to Magnus Nystrom for the SECDIR review.

I am abstaining on this document as it is unclear to me how to evaluate this
document.  Unlike most of the other recent "RTP Payload Format" document I
could find, the text here avoids making a normative reference to a document
formally describing a payload. Colloquially, I'm not sure how one can describe
the "payload format of _something_" without normatively citing that
_something_.  Furthermore, the security basis for this document comes from this
informative reference.

The IETF 117 AVTCORE meeting discussions helpfully pointed out that RFC8817, a
document I balloted on with a "No Objection" position, cites the codec it
relies on informatively.  I appreciate the inconsistency of my position.
Simply put, I missed this detail in my review of RFC8817.  I'll note that
RFC8817 does normatively cite SCIP, albeit the 2013 version, and this document
references 2017.

In my assessment, this approach meets the DISCUSS criteria of "[t]he draft
omits a normative reference necessary for its implementation, or cites such a
reference merely informatively rather than normatively" per
https://www.ietf.org/about/groups/iesg/statements/iesg-discuss-criteria/#stand-disc.
 However, I won't hold a document for reference mismatch as it is clear that
the WG has discussed this issue in depth and there is IETF consensus on this
way ahead.

Additional comments

** I would have appreciated additional justification for the proposed standard
(PS) status either in the text or in the shepherd write-up.  The underlying
codec is proprietary, neither available or intended for users outside of a
closed consortium; and the need for standardization isn't clear since this is
intended for this closed consortium.  MIME registrations can be done without a
PS in the IETF stream.

** Section 1.
   This document provides essential information about audio/scip and
   video/scip media subtypes that enables network equipment
   manufacturers to include settings for "scip" as a known audio and
   video media subtype in their equipment.  This enables network
   administrators to define and implement a compatible security policy

It wasn't clear which text in this document was intended to inform the
definition of security policies.

** Section 5.1 and 5.2.  The IANA review will clarify this, but the stated
"Intended usage" of "Common, Government and Military" doesn't seem consistent
with the guidance in RFC6838 which says that:

   Intended usage:

   (One of COMMON, LIMITED USE, or OBSOLETE.)

** Section 5.1. and 5.2.  I concur with Francesca's ballot which wonders why
the IETF is registering a media type for which it has no change control and the
challenges it might create.