[netconf] Question about NACM username for configured-subscription receivers

Roman Janota <Roman.Janota@cesnet.cz> Tue, 18 August 2026 08:06 UTC

Return-Path: <roman.janota@cesnet.cz>
X-Original-To: netconf@mail2.ietf.org
Delivered-To: netconf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7F53812B750F7 for <netconf@mail2.ietf.org>; Tue, 18 Aug 2026 01:06:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787040414; bh=V3FSGKxhbNUtWKTMRHpVBMVCngrDetUoD/i48tN7EYs=; h=From:Subject:Date:To; b=rJ5VJhO2I4MuVE05iikXzO1M5CylMgmmEMPI/L2TA/bs9/GaNcBx1O33BcmvuEZDP R1Rh1qICXD0zaqheLpGTDGiQjNT2D6IgODx4wzSIKZqOSaMOLBSJ8YQaPcQQHqWlz0 vfGvTIKUbD8ekX4F3g4N4oDbxRuUAl/6EweRxqTc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=cesnet.cz
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2hhtZwTwcX93 for <netconf@mail2.ietf.org>; Tue, 18 Aug 2026 01:06:53 -0700 (PDT)
Received: from office2.cesnet.cz (office2.cesnet.cz [IPv6:2001:718:ff05:10b::237]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 25E7E12B750E6 for <netconf@ietf.org>; Tue, 18 Aug 2026 01:06:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cesnet.cz; s=office2-2020; t=1787040405; bh=ecsw6cOb1BmvXsK8Hb6H+/PVonbi19rlmIfqjVxZO9A=; h=From:Subject:Date:To; b=Jus0WjS60E8Vnxm7w3+b6ZUgagW3MYkXCCAcLEI1Vol4ap7KRZxWEvTalzpLH8suc Ut9UHxPzM8cKPy2mM/+fXvVYp9OppzdUurULIK4WyX9sjHrstvIsxEYhpAU269gyEe xs4ZDUQ5DjSYt3OueP4kIPmI/q/mBBTXo1apXfLhLegVEnlNir/vsZ2B8hHgPLcBql 7NR/UOfOolf8ob1pwHkZ6xF2l5MV1ITXHrbCEee+KKvFr44K+b688dol6rKPKVIJNZ nlA9HGIf5ckNu5lHlLByvxzcOdl86BH9kqKcuOLk25v/AJrw3tbL3Lut91MPH1Ysxt 2fm0irh3kTiKQ==
Received: from smtpclient.apple (a-004300000010.vpn.cesnet.cz [IPv6:2001:718:ff05:acb:a00:43:0:10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by office2.cesnet.cz (Postfix) with ESMTPSA id 9A078118004C for <netconf@ietf.org>; Tue, 18 Aug 2026 10:06:45 +0200 (CEST)
From: Roman Janota <Roman.Janota@cesnet.cz>
Content-Type: multipart/signed; boundary="Apple-Mail=_D8FC9D07-092A-44B2-BAF8-521065F09D90"; protocol="application/pkcs7-signature"; micalg="sha-256"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.600.51.1.1\))
Message-Id: <D7779BF5-33F5-4F93-93AA-2DDBF35D16CC@cesnet.cz>
Date: Tue, 18 Aug 2026 10:06:35 +0200
To: "netconf@ietf.org" <netconf@ietf.org>
X-Mailer: Apple Mail (2.3864.600.51.1.1)
Message-ID-Hash: HHU763W32EH5AMOWFOHLXYTUD7HJZLI2
X-Message-ID-Hash: HHU763W32EH5AMOWFOHLXYTUD7HJZLI2
X-MailFrom: roman.janota@cesnet.cz
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netconf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [netconf] Question about NACM username for configured-subscription receivers
List-Id: NETCONF WG list <netconf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/RyAoivbug57nAV7NSHlPTncBFds>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Owner: <mailto:netconf-owner@ietf.org>
List-Post: <mailto:netconf@ietf.org>
List-Subscribe: <mailto:netconf-join@ietf.org>
List-Unsubscribe: <mailto:netconf-leave@ietf.org>

Hi all,

I'd like to clarify how RFC 8341 (NACM) is supposed to apply to configured subscriptions under RFC 8639, in particular when the transport is draft-ietf-netconf-udp-notif. I've read the three documents together and there is a gap I cannot resolve from the text.

Under RFC 8639 §2.5, configured subscriptions are managed purely through configuration: any client with write permission on /subscriptions can create a receiver-instance and a subscription targeting any event stream the publisher exposes. UDP-Notif defines the receiver-instance transport parameters (remote-address, remote-port, local-address, local-port, dtls), but nothing identity related.

RFC 8639 §2.1 says access control may silently exclude event records for which the receiver has no read access, and §8 lists the “stream" leaf as sensitive because it "could set a subscription to an event stream that does not contain content permitted for the targeted receivers.” - so per receiver read checks are clearly assumed.

My question is where the NACM username comes from. RFC 8341 ties the username to the transport layer during session establishment. For a dynamic subscription the model fits: the receiver is the subscriber, bound to a transport session. For a configured subscription over UDP-notif there is no NETCONF/RESTCONF session associated with the receiver at delivery time, and DTLS gives the publisher no NACM username for the receiver (unless we were to perform some form of cert-to-name mechanism?). As far as I can tell, none of the three documents defines how to obtain the username against which NACM should evaluate the receiver's read access.

Am I missing something in the existing specs, or is this genuinely undefined? Guidance would be appreciated.

Thank you,

Roman Janota