Re: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03

mohamed.boucadair@orange.com Wed, 07 February 2024 15:01 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1D41C14CEFC; Wed, 7 Feb 2024 07:01:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.102
X-Spam-Level:
X-Spam-Status: No, score=-0.102 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, URI_DOTEDU=1, URI_DOTEDU_ENTITY=1] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FjhxpBaQmq_Z; Wed, 7 Feb 2024 07:01:32 -0800 (PST)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.126.238]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79788C14F5E2; Wed, 7 Feb 2024 07:01:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1707318092; x=1738854092; h=to:cc:subject:date:message-id:references:mime-version: from; bh=17VyYman31lSNIxW1Ouzxw9wr0SHCAu6I0o6t4wfBAI=; b=BNoU2I/SGcOSgCW1hUGYNt9sIWM4RH+iIiiDh0/PS/oSe2BxJeS9nvQO DEZ2w+sLeLb5mXe1CCRQ5Pd6UJtzgFFK5Uu3X6b9nAosEQ4JlGCUp5sdj WP443wZZfGQFSxgMPNNn9zvqptT3L91cHKNAlGdV1xw7vBmTwX0+5m0Tk oWg/rN8vIPHeBL77aXqc0vtNdERqb0xgd6t91wvgVx8XOYQ5mdBFjJb9H IiKaoxGrE77YLaS08n3SHyZSu0VvOeuBtnaY90VzDRpoB/e8KpTviUzhj 4ANqUZsabCx7eHHyZw1jGvWHIJTVbs8R2vOzJUJ2FcT3Q9NiIoS3TDAkD w==;
Received: from unknown (HELO opfedv3rlp0f.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 07 Feb 2024 16:01:30 +0100
Received: from unknown (HELO opzinddimail8.si.fr.intraorange) ([x.x.x.x]) by opfedv3rlp0f.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 07 Feb 2024 16:01:29 +0100
Received: from opzinddimail8.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with SMTP id D230576B3C1; Wed, 7 Feb 2024 16:01:28 +0100 (CET)
Received: from opzinddimail8.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id A948A76B212; Wed, 7 Feb 2024 16:00:02 +0100 (CET)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail8.si.fr.intraorange (Postfix) with ESMTPS; Wed, 7 Feb 2024 16:00:02 +0100 (CET)
Received: from mail-he1eur04lp2050.outbound.protection.outlook.com (HELO EUR04-HE1-obe.outbound.protection.outlook.com) ([104.47.13.50]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 07 Feb 2024 16:00:02 +0100
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by AS8PR02MB9235.eurprd02.prod.outlook.com (2603:10a6:20b:5c1::5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7249.36; Wed, 7 Feb 2024 14:59:58 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::5d3b:ed3b:20a7:1b6f]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::5d3b:ed3b:20a7:1b6f%5]) with mapi id 15.20.7249.035; Wed, 7 Feb 2024 14:59:58 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.106.160.158-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=Pass smtp.helo=postmaster@EUR04-HE1-obe.