Re: [secdir] Secdir last call review of draft-ietf-opsawg-l3sm-l3nm-10

Oscar González de Dios <oscar.gonzalezdedios@telefonica.com> Fri, 03 September 2021 08:51 UTC

Return-Path: <oscar.gonzalezdedios@telefonica.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 394C03A13CF; Fri, 3 Sep 2021 01:51:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.553
X-Spam-Level:
X-Spam-Status: No, score=-2.553 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=telefonica.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KOpPJi7MF8HJ; Fri, 3 Sep 2021 01:51:48 -0700 (PDT)
Received: from FRA01-MR2-obe.outbound.protection.outlook.com (mail-eopbgr90127.outbound.protection.outlook.com [40.107.9.127]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 890993A13CC; Fri, 3 Sep 2021 01:51:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=a6ezis5eMHulShyLaXTCJbOPKON3YhaaqZ+4HzIYzsEa5V+ad2ZoLcvYtjisMGFUg/n+5tPQ5LBVAe3eeiMMcd2OiaB85A8Iby+WkD+aCVSrzByeedBevYq/ga8i/xWZbyQAXPoZkyvNuTvc5wwz8g4/kElJXCf5BP/LHZ+hW+ZJj0fi/9P51uNa61VoVRk0VZjh3te815t3TXZ/5vESlSSPTuM9gawNuqFkTrha0VoBB444F5kszg8MAjFOjaKCZTrinybJ4F5jbPqz8CXC9K6G+cARjgzmClA7/ZN4LHkMSt57i4lxbWDSKPMcPEPicXGqspTecAQAD8gD1Bbffw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=zNstzk4e+WhPrBYTnoLDFefByUa34orrWLOoAvzYR6w=; b=ClkE2t0ntCCi6ij/4XYTAoD9wKXmEvJxUxa4zktnEQPzEsuQQU7i+fb1YasxsQ9TApI4wNdiddoIDMg6JK43V03a+yW7o2JGlkKUudWpAfXl8GHBUSMfaK2gH5K310hjnMS5K7JT2O/K6RyYgl1NFJ3q3Xvn8Far6FS3/+HMNj2ouHs9Nz3LAQM/QZRM0kjXo+H31iIFGwA6pJFqmIXKVjqEX3/8g+vIA5L3PV4498NmHXT5s2Lh14ezDJ1j0t4EZSkYHiMbShO29s5gd2aCQ0plcQ61dLtjbfnMOUFGYzjC7ieI1r4V9RTpv0wUICtCdhuzt2PAAHh2vgCsm+vazg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=telefonica.com; dmarc=pass action=none header.from=telefonica.com; dkim=pass header.d=telefonica.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telefonica.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=zNstzk4e+WhPrBYTnoLDFefByUa34orrWLOoAvzYR6w=; b=lsWQiZTWrjlFV90QXZa3d89LScdbiWC8TOZgCTt8IVYE/6UbcWZuSluxANXc6XRoOoQjmSZgHYJC/qX1/DcfjoIE6YSHxxakUvVoN8kGB5Qd6Cu6U/EJdr37P1MrNFA3asNRiuVdPrxEHVsD8dePN3fRi/xNSouUhLuWL2nQRQo=
Received: from PAXPR06MB7872.eurprd06.prod.outlook.com (2603:10a6:102:1a3::9) by PR1PR06MB5756.eurprd06.prod.outlook.com (2603:10a6:102:e::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4478.19; Fri, 3 Sep 2021 08:51:44 +0000
Received: from PAXPR06MB7872.eurprd06.prod.outlook.com ([fe80::dc1e:4a84:4569:af43]) by PAXPR06MB7872.eurprd06.prod.outlook.com ([fe80::dc1e:4a84:4569:af43%9]) with mapi id 15.20.4478.017; Fri, 3 Sep 2021 08:51:44 +0000
From: =?utf-8?B?T3NjYXIgR29uesOhbGV6IGRlIERpb3M=?= <oscar.gonzalezdedios@telefonica.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>, "secdir@ietf.org" <secdir@ietf.org>
