Re: [Iot-onboarding] draft-garciamorchon-t2trg-automated-iot-security-00

"Garcia-Morchon O, Oscar" <oscar.garcia-morchon@philips.com> Mon, 26 November 2018 15:52 UTC

Return-Path: <oscar.garcia-morchon@philips.com>
X-Original-To: iot-onboarding@ietfa.amsl.com
Delivered-To: iot-onboarding@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C2B5012D4EA; Mon, 26 Nov 2018 07:52:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.46
X-Spam-Level:
X-Spam-Status: No, score=-3.46 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.46, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=philips.com header.b=m97/V52F; dkim=pass (1024-bit key) header.d=philips.com header.b=m97/V52F
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id blnhAeIksx9i; Mon, 26 Nov 2018 07:52:00 -0800 (PST)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04on070b.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0c::70b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BA5C7128D68; Mon, 26 Nov 2018 07:51:59 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=philips.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jzZjroIZKpZHaCSIPJmRvNPpBRdno6RTAu9HbK8xgSk=; b=m97/V52Fgl0Xw846W6/S4gdApknqwwBdkXaoamXIXNzPrJ7ixjVUtZgRe6jsSdgaPa8AN5eE8WAoBxrQMlITUgwq0vV9FynEfG1RBK0FknXpDGYK3TSzZoE4f31t9rG8uz1fUoUFIGfMhzgNSMyH/pqvLu9zLC3QHN5DM2eYECs=
Received: from AM3P122CA0003.EURP122.PROD.OUTLOOK.COM (2603:10a6:221:2::17) by AM3P122MB0020.EURP122.PROD.OUTLOOK.COM (2603:10a6:221:2::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1361.19; Mon, 26 Nov 2018 15:51:57 +0000
Received: from HE1EUR01FT029.eop-EUR01.prod.protection.outlook.com (2a01:111:f400:7e1f::203) by AM3P122CA0003.outlook.office365.com (2603:10a6:221:2::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1361.18 via Frontend Transport; Mon, 26 Nov 2018 15:51:57 +0000
Authentication-Results: spf=softfail (sender IP is 52.211.17.155) smtp.mailfrom=philips.com; sandelman.ca; dkim=pass (signature was verified) header.d=philips.com;sandelman.ca; dmarc=pass action=none header.from=philips.com;
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning philips.com discourages use of 52.211.17.155 as permitted sender)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (52.211.17.155) by HE1EUR01FT029.mail.protection.outlook.com (10.152.0.155) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_RSA_WITH_AES_256_CBC_SHA256) id 15.20.1339.10 via Frontend Transport; Mon, 26 Nov 2018 15:51:56 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=philips.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=jzZjroIZKpZHaCSIPJmRvNPpBRdno6RTAu9HbK8xgSk=; b=m97/V52Fgl0Xw846W6/S4gdApknqwwBdkXaoamXIXNzPrJ7ixjVUtZgRe6jsSdgaPa8AN5eE8WAoBxrQMlITUgwq0vV9FynEfG1RBK0FknXpDGYK3TSzZoE4f31t9rG8uz1fUoUFIGfMhzgNSMyH/pqvLu9zLC3QHN5DM2eYECs=
