Re: [homenet] Fwd: I-D Action: draft-ietf-homenet-naming-architecture-dhc-options-08.txt

Daniel Migault <mglt.ietf@gmail.com> Fri, 20 November 2020 08:04 UTC

Return-Path: <mglt.ietf@gmail.com>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C34063A115E for <homenet@ietfa.amsl.com>; Fri, 20 Nov 2020 00:04:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K-9RGfg6zDBq for <homenet@ietfa.amsl.com>; Fri, 20 Nov 2020 00:04:15 -0800 (PST)
Received: from mail-vs1-xe2e.google.com (mail-vs1-xe2e.google.com [IPv6:2607:f8b0:4864:20::e2e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 47A3F3A1045 for <homenet@ietf.org>; Fri, 20 Nov 2020 00:04:15 -0800 (PST)
Received: by mail-vs1-xe2e.google.com with SMTP id f7so4545270vsh.10 for <homenet@ietf.org>; Fri, 20 Nov 2020 00:04:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=V4hBOAosHDHIVH4J3hPhGZeTD+3gLWTs1YPQhRShHqI=; b=bjJVTjog9MplkqpxakvTjIPvXln6YVhUw5wJBdst4kG6eKU2G3y62tcjDb9cq+QQ4h E/HWi1rPCNpi3n9hZiubWlK8yk8+8L/soB2/bYNdFHyTFmN/WKIW2hXfJM/uxuIsGNAF kexMdbrobujIcZ+0xBDySP2jimR0oUQ7uCigf5N4q2BzansI12Qlf/RiMa2bx4OUZnvg ty+QJNAnQh8t2pYGPLZWaQlO0QhZSeDJCtkc2ykHhwr4TXPcF0dCoWaqdAyexTgFnT1Q 7X4l77LziQdLj3j2XmULvsBnedYn0AmOEitSR92LWhWBvurUfLUqLSzhbS1hlgpkimgx gIjw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=V4hBOAosHDHIVH4J3hPhGZeTD+3gLWTs1YPQhRShHqI=; b=N/TLjv6Z8roKq3pIaB5TdfL1nr3QYOi//t4YLate46JRhDVP6a1EwnQw6iYF6ELqRG p6qCHaGJKmAgz1Qzni95VyfpS7rMszcq2Zkh5qjbJ1VW9Lx4GjhTubuUcYMvU8OXYGAf te3Web/tpEpXGv/vZGYfprhZtSQjXEOlNxClVsluhPzihhwRSrQ612nEs5b+OVrQDrVU r8oCKFaYxBsywRrqyrJxBUyf+s/mwcX/afzwJ2qNmttrBycQniFosX0Q+lYIH4ZK31tV GMY0zXY6Fl4Ar9dTg8TI6MjFHs1CvBKjckvqudTyuQhiwHqXrtCVOG1mHPgGqvRIOhcB Fasg==
X-Gm-Message-State: AOAM530mUEVJacQz6FGXKIE2cyHSqHidoaSSOK/42JRlstjMm/OFCoKW tyQ6zGPf8tG+c94f2AGmQNk7EGk9rxQmoc2kG9w13qk+
X-Google-Smtp-Source: ABdhPJyvi2eHSn8betDEMq1B58iVUJZNuVcGnKa58BE6zrGIbfZ/A2Kf18ZjquWrniMGx51Hi06YYG2TTr1uAqAY/Ys=
X-Received: by 2002:a67:6981:: with SMTP id e123mr12322195vsc.40.1605859454257; Fri, 20 Nov 2020 00:04:14 -0800 (PST)
MIME-Version: 1.0
References: <160337182992.8499.7193292073243859221@ietfa.amsl.com> <CADZyTk=1TfOUSVn5RHAQhdigYLppcQYpSjw_-CuXahU8kO1aWQ@mail.gmail.com> <f642d33b-3b00-054b-838d-d952fa5691b2@globis.net>
In-Reply-To: <f642d33b-3b00-054b-838d-d952fa5691b2@globis.net>
From: Daniel Migault <mglt.ietf@gmail.com>
Date: Fri, 20 Nov 2020 03:04:02 -0500
Message-ID: <CADZyTk=zUz1DVoS1RBLFj0ZMUuRgq3FU=LutbUoTqG8hPHd9OA@mail.gmail.com>
To: "Ray Hunter (v6ops)" <v6ops@globis.net>
Cc: homenet <homenet@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000548d2c05b4854ab8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/homenet/gkdGWZR0TKSkm__36sYlzoWh44Q>
Subject: Re: [homenet] Fwd: I-D Action: draft-ietf-homenet-naming-architecture-dhc-options-08.txt
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Homenet WG mailing list <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Nov 2020 08:04:18 -0000

Thanks Ray for the feed backs. Please see my questions inline.
Yours,
Daniel

On Fri, Oct 23, 2020 at 10:52 AM Ray Hunter (v6ops) <v6ops@globis.net>
wrote:

> Hi Daniel,
>
> Thanks for publishing this draft.
>
> I have a three comments/concerns.
>
> Firstly: "this option is also defined in [I-D.ietf-dhc-sedhcpv6]."
>
> I just want to clarify that you are going to provide a new option code,
> but with the identical semantics.
>
> <mglt>
Actually I left this as a comment on similar ideas. The idea was originally
to use the same format and use dhc-sedhcpv6 as the reference for the
format.  As far as I know this draft seems abandoned, and this is why the
current draft does specify the format.

