Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
mohamed.boucadair@orange.com Mon, 22 April 2024 12:07 UTC
Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1AF54C14F618 for <opsawg@ietfa.amsl.com>; Mon, 22 Apr 2024 05:07:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.094
X-Spam-Level:
X-Spam-Status: No, score=-7.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NvdIlYBRaTXd for <opsawg@ietfa.amsl.com>; Mon, 22 Apr 2024 05:07:01 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.126.237]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 540FFC14F68B for <opsawg@ietf.org>; Mon, 22 Apr 2024 05:07:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1713787620; x=1745323620; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:from; bh=CZeI3LQJeQZ7CyXEmIKcuiiSWXkFN6IqX4SK4AArtyo=; b=YiEW84qOcA6B+GvM3fR2aTQtDGOf998lSvH4c1+Kuh2p6wGdSaBA/qLe umsFpjbLFsO8qdJE7mBdiuCIrjnmt+yMW7BKZhmm8vdMEM9Xpm8CWTb6K tKH0uZEqPfVE5rce/KtppOadzytOmnlHZGWngpMVh3pZEgSJuAkLWgYwO C6VHEzRwGMfrN+AfUHEE67S+MCTpQQnOc8dyMCYtshTmXcNL5HPq1Tl87 xgpgI4Czh2OgO7f45i89jJbYMurNcX1NCsSVMBmaNPVO/xc5sJbyAxMnq yc+n61c5efJF8WUgoJYv5btxp1CMW8z56okaiJ43h5URk/L8NHRCWdNOZ Q==;
Received: from unknown (HELO opfedv3rlp0f.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Apr 2024 14:06:59 +0200
Received: from unknown (HELO opzinddimail6.si.fr.intraorange) ([x.x.x.x]) by opfedv3rlp0f.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Apr 2024 14:06:59 +0200
Received: from opzinddimail6.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with SMTP id 494CA122DA1B for <opsawg@ietf.org>; Mon, 22 Apr 2024 14:06:58 +0200 (CEST)
Received: from opzinddimail6.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 69341122FB18 for <opsawg@ietf.org>; Mon, 22 Apr 2024 13:53:16 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail6.si.fr.intraorange (Postfix) with ESMTPS for <opsawg@ietf.org>; Mon, 22 Apr 2024 13:53:16 +0200 (CEST)
Received: from mail-dbaeur03lp2168.outbound.protection.outlook.com (HELO EUR03-DBA-obe.outbound.protection.outlook.com) ([104.47.51.168]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 22 Apr 2024 13:53:16 +0200
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by PAVPR02MB9428.eurprd02.prod.outlook.com (2603:10a6:102:306::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7472.44; Mon, 22 Apr 2024 11:53:13 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::7398:1f78:30c6:e9f]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::7398:1f78:30c6:e9f%4]) with mapi id 15.20.7472.044; Mon, 22 Apr 2024 11:53:13 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.218.35.125-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=None smtp.helo=postmaster@EUR03-DBA-obe.