[netmod] Re: AD - Re: AUTH48: RFC-to-be 9644 <draft-ietf-netconf-ssh-client-server-40> for your review

mohamed.boucadair@orange.com Wed, 18 September 2024 15:00 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 03FDDC151547 for <netmod@ietfa.amsl.com>; Wed, 18 Sep 2024 08:00:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 28HKNwv_r0Mx for <netmod@ietfa.amsl.com>; Wed, 18 Sep 2024 07:59:56 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.210.123]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 752D7C14F5EA for <netmod@ietf.org>; Wed, 18 Sep 2024 07:59:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1726671595; x=1758207595; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:from; bh=b8CIhV0D2Cpgf81ug0EdpLx5UV7fFO+vIewptM5svYM=; b=q9wgcbNkCtXZAGF6u+jIWc7tFPJkRRR9sbkSH+8a8Y8CkTxwrag+0+5T w5h81uwY+JjYaiuZHJKdDq4Dp7yBDhtvr82sbIGg8GSvggGOkJKZH1aGO +V969VVzq2omXIVDLOas/qToqsuhLDnJjcZM73pGjEygvEdjsv+YtFfuu SaARwp0nd/FcNY2lLTSrv2bVNo46w6Mvg2QfYQ3/F4W0wMqPA2oAf3qSx CYwfbWvE8UEvr1HCnXiHEoNY/PZvhdt0QZ46muTGh56+OK90OmeJGYkMx OWPSlp/uz/F3kGUE+2Ud7Unyhwacr7aPMrRs6Oqjf/33jY2o3ttXde0kz g==;
Received: from unknown (HELO opfedv1rlp0f.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Sep 2024 16:59:54 +0200
Received: from unknown (HELO opzinddimail8.si.fr.intraorange) ([x.x.x.x]) by opfedv1rlp0f.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Sep 2024 16:59:54 +0200
Received: from opzinddimail8.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with SMTP id DCEDA761AC0 for <netmod@ietf.org>; Wed, 18 Sep 2024 16:59:53 +0200 (CEST)
Received: from opzinddimail8.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 86A96761AD3 for <netmod@ietf.org>; Wed, 18 Sep 2024 16:59:23 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail8.si.fr.intraorange (Postfix) with ESMTPS for <netmod@ietf.org>; Wed, 18 Sep 2024 16:59:23 +0200 (CEST)
Received: from mail-westeuropeazlp17010001.outbound.protection.outlook.com (HELO AM0PR83CU005.outbound.protection.outlook.com) ([40.93.65.1]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Sep 2024 16:59:15 +0200
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by PA4PR02MB6749.eurprd02.prod.outlook.com (2603:10a6:102:fe::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7982.16; Wed, 18 Sep 2024 14:59:13 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::c9a1:d43c:e7c6:dce1]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::c9a1:d43c:e7c6:dce1%4]) with mapi id 15.20.7962.022; Wed, 18 Sep 2024 14:59:13 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.218.35.127-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=Pass smtp.helo=postmaster@AM0PR83CU005.