Re: [homenet] Next steps for draft-behringer-homenet-trust-bootstrap?

"Michael Behringer (mbehring)" <mbehring@cisco.com> Fri, 15 March 2013 00:16 UTC

Return-Path: <mbehring@cisco.com>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D9CB11E80D9 for <homenet@ietfa.amsl.com>; Thu, 14 Mar 2013 17:16:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9F6b-NX2Gnat for <homenet@ietfa.amsl.com>; Thu, 14 Mar 2013 17:16:22 -0700 (PDT)
Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) by ietfa.amsl.com (Postfix) with ESMTP id 0F62811E8104 for <homenet@ietf.org>; Thu, 14 Mar 2013 17:16:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1535; q=dns/txt; s=iport; t=1363306582; x=1364516182; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=Dl/nVs9yYPP9PKa/ArJxOp50NEbgap3AeJoq8PJfrOg=; b=FSpvwV+Eu4kr8xCxSgt06ycXBwxGRaFLmhRKJdbx/FV9L9ap0SB/BRWb 0gxaBzNJneBQiOLTZu5vPx2oh8RWmNkNaFUHUTza3tkVaNTr0vEoI9LEc FJ12GvIl0EHOq+vVO1Uoi90G9/1j4kJPAE4e8h1DQ2vr0IoAd0jc2947k Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgEFAM5mQlGtJXHB/2dsb2JhbABDxQWBZxZ0gisBAQEEOj8MBAIBCA4DAQMBAQEKFAkHMhQDBggBAQQOBQgTh3nCBI5lMQcGgllhA6dagwqCKA
X-IronPort-AV: E=Sophos;i="4.84,848,1355097600"; d="scan'208";a="184685065"
Received: from rcdn-core2-6.cisco.com ([173.37.113.193]) by rcdn-iport-9.cisco.com with ESMTP; 15 Mar 2013 00:16:21 +0000
Received: from xhc-aln-x07.cisco.com (xhc-aln-x07.cisco.com [173.36.12.81]) by rcdn-core2-6.cisco.com (8.14.5/8.14.5) with ESMTP id r2F0GLlN019545 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 15 Mar 2013 00:16:21 GMT
Received: from xmb-rcd-x14.cisco.com ([169.254.4.51]) by xhc-aln-x07.cisco.com ([173.36.12.81]) with mapi id 14.02.0318.004; Thu, 14 Mar 2013 19:16:21 -0500
From: "Michael Behringer (mbehring)" <mbehring@cisco.com>
To: Michael Thomas <mike@mtcc.com>
Thread-Topic: [homenet] Next steps for draft-behringer-homenet-trust-bootstrap?
Thread-Index: Ac4gyjI7rRa09jDESjm4TcI0Yw8B/QAKw4sAAAgh9XAABD5UAAAFX0EA
Date: Fri, 15 Mar 2013 00:16:20 +0000
Message-ID: <3AA7118E69D7CD4BA3ECD5716BAF28DF0F6EE46B@xmb-rcd-x14.cisco.com>
References: <3AA7118E69D7CD4BA3ECD5716BAF28DF0F6ED6C6@xmb-rcd-x14.cisco.com> <5141F140.2070508@mtcc.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF0F6ED79F@xmb-rcd-x14.cisco.com> <5142444E.10105@mtcc.com>
In-Reply-To: <5142444E.10105@mtcc.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.61.103.73]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: Tim Chown <tjc@ecs.soton.ac.uk>, "homenet@ietf.org Group" <homenet@ietf.org>
Subject: Re: [homenet] Next steps for draft-behringer-homenet-trust-bootstrap?
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/homenet>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Mar 2013 00:16:23 -0000

> -----Original Message-----
> From: Michael Thomas [mailto:mike@mtcc.com]
> Sent: 14 March 2013 17:43
> To: Michael Behringer (mbehring)
> Cc: Tim Chown; homenet@ietf.org Group
> Subject: Re: [homenet] Next steps for draft-behringer-homenet-trust-
> bootstrap?
> 
> On 03/14/2013 10:03 AM, Michael Behringer (mbehring) wrote:
> >> From: Michael Thomas [mailto:mike@mtcc.com]
> > [...]
> >> In today's world access control is gated at L2 via wpa or similar.
> >> Are you suggesting that we have a L3 equivalent? In addition? In
> replacement?
> > We need a solution to this problem. I think this is the first important thing
> to note, and so far it isn't noted (or I missed it). Which solution is open for
> discussion.
> >
> > Can we agree thus far?
> 
> Well, it seems to me that we have a solution today at L2, at least for
> wireless which is the most pressing need. Am I missing something? Or are
> talking about remote access into your homenet?

No, it's not primarily for remote access. 

Even if we have something, the architecture doc should describe that this is an issue and needs to be addressed, and which solutions fit (including existing). 

But I think the need goes beyond wireless. If I have visitors, I may not like it if they plug in a device into the Ethernet socket in the guest room, and the device has full access to everything. I think we need a simple way to accept/deny a new device onto the network, independent of the media type. 

Michael