Re: [OPSEC] Call For Adoption: draft-camwinget-opsec-ns-impact

"Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com> Mon, 15 June 2020 21:54 UTC

Return-Path: <ncamwing@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 24BEC3A09E5 for <opsec@ietfa.amsl.com>; Mon, 15 Jun 2020 14:54:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=dHBr/MpQ; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=st9Oj/Ks
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id epyxPvWRqCqY for <opsec@ietfa.amsl.com>; Mon, 15 Jun 2020 14:54:01 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 161C73A09D8 for <opsec@ietf.org>; Mon, 15 Jun 2020 14:54:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6470; q=dns/txt; s=iport; t=1592258040; x=1593467640; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=BDt5CsY+8HgKh38BzJDVDz26QG0vvo1HpR/+x1p4iLQ=; b=dHBr/MpQEmrA4nPLv2Yaf2tv/qe+DVejUjZGS2npE7nqygAQuLAEcCLe BgZYogKXLChBB2wybBYe8PI7lVN4xKb8LkrRRa7BsPKTM/iNsEGVUX5az rYxmYNob2jzXyejZHBQB3qy7UNk8MyiMGAl+Nl6bwmQ+mCjz7cCsnMd98 M=;
IronPort-PHdr: =?us-ascii?q?9a23=3Am8oRLxF4HHWrRuFJ6byRp51GYnJ96bzpIg4Y7I?= =?us-ascii?q?YmgLtSc6Oluo7vJ1Hb+e401QGbXpje4uhFzezbr/OoVW8B5MOHt3YPONxJWg?= =?us-ascii?q?QegMob1wonHIaeCEL9IfKrCk5yHMlLWFJ/uX3uN09TFZX9eljbuHz06zMOSV?= =?us-ascii?q?3zMANvLbHzHYjfx828y+G1/cjVZANFzDqwaL9/NlO4twLU48IXmoBlbK02z0?= =?us-ascii?q?jE?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0DkBgBT7ede/5ldJa1mHAEBAQEBAQc?= =?us-ascii?q?BARIBAQQEAQFAgUqBUlEHb1gvLAqEGoNGA40YJZhSgUKBEANVCwEBAQwBARg?= =?us-ascii?q?LCgIEAQGERAIXghgCJDgTAgMBAQsBAQUBAQECAQYEbYVbDIVyAQEBAQMBARA?= =?us-ascii?q?LBhEMAQEpAwsBDwIBCBUBAgICJgICAiULFRACBAENBRUNgwQBgksDLgEOqk8?= =?us-ascii?q?CgTmIYXaBMoMBAQEFgUZBQoJhGIIOAwaBDiqCZIgTgVMaggCBEScMEIFPfj6?= =?us-ascii?q?CXAEBAgEBgSYBEgGDNTOCLZIjoh4KglmIPJBfAx2eZ45mgjGKCpQjAgQCBAU?= =?us-ascii?q?CDgEBBYFqImZwcBU7KgGCPlAXAg2OHgwXg06FFIVCdAI1AgYBBwEBAwl8jwU?= =?us-ascii?q?BgRABAQ?=
X-IronPort-AV: E=Sophos;i="5.73,516,1583193600"; d="scan'208";a="774441858"
Received: from rcdn-core-2.cisco.com ([173.37.93.153]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 15 Jun 2020 21:53:59 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by rcdn-core-2.cisco.com (8.15.2/8.15.2) with ESMTPS id 05FLrx9q006004 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 15 Jun 2020 21:54:00 GMT
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 15 Jun 2020 16:53:59 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 15 Jun 2020 17:53:58 -0400
