[OPSEC] What is new in draft-ietf-opsec-v6-15 ?

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Sat, 09 March 2019 21:12 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CC5501295D8 for <opsec@ietfa.amsl.com>; Sat, 9 Mar 2019 13:12:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Level:
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=GIkiF0DT; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=HalwP1yG
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TvmFkaxQLW9M for <opsec@ietfa.amsl.com>; Sat, 9 Mar 2019 13:12:12 -0800 (PST)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 953B9129BBF for <opsec@ietf.org>; Sat, 9 Mar 2019 13:12:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=11575; q=dns/txt; s=iport; t=1552165932; x=1553375532; h=from:to:subject:date:message-id:mime-version; bh=YCc4TFwpgEPeWjHzKIOjEBTFGGo/HU1XQGPLQeK58aU=; b=GIkiF0DTXTNSQKN/mW7A4TVrRy5lqQiEikSAhuUE/C3PCq/puK4a+oIU QdrGibqV3vAetI4up/drQKzu/de8JjdRkjQZ43yOewIna4HtwtQQsR5SQ IkmPV14qSgNiUks+tTAw5MeUbafDXHH4SuB90lLu2wqYLC+FAgTWEPd4g o=;
IronPort-PHdr: 9a23:zfRixBayZDe8O9OewP8scd//LSx94ef9IxIV55w7irlHbqWk+dH4MVfC4el20gebRp3VvvRDjeee87vtX2AN+96giDgDa9QNMn1NksAKh0olCc+BB1f8KavncT08F8dPfFRk5Hq8d0NSHZW2ag==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BMAADZK4Rc/4UNJK1kHgEGBwaBUQkLAYENL1ADaHQECyeECYNHA481SoFokliFc4EkA1QLAQEjCYRAGYQeIjQJDQEBAwEBBwEDAm0cAQuFdB0BATgRAQZEAgQwJwSDNQGBEUwDFQECDJMRkF8CihRxgS+CeAEBBYJGgjUYggwDBYEvAYssF4FAP4ERJwwThWoCAgEXgXSCXTGCJoxNhAiTTwkCgXuFVIN8hz8ZkzqKeIVljGICBAIEBQIOAQEFgUc4gVZwFWUBgkGCCoNuhRSFP3IBgSeNECqCIwEB
X-IronPort-AV: E=Sophos;i="5.58,461,1544486400"; d="scan'208,217";a="242684643"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Mar 2019 21:12:02 +0000
Received: from XCH-RCD-012.cisco.com (xch-rcd-012.cisco.com [173.37.102.22]) by alln-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id x29LC2SQ002344 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL) for <opsec@ietf.org>; Sat, 9 Mar 2019 21:12:02 GMT
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by XCH-RCD-012.cisco.com (173.37.102.22) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 9 Mar 2019 15:12:02 -0600
Received: from xhs-aln-003.cisco.com (173.37.135.120) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 9 Mar 2019 16:12:00 -0500
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-003.cisco.com (173.37.135.120) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Sat, 9 Mar 2019 15:12:00 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector1-cisco-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=YCc4TFwpgEPeWjHzKIOjEBTFGGo/HU1XQGPLQeK58aU=; b=HalwP1yG+YC86aL4s9fZsGBKPdSknpJH51zOHYTfg78bF6GtoZLTFIkJ4iETRyaNQI1eWOI5kaCZymuGRSWCQ8u3aG8ZRZC7I4ksaFhjgF/Vmw0TWmKoUO82EQ50dsBl3P80bKeeGGZ6gq0NmuAcQWZ5Idm2jvkrhSX159RS+VA=
Received: from DM6PR11MB3820.namprd11.prod.outlook.com (20.179.17.28) by DM6PR11MB3737.namprd11.prod.outlook.com (20.179.16.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1686.18; Sat, 9 Mar 2019 21:11:59 +0000
Received: from DM6PR11MB3820.namprd11.prod.outlook.com ([fe80::e5ab:9e18:b14c:9b9c]) by DM6PR11MB3820.namprd11.prod.outlook.com ([fe80::e5ab:9e18:b14c:9b9c%5]) with mapi id 15.20.1686.021; Sat, 9 Mar 2019 21:11:59 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: What is new in draft-ietf-opsec-v6-15 ?
Thread-Index: AQHU1ry7cG9/PTO2OE2GyF5Yh/a/0Q==
Date: Sat, 09 Mar 2019 21:11:59 +0000
Message-ID: <88F7F6C8-2787-4AE7-B344-B341DBC08CD2@cisco.com>
Accept-Language: fr-BE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.15.0.190117
authentication-results: spf=none (sender IP is ) smtp.mailfrom=evyncke@cisco.com;
x-originating-ip: [2001:420:c0c1:36:c504:914a:c2f0:b817]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d99ff324-c09b-4eb0-88ac-08d6a4d3de60
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600127)(711020)(4605104)(2017052603328)(7153060)(7193020); SRVR:DM6PR11MB3737;
x-ms-traffictypediagnostic: DM6PR11MB3737:
x-ms-exchange-purlcount: 1
x-microsoft-exchange-diagnostics: 1;DM6PR11MB3737;23:JPeOAt8u667nVBI67ignkj5oXyvQ26GQ94tnFDLk40F0WFciVxYe2/UFMkownz5DgwoLjFebY45SLPWAJs/v3YT8l46ch6CM5LD+SQRC7bedj7MJF+Vr4pqHVpO8jxPev1paej0vjdXB4ZEsEzC0/saDzDjTXGd4jxKrV/wVuZvo6p1XJYkidtPPX8VNnXzU4y7yCERY/deGvycgf40qP3QCdSpL5vubulsEKKBT8vRSTIwO/Lhy6N1AamrDKCpPZBqsNHLj4TCLH3niF5vkT9ZfU5/yMUNcJ4bStLA6onef1Zjw+A1yb3HR1EPuP5swfmmB09+rjj0NASJlu3p4u7SgT1jGdTRC4petiey6wQCdzBaqusZWcPyD5xCw4dv3NEohFOyTEjoKsFacNm4ZpsoYM4nhytF+DQnAp90u+zTZzvJwbNjapiuz9+K8LGeNCWnC0f5V3wE18t6y7oI7Ff40uxLj7G2iuk0z+f6fDjDcnVG5mrpYeJFaf2C568Gi6uIBJO88JK3LLN6EcmLcd12a+rUlWj0lE1Z7px0XC1n69ZYNUcu+Hv1CF0c9YQVjaACnijoUvODsXjbFa5SRy5OROqj7ES5/2kHNDOte7C5JthEh2BPB4cFbDBazNbuIVO3rZtgCmVGV6MUfh4JDLJedgOcYjk3No574ZgZKgUeMZ12oAwuRVa+zZrcWmjC2vH3yoe9iwcYN/yUEwVztjlre4HOE+Ps8omtxd+iu8yewHK8L6i8DSKdI3KDHz4ooO1YfNnFEE7hBHj+xykJHYvrJW8KnCs+2eh8UHYZJq0OPZAJeYgqHrpgT1Bq3WitsjIvhL72C9mprMp1uxtnyBs29HtdDxQnAuD4s/x90cVSSK+BEuDehrpV/Roq32XjHhzyU1lf/qRgm7ldb+Sb0jbKj5aRdnVpM38PtEK69jjNMW+e84qrVoReM9Gs3fZrhf/7oYl6BGwcyJr7zi3xnxhcIR7wz4gTY5ZmwSfwkAZZLTKVwzv8vdC4FlZpUjJcdeQXGAHmeRFnUy1qNnT+miVI7E/u9mOUr8y9pKBPGN7x3wnweVY2VOKalJMr1j2Bz1HoQebU/YHiY5ZhJdTYfCBmYTaZKl/1ocF7BSEcneqrf3OEaCqJnoznbw6UxIzTSffNLhyIRJWQTIUiisS6bFgA8v8s5O2vFsF77RM5wwunhhkRjbycqYcSzAsOZFSyRcOjDp+LRl5BAfaSCnDaaNYEVdupHYkYkohNwCjaEprU=
x-microsoft-antispam-prvs: <DM6PR11MB3737B874597027D979AC1F9AA94E0@DM6PR11MB3737.namprd11.prod.outlook.com>
x-forefront-prvs: 0971922F40
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39860400002)(376002)(346002)(136003)(396003)(366004)(199004)(189003)(102836004)(83716004)(6436002)(97736004)(2351001)(105586002)(5640700003)(82746002)(33656002)(476003)(2616005)(316002)(486006)(2501003)(81166006)(14454004)(25786009)(106356001)(58126008)(36756003)(2906002)(86362001)(6916009)(71190400001)(8676002)(1730700003)(46003)(71200400001)(81156014)(478600001)(53936002)(6512007)(236005)(186003)(6486002)(966005)(5660300002)(606006)(6116002)(7736002)(68736007)(6506007)(14444005)(256004)(54896002)(8936002)(6306002)(99286004); DIR:OUT; SFP:1101; SCL:1; SRVR:DM6PR11MB3737; H:DM6PR11MB3820.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: kajhZnyhpV+xzNaWNEthGWnjEBP/keMPif77MympagPw+yojH6cawdgOfQ5Frjfs15APlGXR4IaXl/IRdXAx5zT/0QLw46W1rTUjDxTKDYmV0XNGE6+X9wc3ZdX05zfyNfZaWq5H/Y1PDYRjYlWSOHWZMSF7YvovUYNX2mhXiWmRr8bDSRawu9vJHDWWyH3LmM/WwGFNMeVezddVpb9bK9/3GYo424qMbV9MLfnrkJmgoCaNOvkj5QQTlULyBdzX2iKHiw6/Ndlpg9TNkBqDONhpjB8vPVwyuGrhgaAUlxd6CpmaSMObYK/C8JSgCqFJ7bXa7BwlKDLsDoXrY95c9JRApJRwDu62gEJAmlW0BI58IFFKFIPOlYW2+kvZjAfTp9AQYfgYWhB8RCPXd7rrC1THn60blOqGuFy37ruTlLs=
Content-Type: multipart/alternative; boundary="_000_88F7F6C827874AE7B344B341DBC08CD2ciscocom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: d99ff324-c09b-4eb0-88ac-08d6a4d3de60
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Mar 2019 21:11:59.3835 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR11MB3737
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.22, xch-rcd-012.cisco.com
X-Outbound-Node: alln-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/0tbwj96j47RS_hpbWnVKz3b8Ijk>
Subject: [OPSEC] What is new in draft-ietf-opsec-v6-15 ?
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Mar 2019 21:12:25 -0000

The authors have published a new version.

As usual, the diff is https://tools.ietf.org/rfcdiff?url2=draft-ietf-opsec-v6-15.txt

But, it consists mainly (based on comments from Fernando and others):

  *   Some changes in the flow/order to make it more readable + fixing typos
  *   Refresh of the references (I-D becoming RFC, or RFC obsoleting other RFC, IETF is alive 😊)
  *   Section 2.1.2 about ULA is even shorter and we hope fully addresses the comments received at IETF-101 and IETF-102
  *   Same for section 2.1.4 about temporary addresses
  *   Section 2.2.3 more text to clarify the fragment header
  *   Section 2.6 mention SAVI logging to help for monitoring of <IP, MAC> addresses mapping
  *   Added some text in 2.7.3 about some translation mechanisms sharing some issues with CGN

The authors have requested a slot to present those changes at the OPSEC WG meeting at IETF-104 as well as V6OPS (to collect feedback/reviews from operators).

As usual, we welcome comments and reviews esp before the Prague meeting as we will request a WGLC on this document

Regards, for the authors,

-éric -meriko -kk -enno