Re: [IPsec] Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)

"Rob Wilton (rwilton)" <rwilton@cisco.com> Thu, 27 April 2023 10:12 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ADC52C151540; Thu, 27 Apr 2023 03:12:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b="FANt/VSU"; dkim=pass (1024-bit key) header.d=cisco.com header.b="HGbb6rST"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R3tnVjP24OLk; Thu, 27 Apr 2023 03:12:02 -0700 (PDT)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6EC63C14CE4A; Thu, 27 Apr 2023 03:12:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=10400; q=dns/txt; s=iport; t=1682590322; x=1683799922; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=76yahVsetypZPz6mPXOPz2XLJORw98XFpJNlLsSIr4k=; b=FANt/VSUfsIkGIcFRLM7dTFUWE64FUMXEAA+OxZmo7NUWyAig/9IDNbN A+R6NXztcl+H1g/gAsVOgWmhwWZVIcKftyPjXuDaBoAYVC3eZ8MILPiH+ ekRvcvskT0jgbLwCYzwbOySGZgNVuuQ2mLc4CHUdEZRqf8KbjFsLx6NYs w=;
X-IPAS-Result: A0AQAACoSUpkmJxdJa1aHAEBAQEBAQcBARIBAQQEAQFAJYEWBwEBCwGBW1JzAlg8RoghhE6JFwORH4w9FIERA1YPAQEBDQEBRAQBAYUGAoU8AiU0CQ4BAgICAQEBAQMCAwEBAQEBAQMBAQUBAQECAQcEFAEBAQEBAQEBHhkFDhAnhWgNhgMBAQEBAxIuAQE3AQsEAgEIEQQBAS8yHQgCBAENBQgaglwBglwDAaVSAYE/AoogeIE0gQGCCAEBBgQFnyMJgUEBhEmIP4RICB8bgUlEgRVDgmg+gmICgSsBEgEHHIQSgi6MMBELijiBM3KBJ4ExgQQCCQIRa4EQCGWBdEACDWQLDm6BRV9GgXIEAhRCDBdeBHc3A0QdQAMLOzo9NQYOHwUEcYFZBC9AgRMCBAElJJducQEBYgQUDhkYDQcDRiIEAhM9BSgCBAUGKpJRJY5sgTOgbwqDfpsEhh8Xg32MZ4ZrkRJil3ogohYxGQGEdwIEAgQFAg4BB4FjOmtwcBU7gmdSGQ+OIAsOCRWDO495QzI9AgcBCgEBAwmLRQEB
IronPort-PHdr: A9a23:Zdi4ah2iiTnjTvG6smDPZFBlVkEcU/3cJAUZ7N8gk71RN//l9JX5N 0uZ7vJo3xfFXoTevupNkPGe87vhVmoJ/YubvTgcfYZNWR4IhYRenwEpDMOfT0yuBPXrdCc9W s9FUQwt5Gm1ZHBcA922fFjOuju35D8WFA/4MF9vOeXxBonUp8+2zOu1vZbUZlYAiD+0e7gnN Byttk2RrpwPnIJ4I6Atyx3E6ndJYLFQwmVlZBqfyh39/cy3upVk9kxt
IronPort-Data: A9a23:i9uGP6ATukT8GxVW/x/jw5YqxClBgxIJ4kV8jS/XYbTApD0l1jMDz jMZD2nQPqyJZmD2Kd8gPIXj801X6pCGxtNhOVdlrnsFo1CmBibm6XV1Cm+qYkt+++WaFBoPA /02M4WGdIZuJpPljk/F3oLJ9RGQ7onVAOutYAL4EnopH1Q8FH1+0UgLd9MR2+aEv/DoW2thh vuqyyHvEAfNN+lcaz98Bwqr8XuDjdyq0N8qlgVWicNj4Dcyo0Io4Kc3fsldGZdXrr58RYZWT 86bpF2wE/iwEx0FUrtJmZ6jGqEGryK70QWm0hJrt6aebhdqthRv7v0hDMgmSgRXhAmQvs9t8 cpgjMnlIespFvWkdOU1SRJUFWR1OrdLveKBKnmkusvVxErDG5fu66wxVwdtYstJoaAuXD8mG f8wcFjhajiZmOOy3LW9YuJtnc8kasLsOevzv1k8nWCAUqZ8HPgvRY3KxI8bjGkchfxDPq/5d 8sheycoXjv5Nkgn1lA/UcJiw7jAamPEWzxAs1+ejas6/2aVyxZ+uJDsKMHYcdmHAM5Vl0eCv UrH8nj3RBYAO7S3xSCM/G7ph+LTk2b6QJkfH7i1s/dmjBiSxWE7CRAKWx28u/bRok+zQN13K kEI9Gwpt6dayaCwZsP2Uxv9q3mes1tBHdFRCOY9rgqKz8I4/jp1GEAUdmN9M8YehvUVBjwl6 kaogM/QGhFW5ej9pW2myp+Yqja7OC4wJGAEZDMZQQZt3zUFiNxq5v4oZos6eJNZnuEZChmrn G/X9HlWa6E7yJ9Uh//irDgrlhr1/sCRJjPZ8Dk7SY5M0++UTJSua4rt4l/B4LMdao2YVVKG+ nMDnqByDdzi77nQz0Rho81UTNlFAspp1hWH3zaD+LF6rVyQF4aLJ9w43d2HDB4B3jw4UTHoe lTPngha+YVeOnCnBYcuPdLrVp9xnfO4TI60PhwxUjaoSsUuHONg1HwxDXN8I0ix+KTRufhlY MzCIZrE4YgyU/g8kVJauNvxIZdylnxhmgs/tLjwzg+s1vKFdWWJRLIeWGZinchnhJ5oVD79q o4FX+PTkk03eLSnPkH/r9VJRXhUdidTOHwDg5ENHgJ1ClA4SDhJ5j646e5JRrGJaIwMx7uVp SHtBhQIoLc97FWeQTi3hrlYQOqHdb50rGkwOmonOlPA5pTpSd/HAHs3H3fvQYQayQ==
