Re: [netmod] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01

tom petch <ietfc@btconnect.com> Mon, 17 October 2022 11:46 UTC

Return-Path: <ietfc@btconnect.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 432F9C152569 for <netmod@ietfa.amsl.com>; Mon, 17 Oct 2022 04:46:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.908
X-Spam-Level:
X-Spam-Status: No, score=-1.908 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d7aKpFNlLVZN for <netmod@ietfa.amsl.com>; Mon, 17 Oct 2022 04:46:19 -0700 (PDT)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2114.outbound.protection.outlook.com [40.107.20.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 41FD7C1522B8 for <netmod@ietf.org>; Mon, 17 Oct 2022 04:45:24 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=SrOazZFBx9swoD8dQPAPWRBxDGObBuXrmrDGBJ6QZE6bnoCRcTCEkuaau7g4OsrUkuVcbEIsO0kutQwNlAcHdr7HluBpGJgKuieURUgCHghstUbnEzIfHwrZKHAQJFCUozQameH/f+kAVkilO17epUqTGsxjCquMEL0DW+X30abmLZ2vMX2Juvc3hXBjW8l+c4PC57SGseD0GO6zW4v3ytjdwGxugAJcZSOfMBdwR8IxLM12cf6VBJlBQg+KTI/v8PiWyCdklCERD7Ez4iLFjJfkE2BjsrW0PzZWTF5IG5k4sAZ2Twb/YY8ah3/ZiRm3UKhOJ9Vu0VroDKVdJIoJ1Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Cd6WPrI+QHuznG7+sqFQS5q5120AYn5P/8TJK7sr9Pw=; b=LPTZOxcYBPQzfG1n4rANF4Dns+qCEqnTvIoFxawpPSLt8YaNLZrdZKn6Z19VASW1WUGMI/CrvWa27gO0qWylqjF0h1hdX1tjXTb7BV8TSLwHR9U54QnVrYH2p+dspd/vNiQ8M6nrXYZDuyvKZJrNTxP6kofqGvPFNCYzurks0iSKnrj/lFdEMPBNZWjXgmx7FIP7XEG8dXw1AbuHPVIQXewHFqUM9ERsCclIiGdwjzK9MXlOQBB5swip+BHNJBdkBrRBUMerojQ/L3xiNCu7S0jVT0OwHsQgECDDOjOniUcf9xtsHHhyYpYS6jIaLi+XkVeZug55tJRlWOfNCGrueA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=btconnect.com; dmarc=pass action=none header.from=btconnect.com; dkim=pass header.d=btconnect.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector2-btconnect-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Cd6WPrI+QHuznG7+sqFQS5q5120AYn5P/8TJK7sr9Pw=; b=ZOr+Xm5LXEGq6nhbJ/nZeYcPKTxltowW3CDdF6rEMA05A0OEfGwQwlLEug+cvp7bdPOdXfvu1CbA27Zpc1VrlCv5UDBF0Z0xn2UhrOgdubJs42ydMPv7G16EMpXwB4IUmPrYEjoZk7ca3vNRxqNtdYeUEJ4kotWnyRm0yqUm03I=
Received: from AM7PR07MB6248.eurprd07.prod.outlook.com (2603:10a6:20b:134::11) by AM9PR07MB7123.eurprd07.prod.outlook.com (2603:10a6:20b:2c9::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5723.20; Mon, 17 Oct 2022 11:45:20 +0000
Received: from AM7PR07MB6248.eurprd07.prod.outlook.com ([fe80::f3b4:258e:4f7:66fd]) by AM7PR07MB6248.eurprd07.prod.outlook.com ([fe80::f3b4:258e:4f7:66fd%7]) with mapi id 15.20.5723.032; Mon, 17 Oct 2022 11:45:20 +0000
From: tom petch <ietfc@btconnect.com>
To: Oscar González de Dios <oscar.gonzalezdedios@telefonica.com>, "netmod@ietf.org" <netmod@ietf.org>
Thread-Topic: Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01
Thread-Index: AdjddL2vkpV3/9V9SPqnq0V5uDK7SwEqPI80
Date: Mon, 17 Oct 2022 11:45:20 +0000
Message-ID: <AM7PR07MB6248A39DDE89A1D50A222E23A0299@AM7PR07MB6248.eurprd07.prod.outlook.com>
References: <PAXPR06MB787207A71BF252D21F5FB7C2FD239@PAXPR06MB7872.eurprd06.prod.outlook.com>
In-Reply-To: <PAXPR06MB787207A71BF252D21F5FB7C2FD239@PAXPR06MB7872.eurprd06.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=btconnect.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: AM7PR07MB6248:EE_|AM9PR07MB7123:EE_
x-ms-office365-filtering-correlation-id: f95f78f4-3eb7-472b-2ae2-08dab0351192
