Re: [I2nsf] I-D Action: draft-ietf-i2nsf-registration-interface-dm-00.txt

"Diego R. Lopez" <diego.r.lopez@telefonica.com> Sun, 21 October 2018 05:58 UTC

Return-Path: <diego.r.lopez@telefonica.com>
X-Original-To: i2nsf@ietfa.amsl.com
Delivered-To: i2nsf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C472F130E67 for <i2nsf@ietfa.amsl.com>; Sat, 20 Oct 2018 22:58:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.064
X-Spam-Level:
X-Spam-Status: No, score=-2.064 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.064, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=telefonica.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bn0H0oHbO4QL for <i2nsf@ietfa.amsl.com>; Sat, 20 Oct 2018 22:58:30 -0700 (PDT)
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (mail-ve1eur01on0112.outbound.protection.outlook.com [104.47.1.112]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96798126DBF for <i2nsf@ietf.org>; Sat, 20 Oct 2018 22:58:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telefonica.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=opyXaCiWGSbDuO7Uh2yXLAlbvbfCFG1N7e+acaiN5Mc=; b=it5hPytXD8BtaEM5uRq4Ads6EuRQZFBHNgePMsH31+SUhPzY8R30F2p9T/UXMin/ayfTLKmvvzo+opd7CrxmhzDfzjXCTsxDtHCt06I/1N/nXJdN0ikzihbHC/TzyfTn7FcIvHDC8vRnu72acnv5wyx24jmFhVx0e2QQtQTBhNg=
Received: from DB3PR0602MB3788.eurprd06.prod.outlook.com (52.134.70.148) by DB3PR0602MB3756.eurprd06.prod.outlook.com (52.134.71.160) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1228.26; Sun, 21 Oct 2018 05:58:26 +0000
Received: from DB3PR0602MB3788.eurprd06.prod.outlook.com ([fe80::7469:d759:740d:7c53]) by DB3PR0602MB3788.eurprd06.prod.outlook.com ([fe80::7469:d759:740d:7c53%2]) with mapi id 15.20.1250.028; Sun, 21 Oct 2018 05:58:26 +0000
From: "Diego R. Lopez" <diego.r.lopez@telefonica.com>
To: "i2nsf@ietf.org" <i2nsf@ietf.org>
Thread-Topic: [I2nsf] I-D Action: draft-ietf-i2nsf-registration-interface-dm-00.txt
Thread-Index: AQHUaLD5N74ie+oMKUuwsRGwgkCEjqUpVkuA
Date: Sun, 21 Oct 2018 05:58:26 +0000
Message-ID: <1167C929-704F-49AC-9E8C-86652EABFAD9@telefonica.com>
References: <154006619405.13838.11436642111446191940@ietfa.amsl.com>
In-Reply-To: <154006619405.13838.11436642111446191940@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.10.3.181015
x-originating-ip: [212.145.127.19]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DB3PR0602MB3756; 6:JcfBGYvJGLmZkVp1xmfcX/o1fB0b4C/9K0zWxnm2pbc6sf7QXwuoEQu28H3T6I/+8uu35HEpzcKi1YXgImucQkMBtlN15AdO5tVeSk8YWSwZIKZPstnb1ndYn/XsL+t1LhemkRk4Xpy6SFsK6p6X+3pija8QugD8OZYUGQpuEjOT64ZyqqiwDf3VFjfjmpRKRS7FWQw61vSqo64xwcO3hWRNUDxiuiaC2IVn2pp5ViGqdUlhD99pgeTQgYvWo0/Srvm+01LSWs5+XA7KWkfFBFaarWV1FprGZGqgzkDNRuDjL8+NpYDOH0JhwyLmkog/NUvpMoaP4NB6ATCYCUBSX4nRTao0FvyaXzeJc+Yo3qOcHjEmNFSxqBCcVQQzWXOPOM4UF8vNPokr42tTgOWzoXwuPJQLF6g3EcVhd22acFNTD32VA6rjk15ApYw4FHmYp43BSJzJXjGBI3i1JLDulg==; 5:Jh39El6eyBPMybSwPWrRRK41GOSabup8iSI/eTNsbjy2EGwBzStMERk/GpCyR7B2bolRTKIo07DZwcWcfb6ERj68Y//pytWeRhlR2ornyzbGXBkqnDH4SAdCW7K1mRawY/63GYYB0M+DncTBoA2RqV88aKj5MiDDKYP9rxmr2gI=; 7:DUwc4KplP1+1G2IiQURYoT49MI1UISPFIG+dalk5EFLIRHED8NF0jjZI2sJI5kuYDerKd22M++SYc27lH9KPFdUX5iuZa0BeiwwyRylDPqJkRebxK0WZRM/xmvMonvmnwZhhVIQN/d+GzcdlNZJW8kcVDbo6S8GDVq91aReZX7Bf8p61RTRfK0yhlVbdUjS/ZVB13Fo2q8XYvk/wpJbgNVFMd9vowdOyoJeJMG4cDo8JgclY6Nb9fniLI7gc+ozu
