RE: Secdir last call review of draft-ietf-rtgwg-net2cloud-problem-statement-36

Linda Dunbar <linda.dunbar@futurewei.com> Thu, 11 April 2024 22:08 UTC

Return-Path: <linda.dunbar@futurewei.com>
X-Original-To: rtgwg@ietfa.amsl.com
Delivered-To: rtgwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A9EEC14F6BD; Thu, 11 Apr 2024 15:08:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.098
X-Spam-Level:
X-Spam-Status: No, score=-7.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=futurewei.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4N1wv0O9hQUT; Thu, 11 Apr 2024 15:08:33 -0700 (PDT)
Received: from NAM11-CO1-obe.outbound.protection.outlook.com (mail-co1nam11on2117.outbound.protection.outlook.com [40.107.220.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC6B9C14F5FC; Thu, 11 Apr 2024 15:08:32 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=T2wTc7Sk9equKMW75jp5o2OVoeoO+GBMs6fo8mNWZpfVpEThFj2efbZUti43ayEWFjj8lO2Yxa1SrJXXzoloSeIT2b+K0/p5nH/3BLFSGboxGraAL9vgtcfN/Psn8coGsVztOpUcI3blIPioI7FgO3Gyu3eKAUKGy8vKYrr3E/ZzGfZYml2O2KTUrDjcG/hwioyyNF27vLqrDAmlf1E1jO2WVoO0oN/AzAZRl/60ctkmGKoY8n3MLZYHgZx6+R87rZ4fngbVNiOJnXVdq20DimYb0cpqbqXO9wqmdZ9hz6o+ieUijSC9N3jpraFxGuQ0kE1y6yUFX7A2Yhnj3w5UuA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=FPTDYd0uw+a0V4zLpjc0OcdXIrzB/U3lJUUcqqrfayw=; b=m6lHLkAPM4rNjELYdl9RrjN3cAl2eIJHgSmEBxxcFLLWyc+Dep2Fiuf5CGT0qtdUgwV1BOvSI/4ZHlzH++t3vwMLk4a7CA/1RTerWXtQsNsOu22KWtCJMAqiAISZCIfZrd/RxMw+3vH5Q0HHEwtjjzu1YyEpCfElLkduxJlmrDaU9MYKidFZ+gzSkJo0rGGTFiy7Hv3YMeluWX4Q4dMofWP/Lpb7zKU3vLLNXW4sXL17gdz/n8WNomCm+Pf4ErZ5tl64g4M0RxwBIvsm3ktTdHMG76NLxS4L5N6oJxbyQkpBOhorDhdwpMGZZmJl9F3OaUfHoSFEI/JPmQ7Nh1GmkA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=futurewei.com; dmarc=pass action=none header.from=futurewei.com; dkim=pass header.d=futurewei.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Futurewei.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FPTDYd0uw+a0V4zLpjc0OcdXIrzB/U3lJUUcqqrfayw=; b=LE9VcKMnba3A61fDLieyyLXYVb16EvFl9DXM7miH8VthOZKgX8pYsx6acg6H6VwxXMQtQQV2fFJpSgw4IwpSGDlaA1DYFNBpxHj4iNO8nnGS2+nB06gXHStLg5rQEDeTJ61KQi4ABDN0Bv10ykrzd7CCkDyIL25pzHdDxrOIfL8=
Received: from PH0PR13MB4922.namprd13.prod.outlook.com (2603:10b6:510:92::5) by PH0PR13MB5300.namprd13.prod.outlook.com (2603:10b6:510:f8::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.46; Thu, 11 Apr 2024 22:08:28 +0000
Received: from PH0PR13MB4922.namprd13.prod.outlook.com ([fe80::f04d:f937:5fb3:6e22]) by PH0PR13MB4922.namprd13.prod.outlook.com ([fe80::f04d:f937:5fb3:6e22%7]) with mapi id 15.20.7409.053; Thu, 11 Apr 2024 22:08:28 +0000
