Re: [Ideas] Kathleen Moriarty's Block on charter-ietf-ideas-00-03: (with BLOCK)

Robert Moskowitz <rgm-ietf@htt-consult.com> Fri, 29 September 2017 15:49 UTC

Return-Path: <rgm-ietf@htt-consult.com>
X-Original-To: ideas@ietfa.amsl.com
Delivered-To: ideas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D5D01331C1; Fri, 29 Sep 2017 08:49:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KCpzed0vN93j; Fri, 29 Sep 2017 08:49:13 -0700 (PDT)
Received: from z9m9z.htt-consult.com (z9m9z.htt-consult.com [50.253.254.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C497E1331D7; Fri, 29 Sep 2017 08:49:13 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by z9m9z.htt-consult.com (Postfix) with ESMTP id 913F36235F; Fri, 29 Sep 2017 11:49:11 -0400 (EDT)
X-Virus-Scanned: amavisd-new at htt-consult.com
Received: from z9m9z.htt-consult.com ([127.0.0.1]) by localhost (z9m9z.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 9NK3BVcTWnBl; Fri, 29 Sep 2017 11:49:07 -0400 (EDT)
Received: from lx120e.htt-consult.com (unknown [192.168.160.12]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by z9m9z.htt-consult.com (Postfix) with ESMTPSA id A64BA6235C; Fri, 29 Sep 2017 11:49:05 -0400 (EDT)
To: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>, "Alvaro Retana (aretana)" <aretana@cisco.com>
Cc: "ideas@ietf.org" <ideas@ietf.org>, "ideas-chairs@ietf.org" <ideas-chairs@ietf.org>, The IESG <iesg@ietf.org>
References: <150660583574.13768.16265986360409791782.idtracker@ietfa.amsl.com> <9942C847-93A9-4B7A-B5AE-6975E30581FB@cisco.com> <CAHbuEH4+5T+k54J-0vjK7Ng06mFP4KFw5_85rDirgMKqb4rEtQ@mail.gmail.com>
From: Robert Moskowitz <rgm-ietf@htt-consult.com>
Message-ID: <ade9ae43-4206-d1c8-56f8-2b60d8cda76e@htt-consult.com>
Date: Fri, 29 Sep 2017 11:48:51 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <CAHbuEH4+5T+k54J-0vjK7Ng06mFP4KFw5_85rDirgMKqb4rEtQ@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ideas/woiVN5ikSQEdgvX8ja4tjAQ6Mww>
Subject: Re: [Ideas] Kathleen Moriarty's Block on charter-ietf-ideas-00-03: (with BLOCK)
X-BeenThere: ideas@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Discussions relating to the development, clarification, and implementation of control-plane infrastructures and functionalities in ID enabled networks." <ideas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ideas>, <mailto:ideas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ideas/>
List-Post: <mailto:ideas@ietf.org>
List-Help: <mailto:ideas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ideas>, <mailto:ideas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Sep 2017 15:49:17 -0000

Thank you Kathleen.  To me this was such a given, that I did not even 
consider it to put into the charter.

My bad.

What work I have personally done in this direction was to use HIP as the 
meta-data transport so it was protected.  But in this more 'open' 
approach, it will have to be more expllicit.

Bob

On 09/28/2017 10:05 AM, Kathleen Moriarty wrote:
> Thanks, Alvaro!
>
> I think that would be a big improvement, but maybe adding in the word
> requirements so that it sticks a bit more in the resulting work.  How
> about:
>
> - Security analysis of the complete system, including authentication,
> authorization requirements and protection of any metadata.
>
> On Thu, Sep 28, 2017 at 10:02 AM, Alvaro Retana (aretana)
> <aretana@cisco.com> wrote:
>> Hi Kathleen!
>>
>> I agree.  Do you want to suggest something, or would something line this be ok:
>>
>> - Security analysis of the complete system, including authentication, authorization and protection of any metadata.
>>
>> Thanks!
>>
>> Alvaro.
>>
>>
>> On 9/28/17, 9:37 AM, "Kathleen Moriarty" <Kathleen.Moriarty.ietf@gmail.com> wrote:
>>
>> ----------------------------------------------------------------------
>> BLOCK:
>> ----------------------------------------------------------------------
>>
>> I'd like to see an explicit mention of security in the charter text itself in
>> terms of how the metadata will be protected or that it will be protected in
>> some way.   While the threats draft is helpful, the WG should be bound to
>> consider security and provide it with this identifier/locator service.
>>
>>
>>
>
>