IronPort-HdrOrdr: A9a23:Jj62Qah6rXLKZ9BTJZymFX2IKHBQX3d13DAbv31ZSRFFG/FwyP rBoB1L73DJYWgqNE3IwerwRJVoIUm3yXZ0ibNhWYtKLzOWx1dAS7sSobcKogeQVhEWk9Q96U 4OSdkHNDSdNykZsS++2njELz9C+qjJzEnLv5ak854Fd2gDAMEQjDuRSDzraHGeLzM2YqbRYa Dsn/av0ADQH0j/AP7LY0XtWdKvm/T70LbdJTIWDR8u7weDyRmy7qThLhSe1hACFxtS3LYL6w H+4k3Ez5Tml8v+5g7X1mfV4ZgTssDm0MF/CMuFjdVQAinwizyveJ9qV9S5zXAISaCUmRUXee v30lId1vdImjfsl6aO0FzQMjzboXQTArnZuBmlaDXY0JXErXkBerR8bMpiA2rkAgwbzZ9BOG Yh5RPDi3KRZimwxBgU67XzJmFXv1vxrnw4neEJiXtDFYMYdb9KtIQauFhYCZEaAUvBmcga+c RVfbfhDcxtABqnRmGcunMqzM2nX3w1EBvDSk8eutaN2zwTmHxi1UMXyMEWg39FrfsGOtN5zv WBNr4tmKBFT8cQY644DOAdQdGvAmiIRR7XKmqdLVnuCalCMXPQrJz85qkz+YiRCdc15Yp3nI 6EXEJTtGY0dU6rAcqS3IdT+hSIW2m5VSSF8LAo23G4gMyJeFPGC1z3dLl1qbrSnxw2OLyoZ8 qO
X-Talos-CUID: 9a23:cxK8Em6FNG/gjECb7dss5HZJJps/Sk/n7zTQLHOhKHl1caK4cArF
X-Talos-MUID: 9a23:UUUsuQlf48AXqP9akSeAdnpiFZcrs/qCC3wAsswhq8i8JzE3CRik2WE=
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by rcdn-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 27 Apr 2023 10:12:01 +0000
Received: from rcdn-opgw-3.cisco.com (rcdn-opgw-3.cisco.com [72.163.7.164]) by rcdn-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 33RAC031028914 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 27 Apr 2023 10:12:00 GMT
Authentication-Results: rcdn-opgw-3.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=rwilton@cisco.com; dmarc=pass (p=quarantine dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="5.99,230,1677542400"; d="scan'";a="694993"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=R2tggIQxFghOuWl6vQ8tCw0Sv2hl/FOp98f6UjpEUau4ZeKmty5Etb9vRk5Hw3yXSoAQXIDpzLU70yr2BdybKjJhLMMYNVPQiwYOgEb0tXKsiT5GpkaHHatCyljQ5EuDHEYzT1mI5F8ouS43jq3E56waMJhkx8YOI44GeJF2tWaTAiWf+ZI2yRc7UmH0dEdMSPKLFVZ7WSk8xaZZ9qhYOMayPLtfNuCvuLwXRCmQi2XHErrllPIsxSMRTzI/BmBPf+P4tcrkhnhIxnbcj9utiXhrGzX6B+SqqN5Pn61WaCxwLzhnIUirmnGIt+0gcEC3QiMqXUegltSpuwzoRxajDA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=FvLzU8fbXXtJAAJTpSw8Az0hcuPgTuMZWnSv/7IUXPw=; b=jfFVAKJEQrPpf9VsmctwW32NfPTDjQ7b0lTyF66ET8mFfRLOU3E32LFAafaP9AxTqRFmOLLrLUD1A057UCTpuZFtPFhT8VCVLSppcsyTOmZIwxdEUblA4I8HnEgGADVCHRk1MstAJnKHYkPQH3CcXaBAi7VpmhzWq2HZXTt5qI9nKocDPWYMlfL/zCLFixTnA6CXgHI/uRscnvwrlLqEvbUIvmGp6LTthwDJpFkUOiiQLZJ0nuPi0Ps5mTLnDpy6FEtQspaz27lzAhLj0fLUsN8pGPS4CcI76aI5h7zAvrUTQo0CkMAMhYNMNJr5o8Q6rKKnQRHVxzPAr5G2jN+WlA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FvLzU8fbXXtJAAJTpSw8Az0hcuPgTuMZWnSv/7IUXPw=; b=HGbb6rSTUNTuTe90WjpxPwDtpMSv0K7fxuwTmGma3sWOMXOsK/Y/9VmhCT3/YmhJM1lupfHePJhHSYTk8aZeX3dhxRjjB1zP1+HeBeCRZ0aOqp1RfbxrPbOJe8Ja6+qmzKwByRV/h0ask7GC4MKvO6w8rThcUbR4lQ2dT5x2k+w=