From: Linda Dunbar <linda.dunbar@futurewei.com>
To: Deb Cooley <debcooley1@gmail.com>
CC: "secdir@ietf.org" <secdir@ietf.org>, "draft-ietf-rtgwg-net2cloud-problem-statement.all@ietf.org" <draft-ietf-rtgwg-net2cloud-problem-statement.all@ietf.org>, "rtgwg@ietf.org" <rtgwg@ietf.org>
Subject: RE: Secdir last call review of draft-ietf-rtgwg-net2cloud-problem-statement-36
Thread-Topic: Secdir last call review of draft-ietf-rtgwg-net2cloud-problem-statement-36
Thread-Index: AQHaa9HG9RDIlOpAVkOpC4+xTgM5u7EoTIjggAC5uACAFJEZgIAjDYUQgAKAdYCAALxMQA==
Date: Thu, 11 Apr 2024 22:08:28 +0000
Message-ID: <PH0PR13MB4922BB9844C5D95E5001B14A85052@PH0PR13MB4922.namprd13.prod.outlook.com>
References: <170929516566.22050.4912794500698236384@ietfa.amsl.com> <CO1PR13MB49202C23241E301DB62DEE9085222@CO1PR13MB4920.namprd13.prod.outlook.com> <CAGgd1Of_3KuOpg4G9Pf0N4Qm-g+a0ymrVUV36Q0RY93gc-9Tfg@mail.gmail.com> <CAGgd1Oev+UPzLCpf+m+sKUt55KoDXX89gxfhdzqi057Avr51sA@mail.gmail.com> <PH0PR13MB4922280EFDD4CAAB0E2299D285062@PH0PR13MB4922.namprd13.prod.outlook.com> <CAGgd1OdDSS6VpEpikOKyxfm+w7f5r6=0Y=C_6eDj_pW7CCmz9g@mail.gmail.com>
In-Reply-To: <CAGgd1OdDSS6VpEpikOKyxfm+w7f5r6=0Y=C_6eDj_pW7CCmz9g@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=futurewei.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR13MB4922:EE_|PH0PR13MB5300:EE_
x-ms-office365-filtering-correlation-id: 7e0de220-cd38-44fe-c25e-08dc5a73eabc
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: fk5WRl6vwg1ZhlAojzTZtILbjADJvjYXcoxAtS3+dve/tjrZ8HdYGYkzIQAfOO3vVUVxqgU1LWCYBe5MUvc0GYgnZBPpqp06wEEtUKVKZ+ANuXxjkOmLAonO55T2Sgbvx6wROCrcSG3RuQ5p33yogY9MvM3pUz+Id8R+LuS/t4jaLfXiSu7JiU7flcnraZi6Nh/5ScMG4C82CZlaaQUx11Fda1yV059Na+rrXnbp1/1oeaVmTI0uyxB7mKYsQz3fYCLtWdoXvGbmzc9wGZZBLVgr5FLfRWQFfbcFTRoqSPGTHci7SLC9fqx7zSJ0Y243bw1fgrWe0D8/sfQa57ZavRgsFwJioy4TAHWEsKcKY7cptqTWbgPQ1+iDtx53o5X8cYd5s6/a2yh6zWqUmSmbe9E0rwR1KBNYPckQvgrUWsp1aKXJB4+ohmsOuDEZn885YyAySxdrEYeYEHrjekPsZkEaMzG4fBb2z6uEu7HdniGMdeky3ew1lfFLBadG1jn7TinrjNoF9Kjdp7IR+wKWe1dNnAMYak3DFVzVvfWbvxSFfaXGYIdqfY43qYlkHEn7BcJ+lfsE6NruUS5a9dqdMiWzypxclfo3tE6U2pzv2ibodP/VzWMGal5CSNj8sQq0iY3HVBTVQEw8WrMMXPu+yavIcwXiQoINrn5IJbP1QJg58jlTzI5VhfteoQnEm+Z8UoDRZ9SfqXInm2n2zGw76Q==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR13MB4922.namprd13.