Re: [radext] CUI comments in "deprecating insecure transports"

"Mark Grayson (mgrayson)" <mgrayson@cisco.com> Wed, 26 July 2023 15:52 UTC

Return-Path: <mgrayson@cisco.com>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E74DC1527BC for <radext@ietfa.amsl.com>; Wed, 26 Jul 2023 08:52:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.604
X-Spam-Level:
X-Spam-Status: No, score=-14.604 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b="KYCewhAn"; dkim=pass (1024-bit key) header.d=cisco.com header.b="fsOJbrSc"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R-PG2Et1DtLA for <radext@ietfa.amsl.com>; Wed, 26 Jul 2023 08:52:41 -0700 (PDT)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 507FCC1527A6 for <radext@ietf.org>; Wed, 26 Jul 2023 08:52:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7482; q=dns/txt; s=iport; t=1690386761; x=1691596361; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=DSvf0jxvfFH6iGUzlaG2i+wN/Xf2cGlKJVay/PgCDLo=; b=KYCewhAnF50oZLrpfRCFmOl5KHZzC+wGc0YuX7pStRrcEM9BNlmX0Ifw SaAirKrjDpdd49l6a9g4sMkk3T8MLl3Ux9LPZOirPhPkMQZwjdMQxZH6d bFyRVIZo4rEub+/QZkPNA3XwonhN1kUqLh7SaShPMIsSO3KzVy9s9f+M+ M=;
X-IPAS-Result: A0ADAAAwQMFkmI0NJK1QChoBAQEBAQEBAQEBAwEBAQESAQEBAQICAQEBAUAlgRYFAQEBAQsBgS8xUnMCWTxHiB0DhE5fiF8DgROKRItQhk+BJQNWDwEBAQ0BAS4BCgsEAQGEQEYChj8CJTQJDgECAgIBAQEBAwIDAQEBAQEBAwEBBQEBAQIBBwQUAQEBAQEBAQEeGQUOECeFaA2GBAEBAQEDAQEQLgEBLAQHAQ8CAQgRAwECAS4hBgsdCAIEAQ0FCBqCXAGCFRMDMQMBEKEuAYFAAoomeIE0gQGCCQEBBgQFsBYNgkkDBoFCAYdhHgGBSYFahlQnG4FJRIEVQ4FmSjg+giBCAQGBMy8eDYNngi6FSIRAhVEFAjKCOIh1K4EICF6Bbz0CDVULC2OBGFI5gT4CAhEnExRQeBsDBwOBBRAvBwQvBxYJBgkYGBclBlEHLSQJExVABIF6gVYKgQc/FQ4RglErNjgbTIJqCRUGOgdMehAuBBQYgQsIBFQnJRoePRESGw0FCIEBAxoDBgIJAgIEHQNEHUADC3A9NQYOGwUEZ1kFm3ILEAOCORBCHwGBKhAgKBMCaCBVDgIwkkyOQUeNcpN0bwqEC5sQhicXhAClV5gnIIIvjwSQe4VHAgQCBAUCDgEBBoFjOoFbcBU7gmdSGQ+OIAwNCYNShRSKZAF1OwIHCwEBAwmLSAEB
IronPort-PHdr: A9a23:Fng2ExZARg4xobIEJyNWwOj/LTDhhN3EVzX9orIuj7ZIN6O78IunZ wrU5O5mixnCWoCIo/5Hiu+Dq6n7QiRA+peOtnkebYZBHwEIk8QYngEsQYaFBET3IeSsbnkSF 8VZX1gj9Ha+YgBOAMirX1TJuTWp6CIKXBD2NA57POPwT4vdlc2mzOe005bSeA5PwjG6ZOA6I BC/tw6ErsANmsMiMvMo1xLTq31UeuJbjW9pPgeVmBDxp4+8qZVi6C9X/fkm8qZ9
IronPort-Data: A9a23:dFXYx6mR2DydGUfqkxLtQJno5gz5JkRdPkR7XQ2eYbSJt1+Wr1Gzt xJLXT2DOfrbM2ShLopxYIuy8E0Eu5LVmIIwSFFoqiwwQ1tH+JHPbTi7wugcHM8zwunrFh8PA xA2M4GYRCwMZiaA4E/raNANlFEkvU2ybuKU5NXsZGYpHGeIdA970Ug4w7Fj3NYx6TSEK1rlV e3a8pW31GCNg1aYAkpMg05UgEoy1BhakGpwUm0WPZinjneH/5UmJM53yZWKEpfNatI88thW6 Ar05OrREmvxp3/BAz4++1rxWhVirrX6ZWBihpfKMkSvqkAqm8A87ko0HPcdS0ZcsBePo/5K1 YxVrs2QFzkNGaKZzYzxUzEAe81/FaRC/LmCKn+lvInDiUbHaHDrhf5pCSnaP6VBpb0xWj8Ir KdecWxUBvyAr7reLLaTT+Z2j9U4K8/DN4IEsXYmxjbcZRojacmYGfmWvoIAhV/cgOhTJ+zTe +YeRgBtcRrRT0RRM2YqD54hybLAan7XKm0E9w39SbAMy3LawAFhzJDsPcbbPNuQSq1ocl2wr 2bC+SHyBQsXcYzZwjue+XXqjejK9c/mZG4MPLC51P9hu3+V+kIoFUQOTgqb/8edrUHrDrqzN