[netconf] Re: [Last-Call] Re: [netconf] draft-ietf-netconf-yp-transport-capabilities-06 ietf last call Secdir review

Christian Huitema <huitema@huitema.net> Fri, 14 August 2026 15:48 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: netconf@mail2.ietf.org
Delivered-To: netconf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E2248129DD99B; Fri, 14 Aug 2026 08:48:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786722524; bh=2qaOxkOSFvZYe4L1NABIKLdtDr82Al9yK+Gag2xWZNw=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=zP9FbSHa5h/qGRvM9xThY+v4HDZpnFBTR4UMEN1f+QtoBivUI6JCCt2z3qCgUMgnU 0T2rnGJXgWuB6sxB841V8Qnxa8PTarQ7WRPZl02afM4jsjzK6gbzZgP2kwbrpqPyfX 8rDyKedBbNWuElKU0lRLFhYIsin7Q1fVqvLF/r7I=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0GARrUNyDlxN; Fri, 14 Aug 2026 08:48:44 -0700 (PDT)
Received: from semf11.mfg.siteprotect.com (semf11.mfg.siteprotect.com [64.26.60.174]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 307B9129DD507; Fri, 14 Aug 2026 08:48:26 -0700 (PDT)
Received: from smtpauth02.mfg.siteprotect.com ([64.26.60.151]) by se05.mfg.siteprotect.com with esmtp (Exim 4.94.2) (envelope-from <huitema@huitema.net>) id 1wuttj-00G7jT-J3; Fri, 14 Aug 2026 11:48:16 -0400
Received: from [192.168.1.104] (unknown [172.56.15.22]) (Authenticated sender: huitema@huitema.net) by smtpauth02.mfg.siteprotect.com (Postfix) with ESMTPSA id 4hM67t4DG9zCSFvL3; Fri, 14 Aug 2026 11:48:10 -0400 (EDT)
Message-ID: <b1b635ea-2235-4a3e-8a39-825915ceaa60@huitema.net>
Date: Fri, 14 Aug 2026 08:48:08 -0700
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Alex.Huang-Feng=40t-systems.com@dmarc.ietf.org
References: <178615071319.153546.9203560369914607963@dt-datatracker-559c48c7fb-9llwz> <50F320D3-F241-4966-A56C-B147B2A2BBA3@t-systems.com>
Content-Language: en-US
From: Christian Huitema <huitema@huitema.net>
Autocrypt: addr=huitema@huitema.net; keydata= xsBNBFIRX8gBCAC26usy/Ya38IqaLBSu33vKD6hP5Yw390XsWLaAZTeQR64OJEkoOdXpvcOS HWfMIlD5s5+oHfLe8jjmErFAXYJ8yytPj1fD2OdSKAe1TccUBiOXT8wdVxSr5d0alExVv/LO I/vA2aU1TwOkVHKSapD7j8/HZBrqIWRrXUSj2f5n9tY2nJzG9KRzSG0giaJWBfUFiGb4lvsy IaCaIU0YpfkDDk6PtK5YYzuCeF0B+O7N9LhDu/foUUc4MNq4K3EKDPb2FL1Hrv0XHpkXeMRZ olpH8SUFUJbmi+zYRuUgcXgMZRmZFL1tu6z9h6gY4/KPyF9aYot6zG28Qk/BFQRtj7V1ABEB