Re: [secdir] Secdir review of draft-ietf-eman-requirements-10

Magnus Nyström <magnusn@gmail.com> Tue, 29 January 2013 18:26 UTC

Return-Path: <magnusn@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF84A21F8ADB; Tue, 29 Jan 2013 10:26:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.499
X-Spam-Level:
X-Spam-Status: No, score=-1.499 tagged_above=-999 required=5 tests=[AWL=1.799, BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u+-JOdXomm22; Tue, 29 Jan 2013 10:26:57 -0800 (PST)
Received: from mail-wi0-f173.google.com (mail-wi0-f173.google.com [209.85.212.173]) by ietfa.amsl.com (Postfix) with ESMTP id E7B0421F8ACA; Tue, 29 Jan 2013 10:26:56 -0800 (PST)
Received: by mail-wi0-f173.google.com with SMTP id hn17so2785962wib.6 for <multiple recipients>; Tue, 29 Jan 2013 10:26:56 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:x-received:in-reply-to:references:date:message-id :subject:from:to:cc:content-type; bh=8i5v1QCyozphBDVowHMS+53xRS6dQoseCUX8KBAYbO4=; b=fzJ74UWKPCtCjpkaNuvn539To3WOVwAeCa1O94UHfQy+NZj+GSxTOHNdPZEHkt14y+ Ihr0QRW+rzIjuIrsu6zZKiOPC60k/1flVPMAGaEAG53XaOinQkDSmsz0/wRaYWedYFY3 e/Cy2yRcb1mO41zAOV/qGq5YpzkAvcy3dHrmpharfyFIwXnuXUPaVwK7Fwkx/pGT77RC c8XovSD/JFa52yFX1daPdh0OtAQu1McgTAQStIp2/9x0SUN//0f99XOACTUiwMgWzB7A tZIxRxJ3FCm+RVwHQXvtIp7ykjkn0Du40hd21F6bMZu+K+9YHHHj1pGMUwO0xmJM65WL KAsw==
MIME-Version: 1.0
X-Received: by 10.180.109.10 with SMTP id ho10mr4421959wib.9.1359484016133; Tue, 29 Jan 2013 10:26:56 -0800 (PST)
Received: by 10.180.144.77 with HTTP; Tue, 29 Jan 2013 10:26:55 -0800 (PST)
In-Reply-To: <CD2DB835.6B138%quittek@neclab.eu>
References: <CADajj4Z6jQej-Q4jCHZ873wjX5M5-Z+sfCczXhn4aZgb8SkE=w@mail.gmail.com> <CD2DB835.6B138%quittek@neclab.eu>
Date: Tue, 29 Jan 2013 10:26:55 -0800
Message-ID: <CADajj4YSXrWmjLcsBgfqXhAyg9syyWc7NPnHvcgKDV2FFEcVLg@mail.gmail.com>
From: Magnus Nyström <magnusn@gmail.com>
To: Juergen Quittek <Quittek@neclab.eu>
Content-Type: multipart/alternative; boundary="e89a8f3bae49dc068f04d4718931"
Cc: "draft-ietf-eman-requirements@tools.ietf.org" <draft-ietf-eman-requirements@tools.ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] Secdir review of draft-ietf-eman-requirements-10
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 29 Jan 2013 18:26:58 -0000

Thanks; yes this addresses my concern. Thank you!
/M


On Tue, Jan 29, 2013 at 8:40 AM, Juergen Quittek <Quittek@neclab.eu> wrote:

> Hi Magnus,
>
> Many thanks for the review.
>
> As you suggested, I extended the paragraph in the Security
> Considerations section:
>
> OLD
>    Monitoring energy-related quantities of an entity addressed in
>    Sections 5 - 8 can be used to derive more information than just the
>    received and provided energy, so monitored data requires privacy
>    protection.  Monitored data may be used as input to control,
>    accounting, and other actions, so integrity of transmitted
>    information and authentication of the origin may be needed.
>
> NEW
>    Monitoring energy-related quantities of an entity addressed in
>    Sections 5 - 8 can be used to derive more information than just the
>    received and provided energy, so monitored data requires protection.
>    This protection includes authentication and authorization of entities
>    requesting access to monitored data as well as privacy protection
>    during transmission of monitored data.  Monitored data may be used as
>    input to control, accounting, and other actions, so integrity of
>    transmitted information and authentication of the origin may be
>    needed.
>
>
> Does this look OK for you?
>
> Thanks,
>     Juergen
>
>
> On 21.01.13 05:05, "Magnus Nyström" <magnusn@gmail.com> wrote:
>
> >I have reviewed this document as part of the security directorate's
> >ongoing effort to review all IETF documents being processed by the
> >IESG.  These comments were written primarily for the benefit of the
> >security area directors. Document editors and WG chairs should treat
> >these comments just like any other last call comments.
> >
> >This standards-track document describes requirements on standards for
> >managing power entities over networks.
> > As stated in the Security Considerations section, controlling power
> >state and power supply of networked energy entities are highly sensitive
> >actions and thus authorization, privacy etc. may be required. Similarly,
> >the date provided by those entities will often require integrity and
> >sometimes authenticity. The document may gain by also making clear the
> >potential need for the energy entities to identify, authenticate and
> >authorize the entities requesting access to power data. I would suggest
> >to add some text around this - because I assume some requirements on
> >standards will be present for that.
> >
> >
>
>


-- 
-- Magnus