CC: "draft-ietf-opsawg-l3sm-l3nm.all@ietf.org" <draft-ietf-opsawg-l3sm-l3nm.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-opsawg-l3sm-l3nm-10
Thread-Index: AQHXgZdUoDZuW1TYHk+hG7minU9JlauSNPWAgAABjyA=
Date: Fri, 3 Sep 2021 08:51:44 +0000
Message-ID: <PAXPR06MB7872AA6DD7EDEE4D2BDBDE12FDCF9@PAXPR06MB7872.eurprd06.prod.outlook.com>
References: <162724649271.1477.16367299362861096101@ietfa.amsl.com> <13601_1630657022_6131D9FE_13601_86_23_787AE7BB302AE849A7480A190F8B9330353E84CA@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
In-Reply-To: <13601_1630657022_6131D9FE_13601_86_23_787AE7BB302AE849A7480A190F8B9330353E84CA@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
Accept-Language: es-ES, en-US
Content-Language: es-ES
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: orange.com; dkim=none (message not signed) header.d=none;orange.com; dmarc=none action=none header.from=telefonica.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: abb0cc5d-ff37-42e5-3886-08d96eb80e4f
x-ms-traffictypediagnostic: PR1PR06MB5756:
x-microsoft-antispam-prvs: <PR1PR06MB57569BDF61971333AA4B52FAFDCF9@PR1PR06MB5756.eurprd06.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: FGwMfxnr+GvKVOyqm0tHhIZeCn742L0QaBO+iih1a/F+DsBA1m3HYxliN/Jg+p+0v3pc2jx2pI2fJjL6nK60Sx7TaEmQVo9oThs4BpCuPYVN2/VQDJw+Y8ZSs9KsRPA1IMiXFS+Bxh4EqMlYgg/B45oMMZCouF52W6ugX5xh6udwk4Sr8FdPoNLrMP5cUOFdqRFftvytziNx1nzB7Mj2cZ76/wj6oNv9IoMu+3antALl4PcNfejhWvkSHf2/mbCKQVlRJGITGP7uisj5t1oxp+jBVEoNrOPIUATUAgyOD2nVtHBGkjSfZI/s1+j7x9/jhvd0N3OijGUvFMhEg1VSk/s8AJ1NL8X7wy1EBl0o3fE9/5y5/M/LzzdHWKytPETQD8TXb7T5w/dyibNhwQA8VnGQme8HK3Oem30Rr9xbBEE6XmWNzE/gRlcqhMjB+7Tv2iQPkVVWP2jwkFiXJCgmtISD/rxgAwMiTNb/LrpCzrP+EK2QKyWqcVH3O3CSEYQTG9Ph2W1zu9saTYGjyGig4crwhaEkKYxTzfYnzg6ywKci8a79wHzxUKXpAJlW8AH1bzXnsF3qUW6kgd5BSi3gICex2yzwVqLP6gnd8dtKut4jXMicPs/WeoN5F8eV61ER3lY/+gioJ58vlGAuyPnoh5Wp5PX17wGiwXqYpgHZtLEjv/COwaRCTGi5w50eS3TMlZZbLMfno5eYe1ELKxLjTMsyc1NtKg6iyWDWdTK+wIlTAFzg/EWEihewcgOztmDm
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PAXPR06MB7872.eurprd06.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(52536014)(4326008)(66556008)(64756008)(508600001)(66476007)(26005)(54906003)(71200400001)(66446008)(5660300002)(110136005)(85202003)(122000001)(38100700002)(316002)(83380400001)(66574015)(66946007)(76116006)(7696005)(38070700005)(85182001)(86362001)(2906002)(6506007)(8936002)(8676002)(186003)(9686003)(33656002)(55016002)(9010500006); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?utf-8?B?MUdxejlUTng1ejRpMmh0aUYwR0FwYkdOcnlSV09mUTlrZWtzWDJ6VmQ5Q09a?= =?utf-8?B?ZWFPaGdUWEo3ZWdkLzlCVHd6UHQ2SGkxQVFQRWdKSCttM0dZSUhiUFkxS2Y4?= =?utf-8?B?VURPdVFEZ3FNOVloeU1XWVhoQVJBcUJaQlZkdEc5SmcyVm43U0hyUlhQV016?