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 40.93.65.1 as permitted sender) identity=mailfrom; client-ip=40.93.65.1; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: Pass (smtp-in365b.orange.com: domain of postmaster@AM0PR83CU005.outbound.protection.outlook.com designates 40.93.65.1 as permitted sender) identity=helo; client-ip=40.93.65.1; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@AM0PR83CU005.outbound.protection.outlook.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/15 ip4:52.102.0.0/16 ip4:52.103.0.0/17 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all"
IronPort-Data: A9a23:LC8RI6kiMkCH6WgZaiu0lgDo5gyEIURdPkR7XQ2eYbSJt1+Wr1Gzt xIfXj3VPazYN2f9f4sla97k9hsA6MDTztNkHQVtpSs9RC4T+ZvOCOrCIxarNUt+DCFioGGLT Sk6QoOdRCzhZiaE/n9BCpC48T8mk/jgqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYQfNNwJcaDpOt/rS8UM35pwehRtD1rAATaES1LPhvylNZH4vDfnZB2f1RIBSAtm7S 47rpF1u1jqEl/uFIorNfofTKiXmcJaLVeS9oiM+t5yZv/R3jndaPpDXlhYrQRw/Zz2hx7idw TjW3HC6YV9B0qbkwIzxX/TEes1zFfUuxVPJHZSwmZOalVKcIyHF+tpJS3gdOq0Io+EpMFgbo JT0KBhVBvyCr8uTmIqBGrJHu5x7cY/sIZ8VvWxmwXfBF/E6TJvfQqLMo9hFwDM3gcMIFvHbD yYbQWY3KkWbJUMSfA5/5JEWxI9EglH6dD1RrV+Z46Aw/mPawAVwypDqKtPTddHMTsJQ9qqdj j+cpj6pWUBGXDCZ4SeLqXD1lMORpC76AK4vSY+j+/1w3mTGkwT/DzVNDgHn/pFVkHWWWN9ZN w8V9zYghbc76FemSJ/7UgHQiHuGswIcUtxZFeEz7gClxa/d4gLfDW8BJhZHZcAjs8MeRDE22 BmOhdyBONB0mLicSHbY6bqPsT6vIy8NIGYQYTddElNcu4G7+cc0kw7FSctlHOitlNrpFDrsw jeM6i8jm7EUis1N3KK+lbzav96yjsfAFBFvtl/+Z02CqTpSY661Pov22GGOuJ6sM72lZlWGu XEFne2X4+YPEYyBmUSxrAMlTODBCxGtYG20vLJ/I6TN4QhB7FaFWehtDNxWIU5oNoMbdCT1b VLJvhtc7Y1XJCL1NfYvO9roTcM30aLnCNLpEOjOacZDaYRwcwnB+zxyYUmX3Cbml01EfUAD1 XWzLpzE4ZUyUP4PIN+KqwE1jOFDKscWmD67eHwD5077uYdynVbMIVv/DHOAb/oi8ISPqxjP/ tBUOqOikkoFDrCvMnGHr9VKdjjmyETX47in86S7kcbTc2Jb9J0JVaGBn9vNhqQ5wfsJzbeQr hlRpGcBkgKk3CCXQel1VpyTQOi0B8ogxZ7KFSktNkyvwH8tfc6k670HH6bbjpF2nNGPOcVcF qFfE+3ZW6wnYm2ep1w1M8OhxKQ8L07DrVzVYEKYjM0XIsQIq/rhoIG0J2MCNUAmU0KKiCfJi +b9jliDHsRfGWyPzq/+MZqS8r94hlBF8MoaYqcCCoAJEKkw2OCG6hAdj8Pb5+klDE37/GvB/ DvOWUpeovTRqYgo9tWPnbqDs4qiD+p5GAxdAnXf6rG1cyLd+wJPBKdeBf2Qc2m1uHzcoc2fi Sd9l5kQ88HrWH5NqYN6HLstxqU7jzcqj6EP1RxqRR0ncHz3Yo5dzqG64PRy
IronPort-HdrOrdr: A9a23:XIq1qKMWzRPUOcBcT0P155DYdb4zR+YMi2TDiHoddfUFSKalfp 6V98jzjSWE8wr4WBkb+expc8K7MBfhHO1OkPMs1NaZLULbUQSTXeZfBOfZrQEIXheOjtK1tp 0QOZSWaueAa2SS5PySiGXWLz9j+qj/zEnCv5a8854Zd3AOV0gW1XYaNu/0KCxLbTgDIaB8OI uX58JBqTblU28QdN6HCn4MWPWGj8HXlbr9CCR2SyIP2U2rt3eF+bT6Gx+X0lM1SDVU24ov9m DDjkjQ+rijifem0RXRvlWjoKi+2eGRhOerNvb8yvT9GQ+cyTpAo74RGYFqiQpF4d1HLmxa1e Uk7S1Qe/iboEmhA11d6SGdpzUIlgxepkMKgGXo/0cKraHCNU0HItsEioRDfhTD7U08+Nl6za JQxmqc84FaFBXagU3Glq71vjxR5z6JSEAZ4Jkupm0aVZFbZK5arIQZ8k8QGJAcHDji4IRiFO V1FsnT6PtfbFvfNhnizyFS6c3pWm52EgaNQ0AEtMDQ2z9KnGphx09dwMAEhH8P+J80VpEB7e XZNaZjkq1IU6YtHOtALfZERdHyBn3GQBrKPm7XKVP7FLsfM3aIsJLz6KVd3pDeRHXJ9upBpH 3saiIqiYdpQTOeNSSn5uw6zizw