I agree the comment is misleading and should be removed and yes we do ask
for a specific code point if we were using that option ( see below: using a
certificate is probably a better idea.).
</mglt>

I do think you need a separate code to avoid parsing ambiguity.
>
> But also going forward if the specification is amended, then this would
> also be amended for this usage.
>
> i.e. s/DNSKEY RDATA format as defined in [RFC4034]/DNSKEY RDATA format as
> defined in [RFC4034] or as amended/ ?
>
> <mglt>
I believe that only the format would be defined by DNSSEC RFCs and the
usage woudl be defined by our document.
</mglt>

> Second: I was planning on using certificates to secure the control
> channel. The certificate would be linked to the individual HNA.
>
> <mglt>
I think that is a great idea to use certificate instead of raw keys. The
primary reason would be that certificate enables to carry meta
data associated to the key - one of this metada is the CA and overall I
believe that ISPs would be more at ease in managing/accept certificate that
raw keys.
I also believe that certificate will simplify the authentication between
the HNA and the DOI. In fact, it might be the only case where rawkey would
be used to authenticate the HNA. Moving to certificate would provide a
single way to authenticate the client and would not require the TLS library
to support the rawkey authentication.

For keys that are generated by the HNA, building a self-signed certificate
does not add much complexity.
</mglt>

Is there any provision for either downloading the relevant certificate
> given the key data, or for containing the certificate directly in the DHCP
> option?
>
> Thirdly: I know some operators have concerns about "individualising" DHCP
> responses per user, rather than a static "get you configuration here" type
> bootstrap for all users.
>
> Has this concern been discussed with any ISP's and is there an alternative
> method of individualizing the bootstrap process?
>
<mglt>
It seems to be fine to provide an individualized response. In our case I
see the DHCP doing an individual action based on the request. That is good
to get early feed back from ISP. Thanks!
</mglt>

>
> regards,
>
> Daniel Migault wrote on 22/10/2020 15:10:
>
> Hi,
>
> Please find here an update for the DHCP options aiming at configuring the
> Home Naming Authority (HNA). The document has been updated to better
> reflect the changes made on the front-end draft. As the front-end draft
> enables the Distributed Master (DM) and the HNA to agree on some
> configuration parameters, these parameters no longer need to be provided
> via DHCP. As a result, this resulted in simplifying the DHCP options which
> is reflected by the current version.
>
> As always, comments are welcome!
>
> Yours,
> Daniel
>
>
>
>
> ---------- Forwarded message ---------
> From: <internet-drafts@ietf.org>
> Date: Thu, Oct 22, 2020 at 9:04 AM
> Subject: [homenet] I-D Action:
> draft-ietf-homenet-naming-architecture-dhc-options-08.txt
> To: <i-d-announce@ietf.org>
> Cc: <homenet@ietf.org>
>
>
>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the Home Networking WG of the IETF.
>
>         Title           : DHCPv6 Options for Home Network Naming Authority
>         Authors         : Daniel Migault
>                           Ralf Weber
>                           Tomek Mrugalski
>                           Chris Griffiths
>                           Wouter Cloetens
>         Filename        :
> draft-ietf-homenet-naming-architecture-dhc-options-08.txt
>         Pages           : 14
>         Date            : 2020-10-22
>
> Abstract:
>    This document defines DHCPv6 options so any agnostic Homnet Naming
>    Authority (HNA) can automatically proceed to the appropriate
>    configuration and outsource the authoritative naming service for the
>    home network.  In most cases, the outsourcing mechanism is
>    transparent for the end user.
>
>
> The IETF datatracker status page for this draft is:
>
> https://datatracker.ietf.org/doc/draft-ietf-homenet-naming-architecture-dhc-options/
>
> There are also htmlized versions available at:
>
> https://tools.ietf.org/html/draft-ietf-homenet-naming-architecture-dhc-options-08
>
> https://datatracker.ietf.org/doc/html/draft-ietf-homenet-naming-architecture-dhc-options-08
>
> A diff from the previous version is available at:
>
> https://www.ietf.org/rfcdiff?url2=draft-ietf-homenet-naming-architecture-dhc-options-08
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
>
> _______________________________________________
> homenet mailing list
> homenet@ietf.org
> https://www.ietf.org/mailman/listinfo/homenet
>
>
> --
> Daniel Migault
> Ericsson
>
>
> _______________________________________________
> homenet mailing listhomenet@ietf.orghttps://www.ietf.org/mailman/listinfo/homenet
>
>
> --
> regards,
> RayH
>
> <https://www.postbox-inc.com/?utm_source=email&utm_medium=siglink&utm_campaign=reach>
>


-- 
Daniel Migault
Ericsson