Re: [OPSAWG] Start of WGLC for TACACS+ document.

t.petch <ietfc@btconnect.com> Thu, 06 October 2016 10:02 UTC

Return-Path: <ietfc@btconnect.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A374112959F for <opsawg@ietfa.amsl.com>; Thu, 6 Oct 2016 03:02:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5U0ckv3jSjJr for <opsawg@ietfa.amsl.com>; Thu, 6 Oct 2016 03:02:33 -0700 (PDT)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0120.outbound.protection.outlook.com [104.47.2.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 119FD12959D for <OpsAWG@ietf.org>; Thu, 6 Oct 2016 03:02:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector1-btconnect-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=S+1+0Gn54+lQtrbGPiMw36C5OEfztdEXkdRoCwDbbC4=; b=iPZjHxVoRH4MXTzf403Vk0c4nUvkYduxfhSeYkZFeYczqDdsR5IHqGE0sCuBpO65RZs5eJT/v1stGyYdxK3E1n+8UTnO+XcEIpDwDXckvxHKK8OsqbhPRpnZBWOAsUGy2CVD0y3yywqrmiC4ywTbsiM113t2TVt/QU7SI8uNUz0=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=ietfc@btconnect.com;
Received: from pc6 (81.159.102.255) by DB6PR0701MB2997.eurprd07.prod.outlook.com (10.168.84.135) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.649.16; Thu, 6 Oct 2016 10:02:27 +0000
Message-ID: <025401d21fb8$71906e20$4001a8c0@gateway.2wire.net>
From: "t.petch" <ietfc@btconnect.com>
To: Alan DeKok <aland@deployingradius.com>, Warren Kumari <warren@kumari.net>
References: <CAHw9_iK-1=Epr5CLAtFayd0Bss6oZrsDTfyox6y2SfPJAav78Q@mail.gmail.com> <5019ABA9-BB74-4C69-A455-12C17A2958CE@deployingradius.com> <E6C64895-F0C6-40B8-A687-4DC56590B22E@deployingradius.com>
Date: Thu, 06 Oct 2016 11:00:05 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Originating-IP: [81.159.102.255]
X-ClientProxiedBy: HE1PR06CA0054.eurprd06.prod.outlook.com (10.164.28.150) To DB6PR0701MB2997.eurprd07.prod.outlook.com (10.168.84.135)
X-MS-Office365-Filtering-Correlation-Id: 4958d8c4-5f4f-4988-ac52-08d3edcfe13a
X-Microsoft-Exchange-Diagnostics: 1; DB6PR0701MB2997; 2:Sa85ebpgwgjRCtyLDWylSjFLSXLAyGK5zaCaOFB3C8c8/iUR2BB7O0Hw3Z3qUdMPD+ahQ4BTW+3ISIFZ0o/jQ76qpD+67lhHQHbetTYPvkXgyAc+amlTdWQgFXcf3UXyvffnic4ZYYjAsqvPxyFCiQX/fZejXH8R44M4RvyEpkjci0ij9mjG5AwRlFulR2osN0n1wXKd8zzYqlQVaxA66g==; 3:npTPJ0r3waZ8SJo6ggPG0SOU6x8vUDUsRg7oA11cNvUG1b6JeWS0PLlM/OhulfKIc5sRcyZ8VSYK4+hc8A6rSPOMqDFHQmoQiOBxoR03BMyXeTDUt9yec97R3o3uHRclU0UET6o89Lcsfetj8XV1/Q==
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DB6PR0701MB2997;
X-Microsoft-Exchange-Diagnostics: 1; DB6PR0701MB2997; 25:VlLmvq8JSABWaYcGV5TB5r4F7ogZtiyBTC6na3hrpdGLzwVJNJN2FngakHaKLXLrbKKyo3gfQWeSx+p765cHB7m6FZF1IWzLNoftaqmCSH13SIdQIUxwZHXuP3pdR2gB4YSbEsM3wmhcDkjesyZJFbgZVT/s+BoxH9EQpa70Bv+0yKnxi4BDbtjun5veTpTH7E2JsDuTqarx6bkHWmPmOM1feKGC7WFu8RNTbNo4AHoJMJNx/kIFgQTMTw1QgUa32zQk72Zgq1jvRJLmk6jR61sAsq+X6Z54h46WAxf5ArPHckCZj2uIGUvUrvjip4R7Yhuvja5hYGQ+jewK/TBbw+INpj8KKPa1HRZlbA7lvGgo9OllhlL5lv/zxu07ACe4Z3jISPLpfCWIOW8VLXmE/QlHbmkFfkVmcNhDsqfoOeta/2ZC6vLD8mxQPEf6e9EDk39kKF9BK/cVL3TQi5eg6wVdfIDpG6rxMXP8v8NJwRhtyuHH7uKX5vrAqQvLJpOqQ3eSEbRJoZbIanDtLNQGz0RNJo/B0S1wzrfaDYxan+QmyOOa0LzOgp8LCWkxzxRvtp965lXQZiZfoCX9bSJzev6mL2L6i/i7Ij4CFN0fV+nLudsy+MFIenIa+YQuQr16xSHSke90DROYNBFeEp0BKIG+8bIi+UZrTrkeQi1Fr3yGu19wlb3vQTPNyq+Prh3GHn05XNXGJLvZRaD96qwMQrOyddCuuk7AiVALXTf8v+wvzuIA8RevxkwGE1Pdbxjp
X-Microsoft-Exchange-Diagnostics: 1; DB6PR0701MB2997; 31:zT04zwg0c3zwL8cHUZuOLbkXaf2r8u7Y1DVhcHOZK2tNdQvd86V47C3b6kg8hcu+6hVqxgcZHTHEnJZHWXG5MxSxZwea2cRs9Km/uNdfLCWkY472m6u7oQ0kU0zqSmkJObJ0OXnKKILZvaA8nmw+1bTqy4IQPfnVoY0QzkTd0DnQLfK9F5GQcuL8U2l0s738CplzRk83hdTeN+WCHBVz6X/sHht7FBaFlclgudwptgrFijjxlm6+Obf3c+YF+xio; 4:CTzM6TBKNwTOQ74m8Us8B+8hYeOzJlGfWu/rNs0NyiXhqF/DtqfHqfVciR0k6Sory5Iy3NfPz0k7rSeOLCZ/8C3GDo/a1DYzNNtKAAew6HMk6asYBEVA+tUxrnB+BB6cWSpcfILxXnQHBlhF44UjNby6Fap3Pu1JKeOofGc7XF1xNE2VpiPlcAYdzGTRTDcXWGmPEDc+QOsfAtRCedV+02ZbonbgYW1RaGSZV/9EqBQ7UzcdI+iJXWTVOU5Elis/pjtRyNGZFkOXj8003ytBAIxWf0xxQqAE6iKWAr9FpWRHKJYW58yQNJxsWo7r0lvw/9zk9R7iJOGcS9XDMDYlCiVskBJmxt7jD4+jNmbJBOLRm0N7NFvlOVAVvLc2rB2ChQk+OVZ4TwO3JvrpyEBTrjEke7E0kTp8izOWmqqwwTyWzFhnqD7wNWtPN9avsKoSgEkow3QYf+jMJxfeFku2UQ==
X-Microsoft-Antispam-PRVS: <DB6PR0701MB299731881B2F9A15AB1F8CAAA0C70@DB6PR0701MB2997.eurprd07.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(192374486261705);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040176)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046); SRVR:DB6PR0701MB2997; BCL:0; PCL:0; RULEID:; SRVR:DB6PR0701MB2997;
X-Forefront-PRVS: 00872B689F
