Re: [IPsec] New Version Notification for draft-ietf-ipsecme-add-ike-04.txt

mohamed.boucadair@orange.com Fri, 09 September 2022 08:34 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CF9AC1524B7; Fri, 9 Sep 2022 01:34:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6olTc-KjCh-L; Fri, 9 Sep 2022 01:34:07 -0700 (PDT)
Received: from relais-inet.orange.com (relais-inet.orange.com [80.12.66.41]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 416BCC1524BB; Fri, 9 Sep 2022 01:33:58 -0700 (PDT)
Received: from opfedar03.francetelecom.fr (unknown [xx.xx.xx.5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by opfedar25.francetelecom.fr (ESMTP service) with ESMTPS id 4MP8R80VBhz8tBh; Fri, 9 Sep 2022 10:33:56 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; s=ORANGE001; t=1662712436; bh=im9CRV35HQggJvOGIamIJSafxvuAW7uiUBbsMgYHcWk=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version; b=TytCBXMxEM/3JruIoyuySDDbNlbnzq291UljYXQ8GjEkxBJ7qCC5Ko1Kklnd0ET5E 8Br3ByMcbQ+SVWgHWG9LoOjrup48spjyEJJAAT8AtFnRsxQgl2PZOwYzxPwMiQXzSh OdnWDH7btoOm/7lAGLdDeajzPU4Rk0tsR27z1vqU3wFDXrtz7fLFsEVncHC2Eb3U0v xa1ZgkGXXwUnvnNjgXex/pZec8tpEve0FEqrW8QajvKskvvcQf/jNhN+eLn4eWYOx4 g4fwaVwBVly3FmKs0RPfpqYgC6iZ7dShhpaRanHj8KL24OktVEFjPVaT8JiXKNx1f2 ibHSPhwl3QdaQ==
From: mohamed.boucadair@orange.com
To: Valery Smyslov <svan@elvis.ru>, 'Paul Wouters' <paul@nohats.ca>
CC: "ipsec@ietf.org" <ipsec@ietf.org>, 'Tero Kivinen' <kivinen@iki.fi>, "draft-ietf-ipsecme-add-ike@ietf.org" <draft-ietf-ipsecme-add-ike@ietf.org>
Thread-Topic: [IPsec] New Version Notification for draft-ietf-ipsecme-add-ike-04.txt
Thread-Index: Adi8j3bQiq3cF9Gvqk+uHK8xSRd9GgAnjjPQAb4werA=
Date: Fri, 09 Sep 2022 08:33:55 +0000
Message-ID: <28609_1662712435_631AFA73_28609_2_12_a6315354dd094c51b339968a4317fa40@orange.com>
References: <014b01d8bc91$3d153730$b73fa590$@elvis.ru> <5acce58bcf2242da8bed87e8ca744c9f@orange.com>
In-Reply-To: <5acce58bcf2242da8bed87e8ca744c9f@orange.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2022-08-31T11:37:26Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=541b28a1-b0f8-451a-97b4-1a458128d13b; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0
x-originating-ip: [10.115.27.53]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/nOtTII7X1Eb16ovJJ5qqQC5VTBM>
Subject: Re: [IPsec] New Version Notification for draft-ietf-ipsecme-add-ike-04.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Sep 2022 08:34:11 -0000

Hi Paul, all, 

FWIW, I just submitted a new version (-05) to remove the ambiguity about multiple distinct attributes you raised. 

Also fixed some nits and removed some redundant text by simply pointing to existing stable specs. 

Cheers,
Med

> -----Message d'origine-----
> De : BOUCADAIR Mohamed INNOV/NET
> Envoyé : mercredi 31 août 2022 13:39
> À : 'Valery Smyslov' <svan@elvis.ru>; 'Paul Wouters'
> <paul@nohats.ca>
> Cc : ipsec@ietf.org; 'Tero Kivinen' <kivinen@iki.fi>; draft-ietf-
> ipsecme-add-ike@ietf.org
> Objet : RE: [IPsec] New Version Notification for draft-ietf-
> ipsecme-add-ike-04.txt
> 
> Hi all,
> 
> Please see one clarification inline.
> 
> Cheers,
> Med
> 
> > -----Message d'origine-----
> > De : Valery Smyslov <svan@elvis.ru>
> > Envoyé : mardi 30 août 2022 18:55
> > À : 'Paul Wouters' <paul@nohats.ca>; BOUCADAIR Mohamed INNOV/NET
> > <mohamed.boucadair@orange.com> Cc : ipsec@ietf.org; 'Tero
> Kivinen'
> > <kivinen@iki.fi>; draft-ietf- ipsecme-add-ike@ietf.org Objet :
> Re:
> > [IPsec] New Version Notification for draft-ietf-
> > ipsecme-add-ike-04.txt
> >
> > HI Paul,
> >
> > > On Tue, 30 Aug 2022, mohamed.boucadair@orange.com wrote:
> > >
> > > > This version takes into account the comments received during
> > the
> > > > WGLC, mainly the edits suggested by
> > > Tommy.
> > >
> > >  	If the initiator sends multiple attributes of a particular
> > type in
> > >  	the request, all of them MUST be distinct (either be empty
> > or
> > >  	containing different suggested resolvers).
> > >
> > > What does it mean when multiple attributes of a particular
> type
> > are
> > > sent, where one is empty and one is not empty? I think perhaps
> > this
> > > text means to say either it sends one empty one, or it sends
> > multiple
> > > non-empty ones?
> >
> > Yes (with a clarification - multiple _distinct_ non-empty ones).
> >
> > > Another comment on text unchanged in the latest revision that
> I
> > just
> > > noticed:
> > >
> > >     For split-tunnel VPN configurations, the endpoint uses the
> > >     Enterprise-provided encrypted DNS resolver to resolve
> > internal-only
> > >     domain names.
> > >
> > > What if one of the reasons I want a split-tunnel, is to
> actually
> > use
> > > an encrypted DNS over the VPN to protect my non-VPN traffic?
> > This use
> > > case is not captured in A1?
> >
> > It seems so.
> >
> 
> [Med] As a reminder, A1 is specific to the enterprise use case.
> The case mentioned by Paul can be met with the configuration in A2
> (with some local policies).
> 
> > Regards,
> > Valery.
> >
> > > Paul


_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.