Re: [Pce] draft-ietf-pce-pceps-08 available

t.petch <ietfc@btconnect.com> Tue, 08 March 2016 10:35 UTC

Return-Path: <ietfc@btconnect.com>
X-Original-To: pce@ietfa.amsl.com
Delivered-To: pce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E1B5812D5EE for <pce@ietfa.amsl.com>; Tue, 8 Mar 2016 02:35:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.052
X-Spam-Level:
X-Spam-Status: No, score=0.052 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, URG_BIZ=0.573] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([127.0.0.1]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TCdzKAcofPa9 for <pce@ietfa.amsl.com>; Tue, 8 Mar 2016 02:35:27 -0800 (PST)
Received: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0103.outbound.protection.outlook.com [104.47.2.103]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF70712D5E7 for <pce@ietf.org>; Tue, 8 Mar 2016 02:35:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector1-btconnect-com; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=SZr0g0AczCj+K0Tr3x9uJ7uOTLuhIIfOweS5OjKHkIM=; b=Wdd0z18Oc7XHOKkZs45Nw9OlWLGkk56tVZExrkdbFvSpoIqBGiKFysTIOaOeeAzzu++Z7KSg6fl7GxAKpYCmuprCSP6YpDOeNrZ5yHuLte2NecfRN8jOom8G8efs+of+MVeTKblI2vdTbfRHZs3wL0KxSe6zf2ExcH0KC4vGZ9o=
Authentication-Results: telefonica.com; dkim=none (message not signed) header.d=none;telefonica.com; dmarc=none action=none header.from=btconnect.com;
Received: from pc6 (86.167.153.133) by AM4PR07MB1618.eurprd07.prod.outlook.com (10.166.132.148) with Microsoft SMTP Server (TLS) id 15.1.434.11; Tue, 8 Mar 2016 10:35:23 +0000
Message-ID: <021a01d17925$ad52f160$4001a8c0@gateway.2wire.net>
From: "t.petch" <ietfc@btconnect.com>
To: DIEGO LOPEZ GARCIA <diego.r.lopez@telefonica.com>
References: <06EC97F2-E307-4AB9-AF08-ABFAAAE20B42@telefonica.com> <011901d15ea5$73702840$4001a8c0@gateway.2wire.net> <55E4A7A6-4BEB-402E-B7FA-F99B6818B82A@telefonica.com> <30887501-8EDE-41A1-9589-6DCD43F9E4B6@telefonica.com>
Date: Tue, 08 Mar 2016 10:29:31 +0000
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Originating-IP: [86.167.153.133]
X-ClientProxiedBy: AM2PR07CA0016.eurprd07.prod.outlook.com (25.163.24.154) To AM4PR07MB1618.eurprd07.prod.outlook.com (25.166.132.148)
X-MS-Office365-Filtering-Correlation-Id: 92c24cd8-266f-4f84-f78b-08d3473d5b68