Hco0iYpqKEz8mmiQd/8QwC0rRa4Uvg0BoQ4/woStV/l90bE3+qKLjNfFm8bOLTKoOdzFGJ0i gLV9z/8LWE32IB5X05x4Vt9QdmaECwRIGlqicQsElZdu4OLTG3ecnvyojtLGaqxiJj+Hiv9h mDMpykljLJVhskOv0lawbwlq2z2znQqZldqjukyYo5Dxl8lDGJCT9DygWU3Fd4acO6koqCp5 RDoYfS24uEUFo2qnyeQWugLF7zBz6/bYWWH2Q8/RMl7qGnFF5ufkWZ4vmgWyKBBbJ5sRNMVS BS7Vf55vcUKZyL6McebnarhUZpCIVfc+STND6CIMYUmjmlZfw6c9yYmfl+Lw23oiyARfVIXZ /+mnTKXJS9CU8xPlWPuL89EiOND7n5lnwv7G8ukpylLJJLDPhZ5v59fbgvXBg34hYvZyDjoH yF3bJTSlUUHAL2iPkE6M+c7dDg3EJTyPrivw+R/fe+YKQ0gE2YkY8I9C5t4E2C5t8y5Ttv1w 0w=
IronPort-HdrOrdr: A9a23:Yrlaz6AAeemPDv/lHegesceALOsnbusQ8zAXPh9KKCC9I/b3qy nxppsmPEfP+UkssREb8+xpOMG7MBThHO1OkPcs1NaZLUTbUQ6TTL2KgrGSuAEIdxeOk9K1kJ 0QD5SWa+eAQWSS7/yKmjVQeuxIqLLqgcPY59s2jU0dMD2CAJsQiTuRfzzranGeMzM2fKbReq DsgvavoQDMRV0nKuCAQlUVVenKoNPG0Lj8ZwQdOhIh4A6SyRu19b/TCXGjr1kjegIK5Y1n3X nOkgT/6Knmmeq80AXg22ja6IkTsMf9y+FEGNeHhqEuW3TRY0eTFcRcso+5zXIISdKUmRMXeR 730lMd1vFImjDsl6eO0FzQMkfboXATAjTZuC6laDPY0LzErXQBeoV8bUYzSGqA16Lm1+sMiZ 5jziaXsYFaAgjHmzm479/UVwtynk7xunY6l/UP5kYvGbf2RYUh27D3xnklWasoDWb/8sQqAe NuBMbT6LJfdk6bdWnQui1qzMa3Vno+Ex+aSgxa0/blmQR+jTR81Q8V1cYflnAP+NY0TIRF/f 3NNuBtmKtVRsEbYKphDKMKQNexCGbKXRXQWVjiamjPBeUCITbAupT36LI66KWjf4EJ1oI7nN DbXFZRpQcJCjXT4A21rel2Gzz2MRCAtG7Wu7JjDrBCy8/BeIY=
X-Talos-CUID: 9a23:sDgZo2gzPUL1Ljg1u/yDOcW+7zJuf3z/zXzrAUmEJ110EaWOGH/OxodDnJ87
X-Talos-MUID: 9a23:vdZYuwwEyiAtwrW0Ekl5hAZTEUiaqLmUEk0RvZIpgcuZOz1cYimUvQmwTpByfw==
X-IronPort-Anti-Spam-Filtered: true
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-7.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 26 Jul 2023 15:52:40 +0000
Received: from alln-opgw-3.cisco.com (alln-opgw-3.cisco.com [173.37.147.251]) by alln-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id 36QFqcCY015756 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <radext@ietf.org>; Wed, 26 Jul 2023 15:52:39 GMT
Authentication-Results: alln-opgw-3.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=mgrayson@cisco.com; dmarc=pass (p=quarantine dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.01,232,1684800000"; d="scan'208,217";a="4719458"
Received: from mail-dm3nam02lp2040.outbound.protection.outlook.com (HELO NAM02-DM3-obe.outbound.protection.outlook.com) ([104.47.56.40]) by alln-opgw-3.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 26 Jul 2023 15:52:37 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Or+Sbx4g1PGohkw8/vHnYQ5lsaAwtemiGwuPxZjjw298jJ/kwy6ZM4fjp1JNSKcDGvgBDkxS6WSH7NHjFrl7qfSrV9z6/1GDklyQXYzGbpRclp9DcRbcnbMaaRWrVJcXk9WokTYr5YVSmIsPT6aDFSqYpXx5fqZN1LdYUVS3FdseJU2SOUOGoKrbgAKwXwxGxKdr76U8VkHtzaCuMAaLqa9YgyrjHMY7Mk8/mWFA0iVMROPpfOVfCicPfevK7NLHwlMwHioM0tlkLc3Jzl7uhlxea3f3BImntNO70wuPa2XewY0NlTCmHDsW0eRfHpbt0fZDsqA6+irEIin0DnLd+Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gF3Jj3oVOJQvB99Hs4Deut0N8OGmCqIHulCFzh2Fy+I=; b=k/OOHEiItbwppsDTFBnHqSVXG2+j/GJbIx0ZXeGdFYfQ5WSEUhJY9A3pbuLrEkHENGKcZvDZ1rRfTHlB5raB8wpX/CVPl0Qzp05geaa74KIprLpU2RTQnKfetKHPzvO306YMeQdYjF7dwQEdMnyNs6lHHz7mfT9RE7krAC8jgBTmzrnO8dRIIuXGOXg4c73egqcuW13i3BgREaDfNIB86Xb1rnAyCnoouF6yHpfMiwsJpSHf3ypEbiEUGexB1wlliLtmlSk4vocWj8mzQPYcwMfU1UvHp6BqK2l8Ut0lnSwon8KyrcQ4ishd2YaPoGcbRIf/vk+s/rtRFJewn5J46g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gF3Jj3oVOJQvB99Hs4Deut0N8OGmCqIHulCFzh2Fy+I=; b=fsOJbrScDLAwY+2wWvMfIhWOkYCuNVDoHTKhMvYEVXfWQbVMGijn4VX49On+gQT4c3FsrIjXsVxhp7ZsPOSAVKOLa4g8v+awvjmuI9s6DijaqBbZaE8k3exwXzzpVI0J1xxhcd11N6iImcj/BEXTHbx/Ig0b/EEf+xdwPVCrzEg=
Received: from PH0PR11MB5928.namprd11.prod.outlook.com (2603:10b6:510:144::16) by PH8PR11MB6729.namprd11.prod.outlook.com (2603:10b6:510:1c5::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6631.29; Wed, 26 Jul 2023 15:52:36 +0000
Received: from PH0PR11MB5928.namprd11.prod.outlook.com ([fe80::b659:b466:5b2b:d1cd]) by PH0PR11MB5928.namprd11.prod.outlook.com ([fe80::b659:b466:5b2b:d1cd%5]) with mapi id 15.20.6609.030; Wed, 26 Jul 2023 15:52:34 +0000
From: "Mark Grayson (mgrayson)" <mgrayson@cisco.com>
To: Alan DeKok <aland@deployingradius.com>, "josh.howlett@gmail.com" <josh.howlett@gmail.com>
CC: "radext@ietf.org" <radext@ietf.org>
Thread-Topic: [radext] CUI comments in "deprecating insecure transports"
Thread-Index: AQHZvo98w/4fmQtODkSZTAcpN1j7Nq/MBKCAgAAmn4CAAAhlXg==
Date: Wed, 26 Jul 2023 15:52:34 +0000
Message-ID: <PH0PR11MB5928721437690CD39DC3ECEFD200A@PH0PR11MB5928.namprd11.prod.outlook.com>
References: <BC530A34-D348-44D0-886E-DB1ECF3A5010@deployingradius.com> <06c301d9bfc0$e07154d0$a153fe70$@gmail.com> <5F5C2E17-2061-4FFC-942A-9C4ED861EE5F@deployingradius.com>
In-Reply-To: <5F5C2E17-2061-4FFC-942A-9C4ED861EE5F@deployingradius.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR11MB5928:EE_|PH8PR11MB6729:EE_
x-ms-office365-filtering-correlation-id: 64a98118-df8c-4796-2f74-08db8df05405
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 0r2+VmYOZl1Irh6yb8QJn+ZIWJ+wNTGITs1TUzWhppuASbatXz0p/W2lv77JXLl1YHN21Wev6szxqLI+mKQYsjxD6Q84vopkD9n3SEWOKiUUNy5x3pBp0wlzM8++hofwTLxJVxZXW7WnVvQXCHsZLQjWZoTUlxZnwSOVAn428cKQK2Iq/j3ULYE05o6BFlvrb6Nq82aqXLON0MUHTl1aeYa6bDMux/4PfU5U3fu8Su5nCV6Hyn/RwrT/XlruK4JIY/M3DHgosQPqyn3PVvVfij3ALIqE/JrgdfbdWBIB0jVKfoHpwdjc5/QgcSgvH3dUo4x9sWvgtpP9CEmoRuRTOtD3ZoNuX/C2QAD/VYz1NMuZY8iFCASk28lAaiNyb4PmYXm5/rSoOCH6O/w7cp62OiRXEXdOtUJ9pVVjm+wHA1vA1KuKF/T7Z93ZjY4YpsAr5Ejh+5573FulmODjplAcNDeXPivPXq5++fJWGJUuFFgfUeHzZgU/qNSNn1bZAOfxhojDE0GGtHsVjjS8fmXo0RzefnTvZy/0U+ikw43nPIWC6Zc54a/vtNHMuSgn0Sdf7l+olBqCqxpWlQ91gnrlq/G0y4ZJsary76khn4/v454=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB5928.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(376002)(39860400002)(346002)(366004)(396003)(136003)(451199021)(316002)(53546011)(26005)(6506007)(8936002)(66899021)(41300700001)(8676002)(33656002)(110136005)(122000001)(64756008)(66556008)(76116006)(66476007)(66946007)(478600001)(966005)(4326008)(166002)(66446008)(91956017)(9686003)(55016003)(71200400001)(7696005)(38100700002)(2906002)(38070700005)(86362001)(83380400001)(52536014)(186003)(5660300002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: /0d5FBagGoF5RhcpvzekS9wA5uCDKIU+ITBJdGT2UpvOPKrxMyaQHXviCoT7H4OsXIiWycP5EOzvOQf3K8sNJ9CJED0mTo9ITOTeSvev25Ux2GtREVUW011iwCpwuNRnnH3fbdfi+NcS4f5rQL3TqQa1TadTXluCwFANgF72mAK/lKQLSkxr0gNdbh3DEaq1s9Gc9YbVaLqSnE/OHigcp7PFfeRJAoOX4XjPvGJhxTpQAWOXjXJNG2DSuwFjHhfiUHeGhuHTkguGgaum15jRK7QyOk+Ij+BKGfS0zAMdXMLlnldCo3J3ksDt1F3eQxkRzAQOJQCbl/eL3CTgxFI/OKN+XDafs4yBCKewl10k3kxem0t6eLraGD8RmnpUPMjOP6ag60UZJLnMpk9R6krN0XcM38DI38m3eFXjBPTjcNSndgQE5ENgTJQ9ricxMZhNCN4N8wLxT+CNWNr5fIOmL3gDjjNUq/CZAM4vQSHxjuHMDqcZxOhNuOfsxIICRppy4yhwSEGGblFF4SgAlMOz26Y4sOhY8D/pk+5iVEN5KrZPaoEUYRCRW2xxP6er7DPfRBwRBZLaylAD2/iSIeZbMqEnLxG9d8FvPg3NTpGok7WsF2WfKXctOYbs+eqomLQ2EsIh9Bnn5pkU8pSq4VN2dr65NqZCi6aCTfDNQ8LIZRldGrhFPOQR8ZxjuGFpqa5zk8f7K/8gmbtRtexew0op4n1kEhOp+rdwdG8SpRF54fCmH+qswZnYuG3Q5SWhR2dBcHs5zpjrKXZncH91NTajy/Z6yJjuOBEKfIHSs6WnZ2hF968mNno5/HJkEI2jTGrmLfEmJVRn8GLPxxDG2jnXCwfqieXf6xo+It67Gpw5aynPPjwysup1i/yEYtEBSFjg+l5CLYmIdXtwbTizJvdSgNBc35Ck8HX0eZo8QKmYnPrxID+LBtuDT4eUYK/p1M9UvzaZMohsttn174TyO1pAP/O21EZ4hlT9eLVsKJKhZrQOIwZ4em/Kljm0hmUbilsim55WV0A3NWToIFcarcpjwpwC6dKvBzrh8/pUKNi/8FTR4rHAz3ZAu+usIKtB5vbc4Q0courp793I+aPZx6Pu7gLZ3XAkl7JR2bsYlDt2hHsswGK3GmVvT6f6UTugxzG7YEGuj2eCgQLZutb85T/FXG1P3eBG1le5m7083f/RIgRomk+5a8i+Wggb8uvFOcWtJbRA0WxvmnZ4T4nPvxRihP/8Z5SMd+SUVozu8EP7C3Ihr3DlilcdqPyAwTMls1f85j/fyFyvqlevLP/mXdpvJcfeOsX4ykxIg7oYFh20//p/hbq4XaUJ22DYR3VJFZH4OvuyirBE443Xhn4k7HRkG50uMliqF+wPiQ+IjEoBLEKEyqkhX/hI5WszdcTCWo/agKRqOrGfa62DFeWVfmbA4cpThPa0La0EOt83ML08u/qpbkqjX4P6UheKhdd7d+YnOT675lEEKDoKvcIsvIFc5PwwVCTgWRQl91nvQ2tiU7AhQkiOLLXVj4xE/ECUfFbvLD95oeK4Os617Hn9rfZ5ILrgWcsKwAvckVzqBm3tVvOHJtpYagZmTjF2YhvG3mzM9r7TYDkA4yvMwhH//VNWnQ==
Content-Type: multipart/alternative; boundary="_000_PH0PR11MB5928721437690CD39DC3ECEFD200APH0PR11MB5928namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB5928.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 64a98118-df8c-4796-2f74-08db8df05405
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jul 2023 15:52:34.3772 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 5zUf1oJfQY9fSGVnRriG9xegDugSVMl0WwN+t1ZkwmohidppzqPbEBxKY+vz9EtfkrWcTebWZN0ohc/a2InZKg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR11MB6729
X-Outbound-SMTP-Client: 173.37.147.251, alln-opgw-3.cisco.com
X-Outbound-Node: alln-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/SYICskZIo2_E1z1ERrb4qYifxxo>
Subject: Re: [radext] CUI comments in "deprecating insecure transports"
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext/>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Jul 2023 15:52:46 -0000

