[netconf] Re: [Last-Call] Re: [netconf] draft-ietf-netconf-yp-transport-capabilities-06 ietf last call Secdir review
Christian Huitema <huitema@huitema.net> Fri, 14 August 2026 15:48 UTC
Return-Path: <huitema@huitema.net>
X-Original-To: netconf@mail2.ietf.org
Delivered-To: netconf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E2248129DD99B; Fri, 14 Aug 2026 08:48:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786722524; bh=2qaOxkOSFvZYe4L1NABIKLdtDr82Al9yK+Gag2xWZNw=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=zP9FbSHa5h/qGRvM9xThY+v4HDZpnFBTR4UMEN1f+QtoBivUI6JCCt2z3qCgUMgnU 0T2rnGJXgWuB6sxB841V8Qnxa8PTarQ7WRPZl02afM4jsjzK6gbzZgP2kwbrpqPyfX 8rDyKedBbNWuElKU0lRLFhYIsin7Q1fVqvLF/r7I=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0GARrUNyDlxN; Fri, 14 Aug 2026 08:48:44 -0700 (PDT)
Received: from semf11.mfg.siteprotect.com (semf11.mfg.siteprotect.com [64.26.60.174]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 307B9129DD507; Fri, 14 Aug 2026 08:48:26 -0700 (PDT)
Received: from smtpauth02.mfg.siteprotect.com ([64.26.60.151]) by se05.mfg.siteprotect.com with esmtp (Exim 4.94.2) (envelope-from <huitema@huitema.net>) id 1wuttj-00G7jT-J3; Fri, 14 Aug 2026 11:48:16 -0400
Received: from [192.168.1.104] (unknown [172.56.15.22]) (Authenticated sender: huitema@huitema.net) by smtpauth02.mfg.siteprotect.com (Postfix) with ESMTPSA id 4hM67t4DG9zCSFvL3; Fri, 14 Aug 2026 11:48:10 -0400 (EDT)
Message-ID: <b1b635ea-2235-4a3e-8a39-825915ceaa60@huitema.net>
Date: Fri, 14 Aug 2026 08:48:08 -0700
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: Alex.Huang-Feng=40t-systems.com@dmarc.ietf.org
References: <178615071319.153546.9203560369914607963@dt-datatracker-559c48c7fb-9llwz> <50F320D3-F241-4966-A56C-B147B2A2BBA3@t-systems.com>
Content-Language: en-US
From: Christian Huitema <huitema@huitema.net>
Autocrypt: addr=huitema@huitema.net; keydata= xsBNBFIRX8gBCAC26usy/Ya38IqaLBSu33vKD6hP5Yw390XsWLaAZTeQR64OJEkoOdXpvcOS HWfMIlD5s5+oHfLe8jjmErFAXYJ8yytPj1fD2OdSKAe1TccUBiOXT8wdVxSr5d0alExVv/LO I/vA2aU1TwOkVHKSapD7j8/HZBrqIWRrXUSj2f5n9tY2nJzG9KRzSG0giaJWBfUFiGb4lvsy IaCaIU0YpfkDDk6PtK5YYzuCeF0B+O7N9LhDu/foUUc4MNq4K3EKDPb2FL1Hrv0XHpkXeMRZ olpH8SUFUJbmi+zYRuUgcXgMZRmZFL1tu6z9h6gY4/KPyF9aYot6zG28Qk/BFQRtj7V1ABEB AAHNJ0NocmlzdGlhbiBIdWl0ZW1hIDxodWl0ZW1hQGh1aXRlbWEubmV0PsLAeQQTAQIAIwUC UhFfyAIbLwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEJNDCbJVyA1yhbYH/1ud6x6m VqGIp0JcZUfSQO8w+TjugqxCyGNn+w/6Qb5O/xENxNQ4HaMQ5uSRK9n8WKKDDRSzwZ4syKKf wbkfj05vgFxrjCynVbm1zs2X2aGXh+PxPL/WHUaxzEP7KjYbLtCUZDRzOOrm+0LMktngT/k3 6+EZoLEM52hwwpIAzJoscyEz7QfqMOZtFm6xQnlvDQeIrHx0KUvwo/vgDLK3SuruG1CSHcR0 D24kEEUa044AIUKBS3b0b8AR7f6mP2NcnLpdsibtpabi9BzqAidcY/EjTaoea46HXALk/eJd 6OLkLE6UQe1PPzQC4jB7rErX2BxnSkHDw50xMgLRcl5/b1bOwE0EUhFfyAEIAKp7Cp8lqKTV CC9QiAf6QTIjW+lie5J44Ad++0k8gRgANZVWubQuCQ71gxDWLtxYfFkEXjG4TXV/MUtnOliG 5rc2E+ih6Dg61Y5PQakm9OwPIsOx+2R+iSW325ngln2UQrVPgloO83QiUoi7mBJPbcHlxkhZ bd3+EjFxSLIQogt29sTcg2oSh4oljUpz5niTt69IOfZx21kf29NfDE+Iw56gfrxI2ywZbu5o G+d0ZSp0lsovygpk4jK04fDTq0vxjEU5HjPcsXC4CSZdq5E2DrF4nOh1UHkHzeaXdYR2Bn1Y wTePfaHBFlvQzI+Li/Q6AD/uxbTM0vIcsUxrv3MNHCUAEQEAAcLBfgQYAQIACQUCUhFfyAIb LgEpCRCTQwmyVcgNcsBdIAQZAQIABgUCUhFfyAAKCRC22tOSFDh1UOlBB/94RsCJepNvmi/c YiNmMnm0mKb6vjv43OsHkqrrCqJSfo95KHyl5Up4JEp8tiJMyYT2mp4IsirZHxz/5lqkw9Az tcGAF3GlFsj++xTyD07DXlNeddwTKlqPRi/b8sppjtWur6Pm+wnAHp0mQ7GidhxHccFCl65w uT7S/ocb1MjrTgnAMiz+x87d48n1UJ7yIdI41Wpg2XFZiA9xPBiDuuoPwFj14/nK0elV5Dvq 4/HVgfurb4+fd74PV/CC/dmd7hg0ZRlgnB5rFUcFO7ywb7/TvICIIaLWcI42OJDSZjZ/MAzz BeXm263lHh+kFxkh2LxEHnQGHCHGpTYyi4Z3dv03HtkH/1SI8joQMQq00Bv+RdEbJXfEExrT u4gtdZAihwvy97OPA2nCdTAHm/phkzryMeOaOztI4PS8u2Ce5lUB6P/HcGtK/038KdX5MYST Fn8KUDt4o29bkv0CUXwDzS3oTzPNtGdryBkRMc9b+yn9+AdwFEH4auhiTQXPMnl0+G3nhKr7 jvzVFJCRif3OAhEm4vmBNDE3uuaXFQnbK56GJrnqVN+KX5Z3M7X3fA8UcVCGOEHXRP/aubiw Ngawj0V9x+43kUapFp+nF69R53UI65YtJ95ec4PTO/Edvap8h1UbdEOc4+TiYwY1TBuIKltY 1cnrjgAWUh/Ucvr++/KbD9tD6C8=
