Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
"Douglas Gash (dcmgash)" <dcmgash@cisco.com> Mon, 22 April 2024 09:21 UTC
Return-Path: <dcmgash@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6D1A1C14F6FA for <opsawg@ietfa.amsl.com>; Mon, 22 Apr 2024 02:21:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -13.933
X-Spam-Level:
X-Spam-Status: No, score=-13.933 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-2.049, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SPF_HELO_PERMERROR=0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pd-WTrRDBx8S for <opsawg@ietfa.amsl.com>; Mon, 22 Apr 2024 02:21:50 -0700 (PDT)
Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1CBE1C14F6F6 for <opsawg@ietf.org>; Mon, 22 Apr 2024 02:21:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=38776; q=dns/txt; s=iport; t=1713777710; x=1714987310; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=A69Z4Hu1MmAqzBKWmcuVzGUv1oRNrlSSbMhZAgW9ABA=; b=fhc9bHZBbwDgAGreES8zUhULyaQRvvL4BGiR+xnigOSuMorJg9BI82nL c0bxj9PFa0VUbtxDr/3G3yriC/7gROpMIFgFmajsdz4NS9MsLEher3dKM eve6P5MusQ15OUXGtgsxPWECjx6Ggcmz6fzO5h6cc6MqrzHexuDDorBrZ 0=;
X-CSE-ConnectionGUID: xhEeCM8XR0aVJu/cJ24Rag==
X-CSE-MsgGUID: kcBmDLpbQOCKhEV8S2Z3WQ==
X-IPAS-Result: A0ABAADYKiZmmJtdJa1aGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQFAJYEWBAEBAQEBCwGBQDEqKHoCgRlBB4UxgnADhE5fiGwDi2CFYoxHFIERA1YPAQEBDQEBPQcEAQGFBgJPCYdJAiY0CQ4BAgQBAQEBAwIDAQEBAQEBAQEGAQEFAQEBAgEHBRQBAQEBAQEBAR4ZBQ4QJ4U7ATQBDIZZAQEBAQECEhtKAhACAQgRAwECIQEGByARFAkIAgQOBQgXA4JeAYIcFAMxAwEQBqlDAYFAAoooeIE0gQGCGAWBPQIBD0HZCw2CUAaBSAGEcYMeHgEkgTGBcYIYG4RDJxuCDYEVQoJoPoIfQgEBAQEBF4EMBQESAQkaBQcSFgKDXIIvBI17gQMbHWqCKEGBVoEQgRxIgy0MARCHK1R3IgMmMyECARABVRMYFA0kIwIpPgMJChACFgMdFAQwEQkLJgMqBjkCEgwGBgZbIBYJBCMDCAQDUAMgcBEDBBoECwd1gXyBNQQTRxCBMooQDEGBPIE0KYFOKYEOgxhLbYQWgXsOamAdQAMLbT01FBsFBB8BgRgFnHQEOAIBghwBJUYFAmMEDQcEChkWAg0HDQ4BUwJQGRUGCgIXEZJnDQskgw+Lc0eOBZQTcAqEE4wOjyqGKheEBYx+mE1kmGIgjVSEAJEVAj0EC4UEAgQCBAUCDwEBBoFkOmtwcBUagwhSGQ+BGwWNGYEVAQmCQoUUnnx4AjkCBwEKAQEDCYhwLYFLAQE
IronPort-PHdr: A9a23:qhXLvxUbTXuwRZpU7OV8Z/1+RkjV8K01AWYlg6HPw5pUeailupP6M 1OavrNmjUTCWsPQ7PcXw+bVsqW1QWUb+t7Bq3ENdpVQSgUIwdsbhQ0uAcOJSAX7IffmYjZ8H ZFqX15+9Hb9Ok9QS47lf1OHmnSp9nYJHwnncw98J+D7AInX2si80u+74J37aARTjz37arR3f 126qAzLvZwOiJB5YuYpnwHEoHZDZ6xaxHg9I1WVkle06pK7/YVo9GJbvPdJyg==
IronPort-Data: A9a23:rgATvKnMyolN4s0Retza2wno5gz+JkRdPkR7XQ2eYbSJt1+Wr1Gzt xIdUWjQbviIM2bxeNhwO47n9x5Qu5+AzNY2HApkqyo3F1tH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaB4E/rav649SUUOZigHtLUEPTDNj16WThqQSIgjQMLs+Mii+aEu/Dha++2k Y20+5K31GONgWYubjpIsfjb8XuDgdyr0N8mlg1mDRx0lAe2e0k9VPo3Oay3Jn3kdYhYdsbSq zHrlezREsvxpn/BO/v9+lrJWhRiro36YWBivkFrt52K2XCukMCdPpETb5LwYW8P49mAcksYJ N9l7fRcQi9xVkHAdXh0vxRwS0lD0aN6FLDvMXiSvOe2n338K3LS4egpB2NsYbcR9bMiaY1O3 