Re: [Detnet] DetNet Security Draft - IP Data Plane Specific section

"Andrew G. Malis" <agmalis@gmail.com> Tue, 02 July 2019 11:20 UTC

Return-Path: <agmalis@gmail.com>
X-Original-To: detnet@ietfa.amsl.com
Delivered-To: detnet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC51812006F for <detnet@ietfa.amsl.com>; Tue, 2 Jul 2019 04:20:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BWCPiwNZk8A9 for <detnet@ietfa.amsl.com>; Tue, 2 Jul 2019 04:20:32 -0700 (PDT)
Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 461FF120045 for <detnet@ietf.org>; Tue, 2 Jul 2019 04:20:32 -0700 (PDT)
Received: by mail-qt1-x830.google.com with SMTP id h24so14936038qto.0 for <detnet@ietf.org>; Tue, 02 Jul 2019 04:20:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=eF3xckUis4llzjxP5P80hkjBpvt5XBGXolGZ3RW2QTo=; b=bYFqOBWETl569TRNcRlhm/t+Mo3AV4AIR6xfkgVMGS87DfcsVM+1D4X0QfPxRcD0DT AZuevCy5lzNCHs45rWkY9/9ehq4iZSmRiJjB4o9iSyTqWnYuWgUrnSMPl6T+BxCYBlz0 SAWLyS9GAyZR5JaQW9eVBNxUEHXF72ngXfZROP8idiAu5jQXDDY+OR1kuZAeufN3ScJq inT/9kGAfpGwjBYBddCiTngJjYX4dvAfMe0Lbeegr8/GLwnpk9KDj06xFLU4FAr+Io/B 8QxH3WpzH+vNXzJQYhsPXzN7ZmRE0uspevDcm5SwWZ+hxJysEarBy42KCXfyDg0N9bve ysHg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=eF3xckUis4llzjxP5P80hkjBpvt5XBGXolGZ3RW2QTo=; b=TcDwS4yahv0ZHGilOkaGZ+Uvt2NN/1Li7kjGgAK78A9XOImwwIV52f149magVdIdXC IQ6RuMnJ7Phua0C4xDqQTU/HQA4nUGtBvlWaCd0o7jBUsMCfz5PvIvvRMb1nkU3alsZ1 LAWdL8Td6u3dgTM0JSB09Khw6Kx51TZ7NDyGD2RRyH+259xWQ7e9l2njzPOXT+MFkKuy vQOvQUXedQeGvv3A3vfZQ7sSU5UeJNZw49+I8uPnoRPD1lLN0AQwp9k34G5HoKoXd1dR WTSEJu55GKj/WicXyh4F45+kQ9fQ6sZwVXy1ftCP1X9P3K+pevCk7pmdzpNp4gJpWguE Lsag==
X-Gm-Message-State: APjAAAX/35NilA61NNlalH2bEuvOD+vocWy+x9smEQgrT9m/ph/fvOBz zrxrW0r4pcHx4pHu81MG+4BXIa9wkKSyux8v/9EBpw==
X-Google-Smtp-Source: APXvYqzUw70IAHMW9n5xUZot3Co4uwHsk5lH+GqB6dCCnfWhDJN9BrmUUAVfSxFV7Ji386V/LKmrawA4BAnIOBd3As8=
X-Received: by 2002:ac8:3742:: with SMTP id p2mr24093818qtb.121.1562066431387; Tue, 02 Jul 2019 04:20:31 -0700 (PDT)
MIME-Version: 1.0
References: <BYAPR06MB432520A4456F5D35E0B34128C4F80@BYAPR06MB4325.namprd06.prod.outlook.com>
In-Reply-To: <BYAPR06MB432520A4456F5D35E0B34128C4F80@BYAPR06MB4325.namprd06.prod.outlook.com>
From: "Andrew G. Malis" <agmalis@gmail.com>
Date: Tue, 02 Jul 2019 07:20:20 -0400
Message-ID: <CAA=duU3K6Da3OZDjok9r+8rj3o_HK8fgn2h+KO3gwJ8NXOycwg@mail.gmail.com>
To: "Grossman, Ethan A." <eagros@dolby.com>
Cc: detnet WG <detnet@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c22bf8058cb0ee1e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/detnet/q-rdUe6COYOtNKfc8h1PQktSCNk>
Subject: Re: [Detnet] DetNet Security Draft - IP Data Plane Specific section
X-BeenThere: detnet@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions on Deterministic Networking BoF and Proposed WG <detnet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/detnet>, <mailto:detnet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/detnet/>
List-Post: <mailto:detnet@ietf.org>
List-Help: <mailto:detnet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/detnet>, <mailto:detnet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Jul 2019 11:20:35 -0000

Ethan,

That's certainly good as initial text for the section. As far as a SECDIR
review, I'm sure that our WG chars will be asking the SECDIR for an early
review of the entire document before it goes to WG last call. At least that
what I would do in their place. :-)

Cheers,
Andy


On Tue, Jul 2, 2019 at 2:02 AM Grossman, Ethan A. <eagros@dolby.com> wrote:

> Hi All,
>
> I am having difficulty getting a contribution for our proposed “last
> remaining” section of the DetNet Security draft, which is the “IP Data
> Plane Specific” section.  Could it be that there is nothing to say? What if
> I said the following – who would we need to have review this statement to
> poke some holes in it? I mean, that is essentially the text I’m looking
> for, should it actually exist.
>
>
>
> Proposed text for “IP Data Plane Considerations for DetNet” section:
>
>
>
> “The IP protocol has a long history of security considerations and
> mitigations, and its use as a DetNet Data Plane introduces no new security
> issues that were not there before (apart from those already described in
> the data-plane-independent section of this document).
>
>
>
> Thus the security considerations for a DetNet based on an IP data plane
> are purely inherited from the rich IP Security literature and
> code/application base, and the data-plane-independent section of this
> document”.
>
>
>
> Is that good? Should we ask for a review from the SECDIR for this
> statement?
>
>
>
> Ethan (as Editor, DetNet Security draft).
> _______________________________________________
> detnet mailing list
> detnet@ietf.org
> https://www.ietf.org/mailman/listinfo/detnet
>