Re: [Dime] I-D Action: draft-ietf-dime-e2e-sec-req-02.txt

Steve Donovan <srdonovan@usdonovans.com> Fri, 27 March 2015 19:09 UTC

Return-Path: <srdonovan@usdonovans.com>
X-Original-To: dime@ietfa.amsl.com
Delivered-To: dime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1BF221A88FA for <dime@ietfa.amsl.com>; Fri, 27 Mar 2015 12:09:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.121
X-Spam-Level:
X-Spam-Status: No, score=-1.121 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NEUTRAL=0.779] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6XPJ2jNd-k3y for <dime@ietfa.amsl.com>; Fri, 27 Mar 2015 12:09:40 -0700 (PDT)
Received: from biz131.inmotionhosting.com (biz131.inmotionhosting.com [173.247.247.250]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E30DA1A88EC for <dime@ietf.org>; Fri, 27 Mar 2015 12:09:40 -0700 (PDT)
Received: from cpe-76-183-208-111.tx.res.rr.com ([76.183.208.111]:50813 helo=Steves-MacBook-Air.local) by biz131.inmotionhosting.com with esmtpsa (UNKNOWN:RC4-SHA:128) (Exim 4.82) (envelope-from <srdonovan@usdonovans.com>) id 1YbZdR-0003Kx-R7; Fri, 27 Mar 2015 12:09:39 -0700
Message-ID: <5515AAF0.8020502@usdonovans.com>
Date: Fri, 27 Mar 2015 14:09:36 -0500
From: Steve Donovan <srdonovan@usdonovans.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: Jouni Korhonen <jouni.nospam@gmail.com>, dime@ietf.org
References: <20150126150303.15610.1562.idtracker@ietfa.amsl.com> <5511D1AA.40804@usdonovans.com> <55138C07.2070007@gmail.com>
In-Reply-To: <55138C07.2070007@gmail.com>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OutGoing-Spam-Status: No, score=-2.9
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - biz131.inmotionhosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - usdonovans.com
X-Get-Message-Sender-Via: biz131.inmotionhosting.com: authenticated_id: srd+usdonovans.com/only user confirmed/virtual account not confirmed
Archived-At: <http://mailarchive.ietf.org/arch/msg/dime/hF7aS8TBzjmjLUpwFASuUDeT6x4>
Subject: Re: [Dime] I-D Action: draft-ietf-dime-e2e-sec-req-02.txt
X-BeenThere: dime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Diameter Maintanence and Extentions Working Group <dime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dime>, <mailto:dime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dime/>
List-Post: <mailto:dime@ietf.org>
List-Help: <mailto:dime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Mar 2015 19:09:42 -0000


On 3/25/15 11:33 PM, Jouni Korhonen wrote:
> Steve,
>
> See inline..
>
> 3/24/2015, 2:05 PM, Steve Donovan kirjoitti:
>> A few comments on this document.
>>
>> I would suggest adding the following requirement -- The solution MUST
>> ensure that routing AVPs are always sent in the clear.
>
> By routing AVPs you refer to Router-Record and Proxy-Info as per 
> RFC6733, right? In that case I do not see a reason for the "are always 
> sent in the clear".
SRD> No, I mean Destination-Host, Destination-Realm, Origin-Host and 
Origin-Realm.
>
>> Requirement 5 does indicate that not all AVPs are covered by the "
>> cryptographic protection".  I think it would be better to be clear that
>> there is a set of AVPs that MUST NOT be encrypted.
>
> OK.
>
>> In addition, the following requirement might be useful -- The solution
>> MUST support the ability to identify other non routing AVPs that must
>> always be sent in the clear.
>
> I would assume the knowledge which AVPs are ciphered is up to a local 
> policy. If the policy is wrong, the receiver or intermediates will 
> reply with an error.
SRD> That makes sense.  My reason for bringing this up is to make sure 
that the solution allows for these AVPs being sent in the clear.  It 
won't work to arbitrarily encrypt all AVPs or even chunks of AVPs.
>
> - Jouni
>
>> This would be to cover overload, load, message priority and other AVPs
>> that need to be accessible by all nodes in the path of a transaction.
>>
>> Regards,
>>
>> Steve
>>
>> On 1/26/15 9:03 AM, internet-drafts@ietf.org wrote:
>>> A New Internet-Draft is available from the on-line Internet-Drafts 
>>> directories.
>>>   This draft is a work item of the Diameter Maintenance and 
>>> Extensions Working Group of the IETF.
>>>
>>>          Title           : Diameter AVP Level Security End-to-End 
>>> Security: Scenarios and Requirements
>>>          Authors         : Hannes Tschofenig
>>>                            Jouni Korhonen
>>>                            Glen Zorn
>>>                            Kervin Pillay
>>>     Filename        : draft-ietf-dime-e2e-sec-req-02.txt
>>>     Pages           : 9
>>>     Date            : 2015-01-26
>>>
>>> Abstract:
>>>     This specification discusses requirements for providing Diameter
>>>     security at the level of individual Attribute Value Pairs.
>>>
>>>
>>> The IETF datatracker status page for this draft is:
>>> https://datatracker.ietf.org/doc/draft-ietf-dime-e2e-sec-req/
>>>
>>> There's also a htmlized version available at:
>>> http://tools.ietf.org/html/draft-ietf-dime-e2e-sec-req-02
>>>
>>> A diff from the previous version is available at:
>>> http://www.ietf.org/rfcdiff?url2=draft-ietf-dime-e2e-sec-req-02
>>>
>>>
>>> Please note that it may take a couple of minutes from the time of 
>>> submission
>>> until the htmlized version and diff are available at tools.ietf.org.
>>>
>>> Internet-Drafts are also available by anonymous FTP at:
>>> ftp://ftp.ietf.org/internet-drafts/
>>>
>>> _______________________________________________
>>> DiME mailing list
>>> DiME@ietf.org
>>> https://www.ietf.org/mailman/listinfo/dime
>>>
>>
>>
>>
>> _______________________________________________
>> DiME mailing list
>> DiME@ietf.org
>> https://www.ietf.org/mailman/listinfo/dime
>>
>