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(366007)(376005)(1800799015)(38070700009); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: mRhaPjhwjYCLhPmmdrnzR2TqwNK3we956LygONunYD/eUcmQ4t4mx+4zY1yMn0EY3K8u2NOG6X6/7eGM5atLd79CxMgsgdX+OXzCHWWD6H3HLom390YKuQureJBJ5kjm+rY8PnkRa/OhUw577clsdzrK6/yPnexGG5szy3dKJftjF3GIcSjbmoQ0IM9LqB6VA3Ww7qDZYs+uxwz5sTHf6zgQk+3h71Ge5hv0b9di4EQ66SyvHPOymqvioOpQOpHdL6OaMU98dmT0h43DWOxLw3jJn1OOxJ2jDRqLwrSBvYi8ReyKd5Z+3DRjfGkXjZdh6KU9hELYnO6xGp6R34I1jS21hKBpvCI2V1Pq8yd0Yq3T2B2LhqldsvQ8ZNoL4taxb7Yb5sRPcxqgP9XbBrZVvGDQ0dNOzQTa/KoEJuJ1nVj9VUcu54Dm9za+B02Le4RDINvLT4mvhYwWBhV0eQWI5lCIE0zKxqXLv0gBb1Bseb6JFbaADE54rx84gGl7gy6R12GsC9VYVx/oWCX/2JNvhl5cgox7lBjr7lnt5z2RwBj+UJITt1dVBhAxM2h0X/R8F8PtUqM8mrms1NJfoSms/gg3+sdNZhpblP8bEHanaTqt8VnS6Xa6++F/RrTMYPhu+5Dt1XMzIQtBfizGiAt1qKV4Cjdwrx1wGFo2L7v7nGKcK9pPanUjMtA3E+6FcArNhg1XwUgFLNcEBxynL77zTOPBh8Jdi1MSkC7+6KKir6FOmFGOdB3XqB+kgE8HvN0ywc2gZL3/MrEhlGVyx+hoVEKuSc5kuh0HRzvTUJSKfhejc/kFNvyFZZQd0tAzCQMoGmgmkJob1QS073OkGdTlcyCHS8GLXhp84IfhBR4kPtOHhAwwyQZFM/juk6IMyUZO7CuwksvSfJd6HkqjkXLpoSH7iQxYUtGPZNhOkHrbGQT9Mj8YdlcvTC5NzKQsFTfrubtl9RvFEZeC34I/AaYeqRJ6fG9p8x6D8TrJEPeblCLdksB8qNpuuMZ5BbcwXoiuJD9Rr6QxYNILlaM0bOY4zMnwIbZ1qBzl05D0M/0SglEmJ+Q9n9DxU5ID073VDfFiUbHrEKjADw7mkTcHDjaA/+9AHDYgj93BrB5Ao+8GeK8tbBZY41jRxDhM5b7izAcvwq6C6177KWluBFHE8uYhvDw/+nVJm53BXIQ5KgXCw526aXisdoA2QTeXAWdvYpKtItUmvQgMaryilrhatoOAhNN/W8vSW1fJ/lzJRw/8L6aw5vK6WGOdIIXEBHUDNrGRtRKdH7pCJ2ycfcNoMXJqG4S6N3IUHsfUN3OY5erC/jso+b6uyWTaqLhi/fzggomnQ9aJofNCqLN+4xtlfKG/rT0AsPzWzBGBAZ33S3yQLkkcV5hdmyIO/XNJSphnK0+qyIP7RGseZmUYDF0I+XqE82N358K9b6K2X7DEVi5r+5TNNu8VDVCLYLc+w5JX1qH+8FkIccAKHY+YpkLBr+LAkEf6zvVbP119Zymldu+zp1sX/0GGIaqHRtUnY0eoMh9g2/EZauKWMhET1Tk5ScBqSyckH2gZVDoKewKeE7YQ4npIRxW3EVAWGxQWjRe/HJk8
Content-Type: multipart/alternative; boundary="_000_PH0PR13MB4922BB9844C5D95E5001B14A85052PH0PR13MB4922namp_"
MIME-Version: 1.0
X-OriginatorOrg: Futurewei.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR13MB4922.namprd13.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7e0de220-cd38-44fe-c25e-08dc5a73eabc
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Apr 2024 22:08:28.5626 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0fee8ff2-a3b2-4018-9c75-3a1d5591fedc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: gbsECJj77qOW38N8P2jhuFP2/FytiQ0JkRxY2EiTgJ/xvGzOZqzy5ADt/5M//IN3KU8Sbi+i4N/4tlMhngh2og==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR13MB5300
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtgwg/Cl-xC67tzrgzR62RxbNta0F9vuw>
X-BeenThere: rtgwg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Routing Area Working Group <rtgwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtgwg>, <mailto:rtgwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtgwg/>
List-Post: <mailto:rtgwg@ietf.org>
List-Help: <mailto:rtgwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtgwg>, <mailto:rtgwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Apr 2024 22:08:37 -0000

