Re: [AVTCORE] Éric Vyncke's Discuss on draft-ietf-avtcore-rtp-scip-08: (with DISCUSS and COMMENT)

"Dan.Hanson@gd-ms.com" <Dan.Hanson@gd-ms.com> Fri, 02 February 2024 17:47 UTC

Return-Path: <Dan.Hanson@gd-ms.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC94FC14F5F1; Fri, 2 Feb 2024 09:47:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gd-ms.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UCsYFdbs4EES; Fri, 2 Feb 2024 09:47:33 -0800 (PST)
Received: from vadc01-egs01.gd-ms.com (vadc01-egs01.gd-ms.com [137.100.132.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8C99CC14F5F4; Fri, 2 Feb 2024 09:47:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=gd-ms.com; i=@gd-ms.com; q=dns/txt; s=esa; t=1706896053; x=1738432053; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=BfxnONDHUxPSdoQSWYv6/be08PUpXiNm3eYHqrQRThc=; b=I5nJaWsJgEnc0cQ+PeXWqrbnxkpzFPTHD6ZPfaTklfOZPmdHk9lCYzGp fuWUQUpE9bX7YKDBIGaI9KHdnpNvi3n8XhoLpYg5maFGi2UMMdTPqEYKr bIU98mcoSj9X1BgzLo+7379bXWGOcJPUINlbaCKlHJwwWTpF40KNeCdiI c4wmJ7FpoYDqL8y7DVgnWjZ/WwbCcsf9et5DWRK9yCdY73VXZlZM8AIvP 6ZAevGhjC1Ebpcln7vrdn24tQteACK/iGDD/eKP+ao67XSxUC/ZBh7Y61 r3VJJiLb9f/pdb0UgW+qvgmyPo6JbpjSW0UsrKbStsygvUQj7YCSkXKrC A==;
X-CSE-ConnectionGUID: IL8Nk9nUThCVfkLCMFxsWw==
X-CSE-MsgGUID: 2t42cqozTYy6v4GXfm0QRw==
X-IronPort-AV: E=Sophos;i="6.05,238,1701147600"; d="scan'208";a="64619156"
Received: from unknown (HELO eadc-e-fmsprd01.eadc-e.gd-ais.com) ([10.96.30.97]) by vadc01-egs01.gd-ms.com with ESMTP; 02 Feb 2024 12:47:31 -0500
Received: from azr-v-mbx02.GD-MS.US (outlook-east.gd-ms.us [10.144.20.53]) by eadc-e-fmsprd01.eadc-e.gd-ais.com (Postfix) with ESMTP id 98DF1FB04FC; Fri, 2 Feb 2024 17:47:31 +0000 (UTC)
Received: from azr-v-mbx02.GD-MS.US (10.144.20.53) by azr-v-mbx02.GD-MS.US (10.144.20.53) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.35; Fri, 2 Feb 2024 12:47:30 -0500
Received: from USG02-BN3-obe.outbound.protection.office365.us (137.100.132.86) by smtp-relay.gd-ms.us (10.144.20.60) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.35 via Frontend Transport; Fri, 2 Feb 2024 12:47:30 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector5401; d=microsoft.com; cv=none; b=fioeO/cwnRKjXZy0mGsYZr3KWVw41JX5uY6mq0DFavH2xE5gYsIV076eCH/Je/CPphwAbrLntjQvAwdQsnKqAKHwfL5mvL7nI4o4TOcffxixDWhGX8bCl8cSWBnOZe2Gq4pKwzNBQYDBVzeqWAZfAKykHynR8v28sRzv6PJ94otKgGTcxMDumw5Ism73GppUNI7gwnq5QAmdwO4z0agV5zw6iQsw5wegky2CKISzX/vXmp+SS5Ffr8UUzlpYD/9sAJoh7Fi/qAuoWxVPh4O2ndXiDDjt1Ynsab3HWnybp6QhzIsQEk47oVLylW4ukh6W8DtpNE1SKQEJb9oUWUXodw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector5401; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=XNNu/fEGtk9PrC5XYTn7kjnz4wIfnDKTGN3rQyNfzRc=; b=MLIC17+AH5O751m1N68YzAxz5ZBnAedOLFeCSLauZa7CXTA5/Arxw/osoy9MCCMBhcDCDqcRHanfDK2V6i4IIvcfuItytO8z99DB3w9UHdE+LeHFVhViiZ8Rb8Mb3xYBeFvphDQNc04AwtpABbwEa6jcHViRwcSnEkxV768iZejJ6foNtwG5EGudS0Edl9Nli3/t6f4YkrbkPWpODdVzxAczXRxtbqaHirUkMe9MKsJWwqoAI5iF3EWP0HCCQu+hHaDpfswPjrPCXp7ZKD8sFR4ZEDxofJY0n+POuqXPh6dHk60Mr7plVZ2XPBl+YlQc9HOQM1erOZ2+6HWlcuQRNg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=gd-ms.com; dmarc=pass action=none header.from=gd-ms.com; dkim=pass header.d=gd-ms.com; arc=none
