Re: [netconf] AD review of draft-ietf-netconf-over-tls13-02

"Rob Wilton (rwilton)" <rwilton@cisco.com> Fri, 20 October 2023 11:19 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34CB0C151710; Fri, 20 Oct 2023 04:19:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.605
X-Spam-Level:
X-Spam-Status: No, score=-14.605 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b="jDccM0nn"; dkim=pass (1024-bit key) header.d=cisco.com header.b="da0OucEt"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QSFGn7Uo7_QU; Fri, 20 Oct 2023 04:19:52 -0700 (PDT)
Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F59CC14CE22; Fri, 20 Oct 2023 04:19:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8762; q=dns/txt; s=iport; t=1697800792; x=1699010392; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=s5pbCsFJ7ANGdDFR6SIcXkpdIANO0pe6x9ey+2eXQcI=; b=jDccM0nnNAoML7+vScWMxdXjH8ncWSm8sDmLzuY41OkQMveP7bABJPnD R4kmEFvD9qxC/ZgqCXr20uFzGe2vtT5JtTareFJmj9Ba/Y/LOpveZa6J1 Tx1VW23ZdfDmAlp7deeonBWmdGmm3j7dg6qv1TCOO+n5eHD2EnmJWB4Sx o=;
X-CSE-ConnectionGUID: ounJBayhR+G8BALRw68g5g==
X-CSE-MsgGUID: s5fHUbydTbywTGS0qKcXwg==
X-IPAS-Result: A0AzAAC+YTJlmIoNJK1aHQEBAQEJARIBBQUBQCWBFggBCwGBZlJ4AlkqEkiEUoNMA4ROX4hjA5E5jEKBJQNWDwEBAQ0BATsJBAEBhQYCFoZ/AiY0CQ4BAgICAQEBAQMCAwEBAQEBAQECAQEFAQEBAgEHBBQBAQEBAQEBAR4ZBQ4QJ4U7CCUNhkwBAQEBAxIREQwBATcBCwQCAQgRBAEBAQICJgICAjAVCAgBAQQOBQgaglwBgl4DARAGpzABgUACiih6gTKBAYIJAQEGBAWybAMGgRouAYgJAYFQiDYnG4FJRIFYgWaBAj6CYQIBgUcag1k5gi+DdoJ1ggUVLgcygQoMCYEDgkGBF4s5CXhHcBsDBwOBAxArBwQvGwcGCRYtJQZRBC0kCRMSPgSBZ4FRCoEDPw8OEYJDIgIHNjYZS4JbCRUMNE12ECoEFBeBEQRqBRoVHjcREhcNAwh2HQIRIzwDBQMENAoVDQshBRRDA0cGSgsDAhwFAwMEgTYFDR4CEBoGDicDAxlNAhAUAzsDAwYDCzEDMFdHDFkDbB82CTwPDDQDRB1AAwttPRQhFBsFBDspWQWcIANtNIFCECw1ZAQNIhQOAiABdxwrJgMLGRECCwQaljuuMAqEDIwBlT4XhAGMcoZvkSZimDyCT4sWlHkChUcCBAIEBQIOAQEGgWM6gVtwFTuCZ1IZD4UciQQMDQmDVoJkjRV2AjkCBwEKAQEDCYtKAQE
IronPort-PHdr: A9a23:5xtVpxB+POc4WtjzNZReUyQVoxdPi9zP1kY9454jjfdJaqu8usikN 03E7vIrh1jMDs3X6PNB3vLfqLuoGXcB7pCIrG0YfdRSWgUEh8Qbk01oAMOMBUDhav+/Ryc7B 89FElRi+iLzKlBbTf73fEaauXiu9XgXExT7OxByI7HvBY/Wk8Ox/+uz4JbUJQ5PgWn1bbZ7N h7jtQzKrYFWmd57N68rwx3Vo31FM+hX3jZuIlSe3l7ws8yx55VktS9Xvpoc
IronPort-Data: A9a23:3A4fOqKua/HlRdsfFE+RBJUlxSXFcZb7ZxGr2PjKsXjdYENS3zNUm DZMDG6GM/eLNjamfN1zaY2zp0oCvZTcyd82SgYd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcYZsCCea/0/xWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVvW0 T/Oi5eHYgT8g2clajh8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKmWDNrfnL wpr5OjRElLxp3/BOPv8+lrIWhFirorpAOS7oiE+t55OLfR1jndaPq4TbJLwYKrM4tmDt4gZJ N5l7fRcReq1V0HBsLx1bvVWL81xFapb/p3tKGm/i4+8n2fvV0HznaVhUU5jaOX0+s4vaY1P3 fUcLDZIZReZiqfrhrm6UeJrwM8kKaEHPqtG5Somlm+fVK1gGMuTK0nJzYcwMDMYnN9PGerZY eISaCFka1LLZBgn1lI/UcJkw7r43yKkG9FegEnIq4oK6Xnf8AZgz4TCC4LMWde6WsoAyy50o UqfrzimXXn2Lue3xSCM/G7ph+LTk2b9VZ4ZE7u2s/l0jUfW2mgIUUZQXF+/ifi0lkD4XMhQQ 