Re: [Detnet] Secdir last call review of draft-ietf-detnet-pof-06

Balázs Varga A <balazs.a.varga@ericsson.com> Tue, 12 December 2023 08:23 UTC

Return-Path: <balazs.a.varga@ericsson.com>
X-Original-To: detnet@ietfa.amsl.com
Delivered-To: detnet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 48066C40398D; Tue, 12 Dec 2023 00:23:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 55V_JQsT8l1R; Tue, 12 Dec 2023 00:23:35 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2069.outbound.protection.outlook.com [40.107.20.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0EBA9C40397B; Tue, 12 Dec 2023 00:23:34 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=fhrQV3XGZ2vD557EtJHjDiRKLGY72nhOhLYLDBuAbhwcclE10Vb0T85ewrydnWAUs4qLnFJI04Sb+kZkdCj+o78vbaiSHujl1Z/rm2Gw/HwvgzEL+mmZRGfBxnF/DFtXWSpVEnosh8lUkqNyMZuMve044tMexeUKCe+ANhB15CdBQwqxwmtI35BKtDOaFD7Goh5/xjAORsWXLpem0xEdgYz5IADq/jbqzI5OEo1Ha5mWc+GyfJtOSZhOxaaQ4dLMPVKJRar6uy14RUeVZ10ZGpKz114zWDNe200uW3cYSCC6NTAWG95FXxGUB8UPNC7P+bffKqKPPfoK5OZey3AuZw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=K1rzowW9zq0DdjVYhcspx3nIxWKQQOqkLUHBKCG8dcg=; b=XD+NyT6i1ptOxkATXN6D8oJ9OcEZkfoI448R2HG1skW+qlNazTsfIAwR4F1HFJSh/XxIkhn3fBXCxiFDJdMm6gJxsb4ZXB8tM7zh6k0xx/BDaepIBnElvY2wTVpGmmBuUIcBJg+rxsN2kpZDmhY1UfWQ2FYRTchk+h2SFvdinR7SZ7S1J6M4F/k3sKWh82oMgLmFVAC/c8pkJsONs0D3zqKcgWQenm57V9uPW9m6fsiVaiPskQ44s+uFX+zxrYd+FPu5XD0hqLFDi9ZZQuiYQ6vI4Fjj8AFYx15b3HnwTSg8Nq6NIJ0psIMI+OVd04vbrpYH9BXNYxqzk9M5gBwgnA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=K1rzowW9zq0DdjVYhcspx3nIxWKQQOqkLUHBKCG8dcg=; b=Gbo0HW392U3kgHDjpxzEaonFn7IH68F+ERLK88VFI0g0oakNoUINxhlsKsoB7I12nQNVEPKq1vPxm3emxiQP9AA5hv3ss38lQy6uFAnvk9e0jlNlt/xaoGi1uUaxT/4Tkc3MgioO5KTps7OoZsXQfPAUqlsmMYoi+LJjEF+xFWAgS2UB345ttBALjIrxnz15683VoH1Rue17FKamGilhjoHFW71B03xxLEPcTc6QcbQvD3BrCmnpBiZJlfIvu7MgZ2hMAXRh/abCJsepKrRq7z/WI0B6fKcLFCprzr8AyUDqnJppRFLSUSYzq+nho+rt4a6rW5Wp/m4aJXYtNF4SQg==
Received: from AM0PR07MB5347.eurprd07.prod.outlook.com (2603:10a6:208:e7::31) by AS2PR07MB9502.eurprd07.prod.outlook.com (2603:10a6:20b:649::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7068.33; Tue, 12 Dec 2023 08:23:32 +0000
Received: from AM0PR07MB5347.eurprd07.prod.outlook.com ([fe80::a62d:d09d:94ab:2a3d]) by AM0PR07MB5347.eurprd07.prod.outlook.com ([fe80::a62d:d09d:94ab:2a3d%5]) with mapi id 15.20.7068.033; Tue, 12 Dec 2023 08:23:32 +0000
From: Balázs Varga A <balazs.a.varga@ericsson.com>
To: Scott Kelly <scott@hyperthought.com>, "secdir@ietf.org" <secdir@ietf.org>
CC: "detnet@ietf.org" <detnet@ietf.org>, "draft-ietf-detnet-pof.all@ietf.org" <draft-ietf-detnet-pof.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-detnet-pof-06
Thread-Index: AQHaLIeHADFPWYytoEW35e80m2uH4rClTpQA
Date: Tue, 12 Dec 2023 08:23:32 +0000
Message-ID: <AM0PR07MB5347989E7B9BF57ED6D5F484AC8EA@AM0PR07MB5347.eurprd07.prod.outlook.com>
References: <170233634062.42112.4492248784717977119@ietfa.amsl.com>
In-Reply-To: <170233634062.42112.4492248784717977119@ietfa.amsl.com>
Accept-Language: hu-HU, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AM0PR07MB5347:EE_|AS2PR07MB9502:EE_
x-ms-office365-filtering-correlation-id: d4b8bd46-690b-4d1a-86f1-08dbfaeba0bd
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: nyF46p2L6X222rBYGXZTIRIdGC1lpeNfl38FtN2pq02UXUb9ahYQSC6r971TgsLMAzVRcNFXjPQ8mI/AvunVo9Ixob10DNXh3H+tYTaVqLip13lyNEnkEfjajEPIqVLuVugM0KnIR8PnDNZAzPhXmSAIYpyUkX3l7dIOsPqYR3xDqC80ibY0+Qy+Gy+ZJiSDxOzVuGOINGSEzLE2TVkqYmA5xcQFj8Us9OmZXvfqX3JDVdnEmT4hHmG+/LEG69vHFz+OAXzIbaIhwrcr23YlYugHYhQSB2kko93sQ57Y2KLBqSdp0SDHnszzqSbos/gTnmmgxaXiJPUcpEENwbeg80iHJOfjD/chmPrxpHmr/X9eboxOfVFduhv5O8YAPORISeecwJAgXV9b6+USnzD8XvR0bBJxqlaDvS0pm572hy0Yb/JWAlet/dQcIwPBVlOKqoHyK3infVqENVoYTVuai/VUoifJb2WbR9k2u8mW+6LiXLjgA4bdTVYw78/utqBvpTSIRU4rLRLYrH07fah6OGzeTii4dxFJGqVhVleDINCQwMPU87G381tMUmJFFnSZCI57E9nrMNpiXa0cUKKtgYCrmLtAyy1yYhiJdnP55LgSdehRZnYRfo/dSMbkMg3Gp1RhvT1is/IrRtzn9DYpnTKhJB9e6uZBI/dh7l9jvWU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM0PR07MB5347.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(396003)(39860400002)(136003)(346002)(376002)(366004)(230922051799003)(451199024)(186009)(64100799003)(1800799012)(478600001)(83380400001)(9686003)(26005)(122000001)(38100700002)(4326008)(8676002)(8936002)(52536014)(316002)(2906002)(5660300002)(6506007)(7696005)(41300700001)(71200400001)(53546011)(110136005)(54906003)(66446008)(66476007)(66556008)(66946007)(76116006)(64756008)(85202003)(85182001)(82960400001)(33656002)(86362001)(38070700009)(55016003); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: xJutriLDLGSK9DxmJRMxU4S7pwBiFPOt+dgT7pxhzBrRN1u45x5PKN247XSsyctqF1iS9Lm+CvW8t8soLobiwKzQ5WZRJCWACHRQS67DYht3sgKkMCxSivaltlFO9DsiHRH6Vj6+xoJ8TqGrDWXyAdE3i9S3ExhbUi4n2LAIxt71fPhvbcehI6d5n9DsE0PIP5RpiYKebZKrzP8W3foWvC1rfLiwIeqNx8b2rxmpW2xtdpWRo31P1UaoptQXLCRzOHv3SRiSMowAyI/yeouIfEM59kUevBESpbNDberthEG/Ky/mm/o1O3FIYO7oqP4GWsvOeahshh+/8wnUwCgou3vKicwaPdUngn5B9UC7cQyRKB7PmJLuzsKAXug07L8V+R9KsoFlrU+/5ypLfjOPKiwHHXB7QwhujJTEyKmiIQ2dYiRNuhUCUDpq3XC3YKUYAzUACGo9QyS1FZtS/U7hXrF1yr9dcauG7DR9nuaHSHI3moeN//pqXuqLR5tyaeU9GYNedlOd7hQqwBa0iaUCcV6LwNuJBY0WlLi53VCgdcw+e3fiq8l+pzYMDPJtQ+tIzKYKGR5YeKNNnM1f7CfhMj0naHEI4Quah6fsp67oEOYhilkfYB3/sGvC1cWdwv7eMxEpevY6fGE9cPpaxBhQl1V3EevJukIz5kXQPeIdTRwvaKEjcBeaju+4LqMu7jBzEmVfQyl/oiS2QK2dKJqE+4foXLkisT/s3YK1gv3vSAnMts3CFwT8JhhZ3pA4cVkj2hTfRMt1hRqVtYUvQ8LF07kd7TUW+ZLM9BpzCZlnyF+jypkkc8PSqtbU/1OU9gzvYXfiuB1ghRXhbSRFKobVvUUwBSnMLzb8wd4s8w99AAmhTidBU3Dz6AXPRUF69I+f9lU3zNzvdRZmDaDRsmIOzyZrdtiW7783NZSEscwkFo0ZM0Bk9vHVPqfxSbPvMlhP50ANrH4f1h55khGLw0aoSJuaJ1V3+d6KH8JxOEc9PNmkECmf7gyfTyrnAD8qn1A4ZZomjyh8rMAlyk5NOXB4EQmi9ih4i/aEd8ilPEmPwssJ9taYke0IuVojHYa3nN978QmeEA8tjPpd5A61zLwpgJyYfwc1Sgp5RW2D6d8hIo+Of5WE5cLSTpfkypw3yn3KX0Lz44/nmoIWfy84bzlWcRUy11b23RGoYtPN9IQ2vjBDMYbqE7mgFZx9dPubLRVpzPnBgnq/4f+rmw9Gq+Vnsjzqn2WOWxmm6RCmbqgT2te1ZozUg/P8a0L6WUjNmL6ldnSpKZmruOn/XduwBY6mNr2oDDs+wCLh5R9+rlvA3Bigh2aIoUakOF3terAulJpc6vsQtWE2jO4mvLnNrGDFIpPGeEljypkc9WKzW7I/N0dvv6UFKdARI8B1xaTG5OHJ4x3OBgVSiI/3kW92iHNdJqnT86vvY21tElymQ0yZ/oQRktLGljwsVeczUL8snG00gF4oWcggdN2jH7R4537VFfS7xYUvAq5K/M10IGv+1rgUJiq/11xpAwlpH5uVMwM3Z8PJaj57+17cToq8EtDGQGgyg9NDtmRVXcnXr7NcJOzsPoGmU/GtLH5Q8SsV7iYdqBLOsqetuzjuUtyFfZ7jOg==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AM0PR07MB5347.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d4b8bd46-690b-4d1a-86f1-08dbfaeba0bd
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Dec 2023 08:23:32.3741 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 7DKZlrAyegrFx2XzFkr2yB3uFXdcKUPp2nt5i1MqImVFZlyTpDKPxnOzq+UwWO/3YCxRdc/cZhrpvapJ2aidyu/B6b1fXlAIwcqUBfbZcqw=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS2PR07MB9502
Archived-At: <https://mailarchive.ietf.org/arch/msg/detnet/sToDP8J-w0ZhC3uefD1tGNebrJc>
Subject: Re: [Detnet] Secdir last call review of draft-ietf-detnet-pof-06
X-BeenThere: detnet@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussions on Deterministic Networking BoF and Proposed WG <detnet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/detnet>, <mailto:detnet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/detnet/>
List-Post: <mailto:detnet@ietf.org>
List-Help: <mailto:detnet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/detnet>, <mailto:detnet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 12 Dec 2023 08:23:39 -0000

Hi Scott,
Many thanks for the feedback. Just in time, 
draft is on agenda for telechat - 2024-01-04. :--))))
Cheers
Bala'zs

-----Original Message-----
From: Scott Kelly via Datatracker <noreply@ietf.org> 
Sent: Tuesday, December 12, 2023 12:12 AM
To: secdir@ietf.org
Cc: detnet@ietf.org; draft-ietf-detnet-pof.all@ietf.org; last-call@ietf.org
Subject: Secdir last call review of draft-ietf-detnet-pof-06

Reviewer: Scott Kelly
Review result: Ready

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments.

I'm sorry this review is a few weeks late -- I hope it is still useful.

The summary of the review is ready.

RFC8655 describes Deterministic Networking (DetNet) Architecture. The document under review covers a specific aspect of DetNet: the packet ordering function.
From the document abstract,

   The Packet Ordering Function (POF)
   algorithm described herein enables to restore the correct packet
   order when replication and elimination functions are used in DetNet
   networks.

Here is the security considerations section in its entirety:

   PREOF related security considerations (including POF) are described
   in section 3.3 of [RFC9055].  There are no additional POF related
   security considerations originating from this document.

I believe that RFC9055 (Deterministic Networking (DetNet) Security
Considerations) does indeed cover all relevant security considerations. I see no security issues with this draft.