Re: [Lsvr] [OPSEC] security against what?

Christopher Morrow <morrowc.lists@gmail.com> Tue, 04 September 2018 14:09 UTC

Return-Path: <christopher.morrow@gmail.com>
X-Original-To: lsvr@ietfa.amsl.com
Delivered-To: lsvr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7FECE130ED4; Tue, 4 Sep 2018 07:09:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.098
X-Spam-Level:
X-Spam-Status: No, score=-0.098 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VsowKwaGj7dN; Tue, 4 Sep 2018 07:09:00 -0700 (PDT)
Received: from mail-vk0-x234.google.com (mail-vk0-x234.google.com [IPv6:2607:f8b0:400c:c05::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8ABBD130E98; Tue, 4 Sep 2018 07:09:00 -0700 (PDT)
Received: by mail-vk0-x234.google.com with SMTP id j14-v6so1370982vke.8; Tue, 04 Sep 2018 07:09:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=lQocJZec/tUyhVd9e4yypZBwHmQELrKdzekYjSBqmGo=; b=cglBRNJt49BTbFtErgPzCrSFiwipmc0fKCIZttfsPkLfWPr0WqZQOQ7sW5kQmRXCma WoQmeoEpSj0e3h0/CxdvfX/fwE22SA0Oh4rGDi+asfUN56mJUUTmGpzap8oH503VUdIF /8rM1dm6nhYZeo4iDgNXnX6PZcobQ+1EVN2JjFaTLnObllFm4CWpS8ZDLaYOgjo4x69m yKwOBZb16I0YeQGc/Dlta/3K9zMhFT9PU3Tek8YVIZgBUpam0eWjymcZZshVkfXCotUO smo2Gll0tLUaIXvIKy4cmFJZF+Qph/xtlxVf6Gs/y+PqYrGEBwxXj8UL2e4T6/SWiy20 FaPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=lQocJZec/tUyhVd9e4yypZBwHmQELrKdzekYjSBqmGo=; b=e96Owz6FHqkMFnDfOHx71u74k8p0h6lC7jDNmvkAbw2FbNWMLCJfmaZG/gpOF4raIZ s8AT4+6XDv5cJaUAy4UgAceHB7ZkThAclwD/lRR9YGz9JLXo6fumgM8xrhOc26hIAOBH jnWEGnIooFNnL/vewOrWhUXTvZhi0SNit/3maAgLZYVxrRM4jb6ZOfX+MDjcDGYg+jd9 CB10alz+XEUjSHSmt8cdRqWtO/5pqFww/h/rd/mPlQ8D1tXHL3NvoHZD6kwnKJfaoKer xYAyFlFopy+vLpWN46aGhzxq/F6e949OHxSK0YvMqWQKiw/YpELSG9lJYarz3S8MwPJs 0fhA==
X-Gm-Message-State: APzg51BRG9BoywFM3+bvw1lt1zpx6FZqXUOAJpvEHxTLqz6i1XEZnEvw GWZoU2N1uO3T+lMdc+Xc7g3BRN4XE1/AdkZs3eY=
X-Google-Smtp-Source: ANB0VdblRnuLqaCL98v3g4zpNnuIzItK4sPkeaCi2W9+KfkGhgUCRVYcre9rcIIEw2QBkq3Ey8PxU/fmsP4dc1zf61o=
X-Received: by 2002:a1f:5641:: with SMTP id k62-v6mr17081522vkb.12.1536070139190; Tue, 04 Sep 2018 07:08:59 -0700 (PDT)
MIME-Version: 1.0
References: <m21sbkjba8.wl-randy@psg.com> <AM5PR0701MB172966DC99841C55D5E26CA2E0030@AM5PR0701MB1729.eurprd07.prod.outlook.com> <CAAedzxrX5TWxYtA-uCfA3QyF_N1L3-tmjtqWTNThXvNNi4Uppw@mail.gmail.com> <m2zhwxposb.wl-randy@psg.com>
In-Reply-To: <m2zhwxposb.wl-randy@psg.com>
From: Christopher Morrow <morrowc.lists@gmail.com>
Date: Tue, 04 Sep 2018 10:08:47 -0400
Message-ID: <CAL9jLaa0VmEQpi45T0wdNV51R5+ib4Lo8NhmO9RJq-6OiO69EA@mail.gmail.com>
To: Randy Bush <randy@psg.com>
Cc: Erik Kline <ek@google.com>, opsec wg mailing list <opsec@ietf.org>, lsvr@ietf.org, gunter.van_de_velde@nokia.com
Content-Type: multipart/alternative; boundary="000000000000ff292f05750c3295"
Archived-At: <https://mailarchive.ietf.org/arch/msg/lsvr/z6Wq65SNb9pxPY5j_jQQlrvtQ68>
X-Mailman-Approved-At: Tue, 04 Sep 2018 07:10:00 -0700
Subject: Re: [Lsvr] [OPSEC] security against what?
X-BeenThere: lsvr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Link State Vector Routing <lsvr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lsvr>, <mailto:lsvr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lsvr/>
List-Post: <mailto:lsvr@ietf.org>
List-Help: <mailto:lsvr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lsvr>, <mailto:lsvr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 04 Sep 2018 14:09:03 -0000

'datacenter operators' == "hyperscale web wonkers" ?
or 'datacenter operators' == 'colo provider' ('the planet' not 'equinix' -
and 'the planet' is now 'someone else' but...)

On Tue, Sep 4, 2018 at 5:58 AM Randy Bush <randy@psg.com> wrote:

> > Is recommending 802.1x possible/sufficient (given the description in
> > Randy's strawperson comment)?
>
> it's a long way to that radius server
>
> randy
>
> _______________________________________________
> OPSEC mailing list
> OPSEC@ietf.org
> https://www.ietf.org/mailman/listinfo/opsec
>