Re: [netconf] Éric Vyncke's Abstain on draft-ietf-netconf-crypto-types-29: (with COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Wed, 31 January 2024 11:51 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFAF5C14CE53; Wed, 31 Jan 2024 03:51:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -11.905
X-Spam-Level:
X-Spam-Status: No, score=-11.905 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nprwsOVZy7Iz; Wed, 31 Jan 2024 03:51:52 -0800 (PST)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38450C14F701; Wed, 31 Jan 2024 03:51:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=31533; q=dns/txt; s=iport; t=1706701911; x=1707911511; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=uinVfxKWRkVJxn/sSeCHdw3KOtUIyNgc3A5MuxZ3qSM=; b=NAg1b3LqpCMfGbCSwEL91l+Sq9C1SL09ZCRG2TXMymsHcALHzq5T28/P kepbGU5a8+W6Gn7cSsSAGt/rpJyI7x5P5rJcWKNm2F5Mi4j7kdKHGmY9d xcoWEYN0e3JHWVK4qzpnre40t15joTJ5OW6AUvPE0Dykfqnx+aFpVnA0q M=;
X-CSE-ConnectionGUID: Vtjz3kwqSS+w+iCGuuFbdA==
X-CSE-MsgGUID: Z7sbIb6ATXC0c7CYzZPAIw==
X-IPAS-Result: A0ABAACsM7plmJJdJa1XAxoBAQEBAQEBAQEBAwEBAQESAQEBAQICAQEBAWWBFgUBAQEBCwGBNTFSegKBF0iEUoNMA4ROX4hpA4EpijWFYoYtgTiEYBSBEQNWDwEBAQ0BATsJBAEBhQYCFoc8AiY0CQ4BAgQBAQEBAwIDAQEBAQEBAQEGAQEFAQEBAgEHBRQBAQEBAQEBAR4ZBQ4QJ4VsDYZFAQEBAQMSEVYQAgEIEQMBAhYDCAoCAgIeERoDCAIEDgUigl4BghcUAzEDARCpcAGBQAKKKHqBMoEBghYFgU5Brg0Ngk8GgUgBiAcEGgFqZwICg1cmgiSBFIEfCB8bgUlEgRUnG4JoPoIfQgEBA4EWEgERAgEIOB8CBgmDCzmCLwSBE4EAgxgngQyEQ4M8YQKCRAGHbFR5IwN+CARcDRsQHjcREBMNAwhuHQIxOgMFAwQyChIMCyEFE0IDQAZJCwMCGgUDAwSBMAUNGgIQGgYMJgMDEkkCEBQDOAMDBgMKMTBVQQxQA2UfMgk8DwwaAhsbDScjAixAAxEQAhYDIhYENhEJCyYDKgY6AhIMBgYGXSMWCQQlAwgEA1QDIXQRAwQKAxQHCwd4ggmBPgQTRxCBNoM0AxkrHUADC209NRQbBiIBH5h7dwIBgWAKUQUBMzEBAyIZFwEXPwInIDYtESAXBBoPkk4KgxcBSYsbjkmTS0BwCoQRjAePIASGCQQvhAWMdwORcIZMZIYWkj6NbYN9kREgCggPCoUAAgQCBAUCDgEBBjWBLjprcHAVZQGCCAEBATFSGQ+OKw4JiGyKZXY7AgcBCgEBAwkBgjmGWoFTAQE
IronPort-PHdr: A9a23:VKFVxhF4PWDaMNCfek0Psp1GfukY04WdBeZdwpMjj7QLdbys4NG7e kfe/v5qylTOWNaT5/FFjr/Ourv7ESwb4JmHuWwfapEESRIfiMsXkgBhSM6IAEH2NrjrOgQxH d9JUxlu+HToeVNNFpPGbkbJ6ma38SZUHxz+MQRvIeGgF5DDic+02si5+obYZENDgz/uKb93J Q+9+B3YrdJewZM3MKszxxDV6ndJYLFQwmVlZBqfyh39/cy3upVk9kxt
IronPort-Data: A9a23:dl3lyqxSRe080K948pd6t+f9xirEfRIJ4+MujC+fZmUNrF6WrkUEz DcbUDyAOKuNZmCnctB+b4TgphxU65LXzYcwTgtrqVhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlpCCea/lH0auSJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 Y6aT/H3Ygf/h2YtaTtMscpvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE88jmSH rurIBmRpws1zj91Yj+Xuu+Tnn4iHtY+CTOzZk9+AMBOtPTtShsaic7XPNJEAateZq7gc9pZk L2hvrToIesl0zGldOk1C3Fl/y9C0aJuxqPFMyO8rtWo9A7ZMHrH7OhzIks6FNhNkgp3KTkmG f0wMjsBaFWIgPi7hevjDOJtnc8kasLsOevzuFk5kmqfVqlgEMuFGvmUjTNb9G9YasRmEOjPY cEaZBJkbQ/LZFtEPVJ/5JcWxbfx3SmhKmUHwL6TjZho+GLyxlJY7IjGaNGKUe2Yd/18v1nN8 woq+EyiX0lFb4bAodafyVqqi/PEmiX1cIMfCLP+8eRl6HWVy3AYDxsYEFC7qPijkWa/Vs5Rb UsO9UIGobI7+lDuT9ThUVi+rWKPuRgSHtFKAvUm70SR27LZ+C6YC3QKCDlbZ7QOtcItShQr2 0OH2dTzClRSXKa9U3mR8PKfqim/fHFNa2QDfiQDCwAC5rEPvb3fkDrxUtRxS62ql+bOWi6zw hulsTUQjbk62JtjO7qAwXjLhDelp57sRwEz5xnKUm/N0u+fTNP0D2BPwQWLhcusPLqkok+9U G/ocvVyAcgUBp2L0SeKWuhIRenv7PeeOzqaillqd3XAy9hP0yD4FWyzyGgiTKuMDiriUWS5C KM0kVgBjKK/xFPwMcdKj3uZUqzGN5TIG9X/TezzZdFTeJV3fwLv1HgxPRDOhDGxwBF8yfxX1 XKnnSCEUy5y5UNPkWveegvh+eFDKt0WnDqMFc6hk3xLL5LHPC/FIVv6DLd+RrtktPzf+lq9H yd3PMqRwBIXS/zlfiTS6sYSK1tMRUXX9riow/G7gtWre1I8cEl4Uqe56ep4J+RNwf8P/s+Wp S7VZ6Ot4Ael7ZExAV/UOikLhXKGdcsXkE/XygRwYQ/1hyN6OtjHAWV2X8JfQITLPddLlJZcZ /IEYM6HRP9IT1z6F/41N/ERcKQKmMyXuD+z
IronPort-HdrOrdr: A9a23:qr4Tua86AZSJmtb3WQRuk+GYdr1zdoMgy1knxilNoENuA6+lfp GV/MjziyWUtN9IYgBfpTnhAsW9qXO1z+8S3WBjB8bSYOCGghrmEGgM1/qZ/9SNIVybygcZ79 YeT0EcMqy/MbEZt7eG3ODQKb9Jq7f3ktHMuQ6d9QYQcegAUdAY0+4NMHfhLqQAfng/OXNWLu v62uN34xCbVTA8aMO9CnMZX+7FieHqufvdCyIuNloM0iXLqSmnxoLbPnGjsyv2VQkh/Z4StU z+1yDp7KSqtP+2jjXG0XXI0phQkNz9jvNeGc2lkKEuW3XRozftQL4kd6yJvTgzru3qwk0tis PwrxApONk2w2/Nf1uyvQDm12DboXUTAj7ZuB2laEnY0IjErQEBeo18bEViA13kAn8bzZRBOW RwrjukXtRsfEv9dW/Glqj1vllR5zmJSDwZ4K8uZ7g1a/pFVFeXxrZvp3+8Wv07bVDHwZFiH+ 90AM7G4vFKNVuccnDCp2FqhMehR3IpA369MwI/U+GuonBrdUpCvgAl7d1amm1F+IM2SpFC6e iBOqN0lKtWRstTaa5mHu8OTca+F2SIGHv3QS6vCEWiELtCN2PGqpbx7rlw7Oa2eIYQxJ93nJ jaSltXuWM7ZkqrA8yT259A9AzLXQyGLHnQ49Ab44I8tqz3RbLtPyHGQFcyk9G4q/FaGcHfU+ bbAuMePxYiFxqZJW9k5XyIZ3AJEwhqbCQ8gKdOZ26z
X-Talos-CUID: 9a23:e0fiO2wboPnyvAz4//nHBgUqBsI3KX7C1UzrYFD7CE1GVaC7Q1O5rfY=
X-Talos-MUID: 9a23:Cy7cvwq1lwNBaXyNljkezwM9L81J6fqHNHAmyZ5ZkPiWBxRZGijI2Q==
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-10.cisco.com ([173.37.93.146]) by rcdn-iport-2.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 31 Jan 2024 11:51:50 +0000
Received: from alln-opgw-1.cisco.com (alln-opgw-1.cisco.com [173.37.147.229]) by rcdn-core-10.cisco.com (8.15.2/8.15.2) with ESMTPS id 40VBpnSE025910 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 31 Jan 2024 11:51:50 GMT
X-CSE-ConnectionGUID: S/Oo0WRyTh66SN+275Bxkg==
X-CSE-MsgGUID: /PxFU3WzTCSCfpkVudbqug==
Authentication-Results: alln-opgw-1.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=evyncke@cisco.com; dmarc=pass (p=reject dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.05,231,1701129600"; d="scan'208,217";a="22000088"
Received: from mail-mw2nam10lp2101.outbound.protection.outlook.com (HELO NAM10-MW2-obe.outbound.protection.outlook.com) ([104.47.55.101]) by alln-opgw-1.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 31 Jan 2024 11:51:49 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NYmWmHY1AxBn0U6aqLvJj9Spoz9M7srAchZ7TxuCBYFOcumIRR1K75mApU3+eHE8n1o8nmCU1NAuZOvyOVdVGEuNsDqSNjXHeWzbmaVEtYV2ugoSYx18S8o+ojO0ooO72KqHhvxKTMDpvGEFXXum2svWc9GAeiuDJU63WQ0NsuPv1LCZoCFEAAlB3CBkGhXYQuTYCnqb5Kloz+3OdI/BmwgRS0A70VewwzWEiDQIK4GLwzLXOoIQlzLJ4Kh9f6FijzdJyn9xC9NacZHiOgYquT3RxWMyE/Iakhmo5w32+rF7GE64F4cEcKHgUZJ6hwG9K44ze58e91o9KoP2gJetfQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=uinVfxKWRkVJxn/sSeCHdw3KOtUIyNgc3A5MuxZ3qSM=; b=cBrQPXY16dxcWsRp7O0Y8AKoihxhvKyyF+pZUUR6F7tGzFa6LTvNyaQiVJwW0IvbEOYmrnMoLwmJvWifK8fye0otru9ppOCdSdknpvew6gDywddip1NtRcZdKV3C8SsyWowR5xG4/VrcVHxAnVjwck4QGifG3Wr/NRsyFtEM7q6QgK0ItON7OV1/7Ls/e3z7PTalAtUFAZy1Ct3/3pXkjm+w/03BA0MWz2DcAz1DWWev1POSAkFkrKEDZUZh3XaXCIg4nXW/mT/2TeoBJrvmJWLkyApsc/RbjzqwxwcLjkLc+VziE96AEqkMYQu5WAlYRwX9r8NxJh9Bz0KWi4e1fw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by SN7PR11MB6604.namprd11.prod.outlook.com (2603:10b6:806:270::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7249.24; Wed, 31 Jan 2024 11:51:46 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::251c:6e15:4d7d:2a88]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::251c:6e15:4d7d:2a88%7]) with mapi id 15.20.7228.029; Wed, 31 Jan 2024 11:51:46 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Kent Watsen <kent+ietf@watsen.net>
CC: The IESG <iesg@ietf.org>, "draft-ietf-netconf-crypto-types@ietf.org" <draft-ietf-netconf-crypto-types@ietf.org>, "netconf-chairs@ietf.org" <netconf-chairs@ietf.org>, "netconf@ietf.org" <netconf@ietf.org>, Mahesh Jethanandani <mjethanandani@gmail.com>
Thread-Topic: Éric Vyncke's Abstain on draft-ietf-netconf-crypto-types-29: (with COMMENT)
Thread-Index: AQHaUrxJoGnQSUw8R0KlO7d8S6v38bDw5hIAgAL89AA=
Date: Wed, 31 Jan 2024 11:51:46 +0000
Message-ID: <3DAACF3F-273A-4A85-996C-D40E71AD08D1@cisco.com>
References: <170653713829.978.7694069584066312450@ietfa.amsl.com> <0100018d55c8baeb-02f275ef-c496-43da-bd55-22a1dab88501-000000@email.amazonses.com>
In-Reply-To: <0100018d55c8baeb-02f275ef-c496-43da-bd55-22a1dab88501-000000@email.amazonses.com>
Accept-Language: fr-BE, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.81.24012117
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR11MB4966:EE_|SN7PR11MB6604:EE_
x-ms-office365-filtering-correlation-id: ec67a36a-652e-4d82-85fc-08dc22530096
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: jp3NGSYK99Ur+dpGbGbwkIU+5vVL4yTeSGT1uGsLqzcYELw4LVRX3eNSADL9iIDpeQ/+Nvzdbcz6QhYbnCOEbCXaeM4dFUh1361wt4yMrmc6cRBR3xRkdEjVfwcHZutkZumUhVT60tLMCwKNpSRgSfCygPf6MNa68zxoQ+17JilhYou727T6C3lP3GiWYMMUCus+S89mPWY2rM8WGWVk6nk4BrN0BFCsfkGtY6kIXaCcHVnAaYY+C6UGr05TY31EJhNHMjkcU8dI5nyD1oCYJmLpkaEaHjWtnY+DZIM1abc5sRZkPLtZI0CAwhRxw0JuiwYr6vJF6DDqERssW6HOMrjIGp37H3az3kvZBGHvhZ4dSx8KFbPOU4vNan12/lJuALGy3Bqsz84WIpUAqoYRSyC/9zIkLDUOewtE/LGGsHJzbWmzpgYdOGGxKPN4Ayuwb6r9QVFAPs25mAk3avM15gljb2/DoErCcCj2YRUCOfbAHiCxNEKjG8yPpcOCJj80PYjGwCMmq/tC7IhJP9cJn3B3Iy7Ig1UBIOZDkdlleepIrbXT7AUr4ry2qFwf/aZKKcjZ2REHBw29qUs5Z7ketpTYEez8w5T9H14+4sGsZcYyV7LzyT70aoUPRd4NnK8xVJ+ALiULuQLiwzxkV8P4OVM4crcZyQeUyM2g+8Z63nd1AA4hQ8/2xGcXQ2LVLmTJ
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB4966.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376002)(366004)(396003)(346002)(39860400002)(136003)(230922051799003)(451199024)(1800799012)(186009)(64100799003)(83380400001)(41300700001)(66574015)(2616005)(6512007)(38100700002)(122000001)(8936002)(4326008)(5660300002)(2906002)(478600001)(966005)(6486002)(6506007)(53546011)(76116006)(54906003)(64756008)(66446008)(66476007)(66556008)(66946007)(71200400001)(316002)(91956017)(38070700009)(86362001)(224303003)(33656002)(36756003)(66899024)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: K4YlcJ9yMtcYxleYPESmfs/x/nCe363fbbhbGRVYMHdQBclQRkvPcHXCo8sGqt5r763aEmr4E0HwzYX1ypy2x/JEhxv7YFw4VOa7F23QGFJZSuRdM2RSjr9FjO3bFS+I2J8i1i35UMm2HqJV8MtbGnkY/VDSfYXlOFnHQFYlje/KcxDn3WVyaAfv5cCm3KUB6IerXcYclgUvep6vbiJ/wjUIUMMXJTcGwfiXu/Szq/60jzJIeHDjhZMJPMw/sIb8bwQNYTwxR7P1ANg2p6BEdtG3H7Iu3d0ZebmyHKCCGtGMCjygv9YRf4OXGu1mcrSH97rQxS/r3bSSugnH5yqwkJM3hgH4kjmLmGTYVa0aEa1jj4zw6IkFwXiAdzD+qlM1YXwhz2U5Hh6EYJXFaGbm9oZzvHAwcl76VC4AdId+F57USznZBHHA6bfbAW+mok5pgYsGj1rqaabpoxvs6kNM4rnaiG80lwuKPW2I2rzih1AnYvfBk71u3qjECMwhsK782F887IuzvngKBqgLRJYNJgwgLnnuF60VJsozc70E1ZsCNJCn+KbfkrKNlJe1z6zPjy3nuq59u+pJvKG3cTP8alk3uOQMPpqaapkRDKZdwe8X7uLbYHpl+oW51hi+1OQAS2M0W4+YgwRDB9R13CLi6LhLYTZI8Mud6x7OjlG4fi9O43+K8SfyKQTsj1azNGewstMEkXAYiQGwTrbF48pi9yQfjpmLQIGg2GyAt7jYzNC0XQAu4wmHctXtLW5d3xbQt9LvKkF6sdRVvr0mpo4psgok78ot6WfW9vH0aACOMs0t4l6wQxOOHIc6xzlTXBQ3T5zT3237/736l5QmhCYqL+SuLrGE8jQaEA5ip1lnPNY1mtVrpVsqS0T+siGDGNNoy8qszpoTaubEAdVq1d0IrM/4RAn6tnaCXHCnUhTKUkLZ0ybxb8yNv0SujSz3EWO4vMpXqvMgonBX7s+lu6FquPXKk4dC39NK784rN6Fb4h0hLJnI7EpmM6nEZWY2rEAqDuHu8JCiUwsuJyM7FNG6W08Nz8SUs4MDkPDKaWFZJVkZIC5Bs0gT+igTVT6E7dfKbgTZ0DOAWft2uga4jZGLLRF5lPVo+OZal/ygSv1R7ejXTxCSwvQtCaeQe8JWdiptNIBYSTB3Y+GXrnkMqGHtP9ndVfdo7fyyxmouK7DFq7sTSFQynduVpsM9yI6KWF3mjbiY9Rymb1ySn73qUFdxcjLmrbPoZSOA5xCHsHpPGOrl1v2OZv/3csC1VrwXU/UR8HslOE42qiwWX7FvwsVUByIHzXEebGwOVxBc/7KndoGeS6gttgOkAsnnBd7W9lhZO0PuaA9Ok9LkfgRmbf8jQmLalN1cWeZZiMDuRlKPkj5Axdb2OXottotk5A1TSrBChCqCHv7DBxZ/+vCqIrrYDdEVPgc/Bu4RquEBcZ5LJTFrK56sVTUeQTWFfpxNxudw8ug7VOk8GlEsyKCFN63jv//O3toxq0DV0l0yaGWYn6XdczfG8OaiE7r1EYetzDToOYzf1u4jplIez1t9S6EPrv4wPafsFTFAlCyvc6f3EWj+24ny+jvMbG83xvGzjbbadCwpadBCtTgwaDPoPiTaWSOLJwB3KhZyuWvR32wrsFecYzWGB8tN5XTX/b42U74x
Content-Type: multipart/alternative; boundary="_000_3DAACF3F273A4A85996CD40E71AD08D1ciscocom_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ec67a36a-652e-4d82-85fc-08dc22530096
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Jan 2024 11:51:46.6995 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: VSeFtv0ENiXml8f+pG6ms+grW1qKy0hK5CY4jI0+X5zmPJH080UzYbz7MDcIduCqKUwrJlQHKfclwj/4gWBE5A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN7PR11MB6604
X-Outbound-SMTP-Client: 173.37.147.229, alln-opgw-1.cisco.com
X-Outbound-Node: rcdn-core-10.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/l_6XnyNKTrEGZMfCAUvOdl8BxUM>
Subject: Re: [netconf] Éric Vyncke's Abstain on draft-ietf-netconf-crypto-types-29: (with COMMENT)
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Jan 2024 11:51:56 -0000

