Re: [secdir] Secdir last call review of draft-ietf-ecrit-location-profile-registry-policy-01

Linda Dunbar <linda.dunbar@futurewei.com> Tue, 16 March 2021 17:12 UTC

Return-Path: <linda.dunbar@futurewei.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C218C3A1486; Tue, 16 Mar 2021 10:12:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.089
X-Spam-Level:
X-Spam-Status: No, score=-2.089 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=futurewei.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d9-uAjKA6XCU; Tue, 16 Mar 2021 10:12:57 -0700 (PDT)
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10on2093.outbound.protection.outlook.com [40.107.92.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A9A723A1485; Tue, 16 Mar 2021 10:12:56 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=CRpCOv9CHSzVQw1i4+5j1/C96JAmedtvecRoxLq+0BOV3niqepetJvqUxAKYE6Dk7PJKhuGNlo2OzwyUP7KAiq1sgrflfMpHHQR+fTARxWbNfdXf5XqcIfxULMKgd34fJPiIheQpKHv3F45MC2QAplr7zISFY1Yiics5rDPeUq2lyLNT7HNSDdo6CB8QegPWuKcDjawHDVYz+l1VA2zHBijL/hDMkq5GhSuRDIrRuV4sIZrUaMfBzi7rSUs4maSgYItPOg/NHL+jP+5TZ9n8MwSojSizpBEjeu3fQXlklfRrcMZzR8lRinHFEDiaDhcrxI+fuEFjYJJVj/f0deRwWg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1respnJ+oo6qBo94fNKNE1AbNb4bHHnwF+nEXVKv2yc=; b=MAK/NNNU9rO1bru4FbzZIEq8fUnQj3ZvcjLg/k4ZJqTJfPeDAaxK4Pb2RetERcuZlvcKT9537gc2KklYXucD+uYX6TSrxYs2j0ybLG8A2Vn/wkplMrJP3/30SA+Xpwnaz1INfi9DBImjIUdf/oov2cz1KvpUL7t0UeMDYq6D6c5S86JHCtJWdRd4Ly2F3BcrLgVSQqNfc5+2qdqf8noH+CKse5y+C8rCoB9BD7JWKKt5dTp1hCcfBHkVejnBaYrzhyvcHzL4W3k167V6uqfUCB2dzhIb/RFwrN6mKUUX42DFTTPOpgvgaInMhwUJ7hDVsBVehLA6pIW6GIvG2zScUQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=futurewei.com; dmarc=pass action=none header.from=futurewei.com; dkim=pass header.d=futurewei.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Futurewei.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1respnJ+oo6qBo94fNKNE1AbNb4bHHnwF+nEXVKv2yc=; b=CO6Z4R5hfOgLmHNk3ZsfbixbX0hKJLaP4Fr1zmSqc4uXBFDpJONjvcvAEfKPV6ahIMH/fOztgeogna6DrtbzCGTlihqYzktL9dhDU+sDnNoQiZRDqnQTrneF+2WoAZz+WDAjb5sncwXm8tVlInuEy4j/1/B1uf3cyIPGVxloT+c=
Received: from SN6PR13MB2334.namprd13.prod.outlook.com (2603:10b6:805:55::16) by SN6PR13MB4287.namprd13.prod.outlook.com (2603:10b6:805:ea::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3955.11; Tue, 16 Mar 2021 17:12:53 +0000
Received: from SN6PR13MB2334.namprd13.prod.outlook.com ([fe80::3050:546b:c47:a42a]) by SN6PR13MB2334.namprd13.prod.outlook.com ([fe80::3050:546b:c47:a42a%6]) with mapi id 15.20.3955.013; Tue, 16 Mar 2021 17:12:53 +0000
From: Linda Dunbar <linda.dunbar@futurewei.com>
To: "Murray S. Kucherawy" <superuser@gmail.com>
CC: "secdir@ietf.org" <secdir@ietf.org>, "draft-ietf-ecrit-location-profile-registry-policy.all@ietf.org" <draft-ietf-ecrit-location-profile-registry-policy.all@ietf.org>, "ecrit@ietf.org" <ecrit@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>
Thread-Topic: Secdir last call review of draft-ietf-ecrit-location-profile-registry-policy-01
Thread-Index: AQHXGoPdDsBYgrP5+UeHrEXFqCO1yqqG2bew
Date: Tue, 16 Mar 2021 17:12:52 +0000
Message-ID: <SN6PR13MB2334DCB45EB76B47C19AFDEE856B9@SN6PR13MB2334.namprd13.prod.outlook.com>
References: <161591246412.5771.17798271339560020312@ietfa.amsl.com> <CAL0qLwbAmYbX9A3f+okpum0Gz6hKhZz-_CPxhsu-nahFvVO7Bg@mail.gmail.com>
In-Reply-To: <CAL0qLwbAmYbX9A3f+okpum0Gz6hKhZz-_CPxhsu-nahFvVO7Bg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=futurewei.com;
x-originating-ip: [72.180.73.64]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: f592f03e-b4b0-4b34-ce58-08d8e89ebc0f
x-ms-traffictypediagnostic: SN6PR13MB4287:
