Re: [bess] Secdir last call review of draft-ietf-bess-bgp-sdwan-usage-19

Linda Dunbar <linda.dunbar@futurewei.com> Tue, 06 February 2024 18:12 UTC

Return-Path: <linda.dunbar@futurewei.com>
X-Original-To: bess@ietfa.amsl.com
Delivered-To: bess@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68723C1519A0; Tue, 6 Feb 2024 10:12:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.107
X-Spam-Level:
X-Spam-Status: No, score=-7.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=futurewei.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9OXdQX8e2pwm; Tue, 6 Feb 2024 10:12:38 -0800 (PST)
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (mail-mw2nam10on2103.outbound.protection.outlook.com [40.107.94.103]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 49505C151093; Tue, 6 Feb 2024 10:12:04 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kf3bezjDNDw4pxSN62WuOmD37cWFeFQDGtjNK4GAYKi3Sdw7Fll0pdSqZTqmcYrC9F8FCOdEJF77iqhWTZn0CfyydGQxMzitrmBvTBTcjLyGbGT2xqJp8+8QUXSjyAqVrQqDX014kKyGpkOJmnyDtrxoSDbm5xg8WaxhUfcSq81Sh1SVZ8BwOMJdohNRFEBytN/3C0sOERm3htPxPaod8FbBF6QWm9r4DXAQ6ff05/TCgo1/+3/fCWOKgypmuqNM2BLhu9giUjvboChoNiJmez/p33htfKKj9v57hZp2CvPTSH5aLprcWng2wsZ/K1E81XbIhj33HVs00esvGAQ5zQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=O6ekxYJgM+rNfikJp0NwJkRqV+cduNMxri/ykV4fqF8=; b=Qeh7ZM2nk2dgRbCs/4oIMVTJgHZzOJ934BonSxlue1MtvZu55LUGFAAior/VddSTmOwUjGXxwklUalIyGmGV7SKJzTMA+X4D57aVJsT7CohHa0QqvdPfbr7d/i+7OJ6+IXraRNAw/LO0t4MrJusl+ViUVb8Em1Fg3eBtNVb9yQKDTIJAmS8zANMM7OUtsvys4o+ydqDFAIPvuAtZIViw+UOhGwCEuqnV5OqAOp8SUuPZO5Vk0WkEncEP+PVYd+58tlyTkhfPGMN+X75RC9LmMs/syZmnzG5njKdanE63xoJU5NJTEhc9hLSToUK3Bver1Bp4vONsM/xFQBas5vKeqQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=futurewei.com; dmarc=pass action=none header.from=futurewei.com; dkim=pass header.d=futurewei.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Futurewei.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=O6ekxYJgM+rNfikJp0NwJkRqV+cduNMxri/ykV4fqF8=; b=guUhLWKe3bu5lDyJ/t8DU598Tz5zKdkbfFmqmCBSzxuyJ9v3CqqmkQPBNN6QienXb83HFO5OS5Vim0Jio3XG1jx317HbWCWpCZKcMQAFk+v8yK0qaU78vE291TSbwxgCMEjNofpN04qAQV7achAyj/nV8JFoZLIiq0DUTY2FKPI=
Received: from CO1PR13MB4920.namprd13.prod.outlook.com (2603:10b6:303:f7::17) by CH0PR13MB4619.namprd13.prod.outlook.com (2603:10b6:610:c9::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7249.36; Tue, 6 Feb 2024 18:11:59 +0000
Received: from CO1PR13MB4920.namprd13.prod.outlook.com ([fe80::e6e5:1a02:6552:c0c1]) by CO1PR13MB4920.namprd13.prod.outlook.com ([fe80::e6e5:1a02:6552:c0c1%6]) with mapi id 15.20.7249.035; Tue, 6 Feb 2024 18:11:58 +0000
From: Linda Dunbar <linda.dunbar@futurewei.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, "secdir@ietf.org" <secdir@ietf.org>
CC: "bess@ietf.org" <bess@ietf.org>, "draft-ietf-bess-bgp-sdwan-usage.all@ietf.org" <draft-ietf-bess-bgp-sdwan-usage.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-bess-bgp-sdwan-usage-19
Thread-Index: AQHaVeB7l9E64YzBdUijQUHOsOewprD9m8hA
Date: Tue, 06 Feb 2024 18:11:58 +0000
Message-ID: <CO1PR13MB49207C24DDCDA6DA13516DEF85462@CO1PR13MB4920.namprd13.prod.outlook.com>
References: <170688255428.29934.10272482596067024408@ietfa.amsl.com>
In-Reply-To: <170688255428.29934.10272482596067024408@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=futurewei.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: CO1PR13MB4920:EE_|CH0PR13MB4619:EE_
x-ms-office365-filtering-correlation-id: b14fcb84-beae-4705-0356-08dc273f1c33
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: z1aXS2JR5d8cqVhufr6ZasHqVLh8mm1dbc0A/YMlsL9XPlTZcZC6ME/k6PeERB5I0lb3fs7/qVxCOHxQwYntpK31oCC0ixW/EzerEIR2Zm6oxB27JDjKoOXEQziO04CPJ5+TcOJPx2nlfHEioz5TdRD5Sh4dXotWFPGfvLnxsN2VhWJVN2qMB7ulBTsHRxprtaxEIXL8JzZGOm5v5hX4zXe50NhP0SBPah3IVkQQIu7/pqBHdR3CBnuC/wdPa7Q3LoqvZgY8H5D1Jjt6zOTj/1ljWImq/4bGuxGtRlyVviWa3xfhDey1nKN+eXT/10hY2DVoQ+htCcRufAjW3CKViwE2clGkUhuinnLRdN431qrPMOAJAtgyB03KkuIz9Pc1M6eEys+gifPG17EK6Ql3hOnz0A7zrxgjOr7UposFAvbHfS/jpP4MXCSfvHObGgINqtUqEPlkZtRdfipH/dpJCME40naTjzEu/B7VWrakL2Wfng48mOnLhJgm6b3054MJAKuyxBmeSRgMwMARDBFfoN6YHpDk5JZQL47IXSWuzxe84RKBhq2AgAQbhgql7EidE3BZ/SqP882oVbIVWigb5JvrHgXOoz4l+aXZp0adpvE1YSgYV0px/jJe8dpAkfYx
