[netmod] [Incoming] AD review of draft-ietf-netmod-factory-default-12

"Rob Wilton (rwilton)" <rwilton@cisco.com> Mon, 24 February 2020 16:04 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B5E693A0DAE; Mon, 24 Feb 2020 08:04:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.337
X-Spam-Level:
X-Spam-Status: No, score=-9.337 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTML_OBFUSCATE_05_10=0.26, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=QewAY2pQ; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=JAqBEHU4
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7jtdePPWP_DA; Mon, 24 Feb 2020 08:04:53 -0800 (PST)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 17EED3A0E56; Mon, 24 Feb 2020 08:04:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=17610; q=dns/txt; s=iport; t=1582560291; x=1583769891; h=from:to:cc:subject:date:message-id:mime-version; bh=D4urqxCCtk5BuOpZ7/A9lJqYQIp273e7891Z50VlH/I=; b=QewAY2pQ/ggbY79kWW6dy0jwA9iZhmYEUHtvsuSUDRyuWf78qwreDVPe TFPmP+EORH3HRhkc2wi7nx09frRJtF+6hNy9WNzFjpGlOxaGKn98VH+DI gOXpVx1iPNiPb5TQ/Yor/9sdHg34OYieGj8nHHy+MkqTdiUNvbeLwWGWX w=;
IronPort-PHdr: 9a23:1i5NoB83yf1vPv9uRHGN82YQeigqvan1NQcJ650hzqhDabmn44+8ZB7E/fs4iljPUM2b8P9Ch+fM+4HYEW0bqdfk0jgZdYBUERoMiMEYhQslVdSaCEnnK/jCZC0hF8MEX1hgrDm2
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0DrPADr8lNe/4sNJK1mHQEBAQkBEQUFAYF7gSUvUAVsWCAECyoKh1ADinEzmkCBQoEQA1QJAQEBDAEBHw4CBAEBhEACTAEEgTwkOBMCAw0BAQUBAQECAQUEbYU3DIIpgz0WGxMBATcBEQEaZhcPAQQBDQ0agwWBfU0DLgEOoikCgTmIYoIngn8BAQWFABiCDAMGgTiLfiYagUE/gRFHgU6EIAEBA4FJAQIYK4MWgiyWVZlFCoI8h1GPMIJJjGmLfI5wgU2HL5JLAgQCBAUCDgEBBYFpIiqBBQsecBUaIYJsUBgNjh2Dc4UUhUF0gSmLRgEnBIEHAYEPAQE
X-IronPort-AV: E=Sophos;i="5.70,480,1574121600"; d="scan'208,217";a="722497647"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 24 Feb 2020 16:04:50 +0000
Received: from XCH-ALN-002.cisco.com (xch-aln-002.cisco.com [173.36.7.12]) by alln-core-6.cisco.com (8.15.2/8.15.2) with ESMTPS id 01OG4mpM024887 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 24 Feb 2020 16:04:49 GMT
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by XCH-ALN-002.cisco.com (173.36.7.12) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 24 Feb 2020 10:04:48 -0600
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 24 Feb 2020 11:04:45 -0500
Received: from NAM12-MW2-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Mon, 24 Feb 2020 10:04:45 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BqCPU3l56pQc5bIB9lPzmqKFRKu1dlV0lZpBMLcpbOT++TmZyuBmiz2iTkGr4zFL6uoIDgourbnrFC7bROMM28YQWo+hIg3khtkLG8gohxUma8KReY9TkbmpwiB0FYohNNMMMciiq+rUnqQ9SLqesDyqVF1LUkVy/YeshK0Lru5hI2ftG+OqxFkTgENprAMDsinuh5lrhZpRXKbdGgWpN8KG1p1UXiwPkisPdkv0Ra9om6rnPYQmDR7fe6/qDJ680l2kdT/aScwhrgzB5gbOMeeYuakcRgcMWuN8FBpnErM5Yhd3xKDz5Rl774hJywJWeZ+pKqwrxBlF5p3yssV/jg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XeHt0zdeI6H6/wDSlwDFqZJ9VKMwupNuywGrt4ZCbH4=; b=bulOkFju3uz2ZHncdtO2rZ0c01u1htMwe/Darb+R0qtAR4ouGNJ8M6lbYrCZR4gbafsxNUkX0swgR97QV8oJopVHiXDtDaQ21HVTjoFicVmsCQq/K6Q8hxwD+VQZwKgo/e0xMypSho1vlrzG4NWh1cFBdT9EjbHpEKOHeQy6bxzkHap8X+5PJnlJTmyIa7/8rHHCUF1tdYVcPFpcF6Hb3czTO4+n/gy8rx/cCAFvCjI3RAY1mbf/+1ynCN1WHnnKPbipg2X69yhfezDdSYgmXKUzKEm28KSIM4+PSbH/vPRdGRuELuJuKUgwAUiKcu2kMbHyFylS6keSkviGwKDJ5w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XeHt0zdeI6H6/wDSlwDFqZJ9VKMwupNuywGrt4ZCbH4=; b=JAqBEHU4Wk1qclUeCMxyACq2AbZebHVtsoxFkRpISTSbA/+L5WRTkbmqtwokQCSZqRYR0naOrDFK85+JH30ITOiWckiuT/GJq80K9FI3slTnfVGzwDAoGgfz4JinQ5k7MWkFNHWgPcL4/4s3qa096gx4zDb9Q74HmgdsMqtv7oo=
