Re: [OPSEC] Opsdir early review of draft-ietf-opsec-v6-13

Tim Chown <Tim.Chown@jisc.ac.uk> Sun, 14 February 2021 15:55 UTC

Return-Path: <Tim.Chown@jisc.ac.uk>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E80903A0E3F; Sun, 14 Feb 2021 07:55:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.201
X-Spam-Level:
X-Spam-Status: No, score=-0.201 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=jisc.ac.uk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EOyHuos9aep1; Sun, 14 Feb 2021 07:55:28 -0800 (PST)
Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05on2043.outbound.protection.outlook.com [40.107.20.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F3C613A0E3D; Sun, 14 Feb 2021 07:55:24 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lNEdGBmt6varGxuRuvd0uoZ2DiwQxirAXk/WS6B5LV+kxYBcaDCKTvm0VoHjThsli9Sxo7sf36oNg/nyccsRIFRDi+tWigCLRPS7JnDPv5iY7kMAmL+GFo2EKbZwOdlE1fOxA7QNAPxC4I4W9dltdQVH4VBeU5ntxT+IxhhefszXg3pxETxlBp9CsUM1Q36LnT3qzDtJR+UVyqEHxo0KqP2+MpRN/DfekcCRfXZSS0tOiVMOBJn8U6ApZFyTLoTOEuk+9bjOuUFwDrlunflrIQCPX+XMycx2Qm+eyZ4q4VZr4Q0o8nBea+Nq0Ie2LR5G/nPQh0NU42FJ5zg0ZeYwFg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nEl7xGcE7InJDeqBSoDOKV6MqhbDsINVSVxtqgJ+WrU=; b=CFE+3OWmuOoHBkVnxBqgycTzpK4Q1r1DzB2qAZibtVWsM+Md75Dcn/NuLIuSCldp9wNpHpQeWvw1w1molhhqTPGBkQMECPuERKMaS6elzLGY/ckNOzf8uo5S4iAHN1tdDYYa/67uGUzqTXOzJSTe2dyLzq0nQY1TwjSEarz5jYJ7T+OgahjJkQ/jsB9N9mdkQNLmRu7tfBu6vAFdO19SzWA9JpThabNvSrl6wZNeqxX3iZl0nyrSramQz3RDvnM0XIwGMxq0s1c0QgpssWFsvUk10qhpUZyuEulLzmNxofOhkxpijSyvgiunXdm1pV1zZihKCeiyCcVwEH7opt12YQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jisc.ac.uk; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nEl7xGcE7InJDeqBSoDOKV6MqhbDsINVSVxtqgJ+WrU=; b=Yqcdu3jdYdSGG5VXdhYvE12Zc+64r4ErO2ibV0JG3STSGkMC3GgkN8gzEhAIIe5EJD/kHyzEhoPzSx8JD5bkpa8hD/wJTIz9f9S+ExYZe+zkf1vBVtinoeAKCxUyYcSyTt4MlA1rUKg2oKSTpKba8HK6kpGsNygtTthGcgvZQ1M=
Received: from (2603:10a6:802:5f::17) by VI1PR0701MB2510.eurprd07.prod.outlook.com (2603:10a6:800:6f::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3846.11; Sun, 14 Feb 2021 15:55:18 +0000
Received: from VI1PR07MB4205.eurprd07.prod.outlook.com ([fe80::f569:5948:ad02:4af4]) by VI1PR07MB4205.eurprd07.prod.outlook.com ([fe80::f569:5948:ad02:4af4%7]) with mapi id 15.20.3868.015; Sun, 14 Feb 2021 15:55:18 +0000
From: Tim Chown <Tim.Chown@jisc.ac.uk>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
CC: "ops-dir@ietf.org" <ops-dir@ietf.org>, "opsec@ietf.org" <opsec@ietf.org>, "draft-ietf-opsec-v6.all@ietf.org" <draft-ietf-opsec-v6.all@ietf.org>
Thread-Topic: [OPSEC] Opsdir early review of draft-ietf-opsec-v6-13
Thread-Index: AQHW/jIwSjpvdYGyk0yyEp8lUhza1qpX1zAA
Date: Sun, 14 Feb 2021 15:55:18 +0000
Message-ID: <73B48C22-EB99-4D75-937F-1407756E9BF4@jisc.ac.uk>
References: <153055392479.16095.569198674604354407@ietfa.amsl.com> <AEBE3D2F-55AD-40EC-BC80-A9560C4E0298@cisco.com>
In-Reply-To: <AEBE3D2F-55AD-40EC-BC80-A9560C4E0298@cisco.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3608.120.23.2.4)