Deb,

Thank you. The -38 has been uploaded.
https://datatracker.ietf.org/doc/draft-ietf-rtgwg-net2cloud-problem-statement/

Linda

From: Deb Cooley <debcooley1@gmail.com>
Sent: Thursday, April 11, 2024 5:53 AM
To: Linda Dunbar <linda.dunbar@futurewei.com>
Cc: secdir@ietf.org; draft-ietf-rtgwg-net2cloud-problem-statement.all@ietf.org; rtgwg@ietf.org
Subject: Re: Secdir last call review of draft-ietf-rtgwg-net2cloud-problem-statement-36

perfect,  I'll take a look at -38 when it gets published.

Deb

On Wed, Apr 10, 2024 at 10:58 AM Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>> wrote:
Deb,

Thank you very much for the additional comments and the suggested wording.
They are reflected in the revision -38.

Linda

-----Original Message-----
From: Deb Cooley <debcooley1@gmail.com<mailto:debcooley1@gmail.com>>
Sent: Monday, March 18, 2024 8:24 AM
To: Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>>
Cc: secdir@ietf.org<mailto:secdir@ietf.org>; draft-ietf-rtgwg-net2cloud-problem-statement.all@ietf.org<mailto:draft-ietf-rtgwg-net2cloud-problem-statement.all@ietf.org>; rtgwg@ietf.org<mailto:rtgwg@ietf.org>
Subject: Re: Secdir last call review of draft-ietf-rtgwg-net2cloud-problem-statement-36

Here is my review update for
draft-ietf-rtgwg-net2cloud-problem-statement-37:

I will update my review in the datatracker.

original comments (in black), updates (in blue)

1.  Section 5.1, paragraph 2:  Certainly the principles and assumptions of RFC 4535* would apply to any group key management situation (note the word change from 'group encryption' to 'group key management').  The specific protocol addressed by that RFC isn't being used here (even though they mention ISAKMP). How about something like this:

"The group key management protocol documented in [RFC4535] outlines the relevant security risks for any group key management system in Section 3 (Security Considerations).  While this particular protocol isn't being suggested, the drawbacks and risks of group key management are still relevant."

done.
[Linda] Thank you for the suggestion. They are changed in -38.

2.  Section 5.1, paragraph 3:  The draft referenced here is expired and the security of the methods would have to be reviewed.  (that is listed in Section 7)

The expired draft has been replaced with another draft.  The security of the methods would have to be reviewed.  Please list that in Section 7.
[Linda] The referenced draft has been uploaded.

3.  Section 5.2:  The draft referenced in this section is (currently) an individual draft, and again the security of the methods would have to be reviewed. (I see that WG adoption has been requested, and the draft is listed in Section 7).

This is just a note to the WG - no action required as long as the WG agrees.
[Linda] the WG chair said they will start the WG adoption soon.