Re: [netconf] Warren Kumari's No Objection on draft-ietf-netconf-keystore-30: (with COMMENT)

Warren Kumari <warren@kumari.net> Thu, 01 February 2024 15:25 UTC

Return-Path: <warren@kumari.net>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 651EEC14CE2C for <netconf@ietfa.amsl.com>; Thu, 1 Feb 2024 07:25:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kumari.net
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P2DnsSjveKFK for <netconf@ietfa.amsl.com>; Thu, 1 Feb 2024 07:25:33 -0800 (PST)
Received: from mail-ed1-x529.google.com (mail-ed1-x529.google.com [IPv6:2a00:1450:4864:20::529]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2FA4FC151093 for <netconf@ietf.org>; Thu, 1 Feb 2024 07:25:33 -0800 (PST)
Received: by mail-ed1-x529.google.com with SMTP id 4fb4d7f45d1cf-55a5e7fa471so1402133a12.1 for <netconf@ietf.org>; Thu, 01 Feb 2024 07:25:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kumari.net; s=google; t=1706801131; x=1707405931; darn=ietf.org; h=cc:to:subject:message-id:date:from:references:in-reply-to :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=+iLOXHOPo3b3LQ1gt/WkmcqtfpdlrWnY/9eAZENHePs=; b=cmpy+wFiSBybEtXGfMfzHuLqIyWTPOqQrHf5mXYuacVCbWGNdJynRAkYPyynmdoVu5 N9xv2iHfeYxwbwbgIAU018VE8DlEkFRiwYxnumbYexuOSll9qRnszCG08KaWHhgPLd80 jPgAuQcq9idVwNA10HLv1jgfBS6Zm50oqVuhIL1UaFiF+EDqXtcNZt6gy8tB0cpCCEJf 9HWkJPvKKs/0VDRma1OGf8yTfHhUJww38VBYiLKry4QjMohdHQQxItAfYV3i/DIa6WiN 5CJ3iad9J3JnWnGABitmYNVQZ9QoJNNnrn6XkfzFLtF/h8VPrfUKdi65jjfzh6URZM4P oU2A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1706801131; x=1707405931; h=cc:to:subject:message-id:date:from:references:in-reply-to :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=+iLOXHOPo3b3LQ1gt/WkmcqtfpdlrWnY/9eAZENHePs=; b=xMLgbjfA7kv3RLriz1FYhp52uPWF44FMqRF1e5F2bDfPpUvPcRZ4vj3YK1kdZtwUW6 UWXrr7pycr9rgDI1yBMhE7CZQCe9HO5Gc1vGmpSqV6vKuoQ5ojy5KDlUvd6Uhe8y9Ese E/T6bKtNw/TkChnS+i25CvSD7/HjzpZHnSPvcojLpSItrjsZsizLIywn3Bamc5ZubKY1 do1Q1arYm5GfboiVj1LWBrafnEKS/WuonVNJ/TpLNFzFf4S5AQJcxWpjQMRgg7rpkMNk a4UnqqixQpSXGWoI8F5VBsc26hfzRZ0LJCDR7iYIxeA29jVedQoG6NlgG1uVDMuoyOR0 JJaA==
X-Gm-Message-State: AOJu0YyAH0RNS18zeDfnTGv33YqYMHkMHXPJj8BzG0ryva89+36yl/Jb Zw4nAbQMrycOP8vHEUnUbfeha8T93I04pzq2E4KQ6I8nA9Lomh8zJOmWpMMHW2Cvk7/Pl95ZAeq yVQoFQ3Djc8Z3r5ewhW1w+qkYIchxMvBAJUTFMw==
X-Google-Smtp-Source: AGHT+IG0ZFdzOhRwGNcrsZLWfcBpo08kSzHBy23ylzyKOzKXxH2nw81hMCHv5A5nZZi8G2GQlq6zyoYblZ50O8UrzFk=
X-Received: by 2002:a05:6402:341:b0:55f:d808:328c with SMTP id r1-20020a056402034100b0055fd808328cmr327162edw.31.1706801131129; Thu, 01 Feb 2024 07:25:31 -0800 (PST)
Received: from 649336022844 named unknown by gmailapi.google.com with HTTPREST; Thu, 1 Feb 2024 07:25:29 -0800
Mime-Version: 1.0
X-Superhuman-ID: ls3db83w.ca9165c2-da70-45f9-85f2-16d178934511
X-Superhuman-Draft-ID: draft00a91d301a2c5c40
In-Reply-To: <0100018d6189f4dd-7605a0fd-06fe-486c-b654-dc9c3b0079d5-000000@email.amazonses.com>
X-Mailer: Superhuman Desktop (2024-01-31T20:16:52Z)
References: <170666095818.21441.3339510394156215916@ietfa.amsl.com> <0100018d6189f4dd-7605a0fd-06fe-486c-b654-dc9c3b0079d5-000000@email.amazonses.com>
From: Warren Kumari <warren@kumari.net>
Date: Thu, 01 Feb 2024 07:25:29 -0800
Message-ID: <CAHw9_iKpK6nw2BM3CzkZ1xQVmq_tn89f9nQY3Z8m0exwaPqfig@mail.gmail.com>
To: Kent Watsen <kent+ietf@watsen.net>
Cc: The IESG <iesg@ietf.org>, draft-ietf-netconf-keystore@ietf.org, netconf-chairs@ietf.org, netconf@ietf.org, Qin Wu <bill.wu@huawei.com>, Mahesh Jethanandani <mjethanandani@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000001fa1280610539b2d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/6SFI5x7Wt-dFAqE1EYbK24tmFPM>
Subject: Re: [netconf] Warren Kumari's No Objection on draft-ietf-netconf-keystore-30: (with COMMENT)
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Feb 2024 15:25:37 -0000

On Wed, Jan 31, 2024 at 5:00 PM, Kent Watsen <kent+ietf@watsen.net> wrote:

> Hi Warren,
>
> Thank you for you valuable comments.
> Please find below my responses.
>
> Kent
>
> On Jan 30, 2024, at 7:29 PM, Warren Kumari via Datatracker <noreply@ietf.
> org> wrote:
>
> Warren Kumari has entered the following ballot position for
> draft-ietf-netconf-keystore-30: No Objection
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
> Please refer to https://www.ietf.org/about/groups/iesg/statements/
> handling-ballot-positions/ for more information about how to handle
> DISCUSS and COMMENT positions.
>
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-netconf-keystore/
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> I support Roman's DISCUSS.
>
> Also, when reading this document I initially got excited, thinking that
> I'd find more text on the 'hidden keys', but my excitement was short
> lived...:-)
>
> Sorry to disappoint! ;)
>
> Assuming you add text to the other YANG crypto types document, perhaps you
> can include it here too?
>
> Unlike the “crypto-types” draft, this draft has a dedicated section called
> "Support for Built-in Keys”, is it not enough?
>
> One thing I noticed was that this section doesn’t ever use the word
> “hidden”, though it’s mostly the case that they would be hidden, though
> they could possibly be “encrypted”, though it may not be worth saying that.
>
> This being the case, how about this edit?
>
> OLD: Built-in keys are expected to be set by a vendor-specific process.
> NEW: Built-in keys are "hidden" keys expected to be set by a
> vendor-specific process.
>


Thank you, that helps…

W




> Thanks again!
> Kent
>