Re: [radext] Liaison to government agencies

Stephen Farrell <stephen.farrell@cs.tcd.ie> Wed, 23 November 2022 23:26 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C185C14CF14 for <radext@ietfa.amsl.com>; Wed, 23 Nov 2022 15:26:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cs.tcd.ie
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7sL5xRGfLO4N for <radext@ietfa.amsl.com>; Wed, 23 Nov 2022 15:26:47 -0800 (PST)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04on070d.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe0c::70d]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EBA80C14CF12 for <radext@ietf.org>; Wed, 23 Nov 2022 15:26:46 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QDazFosCeq9vhdxYKepTvs0lDkHYvmYhn0ogNtjkffIyhZAIYH8BvhZW7NIECbk6qsJWZoVtVuZhU52UHUQ11NnYv3JvZOXITL6SvvhAFbZyzTwv/IWQ4FE/jB+NEkpSiTj7MUes8VGPm8Vk+fLqLmjFiWJtumVhNm7KIG6GJ4y8mjrY/jriGVcxfW+4J5Jcz1sDvgZG63ElTc50HkEhdspVcL43w50sFSZyKeh61cExxk90aGA2aI23YFC7HQfMyKEhE3y8rcyretr8hJOYP/nVDpDxmDjE0aV1QySbTXz+rha39+xRtU8sFwOZjQ+aKt6QQljP7NLS+GjrXW/75w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=fTlStc5rJaHMepIBr/RKq0K2BD8ACmqfUmuZRiNSgB4=; b=gJodkP49Mwjy2+cA0gJpjdoYri9K3Oh0J9bH80DehKhC00gF6EFJNygZ86pw49xAOJkb5wiGqdUNXliCHMJx0aARgJsiMv3Xc+QV54Nmsr5OmTskK+kgwl14xHzraWLx6yJZWdClH7Kj3YUYaCNHIIbuACURLNyVr8wEbitY9G8+mAz/x+AinTJ5Uo2kEYZipQXwYElm0iSU+msPGXMdBRfbQTZBVovwZoz8tThw81I0ZrlR0RyNu+6SI8i0abLfgU9FelxQS4LSjQbKwuSzFmIsdhJxVBa1m4Rf7cglHInjQLr11ZKCEht5kqbonFazUkbc+dq502y6XwiABpJSAg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cs.tcd.ie; dmarc=pass action=none header.from=cs.tcd.ie; dkim=pass header.d=cs.tcd.ie; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cs.tcd.ie; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=fTlStc5rJaHMepIBr/RKq0K2BD8ACmqfUmuZRiNSgB4=; b=QmeEyeT/fjeoSKQ2S4YZqBQS1aLsDrGXXG3hQUNQjQ+bvX0d6ZdLzhy8maipf/Ll7EdX0UYr7UkkAJKxQwF5eZkzJlc4qSeUB6kL4FStZvbi13Y9yk2xoxnAXtiRUK4UW1HpAcqqxWSGgCFGKMUtO2t+CYvPjmJU7/bqdGK3CfJWoGWdKOXAoO+82w0wHSfvqt/tCknR65xMKT2PJj1a/l0eIyLLZKT48hBI57oc6WeKDj2WugS12cqdaOC7T5cIDZUV6XFSYRuzx74Cnkoeqqg1Movfythbf9zLbjRD70uKDctquoKAyiYhZwAYeKQH5wcdUEgaGuvj5bnRhSejsQ==
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cs.tcd.ie;
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15) by AM9PR02MB7155.eurprd02.prod.outlook.com (2603:10a6:20b:264::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5834.9; Wed, 23 Nov 2022 23:26:41 +0000
