Re: [OPSAWG] Fwd: New Version Notification for draft-ietf-opsawg-mud-21.txt

Eric Rescorla <ekr@rtfm.com> Fri, 18 May 2018 17:58 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 804EC12D95D for <opsawg@ietfa.amsl.com>; Fri, 18 May 2018 10:58:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.909
X-Spam-Level:
X-Spam-Status: No, score=-1.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, T_DKIMWL_WL_MED=-0.01] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rYlW1T2rRbLC for <opsawg@ietfa.amsl.com>; Fri, 18 May 2018 10:58:13 -0700 (PDT)
Received: from mail-ot0-x236.google.com (mail-ot0-x236.google.com [IPv6:2607:f8b0:4003:c0f::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CBF6A12D942 for <opsawg@ietf.org>; Fri, 18 May 2018 10:58:12 -0700 (PDT)
Received: by mail-ot0-x236.google.com with SMTP id n1-v6so10078757otf.7 for <opsawg@ietf.org>; Fri, 18 May 2018 10:58:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=TwLm5XzDQho3K/v+Kfw2dJ8DBxI/aXRkfuZ9yT9yFNs=; b=y0+HvH/LGZt+Y2/6yfwB9Kf3JnfI41i53nXBLU3bdwjawZ6pzb2xqLpnSDipdXkcMx Pxc2xdPf8voEH0fAiJDGWoGlWZEyVL32Ms7MkGttFPRVr2RDVFYzt0lNU+IFM26sW1nu 8xyzfBGt1u4nPmSH9M4NfzWglGzWoDwj+zEfofRK15+mROsSWltAUFe555UlzCsy9JyJ 6Elxlq+ZD8DxzOlRl2JsE8NRa3X/jC6wuRWjiONBvVpfs2mPzJLGeQsmFYi03qw/jkdQ AbGu0M4XGOn6skSdNBb0QxFAjLF7mwl9tryK5RdOBAZl9kPoocLSXoSDZjThcu7wmBjC X4xA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=TwLm5XzDQho3K/v+Kfw2dJ8DBxI/aXRkfuZ9yT9yFNs=; b=uoaaAfaT3Z0uwXwkCjf7O14zvvzx2F34X7JonDOH9E3Bx1Wqjbk5UZ88uBgk5ogRis /Wfapnqad0KjCBtr1bDoVuTpkZiBP2r/h6GCsF3FZAc7DxF7LxXWEHAWWZZ0bwJPhY/6 6BThPSfrbYy1BBIpP3FLuXCMDSCUQ+3tT+p8Jys/A9vw3Q3N43rsOJBXYAFcJBIGs6ud FGq2+6gW2bktWcyN816UbPCNJAL779vXc8iGKJZFIbgzcRMi7l2EIt7WH7wdFOg0o5R+ B/m9h/JsUFtzuIg7wmNL1arKr9Vung971h4Yvsp0t9gWSR6z9AVewmQ4R3fIOWHrFkKb lEDg==
X-Gm-Message-State: ALKqPwcne2fB5XCy05pJ2oJg5kKdDj+pah4XrkKumWj3A0sHMpO7FqMe tpGzLyrwJT3PmVjG4p5KIgSsY7j8nN+W70pOhhrD4w==
X-Google-Smtp-Source: AB8JxZreSDt63lHrwRg5KV445k14UU5fRtvop5AIUzfFxobe2VUGfz7OopMmBf+19zbN17uWdHsxI9rktqx6R3/zcwU=
X-Received: by 2002:a9d:1055:: with SMTP id o21-v6mr7475217oto.371.1526666292185; Fri, 18 May 2018 10:58:12 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.201.118.130 with HTTP; Fri, 18 May 2018 10:57:31 -0700 (PDT)
In-Reply-To: <0dc704d2-73a2-977f-08c8-8e0b01c3b57c@cisco.com>
References: <152657039204.7694.840577957694607451.idtracker@ietfa.amsl.com> <8bafe1e0-12af-6526-d16e-6d39fded3bf3@cisco.com> <0dc704d2-73a2-977f-08c8-8e0b01c3b57c@cisco.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Fri, 18 May 2018 10:57:31 -0700
Message-ID: <CABcZeBPgiSi7rxPwj9XPECcD1SimZ1B=Xnym5tXoUkASFD2TGg@mail.gmail.com>
To: Joe Clarke <jclarke@cisco.com>
Cc: Eliot Lear <lear@cisco.com>, "opsawg@ietf.org" <opsawg@ietf.org>, IESG <iesg@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000095b2c056c7eb2a0"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/5WV9ojYHgBv6ZqX5j-pKWNFrzMc>
Subject: Re: [OPSAWG] Fwd: New Version Notification for draft-ietf-opsawg-mud-21.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 May 2018 17:58:16 -0000

Eliot,

The certificate part seems basically right (I think you should require
specific KeyUsage bits).

Maybe I missed it, but I didn't see anything about the level of trust you
should have in cases where you can't reliably tie the endpoint's
transmissions to its certificate.

-Ekr


On Fri, May 18, 2018 at 3:46 AM, Joe Clarke <jclarke@cisco.com> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Chair hat on:
>
> We would like to give this call for review a week timeout with the WG.
>
> Please pay special attention to the security changes Eliot has
> described below when reviewing the new text.
>
> We are looking to push this forward EOD on May 25.
>
> Thanks.
>
> Joe
>
> On 5/17/18 11:36, Eliot Lear wrote:
> > Hi everyone,
> >
> > This draft is intended to address all IESG comments.  Thanks to the
> > IESG and reviewers for their contributions.  A summary of the
> > changes is below, but people may wish to do a side by side review.
> >
> > Eliot
> >
> >
> > * Small edits to the abstract * Clarity in the introduction that
> > the focus is on protecting the device. * Many grammatical/wording
> > improvements * Clarity when MUD is most effective. * MUD controller
> > -> MUD manager * Normative language boiler plate change * Clarity
> > on what should happen when a MUD manager can't reach a MUD file
> > server * A few reference updates * Clarity on the validity time of
> > a MUD file * Added references to RFCs 5911 and 5912 for SMI
> > changes * one additional data element (documentation) * one change
> > based on an update to the ACL model during its last call *
> > Subsection numbering for node descriptions. * Improved text around
> > "controller", direction-initiated. * Simplified MUD-URL text. *
> > Optional reserved space added to DHCP, LLDP options * Simplified
> > DHCP processing. * A new certificate field to bind the manufacturer
> > certificate to the mud signer. * A content type definition for the
> > SMI. * Updated security considerations.
> >
> >
>
> -----BEGIN PGP SIGNATURE-----
>
> iF0EARECAB0WIQTMiWQHc8wChijkr7lvaI+K/hTPhwUCWv6vBgAKCRBvaI+K/hTP
> hwzAAJ4gQdPZ93IFCwO7nWOca4gu7xbwkwCeJPLWlBoGGKDtuQp8sUHVJy+2lmY=
> =CyhD
> -----END PGP SIGNATURE-----
>
>