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 104.47.13.50 as permitted sender) identity=mailfrom; client-ip=104.47.13.50; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: Pass (smtp-in365b.orange.com: domain of postmaster@EUR04-HE1-obe.outbound.protection.outlook.com designates 104.47.13.50 as permitted sender) identity=helo; client-ip=104.47.13.50; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@EUR04-HE1-obe.outbound.protection.outlook.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all"
IronPort-Data: A9a23:0CWoh65LScOspUygYUGZmgxRtDvAchMFZxGqfqrLsTDasY5as4F+v mNJCD2HaKmOMzTwct0iO4i+8UpTscLSydI2SAI6/Ck8Eysa+MHIO4+Ufxz6V8+wwmwvb67FA +E2MISowBUcFyeEzvuVGuG96yM6jMlkf5KkYMbcICd9WAR4fykojBNnioYRj5Vh6TSDK1vlV eja/YuHZTdJ5xYuajhIs/jb90s11BjPkGhwUmIWNKkjUGD2xyF94KI3fcmZM3b+S49IKe+2L 86rIGaRpz6xE78FU7tJo56jGqE4aue60Tum0xK6b5Ofbi1q/UTe5EqZ2M00Mi+7gx3R9zx4J U4kWZaYEW/FNYWU8AgRvoUx/yxWZcV7FLH7zXeXvOi11FPkX3HX6Kt0U20VYKI348RMDjQbn RAYAGhlghGrqt+MmO7+asQ1w8MpIY/sIZ8VvWxmwXfBF/E6TJvfQqLMo9hFwDM3gcMIFvHbD yYbQWM3MFKcPFsWYRFKUPrSn8/w7pX7WzhfqFuQqKZx6W/OxwV92bn3GN3Pc9qFSINemUPwS mfupTmgW05DZIz3JTyt6iuR1v/xhHrBZqE7TeGF6qIzokC4yTlGYPERfQDg+6Xm4qKkYPpaK UEI+iMopK4+/UqqZtb4Vhy85nWDu3Y0X9BdCeI38imJw6DSpQCUGgAsSDNdbdsqnM47WTJs0 UWG9/vvCCBqt7HQQnKU962PhTK/JSZTKnUNDRLoViMA6tjn5YE+1x/SVI4/FLbv1oCtXzbt3 zqNsS4ywa0JitIG3Lm6+laBhC+wop/OTUg+4QC/sn+ZAh1RaaqDfJKKxVLgxqhac6q6E3aup Vo/lJ3LhAwRNq2lmCuISeQLObim4feZLTHR6WKD+bFxplxBHFbyJehtDCFCGat/DioTURHIC HI/VCtU7Z5XeXunNKJqedrtD9xwlfW4U9P4SvrTc9xCJIBrcxOK9z1vYkjW2H3xlE8rkuc0P pLznSeQ4ZQyWP8PINmeHrx1PVoXKsYWmz67qXfTkUTP7FZmTCTJIYrpyXPXBgzD0IuKoR/O7 /FUPNaQxhNUXYXWO3aPrtRPcQpUfCZhWfgaTvC7kMbSemKK/0lwU5fsLU8JINU4wMy5a8+Uo C7hAR8AmDITe1Wec1zRMiwLhEzTsWZX9ilhYXNE0aeA3nkoe4G066kDP5AwZ6FPyQCQ5a8cc hXxQO3ZWq4nYm2fpVw1NMChxKQ8LkjDrVzVZEKNPmNgF6OMsiSSprcIiCO0qXFSZsd23ONiy 4CdOvTzH8JeGVsyXZaKAB9tpnvo1UUgdCtJdxOgCrFulI/EqeCG9wSZYj4Lz8AwxdHr6wagj 1rTITpB4O7Hrsky7cXDgr2Co8GxCexiE0FGHm7dq7GrKS3d+WnlyohFOApNVS6IT3v6oc1Oe s0Mp8wQ8tVf9LqJj2a4O7FxxKQx6p3koLoyIsFMAiDQd1ryYl9/CiXu4PSjbpFw+4I=
