Re: [HOKEY] Fwd: [IPsec] HOKEY draft draft-ietf-hokey-rfc5296bis

Glen Zorn <gwz@net-zen.net> Tue, 08 March 2011 04:50 UTC

Return-Path: <gwz@net-zen.net>
X-Original-To: hokey@core3.amsl.com
Delivered-To: hokey@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1187C3A69F1 for <hokey@core3.amsl.com>; Mon, 7 Mar 2011 20:50:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bVnQoxPeB1Tp for <hokey@core3.amsl.com>; Mon, 7 Mar 2011 20:50:51 -0800 (PST)
Received: from p3plsmtpa01-09.prod.phx3.secureserver.net (p3plsmtpa01-09.prod.phx3.secureserver.net [72.167.82.89]) by core3.amsl.com (Postfix) with SMTP id EC0AC3A696F for <hokey@ietf.org>; Mon, 7 Mar 2011 20:50:50 -0800 (PST)
Received: (qmail 12217 invoked from network); 8 Mar 2011 04:52:04 -0000
Received: from unknown (124.120.97.114) by p3plsmtpa01-09.prod.phx3.secureserver.net (72.167.82.89) with ESMTP; 08 Mar 2011 04:52:03 -0000
Message-ID: <4D75B5ED.1050108@net-zen.net>
Date: Tue, 08 Mar 2011 11:51:57 +0700
From: Glen Zorn <gwz@net-zen.net>
Organization: Network Zen
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.15) Gecko/20110303 Lightning/1.0b2 Thunderbird/3.1.9
MIME-Version: 1.0
To: Yaron Sheffer <yaronf.ietf@gmail.com>
References: <4D73575C.6090808@gmail.com>
In-Reply-To: <4D73575C.6090808@gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Cc: Yoav Nir <ynir@checkpoint.com>, Paul Hoffman <paul.hoffman@vpnc.org>, hokey@ietf.org
Subject: Re: [HOKEY] Fwd: [IPsec] HOKEY draft draft-ietf-hokey-rfc5296bis
X-BeenThere: hokey@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HOKEY WG Mailing List <hokey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hokey>
List-Post: <mailto:hokey@ietf.org>
List-Help: <mailto:hokey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Mar 2011 04:50:52 -0000

On 3/6/2011 4:43 PM, Yaron Sheffer wrote:
> Hi Stephen,
>
> I gather you are the incoming responsible AD for HOKEY.
>
> ERP (RFC 5296, now reincarnated as a bis document) is one of HOKEY's
> principal work items. The document is making major changes to EAP, and
> seems to have gotten a life of its own, despite the fact that AFAIU
> neither of its protocol users (802.1X and IKEv2) has been changed to
> accommodate it. It seems to me at best like wasted effort, more likely a
> disconnect between the working groups.


First of all, I'd like to express my deep appreciation (& I think that I 
can speak for all the members of the hokey WG) for you kind concern for 
the use of our time.  It is especially wonderful since AFAIK you have 
heretofore shown no interest at all in our activities; to extend 
yourself in this way for a group with which you have essentially no 
connection is truly magnanimous; and to go straight to the Area 
Director, the one person who might be able to save us from this terrible 
waste of effort & time!  I must say that I find it hard to express in 
words how it makes me feel.  Nonetheless, I admit to some puzzlement as 
to the rationale for this action: the referenced draft is a chartered 
work item of the hokey WG, adopted after a call for consensus from the 
members.  Of course, you could not know about the call since you aren't 
a WG member but it did occur.  So while I do appreciate your obviously 
deep and selfless concern, I am inclined to let the actual members of 
the WG decide what (if anything) they deem worthy of effort.  But, 
thanks again!

P.S.
I'm pretty sure that IEEE 802.1X-2010 supports ERP.

>
> Am I missing anything?
>
> Thanks,
> Yaron
>
> -------- Original Message --------
> Subject: [IPsec] HOKEY draft draft-ietf-hokey-rfc5296bis
> Date: Sun, 6 Mar 2011 11:25:54 +0200
> From: Yoav Nir <ynir@checkpoint.com>
> To: ipsec@ietf.org <ipsec@ietf.org>rg>,
> draft-ietf-hokey-rfc5296bis@tools.ietf.org
> <draft-ietf-hokey-rfc5296bis@tools.ietf.org>
>
> Hi all
>
> I have just read the subject draft, and found this in section 6 (and
> similar text in the introduction):
>
> Note that to support ERP, lower-layer specifications may need to be
> revised. Specifically, the IEEE802.1x specification must be revised
> to allow carrying EAP messages of the new codes defined in this
> document in order to support ERP. Similarly, RFC 4306 must be
> updated to include EAP code values higher than 4 in order to use ERP
> with Internet Key Exchange Protocol version 2 (IKEv2). IKEv2 may
> also be updated to support peer-initiated ERP for optimized
> operation. Other lower layers may need similar revisions.
>
> Note that this is not new text, and it appears pretty much the same way
> in RFC 5296.
>
> There's the obvious nit with this text, that RFC 4306 is not a
> reference. If it was, the id-nits would warn about this RFC being
> obsolete. But that's the small problem here.
>
> A bigger problem is that this text says that IKEv2 needs to be updated,
> but there is no draft for this update, nor has there been any message to
> this list about this proposed change.
>
> The simple change they require is to section 3.16:
> o Code (1 octet) indicates whether this message is a Request (1),
> Response (2), Success (3), or Failure (4).
>
> I think this could be done with an errata or a 1-page draft, if all that
> was required was pass-through of codes (5) and (6). But I think it's
> more involved than that.
>
> There's peer-initiated ERP (which would require peer-initiated IKE?) and
> multiple simultaneous operations. I think it may come to a somewhat
> larger draft.
>
> I think there should be at least a work-in-progress reference for 802.1x
> and IKEv2 before the hokey draft progresses.
>
> Yoav
>
> _______________________________________________
> IPsec mailing list
> IPsec@ietf.org
> https://www.ietf.org/mailman/listinfo/ipsec
>
>