In-Reply-To: <50F320D3-F241-4966-A56C-B147B2A2BBA3@t-systems.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=huitema@huitema.net
X-Originating-IP: 64.26.60.151
X-SpamExperts-Domain: mfg.outbound
X-SpamExperts-Username: 64.26.60.150/31
Authentication-Results: mfg.siteprotect.com; auth=pass smtp.auth=64.26.60.150/31@mfg.outbound
X-SpamExperts-Outgoing-Class: ham
X-SpamExperts-Outgoing-Evidence: SB/global_tokens (0.00674273864004)
X-Recommended-Action: accept
X-Filter-ID: 9kzQTOBWQUFZTohSKvQbgI7ZDo5ubYELi59AwcWUnuXEF4coiG8G0G1XkBUeBRx/2fRcyiRaHQwj qh+oywV8gSu2SmbhJN1U9FKs8X3+Nt127hcteP1p0NVNV47moiZtUnZMMMyaNBeO+OvFQHUlG4JL M0i5ZAms0EHrvcCaVIPzS2j7VVYZgOQ1cjn/7IlYGnT3EFAinyrilm9zau/FuzkQt9Nb4Ml7QXdk EetczWDLE03raa/FEALf0Z8wGU5oeB7itP8hgjDRserKv4bhbzi838DBmUKWhOLHfo543wbEMzer JfQa9UAYKsgEV8p+MUJTS2Jsxpkx+IHIsDarm2U3gyy0nlbakKK22WPBaiwbgg495zj6nulrGyqU W0O7BzwjTsVMVyOl19f8lyvzt+r5AKGW9/TOOTahqQAL7UFuFyRuvO4NjGU7J++OBIwAjGF59FBi OEjybg1XAEa3CAd88yMqU0HrXIiiYDPO8En7DffnIB/wxQ+/9g75Ry+DouHzVFIkEQAW/PYuLwxV gHblqFUUenMzeb9l7M2YQBEOpzYr3AGNmWibeLl3v+ynXt4hgySBdQ+JDLfyzXaPoLJfqLd0mkJx 0VeUCOHRhk3j9Mww1rxsEUntOr/IaIo3fAKZvAjuJrqAt2e//bIc/9BXEj0V6NArv3ouNHbuPZdm gtPkD6BTccjiKvE7CDZY6cTrAfIBtLJVe62uoyOAUvYtQLYQpwUf7KSftolpBssZugOMFKUcGN1I f74KjJaKxDM3qyX0GvVAGCrIBFfKfqul/WTobZWAGkW3d7y6oL05kKPcZZ21mzX0AR/E8H5aLvQc MALmJ9ap2na4ef0d1X3akD128a4og9jI3HpK2Y7keVn7KnKadhO/iDad4A8EKQ/tW2zE8IiVVII0 LEBalYZ/6bu8v13qOVHxX3l0NF0T0bbw5qgmAGYJgCiWEPaIa2xA667+/0zShVia5gzbOTpb4wE/ ZcPLofVWyyKeFEwmP04c+P138Fv76xQAwbzDXV0j2xzDtoQ4MAnPQjPcWa6Xy8YqsOR990w7SSnM ppaiHRKKZLTITYajcwsmZ8Uiy0M2f0eec5b2PMBoykxfXS3eq94ck1Z6OhdHl6mvgPE8CVsONrMJ uGzuoGnKTKcypXPpF7SzDgytbgyTMY3rH06OcoJw5Mc6YNazdH7fRbvMcw1VaeVLMg7TU7z13Qm6 StH2P94AA0Ha6+1NAjqHhr2l1CYXE8A5H0Ic3ArAj94daZHfkQpoxYa8asJrla79MxogvjxId3AG 6vsL0WtIBb/s6/VvV6lP9TqbWUXs3Jh+mMTSema1Fa4rG8YQgIU0BvOdHRaQghl54OZphjdyBQ==
X-Report-Abuse-To: spam@se02.mfg.siteprotect.com
X-Complaints-To: abuse@se01.mfg.siteprotect.com
Message-ID-Hash: DBYKVULE34T4V4LPWCNOB4BHH4P7PVK5
X-Message-ID-Hash: DBYKVULE34T4V4LPWCNOB4BHH4P7PVK5
X-MailFrom: huitema@huitema.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netconf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: secdir@ietf.org, draft-ietf-netconf-yp-transport-capabilities.all@ietf.org, last-call@ietf.org, netconf@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [netconf] Re: [Last-Call] Re: [netconf] draft-ietf-netconf-yp-transport-capabilities-06 ietf last call Secdir review
List-Id: NETCONF WG list <netconf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/-w3hSwAhtB1s1Z3aK0kqTxU9-mk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Owner: <mailto:netconf-owner@ietf.org>
List-Post: <mailto:netconf@ietf.org>
List-Subscribe: <mailto:netconf-join@ietf.org>
List-Unsubscribe: <mailto:netconf-leave@ietf.org>
Did you actually submit draft 07? I did not find it yesterday in the IETF data tracker. -- Christian Huitema On 8/13/2026 4:57 AM, Alex.Huang-Feng=40t-systems.com@dmarc.ietf.org wrote: > Dear Christian, > > Thanks for the review. > > We addressed these comments in -07. > > Please find the diff in: > https://author-tools.ietf.org/diff?doc_1=draft-ietf-netconf-yp-transport-capabilities-06&url_2=https://raw.githubusercontent.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/refs/heads/main/draft-ietf-netconf-yp-transport-capabilities-07.txt > <https://author-tools.ietf.org/diff?doc_1=draft-ietf-netconf-yp-transport-capabilities-06&url_2=https://raw.githubusercontent.