IronPort-HdrOrdr: A9a23:Is9Uiq2JhAkOIQQmRmKtpwqjBcRxeYIsimQD101hICG9Lfbo9P xGzc566farslcssSkb6K690cm7LU819fZOkO8s1MSZLXjbUQqTXcBfBOTZskfd8kHFh4pgPO JbAtdD4b7LfBhHZKTBkXSF+r8bqbHtntHL9ILjJjVWPH1Xgspbnn5E43OgYzZLrX59dOIE/f Snl616jgvlU046Ku68AX4IVfXCodrkqLLKCCRtOzcXrCO1oXeN8rDVLzi0ty1yb9pI+9gf2F mAtza8yrSosvm9xBOZ/XTU9Y5qlNzozcYGLNCQi+AOQw+cyDqAVcBEYfmvrTo1qOag5BIBi9 /XuSotOMx19jf4Yny1mx3wwAPtuQxerkMKiGXoxUcLk/aJAg7SOPAx3L6xtSGps3bIiesMl5 6jGVjp7Ka/QymwxhgVrOK4Jy2C3nDE0kbK19RjzEC2leAlGeNsRUt1xjIJLH8NcRiKmrwPAa 1gCtrR6+1Rdk7fZ3fFvnN3yNjpRXgrGAyaK3Jy9vB9fAIm6kyR4nFojvD3pE1wua4VWt1B/a DJI65onLZBQosfar98Hv4IRY+yBnbWSRzBPWqOKRC/fZt3dU7lutry+vE49euqcJsHwN87n4 nASkpRsSo3d1j1AcOD0ZVX+lTGQXm7Xz7q1sZCjqIJ9YHUVf7uK2mOWVoum8yvr7EWBdDaQe +6PNZMD/rqPQLVaM10Ns3FKtFvwFUlIbooU4wAKiezS+rwW/nXn/2ebf7YYL7kETNMYBK3Pk c+
X-Talos-CUID: 9a23:DBWbP28gsysOovStYPqVv0MwPNs7UFHX91yOORCUKjtGZ6S3clDFrQ==
X-Talos-MUID: 9a23:MpPJJQtuIvVVhkzryM2nnGhfZNdW+v2UNmMkyMk7p5XdFzFbNGLI
X-IronPort-AV: E=Sophos;i="6.05,251,1701126000"; d="scan'208,217";a="25117188"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=nAcujhjtbXhR3S1+PfQTio3ujB4xhRNDXVdiJiwjBpGF2GIYv2Fg5unSIpygoGn5uU+ReVyZy7GZGInS5V4Md8o+OWTZoqaYfQcnAG00XvjdhotFTRIuD5jqcDOpKBvH4Uq7ewv+UEmD827VNrtTZnCtRdz4bKB8XJOF91dDU1tzvihiDlOlg4m0M5W1VKFND3R9+ScTV0XsBovRy2rHW2vTvFZEK7WcezOoy3htFYPlibLaFU8WxrnZdia4+Lg+1isDr+JW78riCX57UHIcMeO4HhNjMWjYyBTamo04HR9IWmtHky8CH577iOn8yx7Q5fTkb/X/8WBZ3l0Id+9zEQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=b0odL5X0D+veCweZTYOqhJ70Z8BbM5Q/go3Dk/DiPpg=; b=BJTjLOqV1oZk4Ohbl7hFJYMnwTZ3dGUW6o+15GhOGA73irnfA/Io86/iyHDECOdb/EeZmlB7GplNHmosakl/5rdm6pvvuHuG7d1mCOLbny0A9yD9fhzexWegNLZW395vIrDDYg0Pou6w96xI1AiKD0aBRNPB5RRHwiVVLge+WzFFpOpL55etDWlpGtg5AEtTKSKkrmGtMUhzn30oKu2OMF3+O4XUaD7y09/VLou47hWgLqpqd1CGmNPhbwJKolNxtpAuDxsxo/y7EFhgWSQJ7pr8M/Kw46zR0p9jpGuCrLBneXXQioJGAGAb1fK7Gl6eKl9q3jS7bYIC+MtP9sYVGQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: Mahesh Jethanandani <mjethanandani@gmail.com>
CC: Lou Berger <lberger@labn.net>, NETMOD Group <netmod@ietf.org>, NetMod WG Chairs <netmod-chairs@ietf.org>
Thread-Topic: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03
Thread-Index: AQHaM2jmtZ2/0fB4d0qeT+RWsIzzDrDntdrAgBeO1HA=
Date: Wed, 07 Feb 2024 14:59:58 +0000
Message-ID: <DU2PR02MB10160BD1BE5733F21DA2DE91188452@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <5b6d8915-6c03-4b29-a150-b7611de75d3c@labn.net> <28F35BAC-6CEB-43FB-AF64-E1007F3FAA9C@gmail.com> <DU2PR02MB1016066216B97872FB35981C68897A@DU2PR02MB10160.eurprd02.prod.outlook.com> <4EE597ED-7A0F-4A42-8B08-90C5C47BB73D@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=4d51a72a-4cff-4556-8512-1843f4d890cb; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-02-07T14:57:34Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|AS8PR02MB9235:EE_