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 104.47.51.168 as permitted sender) identity=mailfrom; client-ip=104.47.51.168; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: None (smtp-in365b.orange.com: no sender authenticity information available from domain of postmaster@EUR03-DBA-obe.outbound.protection.outlook.com) identity=helo; client-ip=104.47.51.168; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@EUR03-DBA-obe.outbound.protection.outlook.com"; x-conformance=spf_only
IronPort-Data: A9a23:hLB1kak+417uPvIW4wA6Arfo5gyKIURdPkR7XQ2eYbSJt1+Wr1Gzt xIXXTuCb/aJMDT0edtza9y18xlUuZCAmoQ1SgJpqixnQS4T+ZvOCOrCIxarNUt+DCFioGGLT Sk6QoOdRCzhZiaE/n9BCpC48T8mk/jgqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYADNNwJcaDpOt/rf8kk35ZwehRtD1rAATaES1LPhvylNZH4vDfnZB2f1RIBSAtm7S 47rpF1u1jqEl/uFIorNfofTKiXmcJaLVeS9oiM+t5yZv/R3jndaPpDXlhYrQRw/Zz2hx7idw TjW3HC6YV9B0qbkwIzxX/TEes1zFfUuxVPJHZSwmZydwmaaSHrH+N9BPWwkB4Id0PwsGkgbo JT0KBhVBvyCr8+L+urgD8VGr4EkJsStO54DsHZ9yz2fFewhXZ3IX6TN45lfwSs0gcdNW/3ZY qL1axI2NEiGP0IJZw5RUcxu9AurriGXnzlwrVWVrK867y7ZyxF62bTkMcD9fcaDQ8pY2E2fo woq+kyiX0lDZYbOkFJp9Fq9utGUmR/cVLk7HaWl/8RNsFez/lMcXUh+uVyT+qLj1hHWt8hkA 0Af/yUntqga/02wRd67VBq9yFaEsxcHc8FQCfAw4gyX2+zS7hrxLmECQiRMavQhqMZwXj1C/ kOJmMnyGTFp9rGcSXe1+bKdrDf0Mi8QRUcFfTQNUgQt4tT/rsc0lB2nczp4OKu8j9mwFTv5z i2Q9HM6n+9K055N0Lin91fahT7qvoLOUgM++gTQWCSi8x99Y4mmIYev7DA38MqsMq7JQFSq4 EMFsPO0w9EjH6uCkQaXG/4kSeTBC+m+DBXQhltmHp8E/jur+mK+cY043N2YDBc2WirjUW6xC HI/qT9sCIlv0GyCTIIfXm5cI8EjzKylGd7sW+3ONoFKesIoKl/B+zxyb0mN2WyriFIrjaw0J Zacd4CrEGoeDqNkijGxQo/xMIPHJAhvngs/priilHxLNIZyglbLE9/p13PQNYgEAFus+lm9z jqmH5LiJ+9jeOP/eDLL1oUYMEoHK3M2bbiv9JUMKbXcelE9STl8YxM0/V/HU9w190iyvraQl kxRpmcEkgqh7ZE6AVnUNSw4OOu/NXqBhSthYnJ1bD5EJETPka70t/1DKPPbjJEi9ed5yuVzQ eVNcMKaGpxypsfvqlwggW3GhNU6LnyD3FrQVwL8OWRXV8A6G2ThpIS+FiOxr3ZmM8ZCnZBjy 1FW/liHGsVrqsULJJq+Vc9DOHvt5SJDwbktBhWTSjSREW21mLVXx+XKpqdfC6kxxd/rn1N2C y7+7dYkSejxT0sd3eTz3fvBg62AVux0EwxdAnXR6quwOW/C5G2/zIRcUeGOOzfASGfz/6bkb uJQpx053Dvrg34S27eQ0Z4zpU792zcrj7hAxwJrETPAaFHD5nZIPCydxccW3kFS7uMxhDZag n6yx+Q=
IronPort-HdrOrdr: A9a23:8PjLNaNc8XEAWMBcT0r155DYdb4zR+YMi2TDiHoddfUFSKalfp 6V98jzjSWE8Ar4WBkb+exoS5PwOk80lKQFqbX5Uo3SODUO1FHHEGgm1/qa/9SCIVy0ygc+79 YGT0EWMrSZYTdHZITBkW+F+r0bsbq6GdWT9ILjJgBWPGNXgs9bjjtRO0K+KAlbVQNGDZ02GN 63/cxcvQetfnwRc4CSGmQFd/KrnayHqLvWJTo9QzI34giHij2lrJTgFQKD4xsYWzRThZ8/7G n+lRDj7KnLiYD29vac7R6d031loqqh9jJxPr3NtiHTEESutu+cXvUuZ1RFhkF2nAjg0idurD CGmWZbAy060QKtQojym2qm5+Co6kdQ15fvpGXo/UfLsIj3Qik3BNFGgp8cehzF61A4tNU5y6 5T2XmF3qAnei8osR6NkuQgbSsa4nacsD4ni6oennZfWYwRZPtYqpEe5lpcFNMFEDjh4I4qHe FyBIWEjcwmOG+yfjTcpC1i0dasVnM8ElOPRVUDoNWc13xTkGpix0UVycQDljML9Y47SZND++ PYW54Y4o1mX4sTd+ZwFe0BScy4BijERg/NKnubJRD9GKQOKxv22uzKCXUOlZKXkbAzvesPcc 76IS1lXEYJCjPTNfE=