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO1PR13MB4920.namprd13.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(366004)(136003)(376002)(346002)(39840400004)(396003)(230922051799003)(64100799003)(186009)(1800799012)(451199024)(6506007)(316002)(33656002)(122000001)(55016003)(7696005)(53546011)(38100700002)(83380400001)(86362001)(26005)(41300700001)(296002)(52536014)(4326008)(8936002)(8676002)(9686003)(71200400001)(478600001)(45080400002)(30864003)(966005)(2906002)(5660300002)(54906003)(66476007)(64756008)(66446008)(66556008)(44832011)(66946007)(76116006)(110136005)(38070700009); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: PVHhlV1jath10wj/Z3MI1rKeQ8li0u8Tp0hTonZ/hzwj1ZRYd1QjdqtEFOPCOh1XIokspztJT6TJvV6v32PVQUFWOKEgZy7b9VEB43UAJDj37Mg0oA/l4efP0YAFB6NUeno7elQItuWS/wLL0i0v2G0SGWMt5lgpw4X2DmSJLe0euAGbYeUi5UxiSuEGdbG0KR2yc30bIqI2rZs78IiosizGpxlNtEml27tgJ2Ozd5bAJP28pTpi/3KwKNRlOZBjyyIbkTj/BMKiC+f69zJUy3o19o8s2ysefLafDK1WPD4tDsg6I7WolZRX41psZSsM8xBGB5m3ZldfcN7ntcKfXrQit2M8eLQ9SJjINiLzB+sMbI6GSy+0dpDdGqAIKnV1rg7aNGPMvShuU1kiHs75mxzX1xLcOZjBHfG8wvppz7zyttHkhSWOOnOFi3/c15L1l7oYsw7D65guMNlkW5DyFomPGtV4E8AXtitI8rOBXbujolY3782nN+2NVmbeb6cpJtBvtD18YrmPe3QYzQg9NFmaUR4fXYrD4C+bsK11PVgwiDfDoh3mQmWL4QHsf9FT/o8Ha608BwCas2AqOpKdgoOpC3JRwipRuMbZd6bVSeLPxH+x29anyAmCza2xLqYSW1WcEisOOOky9n2JylompO/pb6sQWhhzLrxc27vIWy8+GFGF+zpJydIRrXT2xGHr3bEE/Q1gWxVYBHbV3rj+7i1Kezv7OdJMRVdt7Y+Zf0MjPLYQu58un+usKwYzmzv2Du8qenBvsQ+oXkwQ1les4zN4vZh+ngliuvyudVZiBEK1fV8a01t52JsP8RL3sdERQB5O/A9cRhnVNbw+Tb9JUmsW8FxiXJPGc7EQxTP+EXDE9Rb3EBrQd5P+XmI42B9Ih5OkPsI101+0Gcjb5wnkhuOFqMa1+d2B/A2Nk1aqiLOLJBywx4HAnQ99hSEXhzfMX2f+ykGCG0KQrCDz4cON9O0bSZme1dwY6hXLdwY8jxTzGG4VVzzvLSgAcufgvx1mfNCUyDNEliYPKrOjm6qnCSGwuXvf2bOEvR01HJCzOSVTn9a984yIh3VXLUBtCqx2B2mPOqOBvltZ4J6zkdLolugKEXexzkGJRZq2ZVpwOs/oM06D+eaNwwXwOF8GejiHqwXWzqm5sZC3si/klFotTEcWNChkkwQAqud6E5P2fiaElwTG9rOQkOvzEHH3kg6MgbFDIDe1jrSI0F+yEcI5VfS5XUdvq7CJUXey5f4xZvuXUCBRUyKEoJ3dWEpiFcTnmGR4sigzfUy44nj3b4+sVfJRSp7hGNgu/5Sqjz0uY/99XdzbHGDXLZUnWdhtff7HRjIXT7G1Ksb2743WOI4N1xiNkB8M2Yi3/3K3l6emT2MJNbb7lNfSW77caQSsVCy5IyudlXMRlv3zCJD5OuQI3SO+wQXwP0K9r/yV8PoB3tMhO0RN9+dIdtbrPOjltFhxPMlltuew92KxdhBr3DeV2M03B69S4i5+/Hiw7v1gIW7fGmxBwcGJQ7b6FNf5SkBJ0nC9TnsUaaAf6358wwlNWuEravMk7CzIRIHMc2Q4lhyrfXmCan7GuxUMwIZeQ1fn
Content-Type: multipart/alternative; boundary="_000_CO1PR13MB49207C24DDCDA6DA13516DEF85462CO1PR13MB4920namp_"
MIME-Version: 1.0
X-OriginatorOrg: Futurewei.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO1PR13MB4920.namprd13.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b14fcb84-beae-4705-0356-08dc273f1c33
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Feb 2024 18:11:58.9140 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0fee8ff2-a3b2-4018-9c75-3a1d5591fedc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: yL/jN5I0E0mqjPOO0P+Bf2Bd2TNREfsHMB0Q4IfvT0V/EYdrgOt7B0K1Waq/p7krNMrqQGjXhPrDvXWuhXiyng==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH0PR13MB4619
Archived-At: <https://mailarchive.ietf.org/arch/msg/bess/1Z7_rPEw0zCMRhGRri5copy30f0>
Subject: Re: [bess] Secdir last call review of draft-ietf-bess-bgp-sdwan-usage-19
X-BeenThere: bess@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: BGP-Enabled ServiceS working group discussion list <bess.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bess>, <mailto:bess-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bess/>
List-Post: <mailto:bess@ietf.org>
List-Help: <mailto:bess-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bess>, <mailto:bess-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Feb 2024 18:12:42 -0000

Stephen,

Thank you very much for the comments.
Please see the resolution below.

Linda

-----Original Message-----
From: Stephen Farrell via Datatracker <noreply@ietf.org>
Sent: Friday, February 2, 2024 8:03 AM
To: secdir@ietf.org
Cc: bess@ietf.org; draft-ietf-bess-bgp-sdwan-usage.all@ietf.org; last-call@ietf.org
Subject: Secdir last call review of draft-ietf-bess-bgp-sdwan-usage-19

Reviewer: Stephen Farrell
Review result: Has Issues

I looked at the diff from -15 to -19.

I think the main security issue of depending on BGP over TLS remains - that seems almost fictional (is it?), whereas the shepherd write-up says: "...this draft is simply describing the usage of existing technologies standardised within bess to SD-WAN." I see Roman's existing discuss already covers this.

I note that https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-wirtgen-bgp-tls%2F&data=05%7C02%7Clinda.dunbar%40futurewei.com%7C865a98f23bb64f96819f08dc23f79b99%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C0%7C638424793593072100%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=WGKAHNvuivJbVIe6HvAU4Eeju741Dw9x70yVlpIpwH4%3D&reserved=0 was posted since I did the review of -15 of this draft, but that seems to be a fairly brief -00 individual submission. Presumably that work would have to have progressed significantly before this draft could reflect reality.

As this draft is aiming to become an informational RFC, I guess one could rewrite the sections mentioning TLS to say that BGP/TLS is needed for this to be secure, is not available today, but is something that is being developed (e.g. referring to draft-wirtgen-bgp-tls). However, doing that before adoption of a work item for BGP/TLS by some routing WG might well be considered premature and overly optimistic?

[Linda] Thank you very much for the suggestion. This draft operates under the assumption that a secure channel exists between the SD-WAN controller and the SD-WAN edges. In the context of extending an VPN network to  the SD-WAN scenario, this secure channel can leverage the operator's primary management channel designed for VPN control. Consequently, there is no strict requirement for BGP over TLS. As a result, we can remove all references to TLS from the document.

In the "Security Considerations", is it beneficial to add a discussion of the security issue of using BGP over TLS?

Linda