x-ms-office365-filtering-correlation-id: b40b9ce1-4986-4720-35b7-08dc27ed73d6
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: VnWfmVWXatwQWbSGzBfkizRd1D8msITg594VyRzJn+LK1w8jJ2hK7nARvyV/JYzfrF3vPJk7joOz43DLwCmewzBmmYzqLs+i+3nwp+rvB12047Ktq9YIf+oLoMe26mcxa8CyFAseA4PIjmIqvEqxGiLIoTi0EqfyXnOcBv9lChCDVDKd0zDX07V0hGZFZWAS0ZNsJRszAT2PojBeRxzq0w4jYMKy8iRUdBFFqDm9YRdp5HcVuzAvJAc6c63dGri6QnPbRdzYREwKUIxwX2wFhDhcJ8FtCeByMNFTeoBFwl4iUw+KRLtBDLH9wynilB5/lSl67ipxDoBPxao0pVJ5XcS1ytYk6kg59uEdGpCi1V4Y5wOr5/BIA5WepfNHHunLcfkLrUYH4XlN1kNuDsIudmjEZ82OHBNpp07NbXi5y2dj/0nPkIIAJLZ2rKnjvkLFvtR0amZazuKLJdcqiZiG3Biyae67egn5OeelyyajZ87YVyGlzCTV+GqFWCt5fyrnRTVZyU0xWgo7jomR+Olp0X5290yZYwbF1el23yY1sVahLPdCYndtEp3HqsyJzPqYxpOAEUw5s4MkAWqSfhksJ3MrMRoHHIsAZrw12VkjgOECJj+qGQAGGh6Mkf58taWB9YtUkIuL4pgePkV+qsug9g==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR02MB10160.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(39860400002)(396003)(366004)(136003)(376002)(346002)(230922051799003)(64100799003)(186009)(1800799012)(451199024)(122000001)(38100700002)(55016003)(166002)(83380400001)(966005)(66574015)(26005)(86362001)(33656002)(7696005)(71200400001)(6506007)(478600001)(9686003)(53546011)(76116006)(6916009)(316002)(66476007)(41300700001)(38070700009)(66946007)(54906003)(64756008)(66446008)(66556008)(8676002)(2906002)(4326008)(52536014)(8936002)(5660300002)(30864003)(4001150100001)(579004); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: L5R2fBCQEZc3PpUN5tCNBYwrUXp+9+nB5SCI20ZsMHvzivGL2JnK9DXYfe31IlvNxHgaFljeG1fI9Kv0IVFyvBt2TToNYgRe1vQCFs+bGcPKOqI4LVEZNtrdDMslwV0QYlO55T1XkJzJWdMZGSmj3xVgC13vWEkHDSr0cGAm97ERcMAmNpRL9ckhqmF19mlGx5YQYJdLGlQubaFfjsimJuLyJ75gFkTdmVNHtib+ONozp0lb7FVj2tBqKiUCuO1Q2/j26YCSmIbrxt6+EV6YnkTe1QTKcgBBcP4Z6uqI3BF6doH7zDqj6wBeN5Qaq7apzxvHWPEy3F+GUtKewNFtR5x5xV+tP+wgFGQrWKWfFsjh++NiXtOppvmxelbMNHzsXbWy5z76wvsrd/tEA1EBf8dA8Jprwf1RKwGxhU9CMUpHHx5Vr7xMaBCEu2phuXLAUZ6JXu7aFfdKnfG5/zNucU/lme3+zXVh87DiohEAds0wJFo2CtuqsWKs2z3ENu7wMKQwNSpbnsmxQ0+/x5Stg/fibPdNYK33qCy3Mm4f5tY6Q+q72AcuoH7DIynongrBVCCvhG9pVvzyB5s05NmsbFcozsC/NqFH1gyR22DvV/F1OvE6awmWDf+6rCXdnPbkezkd/fn9M+y1CajDLaPl8Bob8c8NCL0PRw4KHlQQG+/+nUyWTdemLJG82doBNB4/x59iyYDNygku3H1YG6mrOyg/nlXfWLu2IgbBvamOQ15vFRBmd2/EFbs88TzVoC3zERqPfQDuLbXBwv9/W0ToOElP0s027MfjzLubVnlIPOpM+G6dcAkpMufe9xFRDMSg+yfYWE5B0v7XSEcGwhkYaiLx0lqn1HGeMZ5ytK8/7Oef5IfKS1ejjEPREE4KgsxQhe6N7k/tiybetrf1t3NzVYimFAd8uVriXq4tT3HjK9Cb3zfdYeVoOD+J1G8uL6F80kha/GuaHrXnnlphlD25ULFth5Rp4glG14Mzi3EEFK9lj3ozgBuF2f2nk0qOGzTNzdCEZd4sdoj5PEMvWKVCaBgAQj1luUCxXgWnKZtGsvyXJk5qS5jYG2PDFbSMh8NiGCcdIp3jHIr4HZqVXfp5wyq/hoeM5fs8akeKdwiDXkJw6aHJp325X6OGiowA1BrC+Oal7LpE5n5OAS6mCuR9Vem2FaUYBu9m/tmgqwL5lD6vR30wRYhzkVjLuPv8KoXg7r9Mikz2ioTkNC+tK84iDj6gW55qokFRUUtBL1t/X4Wtz0zGE8FoWdCG8sriB7ww6xxgWJfbK50kUB/I6rV71dRT8tPZDMG2zjgmi+jpVKAS8mY9U5KA5FpUYWL5jr/W3YttUIqCeaUAbuL4h6au4bC8+jwynYjxD6IKlZXIcThSkteytPaDkAjGXXeuh55GQx/oxnEA+u4d+cc7C7vc12l5eV44IzA5R8Zp/2KPBc9tQhdG4O/+XbhzfdU9wkBklCQdN2WDHQ9Jtt8wp7ScPhNI/6F4dD5UAFIq0ZJ/h3YNU4QifHqfgnTGJbiugVRrACqONkvX4dh8f80A1x63GSIkiX/Qsm0b0d+mMwggJuW0LufqpqySB6m/H9ccOEozQEyUC3pczYDKrY7Z3oyHew==
Content-Type: multipart/alternative; boundary="_000_DU2PR02MB10160BD1BE5733F21DA2DE91188452DU2PR02MB10160eu_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b40b9ce1-4986-4720-35b7-08dc27ed73d6
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Feb 2024 14:59:58.3682 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: P90lxr2SmvKxoG9sD+sgKiLhC7GvCGlWB4TD4uKXWU3O6Ub2uxxGa7QQV9VA+epQlH2hfjooqCgPUhmtmiTz7N7uNAYA1r6COdXo35y1IQE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR02MB9235
X-TM-AS-ERS: 10.106.160.158-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.0.1002-28176.000
X-TMASE-Result: 10--37.302700-10.000000
X-TMASE-MatchedRID: jWUjNgV3nn/uYusHgJkgytRncTq+y+h9ebU/xPBdG2LwmCqn/d7uF0UW uNOlf2MMWpHGjdJGHpy1UOlz1sLXckfDovALsZ96+KgiyLtJrSDKU9yK0pqFWeRgEMvCxuZn1Ug 2VvRhaJU0wnbr8xnAo/D85PL62D8dxDiakrJ+SpmRgLeuORRdEpSQTn9jH7uadOACpUpTQnXMzw zM7SwvCuTfPHhZVG8jPVr63xyKNo9f2SdIdby5daTzJo0CZl8hDSG7dmYh9boHU67RzCzrd6MqB Q6g1zLIsRQBIwLJWYNVWK0SX6WmVFCxqE4whnXlAajW+EL+laOa+fApLB35t7yjPKjtY6O+1jox U3t+0uQxBm2TrrWsvDzr4TJKjukKrbw3y7sKQ4fHufTDqn1Kjz+B/tp8itBTXRBOiMotBXLUxgq braLAG6Sb7sFeOcmTaT3VNaZv3CMdZEkR8Y/meWhADSmwSTddhzldYl+vKinEVYfiaFRy6RAAI+ 8BMEGnjAGYI4RyoG9fy7hYybs9Je5CGMbmjumUE7KnN1UvNcLkMnUVL5d0E/+YKp2Mb6xJBVS/z rBxHzdiA2bsGDy/E7u1XV9filGzdPuue3cRiRi6hgVvSdGKo/PPvcvtNTbbNNpQs7sq78gCBvE1 eIcYKrjZDrxGnsOJL9pNzNuyd9bfqVBdB7I8UTKLdeHNQhvIsGbspEp+vvxmfm7ttB3aohTkJPy p5VMlf4rHggDVdNcmheAqCMdRddKhw1CGAxrInzPrJkGalpAl/0ODFh0Vj+RZ+ls/484hEE/NmK AZp8xFS1R7f3eKlIHjRL9SeAjFGUlF/M3Dxp/qtOCMCMzOYZsoi2XrUn/JJ51KgEwAGdm6rRx26 7m9tpWD5DDAqPadgWyBTm39yBmDGx/OQ1GV8lIZuIPZ7iVn8TFGa8PNSpSKIiuM3JGtMZRMZUCE HkRt
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: d8e717fa-582b-4c05-b610-b9803d6b42b5-0-0-200-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/BiSaH0eoSooAULSzkbWEEr9y3tI>
Subject: Re: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Feb 2024 15:01:36 -0000

