Re: [netmod] Stephen Farrell's No Objection on draft-ietf-netmod-yang-json-09: (with COMMENT)

Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de> Tue, 22 March 2016 16:24 UTC

Return-Path: <j.schoenwaelder@jacobs-university.de>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD8D312DAD7; Tue, 22 Mar 2016 09:24:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JbwtAgAM0Dyd; Tue, 22 Mar 2016 09:24:26 -0700 (PDT)
Received: from atlas3.jacobs-university.de (atlas3.jacobs-university.de [212.201.44.18]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E147212DA7B; Tue, 22 Mar 2016 09:23:40 -0700 (PDT)
Received: from localhost (demetrius5.irc-it.jacobs-university.de [10.70.0.222]) by atlas3.jacobs-university.de (Postfix) with ESMTP id 9D951A53; Tue, 22 Mar 2016 17:23:39 +0100 (CET)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from atlas3.jacobs-university.de ([10.70.0.220]) by localhost (demetrius5.jacobs-university.de [10.70.0.222]) (amavisd-new, port 10030) with ESMTP id Az_0n7gEza8H; Tue, 22 Mar 2016 17:23:31 +0100 (CET)
Received: from hermes.jacobs-university.de (hermes.jacobs-university.de [212.201.44.23]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "hermes.jacobs-university.de", Issuer "Jacobs University CA - G01" (verified OK)) by atlas3.jacobs-university.de (Postfix) with ESMTPS; Tue, 22 Mar 2016 17:23:38 +0100 (CET)
Received: from localhost (demetrius1.jacobs-university.de [212.201.44.46]) by hermes.jacobs-university.de (Postfix) with ESMTP id D2E9020044; Tue, 22 Mar 2016 17:23:38 +0100 (CET)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from hermes.jacobs-university.de ([212.201.44.23]) by localhost (demetrius1.jacobs-university.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id UCmfjkhk8JRQ; Tue, 22 Mar 2016 17:23:37 +0100 (CET)
Received: from elstar.local (elstar.jacobs.jacobs-university.de [10.50.231.133]) by hermes.jacobs-university.de (Postfix) with ESMTP id 1AFC420043; Tue, 22 Mar 2016 17:23:37 +0100 (CET)
Received: by elstar.local (Postfix, from userid 501) id 0F5013A50159; Tue, 22 Mar 2016 17:23:37 +0100 (CET)
Date: Tue, 22 Mar 2016 17:23:37 +0100
From: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
To: Eliot Lear <lear@cisco.com>
Message-ID: <20160322162336.GB65254@elstar.local>
Mail-Followup-To: Eliot Lear <lear@cisco.com>, Benoit Claise <bclaise@cisco.com>, Ladislav Lhotka <lhotka@nic.cz>, "netmod-chairs@ietf.org" <netmod-chairs@ietf.org>, Kent Watsen <kwatsen@juniper.net>, "netmod@ietf.org" <netmod@ietf.org>, "draft-ietf-netmod-yang-json@ietf.org" <draft-ietf-netmod-yang-json@ietf.org>, The IESG <iesg@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
References: <m2d1qnj2ec.fsf@birdie.labs.nic.cz> <20160321151914.GA62880@elstar.local> <56F0137B.3090103@cisco.com> <72154E94-3C00-438B-B177-35DB9216DF03@juniper.net> <56F02B21.3080103@cisco.com> <20160322081043.GA64402@elstar.local> <7DA81401-6AE5-4DCA-A8C7-3B41ED5B2C06@nic.cz> <56F15DBC.5050905@cisco.com> <20160322154223.GA65166@elstar.local> <56F16EE8.70703@cisco.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <56F16EE8.70703@cisco.com>
User-Agent: Mutt/1.4.2.3i
Archived-At: <http://mailarchive.ietf.org/arch/msg/netmod/_hIgC0dNxyzldN2CzG5Q911xQhw>
Cc: "netmod-chairs@ietf.org" <netmod-chairs@ietf.org>, "netmod@ietf.org" <netmod@ietf.org>, "draft-ietf-netmod-yang-json@ietf.org" <draft-ietf-netmod-yang-json@ietf.org>, The IESG <iesg@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Subject: Re: [netmod] Stephen Farrell's No Objection on draft-ietf-netmod-yang-json-09: (with COMMENT)
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Mar 2016 16:24:28 -0000

On Tue, Mar 22, 2016 at 05:12:24PM +0100, Eliot Lear wrote:
> Hi Juergen,
> 
> On 3/22/16 4:42 PM, Juergen Schoenwaelder wrote:
> > I think such considerations belongs into documents making use of
> > object signatures and close to 100% of the YANG models today don't
> > so I do not even think this qualifies for RFC6087bis.
> >
> 
> I think there are AT LEAST two areas where signatures are going to be
> necessary:
> 
>   * There exist multi-level authorization schemes today that rely on
>     signatures.  Those have to be transported.
>   * Manufacturer usage descriptions (MUDs) have extremely broad scope in
>     terms of the number of devices that are intended to use the same
>     description (think thousands to millions).  And so an unauthorized
>     change could have a similarly broad impact.
> 
> 
> Thus, wherever the YANG experts think signatures should happen in each
> encoding case is fine with me; but I'd suggest that I'm not the only
> person who's going to want to know.  Is it THAT hard to at least add a
> reference?  Because if it is, that would cause me to wonder if the
> mechanisms are really in place to do the right thing.
> 

Eliot,

I simply fail to understand what the problem is and I fail to see
which addition (ideally in concrete words) is proposed to fix the
problem.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>