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: 5a93680b-f329-462f-2f7e-08d6371a37c3
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989299)(5600074)(711020)(4618075)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7153060)(7193020); SRVR:DB3PR0602MB3756;
x-ms-traffictypediagnostic: DB3PR0602MB3756:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=diego.r.lopez@telefonica.com;
x-microsoft-antispam-prvs: <DB3PR0602MB37563E0F6C5CF978BF1C7B59DFFB0@DB3PR0602MB3756.eurprd06.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(128460861657000)(81160342030619)(40392960112811)(192374486261705)(120809045254105)(163750095850);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(5005006)(8121501046)(3231355)(944501410)(52105095)(10201501046)(93006095)(93001095)(3002001)(6055026)(148016)(149066)(150057)(6041310)(20161123558120)(20161123560045)(201703131423095)(201702281529075)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123562045)(201708071742011)(7699051)(76991095); SRVR:DB3PR0602MB3756; BCL:0; PCL:0; RULEID:; SRVR:DB3PR0602MB3756;
x-forefront-prvs: 083289FD26
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(366004)(376002)(346002)(136003)(396003)(39860400002)(252514010)(40134004)(189003)(199004)(25724002)(486006)(102836004)(3846002)(6116002)(7736002)(36756003)(2900100001)(14454004)(966005)(33656002)(53936002)(66574009)(71190400001)(786003)(316002)(83716004)(6512007)(6916009)(71200400001)(6306002)(58126008)(478600001)(5640700003)(5660300001)(81166006)(81156014)(105586002)(76176011)(106356001)(229853002)(6436002)(82746002)(8676002)(8936002)(99286004)(45080400002)(2351001)(6486002)(2906002)(6506007)(186003)(5250100002)(305945005)(2616005)(11346002)(2501003)(66066001)(6246003)(26005)(25786009)(14444005)(256004)(97736004)(446003)(476003)(4001150100001)(68736007)(86362001); DIR:OUT; SFP:1102; SCL:1; SRVR:DB3PR0602MB3756; H:DB3PR0602MB3788.eurprd06.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: telefonica.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: /e3SoeRuUtFWx6HeV1TjgoWQI7ALbTkYkNSpiJ5JRtVvFM8n4uFr6bxLov6Hga5LrgyoBE5Z5qHbo1i2AxeJds5dw/1EFQVM5UrCXDPV91jLn7rilvpWfECpHfMMQZnrdTs2kVko2FuwFYBouFYEfM2rX/N3GMbMgOTqtERQ+ScvmGHzcmuT39Gjc/2hFN9IxlDH3RIQopmHQvwH7i9vJbz20l8zsqPCr9I9djS3jPjKrQRyMbU4Mv4bTLb5h6EUI6tjhdOaw/WylMFBY6g58oW7266i72n0hHifDWttdXDjFRCYrT5zDLgPExgzgFDR7UudyyzejGcdfiyZEjv0oRDcJd4JdFzhNeLAusmUV1M=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <BAF9E5F64B27B24F8E647F4F80620304@eurprd06.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: telefonica.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 5a93680b-f329-462f-2f7e-08d6371a37c3
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Oct 2018 05:58:26.2469 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB3PR0602MB3756
Archived-At: <https://mailarchive.ietf.org/arch/msg/i2nsf/Z-9Y7MCPUvp4WVVq_KYAFhf35bs>
Subject: Re: [I2nsf] I-D Action: draft-ietf-i2nsf-registration-interface-dm-00.txt
X-BeenThere: i2nsf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "*I2NSF: Interface to Network Security Functions mailing list*" <i2nsf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i2nsf/>
List-Post: <mailto:i2nsf@ietf.org>
List-Help: <mailto:i2nsf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 21 Oct 2018 05:58:34 -0000

