Re: [Int-area] Logging Recommendations for Internet-Facing Servers

Suresh Krishnan <suresh.krishnan@ericsson.com> Tue, 17 June 2014 21:17 UTC

Return-Path: <suresh.krishnan@ericsson.com>
X-Original-To: int-area@ietfa.amsl.com
Delivered-To: int-area@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E0B21A0174 for <int-area@ietfa.amsl.com>; Tue, 17 Jun 2014 14:17:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.601
X-Spam-Level:
X-Spam-Status: No, score=-1.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id raQijB8vh-15 for <int-area@ietfa.amsl.com>; Tue, 17 Jun 2014 14:17:32 -0700 (PDT)
Received: from usevmg21.ericsson.net (usevmg21.ericsson.net [198.24.6.65]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6EBA31A0170 for <int-area@ietf.org>; Tue, 17 Jun 2014 14:17:32 -0700 (PDT)
X-AuditID: c6180641-f79df6d000002de0-2a-53a05cdb4b7d
Received: from EUSAAHC002.ericsson.se (Unknown_Domain [147.117.188.78]) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id 13.21.11744.BDC50A35; Tue, 17 Jun 2014 17:20:59 +0200 (CEST)
Received: from [142.133.113.185] (147.117.188.8) by smtps-am.internal.ericsson.com (147.117.188.78) with Microsoft SMTP Server (TLS) id 14.3.174.1; Tue, 17 Jun 2014 17:17:30 -0400
Message-ID: <53A0B06C.1090604@ericsson.com>
Date: Tue, 17 Jun 2014 17:17:32 -0400
From: Suresh Krishnan <suresh.krishnan@ericsson.com>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.1.1
MIME-Version: 1.0
To: S Moonesamy <sm+ietf@elandsys.com>, Juan-Carlos Zú ñiga <JuanCarlos.Zuniga@InterDigital.com>
References: <6.2.5.6.2.20140616024123.0ba53310@elandnews.com> <787AE7BB302AE849A7480A190F8B9330018425@OPEXCLILM23.corporate.adroot.infra.ftgroup> <8292A630AF4BC647B64BBD509738820909462E3F@GAALPA1MSGUSRAF.ITServices.sbc.com> <6.2.5.6.2.20140617112211.0bb1a980@elandnews.com>
In-Reply-To: <6.2.5.6.2.20140617112211.0bb1a980@elandnews.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [147.117.188.8]
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrBLMWRmVeSWpSXmKPExsUyuXSPn+7tmAXBBnOPWVrcmHWTxeLdgalM Flda1S1e9d9kdWDxeNk/h9Hj3puPTB5Llvxk8lh6vY01gCWKyyYlNSezLLVI3y6BK+No0we2 gnv8FZueTmFrYFzF08XIySEhYCLR9PYJM4QtJnHh3no2EFtI4CijxP39fF2MXED2dkaJvYu+ giV4BbQl+nesYQGxWQRUJWZv6mYHsdmABm3Y+ZkJxBYVCJNovzCTGaJeUOLkzCcsIINEBDoY JR7+esEIkmAWcJD4cHIZWIOwgLdE68XlrBDbJjJJTLl8AaiDg4NTwE5i1vJMiHpbiQtzrrNA 2PIS29/OYYa4VFNi65rvrBAfKEq8OP6TaQKj0Cwku2chaZ+FpH0BI/MqRo7S4tSy3HQjw02M wKA+JsHmuINxwSfLQ4wCHIxKPLwPPBcEC7EmlhVX5h5ilOZgURLn1ayeFywkkJ5YkpqdmlqQ WhRfVJqTWnyIkYmDU6qBccULPf7C8PxQpU0Bnae/qKcvn7bd41FCcsmWrwaqu0+fT740fdH9 GVcOLxKwz2ad27JYtpspyNRAoCFwxuYVoo+rLbTmKGXaxM+I9o882cC35MPDB7Orm+0LDm+/ zraGobbqpPT//G6WHeuuL7i3lo/7UZa/9qPO2UVb/q/aF68otjg10W6uvBJLcUaioRZzUXEi AOF87B1LAgAA
Archived-At: http://mailarchive.ietf.org/arch/msg/int-area/AxBeAIARiGpHGIykyQGUON11G4k
Cc: Scott Sheppard <Scott.Sheppard@att.com>, int-area@ietf.org
Subject: Re: [Int-area] Logging Recommendations for Internet-Facing Servers
X-BeenThere: int-area@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF Internet Area Mailing List <int-area.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/int-area>, <mailto:int-area-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/int-area/>
List-Post: <mailto:int-area@ietf.org>
List-Help: <mailto:int-area-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/int-area>, <mailto:int-area-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Jun 2014 21:17:33 -0000

Hi SM,

On 06/17/2014 02:58 PM, S Moonesamy wrote:
> Hi Suresh, Juan-Carlos,
> At 07:36 17-06-2014, SHEPPARD, SCOTT wrote:
>> To close this for now.
>>
>> I see no compelling reason to change the BCP RFC 6302.
>>
>> Privacy is important. But equally so is the need to protect our
>> customers, ourselves and the population against cyber criminals and
>> they are legion. There is a compelling need for Law Enforcement
>> Agencies and Governments to know some information about traffic as it
>> relates to criminal and military acts (state sponsored cyber espionage
>> etc.,). It is up to the civil authorities to define what is
>> "acceptable reach" for the above agencies actions. It is up to us as
>> citizens to then hold the civil authorities accountable at least in
>> the US.
>>
>> This is far beyond an IETF discussion.
>
> The following in an excerpt of a message posted by the IAB Chair to
> ietf@ietf.org in 2013:
>
>   "1.  The IETF is willing to respond to the pervasive surveillance attack?
>
>        Overwhelming YES.  Silence for NO.
>
>    2. Pervasive surveillance is an attack, and the IETF needs to adjust
> our threat model
>       to consider it when developing standards track specifications.
>
>       Very strong YES.  Silence for NO."
>
> Some persons raised concerns about those hums.  I would not ignore the
> concerns of those persons or argue that they have to agree to the
> excerpt quoted above.  There was a four-weeks Last Call for RFC 7258.
> Several persons raised concerns about the document.  I would not argue
> that they have to agree to RFC 7258.
>
> I would like to have your opinion about which points (see quoted
> message) are appropriate or inappropriate for INTAREA discussion.

As intarea was the wg that produced RFC6302, any discussions regarding 
issues you want to bring up regarding that document are perfectly 
appropriate on this mailing list. Please go ahead and continue the 
discussion.

Thanks
Suresh