Re: [OPSAWG] draft-ietf-opsawg-tacacs-06 Contributions, Status and Plans

Robert Drake <rdrake@direcpath.com> Sat, 13 May 2017 17:24 UTC

Return-Path: <rdrake@direcpath.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0FFBB12AF84 for <opsawg@ietfa.amsl.com>; Sat, 13 May 2017 10:24:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.012
X-Spam-Level:
X-Spam-Status: No, score=-0.012 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=direcpathcorp.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pdOkf2CI9UVz for <opsawg@ietfa.amsl.com>; Sat, 13 May 2017 10:24:11 -0700 (PDT)
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (mail-dm3nam03on0050.outbound.protection.outlook.com [104.47.41.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C1B3D127342 for <opsawg@ietf.org>; Sat, 13 May 2017 10:21:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=direcpathcorp.onmicrosoft.com; s=selector1-direcpath-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=HIZTSBShrplTl31QzEjYtbvzQy7zHkrQCwIcnMzgl5Q=; b=JXuIXKKFQwj1euSC0mK5VD5/qnPTOBqLU2HhfLVRhCj707sGdaK/HjSJgUguHMxKr+bxUGIxoa973CXk/4p4h2Mjk/oljQPTfC5wfrzuNWNdolFlDgsIFsD5rccgRNVGJHPnIj+r3/jePHSbpYQR945g98+7rJUyOPkrGojdZJw=
Authentication-Results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=direcpath.com;
Received: from [IPv6:2607:f1e8:f0f0:5:a055:bc88:8ab:56d7] (2607:f1e8:f0f0:5:a055:bc88:8ab:56d7) by DM2PR0101MB0893.prod.exchangelabs.com (2a01:111:e400:3c04::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1084.16; Sat, 13 May 2017 17:21:40 +0000
To: opsawg@ietf.org
References: <D53BBCC7.22ECC8%dcmgash@cisco.com> <61D9FC7A-6F10-44E6-8400-578C4FEE1988@deployingradius.com> <D53C62F4.22F82E%dcmgash@cisco.com> <E7D62944-46B9-4091-BF16-0AF8CA47626D@deployingradius.com>
From: Robert Drake <rdrake@direcpath.com>
Message-ID: <733ad85f-203e-e252-046f-402af2f230c8@direcpath.com>
Date: Sat, 13 May 2017 13:21:43 -0400
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.1.0
MIME-Version: 1.0
In-Reply-To: <E7D62944-46B9-4091-BF16-0AF8CA47626D@deployingradius.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
X-Originating-IP: [2607:f1e8:f0f0:5:a055:bc88:8ab:56d7]
X-ClientProxiedBy: BN3PR03CA0099.namprd03.prod.outlook.com (2603:10b6:400:4::17) To DM2PR0101MB0893.prod.exchangelabs.com (2a01:111:e400:3c04::17)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 0a0ecd41-9259-42b1-0a57-08d49a248516
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(201703131423075)(201703031133081); SRVR:DM2PR0101MB0893;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB0893; 3:IUqvjmtCY/fCvALKykaQmk/QI2WFAr/YYVKBIFn255ISWWwU8nB1MR77mRKjlO+fotiNkgbILv8dWKhXMP1UJvf7ZmiQUkHS9KXfRXNrlXpMWSgyt2B4WZPcbmXkao9PlfjF2gNMyLaOcCAVf+Kk80QeCDkNcQ6/6cCu2IXTZ8emqY7AJdp8d01df3KWKMUABw4ed50xsEj5u+NYxQRCEDespquTsTl+2AGyTGdwH0NuyDvgj9uc97/gHMumcZyPh2tOq/b+zZI2TPnFEdgzrqbWtmmc3InAsoOKekONBk3ULAM5WNcKv9xlknkpJ5sAkeroUhLarSb19JgUp9EnhA==; 25:HvPTIGuCRVFYpKq0AStZp6PHFsHQ4DeicIoKfVabBVASm70azTCjwTsaNnLv0Mg0LAm+PcoEJ5eJzWAt7XC+gtWtwvb3WtANV6TFcpGASa9ghhAgK4fWj7Gwm9/5QNThOuQjsl4uoeICsKMG0jcgRIehPOGGRPCGR6kvT5YspYo5ybrLuOBSzWNMo5HdZgFu/DsuJ+XcVNEbygDnHLZuA2Vumsq7EzQKqW3WgNiBKhgj15DwN949vLV8H4Fjv2gNBA7KDshPKmkFCxdzL5xTfin/vdpy3VtcUMAFilaygF/RUafVC4x5I1b+FgGslgWr/YXUsJyezaRmKH2o0DayZhbxLyy+1ASgj6Sqgf+sdIfjCcbP/w4H99/MuSUI6ikn9DzlusDSnjg+XitJId4ht5xaGB/M2jSU6NxYLeygi9OhyohRjhOQnhHqI34wyfTHyhqa1JG6ds+b16hvo53OPcayiwy7IwVNUArOy78B9+U=
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB0893; 31:eJ9xkvk+kNhRBxVU16zFq6roPfBhdh47oBqdYAQzcrwmbYHwAsD7eKScpW8ADPWS+dcLKFNsxJDkox8pdk/bFxNpBYKj2iLjpduYAlsWx86gT9Gu/Qde5pCUzjjaMwGKTtwv2wXpovohv32nWMzhkI0vbk6BTHEDZxUpCxXPSdJikGqmtMwR4TVY9y2zJmY/W3Su7XYP5UXjFnEbIMsVizQYXgplyKjnfee7J6EiQBmVUr/Y/98sfP1LGy1THE7EsZeKRuGGuFu2WDWKDFUZ9A==
X-Microsoft-Antispam-PRVS: <DM2PR0101MB0893C8C9B48CB740B6BCBCCDCAE30@DM2PR0101MB0893.prod.exchangelabs.com>
X-Exchange-Antispam-Report-Test: UriScan:(788757137089)(100405760836317);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(2401047)(8121501046)(5005006)(10201501046)(3002001)(93006095)(93001095)(6041248)(20161123555025)(20161123560025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123562025)(6072148); SRVR:DM2PR0101MB0893; BCL:0; PCL:0; RULEID:; SRVR:DM2PR0101MB0893;
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB0893; 4:j7mDE3+0eYFkgJ2iALqxUzraUusDvturJSgS3F2cfEKd1KNLepp+rVBe+fBTeEKj/za2zqYQwUWZ9EaGIjqqTDf25BXo4p8XSyjBFRXipo72aQDrJddacWJc6kPfX0GfHVSLyMY9FppQiET6zkVoOl2aRAKLYM9a6LzuKGjHyyjgAsNo2gMlvUv8feVZePV/R8RTpnDKO2ypu4l/+hWVKbwr6SJUmvtuZyA15O60v0XwSjf2m3GgFcCbAj1ed4pEHbuxXdVFLcEM3o6Unq7IgOC33xIAOypClSdt68l6R9pDnhu9w8Ut+GPthKOtJ8U/9VrMFaQGS4neHnnRquRH/JkFsuz6Ib0NuBxjO7gkS5N5OaOntpgjEWXcyPgUx4RijqPudI0Z3FgywIPWEHDwY2y9a4bgLPd8z2srpB65QUeeCL5Mip2u9GQD0xme7oNR1iSvVcZ+0kCbWMk0wNRQff63vIb89IFadI6iUIR/EaExoVoPQWKodvjyPuuxqAf5fHY0/OydVZRl7uE4WFUZXp1uUEwN87L3RjmDnaGhD7UEy1efxHjO8rk6mLcEXYtEWVWzT3alaFxH9juf3RQ8jvvbe+kXA2MCAocenK1RqVUJKQGIicHuK4Hh5HBAqeYwLhqtb6kqn57wCqEJoSdGSCazfuyr5fefXcVehNt4F6hrQgG5qYByHLj9GPHncjR9+1WOf9nq6sCOqkI+bFDkj28jcm2/NLjVzLqV48dPohjdYeevpPk4sq3NapXtcO+tUVPoc+rfKI/aocGgOX2h2/xKVgTOa82xZFkW57MOBFbsSfMlezC++wy+/CAbUzSs9Z8TNbaA1FSKY+DRex8AjQ==
