Re: [Ideas] [E] Spencer Dawkins' Yes on charter-ietf-ideas-00-00: (with COMMENT)

Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com> Mon, 11 September 2017 19:17 UTC

Return-Path: <spencerdawkins.ietf@gmail.com>
X-Original-To: ideas@ietfa.amsl.com
Delivered-To: ideas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4A51A132ED5; Mon, 11 Sep 2017 12:17:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.698
X-Spam-Level:
X-Spam-Status: No, score=-2.698 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JLWpuv_A4slI; Mon, 11 Sep 2017 12:17:25 -0700 (PDT)
Received: from mail-yw0-x235.google.com (mail-yw0-x235.google.com [IPv6:2607:f8b0:4002:c05::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D2023132F2F; Mon, 11 Sep 2017 12:17:24 -0700 (PDT)
Received: by mail-yw0-x235.google.com with SMTP id r85so23729594ywg.1; Mon, 11 Sep 2017 12:17:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=DEP+cxLEBJMMwKbBUEQapic6VnZp8lLRheRl4SGL4Y4=; b=XwgZmlguBbYMoL2sfznOxujHAOHp+0OucZE1P526CVyjeNk5/5L7t7015POfC3228S w1MYNVAlzE0JpYBDq8JoHaOGmKquDZwjsHS/aJzlHpNb2yszoF8VCLWG6yEqyiGxrli+ pOYJ2ZZsexP6owftTbkKUNhFReJqW0VK7Fq07hbmfvyuEgyW3fd569yULHMJv6LXdFL0 QzOOALqRpv5RArMYxoQeITpdSi7Tvi5yrpzmqKutUVzUcnaqezRVBtCaFcLcpFwvouUI 2BbXJiKRW+qeBFGUNJiKXIIFrEowRpXDCrzhKYuqjU+XOxbqSZdHuOpYBhKAt5pAUhVl o4VA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=DEP+cxLEBJMMwKbBUEQapic6VnZp8lLRheRl4SGL4Y4=; b=D6ePfj4KnDNbETJ4uEK1rleNN+WEVn+ngz43GOq6SqJPhyAI74Q1vjDWnDIpCutDKL UAqeY201VWF83I3VGEkzKu900XBXeMSkyX1n9zq85QIhuJH4qB1dxO2g2eiTPRNeXvQ6 ErXNOYepz80aVKjcLW7oTlSsY9BNWN8YcOzZ/fFr2bqtfX1epmx69HuIIEbYE/q66ubi u73BF2kdo3/cVnggJ8M0oljvHRokQ8qYaJgo6dE06fsy9LhkPcMBpTlJaga2Km2NUSNS vyb1eHTSIj1EgBONqaFegqsAv/RQzlncC8JuUBA0jaddd/bpJKfZ+8mUoQUr/hDhMcHb MCdA==
X-Gm-Message-State: AHPjjUjHJUlaC1TcmQWj6j8sn+ahTghiafdaxJ+dfu7tdsqiNCe2bg0M da4iXAa/B+T5lQ6j5gWMd+TaOtoySw==
X-Google-Smtp-Source: ADKCNb4fgj/zipgR9q01JEj+ZgzSj2meW9l8oc/vP3kDs5STdrQOvl3zjPo1MhMOpjN32GfAgYsGcHVYtIId15jvQe4=
X-Received: by 10.129.169.134 with SMTP id g128mr3926862ywh.57.1505157443989; Mon, 11 Sep 2017 12:17:23 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.2.15 with HTTP; Mon, 11 Sep 2017 12:17:23 -0700 (PDT)
In-Reply-To: <44fc229a947949199a2506f532b7a801@scwexch12apd.uswin.ad.vzwcorp.com>
References: <150490809267.17244.96544246533076816.idtracker@ietfa.amsl.com> <44fc229a947949199a2506f532b7a801@scwexch12apd.uswin.ad.vzwcorp.com>
From: Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com>
Date: Mon, 11 Sep 2017 14:17:23 -0500
Message-ID: <CAKKJt-fipwWsDWO3UsOzoeZx+hPZEgzdw14BpVTNH2jwheX3Hg@mail.gmail.com>
To: "Bogineni, Kalyani" <Kalyani.Bogineni@verizonwireless.com>
Cc: The IESG <iesg@ietf.org>, "aretana@cisco.com" <aretana@cisco.com>, "ideas@ietf.org" <ideas@ietf.org>, "ideas-chairs@ietf.org" <ideas-chairs@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c13cb78c7b6860558eec612"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ideas/wn1klR2AVkIlkBKT7zAA4rg4pvc>
Subject: Re: [Ideas] [E] Spencer Dawkins' Yes on charter-ietf-ideas-00-00: (with COMMENT)
X-BeenThere: ideas@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussions relating to the development, clarification, and implementation of control-plane infrastructures and functionalities in ID enabled networks." <ideas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ideas>, <mailto:ideas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ideas/>
List-Post: <mailto:ideas@ietf.org>
List-Help: <mailto:ideas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ideas>, <mailto:ideas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Sep 2017 19:17:27 -0000

