Return-Path: <david.black@emc.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id EECF712D59E;
 Fri, 12 Aug 2016 08:51:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level: 
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01,
 RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key)
 header.d=emc.com header.b=hK/rIUIs;
 dkim=pass (1024-bit key)
 header.d=emc.com header.b=SoiHpT/j
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id N9vxbulmEgUJ; Fri, 12 Aug 2016 08:51:12 -0700 (PDT)
Received: from esa8.dell-outbound.iphmx.com (esa8.dell-outbound.iphmx.com
 [68.232.149.218])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 0849212D176;
 Fri, 12 Aug 2016 08:51:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
 d=emc.com; i=@emc.com; q=dns/txt; s=jan2013;
 t=1471017072; x=1502553072;
 h=from:to:cc:subject:date:message-id:references:
 in-reply-to:mime-version;
 bh=iMyte+q+PzcrRt7Z8OHwRONEpz9GzYEMqWzoo4b17tQ=;
 b=hK/rIUIsxiApq+wHvsWw9ebwWH/GLR8OWU2GY8DnbEElvUweecX/ms7l
 abyq7FdnlbTvWoHPqC+9FKuaaFA/vUP82wpm3wtSgsmrvwZQryUXJUyfO
 0cv9z064vAlX/GyK10gsJhCCkF6w/4Hn/U3krapKeU5Zp+B37/2dqVmTN M=;
Received: from mailuogwdur.emc.com ([128.221.224.79])
 by esa8.dell-outbound.iphmx.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384;
 12 Aug 2016 10:51:10 -0500
Received: from maildlpprd56.lss.emc.com (maildlpprd56.lss.emc.com
 [10.106.48.160])
 by mailuogwprd51.lss.emc.com (Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with
 ESMTP id u7CFp9Xm005278
 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO);
 Fri, 12 Aug 2016 11:51:09 -0400
X-DKIM: OpenDKIM Filter v2.4.3 mailuogwprd51.lss.emc.com u7CFp9Xm005278
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=emc.com; s=jan2013;
 t=1471017069; bh=XKsKJxSnC8K6ntIlRWX04KGjMNA=;
 h=From:To:CC:Subject:Date:Message-ID:References:In-Reply-To:
 Content-Type:MIME-Version;
 b=SoiHpT/j2WM8wQZy2MySiChY9rDS3Q/yzy6QWVI/umm27rtEhJTykQteaS4j64sik
 z61QyfNpkZD5oa8YROv4VA3cxJTERi3LtZpsdMNaSUKzjJd0vsmev92DYtIKym1Owa
 dt12AZ//ncn4er7VmQXteOxtoy5nj0nyRGQ8RZuY=
X-DKIM: OpenDKIM Filter v2.4.3 mailuogwprd51.lss.emc.com u7CFp9Xm005278
Received: from mailusrhubprd52.lss.emc.com (mailusrhubprd52.lss.emc.com
 [10.106.48.25]) by maildlpprd56.lss.emc.com (RSA Interceptor);
 Fri, 12 Aug 2016 11:50:47 -0400
Received: from MXHUB306.corp.emc.com (MXHUB306.corp.emc.com [10.146.3.32])
 by mailusrhubprd52.lss.emc.com (Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with
 ESMTP id u7CFp1TA021501
 (version=TLSv1.2 cipher=AES128-SHA256 bits=128 verify=FAIL);
 Fri, 12 Aug 2016 11:51:02 -0400
Received: from MX307CL04.corp.emc.com ([fe80::849f:5da2:11b:4385]) by
 MXHUB306.corp.emc.com ([10.146.3.32]) with mapi id 14.03.0266.001; Fri, 12
 Aug 2016 11:51:01 -0400
From: "Black, David" <david.black@emc.com>
To: Takeshi Takahashi <takeshi_takahashi@nict.go.jp>,
 "draft-ietf-nvo3-arch.all@ietf.org" <draft-ietf-nvo3-arch.all@ietf.org>
Thread-Topic: Secdir review of draft-ietf-nvo3-arch-06
Thread-Index: AdH0qsTgaG4vD7ROT6y/ONbw1H4BGgABFwhQ
Date: Fri, 12 Aug 2016 15:51:00 +0000
Message-ID: <CE03DB3D7B45C245BCA0D243277949362F63B90F@MX307CL04.corp.emc.com>
References: <225101d1f4ab$be76d9a0$3b648ce0$@nict.go.jp>
In-Reply-To: <225101d1f4ab$be76d9a0$3b648ce0$@nict.go.jp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.238.44.130]
Content-Type: multipart/alternative;
 boundary="_000_CE03DB3D7B45C245BCA0D243277949362F63B90FMX307CL04corpem_"
MIME-Version: 1.0
X-Sentrion-Hostname: mailusrhubprd52.lss.emc.com
X-RSA-Classifications: public
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/k2hoKv8rxDEaewxd8DdU_TUoON4>
Cc: "Black, David" <david.black@emc.com>, "nvo3@ietf.org" <nvo3@ietf.org>,
 "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
Subject: Re: [secdir] Secdir review of draft-ietf-nvo3-arch-06
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>,
 <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>,
 <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Aug 2016 15:51:14 -0000

--_000_CE03DB3D7B45C245BCA0D243277949362F63B90FMX307CL04corpem_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Take-san,

Thank you for the review.   I've made changes to address all of your commen=
ts in my working copy of this draft that will be posted as the -07 version =
next week.

The minor comment on information leakage affects both the data plane and co=
ntrol plane and hence I've made changes to address it in two paragraphs in =
the Security Considerations section.  Here are the revised versions of both=
 paragraphs:

For the data plane, tunneled application traffic may need protection agains=
t being misdelivered, modified, or having its content exposed to an inappro=
priate third party. In all cases, encryption between authenticated tunnel e=
ndpoints and enforcing policies that control which endpoints and VNs are pe=
rmitted to exchange traffic can be used to mitigate risks.

[...]

Leakage of sensitive information about users or other entities associated w=
ith VMs whose traffic is virtualized can also be covered by using encryptio=
n for the control plane protocols and enforcing policies that control which=
 NVO3 components are permitted to exchange control plane traffic.

Thanks, --David

From: Takeshi Takahashi [mailto:takeshi_takahashi@nict.go.jp]
Sent: Friday, August 12, 2016 11:11 AM
To: draft-ietf-nvo3-arch.all@ietf.org
Cc: iesg@ietf.org; secdir@ietf.org; nvo3@ietf.org
Subject: Secdir review of draft-ietf-nvo3-arch-06

I have reviewed this document as part of the security directorate's ongoing=
 effort to review all IETF documents being processed by the IESG.
These comments were written primarily for the benefit of the security area =
directors.
Document editors and WG chairs should treat these comments just like any ot=
her last call comments.

[General summary]
This document is ready.

[Topic of this draft]
This informational document describes a high-level overview architecture fo=
r building data center network viatualization overlay (NVO3) networks.
It breaks down the architecture and defines several components needed for r=
ealizing the architecture, such as Network Virtualization Edge (NVE) and Ne=
twork Virtualization Authority (NVA).

[Minor Comment]
In Section 16 "Security Considerations", you could consider addressing the =
policy enforcement issue you've discussed in Section 5.4.
The sentence starting with "Leakage of sensitive information" could be, for=
 instance, changed from "...by using encryption" to "...by using encryption=
 and ensuring policy enforcement".

[Editorial Comment]
In Page 9, there is a sentence "NVAs provide a service, and NVEs access tha=
t service via an NVE-to-NVA protocol as discussed in Section 4.3."
This current sentence is fine, but referring Section 8 "NVE-to-NVA Protocol=
" (instead of Section 4.3 "NVE State") could be better.

In Section 2, definition of "VLAN": "are used in this document denote a C-V=
LAN", could be "are used in this document to denote a C-VLAN".

I enjoyed reading the draft.

