Re: [OPSEC] I-D Action: draft-ietf-opsec-v6-20.txt

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Sat, 12 October 2019 07:40 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B71C1120845 for <opsec@ietfa.amsl.com>; Sat, 12 Oct 2019 00:40:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.5
X-Spam-Level:
X-Spam-Status: No, score=-14.5 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=QzmkGBgW; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=nd7ufm+2
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V3yAdDGNAqxY for <opsec@ietfa.amsl.com>; Sat, 12 Oct 2019 00:40:56 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A03AC120851 for <opsec@ietf.org>; Sat, 12 Oct 2019 00:40:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=4148; q=dns/txt; s=iport; t=1570866056; x=1572075656; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=fU6t854t3uWfxi5KvK2hQ5q/RHa/R/G7XdS+TYyOVm8=; b=QzmkGBgWy6TriFAXbMlOvN2MdY+AHHNHDDrIxG2howlzWpPaQD92Grek wgFvloXVcLvoY7K5uHLsdn81BjpCXMNQ7EZYNYg6CMAgWg8w7Zck7Kbc5 2vZOhawAXipD5lLihOC1WFgW5NYN/YFtX/j00tMSAg60F0lXTnZkm9jZe U=;
IronPort-PHdr: 9a23:WMgHaBO0sOK0Pluq/gEl6mtXPHoupqn0MwgJ65Eul7NJdOG58o//OFDEu60/l0fHCIPc7f8My/HbtaztQyQh2d6AqzhDFf4ETBoZkYMTlg0kDtSCDBj2Mu/sZC83NM9DT1RiuXq8NBsdFQ==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AYAAAqg6Fd/4cNJK1mGwEBAQEBAQEFAQEBEQEBAwMBAQGBZwYBAQELAYFKUAVsViAECyqEI4NHA4RYhXKaWoEugSQDVAkBAQEMAQEYCwoCAQGEQAIXgkcjNAkOAgMJAQEEAQEBAgEFBG2FLQELhUwCBAEBEBERDAEBLAsBDwIBCBoCJgICAiULFRACBA4FIoMAAYJGAy4BAgynIwKBOIhhdYEygn0BAQWBOAIOQUCCOhiCFwmBDCgBjA0YgUA/gREnH4JMPoJhAQECAQEWgUcXgncygiyPb51YCoIihwiJM4ReG4I6L0OGXI84ji2IIpEVAgQCBAUCDgEBBYFSOYFYcBUaISoBgkEJRxAUgU+Dc4UUhT90gSmQHgEB
X-IronPort-AV: E=Sophos;i="5.67,286,1566864000"; d="scan'208";a="645586381"
Received: from alln-core-2.cisco.com ([173.36.13.135]) by rcdn-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 12 Oct 2019 07:40:56 +0000
Received: from XCH-ALN-002.cisco.com (xch-aln-002.cisco.com [173.36.7.12]) by alln-core-2.cisco.com (8.15.2/8.15.2) with ESMTPS id x9C7etXw016829 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Sat, 12 Oct 2019 07:40:56 GMT
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by XCH-ALN-002.cisco.com (173.36.7.12) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 12 Oct 2019 02:40:55 -0500
Received: from xhs-rtp-001.cisco.com (64.101.210.228) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 12 Oct 2019 03:40:54 -0400
Received: from NAM05-DM3-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-001.cisco.com (64.101.210.228) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Sat, 12 Oct 2019 03:40:54 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=WhLax8vGdwfapPl2zo3RBjWKU51tC+1MlbzrI7eGTgBzPBbuXbLrm0qYUteHsYDZbN9W+jCDX6tMMS5Kquiy96ukoRaEf6HrjvMoYOPWUG3HE6LyD2rK1BDgZRXrEAFaim/QxErvWgFOsLe76a2WlMCSW1MzWTIi8atFR54P/2MZExCPq3bwXht3Q0uy9JKeaRy/do2vfDk781M7utrPSUrJpk8oKw3jRuFMuyCVzNdVa3MIamd9z8UAoZGrvSJjonwZx9/p50jW0Pvzt1UxC47n3K1TBH66pGANqcnrAlnz7WsQ1UtcG0bq6ghIv1hczt46cRDFC7fbAWhga/yPRw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fU6t854t3uWfxi5KvK2hQ5q/RHa/R/G7XdS+TYyOVm8=; b=B/2kP6aO37RG7Vh67+d+hR2D8g6Huuk9V0MxhU4WgwLQ97RlhIK7jW58STXjhZH6dhC8A5tl5iHbs8KunoUqm3LMkD+ksc9PxgxBEszNHtxwZNov1zy6HAcrGkW4TdLjXTyLpdV0dQGJ+GEVvfAAD/iLVP6EIUV8Ta/2rBDj3RL1JV8TF28wnktklGNf/xIs2BvInnt4vcNsit2oOWFf/bBBc6UI8GfUpdg+L2HBaHPQX/smJ5+TBsko/5bpEsRxjtbrySx+tfFWXyioxSDwl9nm5v5VNO/D0P8EO6oMfB0jQh3BewpthR+0TDB6X0UKiLhcOjyeHBR7mHRboFFijQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fU6t854t3uWfxi5KvK2hQ5q/RHa/R/G7XdS+TYyOVm8=; b=nd7ufm+2gfXICct0oIvNuRdGw4Dpb5moYfCdlB52yWnb3j1OsaatcF+YKCobM5Lr2I0Ieki8iDutXrzDSIp4LcmJURaEXAeFHNrOktwaHHpiuFbhTRLDKHOYwXWIBPEHWExomkGGU6l9UD8rh+X1pbu6D4I4XvHhlvNmVJYrDvM=
