Re: I-D Action: draft-ietf-bfd-secure-sequence-numbers-08.txt

Mahesh Jethanandani <mjethanandani@gmail.com> Wed, 10 March 2021 20:02 UTC

Return-Path: <mjethanandani@gmail.com>
X-Original-To: rtg-bfd@ietfa.amsl.com
Delivered-To: rtg-bfd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 600933A16EC for <rtg-bfd@ietfa.amsl.com>; Wed, 10 Mar 2021 12:02:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SNPeVUyZ_hnW for <rtg-bfd@ietfa.amsl.com>; Wed, 10 Mar 2021 12:02:49 -0800 (PST)
Received: from mail-pj1-x102d.google.com (mail-pj1-x102d.google.com [IPv6:2607:f8b0:4864:20::102d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7839E3A16EF for <rtg-bfd@ietf.org>; Wed, 10 Mar 2021 12:02:13 -0800 (PST)
Received: by mail-pj1-x102d.google.com with SMTP id q2-20020a17090a2e02b02900bee668844dso7841971pjd.3 for <rtg-bfd@ietf.org>; Wed, 10 Mar 2021 12:02:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=tGvDbvIo8PNa3x1q6AZ/3Cif+vNjcZ9Yx8V7j95QW1E=; b=jcWEsbuJbXRU8JY1uVs9ldB9aUcRC6ep1sMc3+QWKm+wI0/Tk/nCeQBbF5tl1D6OIZ YyrB9lvsyWEsoWQ1eHVmnsT64MQCZ+H0aJvE4JwKrgBgwpPpJweDPDA3FzbWIeaRYDLy iF/dmzec5G2jAR0mWU176P84ypnFqbZIqaibTv7QnUWDR0Ds1K1alJxqD8pzc8DyWgnY Q0djwsVsxWll40KUgIIe3Y4k9VfNA+MmFyZj6nntqIrVfBejzOZHdQhOptSKJwLSHM4X lEicQBpJHVVQiBUmPv40r17OjbOR0+aFnjQnk2KCNliLF3PeZQVK5XaeqP126tJnlWtu Ubmw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=tGvDbvIo8PNa3x1q6AZ/3Cif+vNjcZ9Yx8V7j95QW1E=; b=i3woX2VGmjuPOMmQsyj9pJ45n8dRzj23vjMbMXz2LemJDrsjXuJE+6Gf8EpIkS+UMr LNGm3X01NIIip/XgHoDjzNSlW/l7169Bot1FPsaURFjrBhOGg2kRgMBI5cCpDHVPJ+4n SdOeo2sSpRJabfhFdJdHnkK4jnuwttZ5oktgwRA4TV+91nLiNtmcec40btO8EHhRr4Y6 ispA0PUfP3d5cRGgAgmX9otgtMP50mYTRfBVcwlGJCv+p227d/8Y0aeaxS+wox13iYWK cV5meQCDrvZYWD7aTX6dhoCc751Bp0khB0ncODL46As80ko1czOwwxP48KVQMNy+MeHm ZrFQ==
X-Gm-Message-State: AOAM532XyWaJZCUmK+bJIhEldi14Rw1BfePdlX2rYMxqyO7rUeqQUfVi xnniXz6SnrYmGThd27EtMnE=
X-Google-Smtp-Source: ABdhPJyURTmRwbaIJcL2LAwpZUOImCsdr7Fpbchm+T7T7T72HSVyu8/UfwwxCsoFgN+bsxPTaaIa2g==
X-Received: by 2002:a17:90b:1202:: with SMTP id gl2mr5160025pjb.121.1615406531521; Wed, 10 Mar 2021 12:02:11 -0800 (PST)
Received: from ?IPv6:2601:647:5600:5020:3d37:5e78:3342:78d5? ([2601:647:5600:5020:3d37:5e78:3342:78d5]) by smtp.gmail.com with ESMTPSA id t12sm303730pga.85.2021.03.10.12.02.10 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 10 Mar 2021 12:02:10 -0800 (PST)
From: Mahesh Jethanandani <mjethanandani@gmail.com>
Message-Id: <106C31C7-4118-4CEE-935A-D0F02183C987@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_692B87E2-6317-4C55-B67C-F6C4071A9011"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
Subject: Re: I-D Action: draft-ietf-bfd-secure-sequence-numbers-08.txt
Date: Wed, 10 Mar 2021 12:02:09 -0800
In-Reply-To: <D057A636-3E75-4E44-BCCB-04280DF93B26@yahoo.com>
Cc: Sonal Agarwal <sagarwal12@gmail.com>, "rtg-bfd@ietf. org" <rtg-bfd@ietf.org>
To: Reshad Rahman <reshad=40yahoo.com@dmarc.ietf.org>
References: <161523096352.2145.10949026299560929284@ietfa.amsl.com> <CAMMHi8gvfyQFwa6jnr7v-1u1GV-16QKdFBCtJ_R7oyXZeh3D7A@mail.gmail.com> <D057A636-3E75-4E44-BCCB-04280DF93B26@yahoo.com>
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtg-bfd/NuNfW6cYIQ4pJ74wNIV-GgxwIXY>
X-BeenThere: rtg-bfd@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "RTG Area: Bidirectional Forwarding Detection DT" <rtg-bfd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtg-bfd/>
List-Post: <mailto:rtg-bfd@ietf.org>
List-Help: <mailto:rtg-bfd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Mar 2021 20:02:51 -0000