Received: from MN2PR11MB4366.namprd11.prod.outlook.com (2603:10b6:208:190::17) by MN2PR11MB4207.namprd11.prod.outlook.com (2603:10b6:208:18a::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2750.22; Mon, 24 Feb 2020 16:04:44 +0000
Received: from MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::b9ce:1058:5fa6:44a1]) by MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::b9ce:1058:5fa6:44a1%7]) with mapi id 15.20.2750.021; Mon, 24 Feb 2020 16:04:43 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: "draft-ietf-netmod-factory-default@ietf.org" <draft-ietf-netmod-factory-default@ietf.org>, "netmod@ietf.org" <netmod@ietf.org>
CC: Warren Kumari <warren@kumari.net>
Thread-Topic: [Incoming] AD review of draft-ietf-netmod-factory-default-12
Thread-Index: AdXrK91DLlBAy7r2SwW5K4lCI86Kqg==
Date: Mon, 24 Feb 2020 16:04:43 +0000
Message-ID: <MN2PR11MB43660B9F19E8794C5A8B7144B5EC0@MN2PR11MB4366.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=rwilton@cisco.com;
x-originating-ip: [173.38.220.62]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b92182bf-f577-4013-9af8-08d7b9434355
x-ms-traffictypediagnostic: MN2PR11MB4207:
x-microsoft-antispam-prvs: <MN2PR11MB4207CF53091008EB81060769B5EC0@MN2PR11MB4207.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-forefront-prvs: 032334F434
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(396003)(39860400002)(366004)(136003)(346002)(376002)(189003)(199004)(110136005)(316002)(6506007)(5660300002)(76116006)(66946007)(478600001)(52536014)(55016002)(9686003)(86362001)(2906002)(4326008)(81166006)(81156014)(8676002)(8936002)(71200400001)(33656002)(64756008)(66446008)(66476007)(66556008)(186003)(7696005)(26005)(9326002); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR11MB4207; H:MN2PR11MB4366.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: cqJS7uUFBdL4D9rVvl+vDelG3nZWHMZuRrg0GlBd0J94T3YYVhWwm+N3Tbj+HuFlB+stji0SNM7/W5hvJKfb84p5LxMiwJrvxGl8XJNchxH6YHxCZR/grR0HTOCvOHibTx0nHVIRm4XgiNP50/wxqIUAfL2j37hxmvi9naGdCy1P2ocMphdY7YuDPVxY935j4gWBOjOFI3oK3miUjrwrIBGR6zFxT7/0lUcRELI5tt3frqOgIuu7nbN8Z0CdtojXoW2Db1nHLOccRpubUMdS3bq730A6JEOpGOpnFGw9bCNYCCKyGiraOcjbwwWf7Zb/4KgKrrH+r1seuEhUXup0RneFgP9e8VeESUy5zOH0q+sJXwgQnAOA6yXtEn0nbMabtQe5W5EgvrQWkJEo4Ot65J6esydKDcVd3jHEbmpToIbPJbUewzHMzN0VRk2qfOxXaHiQiQBdEAQFC8a/EHCpSBdtbmCwqng1ay9iuQCVnepH9Y+vwahkE7jxr1oEyPwjRe5CUNq3hyuzHFH55HcZEA==
x-ms-exchange-antispam-messagedata: s+0vpHSnkr/JYqCpF80+tDu+mY9iQVYurcIeWx8bvTvXFpYRgBl9ioWh0IuQ+VwrxqD64AGOjkAugpuDiVJG1SqaEYFUagQ3L4BbnUBbK57fzO/d87j/AwMnC1xDhxvMiM8QBUJ2XRRYZwCAsC8ifA==
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_MN2PR11MB43660B9F19E8794C5A8B7144B5EC0MN2PR11MB4366namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: b92182bf-f577-4013-9af8-08d7b9434355
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Feb 2020 16:04:43.8016 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LD+B0yvw29K0KYbPxTIbO+Sm6n0hXwieID7CW6bonL9pxFM9jZMvYitqAlhhGRc7rMAfvjX1DHvUf3UpYwlylw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4207
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.12, xch-aln-002.cisco.com
X-Outbound-Node: alln-core-6.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/m84_5Q7sHdoVy1bvvPH5Zwlgip0>
Subject: [netmod] [Incoming] AD review of draft-ietf-netmod-factory-default-12
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Feb 2020 16:04:57 -0000