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(7916002)(199003)(189002)(13464003)(33646002)(116806002)(61296003)(7736002)(1456003)(7846002)(1556002)(305945005)(5660300001)(81166006)(230700001)(6666003)(81156014)(77096005)(19580405001)(62236002)(42186005)(86362001)(50466002)(586003)(19580395003)(2906002)(6116002)(66066001)(84392002)(4326007)(68736007)(81816999)(23756003)(8676002)(81686999)(105586002)(92566002)(14496001)(44736004)(50986999)(4720700003)(76176999)(47776003)(9686002)(189998001)(5001770100001)(106356001)(97736004)(44716002)(101416001)(50226002)(3846002)(74416001)(7726001)(7756004); DIR:OUT; SFP:1102; SCL:1; SRVR:DB6PR0701MB2997; H:pc6; FPR:; SPF:None; PTR:InfoNoRecords; A:0; MX:1; LANG:en;
Received-SPF: None (protection.outlook.com: btconnect.com does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; DB6PR0701MB2997; 23:Jy07QRqebIhlRRHfpPetkPxoBWBGuqj+/K9rUfIe0FaGRRlH4DVSEeT9LHSFrKFsILh7xqkPwvpNgXH/Zr7Y1cscejV0ND9mYlF7mJ07ymvFo95F9BlSufF/kTG12DcHcw/COhBamNHdTvCUSmPmv78fdtwPLdE0yK82M1d7/SDmkK3+arRtF/bCXXbaj0oy83tqBE3jNgvL733iAPgheTomNTgh77aLNcAXb9F2DuNJDRdrrJWqzzoELnjx8LXDkW8bxXTJhnEiB9ugEBxI4eDaTnh754fvJTBLjrWbqv23SJcIOS3CaE5y618/KVFnEZi57IX7VMiKT/ReXGfrKO5krYqd/Mdc44Tx6JUzZJydMhZ4MrQ1gC3Fy2EFgb7USNG04D32c7y9qtks0SphIGR0VdV9V8fyCTG+ulIabiCH65fTzQRPvEPqlpsC35B2n3tLFQ0DcRcKwJGuxhaztsudIwoFfrJ++RnoKx0iWzn9KIq/SAYWalqQrAlzmu9UaQ4mSbP9lElNCD4IxISENHs4WPL0vuKYNj+thq58oyEHv5T4AGcLWoMFJnZNFEkESKTAZyV1+Z8gIlteq1BeVLFPPEv0rnX3mKF+NQz1NHj+/Z+lU0XcZaS+nJZzc9tdNzV23rpBv2FJ6uDGjKABEVmNqYbwAYWa6irRsosOoWPteueI9mB415sWjXGrmEdFQ+KfY6J4Q2M5VAMvX3J14OFt9dhCUAcKWXmaSTRs5K65lFJR0/n1LnnNq8TrBDyEV4q5ksKxGXbWI5IYRvKxJBLvQIJmQ0SeSaaCwOLgxbT8mKZNk+yt2sMcXo82KEmVL+CZUTsCcJxkoSB5MvCxKd2A3vPAVrWeJs+X2liOpU53p/iRhacDP8+Z0mHclMVnwo5HyidLW+LzlPCm08BxlG76mcAF3phSCJWZ7VJS4fV+UXGBW6jN0M21VYnyByIkxYDPDBp5XMm91Dy0Mjuf/85OKDHRdB4ZIgJGBRQTkL5URyDXb+W/iyHe5k+PCKtwoWWGtqrkqrI8qu6ispcaz5R8CwZB+ttEz5LzLBLs9jux+k3vb/WUZonR3tkfgjE1OMjFwaxWMOwAJve5FEitK3p5d4nViyWWnK/CpW1uP/uExFcHK893ywFV/46CWyWuIbJfqXNhHNYK3gNnY8W55QNBeGgCvXKiF8wdE79ykj6lguiXAUeC8UtOjv/8TA8YsHhi0jt4GHjaHd1F9uIPUzWWQR93NffPCXGvIH43i0dh1gviAieNPY8ot/bCq4Jw7e6WnWYUAole4UAMgs2nV0eYe8rB5ZxKrSw823EVvH6G9D/+Yc3n9XpVNKZp8gMtm1ThVUCMCCNbsH9fPEUHZkkkYZszu2OBEuNhgWHQl0w=
X-Microsoft-Exchange-Diagnostics: 1; DB6PR0701MB2997; 6:Dn2ZSuKI59Y27exXUXgUt0t+vIK21fbD7LcixYRuVLW77slKZdUXxueTMmj6Lvnot7hNM4NGO4jAT6yuuOI3jNh42NEIgom+/4IPp6YuEgSrwgwmoyJjjS0Q8J/Y6GB8MtN/8uQB1TH0zdOoh9NI+x2gX3oevfLxsyVf60qyEfBbUjsCC6vTnpx9sr7jJ9J4AAwXnVW+OCqgfplQf5fjvppZFSbLGMVE03ib0badUsVXs1QHmPwqIBEvijaXpremESunKpPNrc8WwxROIrRXurJZb1o5NPGxXVwZ5sMfgkBYiigzrZ3bEwoeUb9dOG8w; 5:VD+Nkcf4vpXdgtzELxReb9fkRsT4WWX6Z1spGTbJvHkZ4/soXhwy9nqc/JbHqkgs5/yDPjtMhGwVlYc2sSHO9DT0kcc8XgCoHLb6n4/1yUi3SvpKgPEyNFJB0SAC2SYyvrJ6h5dfnD3/j9KuomtfceNhZ9dL5K+8mVjsppjkB70=; 24:wUUoRUEv8r/HMvxt6RjQuknpQgSSTgnzAsSYQNyR6DekKeJhtgE4lvPUObMrEvTjZjWIw0RtcR/LPE7uq26rWZR3I09xGC/7O5N1Yvp5scA=; 7:RXmlrZoDTQUg4jT6uN5WbZ64CC4kFg9KMZRPrudhAkCgRrXu1VZvAw+pH1EvMpRrvKw+W8JaMOjWQhsf1CmcMXD0axrNQ20KWhqW9ygMONT4UMKYB99qyU+MsKmij7Xbe5BJtXYfMeLgmiHh3qmko4cfz6x3juMaNC34dvjOfUMqkYZHf0Gtjd37Yc6czLxrbzXW6Teq2yxZLDFZiZbNGxn4EkqFHYGQ7gokr2zVURca1lc2A7MWDSHsv3oiRbwywww1sLcNFU7ZGjz5U9HilM2QSDvPpcJB+qlM/qKBk9ZdT3id9gD6DOZkvpQ1X2DicXYGXy7jioh3qpx8zMNgoQ==
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 06 Oct 2016 10:02:27.3456 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6PR0701MB2997
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/EzGr24IgnjFivAayYxydNedMmLE>
Cc: "opsawg@ietf.org" <OpsAWG@ietf.org>, draft-ietf-opsawg-tacacs-05@tools.ietf.org, "opsawg-chairs@tools.ietf.org" <OpsAWG-chairs@tools.ietf.org>
Subject: Re: [OPSAWG] Start of WGLC for TACACS+ document.
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 06 Oct 2016 10:02:37 -0000

Um

Alan is right to pick up on the style - philosophical - and the
security - lack of.

But do we want to change it all at this time?

This is an Informational document describing the state of play as of
some time past, perhaps not as far back as 1997 but not for 2016.  It
would require many changes to make it a 2016 Standards Track document
but that is not what I see us doing except that is how I take Alan's
comments.

The analogy I have in mind is when SSL v3 was published, long after it
had been superseded by anyone who took security seriously, but was
needed as an RFC to refer to, although it would not pass muster because
the security thereof was too weak.  It would not have met the standards
of the day but was published  despite that.

Tom Petch


----- Original Message -----
From: "Alan DeKok" <aland@deployingradius.com>
To: "Warren Kumari" <warren@kumari.net>
Cc: "opsawg@ietf.org" <OpsAWG@ietf.org>;
<draft-ietf-opsawg-tacacs-05@tools.ietf.org>;
"opsawg-chairs@tools.ietf.org" <OpsAWG-