X-Talos-CUID: 9a23:vLFqJ2Aqn0kuo6/6E3lp+WVIIcEOSVfy/VrCGUC9I3wyU5TAHA==
X-Talos-MUID: 9a23:b8PHvQjmPx2alzGIwp3lXMMpJftWuKCSL0w2uJwepsC+Ehx6Gw+ig2Hi
X-IronPort-AV: E=Sophos;i="6.07,220,1708383600"; d="scan'208,217";a="35019291"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=DuFFsJGFXl/HEhC7/2m11Npo5gxk7zACCnbbCmVTLjk5jG4DlpuEymqfwt5eZsq623XLUrH6d69MCWJx8Y7r6MSPOM1nznL3G+lYX4uFsImwzxhgOX2R8nFp8ffxfJIMe34mDBi2+cm+JibwjVdjwUy3ryTfaiFmzr6rdByoXUSw+7FsT4uSqFNKiyYQmQNUqZiGQIeL7QYL0FmJ0x4VE0H8WHKHJpHlocRJyDR6jKMcOkxwTGl3TRR0XaaIKJ+diM5TLv2WZj8KknZo5SPL7duwEupIzBonzPjkxBmC0WMwBi8GE5ywrgPaQawKlxaXMdQMEP4Shj8mMiWkTUPm0Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=UO+6eTlOFp9rkGQXvW4COy6HtK4PXBIE5WrtmkEe5D0=; b=C2NfB+rQbxYVejNDKO1inaCJ1QbsuowDd1Jy8nzGdRVaJoD0QYtV+nu4GrHLEJIK9m+S6IDsXxTxAeQlwkf4KZpiVEPGoEWsN7NHkET8YPAWcsnTfeNhyqjJTKJJtzNExvhc8IgklRSF0zuhHfR/3ctcZGFHFY9f4nsRd13+v+8gmeN729u5DHsMxPyHIUv9rARbiwL/7pJym2c6r/2/vC8AM7/UK40KPnTtQFtcL/GxhRd41sl2viSeOaTHKLyNyPz2jzoD49AQV7jPEnHKp/QsD5vss6SM8NVdeghBGyWXxVQRzZFw1ZNwgDw3TWxAuFDsKhHTUnCEBW/+N0KIMQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: "Douglas Gash (dcmgash)" <dcmgash@cisco.com>
CC: John Heasley <heas@shrubbery.net>, Andrej Ota <andrej@ota.si>, Thorsten Dahm <thorsten.dahm@gmail.com>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
Thread-Index: AQHaknkV5UFry3XPykaOc/4zi7RiALFv0X2ggAQpGM2AADTGsA==
Date: Mon, 22 Apr 2024 11:53:13 +0000
Message-ID: <DU2PR02MB1016094039CEE85F00F82B4BF88122@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <171094844069.8406.1730131072887926375@ietfa.amsl.com> <BL3PR11MB6364F94772DDCCC57DF18748B7332@BL3PR11MB6364.namprd11.prod.outlook.com> <DU2PR02MB10160514500051EDA4B5D1441880F2@DU2PR02MB10160.eurprd02.prod.outlook.com> <BL3PR11MB6364B8968DE1CC0E83600660B70D2@BL3PR11MB6364.namprd11.prod.outlook.com> <DU2PR02MB1016055635A500C074019FE3A880D2@DU2PR02MB10160.eurprd02.prod.outlook.com> <BL3PR11MB63646F83D464F49D9D729ACAB7122@BL3PR11MB6364.namprd11.prod.outlook.com>
In-Reply-To: <BL3PR11MB63646F83D464F49D9D729ACAB7122@BL3PR11MB6364.namprd11.prod.outlook.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=True; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2024-04-17T15:33:41.0000000Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|PAVPR02MB9428:EE_