2QS9zYlqq483E2mUte7WAe3yENopTYVX95WVuY98gzIl+zf4h2SAS4PSTsphMEaWNEeQiEs9 HWAjtPTRhM/mpSxc23DprjJombnUcQKFlMqaSgBRAoDxtDspoAvkx7CJuqP9obo37UZ/hmtn Fi3QDgCa6Y71pVSi/jilbzTq3f9+cCXH19dChD/AzrN0+9vWGKyi2VEA3D34PBcK4DxorKp4 yZewpD2AAzj8fiweMGlSeEJGvSi4OyIdWCail90FJ5n/DOok5JCQWyyyG8lTKuKGp9bEdMMX KM1kV8IjHO0FCD7BZKbm6rrV6wXIVHITLwJrMz8YNtUeYRWfwSa5ixobkP49zmzwRdzzfllZ c7GK5fE4ZMm5UJPkmLeqwA1j+dD+8zC7Ti7qW3Tlk7+iuPOOBZ5t59caQrXBgzG0E90iFyFr 4kAXyd74x5eS+b5KjLG6pIeKEtiEJTILc6eliCjTcbaelAOMDh4U5f5mOp9E6Q7xP49vrmTo RmAtrpwlQCXaYvvc1vaMxiOqdrHAP5CkJ7MFXJzYg/ygSF5OO5CLs43LvMKQFXuz8Q6pdZcR PgecMLGCfNKIgkrMRxHBXUhhOSOrCiWuD8=
IronPort-HdrOrdr: A9a23:livwl6DFdyXitjblHejpsseALOsnbusQ8zAXPh9KOH9om52j9/ xGws576fatskdhZJhBo7y90KnpewKkyXcH2/hgAV7EZniphILIFvAs0WKG+UyDJ8SQzJ8h6U 4NSdkYNDS0NykFsS+Y2nj4Lz9D+qj6zEnAv463pBkdKHAPV0gj1XYHNu/xKDwPeOAyP+tCKH Pq3Ls9m9PPQwVwUu2LQlM+c6zoodrNmJj6YRgAKSIGxWC15w+A2frRKTTd+g0RfQ9u7N4ZnF QtlTaX2oyT99WAjjPM3W7a6Jpb3PH7zMFYOcCKgs8Jbh3xlweBfu1aKv6/lQFwhNvqxEchkd HKrRtlFd908Wntcma8pgao8xX80Qwp92TpxTaj8DneSI3CNXcH4vh69MVkmyjimgwdVRZHof t2Nleixt5q5NX77XzADpbzJkpXfwGP0AkfeKYo/g5iuM0lGf9sRUh1xjIJLH/GdxiKsrwPAa 1gCtrR6+1Rdk7fZ3fFvnN3yNjpRXgrGAyaK3Jy8PB9/gIm1EyR9XFoj/A3jzMF7tYwWpNE7+ PLPuBhk6xPVNYfaeZ4CP0aScW6B2TRSVaUWVjibWjPBeUCITbAupT36LI66KWjf4EJ1oI7nN DEXElDvWA/dkryAYmF3YFN8BrKXGKhNA6dh/129tx8oPnxVbDrOSqMRBQnlNahuewWBonBV/ O6KPttcrbexKvVaPB0NiHFKu5vwCMlIbgoU/4AKiaznv4=
X-Talos-CUID: 9a23:FfzXXW2/+hAQEio2Rgh8/bxfHd0jUFfU3XfqYGDoI09NcqLLGVDN9/Yx
X-Talos-MUID: 9a23:wT3P7wn+fi2XjwvDbDRPdnp5aclI3q6/BHwHgIo6lPLcLA97CyiS2WE=
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-core-5.cisco.com ([173.36.13.138]) by alln-iport-1.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Oct 2023 11:19:50 +0000
Received: from alln-opgw-4.cisco.com (alln-opgw-4.cisco.com [173.37.147.252]) by alln-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 39KBJoFE015006 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 20 Oct 2023 11:19:50 GMT
X-CSE-ConnectionGUID: H8fW/F6WQnW6yYy9UFt3Rw==
X-CSE-MsgGUID: tgpAB3uRQ3KgftJWHyvPhA==
Authentication-Results: alln-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=rwilton@cisco.com; dmarc=pass (p=quarantine dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.03,238,1694736000"; d="scan'208";a="5567800"
Received: from mail-dm6nam11lp2169.outbound.protection.outlook.com (HELO NAM11-DM6-obe.outbound.protection.outlook.com) ([104.47.57.169]) by alln-opgw-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Oct 2023 11:19:50 