aRwxDEldBuPgae9x6i2D7UqjcU4J86tN4Qa0p1i5WiGVrB9HtaSGOOTuIIwMDQY3qiiGd7Sb M8WYCFvRB/BeBZIfFwQDfrSmc/y3iikK2UG9gz9Sawf4GP5ySBVyLLUF/H2evG0Ff4PrB2nn zeTl4j+KkpHbIPEk2XtHmiXrujXhirkV6oTGaG2sPlwjzWuKnc7EhYaUx6wpuO0zxL4UNNEI EtS8S0rxUQvyKC1Zsn9chCThS60hEYVZfhNVOYYsl23w6WBtm51GVM4ZjJGbdUnsuo/Sjory kKFkrvV6dpH7e39pZW1qO38kN+iBRX5O1PucsPtcOfoy8PorId2hRXVQ5M/VqW0ldbyXzr3x lhmTRTSZZ1N3abnNI3ioTgrZg5AQLCTH2bZAS2MAwqYAvtRPtLNWmBRwQGzAQx8BIiYVEKdm 3MPhtKT6usDZbnUy3XWH75SRO34uandWNE5vbKJN8R9n9hK0yPyFb28HBkvTKuUGp9dJm+3O hO7Vf15vscPYBNGkpObk6rqVpx1lvK/fTgUfvvVddFJKoNgbxOK+TomZEibmQjQfLsEz8kC1 WOgWZ/0Vx4yUP0/pBLvHrt1+eFwnEgWmziMLa0XOjz6i9JyklbPF+dcWLZPB8hkhJ65TPL9r 44FaZLRlEwBC4UToED/qOYuELzDFlBibbjeoM1MfenFKQ1jcFzNwdeIqV/9U+SJR5hoq9o=
IronPort-HdrOrdr: A9a23:YZcOJqMG8NyK18BcT4H255DYdb4zR+YMi2TDiHoBKiC9I/b5qy nxppUmPEfP+UgssREb9expOMG7MBXhHO1OkPgs1NaZLUbbUQSTXftfBOfZslnd8mjFh5FgPM RbAuZD4b/LfCVHZK/BiWHSfadDsby6GeKT9JvjJhxWPHhXgtRbnnxE43GgYzVLrWd9dP0EPa vZzPBq4xCnfnMaZNm6AH4qY8jvzuegqLvWJTQ9K1oC8gehsROEgYSWL/Gf5HgjegIK5Y1n3X nOkgT/6Knmmeq80AXg22ja6IkTsMf9y/NYbfb8yvQ9G3HJsEKFdY5hU7qNsHQeu+e08msnl9 HKvlMJI9lz0XXMZWu4yCGdmDUIkQxeqUMK+2XoxUcLkvaJAw7SzPAxw76xRyGprnbIeusMiZ 6jkVjp76a/Rimw7BgVr+K4JC2C0HDE4EbLVYUo/iZiuUx0Us4LkWQSkXklYqsoDWb07psqH/ JpC9yZ7PFKcUmCZ3ScpWV3xsewN05DVCtub3Jy8vB96QIm10xR3g8d3ogSj30A/JUyR91N4P nFKL1hkPVLQtUNZaxwCe8dSY/vY1a9DS7kISaXOxDqBasHM3XCp9r+56g0/vijfNgNwIEpkJ rMXVtEvSo5el7oC8eJwJpXmyq9DVmVTHDo0IVT9pJ5srrzSP7iNjCCUkknl4+6r/AWEqTgKr +O0VJtconexEfVaPF0NlfFKuxvwFElIbkohuo=
X-Talos-CUID: 9a23:etMGgWtP3Mx5ttt/b/renujY6Is1clDQ51KAE3XgAFhLVfqeawXMwqprxp8=
X-Talos-MUID: 9a23:1mYWRgTqyLTTm2l4RXTvjxtnGONw6Z2JI2MNvKtWgJO2bhNJbmI=
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by rcdn-iport-5.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Apr 2024 09:21:48 +0000
Received: from rcdn-opgw-3.cisco.com (rcdn-opgw-3.cisco.com [72.163.7.164]) by rcdn-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 43M9LmUx012531 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <opsawg@ietf.org>; Mon, 22 Apr 2024 09:21:48 GMT
X-CSE-ConnectionGUID: Ve3XmbyrS5y6vAUbuIX/7w==
X-CSE-MsgGUID: 33ptiGOiSdG1aQXOcbM3GQ==
Authentication-Results: rcdn-opgw-3.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=dcmgash@cisco.com; dmarc=pass (p=reject dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.07,220,1708387200"; d="scan'208,217";a="17963448"
