Re: [Last-Call] [Iot-directorate] Iotdir telechat review of draft-ietf-taps-transport-security-11

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Thu, 02 April 2020 12:03 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C6723A10E6; Thu, 2 Apr 2020 05:03:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=IUv6EJFv; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=ZaSFIFKn
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T_ENLp00-518; Thu, 2 Apr 2020 05:03:24 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7769C3A10BE; Thu, 2 Apr 2020 05:03:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3088; q=dns/txt; s=iport; t=1585829001; x=1587038601; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=ozbwvFpa/bQy2JrLY0TSBugla4Oc2PCylNwMIO1uZcc=; b=IUv6EJFvCH59KHzfV7cvJOU2wEslivPrGNybZ91LnXsDMAVGgUVVeMUK 2o3a9R1DcTKDLD7y0dZZu+1JZZStFvv81hRoY6Xa0ZbFNNjzUj4usclKn 4vJZSccPrsEHVdt5U9mypKoZZ0XjZMDWCYJrjwLrVks0LE1NlSDGbRQrU 8=;
IronPort-PHdr: 9a23:wvkJKhZIWBLJFaREsKTHYoT/LSx94ef9IxIV55w7irlHbqWk+dH4MVfC4el20gebRp3VvvRDjeee87vtX2AN+96giDgDa9QNMn1NksAKh0olCc+BB1f8KavncT08F8dPfFRk5Hq8d0NSHZW2ag==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0DhAQDr04Ve/5BdJa1mGwEBAQEBAQEFAQEBEQEBAwMBAQGBe4FUUAVsWCAECyqEG4NFA4ptgl+YHoFCgRADVAoBAQEMAQEYCwoCBAEBhEQCF4IpJDgTAgMBAQsBAQUBAQECAQUEbYVWDIVwAQEBAQMBARARBA0MAQEsCwELBAIBCBEDAQIDAhEVAgICJQsUAQgIAgQBDQUigwQBgksDLgEOpBcCgTmIYnV/M4J/AQEFhTIYggwDBoEOKollgkwagUE/gTgggk0+gmcBAYEeRz+CUzKCLI1ogxqQLY9XCoI9kmeENB2CTIg1kHGPKZwWAgQCBAUCDgEBBYFpIoFXcBUaISoBgj5QGA2OHQ0WFYM7hRSFQXQCC4Eci10tghQBAQ
X-IronPort-AV: E=Sophos;i="5.72,335,1580774400"; d="scan'208";a="750077511"
Received: from rcdn-core-8.cisco.com ([173.37.93.144]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 02 Apr 2020 12:03:20 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by rcdn-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id 032C3KZs008303 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 2 Apr 2020 12:03:20 GMT
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 2 Apr 2020 07:03:20 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 2 Apr 2020 07:03:19 -0500
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 2 Apr 2020 07:03:19 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=k2L7gqX0KB5s9j1moSGRvgiLv8TTCtgAT+p4Aeu2ApiSQsRmMnzGGtHzFjP+aasdKprEYBvSsmm079YUSb5kQAa6qenUqVy0kSXZJVWqfV4n4HiGyDh+aDbqIrtWPe44LZEHAEFJzAfBuK7bKNCoAV1+0tHHhtwyh2XHXe3HM2DBChGigAqUaDCPTzmKnI70/z5DOmxuE8uhmviYjYclOnd0sGXffwiD7sOeEm73e6vM6KZUi5L6+Fy7C4WGA6eRJY7Mx6dAHHyy9u12bLvPxBlO5NRIdIvvePKF22iUJFl2Y3zKxHI/mE53VL3nnFy/yaQVfC3p3eMw337kzw5Pwg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ozbwvFpa/bQy2JrLY0TSBugla4Oc2PCylNwMIO1uZcc=; b=NXJKXkQyJaRmHWuhHAeYsAPKEaBGBQ+fCP8U6eeofy8ZwuU3JkQC223WFSPY0LqeCWPndIZG2LSEMdxMztUKJl+CP4A6godtzgJhDBfK4N0RhxvJ1N7nBt+9f8yEpDMEdjr/oqHdZZ7p6srQrWXpIRpRGEpnLa+jJZqgBoGjIJNbj/znekB+MzReu4+0XOa/HOcIdhnzjs8SG1QhWlgEyfP9lxVxql7BJQ8c2b9HWQcE8EvpFuY6BSwWUJiV3RhjTVatqEKOMDa3pXRx4Dw6a6rPO1+vFh1HLR9P/7OElv+vhrz0ZOmK/cUgnwvcuje3OhUr8eiuMez482KbfzIjBQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ozbwvFpa/bQy2JrLY0TSBugla4Oc2PCylNwMIO1uZcc=; b=ZaSFIFKn+SOGs/EqEmsEC7eJef+9K11cosd9jSeCUxJgBaftjL1svqqt5zHCJWA2N+trYO2RfE90KahQuOnWPhgicfjdV3us5TeNETLlm+EIzFSbKLnhvuIgXJ6godHwllNZ74HjZ9AZnUGkijLX/L8n7WZ4UCt+I20ExQRUGVk=
Received: from DM5PR11MB1753.namprd11.prod.outlook.com (2603:10b6:3:10d::13) by DM5PR11MB0076.namprd11.prod.outlook.com (2603:10b6:4:6b::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2878.16; Thu, 2 Apr 2020 12:03:18 +0000