X-Forefront-PRVS: 0306EE2ED4
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10009020)(4630300001)(6009001)(39400400002)(39410400002)(39450400003)(39830400002)(24454002)(377454003)(53546009)(42186005)(25786009)(36756003)(31686004)(33646002)(6116002)(86362001)(305945005)(2351001)(31696002)(81166006)(230700001)(8676002)(7736002)(189998001)(6486002)(4001350100001)(50466002)(64126003)(23676002)(65806001)(478600001)(47776003)(230783001)(38730400002)(93886004)(110136004)(2906002)(6246003)(76176999)(50986999)(53936002)(54356999)(6916009)(229853002)(83506001)(5660300001)(2950100002)(65826007); DIR:OUT; SFP:1101; SCL:1; SRVR:DM2PR0101MB0893; H:[IPv6:2607:f1e8:f0f0:5:a055:bc88:8ab:56d7]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;DM2PR0101MB0893;23:1NJVwdFuVI6UkjbbbSz8YLpAEAkR3VvEF+a0YCtLKM9a1QcEh0I8AEOoVis3NSjmvVkP7drD7rZIVmPZOZQ5nTD+GLxaY9cIKzJfedrawguZfy5ziDLKHOhFWTnK1Dyd6ZOFuPt7ekChMyZ/YnmlRCuRwdQtD3YhGHXQ/cMuvceB02rIFdC2XgaP9mEN5pUZDmc5GrEz4p4mkmuPQ8wGXaqAkQCoYzkvoOTVhmtQ+YeVgNc0hSge3YaAILWl5D03BxU16Ba32u3x6vkRV0CTBKK+qpJtHpTTW9sJ+zDlkUUvexbh1tYjOsZJm/1tmxzAhoB5zA/lAB/KAIgRLkGUV91CW1rmx5SNof/n6RfWheNGzcPL2/uJiF8eChJncSRm99doQaYKN6SV7VWXBMNOV2n3mPZetwrpvBtUJU1Yl78DR1BgBwHFKOP9FF3wlnQkZVqq4/cQlVaULvmDJIRomeW9lWRKMR7E6jBfNf5u7monUd8/2vrpHwa1zjkZs2N+Os/Wf8yH95J2gL3deH12WMTh8vZcben2kpMBOtfwT9aE1rRbctM0lvW4bYIziUK2OisFRn5qcXtkqpXO+EVQIHjJeWbdGCpCb7I8pXlDd4eyikBe5lkOfepA14fix5npp0Rm5Z2D5oG/zGBDzdiwGMx8SMFy+4dxNHtmZWeD/MPqKxyXzo4Ie1sumsWl1TOG5doTkEGyJiDYvf95+lS8vD7srUaD/S8CLMcmTXR2MfiYFaH3T4cx8EmoocxVuCYtjRActpwwbF3vHiZxn0jUrDkcZhyoaSvSFkbH4JPumjQeMCttLzFdsyB+HJy3e5CYVveD7RvM6+tsDnt6jAcCerjBwHYC7LGcXAV58Va0cM4AoywcLnNuXSFs+22GkJ+/tx6K/JBbSgMVGccWTzbxgbYDfIx/p5AWpNvgu6tSCCgMpHtjdt/c/XFF7SMXKy3+lYSjMFbQtE3wzGIU7lEX122Wd8cdlBhU7qnUlt/YNEXsrqUlsMpbBOf0D+vd/GsmOTGVa5GK0U1Ct3DyvU3nS+JQpHq98blufIDFf2actk5A+L2SPudETm740s8Bn56hPAnweVEN3BNf5+eDv9ViXxtzcNJw2abDzFyd6Sbcmlx0n56iWDdrfX54SRhBkkwvFw5SBFDB8Kqq8CB642d3gHfZBLmCW/FWM8hFRwkllP5z/y8/Dy1KAAjqz/eLu8fw
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB0893; 6:fZxr9pDECkewPQ/8ONW2RQqs8d4cDF3DZLxRqB32snPVFufujtB/IrhIFetFkrt5K1pCQk6pZTOMBelOAZ3F6jp2CJw2tmsOhCKyz5SGzRkOyw5c8EYJ+cyMZbnVQPcEbsrjG6IVxeQIAabw/0Hnn78gw5CU83cF87WgoX1P5X6Bs3OcCtbJsEMdP+SXKp4XnpaZKpdKj70ug+Pp5OtjL7PaIprtqiIKV54iU1EbDslljNJP33mdJPEsK9HN2JWYXOWlSDHAAAPXV6vysWXHpCFVkIrHjMIspwwMo+ScAiLl8LeN/Lt/oyYTLhNn53MjPr3FRxqwRwD8SoeJEF9b7+YFOAfP7ybvlXHochyYDNRfJTeOTg25F1KqhAua/uDKeHU0UcHEtRGMKsME+Nb8Vn0VV3f5XQgfZFYDA1qwvDaato8BysTy9XjhDXRifqUqSrFN86v6TuROnW6lS/M97s2tmgDDRZJDMj4OIeSGo1oGonUZOqwRjPkJztDzDJEZJeSN5jbfC9D4eytbDp83kw==; 