Re: [Int-area] Logging Recommendations for Internet-Facing Servers

"SHEPPARD, SCOTT" <ss6667@att.com> Mon, 16 June 2014 13:50 UTC

Return-Path: <ss6667@att.com>
X-Original-To: int-area@ietfa.amsl.com
Delivered-To: int-area@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FFBA1A0029 for <int-area@ietfa.amsl.com>; Mon, 16 Jun 2014 06:50:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.851
X-Spam-Level:
X-Spam-Status: No, score=-4.851 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.651] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 98T2hqwVg73O for <int-area@ietfa.amsl.com>; Mon, 16 Jun 2014 06:49:50 -0700 (PDT)
Received: from nbfkord-smmo06.seg.att.com (nbfkord-smmo06.seg.att.com [209.65.160.94]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 865521A002E for <int-area@ietf.org>; Mon, 16 Jun 2014 06:49:48 -0700 (PDT)
Received: from unknown [144.160.229.23] (EHLO alpi154.enaf.aldc.att.com) by nbfkord-smmo06.seg.att.com(mxl_mta-7.2.1-0) with ESMTP id cf5fe935.2b3fcd52b940.5812738.00-2428.16256132.nbfkord-smmo06.seg.att.com (envelope-from <ss6667@att.com>); Mon, 16 Jun 2014 13:49:48 +0000 (UTC)
X-MXL-Hash: 539ef5fc32cb6db6-96d68df8195a3eb297ad1ec0ddf92d4e98bf51ac
Received: from unknown [144.160.229.23] (EHLO alpi154.enaf.aldc.att.com) by nbfkord-smmo06.seg.att.com(mxl_mta-7.2.1-0) over TLS secured channel with ESMTP id ce5fe935.0.5812569.00-2068.16255615.nbfkord-smmo06.seg.att.com (envelope-from <ss6667@att.com>); Mon, 16 Jun 2014 13:49:46 +0000 (UTC)
X-MXL-Hash: 539ef5fa7be8114b-6b4fad43cd460e0e0125dbc3575a2d8cd97d64b5
Received: from enaf.aldc.att.com (localhost [127.0.0.1]) by alpi154.enaf.aldc.att.com (8.14.5/8.14.5) with ESMTP id s5GDnW0p000650; Mon, 16 Jun 2014 09:49:32 -0400
Received: from alpi133.aldc.att.com (alpi133.aldc.att.com [130.8.217.3]) by alpi154.enaf.aldc.att.com (8.14.5/8.14.5) with ESMTP id s5GDnR8J000600 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 16 Jun 2014 09:49:28 -0400
Received: from GAALPA1MSGHUB9D.ITServices.sbc.com (GAALPA1MSGHUB9D.itservices.sbc.com [130.8.36.90]) by alpi133.aldc.att.com (RSA Interceptor); Mon, 16 Jun 2014 13:49:20 GMT
Received: from GAALPA1MSGUSRAF.ITServices.sbc.com ([169.254.6.40]) by GAALPA1MSGHUB9D.ITServices.sbc.com ([130.8.36.90]) with mapi id 14.03.0174.001; Mon, 16 Jun 2014 09:49:20 -0400
From: "SHEPPARD, SCOTT" <ss6667@att.com>
To: S Moonesamy <sm+ietf@elandsys.com>, Alain Durand <adurand@juniper.net>, Igor Gashinsky <igor@yahoo-inc.com>, Donn Lee <donn@fb.com>, Scott Sheppard <Scott.Sheppard@att.com>
Thread-Topic: Logging Recommendations for Internet-Facing Servers
Thread-Index: AQHPiUhYOawrDqtSa0WGCiVbPeYIxZtzwIUw
Date: Mon, 16 Jun 2014 13:49:20 +0000
Message-ID: <8292A630AF4BC647B64BBD5097388209094628A5@GAALPA1MSGUSRAF.ITServices.sbc.com>
References: <6.2.5.6.2.20140616024123.0ba53310@elandnews.com>
In-Reply-To: <6.2.5.6.2.20140616024123.0ba53310@elandnews.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [135.70.236.152]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-RSA-Inspected: yes
X-RSA-Classifications: public
X-AnalysisOut: [v=2.0 cv=OMyQK1mB c=1 sm=1 a=VXHOiMMwGAwA+y4G3/O+aw==:17 a]
X-AnalysisOut: [=Ug-TAP4kQqYA:10 a=ofMgfj31e3cA:10 a=hgubIOLJz70A:10 a=BLc]
X-AnalysisOut: [eEmwcHowA:10 a=kj9zAlcOel0A:10 a=zQP7CpKOAAAA:8 a=XIqpo32R]
X-AnalysisOut: [AAAA:8 a=wPPvXI8NAAAA:8 a=48vgC7mUAAAA:8 a=6h9VOnCHJl68XYS]
X-AnalysisOut: [HBhMA:9 a=CjuIK1q_8ugA:10 a=DswvqmXAlqEA:10 a=6twC2c18jGIA]
X-AnalysisOut: [:10 a=2mDhba3wg4UA:10 a=7Nb30phM6KoA:10 a=JedbxzJ0HZAA:10 ]
X-AnalysisOut: [a=Hz7IrDYlS0cA:10 a=pOcSzP0BEVkA:10 a=lZB815dzVvQA:10]
X-Spam: [F=0.2000000000; CM=0.500; S=0.200(2014051901)]
X-MAIL-FROM: <ss6667@att.com>
X-SOURCE-IP: [144.160.229.23]
Archived-At: http://mailarchive.ietf.org/arch/msg/int-area/3rmdWrlJ2MSrczCU2y8jJVxOAWg
X-Mailman-Approved-At: Tue, 17 Jun 2014 07:58:59 -0700
Cc: Linus Nordberg <linus@nordberg.se>, "int-area@ietf.org" <int-area@ietf.org>
Subject: Re: [Int-area] Logging Recommendations for Internet-Facing Servers
X-BeenThere: int-area@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF Internet Area Mailing List <int-area.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/int-area>, <mailto:int-area-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/int-area/>
List-Post: <mailto:int-area@ietf.org>
List-Help: <mailto:int-area-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/int-area>, <mailto:int-area-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jun 2014 13:50:04 -0000

