Re: [dtn] [EXTERNAL] BPbis consensus status

Magnus Westerlund <magnus.westerlund@ericsson.com> Fri, 18 September 2020 14:03 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: dtn@ietfa.amsl.com
Delivered-To: dtn@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EAE13A0977 for <dtn@ietfa.amsl.com>; Fri, 18 Sep 2020 07:03:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.796
X-Spam-Level:
X-Spam-Status: No, score=-3.796 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.695, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Sw7aFIgy8Ub2 for <dtn@ietfa.amsl.com>; Fri, 18 Sep 2020 07:03:29 -0700 (PDT)
Received: from EUR03-VE1-obe.outbound.protection.outlook.com (mail-eopbgr50051.outbound.protection.outlook.com [40.107.5.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F2813A0972 for <dtn@ietf.org>; Fri, 18 Sep 2020 07:03:29 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=KADrWqis1JoEN4RD3lwuqOZMlocS6vKnRaRxgA0qtu1sX724D8Pk4Ehdvy42lE9fx5lJbI+ZZ1lrPfFSFMz02nujTrFFqTVe0vjKjSKTWx7lQatNfXnqgVi/Q+fNT+WaTzIHdVWU5WipvANJvDOnUn6sSjY2+QHBuPoQ3Ks8uQ/uHq+tYrJ6auykOkP2hddEZHV9ZswTvre/L1xDYs/8u7RcPOeTQZL6UMOmodGCPWSqnmSaxkTbHpJrCnavIG2ttsxpRnuTQUGpsZZgdeQ71bQ/v3LsBEHfn3SnDQan+/iim22J9wqE9YpMUG+0FXemMK4g6UOCcx7G436WuPpMGg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Eiwt3aldYGl4rA/yJluIpxmDSPzzMtn0YVIodAgomA4=; b=EFfSdLjg6DguvQxj/EdAjKEuxxGZVB23pzwo1CGyDn+kpVGo/BucVOFtBFjpa3QbvqfJ3SHIxqTHRUI/XmCJ62abctM+GJkJJTgMWya48T1Ta0tOO0fhJYKxeYMOpwA8Smwt/2OtjOIKI29k/jCH7goBozwx9Plmui/FposORRWNfXUA+LqZtE7rXUxgzU9d0BQaSObe3lAyMf4jXy+9Bq2TXMRKynyiWWnVDdU7DCHNLXOkKfrKL3mYhO1Z+/Do3ChF0hIpndQvESsw5BwG2Psx5iEOD1Z7TGGLi4kIeIPrG9Zk30eNbBYyp87Wm/f/uHkc+yJDGhG+lXep3lqpUQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Eiwt3aldYGl4rA/yJluIpxmDSPzzMtn0YVIodAgomA4=; b=kDZZseRzx7kcwe7wh2ZbyckGN9WwOcxk2fO2qui/eOvwk1F61gn9mHQX/LmZgqkOo56lAQoSUJfzErXdZnkLJbYqJxiBZ5gIqIzTQ8xe/2eRO96af2ln6CIlKyFEIdoLB7VejSc2yTmD+YhXXwshG3hLcRQhvwz+mUw5yAPoCks=
Received: from HE1PR0702MB3772.eurprd07.prod.outlook.com (2603:10a6:7:8e::14) by HE1PR07MB4219.eurprd07.prod.outlook.com (2603:10a6:7:9f::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3412.4; Fri, 18 Sep 2020 14:03:26 +0000
Received: from HE1PR0702MB3772.eurprd07.prod.outlook.com ([fe80::c98a:9a0c:1eea:3fdc]) by HE1PR0702MB3772.eurprd07.prod.outlook.com ([fe80::c98a:9a0c:1eea:3fdc%6]) with mapi id 15.20.3391.009; Fri, 18 Sep 2020 14:03:26 +0000
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
To: "rja.lists@gmail.com" <rja.lists@gmail.com>, "dtn@ietf.org" <dtn@ietf.org>
Thread-Topic: [dtn] [EXTERNAL] BPbis consensus status
Thread-Index: AQHWjKJJhEk81s0iMEOC2n5gBSFMfKltb2mAgADo4IA=
Date: Fri, 18 Sep 2020 14:03:26 +0000
Message-ID: <e8d3d3bfb224df27042a229c1e13074483600bdf.camel@ericsson.com>
References: <34a7886b09d946faa816acbd26700d65@jpl.nasa.gov> <F2B67324-D3F5-4F28-8CC3-207EB607E6EA@viagenie.ca> <ED9CEA8D-3B22-4623-A7F7-F9ACA4C3A071@gmail.com> <CEBD7985-410F-4AF4-B367-1B08C99CB38A@viagenie.ca> <d2eb737bc35b46019bdb5c5e82e96126@jpl.nasa.gov> <A2CD01A8-EDBE-4840-8CFC-5A3732AA28D2@viagenie.ca> <5B167E21-175E-4F87-8D67-59FBA0CB4A28@gmail.com>
In-Reply-To: <5B167E21-175E-4F87-8D67-59FBA0CB4A28@gmail.com>
Accept-Language: sv-SE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Evolution 3.28.5-0ubuntu0.18.04.2
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [192.176.1.85]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b77fb15f-a464-4efa-eca3-08d85bdb9d0c
x-ms-traffictypediagnostic: HE1PR07MB4219:
x-microsoft-antispam-prvs: <HE1PR07MB4219675AD4C5F29C8D5D8ADA953F0@HE1PR07MB4219.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 1ZlcCb/HLi2VPRf6YY8fcqDKtUkD2nSpZVKDCRJDbpoHjJvdFR7zJqBsB7MiQ/5yhGxgSG+AoWG+ZF5wbpAWULLkRphElnQlRXQa4xYi/rBfCBwBkPoubXKAjx18/knHYGuRpGcMPH/jm8hlBkiD3xT2vIrDyhgQq1bT05bSqTnT7/veLwtMgmlDgi5WQtxKCIA0hDBCBfen0ClGZ1/beb4ts5eozar99urrI7n7GhHU24LBuUjTKe70y7l+Wqvt/A2Gf83SOuiJ4o4ZIcJWXzDqp6FuSCHH0XYhVdxarEhPebs8EzjjIx7xNwDyYZ/gJ+vBDrKrZQaWa0mCv9xpjKOEWK6btVPiMohW8bTsifDLv8olCt0a4qYhiGjc8V4awf+vK2yh+uVXmtcANfEAAfz0JK6bjY31dHNeqd24sygMyln6c5K3HgO02CbV0OOtg0keAYIsDWVmrZwgZMWSkA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0702MB3772.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(136003)(39860400002)(346002)(376002)(366004)(396003)(2616005)(966005)(66574015)(83380400001)(36756003)(6512007)(5660300002)(71200400001)(110136005)(8676002)(86362001)(8936002)(6506007)(53546011)(6486002)(26005)(64756008)(76116006)(66556008)(66476007)(66946007)(91956017)(66446008)(478600001)(44832011)(2906002)(316002)(186003)(99106002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: fNfHdTQW4OYPl1fmZMoIbZ/mHreqxx2E6fr5VvkVGmnQqbw78QwsAn3OZNRNPaEnMjA0nDFzNGCVEfHl6p0IbcsxGdutC2nANWCLIWJcQD0hat9Biw0nEyG6S6ed2+jQYRNfkiUj1wpoxSm9ygDlw6a0Eo9e+mU6OnZH+1uNUHIg4Az9pxHQBrOdTaLCVEg6Ij0MdBoI2GDUXp7Qkmq1tcW1Wi1b6yBNgTCFw762yfZxlDI4t2iHhftcpfEzo5Aiqvn+m4QMZN2onNHN5n4YT3Vj8QwTugPlYn/bqRCOdhfLUjE3OpGxNx4zYAlb9O5loleNBuSUBBIwphAJo0Xb+75YrVguQSx7HL20gSIWltgDgkTfNYwasdm680Nt7dzetlO2r9Pe+Ck9zaGnrkPJdjGF+0jUzz846QsNlXB0ZjkV16WWdIchLltxVmF8Ap4eK5ecFxrVFdZ2L84go+a3rfq7c1AjejdnrBFs/yFsOjlXlndXf+ak7Q0ziyLD98P1yCz1zhB+zdQV5HucjMw0F/HMvfLieAMEvmDXl0HfVdqxC6DWzDUXhrdCIPAPzmxfDe55F6OuzRN/zwKes6kkOTFcWpqi6w2TejrJYNn1BTOxN2h9+cenv7NCSfsXfVILurLFXpmfgLm3gPZFagXtwg==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <1A23AEB9A236CC4DBAFC996356365DF8@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0702MB3772.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b77fb15f-a464-4efa-eca3-08d85bdb9d0c
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Sep 2020 14:03:26.2421 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ktt9NrOczvkiiqswwxpgV7KENvaiCuw2Mjmb6TwGOymllyUHoQo+qE73XxqHrlVPb59R9KgTDDenS7/bZk5g4TJqdPxB1zXekR0n3OW9BKg=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB4219
Archived-At: <https://mailarchive.ietf.org/arch/msg/dtn/nH6FjPDYOrfQm2QnFV94IRcvSeI>
Subject: Re: [dtn] [EXTERNAL] BPbis consensus status
X-BeenThere: dtn@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Delay Tolerant Networking \(DTN\) discussion list at the IETF." <dtn.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dtn>, <mailto:dtn-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dtn/>
List-Post: <mailto:dtn@ietf.org>
List-Help: <mailto:dtn-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dtn>, <mailto:dtn-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Sep 2020 14:03:31 -0000

