Re: [dhcwg] Alissa Cooper's No Objection on draft-ietf-dhc-dhcp4o6-saddr-opt-06: (with COMMENT)

<ian.farrer@telekom.de> Fri, 12 October 2018 07:19 UTC

Return-Path: <ian.farrer@telekom.de>
X-Original-To: dhcwg@ietfa.amsl.com
Delivered-To: dhcwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1EA16130E01; Fri, 12 Oct 2018 00:19:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.756
X-Spam-Level:
X-Spam-Status: No, score=-4.756 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.456, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=telekom.de
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jAksGK_uwO5L; Fri, 12 Oct 2018 00:19:32 -0700 (PDT)
Received: from mailout23.telekom.de (MAILOUT23.telekom.de [80.149.113.253]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 675AD130DFD; Fri, 12 Oct 2018 00:19:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telekom.de; i=@telekom.de; q=dns/txt; s=dtag1; t=1539328772; x=1570864772; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=2R3wmUdZknT3zPQx2S8QD2U5+cHEyGXVrL1+iRu/fPc=; b=RqyEeMxZhJfj7jeOlUfCc5um1ED3B8QgaX+Q5bHntPFHhhPGj19+iG6c GqxR39QiurBy0iFPZ40b5jmKcbxATCPgCEYh7vPaUGCG/NpjCRLf6zVfd IGIaHqEWg431tWGAddQY3OJj2S8AIIEZcbK+oNbd9VkEsGCkeLzVLeRQP pyu9zoVwpJfxVoEZ5WsJucq9K5LJI+9fCYaK2TigutUPxuBH1gAKWDU34 znwlR96Njbt01JCIQPvQvGf3R1j35jscuul+16on6Oars4jesLSo0xcIZ sc3joBAI842IAvWXM4dzvNhemtK3294av8j92QeRMCzLOdFvln/SzpbHs Q==;
Received: from qdec94.de.t-internal.com ([10.171.255.41]) by MAILOUT21.telekom.de with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 12 Oct 2018 09:19:30 +0200
X-IronPort-AV: E=Sophos;i="5.54,371,1534802400"; d="scan'208";a="271895227"
Received: from he105704.emea1.cds.t-internal.com ([10.169.119.21]) by QDEC97.de.t-internal.com with ESMTP/TLS/AES256-SHA; 12 Oct 2018 09:19:30 +0200
Received: from HE105700.EMEA1.cds.t-internal.com (10.169.119.29) by HE105704.emea1.cds.t-internal.com (10.169.119.21) with Microsoft SMTP Server (TLS) id 15.0.1395.4; Fri, 12 Oct 2018 09:19:30 +0200
Received: from HE104163.emea1.cds.t-internal.com (10.171.40.38) by HE105700.EMEA1.cds.t-internal.com (10.169.119.29) with Microsoft SMTP Server (TLS) id 15.0.1395.4 via Frontend Transport; Fri, 12 Oct 2018 09:19:30 +0200
Received: from GER01-LEJ-obe.outbound.protection.outlook.de (51.5.80.18) by O365mail05.telekom.de (172.30.0.230) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Fri, 12 Oct 2018 09:19:39 +0200
Received: from FRXPR01MB0661.DEUPRD01.PROD.OUTLOOK.DE (10.158.154.13) by FRXPR01MB0664.DEUPRD01.PROD.OUTLOOK.DE (10.158.154.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1207.27; Fri, 12 Oct 2018 07:19:27 +0000
Received: from FRXPR01MB0661.DEUPRD01.PROD.OUTLOOK.DE ([fe80::6de4:4cd2:cebf:df95]) by FRXPR01MB0661.DEUPRD01.PROD.OUTLOOK.DE ([fe80::6de4:4cd2:cebf:df95%3]) with mapi id 15.20.1207.029; Fri, 12 Oct 2018 07:19:27 +0000
From: ian.farrer@telekom.de
To: alissa@cooperw.in, iesg@ietf.org
CC: draft-ietf-dhc-dhcp4o6-saddr-opt@ietf.org, volz@cisco.com, dhcwg@ietf.org, dhc-chairs@ietf.org
Thread-Topic: [dhcwg] Alissa Cooper's No Objection on draft-ietf-dhc-dhcp4o6-saddr-opt-06: (with COMMENT)
Thread-Index: AQHUYMz+ETYUKE8i2U2d+SvnbJcEGaUaPKIA
Date: Fri, 12 Oct 2018 07:19:26 +0000
Message-ID: <90D965D8-B309-4D49-9122-913DC7AAC542@telekom.de>
References: <153919863828.5844.16938481415371228690.idtracker@ietfa.amsl.com>
In-Reply-To: <153919863828.5844.16938481415371228690.idtracker@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.10.2.180910
authentication-results: spf=none (sender IP is ) smtp.mailfrom=ian.farrer@telekom.de;
