Re: [netconf] AD review of draft-ietf-netconf-sztp-csr

"Rob Wilton (rwilton)" <rwilton@cisco.com> Wed, 07 July 2021 20:43 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73B333A275B; Wed, 7 Jul 2021 13:43:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -11.895
X-Spam-Level:
X-Spam-Status: No, score=-11.895 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=lxYjf1Vc; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=lIZr30HK
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NNkhBBCQLsfq; Wed, 7 Jul 2021 13:43:07 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 32B503A26D4; Wed, 7 Jul 2021 13:42:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=11182; q=dns/txt; s=iport; t=1625690532; x=1626900132; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=3mYpj9DTWLEeQDrQzjHRrOmwxltqoyy4WMWAobq9kGQ=; b=lxYjf1VcFOIrRsFkVfomEHjPqhuA0zKUYGeM1lHFWa36ydtq0k0YdU64 tciDLSK3a/B6xXI57nyE0EcQcgvDW2iQQhB1xnLVqmZN+SNxkfqMPaIM4 PSDX4OQD5hRm3NVCr3Oa/3o01ioUTzHyREWL9Z1Nopfs8GLpvusxG28Z9 4=;
X-IPAS-Result: A0AfAgAyEeZgl4kNJK1RCR4BAQsSDIIOC4EjMFF+WjcxhEiDSAOFOYhcA5UnhQCBLoElA1QLAQEBDQEBNwoEAQGEUwIXgl4CJTQJDgIEAQEBAQMCAwEBAQEFAQEFAQEBAgEGBBQBAQEBAQEBAWiFaA2GRQEBAQQSEQoTAQE3AQ8CAQgRBAEBKwICAjAdCAEBBA4FCBqCTwGBflcDLwEOm0oBgToCih96gTKBAYIHAQEGBASBNQGDaBiCMgMGgTqCe4QMAQGGYSccgUlEgViCYj6CYgKBNC4rgmo2gi6CIRpgPypDECBTWiwakiKDKYgsjTCSEQqDIYonlBoSg2OLSZcFoieYTAIEAgQFAg4BAQaCJzmBW3AVgyRQGQ6OHxmDV4pecwstAgYBCQEBAwmKZQEB
IronPort-PHdr: A9a23:TBQg0h1CBeBXF6yvsmDPt1BlVkEcU/3cIQcJ8ZchzbRDbvfr85fjO RnZ4vNgxB/MUJ7A4v1Jw+zRr+j7WGMG7JrA1RJKcJFFWxIfz8lDmQsmDZ2aAFHgIfisaSEmT 4xOUVZ/9CS9Nk5YUM/1e1zVpCi06jgfUhXyPAZ4PKL7AInX2s+2zOu1vZbUZlYguQ==
IronPort-HdrOrdr: A9a23:OgjFuKEbiWY9czbLpLqFaJHXdLJyesId70hD6qkvc31om52j+f xGws516fatskdvZJkh8erwX5VoMkmsi6KdgLNhc4tKOTOHhILGFvAY0WKP+UyEJ8S6zJ8g6U 4CSdk+NDSTNykBsS+S2mDReLxMrKjlgcKVbKXlvgpQpGpRGsddBnJCe36m+zpNNXB77PQCZf 6hz/sCgwDlVWUcb8y9CHVAdfPEvcf3mJXvZgNDLwI76SGV5AnYqILSIly95FMzQjlPybAt/S zuiAri/JiutPm911v1y3LT1ZJLg9Hso+EzR/Bky/JlaAkEuDzYILiJaIfy+wzdZ9vfrmrCpe O85ivI+f4Dsk85MFvF+ScFkDOQoQrGo0WSuWNwx0GT+vAQgFkBepd8bUUzSGqC16NohqAO7I tbm22erJZZFhXGgWD04MXJTQhjkg6urWMlivN7tQ0UbWIyUs4YkWUkxjIfLH7AJlOM1Kk3VO 11SM3M7vdfdl2XK3jfo2l02dSpGnA+BA2PTEQOstGcl2E+pgE082IIgMgE2nsQ/pM0TJdJo+ zCL6RzjblLCssbd7h0CusNSda+TmbNXRXPOmSPJkmPLtBLB5sMke+/3FwR3pDkRHUl9upGpH 3xaiIviYdpQTOdNSSn5uw+zizw
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.84,221,1620691200"; d="scan'208,217";a="720842721"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by alln-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 07 Jul 2021 20:42:11 +0000
Received: from mail.cisco.com (xbe-rcd-002.cisco.com [173.37.102.17]) by alln-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 167KgADW027615 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 7 Jul 2021 20:42:11 GMT
Received: from xfe-rtp-001.cisco.com (64.101.210.231) by xbe-rcd-002.cisco.com (173.37.102.17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15; Wed, 7 Jul 2021 15:42:10 -0500
Received: from xfe-rcd-005.cisco.com (173.37.227.253) by xfe-rtp-001.cisco.com (64.101.210.231) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15; Wed, 7 Jul 2021 16:42:09 -0400
Received: from NAM12-MW2-obe.outbound.protection.outlook.com (72.163.14.9) by xfe-rcd-005.cisco.com (173.37.227.253) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.15 via Frontend Transport; Wed, 7 Jul 2021 15:42:09 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=e1WkRQ3wKdLCoszc+ywt/2WU1Xt5h/0zEWaLRXDX3gHwqYa4jFaNU+f2SSc2d5BgskZq824clw4qFIue8AnWygiQQIYDVxiWx5r7myDpKrjRxIzpk5C+TVzsLTaRkNapE5neZNdZ7bjqC8FPsOjypDAkHmBdgKFaHbCkz+VDzujrPaKfLlVv1N96/xWbA9uU2roJxCo1TsaCqdYiDYu4f7pp6BbH7lWpbzYDCVMEbUviXC/rMz5V2s/zv3YILz4NJVHTCgNxgRq6eJaSzlxDzPowUtF6CWYqO/LXg3AAvR6ahDP2YLfuFvYxDBlu5bQ0XwmSEcYOTIyAmqXlNrUKgw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3mYpj9DTWLEeQDrQzjHRrOmwxltqoyy4WMWAobq9kGQ=; b=RE2v/ZEPFm6B03E2EC+ijowA4DKXR2LGlfR82nKQ6ZLj9qSkjtLXK5eN5/2iw+4lEq3ds+RoBVn+NcRBk/uTyiOKikQi+8P3nErA5QOt8wW5YPAi0BizC+hI8YaVJrip+CiH0RkcJuk7LgBvj6iGjRw5Y2p7aroYEeVNEIjtpICZ6r+E4FgYBc8C23i8aYg1vHQpqUpaix9XUfw0NJe+oHosuy4x6R5hVNGD/bw+2dT/TiNkI+Aw7JzfJXzqL7U/A490BAHbqWDLJd/fPsRmiOuy32FBoGXTzWCK9fV3t3W556XK56hNPNw9BwJr0CN9TtauSjI4c9gCpkxYwrDaUA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3mYpj9DTWLEeQDrQzjHRrOmwxltqoyy4WMWAobq9kGQ=; b=lIZr30HKja70viuQGl4OXvQwi1mNtdW3M8n1X4O+2hpe4rGU64Bp6jN+l8mJ5Y7/861k7UJYrkjQK0LpL3PWfdokUhbfFtXuzagXugvHxVDqlziP/bgGfruRTR4I0PCDc4B25rDioHauYp+335t9eL/mONPfMDs26ayQtKJlogY=
Received: from DM4PR11MB5438.namprd11.prod.outlook.com (2603:10b6:5:399::21) by DM5PR11MB1388.namprd11.prod.outlook.com (2603:10b6:3:12::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4287.31; Wed, 7 Jul 2021 20:42:02 +0000
Received: from DM4PR11MB5438.namprd11.prod.outlook.com ([fe80::a85a:cb8b:2d73:5e12]) by DM4PR11MB5438.namprd11.prod.outlook.com ([fe80::a85a:cb8b:2d73:5e12%6]) with mapi id 15.20.4308.021; Wed, 7 Jul 2021 20:42:02 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: Kent Watsen <kent+ietf@watsen.net>
CC: "netconf@ietf.org" <netconf@ietf.org>, "draft-ietf-netconf-sztp-csr@ietf.org" <draft-ietf-netconf-sztp-csr@ietf.org>
Thread-Topic: [netconf] AD review of draft-ietf-netconf-sztp-csr
Thread-Index: Addu5AFNiNMInIAwQECG9i1E+R6tMQAX418AAMixnwAAPndtAAACvQoA
Date: Wed, 07 Jul 2021 20:42:02 +0000
Message-ID: <DM4PR11MB5438262BEE03561CE34C73FBB51A9@DM4PR11MB5438.namprd11.prod.outlook.com>
References: <c318ff6892614640b89a0eb775e9bf42@huawei.com> <0100017a67571569-f34e8df5-f018-4f08-ba46-5bd919b6d127-000000@email.amazonses.com> <DM4PR11MB5438034DFB9BBCC8963445C2B51B9@DM4PR11MB5438.namprd11.prod.outlook.com> <0100017a8249ae8c-9dddaf10-597b-41dd-9e00-6352d110c362-000000@email.amazonses.com>
In-Reply-To: <0100017a8249ae8c-9dddaf10-597b-41dd-9e00-6352d110c362-000000@email.amazonses.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: watsen.net; dkim=none (message not signed) header.d=none;watsen.net; dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 7ab7fc81-1efb-4e56-5936-08d94187ace8
x-ms-traffictypediagnostic: DM5PR11MB1388:
x-microsoft-antispam-prvs: <DM5PR11MB1388305BB7A98489B3D1FE9AB51A9@DM5PR11MB1388.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: dfWMLomrHya1VtdSR258UwJlWPB8WbKy8y0jU0zeY16w+tHktqpiK17vQ+hrvVw+LHyJzRgO5fXF96tnzacM3G5ZBw0s9z6R0O8qng95dfwWAcEG2m6F0zSVaz8ua9YYL0ea2CRjX9i6VPVhl0wUkBvDVGbExp3J2FH5HHp8JOh+0tDJaRkjCE4YWxYgv38E8ZJGxhr23RpqAoZAJWVyknpS43OidabT3nvNpo8BOmERGSt3mKn8igrt5U+sI4U+aS8lfoAngWquzvOZcRoL9M6kmnbomqO0KXpPSSeL3iWRBb1+fmy3tx+iIqUzYrVDzwj75a7nVXkAcvLYkZaTgbqi/Y32rVwnz92tSIZYTR/9AyHnGBCJIRt4w7W6KZRPy2t8/MyTT0PRl8hTb1wWGtZAkjs57NmWdHIOibev/lGF5j0tiCGMVJrdmxO1Wa/wZ1cPaq0+KB0OUo3vIEqRdqPmyDfYveuTKWmuBZfMRy1pGRIC1Di/i/amtKaHhi0/0OZ+Wrhh+FkVBTSyuM5wytcD/X3vwZoht+RQcjGAiI4rpNGXW6OdrFCSl/YjiHVahj4TA13P7lwngVRQBP4SMLbnCOyqls4u4yhAddCpefFoVHwZFP3wMjt3hoQWmKbNiyoe/AQGj7XC3BPYv4CX+fRln+bX+P7jx0NO9OTKb/q+97hAAyEWproYuAstbMhXH5qxO0Jowa44DLKhUXtWsMH87/O1Wk/LDlFIfAZGIoLU0CvgY2VLEk3dvklx+LuUIfxA+LEmMY6ioVAjffvd2A==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM4PR11MB5438.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(39860400002)(376002)(396003)(136003)(346002)(366004)(26005)(66446008)(166002)(316002)(71200400001)(76116006)(9326002)(53546011)(66946007)(8676002)(86362001)(64756008)(186003)(8936002)(33656002)(83380400001)(7696005)(52536014)(5660300002)(66476007)(4326008)(478600001)(55016002)(9686003)(6506007)(2906002)(38100700002)(66556008)(54906003)(122000001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: KmKONTyKx2B46dHstIIi1etZTAn46ErpFDGofrDBDC7ffXKozGl0S20ROC6gODG9LOoXDyKfOn1bXmsjhwoPvmc1dCmGPFZEZqbYBhR68fRV4IO7X8rEsWsCIn+r4B9AwIdnc6v9rf0gyA9hLwdf78EcQKXUvBpfyURwI5HkRG2dwJvlKcvpL9Xm1o4T6e6WhGX7Qw+IQ+4eQpYFy+7wm2yu4LRZR9enFg7CTxUKos/VjAJ1goLLvxX7VoMYQj+Iujg21PGZUG3qvgyIfflYNi0ef5/7N9ZUzfoxdDBX6dT7UfzDc8dg3WBxBQGCaZxBhHVMwCRJyi//CJwYBuKSEVx+nbjaZPrkdH9Ojp+TTQN8lX3cZGzy5w39jWjGCtB2al8RjHT9rgHMSdFCGA4ehZaIVvB9H82dGI213UpgvPfR1AzxPSNmffd5ihyOGFgjVe+5958QfTX8Vin8eBYL82rR6AnHw6BVpRhPTtgk+idH1Hz4kQYHAPuSE8+EMepO5009Gd/VOlDJ6DmZ7+IpchhuDQ+tpD3LrKIS6ot7fZvm4QjpbnV6eaQilK+2k0hvdz7YTbwH00WIXO8plsx/bUTut4iBuNjNHSx7I4HZTzaBF87tYulLGyr3baxlPT9pamwv2eT89+8Ce+tcNSc+3nOf6GnpXg5kK+VVN/DvmXEy7yOfnpqG5rD/BxrTw+RIomytE5Kp7pXqeY5WMekr/RmkmiAiYVkbnYxsuEo4OneMTym6kjS43x3g7nOdIHJ6LvC+XO6cJYFQdoYfeMjbSMGkYjnEX72EJXbHZoAyi0obei1sVtpj/CZjc5OgqKueSEs0wTqrcYUq7SzJWKmtVgkl9wePzIKUQDqejuNmY4YAyMT8qnCvME2x7+EjGa9Sj+Zz21YsMr6XmeB8ZJkhY18bFfK6DgRwf2/JAHmtRFH65HApjvdI3G4JhU+kfJCysMzgv+/WG/alUWMltKj8he0TmLTu//ieswMxlCirnxYfWyavtdiVutWuq8ALzRyAJsw2Ap4WZPBa6R/oFSVaUWlI57htDWRDhuj5EQwWl4oHshE3Bei1b3obyT/nXv3D77qBmQP1PFe/L6Vq2BAMhfzSp6POTApPqq+nW6Ze00iiMpTRBL+GlHAJMuxh8/m6+NMOYMA5M7oQj379UzeOGCrqOeYYIgDll256EYKs0rINhIaNsi+HTPmcKqO0VbfPGRl9KOoV/nkBYndKOz0nvr7oFRnCaeVTGkHwMeJ0PjXkBfN1d8y3H2nvYUBk/EXSRtKTvlJdeIyyL32x4BYl5bqHZfxhOztGRqmSXWb4tySYofZx7o6J1yZOwLZGZg11
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DM4PR11MB5438262BEE03561CE34C73FBB51A9DM4PR11MB5438namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM4PR11MB5438.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7ab7fc81-1efb-4e56-5936-08d94187ace8
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jul 2021 20:42:02.5650 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: QygwldwtX1pVqQip/doum5eo/zVqybY71sNpuzm+Eqpfgnp7tcaABW3kg2yNngLAPnmis0jW5qPbkrkyp1CPkA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR11MB1388
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.17, xbe-rcd-002.cisco.com
X-Outbound-Node: alln-core-4.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/eo95MHQl1VH4Y-smtLIVAJPfws8>
Subject: Re: [netconf] AD review of draft-ietf-netconf-sztp-csr
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jul 2021 20:43:12 -0000

Hi Kent,

Looks good.

So, am I right in that we just need resolution of the other ANIMA thread on whether the groupings can be reused?  Please can you remind me what the current status is of that thread/issue.  I thought that the action was with the authors to decide, but I might have missed further discussion.

Thanks,
Rob



From: Kent Watsen <kent+ietf@watsen.net>
Sent: 07 July 2021 19:45
To: Rob Wilton (rwilton) <rwilton@cisco.com>
Cc: netconf@ietf.org; draft-ietf-netconf-sztp-csr@ietf.org
Subject: Re: [netconf] AD review of draft-ietf-netconf-sztp-csr

Hi Rob,

-05 just posted.   More comments below.




So, I agree on moving back to “400”.

Done!  (commit<https://github.com/netconf-wg/sztp-csr/commit/55947184e8b6446444e4b2229e106259619bf6b2>)



BTW, one of my colleagues was looking at this draft, and couldn’t immediately understand what it was for.  Hence, would it be helpful to add a sentence or two in the introduction to explain why having a signed LDevID on the device is helpful?

We (the authors) added this to the Introduction: (commit<https://github.com/netconf-wg/sztp-csr/commit/6dac677edf879d9a6fd1fe4c5ad9c1f98e7745e9>)

            The ability to provision an identity certificate that is purpose-built
            for a production environment during the bootstrapping process
            removes reliance on the manufacturer CA, and it also enables the
            bootstraped device to join the production environment with an
            appropriate identity and other attributes in its LDevID
            certificate.

 Regards,
Rob

K.  // as co-author