RE: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt

john.loughney@nokia.com Tue, 17 June 2003 14:02 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA16361 for <nsis-archive@odin.ietf.org>; Tue, 17 Jun 2003 10:02:10 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5HE1h830316 for nsis-archive@odin.ietf.org; Tue, 17 Jun 2003 10:01:43 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5H8N2a05222; Tue, 17 Jun 2003 04:23:02 -0400
Received: from ietf.org (lists.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5H8MYm05211 for <nsis@optimus.ietf.org>; Tue, 17 Jun 2003 04:22:34 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id EAA03566 for <nsis@ietf.org>; Tue, 17 Jun 2003 04:22:32 -0400 (EDT)
From: john.loughney@nokia.com
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19SBhR-00043v-00 for nsis@ietf.org; Tue, 17 Jun 2003 04:20:17 -0400
Received: from mgw-x1.nokia.com ([131.228.20.21]) by ietf-mx with esmtp (Exim 4.12) id 19SBhP-00043m-00 for nsis@ietf.org; Tue, 17 Jun 2003 04:20:15 -0400
Received: from esvir05nok.ntc.nokia.com (esvir05nokt.ntc.nokia.com [172.21.143.37]) by mgw-x1.nokia.com (Switch-2.2.6/Switch-2.2.6) with ESMTP id h5H8Lea13243 for <nsis@ietf.org>; Tue, 17 Jun 2003 11:21:40 +0300 (EET DST)
Received: from esebh002.NOE.Nokia.com (unverified) by esvir05nok.ntc.nokia.com (Content Technologies SMTPRS 4.2.5) with ESMTP id <T62e1e747f6ac158f258d8@esvir05nok.ntc.nokia.com>; Tue, 17 Jun 2003 11:20:25 +0300
Received: from esebh005.NOE.Nokia.com ([172.21.138.86]) by esebh002.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139); Tue, 17 Jun 2003 11:20:25 +0300
Received: from esebe014.NOE.Nokia.com ([172.21.138.53]) by esebh005.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139); Tue, 17 Jun 2003 11:20:25 +0300
Received: from esebe023.NOE.Nokia.com ([172.21.138.115]) by esebe014.NOE.Nokia.com with Microsoft SMTPSVC(5.0.2195.6139); Tue, 17 Jun 2003 11:20:25 +0300
X-MimeOLE: Produced By Microsoft Exchange V6.0.6375.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Subject: RE: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt
Date: Tue, 17 Jun 2003 11:20:24 +0300
Message-ID: <DADF50F5EC506B41A0F375ABEB32063658EEAD@esebe023.ntc.nokia.com>
Thread-Topic: [NSIS] AD Review comments on draft-ietf-nsis-req-07.txt
Thread-Index: AcM0p9aYaKlYfBlETM6iOMj1z9BkugAAN3xw
To: karagian@cs.utwente.nl
Cc: nsis@ietf.org
X-OriginalArrivalTime: 17 Jun 2003 08:20:25.0049 (UTC) FILETIME=[4D7A6490:01C334A9]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by www1.ietf.org id h5H8MYm05212
Sender: nsis-admin@ietf.org
Errors-To: nsis-admin@ietf.org
X-BeenThere: nsis@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/nsis>, <mailto:nsis-request@ietf.org?subject=unsubscribe>
List-Id: Next Steps in Signaling <nsis.ietf.org>
List-Post: <mailto:nsis@ietf.org>
List-Help: <mailto:nsis-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/nsis>, <mailto:nsis-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 8bit

Hi Georgios,

> You are right, but there are situations where security can be provided,
> without adding additional functionality into the protocol.

What we are requiring is not that NSIS develop new mechanism, but support
existing ones.  

> For example, the security threats within a trusted administrative domain are
> different then the security threats in a inter-domain communication. Therefore, the
> security features required in these two situations are different.

Can you give me a pointer to where a 'trusted administrative domain' is
defined, especially in IETF literature?  As I understand, trusted
domains are not accepted in the IETF as proper security mechanisms.

We have had this discussion in the SIGTRAN wg, and the IESG told us
that trusted networks was not a good model, and asked us to reconsider this.
The result can be found here:

http://www.ietf.org/internet-drafts/draft-ietf-sigtran-security-02.txt

br,
John
_______________________________________________
nsis mailing list
nsis@ietf.org
https://www1.ietf.org/mailman/listinfo/nsis