Re: [perpass] Fwd: FW: I-D Action: draft-farrelll-mpls-opportunistic-encrypt-00.txt

Watson Ladd <watsonbladd@gmail.com> Fri, 10 January 2014 17:27 UTC

Return-Path: <watsonbladd@gmail.com>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E8D71ADFB9 for <perpass@ietfa.amsl.com>; Fri, 10 Jan 2014 09:27:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Gj-oIaxiO0SY for <perpass@ietfa.amsl.com>; Fri, 10 Jan 2014 09:27:47 -0800 (PST)
Received: from mail-we0-x236.google.com (mail-we0-x236.google.com [IPv6:2a00:1450:400c:c03::236]) by ietfa.amsl.com (Postfix) with ESMTP id B77D31ADF7D for <perpass@ietf.org>; Fri, 10 Jan 2014 09:27:46 -0800 (PST)
Received: by mail-we0-f182.google.com with SMTP id q59so4438976wes.27 for <perpass@ietf.org>; Fri, 10 Jan 2014 09:27:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=usXwnaoxGLgC+mVAM09tpWk4TZsPMgaxyV1YSrAD5dM=; b=F7iTrxYQ2QmnQAArFABCd9xOprd22KlztKFSfE1ZF+sZE1oj259thawnqf+tltO6Uu pN3WL3+2HU2buXpW/N5lcdGRM91hWVZ0/orPZ+ktdlzw6sKD29aRt9QBdw/DCCyBGjbH LBacq7NKwBqxPjIa5TkFH5Ja6XsW9OpWSC5CY/t/IL2voLTaOnJdbn3FQxUG6J/10h4x nBNW+7b/uz2oVvWriojqC88DxqGJl+/8wg5E8dcvf+YaGvVdxrPkHXIHW67KqczaPlBr cuZrc61lenWFQCzens3v7nJjQu76A0uEkuPYZG0XSgiXxtJWxg3GAw0E05gNSS0qQrDQ vh1A==
MIME-Version: 1.0
X-Received: by 10.194.189.132 with SMTP id gi4mr9730386wjc.5.1389374856259; Fri, 10 Jan 2014 09:27:36 -0800 (PST)
Received: by 10.194.242.131 with HTTP; Fri, 10 Jan 2014 09:27:36 -0800 (PST)
In-Reply-To: <52D02C27.8050009@cs.tcd.ie>
References: <01be01cf0d31$13fdea40$3bf9bec0$@olddog.co.uk> <52CE9383.8050006@cs.tcd.ie> <CACsn0c=6_EYSaAh0QbZWYTRvUPnRKm5iSgOoZ7yqWmqQC4x8VQ@mail.gmail.com> <52D02C27.8050009@cs.tcd.ie>
Date: Fri, 10 Jan 2014 09:27:36 -0800
Message-ID: <CACsn0cnXHO-4MpbXREMAWKL_-LRrgngbNbYVJH5nUeOUFDTQgw@mail.gmail.com>
From: Watson Ladd <watsonbladd@gmail.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Content-Type: text/plain; charset="UTF-8"
Cc: Adrian Farrel <adrian@olddog.co.uk>, perpass <perpass@ietf.org>
Subject: Re: [perpass] Fwd: FW: I-D Action: draft-farrelll-mpls-opportunistic-encrypt-00.txt
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 10 Jan 2014 17:27:48 -0000

On Fri, Jan 10, 2014 at 9:21 AM, Stephen Farrell
<stephen.farrell@cs.tcd.ie> wrote:
>
> Hiya,
>
><snip>
>> Otherwise this seems reasonable: it might be worth considering if this
>> can be extended to
>> authenticate both sides cleanly if some large networks want to be safe
>> against that.
>
> Not sure what you mean by cleanly?

By cleanly I mean if authentication is configured, it works, if not,
we wind up with OE without too much
in the way of complexity. This might be a bridge too far, but I
wouldn't be surprised if some people were concerned about false
termination in the middle of their MLPS networks induced by malicious
configuration.

>
> Thanks for the comments,
> S.
>



-- 
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin