[netconf] Re: draft-kwatsen-netconf-quic-call-home
Qin Wu <bill.wu@huawei.com> Thu, 30 July 2026 11:54 UTC
Return-Path: <bill.wu@huawei.com>
X-Original-To: netconf@mail2.ietf.org
Delivered-To: netconf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 54F42120FABD5; Thu, 30 Jul 2026 04:54:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785412493; bh=Of3V9Z7aDS2wA6x/j7eLFKLK+Fo7jSk3IS6pMcaN5jQ=; h=From:To:CC:Subject:Date; b=YyISOEjGmlLjoSx9U8Dc5i0CZb6s3T21PA4gCT5zTonZVSWeMrEPa0G1+UVgx5jo5 M2sxYo7pt/l8o/UgyiusD3VCzSK8FfpdCP4TXc94cnltp+rivaehgYKhixqjIacbu/ MbS3ga5GFUvvTf7pBSyBzbNNMTYkO9b44Q6USJ/Y=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.394
X-Spam-Level:
X-Spam-Status: No, score=-4.394 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=huawei.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fXDfNtKgzkZi; Thu, 30 Jul 2026 04:54:52 -0700 (PDT)
Received: from frasgout.his.huawei.com (frasgout.his.huawei.com [185.176.79.56]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 319F8120FABD0; Thu, 30 Jul 2026 04:54:52 -0700 (PDT)
dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=Of3V9Z7aDS2wA6x/j7eLFKLK+Fo7jSk3IS6pMcaN5jQ=; b=3AscT/BDc68J0LGuoUy7hE0t4a+OrF/J/PeaCj6Sx9/vObRueKCLRt125nsAx997Cd4cPTzCK xmYwWckEFgmNd90kAxGMIyLlMppNf25eUQ04pj0mbic9M8wSX2sEbnaDThT+CPo8YzYmWhUj7t9 fEz360b8ARNxj1vHuIk/68Q=
Received: from mail.maildlp.com (unknown [172.18.224.150]) by frasgout.his.huawei.com (SkyGuard) with ESMTPS id 4h9nfj4PM2zHnGcq; Thu, 30 Jul 2026 19:54:05 +0800 (CST)
Received: from kwepemh500011.china.huawei.com (unknown [7.202.181.142]) by mail.maildlp.com (Postfix) with ESMTPS id 8230A40570; Thu, 30 Jul 2026 19:54:47 +0800 (CST)
Received: from kwepemf200006.china.huawei.com (7.202.181.232) by kwepemh500011.china.huawei.com (7.202.181.142) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Thu, 30 Jul 2026 19:54:44 +0800
Received: from kwepemf200004.china.huawei.com (7.202.181.230) by kwepemf200006.china.huawei.com (7.202.181.232) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Thu, 30 Jul 2026 19:54:44 +0800
Received: from kwepemf200004.china.huawei.com ([7.202.181.230]) by kwepemf200004.china.huawei.com ([7.202.181.230]) with mapi id 15.02.1544.011; Thu, 30 Jul 2026 19:54:44 +0800
From: Qin Wu <bill.wu@huawei.com>
To: Christian Huitema <huitema@huitema.net>, Magnus Westerlund <magnus.westerlund=40ericsson.com@dmarc.ietf.org>, Kent Watsen <kent+ietf@watsen.net>, "netconf@ietf.org" <netconf@ietf.org>
Thread-Topic: [netconf] Re: draft-kwatsen-netconf-quic-call-home
Thread-Index: Ad0gGYonYQgtLCQWRMW7zwcV61kUjQ==
Date: Thu, 30 Jul 2026 11:54:44 +0000
Message-ID: <5511babc1521433baa0d7a8b88e22517@huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.136.132.204]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Message-ID-Hash: 7GH36EGOSHKALQYN33WEOAMMOWZIF4ZX
X-Message-ID-Hash: 7GH36EGOSHKALQYN33WEOAMMOWZIF4ZX
X-MailFrom: bill.wu@huawei.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netconf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "quic@ietf.org" <quic@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [netconf] Re: draft-kwatsen-netconf-quic-call-home
List-Id: NETCONF WG list <netconf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/uq5-mXIn9n8GGGaPogggmsGfzUE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Owner: <mailto:netconf-owner@ietf.org>
List-Post: <mailto:netconf@ietf.org>
List-Subscribe: <mailto:netconf-join@ietf.org>
List-Unsubscribe: <mailto:netconf-leave@ietf.org>
-----邮件原件----- 发件人: Christian Huitema [mailto:huitema@huitema.net] 发送时间: 2026年7月30日 1:46 收件人: Magnus Westerlund <magnus.westerlund=40ericsson.com@dmarc.ietf.org>; Kent Watsen <kent+ietf@watsen.net>; netconf@ietf.org 抄送: quic@ietf.org 主题: [netconf] Re: draft-kwatsen-netconf-quic-call-home On 7/29/2026 1:31 AM, Magnus Westerlund wrote: > Hi, > > If I understand this correctly you are doing mutual TLS for > authentication so both the *CONF client and server knows who they are > expecting to talk to. The server also knows the client’s address port. > So why complicating it with a new packet type rather than to just > define that both *CONF clients and servers shall act as QUIC Servers, > and *CONF servers MAY be QUIC clients and the *CONF client MUST be > QUIC client, then after the QUIC connection is established the *CONF > Client knows its role and does the *CONF procedures over the > established connection? Netconf requires mutual auth, but H3 typically does not. To run Netconf over H3 and get mutual auth, the standard solution would be to authenticate the client after H3 is established, probably using OAUTH. Or, if that is possible, define a profile of H3 that requires mutual auth at the TLS/QUIC level. I wonder which of these solutions is used for Netconf over H2. [QW]Not sure there is NETCONF over H2, but RESTCONF is independent of the HTTP version and recommend using H2. If my understanding is correct, draft-kwatsen-netconf-quic-call-home is separated from draft-ietf-netconf-over-quic which has been adopted in NETCONF WG. NETCONF over QUIC bypasses the HTTP stack entirely to send raw NETCONF XML/RPC messages directly over native QUIC streams. OAuth is a web-centric application-layer authorization framework designed for HTTP workflows. OAuth is not supported, Forcing OAuth into NETCONF layer would add unnecessary web semantics and processing overhead. -- Christian Huitema _______________________________________________ netconf mailing list -- netconf@ietf.org To unsubscribe send an email to netconf-leave@ietf.org
- [netconf] draft-kwatsen-netconf-quic-call-home Kent Watsen
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Dan Wing
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Kent Watsen
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Magnus Westerlund
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Kent Watsen
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Magnus Westerlund
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Christian Huitema
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Qin Wu
- [netconf] Re: draft-kwatsen-netconf-quic-call-home Qin Wu