X-Talos-CUID: 9a23:Sz7bxGOKndu5Je5DByA96xREQOkcXVqa9VzXA1/hDjhYcejA
X-Talos-MUID: 9a23:dysc6gupnnFdPW6pkc2nmT85Np56z/qXBUFVvahbidKJNjYuAmLI
X-IronPort-AV: E=Sophos;i="6.10,239,1719871200"; d="scan'208,217";a="52128394"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=B+oleKYnNW9Vbbmym9xZyO4Y3qD/pnyMG0WY3JCfG3D+x+7kU78VyrMC8oA2dULmxEWAqxhzb8TAIBU/Da3amD/tXfkkl6YeiWkcxAygbZoFCPiOxxKnJZyHFPOpjslEd7o69bJ5UocIm4DOrZEb5fqTa4JDMyKAdxjYP7n4GYVmY46rsk9a16uFL9YMZPfoNTfTFc6i6fLyYqK4cTa6M9mL5icbrtAWTPWKtTNQ+tWQgSBMcl642Bd/8IxoCZtRgkCvxZserrbX9AVUD0MpdM9eR/+x41W7hVAam5GZ04gThtjBC5l4zhNJNgdCN0y1Hvs3ENWS24c0PTLMNzbMRw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=z8QJbY6futnpmE3LvDE/9sPiz4NINj8Gzy+4om5j4cc=; b=X4aRmDBtYUcabPJWgE/tepuUGuB5rULdNBoLfymD2x4rL+GUeuqVLc53efpqfyBPvxgx6rtrzRPms7ROf2g8fbii5kYp0tV3yOPrbGRBdjVb79aJcFFB9Jgm72YULTZf3BONT5Q9EFIt52xPTSc4d9VGTZdmjuFgy48KIFkQp7ojoVRVayEA2RwLf3+1EIjDbPx/Tjg2gF/Y5yzpLypEsNKFkkjae4xJidtanJMnFLU4SgmFhLqbbz9Rtd/7xs0BSrOnDMWh6ljGP0Lpa9d0RDnd1UskTcrNDsT1AXSe44OqkTpmYlCF9FJqtQuol/GU/OFb3dpNUUPvSDcOBQ1CSA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: Kent Watsen <kent+ietf@watsen.net>
Thread-Topic: [netmod] AD - Re: AUTH48: RFC-to-be 9644 <draft-ietf-netconf-ssh-client-server-40> for your review
Thread-Index: AQHbBS09Dl/igNphfUSLVtUeuAo++bJdqghA
Content-Class:
Date: Wed, 18 Sep 2024 14:59:12 +0000
Message-ID: <DU2PR02MB101601D568F5AA4CD8272FA5C88622@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <DU2PR02MB10160B7C5E0C210F82B774BD788642@DU2PR02MB10160.eurprd02.prod.outlook.com> <01000191e5e7bd22-2999d337-8925-470f-abb4-890ca32884aa-000000@email.amazonses.com> <DU2PR02MB10160807B1741AC3C990199AF88642@DU2PR02MB10160.eurprd02.prod.outlook.com> <01000191e6f83d74-cc10b47d-554c-4882-8da0-37ba8861baeb-000000@email.amazonses.com>
In-Reply-To: <01000191e6f83d74-cc10b47d-554c-4882-8da0-37ba8861baeb-000000@email.amazonses.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-09-18T14:51:17Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=e1e1972b-cdad-4c81-af68-27a8ac78080a; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|PA4PR02MB6749:EE_
x-ms-office365-filtering-correlation-id: 5d994b81-3555-43b1-4be2-08dcd7f27556
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|1800799024|38070700018;
