Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.

mohamed.boucadair@orange.com Fri, 19 April 2024 17:29 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 37655C14F6A1 for <opsawg@ietfa.amsl.com>; Fri, 19 Apr 2024 10:29:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.093
X-Spam-Level:
X-Spam-Status: No, score=-2.093 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mV6HMYqOj1JB for <opsawg@ietfa.amsl.com>; Fri, 19 Apr 2024 10:29:18 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.210.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CFBAAC14F696 for <opsawg@ietf.org>; Fri, 19 Apr 2024 10:29:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1713547758; x=1745083758; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:from; bh=Ttm8hzTEkC4Wu+oIqY5xEEAXXk0anowMrppeMHqC/as=; b=W+Aq+1zCRu/2WuhbHHWnWfm8kMyE8LjvxyShXlSra/CrJVyph1B2EWPx jGaBgb0xGr34JOaTzNaRu1DUaHNJFGkCiUb8Gfm3dDEvHotYZopyBoeBK 8EcOG7biuWR6S7I/pjO09LHaq7N2DLJ8Di3xv8OazabU6eXJy8L9OC7eq 2DYurmFwguwo3OuUMsQluZvZE03jrdAgMS5upZcZKYYYotxk4U4qG5lKD 9Zd0QKMnEuRxg7YuW+oxaPlBb3qtcJCDDRml1l+O5JaiUU008mjwmNcee QVkWDb4HLOZJ24ySVXa3dxb3l4exUpZGNTDHhBiC2LK4n2m0SnQmXl2Df Q==;
Received: from unknown (HELO opfedv1rlp0a.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Apr 2024 19:29:15 +0200
Received: from unknown (HELO opzinddimail3.si.francetelecom.fr) ([x.x.x.x]) by opfedv1rlp0a.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Apr 2024 19:29:15 +0200
Received: from opzinddimail3.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with SMTP id 9E7065203C52 for <opsawg@ietf.org>; Fri, 19 Apr 2024 19:29:15 +0200 (CEST)
Received: from opzinddimail3.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 2DC365203CD1 for <opsawg@ietf.org>; Fri, 19 Apr 2024 19:29:00 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail3.si.francetelecom.fr (Postfix) with ESMTPS for <opsawg@ietf.org>; Fri, 19 Apr 2024 19:29:00 +0200 (CEST)
Received: from mail-vi1eur04lp2050.outbound.protection.outlook.com (HELO EUR04-VI1-obe.outbound.protection.outlook.com) ([104.47.14.50]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Apr 2024 19:28:58 +0200
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by PA6PR02MB10669.eurprd02.prod.outlook.com (2603:10a6:102:3d4::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7472.39; Fri, 19 Apr 2024 17:28:58 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::7398:1f78:30c6:e9f]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::7398:1f78:30c6:e9f%4]) with mapi id 15.20.7472.037; Fri, 19 Apr 2024 17:28:57 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.106.160.161-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=Pass smtp.helo=postmaster@EUR04-VI1-obe.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 104.47.14.50 as permitted sender) identity=mailfrom; client-ip=104.47.14.50; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: Pass (smtp-in365b.orange.com: domain of postmaster@EUR04-VI1-obe.outbound.protection.outlook.com designates 104.47.14.50 as permitted sender) identity=helo; client-ip=104.47.14.50; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@EUR04-VI1-obe.outbound.protection.outlook.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/51 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all"
IronPort-Data: A9a23:lIC73q2QK90chM6UiPbD5cV2kn2cJEfYwER7XKvMYLTBsI5bpzACx jcXCm/UP/aOMGWhL91yatuy9xkFuJKEyd4xSgVrqSg9HnlHl5HIVI+TRqvS04J+DSFhoGZPt Zh2hgzodZhsJpPkjk7xdOKn9BGQ7InQLpLkEunIJyttcgFtTSYlmHpLlvUw6mJSqYDR7zil5 5Wq/KUzBHf/g2Qoaj5NuvrYwP9SlK+aVA0w7wVWic9j7Ae2e0k9VPo3Oay3Jn3kdYhYdsbSq zHrlezREsvxpn/BO/v9+lrJWhRiro36ZGBivkFrt52K2XCukMCQPpETb5LwYW8P49mAcksYJ N9l7fRcQi9xVkHAdXh0vxRwS0lD0aN6FLDvAnjusZeq4W39a1j1/a83FHtvIrIAw7MiaY1O3 aRwxDElQy25377z/pPiD+5mi4IkMdXhO54Ztjd41zbFAP06QJfFBaLX+dtf2zR2jcdLdRrcT 5NBNXwzM1KZP1sSYj/7C7pm9Ausrnz4czRdpV7Tr60q6GHfxQ1r+L/3Odzad5qBQsA9ckOw/ TmbozqhXEBy2Nq30RWK7Xb33s70uxjpQa01COCh/KQ0qQjGroAUIEZNDwfkyRWjsWayUNdQI lcU0iEvtqM1skesS7HVXxCxu1afvgQBUdBdCfx87gyRooLd5QqDC2osSSJILscn3OcqRTswz UOEmZXlDDxqmLKQQHOZsLyTqFuaPjAOJHANTS4JUQVD5MPsyLzflTrKR9dnVbC019DoA2msx yjQ9HVmwbIOkcQMyqO3u0jdhC6hrYTISQhz4RjLWmWi7UVyY4vNi5GUBUbzzvYRLN2gYHm6p FsdpZLH9NpXEq6VrXnYKAkSJ42B6/GAOTzapFdgGZg96jigk0JPm6gAsVmSw284aq45lS/VX aPFhe9GzLZvVEZGgIdyaoO1TtorlKX9D4y5UuiONocWJJ9saAWA4SdiI1aK2Hzgm1Qtlqd5P oqHdcGrDjARDqEPINuKqwU1gOVDKsMWnDi7qXXHI/KPj+X2iJm9F+ptDbd2RrplhJ5oWS2Mm zqlC+OEyg9ETMr1aTTN/IgYIDgidCdiXsyo9pQJKLHSc2KK/V3N7deAmdvNnKQ0x8xoehvgo ivmBye0NXKj2yCYeV/WMhiPlpu2B8gv9ytT0dMQ0aaAgCN5PdnHAFY3cpo8Z7488+J/hfVzV eFtRilzKqUnd9gzwBxENcOVhNU6KnyD3FvSVwL7OmRXV8A7HGThpIS7FjYDAQFVUkJbQ+Nl/ uX8vu4aKLJfLzlf4DH+MaP2lQ7p4SFHwIqfnSLge7FuRakly6AyQwSZsxP9C5hkxcnrrtdb6 +qXPfvcjcTwmddptefo3OWDpYrvFPZiFE1HGWWd9ayxKSTR4mukx8lHTfqMejfeEmjz/c1Oo M1LmurkPqRvcEli6uJB/3RDlcrSJOcDY5dd1A1iE3iNZFOuYl+lCmfTxtFB78Wh2ZcF0TaLt pqzx+Rn
IronPort-HdrOrdr: A9a23:FMRP+KMC6n9/e8BcT0r155DYdb4zR+YMi2TDiHoddfUFSKalfp 6V98jzjSWE8Ar4WBkb+exoS5PwOk80lKQFqbX5Uo3SODUO1FHHEGgm1/qa/9SCIVy0ygc+79 YGT0EWMrSZYTdHZITBkW+F+r0bsbq6GdWT9ILjJgBWPGNXgs9bjjtRO0K+KAlbVQNGDZ02GN 63/cxcvQetfnwRc4CSGmQFd/KrnayHqLvWJTo9QzI34giHij2lrJTgFQKD4xsYWzRThZ8/7G n+lRDj7KnLiYD29vac7R6d031loqqh9jJxPr3NtiHTEESutu+cXvUuZ1RFhkF2nAjg0idurD CGmWZbAy060QKtQojym2qm5+Co6kdQ15fvpGXo/UfLsIj3Qik3BNFGgp8cehzF61A4tNU5y6 5T2XmF3qAnei8osR6NkuQgbSsa4nacsD4ni6oennZfWYwRZPtYqpEe5lpcFNMFEDjh4I4qHe FyBIWEjcwmOG+yfjTcpC1i0dasVnM8ElOPRVUDoNWc13xTkGpix0UVycQDljML9Y47SZND++ PYW54Y4o1mX4sTd+ZwFe0BScy4BijERg/NKnubJRD9GKQOKxv22uzKCXUOlZKXkbAzvesPcc 76IS1lXEYJCjPTNfE=
X-Talos-CUID: 9a23:bD38U22VsLq99rMXMOWP5bxfOcB0cibk4lfrO2yhNzwwUIfMVmCIwfYx
X-Talos-MUID: 9a23:H4b8sgbBBpwXs+BTrxDjmzU5bOZTxZ+8EW8qjcgfsZPaHHkl
X-IronPort-AV: E=Sophos;i="6.07,214,1708383600"; d="scan'208,217";a="33546069"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cZ5Lzq7FRuhXeqNI6qGNl+BmbVlVeEU/MM4YZWC01pLuNDj1X/QsIxaMgcG/00NMqwY0NA/LW5jGnfSSJFn26odSy2zbh0wCRDadg5ZQYeqXhajuvq0fTxB1XNnjHjskiTXEeb0jksGozduGOeHfEJgi7R/QBkmCcGDrsEPz6siz8//B5kiOlUW27sW3iTYyE/P3EJ4Rb6qTy94svWsN1EqvF3Jq7XrhR+cYxm+z7R+lz17MwmdlZC94yIgC99rdY4Ti+nfuAJ34YL/vHFMEFAo3tzG7/ssPAcTgP5f+mZwsPdz2tvEhK1R25bsjG3EpKEApRVg+RaPcQBlhKoD17w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=OGRd8vMqpbY04AZOR6wYZflFshmVh4jD3cf9eKUmQNM=; b=SAVwhwKhRohJuZQaAMwxx3Z7ORB7oD+ZYTetmwGIoaRejtOL8EedSaRqOcSHI+DIMo7NW3mTjckAq9HUwtxDI2Hgjjc3CHpO8QIsRpnaouy/5uvSVOZZz6h7qB8peUmFx+INuu9ZHMerYQfx6d5sM3V2rjVVmPiTqjSYzUlPIvqlxYvIIwPUMnZ+K/vposUswdFuNI6sM4AtIxWSnJt7g8gBapFC8ucfvRjC/AGIoZ0eVRXtMtRqwX8O1WeLF0InqTb3dgSlnDBKKVty2i08xBpLKhsoLcrfswA/7hlE62h0rSYHTDNaTHouFPo4TdGQkCUWjtNgYum86u4Q9DlUHw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: "Douglas Gash (dcmgash)" <dcmgash@cisco.com>
CC: John Heasley <heas@shrubbery.net>, Andrej Ota <andrej@ota.si>, Thorsten Dahm <thorsten.dahm@gmail.com>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
Thread-Index: AQHaknkV5UFry3XPykaOc/4zi7RiALFv0X2g
Date: Fri, 19 Apr 2024 17:28:57 +0000
Message-ID: <DU2PR02MB1016055635A500C074019FE3A880D2@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <171094844069.8406.1730131072887926375@ietfa.amsl.com> <BL3PR11MB6364F94772DDCCC57DF18748B7332@BL3PR11MB6364.namprd11.prod.outlook.com> <DU2PR02MB10160514500051EDA4B5D1441880F2@DU2PR02MB10160.eurprd02.prod.outlook.com> <BL3PR11MB6364B8968DE1CC0E83600660B70D2@BL3PR11MB6364.namprd11.prod.outlook.com>
In-Reply-To: <BL3PR11MB6364B8968DE1CC0E83600660B70D2@BL3PR11MB6364.namprd11.prod.outlook.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=True; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-04-17T15:33:41.0000000Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|PA6PR02MB10669:EE_
x-ms-office365-filtering-correlation-id: d7ba7517-974b-4a49-1c7c-08dc609631f7
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: AJeu6F29l8gNQvr5mXkigyJuhdXzltRAZNY7z/olLSEFBNIjZ9FkkdJ/9O91OZYYZ/LN6LR9lzcfIk613P21yu4upq5L+RWtBjNNrNQvuWftwxqhlib1ufmOeAK7jeLIVclDo9hxNVa4gRbm+Fl3kuUwzKehiLcI/Gc7vC3Jpf3MnLAJ9em23ZIycskOpviDMfTF2A6xJI1rF6Iy86AMmeDv5uu8KQSHu/LmFZ6OsAQHomvQIcO8TO7194SlIAJkyS6r+9a/D/YcaY3z+R/bM5crrMS5N483QrV9T5HIyHh4bLg1SbukzqqE63fg5BzGcy50yhsdjnqCe7ytTofheP1KbY9HeVF7qdVt2YaFE3OSKSziAZP530UCTbZFo4ZX6ZaBqF7JAI2Ra8NXQ0tF/jOA6MhwyDWbIPq+aMymmzNc5Kft5RAvst8yMuGfhJvpaniDQ05m/qfMhZKwGU/USz+cWFlSOFw0lOwfocpjmyBGYFmExVLxAs+afSYfod3NZKp89bNXco8xb2K1hJNeVBnLYSoMt2xPSitdjH4BnsbWZ4AV1oagZSuAvPjdJNJDf4ShddA2ugkmCxP3A8i+S45RfA83aYPylhfNwI13uAGA1Q0rDyRMLzRui+C0trJZmsy8QhA3h5A2hJVvOrhPPIic8DA16eE+KU5HbqerlZg8IVpdAvmpC5Vk3OI48KWlh27oJXtyMz5D193gDFyvNAcyUcSVit0I81X4pScl8hmHk5ty/9wf4FfDUehwGeQuvMRaxy8kkTkaBwpvOrajkpww+9g1mJyw+eIV7j7LQlzCxLhz5dehk9PFs9dIHFBtwe8dOq98fXGv6q0k7Pfj+uAe0wIeoN9h2XcjbYnboIbUjVFbkv4kv9Qev8K+Ph0tUEd1Xl1UVCgrcsbl0AJShKI5sYix3V8E7lINApcwOL0FHrlPEqWNF1yFZR19XHXFIgXTXUJow9PlOHK9mqEiieNhj1Ho7ENcgEvSjArbQs6zOgxH/0zOCSj9Rcs99j2WJIqCLsxFo0FArF//YrYqW+pFsiNelWVu1O81CAXaGqcwGzZrCww0Ahi+bAm2XDrE3Yvm0ABoocfSkfI3MO1PBp98zww2gYh2/TiMsCaSy0FIN3Nqs/9EMBykXbnjHbr9jsiniatrKsG2UPPBs23FzKmhEWr4CnntD0kVBOogdftyodZz8gTnG0jsu+XuCjZeA6XK63OnCXCsjgZimDEfgt/h/r5gYZi29MVMLve6aaJDpyr0VsNebrEoolT7cUdrC5rTTvu7kLiPNGBmffXzM3D/EhDkSrti7zcgwz3Dnug=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR02MB10160.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(1800799015)(376005)(366007)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: fWfbd6tMQVTnlqUoAn28QVvIw/xHTNPjBSWEcJqvSoCyHB/fS2f8dybZ7fmghpvH7X6xxkh0CYVAiRkJvr53QY3o+xlVm7/Rf9Me5WVpce40DdjUNXyVbduLnX69KBvGnytS6FDbOl1bhf2tNYyfIUb9MdA3lJt9ayGhVbEDjCwrRit1/pxc9iQY/WtD3wR2dV5/tCQI00rixZc7ysHc9XNz7ckrrV7ZhqpgLHvHfvaP0KvcW64lrY+dxEMLZHlgf1IfXRIHx826uPWfElKurXRYfu/QQXFj4gvuygI+zgGqjzOtuwHwalH0Mh6t/6g/nkfNjVMyaE/vj70LxkqGNmnljBCylGeuyCQDEw9T6+kckC2wh3NN0zPM9jGrhN9/iRd2Q4QBFUFA0ZVAPV48zmqJqpLPQOQGE+OKY1DYsQCUbReJkdTo+9AE0P240aLCxrYUIr/1QVy54ts13fwl6BXonQvCbTiwF6E33sQP5zatj2avwTXOWpQkD4ysIDTOlVM1W14L/ZuZxxMdtgZPtR0N764FzHlxbVYO3DpigaT5h6q9WlnPk+6XCoKrKXb4FtGMKDaThspaWCwMPxjs9OHwaZzsze3GZ8ff/nWh/ZXG9efoebb5X6os5Dcd2CvHbV5rUsd5doqxJSQ4lhWz9t7lfpqx57EgPxCci+Eb/12QcDCSPs21CsdRWYLq+LOyzCmeYTw7bZ0bZunujJMxmfvE337qQcGb7K3D6z6v/BgTRc3Ml+tB4JzJVmt2/5C969VK29Ep6QqM4T7ZthB0PZSe4ubIAySKFihPhLnNLwauLfdZcmjoW2guG2/xj+tHyobq8+nz8jzJAu0xEAlWVRII8CDewqJHfmfx91DhCmLYiCcsOXswANiGzRLrjuEtcnJ4hYd2q5pUlfjFGD8ghW6CxAwELuJaOemFYVpbntKM9v1mMN2AWu2OuiDF+iDQ6T+c06s+HOQ31WGtDhCi2hlQnHXNvYApkVBvTCvtVMGZRkU6/PHyqkEuLmlTSE9z3K20gR/gIzWWQGGrBzBP2cTvlgg2pUZruyzzTOM1C+BwyQboC6COdbu7sKKkm7vCNWF64iOSj9g7hOXTZuOMNgq5ZWNdWWgcP+xzvRhwrc0+WfxXJ/0aUUOF1Uq4c41GrhDMYHbf/J7KxfmlTkdV8SX3BgTAAXxQGBFh51e/jzkG9CWZD0us6asfRJRo5h9bLp0LG1AcT9hpUskfIDy/FFXdEMg3swxOvy6CbqdQDiFAgSK7Cza6JloX5cKtY3vmQF0KFSVVvCJY2CppsIphFqjcZKFXcF4brtStNKvDJaGYIXBxSTmbqJ7K9wwKRIX3fn7ds6sekytwxs4Js3l2nZV7ByVbTVXdlO2YQJKz6jLGN+QLudIeBN0+Ik1nMFpE98wksDj2MfypHkMEZoyu2wZioqRVoPMSV5TCa1yMXIkDHTQbpSLvaJi4vMW3FsmI+RgZhQ0WE9g6rDcRrfbQPHid+v1qqII9Of3MzJpVWU2CVeux+JYzCPj6d/r7GQwURTfp8RBDhDUCAjp/LVYRDMEhL1h5CG0tV2jI+LnNMmN3T5njYIHS3vnWdRfkOoqsfOZdy6y4ibdf169i71tW3g==
Content-Type: multipart/alternative; boundary="_000_DU2PR02MB1016055635A500C074019FE3A880D2DU2PR02MB10160eu_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d7ba7517-974b-4a49-1c7c-08dc609631f7
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Apr 2024 17:28:57.8789 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Za3La/GU4c/PBc9UqJhABMxjYLBNmWY7F9Q0fD6/XYNG51ud86RwwiASKdoDSLwxoEuus8liCupsH/3fQET7Vr5Z5XmBzhDD84rwL87ojWM=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PA6PR02MB10669
X-TM-AS-ERS: 10.106.160.161-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-28332.001
X-TMASE-Result: 10--35.743900-10.000000
X-TMASE-MatchedRID: 7u3eoxEoplDZU9L012+8KrdXJOYbkh1avHKClHGjjr1vQ1w4VLB58jAD TOtbgClvTledWAKUpYott0wTiNVCj3jRl4N3GbMPav0c60mfQvsK3Ma88LL+bgv/9UzFeXITE6Q 8W/07bcqbQjlD8tgVWr7O+YHGOXsuTJvoTQPDohG1TiWqZWCoj5Ak4Vz6rKor+VJ6lZyB0s8oW2 Xbi4hX2/GG5PZMzxFolC/Kpkf0iefaZVMiCHsG8XHPBvSspzfj2Sa33ZGXWdaZmLDnd2pI3z3jh zzlBjmI/NfdZbwLczkV1YFs2RGT9G8gRmAK2/cekumURBPOKgIIoUOTWQl7ErqGBW9J0YqjKIhc odY8l2H7GPGzY5d4BgMK9XdTA/p4o4vCb3thAW2PnoiNOctH6X2/y3jJprUQTSz0JdEAJbQ2rkd TpVyUQfFL2at5iqkWJ5a9ikCjUSQpvlwsQRN0bEy1Gp6wlTKh+HOeNEbLAokdT+C3FmuTE8dUJ/ J9esv1xnUXzyseixwFygwpXlHIIN4060OX1gzQLvv2cUtLK/sM6z3iDvziB0hMRy+qNwXgS6Qiz eDUeN52PqBW66jvyfIRpGbhvZ1fpHlO2q6rss4VEVrDTaghS2gws6g0ewz2Uh4weWPqOWSeEPi9 wVyFrnPELICp7p8EfNFddAIkgiPslFFu3rcIwQ1ut4qW8n6DmqdQuKXkmovQ2dRRUyVMpjcVUt0 cYK5uXd1Z+c8DjfkNUPX9GaIKHsfwdC+VMLcVzt46wm6+XFMw+d7medOXaOsl5dA8uaDLzThqPh GWj/za59jtQMEidN5xN1m9bHhVPXOnTTE//dhJI5ZUl647UMBX4Iey09T4Vb3rZjw/bpwUyRS/O CD9xZUdXE/WGn0FuJhoZaSpA56RX0oTG5q4N+JGF26G8SWy8lP6F/raTZghtlJZdlnnbQ==
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: 1ed1d794-99e0-482c-a781-245d784ecd41-0-0-200-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/OLhGWZ86dcLMxJI720wHfDdPhiY>
Subject: Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Apr 2024 17:29:22 -0000