Thank you.
Take


--_000_CE03DB3D7B45C245BCA0D243277949362F63B90FMX307CL04corpem_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:"Yu Gothic";}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	text-align:justify;
	font-size:10.5pt;
	font-family:"Yu Gothic";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Yu Gothic";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;
	font-weight:normal;
	font-style:normal;
	text-decoration:none none;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:99.25pt 85.05pt 85.05pt 85.05pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72" style=3D"text-justi=
fy-trim:punctuation">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Take-san,<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Thank you for the review.=
&nbsp;&nbsp; I&#8217;ve made changes to address all of your comments in my =
working copy of this draft that will be posted as the -07 version next week=
.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">The minor comment on info=
rmation leakage affects both the data plane and control plane and hence I&#=
8217;ve made changes to address it in two paragraphs in the Security
 Considerations section.&nbsp; Here are the revised versions of both paragr=
aphs:<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D=
">For the data plane, tunneled application traffic may need protection agai=
nst being misdelivered, modified, or having its content exposed
 to an inappropriate third party. In all cases, encryption between authenti=
cated tunnel endpoints and enforcing policies that control which endpoints =
and VNs are permitted to exchange traffic can be used to mitigate risks.<o:=
p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D=
"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D=
">[...]<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D=
"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D=
">Leakage of sensitive information about users or other entities associated=
 with VMs whose traffic is virtualized can also be covered
 by using encryption for the control plane protocols and enforcing policies=
 that control which NVO3 components are permitted to exchange control plane=
 traffic.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><span style=
=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;=
;color:#1F497D">Thanks, --David<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><b><span st=
yle=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quo=
t;">From:</span></b><span style=3D"font-size:10.0pt;font-family:&quot;Tahom=
a&quot;,&quot;sans-serif&quot;"> Takeshi Takahashi [mailto:takeshi_takahash=
i@nict.go.jp]
<br>
<b>Sent:</b> Friday, August 12, 2016 11:11 AM<br>
<b>To:</b> draft-ietf-nvo3-arch.all@ietf.org<br>
<b>Cc:</b> iesg@ietf.org; secdir@ietf.org; nvo3@ietf.org<br>
<b>Subject:</b> Secdir review of draft-ietf-nvo3-arch-06<o:p></o:p></span><=
/p>
</div>
</div>
<p class=3D"MsoNormal" align=3D"left" style=3D"text-align:left"><o:p>&nbsp;=
</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">I have reviewed this document as part of the security directorate's on=
going effort to review all IETF documents being processed by the IESG.<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">These comments were written primarily for the benefit of the security =
area directors.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">Document editors and WG chairs should treat these comments just like a=
ny other last call comments.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">[General summary]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">This document is ready.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">[Topic of this draft]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">This informational document describes a high-level overview architectu=
re for building data center network viatualization overlay (NVO3) networks.=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">It breaks down the architecture and defines several components needed =
for realizing the architecture, such as Network Virtualization Edge (NVE) a=
nd Network Virtualization Authority
 (NVA).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">[Minor Comment]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">In Section 16 &#8220;Security Considerations&#8221;, you could conside=
r addressing the policy enforcement issue you've discussed in Section 5.4.<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">The sentence starting with &quot;Leakage of sensitive information&quot=
; could be, for instance, changed from &quot;...by using encryption&quot; t=
o &quot;...by using encryption and ensuring policy enforcement&quot;.<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">[Editorial Comment]<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">In Page 9, there is a sentence &quot;NVAs provide a service, and NVEs =
access that service via an NVE-to-NVA protocol as discussed in Section 4.3.=
&quot;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">This current sentence is fine, but referring Section 8 &quot;NVE-to-NV=
A Protocol&quot; (instead of Section 4.3 &quot;NVE State&quot;) could be be=
tter.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">In Section 2, definition of &quot;VLAN&quot;: &quot;are used in this d=
ocument denote a C-VLAN&quot;, could be &quot;are used in this document to =
denote a C-VLAN&quot;.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">I enjoyed reading the draft.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">Thank you.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA">Take<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;mso-fareast-language=
:JA"><o:p>&nbsp;</o:p></span></p>
</div>
</div>
</body>
</html>

--_000_CE03DB3D7B45C245BCA0D243277949362F63B90FMX307CL04corpem_--