x-microsoft-antispam-message-info: k3WVWELbq8hQRh9Z2p7lIALWS77sybQzcZU6TZckympRK2Mea5S/LMwxvElPlT4Oll9BAjQH1Yg/TEhphhkrx2Xrgj/DZvKJbZevNEPSJJJdOkhfdLl6rwZJQOgWy1Xa7PEO7MCLvAgTfIng8UIjjgjG/a1abWjWxCaCgwVQIoQVMWRWiZqHy+f9LS25CactVmmVENcrw6HwfcV8grdjg86hBFsNcUtwBx9+FTEKUN4VaIZ+eumBrGdbxI2RJ47M5sItPwboG5A7tDgzTd70KB7LFTLK4hfXwrFUZgWyWCCtEHO60p0tpMQRXLQLYQ330kvUjM0NYFrNmmQqhQ5cPVNxvCN8vNWhWxyNi1ooHV1woAgsvfo7UDLyijn6j+LqmjXF+SKLSNH9rTXJjS3pWXOeqJ/KTlVHKnWcGpTXW5bXfZqcSZF2EqfPb7s5joNcdMDjCmXWPG79VROV7IKRTLUWowV4Va3dvafwWTEyP3tXzLbYH080zu6sFE9gO16bnG7/fpAh8q9YViD4fGp6wjRFK+fjC89Rw3EATmLeHTnEc3zg7/01KApS7K0UXErr75o4t5R5AxhLy0llIB2LZq3TU56h/jR6XeLWd1wGaRIdR2/b0OdoV3ace0WbElvf9ja6ssFPoqssIA/n5VWgFFnWhOLOxMz9BAZ663iePSe+/83K6SqMXY2s74H8ZQzqQ23hZ1RH5BNUrQL1VmgnsGfoAf+hfbbBgeNjxzU/qUNkOGT1Qiygrm2LtEbNgQYXrEG2l/uXMn7wZkfODCLWiCocExGzwsXkkCuPEf7tcoUI35uad5xYuZt39nbJDUKWwx8BZmvEjSC2d/SCxKNAby4iCSnHzDUaPgorTjzzS8rShVWVTUxZKPLqxJn4mxmTuaEoyT5ZgByt3nk5nWIPH5SHy8gmW9gyVEn8g1xgV2aGG09NvubTW7L/yK4jbt/aHU0C3vVYN1HqvVfqatCvat4xDvFRKTX7u+Gb0qhvSYZc+K/VuGNcZdbKaKCP28N0mbFHomsmJpYRFjV+Wjit/GfXKDEff4l3rcq+IF0UfTiweX+2fQ/dVY2fq2CUfgh8vN7NNG5D/m76We0c/DYOpNYukOm8wjEbYjNRxGWgPvWrkJzQn5XwsAedITRj+F/2w3RPpaIp0CdzH46zNfToplNuq+prBAk29WjyMDs7p9MOp8CSK4gY04hg2dbRR1HroenZUiTxg39bRoIHXGo3kXEprFGK2/LQWHbqHL1BHxwa2ytVslaBEq1N/t5fJC6eel3zNMhuFjfFkQVIqGuubxFlBjscqsYgeTEg3sZ8xsA51TaQj1bAWJISz4cz0geHYiGtrk1AWOYSMaUpLTZP1tzd8TwbMy4vSRDKhO0tS8Q=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU2PR02MB10160.eurprd02.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: lXNmEPcHwXzv5KP/lC0v2ihhkuUgWO6IAPkx3GhuoYCcuc2CRFgtNd7WcwGqN+JLJlrclP+FjJXSgkXNerL/Oa8sZ2Fz8EyUBxAQnHbXAR8fPsgpDz8meUK5UGLDqjXDRoxp+cobHDsprAdI9k6PiCoBLclidSVN7wP+86J57bOV2EV6n87sDhxkbnNERybb6gUWSqWfUobBG4y80ctWh1sy91LGVDYJDBWvtIl8MBea93CHgpmiXOZLAnXaVqLPugZSqYexYxZjtPWBOxVPyhf5zmEgKIpbGn4NhXyOYZZVNLfY4h1XK91LGOuPTzCjycfr6SZ90T0BIg/vlv3O7v7KvEyeCLCRFQbDAv+9yCYtU19vQ9dUUqRIHlu4GmGyYMtgxEloYfZ+huGVeqJVPjDNGmoSL3/fglY4/dqpcvHrpgAevufmdUoH6Y07Y8V4Qox4usGUa7LLfRd+vXqczBMXbrsiHzBAzZNhsLwKTLc4PDX466eOvou4c/8y3dw8KJ6Qg8fWTSCgY+7j8ninjkgT3on0L13EsnXLrC/8SWtv4ZjUDp5Uo89LCP2G6i6CkKn7ylB2IwZ/v1XVkqzdL6TmFIbiVgPt9FZJQco09c8TAr7A9KOg9d/ZSP+SSrWc5McqL5lIymjsL6wgf7sPY0ueKBb9dAyzONsmowcZDkYHx2pRRlKPV25hTeizpWw51p0eHsAUGbdw241ubb3v96meEMs/ONE2rKJ4gJkxae2O+84IYfNZCC3ZlGn8BWiwgulEoVm42jeQ7fS6KwE/qkHk+Uyxfz63Qa68RLhtLD3xBqeekJt0t1KPKFiCrlgwoJia4NAn2IJAh96DCZPe68SuZ+FXR0cmH+m8YDje+caVAlyHPXbHBUofRUIvduxVCaWK4pGHRcAdi8UOfWWDOZndnWzFDMBOb4J57VPM/Xy5QAj0WIZI3fP3GNNurkCem5QAuoUvrJi7KlNvjziyv9gR/NJJdlmmtwxv3+XMFIaOseCTIv8Z7DWrHIXOLHLC44hNKiDgYjk9cbxRF1S2eeKeZamMw9e3BJT9g64fmOIWNK0T5jIjUH9DXv/xT9VEayQT88u9olhDOVaGmtyvYciRbhubVNn1hcafQH6Jqnvg9TFzRmK7Rr53qT3mVvk/SUVGOjvXGlXKnhO3rGKEpEa86D2CNkTpjf6IqMy0bqM2/W+OfC5zMwj0kPr8+IwrEy88M7A3NsL8O7FbR1hLDuhG/PgLjjLwnqy589D1fwVRuRgO0EftBXsszIT1TG5TH1sXsxSDBDUceWQMugFcd6xEee58CzhuaGTrXfPFjR2oqYRozKFds4tmpgbXTpb2IVJoGT+Pr9TKoiCAKsjanExXKMopYuSoMjQgewTU7j58+hK8Qc5rbnLl/z+q4zZnHHmjXkPhmq81cIyYeIdJzgPBEDf/+e9udurpPh6qnaA3Rt1mS4PW+RawnQnYg0f3xQgMf8kN0iq4T6Sds/+NfOG45df4hlidcy5FYNcaq7UPlUQFgsU0NzuOaufNBZZppUpUqlpqY7Hk4d9L9DWZtCdhgG4B+BLpOxmmuaqqOHyYCFyRjK2cjbqwsFv9OmYw