Received: from VI1P122MB0109.EURP122.PROD.OUTLOOK.COM (20.176.11.20) by VI1P122MB0064.EURP122.PROD.OUTLOOK.COM (129.75.142.91) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1361.19; Mon, 26 Nov 2018 15:51:52 +0000
Received: from VI1P122MB0109.EURP122.PROD.OUTLOOK.COM ([fe80::38a4:381c:9d43:929e]) by VI1P122MB0109.EURP122.PROD.OUTLOOK.COM ([fe80::38a4:381c:9d43:929e%8]) with mapi id 15.20.1361.019; Mon, 26 Nov 2018 15:51:52 +0000
From: "Garcia-Morchon O, Oscar" <oscar.garcia-morchon@philips.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, "draft-garciamorchon-t2trg-automated-iot-security@ietf.org" <draft-garciamorchon-t2trg-automated-iot-security@ietf.org>, "t2trg@irtf.org" <t2trg@irtf.org>
CC: "iot-onboarding@ietf.org" <iot-onboarding@ietf.org>
Thread-Topic: draft-garciamorchon-t2trg-automated-iot-security-00
Thread-Index: AQHUgO1mj9Jjuw2B7U6S9Mp35eMR3qViTs2A
Date: Mon, 26 Nov 2018 15:51:52 +0000
Message-ID: <BDE13F49-82C3-4CFC-94BF-8996E4E85C8F@philips.com>
References: <580.1542731003@localhost>
In-Reply-To: <580.1542731003@localhost>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.12.0.181008
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=oscar.garcia-morchon@philips.com;
x-originating-ip: [2a02:a450:cb83:1:79af:591a:56b7:ec86]
x-ms-publictraffictype: Email
x-ms-exchange-antispam-srfa-diagnostics: SOS;
X-MS-Office365-Filtering-Correlation-Id: 1e7e836c-e61f-4c82-798c-08d653b717fd
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam-Untrusted: BCL:0; PCL:0; RULEID:(2390098)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600074)(711020)(4618075)(2017052603328)(7153060)(7193020); SRVR:VI1P122MB0064;
X-MS-TrafficTypeDiagnostic: VI1P122MB0064:|AM3P122MB0020:
x-detectorid: 129eaf33-3aaf-4ff1-b782-ae61f80ca9eb
X-Microsoft-Antispam-PRVS: <AM3P122MB0020CA46401BE706510B1A92C8D70@AM3P122MB0020.EURP122.PROD.OUTLOOK.COM>
X-MS-Exchange-SenderADCheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(93006095)(93001095)(3231443)(944501410)(52105112)(10201501046)(3002001)(6055026)(148016)(149066)(150057)(6041310)(20161123564045)(20161123560045)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(20161123562045)(201708071742011)(7699051)(76991095); SRVR:VI1P122MB0064; BCL:0; PCL:0; RULEID:; SRVR:VI1P122MB0064; BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(10201501046)(93006095)(93005095)(3002001)(3231443)(944501410)(52105112)(6055026)(148016)(149066)(150057)(6041310)(20161123558120)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(20161123560045)(20161123564045)(20161123562045)(201708071742011)(7699051)(76991095); SRVR:AM3P122MB0020; BCL:0; PCL:0; RULEID:; SRVR:AM3P122MB0020;
x-forefront-prvs: 086831DFB4
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10019020)(39860400002)(136003)(346002)(396003)(366004)(376002)(189003)(199004)(374574003)(55904004)(6246003)(14454004)(68736007)(4326008)(6486002)(81166006)(82746002)(8676002)(8936002)(15650500001)(81156014)(6436002)(106356001)(105586002)(305945005)(229853002)(97736004)(6116002)(25786009)(36756003)(53936002)(186003)(46003)(2906002)(33656002)(83716004)(316002)(71190400001)(71200400001)(86362001)(58126008)(110136005)(508600001)(99286004)(256004)(14444005)(2501003)(486006)(2616005)(476003)(446003)(11346002)(6512007)(7736002)(6506007)(5660300001)(102836004)(76176011); DIR:OUT; SFP:1102; SCL:1; SRVR:VI1P122MB0064; H:VI1P122MB0109.EURP122.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: philips.com does not designate permitted sender hosts)
X-Microsoft-Antispam-Message-Info-Original: oM/22FGtVT7SyxHu4eNUJUZMVl8wngULGLinyC11PeMGvBZPwTu//GHwCoM6pL9beLh866BiMeCTJytQdqBSmh8o0AvoOaL0ZqB3u/2dxlh+FbfpZO8aKljJgXTDgULsbRan2JCu1lTPHJzbd3T7aKugECbetLTtIMaynJxfy2K0nd+QOdwosLrt8N3mJSbPSatcYntsZHt4swhU2K7sIjQMKBGZ2FCXdN1tYeT9t+wDPgjm7fPWfRefk+eOSl6wIUEGKBp0nuGoN+0JZ0P/pQ5z4wPiTS0NSt9Nr1E89Ncf423fa/qiWdgpiuvPv1gkioua7gxPPhxyI1Ki5FNErROu2lRGH94OqLIHRRY98Q8=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <E30FC9033D16034485F7C8D8F6F26D74@EURP122.PROD.OUTLOOK.COM>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1P122MB0064
X-CFilter-Loop: Reflected
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: HE1EUR01FT029.eop-EUR01.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:52.211.17.155; IPV:NLI; CTRY:US; EFV:NLI; SFV:NSPM; SFS:(10019020)(346002)(376002)(136003)(396003)(39860400002)(2980300002)(55904004)(374574003)(199004)(189003)(6506007)(2616005)(105596002)(5660300001)(508600001)(83716004)(106466001)(99286004)(14454004)(23676004)(2486003)(6486002)(55236004)(110136005)(14444005)(476003)(2501003)(446003)(8936002)(336012)(6246003)(25786009)(36756003)(50466002)(82746002)(33656002)(81156014)(8676002)(81166006)(436003)(86362001)(6116002)(356004)(316002)(2906002)(47776003)(6512007)(102836004)(486006)(11346002)(229853002)(7736002)(126002)(15650500001)(305945005)(186003)(76176011)(4326008)(26005)(58126008)(6436002); DIR:OUT; SFP:1102; SCL:1; SRVR:AM3P122MB0020; H:EUR01-DB5-obe.outbound.protection.outlook.com; FPR:; SPF:SoftFail; LANG:en; PTR:eu-west-1b.mta.dlp.protect.symantec.com; A:1; MX:1;
X-Microsoft-Exchange-Diagnostics: 1; HE1EUR01FT029; 1:f/3zgPqbWPYqem8N1gWZ//zC8kbXoapWphGt0GeASbS7wfSVx3uxua0zBpGkahnZtLrysv1oAfPxbvV4OUloYLi0Kla1TS5ggFu6Hfi3S3st9eX3QqdmAsqSj15cX2Dv
X-MS-Office365-Filtering-Correlation-Id-Prvs: 15874157-c2a9-4c3d-ea5e-08d653b715cb
X-Microsoft-Antispam: BCL:0; PCL:0; RULEID:(2390098)(7020095)(4652040)(8989299)(5600074)(710020)(711020)(4608076)(4534185)(7168020)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7167020)(7153060)(7193020); SRVR:AM3P122MB0020;
X-Microsoft-Exchange-Diagnostics: 1; AM3P122MB0020; 3:v0YVjjhlAv+IQwTcUKFMMUNx3wE0fGVsLOaAdpc5JLaSFXBLXFTQpPrRo8G0PLxh7R8ngKzsId4yFjDSWCrBZxENNn1NCv0IaLi23gurC04Ir1M+t6FCzNqurGWi3HAJptHGcvZl9SrCLEwAHEMUdygj2Gkyc7jfujv1bykU6OOond4xbYRR52U1F82GLrMzPYbgCNCm2i5p15FGrjriFLzLtawz8zkoWJQmV87wFmYsHUXq2f0w9ZpboJOoa5lF/pYQSFmdv9j1l2WQDuLg8K2fKsI/1Q5s4kiaUPtdIVs/cOOpEG+I17e6BJD+uD09Cf8Z7PowiEPC25Xb5FuU+dc3Xi8FceqZ9fcSPlJnaCM=; 25:lUM8wDGZykGZotqR/A4PWTE795MZXIgrRjcp3aCB4FRHYDQsI4au08M3Tx9f6F4KvUeQiYHJ9i/aa55i81cstVs7fdWoUV+yRSqCsWPLr1WTkETRkHLrMScgRXNJmcO0G46psQDggZ0Eed0a+sGr/MfHvpfq2iSAYcB7kHdgG1ndzpS599xBEGocb1tLUJX1Jn5rE4fBXaSwi/PT17t3cNyoUSn0OD5KD2kO9OnPwsb5VxUkmOXcSt8xsRSSznUuO1DIypQ10xiC+m5ynxyGNpl4/uuVblaSMJB3/rDr4vB6SsIDDNyhvGz0JJg7k/UFwXQIPzvOSaSeLFauz1YpxA==
X-Microsoft-Exchange-Diagnostics: 1; AM3P122MB0020; 31:oB6tm8syYrF6FBkLmlhnNgHMogYo0Js7fMOJ52nTGr2IID1iPHcPvW3FUw3BdhMYf6g/Pp9WjA2WXMtE7hTJCuW59QfO5qSNEW5nMuzLNG/d9XlyYqosdgBPVYQkYhMyNLMs2T9YYGZPZj2GBCpT+aph+XNfgxV7u79g37IOOHz0g6o+3ADRhxtP9xoTV81rxdnkzBtlUVT4IDRJ8JtW5IBmYrePINvHFvogw5nNrVA=; 20:DzHI9iurv2xRIl1HNUu4QYa7Eey04JQFLl+YarHQECrUDVku6zJWK1dTLCyT5vy+N3fep47qvhoHTcqOEv55jiWc5+vjy2s4Sw8gZn+7C8xYudDNuXulSxT+qrN5fGDwrkEtWPONwKXDn+5lgabwiiRGI9LcYZL5We4v2tb3Thd3APXz4sgA5AWEL1mMvV9ENOL+IJwyAMH/Euob3o66IdfELBIECTm7/M2m4UZOkdnZydDLxYKUQ+UYy7ufXw2/oLf8H0/+6+vzp4qqiDclyECJTKOUxaBUx5mKjeM5GPl62aKkbQfK5QPILjmrRYBI1qDEjJCBwKO9sbMlGkAeGyO4FokS8dhqtiWPYTLfia2eUPkpzz7YbZpDDj64sjUZYBmMy7DMNOQdrgv1M5w0uBMRkRG/f5YxazNTFYSBxw0gJ0BADky4R0rgdALe8x4ctbSgup57HZ0vC8b00PyrKq4a/MQl63K4Sl72vFz4W2zDzdNK/TwoKPN+tDHj2U+R
X-Microsoft-Exchange-Diagnostics: 1; AM3P122MB0020; 4:+g5ih++FPOUIFHMSLy2PerbqbksvCopwpQWWWdP07gG1hFeTVnm29B+5IJmGxwKALdeSM6umdKzasYGQer2OolqaTENER8jSLV5uKJBoxX9KNRwMSlZPAf99qOav/h9fpi2G8IDRaefQCwJStBqTvclgdKwX0q6yzYXsIxdgs68nC7CNJO8V95xOwz6aiDTKMQoZimomQybk3f8NxaT81/Fdo72ff+q/dpLciiyLHVD8Ij2ahE23pvipGQMJ6QIflb7ScdvAyzWnU86lJ1mB/Q==
X-Forefront-PRVS: 086831DFB4
X-Microsoft-Exchange-Diagnostics: 1;AM3P122MB0020;23:mqd4beqJ01LjHG29uJc572eYJy5Dg5MSjgnNkIYMc4Ohc9OJBrs3/j7vrh4p3HX5QWy1mHv6BL5N0mmhS6RPt1UeXoHsQ05h41ZJy2utmYu0oPrvWPHWeh+7Gpa/hzOFZ3qCidsoYpsTQJFHdkSesWMMEosNXDzRl1vkw9RQS/RnuDVYRbTtoGTNy0W93k0lLlzbmyO8Sq1HgErW1QdMiyJn9/vPn3xtJea+tpngauc/wzHeOZOiJRK5ECM45hTTMWtX9gvXmDit49E/Buvapz4/+KivigPbZ9vaIdJQbt/51Uw8fgv6gYLOOa5DH5FFyIXEhm24Z5tdPr2jza1rb+tWjXcn7rVoYDUE1ELg1NgvSFtjB5r15gJD+c78mN2KK7mYBf5vvD/58ZDr1t/qysuOixalFrHS5j6YMN3xlh2lXKc0cZobgMuvL8/iFlvG600TPRTF1shN5VHi83x+AaP9NCOoHci0ihCMeFtU3gYKCQ9UOGxq+DTm3swQB4MwsjxeyKgPmeEt2gVTfPrwMv/cqvoefHfkjeRfma99AfUoICBkW/kwg0TiCEpr6VVfOYnd68h/1MJkwoGSSrPC4RJp2Ps80QmE7Cx9RxHt5oFR4vHXcos55LsyHBPh9kJxT+PlfHGufSRBBynYIrBFEZU0gnpoeeQ56Fu9Io/A1CjjEguUQzuHPK4hvBsHsjxyDq99nJaEHj9ycCa/lOoodk8EJj5/NuHdUpPlSy55v+Hl6qZEQyZWKCSKDPB0v10qVTJSAT4OLWfpcTO+f2S84CB+tuxJqkKGAczrvF397zSeG7/rbqLNlXBH2o/Dj2n9JLFV9aLUozamJ774j3V+OS6oO1fvsajvtHacGhDBc/1/BfU6oJQB1PVHDamZuhHKUUrLWAIkyvxfgMigOfj59CdaRm1u11rK/An2wuIbbTSJ2mfvzKsiPEI5P5I7aCbCocesHleVq11ngcTEmNODZl5WwGT2Fz8f4httTH9FqnexwD3bSp+xsIs94sm8YdtFbXjRwpEtqIyOMfUL00B4wE2maMd98qV131V4PwapKiwOcrMkQ8n4JYyDcGUsRm3nStQoNk71jeNsIJC7LOoy549X4sknqNUqm6dxhOlRV5BqLXTdTwv2KkNDGU+/YA8n2/bD9dorVJEpc8yUzZiap0abivAgFJiEnx5TPkFf6dRcLIrzGwIsSZpKetqBOOBYuUiPoqwa/lEZeuYJgarEQxFKmxMryBDG8mndGXJdPpoezPEQM0haDCynrjet/L4Gjyks2BSqJH9zkYMVzL5jUIKV917lhZjGOYO/tAokKJ228A8BixtPa2x4SqaH8JZ+
X-Microsoft-Antispam-Message-Info: qboaZU98VcDhjelSU2vdc2FOa2J5M8RSf+6ZpKj9kAwyR5G6gq2PmiK8cx5T8K6cCzKc4kiT1WmZyWiDMgJI4J1AqjzCIzf7YhYm2Mad+GxC2T4QuMVgSFazRSL4ENF9+3CcwIrsumzEsQGbGin2N6MMKVjrTbmhh5nB8VscuFhHXisJhQXPVGr6FWLgT//nAvyou4CQJ309VN3JWuYa6CEMTTLzqQdRTIzn9Qef99SPrR6FBs6DQHuoQmEMyXzi61PkcCYYwr/YzVxoXOXNybnjZssvMmRBH4zuNsDJ4PG59SP1o0Xk/Sa0d5muqfCHl1iD+Plk2pviqLjeKQ+3t9RX3qXUhhTENOB5CcFbQ4E=
X-Microsoft-Exchange-Diagnostics: 1; AM3P122MB0020; 6:XynAFD5Q3iC+C4xPFRfckIRs5LHMG/6I0FfR6D3IH/12lIY1GyR7oWNp9j5RUCIIebOz7MgrBlk+2aFa7qQ8uZdqY6Xo/5MOw3Ghc7gQg2AciOGxejMJ2BGwZVVrEPmomMWOQeoBi9I5zrJS8C+hArMbIEnwxJ6jG8c6MGBP7PNzLcgW+imqW/5XbTmdZ8HP4kSTMtgqkuUpTSb6xQyNSrh8XGPqtuOxXQjxv+KbwlCUiL5ZwEdgWS4HpxTL7x7lzyVXQdDAggafVvaS2WDIUbprQUPA3cX51/4y0e7Zoh0fmgEQN659KCBKvtBhBcGz7klgxx+jmDwvHS4KOog966eFwkKKBFZzQlVj6tZROdV3v61i7W9+b6gGX5X6yha01kTZRTFC/B3Mqv1UDF/TFx/iZYSO9a2Yj3g2c9vSUwUV7l71msF6VnvFhW7D80r5FCzpQiNyy0hxX8y1KmvwGA==; 5:PPz4TBRkAVWX0x9MIe/ZHMJlC5hqE0KEn01yhY2OG7bcyIc34wxUGpbhLoe0Q7ydQyHCkHUm7jkR2ZN5pcnn+6CWTveAu4XQId8PVVkLJGrkSMzSUW4mrj7xhs/1iI+PKkG9MlexNaDdQdZUqG0ZisO66RW2opZaAq5HMd+lUME=; 7:TVmfDCv941R+7B4p38nyElJH6Ik/ZbhKPOOkJFJWQ9fs/d3PKgPZeI/2hnFOg5aFFcGN7L35GqmjrOv+PjZy5TDle9bU0WnI8Qly33fRvx6P4zmM5+u05SDe/NImZIryqglfnOM03EyAvyfaz19M2Q==
X-OriginatorOrg: philips.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Nov 2018 15:51:56.1112 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 1e7e836c-e61f-4c82-798c-08d653b717fd
X-MS-Exchange-CrossTenant-Id: 1a407a2d-7675-4d17-8692-b3ac285306e4
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=1a407a2d-7675-4d17-8692-b3ac285306e4; Ip=[52.211.17.155]; Helo=[EUR01-DB5-obe.outbound.protection.outlook.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM3P122MB0020
Archived-At: <https://mailarchive.ietf.org/arch/msg/iot-onboarding/h5ptDZDCiRP2j9G30L-VChMO_FQ>
X-Mailman-Approved-At: Wed, 28 Nov 2018 01:04:41 -0800
Subject: Re: [Iot-onboarding] draft-garciamorchon-t2trg-automated-iot-security-00
X-BeenThere: iot-onboarding@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <iot-onboarding.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/iot-onboarding>, <mailto:iot-onboarding-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/iot-onboarding/>
List-Post: <mailto:iot-onboarding@ietf.org>
List-Help: <mailto:iot-onboarding-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/iot-onboarding>, <mailto:iot-onboarding-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Nov 2018 15:52:04 -0000

