Re: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt

Schönwälder, Jürgen <J.Schoenwaelder@jacobs-university.de> Tue, 05 November 2019 07:47 UTC

Return-Path: <J.Schoenwaelder@jacobs-university.de>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BF58D120096 for <netmod@ietfa.amsl.com>; Mon, 4 Nov 2019 23:47:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=jacobsuniversity.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bS8MW4oezjlD for <netmod@ietfa.amsl.com>; Mon, 4 Nov 2019 23:47:15 -0800 (PST)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30054.outbound.protection.outlook.com [40.107.3.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22EAD12007C for <netmod@ietf.org>; Mon, 4 Nov 2019 23:47:15 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ONOGEAknXGBFRcVK0bkn8t4ynQEUqyLckCXEKGQvjyE2ilrVifpj4jN+dAlYyR6Dqv8L3xz4pq+3tY6kqLryns85TnphdT5NsatAbtEY1UkPM2v8FgEmluHzc+VGjFoJ8OS5jYy54DEuH3m1RNUuIAtphq3kjIBjZbtpcXn7yaNq9NmHo8WEES8JsvGOkVpWHFhW+kRmWR0XG6mbrNOgTlLwDQNdNBrmrcL73sJCL2hRP7b7vJqv1cWAGlU4jKTWBn5Q8/ICFfV2Nzw+oCvb4OZ7/6sIT2TrdnKqAajgwAmTAyXAVONK9A9V/gfT0WGWFCitEnEujI5Lm/gTW3MQlw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pOcI5MV3AACUZOGpImbnNtpaESTQVyP1WRlq9JjM2sA=; b=g83WkXGLv39SvWo5tK90Uz8OCVH2Q6mTnmCSsqANMUmr2iO6gtUBZzR2YnUB5VfQrqJud+y58ZbEs5ifpHDR/ofZH90xfZVFPVuQ2whmVq5E27bZYk6U7bhgL7Vz1G6U+ZloXrCY7M+w/MrYbAjcRPGgMpxy9MRnlAJIn8mCMwqE9zaouZsBSdzTiohfoM6Sp6Dx0wGYTiSxH+D3Ml0UwHTG501pbkd/lPj2Ol3BK5bPu8m4LAhZNyLUBkXtXb3Ry9sDnDdjFiYW1ldnh4x/6Vp+LfrIvtzOvSYkS/pYL2lbtfeY59nN5VP87P4teOt+AzbTfGhEMyCH45Qq8wlP/w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jacobs-university.de; dmarc=pass action=none header.from=jacobs-university.de; dkim=pass header.d=jacobs-university.de; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jacobsuniversity.onmicrosoft.com; s=selector2-jacobsuniversity-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=pOcI5MV3AACUZOGpImbnNtpaESTQVyP1WRlq9JjM2sA=; b=b/j3xwCzZnnioenPThDwK4KMSjVLUjRy7FhBnEqqjG5SjYBzcJGJfktBP/DKOBpsgUKUKLHshnKZ7ZddBq7mbLFAAFdhT5zzaWKwtvEGtPraAvLFFuJ1LLk34u11VYaCM0RY+vHlduMzSNl6iGYJ4NhEEir5Zes/krXjnZ8h29E=
Received: from AM5P190MB0482.EURP190.PROD.OUTLOOK.COM (10.161.65.11) by AM5P190MB0449.EURP190.PROD.OUTLOOK.COM (10.161.64.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2408.24; Tue, 5 Nov 2019 07:47:12 +0000
Received: from AM5P190MB0482.EURP190.PROD.OUTLOOK.COM ([fe80::6c6c:2cd2:11dd:2aff]) by AM5P190MB0482.EURP190.PROD.OUTLOOK.COM ([fe80::6c6c:2cd2:11dd:2aff%5]) with mapi id 15.20.2408.024; Tue, 5 Nov 2019 07:47:12 +0000
From: "Schönwälder, Jürgen" <J.Schoenwaelder@jacobs-university.de>
To: john heasley <heas@shrubbery.net>
CC: "netmod@ietf.org" <netmod@ietf.org>
Thread-Topic: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt
Thread-Index: AQHVk6yPLHpFwh9MdkSEnVZYIG8pDKd8Mx2A
Date: Tue, 05 Nov 2019 07:47:12 +0000
Message-ID: <20191105074711.qo4aauxxbqtnfu6h@anna.jacobs.jacobs-university.de>
References: <157223376272.17168.5194653341767680835@ietfa.amsl.com> <20191105074206.GA11275@shrubbery.net>
In-Reply-To: <20191105074206.GA11275@shrubbery.net>
Reply-To: "Schönwälder, Jürgen" <J.Schoenwaelder@jacobs-university.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-clientproxiedby: AM3PR03CA0053.eurprd03.prod.outlook.com (2603:10a6:207:5::11) To AM5P190MB0482.EURP190.PROD.OUTLOOK.COM (2603:10a6:206:1d::11)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=J.Schoenwaelder@jacobs-university.de;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [2001:638:709:5::7]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 51efaab7-bfa3-4c27-4ab3-08d761c45e55