Received: from BY5PR11MB4196.namprd11.prod.outlook.com (2603:10b6:a03:1ce::13) by DM4PR11MB5470.namprd11.prod.outlook.com (2603:10b6:5:39c::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6340.21; Thu, 27 Apr 2023 10:11:57 +0000
Received: from BY5PR11MB4196.namprd11.prod.outlook.com ([fe80::ef4:1432:b69e:19b2]) by BY5PR11MB4196.namprd11.prod.outlook.com ([fe80::ef4:1432:b69e:19b2%7]) with mapi id 15.20.6340.022; Thu, 27 Apr 2023 10:11:57 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, The IESG <iesg@ietf.org>
CC: "draft-ietf-ipsecme-add-ike@ietf.org" <draft-ietf-ipsecme-add-ike@ietf.org>, "ipsecme-chairs@ietf.org" <ipsecme-chairs@ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>, "kivinen@iki.fi" <kivinen@iki.fi>
Thread-Topic: Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)
Thread-Index: AQHZeOluvPxCbHtogUqzlTxvecOD3K8+6PiAgAAEIVA=
Date: Thu, 27 Apr 2023 10:11:57 +0000
Message-ID: <BY5PR11MB41966EEB889CBBBB4DE6A21DB56A9@BY5PR11MB4196.namprd11.prod.outlook.com>
References: <168258716961.30194.4411331064355666357@ietfa.amsl.com> <58988_1682588901_644A44E5_58988_382_1_PAVPR02MB9673870C49FBAA1EDA6A514A886A9@PAVPR02MB9673.eurprd02.prod.outlook.com>
In-Reply-To: <58988_1682588901_644A44E5_58988_382_1_PAVPR02MB9673870C49FBAA1EDA6A514A886A9@PAVPR02MB9673.eurprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SetDate=2023-04-27T09:48:17Z; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Name=Orange_restricted_external.2; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ActionId=3977101b-bcd1-42ba-9096-7abc73ce86c2; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=2
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BY5PR11MB4196:EE_|DM4PR11MB5470:EE_
x-ms-office365-filtering-correlation-id: 38e05160-ab5b-4e73-0309-08db4707d5ad
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: iQMM/qdoPLGX506Z/nOfqw0ycfbfJNQHTYMQJtgzramTalrVXLZ4xQcp4W4ewkBS6CCHouADJkUoKIae4isog66yGxnOqRDVSVcDHwtvKf2Y/I3leOl+5K/kVuq3HLx8q1X7O3r+j2Hqs+gZJnQ/7ZRrxbMYuNr3Fp4nSFlzONol77KCw+y9OB0E6GtJl6hMP9Dx+dwkQOXGzCNkzg+kfdorwUnr503glbVAXZOgajGyKmxugpmAPwvGz6QTUKjW+RRYF5AeAZJBjyaIwaec1ZnbwpLsCil67Aezf+T7ktVZBs7zWU4cEOlJcQcvcrXGkIacDHXY+RmEdkipgMGNM6XY1VP3AFbAkvRGXZ4UxhO5o9LWligtASn7MzfLrU7ocn0Ud81g/B9IllbR56SHHNOG20nxlrO5f6RrfK/ktUDeArHPPqBBCW9I3NqFO8Hzo0SqBrwDfw5mBzq8/0mKIWMZVSDneeZtW6ZeHYIMgIJig4lFd7REgmJ3crjOtYtZJ0mB/zYNvJfq3enb4LvC2G9G3KlaROQx+xJElLMTddEOOUWYe8w6rF1dsOpkGw7gEMGYood/1rlk5FrdskPx6lXGQLqQwGIDEYz4i3p5bGpfPxqITi2RCFH6PCrTOeXj
