[secdir] YANG Reviews

Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com> Mon, 08 January 2018 21:44 UTC

Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3420C1243F6 for <secdir@ietfa.amsl.com>; Mon, 8 Jan 2018 13:44:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aeQ2qE2uQ9CN for <secdir@ietfa.amsl.com>; Mon, 8 Jan 2018 13:44:40 -0800 (PST)
Received: from mail-pg0-x22a.google.com (mail-pg0-x22a.google.com [IPv6:2607:f8b0:400e:c05::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 36373120726 for <secdir@ietf.org>; Mon, 8 Jan 2018 13:44:40 -0800 (PST)
Received: by mail-pg0-x22a.google.com with SMTP id r2so6460505pgq.13 for <secdir@ietf.org>; Mon, 08 Jan 2018 13:44:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=0F8zg7nkJm8y0NrzHoY7hXGD0rws1k3iQ8F+kD/9QxE=; b=TvCizWqJAz/n5SBMjZTYaoUEJlzTU3MlUoPFdYpNWX7dvElKgrvlQbTql14QwNN+Sa MrX7DoF9+vvPasRWnFiYSQ7+kgt4tk1Nhe619u7SF3V7e5zNlKllrCduSz+RGvpE3aet jJLEvIOhX/KObrx5OsXcQr8SW42I5RNYg1/kWCDwlJ6pCwC8Rs3E/VmknA8PXb12Kcve Alb0oOyZB2c3IzhePR7qRs+w37z78tI9NQOu7tScYdgThJMIWS7sWrkk6Yy4z7m3D14d 65lmRAB88m21QgxAXpicO/0KsvRQfRy5koCt4i6cY8IqAsbe+6jdMzrnd8EzUqnvBOr0 tFKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=0F8zg7nkJm8y0NrzHoY7hXGD0rws1k3iQ8F+kD/9QxE=; b=lMOiW91ScTnoX1ctKQSsVuyKh2uWlFTgpQ3aQYeN26sMQXlInZPrYjaGchtuOOrElv wZ+wHJjy7KFUX31vGxofifsbfvzLSb/cwo39J4OHw40ZM5m65/pOOTcztFtRFH46Bw43 YL65rB9MNcoyq3JB2AduEZipwI4nZjbVQN8vgwOjwYlBkGmhwUrgLicHJE7kjcxysBTa FVWIfW/47Rvcg3GW6fjhNtIsapwmeWO0sDCNVCBBIX+xxlDTuhaNck3ndOkBEdBsuEro IqoxeHplOXLlF9uVZ4wJOz4rU3PNiblvZuoUooobhaAq/nzXnCfxlvBPNaf0d+zis7i7 BYRw==
X-Gm-Message-State: AKGB3mIGDC6kzX5eBnakAEQEXVeXYL8gG5JyRbo2EZakSQ2MJxc1WbjR 1VTuN0Yd+iYXl7axNxVBAwha0WJdA0Gj6y/Nc0UPug==
X-Google-Smtp-Source: ACJfBotvIIDRuInzzHhtsBss804oBIIy6PWlp23sEyLvQk+k+mJ9KTqlltLInJH4xRDLYoL++nCyFMsiwclwQGoDMC8=
X-Received: by 10.98.138.3 with SMTP id y3mr11855279pfd.132.1515447879756; Mon, 08 Jan 2018 13:44:39 -0800 (PST)
MIME-Version: 1.0
Received: by 10.100.186.208 with HTTP; Mon, 8 Jan 2018 13:43:59 -0800 (PST)
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Date: Mon, 08 Jan 2018 16:43:59 -0500
Message-ID: <CAHbuEH5hfwe0OVT74vNPgxF_HEPG2iCmQbr-bx7XB1vVSeekHw@mail.gmail.com>
To: secdir@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/TT8Z8TiAECSzfiFXHkz0GNUlS5U>
Subject: [secdir] YANG Reviews
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Jan 2018 21:44:42 -0000

Hello,

We will be seeing many YANG module reviews come through, please don't
let page counts scare you on these.  One of the main things to look
for is that they used the Security Considerations template and filled
it out, catching any data nodes that need to be enumerated in the
considerations.

Templates like this tend to get updated every time there's a new
SecAD, :-) . As such, it'll likely be updated again in a few months.
Here's the draft with the current template.  Have a look so you know
key things to look for (transport security is called out and
subtrees/data nodes of concern should be listed out).  Sometimes more
is needed specific to the draft, but often times, this covers it.

https://tools.ietf.org/html/draft-ietf-netmod-rfc6087bis-10#page-52

Thanks again for all your reviews, it is a tremendous help to us!

-- 

Best regards,
Kathleen