x-microsoft-antispam-prvs: <SN6PR13MB4287C5CD773EC01CFAD7897A856B9@SN6PR13MB4287.namprd13.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:5797;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: fnjt1G13/+xAkJRbHhe8Tnzji+zjMFWZaLqcWQqwIHaeibzE16J6To4O/bPNMycy+e0//yPUKiH6lgdKK2s/Bz6iSeCUq4+Et8hTJdJZjVuXzRNoYEr6s/6HqbBFUmk5j2qc5hmO0/8faUqTb43weu5bGupWwpoUJt4CH8ez7I1fVMUbbhKoAw8wUhwH+v84dtqCKo/nRb9oHn84hjxb1inc8DdEPtYerYnKKYZVzhUEuhjRbyMlER3ZyGodErAuUr9PrANO3ADgovhfgN3eGoQOOEzmiMf05OT01t5z3DrAStnBjcnl178vglay/IyD2dg0YcarfwP0KFwDafm/eoNcJg2G5C3sLS0WpCuGqN8DBmYreAiqSQuLaMLij0KPG7AEz9wLU9p1MDiIiiOQiK9YghECV4hkLUPK+sJRax+P94KnSBLtVBm5BqgjIlkczYGe0NJ8N89Ty2sALkhWZlLKKGEm291dKsjHCDYEAlQFEehTrply2PhJkqhEzwTWFg1Bn5+Vyjd6CmjYmTrZAncWR1DW8UlO4UD3/hMUND6ux8H4mpmuWajC5E3xNm6/
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SN6PR13MB2334.namprd13.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(346002)(396003)(376002)(366004)(39840400004)(136003)(52536014)(33656002)(55016002)(64756008)(76116006)(6506007)(26005)(86362001)(8676002)(4326008)(71200400001)(44832011)(6916009)(83380400001)(316002)(9686003)(186003)(66946007)(8936002)(66556008)(66446008)(5660300002)(478600001)(7696005)(54906003)(66476007)(2906002)(53546011); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: Kkh8xAJbWdBJx6Rk7cdOzcINUxlWVZqXJCupl1NZZdvVPRvAz2vySPW/FjcxdJtq7UyPmi+070dfGiydIuObDKxmMNXbhIDEPKldgMAirNGM11GE2rXqdPFfLRI61WtFElkYJRP6Y9nsBCpUySZTwThoLmvmBq8zTNYCsAh22afgGgv08yQqggMlW7xTISfyAfQFvkl6Wcd1CtKBAZvwRpF6h3+DBq4Qr+2SglfSq9j2uSdioiKyqD7UnBqoVrLSme7fmu5eDmmjyk+q7v4B4yuOLPvqyEf+fPEnqG4ZDY8O6l+Vit0LhrHTO1DH+y5U10vidhocrb/dSPQ4eQG2ce17cxZdl5DQkv4nHIWQjtO/TuNpcp5uq0mhNmaJL8C9ibgz3/e+tBEPtQQGzxzfUfWEvRvSG8w7z+7ZY2VFobCC4mYIT5n5AlyAen2LLilF310RL5naVYAQbK33/UYlcidEBTzqXz+HWQrxH/yE5L1KZSrf0AFFefnU4pgoKHNWnd9H+lOlH3JSwI8L89csxL2smwew/Lwjaw6x+I40CAFWSMRlA1u8G4rwvpCYF/UAHqpcIgNfBmNZTEyo92qjN3OI2DUggYl4Bm+V2Auc2GPensApkrqF8+4TgCWQFBjDioXJy+CRE0fOJzwx6zqf25UjD3ySzrB3+HSPF3SeVD3vj1iLO2b10tDw+iINsTV6p1U7pz2c8KUAF2MOK+HrqYsXEJoSQqj03oARbuspPtoMMVvzUt1y0WcofL/Dotq/hsZOayjSyW8N9ZCgd1pBYfjCpG5pSys0qEsZPLPG4GcHfvuVZdLSsoTrfpWwzoUG7UK9qJAqczUG/mOOELiAozzttg3ZSlyO27h+dEWY8oUjALSYJzu3Ia+ej48wpFxGScHzys1vtNDabLNEMfL2I38xiNeEfIVVc4+gtrtuUa1Vl3xCm4Z8lj910AnOHVsu5YDLm2llDUlmB3Eo80syePjlUwrlVelcQJoaXN4fZc6g4sUwOOciuHVeV7vYbjqMj4Y45fsdlY/1nsZ9NxqNt/BZY/IFxhivJbuFsFK6Hdnks98byvi1PKi0ZPI0zHqYDW9hTPpduo+7tgYXyNgoxZzArnlb4QdzQdHc0y996vj2KMk2T/p+E00u2ic6zUmLEMNQKQyKZBO/0lGo7zEUdZ/PL9LQ6+00pSVYu0xU/1MLOcUiswbbqmo92lCnEeAzAQhPBLaqcSKIvMB5aI7fK+q+1hUCXGnIRqU1mbTRui/S1NteBg509H7SOG77Jg2nl6w+MeKG8JVuVp5bNRXhr4gSnGiaZIVMQEjuC1CQ41U=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_SN6PR13MB2334DCB45EB76B47C19AFDEE856B9SN6PR13MB2334namp_"
MIME-Version: 1.0
X-OriginatorOrg: Futurewei.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN6PR13MB2334.namprd13.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f592f03e-b4b0-4b34-ce58-08d8e89ebc0f
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Mar 2021 17:12:52.9305 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0fee8ff2-a3b2-4018-9c75-3a1d5591fedc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: LhickHhNIEiEQfVQYBt+ZcveisKYyyj2/2y9m+MgJmK6A9rau0r5KgoJ1H4Zq1rSmgJOhT7ZmpN5gp3U4pPcOA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR13MB4287
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/ZdELwnE4J5EK2HfEsI-egj_kXhU>
Subject: Re: [secdir] Secdir last call review of draft-ietf-ecrit-location-profile-registry-policy-01
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Mar 2021 17:12:59 -0000