AAHNJ0NocmlzdGlhbiBIdWl0ZW1hIDxodWl0ZW1hQGh1aXRlbWEubmV0PsLAeQQTAQIAIwUC UhFfyAIbLwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEJNDCbJVyA1yhbYH/1ud6x6m VqGIp0JcZUfSQO8w+TjugqxCyGNn+w/6Qb5O/xENxNQ4HaMQ5uSRK9n8WKKDDRSzwZ4syKKf wbkfj05vgFxrjCynVbm1zs2X2aGXh+PxPL/WHUaxzEP7KjYbLtCUZDRzOOrm+0LMktngT/k3 6+EZoLEM52hwwpIAzJoscyEz7QfqMOZtFm6xQnlvDQeIrHx0KUvwo/vgDLK3SuruG1CSHcR0 D24kEEUa044AIUKBS3b0b8AR7f6mP2NcnLpdsibtpabi9BzqAidcY/EjTaoea46HXALk/eJd 6OLkLE6UQe1PPzQC4jB7rErX2BxnSkHDw50xMgLRcl5/b1bOwE0EUhFfyAEIAKp7Cp8lqKTV CC9QiAf6QTIjW+lie5J44Ad++0k8gRgANZVWubQuCQ71gxDWLtxYfFkEXjG4TXV/MUtnOliG 5rc2E+ih6Dg61Y5PQakm9OwPIsOx+2R+iSW325ngln2UQrVPgloO83QiUoi7mBJPbcHlxkhZ bd3+EjFxSLIQogt29sTcg2oSh4oljUpz5niTt69IOfZx21kf29NfDE+Iw56gfrxI2ywZbu5o G+d0ZSp0lsovygpk4jK04fDTq0vxjEU5HjPcsXC4CSZdq5E2DrF4nOh1UHkHzeaXdYR2Bn1Y wTePfaHBFlvQzI+Li/Q6AD/uxbTM0vIcsUxrv3MNHCUAEQEAAcLBfgQYAQIACQUCUhFfyAIb LgEpCRCTQwmyVcgNcsBdIAQZAQIABgUCUhFfyAAKCRC22tOSFDh1UOlBB/94RsCJepNvmi/c YiNmMnm0mKb6vjv43OsHkqrrCqJSfo95KHyl5Up4JEp8tiJMyYT2mp4IsirZHxz/5lqkw9Az tcGAF3GlFsj++xTyD07DXlNeddwTKlqPRi/b8sppjtWur6Pm+wnAHp0mQ7GidhxHccFCl65w uT7S/ocb1MjrTgnAMiz+x87d48n1UJ7yIdI41Wpg2XFZiA9xPBiDuuoPwFj14/nK0elV5Dvq 4/HVgfurb4+fd74PV/CC/dmd7hg0ZRlgnB5rFUcFO7ywb7/TvICIIaLWcI42OJDSZjZ/MAzz BeXm263lHh+kFxkh2LxEHnQGHCHGpTYyi4Z3dv03HtkH/1SI8joQMQq00Bv+RdEbJXfEExrT u4gtdZAihwvy97OPA2nCdTAHm/phkzryMeOaOztI4PS8u2Ce5lUB6P/HcGtK/038KdX5MYST Fn8KUDt4o29bkv0CUXwDzS3oTzPNtGdryBkRMc9b+yn9+AdwFEH4auhiTQXPMnl0+G3nhKr7 jvzVFJCRif3OAhEm4vmBNDE3uuaXFQnbK56GJrnqVN+KX5Z3M7X3fA8UcVCGOEHXRP/aubiw Ngawj0V9x+43kUapFp+nF69R53UI65YtJ95ec4PTO/Edvap8h1UbdEOc4+TiYwY1TBuIKltY 1cnrjgAWUh/Ucvr++/KbD9tD6C8=
In-Reply-To: <50F320D3-F241-4966-A56C-B147B2A2BBA3@t-systems.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=huitema@huitema.net
X-Originating-IP: 64.26.60.151
X-SpamExperts-Domain: mfg.outbound
X-SpamExperts-Username: 64.26.60.150/31
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=64.26.60.150/31@mfg.outbound
X-SpamExperts-Outgoing-Class: ham
X-SpamExperts-Outgoing-Evidence: SB/global_tokens (0.00674273864004)
X-Recommended-Action: accept