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 15 Jun 2020 16:53:58 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ViLBPvaJ+G/WWHgrgxQ/CbhVU2Ka01N1P3tFyudrxfmb83OJNqBn2a9u76loYRMWIA3FrM5ihSuWr/22zVID1HCRHEUljJ12QMT8W+oKTB2873oDRmyyV+/6GYIDC5S6Gr8Npf/WNutK8iURyVcqVHBqdndRtd9kL6N/pW1ml/fBtgxRX2XYEE1nU33ZgFjTSyeFKCsENMMZLT4TJ1W6wRIWEWLlQ788Sew5Q2+vqsTwcts8zxWy7uBnuEFo4qXNUKt+mp3d7zsn+uz5gwWFt10PfpV0c2aI2rabnoYZxFoxVVcKyzQUz8urILEFN/FrvZBIwP21bGAaB/Be+sVBww==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BDt5CsY+8HgKh38BzJDVDz26QG0vvo1HpR/+x1p4iLQ=; b=OQaA2qw8FS6UkYRXfPWLxlfwue9Vd6Gnxj9Ngqhm4HzGTf6goCLRLrGu6lUtBmHWG2mjT6FuRXdhWjJUDeBe3570DPlfkH/SLXj19NYX4dtbwlvhDvPUIU5alw/+bikHI1nsbq/r2BiXZOKPDF2F65mofqSCTPBEn8pZnOSQUt0nEpGSP8CRNUPZhzSI7fFDZqUpOX3LsLRLA/rkZkidcQCKbl4Al1fJt/vApqqfTIkufNyG4JUHa8H39uWFI00FjpRNjgP5/CJ/APf/3Dx4JA1bPPLnH9lqcJIbbs0jglWDp/sjR0PEkaVtUpgbJPSwTH4TJEioA87yrHWSfhUhRQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BDt5CsY+8HgKh38BzJDVDz26QG0vvo1HpR/+x1p4iLQ=; b=st9Oj/Ks1cSsMRLoaADw9hzc/jW+f+scVK47TjlQcbz9MfqHZzBP7L75fca1Oh+abABjclUc0kBO4MBcKS9PaFfRG+O385DTilSehAF3t4YTCz6BqLc6hf89+mZfPcGXZS5KJiHCO8Ssa/Hd/mhp86K6O/4RgCIznQ+VEZmrhcg=
Received: from BY5PR11MB4070.namprd11.prod.outlook.com (2603:10b6:a03:181::16) by BY5PR11MB3958.namprd11.prod.outlook.com (2603:10b6:a03:18e::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3088.22; Mon, 15 Jun 2020 21:53:57 +0000
Received: from BY5PR11MB4070.namprd11.prod.outlook.com ([fe80::e42f:216e:af3e:8ce5]) by BY5PR11MB4070.namprd11.prod.outlook.com ([fe80::e42f:216e:af3e:8ce5%7]) with mapi id 15.20.3088.029; Mon, 15 Jun 2020 21:53:57 +0000
From: "Nancy Cam-Winget (ncamwing)" <ncamwing@cisco.com>
To: Warren Kumari <warren@kumari.net>, tom petch <ietfa@btconnect.com>
CC: Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org>, OPSEC <opsec@ietf.org>
Thread-Topic: [OPSEC] Call For Adoption: draft-camwinget-opsec-ns-impact
Thread-Index: AdY7SqenvbjZws5fQM2HvBhyR2hakgDxZGhwAAURfQAADkiYgAAaV6AkAN/xuwD//7wIAA==
Date: Mon, 15 Jun 2020 21:53:57 +0000
Message-ID: <77D0DC2F-B701-4889-8353-8DA45794B7DC@cisco.com>
References: <DM6PR05MB63480144A85175AA35841326AE860@DM6PR05MB6348.namprd05.prod.outlook.com> <DB7PR07MB534069F46322B83AD13C216CA2830@DB7PR07MB5340.eurprd07.prod.outlook.com> <CAHw9_iJvJk16oPYEON_+G=jxUtFVHBnpZUt0RTE6aosQytHpew@mail.gmail.com> <7ECCE190-01DA-410C-B891-6732EB300FC1@cisco.com> <DB7PR07MB5340FC40FE8614C69BAD1FFBA2800@DB7PR07MB5340.eurprd07.prod.outlook.com> <CAHw9_iJ5Kz3okmf2vK9NH7ZfFxaHTGAnamYeS5jaZXtUcY9wMg@mail.gmail.com>
In-Reply-To: <CAHw9_iJ5Kz3okmf2vK9NH7ZfFxaHTGAnamYeS5jaZXtUcY9wMg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.10.16.200509