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cIaNpWfPFUPr7NjkMjvEk7kAVnAyh+e8Qo3oIrW80W9V/3cQDHhrq3jtcPJMlCSNdX7q/bNV2XgHvAJM6ijfkVOgJsSxxoSci+Q1XkidqomnvG5VDtkxXR6/ytl7E/Ot89yUOWvmiLd0P9Jro3H05dMVCMKEjnHbRVRNGduMwXAMd5UodmZLlpbq2eHheY/YMCYTJU2q8AxtsJaKBpfbeQyk7gZrGcPlYIzWNqriWmRiKSPQVZNugMkyTh/UXYN3X5+MiyDsjwRwT0pwRBM8Xvp5erSGxjL0vscUlqGPR10kk+8PsRAyVmS6xgEvZD0myfqbnni7ctKjpeGcto/S5A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=s5pbCsFJ7ANGdDFR6SIcXkpdIANO0pe6x9ey+2eXQcI=; b=MmKoOs3IZ0YWpy5zkLWYVN9t8AC0/jDdHI0LZcAz3+1YdGkenAOeRwTXv6yPTMd6esYO8mohzTIxmZZXV6sTVJSNnpZyYv9EPt5xezEILNzZ6dFwkTGXy07mbDEBx+jKYmSANE/jjkXiWMri9I0EKwNIl8DsjpZc4E7kDYmVs8y86PLO9Fi5RPNhzDAvCtFLpoesq7ngN0PwnBymj1nLquk6ZXBl8/9ukjqoClrmiM9SIxAhuteTU26VcjpRTJ2E38Iqp3vjOwBamayJQKbc8+CK+2c2gSKU2cg5TEVYO1U4ycMQg72ZRZDAsubnWDs5uWTxMoXI26Y/8CophQj8/Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=s5pbCsFJ7ANGdDFR6SIcXkpdIANO0pe6x9ey+2eXQcI=; b=da0OucEtXVXW0LeVMm1NbTxTRrlkY45w/xgjL1MbGz3i1BoATcsIvXnlEtRbQ0Ig+ZICTVmH+kyRbjoJfZvSGPIjPqK/DN4QG7HI/t3Y/svZsM2FCKM/3Oh/PY1RMd4ykyzt80YnD3pl9uU6gHxSMOh/fK+qwYS1bjBvKnpv5sk=
Received: from BY5PR11MB4196.namprd11.prod.outlook.com (2603:10b6:a03:1ce::13) by SA1PR11MB7132.namprd11.prod.outlook.com (2603:10b6:806:29e::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6907.26; Fri, 20 Oct 2023 11:19:48 +0000
Received: from BY5PR11MB4196.namprd11.prod.outlook.com ([fe80::97f2:7572:4ef5:6bf9]) by BY5PR11MB4196.namprd11.prod.outlook.com ([fe80::97f2:7572:4ef5:6bf9%3]) with mapi id 15.20.6863.046; Fri, 20 Oct 2023 11:19:48 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: Sean Turner <sean@sn3rd.com>
CC: "netconf@ietf.org" <netconf@ietf.org>, "draft-ietf-netconf-over-tls13.all@ietf.org" <draft-ietf-netconf-over-tls13.all@ietf.org>
Thread-Topic: AD review of draft-ietf-netconf-over-tls13-02
Thread-Index: Adn9waTZSPIJFM3yTeGVzsA+yQcRegDqLz0AAHbBEmA=
Date: Fri, 20 Oct 2023 11:19:48 +0000
Message-ID: <BY5PR11MB4196118E3E86191A4C0661EFB5DBA@BY5PR11MB4196.namprd11.prod.outlook.com>
References: <BY5PR11MB41962FEFE7C44751A69EEC59B5D2A@BY5PR11MB4196.namprd11.prod.outlook.com> <28CEF1D2-A881-46D1-A95C-991EA42817F9@sn3rd.com>
In-Reply-To: <28CEF1D2-A881-46D1-A95C-991EA42817F9@sn3rd.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BY5PR11MB4196:EE_|SA1PR11MB7132:EE_
x-ms-office365-filtering-correlation-id: 08fdb33f-faff-4068-20ed-08dbd15e78c0
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 96zGadh2dBWm9fdpMI892jTAJOYYawftGRuDDXnh2BoNA2sTYX8H6pwwWq+5r4G7o3OhnwNtvIYcfxuVR48ACRl04rtXExfaMCkrSYtwZY6Kvskfr30LN06xG5yT8nmNGeOC37dmxgfOA3/kpHd+uCWsC4qJ7JSZF769DMyNTJhL4kqc0ZoaALhJJY6mIPUdFCml5mjTqUbz2jdyTa+OFKL6hmVs7KbDYFqK9/E9OK9BgItTQfKZ98YVBAc5YEZwl0NFunhWVZuq42LWW6lMq6YyB+enfK8QrR8n8WptU/i6agBbEyupPwo+6bbpK3Ac+ay/cRqSM8ep0J0szylpkR4XpgJI0+X8rxnu0QTH3pHYvSp1beVLw4mB6hprV7hp8zocBFxis51QtNsKtIfvczQPqg+IZUKyKrpv7eKa3ndKTX7iDrKARQs1y38YDCPOXTJ0HP3uePxYQKm8PiigvKuWWINUYCrMoQkJdOqyLoPk7oTi7ONnvJ6eTizNPcqEqzuXDCIyDxB1Wz57kU4pseSeLB/II+UBX8Wfs3JjXKJUQb4KrF/GDzn9+Mv/z4C4bkg81ogaJx4pmZdgfQT65+tzT4Y9baLIsnUSh4B01mI=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY5PR11MB4196.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(346002)(136003)(396003)(39860400002)(376002)(366004)(230922051799003)(1800799009)(64100799003)(451199024)(186009)(26005)(6506007)(7696005)(9686003)(6916009)(316002)(64756008)(66946007)(66476007)(66446008)(66556008)(54906003)(76116006)(966005)(478600001)(55016003)(83380400001)(53546011)(2906002)(71200400001)(5660300002)(41300700001)(4326008)(8936002)(8676002)(52536014)(86362001)(38100700002)(122000001)(33656002)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ZwM0pXA9eqyO09h6elN67VcvoKZrahdUkLSQ6ZUObtTWfhTDmqI843LSvF+ohNnI5g4U6lmVu3Z4pWy+6wGAY5PCgt4ZnixEKxzxzNi+sGxXeypUzIIwImrFUTNsi1BXae5ROW189CJmwObRVF2nUM7OGCpuSj8LF+BoVhqbf5GfcQ7dnqxl4VvWfLt2CCCAd1i/TtHddU68HZYDHiQOAuJYrtxw849v6qAkjsGJ6INgaVr1YkmCj4vA9OFwPpWvRUmIDEEloQXsXQMlbG5WP2iksDmxBbFGxjR0lnmTysGL7Vz9ESamfiMUSXwfQl/x7624e52fKrymXD87+LEXCc9utJ4mMPOI/Ez2hE/sy2XKcUA5qlCwrD4gGfj2SnxLKDDf1xhToZ37iejZrqBCRFKlbVfYeELkx9M57jdOGHAO5j/WHPlSGCmGFMG5kkMxX3/or2LTWU6/JpxdT+h3EcaRhJgRK2G2j/rWh9IdTj2X78gHhN1WyYuu84P6BWBFYolNMzJpyfA/kB3Nf7c/arse+1lAb4YL5NwslYsoNzeD6dlY5V+d73MTreyaIJodFTOKR9TpGvebtX4rTifl7tV5DfbcEA/O/4FNw7GpfLuAbiNAPU2ekVGog0jGHWFmN/Rdsm/zXFR+PqrqvYWzVGGfWCSwGFrF3XUHVbcC7pnNMhfITfIDU0eIQx8QnRWFiwST493ohoBmfKHCjmm1WkeKYxCNHn2zFRGIueAYZrD7gBjgxYaiou85MKoZuLGzjPPZO4xtWFghEH/w3bGM57c08LjmkaUKHcwNl8fZpS5QZoSwut0NZW4vtAc0v5Xn71DrMnOHYtp1x3RdBnTi+01MpExttgu0JwTPpDz6cYC/MzAbC5/6tkLace4A3Nwk88xhZArQDWFrndyH9E7lUNvElU5WbAG9Lqjlsui+f1cXqEK2NxLB8AM/P7LV3yJ7OLlP8zBz2vbBmujb3OPCYg3bmu4QahC5ziT3oyTCjwrlBKg1HhZlFeaADBqTPNGcUPitQsmSWd9PeoTgmEDuU7m+DQtmfadKtd7tmDCxwVqvf7Ok9/uIvHoRP9CleV6EOhb8l0nq5Qq3xay5Su7ERkwTo4a2vCwQzVsPnrm74FHIdQZNxn8r49N9VNQCPNlEKuRIwIDIAcB9Xs1ZtEmAjUE27DgWIKl6tBahVqgsLy69Bf1q6UqRzf7aSXhjG3lLvSa6+cdmWi9ts9IVSrwrazSIlPwFw2u02qUHKUZKZyXLp10URXHWEpJNWpjz6KoV1pZBR81zPDNyxtp7S8y5ihEVT521jHMZ/lO/fPVyYepW6PA/8qy+rfoxLSogd+w0JpQETN32mXOEwa0+0oHp4lZTBHp/vpM2UvDtpgqgxMapb4fqEOLfLWGu/2oASWfUAJ3+/H0cLC53f+y8rOskL1JcZtoox4OEt8dx8mjeDAaM/gd87bFHjaHqrxrtNU9lSAvTxqqPtDsTucLLpHjazYfV0MWbXc3XNV1+kyr4YFl91G5k3uwcxm522b1m4DcQ+P+jdLELnBzRoJZeBlx+pPOmC1nU6vmEthdhA2T9kv4=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY5PR11MB4196.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 08fdb33f-faff-4068-20ed-08dbd15e78c0
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Oct 2023 11:19:48.5355 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: UhEwIlbOktijLYvYsbMzE37srGydt3fNjCgng/iUVFSHvb1n28jiUWd6lW2GFM5OnMvzefBd9zMit8QWzimQCA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR11MB7132
X-Outbound-SMTP-Client: 173.37.147.252, alln-opgw-4.cisco.com
X-Outbound-Node: alln-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/ys8shNIS2Rw-vZs42LXAhGZ3bmM>
Subject: Re: [netconf] AD review of draft-ietf-netconf-over-tls13-02
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETCONF WG list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Oct 2023 11:19:56 -0000

