Re: [I2nsf] Tsvart last call review of draft-ietf-i2nsf-applicability-13

"Mr. Jaehoon Paul Jeong" <jaehoon.paul@gmail.com> Mon, 22 July 2019 15:02 UTC

Return-Path: <jaehoon.paul@gmail.com>
X-Original-To: i2nsf@ietfa.amsl.com
Delivered-To: i2nsf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 541FC1201D3; Mon, 22 Jul 2019 08:02:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.498
X-Spam-Level:
X-Spam-Status: No, score=-0.498 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HK_NAME_FM_MR_MRS=1.499, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bipPEKbE7pdK; Mon, 22 Jul 2019 08:02:49 -0700 (PDT)
Received: from mail-wm1-x335.google.com (mail-wm1-x335.google.com [IPv6:2a00:1450:4864:20::335]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2F03C120059; Mon, 22 Jul 2019 08:02:49 -0700 (PDT)
Received: by mail-wm1-x335.google.com with SMTP id 207so35551997wma.1; Mon, 22 Jul 2019 08:02:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=PTTY7FUyd747hDCKIU/x6A0llHduMEZSyaqrMDbNWyc=; b=HbaUqme3NLuzfSPROLJdG15NRVR7i49KnpnFa/8cRwCj3UtQY1bvv1gQ6VO8FNQfb3 l/MTb8QHYJP3o5sb2Taq6avCwsHtwn8S56kgatY2zzSnTL5b4DlTV+dAPQFfygklDEGE y2NyYZyg4RpzkLWcLo3FCHTKHVrT+GLiHvXba15pZT+I9Si/MYLeEkfq8KXkK4p6ECZa XbvFbtg76H5/DAQ1R5sMY0vTdcyOkFFPZ8XivrEQHoPKHlWYHMfr7snhBfVTlz08QqTb AvpBNoXQhFuCWcLcx7+lA3ce919S7Val10CSb5Xc5FtA10y6e61tnnKcB4OXUcP5Ghw8 z5ig==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=PTTY7FUyd747hDCKIU/x6A0llHduMEZSyaqrMDbNWyc=; b=TR7XukUdC/J5NhZxK5ZcCHA+YLUS7LoOElwy3MM/Fpck48TFZR1scvndwJAkKFhL4Q 3iVTLGY2eJ4liaUFwE9XdJ9fXrdQ5GzolDKrKnO+HaJt7tpRzNwyUSRoGUxsVIpL7DzI N/QtMgQPkIsALNp5WPUl9WitHjBLLBjawUlmGUevXv/WvvEJlopg8wzVH98LdlYxbGXx KERx4QSqGyo31r86PQH6UPas1lx+jXJWXKoWcuUauDm2OLZEXZZZfOImi8AzA2hbjPNU FQR5EHHAbVwYKDbOtdyy+1AK4UDlcuUL0Es5zXKJsRjdoLRO1c5QulZbFPFnkfE3eGBy 8aZA==
X-Gm-Message-State: APjAAAVmxP9dcfSKqjnlGR3lyTxcNe7FEHZTGywidnpYQJTUy/A7VMk6 b+IR3hwHlMMK8+dgEQchaY6cZgtceaggjx/NeMM=
X-Google-Smtp-Source: APXvYqwD5TC8tquHAy8xZ0nV4ebL3teJ/oHFHaXRTgi4cV4vfGkZCk7Vslh2xsb5smqWC2EZSKS9Hpbm8rVYT7+OwyE=
X-Received: by 2002:a1c:63d7:: with SMTP id x206mr65098899wmb.19.1563807767447; Mon, 22 Jul 2019 08:02:47 -0700 (PDT)
MIME-Version: 1.0
References: <156218558317.14631.14734667974826685969@ietfa.amsl.com> <CAPK2DeyHVq5UbzcE0BMDC94TPOmgGERGWjy+8PdCman+XfRZKw@mail.gmail.com> <20190722040501.GQ99187@kduck.mit.edu>
In-Reply-To: <20190722040501.GQ99187@kduck.mit.edu>
From: "Mr. Jaehoon Paul Jeong" <jaehoon.paul@gmail.com>
Date: Mon, 22 Jul 2019 11:02:10 -0400
Message-ID: <CAPK2DewR7-T6gYUYL-gAfyPQWYzsyP0hofiFMK=CWZnVcf9RJg@mail.gmail.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: Tommy Pauly <tpauly@apple.com>, skku_iotlab_seminar@googlegroups.com, IETF Discussion <ietf@ietf.org>, "i2nsf@ietf.org" <i2nsf@ietf.org>, skku_secu-brain_all@googlegroups.com, draft-ietf-i2nsf-applicability.all@ietf.org, tsv-art@ietf.org, "Mr. Jaehoon Paul Jeong" <jaehoon.paul@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000079cd83058e465e08"
Archived-At: <https://mailarchive.ietf.org/arch/msg/i2nsf/9Rhx5V75-7-0jM6zCt0WKf8C1OU>
Subject: Re: [I2nsf] Tsvart last call review of draft-ietf-i2nsf-applicability-13
X-BeenThere: i2nsf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "*I2NSF: Interface to Network Security Functions mailing list*" <i2nsf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i2nsf/>
List-Post: <mailto:i2nsf@ietf.org>
List-Help: <mailto:i2nsf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jul 2019 15:02:52 -0000

Hi Ben,
Thanks for your clarification.

I will reflect your comments in the revision as follows:

OLD:
   Thus, the IP address(es) corresponding to the target URL
   needs to be obtained from the certificate in TLS versions prior to
   1.3 [RFC8446] or the Server Name Indication (SNI) in a TCP-session
   packet in TLS.

NEW:
   Thus, the IP address(es) corresponding to the target URL
   needs to be obtained from the certificate in TLS versions prior to
   1.3 [RFC8446] or the Server Name Indication (SNI) in a TCP-session
   packet in TLS versions without the encrypted SNI [tls-esni].
...
   [tls-esni] Rescorla, E., Oku, K., Sullivan, N., and C. Wood,
   "Encrypted Server Name Indication for TLS 1.3",
   draft-ietf-tls-esni-04 (work in progress), July 2019.

Is this change fine to you?

If it is okay to you, I will submit the revised version.

Thanks.

Best Regards,
Paul



On Mon, Jul 22, 2019 at 12:05 AM Benjamin Kaduk <kaduk@mit.edu> wrote:

> On Sun, Jul 21, 2019 at 01:18:29AM -0400, Mr. Jaehoon Paul Jeong wrote:
> > Hi Tommy,
> > I have reflected all your comments on version -14:
> > https://tools.ietf.org/html/draft-ietf-i2nsf-applicability-14
> >
> > I answer your comments one by one with an attached revision letter.
> >
> > If you have comments on this revision, please let me know.
>
> I see that in several places the new text refers to "obtained from the
> certificate in TLS versions prior to 1.3 [RFC8446] or the Server Name
> Indication (SNI) in a TCP-session packet in TLS", but as Tommy attempted to
> note, when draft-ietf-tls-esni becomes available, even the SNI value will
> be encrypted and not visible to the network.
>
> -Ben
>


-- 
===========================
Mr. Jaehoon (Paul) Jeong, Ph.D.
Associate Professor
Department of Software
Sungkyunkwan University
Office: +82-31-299-4957
Email: jaehoon.paul@gmail.com, pauljeong@skku.edu
Personal Homepage: http://iotlab.skku.edu/people-jaehoon-jeong.php
<http://cpslab.skku.edu/people-jaehoon-jeong.php>