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY5PR11MB4196.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(39860400002)(366004)(376002)(396003)(136003)(346002)(451199021)(52536014)(2906002)(122000001)(38100700002)(5660300002)(66476007)(66946007)(76116006)(8936002)(66446008)(8676002)(66556008)(64756008)(86362001)(41300700001)(316002)(4326008)(38070700005)(55016003)(6506007)(186003)(9686003)(53546011)(7696005)(71200400001)(66574015)(83380400001)(33656002)(478600001)(54906003)(110136005); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: emfMapgzbqhT6DFrT1MmE2u9lOC0ibHIwIJ453usA0sDLPyJ2DDJa0O0AF4gRUT5MWhULZ+AsY0gwTeNhsCMm9+DAsJJZWL3nvADlxLsQaEZXPuP2qXZ8wwXWO/JUTj7ZGD/6GvGfN0kixV0GtRcivjvVMI5iLqpGz/aUY8BaxhHSU566KyfN0g9bhWUxJ3gbhrELsPDV2fGBwiW/qdRRmyum/4HBtrlrgLwK+TP5j+gVTuJCMKD5yRmGglVnjMwBSo1CqBZP7U9IVvi1kIk6RWUJ+q67e51YPPkNc9obzFAQI0Y3LGkLaMBMSbN6teiq3HI2onS2O6/ss0M4v6W7uISjE1K3lEdD7uvSo8/t1E8d+8dAqaCjnvWt4fu+29XFZK9Td31GETm03gCKl6AB5jNZdc/DvPks8OOLW+za748PFAGPe8vzy0G7r2cViiWqk1QClzI6gdqczxXzYqXvSVso5Os289qKOhZps8cOr2MUsXuyriFJvQuYRcJeONbcq84Au/2FhTzIq3hVhGmhovECm9hq8nXXyKFNdz8sbVWVXfVDd/DbhpeGqXKM31ZtFzgE6LRHvWcfVbx6jBcqtwdJ0jgvBsOrNKCdn8G4dKQ0COCi5kd0Gr75ace8QV0/SzWNyABC9bAUUHc6uw37bjsHo2fUXZtHDIaNqONHiGe0EWIkT7h3X+YpJ5qKHhDADJQLStdMXh4MDC48iY5eBbWayRStGozHOTrsOY4k1OSmomFqS1G6gNx61Wo2JH81S5YXBXGqVAwV9owmc6Szqa9jEc7Bx67CPb7ezO4w1InbBEqILiLJlxoEQ6F1AaTGxFfBVMqT6tQMvYdI9GlZEBuaAIxGLP9Ad00fIsnaP+JFUEijhoJBK8Z6bbwU4K3UTkh+tIVPV0IaWGDQIOS+jIUGqEiAUZlBnJLh5gS5+cVe7hSBPj4A5gy2livIxGgw8sAL8MRQKv+sPvTujNdQqINPwFlTYWcTvXdsmmST3SuBB6QxG/d+DQGK8MQP+hElPn2QrzIyylNq7AR0wi/p3L2hWVT6FxCxZJvqyjOJBbkG3My2G9QkUYUvIq+wiW7L768H7MHKgQ32axWJ8r0AwFFBWuH0T/XalnNSMuPkLAtAEikVvR4ikTtZh2VCCMzG/SDPdStLemrN2phTbi59t2FIPre6FobII10IKkQEcSj0YcuB3fpwUDwqyK4nXy6+u+kvem5MBGT1E8Fel5C+PhpDM3Dbos0TuE1gLjbLzUwWgJlqf82VTYWec30QmXRYYi4HKbAKILK3qFxM3n8EQ178O3WITHEH4V6FoYG5kKStVF973A4A8ikky9/rBTz5u+vVAdFoCg0eCZlULAPwVqvpPQBPXtb9BiQIVuNiIU1/P4fYYZfBZPFZAHYLs9KqTYMqjgwC6cu92J69WCpjiuT6EfD6mtmPPYlclzcxJl+uQSEfNAWmroXGXUR5e/R8eJbD8VXhL4FFwMuGRr0dlA2MQ5aDMQsFQaT8AWPJVuA8vwfC+vQIQBQg1AXRyU4t2x0TrdgLihWUfxQBbsb6AqQMHljo4lh5bJcYf8JKgh+6SGrZzcyogPQk5q3RRYKHM8qmGy/gLblTcTMzLXX2D9BSL0AkicrIYxFFRh/Fq8=
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY5PR11MB4196.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 38e05160-ab5b-4e73-0309-08db4707d5ad
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Apr 2023 10:11:57.7829 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: wym8hzXLnkz8iBXS8Ppz2UgKzmap6LE4ht31I3/Bb7tZ9v7yn3pv6AsAWvZsQfcPHSYRktIuDpwMdjOe+Mc5Kw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR11MB5470
X-Outbound-SMTP-Client: 72.163.7.164, rcdn-opgw-3.cisco.com
X-Outbound-Node: rcdn-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/knGvtoRZkXwKGY_8h7xUc27mx_o>
Subject: Re: [IPsec] Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Apr 2023 10:12:06 -0000