Hi, Kalyani,

On Mon, Sep 11, 2017 at 1:55 PM, Bogineni, Kalyani <
Kalyani.Bogineni@verizonwireless.com> wrote:

> charter-ietf-ideas-00-00: Yes
> We support standardizing the mapping system and control plane protocols.
>

I'm sorry, but I don't understand this as a response to whether security
analysis at the framework level is in scope for IDEAS?

Thanks,

Spencer


>
> Kalyani Bogineni
> Verizon
>
> -----Original Message-----
> From: Ideas [mailto:ideas-bounces@ietf.org] On Behalf Of Spencer Dawkins
> Sent: Friday, September 08, 2017 6:02 PM
> To: The IESG
> Cc: aretana@cisco.com; ideas@ietf.org; ideas-chairs@ietf.org
> Subject: [E] [Ideas] Spencer Dawkins' Yes on charter-ietf-ideas-00-00:
> (with COMMENT)
>
> Spencer Dawkins has entered the following ballot position for
> charter-ietf-ideas-00-00: Yes
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
>
>
> The document, along with other ballot positions, can be found here:
> https://urldefense.proofpoint.com/v2/url?u=https-3A__
> datatracker.ietf.org_doc_charter-2Dietf-2Dideas_&d=DwICAg&c=
> udBTRvFvXC5Dhqg7UHpJlPps3mZ3LRxpb6__0PomBTQ&r=
> IdiSODh8aDRjdCeGgd9Mzr2tsDA8-g976yWB1sPbdMo&m=4iTQevao0FvmGJ2lQosFV_
> brUjdjM9g2wGBLFxgT5Fs&s=w6TJbOQo5YtxXCLwzLkvFZmbH9XAyByGSWycK2md3Hs&e=
>
>
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> If only "Yes, but ..." was a position I could select ...
>
> I'm really glad to see this going forward - enough to ballot "Yes".
>
> This looks like a framework that could be used in a number of use cases,
> and my "Yes, but ..." is that it's not clear to me, how much analysis of
> ID/Loc separation security implications that some folks downstream are
> going to have to do, when using this framework.
>
> I'm remembering an exchange with a document editor on the last telechat
> that could be summarized as "we didn't do the work on general security
> implications of X, so each usage of X has to do that work itself, rather
> than pointing to previous work". OK, if that's where we are, but IDEAS
> hasn't already done the same thing (yet).
>
> I'm looking at deliverables like "Requirements for identity authentication
> and authorization service (for GRIDS)" and "Threat model document", so I
> know there's SOMEthing in there, but I don't know what else might be
> required, if someone wanted to think about the general security
> implications of GRIDS, and I note that those deliverables are listed as
> living drafts or wiki entries, which doesn't sound like anything GRIDS
> framework usages would be able to point to, when they need to look at
> security implications.
>
> Is a look at general security implications, in a form that specific
> framework usages can point to, on the table for IDEAS?
>
> (It doesn't have to be, for me to ballot Yes, but I did have to ask,
> right?)
>
>
> _______________________________________________
> Ideas mailing list
> Ideas@ietf.org
> https://urldefense.proofpoint.com/v2/url?u=https-3A__www.
> ietf.org_mailman_listinfo_ideas&d=DwICAg&c=udBTRvFvXC5Dhqg7UHpJlPps3mZ3LR
> xpb6__0PomBTQ&r=IdiSODh8aDRjdCeGgd9Mzr2tsDA8-g976yWB1sPbdMo&m=
> 4iTQevao0FvmGJ2lQosFV_brUjdjM9g2wGBLFxgT5Fs&s=
> t9wokY80pZ8u3yVsBlAumHv46uTMT6LWzptTTFlFlys&e=
>