Received: from DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::ec35:f546:d772:4fc6]) by DB7PR02MB5113.eurprd02.prod.outlook.com ([fe80::ec35:f546:d772:4fc6%4]) with mapi id 15.20.5834.015; Wed, 23 Nov 2022 23:26:41 +0000
Message-ID: <30e717f9-5d7d-2846-c87d-42b59b7f5b25@cs.tcd.ie>
Date: Wed, 23 Nov 2022 23:26:39 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.4.2
Content-Language: en-US
To: Bernard Aboba <bernard.aboba@gmail.com>
Cc: Peter Deacon <peterd@iea-software.com>, radext@ietf.org
References: <4ce6d292-bb34-5dd7-7b8b-d43c282658f1@iea-software.com> <329FE6EA-C1E6-4E16-8D0C-A68C32B67FB9@gmail.com> <FC5C81F9-FEB5-4F9C-9A02-36837B7ABC09@deployingradius.com> <CAOW+2dtANzJDbAjmhHiz_m1pkk+SyfHu5uZ_ddp4PPMi17=0-A@mail.gmail.com> <E59F655C-ADC3-465A-BC9E-4445135BFE97@deployingradius.com> <2f8a0921-2e9e-751e-4f5d-42c5c9c3cb8a@dfn.de> <b96210fb-8a59-2606-bb0c-7cf365fb23e0@iea-software.com> <81A7763B-B2AE-4FBE-9A5E-1234C87393AE@deployingradius.com> <CAOW+2dvg2z9e_X0QzB+gnxDRK9wMdZy=S4x1LbsXzfP6AxrwtA@mail.gmail.com> <b036f5fd-60fc-352e-bf91-d832adba2545@cs.tcd.ie> <CAOW+2dvbercDhpHGhud8wbTOzVem+=CZ3qY2cat9Wno6G7VgjQ@mail.gmail.com> <ac383e60-b8b4-f46c-4b3c-4834fc4c827d@cs.tcd.ie> <CAOW+2dvkaHgjMPkA4J4hC2NsC=VqEJFOs2a0WPiP2Y4HQ7ppig@mail.gmail.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
In-Reply-To: <CAOW+2dvkaHgjMPkA4J4hC2NsC=VqEJFOs2a0WPiP2Y4HQ7ppig@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------XUZzoLtek07FOQ6v4twvpdT0"
X-ClientProxiedBy: DB6PR07CA0185.eurprd07.prod.outlook.com (2603:10a6:6:42::15) To DB7PR02MB5113.eurprd02.prod.outlook.com (2603:10a6:10:77::15)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DB7PR02MB5113:EE_|AM9PR02MB7155:EE_
X-MS-Office365-Filtering-Correlation-Id: e512ba1d-2c05-4d7f-c853-08dacdaa2d23
X-MS-Exchange-SharedMailbox-RoutingAgent-Processed: True
X-TCD-Routed-via-EOP: Routed via EOP
X-TCD-ROUTED: Passed-Transport-Routing-Rules
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 4qVlhhyS2R/00B5olWoSzi1+R6P7q2TnzVfRdwNMOpIqC95kMcvuaV5w8OWqMunu9H0ewvCeu/cPUktTHjFILelgg5QSh/b7NJVci5rfaoVgRzs0HKqk+kSPRaWJxgzmJB9om/0euKEBzGKHYkjoZu97gp0d6ccW99MucOg0O6EUtLh8natrXiisem7Rv2/qlnRFKyvA9+SxOoy/G5AMFAGI/xoAPW+G38w/duGPzhuMxgjJSSyvfEqB3xAGI+vcc1czMkehrOZyrhWTsyvx9JCFaO11Rj8WZq/8vaC5meuYwVKnjt38tfd9Xxs1W6J85KHVB2BI9OFa9nOgQomsbIb6MhUkXXD7eQ3MgPgrTDnwtUw7JFiADz5+OVngJB5mtQwe9uSCU0ysdsFcKrMgYVCs4eYhETfQ9J+BtcgSzx+1HyE8c28wKADH4coFXLk6O82m8cZH19sVi6aZnRj+ZC9rMPM3cj0/CCOTp60JJ/rdESFfa2Nb0anPCbIXdwNvor3OgZNIpZQBWd8Lz17xDvR2UQyfxYKk9gJkpIdxp/w49PZX4zsK3MbPoO34qY4KRGqwq30GCFiC3r3tWuwXi6gFSLsaX9rIsjuhvrtjnBSbe1uxfCyDxuE6lfARLle62hkhVRgoKwDnPX7bHjtzKs5xrSXqLG0JWovzBJYQfdOkV/3DM125hpy2kIirjFga71n6waOEzobdGxGz78cMjA3t643FcS+Ekhy+j01Q1FM=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB7PR02MB5113.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(346002)(136003)(396003)(366004)(39860400002)(376002)(451199015)(41300700001)(8936002)(66899015)(5660300002)(4326008)(316002)(786003)(6916009)(66556008)(66946007)(66476007)(44832011)(31686004)(235185007)(8676002)(36756003)(6512007)(53546011)(2906002)(33964004)(6506007)(6486002)(478600001)(186003)(2616005)(21480400003)(38100700002)(86362001)(31696002)(83380400001)(41320700001)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: hCrmyRrknScoZUASBqldxhbHW7G26hQ1+hFZIhBvw8YJZqHZEizF7hLycx1WSEKhqXfm85f+6BaG2MLb8bHQ5QW4H8MW8FE/wrRZOV2AWzkGLRxNzuTB+IByrtOz6QmipmVfO3wqdZK0WHgB3hVbAM5BKsuHIClteHaNKe/2Rnr3v707s+FG3gI1yFinzIp/FhnmrxFj8vMNRh7GbIxkw8GFhGuU2/BsinPVGUY46aAaCIM/xtuHF1sgUHhItvjl3BrDoBbtPR9EsoZl4g+QxXqvW3nitUFLGXdqt413asiQsqtyKlu/OhOGQBNqjzjQ/UtjDdtfQmhXbhhfMgG7SMmyUsBeHGItp/eDvoGCU6aHnUsiXp+imz/L5uBRSr1VZusF+G7OTqKX+APYgRt039zc0OIkvj0KQQpyYZc1SOiEaCa6do9bRBZYgLS56ggszOIsMlnKfLYdUb53M45Q3yVj49o5S6ao1w3QPn9XbR3RvLeSiZtgvdEQYtMlG/2ZAxUkuoixMyq9KVOmvaGgZZOPydag0GKC67KOPgZjrW+CV4MB+VW2+JaL5IaXmb0g6NlOhkPuNNSwbV1qsvR48D32vGL2T0ctvxBBaoIJDfVKTZxgMDA//E6Kag37k+NE88Wv5o5hahHSHnu5dIltWqIKUoaNy7J88oPOPmP5EsGSEIW5rb5Jx/DkVDG69mW/7KE4eZ8KUjbANjSffc4Jno0YDqkDlLFCOlRUrOv6nGI1XN+KomooVXDNupXNaojJgUXR1ovL+8uDqOtSG4D1HubxjEwRvlwgSKWDGPjcQshYf6gx/T5/FWG5fFwgnEdYHsJHqiUOdc18fQLTfo2Q8gBbZgowIG8pVCB0l5vxgEzKykGpd250R0CSCeZirrtik1DadyjHe2BmgG+j62dP9AlU37hzmyodg/LzWaiBN8IkoHK4dioZiA/JV+LktZtVniV0ghwbIzNwiAuegK5H2bfK7oR0dpd6BmyQvZbEEnIifM8Bu/WV/oQxnVn+zdu0jnQm7eh0z9jXlZGm0Nqttikslp4lK9br6vqfA4MfGa2hqz3UibenXYaL+OAYAPXsx8GdDNivVOwf3XqkRJaw7qw3DnRncmYqEvubFos1LNXGdEZqMukRqLnrLOtkpaC8YHt/AiksNh0z8ziTr+gF4uHy5FiLG/0Ubi5C/NOW/gI89zGKJoakEJZohk2q8abTghFGAVdfbvfNTxqdUAGogN75JwMV1KHKlvtEjqUspwYtbJ1maVYmdFr+PtEgkXWa+Nbmi16eCHENJJobKBOOcoaxW9mKk3q6Qp1hoxOvzcnEJ2UfDllnSesrvnD3s4yJsylGmI1jl88bFdrSF0YoDCWiE5Wp6IGUJf6dUrm8ykhfW4Q/JdslRAvxKTIghGsGH3In+Ivi4TOakULKrODE1EO6nDG7dW5BFWUNGBMGsbLb5F8NmWOS/ihGvjLq48l+l9PcHM18UM+e2Vyzpe60B74ZmJ95uAwD69uhngSG41gy6usNtrY1wWzL68gHP/za+lhKf45WCJ9FnO1r7PoYp686x6jqMBl28GrKFQOydIhY5gR2nhO6cyyvvpE3UlYHUT251Ooy4Grz7Zv6xaO5mkLs5ajOnZyPjDYUdI3ZPk0hUvxTcniHcMw0drLJam9x
X-OriginatorOrg: cs.tcd.ie
X-MS-Exchange-CrossTenant-Network-Message-Id: e512ba1d-2c05-4d7f-c853-08dacdaa2d23
X-MS-Exchange-CrossTenant-AuthSource: DB7PR02MB5113.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 23 Nov 2022 23:26:41.4456 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: d595be8d-b306-45f4-8064-9e5b82fbe52b