authentication-results: kumari.net; dkim=none (message not signed) header.d=none;kumari.net; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [73.162.233.180]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 6870ab57-6164-483b-c1bf-08d811769b03
x-ms-traffictypediagnostic: BY5PR11MB3958:
x-microsoft-antispam-prvs: <BY5PR11MB39585DF560392010C0E271D7D69C0@BY5PR11MB3958.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:6790;
x-forefront-prvs: 04359FAD81
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: DOMSvB/BE2vhI/MCsA+tN4vWilu/+frc4wzJD8dYq5tqC8FKAbCj5A35XS8n+sysTAvNH8W+9vT3cXjRzsIaV7DnKjqFbRmNHvFTFusvAIxjvI65kPFikZ0FRvgM/RSi1D4KSfqk+atGoaP6KQrTgDhCy8ceVwwC9mwKQhM3ZDN34X+zjDujpFSWpH3Qa3K7ZbipHZCs/kyJn6lcOB+WHKNv2ojhOuriUbPyOawI8AZI6tz3zfbUGjLOQO/upxYi6HYIREhQKkeszK6qI1BFqFhYCqxnTj0sp3Rh3dRdeTZzOssEOHR8yRTmUKI7CLQLXENn/tkmNsZ+HwpTtcfJNp/FUsUaV9LpiPVHnEQ/Wyx5DOHlskZdfoOtFE747xTLBZwMzfxHq6IlOX6ffzQFOQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY5PR11MB4070.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(39860400002)(366004)(396003)(136003)(376002)(346002)(36756003)(83380400001)(186003)(53546011)(6506007)(478600001)(26005)(66476007)(66556008)(6512007)(6486002)(86362001)(2906002)(66946007)(76116006)(66446008)(64756008)(33656002)(4326008)(71200400001)(8936002)(316002)(8676002)(5660300002)(966005)(2616005)(110136005)(54906003); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: ETaYMO1++f3XGXxNomyUzxzv0bK6v+2i8No32ZSd+IrjMyKGGT0X3j3jW0piS6TB9UEnYmclfkW088gwT+/xzhxpGw0AjArwItBTD5eoh2/s9UTWaPWv7bpERMzG93EPHnFCFH3QTn66JrpojskSJGRqBELMczjAyOKmFOKbC7e4wAkH7PM6xJb8scSd8rilYFcj3dIYL6FHCxhdBG8iGvs8zaXioz/PQldd4pTBlCjZXZnivHcOAHq936IBRAc1EHPxvuFmQmeubFdf7XraGmEjE0QdRP6CtsYSKagkvYKH88OIScdnUW6Qevaa67Hlmisb5TupOpIt1I7u77hg4h1Pif6tXBAQgWfwplKl8QP30Pl6F3lihZLvDpEyNtt6pkOMCklpiQ7/9zkW7t3xCYhJXeDOlbiFOyfZOfRoAVrQqotRa36Xe89GK9JFG+Nc7mWmwEVfz/1n/zjiydCE8bRn0JWkSduYQVw1PtCj7xTU40rCX+DMLM3dh950MR1S
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <E095505733BDC842BE1DE3FA6A6D957C@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 6870ab57-6164-483b-c1bf-08d811769b03
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Jun 2020 21:53:57.5833 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: lGgdXHQwFrY27DiexHzUxXCnd3kk4ydRtnmw5sh0CwGd49pkQnkNy6084bYX4p/rlxaFDPM6LMwzkDaX4HqRUw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BY5PR11MB3958
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.13, xch-aln-003.cisco.com
X-Outbound-Node: rcdn-core-2.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/OEWz7dp4su-f9pCEhWd-stQ_zJM>
Subject: Re: [OPSEC] Call For Adoption: draft-camwinget-opsec-ns-impact
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Jun 2020 21:54:04 -0000