Hi Sean, authors,

I think that your updates are basically good, but with a couple of minor nits/suggestions on the security considerations (https://netconf-wg.github.io/netconf-over-tls13/draft-ietf-netconf-over-tls13.html)

1.
  "NETCONF implementations SHOULD follow the recommendations given in	
  [RFC9325]."

Consider tweaking to "SHOULD also follow the TLS recommendations".  I.e., really to just emphasize that this isn't just referring to the security considerations of RFC 9325 (which I know the doc as previously just mentioned anyway).

2.
"As specified in [RFC7589], NETCONF over TLS requires mutual authentication. For implementations that support TLS 1.3 [I-D.ietf-tls-rfc8446bis]:"

Probably should split this to two separate paragraphs, on the presumption that "NETCONF over TLS requires mutual authentication" isn't specific to TLS 1.3.

Either way, I'm happy to defer to your judgement on these, so please resolve as you see fit, and post an updated draft and I'll start IETF LC.

Regards,
Rob


> -----Original Message-----
> From: Sean Turner <sean@sn3rd.com>
> Sent: Wednesday, October 18, 2023 3:26 AM
> To: Rob Wilton (rwilton) <rwilton@cisco.com>
> Cc: netconf@ietf.org; draft-ietf-netconf-over-tls13.all@ietf.org
> Subject: Re: AD review of draft-ietf-netconf-over-tls13-02
> 
> 
> > On Oct 13, 2023, at 06:40, Rob Wilton (rwilton) <rwilton@cisco.com> wrote:
> >
> > Hi,
> >
> > Thanks for this document.  Here is my AD review of draft-ietf-netconf-over-
> tls13.  I found this document pretty easy to read, and after all, it is quite short
> but have a few questions/comments:
> 
> Excellent!
> 
> > Moderate level comments:
> >
> > (1) p 3, sec 5.  Security Considerations
> >
> >   For implementations that support TLS 1.3, the Security Considerations
> >   of TLS 1.3 [I-D.ietf-tls-rfc8446bis] apply.
> >
> > Note, this will create a normative dependency on ietf-tls-rfc8446bis,
> potentially delaying the doc.  If this was a concern then it would seem that
> referencing RFC 8446 would be equally valid?
> 
> It will, but I think we’re okay with waiting. -rfc8446bis and -rfc8447bis should
> be coming along shortly; I’m shepherding one and authoring the other ;)
[Rob Wilton (rwilton)] 
Okay!