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: EuiZ1eyyblpXCPbwgRkMdD834k76m+SvjH624t/KAce7BaXCOqTmdb8u+O7XGDgf
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9PR02MB7155
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/2y-oQJfxyl68kICb4DzYQD6Z8Ks>
Subject: Re: [radext] Liaison to government agencies
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext/>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Nov 2022 23:26:52 -0000

Hiya,

On 23/11/2022 23:06, Bernard Aboba wrote:
> Stephen said:
> 
> "Perhaps the charter text you'd like added would say that the WG needs to
> establish what protocol requirements need to be met for FIPS-140 compliance
> before defining anything?"
> 
> [BA] That seems like a good way to go about it. 

Cool. Next step there would be for someone to propose
concrete wording for that, then our AD can decide to
update the draft charter or not. I can give it a shot
tomorrow if that's useful, and if nobody else does it
first:-)

Cheers,
S.

> Just like the IETF has
> learned to avoid "amateur lawyering", it is necessary to avoid "amateur
> regulation interpretation", where participants offer their own
> interpretation of regulations, speaking on behalf of government agencies.
> In the RADEXT WG, we adopted the policies of other IETF WGs in requiring
> that only employees or authorized representatives of government agencies be
> allowed to speak on behalf of those agencies.
> 
>   "Establishing what protocol requirements need to be met"  shouldn't invite
> a discussion among "amateur regulators" about what they think FIPS-140
> "should mean".
> 
> On Wed, Nov 23, 2022 at 1:49 PM Stephen Farrell <stephen.farrell@cs.tcd.ie>
> wrote:
> 
>>
>> Hiya,
>>
>> On 23/11/2022 17:11, Bernard Aboba wrote:
>>> [BA] Employees of NIST have a long history of engagement on network
>> access
>>> security.  The design of 802.11 security (including the RADIUS aspects)
>> was
>>> kicked off by a meeting at NIST. If FIPS compliance is a goal for this WG
>>> (as some seem to think) then we should get info “from the horses mouth”.
>>
>> Ok, think I understand what you're after now, but I'm not
>> sure that requires or would work via a liaison though, for
>> various reasons.
>>
>> Perhaps the charter text you'd like added would say that
>> the WG needs to establish what protocol requirements need
>> to be met for FIPS-140 compliance before defining anything?
>>
>> S.
>>
>