Hi Mahesh, all,

FWIW, we submitted an updated version of the draft to address the pending points from your reviews. A diff to track the changes vs. -04 can be seen at: https://author-tools.ietf.org/iddiff?url1=draft-ietf-netmod-acl-extensions-04&url2=draft-ietf-netmod-acl-extensions-06&difftype=--html.

Cheers,
Med

De : BOUCADAIR Mohamed INNOV/NET
Envoyé : mardi 23 janvier 2024 16:57
À : 'Mahesh Jethanandani' <mjethanandani@gmail.com>
Cc : Lou Berger <lberger@labn.net>; NETMOD Group <netmod@ietf.org>; NetMod WG Chairs <netmod-chairs@ietf.org>
Objet : RE: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03

Hi Mahesh,

Thanks for the follow-up. Made some changes as you can see at https://boucadair.github.io/enhanced-acl-netmod/#go.draft-ietf-netmod-acl-extensions.diff.

Please see inline for more context.

Cheers,
Med



Orange Restricted
De : Mahesh Jethanandani <mjethanandani@gmail.com<mailto:mjethanandani@gmail.com>>
Envoyé : mercredi 20 décembre 2023 18:20
À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>>
Cc : Lou Berger <lberger@labn.net<mailto:lberger@labn.net>>; NETMOD Group <netmod@ietf.org<mailto:netmod@ietf.org>>; NetMod WG Chairs <netmod-chairs@ietf.org<mailto:netmod-chairs@ietf.org>>
Objet : Re: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03

Hi Med,

Thanks for addressing some of my comments. Please see inline.

On Dec 19, 2023, at 12:09 AM, mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> wrote:

Hi Mahesh, all,

Thank you for the review and comments. We just posed draft-ietf-netmod-acl-extensions-04.

Please see more context inline.

Cheers,
Med

De : netmod <netmod-bounces@ietf.org<mailto:netmod-bounces@ietf.org>> De la part de Mahesh Jethanandani
Envoyé : mardi 5 décembre 2023 23:09
À : Lou Berger <lberger@labn.net<mailto:lberger@labn.net>>
Cc : NETMOD Group <netmod@ietf.org<mailto:netmod@ietf.org>>; NetMod WG Chairs <netmod-chairs@ietf.org<mailto:netmod-chairs@ietf.org>>
Objet : Re: [netmod] WG Last Call: draft-ietf-netmod-acl-extensions-03

Hi,

I do support this work, as it is much needed, and would like to see it progress. However, I do believe that the document needs to undergo a revision to qualify for LC. Some of the comments are editorial or minor, and can be addressed easily, but others are not. They should all be addressed for the WG to call the document ready.

- The Security Considerations section has both the read/write nodes and the read-only nodes as empty (or marked as TBC, which I imagine stands for To Be Completed). This needs to be filled out, or if no nodes are worth any security considerations, it should be stated so, and why.

[Med] ACK. We don’t repeat what is already in 8519 but focus on key additions in the spec: https://github.com/boucadair/enhanced-acl-netmod/pull/65/files

[mj] Thanks for updating the section.

s/setf/set/
s/Simialr/Similar/

and in other place
s/modelled/modeled/

[Med] Thanks. Fixed.


- Isn’t the YANG model normative portion of the document? Isn’t what this document all about? Why is it then in the Appendix?