Received: from DM5PR11MB1753.namprd11.prod.outlook.com ([fe80::680d:e22e:72d5:67ca]) by DM5PR11MB1753.namprd11.prod.outlook.com ([fe80::680d:e22e:72d5:67ca%3]) with mapi id 15.20.2856.019; Thu, 2 Apr 2020 12:03:18 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Mohit Sethi <mohit.m.sethi@ericsson.com>, "iot-directorate@ietf.org" <iot-directorate@ietf.org>
CC: "last-call@ietf.org" <last-call@ietf.org>, "draft-ietf-taps-transport-security.all@ietf.org" <draft-ietf-taps-transport-security.all@ietf.org>, "taps@ietf.org" <taps@ietf.org>
Thread-Topic: [Iot-directorate] Iotdir telechat review of draft-ietf-taps-transport-security-11
Thread-Index: AQHWCBKtQZhKlC2S9E+3hLwrcn7MGqhl3sYA
Date: Thu, 02 Apr 2020 12:03:18 +0000
Message-ID: <5C72A1F6-DAD5-484A-B62E-FD26F83ADE20@cisco.com>
References: <158573789268.30918.7424398883276797270@ietfa.amsl.com>
In-Reply-To: <158573789268.30918.7424398883276797270@ietfa.amsl.com>
Accept-Language: fr-BE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.35.20030802
authentication-results: spf=none (sender IP is ) smtp.mailfrom=evyncke@cisco.com;
x-originating-ip: [2001:420:c0c1:36:ad33:1e6:78ba:617b]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1d584cad-36c3-4f9d-b15b-08d7d6fdd548
x-ms-traffictypediagnostic: DM5PR11MB0076:
x-microsoft-antispam-prvs: <DM5PR11MB0076B71E11066B72B30A1600A9C60@DM5PR11MB0076.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0361212EA8
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM5PR11MB1753.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(10009020)(4636009)(366004)(136003)(396003)(346002)(39860400002)(376002)(6486002)(110136005)(4326008)(33656002)(54906003)(5660300002)(2906002)(966005)(71200400001)(316002)(478600001)(36756003)(6506007)(6512007)(66946007)(81166006)(76116006)(186003)(53546011)(91956017)(2616005)(15650500001)(86362001)(66556008)(66446008)(8936002)(64756008)(8676002)(66476007)(81156014); DIR:OUT; SFP:1101;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: IGhZPutcNkQol/9gilAgPZVmjX9tYbfECZB97hhJRDuAJ/0+kzKMN0LR6DFR9t5W9E3K/Guh2yDfaGMQhZmJA/C0be+coSoC9kLQsUiz7WOtwgLO0KVXiUT7v2crMnH2oGTn3bce+Do1D5n74NIUmprLgOrz6KWGCWilwzgvgFA0NHh5Zu7mlNod50Y0DRId6Xv/f2nwMlBCrLkg88Hdd6nUHefbxaj/BYQOnL5bWz1JBo1ZKcKlwKqqp0LkDzy/H8I295SKdcdR3uobL5KNVrTgv6yxSj01fQCgOnYo/cXPOQpUAwCpcqioLrN3I/LJ3Rm9rpRS/nJ5PnWGimXdpRe6ES+1b/4Rm7q670xvEjd5dg8ra5QDZM4uV6O6g479l+BRMg5tj3AEoP5IMcphpYEz/2L9BdNakdWs+cDSCZs9sAoRV7xYNp8pQtSTLPIZZEvE1S7razglFeMoYkr7bY9FMpToDFd9kSFCCl0nNr6yXuGgbMqUvMMDwPZJ23RwniiElUImi9aqNTTTHnU1rw==
x-ms-exchange-antispam-messagedata: bZVYVHsYflGtfzFMqJqeLwON51axJW25q0HBg+Hob8CqXksRvuE+47TF2vWJ4UGYAhMBD9hKZymMk6pUZS4ujmNbKMRrHTMsinZLlmqTD8a+apI7bUhb3aTjISq7V+mLFi1bdunXfVCefEjcQAL2DyDFvScIN6DHPGi9rt3McbxESkrCHLqdqYYaa0B52BTZ4DtYNQvF/EZyRpby7e3ydA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <74FDC60FF17EB2459D77073CBEF2D79F@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 1d584cad-36c3-4f9d-b15b-08d7d6fdd548
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Apr 2020 12:03:18.8186 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: JAFz9n9BsbHjOP24zZzwH5Njv5Fzzfr4ZWJV/5SMAEL5ikOMZ+n3aI2veIvRLeng8KCOLptgvRhJS6gFcgGXHA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR11MB0076
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.13, xch-aln-003.cisco.com
X-Outbound-Node: rcdn-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/cQtE_m8rXUTVs7OIodaSqAG9OoY>
Subject: Re: [Last-Call] [Iot-directorate] Iotdir telechat review of draft-ietf-taps-transport-security-11
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Apr 2020 12:03:31 -0000