Hello Kent,

Thanks for your prompt reply and the comments.

As my corporate mail agent is not the most suitable one, please see below for EVY>

While my ballot is not blocking your document, I will welcome the discussion on the “key rollover” and “not valid before” topics.

Regards

-éric

From: Kent Watsen <kent+ietf@watsen.net>
Date: Monday, 29 January 2024 at 16:14
To: Eric Vyncke <evyncke@cisco.com>
Cc: The IESG <iesg@ietf.org>, "draft-ietf-netconf-crypto-types@ietf.org" <draft-ietf-netconf-crypto-types@ietf.org>, "netconf-chairs@ietf.org" <netconf-chairs@ietf.org>, "netconf@ietf.org" <netconf@ietf.org>, Mahesh Jethanandani <mjethanandani@gmail.com>
Subject: Re: Éric Vyncke's Abstain on draft-ietf-netconf-crypto-types-29: (with COMMENT)

Hi Éric,

Thank you for your review.
Please find below my responses to your comments.

Kent



On Jan 29, 2024, at 9:05 AM, Éric Vyncke via Datatracker <noreply@ietf.org> wrote:

Éric Vyncke has entered the following ballot position for
draft-ietf-netconf-crypto-types-29: Abstain

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-netconf-crypto-types/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks for the work done.

The shepherd's writeup would benefit from a better justification of the
intended status.

There is not much I can do about the shepherd writeup…  ;)

The document’s header says the Intended Status is "Standards Track”.
  - is this okay?

EVY> indeed the author can do nothing about it, but usually there are some justifications about why it is ‘proposed standard’.


Is there a reason why there are several NETCONF WG crypto-related I-Ds rather
than a single one ?

Do you mean the suite of documents - 9 documents in total?

EVY> Yes, and thanks for the explanations below. I understand the point of view.

I guess because each document has its focus and can be referenced by other
documents individually.

For instance, other WGs have documents that reference the “keystore” document,
while others reference the “tis-client-server” draft.  If there were a single document,
those references would be too course.  Makes sense?



I was about to DISCUSS the following point but balloting ABSTAIN as I am unsure
about the use case: the model has cleartext and encrypted passwords (the latter
is a hint that the password can be decrypted back to cleartext) but what about
password hashes if the remote party should also be authenticated over a
protected channel by sending a clear text password ?

The password documented here is for when configuring a server to connect to a
remote system, in which case the cleartext password is needed.

EVY> if this is only for authenticating *TO* a peer, then we agree. It was unclear to me whether authentication *BY* a peer was also in scope.

Elsewhere (in the "ssh-client-server" and "http-client-server" drafts), there are passwords
used for local users (i.e., users logging into the server itself).  The configuration for
those passwords use the “crypt-hash” type from RFC 7317.

Makes sense?



Another near-DISCUSS point: what about key rollover when 2 keys/passwords could
be used ?

What do you mean?  Can you say some more?

EVY> in many systems, it is nearly impossible to change the keys/passwords everywhere simultaneously (notably because some systems could be unreachable).
EVY> I.e., two keys/passwords can be used simultaneously for a short period of time to allow *all* peers to synchronize the credentials.
EVY> typical case with certificates and also IPsec key rollover.
EVY> for a OPS WG document, I would expect those operational considerations taken into account.


As in another document, it is nice to have a certificate expiration date but
what about a 'not valid before' date ? This is similar to the previous point of
key rollover.

The “certificate-expiration” notification is an asynchronous  message used to alert
when a certificate is about to become invalid.

AFAICT, there isn’t a need for an asynchronous notification that a certificate isn’t
valid yet, or even when a cert is about the become valid, and hence not notification
is defined for this case - make sense?

EVY> Very similar to the discussion about roll-over. If a node has two certificates (e.g., 1 day before the expiration, a new one is requested/installed),
EVY> which one should be used? Especially, if one is not *yet* valid.


Please add a reference to `rainbow attacks`.

A rainbow attack is used to crack hashed passwords.

As mentioned above, RFC 7317 defines the “crypt-hash” type, which is used by
other documents in this document-series (specifically the "ssh-client-server” and
"http-client-server” drafts).

The “password-grouping” defined in this document isn't for local users, where
hashed-passwords would be used, but rather to configure clients to connect to
remote systems, where a cleartext password is needed.

I don’t understand why this document might reference rainbow attacks.  Perhaps
RFC 7317 could’ve referenced rainbow attacks, but it didn’t.

Please let me know if there is anything I can do to improve the text!


Thanks,
Kent