Murray,

Then why need this document?
Isn’t it already the practice that “The IESG will be tasked with appointing a designated expert (DE) to review registration requests against the published specification”?

Linda

From: Murray S. Kucherawy <superuser@gmail.com>
Sent: Tuesday, March 16, 2021 11:46 AM
To: Linda Dunbar <linda.dunbar@futurewei.com>
Cc: secdir@ietf.org; draft-ietf-ecrit-location-profile-registry-policy.all@ietf.org; ecrit@ietf.org; last-call@ietf.org
Subject: Re: Secdir last call review of draft-ietf-ecrit-location-profile-registry-policy-01

Hi Linda, thanks for your review.  Comments below.

On Tue, Mar 16, 2021 at 9:34 AM Linda Dunbar via Datatracker <noreply@ietf.org<mailto:noreply@ietf.org>> wrote:
This document doesn't seem to be complete. The document claims that it changes
the policy of the Location-to-Service Translation (LoST) Location Profile
registry from Standards Action to Specification Required, but it doesn't
specify what is the new procedure.  It says allowing other SDOs to change or
add values. But which SDOs are allowed? Are there any procedures to identify
which SDOs are legitimate? can any organizations, say XYZ, change, add or
delete the values?

Specification Required is defined in RFC 8162.  The IESG will be tasked with appointing a designated expert (DE) to review registration requests against the published specification.  The DE will have discretion to determine whether an application should be accepted.  The document contains no guidance about particular SDOs, so the DE is left to decide whether to factor the source into the approval or rejection of the request.

So any SDO can make a request to update the registry.  The DE makes the call about "legitimate".

-MSK