[Netconf] RE:  WGLC for draft-ietf-netconf-t ls-04.txt

badra@isima.fr Mon, 29 September 2008 19:14 UTC

Return-Path: <netconf-bounces@ietf.org>
X-Original-To: netconf-archive@ietf.org
Delivered-To: ietfarch-netconf-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8C11C3A690A; Mon, 29 Sep 2008 12:14:08 -0700 (PDT)
X-Original-To: netconf@core3.amsl.com
Delivered-To: netconf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E3FAE3A67D8 for <netconf@core3.amsl.com>; Mon, 29 Sep 2008 12:14:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.392
X-Spam-Level:
X-Spam-Status: No, score=-1.392 tagged_above=-999 required=5 tests=[AWL=0.405, BAYES_00=-2.599, HELO_EQ_FR=0.35, MIME_8BIT_HEADER=0.3, SARE_SUB_ENC_UTF8=0.152]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q8WWgTtyRKQD for <netconf@core3.amsl.com>; Mon, 29 Sep 2008 12:14:07 -0700 (PDT)
Received: from sp.isima.fr (sp.isima.fr [193.55.95.1]) by core3.amsl.com (Postfix) with ESMTP id E9AEA3A67A5 for <netconf@ietf.org>; Mon, 29 Sep 2008 12:14:06 -0700 (PDT)
Received: from www.isima.fr (www-data@www.isima.fr [193.55.95.79]) by sp.isima.fr (8.13.8/8.13.8) with SMTP id m8TKEB4r803032; Mon, 29 Sep 2008 21:14:11 +0100
Received: from 88.164.98.77 (SquirrelMail authenticated user badra) by www.isima.fr with HTTP; Mon, 29 Sep 2008 21:13:06 +0200 (CEST)
Message-ID: <59731.88.164.98.77.1222715586.squirrel@www.isima.fr>
In-Reply-To: <00bb01c92265$a9c7ba90$0600a8c0@china.huawei.com>
References: <50947.88.164.98.77.1222460713.squirrel@www.isima.fr> <00bb01c92265$a9c7ba90$0600a8c0@china.huawei.com>
Date: Mon, 29 Sep 2008 21:13:06 +0200
From: badra@isima.fr
To: David� B� Harrington� <dbharrington@comcast.net>
User-Agent: SquirrelMail/1.4.2
MIME-Version: 1.0
X-Priority: 3
Importance: Normal
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-3.0 (sp.isima.fr [193.55.95.1]); Mon, 29 Sep 2008 21:14:11 +0100 (WEST)
Cc: � <netconf@ietf.org>
Subject: [Netconf] RE:  WGLC for draft-ietf-netconf-t ls-04.txt
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Network Configuration WG mailing list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://www.ietf.org/mailman/private/netconf>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: netconf-bounces@ietf.org
Errors-To: netconf-bounces@ietf.org

Dear David,

> In syslog WG, we worked with the AD to decide what text was needed
> regarding ciphersuite support. We removed ciphersuite text that was
> redundant with TLS specs, and simplified ciphersuite support to this:
>
>    TLS typically uses certificates [RFC5280] to authenticate peers.
>    Implementations MUST support TLS 1.2 [RFC5246] and are REQUIRED to
>    support the mandatory to implement cipher suite, which is
>    TLS_RSA_WITH_AES_128_CBC_SHA.  This document is assumed to apply to
>    future versions of TLS, in which case the mandatory to implement
>    cipher suite for the implemented version MUST be supported.


Thank you for this better text. I will certainly integrate it entirely.
However, there is still a need to add a simple sentence on the PSK
authentication (the document optionally enable PSK authentication):

     For authentication based on PSKs, a compliant implementation MUST
     implement the cipher suite TLS_DHE_PSK_WITH_AES_128_CBC_SHA.

Best regards,
Badra
_______________________________________________
Netconf mailing list
Netconf@ietf.org
https://www.ietf.org/mailman/listinfo/netconf