[OPSAWG] Protocol Action: 'Updates to the TLS Transport Model for SNMP' to Proposed Standard (draft-ietf-opsawg-tlstm-update-14.txt)

The IESG <iesg-secretary@ietf.org> Mon, 17 April 2023 17:41 UTC

Return-Path: <iesg-secretary@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 3EE0CC151B23; Mon, 17 Apr 2023 10:41:56 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 10.0.0
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, draft-ietf-opsawg-tlstm-update@ietf.org, jclarke@cisco.com, opsawg-chairs@ietf.org, opsawg@ietf.org, rfc-editor@rfc-editor.org, rwilton@cisco.com
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <168175331625.58909.17553851960089772832@ietfa.amsl.com>
Date: Mon, 17 Apr 2023 10:41:56 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/nAtMpj4tkvTg_KfAe0rmzI1raNs>
Subject: [OPSAWG] Protocol Action: 'Updates to the TLS Transport Model for SNMP' to Proposed Standard (draft-ietf-opsawg-tlstm-update-14.txt)
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Apr 2023 17:41:56 -0000

The IESG has approved the following document:
- 'Updates to the TLS Transport Model for SNMP'
  (draft-ietf-opsawg-tlstm-update-14.txt) as Proposed Standard

This document is the product of the Operations and Management Area Working
Group.

The IESG contact persons are Warren Kumari and Robert Wilton.

A URL of this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsawg-tlstm-update/





Technical Summary

   This document updates RFC 6353 "Transport Layer Security (TLS)
   Transport Model for the Simple Network Management Protocol (SNMP)",
   to reflect changes necessary to support Transport Layer Security
   Version 1.3 (TLS 1.3) and Datagram Transport Layer Security Version
   1.3 (DTLS 1.3), which are jointly known as "(D)TLS 1.3".  This
   document is compatible with (D)TLS 1.2 and is intended to be
   compatible with future versions of SNMP and (D)TLS.

Working Group Summary

   From the shepherd writeup:

    The document was actively discussed between a number of working group
    individuals as well as in consultation with members of the TLS working group. 
    No one has expressed dissent in the work or its direction, but I would have
    liked to see reviews from the SEC DIR and from the broader OPS DIR.  Requests
    for those reviews went unanswered.

    One area to pay special attention to is how new hash algorithms are allocated
    in the new IANA-maintained registry.  One thought was to have new algorithms
    auto-added based on work happening in TLS 1.3.  However, that could lead to a
    proliferation of algorithms in this registry that are never used.  Therefore,
    the current text stipulates an additional expert review and work on behalf of
    interested parties to propose a new hash algorithm be added (and that
    represents the consensus of the group).

    It is also important to call out that the reason this document requests a new
    registry vs. adding to the existing one is that the TLS working group did not
    want to imply that any new algorithms added to the existing fingerprint
    registry worked with TLS 1.2.  Choosing this approach allowed for a much more
    simplified update to RFC 6353.

Document Quality

   This is really a security update.  My understanding is that
   there are vendors who are keen to implement, and others can
   be expected to do over time.

Personnel

   Doc Shepherd is Joe Clarke
   Responsible AD is Rob Wilton

   IANA experts are TBD (need to check with authors and SEC ADs).