x-originating-ip: [2003:1c09:21:c20:cdd4:4e11:5e13:7295]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; FRXPR01MB0664; 6:QuKCdZTnCStwoSDgBkYhneIX8nd3HLx0L1jXLEt7Pg6wyGNfaLnJ2qdlrLl4RpseBtHxNhPcfn/mtSs1rqyBrWMiWLcHa/rZwNQ4MtPG4o9DqSSUysjoVR7rifrF9lzJDDTc6gFqk304Pa0WJSmkdMdhNEnCC/cLGOG5P0RrCqjzMZNEuk8WqsYIMFhDXXmHT0o6q54v+0Bs9frTpQsPgsBT7P0u/lrwdd9MVylH26SmSEFsLB9gx+RMo2s6r6d1IDx9bOMrNUdLFFzwzECdhLPAmsJsiCcSCGUOCfpWeXSBkWohgK7vmBmdBYuoMnXSnkd8BjcFmV+MpiE3+1T/CyeaQuPrlfCGvisggLnrF4Arz4fcbOsDQjyb4BxhuaBkc+IsJ+dvIDpTkUwRwQaVCSlYMHSWO89o+oa2DG7wQ2z67eUyz3gpBjWNmw3uxBNhMKgzKdynuvrqxHoy6odRAw==; 5:HVSJz1oi1SN6to2XkTcgcQ084Yyc/lg3VtDv36wU5yElckKVI6e+Lq8KYcVoFFyzS2fQK06PODhSadE9dZBdfdc5oR7q2NU789KSKKJ+/TzTN6xdp73mBVHxQc0lf616ZxPIbt8Twctkb/D44cXl0KoGVqE21lA+GCHwVSzP2yc=; 7:Rw/RpEDSEbIn8ECjeAhc8lUIjnehKgVOHWUObAP06ztgPuAKOneePCI9Tg8ihjMpwF9pf0VGavpdvuy8T5CSsFASCN+bs+VZTt8ajAA7lN8xvsXjm1B93/YY2xMlH9v1kyotMH+iLd0macTh6b4UVAi21u8tgfS+Jd3nh1GFDs+BidsQ+yK0DVg/mCvC6Fpg0llWzogJifcyOlC4gmnfbwrFjNi2WxETJorqsDqvQ124HWdgm8JmS031nEVb6y85
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: 8e66ef6a-bb6d-4fa6-9294-08d630130b46
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600074)(711020)(2017052603328)(7153060)(7193020); SRVR:FRXPR01MB0664;
x-ms-traffictypediagnostic: FRXPR01MB0664:
x-microsoft-antispam-prvs: <FRXPR01MB0664E0A30D623D2593CC46E1FCE20@FRXPR01MB0664.DEUPRD01.PROD.OUTLOOK.DE>
x-exchange-antispam-report-test: UriScan:(120809045254105)(192374486261705)(158342451672863);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040522)(2401047)(8121501046)(5005006)(3231355)(944501410)(52105095)(3002001)(10201501046)(93006095)(93001095)(149066)(150057)(6041310)(20161123564045)(20161123560045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123562045)(20161123558120)(201708071742011)(7699051); SRVR:FRXPR01MB0664; BCL:0; PCL:0; RULEID:; SRVR:FRXPR01MB0664;
x-forefront-prvs: 0823A5777B
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(396003)(376002)(346002)(366004)(39860400002)(136003)(189003)(199004)(51914003)(8676002)(52396003)(110136005)(6246003)(53936002)(97736004)(58126008)(6306002)(54906003)(106356001)(105586002)(14454004)(74482002)(14444005)(966005)(256004)(82746002)(2906002)(4326008)(478600001)(102836004)(75402003)(6116002)(316002)(76176011)(11346002)(33656002)(229853002)(186003)(81156014)(68736007)(446003)(2900100001)(5250100002)(36756003)(83716004)(486006)(81166006)(7736002)(71190400001)(5660300001)(86362001)(46003)(8936002)(71200400001)(476003)(305945005)(2616005); DIR:OUT; SFP:1101; SCL:1; SRVR:FRXPR01MB0664; H:FRXPR01MB0661.DEUPRD01.PROD.OUTLOOK.DE; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: telekom.de does not designate permitted sender hosts)
x-microsoft-antispam-message-info: kPqWE/M3EXyKIhNLfJR4+3zrc9K/pjEDLuQIL3z9k5LAmz9pG428Ocgt7ZoawEHVcCIDcv9bxjedv1FQUvrv+jmW4RMfBOg4kUk0vFhNMG3rGBOp5y38l8lHro/BKXa0BpM2NUsoFMUtNLnBot2R8qG+QNVR/q9VatWk0s0o4+QThwqYQtIrPeMgHUZEa0lcPHPmENEioKJyjzGitg1f+oDg5TZHHZuMa/v2RFdmGUlxT6ESLuPLmMAO6SzcrIjLD5f7Fklc9SDAZHa5cM0HibubdM7IcVdpkonvTrRi0hFCa0v6fzuxg66FOlcRZL7OLS5ABO0nwuE3XuowBV8Kt/wpA+ZOyTof3Se8GCLdytQ=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <55A0EE30D52CBB4BAC8FE9B8611FF1C3@DEUPRD01.PROD.OUTLOOK.DE>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 8e66ef6a-bb6d-4fa6-9294-08d630130b46
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Oct 2018 07:19:26.1814 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bde4dffc-4b60-4cf6-8b04-a5eeb25f5c4f
X-MS-Exchange-Transport-CrossTenantHeadersStamped: FRXPR01MB0664
X-OriginatorOrg: telekom.de
Archived-At: <https://mailarchive.ietf.org/arch/msg/dhcwg/xbVg8YwadMw-Ngr91sX9jGGpAY8>
Subject: Re: [dhcwg] Alissa Cooper's No Objection on draft-ietf-dhc-dhcp4o6-saddr-opt-06: (with COMMENT)
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dhcwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcwg/>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Oct 2018 07:19:36 -0000