x-ms-office365-filtering-correlation-id: 9040f52a-9518-41ce-2fdb-08dc62c2ca35
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: gm1Ms9HC33zWoSYDwYVQywG4CZmOPhLBIed/mNRm79I6pF0H17uiQr/9aDuzI+0nxU4HYArOKDccbPVr5Y9UBW3KypwnCsW8qCDHE0iAtJX2vrdSsMgU/btJLo9nTCX5RNCqrY9TuyRWXVEQZ56kW+sVGrNRI7asQnwH6S5L/zlIKuLJR7DguxXkzzIYQ0XftbKWT+VCDo0auSlC8UV+bWIKN1HJ9h+2Rq4V0L5jBbZs0/JPuYoeDClgWYqk1SHqOBR8mp8pcMSydZVaDnetj9cl4/SFQ+sZpCCa/t6L5MkRoAwAHCAaLAl35GYHo3i8FwzyMYXyXmuKH6egUcgAgh0cb3dnoDlBqSZhEtpor9TU2PWgZJE5tvc8u8d+vkHxdNX5j450MqvpVVf6pTbWvZ9OQlUwCrFz3sqiwKX6pXt9M3VfvfuCZgnbazDhPRyoSmikWBQuY0rUkbyVtESf5Jb0knsaoKkcTW7BBccKx0M/hkqB/9lfeRtZdWIQPWWDO24LRcz/K5OeI2JbtL9+qR4hhnqwnt5FE3VsdSDqnD8S4p7t4ML+N6vV2qbc812DW2pEqIKzN/rqNy+CVHlvrwCl2S3l3CgnyF0uzkkqRDEhwgIi7C5Bs4D9pSQfzkR3I7zSNaqZfTld3MIzs+x363pmJd18erbpgMyKDDxMjrI1gO2lbozpLZIanJLyQqY3deqP22kyeN91HzXVcb+8jv4eyTJVT8IVv1nG5Q/SEMjaO4hCMloQB32Qc0Ug2CCCKZfATEUApaEXoF/2giTmWenjDjWCGn9viamjxmEl8KoZT2e5GbtMeV/dvSiByDDEZxGuKYNN6suYiGMW0Iq/4W8Yd1mB9w5APmPScqyataFDzOtbuwM0pl3Iinb0tjIdPohqKHwA9LUZ6j0zNrBhYh1VQRuUtEsiQ1cfMhundG5oZ+0OAntbVzChqvJXFwjn2VaZJyLlZWCcqntRSUb2WdIexot87OlsV62Db0yPWQ94h1W7jpszHClgCu6v3eCu+9ahSZdrIaRhUQuQWG0qfZSGTzOR+69ihQxY1Se0EKfkNYuSeT3MDFRuFLI0Q2LCrKp3iyJeifJ+NhSHN5r0+EELF7NtHRX4uvSmD6JQlEkQ6X++F151Vqen0jBIC4QWIK6BedxLsBPv2LysbEwd6FHZRvNZ2u2DzpdExwnOAviAhAr/1FUTS/UFW91OD4UL0ybJH3ERslnDoIaJjgVzLw/FJeLLk+Xyni9cT0L2VVNsa6brGJ12FALbk1BxyLw52DCbX/PYLDqs933r7R1ALxIGnztX0jmg7bYYIIfo4CU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR02MB10160.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(1800799015)(376005)(366007)(38070700009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: t9aQ/xZNqjBXHnA7b3V0UlJBFMw3USs4XsZpea5EQ/rUdfhq7cgAxF6uA2UN4U+A6sRVWGVbt0eScaClweVLOVTYFqVTg16s/1n+gjoFZpjesqNSRVe5u4M5M5x1L2bn+N7gsUUUfTps1rdlgaOiKS1jPfH1wQnoTldKObIS+TYpUkUXe/D90rVUJb30YCCgHPtH+DQpzqkOcifpHLFSeGfNS8bI2SvVFJl2dfMXX9qZ0SutUqSbZ6DMvMF8M6mLCS1eV8Gp5tKPcK5peqteNM0I26PxJCke4Lh8uGBYLV2c0o/EUOmDf9o81LZW+zHPJ87ziGDL/+mnJ1ZKhdEdliWpNpsfSNQbwTu8Wlt0pbYjJDMX7Zy+Pk2aDWuwvHoiSaNDkJAz0PpWCaP2nLWutRTuevT2QvSEaKOgRm5jQxlhr1zkTK7PN5plbFH452JKrPVgA1vxWSjFJgKLVW/q0e1N4mVzm+9xcqUITTjOUv6DzqShvn96fuWn9Q3d3c0XxseTMpGmKb+P8mj/xA16WlMTtk4e6YHz1682Zlh8ONv80hlaeC7ayC7d062ZfCOa7fA6BXu0VHBpXG9CMo4ylwEg4/xXwKVU3+YbmnoI9AbPp1cFp+H4T2rTsRblezzTehOEKaba7Zc8B3uIyLxHbt1xSh/W/ryqufGDAabIQopjCEX5mqVYLdGcw0zox3pj7hPdu29y6k3UlWwT4zP3XjEgyVIhsewZmYW1XcRXriRsRjvdHZuLPusvv9ftPYt9L7g6mHafvv+b/bM8YoCtel9lYnoivo+ruc4624xvW9VmDXnVM3zMl5RrN/nwwRLlm5uLJ/9n9pM9j+e8J7afccJvNYqNFnAut8MMqPgR9A86HhMLbuBerCWDzuN7tQGQzIm8fDBn70k9mj0ibVyctOy3