X-Microsoft-Exchange-Diagnostics: 1; AM4PR07MB1618; 2:cSvP3bEFmxAXwWDS+jeklGt0YDXbYxiuIwO7CnRyMKTMKp+Otma/9M49WQx7gMjH3VJRTnifY/IR4vtPTA7SBqEijjwG+mac92HHMaNfm7yzYdCICnvdhsfc8OMha5LmdT6+50aPVjAVXqHuIiSWIq+DVzz5jpebnzH077qtnYkSUkzDEV1sZM5GYfcMc35d; 3:d6jCwGRIFbFKJvI/qBIH5f3eNJ0vDIvQ0frXBh8T68QRnaq5AyTkk8rtolXPvoxp854GLXJuMl+k7VM3TmHSp625mWoFb2estgYgV53RpXXVLDCoth5vt1I1yiYiUK2t; 25:c3IroKJxDjNDAOryCWRz+g2rGmp5c5I5/olWhj9eeTAMMg7LInO43iPhFoGp1cZgEk9E5G5K/f8iSab9puO/iBOb1i1wS61a/rTwUS94ARP81msZWSs7cbb12LKS8oyVohyjTHi6yclLq8NVve3CgqM2vGQRW4Dpei2xhda8rv2hO0kAvdoGDdx7qxHZmuB51/pnsZZ7LnNAOHtMXoAJWKHhJoWNuETRNsEHCRWqBr0MyaQK3kyI9hQPh6SY4N4oneLgntqgAEiGybh+k9hJlj0THiPCF4U9TlNUO72e3As25JtMPrcI04QDibbFDSzuNA1psGB2NXwyLHgGp/7UfQ==
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:AM4PR07MB1618;
X-Microsoft-Antispam-PRVS: <AM4PR07MB1618ADAB34DE3C446E517263A0B20@AM4PR07MB1618.eurprd07.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(178726229863574);
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001); SRVR:AM4PR07MB1618; BCL:0; PCL:0; RULEID:; SRVR:AM4PR07MB1618;
X-Microsoft-Exchange-Diagnostics: 1; AM4PR07MB1618; 4:QKZ5yrPIAN8zLNxR2gbWMKGaDdfQ0AXXXM+aGMYwM3SXcqdX+5w0D0m8zbdjxOodHzK8A9KZCPutDZX7ZcEUZZEv47+m2n/q+bzGl4apn7DeatwpV2JVvBE8nz/YFzNS/6Gh953kjvTkig+1Ge2R78HHn9VnOv0HRH9HV1OWO8ZVRrE5v+W6f3H+7Hub4IDuUne/N8oaKFsSrNyFZc/lenXK950Xq1JOfZcOBPodpdztyMFFaltN1EbM8Dv4ZQjq5Lr7IHo8PJZnQ4T+5dAvu8xSASEjQ7nroUPSgSWW25IvmJq7AjUJ7cayQQWvOArIaBOQpUl1EbVMHk73Qt4W3v5HSsiiM4pQr/m5gN/RDix1ExKbx4GK7xUvtGZbA+ktEAj+brb1/woHd2FrNeko/pLniuyb3zN316L+GbEk0Z8=
X-Forefront-PRVS: 08756AC3C8
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(979002)(6009001)(25724002)(377454003)(40134004)(13464003)(24454002)(252514010)(116806002)(86362001)(44736004)(81166005)(93886004)(47776003)(19580405001)(5008740100001)(586003)(23676002)(40100003)(3846002)(81686999)(76176999)(189998001)(6116002)(66066001)(122386002)(230783001)(50466002)(2870700001)(1456003)(15975445007)(2906002)(42186005)(87976001)(50986999)(1096002)(1556002)(61296003)(92566002)(5004730100002)(4326007)(84392002)(50226001)(14496001)(81816999)(19580395003)(110136002)(33646002)(77096005)(62236002)(44716002)(74416001)(7726001)(4720700001)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:AM4PR07MB1618; H:pc6; FPR:; SPF:None; MLV:ovr; PTR:InfoNoRecords; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1;AM4PR07MB1618;23:KiI0wEYN48iAmfeTwihsy13qDFf+KYtP1XGKrXNR38Qtwykfx2YnBrjOqni48Dn0IN2fYM6U9mFmKKwZr+wqIBD+pgXaCiz6fLogOUBItmi6wg0YoThnu1on3twGzehr7mKJJONrNZsSl5F1sZRRhSRYHo5dM0tTHraMCrbu53AMzBAveJn5R+Hu7+r6eqTJGn51pg0QMZv0AQUHhzeo8M4cx5Mghy4NC+5ub6vK8i5lic6txVhisbgrl0+1KMbhK1bjIGTxZn7K2X4Mj+TlGW6f54NNZvJ62oJl8XAgoU/Hnuw9Ok546InwDYqIWVYXn2TI7HjdIAiS067nRR11QZ22PcTszAScmIX3ysdEjmZv3iA19675MIH8J9SXSyMgT9hAWiDWRHaZQtO2OGXo7pJ6EEnhrH6nOD/Et6mXFTDSJUIcV6nJfT2uORjzdeDOO72YoBiliKE2C8l3plPl09ZluxMdj/ygG5NPDbyKIdhCsE/I7NoxouJbK2AglB5w0HVraFwGoVz8iSSRlwrTi5+BiDRTZ17/XIO6jbIzcF3sWA0ihSP4YPAzh5friTf0kr3B72MgAWB2jVF2iGYWdez6RMGkUUKFFz9bWtJIZuc/kZ/e3PNt+A3pRVRny1HCR62bqK1PbPuSVIA3grn0ERZQJk6xbaashg3XaicKYi8j94iTK5MntqjF6Qgc/DeWrK85EGZuf//ZTBNMyuwJnpXBswmJ3MMwz3NwYXcOkM7VREkfB7H2ylUuyjVudS93oO8m84oIgR2nn1ho9bo0yk8AgiyHNksPlY9elVGYq2hrujon6uZRAUlzehkKiubavQIsSFQKWTBkeoWNT6zBrU0FBWFpS7kPZtPZEhGdiKbNKwltc+ONn3b24r8J8s+vQrT635SgGHTZgK9e6jNd7b7is5sLHBNFFTwxhegy6wQO9H2zbBi94F0MqGnL6M5SF5ty+N7qliyTDIUPULehWXpBAGtQ90vhXsXmC22FvtpmHkTpLj2sjOWE9O9coRMqVkmoUYYx2D9cEDQCQc606HC++eBbjKoaPHPei+cMEnxnleoYrm97pREigPCm3NDzsTBsO+ZmzjaEnrTuoeFrd4QDOwFxM8n+WIEmyX9OypMg0irgHDE0K/4NA/t2oqEGVHADFktCorMjyeiL4tkztxt/W66s8F+v/XuFyL9SpSNnQ8s4yojbh2/OqlcDYk+wZFWubPAWxXH/nfnN2IWIBlz/j+g7vJGEvHpoe3xNyIwjY6Indv9MwpuKnEX3EHdn6x/HcIlLiozeYDyC4k/X2ffkpgRYb4P/2lh6aHB3pOf0w97E089vXVGlH8JArbVPrROmCfdJJIF9qAr1H7kxw9T0cMa1967iQkUiOOaGYerqbs27PC/yXT2YBld6iFMOGD/YFbzkMV0rFqw4bqxFjN2RIfI2xAby/EtNTZ7D9XXDeyHGsQXQ2f9aKpvoeu+J
X-Microsoft-Exchange-Diagnostics: 1; AM4PR07MB1618; 5:eJUF4VSaRfdqspciOSwYuovlfRRI+UlarrC80Myl4xomSsDye6rT2wPKGkLq/VagNMsCsCc1SHoC+wkt7OrWTSy8LtE9mkay55sVABqOvqdS9UVqrG05o+LwRw70osgdcsPTy4Y0ojY8UHl2OHJVZw==; 24:4fH+TRh6MgsXrUJFDxjZGFjumnUmiOSIZxPmRpTBonYyGdyXRbSZIkHd5JPGhWM40aURmeLErdG2WmQIuS+Gw7oGcw70bq5ZJpTZu360KTM=
SpamDiagnosticOutput: 1:23
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 08 Mar 2016 10:35:23.9836 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM4PR07MB1618
Archived-At: <http://mailarchive.ietf.org/arch/msg/pce/fSAAxdyHOy6yeM-CrjvtvfJCKic>
Cc: pce@ietf.org
Subject: Re: [Pce] draft-ietf-pce-pceps-08 available
X-BeenThere: pce@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Path Computation Element <pce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pce>, <mailto:pce-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pce/>
List-Post: <mailto:pce@ietf.org>
List-Help: <mailto:pce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pce>, <mailto:pce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Mar 2016 10:35:30 -0000