Hi,

I read the t2trg automated iot security document.
      draft-garciamorchon-t2trg-automated-iot-security-00
    I read -00, as I guess I started reading before the -01 came out.
    I looked at the diff just now, and I suspect that it's an improvement.

>> Yes. We removed unnecessary details and we tried to highlight the motivation and architecture view. We also tried to show how (a very first version of) such a system can be built.

    I liked the abstract concepts of the PACS and PAVA.

>> Thank you.

    I think it might be important to understand that there isn't a MUD
    "protocol", just a file format.  MUD pointers are carried in a variety of
    other protocols until DHCP, LLDP, BRSKI and even QR codes.

>> Good point. This should be better explained in the document.

    I'm not sure what to do with this document.
    I don't think it defines a protocol that we can implement, but rather a
    conceptual architecture that might guide future protocol work.  It feels like
    it could be a roadmap document for some WG which does not currently exist.

>> Version -01 was written with the goal of describing the problem space and solution direction. It indeed only describes a high-level architecture. We only describe "next steps" in Section 6 where we give some (first) details about how the "high-level architecture" in Section 4 can be instantiated.

    I am not sure that the assessments proposed are feasible in current CPE
    devices that are deployed in homes; but I suppose that the cloud might come
    to the rescue.  However, in order for this to be widely useful the inputs and
    outputs needs to be well defined, and there needs to be a standard format
    for the audit trail of decisions made.   I am reminded of the spamassassin
    explanation of why something is or isn't spam.

>> Yes, if we want to perform any type of (risk/privacy) assessment after deployment, contents and formats need standardization.
>> Here, there will be technical solutions that will be able to cover many use cases, but they will be also (more) complex.  Some solutions require (much) less work and can easily help to improve the security level in IoT systems.

On 20/11/2018, 17:23, "Michael Richardson" <mcr+ietf@sandelman.ca> wrote:


    I read the t2trg automated iot security document.
      draft-garciamorchon-t2trg-automated-iot-security-00
    I read -00, as I guess I started reading before the -01 came out.
    I looked at the diff just now, and I suspect that it's an improvement.

    I liked the abstract concepts of the PACS and PAVA.
    I think it might be important to understand that there isn't a MUD
    "protocol", just a file format.  MUD pointers are carried in a variety of
    other protocols until DHCP, LLDP, BRSKI and even QR codes.

    I'm not sure what to do with this document.
    I don't think it defines a protocol that we can implement, but rather a
    conceptual architecture that might guide future protocol work.  It feels like
    it could be a roadmap document for some WG which does not currently exist.

    I am not sure that the assessments proposed are feasible in current CPE
    devices that are deployed in homes; but I suppose that the cloud might come
    to the rescue.  However, in order for this to be widely useful the inputs and
    outputs needs to be well defined, and there needs to be a standard format
    for the audit trail of decisions made.   I am reminded of the spamassassin
    explanation of why something is or isn't spam.

    --
    Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
     -= IPv6 IoT consulting =-






________________________________
The information contained in this message may be confidential and legally protected under applicable law. The message is intended solely for the addressee(s). If you are not the intended recipient, you are hereby notified that any use, forwarding, dissemination, or reproduction of this message is strictly prohibited and may be unlawful. If you are not the intended recipient, please contact the sender by return e-mail and destroy all copies of the original message.