Hi Reshad,

See inline with [mj]

> On Mar 9, 2021, at 7:28 PM, Reshad Rahman <reshad=40yahoo.com@dmarc.ietf.org> wrote:
> 
> Hi Sonal,
>  
> Thanks for the update. But I believe not all comments from ~2 weeks ago (see attached) have been addressed. E.g. use of “symmetric algorithm” and “shared secret key” (as opposed to using variations of the same term).

[mj] I looked at the use of the word “shared” in the draft, and there are four instances.I believe in two of those cases it is being used to indicate that the key has to be shared between the sender the receiver, i.e. as an adjective to the word key.  Do you have another way to suggest similar text?

The two other instances where it is still being used, in Section 3 with this line:

The result is computed, using a shared key, on the sequence number.

and then later in the same section with this line:

   Upon receiving the BFD Control packet, the receiver decrypts the
   ciphertext using the same provisioned shared key to produce the
   received sequence number.

we could change it to say “shared symmetric key”.

>  Also, section 4 headline is still “Impact of using a hash”, but the text has been changed (hash -> cyphertext) here <https://www.ietf.org/rfcdiff?url2=draft-ietf-bfd-secure-sequence-numbers-07>.

[mj]. Agree. We can change the header to say “Impact of using ciphertext in-lieu of sequence number”.

Would these changes address the remaining comments?

>  
> Regards,
> Reshad.
>  
> From: Rtg-bfd <rtg-bfd-bounces@ietf.org <mailto:rtg-bfd-bounces@ietf.org>> on behalf of Sonal Agarwal <sagarwal12@gmail.com <mailto:sagarwal12@gmail.com>>
> Date: Monday, March 8, 2021 at 2:40 PM
> To: <rtg-bfd@ietf.org <mailto:rtg-bfd@ietf.org>>
> Subject: Re: I-D Action: draft-ietf-bfd-secure-sequence-numbers-08.txt
>  
> Hi all,
>  
> Version 8 of the draft addresses all Shepherd comments.
>  
> Regards,
> Sonal.
>  
>  
> On Mon, Mar 8, 2021 at 11:16 AM <internet-drafts@ietf.org <mailto:internet-drafts@ietf.org>> wrote:
>> 
>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>> This draft is a work item of the Bidirectional Forwarding Detection WG of the IETF.
>> 
>>         Title           : Secure BFD Sequence Numbers
>>         Authors         : Mahesh Jethanandani
>>                           Sonal Agarwal
>>                           Ashesh Mishra
>>                           Ankur Saxena
>>                           Alan DeKok
>>         Filename        : draft-ietf-bfd-secure-sequence-numbers-08.txt
>>         Pages           : 6
>>         Date            : 2021-03-08
>> 
>> Abstract:
>>    This document describes a security enhancement for the sequence
>>    number used in BFD control packets.  This document updates RFC 5880.
>> 
>> 
>> The IETF datatracker status page for this draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-bfd-secure-sequence-numbers/ <https://datatracker.ietf.org/doc/draft-ietf-bfd-secure-sequence-numbers/>
>> 
>> There are also htmlized versions available at:
>> https://tools.ietf.org/html/draft-ietf-bfd-secure-sequence-numbers-08 <https://tools.ietf.org/html/draft-ietf-bfd-secure-sequence-numbers-08>
>> https://datatracker.ietf.org/doc/html/draft-ietf-bfd-secure-sequence-numbers-08 <https://datatracker.ietf.org/doc/html/draft-ietf-bfd-secure-sequence-numbers-08>
>> 
>> A diff from the previous version is available at:
>> https://www.ietf.org/rfcdiff?url2=draft-ietf-bfd-secure-sequence-numbers-08 <https://www.ietf.org/rfcdiff?url2=draft-ietf-bfd-secure-sequence-numbers-08>
>> 
>> 
>> Please note that it may take a couple of minutes from the time of submission
>> until the htmlized version and diff are available at tools.ietf.org <http://tools.ietf.org/>.
>> 
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/ <ftp://ftp.ietf.org/internet-drafts/>
>> 
> <Mail Attachment.eml>

Mahesh Jethanandani
mjethanandani@gmail.com