Re: [netconf] Warren Kumari's No Objection on draft-ietf-netconf-keystore-30: (with COMMENT)

Kent Watsen <kent+ietf@watsen.net> Wed, 31 January 2024 22:02 UTC

Return-Path: <0100018d6189f4dd-7605a0fd-06fe-486c-b654-dc9c3b0079d5-000000@amazonses.watsen.net>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C0E6C14F68C; Wed, 31 Jan 2024 14:02:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.904
X-Spam-Level:
X-Spam-Status: No, score=-6.904 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=amazonses.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DDbbWu4-C77P; Wed, 31 Jan 2024 14:02:00 -0800 (PST)
Received: from a8-96.smtp-out.amazonses.com (a8-96.smtp-out.amazonses.com [54.240.8.96]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C5C33C14CEFF; Wed, 31 Jan 2024 14:00:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=224i4yxa5dv7c2xz3womw6peuasteono; d=amazonses.com; t=1706738447; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc:Content-Transfer-Encoding:Message-Id:References:To:Feedback-ID; bh=VvBXRuBcXmeW6/6cxqBieOx1IYOn+DZwQyRlrUixyUM=; b=WhiY5gin9wj3/Wz+qGDTsi6NWUzsBoIhTDEpubDokbgcJKN4OKmMrQYpUoJTe0lH oqnNZLMIOX3pX2lImXvHUya9tj+U4uswEzlGlLvQ7Edufr9a3QvX9mCUUne98ptt4ve rX3pnMJUMvAcGsfHejxVbW30LuYykWZnFs/cQ6cY=
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.600.7\))
From: Kent Watsen <kent+ietf@watsen.net>
In-Reply-To: <170666095818.21441.3339510394156215916@ietfa.amsl.com>
Date: Wed, 31 Jan 2024 22:00:47 +0000
Cc: The IESG <iesg@ietf.org>, draft-ietf-netconf-keystore@ietf.org, "netconf-chairs@ietf.org" <netconf-chairs@ietf.org>, "netconf@ietf.org" <netconf@ietf.org>, Qin Wu <bill.wu@huawei.com>, Mahesh Jethanandani <mjethanandani@gmail.com>
Content-Transfer-Encoding: quoted-printable
Message-ID: <0100018d6189f4dd-7605a0fd-06fe-486c-b654-dc9c3b0079d5-000000@email.amazonses.com>
References: <170666095818.21441.3339510394156215916@ietfa.amsl.com>
To: Warren Kumari <warren@kumari.net>
X-Mailer: Apple Mail (2.3731.600.7)
Feedback-ID: 1.us-east-1.DKmIRZFhhsBhtmFMNikgwZUWVrODEw9qVcPhqJEI2DA=:AmazonSES
X-SES-Outgoing: 2024.01.31-54.240.8.96
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/gxAwVvfau-B289qtoxhUdd0BCXI>
Subject: Re: [netconf] Warren Kumari's No Objection on draft-ietf-netconf-keystore-30: (with COMMENT)
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jan 2024 22:02:01 -0000

Hi Warren,

Thank you for you valuable comments.
Please find below my responses.

Kent


> On Jan 30, 2024, at 7:29 PM, Warren Kumari via Datatracker <noreply@ietf.org> wrote:
> 
> Warren Kumari has entered the following ballot position for
> draft-ietf-netconf-keystore-30: No Objection
> 
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
> 
> 
> Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ 
> for more information about how to handle DISCUSS and COMMENT positions.
> 
> 
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-netconf-keystore/
> 
> 
> 
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
> 
> I support Roman's DISCUSS.
> 
> Also, when reading this document I initially got excited, thinking that I'd
> find more text on the 'hidden keys', but my excitement was short lived...:-)

Sorry to disappoint!  ;)


> Assuming you add text to the other YANG crypto types document, perhaps you can
> include it here too?

Unlike the “crypto-types” draft, this draft has a dedicated section called "Support for Built-in Keys”, is it not enough?

One thing I noticed was that this section doesn’t ever use the word “hidden”, though it’s mostly the case that they would be hidden, though they could possibly be “encrypted”, though it may not be worth saying that.

This being the case, how about this edit?

OLD: Built-in keys are expected to be set by a vendor-specific process.
NEW: Built-in keys are "hidden" keys expected to be set by a vendor-specific process.


Thanks again!
Kent