Received: from mail-dm6nam10lp2100.outbound.protection.outlook.com (HELO NAM10-DM6-obe.outbound.protection.outlook.com) ([104.47.58.100]) by rcdn-opgw-3.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Apr 2024 09:21:47 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lxFTOgKmMtSMJ2rY05SN9S5b/ymeTiQ9lP/jDTSAL0MeQiXib/HML27xE/QNYG1rgAxERaJbxg50hVNkutIdAPMn4Ymq0DJBzFHOVl5WOyed4D49iZDARQwUlf8uj+YIa4mQPIzjv1eAG5DDKtNDNG8qGrKuDb/Rz7ndKWo42tLuMJbmFz9+cqRYjYQwVVKGnD8ZyJY4KzYWLhTKZqp34JmhrcdQ7nuox16sBGaXqud5ncSF9HVPUQocHbzuY8QCwKVInbmMC6mpw3jr69ffVZdlagzgjEn+lwlfU+LZxVA8zbOnlFEk9ljGH3S70a2fx/9NmdtqyVcGAM4sgKdt2w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=A69Z4Hu1MmAqzBKWmcuVzGUv1oRNrlSSbMhZAgW9ABA=; b=fvoWbwDNGu0L+5uMkyy1y+Z4y0uIhyyHzyJAvCf5L2L6PG9bYXSfPXmoqoeDwqxgd0BwK0Gm6IxzpdUlbslU2+/NZMLGoZYVlNIWHNAz8eXjIcgQOzFCxlW2wdASb1PWnV4BE/Y9Qa6gbiydY9PObhMIzmoLsISo8Ube3jeQJl3lE8z01zVuAgBmpQdT6wn3S8dbV1S9C7lsgoE/DzpV9muTz4OmAmq2Fy1KwOHFr3vUxp6PD6klAjHYYVt8WwV4/ZlWLRVBGUkBQ9a6Hxc/xcUnsegaPjWGFVsDv6urMqvybUvG1NhDJbFMhcsGGT/mOLm5PlEDlU4+ZWzRZrlEwg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from BL3PR11MB6364.namprd11.prod.outlook.com (2603:10b6:208:3b7::12) by MW5PR11MB5764.namprd11.prod.outlook.com (2603:10b6:303:197::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7519.20; Mon, 22 Apr 2024 09:21:46 +0000
Received: from BL3PR11MB6364.namprd11.prod.outlook.com ([fe80::d06:62c3:9a6b:2b5c]) by BL3PR11MB6364.namprd11.prod.outlook.com ([fe80::d06:62c3:9a6b:2b5c%6]) with mapi id 15.20.7519.018; Mon, 22 Apr 2024 09:21:46 +0000
From: "Douglas Gash (dcmgash)" <dcmgash@cisco.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>
CC: John Heasley <heas@shrubbery.net>, Andrej Ota <andrej@ota.si>, Thorsten Dahm <thorsten.dahm@gmail.com>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
Thread-Index: AQHaknkV5UFry3XPykaOc/4zi7RiALFv0X2ggAQpGM0=
Date: Mon, 22 Apr 2024 09:21:46 +0000
Message-ID: <BL3PR11MB63646F83D464F49D9D729ACAB7122@BL3PR11MB6364.namprd11.prod.outlook.com>
References: <171094844069.8406.1730131072887926375@ietfa.amsl.com> <BL3PR11MB6364F94772DDCCC57DF18748B7332@BL3PR11MB6364.namprd11.prod.outlook.com> <DU2PR02MB10160514500051EDA4B5D1441880F2@DU2PR02MB10160.eurprd02.prod.outlook.com> <BL3PR11MB6364B8968DE1CC0E83600660B70D2@BL3PR11MB6364.namprd11.prod.outlook.com> <DU2PR02MB1016055635A500C074019FE3A880D2@DU2PR02MB10160.eurprd02.prod.outlook.com>
In-Reply-To: <DU2PR02MB1016055635A500C074019FE3A880D2@DU2PR02MB10160.eurprd02.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=True; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-04-17T15:33:41.0000000Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BL3PR11MB6364:EE_|MW5PR11MB5764:EE_
x-ms-office365-filtering-correlation-id: 8e80cf31-e48b-4b8d-85af-08dc62ada1ce
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0; ARA:13230031|376005|1800799015|366007|38070700009;
x-microsoft-antispam-message-info: Q5AZjf6ZWF7/LY2xewtVrAbRVDeMa2XEcD8Yz/bAP1rP9aiG8QIblgQ3NzN5rjqzZik/VZPFrhgE0yZHKjnnAgMY1GlStFxk45H7I4l18g6dyvADxx5fdWIWhr68GlIdPSLOUOMYFX+kNups0mhn6Hw3HsLxaDTUqaxX50jiSG16UKiIf+bFmRinkpzV08MaHwUuW8+aqBngZ6bwRhkKduYok42vnSasIf7TpzNfvDYgvmIMsHng0JQEQ0HglgIEsDwTCK/YkZp1f6UJezRb3QIWSp/uDdf/kKc5YcO0LWWHeJhqHEqZlnV/ezbO5vl1aUiYANvIHhIZmg3t0HrBYMbwUfTJoxzR91QANezzWnkIpG4nVNSFx2rEgV/rjlgf2vbQtMgu4XJVo0auZ1Pec7GKSN8aQuGkFux8arMlRd6uag+Hgx8lcd97YyWj3CYIRG8X/TVTKGptRCbgpw9Ivk8N9bJ1dAVmk18wUxoYsWidNLzFnuHhaChKwhOfTNnoP6Hl40J2HqKaPf1jb2rQMN8ot4iHbm1neu0Wktt4GMFyEe/U8offglH0CoHQWzGnFoyeZiHHyJtNegVZcV8gQA3ABZJnupPcfChS1JbfhoXeLiteqNU0emtECQxGRYBUBiSwRiOyBz3ut11dc0PlPNCXatZzTjivnUMtqG1aL97VTxqic3maBlp3cVnXrlZdbv3A7qIo41IktoIXmTDZLlqlFCEvnJ1J2thzaT4k2uNPf8HRGk/vwm+drl6J26HOJw0e3822cppSTh2wg1It9Vu3uqaUL592s7UtJEA8strx8BMviYPG/yEyBtV0Hr8Cy5bH6p84HDIzpiEwThclAGo9oH2xpKXHC7dxnukv2dTShGJ7kAYwXE89PaQawW19cht8IcePhJm0rySyUGFvYzP2ZCu4Dl62g0dLcv/5oJKFTqy8JGmPHDgK4/IqqKuUPIqHymMCjSR+DYkxA9BrYanBEb/PJytamEq5vp6I2DiBGr7gb9/LV5QwzGdQhOajaUTGjRYaoeg/pPUA2xWc3qYSPqeuZSI1h73NJqRhEDNtjO3gl6aXUMZqEYh4VLQVlVGOZionbcBxhyJNJNaLw4TOrdsIvGsg4ITeKW4vRPujrWtKgEuuHQg4D/EjknCtEGonl2x6BmPWJNX1iXnsBeVKWka5k+0fOnCA0R8i9snORzONuFkzx5VEL59d7ZsDn5aVoddob3BYcH0Gg77xSgOil0tGH5pCjZshVQnNZWL+ZGcfAHxbAAza9T3eQSAvodHFrL8h/zXw9j8NQKDjnPau+IlCWnqOf5caRoSZ0xk=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL3PR11MB6364.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015)(366007)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: xlr6kh3fmmRG4HfBWxW/hLlEDGq7feCfzif/y7GQZDqx8s1E20Nh3vWCxGHWk8fg70+OpNU0D6Q8dwC6t+sa4rZw9KbrSlhb1tXQsAX98BJr7wKn5GtR0Fhklu6dACwzxmdRi5GehTg0SLppi5DL/y9+gXvmxKo1jH2NLvsyfUkwzZF+UZSoliYpxKeb28pQ7bZp1LJBVX8QVfPQV9X/fvenzH0p4yoYZsDwKeiFzszxg7FyKqAuGUBA5qXIdZHkdQuk8p+LRx3/3ClvDx8l+05X/F5JtnnQ47X0OCk+rHMerW/973IttqraIMG7LqLeadpVqUgV/eTui+lQ+d0cz53WX5URxnC1SOos81kv0iEt+epu9gmg6l8UNlm7iumnRqUQ0SV7rJw4u0p596uOKboRDYSrIdRUgcJo7lNxJM5RBG5rhgrzFW4q+F5x5rL3YZQZuULyFShd1HGyzDnHAUs04Xr3ZIaY+KTZgF91pAXjPKbGrbeoAnycskQrqqVNL5kmtlVgmhWb5ttFHyLCYX2x3sVthR8RpS+FK+KHgsn3OerD9Hd0GkOKRv98RdRSzhQkMhGmyuxPSJaMvqjwfuoSSr7iYNPC18jXj707Glpr0KqoIq/gPOoB3IxQ1b4tpqx5UbO21zy6xD2rqBntQYKBxHV5sCpBTh2rZzDEL67ubNJHoAsoLMylCciBnJNkunWMWAgesA4OvL1WEWWf1CQyeO5Tsr3HPqJZgmXo7tWuBq3s3Wr9mIt9y5DjOyOq+XqPOe6fpk+cl169bW9XjS8dwf7AbpW+5EZFx409LelUgGO6BhAlLizhS2vLh1qLODdM7nCVZlSo+aJ62lWVzUXTQm5IXr/95PovDceT1wUJcoOJ2m4B+d6oMyvP1dpNe3xpJ75uXBqeRtw86BAS8cWlB5zNkDsR6QHabLp3Uqt2OpOim0uQkffv5bcHVvCS9t55UKyL6VR2FWfdwX+8Ey1DD3mXyxmySokktUoqvSYfdWshYiyjlnu/ZJWmAcz/XqDyxKtvUbnqOv2Nlrwrz5yaKLhp76DmiQJQiMgJUKEt1rHneJlAwqCzCa2B4cdAWLfM3JHa1IJYlMjGsbP9xufSf++8PeZsaN9DeDd3rfGhNX23f+UI4rBJkemSyNhtRhCXUco7B7Horq/6tIC7VMui57qwnU+91LCaMRTXi/L/Ws5uoCBlaupoYVN7Kf376WK+LL5M0mbjvcct9/A4ZB2LNwSK9ENLw44BqbRon2SSqdubjxPrRMTSB38WSiu4PLyNyq0SRX1SvIC5ASzW+pQ/+WQ3hWgdC+AB1NFFDbZCruBq4g9BixPEj3fmAKEP9oy0xqLdEME4e2T5jpciF88Zs6r35j4+PoUoUiQRHizTA/MAgvjxtyOdoffCmn5IYQTPjBRxGzCh8RHLjnwhEiyKINtIxQbMGZV9wN47RFvGqX+g7WAL3gVtC1OSFOVk/wz2fIIMZlJvfusOURjQsL8Hga/w9efVkge9tSp0luQcUwhijLTj2gBm+FBWWMEJa98wnFyjScOG36q7nex1B6NOvxjgHTR3FoOA+93W5nODfSjKOdSsvpe3JjaMegQPIg2kzRuXhyByYREOaUtECvVMscyAiqxJUduyaLFoB/o=