u4ng3grGvEuCVzJUbKFGH+ejks8crK32nZuiIZEO8cL4WDOUPEss04ZRNnI9jL59ZeeC/jIgY+k7n0o6HGH6CzPaITapfAkjijCQqAeZCfCvQLDjU7GbnWllV/RfsiI8v+EdJzugr+jZcl39PW/vj0CBtSm0irNMKMQy1JhWVT3DzWC9/q3k7punpilDRCsqYls7jDb+y1C9mNi2WJ3iSg/ilC0C0yfulf3T7jINZDJ0Op8wAlLUXSKZyYYPukGmNuVMm80xLtctYxyi5e3FWHhSxAN3Qsk5bxei/L5GrOzIQJPPaRDx39FetWOXADmOsgQtE4c8G+/28elXmk1dTNYVi0+x2+49+IxS4lhPoqeIh3blhaoN/lynx09Hqk1TFD0lYUVoGIdGUN4Io6WgI6lpOQL2eDK/63/veR6boiYfeFZ7IAmCvHQSFLtQvCMLkYmqybIoEhyDsv5OqFhvM/WnJkMFSP8XhmnB4tyvfmz0Zmg7NKtTsTVYrFQcmTqWXLyk9/K5tNzKJPM11760CUOuE75NTTMp3pW2A+jobQ1FzLx20IlsdW9aO2CUbPTlPCsNuhkx5LwBvP3sjlGh1XU3wbJwTc8fPLNNua9kRW16FwFgAnV9sMvKfkLrRX4SS7oDnpRdyf26KVvcynvnMujypvCy8YsoHs0u3DC/LThvWWfqh0GWVzbIxf5FrA==
Content-Type: multipart/alternative; boundary="_000_DU2PR02MB1016094039CEE85F00F82B4BF88122DU2PR02MB10160eu_"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 9040f52a-9518-41ce-2fdb-08dc62c2ca35
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Apr 2024 11:53:13.4878 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: MT1WNEBwrxlgq5BbyfZCpcPdF9flIvlAsBp9DSXitLJF828xPN37mVV9OCM/nmmq/+/+7zrHBC5Gj1hcyclUkF2Hdo1ZyroHdzOVyUltzw8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PAVPR02MB9428
X-TM-AS-ERS: 10.218.35.125-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-28336.007
X-TMASE-Result: 10--38.164700-10.000000
X-TMASE-MatchedRID: iKTMlETJ4pvZU9L012+8KrdXJOYbkh1avHKClHGjjr1vQ1w4VLB58jAD TOtbgClvTledWAKUpYrVSDZW9GFolRPeoPt4pp+5av0c60mfQvsK3Ma88LL+bgv/9UzFeXITY+h ZW0x5YxaL2sCeHVx5vSBdk1lAhP0Ll4YiZIj2ilNlmfQm2WX/m95x7RpGJf1apWOBfK9L1z9bxW jmuC04k+zn6eE2grwn5ZHdquAwKoEKdxceKmUcJzILfjgCHmvK3IFFT9wqfr2p/958oU3WcOumZ jiPfDR2mKbhu5KaCkdvi3cZdjyXravQ0s0JA35q7DLY2FGw/JtB9I5g6XEpi4PAtNs5CO8OgcoR xwA1MHbPimpQ9gESSa8L0ZBzQg9T7PgxMG3DtmTo0gKoBBRzz8Q4mpKyfkqZXHlQSIX8DvV68Vp iQd7QGNO82lWRIPgz/57ghY35qk6YiZd41VxmDispnLLvaSPuLTHwnYOikQ1K4f4Z+CZAZ8iCh8 yBqE+tSr35p7eE8N8hbOahTKQ9CMwNU6bH7awGfrWrPxU2TBY3Gqvmq0YYlEjmbQR0Nyy8Ld65q L++oKw4W7mlECl6bKvZ9D9IWyPdp6l9FCowYcWjbvGIi5SCUEEOfoWOrvuO+KgiyLtJrSDfn9D9 CqUkM+G2PJIbMHnZLVNf/OpYEY9YKJTez2dVw5PTmlFr64XTx0gyixf3FjhCVJggkIOusMLr6o8 RmanZQUSAOcUbYfgYdmQBBki6+r8elP/2IwgBAh0bifcDYKQM6z3iDvziB0hMRy+qNwXgS6Qize DUeN52PqBW66jvyfIRpGbhvZ1fpHlO2q6rss4YB2fOueQzjxhU9Ko9M4u98gGd4jv8zaP9a7Q38 w1tP3OoR/K+A1gw4E9s12Gvf50E8MoXbRXBn23U7j2vVURrIG4YlbCDECtruV6hT84yE/IxdJB3 PGL0
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: 984b30cd-bfb7-4422-81f1-a2270795df92-0-0-200-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/uDGkEirCBi7KhOVsK2-SaXtGyTs>
Subject: Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt.