X-Filter-ID: 9kzQTOBWQUFZTohSKvQbgI7ZDo5ubYELi59AwcWUnuXEF4coiG8G0G1XkBUeBRx/2fRcyiRaHQwj qh+oywV8gSu2SmbhJN1U9FKs8X3+Nt127hcteP1p0NVNV47moiZtUnZMMMyaNBeO+OvFQHUlG4JL M0i5ZAms0EHrvcCaVIPzS2j7VVYZgOQ1cjn/7IlYGnT3EFAinyrilm9zau/FuzkQt9Nb4Ml7QXdk EetczWDLE03raa/FEALf0Z8wGU5oeB7itP8hgjDRserKv4bhbzi838DBmUKWhOLHfo543wbEMzer JfQa9UAYKsgEV8p+MUJTS2Jsxpkx+IHIsDarm2U3gyy0nlbakKK22WPBaiwbgg495zj6nulrGyqU W0O7BzwjTsVMVyOl19f8lyvzt+r5AKGW9/TOOTahqQAL7UFuFyRuvO4NjGU7J++OBIwAjGF59FBi OEjybg1XAEa3CAd88yMqU0HrXIiiYDPO8En7DffnIB/wxQ+/9g75Ry+DouHzVFIkEQAW/PYuLwxV gHblqFUUenMzeb9l7M2YQBEOpzYr3AGNmWibeLl3v+ynXt4hgySBdQ+JDLfyzXaPoLJfqLd0mkJx 0VeUCOHRhk3j9Mww1rxsEUntOr/IaIo3fAKZvAjuJrqAt2e//bIc/9BXEj0V6NArv3ouNHbuPZdm gtPkD6BTccjiKvE7CDZY6cTrAfIBtLJVe62uoyOAUvYtQLYQpwUf7KSftolpBssZugOMFKUcGN1I f74KjJaKxDM3qyX0GvVAGCrIBFfKfqul/WTobZWAGkW3d7y6oL05kKPcZZ21mzX0AR/E8H5aLvQc MALmJ9ap2na4ef0d1X3akD128a4og9jI3HpK2Y7keVn7KnKadhO/iDad4A8EKQ/tW2zE8IiVVII0 LEBalYZ/6bu8v13qOVHxX3l0NF0T0bbw5qgmAGYJgCiWEPaIa2xA667+/0zShVia5gzbOTpb4wE/ ZcPLofVWyyKeFEwmP04c+P138Fv76xQAwbzDXV0j2xzDtoQ4MAnPQjPcWa6Xy8YqsOR990w7SSnM ppaiHRKKZLTITYajcwsmZ8Uiy0M2f0eec5b2PMBoykxfXS3eq94ck1Z6OhdHl6mvgPE8CVsONrMJ uGzuoGnKTKcypXPpF7SzDgytbgyTMY3rH06OcoJw5Mc6YNazdH7fRbvMcw1VaeVLMg7TU7z13Qm6 StH2P94AA0Ha6+1NAjqHhr2l1CYXE8A5H0Ic3ArAj94daZHfkQpoxYa8asJrla79MxogvjxId3AG 6vsL0WtIBb/s6/VvV6lP9TqbWUXs3Jh+mMTSema1Fa4rG8YQgIU0BvOdHRaQghl54OZphjdyBQ==
X-Report-Abuse-To: spam@se02.mfg.siteprotect.com
X-Complaints-To: abuse@se01.mfg.siteprotect.com
Message-ID-Hash: DBYKVULE34T4V4LPWCNOB4BHH4P7PVK5
X-Message-ID-Hash: DBYKVULE34T4V4LPWCNOB4BHH4P7PVK5
X-MailFrom: huitema@huitema.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netconf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir@ietf.org, draft-ietf-netconf-yp-transport-capabilities.all@ietf.org, last-call@ietf.org, netconf@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [netconf] Re: [Last-Call] Re: [netconf] draft-ietf-netconf-yp-transport-capabilities-06 ietf last call Secdir review
List-Id: NETCONF WG list <netconf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/-w3hSwAhtB1s1Z3aK0kqTxU9-mk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Owner: <mailto:netconf-owner@ietf.org>
List-Post: <mailto:netconf@ietf.org>
List-Subscribe: <mailto:netconf-join@ietf.org>
List-Unsubscribe: <mailto:netconf-leave@ietf.org>

Did you actually submit draft 07? I did not find it yesterday in the 
IETF data tracker.