Hi Med,

> -----Original Message-----
> From: mohamed.boucadair@orange.com <mohamed.boucadair@orange.com>
> Sent: 27 April 2023 10:48
> To: Rob Wilton (rwilton) <rwilton@cisco.com>; The IESG <iesg@ietf.org>
> Cc: draft-ietf-ipsecme-add-ike@ietf.org; ipsecme-chairs@ietf.org;
> ipsec@ietf.org; kivinen@iki.fi
> Subject: RE: Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with
> DISCUSS and COMMENT)
> 
> Hi Rob,
> 
> Thanks for the review.
> 
> Please see inline.
> 
> Cheers,
> Med
> 
> 
> Orange Restricted
> 
> > -----Message d'origine-----
> > De : Robert Wilton via Datatracker <noreply@ietf.org>
> > Envoyé : jeudi 27 avril 2023 11:19
> > À : The IESG <iesg@ietf.org>
> > Cc : draft-ietf-ipsecme-add-ike@ietf.org; ipsecme-chairs@ietf.org;
> > ipsec@ietf.org; kivinen@iki.fi; kivinen@iki.fi
> > Objet : Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11:
> > (with DISCUSS and COMMENT)
> >
> > Robert Wilton has entered the following ballot position for
> > draft-ietf-ipsecme-add-ike-11: Discuss
> >
> > When responding, please keep the subject line intact and reply to
> > all email addresses included in the To and CC lines. (Feel free to
> > cut this introductory paragraph, however.)
> >
> > ------------------------------------------------------------------
> > ----
> > DISCUSS:
> > ------------------------------------------------------------------
> > ----
> >
> > Hi,
> >
> > Thanks for this document.
> >
> > This should be a trivial discuss to resolve, and only flagging it
> > as a discuss
> > because I think that it makes the spec unclear (or wrong):
> >
> > (1) p 4, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> >
> >    *  IP Address(es) (variable) - Includes one or more IP
> > addresses that
> >       can be used to reach the encrypted DNS resolver identified
> > by the
> >       Authentication Domain Name.  For ENCDNS_IP4 this field
> > contains
> >       one or more 4-octet IPv4 addresses, and for ENCDNS_IP6 this
> > field
> >       contains one or more 16-octet IPv6 addresses.
> >
> > Shouldn't this be zero or more IP addresses?  Otherwise, the
> > example that only
> > contains a domain and no IP address appears to be invalid.
> >
> 
> [Med] That text is correct. The field is present only when there is an IP address
> to convey; otherwise the field is skipped. The presence is indicated by this field:
> 
> Num Addresses (1 octet) - Indicates the number of enclosed IPv4 (for
> ENCDNS_IP4) or IPv6 (for ENCDNS_IP6) addresses.
[Rob Wilton (rwilton)] 