Hi,

I've gone through the new version of the Registration Interface mode draft, that does look much better and integrated to me now, and I have a few comments, most of them on the procedures described for using the interface and the connection of Controller and the DMS:

1) First of all, related to terminology: Why do you define the term "NSF Profile"? Why not refer to the "Profile" definition in the terminology document? By referring just to "Profile" I think you can freely use "NSF Profile" later on...

2) The actions described in section 4 seems to imply a direct and dynamic communication between Controller and DMS, when what I foresee is something similar to the onboarding mechanisms in current software-based networks: The DMS uses the registration interface to provide and update the capabilities of those NSFs provided to the Controller, and the Controller makes the appropriate selection once it receives a request from a client, instantiating them from the repository. But by no means a direct dialog between Controller and DMS should be assumed, nor I think we should specify a dynamic instantiation mechanism in this document.

3) The same happens with the process described in section 5. We should change this into a decoupled register-select-instantiate operation sequence. And, BTW, what do you mean by "a specific NSF required or *wasted* in the current system"? Wasted by whom and how?

4) Following this, the instantiation and deinstantaiation operations described in 5.1 should not be used. What is more, I'd say they are out of the scope of this document, and while mechanisms for instance management could be generally mentioned, they should not be described in detail here.

5) And a question on the access information described in section 5.3: should it not include a reference to the mechanisms to secure the access, like encryption, reference to certificates or key repositories, etc. I am not asking for storing credentials, but at least to let the Controller know that IPsec using certificates approved by a particular CA should be used, for example.

Be goode,

 --
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez
Telefonica I+D
https://www.linkedin.com/in/dr2lopez/

e-mail: diego.r.lopez@telefonica.com
Tel:         +34 913 129 041
Mobile:  +34 682 051 091
----------------------------------

On 20/10/2018, 22:10, "I2nsf on behalf of internet-drafts@ietf.org" <i2nsf-bounces@ietf.org on behalf of internet-drafts@ietf.org> wrote:


    A New Internet-Draft is available from the on-line Internet-Drafts directories.
    This draft is a work item of the Interface to Network Security Functions WG of the IETF.

            Title           : I2NSF Registration Interface Data Model
            Authors         : Sangwon Hyun
                              Jaehoon Paul Jeong
                              Taekyun Roh
                              Sarang Wi
                              Jung-Soo Park
    Filename        : draft-ietf-i2nsf-registration-interface-dm-00.txt
    Pages           : 23
    Date            : 2018-10-20

    Abstract:
       This document defines an information model and a YANG data model for
       Interface to Network Security Functions (I2NSF) Registration
       Interface between Security Controller and Developer's Management
       System (DMS).  The objective of these information and data models is
       to support NSF search, instantiation and registration according to
       required security capabilities via I2NSF Registration Interface.


    The IETF datatracker status page for this draft is:
    https://datatracker.ietf.org/doc/draft-ietf-i2nsf-registration-interface-dm/

    There are also htmlized versions available at:
    https://tools.ietf.org/html/draft-ietf-i2nsf-registration-interface-dm-00
    https://datatracker.ietf.org/doc/html/draft-ietf-i2nsf-registration-interface-dm-00


    Please note that it may take a couple of minutes from the time of submission
    until the htmlized version and diff are available at tools.ietf.org.

    Internet-Drafts are also available by anonymous FTP at:
    ftp://ftp.ietf.org/internet-drafts/

    _______________________________________________
    I2nsf mailing list
    I2nsf@ietf.org
    https://www.ietf.org/mailman/listinfo/i2nsf



________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição