Re: [IPsec] [Nav6tf] Announcing the USGv6 Testing Meeting at NIST

"Latif LADID \(\"The New Internet based on IPv6\"\)" <latif@ladid.lu> Thu, 22 April 2010 16:42 UTC

Return-Path: <latif@ladid.lu>
X-Original-To: ipsec@core3.amsl.com
Delivered-To: ipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8CDC628C0EE; Thu, 22 Apr 2010 09:42:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.046
X-Spam-Level:
X-Spam-Status: No, score=0.046 tagged_above=-999 required=5 tests=[AWL=-0.045, BAYES_05=-1.11, HTML_MESSAGE=0.001, J_CHICKENPOX_12=0.6, J_CHICKENPOX_32=0.6]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MLCX4h2HPEqP; Thu, 22 Apr 2010 09:42:01 -0700 (PDT)
Received: from mailout4.pt.lu (mailout4.pt.lu [195.46.255.246]) by core3.amsl.com (Postfix) with ESMTP id 90D383A6900; Thu, 22 Apr 2010 09:41:59 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AjcFAHwZ0EvCmsBU/2dsb2JhbACBP492inJxiCK4NQKCc4IaBIZP
X-IronPort-AV: E=Sophos; i="4.52,257,1270418400"; d="scan'208,217"; a="51445838"
Received: from webhost1.pt.lu ([194.154.192.84]) by smtp.pt.lu with ESMTP/TLS/DHE-RSA-AES256-SHA; 22 Apr 2010 18:41:47 +0200
Received: from IPv6ForumPC (ip-88-207-169-205.dyn.luxdsl.pt.lu [88.207.169.205] (may be forged)) (authenticated bits=0) by webhost1.pt.lu with ESMTP id o3MGfgFc007686; Thu, 22 Apr 2010 18:41:45 +0200
From: "Latif LADID (\"The New Internet based on IPv6\")" <latif@ladid.lu>
To: "'Davis, Terry L'" <terry.l.davis@boeing.com>, "'Frankel, Sheila E.'" <sheila.frankel@nist.gov>, ipsec@ietf.org, ipv6@ietf.org
References: <D7A0423E5E193F40BE6E94126930C49307A0C19C47@MBCLUSTER.xchange.nist.gov> <020601cae224$9ab391c0$d01ab540$@lu> <0267B5481DCC474D8088BF4A25C7F1DF5516235A2A@XCH-NW-05V.nw.nos.boeing.com>
In-Reply-To: <0267B5481DCC474D8088BF4A25C7F1DF5516235A2A@XCH-NW-05V.nw.nos.boeing.com>
Date: Thu, 22 Apr 2010 18:41:39 +0200
Message-ID: <027301cae23a$b1592370$140b6a50$@lu>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0274_01CAE24B.74E1F370"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: Acrgnico98ik2GHIRGmPrMP7EVsXWAAsi+sgADTzSyAAArx+YAACgoxg
Content-Language: en-gb
X-Seen-By: scanner3.pt.lu
X-Mailman-Approved-At: Thu, 22 Apr 2010 09:59:25 -0700
Cc: "'Whitlock, Stephen'" <stephen.whitlock@boeing.com>, ipv6ready-tech@ipv6ready.org, nav6tf@ipv6forum.com, members@ipv6forum.com, tim.polk@nist.gov
Subject: Re: [IPsec] [Nav6tf] Announcing the USGv6 Testing Meeting at NIST
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 22 Apr 2010 16:42:07 -0000

Terry,

 

You touch a core issue of the he IPv6 Ready Logo program.

 

The v6RL Phase II (Logo) includes IPsec interop testing.

 

Though we have stayed away at this staged from mandating IPsec per RFC to
give industry the time to put its arms around IPv6 issues first,

there a dozen of products that tested IPsec succesfully: 

 

http://cf.v6pc.jp/logo_db/approved_list_ph2.php

 

We have not yet defined Phase III which could include IPsec mandated. Now,
we need to carefully define the test profiles.

 

This needs a serious discussion before moving forward.

 

Cheers

Latif 

 

 

From: nav6tf-bounces@ipv6forum.com [mailto:nav6tf-bounces@ipv6forum.com] On
Behalf Of Davis, Terry L
Sent: 22 April 2010 18:06
To: 'Latif LADID ("The New Internet based on IPv6")'; 'Frankel, Sheila E.';
ipsec@ietf.org; ipv6@ietf.org
Cc: Whitlock, Stephen; ipv6ready-tech@ipv6ready.org; nav6tf@ipv6forum.com;
'tim.polk@nist.gov'
Subject: Re: [Nav6tf] Announcing the USGv6 Testing Meeting at NIST

 

Sheila

Like Latif said, THANK YOU!

As you know from the Seattle meeting with aviation industry representatives
and the vendor community last fall, the Internet security protocols'
interoperability is a key lynchpin in being able to ensure that the next
generation of Internet enabled aircraft can establish secure communications
in the global aviation environment.  Aviation continues to be concerned that
current IPv4 versions of IPsec, IKE, and IKEv2 still have  vendor-to-vendor
compatibility issues that would be difficult for us to overcome in a fully
heterogeneous global environment.  In our environment, an aircraft is
continually making and breaking security associations between different
service providers and air traffic management entities as it transverses from
country to country and continent to continent.  Thus our environment
requires a very high degree of confidence in the ability of our systems to
dynamically re-establish secure links with these new entities.

We would encourage that interoperability testing fully include versions of
IPSec, IKE, and IKEv2 to ensure these issues do not continue with IPv6 on
which the next generations of global air traffic management will reply on
(ICAO Document 9896).  The testing ideally should demonstrate a vendor's
system's ability to establish links with other vendors systems with minimal
time and effort for setup and link customization as the ease-of-use and
ease-of-deployment will be critical for a global aviation infrastructure.

Unfortunately I will be unable to attend as I will in ICAO meetings that
week, part of which will focus on these same issues.

Take care

Terry L Davis, P.E 
Boeing Technical Fellow 

Aircraft Network and Security, Architecture & Strategy 
Engineering Core - Avionics 
Boeing Commercial Airplanes 

Phone:  206-280-3716 
Email:   Terry.L.Davis@Boeing.com 

PS:  It would also seem likely that the other CI sectors would have similar
IPv6 security interoperability needs.




> -----Original Message-----
> From: nav6tf-bounces@ipv6forum.com
> [mailto:nav6tf-bounces@ipv6forum.com] On Behalf Of Latif
> LADID ("The New Internet based on IPv6")
> Sent: Thursday, April 22, 2010 7:04 AM
> To: 'Frankel, Sheila E.'; IPSec@ietf.org; ipv6@ietf.org
> Cc: ipv6ready-tech@ipv6ready.org; nav6tf@ipv6forum.com
> Subject: Re: [Nav6tf] Announcing the USGv6 Testing Meeting at NIST
>
> Thanks Sheila! Good to see you working on IPv6 so vigorously
> recalling our
> days of work on IPsec back in 99.
>
> I have Copied the North American v6 Task Force members and
> the IPv6 Ready
> logo program team.
>
> Cheers
> Latif
>
> -----Original Message-----
> From: ipv6-bounces@ietf.org [mailto:ipv6-bounces@ietf.org] On
> Behalf Of
> Frankel, Sheila E.
> Sent: 21 April 2010 14:46
> To: ipsec@ietf.org; ipv6@ietf.org
> Subject: Announcing the USGv6 Testing Meeting at NIST
>
> Announcing the USGv6 Testing Meeting at NIST.
>
> To be held on Thursday May 20th 2010 in the AML Conference Room,
> Building 215 Room C103, from 9am till 5pm.
>
> Following publication of the USG Profile NIST has established
> a testing
> program to determine products' compliance to USGv6
> capabilities. There
> are at present 2 accreditors and 2 accredited test
> laboratories enrolled
> in the program, with more test laboratories in consideration.
>  July 2010
> marks the date when USG Federal Agencies begin to make IT
> acquisitions
> using the USGv6 profile version 1.0.  We wanted to host a
> public meeting
> to give:
>     - a review of how the testing program is operating.
>     - an opportunity for feedback from Stakeholders, including test
> laboratories, product vendors and USG Agencies.
>
> Accordingly we seek discussion inputs to include:
>     - statements from accredited and prospective test laboratories.
>     - statements/questions and issues from Agencies and users.
>     - statements, questions and issues from USGv6 product vendors.
>
> Issues are expected to include:
>     - testing operations and interlaboratory comparisons.
>     - USGv6 capabilities and requirements.
>     - Suppliers Declaration of Conformity.
>
> There will also be some discussion of the forthcoming USGv6 profile
> version 2.  A full Agenda will be posted to signed up
> attendees closer
> to the day of the meeting.  Due to room size limitations
> there can be a
> maximum of about 70 participants at this meeting, and attendance from
> any one company may need to be limited. Reply to
> usgv6-project@antd.nist.gov if you wish to participate, giving full
> name, company affiliation, title, contact details and whether
> you are a
> U.S. citizen. Please also let us know if you have issues you wish to
> present, with a maximum of 2 or 3 slides, and speaking time limited
> depending on the response.
>
> For further information, please contact Stephen Nightingale
> (night@nist.gov)
>
>
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> --------------------------------------------------------------------
>
> _______________________________________________
> Nav6tf mailing list
> Nav6tf@ipv6forum.com
> http://lists.ipv6forum.com/mailman/listinfo/nav6tf
>