I've just rechecked it, and I still don't find the text clear in that section that this field is optional.  I think that some more words are required somewhere :-)

E.g., the overall length field is defined like this:

   *  Length (2 octets, unsigned integer) - Length of the enclosed data
      in octets.  In particular, this field is set to:

      -  0 if the Configuration payload has types CFG_REQUEST (if no
         specific DNS resolver is requested) or CFG_ACK.  If the
         'Length' field is set to 0, then later fields shown in Figure 1
         are not present.

ADN Length is defined as:

   *  ADN Length (1 octet) - Indicates the length of the "Authentication
      Domain Name" field in octets.  When set to '0', this means that no
      ADN is enclosed in the attribute.

Whereas, Num Addresses is defined as:

   *  Num Addresses (1 octet) - Indicates the number of enclosed IPv4
      (for ENCDNS_IP4) or IPv6 (for ENCDNS_IP6) addresses.  This value
      MUST NOT be set to 0 if the Configuration payload is of type
      CFG_REPLY or CFG_SET.

- This doesn't indicate that 0 addresses allowed (which might be okay), but it also doesn't indicate that the IP Addresses field is absent if there are no addresses.

As in I would still read section 3.1 in its entirety as needing as least 1 IP address to be specified unless ADN Length is set to 0.

Thanks,
Rob


> 
> >
> > ------------------------------------------------------------------
> > ----
> > COMMENT:
> > ------------------------------------------------------------------
> > ----
> >
> > Minor level comments:
> >
> > (2) p 0, sec
> >
> >    This document specifies new Internet Key Exchange Protocol
> > Version 2
> >    (IKEv2) Configuration Payload Attribute Types to assign DNS
> > resolvers
> >    that support encrypted DNS protocols, such as DNS-over-HTTPS
> > (DoH),
> >    DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ).
> >
> > Are there any updates needed to RFC 9061 needed to cover
> > manageability
> > aspects/updates of the attributes defined in this draft?  Note,
> > I'm not
> > requesting that they be added to this draft, but instead, I want
> > to check if
> > there is any need or plan to address them.
> 
> Med: Not AFAIK.
> 
> 
> >
> > (3) p 2, sec 2.  Terminology
> >
> >    Do53:  refers to unencrypted DNS.
> >
> > This term only turns up a few (3 times) in this doc, and its not
> > clear to me
> > that it improves its readability.  I didn't know what it meant,
> > possibly just
> > referencing to "Unencrypted DNS" would be better for the wider
> > audience?
> >
> 
> [Med] Do53 is widely used but without a reference. I prefer to maintain in this
> section. Thanks.
> 
> > (4) p 3, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> >
> >       -  0 if the Configuration payload has types CFG_REQUEST (if
> > no
> >          specific DNS resolver is requested) or CFG_ACK.  If the
> >          'Length' field is set to 0, then later fields shown in
> > Figure 1
> >          are not present.
> >
> > I found this text unclear & confusing when combined with the
> > following two
> > paragraphs.  I would suggest rewording the first sentence to
> > something like:
> >
> >    0, if the Configuration payload has (i) type CFG_REQUEST and no
> >    specific DNS resolver is requested or (ii) type CFG_ACK.
> >
> 
> [Med] OK.
> 
> 
> > (5) p 13, sec Appendix A.  Sample Deployment Scenarios
> >
> > Readability may be slightly improved by adding a sentence here to
> > explain what
> > the purpose of this section is.
> 
> [Med] We have a sentence in the intro:
> 
>    Sample use cases are described in Appendix A.  The Configuration
>    Payload Attribute Types defined in this document are not specific to