Received: from PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:189::10) by PH1P110MB1409.NAMP110.PROD.OUTLOOK.COM (2001:489a:200:18c::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7249.30; Fri, 2 Feb 2024 17:47:29 +0000
Received: from PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM ([fe80::5a98:a96:eff7:edac]) by PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM ([fe80::5a98:a96:eff7:edac%6]) with mapi id 15.20.7249.027; Fri, 2 Feb 2024 17:47:29 +0000
From: "Dan.Hanson@gd-ms.com" <Dan.Hanson@gd-ms.com>
To: Éric Vyncke <evyncke@cisco.com>, The IESG <iesg@ietf.org>
CC: "draft-ietf-avtcore-rtp-scip@ietf.org" <draft-ietf-avtcore-rtp-scip@ietf.org>, "avtcore-chairs@ietf.org" <avtcore-chairs@ietf.org>, "avt@ietf.org" <avt@ietf.org>, "jonathan.lennox@8x8.com" <jonathan.lennox@8x8.com>, "bernard.aboba@gmail.com" <bernard.aboba@gmail.com>
Thread-Topic: Éric Vyncke's Discuss on draft-ietf-avtcore-rtp-scip-08: (with DISCUSS and COMMENT)
Thread-Index: AQHaVdyFYtfucJm7ckazYago1UfykbD3UK9w
Date: Fri, 02 Feb 2024 17:47:29 +0000
Message-ID: <PH1P110MB117291B1233AB7F6522663FED542A@PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM>
References: <170688085244.27140.3271707817213892752@ietfa.amsl.com>
In-Reply-To: <170688085244.27140.3271707817213892752@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=gd-ms.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH1P110MB1172:EE_|PH1P110MB1409:EE_
x-ms-office365-filtering-correlation-id: 515816bd-c7fa-461d-b7bb-08dc241706bb
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 00Ehq+Mg7A0d0Z6S78kKtbVJS9Ydhx+34KjhFx+UtUhayWybcoqtDnGb7yJQKbrmZRXCXfRehKsqyOoyFdwWaHtXFeAsvvibBDlkBZeO9C8X7O42BgbqVR0y62nRouwRAZqMF1sUV9hkMDVpnbhE9iOhAnsQ2VUtG2geLGbsyr+kOVaRQNmwjOOgxA7XtVt8x90tqa5aolEcjls3K/65iHutg6nGJ2+LRAO8JiktQv4Edxx7APcNmWJiO/by8zAZhbBa3F7FAZq0yIF7ecZA6EAM6aZSbAKFgRpkkypQNYqJt+MXfUwlE7NGjZkPt2qkjEB+SJVuJ3wQ5O1noFOin315gxqoFiDYm7HqbYwvNxUmL3lXktBMtHI5EJl6fkqXkHZ0tK1jFwB/GUHT/3Gm40zgdf1irZ4x1iOd/MSx2Bfzyve/aOE/LDFVG2VzVMGn/DhyOjak6VIIMKV6YCaoyAprwmWwckTa5iR5rkOrJl2/2a4NNczZxqvpOWb0r+NieYz7kmDAW5yhNQu9BgHOlBWccQfE85m/FUjJku/deAie/z7ntY4T5PZfJ/sFsyfEqayfDbt4yXC0emCpHwA3QZJ5IXLQCLw6JM5k5JWLgf5NQVwql/rHhVOuU87UjdBtHdouEhCMamsgSe3Pe65i/MbZ4eXKIqlwkeBIAF4J+FDejVRxhTZ4WRswPeMZCsff