Hi,

Personal opinions below. 

Marc, I think comparing BPSec with IP and IPsec is wrong for several reasons. I
think one of the more significant ones are related to the identification of the
peer entitity and who you are and establishing security between these two
entities end-to-end. IPSec is to low level for that to work in the Internet as
endpoint or possibly whole networks (due to NATs) exist under the umbrella of an
IP address. However, I don't see that being the case for BP. Here BP can address
the applicaiton specifically and create security association end-to-end between
the application entities on different nodes. Becasue the BP agent can provide
unique DTN addresses for each application and establish different BPSec security
contexts to prevent this missmatch. So BPSec has all the chance of being the
basic security layer end-to-end that IPsec never succed as. 

Yes, there are hurdle to get the details for security contexts (security
profile) and its key-management done. But without this I don't see how DTN will
even become more that narrow nichese where it is used ontop of a private
network. There are some utility in that, but far from the promise of the network
and networks for delay tolerant applications that could use a interwork layer. I
think BP can succeed, but not without a security solution that work and are
generally available and supported. 

Cheers

Magnus




On Thu, 2020-09-17 at 18:46 -0400, R. Atkinson wrote:
> > On Sep 16, 2020, at 23:25, Marc Blanchet <marc.blanchet@viagenie.ca> wrote:
> > ... as current Internet deployment tells us, the applications need to be
> > aware
> > of security services ...
> 
> Marc,
> 
> Your words above - to the extent they are true — are a reason 
> to have a well documented BPsec API which applications can use
> if/when appropriate.
> 
> Such an API probably should be documented in an Informational RFC.
> Is that something you might want to undertake — since you are so
> passionate about it ??
> 
> From a logic perspective, those words quoted above are really NOT a reason 
> for  BPsec to be optional to implement.
> 
> Yours,
> 
> Ran
> 
> _______________________________________________
> dtn mailing list
> dtn@ietf.org
> https://www.ietf.org/mailman/listinfo/dtn
-- 
Cheers

Magnus Westerlund 


----------------------------------------------------------------------
Networks, Ericsson Research
----------------------------------------------------------------------
Ericsson AB                 | Mobile +46 73 0949079
Torshamnsgatan 23           |
SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------