Received: from MN2PR11MB4144.namprd11.prod.outlook.com (20.179.150.210) by MN2PR11MB3630.namprd11.prod.outlook.com (20.178.253.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2347.18; Sat, 12 Oct 2019 07:40:53 +0000
Received: from MN2PR11MB4144.namprd11.prod.outlook.com ([fe80::e4f8:d335:c018:c62a]) by MN2PR11MB4144.namprd11.prod.outlook.com ([fe80::e4f8:d335:c018:c62a%7]) with mapi id 15.20.2347.021; Sat, 12 Oct 2019 07:40:53 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: "opsec@ietf.org" <opsec@ietf.org>
Thread-Topic: [OPSEC] I-D Action: draft-ietf-opsec-v6-20.txt
Thread-Index: AQHVgM9rjNu0gahqL0CwhI/yzqaHUKdWwKcA
Date: Sat, 12 Oct 2019 07:40:52 +0000
Message-ID: <AD406E0A-4CAF-44FE-A583-3A6E4E4A0FD4@cisco.com>
References: <157086559138.1393.1472645196672102960@ietfa.amsl.com>
In-Reply-To: <157086559138.1393.1472645196672102960@ietfa.amsl.com>
Accept-Language: fr-BE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1d.0.190908
authentication-results: spf=none (sender IP is ) smtp.mailfrom=evyncke@cisco.com;
x-originating-ip: [2001:420:c0c1:36:750f:3f7a:6233:2b3e]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b35d3474-b4b2-451d-7508-08d74ee78282
x-ms-traffictypediagnostic: MN2PR11MB3630:
x-ms-exchange-purlcount: 5
x-microsoft-antispam-prvs: <MN2PR11MB3630C59D4614E230085C23F3A9960@MN2PR11MB3630.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0188D66E61
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(366004)(396003)(39860400002)(376002)(346002)(136003)(189003)(199004)(76116006)(91956017)(2501003)(64756008)(2906002)(256004)(476003)(6306002)(966005)(66556008)(66446008)(76176011)(6512007)(66476007)(81156014)(81166006)(66946007)(8936002)(58126008)(486006)(33656002)(54906003)(8676002)(6116002)(14444005)(4326008)(99286004)(1730700003)(186003)(102836004)(316002)(6506007)(6436002)(6486002)(71200400001)(305945005)(446003)(36756003)(6246003)(2351001)(25786009)(71190400001)(66574012)(6916009)(229853002)(478600001)(2616005)(5660300002)(7736002)(4001150100001)(14454004)(86362001)(5640700003)(11346002)(46003); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR11MB3630; H:MN2PR11MB4144.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ive+ufKTnjNKXq1+2Jno5T8b4JNliQLotuo9HJGgUvhuphyUCm5BjhH3bQ8xHEoi6uvYLQZTCrampB6ThqGhvyECKERhaGl6GaILGPpL+Gc9zyLdcjLQuQC4LNL7Wt/k+gw1IrepE2cvsYofqOUlMFsXfAHoZsEM/pSAfT3S0OviCypHN/lhKdJhRT1MLn81wZ11orvR598VQwiUTK1OPI0kqyi9hnT7IOx76dnfMgOQ+xQOzDXFjgVRt8BBA0qVjjgwxtKDXVhFeKrS9h2JOENiVtQkS7fiff5K8BEaGEwBDNtq8+Gc9tga5bQkpkTHHHs4suXcpwPN01nZGK47IKBKN1IkjdZiNB9mc8/Va8y4uLjWqK1slDtuXiKfaWSKSXyUDV58/1ONPvl2AXLvppBedNnNdnli1uPuP2D3Vh9cyi1FKGsrl+n22u8xCGE6m0TLUxYSLWWmId1SuaIRFA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <81FB5D0011BCE143AF4F3B478757BDDE@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: b35d3474-b4b2-451d-7508-08d74ee78282
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Oct 2019 07:40:52.7715 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: a5JW50flfkT4opinM/BOtS4ROlUHBVoWe69Dh0Pxx9L85NNm+MmBDWQKZ0HGznQr7MfFQ2VWG+3NoL3U0aOV1w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB3630
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.12, xch-aln-002.cisco.com
X-Outbound-Node: alln-core-2.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/ssxpre9hkQ91L61a2vcxzZO1dLY>
Subject: Re: [OPSEC] I-D Action: draft-ietf-opsec-v6-20.txt
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 12 Oct 2019 07:41:07 -0000

