Re: [dhcwg] New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

"Bernie Volz (volz)" <volz@cisco.com> Mon, 27 February 2017 20:33 UTC

Return-Path: <volz@cisco.com>
X-Original-To: dhcwg@ietfa.amsl.com
Delivered-To: dhcwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A28DF12A31D for <dhcwg@ietfa.amsl.com>; Mon, 27 Feb 2017 12:33:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level:
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LPu1deWXT_HV for <dhcwg@ietfa.amsl.com>; Mon, 27 Feb 2017 12:33:34 -0800 (PST)
Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62F4412A31B for <dhcwg@ietf.org>; Mon, 27 Feb 2017 12:33:34 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=61928; q=dns/txt; s=iport; t=1488227614; x=1489437214; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=fA9cY+OD0b5FtgHVKO7ala8F12PtZAVohqtpsM9hG9M=; b=Xm8MG2oQjhtoJSh8RKrYKulACpIfjfvR0e1jFKzr8rKMWbK1U+J+vlRn O+FqGbIu3nRnn4VLBRIMwq8xcmF6NnZEYyTgQrk1nCG/EJrlZe6IEyWyb LOTJ24UhAEiXiL518i/qBK6WymRpGD+d1/twl77jVtwyP6v4Mnd+uMn2h A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0C8AQDRjLRY/51dJa1eGQEBAQEBAQEBA?= =?us-ascii?q?QEBBwEBAQEBgm5iYYEJB4NUigiRYYgMjSmCCgMfAQ6FdAIaggk/GAECAQEBAQE?= =?us-ascii?q?BAWIohHABAQECAQEBASEKQQkCBQsCAQYCDgMEAQEhAQYDAgICHwYLFAkIAgQOB?= =?us-ascii?q?QgBEolBAw0IDpMJnViCJoc4DYNoAQEBAQEBAQEBAQEBAQEBAQEBAQEBHYs7glG?= =?us-ascii?q?BYA0kCR+CUIJfBZVthXc6AY4FhBiRIYpKiGYBHziBAVQVPoRPHYFhdQGHXYEvg?= =?us-ascii?q?Q0BAQE?=
X-IronPort-AV: E=Sophos;i="5.35,215,1484006400"; d="scan'208,217";a="391050482"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by alln-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 27 Feb 2017 20:33:33 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id v1RKXXlq017113 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 27 Feb 2017 20:33:33 GMT
Received: from xch-aln-003.cisco.com (173.36.7.13) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Mon, 27 Feb 2017 14:33:32 -0600
Received: from xch-aln-003.cisco.com ([173.36.7.13]) by XCH-ALN-003.cisco.com ([173.36.7.13]) with mapi id 15.00.1210.000; Mon, 27 Feb 2017 14:33:32 -0600
From: "Bernie Volz (volz)" <volz@cisco.com>
To: Ralph Droms <rdroms.ietf@gmail.com>
Thread-Topic: [dhcwg] New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt
Thread-Index: AQHSkTcYLHgVrFA15kCLoS3gsOMP5aF9TAvA
Date: Mon, 27 Feb 2017 20:33:32 +0000
Message-ID: <ce035fef09694414854203da8e55ad8a@XCH-ALN-003.cisco.com>
References: <148455739520.22478.14651605359463322132.idtracker@ietfa.amsl.com> <CAJ3w4NdCk8CBfNagcXT_VW_50+=xK=N7aB5HHqqn3stMt7Gy-Q@mail.gmail.com> <CAJE_bqf_AP9w1Bh_5kSB4YkLaV9XJ1tngufAiOMxVqQLwMruNA@mail.gmail.com> <aba52c11e462426bb3cbf66fcdca7783@XCH15-06-08.nw.nos.boeing.com> <CAJE_bqcG004FuUkKa0Xk1AiOo-bO4aHweYDpxMeeg+_=dSK6FQ@mail.gmail.com> <5c9ed55cfdc94456baf19740ba62910c@XCH15-06-08.nw.nos.boeing.com> <CAJE_bqeshAHmvGukto+PKs_skVPF5bnukvw8+5_04YEx_6m_sQ@mail.gmail.com> <ABDD8B01-EC93-4ADD-AF59-57332A9C255E@fugue.com> <9d9d50b20005459aafffcd8f64bfb281@XCH-ALN-003.cisco.com> <21bd317edc764fc89dc4a13aa541b1c1@XCH15-06-08.nw.nos.boeing.com> <3e5776023c0d447aaccb81dc8ec8724a@XCH-ALN-003.cisco.com> <49129cb6c19c4be3bd483ceb3312bd72@XCH15-06-08.nw.nos.boeing.com> <CAPt1N1nuL8dPWc_o_je9C5YGwVOC-jn412U2Z367RFBrgebO+A@mail.gmail.com> <CAPt1N1kt51wpxwp94RyYGTtgYpWvBs8qxhHp5F0XOML39TRiEw@mail.gmail.com> <CAPt1N1ndGDz2q3ZRpzb1o51QyfzQHEZFNc0w-NmS1-Seak53-g@mail.gmail.com> <5109024ddba44de9a3270e58a4c3270a@XCH15-06-08.nw.nos.boeing.com> <D02D0C01-D483-40C8-B1E1-51862869E8CB@gmail.com>
In-Reply-To: <D02D0C01-D483-40C8-B1E1-51862869E8CB@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.98.1.197]
Content-Type: multipart/alternative; boundary="_000_ce035fef09694414854203da8e55ad8aXCHALN003ciscocom_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dhcwg/7QSOxmbD9FLFobaLT4xDqtd0R1k>
Cc: dhcwg <dhcwg@ietf.org>, Ted Lemon <mellon@fugue.com>
Subject: Re: [dhcwg] New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: <dhcwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcwg/>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Feb 2017 20:33:36 -0000

Hi:

I would think we would start with the current RAAN document (I think we can easily create the XML from the TXT; would have been easier not to have to do that if XML was available).

We haven’t discussed it seriously in the WG yet, and no one has requested time to discuss further at IETF-98 (Chicago). Though of course we can do it here on the ML.

My hope would be that we can restart this work perhaps between Chicago and Prague, as hopefully seDHCPv6 will go to WGLC sometime soon. But of course, seDHCPv6 has been there before and it was in the IESG that it was bounced back to the WG – though hopefully third time will be the charm?

When it is time, I was just planning to do the conversion and resubmit it as the next version of the RAAN document (perhaps with minor edits). I guess though there is the question of whether we should “restart” as an individual submission or whether the WG just agrees to resume work on this document as a WG document. Anyway, we can debate that on the list before publication.

Of course, also need to also check with the co-authors (you and Ole) to see how best to proceed. I had assumed you both would stay on …

At present, the only one really pushing for this to start now is Fred T.


-          Bernie

From: Ralph Droms [mailto:rdroms.ietf@gmail.com]
Sent: Monday, February 27, 2017 3:22 PM
To: Bernie Volz (volz) <volz@cisco.com>;
Cc: Ted Lemon <mellon@fugue.com>;; dhcwg <dhcwg@ietf.org>;; 神明達哉 <jinmei@wide.ad.jp>;; Templin, Fred L <Fred.L.Templin@boeing.com>;
Subject: Re: [dhcwg] New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

Bernie - a long time ago, if I recall correctly, you asked me if I had XML source for the earlier RAAN document.  I searched around, but can't seem to find that file.  Is the text in that earlier doc at all useful for this instantiation of RAAN?

- Ralph

On Feb 27, 2017, at 3:17 PM, Templin, Fred L <Fred.L.Templin@boeing.com<mailto:Fred.L.Templin@boeing.com>> wrote:

Hi Ted,

Just getting back to this after being away for the past week:

>  Fred, I think we all agree that this problem needs to be solved.

I still think it would be cleanest and most consistent with past works if the base
sedhcpv6 specification were to include the RAAN option itself. But, if that would
not be possible and if (as you say) there is agreement that this problem needs
to be solved, then we should adopt the RAAN draft as a dhcwg working group
item now.

>  We don't agree that work on the security draft must stop until the raan draft is done.

I never said or meant to imply that the security draft must stop until RAAN is done.
To the contrary, the two documents could run in parallel with both being dhcwg WG
items now and with no interdependencies. By adopting RAAN as a WG item now,
implementers would be more likely to implement RAAN in parallel with sedhcpv6
rather than defer it to some (much) later time.

>  It's just not that hard.

Definitely agree.

Thanks - Fred

From: Ted Lemon [mailto:mellon@fugue.com]
Sent: Saturday, February 18, 2017 9:17 AM
To: Templin, Fred L <Fred.L.Templin@boeing.com<mailto:Fred.L.Templin@boeing.com>>
Cc: dhcwg <dhcwg@ietf.org<mailto:dhcwg@ietf.org>>; 神明達哉 <jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>>; Bernie Volz (volz) <volz@cisco.com<mailto:volz@cisco.com>>
Subject: RE: [dhcwg] Fwd: New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

Fred, I think we all agree that this problem needs to be solved. We don't agree that work on the security draft must stop until the raan draft is done. It's just not that hard.

On Feb 18, 2017 11:28 AM, "Templin, Fred L" <Fred.L.Templin@boeing.com<mailto:Fred.L.Templin@boeing.com>> wrote:
Hi Bernie,

My understanding  is that sedhcpv6 is intended to be a product of the IETF,
so I therefore assume that it is intended to be a product of engineering. It
has been shown that sedhcpv6 has an omission that will limit its applicability,
and that that omission can be rather easily remedied prior to publication. It
therefore makes good engineering sense to fix the omission now.

The proposal again is to have sedhcpv6 specify the RAAN option as part of
the base document.

Thanks - Fred

From: Bernie Volz (volz) [mailto:volz@cisco.com<mailto:volz@cisco.com>]
Sent: Friday, February 17, 2017 3:00 PM
To: Templin, Fred L <Fred.L.Templin@boeing.com<mailto:Fred.L.Templin@boeing.com>>; Ted Lemon <mellon@fugue.com<mailto:mellon@fugue.com>>;神明達哉 <jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>>

Cc: dhcwg <dhcwg@ietf.org<mailto:dhcwg@ietf.org>>
Subject: RE: [dhcwg] Fwd: New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

I think the plan here makes some sense … seDHCPv6 has had several attempts and been kicked back to the WG. So, I think the WG wants to go slowly and not develop a solution until seDHCPv6 is likely to advance in the IESG (encryption was only added fairly “recently”).

And, it isn’t like the day after seDHCPv6 is “approved” that every client (and server) will support this. It will take time to roll out. And, hopefully we can get the RAAN work out in a fairly short time.

In your networks, if you can’t support seDHCPv6 until you have something to so solve the RAAN issues, you obviously can’t deploy seDHCPv6. But there may be plenty of other networks where this isn’t an issue and it could start to be deployed (coffee shops and enterprises).


-          Bernie

From: Templin, Fred L [mailto:Fred.L.Templin@boeing.com]
Sent: Friday, February 17, 2017 5:35 PM
To: Bernie Volz (volz) <volz@cisco.com<mailto:volz@cisco.com>>; Ted Lemon <mellon@fugue.com<mailto:mellon@fugue.com>>; 神明達哉<jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>>
Cc: dhcwg <dhcwg@ietf.org<mailto:dhcwg@ietf.org>>
Subject: RE: [dhcwg] Fwd: New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

Bernie,

The discussion gravitated towards not resurrecting until the sedhcpv6
I-D progresses further. We will reevaluate this once sedhcpv6 is done.

This does not make sense to me; sedhcpv6 is the very reason that RAAN is important.
Just like RFC3971 did with IPv6 ND Timestamp and Nonce options, sedhcpv6 could
define the RAAN operation and have everything over and done with in one pass.
And, I have already identified a use case where RAAN is absolutely necessary.
Also, I was unable to attend  IETF97, where I certainly would have stood up and
voiced my position.

Thanks - Fred

From: dhcwg [mailto:dhcwg-bounces@ietf.org] On Behalf Of Bernie Volz (volz)
Sent: Thursday, February 16, 2017 2:39 PM
To: Ted Lemon <mellon@fugue.com<mailto:mellon@fugue.com>>; 神明達哉 <jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>>
Cc: dhcwg <dhcwg@ietf.org<mailto:dhcwg@ietf.org>>
Subject: Re: [dhcwg] Fwd: New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

I presented about resurrecting draft-ietf-dhc-dhcpv6-agentopt-delegate at IETF-97 (seehttps://www.ietf.org/proceedings/97/slides/slides-97-dhc-resurrect-draft-ietf-dhc-dhcpv6-agentopt-delegate-00.pdf).

And the conclusion then was (see https://www.ietf.org/proceedings/97/minutes/minutes-97-dhc-00.txt):

The discussion gravitated towards not resurrecting until the sedhcpv6
I-D progresses further. We will reevaluate this once sedhcpv6 is done.


-          Bernie

From: dhcwg [mailto:dhcwg-bounces@ietf.org] On Behalf Of Ted Lemon
Sent: Wednesday, February 15, 2017 1:49 PM
To: 神明達哉 <jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>>
Cc: dhcwg <dhcwg@ietf.org<mailto:dhcwg@ietf.org>>
Subject: Re: [dhcwg] Fwd: New Version Notification for draft-ietf-dhc-sedhcpv6-20.txt

On Feb 15, 2017, at 1:32 PM, 神明達哉 <jinmei@wide.ad.jp<mailto:jinmei@wide.ad.jp>> wrote:
I personally don't think it a blocking issue for sedhcpv6, but, of
course, the wg should decide it.

It definitely isn't a blocking issue, but Fred is right that if we are going ahead with encryption-only, which I agree is the right move, we need to do this work as well.


_______________________________________________
dhcwg mailing list
dhcwg@ietf.org<mailto:dhcwg@ietf.org>
https://www.ietf.org/mailman/listinfo/dhcwg