-- Christian  Huitema

On 8/13/2026 4:57 AM, Alex.Huang-Feng=40t-systems.com@dmarc.ietf.org wrote:
> Dear Christian,
>
> Thanks for the review.
>
> We addressed these comments in -07.
>
> Please find the diff in: 
> https://author-tools.ietf.org/diff?doc_1=draft-ietf-netconf-yp-transport-capabilities-06&url_2=https://raw.githubusercontent.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/refs/heads/main/draft-ietf-netconf-yp-transport-capabilities-07.txt 
> <https://author-tools.ietf.org/diff?doc_1=draft-ietf-netconf-yp-transport-capabilities-06&url_2=https://raw.githubusercontent.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/refs/heads/main/draft-ietf-netconf-yp-transport-capabilities-07.txt>
>
> And the document: 
> https://github.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/blob/main/draft-ietf-netconf-yp-transport-capabilities-07.txt
>
> Please see inline.
>
>> On 8 Aug 2026, at 02:58, Christian Huitema via Datatracker 
>> <noreply@ietf.org> wrote:
>>
>> Document: draft-ietf-netconf-yp-transport-capabilities
>> Title: YANG Notification Transport Capabilities
>> Reviewer: Christian Huitema
>> Review result: Not Ready
>>
>> I have reviewed draft-ietf-netconf-yp-transport-capabilities-06
>> as part of the security directorate's ongoing effort to review all
>> IETF documents being processed by the IESG. Theses comments were written
>> primarily for the benefit of the security area directors. Document 
>> editors and
>> WG chairs should treat these comments just like any other last call 
>> comments.
>>
>>  The summary of the review is Not Ready.
>>
>> I find this document confusingbecause it uses generic terms like "server"
>> or "transport" outside of the general understanding of these terms in 
>> IETF RFCs.
>>
>> Let's start with the introduction: The "ietf-system-capabilities" 
>> YANG module
>> defined in [RFC9196] allows a client to discover a set of capabilities
>> supported by a server (including, basic system capabilities and YANG-Push
>> related capabilities) both at implementation time and at runtime. OK. 
>> What kind
>> of server are we speaking about? A web server? An SMTP server? A server
>> implementing protocols like NETCONF? A VPN server? Capabilities of 
>> servers tend
>> to be very dependent on the type of application that the server is
>> implementing. The split of functions between client and servers is 
>> also very
>> dependent on the application. For example, a recursive DNS server is 
>> both a
>> server for stub DNS resolvers and a client to authoritative DNS 
>> resolvers.
>>
>> If we mean any server on the Internet, then the review could just as 
>> well stop
>> here. The concept of a unifying model for all Internet nodes that 
>> happen to
>> accept a request and do something for another node is just silly.
>>
>> If we mean specialized servers used in network management such as 
>> NETCONF or
>> RESTCONF, the draft should say so.
> Yes, we meant NETCONF/RESTCONF server.
>
> We changed the wording throughout the document to refer to the 
> NETCONF/RESTCONF client/server explicitly.
> Additionally, note we have client/server definitions in the 
> terminology section where we refer to RFC8342 for their definitions.
>
> These changes can be found in the abstract, introduction and section 2.