> 
> > (2) p 3, sec 5.  Security Considerations
> >
> >      NETCONF is used to access configuration and state information and
> >      to modify configuration information.  TLS 1.3 mutual
> >      authentication is used to ensure that only authorized users and
> >      systems are able to view the NETCONF server's configuration and
> >      state or to modify the NETCONF server's configuration.  To this
> >      end, neither the client nor the server should establish a NETCONF
> >      over TLS 1.3 connection with an unknown, unexpected, or
> >      incorrectly identified peer; see Section 7 of [RFC7589].  If
> >      deployments make use of a trusted list of Certification Authority
> >      (CA) certificates [RFC5280], then the listed CAs should only issue
> >      certificates to parties that are authorized to access the NETCONF
> >      servers.  Doing otherwise will allow certificates that were issued
> >      for other purposes to be inappropriately accepted by a NETCONF
> >      server.
> >
> > It is unclear which paragraph in RFC 7589 is being modified, and it is unclear
> to me whether the intent it to append a new paragraph or replace an existing
> one.  It looks like this is updating the first paragraph of the security
> considerations (sec 9).  But it could be interpreted that you are replacing a
> paragraph that would also apply to TLS 1.2 to only apply to TLS 1.3.  Would it
> be better to add a new paragraph that only covers TLS 1.3.  I.e., the text that
> you have above minus the first sentence?
> 
> It’s about adding new text for TLS 1.3. How about:
> 
> OLD:
> 
> The following considerations from [RFC7589] has been modified to also
>    apply to TLS 1.3 [I-D.ietf-tls-rfc8446bis]:
> 
>       NETCONF is used to access configuration and state information and
>       to modify configuration information. TLS 1.3 mutual ...
> 
> NEW:
> 
> As specified in [RFC7589], NETCONF over TLS requires mutual authentication.
> For implementations that support TLS 1.3:
> 
>    TLS 1.3 mutual …
> 
> See the following PR:
> https://github.com/netconf-wg/netconf-over-tls13/pull/15
> 
> > Minor level comments:
> >
> > (3) p 1, sec 1.  Introduction
> >
> >   This document updates [RFC7589] to address support
> >   requirements for TLS 1.2 [RFC5246] and TLS 1.3
> >   [I-D.ietf-tls-rfc8446bis] and the use of TLS 1.3's early data, which
> >   is also known as 0-RTT data.
> >
> > Did you mean "address support".  Perhaps "to update support requirements
> for TLS 1.2 ..."?  If you agree to change, then it would be worth making a similar
> change in the abstract.
> 
> I did mean address as in to speak to in a formal way, but maybe that’s not the
> best way to phrase it.  It does update the 1.2 requirements, but it add 1.3
> requirements.  Maybe something like:
> 
> This document updates RFC 7589 to update support requirements for TLS 1.2
> and add TLS 1.3 support requirements, including restrictions on the
> use of TLS 1.3's early data.
> 
> See the following PR:
> https://github.com/netconf-wg/netconf-over-tls13/pull/15
> 
> > (4) p 3, sec 4.  Cipher Suites
> >
> >   NETCONF implementations SHOULD follow the recommendations given in
> >   [RFC9325].
> >
> > I'm not sure that this is actionable, but I was wondering how many of the
> recommendations in RFC 9325 are relevant for NETCONF and haven't already
> been stated above.  I.e., I presume it doesn't make sense to cherry pick, or
> highlight the specific recommendations for RFC 9325 that are relevant?  I also
> note that this comment is within the Cipher Suites section but it wasn't clear
> whether the intention was to follow the recommendations more broadly?
> 
> RFC 9325 is a BCP about applications implementing TLS so I think it applies
> more broadly as NETCONF could be thought of as the application. How about
> we move that bit to the Security Considerations section?
> 
> See the following PR:
> https://github.com/netconf-wg/netconf-over-tls13/pull/15
> 
> > Regards,
> > Rob
> 
> 
> Cheers,
> spt