Thank you Warren for checking in with Ben....and yes, Roman is a co-author but will let him voice his own opinion __

Giving a heads up to the TLS group makes sense as that is where the bulk of the comments to drive this latest version came from.

Warm regards, Nancy

On 6/15/20, 11:58 AM, "Warren Kumari" <warren@kumari.net> wrote:

    [ Top post ]
    
    Thanks Nancy, Tom, et al,
    
    I also checked with the TLS chairs and ADs[0], and Ben replied saying
    that he feels it should be fine in OPSEC[1], but that it's probably
    worth giving a heads-up to TLS if / when this approaches WGLC.
    
    So, great - as I think I've already mentioned, I happen to think that
    this is useful.
    
    Thanks everyone,
    W
    
    [0]: It's really not good having WGs stepping on each other's toes,
    and I hadn't been following this in TLS...
    [1]: Seeing as Roman is an author, I'm gonna count that as implicit
    support for it being here :-)
    
    
    
    
    On Thu, Jun 11, 2020 at 4:14 AM tom petch <ietfa@btconnect.com> wrote:
    >
    > From: Nancy Cam-Winget (ncamwing) <ncamwing@cisco.com>
    > Sent: 11 June 2020 03:30
    >
    > On 6/10/20, 5:42 AM, "OPSEC on behalf of Warren Kumari" <opsec-bounces@ietf.org on behalf of warren@kumari.net> wrote:
    >
    >     On Wed, Jun 10, 2020 at 6:18 AM tom petch <ietfa@btconnect.com> wrote:
    >     > From: OPSEC <opsec-bounces@ietf.org> on behalf of Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org>
    >     > Sent: 05 June 2020 16:04
    >     >
    >     > Folks,
    >     >
    >     > This email begins a call for adoption on draft-camwinget-opsec-ns-impact<https://datatracker.ietf.org/doc/draft-camwinget-opsec-ns-impact/>t/>. The call for adoption will end on 6/19/2020.
    >     >
    >     > Support
    >     >
    >     > I would have liked this to be a TLS document but the fact that it is not makes it even more important that it is adopted.
    >
    >     Actually, that raises an important point -- why is it *not* a TLS
    >     document? Are we wading into deep waters here? Did TLS object to this
    >     document, or just show no interest, or say "'tis a fine idea, but too
    >     operational for here, vaya con dios"?
    > [NCW] It is the latter, that is, it is more about the operational impacts of network security.  When it was presented at the TLS WG,
    > It was noted that the draft presented TLS use cases but from an operational perspective and didn't fit with their current charter.
    > There were suggestions that opsec could be a better fit.
    >
    > <tp>
    > I track the discussions on the TLS list, saw the discussion there inter alia and have a more jaundiced view.
    > <rant>
    > The TLS WG has many highly skilled, highly active proponents, more so than any other IETF WG I know.  Its culture I see as perfect security no matter what.  TLS 1.3 thus addresses all known problems no matter what.  If this renders it unusable in places, too bad - perfect security cannot be compromised.  This I-D says TLS 1.3 is not perfect in some settings so the TLS WG would commit suicide before ever adopting it.  Which is a shame since that is where the expertise lies and where any infelicities in the I-D might be detected.  Shame, but that is how it is.
    > </rant>
    > Tom Petch
    >
    >     Can this CfA be CCed to the TLS WG so that we get more review?
    >
    >
    >     W
    >
    >     >
    >     > Tom Petch
    >     >
    >     >                                         Ron and Jen
    >     >
    >     >
    >     > Juniper Business Use Only
    >     >
    >     > _______________________________________________
    >     > OPSEC mailing list
    >     > OPSEC@ietf.org
    >     > https://www.ietf.org/mailman/listinfo/opsec
    >
    >
    >
    >     --
    >     I don't think the execution is relevant when it was obviously a bad
    >     idea in the first place.
    >     This is like putting rabid weasels in your pants, and later expressing
    >     regret at having chosen those particular rabid weasels and that pair
    >     of pants.
    >        ---maf
    >
    >     _______________________________________________
    >     OPSEC mailing list
    >     OPSEC@ietf.org
    >     https://www.ietf.org/mailman/listinfo/opsec
    >
    >
    
    
    -- 
    I don't think the execution is relevant when it was obviously a bad
    idea in the first place.
    This is like putting rabid weasels in your pants, and later expressing
    regret at having chosen those particular rabid weasels and that pair
    of pants.
       ---maf