[radext] Re: Interim Meeting Tomorrow

Jan-Frederik Rieckers <rieckers@dfn.de> Tue, 03 March 2026 09:20 UTC

Return-Path: <rieckers@dfn.de>
X-Original-To: radext@mail2.ietf.org
Delivered-To: radext@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6DEBBC34F44C for <radext@mail2.ietf.org>; Tue, 3 Mar 2026 01:20:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=dfn.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MzpKLjY1hwTt for <radext@mail2.ietf.org>; Tue, 3 Mar 2026 01:20:18 -0800 (PST)
Received: from b1004.mx.srv.dfn.de (b1004.mx.srv.dfn.de [IPv6:2001:638:d:c302:acdc:1979:2:58]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 06F1FC34E046 for <radext@ietf.org>; Tue, 3 Mar 2026 01:13:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=dfn.de; h= content-type:content-type:in-reply-to:organization:from:from :content-language:references:subject:subject:user-agent :mime-version:date:date:message-id:received; s=s1; t=1772529182; x=1774343583; bh=Lb4sEn2RHl38iq7yMbUNCdsW2+rEZdfeI3xoXNm7EOU=; b= ZyotAbfTeuT1nmoVXUgEO0rOSljBrWP+NPxKGrKBY6SILgRZ/BW92nhR6Tr03KEb /G/SrF/oXfSwaeZdduVwi+FL8RdhsCBHF0GFL/DziDvvBwsI+I4SxJDNJ8rrAap7 IHxmhyim61QAWAydb/Jw3d+dVuTE3Q8mj/LEfUSwMfs=
Received: from mail.dfn.de (mail.dfn.de [194.95.245.150]) by b1004.mx.srv.dfn.de (Postfix) with ESMTPS id 9BF9B22017F for <radext@ietf.org>; Tue, 3 Mar 2026 10:13:02 +0100 (CET)
Received: from [IPV6:2001:638:708:301:69c7:98b9:d030:81a6] (unknown [IPv6:2001:638:708:301:69c7:98b9:d030:81a6]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mspool2.in.dfn.de (Postfix) with ESMTPSA id 813BC39B for <radext@ietf.org>; Tue, 3 Mar 2026 10:13:02 +0100 (CET)
Message-ID: <e22fe2ef-9c89-40ba-9bbe-0aeaa18d6d2d@dfn.de>
Date: Tue, 03 Mar 2026 10:13:00 +0100
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: radext@ietf.org
References: <CADZZzuqBDypBnOp9-sz=ZAnHC+-Qno-snm__MPFGY50NC_SLgg@mail.gmail.com> <08e101dca673$631b0fc0$29512f40$@smyslov.net>
Content-Language: en-US
From: Jan-Frederik Rieckers <rieckers@dfn.de>
X-Enigmail-Draft-Status: N11222
Organization: DFN e.V.
In-Reply-To: <08e101dca673$631b0fc0$29512f40$@smyslov.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms040609050009040609010705"
Message-ID-Hash: 47W3YJCMTLUUQKKFLOQV3PL72W4F3JGE
X-Message-ID-Hash: 47W3YJCMTLUUQKKFLOQV3PL72W4F3JGE
X-MailFrom: rieckers@dfn.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-radext.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [radext] Re: Interim Meeting Tomorrow
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/cD75K2wORg6Y7s2_jVpfUsH0Qj0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Owner: <mailto:radext-owner@ietf.org>
List-Post: <mailto:radext@ietf.org>
List-Subscribe: <mailto:radext-join@ietf.org>
List-Unsubscribe: <mailto:radext-leave@ietf.org>

Hi all,

given that no one has objected and the telechat is in two days, I would 
just apply the following changes and upload a new draft version.

On 2/25/26 17:25, Valery Smyslov wrote:
>  1. We agreed to add a text to draft-ietf-radext-radiusdtls-bis about ALPN
> 
> with indication, that ALPN is "SHOULD" (and not "MUST").
> 
> See also https://github.com/radext-wg/draft-ietf-radext-radiusdtls-bis/ 
> issues/158

https://github.com/radext-wg/draft-ietf-radext-radiusdtls-bis/pull/162
The pull request looks good to me. Thanks Alan!
I would merge this pull request.


>  2. As to whether re-asses RadSEc connections when trust anchor(s) change,
> 
> there was weak consensus that we "MUST" do this. See also
> 
> https://github.com/radext-wg/draft-ietf-radext-radiusdtls-bis/issues/159

I would change the SHOULD to MUST, also to address the comment from Éric 
that every SHOULD should have a reasoning in what circumstances this can 
be ignored and what happens otherwise.


>  3. There was a consensus not to mandate any specific logging when
> 
> a fallback from RadSec to RADIUS/UDP occurs. See also
> 
> https://github.com/radext-wg/draft-ietf-radext-radiusdtls-bis/issues/160
Given that no one chimed in in favor of this, I would not change anything.

Cheers,
Janfred
-- 
Herr Jan-Frederik Rieckers
Security, Trust & Identity Services

E-Mail: rieckers@dfn.de | Fon: +49 30884299-339 | Fax: +49 30884299-370
Pronomen: er/sein | Pronouns: he/him
__________________________________________________________________________________

DFN - Deutsches Forschungsnetz | German National Research and Education 
Network
Verein zur Förderung eines Deutschen Forschungsnetzes e.V.
Alexanderplatz 1 | 10178 Berlin
https://www.dfn.de

Vorstand: Prof. Dr.-Ing. Stefan Wesner | Prof. Dr. Helmut Reiser | 
Christian Zens
Geschäftsführung: Dr. Christian Grimm | Alina Hain
VR AG Charlottenburg 7729B | USt.-ID. DE 136623822