Content-Type: multipart/alternative; boundary="_000_DU2PR02MB101601D568F5AA4CD8272FA5C88622DU2PR02MB10160eu_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 5d994b81-3555-43b1-4be2-08dcd7f27556
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Sep 2024 14:59:12.9846 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 8waR6f6apLe8PpztQBRXcA0MuAdnSLEemppYwbK1GfmpZAJCBwCb6YojUPbXLX8JeWig3d599YfDkijt6uhGBy6gCFir1xtFoq0ZVb0aIDc=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA4PR02MB6749
X-TM-AS-ERS: 10.218.35.127-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-28672.000
X-TMASE-Result: 10--26.674700-10.000000
X-TMASE-MatchedRID: sUHBEr3cTN/uYusHgJkgyqYERiJGNri88cT/p2AepNMkO/iPMp5UmZ// qyYXn5BgU3ljwEApOTDtzSKzUmDUV4h/ebSxR/HnIWnK2PB3w5WueqlDxh8TobxPAHVpSmorGT0 u8vw7+IAmcIj/rrT+da0EmYyuPyLJ9Ib/6w+1lWT4qCLIu0mtIN9Pf20Td37SaRnuwdqIKHsJmU jf8zXUe3srvhE+pg/iq6H6eyKIRsPhhAk2yII2+aUfpvLQYumSo8UNgJQ6rsdjFrzDFNuGezgF7 aRRXwT+Je36Z4bPXwho0mANueCMqSyEakGwrofurHCvytg5b46+y4Y487IcAUmb/vjP+wrhYwOU YWoGEGcyNJAGB7SC9K1X5QS2bmlZ36lQXQeyPFFNLPQl0QAltOtAZR7HU8v1Iubj9bOa7MuqH12 uH+NHwquLSq9X0pIEOadcYp4kZW/O6wQgUuSnLReK/B+WKxKs3ymqV5Ai0QVhocya4R+dQf6d3f iDekevuFcRhUATSXiBgK4uB6zi20H0jmDpcSmLSOZtBHQ3LLzB8Ugf1J6jaCoqjQZKdmo9ZNApq whso4GJSLTDFCW9/IXAsaqEBr1V+Basxm9uZ4cEx2nnXvzNI7AHBS2nS6QWFvJu8YoHTSBXvL9f W8P6jB4M47yfXNlXY7LZnVCm9AGJJ72DuZB0nDoSfZud5+Ggnh9Nb18N1uBlWGAuNI6SxsNoTaj pI9Vw9NBnRu48ed2juFQRvlawkum3e48zTc8R+VJ6lZyB0s8Q9UOsHuS6PIxSvzXEuxuJ0GPlcZ 3veCVUZ9ABKSaJUObBKxXcSPJZzfqlpbtmcWhKHhaQPPG6/o5hyiW8kJaQBNVCIloTK1P9dU4/w VV+on41niV9KymzQ2B/dw3ziQ5RGaeOJTnMW2mRqNBHmBveuME6WhSqqOE8iiEXp38wSLXwHj/A msmG4kYXbobxJbLyU/oX+tpNmCG2Ull2Wedt
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: 66883446-8f57-459c-ae4a-a9f87f4131dd-0-0-200-0
Message-ID-Hash: N6QL443ZBC2DXJ2ZCNF3GGCNI4GZJKJ3
X-Message-ID-Hash: N6QL443ZBC2DXJ2ZCNF3GGCNI4GZJKJ3
X-MailFrom: mohamed.boucadair@orange.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netmod.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "netmod@ietf.org" <netmod@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [netmod] Re: AD - Re: AUTH48: RFC-to-be 9644 <draft-ietf-netconf-ssh-client-server-40> for your review
List-Id: NETMOD WG list <netmod.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/i7gUVqwHK29JbGAew9PpmibjELU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Owner: <mailto:netmod-owner@ietf.org>
List-Post: <mailto:netmod@ietf.org>
List-Subscribe: <mailto:netmod-join@ietf.org>
List-Unsubscribe: <mailto:netmod-leave@ietf.org>

Hi Kent,

Thanks for the follow-up.

I went with many of your proposals. For "have to use/have mandatory/MUST use", I went for "have to use" for now. The use of normative language may be questionable as this is more about use, less of an interop matter.

A full diff to track changes can be seen here: https://author-tools.ietf.org/api/iddiff?url_1=https://netmod-wg.github.io/rfc8407bis/draft-ietf-netmod-rfc8407bis.txt&url_2=https://netmod-wg.github.io/rfc8407bis/sec-comment-from-Kent/draft-ietf-netmod-rfc8407bis.txt.

Let me know if there are other occurrences that I missed where we need to follow "modeled after" approach. Thank you.

Cheers,
Med

De : Kent Watsen <kent+ietf@watsen.net>
Envoyé : jeudi 12 septembre 2024 18:02
À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>
Cc : Mahesh Jethanandani <mjethanandani@gmail.com>; netmod@ietf.org
Objet : Re: [netmod] AD - Re: AUTH48: RFC-to-be 9644 <draft-ietf-netconf-ssh-client-server-40> for your review


Hi Med,

Sorry this is taking so long, but we're getting there!  ;)


The reference of QUIC is to the protocol, RFC 9000, not NETCONF over QUIC, an I-D as you note; just as the reference is to SSH protocol, RFC 4252, not NETCONF over SSH, RFC 6242.
[Med] I understand the intent is to cite the transport themselves, but the text refers to MTI of these "YANG-based management protocols". I don't think we can make any claim about QUIC here as we don't have an authoritative spec for that. If we want to cite QUIC, some further tweaking to the text is needed, IMO.

RESTCONF already supports QUIC.
[Med] Yes, RESTCONF does not  require a specific version of HTTP but still TLS is what is indicated as MTI for RC per rfc8040#section-2.1.

I was thinking about this nuance too.  QUIC uses TLS, so I think rfc8040#section-2.1 is still satisfied.  That said, the NETCONF WG will be working on a RESTCONF-next version, for which it would be easy to add some clarifying text - agreed?   I just added this (https://github.com/netconf-wg/restconf-next/issues/19) - good for now?

No transport-binding document will be written to enable QUIC for RC.
[Med] Isn't rfc9114 that is applicable for RC, rather than 9000?

RFC 9112: HTTP/1.1 (i.e., TCP-or-TLS over TCP)
RFC 9113: HTTP/2 (i.e., TLS over TCP)
RFC 9114: HTTP/3 (i.e., QUIC, i.e., TLS over UDP)

If we ref 9114, then we'd have to ref the others also, which isn't what we want.  This is why 9000 is refed - makes sense?



[mj] Why do you say that? The statement says the protocols have mandatory-to-implement ...
[Med] Having an MTI does not mean that MTI is actually used/enabled.

Touché  :)

One could process "implement" to be at the runtime-level or code-level.  I meant the former, and see that you're interpreting the later, which is fair.

First, I wonder if there isn't a formal definition for MTI that disambiguates the two cases.  Looking, I see MTI used in the context of algorithms, which lends itself to the "code level" interpretation.  Fine.

[Med] Thanks

Then either s/implement/use/  or  s/-to-implement// ?
[Med] « have to use » would be better, IMO.

Hmmm, so this?

These protocols have to use a secure transport layer (e.g., SSH [RFC4252], TLS [RFC8446], QUIC [RFC9000]) and have to use mutual authentication.

vs

These protocols have mandatory to use secure transport layers (e.g., SSH [RFC4252], TLS [RFC8446], QUIC [RFC9000]) and mandatory to use mutual authentication.

Vs

These protocols have mandatory secure transport layers (e.g., SSH [RFC4252], TLS [RFC8446], QUIC [RFC9000]) and mandatory mutual authentication.


Of the three, I like the last one most, but like the first one (yours) next.   I like the last one since the statement seems stronger.  One idea might be this:


These protocols MUST use a secure transport layer (e.g., SSH [RFC4252], TLS [RFC8446], QUIC [RFC9000]) and MUST use mutual authentication.


But I don't think RFC2119 language should be in the Security Considerations section.

Thoughts?



This section is modeled after the template described in Section 3.7 of [RFCAAAA].

This first line wasn't picked up.  Note that the word "modeled" gives an authors a little flexibility, as is needed sometimes.

To point, the RFC Editor takes the words literally and raise issues when things aren't exactly same...until this word was changed.

Honestly, the same should be done to all of the templates defined in the document.

[Med] This is fair. Please see: https://github.com/netmod-wg/rfc8407bis/commit/972970ce16c050d8420f50f07637f4e00770cdd5

Thanks, both for accommodating and the link.

Looking at the PR, it is only for this template.  Do you not agree that "modeled after" is good for all of the templates?




The "<module-name>" YANG module defines a data model that is designed to be accessed via YANG-

IIRC, you use different words than "data model".   I'm trying to use sufficiently ambiguous language that includes also modules that only define identities, or only enumerations, or only typedefs, etc.

I was going to write "data model, or parts of data models," but it seemed unnecessarily wordy and obscures the main point of the sentence.

I don't deny that my text could be improved, but your take didn't seem right either.

Can you reply to this?

So we have:

The "<module-name>" YANG module defines a data model that is designed to be accessed via YANG-based management protocols,

vs.

The "<module-name>" YANG module defines a schema for data that is designed to be accessed via YANG-based management protocols,




FWIW, I only know about your changes to my text because I received GitHub notifications.  Was a link for the PR sent?  In any case, it would've been nice if you'd stated that changes had been made, rather than me having to discover them on my own.

[Med] I didn't share the PR because that wasn't ready yet and I was waiting for the discussion to converge to have something I'm more happy with it. Now that you are on it, feel free to propose your edits directly there :-) Thanks.

I'm unsure what you mean, but I don't want to submit PRs and, honestly, I don't want to look at PRs.  I want the full conversation to be on the list.


Kent // contributor


____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.