Re: [Ideas] Fwd: Fwd: Re: WG Review: IDentity Enabled Networks (ideas)

"Templin, Fred L" <Fred.L.Templin@boeing.com> Mon, 02 October 2017 17:08 UTC

Return-Path: <Fred.L.Templin@boeing.com>
X-Original-To: ideas@ietfa.amsl.com
Delivered-To: ideas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DAA7A133052; Mon, 2 Oct 2017 10:08:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level:
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9r1iHaRTQqXu; Mon, 2 Oct 2017 10:08:55 -0700 (PDT)
Received: from phx-mbsout-01.mbs.boeing.net (phx-mbsout-01.mbs.boeing.net [130.76.184.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 750D8133039; Mon, 2 Oct 2017 10:08:55 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by phx-mbsout-01.mbs.boeing.net (8.14.4/8.14.4/DOWNSTREAM_MBSOUT) with SMTP id v92H8sVb062315; Mon, 2 Oct 2017 10:08:54 -0700
Received: from XCH15-06-08.nw.nos.boeing.com (xch15-06-08.nw.nos.boeing.com [137.136.238.222]) by phx-mbsout-01.mbs.boeing.net (8.14.4/8.14.4/UPSTREAM_MBSOUT) with ESMTP id v92H8lMt061866 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=OK); Mon, 2 Oct 2017 10:08:47 -0700
Received: from XCH15-06-08.nw.nos.boeing.com (2002:8988:eede::8988:eede) by XCH15-06-08.nw.nos.boeing.com (2002:8988:eede::8988:eede) with Microsoft SMTP Server (TLS) id 15.0.1320.4; Mon, 2 Oct 2017 10:08:47 -0700
Received: from XCH15-06-08.nw.nos.boeing.com ([137.136.238.222]) by XCH15-06-08.nw.nos.boeing.com ([137.136.238.222]) with mapi id 15.00.1320.000; Mon, 2 Oct 2017 10:08:47 -0700
From: "Templin, Fred L" <Fred.L.Templin@boeing.com>
To: Tom Herbert <tom@herbertland.com>
CC: Christian Huitema <huitema@huitema.net>, The IESG <iesg@ietf.org>, "ideas@ietf.org" <ideas@ietf.org>
Thread-Topic: [Ideas] Fwd: Fwd: Re: WG Review: IDentity Enabled Networks (ideas)
Thread-Index: AQHTO5b1XXR8U7Y2UkCpxQHITCbUoqLQumHAgAB6ewD//4r3YIAAeuGA//+LOjCAAHk2AP//ixKA
Date: Mon, 02 Oct 2017 17:08:46 +0000
Message-ID: <9215a0fba5bf4a8dabf85ed457237ae2@XCH15-06-08.nw.nos.boeing.com>
References: <e476f817-580b-9083-48bb-72de1745f1c1@huitema.net> <67067a23-bb7f-08e4-3766-8802d8f3121f@huitema.net> <45e8993a73ef4bb9b3914f32c4609823@XCH15-06-08.nw.nos.boeing.com> <CALx6S35GKkW1GzSDA2qPx9SJWUfGE23SC4gct3H7eg=EUixgCA@mail.gmail.com> <3a9cf74ba67d4222b1c543d8bfccfe20@XCH15-06-08.nw.nos.boeing.com> <a456a012-8baf-0c24-de1c-90f0a17b4f67@huitema.net> <c849f4452b574931a6010784711a2b26@XCH15-06-08.nw.nos.boeing.com> <CALx6S36h_w7hesVLEhyKKHx-iW8sE_-RzGoQepAR_k8x92XgLA@mail.gmail.com>
In-Reply-To: <CALx6S36h_w7hesVLEhyKKHx-iW8sE_-RzGoQepAR_k8x92XgLA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [137.136.248.6]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-TM-AS-MML: disable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ideas/kTPphoaZLAfD__hQmYHmWs1wsqw>
Subject: Re: [Ideas] Fwd: Fwd: Re: WG Review: IDentity Enabled Networks (ideas)
X-BeenThere: ideas@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussions relating to the development, clarification, and implementation of control-plane infrastructures and functionalities in ID enabled networks." <ideas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ideas>, <mailto:ideas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ideas/>
List-Post: <mailto:ideas@ietf.org>
List-Help: <mailto:ideas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ideas>, <mailto:ideas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Oct 2017 17:08:57 -0000

Hi Tom,

> -----Original Message-----
> From: Tom Herbert [mailto:tom@herbertland.com]
> Sent: Monday, October 02, 2017 10:04 AM
> To: Templin, Fred L <Fred.L.Templin@boeing.com>
> Cc: Christian Huitema <huitema@huitema.net>; The IESG <iesg@ietf.org>; ideas@ietf.org
> Subject: Re: [Ideas] Fwd: Fwd: Re: WG Review: IDentity Enabled Networks (ideas)
> 
> On Mon, Oct 2, 2017 at 9:55 AM, Templin, Fred L
> <Fred.L.Templin@boeing.com> wrote:
> > Hi Christian,
> >
> >
> >
> >>Fred, that's the kind of statements that really give me pause. "Let's do
> >> something dangerous
> >
> >> on my network because it is well isolated and secure." I am pretty sure
> >> that the gentle folks at
> >
> >> Equifax were thinking along similar lines.
> >
> >
> >
> > Understood, but for the Aeronautical Telecommunications Network (ATN) it
> > really
> >
> > is secured at the lower layers and has to be that way. There are no
> > connections to the
> >
> > open Internet, and there can be no opportunity for rogue ATCs to come in and
> > start
> >
> > giving orders to airplanes. This is true whether/not there is a Loc/ID split
> > architecture
> >
> Fred,
> 
> That may be true for your use case, but we can never define IETF
> protocols on the basis that something at a lower layer will secure
> them.

IPv6 Neighbor Discovery [RFC4861] is a prominent example of an
IETF protocol that relies on lower layer security.

Thanks - Fred

> Tom