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230031)(366004)(230473577357003)(230373577357003)(230273577357003)(230173577357003)(230922051799003)(186009)(1800799012)(451199024)(55016003)(2906002)(66899024)(498600001)(5660300002)(82960400001)(38070700009)(83380400001)(966005)(52536014)(76116006)(110136005)(224303003)(66476007)(66446008)(54906003)(64756008)(7696005)(9686003)(6506007)(33656002)(71200400001)(86362001)(4326008)(8936002)(53546011)(66556008)(66946007)(26005)(122000001)(38100700002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: eI2ywpAopvFfK71yFc8hPsLKw1bR7v7fVOiJOOj2wGuPDMDe8Vs91+tDdx6AHxZ/aKEzmqBww31VmK+k+pcin4AITKZoWXGYmBsjxBGJ+L5lw65YePvS4ju5SqOSJwiY1VDv92KpIiRSM00mvfp6yAq5wBoDyR+eKBmxth4mbR38E/A6vrau12DOi3/JfzyeE3ChKG6d7oSPtomusvz3RpUaPlO14IPWeJWgjp67GkSICzJoY2X8ly3YU6tg9J2a8wtBe0GS8GR+RuO9tYzUD6c0RWu272asONWVqqzKmXgxxCWf8IELD7+T1GgTeuAZdRbTk7sEMlOrwsbkj1yz9mxRnFsU4E0I/7uYITZb+zwjAvm14OTn0rwLJ3h0NZ3p8hYz87akBhtnEE+J+RHZ/w586q6+vfVrBQuvnFF1g0vymv/O0H5XzwuzK3PoJn+xkCyWi9eoS8R6xjVY3IyvKLyzC2a3RbuQCAjdAn+UIQuzeAJejOhovu6KN0h0zJkidVEoqnPDZSQpusKVbK1szdH9uHXUFjiSP2z6HoGyp8z063h/yfpSIX20Iv1rVgBoCVqmAS8TB0DgO6k/Du+3ONHXQoGyevbVJeswEprCc/m8u9fKIpsZAPR/RGtITBKqYbHgKgGRcSFGb4pVuwmFDgIR9iIjddrxKhUo/J0zNWwfoqGeua9wBpZM2gQoQXNE2Q0Fzmj6f1sPlGmPKmTey5ZocdduyVmnVgwse+ivevGhC9AoQA3za6gUBjXD3/h8Wa48P5j2YL9RYfvt21856366WTEXyjxVTL5Ca/Ot4wHrU7SRleSHkerhvRKaazw21b0GskgF+1r3MXwW33UoGxTMyHjehv6+kr1xsouxzAxRq8aFGP1k/pFEr8wnpVObxF7IqTVA5N+H/b2C5KgQn+meHeOyX2QnCrGtqSelYhO5DksUOQpASDJcrC8jET0VlifbVSChEPcrlZ1OpTO38/in+xV+QdhCn5S9+N3QJ815flQmCsQ9SnxyNjRDHS7XN5SyR3lRFgkq7quIyLIPxz+fewLdJ9gmKeBLiwj2pleHAuy19Yup6CK6iVPy6ZOL5lSHKqMswYED5eWO69K1Qcuhg6pB9QTeUquj41+YP85AjgY083vYLtpygDh2YOcTzUMibWQAVE4g7sdvdVxyt5AhXVH8DPk0dvB79RQl72J3jgVNyHxfNeTXNsHvStxoimIn30pWGFmb+a4aTI/vv31JsVGS/LAgiAqof46LmqTxQRiWqmta1SVUmHPEb4NgExrjf/vqGBX2cRCfayyMy0SIgKNygJr19Due2/jFqsI7bivcgsZpUhC+c5sEx+NC/ehnYVtJPfH7Bff1FilHlb44ZWPt6NG/LjywocsuBsl2mlmIHjP5SyO8nuKepvHsRIDyIiQNRNTAXnWQAj1aUZvck6Hsza2jpyf1BN3qQbkDXxj+qva0p6S5lJ3OppF1bA726QjadCvrV4NZ5hNB5nXs8iMHyRCK/QxOtsidrxA=
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH1P110MB1172.NAMP110.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 515816bd-c7fa-461d-b7bb-08dc241706bb
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Feb 2024 17:47:29.5454 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 7c5a26cf-ddf0-400c-9703-4070b4e3a54d
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH1P110MB1409
X-OriginatorOrg: gd-ms.com
X-Content-Scanned: Fidelis Mail
Archived-At: <https://mailarchive.ietf.org/arch/msg/avt/HTLZfpOOTTufan5ijgtbaFghPcQ>
Subject: Re: [AVTCORE] Éric Vyncke's Discuss on draft-ietf-avtcore-rtp-scip-08: (with DISCUSS and COMMENT)
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/avt/>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Feb 2024 17:47:37 -0000

Eric,

Thank you for reviewing the document.

We have provided the public link to the SCIP-210 specification in the Informative reference section so that reader can have some idea of the different types of messages and data streams that might appear in the packets.  SCIP-210 can satisfy the assertion that it provides the security services stated in this draft.  This assertion is fundamental for the statement in the Security Consideration section regarding the use of (or not) Secure RTP.  This assertion is necessary for the entire concept of an encrypted and tunneled payload in this document.

The authors are perplexed how RFC 8817 (TSVCIS) was published given it is very similar to SCIP, including it being based on a non-public protocol specification as an Informative Reference.  We know that there is far more to the payload format that is not specified in that RFC.


Regards,
Dan Hanson
General Dynamics Mission Systems 

This message and/or attachments may include information subject to GD Corporate Policies 07-103 and 07-105 and is intended to be accessed only by authorized recipients.  Use, storage and transmission are governed by General Dynamics and its policies. Contractual restrictions apply to third parties.  Recipients should refer to the policies or contract to determine proper handling.  Unauthorized review, use, disclosure or distribution is prohibited.  If you are not an intended recipient, please contact the sender and destroy all copies of the original message.

-----Original Message-----
From: Éric Vyncke via Datatracker <noreply@ietf.org> 
Sent: Friday, February 2, 2024 8:34 AM
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-avtcore-rtp-scip@ietf.org; avtcore-chairs@ietf.org; avt@ietf.org; jonathan.lennox@8x8.com; bernard.aboba@gmail.com; bernard.aboba@gmail.com
Subject: Éric Vyncke's Discuss on draft-ietf-avtcore-rtp-scip-08: (with DISCUSS and COMMENT)

----
External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.

Éric Vyncke has entered the following ballot position for
draft-ietf-avtcore-rtp-scip-08: Discuss

When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-avtcore-rtp-scip/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------


# Éric Vyncke, INT AD, comments for draft-ietf-avtcore-rtp-scip-05

Thank you for the work put into this document. Alas, even after some email
discussions with the authors, the core of my discuss is still there. So, I
cannot clear my discuss.

Previous DISCUSS is at:
https://mailarchive.ietf.org/arch/msg/avt/xFC3Ux9AfYt3e5T0GSzrasQe_j4/

# DISCUSS

As noted in https://www.ietf.org/blog/handling-iesg-ballot-positions/, a
DISCUSS ballot is a request to have a discussion on the following topics:

## Section 3 and abstract

I am afraid that without free and public access to the IETF community (whether
informational or normative) to the SCIP protocol itself, the IETF stream cannot
publish any document (even informational or experimental) with the following
assertions/claims:

- `SCIP is an application layer protocol that provides ... security services
such as confidentiality and integrity protection` - `The SCIP protocol defined
in SCIP-210 [SCIP210] includes ... security services such as end-to-end
confidentiality and integrity protection.`

Indeed, all IETF stream documents require that the IETF community was able to
review it. The nature of SCIP standard has prevented such review, therefore, it
is not possible for an IETF stream document to make those claims (that are
probably correct).

Suggest removing any such claim from the text or rephrasing them so that they
do not appear as an IETF claim, e.g., "NATO claims that..." or "NATO certifies
that ..."


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------


# COMMENTS

## Abstract

Is there a reason why is SDP expanded and not RTP ?

## Section 1

Unsure whether the following text has a place into an IETF RFC `This document
provides a reference for network security policymakers, network equipment OEMs,
procurement personnel, and government agency and commercial industry
representatives.`. Suggest to remove it.

I wonder to wonder whether the USA has left NATO ? The text `SCIP is presently
implemented in United States and NATO` seems to indicate that the USA are not
included in NATO.

## Section 1.2

The DTX acronym is expanded twice and never used. Suggest to remove it.

## Section 2

Per `Secure Communication Interoperability Protocol (SCIP) allows the
negotiation of several voice, data, and video applications`, it appears that
SCIP can also be used for *data*, but this document is only about video/audio.
I.e., some text should explain to the reader what happens to the data.

Please explain what is a STANAG or provide an informational reference to STANAG
5068.

The reader will welcome explanations about the numbers in `scip/8000 and
scip/90000` (e.g., by a reference to section 5)

## Section 3.1

Should there be informative references for MELPe, G.729D ?

Is this subsection useful ? This document is about RTP payload and this
subsection is more fit for the SCIP endpoints themselves. But, I am neither a
transport nor an application expert, so, feel free to keep this subsection.

# NITS

The official name of the UNO member state is "United States of America" and not
simply "United States".