Hi Alissa,

Thanks for the comment. I've proposed some new text below to address this.

Regards,
Ian 

On 10.10.18, 21:11, "dhcwg on behalf of Alissa Cooper" <dhcwg-bounces@ietf.org on behalf of alissa@cooperw.in> wrote:

    Alissa Cooper has entered the following ballot position for
    draft-ietf-dhc-dhcp4o6-saddr-opt-06: No Objection
    
    When responding, please keep the subject line intact and reply to all
    email addresses included in the To and CC lines. (Feel free to cut this
    introductory paragraph, however.)
    
    
    Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
    for more information about IESG DISCUSS and COMMENT positions.
    
    
    The document, along with other ballot positions, can be found here:
    https://datatracker.ietf.org/doc/draft-ietf-dhc-dhcp4o6-saddr-opt/
    
    
    
    ----------------------------------------------------------------------
    COMMENT:
    ----------------------------------------------------------------------
    
    I think this document could benefit from some discussion of the privacy
    considerations associated with the new options specified in the document. E.g.,
    if one were to apply the analysis in RFC 7844, what would the guidance be to
    clients that want to limit the disclosure of information about themselves? (It
    might be "don't use DHCP4o6," but even that is worth saying if that's the best
    advice available.)

[if - proposed new text to be added to the Security Consideration section:

9.1.  Client Privacy Considerations

   [RFC7844] describes anonymity profiles for DHCP clients.  These
   considerations and recommendations are also applicable to clients
   implementing the mechanism described in this document.  As DHCP4o6
   only uses DHCPv6 as a stateless transport for DHCPv4 messages, the
   "Anonymity Profile for DHCPv4" described in Section 3 is most
   relevant here.

   In addition to the considerations given in [RFC7844], the mechanism
   that the client uses for constructing the interface identifier for
   its IPv6 softwire source address (see Section 7.1), could result in
   the device being trackable across different networks and sessions,
   e.g., if the client's softwire IID is immutable.

   This can be mitigated by constructing the softwire source IPv6
   address as per Section 6 of [RFC7597].  Here, the address' IID
   contains only the allocated IPv4 address (and port set identifier if
   [RFC7618] is being used).  This means no additional client
   information is exposed to the DHCP4o6 server, and will also mean that
   the IID will change as the leased IPv4 address changes (e.g., between
   sessions when Section 3.5 of [RFC7844] is implemented).   
]

    _______________________________________________
    dhcwg mailing list
    dhcwg@ietf.org
    https://www.ietf.org/mailman/listinfo/dhcwg