Hi Douglas,

Please see inline.

Cheers,
Med

De : Douglas Gash (dcmgash) <dcmgash@cisco.com>
Envoyé : vendredi 19 avril 2024 18:46
À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>
Cc : John Heasley <heas@shrubbery.net>; Andrej Ota <andrej@ota.si>; Thorsten Dahm <thorsten.dahm@gmail.com>; opsawg@ietf.org
Objet : Re: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.


Hi Mohamad,

We are working through the comments and enhancements that you kindly sent.

There are two comments that we'd be grateful if you could clarify:


  1.  BMI10: "What about raw public keys?" (on: Implementations MAY support TLS authentication with Pre-Shared Keys): I'm guessing this relates to fact that, as we mention only PSK, that this indicates that we mean to imply that non PSK authentications are not included. If this is the case, then for sure, we will clarify that they are. If you have something else in mind, please expand, thanks!
[Med] Yeah.


  1.  BMI16: "What about configuration of name/address/port number of the server?" (on: Certificate Provisioning is out of scope of this document.), would be grateful if you could please expand on what you had in mind here
[Med] Clients should be provided with the IP address(es) and alternate port number (if the default is not used) of the server. Clients may also require to be provided with the domain name of the server. Also, given that you define "tacacss", do you had in mind to use that for service discovery?

Please note that if a name is also provided to the client, then you may indicate that the name will be used also for rfc9525 validation to compare the domain name with the certificate that is provided. If no name is provided, do you assume that the certificate is

BTW, I wonder whether you need to indicate whether the certificate authority that issued the server certificate will need to support at least DNS-ID and SRV-ID identifier types? I don't think URI-ID is needed. Similarly, do we need to include a mention about wildcard "*"? I think it SHOULD NOT.

Feel free to grab whatever useful for you. Thanks.

Many thanks!

From: mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>>
Date: Wednesday, 17 April 2024 at 16:42
To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, opsawg@ietf.org<mailto:opsawg@ietf.org> <opsawg@ietf.org<mailto:opsawg@ietf.org>>
Cc: John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>
Subject: RE: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt
Hi Douglas, all,

Thank you for taking care of the comments. I managed to review the latest version. FWIW, the comments can be retrieved here:


·         Pdf: https://github.com/boucadair/IETF-Drafts-Reviews/blob/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.pdf

·         Doc: https://github.com/boucadair/IETF-Drafts-Reviews/raw/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.doc

There are still some points to be fixed, but I think the document is getting stable more and more.

Cheers,
Med

De : OPSAWG <opsawg-bounces@ietf.org<mailto:opsawg-bounces@ietf.org>> De la part de Douglas Gash (dcmgash)
Envoyé : mercredi 20 mars 2024 16:40
À : opsawg@ietf.org<mailto:opsawg@ietf.org>
Cc : John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>; Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>
Objet : Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt

Dear OPSAWG,

We have uploaded a new version of the doc, primarily to address as much as possible of the comprehensive review kindly submitted by Mohamed Boucadair. We thank Mohamed for the time and trouble taken to the review the doc so thoroughly. We will be happy to discuss further any omissions or new comments and rectify quickly.

And we will endeavour to respond ASAP to any other comments of any kind on the doc.

Many thanks,

Regards,

The Authors.

From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> <internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>>
Date: Wednesday, 20 March 2024 at 15:27
To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>, John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Thorsten Dahm <thorsten.dahm@gmail.com<mailto:thorsten.dahm@gmail.com>>
Subject: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt
A new version of Internet-Draft draft-ietf-opsawg-tacacs-tls13-06.txt has been
successfully submitted by Douglas C. Medway Gash and posted to the
IETF repository.

Name:     draft-ietf-opsawg-tacacs-tls13
Revision: 06
Title:    TACACS+ TLS 1.3
Date:     2024-03-20
Group:    opsawg
Pages:    15
URL:      https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.txt
Status:   https://datatracker.ietf.org/doc/draft-ietf-opsawg-tacacs-tls13/
HTML:     https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-tacacs-tls13
Diff:     https://author-tools.ietf.org/iddiff?url2=draft-ietf-opsawg-tacacs-tls13-06

Abstract:

   The Terminal Access Controller Access-Control System Plus (TACACS+)
   Protocol [RFC8907] provides device administration for routers,
   network access servers and other networked computing devices via one
   or more centralized servers.  This document adds Transport Layer
   Security (TLS 1.3) support and obsoletes former inferior security
   mechanisms.



The IETF Secretariat

____________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc

pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler

a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,

Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.



This message and its attachments may contain confidential or privileged information that may be protected by law;

they should not be distributed, used or copied without authorisation.

If you have received this email in error, please notify the sender and delete this message and its attachments.

As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.

Thank you.
____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.