Diego,

Yes, understand the logic but (ducking) it was
"  In addition, a PCC MAY apply the procedures described in [RFC6698]"
and is now
"  In addition, a PCV MAY apply the procedures described in [RFC6698]"

Separately (why can't I get it right first time?), your MTI ciphersuites
are defined in RFC5288 which I think should be a Normative Reference
from s.3.4

Tom Petch

----- Original Message -----
From: "DIEGO LOPEZ GARCIA" <diego.r.lopez@telefonica.com>
To: "t.petch" <ietfc@btconnect.com>
Cc: <pce@ietf.org>
Sent: Sunday, March 06, 2016 8:18 PM


> Hi again,
>
> I forgot to mention that we’ll change the mention to “client” and
“client certificate” in the third paragraph of 3.5. But the mention to
PCC in the discussion of the use of DANE has to remain, as DANE is
mentioned in the context of DNS discovery, that is only applicable by a
PCC.
>
> Be goode,
>
> On 6 Mar 2016, at 21:08 , DIEGO LOPEZ GARCIA
<diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com>>
wrote:
>
> Hi Tom,
>
> Apologies for the delay (other urgent requests piling up…) Dhruv has
just reminded me of this comment of yours. I think you are right: It is
much better to maintain symmetry in the TLS verification and use a
general term that includes both peers. I’ll upload an updated version
right now.
>
> Be goode,
>
> On 3 Feb 2016, at 18:06 , t.petch
<ietfc@btconnect.com<mailto:ietfc@btconnect.com>> wrote:
>
> Diego
>
> Looks good with one slight query.  I commented before on the use of
> 'client' in s.3.5 which suggested an asymmetric protocol, where the
PCE
> checks on the PCC needed to be more stringent that those of the PCC on
> the PCE.  I notice that one of the 'client' has gone but one has not
and
> there is still a 'PCC' in there so it still to me carries the flavour
> that PCE checking of the PCC is more important than the other way
round.
> I do not know if this is ok or not, how it lines up with the threat
> model.
>
> Tom Petch
>
>
> ----- Original Message -----
> From: "DIEGO LOPEZ GARCIA"
<diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com>>
> To: <pce@ietf.org<mailto:pce@ietf.org>>
> Sent: Thursday, January 21, 2016 2:07 PM
>
> Hi,
>
> We have just uploaded a new version of draft-ietf-pce-pceps
> (https://datatracker.ietf.org/doc/draft-ietf-pce-pceps/)
>
> We believe this new version addresses all the comments received from
the
> SECDIR review after the last call period, and other pending ones
> provided by Tom while that SECDIR review was taking place. As far as
the
> authors can say, the document is ready to progress.
>
> Be goode,
>
> --
> "Esta vez no fallaremos, Doctor Infierno"
>
> Dr Diego R. Lopez
> Telefonica I+D
> http://people.tid.es/diego.lopez/
>
> e-mail:
diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com>
> Tel:    +34 913 129 041
> Mobile: +34 682 051 091
> ----------------------------------
>
>
>
> --
> "Esta vez no fallaremos, Doctor Infierno"
>
> Dr Diego R. Lopez
> Telefonica I+D
> http://people.tid.es/diego.lopez/
>
> e-mail:
diego.r.lopez@telefonica.com<mailto:diego.r.lopez@telefonica.com>
> Tel:    +34 913 129 041
> Mobile: +34 682 051 091
> ----------------------------------
>
>
> ________________________________
>
> Este mensaje y sus adjuntos se dirigen exclusivamente a su
destinatario, puede contener información privilegiada o confidencial y
es para uso exclusivo de la persona o entidad de destino. Si no es
usted. el destinatario indicado, queda notificado de que la lectura,
utilización, divulgación y/o copia sin autorización puede estar
prohibida en virtud de la legislación vigente. Si ha recibido este
mensaje por error, le rogamos que nos lo comunique inmediatamente por
esta misma vía y proceda a su destrucción.
>
> The information contained in this transmission is privileged and
confidential information intended only for the use of the individual or
entity named above. If the reader of this message is not the intended
recipient, you are hereby notified that any dissemination, distribution
or copying of this communication is strictly prohibited. If you have
received this transmission in error, do not read it. Please immediately
reply to the sender that you have received this communication in error
and then delete it.
>
> Esta mensagem e seus anexos se dirigem exclusivamente ao seu
destinatário, pode conter informação privilegiada ou confidencial e é
para uso exclusivo da pessoa ou entidade de destino. Se não é vossa
senhoria o destinatário indicado, fica notificado de que a leitura,
utilização, divulgação e/ou cópia sem autorização pode estar proibida em
virtude da legislação vigente. Se recebeu esta mensagem por erro,
rogamos-lhe que nos o comunique imediatamente por esta mesma via e
proceda a sua destruição
> _______________________________________________
> Pce mailing list
> Pce@ietf.org<mailto:Pce@ietf.org>
> https://www.ietf.org/mailman/listinfo/pce
>
> --
> "Esta vez no fallaremos, Doctor Infierno"
>
> Dr Diego R. Lopez
> Telefonica I+D
> http://people.tid.es/diego.lopez/
>
> e-mail: diego.r.lopez@telefonica.com
> Tel:    +34 913 129 041
> Mobile: +34 682 051 091
> ----------------------------------
>
>
> ________________________________
>
> Este mensaje y sus adjuntos se dirigen exclusivamente a su
destinatario, puede contener información privilegiada o confidencial y
es para uso exclusivo de la persona o entidad de destino. Si no es
usted. el destinatario indicado, queda notificado de que la lectura,
utilización, divulgación y/o copia sin autorización puede estar
prohibida en virtud de la legislación vigente. Si ha recibido este
mensaje por error, le rogamos que nos lo comunique inmediatamente por
esta misma vía y proceda a su destrucción.
>
> The information contained in this transmission is privileged and
confidential information intended only for the use of the individual or
entity named above. If the reader of this message is not the intended
recipient, you are hereby notified that any dissemination, distribution
or copying of this communication is strictly prohibited. If you have
received this transmission in error, do not read it. Please immediately
reply to the sender that you have received this communication in error
and then delete it.
>
> Esta mensagem e seus anexos se dirigem exclusivamente ao seu
destinatário, pode conter informação privilegiada ou confidencial e é
para uso exclusivo da pessoa ou entidade de destino. Se não é vossa
senhoria o destinatário indicado, fica notificado de que a leitura,
utilização, divulgação e/ou cópia sem autorização pode estar proibida em
virtude da legislação vigente. Se recebeu esta mensagem por erro,
rogamos-lhe que nos o comunique imediatamente por esta mesma via e
proceda a sua destruição
>