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Apr 2024 12:07:06 -0000
Hi Douglas, Please see inline. Cheers, Med De : Douglas Gash (dcmgash) <dcmgash@cisco.com> Envoyé : lundi 22 avril 2024 11:22 À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com> Cc : John Heasley <heas@shrubbery.net>; Andrej Ota <andrej@ota.si>; Thorsten Dahm <thorsten.dahm@gmail.com>; opsawg@ietf.org Objet : Re: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt. Thanks Mohamed, please see inline... <Doug/> From: mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>> Date: Friday, 19 April 2024 at 18:31 To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>> Cc: John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>, Thorsten Dahm <thorsten.dahm@gmail.com<mailto:thorsten.dahm@gmail.com>>, opsawg@ietf.org<mailto:opsawg@ietf.org> <opsawg@ietf.org<mailto:opsawg@ietf.org>> Subject: RE: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt. Hi Douglas, Please see inline. Cheers, Med De : Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>> Envoyé : vendredi 19 avril 2024 18:46 À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>> Cc : John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>; Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>; Thorsten Dahm <thorsten.dahm@gmail.com<mailto:thorsten.dahm@gmail.com>>; opsawg@ietf.org<mailto:opsawg@ietf.org> Objet : Re: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt. Hi Mohamad, We are working through the comments and enhancements that you kindly sent. There are two comments that we'd be grateful if you could clarify: 1. BMI10: "What about raw public keys?" (on: Implementations MAY support TLS authentication with Pre-Shared Keys): I'm guessing this relates to fact that, as we mention only PSK, that this indicates that we mean to imply that non PSK authentications are not included. If this is the case, then for sure, we will clarify that they are. If you have something else in mind, please expand, thanks! [Med] Yeah. <Doug>Got it, will clarify that this section just relates to PSK and dosent impact the use of other PKI options</Doug> 2. BMI16: "What about configuration of name/address/port number of the server?" (on: Certificate Provisioning is out of scope of this document.), would be grateful if you could please expand on what you had in mind here [Med] Clients should be provided with the IP address(es) and alternate port number (if the default is not used) of the server. Clients may also require to be provided with the domain name of the server. <Doug>So we didn't have in mind any additional configuration at the T+ level other than the regular TACACS+ for this, (where clients will have servers defined and vice versa) [Med] I checked rfc8907 but failed to see where this was described. I suggest you include a note to basically echo what you said. Thanks. , with the caveat of the restrictions in 5.2. TACACS+ Configuration (to ensure that TLS and non TLS can be easily differentiated at implementation level to reduce the likelihood of operators accidentally mixing TLS and non TLS traffic which may lead to downgrade attacks.) </Doug> Also, given that you define "tacacss", do you had in mind to use that for service discovery? <Doug> not at this point, it is more for IANA considerations [Med] Then, call that explicitly: "Considerations about service discovery are out of scope." , assuming that we do end up requesting a new port number</Doug> [Med] The name can be registered independent of whether a port number is assigned. Please note that if a name is also provided to the client, then you may indicate that the name will be used also for rfc9525 validation to compare the domain name with the certificate that is provided. If no name is provided, do you assume that the certificate is <Doug>To restate to ensure I'm on your page : the actual T+ protocol won't have the domain name embedded anywhere, so this is OOB of tacacs and encapsulated within the TLS transport and peer configuration, which can validate as usual as it knows the peer connection details. We will clarify that recommendation. If there is somehting we're missing there, LMK, thanks !</Doug> [Med] The point is that, without making a assumption about how the client is aware about a name of the server, leverage 9525 validation based on that provisioned name and the certificate presented. I think this is important to cover because certificate bound on an IP address may not be available. FWIW, 6125 used to have this text: Some certification authorities issue server certificates based on IP addresses, but preliminary evidence indicates that such certificates are a very small percentage (less than 1%) of issued certificates. BTW, I wonder whether you need to indicate whether the certificate authority that issued the server certificate will need to support at least DNS-ID and SRV-ID identifier types? I don't think URI-ID is needed. Similarly, do we need to include a mention about wildcard "*"? I think it SHOULD NOT. <Doug>Agreed, I think there was a discussion on that, and it was discounted. We'll make that explicit</Doug> [Med] Thank you. Feel free to grab whatever useful for you. Thanks. Many thanks! From: mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com> <mohamed.boucadair@orange.com<mailto:mohamed.boucadair@orange.com>> Date: Wednesday, 17 April 2024 at 16:42 To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, opsawg@ietf.org<mailto:opsawg@ietf.org> <opsawg@ietf.org<mailto:opsawg@ietf.org>> Cc: John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>> Subject: RE: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt Hi Douglas, all, Thank you for taking care of the comments. I managed to review the latest version. FWIW, the comments can be retrieved here: Pdf: https://github.com/boucadair/IETF-Drafts-Reviews/blob/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.pdf Doc: https://github.com/boucadair/IETF-Drafts-Reviews/raw/master/2024/draft-ietf-opsawg-tacacs-tls13-06-rev%20Med.doc There are still some points to be fixed, but I think the document is getting stable more and more. Cheers, Med De : OPSAWG <opsawg-bounces@ietf.org<mailto:opsawg-bounces@ietf.org>> De la part de Douglas Gash (dcmgash) Envoyé : mercredi 20 mars 2024 16:40 À : opsawg@ietf.org<mailto:opsawg@ietf.org> Cc : John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>; Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>> Objet : Re: [OPSAWG] New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt Dear OPSAWG, We have uploaded a new version of the doc, primarily to address as much as possible of the comprehensive review kindly submitted by Mohamed Boucadair. We thank Mohamed for the time and trouble taken to the review the doc so thoroughly. We will be happy to discuss further any omissions or new comments and rectify quickly. And we will endeavour to respond ASAP to any other comments of any kind on the doc. Many thanks, Regards, The Authors. From: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org> <internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>> Date: Wednesday, 20 March 2024 at 15:27 To: Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Douglas Gash (dcmgash) <dcmgash@cisco.com<mailto:dcmgash@cisco.com>>, Andrej Ota <andrej@ota.si<mailto:andrej@ota.si>>, John Heasley <heas@shrubbery.net<mailto:heas@shrubbery.net>>, Thorsten Dahm <thorsten.dahm@gmail.com<mailto:thorsten.dahm@gmail.com>> Subject: New Version Notification for draft-ietf-opsawg-tacacs-tls13-06.txt A new version of Internet-Draft draft-ietf-opsawg-tacacs-tls13-06.txt has been successfully submitted by Douglas C. Medway Gash and posted to the IETF repository. Name: draft-ietf-opsawg-tacacs-tls13 Revision: 06 Title: TACACS+ TLS 1.3 Date: 2024-03-20 Group: opsawg Pages: 15 URL: https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.txt Status: https://datatracker.ietf.org/doc/draft-ietf-opsawg-tacacs-tls13/ HTML: https://www.ietf.org/archive/id/draft-ietf-opsawg-tacacs-tls13-06.html HTMLized: https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-tacacs-tls13 Diff: https://author-tools.ietf.org/iddiff?url2=draft-ietf-opsawg-tacacs-tls13-06 Abstract: The Terminal Access Controller Access-Control System Plus (TACACS+) Protocol [RFC8907] provides device administration for routers, network access servers and other networked computing devices via one or more centralized servers. This document adds Transport Layer Security (TLS 1.3) support and obsoletes former inferior security mechanisms. The IETF Secretariat ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you. ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you. ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you.
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- Re: [OPSAWG] New Version Notification for draft-i… Douglas Gash (dcmgash)
- Re: [OPSAWG] New Version Notification for draft-i… mohamed.boucadair
- [OPSAWG]Re: New Version Notification for draft-ie… Douglas Gash (dcmgash)
- [OPSAWG]Re: New Version Notification for draft-ie… mohamed.boucadair
- [OPSAWG]Re: New Version Notification for draft-ie… Douglas Gash (dcmgash)