5:k0EMbOl83mEV44UI37GHNKJ/vR6VshUKpDDxbn2S0LwuRNqaPELZ5g3p1jzT3sGEZvBXeSYhwTmQOJi+Q1RrHZsWq+F+mU40O/YPAWOdZwFWX+clDnW43Z+LwXRh0a2OSdaD8GeD1OaD7788qTo0Yg==; 24:ZGZXqG42iWrGAydew+aLF5WH34o0Lv/OwgcCY0W1UHMGnXEinfip5qSPpIvzL5lFDTTKdBnxq4W+Mtaeb7TJdtD9wV2ABcG9q2qm63EhKFQ=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; DM2PR0101MB0893; 7:ZQN9szlabyZ/7kdfQYg06Sx1f165ovXZoY0uzIYU3MAOExqTChlP+ZQTE+k7KNfh3I3Eb6TFG6bVkQZxwBgxfD94pjC/a8ifduX3LU/vSATkoWx5Y0P7ZYtWvNsCkMTHUtABLQl68DwMOQwbqb9h5YYnKwxKgual4QLey4bjU2eWPnaGlx3Bh+TmG9AVCqf6KxaMv0hjd4s2+Js0qudWUmiLk3jOmsbTE4mRCeyljB9xtP4IUJSg7UQnwmjUb1QHTwD8PfwAr5UR5igAJajmXKYxP9a2Zz2KuIbv+xAXWmb2CKL/U9W/Tx8x2D3H+OWn2FrX0BnLYAva8/ceImN9dQ==
X-OriginatorOrg: direcpath.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 May 2017 17:21:40.6865 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR0101MB0893
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/akLUSsLoAcak6xzTO6TaUFGSEBE>
Subject: Re: [OPSAWG] draft-ietf-opsawg-tacacs-06 Contributions, Status and Plans
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 13 May 2017 17:24:15 -0000

On 5/13/2017 7:59 AM, Alan DeKok wrote:
>    If you're not going to work towards WG consensus, I suggest the chairs replace you with authors who will.
That seems unnecessarily rude.


This draft is still about documenting the existing tacacs+ protocol 
right?  Why?

You've been discussing this thing for a year and can't reach a consensus 
about an existing protocol.  I doubt very strongly that a completed 
document will be useful to anyone.  Nobody needs this to implement the 
existing protocol.

My personal belief is that extending the protocol isn't a good idea 
anymore.  Instead just rewrite it to use HTTPS/TLS transport with 
JSON/XML encoding.  That should cut out about half of the documentation 
in the draft.  The new protocol doesn't have to run on the same port.  
It could use 443 or whatever the user declares in the connection URI.  
Vendors could leave their existing tacacs+ client in the code until 
people don't need it anymore.  Servers could be adapted to support both 
protocols.

The most important thing to me is that something gets created.  This 
should be moving from a thought experiment to a reference implementation 
so that people can comment on the details.