Hello

Can you be more specific in your concern?
" there has been some  concerns about RFC 6302"

I am willing to have a go but more focused guidance is needed here. 

Peace


Scott Sheppard
LMTS AT&T ATS
IPNSG 
404 499 5539 desk
732 861 3383 cell
ss6667@att.com email

Two messages
Authentic power is service - Pope Francis 
Sillyness is Essential - The Three Stooges
Both are important 

This e-mail and any files transmitted with it are the property
Of the AT&T companies, are confidential, and are intended solely
For the use of the individual or entity to whom this e-mail is 
Addressed. If you are not the one of the named recipients or 
Otherwise have reason to believe that you have received this
Message in error, please notify the sender at (732) 420-0965 and 
Delete this message immediately from your computer. Any other
Use, retention, dissemination, forwarding, printing, or copying
Of this e-mail is strictly prohibited.




-----Original Message-----
From: S Moonesamy [mailto:sm+ietf@elandsys.com] 
Sent: Monday, June 16, 2014 5:48 AM
To: Alain Durand; Igor Gashinsky; Donn Lee; Scott Sheppard
Cc: int-area@ietf.org; Linus Nordberg
Subject: Logging Recommendations for Internet-Facing Servers

Hello,

In the wake of the revelations about surveillance there has been some 
concerns about RFC 6302.  I would be grateful if the authors of RFC 
6302 could review the comments at 
http://www.ietf.org/mail-archive/web/ietf-privacy/current/msg00454.html 
and provide some feedback.

Regards,
S. Moonesamy