Re: [secdir] [IPsec] I-D Action: draft-harkins-brainpool-ike-groups-00.txt

Paul Hoffman <paul.hoffman@vpnc.org> Tue, 28 August 2012 18:18 UTC

Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D0F721F85DA; Tue, 28 Aug 2012 11:18:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.566
X-Spam-Level:
X-Spam-Status: No, score=-102.566 tagged_above=-999 required=5 tests=[AWL=0.033, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q5fHfPQZTAr9; Tue, 28 Aug 2012 11:18:31 -0700 (PDT)
Received: from hoffman.proper.com (IPv6.Hoffman.Proper.COM [IPv6:2605:8e00:100:41::81]) by ietfa.amsl.com (Postfix) with ESMTP id 6B7D221F85F7; Tue, 28 Aug 2012 11:18:31 -0700 (PDT)
Received: from [10.20.30.108] (50-1-50-97.dsl.dynamic.fusionbroadband.com [50.1.50.97]) (authenticated bits=0) by hoffman.proper.com (8.14.5/8.14.5) with ESMTP id q7SIIQ6M013774 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Tue, 28 Aug 2012 11:18:27 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Mime-Version: 1.0 (Mac OS X Mail 6.0 \(1486\))
Content-Type: text/plain; charset="us-ascii"
From: Paul Hoffman <paul.hoffman@vpnc.org>
X-Priority: 3 (Normal)
In-Reply-To: <d27c02a7ccb21b129b59b4f81a986490.squirrel@www.trepanning.net>
Date: Tue, 28 Aug 2012 11:18:27 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <DC26318D-4A8E-4935-91A5-A3BA716174BF@vpnc.org>
References: <20120809010519.15222.89232.idtracker@ietfa.amsl.com> <503CAA6F.30302@ieca.com> <9035196F-001D-4E15-B6D6-30B59BEBBB01@cs.tcd.ie>, <73F8581B-716F-4466-8F6B-645206789C5E@checkpoint.com> <DDAF3F15-4C72-4CC9-AC4D-29D7496A7BD3@mimectl> <f78fae22050825d0da20c332fc4136d4.squirrel@www.trepanning.net> <503CEC59.9080601@gmail.com> <d27c02a7ccb21b129b59b4f81a986490.squirrel@www.trepanning.net>
To: Dan Harkins <dharkins@lounge.org>
X-Mailer: Apple Mail (2.1486)
Cc: IPsecme WG <ipsec@ietf.org>, secdir <secdir@ietf.org>
Subject: Re: [secdir] [IPsec] I-D Action: draft-harkins-brainpool-ike-groups-00.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Aug 2012 18:18:32 -0000

On Aug 28, 2012, at 10:49 AM, Dan Harkins <dharkins@lounge.org> wrote:

> When the IEEE liaison brought up this issue, your co-chairman
> said, "Yaron and I should "not* be part of this discussion because
> the issue is *not* an IPsecME WG issue. It is not in our charter
> to make additions to the obsoleted-but-still-widely-used IKEv1
> protocol." He is also the one who insisted on the note that the
> draft adds to the registry, which sort of makes this not an IKE
> code point discussion.

I was with you until that last phrase. It most certainly is an IKEv1 code point discussion.

>  If this is an IKE discussion, I'd be happy to discuss this on the
> ipsecme list and I'd be, therefore, happy to remove the note and the
> corresponding "Insecurity Considerations" from the draft.
> 
>  But maybe you guys should go off and decide what you want.

What I want is for you to be less snarky in your communication, both on-list and in the Internet-Drafts you write. I would also want you to be clearer in your drafts when you are talking about IKEv1 or IKEv2: in this draft, even in the filename, you kind of hid that.

Whether or not you want to do those, I want the ADs to decide whether it is appropriate to do more work on IKEv1, such as adding these curves to the IKEv1 registries. If they think the work is appropriate, they can also say where it should be done.

--Paul Hoffman