authentication-results: cisco.com; dkim=none (message not signed) header.d=none;cisco.com; dmarc=none action=none header.from=jisc.ac.uk;
x-originating-ip: [212.188.254.49]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 4d48b1be-09ec-41f9-7a8f-08d8d100ed66
x-ms-traffictypediagnostic: VI1PR0701MB2510:
x-microsoft-antispam-prvs: <VI1PR0701MB251010E494811DC6AB551E23D6899@VI1PR0701MB2510.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: mzo4F0xMrM2RaVR74v4jHKPx9UVRSKP6xKekcFh8Hw7pZqt7b5rhyJScPvTzT+dJVWyMixSwHRKRlZkZzrfiMDwmB0rlMAqefYzt/Ryd8KQsmyvnzXicTDoKPISCWt+bDLs3ijfQOD3clvgalTqFw+MD6SuQcPj0sM/E4/BtWSV+Quwp+diMnmpGXrRd0q5gYM4zLXGmv+N9CI4C76rUBcW98MnWsinCgO8/szRrUmMgs08DinHuCtaZ/JD3B2KeT4zTRKFm3oS0cQsBwztNf3u41irucXYKuIj1ytK3yluoiZdh+w4L/fPCOIU3Qpa5DyoZYHJb+q2hB3WmDNEORQ0wsJN0io3WuBX3+QoRlrtvwWuEkflw6tRkUXzt6Zwy/IFYpVnkLupN6VW7aH2teZsfcx8JbNJrT6r3s2t+XiqgpRrxibS5Wwoy9str8/RjIHGLJ+LfbZBy/DNbHOYUYyS9//x3CbrxDlsYI3RZcOBKD4xop2GV14Sp6qeRbuoa2LA412xM3el/YX8R0ePdw8TZIX+Tz/+6C0QIJ/uAR8usr+W7Last95iKEjTLGd/XHZp/4Elg0ivs7xYnBFuw+A==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR07MB4205.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(136003)(346002)(396003)(39840400004)(376002)(366004)(786003)(6506007)(8676002)(26005)(86362001)(2616005)(6916009)(6486002)(54906003)(53546011)(316002)(36756003)(5660300002)(186003)(66946007)(55236004)(66476007)(71200400001)(76116006)(91956017)(8936002)(66446008)(64756008)(66556008)(2906002)(478600001)(4326008)(6512007)(33656002)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: =?utf-8?B?UVlPVlgrcXJiSkNSa0xwQ25wcU1sNFFzN1c5VHdMU1cxS2ZnZkNjVXd5bTVZ?= =?utf-8?B?UVZrLytBUkIyQlhGSlZoS3YzOStpd3pQUkV0MGxrOUxSSEN5clhOVjlNTGRi?= =?utf-8?B?UlhOZFN1bHd5YmJCalhuMXNWNmtVc3FRdExvTlVTcmU1TnFOMXhoVUdHR09r?= =?utf-8?B?MnB0QnhoTWo5dUVibHVBRURoMTZrSXAxNXFEQ1JmNkxxMXFyZkdYdThlZVpM?= =?utf-8?B?c2lzSzBST1lLWEcxWkpwbVZCZ1kwc0htM0M2NUxYWnMzeXg3NGdpSWt2d2RH?= =?utf-8?B?eWxpTXdoVEV5MEdkVDFNcDlPZ0VaY25SS1hoVUJmUlNFNm1TSVNMRU0wdmhs?= =?utf-8?B?bG9pOWJDT1cvMnNVRnR2UTlkLzB0bzJZcndtaGlEWFg3eUJVMVBRdTZMSnEy?= =?utf-8?B?dDIxUkhQeU14Z3NjWVVYZVRlSTYySFlrN3g4NnhvcVRGY1lqNGtqQkVHSEdy?= =?utf-8?B?elN4Ti9tbHYzRWVJdW1rNVlYTjV0VVNlRUlhRVoreUxKQ1JqWGR6VUl2TVlD?= =?utf-8?B?SnBUYTZRc3diSmF6blAxdzRPaGowOFVkRmY1UXFrVjV5c2tFbHh4NVN6MTlM?= =?utf-8?B?UXNHVlQ4T1Q2eFdxMHdIdW1LNHlrWEtlSENRNjBOMU1sRnJtOHJvVytBYTNS?= =?utf-8?B?RXBlb3dGTDkwOFRmcllvRGw1S2Vwc3Ixdm1VWUxjY2dMNk93S3lhVnhOcDBP?= =?utf-8?B?dVp2cG11K1M5Q1BBeUhNNEEzQzZSRzFDcHhwTlo2WDdyOExwUmNHcTN2Y2tt?= =?utf-8?B?enFPT1NaWjBDMnpzVWxXTUpydXZGVzlhekc4aUQxOXRaejV2Rk9GNDJKZC9k?= =?utf-8?B?aVFISFBYVzZoV2hGTmNVNi9WV0dpZVlWZTBTaUdhWWVDbWJVRmpMSDNXVkZY?= =?utf-8?B?TkZkcUdNeGpURUhGWHF3cGM1cEdjdElnQ2M4SjZOenp5VHRHbTFqZENXRmxk?= =?utf-8?B?T2xhU2lLK0oxK1pESUNRVEh4SkViczdFTEU2QXUxbmlLVUZYcWpLVVpmYm9H?= =?utf-8?B?VFdsSnlraFVWb3EwTUVVdEJWazlDRnlJL1U2bzBvdm9DVEZTK2J3d2hvWUdI?= =?utf-8?B?bStPS3IvNmNRRlRNK1RzL1djS2VYNVJ4SFV5d2ZqUmVYanBjVi80eDhLRDRo?= =?utf-8?B?cmVTRjB1bFJIaE1peWpoTC9Xc2lEb1hUazZRcU5NQ1B3bTNVQ3gxVzlhYmJ3?= =?utf-8?B?NFk0RktZRDNQVmpSek0rckxIWGRiYTUzNndyUERpelhwN1BZbEdVYWgzK1c3?= =?utf-8?B?ZWwxR3BZKzVMVFVDZS8wR0N0elQ2Zlcra1BZNHBBT2JhbjhTeXRpcWRrdnFH?= =?utf-8?B?Y3VtU2RBWEUyQkducDlZc2E5NktYOG1XTTQybjNIZVdVM1ZkUkh1cXpsb3cy?= =?utf-8?B?UEF4S2diQmM3YVlUSDR0ZHNqYTdFb2R3bUJlRjdlTzNhVFljTW9vdjlMd1ZI?= =?utf-8?B?bmMxMXRiVlZ6SUVQaDBIVkhaR04wK205U1pWY05HaTJxN05NVU8xb05lb1d4?= =?utf-8?B?ejNaVGNBcDNwY1VGTTJudjdYUUVnbXR2TXhyOW5OWndLS3NNQnlERE80aFdJ?= =?utf-8?B?cGFFMDBTVUlGc1cxMHo5RjFvejdCTlZ4ME5Hc0dNa3FaVlFPS1dXc2RVN3BH?= =?utf-8?B?NVBtYUVEeVBaaE9rMG5xWHNaSTRGbGlRdXdCOFVSSGM4dDlIOXREWDdDSzFC?= =?utf-8?B?eDBkNGRIN0UwbUEyaHlWK3RSN1NEQzJDMnhqTW5DaVd1M2h3OWxNbjRBb3cy?= =?utf-8?B?S1MvM21xRGhEVkYzQWhMS3dGSU04Rm41K2JUZUg4dmVnVGhaRDlWVHZiYjdD?= =?utf-8?B?SjYrNnRBSUxoSmYyanh6Zz09?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <CB3D68A26DFF6844A6CCDEF1BE6FDC76@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: jisc.ac.uk
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: VI1PR07MB4205.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4d48b1be-09ec-41f9-7a8f-08d8d100ed66
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Feb 2021 15:55:18.5267 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 48f9394d-8a14-4d27-82a6-f35f12361205
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: c4g6F0Ncb1I8wYU6FJ7vuVnKfodMwA6FQ/rDylJvB2fYOqFcIXoSmyZEtaS4pKKvrLyezNDH4j5z0qyHVgPCMg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0701MB2510
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/WBJ-4L0rnCL9il8GddgyWYfun74>
Subject: Re: [OPSEC] Opsdir early review of draft-ietf-opsec-v6-13
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Feb 2021 15:55:31 -0000

Hi Eric,

> On 8 Feb 2021, at 15:50, Eric Vyncke (evyncke) <evyncke@cisco.com> wrote:
> 
> Hello Tim,
> 
> Better very late than never… Having some time this week to make some progress on this I-D... I hope to publish a -22 before the IETF-110.

Good luck with that!

> Some comments on the outdated review are prefixed with EV>
> 
> Thank you for your review :-)

The rewritten sections look a lot better.  Everything you’ve said below inline seems ok, but I guess we’ll be re-reading the fine final draft soon?

>    There are seven pages on transition technologies; might that be better homed in
>    a -bis of RFC 4942?
> 
> EV> we tried to be exhaustive and gather all (?) references in this single document even at the expense of 7 pages.

Fair enough, and a -bis of 4942 could be another epic undertaking!

>    The recommendation to use PI for a larger network implicitly means no NPTv6?
> 
> EV> the text has been modified in more recent versions.

Seems a good compromise, though invariably contentious.

>    p.13
> 
>    A lot of text on something hardly used?
> 
> EV> let's leave the SeND text here anyway for archival __

I guess so, but that “over a decade” since specification is soon two decades :)

Best wishes,
Tim