Content-Type: multipart/alternative; boundary="_000_BL3PR11MB63646F83D464F49D9D729ACAB7122BL3PR11MB6364namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BL3PR11MB6364.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8e80cf31-e48b-4b8d-85af-08dc62ada1ce
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Apr 2024 09:21:46.3223 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: MC9XSI+meteqoM7eM/q99846fEGgm4vyfVkvEtdAIlh7lvmIgCjISBub4oBNf4FHzGRRF3GvIMrj3KSkdblmIQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW5PR11MB5764
X-Outbound-SMTP-Client: 72.163.7.164, rcdn-opgw-3.cisco.com
X-Outbound-Node: rcdn-core-4.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/15eFsuHnrSO59tgc77wct78dAzE>
Subject: Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Apr 2024 09:21:54 -0000
Thanks Mohamed, please see inline… <Doug/> From: mohamed.boucadair@orange.com <mohamed.boucadair@orange.com> Date: Friday, 19 April 2024 at 18:31 To: Douglas Gash (dcmgash) <dcmgash@cisco.com> Cc: John Heasley <heas@shrubbery.net>, Andrej Ota <andrej@ota.si>, Thorsten Dahm <thorsten.dahm@gmail.com>, opsawg@ietf.org <opsawg@ietf.org> Subject: RE: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt. Hi Douglas, Please see inline. Cheers, Med De : Douglas Gash (dcmgash) <dcmgash@cisco.com> Envoyé : vendredi 19 avril 2024 18:46 À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com> Cc : John Heasley <heas@shrubbery.net>; Andrej Ota <andrej@ota.si>; Thorsten Dahm <thorsten.dahm@gmail.com>; opsawg@ietf.org Objet : Re: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt. Hi Mohamad, We are working through the comments and enhancements that you kindly sent. There are two comments that we’d be grateful if you could clarify: 1. BMI10: “What about raw public keys?” (on: Implementations MAY support TLS authentication with Pre-Shared Keys): I’m guessing this relates to fact that, as we mention only PSK, that this indicates that we mean to imply that non PSK authentications are not included. If this is the case, then for sure, we will clarify that they are. If you have something else in mind, please expand, thanks! [Med] Yeah. <Doug>Got it, will clarify that this section just relates to PSK and dosent impact the use of other PKI options</Doug> 2. BMI16: “What about configuration of name/address/port number of the server?” (on: Certificate Provisioning is out of scope of this document.), would be grateful if you could please expand on what you had in mind here [Med] Clients should be provided with the IP address(es) and alternate port number (if the default is not used) of the server. Clients may also require to be provided with the domain name of the server. <Doug>So we didn’t have in mind any additional configuration at the T+ level other than the regular TACACS+ for this, (where clients will have servers defined and vice versa), with the caveat of the restrictions in 5.2. TACACS+ Configuration (to ensure that TLS and non TLS can be easily differentiated at implementation level to reduce the likelihood of operators accidentally mixing TLS and non TLS traffic which may lead to downgrade attacks.) </Doug> Also, given that you define “tacacss”, do you had in mind to use that for service discovery? <Doug> not at this point, it is more for IANA considerations, assuming that we do end up requesting a new port number</Doug> Please note that if a name is also provided to the client, then you may indicate that the name will be used also for rfc9525 validation to compare the domain name with the certificate that is provided. If no name is provided, do you assume that the certificate is <Doug>To restate to ensure I’m on your page : the actual T+ protocol won’t have the domain name embedded anywhere, so this is OOB of tacacs and encapsulated within the TLS transport and peer configuration, which can validate as usual as it knows the peer connection details. We will clarify that recommendation. If there is somehting we’re missing there, LMK, thanks !</Doug> BTW, I wonder whether you need to indicate whether the certificate authority that issued the server certificate will need to support at least DNS-ID and SRV-ID identifier types? I don’t think URI-ID is needed. Similarly, do we need to include a mention about wildcard “*”? I think it SHOULD NOT. <Doug>Agreed, I think there was a discussion on that, and it was discounted. We’ll make that explicit</Doug> Feel free to grab whatever useful for you. Thanks. Many thanks! From: mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>> Date: Wednesday, 17 April 2024 at 16:42 To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, opsawg@ietf.org<mailto:opsawg@ietf.org> <opsawg@ietf.org<mailto:opsawg@ietf.org>> Cc: John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>> Subject: RE: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt Hi Douglas, all, Thank you for taking care of the comments. I managed to review the latest version. FWIW, the comments can be retrieved here: Pdf: https://github.com/boucadair/IETF-Drafts-Reviews/blob/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.pdf Doc: https://github.com/boucadair/IETF-Drafts-Reviews/raw/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.doc There