[Med] We are using a script to generate the IANA modules + we are actually following this part from the 8407bis:

   It is RECOMMENDED to include the URL from where to retrieve the
   recent version of the module.  When a script is used, the Internet-
   Draft that defines an IANA-maintained module SHOULD include an
   appendix with the initial full version of the module.  Including such
   an appendix in pre-RFC versions is meant to assess the correctness of
   the outcome of the supplied script.  The authors MUST include a note
   to the RFC Editor requesting that the appendix be removed before
   publication as RFC and that RFC IIII is replaced with the RFC number
   that is assigned to the document.  Initial versions of IANA-
   maintained modules that are published in RFCs may be misused despite
   the appropriate language to refer to the IANA registry to retrieve
   the up-to-date module.

[mj] I am not clear on what happens to the IANA module once the draft is published as an RFC based on what you cite from 8407bis.
[Med] It will be removed as per the note:

(2) The modules are provided in {{iana-icmp}}, {{iana-icmpv6}}, and {{iana-ipv6-ext}} for the users convenience before publication as RFC. Please remove these appendices from the final RFC.

The document states that the reference to “RFC IIII” is replaced with the actual RFC number, but  it also says that the Appendix be removed. What happens to the initial version of the module itself? Is it removed if the Appendix is removed?
[Med] It will be removed as per the note above. Please note that this practice is already followed in rfc9108, for example.

Or does it remain in the Appendix as an initial version, with language that indicates that the IANA registry should be used to retrieve the most up-to-date model? The language in Section 1.1 item (2) does not help.

The above text from 8407bis needs to be explicit on what happens to the initial version of the module as part of the RFC publication.
[Med] Please feel free to propose changes to this part of the bis for better clarity:

   The authors MUST include a note
   to the RFC Editor requesting that the appendix be removed before
   publication as RFC and that RFC IIII is replaced with the RFC number
   that is assigned to the document.


- Why is the Section titled "Initial Version of the The ICMPv4 Types IANA-Maintained Module”, when the model in question is "iana-icmpv6-types@2020-09-25.yang<mailto:iana-icmpv6-types@2020-09-25.yang>”?
[Med] This was a typo. Fixed.

[mj] You fixed it another location. However, I still see the following in the -04 version of the document.
[Med] Thanks for catching this. Fixed.

B.2. Initial Version of the The ICMPv4 Types IANA-Maintained Module
<CODE BEGINS> file "iana-icmpv6-types@2020-09-25.yang<mailto:types@2020-09-25.yang>"


module iana-icmpv6-types {


- ‘defined-sets’ and ‘aliases’ have been defined in a the separate model ‘ietf-acl-enh’. Are these sets and aliases defined to be used outside of ACL? If that is the case then having them outside the ‘ietf-access-control-list’ model makes sense. Otherwise, almost everything in the ‘ietf-acl-enh’ is an augmentation of the model defined in RFC 8519, as stated in the Introduction of the document

[Med] These are defined to be consumed for ACL policies.


"The YANG module in this document is solely based on augmentations to the ACL YANG module defined in [RFC8519].”

[Med] The intent was to highlight that we are not using a bis approach. Tweaked the paragraph that includes that text for better clarity.

[mj] I think it already clear that this model an augmentation and not a bis. A bis is when you take the original document and edit it for updates, and this is clearly not that.

I actually agree with your above statement in the Introduction that you had, about the module being solely an enhancement of the ACL YANG model, and was surprised to see it taken out. The point I was making was that just like what you have done with augmenting "/acl:acls/acl:acl/acl:aces/acl:ace/acl:matches” to add ‘choice payload’, ‘choice alias’ etc, you could have augmented “/acl:acls” to add ‘defined-sets’ and ‘aliases’.
Right now, as is, the ietf-acl-enh module sits on the root of the config tree, with no relation to the ACL model, other than references to it from within the ACL model. If the definitions in ietf-acl-enh are to be consumed by the ACL model only, why not augment the ACL model (as shown below) to add them in the ACL tree?

[Med] This is fair. Now that I managed to refresh the context in my mind I confirm that we have done that in a previous version of the spec, but the feedback we received from the WG was to move those upper in the hierarchy (because there might be other cases). See for example https://datatracker.ietf.org/doc/minutes-115-netmod-202211080930/:

==
Joe Clarke: It would be nice in a standalone container (i.e. groupings that could be imported). I see some other use cases for these defined groupings besides just ACLs.
==


If that is the case I see no reason why those containers should not be augmentations into the same model, as in

augment “/acl:acls” {
  container defined-sets {
  ….
  }

  container aliases {
     …
  }
}


- I just pulled down the latest version (-03) of the draft, and ran into this error.