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 96NnKETCci2eKpr+JUR6u0pVgWGTfqCAedbRMA2MFrdjIFUIkYOLrdTeR6IcQjlGMd4CQIbRjiTv6GkHSv7D6ofUaiGU2f3lAyAekpcS8wvwt9xRg71jnvc4UwAqPZR5LuPpzHQhMf7ET4CInNVH1lEmt8sICcPjvE/yWkDHh6HuJbXQt9geVVgg2yG2E5r89geItb6bj7G+PvyH0a6HDDp7I+/IBl+hpUlM4oPTlLmztHdqh6kU3lrLazuG0knKQPxIxmywuBD545DjRsn2HHPbj3eZaf4b0OShyrGS9Ao5eHGo0iQ91qDe8FZqrohbvfHYwcOwfzCpLBW87Pp6tmCWLUlJVaOpMtQH+PAIbDc8gQ01XAmFVx7eNwhXYfbgbfqivU9cJ2qJCV1RUtXJYPBKv+BQVPo2MHZxaEx3L/QUPb3IOCM2ssmNk1isnJxXWWC40hDAUwG1zYtF2xB6stnzWOQ7i4lIJ+0u5wfB1nUSaJJ2cJmADR0uBIBkZNPjiZuVZ6IX98pBKw35YZAY3zNkVA0race2KF4vv2BhcFR//tIY/LbjkiKTkA+WXM/xCNU2Og5gcUtAiG+VoXPtCJEgrpdtv48OO8AzGJB8+yuDLiZ9atlGxz3Nlok7A+FgwUAuav8HP/R7Uxv/DG2rabRJvSTqOqaZ1UVa6eOcnN50EyEsUBVuZfVeZRFven7sz5umYemWu9tKHIuHfPCj/Gfp0c/bmVGPnkVh1vuzCdECsbEpP4Qdu767G1qkf2pZIEHsyrzIDz5KwDWR1DZIwB4Iyr2kZ0ASzQ7eorR2pvsH/tocHcx3JRPQOWFru5PLmXm680sioUsvz82/I+Mj6mkjp5Llxnb/mUlB6UACbQWVXYjIl2XApob1IFiQvl1Z
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM7PR07MB6248.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(346002)(39860400002)(366004)(376002)(136003)(396003)(451199015)(8936002)(38070700005)(66574015)(9686003)(26005)(5660300002)(66946007)(64756008)(86362001)(83380400001)(71200400001)(66556008)(55016003)(76116006)(8676002)(66446008)(66476007)(82960400001)(2906002)(316002)(52536014)(7696005)(91956017)(6506007)(296002)(33656002)(38100700002)(478600001)(186003)(122000001)(110136005)(966005)(41300700001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 6vqxHhiq9TEm9aCuwKbbf+TzxchjD6pnDhbn57P3WTAvKfLwEcjPBhxv4lu3AMe+WEaTgF29KDYTBarE0d2TEIYRYJa1XLyTxh2P1CYUMk2PAbU7zbSGmYwtW33C3Jwn323H67p3KWKtZj2hFczLVw1jkf4OBX/TbKeILY4vyQUizogL9FzzsJWI5hbROPb1aLmt1+oRJhvBctDbuUB7TyHMRGTFlbD7G2cK695IooFxHBVcFft5guOoHJZoJcE7Rj+dOIi9nSWbVS2eh8xF15Ee+Fhfmv1EySV+HBloPnAtXTvJnOqg03PUtar1lf/ccDAsD2kP9VkXIR3SeA3xjYfauqgoeRiaxjhjUxlTkt0lJca/EeQ7KVmRp3nqTz6wwZQG8Z6t4uUi7i/x5t5t79A1UMbuPqRN5C/Yyo7d4sjcUsmVq4hGfmk3ZFVyzqqmAmYWimCk1SmUeKqNsOtuh8KaFer+ZHQpQU7HE3QRzSMncAX04/9ROQlI0e9ONosH2DrWRZB2HlMZjHCoK/9un7YCl54gFKKNlLvJ/xfXL7VktYMTQS+E7o7bvjtaHjv6pYSEJAmoA1WFenUjzl8S/KYTqu8RiS7ByDlTFhcpQHBouy3U/R9PPP0vXR2eyZaSSP/ISGZWWaUjioDJTWqhXnIJgANnltgCkoCLyVKsGbvQnyPh5JwOPQO0QpvKPLpVpKI5iaNCd2q0j1UpHNHlp0ZdJKxL7bpH8yNvKkHqtvbfRezGvnmDNfEOazC1kEe+GFdeCs8eHfe7Gh+gsT0nLuHopG2tOH6RyU66h7QYyWDt0gpl02sGcwMVTHT7M4v8a66tVusBkpGCAN+anTtbah3D3ABH67NzlarxFcRA36cOE/MsfnSm374g+k9bmeWce7N8dcsmJuaMXkeT5Qu77u6U4HvTNaby2IsUlOTjs64DEniLEGZK0RRch8hkm1fMZSgGHCuBFSnn2Vn5mALjIUDYHHQDRpfpX4uMjJoa0FGOPyKBzXSqRkwG10HhI3IFAWPHMf4vLJ8nYX3h9QtlPHGBXQHlD7fQXK9bFnznb7QK1Jk75PrAZbC/A3X7mThEMCRsXfGvP/PPdF8Ldg22SXmPdWPut18AhboNnxk/yhhuz3f1gnJJ6PiG9CpUe9b+EPhTU06vB2w3irU33pbqIGWlaZrpbW8ckh+Px83Ne5IaKuAdu/LghrW1F6l/kRceIO3H73hijCQghjEAcTIhgfBOzpd9bFmQL60Ml2kUJ8RqnXNrEFKbsUyIX3BoVXBefq/XDoKwctIRL4IJdNrASfUhUQ77Gw+xnDCtCoM6CR1pNnsxaFv6ULotbSWl2Shj9FJo5slr3RzrAm+jiFIswEA2dCKg5xf1dcmIHQ3IJF8MtOPazxabipx3KdnrChKUBsUDhxu2s21MYe87nswB4F2qEmrlWjy2HMukaxJgZIZIdL+0O8+28YF9dMGqW21SWhBNIsnXJG1k+/xoVXy0FjvaLGvbIcAKDkuCRnTZHqwXAHdFa3bY5W9enzQZzhIJVKpc/wuIgZMmslkY6ZenMbiQiZJIGCvFcW2il2VFvznKBdeuYq54ZTWGweci2yf8
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AM7PR07MB6248.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f95f78f4-3eb7-472b-2ae2-08dab0351192
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Oct 2022 11:45:20.0425 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf8853ed-96e5-465b-9185-806bfe185e30
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: i2s9f8QqjWMUV6Jc7UY2XD36NEvYX60MhggYN+k3SGrzj/r56Rm6i4vPNRX4U2Sj8Qfov2NhwyuQpLoXBQHedw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9PR07MB7123
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/nbUKzCmHXSgSnUTS7evV8D7qQiQ>
Subject: Re: [netmod] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Oct 2022 11:46:24 -0000