>>
>> Let's continue with the second paragraph of the introduction, the 
>> notion of
>> transport protocol. At the lowest level, mentioning transport 
>> protocols on the
>> Internet means something like TCP, UDP or QUIC. But then, the 
>> examples go on to
>> include TLS, DTLS. I suspect that the authors' cocnept of what 
>> "transport"
>> means is different from the regular understanding in, say, the IETF 
>> Web and
>> Internet Transport Area. Again, it would be nice if the draft was 
>> rewritten to
>> explain what is mean here by "transport", and if possible pick 
>> another name.
> Good point. I changed the wording to "notification delivery protocol”. 
> I also added the term “transport protocol” in the terminology section 
> to specify that we refer to the protocol used to deliver notifications 
> between a publisher and a receiver.
> As this term comes from RFC8639, we refrain from changing it in the 
> YANG module.
>>
>> The draft goes on to differentiate between TLS 1.2 and TLS 1.3, DTLS 
>> 1.2 and
>> DTLS 1.3, which seems wrong. TLS 1.3 is defined in RFC 9846, which 
>> obsoletes
>> older RFCa including RFC 5246 (TLS 1.2) and RFC 8446 (the original
>> specification of TLS 1.3). RFC 6347 (DTLS 1.2) is obsoleted by RFC 
>> 9147 (DTLS
>> 1.3). The draft should not make normative references to RFCs that are 
>> obsolete.
>> I do not think that the draft should differentiate "identity dtls12" and
>> "identity dtls13" -- these are just two version of the same protocol, 
>> that
>> certainly do not change the "identity" of the server.
> Such modelling was agreed by the WG and YANG doctors. The use of 
> identities directly rather than the protocol and its version is 
> because it would allow future users/developers to directly augment 
> such YANG identities.
> RFC9645 already uses this structure and we followed for consistency.
>
> Regarding referencing obsoleted RFCs as normative is because we define 
> those identities. Shall we move these obsoleted references to informative?
>>
>> I can understand the need to provide the list of supported
>> TLS or DTLS versions for management purposes, but this should be 
>> achieved by
>> something like a supported version parameter. The TLS and DTLS 
>> negotiations
>> include the capability of "negotiating down" from [D]TLS 1.3 to 
>> [D]TLS 1.2, if
>> the server and the client are specifically configured to tolerate such
>> downgrade. Maybe that acceptance or refusal of downgrade should be 
>> documented
>> in the YML text?
> The current document is not recommending any version of TLS or DTLS. 
> The scope of the document is rather providing the NETCONF/RESTCONF 
> server the capability to advertise what it supports for the 
> notification delivery protocols, it does not define which protocols 
> should be configured.
>
> Recommendations about which version to use are defined in their 
> respective transport protocols (e.g. 
> https://datatracker.ietf.org/doc/html/draft-ietf-netconf-udp-notif#name-secured-layer-for-udp-notif)
>
>>
>> I also do not really understand the relation between this "transport 
>> capability"
>> description and the "HTTPS" or "CSVRV" DNS records that clients use to
>> determine how to contact a server. Maybe that should be explained? 
>> Are clients
>> expected to retrieve the YML description of the server before 
>> establishing a
>> connection? It is pretty hard to review the security properties of this
>> proposal without understanding its planned usage.
> The intended usage of this model is between an orchestrator and a 
> network device. Such network is configured beforehand by an operator 
> and is typically dedicated to exchange configuration information.
> We added the following paragraph, helping the reader about the 
> expected usage:
>
>    This model is intended to be used between an orchestrator and a
>    network device that provides YANG notifications.  A management
>    network between the orchestrator and the network device is assumed to
>    be available for exchanging YANG management information.  The
>    management connectivity and endpoint of the network device are
>    expected to be provisioned as part of the management network
>    configuration.  The orchestrator can use the established management
>    connection to discover the notification transport capabilities of the
>    network device before establishing the notification subscription.
>
> I hope this text makes the document clearer.
>
> Regards,
> Alex
>>
>>
>>
>> _______________________________________________
>> netconf mailing list -- netconf@ietf.org
>> To unsubscribe send an email to netconf-leave@ietf.org
>
>