= =?utf-8?B?cVp5VDFRbUtJQk5aUUdxYTIxZTJQNnBBcWMrTDZ6WmVyUzNWV3pmRXg4bkVY?= =?utf-8?B?NXpZazgyaEJEY0tQM3JFYitDblNJbjdwTk9IWHdiM1V3TlBNeE1BbnB2dkdN?= =?utf-8?B?b1d0aVNIUVh4REZRejFRU3BEZHJiMlJyelJXR21vTnQySFRaUjhKZmlxT1lw?= =?utf-8?B?a3o4NFdSM2pXWHlUNGxibW82ZmhZSHFmVTJmNlI0UUJldW9Wc3NUOFFYWC9L?= =?utf-8?B?MncyalJjWk1SQ0V5L2ZiWk90RWpHNDhOcUxPeWZCVWl2NmNtcnVabXZqY2tS?= =?utf-8?B?amJGVDZ3cm9GN1F6MC85bW5tN1FYVkg4VTRnOWRQWEJSd0xieUthbmY0amQ1?= =?utf-8?B?N2FwZU92bjg5NkFYWVFGNmp2UUdhUTZNSGNDT1FpZFZERU1jZmVVcThBSHFK?= =?utf-8?B?U1RhL0piaDI5dDJpYUhleUpzQ04ydEpDYnVSZHNYWXlvWGdCUUMxWnNmOG9i?= =?utf-8?B?MmhNOE1IVktaa3JINWVSbVZVNEx6eDJqcHhML05TNjJ0RjFISGI1Ty9maU5W?= =?utf-8?B?aU1Pa3FGTy9sSzFWY2I4VDdSZ0QyV3JhS0hublcvZ0E3L3U0aDFRSVFPaWV3?= =?utf-8?B?NDkvc2QxeC9nNURQT3IzMlZRTDN6cWZsblliVnYyRE8yMDh2OXgzNTlQOHlP?= =?utf-8?B?YmcwVlgxTFk5azhTWW1MOVkrcTdoemtNQVNkSUpBYUFaSzVhd1dwcVhNVzVp?= =?utf-8?B?YVplVm9Ga1pqVzBER0lDdTRNYVhPU2x5cjZrNFhndFcrOFdpMkYxeUN4QUVL?= =?utf-8?B?UFVCYVBGajBENWtZOXpJdlorYjZGOEZreEM2ejF6UHh5T1h1WEVzc1RLZm5W?= =?utf-8?B?SThmeVN6c1N1V2FKZ2psMmcwUWJVbmFlY0xQSDN1bCtLTFBET0pZZVRSeUp1?= =?utf-8?B?Q2tpWTFHR1hIS1dmNDRsSXN4VE9UWFk5UTk0ZmtrNXFXbmZwN0RiZitBUGls?= =?utf-8?B?UHM3UXRPYlBMbHZXOUxIcUdRb0J2NVF6OVdOMmNDKzk4QVI1Z243VVBQTUFv?= =?utf-8?B?ZEpaenAvLzJkTVBUd0RWaGswdDNXWjQ5SjFiaTNKMnhFWHQxN2pTZzY2N21V?= =?utf-8?B?bllwT2h6TysyNVhueERUYVpuWWZydU0veGorb1NaZnRTSFIzdGh2MWgzVWNm?= =?utf-8?B?alFkNCs2cWVZZWh4ZjJubHJzS0VzM2FFSzhrUUNPOWJQdzFBN3kxSTlCYi9n?= =?utf-8?B?RVBlOVVDaUtiU3NmdkVXa2hvcXJ1Q1dUUVY4Rlh0aDJBSlNvUXBIQ3Evak5a?= =?utf-8?B?Tm9KSVcvNHh5ZXhubUdxcFpBMXhHMmFFOXR4MWVuZndRaVM0VFBtYjlHNmk3?= =?utf-8?B?RFRKMWhLaUFobzNZSFhnaFhhd3VTalYwNmZHcUwyS1RiRmNPMGNpT3JySjAy?= =?utf-8?B?MFhwSTRBZXhCeVFwVWJwLy96ZGRXU05KekxMRi94TUoreEEzWG9walIxSjU0?= =?utf-8?B?ZGRhSUp2RitkTFRqSEJ1N0dIYjljSDIzSzNHd3dkS2hKTitZMXp3MStieGFV?= =?utf-8?B?bkJZRmpiME9QTE9PK3VMUC9yTDI1NEFwU00vbjYzWUVkVjZtVXErOUF1N3hO?= =?utf-8?Q?UfoysLZyI4/jIB/0m2/U/ccHGQfqtTOTdoPKlcN?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: telefonica.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAXPR06MB7872.eurprd06.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: abb0cc5d-ff37-42e5-3886-08d96eb80e4f
X-MS-Exchange-CrossTenant-originalarrivaltime: 03 Sep 2021 08:51:44.0874 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: kPkBLxwFhoBBECeh7Vl3JVUUAHmIinVgWGRZieswYibV/71BA8sWKyAj/v+16oRCkqIeAa+yMttHJ8QVgvJvSsKI/ZRWlE6QBpOrcrKNRHpCGW+U+tZWBs3p5/oipdm2
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PR1PR06MB5756
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/ZIBsgN7qGX0WZ76CTt0w7SvnWmM>
Subject: Re: [secdir] Secdir last call review of draft-ietf-opsawg-l3sm-l3nm-10
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Sep 2021 08:51:55 -0000