Thank you Mohit for the review.

I will take it into account for my ballot position.

Regards

-éric

-----Original Message-----
From: Iot-directorate <iot-directorate-bounces@ietf.org> on behalf of Mohit Sethi via Datatracker <noreply@ietf.org>
Reply-To: Mohit Sethi <mohit.m.sethi@ericsson.com>
Date: Wednesday, 1 April 2020 at 12:45
To: "iot-directorate@ietf.org" <iot-directorate@ietf.org>
Cc: "last-call@ietf.org" <last-call@ietf.org>, "draft-ietf-taps-transport-security.all@ietf.org" <draft-ietf-taps-transport-security.all@ietf.org>, "taps@ietf.org" <taps@ietf.org>
Subject: [Iot-directorate] Iotdir telechat review of draft-ietf-taps-transport-security-11

    Reviewer: Mohit Sethi
    Review result: Ready with Nits
    
    This document provides a summary of common security protocols. It then
    discusses the interfaces that exist between applications and security protocols
    as well as security protocols and transport services.
    
    Major issues: The document header says that this document is about interfaces
    between security protocols and transport services. Yet, later on, I find that
    the document is also discussing the interfaces between security protocols and
    applications. Perhaps you could add 'applications' to the title -> 'Interaction
    Between Applications, Security Protocols, and Transport Services'
    
    Editorial issues:
    - Instead of saying 'This protocol obsoletes TCP MD5 "signature" options', can
    we say 'TCP-AO obsoletes....' to avoid confusion of what is 'this' - Please
    expand 'and IPsec AH [RFC4302]' -> IP Authentication Header - Are you talking
    about cryptographic agility here 'security protocols: confidentiality, privacy
    protections, and agility.' ? - Consider changing 'interface surface exposed '->
    interface exposed by'. Otherwise it sounds too similar to attack surface
    exposed. - Expand EAP and reference RFC3748. - Perhaps you could say that
    Source Address Validation (SAV) to prevent DoS is relevant for protocols that
    use unreliable transport?
    
    
    -- 
    Iot-directorate mailing list
    Iot-directorate@ietf.org
    https://www.ietf.org/mailman/listinfo/iot-directorate