As you will notice in https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-v6-20 this latest revision addresses a suggestion by Gyan Mishra issued during the Working Group Last Call. Other changes are mainly replacing the normative "MUST" and "SHOULD" as it is an informational document (so it is now "must" and "should") + removing an unused informational reference.

Jen and Ron, as the authors have addressed all comments received during the WGLC (actually by only one reviewer) and the extensive review by Jen, may I kindly request publication of this document?

Thank  you all

-éric -merike - kk -enno


On 12/10/2019, 09:34, "OPSEC on behalf of internet-drafts@ietf.org" <opsec-bounces@ietf.org on behalf of internet-drafts@ietf.org> wrote:

    
    A New Internet-Draft is available from the on-line Internet-Drafts directories.
    This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure WG of the IETF.
    
            Title           : Operational Security Considerations for IPv6 Networks
            Authors         : Eric Vyncke
                              Kiran K. Chittimaneni
                              Merike Kaeo
                              Enno Rey
    	Filename        : draft-ietf-opsec-v6-20.txt
    	Pages           : 52
    	Date            : 2019-10-12
    
    Abstract:
       Knowledge and experience on how to operate IPv4 securely is
       available: whether it is the Internet or an enterprise internal
       network.  However, IPv6 presents some new security challenges.  RFC
       4942 describes the security issues in the protocol but network
       managers also need a more practical, operations-minded document to
       enumerate advantages and/or disadvantages of certain choices.
    
       This document analyzes the operational security issues in several
       places of a network (enterprises, service providers and residential
       users) and proposes technical and procedural mitigations techniques.
       Some very specific places of a network such as the Internet of Things
       are not discussed in this document.
    
    
    The IETF datatracker status page for this draft is:
    https://datatracker.ietf.org/doc/draft-ietf-opsec-v6/
    
    There are also htmlized versions available at:
    https://tools.ietf.org/html/draft-ietf-opsec-v6-20
    https://datatracker.ietf.org/doc/html/draft-ietf-opsec-v6-20
    
    A diff from the previous version is available at:
    https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-v6-20
    
    
    Please note that it may take a couple of minutes from the time of submission
    until the htmlized version and diff are available at tools.ietf.org.
    
    Internet-Drafts are also available by anonymous FTP at:
    ftp://ftp.ietf.org/internet-drafts/
    
    _______________________________________________
    OPSEC mailing list
    OPSEC@ietf.org
    https://www.ietf.org/mailman/listinfo/opsec