Re: [netconf] Re: draft-kwatsen-netconf-quic-call-home

Kent Watsen <kent+ietf@watsen.net> Wed, 29 July 2026 10:08 UTC

Return-Path: <0100019fad5860ab-d7069395-b903-41c2-90a6-87bdfbcdcf7c-000000@amazonses.watsen.net>
X-Original-To: quic@mail2.ietf.org
Delivered-To: quic@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 225CA1205C7E9; Wed, 29 Jul 2026 03:08:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785319685; bh=Jb5K7He3DuxmrX7l0EgjxsXL3irqYqQIeYY38yS6r64=; h=From:Subject:Date:References:Cc:In-Reply-To:To; b=XncjqjeEdeq8jyBu4wg2D53ML+pBMidtxSCukcPrgH1xymLA5oIuBMHJuDwta6UOb zmSb2lmthanHudZOJYY9Kv1lTlBY6XQty1FeBTguRz/XkJxHbsSkS73/AW0Blu9f6g mcLqDF/AJr3EHtkD5HWg3Ib2H6NRAFZVqjpapsF8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.004
X-Spam-Level:
X-Spam-Status: No, score=-1.004 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, MIME_HTML_ONLY_MULTI=0.001, MIME_QP_LONG_LINE=0.001, MPART_ALT_DIFF=0.79, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=amazonses.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id knTFnE4XdGjU; Wed, 29 Jul 2026 03:08:04 -0700 (PDT)
Received: from a8-96.smtp-out.amazonses.com (a8-96.smtp-out.amazonses.com [54.240.8.96]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9E4D51205C7E6; Wed, 29 Jul 2026 03:08:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=224i4yxa5dv7c2xz3womw6peuasteono; d=amazonses.com; t=1785319678; h=Content-Type:Content-Transfer-Encoding:From:Mime-Version:Subject:Date:Message-Id:References:Cc:In-Reply-To:To:Feedback-ID; bh=Jb5K7He3DuxmrX7l0EgjxsXL3irqYqQIeYY38yS6r64=; b=cQfKMnjG+J/pI/AAwLo567Ghw/zxljkdYckogag3obbhkuUxiVKhDjrY+tj4oO6L zpel0yMnhgmDV7unGnl9N6Fd8kYfAp09wHhmP+1Ii/j3IgbFGursOwEIKGQfzOn6aL4 IRz14iFeIaKt2rFTsrSxxdn8kV11KqDuZPs8W5qk=
Content-Type: multipart/alternative; boundary="Apple-Mail-8893360B-ABDF-4B76-9AE7-249FE252A4B3"
Content-Transfer-Encoding: 7bit
From: Kent Watsen <kent+ietf@watsen.net>
Mime-Version: 1.0 (1.0)
Subject: Re: [netconf] Re: draft-kwatsen-netconf-quic-call-home
Date: Wed, 29 Jul 2026 10:07:58 +0000
Message-ID: <0100019fad5860ab-d7069395-b903-41c2-90a6-87bdfbcdcf7c-000000@email.amazonses.com>
References: <FRWPR07MB1062415EB8D35C34A53816B0395CA2@FRWPR07MB10624.eurprd07.prod.outlook.com>
In-Reply-To: <FRWPR07MB1062415EB8D35C34A53816B0395CA2@FRWPR07MB10624.eurprd07.prod.outlook.com>
To: Magnus Westerlund <magnus.westerlund=40ericsson.com@dmarc.ietf.org>
X-Mailer: iPhone Mail (23F84)
Feedback-ID: ::1.us-east-1.DKmIRZFhhsBhtmFMNikgwZUWVrODEw9qVcPhqJEI2DA=:AmazonSES
X-SES-Outgoing: 2026.07.29-54.240.8.96
Message-ID-Hash: PU54327U4DEMO4OWDRSEURHP2UGRGP3G
X-Message-ID-Hash: PU54327U4DEMO4OWDRSEURHP2UGRGP3G
X-MailFrom: 0100019fad5860ab-d7069395-b903-41c2-90a6-87bdfbcdcf7c-000000@amazonses.watsen.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-quic.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: netconf@ietf.org, quic@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/umX--7c--sIyeXKEP69CeRT_SHI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Owner: <mailto:quic-owner@ietf.org>
List-Post: <mailto:quic@ietf.org>
List-Subscribe: <mailto:quic-join@ietf.org>
List-Unsubscribe: <mailto:quic-leave@ietf.org>

Thanks Magnus. 

Some comments to ensure that I understand your idea correctly.

You mention mutual authentication, which is indeed required for the *CONF protocols, but note that client-auth MAY be via TLS client-cert or via higher-layer client auth mechanism (e.g., HTTP client auth). 

Also note that the directionality of the auth is critical, as Operators demand that it’s stable between regular and call home connections.  

My understanding is that ServerHello cannot be sent before ClientHello. 

Is your idea still a good fit?

Kent 


On Jul 29, 2026, at 4:32 AM, Magnus Westerlund <magnus.westerlund=40ericsson.com@dmarc.ietf.org> wrote:


Hi,

If I understand this correctly you are doing mutual TLS for authentication so both the *CONF client and server knows who they are expecting to talk to. The server also knows the client’s address port. So why complicating it with a new packet type rather than to just define that both *CONF clients and servers shall act as QUIC Servers, and *CONF servers MAY be QUIC clients and the *CONF client MUST be QUIC client, then after the QUIC connection is established the *CONF Client knows its role and does the *CONF procedures over the established connection?

/Magnus


From: Kent Watsen <kent+ietf@watsen.net>
Date: Wednesday, 29 July 2026 at 01:28
To: netconf@ietf.org <netconf@ietf.org>
Cc: quic@ietf.org <quic@ietf.org>
Subject: draft-kwatsen-netconf-quic-call-home

This short I-D extends https://datatracker.ietf.org/doc/rfc8071/" rel="nofollow"> RFC 8071 to support QUIC:


The "solution" (if it stands) is to add a single UDP datagram into the connection exchange before the standard Initial Packet.

Comments, questions, concerns?

Kent  // author of RFC 8071