Re: [Pce] draft-ietf-pce-pceps-08 available

DIEGO LOPEZ GARCIA <diego.r.lopez@telefonica.com> Tue, 08 March 2016 23:23 UTC

Return-Path: <diego.r.lopez@telefonica.com>
X-Original-To: pce@ietfa.amsl.com
Delivered-To: pce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9F5BA12DC1A for <pce@ietfa.amsl.com>; Tue, 8 Mar 2016 15:23:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.048
X-Spam-Level:
X-Spam-Status: No, score=-2.048 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URG_BIZ=0.573] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([127.0.0.1]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PIfJ6dHATUTI for <pce@ietfa.amsl.com>; Tue, 8 Mar 2016 15:23:45 -0800 (PST)
Received: from smtptc.telefonica.com (smtptc.telefonica.com [195.76.34.108]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AAFC812DBF6 for <pce@ietf.org>; Tue, 8 Mar 2016 15:23:44 -0800 (PST)
Received: from smtptc.telefonica.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E3FDE4610B0; Wed, 9 Mar 2016 00:23:41 +0100 (CET)
Received: from ESTGVMSP112.EUROPE.telefonica.corp (unknown [10.92.4.9]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (Client CN "ESTGVMSP112", Issuer "ESTGVMSP112" (not verified)) by smtptc.telefonica.com (Postfix) with ESMTPS id CA6E64610A4; Wed, 9 Mar 2016 00:23:41 +0100 (CET)
Received: from emea01-am1-obe.outbound.protection.outlook.com (10.92.5.139) by tls.telefonica.com (10.93.6.54) with Microsoft SMTP Server (TLS) id 14.3.235.1; Wed, 9 Mar 2016 00:23:41 +0100
Received: from DB4PR06MB0624.eurprd06.prod.outlook.com (10.161.13.142) by DB4PR06MB0621.eurprd06.prod.outlook.com (10.161.13.139) with Microsoft SMTP Server (TLS) id 15.1.415.20; Tue, 8 Mar 2016 23:22:39 +0000
Received: from DB4PR06MB0624.eurprd06.prod.outlook.com ([10.161.13.142]) by DB4PR06MB0624.eurprd06.prod.outlook.com ([10.161.13.142]) with mapi id 15.01.0415.024; Tue, 8 Mar 2016 23:22:39 +0000
From: DIEGO LOPEZ GARCIA <diego.r.lopez@telefonica.com>
To: "t.petch" <ietfc@btconnect.com>
Thread-Topic: [Pce] draft-ietf-pce-pceps-08 available
Thread-Index: AQHReSZCB5QxNJ2BTE2pkaWi/ipC2p9QMIEA
Date: Tue, 08 Mar 2016 23:22:39 +0000
Message-ID: <408A224E-788A-41FB-9DDF-645154088A40@telefonica.com>
References: <06EC97F2-E307-4AB9-AF08-ABFAAAE20B42@telefonica.com> <011901d15ea5$73702840$4001a8c0@gateway.2wire.net> <55E4A7A6-4BEB-402E-B7FA-F99B6818B82A@telefonica.com> <30887501-8EDE-41A1-9589-6DCD43F9E4B6@telefonica.com> <021a01d17925$ad52f160$4001a8c0@gateway.2wire.net>
In-Reply-To: <021a01d17925$ad52f160$4001a8c0@gateway.2wire.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: btconnect.com; dkim=none (message not signed) header.d=none;btconnect.com; dmarc=none action=none header.from=telefonica.com;
x-ms-exchange-messagesentrepresentingtype: 1
x-originating-ip: [92.103.206.2]
x-microsoft-exchange-diagnostics: 1; DB4PR06MB0621; 5:AW7IPAV4XjCcaT3DmQxWpcozG6teg8wq98G6JX1upAIOIlU73KQScE9YZ4hi4QiZQKZjocZwPdOkiCmvjl87oEqn1TZhFZuDlsJ/Cnv9Ck+HKtkiVOCBiSuzNLyA01xr/btaazBf9OIukSbVPFgvmw==; 24:VKBWm2wHl6p8jTLyLSBjYkdzNkDIZ99NkyVK5Et7djRCY6jabMbqE18lCAyKgI18mMMFL+7LOTf4yWHYw5Lwbc3guXlbJck9fhHdmYUBnsA=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:DB4PR06MB0621;
x-ms-office365-filtering-correlation-id: bd270b32-2c5d-40ac-b4f7-08d347a88a70
x-microsoft-antispam-prvs: <DB4PR06MB06211904F5BB98DFEFF2CDD8DFB20@DB4PR06MB0621.eurprd06.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(178726229863574);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001); SRVR:DB4PR06MB0621; BCL:0; PCL:0; RULEID:; SRVR:DB4PR06MB0621;
x-forefront-prvs: 08756AC3C8
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(40134004)(24454002)(13464003)(252514010)(377454003)(25724002)(122556002)(36756003)(230783001)(87936001)(5004730100002)(83716003)(77096005)(15975445007)(110136002)(16236675004)(19580395003)(3846002)(6116002)(50986999)(19617315012)(66066001)(93886004)(2906002)(76176999)(86362001)(5002640100001)(54356999)(106116001)(4326007)(102836003)(1096002)(92566002)(33656002)(189998001)(10400500002)(19580405001)(2950100001)(11100500001)(3660700001)(3280700002)(5008740100001)(81166005)(2900100001)(586003)(82746002)(1220700001)(7059030)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:DB4PR06MB0621; H:DB4PR06MB0624.eurprd06.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_408A224E788A41FB9DDF645154088A40telefonicacom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 08 Mar 2016 23:22:39.0216 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB4PR06MB0621
X-OriginatorOrg: telefonica.com
X-TM-AS-GCONF: 00
X-TM-AS-Product-Ver: IMSVA-9.0.0.1549-8.0.0.1202-22180.003
X-TM-AS-Result: No--16.064-7.0-31-10
X-imss-scan-details: No--16.064-7.0-31-10
X-TMASE-Version: IMSVA-9.0.0.1549-8.0.1202-22180.003
X-TMASE-Result: 10--16.063800-10.000000
X-TMASE-MatchedRID: J/7EfC5NCOHuYusHgJkgyv+o/UjIXF0CgB9jdxVa+8niXx1dRWbSN2/s 2eocV1AZpX/ylnplxk4OwH4pD14DsCxnoxrvBxBL7GmyCFxoQXyvloAnGr4qhnymGU60F0DfYjA FsAuJw/US9vqRGF04eOS7PZsP9IZBtqvi2c3GYAohotH7bEpEMlUIlHgugm7izhDLXqypizGAwv 1Q6AIE9xJyXcKHwTmXirohpD7u1qfMtcKqKm5OTxE2nvEP7i9Rm3r1P/1/af3fl0PvqvMF942nX OxgW0tACE4ZIPoJ1hCKjenjWS+n4WwjJ4TFeU1uddAlhLX1ybUSiK+jB2RSdRZ0n9DHfDte3gcc Fgm2Mi5UAnueMw/a9cL+5IGlCvSWcFEiuPxHjsVzijlDBYeD/BPigAxSY2xyZYwvxnUY2Yt/kjA 7LIzvhPmyw6BAQmGz7nVkzMb2RnJ7yUFXk36O1r3uMg0Sp91V1b8ouJyjd7bFwC8P6iOcdE701z X0l7ellhyjQ88fgWxSBV8Hd/TXHU7kaVDgZS3v8tTecmKZD7VQA8bD9y6NeoiibtwoSwQQqV+up Ebvkl1COFtbMEPQCkiaSgSucQFJw/iEAlSd4kZvuwkbg5k7VaqOtCJT2Ac7Vj85bTD+v41NQDaK 5NBPFLRd0WwZSVdN/Nck001Q47wwiJTf3kjwffcku775L1VGW+jwVKpqvlLSXEchHk0QJP8YY65 2UuuS3OFhFhfTARl4+z8LHUMl3Wpvu7nPUm2NsFKgbrcPaUy0REtjlqSW5epTLxovCU8rT0qDR5 5DxM6XZ4pHs8oNkmPQjzs+tSjfl+MkkDBAmyiM6WiEDYDvJ5soi2XrUn/JlR1cT9YafQUVR7DQW X/WkUx6nJ5EP0r4vWwHpaiOpDlw69XmV1XYOAgba0jhlfsrF9JIs6gnfFhROSSE0kffi5tNm/uJ Gtb6SUXV+ZdI3bpTXE+tJQscZzy30vr15Zmku6TZFUvTmikvsIQcw0Vs1+k+ebCLJQBDPgxj8jK /OpU=
X-TMASE-SNAP-Result: 1.811037.0001-0-1-22:0,12:0
Archived-At: <http://mailarchive.ietf.org/arch/msg/pce/2kZK9_e7_8tq-HretWgyOfkp7lk>
Cc: "pce@ietf.org" <pce@ietf.org>
Subject: Re: [Pce] draft-ietf-pce-pceps-08 available
X-BeenThere: pce@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Path Computation Element <pce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pce>, <mailto:pce-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pce/>
List-Post: <mailto:pce@ietf.org>
List-Help: <mailto:pce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pce>, <mailto:pce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Mar 2016 23:23:48 -0000

