[OPSEC] draft-ietf-opsec-v6-17

"Bernie Volz (volz)" <volz@cisco.com> Mon, 22 July 2019 22:12 UTC

Return-Path: <volz@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E66A1200B8 for <opsec@ietfa.amsl.com>; Mon, 22 Jul 2019 15:12:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Level:
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=Cv8d7xUj; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=zEW2nAl8
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U4A-XwgKvbpe for <opsec@ietfa.amsl.com>; Mon, 22 Jul 2019 15:12:07 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EFD751200B1 for <opsec@ietf.org>; Mon, 22 Jul 2019 15:12:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1072; q=dns/txt; s=iport; t=1563833526; x=1565043126; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=W/TKpcm9unFkH2SUOSk8v1Yh8PgEjylK6GS2Ljm3dpU=; b=Cv8d7xUj0Ri8PXa5CQVHxzbrClgtyS5bF2xc2fzyCy3dzppvoE75fZUc rsx2QLMv4ZePwBAeJOPszneLsZmgXi1e7F0anRE1eif/IzvzCZgj1GCR/ EE/3CzxrYDw9m298LWCjxNDtd7Cq154swo8b20oVyhtVqY/bciKMWqBuv w=;
IronPort-PHdr: =?us-ascii?q?9a23=3Ai15juBw3vzaqCQ3XCy+N+z0EezQntrPoPwUc9p?= =?us-ascii?q?sgjfdUf7+++4j5YRGN/u1j2VnOW4iTq+lJjebbqejBYSQB+t7A+GsHbIQKUh?= =?us-ascii?q?YEjcsMmAl1HsmBG2XwLeXhaGoxG8ERHFI=3D?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0AIAAB7MzZd/5NdJa1cChoBAQEBAQI?= =?us-ascii?q?BAQEBBwIBAQEBgVMFAQEBAQsBgUNQA4FCIAQLFhQKh1oDhFKJK5orgS6BJAN?= =?us-ascii?q?UCQEBAQwBAS0CAQGEQAKCYyM0CQ4BAwEBBAEBAgEGbYUeDIVLAgEDEigGAQE?= =?us-ascii?q?3AQ8CAT4QMiUBAQQODRqEawMdAQKgUQKBOIhggiOCeQEBBYUMGIITCYE0AYt?= =?us-ascii?q?eF4F/gRFGhxoJLYM7giaqZwkCghmUJ5gKpQUCBAIEBQIOAQEFgVA4gVhwFYM?= =?us-ascii?q?ngkKDcYpTcoEpjUwBgSABAQ?=
X-IronPort-AV: E=Sophos;i="5.64,296,1559520000"; d="scan'208";a="600092276"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 22 Jul 2019 22:12:06 +0000
Received: from XCH-ALN-011.cisco.com (xch-aln-011.cisco.com [173.36.7.21]) by rcdn-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id x6MMC6Ui011375 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL) for <opsec@ietf.org>; Mon, 22 Jul 2019 22:12:06 GMT
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by XCH-ALN-011.cisco.com (173.36.7.21) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 22 Jul 2019 17:12:05 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Mon, 22 Jul 2019 17:12:05 -0500
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Mon, 22 Jul 2019 17:12:05 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=n3IAVsgdJS2a1kEtmxg9DImEpk5pVUHtJlbshNIFngwUpkKvMLtnwW9TOuXfrh+PSekUGXPvNTdosu78FuxxPVC5R/Z1dQcdkBh5xAIUtfv/ut2bG4dHz4fjvFN/zS3rrdwD3y7mbbXRymUht83V9KVlP2DCucnlZ6e6C4oKPKpljT6wGQXrJtUXJ4GbC1rwePqIum2NiJvjimOrZRfSzsKgzxOoK3b++vRBc/H5oojKDzn/IWRzJgQF5AtinpB2R5eFT6u7tiNBt7ydkzbfhzEv1wpQWPt2VqxzsuNg2BcXoOfz2+rFBPlyY1lD/3LtUwHIOeWf8+mQCk1gizBdKg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=W/TKpcm9unFkH2SUOSk8v1Yh8PgEjylK6GS2Ljm3dpU=; b=SWSOtDBpTtPw/9rgnpoIA5sucrLiCF9FBF4k2KvhkaHkTaHRFsTOsp2bXyiiC1m30rgB2ojnM+0E2wb1vegDeNDhMkpkWbmSq837yg8lSlzVpTGOIclBooz8tLfEMn/salaTSYeRKkbzc72S1cBss1T0xDR5dqIzLADrj53kmsHMXecY3CjQyvg4Q8/pLU44xB6dv6jJZXxG49SP+tfBOENsqVCTPOcF5dvaZDlndE/2BzMzvHWQQ3j3JLA+UW+OkFkLya0pTQJMkSH1nn/E6fe5Lee6L+VaSvTcFte5IQigeMN1TipPh8l2zrMCFnGSrBD1qiA9bbhps3d7Hnh+ng==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=cisco.com;dmarc=pass action=none header.from=cisco.com;dkim=pass header.d=cisco.com;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=W/TKpcm9unFkH2SUOSk8v1Yh8PgEjylK6GS2Ljm3dpU=; b=zEW2nAl8RYKkyI/TIy/uBLCrFvtIvajPfxQq8XwiuMP0jlBBFSA5MKyqNtj41Abh6DSijTgFl4rRn9T1DUILn2y4J5yhZCGJOnhyRqHTaQXAuGQyTyEUxsnPCAniikoIf29cQZ4J7SSqW47KHXPz8tk+BHdjVSu674cpVUG+Srw=
Received: from BN8PR11MB3601.namprd11.prod.outlook.com (20.178.219.23) by BN8PR11MB3602.namprd11.prod.outlook.com (20.178.219.24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2094.16; Mon, 22 Jul 2019 22:12:04 +0000
Received: from BN8PR11MB3601.namprd11.prod.outlook.com ([fe80::78f2:2e3e:7140:d829]) by BN8PR11MB3601.namprd11.prod.outlook.com ([fe80::78f2:2e3e:7140:d829%7]) with mapi id 15.20.2094.017; Mon, 22 Jul 2019 22:12:04 +0000
From: "Bernie Volz (volz)" <volz@cisco.com>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
CC: "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: draft-ietf-opsec-v6-17
Thread-Index: AdVA131ZRg7Av2Q1S0WVN4M41LlOvgAAumVg
Date: Mon, 22 Jul 2019 22:12:04 +0000
Message-ID: <BN8PR11MB360165CD7D50E6E65B976CA8CFC40@BN8PR11MB3601.namprd11.prod.outlook.com>
References: <BN8PR11MB36010E0BFF96507F396A6273CFC40@BN8PR11MB3601.namprd11.prod.outlook.com>
In-Reply-To: <BN8PR11MB36010E0BFF96507F396A6273CFC40@BN8PR11MB3601.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=volz@cisco.com;
x-originating-ip: [173.38.117.80]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: a3dd361e-503c-4f52-8601-08d70ef1a0c0
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:BN8PR11MB3602;
x-ms-traffictypediagnostic: BN8PR11MB3602:
x-microsoft-antispam-prvs: <BN8PR11MB3602EF81EA58D46957A6F451CFC40@BN8PR11MB3602.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:2512;
x-forefront-prvs: 01068D0A20
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(376002)(346002)(136003)(366004)(39860400002)(396003)(199004)(189003)(33656002)(74316002)(99286004)(14444005)(66446008)(256004)(64756008)(66556008)(76116006)(66946007)(66476007)(2940100002)(71190400001)(316002)(8936002)(486006)(6116002)(3846002)(2906002)(71200400001)(81166006)(81156014)(6862004)(478600001)(26005)(52536014)(9686003)(7736002)(55016002)(186003)(476003)(25786009)(11346002)(66066001)(305945005)(8676002)(53936002)(5660300002)(446003)(102836004)(6636002)(76176011)(4326008)(68736007)(7696005)(86362001)(6436002)(14454004)(6506007); DIR:OUT; SFP:1101; SCL:1; SRVR:BN8PR11MB3602; H:BN8PR11MB3601.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: 40ABLUcXQVW2FSYbDDOxE1yq+WMzO6jXGNDrH5VT8arlQqCCyMK9XmkpEbEpbOXZgFdCnhLta+/4b6rbDBLqNf0voynmfOHol3X4DZxxfSxK7F4I4MFrDwNzezhxi8U5C+eXXcnDx1ESQ1e6QEIwUj45M+nrdbtduVroi616fZBhe4LGCosqSfKWN14YxjaEiSrR49TpfNSa0l4msaV8jZQBgZ9ChqamEfrkfyywqo/I/65/ZfyXrBXl3FWcZvQ9Pv0axgagPTRg3WWKr0ofABdW1STHJ8pBjS64k0yYeS0mLzCHHzY1rgRMHQ1RtNy8FNcDOoLjzsIWxQRypLdm1BhQNMhkJboGQhA4LNeU6QXkfVPOkQOllnB0fNMRKN3JCuLzq/0UvPeDD+WdcDVzNQZ2e+LmveweJTu6/i+h5m4=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: a3dd361e-503c-4f52-8601-08d70ef1a0c0
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Jul 2019 22:12:04.2743 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: volz@cisco.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN8PR11MB3602
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.21, xch-aln-011.cisco.com
X-Outbound-Node: rcdn-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/dV-yw0AwUj35DG6ZgHRfUG-q-tk>
Subject: [OPSEC] draft-ietf-opsec-v6-17
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jul 2019 22:12:09 -0000

Hi:

Here's some very minor nits (RFC editor would correct):

1. s/feasable/feasible/
2. s/section Section 2.6./Section 2.6./
3. s/connectivity.Disabling/connectivity. Disabling/ 4. s/it has lead to nodes/it has led to nodes/ 5. s/formated/formatted/ 6. s/occurences/occurrences/ 7. s/ bypassed by an hostile party/ bypassed by a hostile party/ 8. s/be be/be/ 9. s/explicitely/explicitly/ 10. s/to identifity the interface/ to identify the interface/ 11. s/seperation/separation/ 12. s/hardened agains miscreant/hardened against miscreant/ 13. s/exception of an handful/exception of a handful/

Perhaps I missed it, but the document doesn't mention anything about using a random link-layer address (other than in the context of generating IPv6 addresses). Perhaps that's OK as this is an IPv6 document and that really is a separate link-layer security issue -- and you do have to draw the line somewhere otherwise it will never get done.

In all the document does look very good and hopefully can move to WGLC soon!

- Bernie