>    these deployments, but can also be used in other deployment contexts.
>    It is out of the scope of this document to provide a comprehensive
>    list of deployment contexts.
> 
> Will see if we can make a change.
> 
> >
> > (6) p 14, sec Appendix A.  Sample Deployment Scenarios
> >
> >    Enterprise networks are susceptible to internal and external
> > attacks.
> >    To minimize that risk all enterprise traffic is encrypted
> >    (Section 2.1 of [I-D.arkko-farrell-arch-model-t]).
> >
> > Would "SHOULD be encrypted" be better than "is encrypted"? Or,
> > alternatively,
> > "Encrypting all internal enterprise traffic minimizes the risks of
> > attacks
> > (Section 2.1 of [I-D.arkko-farrell-arch-model-t]).
> >
> 
> [Med] We removed that sentence as per a comment from Paul.
> 
> 
> > (7) p 14, sec Appendix B.  Examples
> >
> > I would suggest putting each of the two examples into its own
> > subsection.
> >
> 
> [Med] OK.
> 
> > Nit level comments:
> >
> > (8) p 4, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> >
> >       -  0 if the Configuration payload has types CFG_REQUEST (if
> > no
> >          specific DNS resolver is requested) or CFG_ACK.  If the
> >          'Length' field is set to 0, then later fields shown in
> > Figure 1
> >          are not present.
> >       -  (4 + Length of the ADN + N * 4 + Length of SvcParams) for
> >          ENCDNS_IP4 attributes if the Configuration payload has
> > types
> >          CFG_REQUEST or CFG_REPLY or CFG_SET; N being the number
> > of
> >          included IPv4 addresses ('Num addresses').
> >
> > Possibly "(4 + 'Length of the ADN' + (N * 4) + Length of
> > SvcParams)", and
> > similarly for IPv6, would be more explicit.
> >
> 
> [Med] OK
> 
> > (9) p 5, sec 3.2.  ENCDNS_DIGEST_INFO Configuration Payload
> > Attribute
> >
> >    *  Length (2 octets, unsigned integer) - Length of the enclosed
> > data
> >       in octets.  This field MUST be set to "2 + 2 * number of
> > included
> >       hash algorithm identifiers".
> >
> > For clarity, I suggest: "2 + (2 * 'number of included
> >       hash algorithm identifiers')"
> >
> 
> [Med] OK
> 
> > (10) p 6, sec 3.2.  ENCDNS_DIGEST_INFO Configuration Payload
> > Attribute
> >
> >    *  Length (2 octets, unsigned integer) - Length of the enclosed
> > data
> >       in octets.  This field MUST be set to "2 + 2 * number of
> > included
> >       hash algorithm identifiers".
> >    *  Num Hash Algs (1 octet) - Indicates the number of included
> > hash
> >       algorithm identifiers.  This field MUST be set to "(Length -
> >       2)/2".
> >
> > I suggest, included 'hash algorithm identifiers'.
> >
> 
> [Med] OK
> 
> > Regards,
> > Rob
> >
> >
> 
> ________________________________________________________________
> _________________________________________________________
> 
> Ce message et ses pieces jointes peuvent contenir des informations
> confidentielles ou privilegiees et ne doivent donc
> pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce
> message par erreur, veuillez le signaler
> a l'expediteur et le detruire ainsi que les pieces jointes. Les messages
> electroniques etant susceptibles d'alteration,
> Orange decline toute responsabilite si ce message a ete altere, deforme ou
> falsifie. Merci.
> 
> This message and its attachments may contain confidential or privileged
> information that may be protected by law;
> they should not be distributed, used or copied without authorisation.
> If you have received this email in error, please notify the sender and delete this
> message and its attachments.
> As emails may be altered, Orange is not liable for messages that have been
> modified, changed or falsified.
> Thank you.