Re: [IPsec] Mirja Kuehlewind's Discuss on draft-ietf-ipsecme-tcp-encaps-09: (with DISCUSS)

"Mirja Kuehlewind (IETF)" <ietf@kuehlewind.net> Tue, 02 May 2017 10:12 UTC

Return-Path: <ietf@kuehlewind.net>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 674A012EBAD for <ipsec@ietfa.amsl.com>; Tue, 2 May 2017 03:12:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.003
X-Spam-Level:
X-Spam-Status: No, score=-2.003 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); domainkeys=pass (1024-bit key) header.from=ietf@kuehlewind.net header.d=kuehlewind.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 00g1xQyEHo0l for <ipsec@ietfa.amsl.com>; Tue, 2 May 2017 03:12:27 -0700 (PDT)
Received: from kuehlewind.net (kuehlewind.net [83.169.45.111]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C4F28131449 for <ipsec@ietf.org>; Tue, 2 May 2017 03:08:18 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=kuehlewind.net; b=IJmtwIee1WwIe/EOc2Gr/VMIQr4KeNnFgEsw/V4i0EUw6iKLJZlFZIt+RIQeOmxcAYgallc+zdP7amsNhJGUH0tl6yKvaqbo/jgCPnNob1kG/mJQPFkryXubbDJhBAq6G5KlaxWG82wIJ7ySzq5HMIniX1FncH3L9kBneBotRgA=; h=Received:Received:Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc:Content-Transfer-Encoding:Message-Id:References:To:X-Mailer:X-PPP-Message-ID:X-PPP-Vhost;
Received: (qmail 25882 invoked from network); 2 May 2017 12:01:35 +0200
Received: from p5dec2bdc.dip0.t-ipconnect.de (HELO ?192.168.178.33?) (93.236.43.220) by kuehlewind.net with ESMTPSA (DHE-RSA-AES256-SHA encrypted, authenticated); 2 May 2017 12:01:35 +0200
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: "Mirja Kuehlewind (IETF)" <ietf@kuehlewind.net>
In-Reply-To: <22792.20148.255067.132946@fireball.acr.fi>
Date: Tue, 02 May 2017 12:01:32 +0200
Cc: Tommy Pauly <tpauly@apple.com>, Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com>, Eric Rescorla <ekr@rtfm.com>, ipsecme-chairs@ietf.org, IPsecME WG <ipsec@ietf.org>, The IESG <iesg@ietf.org>, draft-ietf-ipsecme-tcp-encaps@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <82B5E72F-C518-420B-B941-E4CE4DD1BF87@kuehlewind.net>
References: <149312449263.5884.11168631631187069210.idtracker@ietfa.amsl.com> <1CD2BB99-CDA2-472A-9833-741FB14CAE4A@apple.com> <752dde8c-0592-288e-6920-53a211834740@kuehlewind.net> <CABcZeBMj9UpzD+CpvOMKOkUsYNSL-UQCwuYt__5XCXtH=zyesA@mail.gmail.com> <22fac532-f30b-03e3-0757-aed213e5a346@kuehlewind.net> <22785.64570.259658.376130@fireball.acr.fi> <277aa94d-5aa1-7a28-94c7-81da0966c172@kuehlewind.net> <41594727-9667-42BD-ABB1-4583A3B00EA2@apple.com> <CAKKJt-fb1vx=SzpJ_9gvtJ+SEH08nyBRGqb7F36PGw0EyJ6zmA@mail.gmail.com> <853700CB-D5DD-4BC7-A1F5-5AB61330E70D@apple.com> <22792.20148.255067.132946@fireball.acr.fi>
To: Tero Kivinen <kivinen@iki.fi>
X-Mailer: Apple Mail (2.3273)
X-PPP-Message-ID: <20170502100135.25871.96870@lvps83-169-45-111.dedicated.hosteurope.de>
X-PPP-Vhost: kuehlewind.net
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/qL7Gi7K7_NnYMO3QDSWJPfSqrN0>
Subject: Re: [IPsec] Mirja Kuehlewind's Discuss on draft-ietf-ipsecme-tcp-encaps-09: (with DISCUSS)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 May 2017 10:12:28 -0000

Hi all,

so first updating is a request to IANA, so you have to remove the first sentence. Then the update of the UPD port should probably be done in a separate document that potentially also obsoletes 3947 if that was missed with 7296.

Mirja


> Am 02.05.2017 um 11:17 schrieb Tero Kivinen <kivinen@iki.fi>:
> 
> Tommy Pauly writes:
>> I'll defer to Tero on this one. Tero, what do you prefer to do with the IANA
>> Considerations text?
> 
> [Note, that I am just talking as individual here, these IANA actions
> do not relate the IKEv2 registries where I am IANA Expert]
> 
> I proposed to change both the UDP and TCP references for the port
> 4500, as even if the RFC3947 did do the IANA actions, it does not
> describe the protocol used on the port. RFC3948 and 7296 does.
> 
> So from my previous email I would suggest following text:
> 
> ----------------------------------------------------------------------
>  14.  IANA Considerations
> 
>    This memo includes no request to IANA.
> 
>    TCP port 4500 is already allocated to IPsec for NAT Traversal.
>    This port SHOULD be used for TCP encapsulated IKE and ESP as
>    described in this document.
> 
>    This document updates both TCP and UDP references of the port 4500
>    to match the current protocols used on those ports:
> 
>    Keyword       Decimal    Description          Reference
>    -------       -------    -----------          ---------
>    ipsec-nat-t   4500/tcp   IPsec NAT-Traversal  [RFC-this-rfc]
>    ipsec-nat-t   4500/udp   IPsec NAT-Traversal  [RFC3948], [RFC7296]
> 
> -- 
> kivinen@iki.fi