Re: [Hipsec] Adam Roach's No Objection on draft-ietf-hip-native-nat-traversal-30: (with COMMENT)

Miika Komu <miika.komu@ericsson.com> Fri, 06 March 2020 14:33 UTC

Return-Path: <miika.komu@ericsson.com>
X-Original-To: hipsec@ietfa.amsl.com
Delivered-To: hipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCC2A3A07DF; Fri, 6 Mar 2020 06:33:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fXpzkB9t-L1Y; Fri, 6 Mar 2020 06:33:11 -0800 (PST)
Received: from EUR05-VI1-obe.outbound.protection.outlook.com (mail-vi1eur05on2082.outbound.protection.outlook.com [40.107.21.82]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D5C633A07D6; Fri, 6 Mar 2020 06:33:10 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Hx3zMpdXc9+m2Qj9YdjcMVA2vtfSo0/sdA4qmrivfLW+uRfzcq+boleRmMlA4eNFoyehfaXyT/lAPAf4lZ2Esit+kwRAfT/t8si36AB7mV7hg8xwtp/7VwQwUwRR911ZjR19f5hrZ2LgW/Wc4ht8YAek8N581SeA2gqaj7rv3MbGpAi075SWk0tND2rYjpoMMbcozMu+ub5DyOsMiDEO2BocbysflY6JixqbFeJY84ADSfwsZBkeNRHuD7RmWki2jhUyd8b/GNgdY6YPZlU6HlXZ7nftu2zBlW3MUinIcTLgS2wPPyP6cLPqblYAJD42TdzfsbIAVM8woLUcPJWxNQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=ylwn5E0kG9s07GF9O1jA/0y4hj+wmMa1wcYYwdSNQ3s=; b=GgPLkdfvEI4fh+iMRO2L+wmnWGZjEC5W5VQHnDe6tLbcoXWPhmQL8CoA2agbFWq0U0zCSuZBJ09gNdGhjbco534m4I65+JysSJ+k7STgqS0FhoQ1Kg3WLCENAdG542l30xHNDr9btM16g1tG2qKjJv3LYFfaxQvTKQfPi5nr7q0wjj5mhkdsDQjEyt9VA53J+prV0aNBy0HRsHoFXLr9ySilszphIJEkyoZGCXy1SJeOA6asiMKnHzRsrSCJgJ/ZB6SYFjNSbi9PmhzHS4cpgj/a63mXey12pOw/rdSWV6Qsl+wlUqWb0nQljqMNG7t/H1znlTow86FFrQfqOYWAkA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=ylwn5E0kG9s07GF9O1jA/0y4hj+wmMa1wcYYwdSNQ3s=; b=dKA+vBO0dlxofHx0HgRlZEnxqRjvc5O3Ef/mY2BtIUAsdZGQ18boRhZl1AwvwPShBiYptjeC8CO9JZCpDZiDkhDRQlHsESDGC6lu2jC7lwYxB1bUNO/AT1fgSFyunpxeIk9pOk01lJVYl6GntVVsqgrdHCgzqdmcD7n0OKswRSQ=
Received: from AM0PR07MB3876.eurprd07.prod.outlook.com (52.134.81.144) by AM0PR07MB4308.eurprd07.prod.outlook.com (52.133.60.156) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2793.11; Fri, 6 Mar 2020 14:33:06 +0000
Received: from AM0PR07MB3876.eurprd07.prod.outlook.com ([fe80::790c:4b51:77d2:7767]) by AM0PR07MB3876.eurprd07.prod.outlook.com ([fe80::790c:4b51:77d2:7767%5]) with mapi id 15.20.2793.013; Fri, 6 Mar 2020 14:33:06 +0000
From: Miika Komu <miika.komu@ericsson.com>
To: "iesg@ietf.org" <iesg@ietf.org>, "adam@nostrum.com" <adam@nostrum.com>
CC: "draft-ietf-hip-native-nat-traversal@ietf.org" <draft-ietf-hip-native-nat-traversal@ietf.org>, "hip-chairs@ietf.org" <hip-chairs@ietf.org>, Gonzalo Camarillo <gonzalo.camarillo@ericsson.com>, "hipsec@ietf.org" <hipsec@ietf.org>
Thread-Topic: Adam Roach's No Objection on draft-ietf-hip-native-nat-traversal-30: (with COMMENT)
Thread-Index: AQHV6zYXYqOBrY11mU6Er/aZUfyTv6g7seAA
Date: Fri, 06 Mar 2020 14:33:06 +0000
Message-ID: <f3189637dcdb7854d7c8b84b738a897a7685039d.camel@ericsson.com>
References: <158256455409.5317.3970484745957517223.idtracker@ietfa.amsl.com>
In-Reply-To: <158256455409.5317.3970484745957517223.idtracker@ietfa.amsl.com>
Accept-Language: fi-FI, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Evolution 3.28.5-0ubuntu0.18.04.1
authentication-results: spf=none (sender IP is ) smtp.mailfrom=miika.komu@ericsson.com;
x-originating-ip: [88.148.205.35]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 98d1d649-96e1-4118-221f-08d7c1db494e
x-ms-traffictypediagnostic: AM0PR07MB4308:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <AM0PR07MB4308FFAA6845C8242BD39C5CFCE30@AM0PR07MB4308.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0334223192
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(396003)(39860400002)(366004)(346002)(376002)(136003)(189003)(199004)(6512007)(478600001)(966005)(316002)(2906002)(86362001)(8676002)(44832011)(4326008)(8936002)(5660300002)(81156014)(81166006)(2616005)(6486002)(110136005)(54906003)(6506007)(186003)(76116006)(36756003)(26005)(64756008)(66946007)(66446008)(91956017)(66476007)(66556008)(71200400001)(99106002); DIR:OUT; SFP:1101; SCL:1; SRVR:AM0PR07MB4308; H:AM0PR07MB3876.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Ummhma+UvyJIFD2/Jvlu6VN1MdKgU1/+UNpdzuaJNrlDBu906NS/gR49AMoTzAUi1D6wg3ux1ONsmRym7RAVMjA6o0P3nJ0bRPwFsO5YsASSjPEXuDnY57nXmig9wmDZ9c5mpy0RKVTHocvw09uMkcjSyI7oeqS30D+yr7bmfo8ZF/zjqAyQHhl+Ykn7NE51ufQV06LDke7CGF+ythRL8MCqTmdtl+BiDn13s7bNSojr33pLjXvlh1UAIcmpjHF5ld1XboFZD4jyjzB34kOO785zhFvHjEQan1kEKMf8peojFWm7cRPVhx0NhtgeidW8q0JkXqIW0/Pp2h1zcSpK6KON4fVfPT6DZEBhDVPabbbdMIBnQDdjZB2VhalPAoXn/EHzuuKK0FlOj+GymqQZbRfimO6PStBKgH8NyhLYIhdB3ok9E2gDUuDXGPRK1sDbI//ae08bx/tWHyTtieFrwmeMJ9lYdTG7+4lG23F6LUfFbBm+eAQuFh0jx3N/wx9hQj+wPrTMW2llAvYPTr2hVxO8+tHzwx+vaK8oNtDCX6ZNoCiqm56GSE+bGkk7q6lW
x-ms-exchange-antispam-messagedata: d0qm/VGYvo89/eCiGAtJpqCm64Zyaw5pA5bfPRwPn80G6qU+06DtQsblD7+zqbfxwuqbulVmK41YPpSsDVed5a1IBzHWv89rKGbQciImUy97AIfBghaUMyDAZ8Cur+wH3mSsEoxrw+DrTE+oSJv22g==
Content-Type: text/plain; charset="utf-8"
Content-ID: <8AA2453DD18F234BBDEFDE75C9480479@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 98d1d649-96e1-4118-221f-08d7c1db494e
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Mar 2020 14:33:06.7300 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 4lXX4SILecPmF1MIXeFHI+d7uFxKXDXgbmP465yK85y/MkSsneVfUmZxIGd+r9BfEdCZpj8GYRaTRMtEb50sJA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR07MB4308
Archived-At: <https://mailarchive.ietf.org/arch/msg/hipsec/_PvUifgAKVk1F6pTWWMthCXNELU>
Subject: Re: [Hipsec] Adam Roach's No Objection on draft-ietf-hip-native-nat-traversal-30: (with COMMENT)
X-BeenThere: hipsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the official IETF Mailing List for the HIP Working Group." <hipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hipsec>, <mailto:hipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/hipsec/>
List-Post: <mailto:hipsec@ietf.org>
List-Help: <mailto:hipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hipsec>, <mailto:hipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Mar 2020 14:33:19 -0000

Hi Adam,

ma, 2020-02-24 kello 09:15 -0800, Adam Roach via Datatracker kirjoitti:
> Adam Roach has entered the following ballot position for
> draft-ietf-hip-native-nat-traversal-30: No Objection
> 
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut
> this
> introductory paragraph, however.)
> 
> 
> Please refer to 
> https://www.ietf.org/iesg/statement/discuss-criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
> 
> 
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-hip-native-nat-traversal/
> 
> 
> 
> -------------------------------------------------------------------
> ---
> COMMENT:
> -------------------------------------------------------------------
> ---
> 
> Thanks to the authors for taking some of the concerns I laid out in
> my original
> ballot into account. I still do not believe this approach is good for
> HIP's
> benefit, but am no longer worried about collateral damage from other
> protocols
> imitating this approach. Accordingly, I am balloting "No Objection."
> 
> There is one remaining comment from my initial review that I think
> can and
> should be addressed prior to publication:
> 
> Appendix B:
> 
> >  o  Unlike in ICE, the addresses are not XOR-ed in Native ICE-HIP
> >     protocol in order to avoid middlebox tampering.
> 
> This bullet should explain why such obfuscation is unnecessary.

based on discussion with Rescolarla, it actually says:

"Unlike in ICE, the addresses are not XOR-ed in Native ICE-HIP protocol
but rather encrypted to avoid middlebox tampering."


https://tools.ietf.org/html/draft-ietf-hip-native-nat-traversal-30#appendix-B

P.S. Thanks again for your time and effort in reviewing the document!