$ pyang ietf-acl-enh@2022-10-24.yang<mailto:ietf-acl-enh@2022-10-24.yang>
iana-icmpv6-types@2020-09-25.yang<mailto:iana-icmpv6-types@2020-09-25.yang>:1: error: unexpected latest revision "2023-04-28" in iana-icmpv6-types@2020-09-25.yang<mailto:iana-icmpv6-types@2020-09-25.yang>, should be "2020-09-25”.

[Med] Fixed. Thanks.

- Section 3.4. TCP Flags Handling. The document states that.

"Clients that support both 'flags-bitmask' and 'flags' matching fields MUST NOT set these fields in the same request.”.

Can the model have a must statement to prevent this from being configured inadvertently?

[Med] We don’t see how to do that with a must statement, hence the normative language in the narrative text.

[mj] How about something like

must “not(/acl:acls/acl:acl/acl:aces/acl:ace/acl:matches/acl:l4/acl:tcp/acl:flags)”  {
  error-message
    “Either flags or flags-bitmask should be configured, but not both.”;
}

under ‘flags-bitmask’?
[Med] Thanks.

If you are feeling adventurous, you could add a deviation add statement to add a similar must statement under tcp/flags also :-).


Same for Section 3.5 Fragments Handling
[Med] Same answer :-)

- There should be clear direction to the RFC Editor on what should be done with revision dates. The same is true for other placeholder text. For example, what is the RFC Editor to do with text "RFC XXXX"?
[Med] Done: https://github.com/boucadair/enhanced-acl-netmod/pull/59/files

[mj] Thanks.


- References in the YANG model should be expanded to include the title of the RFC.

[Med] We are echoing references as listed in an IANA registry, so we do not have control over that reference.

- Examples are always good. Not only can they be used to validate the model, but users get to understand how it can be used. See other models such as BGP, TCP, BFD on how an example can be added.

[Med] We do already have many in the core document. Will consider adding more if needed.

[mj] I am referring to the example as stated in Section 3.12 of RFC 8407<https://datatracker.ietf.org/doc/html/rfc8407#section-3.12>. If by core you are referring to RFC 8519, then unfortunately, we the authors missed it too -:( But here is a module usage example from another draft.
[Med] I’m referring to examples such as those in https://datatracker.ietf.org/doc/html/draft-ietf-netmod-acl-extensions-04#name-tcp-flags-handling.

https://datatracker.ietf.org/doc/html/draft-ietf-idr-bgp-model-17#name-creating-bgp-instance



- How is this a reference?

        reference

          "- Bill Simpson <mailto:Bill.Simpson&um.cc.umich.edu<http://um.cc.umich.edu/>>

[Med] We are echoing a reference as cited in an IANA registry, so we do not have control over that reference.

[mj] Regardless, and I am repeating the question, how is this a reference?
[Med] That’s a reference as per the IANA registry:

33  IPv6 Where-Are-You (Deprecated) [Simpson][RFC6918]
34  IPv6 I-Am-Here (Deprecated)     [Simpson][RFC6918]
35  Mobile Registration Request (Deprecated)   [Simpson][RFC6918]
36  Mobile Registration Reply (Deprecated)     [Simpson][RFC6918]

I think having RFC 6918 as a reference is good enough.
[Med] but this will deviate from what is in the IANA registries.

And that brings up another point. The sections that contain the YANG models need to list out all the references cited in the model at the beginning of the section. For example, Section 4 needs to list RFC 9293, 3032, 792, 4443 etc. at the beginning of the section, such that they are included in the Normative list of references. See Section 3.9 of RFC 8407<https://datatracker.ietf.org/doc/html/rfc8407#section-3.9>.

[Med] We are familiar with that part. The point here is that we don’t cite them in the main text because the IANA modules will be removed from the final RFC as per the comment above.

Thanks.


Thanks.
[Med] Thanks for the review. Much appreciated.



Thank you.


Mahesh Jethanandani
mjethanandani@gmail.com<mailto:mjethanandani@gmail.com>





____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.