Re: [OPSAWG] I-D Action: draft-ietf-opsawg-tacacs-tls13-01.txt

Marc Huber <Marc.Huber@web.de> Thu, 01 December 2022 18:14 UTC

Return-Path: <Marc.Huber@web.de>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B2F65C14F719 for <opsawg@ietfa.amsl.com>; Thu, 1 Dec 2022 10:14:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=web.de
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oHTpFK5wRliC for <opsawg@ietfa.amsl.com>; Thu, 1 Dec 2022 10:14:25 -0800 (PST)
Received: from mout.web.de (mout.web.de [212.227.17.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E4009C14F6EB for <opsawg@ietf.org>; Thu, 1 Dec 2022 10:14:24 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=s29768273; t=1669918461; bh=f2Cjl5+hBv56VsFy1bCkVXr6i1027KAhgYbMGQ4FzpQ=; h=X-UI-Sender-Class:Date:Subject:To:References:From:In-Reply-To; b=B1ZDEdA+79VvkVM+dt7OfVG64ScMp6fvHPpu//OANHCVYWLelZYhw+QMIDvvO8NmT YpdcvgJW6Gkv9V93AdJ9syALzso9Lff/eN+y4TZQMr7C7B2T5DQ5v0q34UfNriGAKj uGR84oissiJtO8vVgg82qxuPN8Cx//xT04LbuDiK1XSQ+J+y+O2HENY17A+SxG4XvL JdG1VvLxaYpxtp05KrMy0hocM8QpSaQk3onDYt5KI0YkqkCS4S0mPhnJqjeEcaemHd Q9zLEzjxniq9mlvacsdMJTJoxbrFgx8ZbPHD4Xt8C2FJBaCC3x0LCLg4VmyntvVd3F M2gxOg/9+Y8EQ==
X-UI-Sender-Class: 814a7b36-bfc1-4dae-8640-3722d8ec6cd6
Received: from [172.16.0.4] ([62.225.218.46]) by smtp.web.de (mrweb105 [213.165.67.124]) with ESMTPSA (Nemesis) id 1MVrg7-1pSTOa2MGz-00RkDh for <opsawg@ietf.org>; Thu, 01 Dec 2022 19:14:21 +0100
Content-Type: multipart/alternative; boundary="------------osu10fWYuakKR6qyxQeRczgn"
Message-ID: <43ee82a3-c554-a4c3-cbb0-4525dee143b0@web.de>
Date: Thu, 01 Dec 2022 19:14:15 +0100
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.5.0
To: opsawg@ietf.org
References: <166987104468.50685.985158519755735069@ietfa.amsl.com> <Y4g8SzupPkBSLotd@shrubbery.net>
From: Marc Huber <Marc.Huber@web.de>
In-Reply-To: <Y4g8SzupPkBSLotd@shrubbery.net>
X-Provags-ID: V03:K1:FiNuTITSmx9OSNvFZ4cpkN81wnf+i0GSmJ8KBDN83EY49wdmD1j guZOygIe2DrL6OmfaCZkL4r6r2EydRsbG490VaWwThACioZa3/bH3V+m7N49delbqkcc+8z uiua6w0Aiy60US9pvdslWTxWi6eLvE08lFLu+8Q9AtaE9AgkPXE8WgSWt4w+1DPI7E3NPSc klmmVAPK5yMzePnXDCM0Q==
UI-OutboundReport: notjunk:1;M01:P0:ibUPGpIZDlg=;blbN4Sq9CHx9FioD+bU2wwZnZXh DaqRIexhG+yChfKuL3kpG1JAnMcBk3VA3a5IL7QUv+bFaN9TzZHzIulDpm/D+kmD7uI3pXYG2 Vej/1bLaXT4eOFIeqKy+XHYz2NFUvQdmZQNQSH9l7FHTiL5dMLJKohdOM6zDpxu0COKnGVhKt 2tRiha8w8MnyC6HCX5mMCugCiFzTSvg5q12ob/FHZ3Vhtp3Dendc7W2AqCggQ36MgP1/xWrPM lspCnoZia/VsVkZ0oIRug/9ypPszAxgiaPemL/W66v1XwQOTjxxQHqiz6DKF+upzClvg7zRK7 EmCNHeAIRA//XZEeQqOeeYjG2oN8jQKMChu1xV2o7qizLu/2IS/auwFuu1/Pey/ipqBpz+RJT +8GvGT+ra1Q7pbJmWM0Mcqj68O0omM0OAE0spTGrpBmzUJ1S8MNMyOrYsKquvIJwgoBpTl1XP 4Boo1tDF6UZjBNdmP/rIfNgRdJHGtmpgodhEtlaowh3VUxrQfiWRQLHflSCyWSlmsSavZ+V1N BMd9f4+sH/LMhdqumUB6wY/evcSu6rR/S9axflCT+5t0e6M96Os4bwm3fiRwkkSJhT+JmtLoI xn3G6cngK2CI1mI+6UoVVsUep3GPE/wf41qFhXOJWvuxGmQ+CLglDCAHcQVwaUBhzsJVYXB1o uKJYyyNSfkoguRSnEUgX5MTKRBXjZ79bsKDSmk30lXEk53jOidCR0FBos4VVR3kjdOcWVb5vF Wbo3wLyEDYTBcdWUlHpqa2E83irAdfGsLPOLHyMgfXa6Ax20taKrCTNtPRmR9YoxxvRQiru64 rMKKgSV+N94fMJ2PwGEnw5qPkvnlDeF6D+WJoC67RQhLxfxX/gBeugWxx1pWGuKQr0JeJmjny Y6vUD5+vYMP70MraRWNK/EWEbGMT2VzvySO3o42Lw02qV7i8JVNoUA3w2yke7rRKy4JMcg635 gHTzbITZSitPot5h/Yang93zSr8=
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/a8S6hwmU2ubfRjFpTGM33dEJtuE>
Subject: Re: [OPSAWG] I-D Action: draft-ietf-opsawg-tacacs-tls13-01.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Dec 2022 18:14:29 -0000

Hi,

I've the gut feeling that

    Peers MUST NOT use Obfuscation with TLS.

    A TACACS+ client initiating a TACACS+ TLS connection MUST set the
    TAC_PLUS_UNENCRYPTED_FLAG bit, thereby asserting that Obfuscation is
    not used for the Session.  All subsequent packets MUST have the
    TAC_PLUS_UNENCRYPTED_FLAG set.

    A TACACS+ server that receives a packet with the
    TAC_PLUS_UNENCRYPTED_FLAG not set (cleared) over a TLS connection,
    MUST return an error of TAC_PLUS_AUTHEN_STATUS_ERROR,
    TAC_PLUS_AUTHOR_STATUS_ERROR, or TAC_PLUS_ACCT_STATUS_ERROR as
    appropriate for the TACACS+ message type, with the
    TAC_PLUS_UNENCRYPTED_FLAG set, and terminate the Session.

isn't the best approach. This would break the transition process
compatibility for devices that don't encrypt on their own which move TLS
to an intermediate system (a reverse proxy, essentially).

This might be a corner case, but I'd prefer a standard for
TACACS+-over-TLS that just leaves the TACACS+ protocol as-is and simply
encrypts/decrypts. TACACS+ over TLS shouldn't behave differently to
plain TACACS+.

Thanks,

Marc