are still some points to be fixed, but I think the document is getting stable more and more. Cheers, Med De : OPSAWG <opsawg-bounces@ietf.org<mailto:opsawg-bounces@ietf.org>> De la part de Douglas Gash (dcmgash) Envoyé : mercredi 20 mars 2024 16:40 À : opsawg@ietf.org<mailto:opsawg@ietf.org> Cc : John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>; Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>> Objet : Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt Dear OPSAWG, We have uploaded a new version of the doc, primarily to address as much as possible of the comprehensive review kindly submitted by Mohamed Boucadair. We thank Mohamed for the time and trouble taken to the review the doc so thoroughly. We will be happy to discuss further any omissions or new comments and rectify quickly. And we will endeavour to respond ASAP to any other comments of any kind on the doc. Many thanks, Regards, The Authors. From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> <internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>> Date: Wednesday, 20 March 2024 at 15:27 To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>, John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Thorsten Dahm <thorsten.dahm@gmail.com<mailto:thorsten.dahm@gmail.com>> Subject: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt A new version of Internet-Draft draft-ietf-opsawg-tacacs-tls13-06.txt has been successfully submitted by Douglas C. Medway Gash and posted to the IETF repository. Name: draft-ietf-opsawg-tacacs-tls13 Revision: 06 Title: TACACS+ TLS 1.3 Date: 2024-03-20 Group: opsawg Pages: 15 URL: https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.txt Status: https://datatracker.ietf.org/doc/draft-ietf-opsawg-tacacs-tls13/ HTML: https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.html HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-tacacs-tls13 Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-opsawg-tacacs-tls13-06 Abstract: The Terminal Access Controller Access-Control System Plus (TACACS+) Protocol [RFC8907] provides device administration for routers, network access servers and other networked computing devices via one or more centralized servers. This document adds Transport Layer Security (TLS 1.3) support and obsoletes former inferior security mechanisms. The IETF Secretariat ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you. ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you.
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- [OPSAWG]Re: New Version Notification for draft-ie… Douglas Gash (dcmgash)
- [OPSAWG]Re: New Version Notification for draft-ie… mohamed.boucadair
- [OPSAWG]Re: New Version Notification for draft-ie… Douglas Gash (dcmgash)