[netmod] RFC7952 annotation to identify leaf encryption/hashing format

"Sterne, Jason (Nokia - CA/Ottawa)" <jason.sterne@nokia.com> Mon, 22 May 2017 17:16 UTC

Return-Path: <jason.sterne@nokia.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4AB65129B9E for <netmod@ietfa.amsl.com>; Mon, 22 May 2017 10:16:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.595
X-Spam-Level:
X-Spam-Status: No, score=-0.595 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, TRACKER_ID=1.306] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CVXpipM9tjtW for <netmod@ietfa.amsl.com>; Mon, 22 May 2017 10:16:41 -0700 (PDT)
Received: from EUR03-DB5-obe.outbound.protection.outlook.com (mail-eopbgr40114.outbound.protection.outlook.com [40.107.4.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 59EF9126C23 for <netmod@ietf.org>; Mon, 22 May 2017 10:16:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=DtTdzH0vv7NWcNSVASR4MyltxQ9irFUovG67hOvr6Go=; b=MZnIPk5PAc1CT8EKEygKiaxOmFzE7zx2P0YyKAKUfz0fs8Qv2q8O20PrkGy1qWlCV/y78i47mPq63XsDNu3ObmgFK9bv7BKbf9d/OVzninFI9uG5ErbfQ8VG0LLoa6r/P/gTUq87v+thR76Xxwc4XuWO2w2nwkKs/8r9dOMPeJk=
Received: from HE1PR07MB0843.eurprd07.prod.outlook.com (10.162.24.16) by HE1PR07MB0841.eurprd07.prod.outlook.com (10.162.24.155) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1124.5; Mon, 22 May 2017 17:16:36 +0000
Received: from HE1PR07MB0843.eurprd07.prod.outlook.com ([fe80::8d4b:9f87:2a89:44d2]) by HE1PR07MB0843.eurprd07.prod.outlook.com ([fe80::8d4b:9f87:2a89:44d2%18]) with mapi id 15.01.1124.007; Mon, 22 May 2017 17:16:37 +0000
From: "Sterne, Jason (Nokia - CA/Ottawa)" <jason.sterne@nokia.com>
To: "netmod@ietf.org" <netmod@ietf.org>
Thread-Topic: RFC7952 annotation to identify leaf encryption/hashing format
Thread-Index: AdLTHp/qRcAoPTtCSC+aPJgpTKWFjA==
Date: Mon, 22 May 2017 17:16:36 +0000
Message-ID: <HE1PR07MB0843F3616FA7398A29599A749BF80@HE1PR07MB0843.eurprd07.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=nokia.com;
x-originating-ip: [157.52.0.58]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; HE1PR07MB0841; 7:EG3EE7ESejgJt/JzSZFr53jicN0CKtgvslVF6N5Bg9e7PNyvEK3qEofv7gCQQSeNYoK5LitMofqYzigjSDKBJe+hpO+X1EKgsGIi6q6WIAm8mdOqGnMCjD9MZAmm3TY8NUKyKAheUYJlWTTiN707+p8HEj2OAN4OD+Jkc8HKGSbmWOqTsj+HcspqVYzz0WIwZbYtqTC1boF+9OoVA2JoY+RwS0AKSMX8gncqYpvM1ogDm7Ym/GaDp54PLn69esjD9kq3fOfdBuSPJg1eiWfgCcODiVGqoQ/m3njhlEwAZzCsVyTtZ+wq2miB8Kr6DbXQhy5aI3hJnkpShYtLf2Gw5A==
x-ms-traffictypediagnostic: HE1PR07MB0841:
x-ms-office365-filtering-correlation-id: a5d09ee2-bcec-4665-55b9-08d4a1364dbe
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075)(48565401081)(201703131423075)(201703031133081)(201702281549075); SRVR:HE1PR07MB0841;
x-microsoft-antispam-prvs: <HE1PR07MB084137C7BB7427A78BCB5C789BF80@HE1PR07MB0841.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700036)(100105000095)(100000701036)(100105300095)(100000702036)(100105100095)(6040450)(601004)(2401047)(8121501046)(5005006)(3002001)(100000703036)(100105400095)(93006095)(93001095)(10201501046)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123564025)(20161123558100)(20161123555025)(20161123560025)(6072148)(100000704036)(100105200095)(100000705036)(100105500095); SRVR:HE1PR07MB0841; BCL:0; PCL:0; RULEID:(100000800036)(100110000095)(100000801036)(100110300095)(100000802036)(100110100095)(100000803036)(100110400095)(100000804036)(100110200095)(100000805036)(100110500095); SRVR:HE1PR07MB0841;
x-forefront-prvs: 03152A99FF
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(39400400002)(39450400003)(39860400002)(39850400002)(39840400002)(39410400002)(53754006)(6436002)(2351001)(2906002)(6506006)(54356999)(9686003)(189998001)(6306002)(7736002)(74316002)(50986999)(5640700003)(102836003)(5660300001)(6916009)(99286003)(54896002)(66066001)(790700001)(3846002)(6116002)(551544002)(7696004)(33656002)(55016002)(25786009)(86362001)(2501003)(38730400002)(97736004)(5630700001)(110136004)(8936002)(81166006)(8676002)(1730700003)(5250100002)(478600001)(3660700001)(3280700002)(53936002)(19609705001)(2900100001); DIR:OUT; SFP:1102; SCL:1; SRVR:HE1PR07MB0841; H:HE1PR07MB0843.eurprd07.prod.outlook.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_HE1PR07MB0843F3616FA7398A29599A749BF80HE1PR07MB0843eurp_"
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 May 2017 17:16:36.8832 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB0841
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/b2G3BK8Mk3NM56vw4EXyQWOnN3E>
Subject: [netmod] RFC7952 annotation to identify leaf encryption/hashing format
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 May 2017 17:16:43 -0000

Hi all,

Does anyone see any reasons why RFC7952 annotations couldn't/shouldn't be used to identify the encryption/hashing format of an encrypted/hashed leaf ?

There are a number of approaches out there for encrypted/hashed leafs (e.g. RFC7317 crypt-hash which encodes the hash function by prepending $x$ to the password, using multiple leafs for the value/algorithm, etc).

These are leafs that can be typically written in cleartext or encrypted/hashed format, but return only an encrypted/hashed format when retrieved from a device.

I think RFC7952 annotation could also be used as an approach to this problem.

Annotation definition:

     md:annotation hash-format {
       type enumeration {
         enum md5l
         enum sha-256
         ...
       }
     }

An 'auth-key' leaf that is hashed:

    <auth-key hash-format="sha-256">
      QsdsEWfjKAowjjhQHHslJSHHll
    </auth-key>


Regards,
Jason

Note - I don't believe this statement in section 9 would point anyone away from using annotations for encryption/hashing information (since the encrypted leafs are data nodes):  "It is RECOMMENDED that security-sensitive or privacy-sensitive data be modeled as regular YANG data nodes rather than annotations."