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/refs/heads/main/draft-ietf-netconf-yp-transport-capabilities-07.txt> > > And the document: > https://github.com/network-analytics/draft-netana-netconf-yang-push-transport-capabilities/blob/main/draft-ietf-netconf-yp-transport-capabilities-07.txt > > Please see inline. > >> On 8 Aug 2026, at 02:58, Christian Huitema via Datatracker >> <noreply@ietf.org> wrote: >> >> Document: draft-ietf-netconf-yp-transport-capabilities >> Title: YANG Notification Transport Capabilities >> Reviewer: Christian Huitema >> Review result: Not Ready >> >> I have reviewed draft-ietf-netconf-yp-transport-capabilities-06 >> as part of the security directorate's ongoing effort to review all >> IETF documents being processed by the IESG. Theses comments were written >> primarily for the benefit of the security area directors. Document >> editors and >> WG chairs should treat these comments just like any other last call >> comments. >> >> The summary of the review is Not Ready. >> >> I find this document confusingbecause it uses generic terms like "server" >> or "transport" outside of the general understanding of these terms in >> IETF RFCs. >> >> Let's start with the introduction: The "ietf-system-capabilities" >> YANG module >> defined in [RFC9196] allows a client to discover a set of capabilities >> supported by a server (including, basic system capabilities and YANG-Push >> related capabilities) both at implementation time and at runtime. OK. >> What kind >> of server are we speaking about? A web server? An SMTP server? A server >> implementing protocols like NETCONF? A VPN server? Capabilities of >> servers tend >> to be very dependent on the type of application that the server is >> implementing. The split of functions between client and servers is >> also very >> dependent on the application. For example, a recursive DNS server is >> both a >> server for stub DNS resolvers and a client to authoritative DNS >> resolvers. >> >> If we mean any server on the Internet, then the review could just as >> well stop >> here. The concept of a unifying model for all Internet nodes that >> happen to >> accept a request and do something for another node is just silly. >> >> If we mean specialized servers used in network management such as >> NETCONF or >> RESTCONF, the draft should say so. > Yes, we meant NETCONF/RESTCONF server. > > We changed the wording throughout the document to refer to the > NETCONF/RESTCONF client/server explicitly. > Additionally, note we have client/server definitions in the > terminology section where we refer to RFC8342 for their definitions. > > These changes can be found in the abstract, introduction and section 2. >> >> Let's continue with the second paragraph of the introduction, the >> notion of >> transport protocol. At the lowest level, mentioning transport >> protocols on the >> Internet means something like TCP, UDP or QUIC. But then, the >> examples go on to >> include TLS, DTLS. I suspect that the authors' cocnept of what >> "transport" >> means is different from the regular understanding in, say, the IETF >> Web and >> Internet Transport Area. Again, it would be nice if the draft was >> rewritten to >> explain what is mean here by "transport", and if possible pick >> another name. > Good point. I changed the wording to "notification delivery protocol”. > I also added the term “transport protocol” in the terminology section > to specify that we refer to the protocol used to deliver notifications > between a publisher and a receiver. > As this term comes from RFC8639, we refrain from changing it in the > YANG module. >> >> The draft goes on to differentiate between TLS 1.2 and TLS 1.3, DTLS >> 1.2 and >> DTLS 1.3, which seems wrong. TLS 1.3 is defined in RFC 9846, which >> obsoletes >> older RFCa including RFC 5246 (TLS 1.2) and RFC 8446 (the original >> specification of TLS 1.3). RFC 6347 (DTLS 1.2) is obsoleted by RFC >> 9147 (DTLS >> 1.3). The draft should not make normative references to RFCs that are >> obsolete. >> I do not think that the draft should differentiate "identity dtls12" and >> "identity dtls13" -- these are just two version of the same protocol, >> that >> certainly do not change the "identity" of the server. > Such modelling was agreed by the WG and YANG doctors. The use of > identities directly rather than the protocol and its version is > because it would allow future users/developers to directly augment > such YANG identities. > RFC9645 already uses this structure and we followed for consistency. > > Regarding referencing obsoleted RFCs as normative is because we define > those identities. Shall we move these obsoleted references to informative? >> >> I can understand the need to provide the list of supported >> TLS or DTLS versions for management purposes, but this should be >> achieved by >> something like a supported version parameter. The TLS and DTLS >> negotiations >> include the capability of "negotiating down" from [D]TLS 1.3 to >> [D]TLS 1.2, if >> the server and the client are specifically configured to tolerate such >> downgrade. Maybe that acceptance or refusal of downgrade should be >> documented >> in the YML text? > The current document is not recommending any version of TLS or DTLS. > The scope of the document is rather providing the NETCONF/RESTCONF > server the capability to advertise what it supports for the > notification delivery protocols, it does not define which protocols > should be configured. > > Recommendations about which version to use are defined in their > respective transport protocols (e.g. > https://datatracker.ietf.org/doc/html/draft-ietf-netconf-udp-notif#name-secured-layer-for-udp-notif) > >> >> I also do not really understand the relation between this "transport >> capability" >> description and the "HTTPS" or "CSVRV" DNS records that clients use to >> determine how to contact a server. Maybe that should be explained? >> Are clients >> expected to retrieve the YML description of the server before >> establishing a >> connection? It is pretty hard to review the security properties of this >> proposal without understanding its planned usage. > The intended usage of this model is between an orchestrator and a > network device. Such network is configured beforehand by an operator > and is typically dedicated to exchange configuration information. > We added the following paragraph, helping the reader about the > expected usage: > > This model is intended to be used between an orchestrator and a > network device that provides YANG notifications. A management > network between the orchestrator and the network device is assumed to > be available for exchanging YANG management information. The > management connectivity and endpoint of the network device are > expected to be provisioned as part of the management network > configuration. The orchestrator can use the established management > connection to discover the notification transport capabilities of the > network device before establishing the notification subscription. > > I hope this text makes the document clearer. > > Regards, > Alex >> >> >> >> _______________________________________________ >> netconf mailing list -- netconf@ietf.org >> To unsubscribe send an email to netconf-leave@ietf.org > >
- [netconf] draft-ietf-netconf-yp-transport-capabil… Christian Huitema via Datatracker
- [netconf] Re: draft-ietf-netconf-yp-transport-cap… Alex.Huang-Feng
- [netconf] Re: [Last-Call] Re: [netconf] draft-iet… Christian Huitema