Hi Tom,

(what are you going to leave for the shepherd and the RFC editors? :-))

The PCC/PCV mistake was caused by my fiddling with line breaks to make a more readable XML source when updating to -08. Good catch!

And you are right that RFC5288 should be mentioned in section 3.4, and among the normative references.

-09 on its way. I hope this will be the one able to progress…

Be goode,

On 8 Mar 2016, at 11:29 , t.petch <ietfc@btconnect.com<mailto:ietfc@btconnect.com>> wrote:

Diego,

Yes, understand the logic but (ducking) it was
"  In addition, a PCC MAY apply the procedures described in [RFC6698]"
and is now
"  In addition, a PCV MAY apply the procedures described in [RFC6698]"

Separately (why can't I get it right first time?), your MTI ciphersuites
are defined in RFC5288 which I think should be a Normative Reference
from s.3.4

Tom Petch

----- Original Message -----
From: "DIEGO LOPEZ GARCIA" <diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com>>
To: "t.petch" <ietfc@btconnect.com<mailto:ietfc@btconnect.com>>
Cc: <pce@ietf.org<mailto:pce@ietf.org>>
Sent: Sunday, March 06, 2016 8:18 PM


Hi again,

I forgot to mention that we’ll change the mention to “client” and
“client certificate” in the third paragraph of 3.5. But the mention to
PCC in the discussion of the use of DANE has to remain, as DANE is
mentioned in the context of DNS discovery, that is only applicable by a
PCC.

Be goode,

On 6 Mar 2016, at 21:08 , DIEGO LOPEZ GARCIA
<diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com><mailto:diego.r.lopez@telefonica.com>>
wrote:

Hi Tom,

Apologies for the delay (other urgent requests piling up…) Dhruv has
just reminded me of this comment of yours. I think you are right: It is
much better to maintain symmetry in the TLS verification and use a
general term that includes both peers. I’ll upload an updated version
right now.

Be goode,

On 3 Feb 2016, at 18:06 , t.petch
<ietfc@btconnect.com<mailto:ietfc@btconnect.com><mailto:ietfc@btconnect.com>> wrote:

Diego

Looks good with one slight query.  I commented before on the use of
'client' in s.3.5 which suggested an asymmetric protocol, where the
PCE
checks on the PCC needed to be more stringent that those of the PCC on
the PCE.  I notice that one of the 'client' has gone but one has not
and
there is still a 'PCC' in there so it still to me carries the flavour
that PCE checking of the PCC is more important than the other way
round.
I do not know if this is ok or not, how it lines up with the threat
model.

Tom Petch


----- Original Message -----
From: "DIEGO LOPEZ GARCIA"
<diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com><mailto:diego.r.lopez@telefonica.com>>
To: <pce@ietf.org<mailto:pce@ietf.org><mailto:pce@ietf.org>>
Sent: Thursday, January 21, 2016 2:07 PM

Hi,

We have just uploaded a new version of draft-ietf-pce-pceps
(https://datatracker.ietf.org/doc/draft-ietf-pce-pceps/)

We believe this new version addresses all the comments received from
the
SECDIR review after the last call period, and other pending ones
provided by Tom while that SECDIR review was taking place. As far as
the
authors can say, the document is ready to progress.

Be goode,

--
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez
Telefonica I+D
http://people.tid.es/diego.lopez/

e-mail:
diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com><mailto:diego.r.lopez@telefonica.com>
Tel:    +34 913 129 041
Mobile: +34 682 051 091
----------------------------------



--
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez
Telefonica I+D
http://people.tid.es/diego.lopez/

e-mail:
diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com><mailto:diego.r.lopez@telefonica.com>
Tel:    +34 913 129 041
Mobile: +34 682 051 091
----------------------------------


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su
destinatario, puede contener información privilegiada o confidencial y
es para uso exclusivo de la persona o entidad de destino. Si no es
usted. el destinatario indicado, queda notificado de que la lectura,
utilización, divulgación y/o copia sin autorización puede estar
prohibida en virtud de la legislación vigente. Si ha recibido este
mensaje por error, le rogamos que nos lo comunique inmediatamente por
esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and
confidential information intended only for the use of the individual or
entity named above. If the reader of this message is not the intended
recipient, you are hereby notified that any dissemination, distribution
or copying of this communication is strictly prohibited. If you have
received this transmission in error, do not read it. Please immediately
reply to the sender that you have received this communication in error
and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu
destinatário, pode conter informação privilegiada ou confidencial e é
para uso exclusivo da pessoa ou entidade de destino. Se não é vossa
senhoria o destinatário indicado, fica notificado de que a leitura,
utilização, divulgação e/ou cópia sem autorização pode estar proibida em
virtude da legislação vigente. Se recebeu esta mensagem por erro,
rogamos-lhe que nos o comunique imediatamente por esta mesma via e
proceda a sua destruição
_______________________________________________
Pce mailing list
Pce@ietf.org<mailto:Pce@ietf.org><mailto:Pce@ietf.org>
https://www.ietf.org/mailman/listinfo/pce

--
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez
Telefonica I+D
http://people.tid.es/diego.lopez/

e-mail: diego.r.lopez@telefonica.com
Tel:    +34 913 129 041
Mobile: +34 682 051 091
----------------------------------


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su
destinatario, puede contener información privilegiada o confidencial y
es para uso exclusivo de la persona o entidad de destino. Si no es
usted. el destinatario indicado, queda notificado de que la lectura,
utilización, divulgación y/o copia sin autorización puede estar
prohibida en virtud de la legislación vigente. Si ha recibido este
mensaje por error, le rogamos que nos lo comunique inmediatamente por
esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and
confidential information intended only for the use of the individual or
entity named above. If the reader of this message is not the intended
recipient, you are hereby notified that any dissemination, distribution
or copying of this communication is strictly prohibited. If you have
received this transmission in error, do not read it. Please immediately
reply to the sender that you have received this communication in error
and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu
destinatário, pode conter informação privilegiada ou confidencial e é
para uso exclusivo da pessoa ou entidade de destino. Se não é vossa
senhoria o destinatário indicado, fica notificado de que a leitura,
utilização, divulgação e/ou cópia sem autorização pode estar proibida em
virtude da legislação vigente. Se recebeu esta mensagem por erro,
rogamos-lhe que nos o comunique imediatamente por esta mesma via e
proceda a sua destruição



--
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez
Telefonica I+D
http://people.tid.es/diego.lopez/

e-mail: diego.r.lopez@telefonica.com
Tel:    +34 913 129 041
Mobile: +34 682 051 091
----------------------------------


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição