[secdir] Secdir review of draft-ietf-ccamp-microwave-framework-05

Radia Perlman <radiaperlman@gmail.com> Mon, 07 May 2018 06:54 UTC

Return-Path: <radiaperlman@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1FECD1270B4; Sun, 6 May 2018 23:54:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level:
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z7TIf-p9OtMU; Sun, 6 May 2018 23:54:39 -0700 (PDT)
Received: from mail-io0-x22b.google.com (mail-io0-x22b.google.com [IPv6:2607:f8b0:4001:c06::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28871126D0C; Sun, 6 May 2018 23:54:39 -0700 (PDT)
Received: by mail-io0-x22b.google.com with SMTP id p124-v6so32424893iod.1; Sun, 06 May 2018 23:54:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=1f/76lrkPpKVR9zok7lFoIuD0hETb4j55Mzg+gQOmyU=; b=KNjSQKD1dXmj6Fxz+Gc48QJSBnNzq7F4PWEEHZqK338SaPd31BsUDvGTk+Kk2XrAJB CR0kwOQnO9913QDhrcLrJS7oEcVmDZlDJ8hopAoXQFJ5moDX7H4cR5UV4KkF+63C53sn UTaph31U60nND0H8BbR/+6+tn6e0Q4znE9I7HWTRxGVxfP7syg0oP7kbmYDuzR/wJNWG BCwtekfoefayspMSUBMKYXuDMocfHx1TjoJzq3B6QH72vtJDH+49w7YB+Z2CbWxiz3qg Gy4vjx73AszpXOvlQ2fKP81otxmNPe7uBePOdIf+K78H6FHY0aYbZ/VcK212M02vaGs4 9N4w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=1f/76lrkPpKVR9zok7lFoIuD0hETb4j55Mzg+gQOmyU=; b=eNh1xgOwKV9q6MWMyhyZ8cMFEsO/mRa9Nu0Z0YD1nPqN2srV7Mt6KagkvXr+QrF1AL CKVzZPWRGuGz7hFXyiXnkWlmguneJPTO0zPk9iQoimj4TfkC4U5vWLgtiyC0iikf/slT 0I+O/ZCm4gqJZD2OyIvr3U8dW0NyqdhKtxKEWBCOEwkYJdP89yzFpIgR4/Q7zMrgyV9z m+Hobacr6ClLwgSFegFDhuHnBEaFvArkjnONLP1vfNOqkz2OOr1VqwXMISVlFlOl2XTP NhMiZoGWRzFKaiQrd3VltW9aeJbHWhflm0hf+3Wxsu9snUXhUVjhvJHchkgvxOzD43Ke OuEw==
X-Gm-Message-State: ALQs6tD3fYjgFovqkgeNavdtMzOAHtKEhR4tZUbv8aMwDyjUUqSG3ljz SHhQnbhKkkF6Rhc3Hhp4BK30rVsrgw5OP/tJSWY=
X-Google-Smtp-Source: AB8JxZq4ZJ7duSdQvpy+g9/kmpZsNlB89KxkgZ2jIuMO4RM+cBq+7SWsByKa1P9uukE65iFH5qMpswaQybcp70N4xmk=
X-Received: by 2002:a6b:6113:: with SMTP id v19-v6mr37870114iob.11.1525676078524; Sun, 06 May 2018 23:54:38 -0700 (PDT)
MIME-Version: 1.0
Received: by 2002:a02:2a02:0:0:0:0:0 with HTTP; Sun, 6 May 2018 23:54:38 -0700 (PDT)
From: Radia Perlman <radiaperlman@gmail.com>
Date: Sun, 06 May 2018 23:54:38 -0700
Message-ID: <CAFOuuo7PmeTWMYnetwi_8d-11UZmkPXx7WSje-coH_=ROfr9bA@mail.gmail.com>
To: draft-ietf-ccamp-microwave-framework.all@tools.ietf.org, The IESG <iesg@ietf.org>, secdir@ietf.org
Content-Type: multipart/alternative; boundary="000000000000b3ecc6056b98242e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/RB44zAfBoW1_Cxwl8tWI2Na4cFw>
Subject: [secdir] Secdir review of draft-ietf-ccamp-microwave-framework-05
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 May 2018 06:54:41 -0000

Sorry...resending because I mistyped the author address.


---------- Forwarded message ----------
From: Radia Perlman <radiaperlman@gmail.com>
Date: Sun, May 6, 2018 at 11:48 PM
Subject: Secdir review of draft-ietf-ccamp-microwave-framework-05
To: draft-ietf-ccamp-microwave-framework-05.all@tools.ietf.org, The IESG <
iesg@ietf.org>, secdir@ietf.org


Summary:  No security issues found, but I do have questions, and there are
editing glitches

I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG.  These
comments were written primarily for the benefit of the security area
directors.  Document editors and WG chairs should treat these comments just
like any other last call comments.

This document describes the management interface for microwave radio links.
It advocates (correctly, I believe) that such an interface should be
extensible to provide for vendor-specific features.

I don't understand the difference between a "a traditional network
management system" and SDN.  Perhaps it is not the job of this document to
clearly make the distinction, and I suspect there is no real
distinction...setting parameters (traditional network management) is a way
of "programming" an interface ("SDN").

This document could use an editing pass for glitches, but these glitches do
not impact its readability.

The glitches consist  mostly of leaving out little words like "of" in the
following sentence.
"The adoption of an SDN framework for management and
   control the microwave interface is one of the key applications for
   this work."

The security considerations say that they assume a secure transport layer
(authenticated, probably encryption isn't necessary) for communication.
Other than that, perhaps, there might be security considerations for
inadvertently setting parameters incorrectly, or maliciously by a trusted
administrator.  But this document does not specify the specific parameters
to be managed, just a general framework.

Radia