Re: [babel] 6126bis: implementing Babel-MAC is RECOMMENDED

Donald Eastlake <d3e3e3@gmail.com> Tue, 24 December 2019 15:59 UTC

Return-Path: <d3e3e3@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1E9C12011E for <babel@ietfa.amsl.com>; Tue, 24 Dec 2019 07:59:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.748
X-Spam-Level:
X-Spam-Status: No, score=-1.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SysOOQuMtgzH for <babel@ietfa.amsl.com>; Tue, 24 Dec 2019 07:59:11 -0800 (PST)
Received: from mail-io1-xd31.google.com (mail-io1-xd31.google.com [IPv6:2607:f8b0:4864:20::d31]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 54C37120118 for <babel@ietf.org>; Tue, 24 Dec 2019 07:59:11 -0800 (PST)
Received: by mail-io1-xd31.google.com with SMTP id c16so18038224ioh.6 for <babel@ietf.org>; Tue, 24 Dec 2019 07:59:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Fy0jqUE6HB8YztTfi8deDNigHi1vuFBYnUl+GwvPUvs=; b=Sf/cU+JrhmX5ltR3FFp3m2PJ/VG2UyKslv/K6s1L8uKSAFPYw9Sa7RNqANKiUapC34 834fvvjbWrXOBRv3AFAIhe99r/EPJFlac2fowakeQft1vJTXcKMvQhujHd+G/RM+Ivpn 3OxKYH8YeDoXirwGbp3tDNVSf9iINDeib473vgnGW+aRp3N3FqRAh21DVfSe0ldhVTDr Wwxj4tY2T+28UhSVI5uRFwsvXUB2svBJx4awtKB6iSLYf5PWooU6qTmpTZOuOHfY317m 09AtxoWZDzqmyeSozo+SAEwl31Q6812btx6yHtBhUdZCQgwQ+CoCSaGeMBRyOwTLwefw kTPw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Fy0jqUE6HB8YztTfi8deDNigHi1vuFBYnUl+GwvPUvs=; b=r3b6F9H6BFH0IPSqkFcyWz+Swfyh2hyNne+lm/xlTUpfUDtnI/TxBN4fGcxREECJxg 8I7LEkYwpa+kdqEw7+q9ttdvYG9cmS9jrP1+rhAe7zTNN5XLZjusSly+dJBnF5GY62VS wm3lqTol4inkC7o+/ECewqqB1gTqvBSWp3K8x4DCBIdFYX6sIRF5D6qvL/5DgLpMBIWx hCSWvKTHko3QQzQAtnLVxgrVpiN4mu/IPWhSeZicXqJWR9HjCcYRtiQTx95r8G9DCUxv ZwOhr5hBti/bACFxdpKpVJRcRHE8xI7P8cjbFuJsv1t7xzBcWVoXjdSrPB7tMWG627GJ i7rQ==
X-Gm-Message-State: APjAAAWmvpY68d+tzh4GxHm1KrrDf5UydjwiQEbGNWXspV2ae94oz0Yu XkJO+h3o6ugaayIoztbQjkk6H9FPg5aiwTE8WGQ=
X-Google-Smtp-Source: APXvYqwr3nu62i1/xN7CN3IBTEDCbVnvvwJEBUcbTAefXm9FjGUULiyHuyF6GGUjj74g4yPDgvqAYL+Ab4kC4pTWwoU=
X-Received: by 2002:a6b:b941:: with SMTP id j62mr25526506iof.168.1577203150606; Tue, 24 Dec 2019 07:59:10 -0800 (PST)
MIME-Version: 1.0
References: <87y2v2vcb7.wl-jch@irif.fr> <87d0cewqi5.wl-jch@irif.fr>
In-Reply-To: <87d0cewqi5.wl-jch@irif.fr>
From: Donald Eastlake <d3e3e3@gmail.com>
Date: Tue, 24 Dec 2019 10:58:59 -0500
Message-ID: <CAF4+nEHk+-v2ewPCSSQhk5y2cQAaGqA5W=HTogbHbytLd_wWHQ@mail.gmail.com>
To: Juliusz Chroboczek <jch@irif.fr>
Cc: Babel at IETF <babel@ietf.org>, David Schinazi <dschinazi.ietf@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/br5uqjct4KunnuZBheL_J-FSi2s>
Subject: Re: [babel] 6126bis: implementing Babel-MAC is RECOMMENDED
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Dec 2019 15:59:13 -0000

Hi Juliusz,

Season's Greetings!

Speaking just as a member of the WG, I think this is a reasonable
minor change. As you point out, use of Babel-MAC was recommended when
it provided the security features needed so it seems reasonable to
RECOMMEND its implementation.

Thanks,
Donald
===============================
 Donald E. Eastlake 3rd   +1-508-333-2270 (cell)
 2386 Panoramic Circle, Apopka, FL 32703 USA
 d3e3e3@gmail.com

On Mon, Dec 23, 2019 at 6:50 PM Juliusz Chroboczek <jch@irif.fr> wrote:
>
> >     Every implementation of Babel SHOULD implement BABEL-MAC.
>
> I'm realising that this may seem somewhat cryptic to those of you who
> haven't been following the ongoing discussion with the IESG.
>
> Babel-MAC is already the RECOMMENDED cryptographic protection mechanism.
> However, there's no normative language that recommends implementing
> Babel-MAC.  This merely adds a recommendation for implementers, as opposed
> to network administrators (who are already encouraged to deploy Babel-MAC).
>
> -- Juliusz
>
> _______________________________________________
> babel mailing list
> babel@ietf.org
> https://www.ietf.org/mailman/listinfo/babel