x-ms-traffictypediagnostic: AM5P190MB0449:
x-ms-exchange-purlcount: 1
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <AM5P190MB04491D603E1D174D052E1E68DE7E0@AM5P190MB0449.EURP190.PROD.OUTLOOK.COM>
x-ms-oob-tlc-oobclassifiers: OLM:6430;
x-forefront-prvs: 0212BDE3BE
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(136003)(396003)(376002)(366004)(346002)(39850400004)(199004)(189003)(4326008)(102836004)(81156014)(45776006)(486006)(3450700001)(81166006)(14444005)(64756008)(6306002)(66446008)(5660300002)(6506007)(71200400001)(386003)(71190400001)(66946007)(8676002)(6512007)(478600001)(6436002)(229853002)(11346002)(446003)(14454004)(316002)(25786009)(6116002)(186003)(476003)(66476007)(305945005)(43066004)(7736002)(2906002)(66556008)(256004)(46003)(786003)(6246003)(8936002)(99286004)(86362001)(76176011)(1076003)(52116002)(6486002)(6916009); DIR:OUT; SFP:1101; SCL:1; SRVR:AM5P190MB0449; H:AM5P190MB0482.EURP190.PROD.OUTLOOK.COM; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: jacobs-university.de does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: s6sDBC7EycIW1aSjhz76UtwiSlUQdVPbqoB7dmah7jSTMG2P676ge27A823AudaBAyXWqXoL++FL1nUE4pjyFGcpiNZETqxMJ5M/q9Cn7fcmK47AIfg7OYLArYIzWC7lINli/z5awlCDZ4Mo4HfY+bf+31UXUZpS9HVlPzbL4yj991L4fgqv6XnjW0kHQ4uPKiKP22tHsvkCIrR3wl+GJIytHhkAyFS7nylxiPuEypAkvUyFBsilzMIH8jNjcV/lr2LZuJI1uJ1fjBA213y4633eenTlq9kBpA1k7b94aDzSSqvq8xFYDzT3GXp2l23nWop0Xy1sZNlTO0tx6s5Kilu4z563257Kevfcu0J2i8lS4d62Hi5JKyqNQzbwp345Bzc0GMvTi+pDv8h3N78afD4fTMWIcltr8WBfpXVhWsoHNn93jA0syiTztOKppKj9DkjCvyStUVzw3hbp80mn3NFzDruapakSZWWMTshQE4g=
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <E7E41EA455BDE14FB7F8B2F6AD3D660B@EURP190.PROD.OUTLOOK.COM>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: jacobs-university.de
X-MS-Exchange-CrossTenant-Network-Message-Id: 51efaab7-bfa3-4c27-4ab3-08d761c45e55
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Nov 2019 07:47:12.1686 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f78e973e-5c0b-4ab8-bbd7-9887c95a8ebd
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: jn+b5CjGzRs7/nOKmF+1HnV3+WrFIx2HusPf8zGMkf6CykVdT4evh1AcBEWePsh3ZQvasFkCCi9tG92yZOuZHiq4CGefzIV8BH8YpIKvBIo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM5P190MB0449
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/vTBHVzcG36HAslJq64jPMRJTjkI>
Subject: Re: [netmod] I-D Action: draft-ietf-netmod-factory-default-04.txt
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Nov 2019 07:47:18 -0000

On Tue, Nov 05, 2019 at 07:42:06AM +0000, john heasley wrote:
>    In addition,the "factory-reset" RPC might also be used
>    to trigger some other restoring and resetting tasks such as files
>    cleanup, restarting the node or some of the software processes,
>    setting some security data/passwords to the default value, removing
>    logs, or removing any temporary data (from datastore or elsewhere),
>    etc.
> 
> It seems that this should all be part of this draft.  An operation that
> wipes a device for decommission is useful.  Whether it is a home or
> commercial device.

Yes to your point.

But every time I read the phrase "setting some security data/passwords
to the default value" I am feeling uneasy. The notion of 'default
passwords' is scary and a knob to restore default passwords even more
so. Perhaps the text should say instead 'removing security credentials
and restoring default security settings'.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <https://www.jacobs-university.de/>