Hi,

Thanks for writing this document.  I found this document to be well written, clear and understandable.  However, there are a few issues which I think could be addressed before kicking off IETF LC.

I have the following comments:


  1.  Title: The title of the document may be clearer as: "A YANG Data Model for Factory Default Settings".


  1.  Abstract: I would suggest condensing the abstract, which is currently very similar to the introduction, perhaps to the following text:



 "This document defines a YANG data model to allow clients to

  reset a server back to its factory default condition.  It

  also defines a "factory-default" datastore to allow clients

  to read the factory default configuration for the device.



  The YANG data model in this document conforms to the Network

  Management Datastore Architecture (NMDA) defined in RFC 8342<https://tools.ietf.org/html/rfc8342>.
   "


  1.  Introduction: It might be useful to include instructions for the RFC editor at the beginning of the introduction to summarize what actions are required before publication.



  1.  Terminology (section 1.1).   For the definition of the factory-default datastore, I would add the sentence "This datastore is referred to as "<factory-default>."



  1.  Terminology (section 1.1).  I propose that you also important the term "datastore schema" from RFC 8342, for use with a proposed update to section 3.



  1.  Section 2, third bullet.  It might be better to replace "ephemeral datastores" with "dynamic configuration datastores", since that is the reference is RFC 8342.



  1.  Section 3, first paragraph.  I suggest removing the word minimal, i.e. "preconfigured minimal initial configuration" => "preconfigured initial configuration", since it isn't required that the factory default configuration is minimal, although it would normally be so.


  1.  Section 3. I think that the document must define what the schema is for the "factory-default".  Hence, rather than "YANG modules: all", perhaps "YANG modules: The factory default datastore schema MUST either be the same as the conventional configuration datastores, or a subset of the datastore schema for the conventional configuration datastores."


  1.  Section 3. Probably add the following sentence to the end of section 3: "If supported, the factory-default datastore MUST be included in the list of datastores in YANG library [RFC 8525]."  This would probably also add RFC 8525 as a normative reference.


  1.  YANG module, rpc factory-reset description.  I suggest changing the description to



"The server resets all datastores to their factory default content and any non-volatile storage back to factory condition, deleting all dynamically generated files, including those containing keys, certificates, logs, and other temporary files.



Depending on the factory default configuration, after being reset, the device may become unreachable on the network."


  1.  I think that the security section needs to explicitly mention that non volatile storage is expected to be wiped clean and reset back to the factory default state, but that there is no guarantee that the data is wiped to any particular data cleansing particular standard, and the owner of the device MUST NOT rely on any temporary data (e.g., including private keys) being unrecoverable after the factory-reset RPC has been invoked.


Nits:

Section 2:
"are all reset to" => "are reset to"
"datastores(e.g. " => "datastores (e.g., "

Section 3:
"with <operational> => "with the <operational>".

Section 7: ", Susan Hares to review this draft and provide important input to this document" => ", and Susan Hares for reviewing this document and providing important input".

Regards,
Rob