[Dhcpv6bis] Security / Privacy Considerations for draft-ietf-dhc-rfc3315bis

"Bernie Volz (volz)" <volz@cisco.com> Wed, 09 August 2017 19:36 UTC

Return-Path: <volz@cisco.com>
X-Original-To: dhcpv6bis@ietfa.amsl.com
Delivered-To: dhcpv6bis@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB917132489 for <dhcpv6bis@ietfa.amsl.com>; Wed, 9 Aug 2017 12:36:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.52
X-Spam-Level:
X-Spam-Status: No, score=-14.52 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W9S4nQcvvRm0 for <dhcpv6bis@ietfa.amsl.com>; Wed, 9 Aug 2017 12:36:26 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DC931324A3 for <dhcpv6bis@ietf.org>; Wed, 9 Aug 2017 12:36:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=14366; q=dns/txt; s=iport; t=1502307386; x=1503516986; h=from:to:subject:date:message-id:mime-version; bh=32pRfiabeYYEailYCzw0HLIksSd+ESU7hceXIMjHYi4=; b=m+o/BrKExNBeWr587090dtTZMNK2bBU2QH9MeT/HO6sBMssPIBL53BvJ EvHxxy6ACofcZywaQ7b4SKPQa44nqy/W9SgdOkNzZCfKwz4ex2QZygG4D ehied4PNCrfxY6FOyCDv1lS/yhe/PAZvIksQzz/ghACW7HouFIj0ftvaS Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AmAAAXY4tZ/51dJa1ZAxkBAQEBAQEBAQEBAQcBAQEBAYJvAWpkgRQHhFqJLpAGhReNOYUzgSoFYwcphEhPHIRkPxgBAgEBAQEBAQFrKIUdAiMKOSEEATQWAgQZFyQCAQQTCIlDZBCuFIImi2YBAQEBAQEBAQEBAQEBAQEBAQEBAQ8KBQWDI4ICgy+GJyaBBTkmCiaCDz2CYQWKZ4ZcjlQCh1GHI4U3ghgbhUKKZZYKAR84TD53FYMYg3xPdgGJBwGBDgEBAQ
X-IronPort-AV: E=Sophos;i="5.41,349,1498521600"; d="scan'208,217";a="278808215"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Aug 2017 19:36:25 +0000
Received: from XCH-RCD-004.cisco.com (xch-rcd-004.cisco.com [173.37.102.14]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id v79JaPB5011426 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dhcpv6bis@ietf.org>; Wed, 9 Aug 2017 19:36:25 GMT
Received: from xch-aln-003.cisco.com (173.36.7.13) by XCH-RCD-004.cisco.com (173.37.102.14) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Wed, 9 Aug 2017 14:36:24 -0500
Received: from xch-aln-003.cisco.com ([173.36.7.13]) by XCH-ALN-003.cisco.com ([173.36.7.13]) with mapi id 15.00.1210.000; Wed, 9 Aug 2017 14:36:24 -0500
From: "Bernie Volz (volz)" <volz@cisco.com>
To: "'dhcpv6bis@ietf.org'" <dhcpv6bis@ietf.org>
Thread-Topic: Security / Privacy Considerations for draft-ietf-dhc-rfc3315bis
Thread-Index: AdMRRggprtY+yKy3RsqMREz6Q/gSsQAALnZA
Date: Wed, 09 Aug 2017 19:36:24 +0000
Message-ID: <fdb3cc5859474cbb973758f00e073290@XCH-ALN-003.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [161.44.67.114]
Content-Type: multipart/alternative; boundary="_000_fdb3cc5859474cbb973758f00e073290XCHALN003ciscocom_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dhcpv6bis/Q87FhnHPoJ6s8uJi1VLSLTv1MZY>
Subject: [Dhcpv6bis] Security / Privacy Considerations for draft-ietf-dhc-rfc3315bis
X-BeenThere: dhcpv6bis@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "DHCPv6 \(RFC3315\) bis discussion list" <dhcpv6bis.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcpv6bis>, <mailto:dhcpv6bis-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcpv6bis/>
List-Post: <mailto:dhcpv6bis@ietf.org>
List-Help: <mailto:dhcpv6bis-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcpv6bis>, <mailto:dhcpv6bis-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Aug 2017 19:36:29 -0000

Hi:

This meeting is to discuss the Security/Privacy Considerations for draft-ietf-dhc-rfc3315bis so we can publish the -10 which:

1.      Removes reference to draft-ietf-dhc-sedhcpv6
2.      Provides sufficient discussion of why something like sedhcpv6 isn't needed (to head off the question from the IESG about why DHCPv6 has no security)

I have drafted an initial proposal at https://docs.google.com/document/d/1sIH0vbaM26zEuOlneTFSB_0TOK56pZKVLlA1R-KelLQ/edit which you should review and definitely feel free to work to improve - I'm not that happy with it as is (new text is mostly at the end). Is there enough there? Should it be organized differently? ...

PLEASE RSVP SO WE CAN MAKE SURE THERE IS SUFFICIENT QUORUM. If you can't make it, please suggest alternative dates/times.

-       Bernie


-- Do not delete or change any of the following text. --


Join me now in my Personal Room.

Join WebEx meeting
https://cisco.webex.com/join/volz   |  207 497 612

Join from a video conferencing system or application
Dial volz@cisco.webex.com<sip:volz@cisco.webex.com>
>From the Cisco internal network, dial *267* and the 9-digit meeting number. If you are the host, enter your PIN when prompted.
If you are the host, you can also enter your host PIN in your video conferencing system or application to start the meeting.

Join by phone
+1-408-525-6800 Call-in toll number (US/Canada)
+1-866-432-9903 Call-in toll-free number (US/Canada)
Access code: 207 497 612
Global call-in numbers<https://cisco.webex.com/cmp3200/webcomponents/widget/globalcallin/globalcallin.do?siteurl=cisco&serviceType=MC&ED=303966212&tollFree=1>  |  Toll-free calling restrictions<https://www.webex.com/pdf/tollfree_restrictions.pdf>

Can't join the meeting? Contact support.<https://cisco.webex.com/mc>

IMPORTANT NOTICE: Please note that this WebEx service allows audio and other information sent during the session to be recorded, which may be discoverable in a legal matter. By joining this session, you automatically consent to such recordings. If you do not consent to being recorded, discuss your concerns with the host or do not join the session.