Whereas there is text on binding-lifetime for CUI, does there need to be equivalent discussion around the use of user-name re-write and class attribute?

Cheers,
Mark

From: radext <radext-bounces@ietf.org> on behalf of Alan DeKok <aland@deployingradius.com>
Date: Wednesday, 26 July 2023 at 16:17
To: josh.howlett@gmail.com <josh.howlett@gmail.com>
Cc: radext@ietf.org <radext@ietf.org>
Subject: Re: [radext] CUI comments in "deprecating insecure transports"
On Jul 26, 2023, at 5:58 AM, <josh.howlett@gmail.com> <josh.howlett@gmail.com> wrote:
>
> There are good reasons for the CUI value to be persistent, provided that it
> is targeted to each network access provider. In this way, different
> providers cannot collude to track users. However, they still maintain the
> ability to *recognise* (but not identify) the same user that they saw
> previously.
>
> There are legitimate reasons to track and, if necessary, identify users,
> including troubleshooting and prevention of service abuse.

  The intent of CUI was that if a user was abusive, the visited network could report the CUI to the IdP.  The IdP would then block the user.  While this isn't perfect, it provides for better user privacy.

  Where there is a trade-off around user privacy, I would lean towards keeping user privacy at the cost of increased effort in the network.

  I'll see if I can update the wording to suggest that the CUI can be static for one visited / home network relationship, provided they both agree to this.  But generally it's better to have it different for every session.

  The issue of CUI changing is made a little less relevant by the fact that the MAC address doesn't change for one visited network (SSID, etc).  So the visited network can always correlate MACs across sessions.

  But for me, this is about nibbling away at the privacy bits one problem at a time.  At some point, MADINAS will perhaps allow MACs to be changed per session, and then that problem will go away.  And the CUI will already be different per session (usually).  So we won't have to go back and fix it again.

  Alan DeKok.

_______________________________________________
radext mailing list
radext@ietf.org
https://www.ietf.org/mailman/listinfo/radext