Hi Rifaat, Med, further comments inline

-----Mensaje original-----
De: mohamed.boucadair@orange.com <mohamed.boucadair@orange.com>
Enviado el: viernes, 3 de septiembre de 2021 10:17
Para: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>om>; secdir@ietf.org
CC: draft-ietf-opsawg-l3sm-l3nm.all@ietf.org; last-call@ietf.org; opsawg@ietf.org
Asunto: RE: Secdir last call review of draft-ietf-opsawg-l3sm-l3nm-10

Hi Rifaat,

Thank you for the review.

Please see inline.

Cheers,
Med

> -----Message d'origine-----
> De : Rifaat Shekh-Yusef via Datatracker [mailto:noreply@ietf.org]
> Envoyé : dimanche 25 juillet 2021 22:55 À : secdir@ietf.org Cc :
> draft-ietf-opsawg-l3sm-l3nm.all@ietf.org; last-call@ietf.org;
> opsawg@ietf.org Objet : Secdir last call review of
> draft-ietf-opsawg-l3sm-l3nm-10
>
> Reviewer: Rifaat Shekh-Yusef
> Review result: Has Issues
>
> I have reviewed this document as part of the security directorate's
> ongoing effort to review all IETF documents being processed by the
> IESG.  These comments were written primarily for the benefit of the
> security area directors.  Document editors and WG chairs should treat
> these comments just like any other last call comments.
>
> This document defines an L3VPN Network YANG Model (L3NM) that can be
> used for the provisioning of Layer 3 Virtual Private Network (VPN)
> services within a service provider network.  The model provides a
> network-centric view of L3VPN services.
>
>
> Issues:
>
> 1. The following is a quote from Security Consideration section:
>     "Several data nodes defined in the L3NM rely upon [RFC8177] for
>      authentication purposes."
>
> I think it would be helpful to elaborate on which nodes need the
> mechanism defined in RFC8177 and why?
>

[Med] 8177 is used here to ease the mapping with underlying device modules, particularly routing protocols.

Updated the text to cite the nodes. NEW:

"Several data nodes ('bgp', 'ospf', 'isis', 'rip', and 'bfd') rely upon ..."

>
> 2. The summary bullets:
>
>    o  Malicious clients attempting to delete or modify VPN services.
>
> Why 'create' and 'read' are not part of the risks in this case?
>

[Med] because 'create' is covered in the next bullet:

   o  Unauthorized clients attempting to create/modify/delete a VPN
      service.

And 'read' in the third one:

   o  Unauthorized clients attempting to read VPN service related
      information.


[Oscar] Complementing, the main intention of the bullet was to highlight that, in this case, there can be a direct impact on a running service (and the impact can potentially be huge). Read is different, gets knowledge, but does not hit the service. Create also does not impact directly running services.

After re-reading the text to check your comment, I figured out that we don't actually need this list as it is redundant with the risks cited for both write and read nodes. The bullet list will be removed.

[Oscar] The original aim of the bullets was to briefly summarize and highlight the different intentions and impacts of the risks, one for malicious clients that can impact running services, so the customer of the service could be directly hit (huge problem), other someone creating a service and making use of the network without authorization  (but does not impact other services)  and unauthorized clients that don't impact directly the service, but just gain knowledge of it (the data can be used for malicious purposes, but at the moment of the attack, the service is not hit). Even though it is true it can be redundant for the risks already cited before for read and write nodes, I see no harm in explicitly adding the classification (network models are a powerful tool, use them wisely :-) ).

Your review will be ACKed in the next iteration of the document. Thank you.

Cheers,
Med

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição