Re: [bess] Benoit Claise's Discuss on draft-ietf-bess-mvpn-extranet-04: (with DISCUSS and COMMENT)

Stephen Farrell <stephen.farrell@cs.tcd.ie> Thu, 17 December 2015 13:54 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: bess@ietfa.amsl.com
Delivered-To: bess@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E8A11B2DE1; Thu, 17 Dec 2015 05:54:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.311
X-Spam-Level:
X-Spam-Status: No, score=-4.311 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kRehBTK-d5B7; Thu, 17 Dec 2015 05:54:23 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 42F821B2DD4; Thu, 17 Dec 2015 05:54:23 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mercury.scss.tcd.ie (Postfix) with ESMTP id D94D2BEA4; Thu, 17 Dec 2015 13:54:21 +0000 (GMT)
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from mercury.scss.tcd.ie ([127.0.0.1]) by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OEv7RskA_KJt; Thu, 17 Dec 2015 13:54:20 +0000 (GMT)
Received: from [10.87.48.95] (unknown [86.46.31.96]) by mercury.scss.tcd.ie (Postfix) with ESMTPSA id EED22BE9C; Thu, 17 Dec 2015 13:54:19 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail; t=1450360460; bh=6NyT3zoGk2Fl5NzeCQpnjTN85mFaRtlUMJOjiYokH64=; h=Subject:To:References:Cc:From:Date:In-Reply-To:From; b=PMRs+PJwQ2UoaHgMxxnCua5Y/TeAiGwDsfM6Jt4p5ESkCTu0GhRH81OMhSw/ggLhl BOiM9hd/IuL63vcE9vsZVvBwloL1RBth16NYM7WGkwbPbWvoySOwPOohYxGt3kHOSh mHOdPph5jGHdHoHEksh6GkD4JE9B9W7QZ1b/1Z48=
To: Benoit Claise <bclaise@cisco.com>, The IESG <iesg@ietf.org>
References: <20151217133049.1038.44405.idtracker@ietfa.amsl.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <5672BE86.3090505@cs.tcd.ie>
Date: Thu, 17 Dec 2015 13:54:14 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.4.0
MIME-Version: 1.0
In-Reply-To: <20151217133049.1038.44405.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/bess/8eoxnJnCvswWo6TfrzjONujNS4M>
Cc: draft-ietf-bess-mvpn-extranet@ietf.org, bess@ietf.org, aretana@cisco.com, bess-chairs@ietf.org, martin.vigoureux@alcatel-lucent.com, shares@ndzh.com
Subject: Re: [bess] Benoit Claise's Discuss on draft-ietf-bess-mvpn-extranet-04: (with DISCUSS and COMMENT)
X-BeenThere: bess@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: BGP-Enabled ServiceS working group discussion list <bess.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bess>, <mailto:bess-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bess/>
List-Post: <mailto:bess@ietf.org>
List-Help: <mailto:bess-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bess>, <mailto:bess-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2015 13:54:25 -0000


On 17/12/15 13:30, Benoit Claise wrote:
> 3)      Is security section really a security section? It seems more like
> “do this policy” or this will fail.  It should get a stronger review from
> the security directorate

I've not posted a ballot for this one as my question is more
"What does P really stand for in this kind of VPN?" and I don't
really get what here is new that requires a PS. So any security
discuss would likely be met by "not new, can't change" and is
therefore perhaps not the best use of our time. It'd be better
if we could get some folks to try to re-instate the P == Private
in VPN. (But that is admittedly very hard if one really has to
do multicast.)

S.