Top posting at a slight tangent, there is an OPSAWG I-D, mud-tls, which augments RFC8519 with TLS related groupings.

Tom Petch

________________________________________
From: netmod <netmod-bounces@ietf.org> on behalf of Oscar González de Dios <oscar.gonzalezdedios@telefonica.com>
Sent: 11 October 2022 14:36

Dear Netmod colleagues,

        While back ago we discussed in the list a few set of potential enhancements to the Access Control Lists Yang Model based on operational experiences. There was good feedback on the need of those extensions which were documented  in the enhanced acl -00 draft. Then, the next step to solve was "the how". The feedback in IETF 112 was to prepare a new version with the Yang code proposals, so the working group could decide whether the augmentation approach was sufficient, or a -bis version is a better choice.

        Together with Med and Samier we prepared a second version of the enhanced ACL draft in which we include a proposal with Yang code to implement the enhancements based on augmentations. You can find the -01 version in https://datatracker.ietf.org/doc/html/draft-dbb-netmod-acl

        We would like to receive feedback from the working group members on the draft and guidance on the approach (augmentation vs -bis version of the ACL yang model).

        Best Regards

                Oscar

------------------------------------------------

A new version of I-D, draft-dbb-netmod-acl-01.txt has been successfully submitted by Mohamed Boucadair and posted to the IETF repository.

Name:           draft-dbb-netmod-acl
Revision:       01
Title:          Extensions to the Access Control Lists (ACLs) YANG Model
Document date:  2022-06-29
Group:          Individual Submission
Pages:          26
URL:            https://www.ietf.org/archive/id/draft-dbb-netmod-acl-01.txt
Status:         https://datatracker.ietf.org/doc/draft-dbb-netmod-acl/
Htmlized:       https://datatracker.ietf.org/doc/html/draft-dbb-netmod-acl
Diff:           https://www.ietf.org/rfcdiff?url2=draft-dbb-netmod-acl-01

Abstract:
   RFC 8519 defines a YANG data model for Access Control Lists (ACLs).
   This document discusses a set of extensions that fix many of the
   limitations of the ACL model as initially defined in RFC 8519.

Discussion Venues

   This note is to be removed before publishing as an RFC.

   Discussion of this document takes place on the Network Modeling
   Working Group mailing list (netmod@ietf.org), which is archived at
   https://mailarchive.ietf.org/arch/browse/netmod/.

   Source for this draft and an issue tracker can be found at
   https://github.com/oscargdd/draft-dbb-netmod-enhanced-acl.




The IETF Secretariat