Re: [Netconf] [i2rs] 1 week extension to WG Adoption call for draft-mglt-i2rs-security-environments

Linda Dunbar <linda.dunbar@huawei.com> Wed, 02 September 2015 16:54 UTC

Return-Path: <linda.dunbar@huawei.com>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4BE11B4CC0; Wed, 2 Sep 2015 09:54:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rbyoIcb4lMKA; Wed, 2 Sep 2015 09:54:12 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E08E11B4D93; Wed, 2 Sep 2015 09:54:10 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml405-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BXB70853; Wed, 02 Sep 2015 16:54:09 +0000 (GMT)
Received: from DFWEML703-CHM.china.huawei.com (10.193.5.130) by lhreml405-hub.china.huawei.com (10.201.5.242) with Microsoft SMTP Server (TLS) id 14.3.235.1; Wed, 2 Sep 2015 17:54:08 +0100
Received: from DFWEML701-CHM.china.huawei.com ([10.193.5.50]) by dfweml703-chm ([10.193.5.130]) with mapi id 14.03.0235.001; Wed, 2 Sep 2015 09:54:03 -0700
From: Linda Dunbar <linda.dunbar@huawei.com>
To: Susan Hares <shares@ndzh.com>, "i2rs@ietf.org" <i2rs@ietf.org>
Thread-Topic: [i2rs] 1 week extension to WG Adoption call for draft-mglt-i2rs-security-environments
Thread-Index: AdDk2DUeqLRB1NvQQYSu5wfT4zHsdAAxvnFA
Date: Wed, 02 Sep 2015 16:54:03 +0000
Message-ID: <4A95BA014132FF49AE685FAB4B9F17F657D1D986@dfweml701-chm>
References: <005101d0e4d8$fb07ddd0$f1179970$@ndzh.com>
In-Reply-To: <005101d0e4d8$fb07ddd0$f1179970$@ndzh.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [10.192.11.192]
Content-Type: multipart/mixed; boundary="_004_4A95BA014132FF49AE685FAB4B9F17F657D1D986dfweml701chm_"
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: <http://mailarchive.ietf.org/arch/msg/netconf/Yv7uEkfR88JF5_5_6SzCA1GwVnk>
Cc: 'Netconf' <netconf@ietf.org>
Subject: Re: [Netconf] [i2rs] 1 week extension to WG Adoption call for draft-mglt-i2rs-security-environments
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Network Configuration WG mailing list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Sep 2015 16:54:16 -0000

Can the authors address my comments and the suggested changes to add a section on security threats and the associated requirements  with Closed Environment?

Closed environment deployment can easily give people a sense of secure because the links between I2RS Client and I2RS Agent are guided by a physical "Wall".  The false sense of "Secure" is actually more dangerous because it can easily make the deployment miss the crucial security procedure.

Therefore, I think it is important to have a dedicated section on security threats and requirement for the Closed Environment.

Attached is my suggested text.

Linda

From: i2rs [mailto:i2rs-bounces@ietf.org] On Behalf Of Susan Hares
Sent: Tuesday, September 01, 2015 12:10 PM
To: i2rs@ietf.org
Cc: 'Jeffrey Haas'; 'Netconf'
Subject: [i2rs] 1 week extension to WG Adoption call for draft-mglt-i2rs-security-environments

This is a 1 week extension to the WG adoption call for draft-mglt-i2rs-security.  Due error in the initial call email, the exact text to review was unclear ( https://mailarchive.ietf.org/arch/msg/i2rs/wwv1o8_mwurB05dN4D2yjr9tNFg).

In reviewing the email, it appears that the authors have agree to change or delete most of the concerns except for combining this draft with draft-hares-i2rs-auth-trans-04.txt.   The chairs have decided to adopt both drafts as WG drafts, and make a subsequent WG calls to determine if the drafts should be combined.

This draft is at:

https://www.ietf.org/id/draft-mglt-i2rs-security-environment-reqs-00.txt

Daniel has indicated several changes on the list.  If you would like to see a revised draft for further comments, please indicate this on the list.

Sue Hares and Jeff Haas
I2RS co-chairs