Re: [sfc] Zaheduzzaman Sarker's No Objection on draft-ietf-sfc-nsh-integrity-06: (with COMMENT)

Zaheduzzaman Sarker <zaheduzzaman.sarker@ericsson.com> Tue, 13 July 2021 14:09 UTC

Return-Path: <zaheduzzaman.sarker@ericsson.com>
X-Original-To: sfc@ietfa.amsl.com
Delivered-To: sfc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42C463A11E7; Tue, 13 Jul 2021 07:09:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.553
X-Spam-Level:
X-Spam-Status: No, score=-2.553 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.452, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TrHJc1hTonw4; Tue, 13 Jul 2021 07:09:12 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2067.outbound.protection.outlook.com [40.107.22.67]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DEA923A11E0; Tue, 13 Jul 2021 07:09:11 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LndE/+RbG/l2L3r61d3Rr6NKf2h0+cOUxaw41ARTMm0yGaiplDfoj9ZZvOg6TATa+bgAlNjZAKjFdEOJNMkpI8PCwYtTOiMqNkOe4kPK2oYa0zIkhqhiYBQmA/JFMHeQb40yQJ9CUOE+fUFSiJi3sw4APGBSowLSpOrR7z1YSdFU2iZtUXOjEECj7mdFKmhbkyCnwltxtcXomBAWpR9/6uOGnD6b2kId533Pqodc/xAfLRyB+5Kf2Ib2N/nhfiVj9FJBkg+ALTfuFAZ954ldyhpMSequOWgAhDggcyNaUhuSDCpGt+PtA4+hlYfGYVjhmLY4LHIIe0dHg+cVCmCZ6A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=meNL0UZ8jZNu3U7Pq6ISdeTYKZrWP4kqfcruS6e8lUY=; b=oa2G6rtTcJfz24WGbXYG/o2xJ/co53NJOky45DNwZXfqgFpwEdTtEkcJh7pmR0XtzSJwFM5MpGw4DxSggpTF9XayzR9gmuigDCtXoi0RLfsWmr9ez2YphyG+SBpkwZ5rRfgl6TOpv5rZfrA0jl8CGsmhCsHJbyaAuBsiJVCfXdjGeHUEkNsb1kLzt1paOV+Ve9cGrW0oF25h73itpRd78qSy4S/a/D2G0gqkbZEBCA2PjgUHMNJysJmdvXsnZY1UsrrHIjzRcZA9XB6UK0THZAg4hK1G75RNS0+xLrBRX1n2NwMGhRASgPQ/t4R9JCG4TsfY1LK5O6fVs1GnVKJ8pg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=meNL0UZ8jZNu3U7Pq6ISdeTYKZrWP4kqfcruS6e8lUY=; b=V/M4TJrGz39Fbm2RX+rFvA7D74yno+M3p/v0+TohvxrqU3SWwm0puMqnIdT/KozYu6rPN65JZZWdEy/V5+3U+Z+1Xb8WsTNGmGo7WLE/QVgL+XCG2TL1THxTQeQU0z8zA+aLg0AJjRCG//O1XY3541UpthGVAH7Q00+NimTomrM=
Received: from HE1PR07MB4187.eurprd07.prod.outlook.com (2603:10a6:7:98::23) by HE1PR0701MB2169.eurprd07.prod.outlook.com (2603:10a6:3:28::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4331.17; Tue, 13 Jul 2021 14:09:07 +0000
Received: from HE1PR07MB4187.eurprd07.prod.outlook.com ([fe80::158:faff:a530:9dcd]) by HE1PR07MB4187.eurprd07.prod.outlook.com ([fe80::158:faff:a530:9dcd%6]) with mapi id 15.20.4331.021; Tue, 13 Jul 2021 14:09:07 +0000
From: Zaheduzzaman Sarker <zaheduzzaman.sarker@ericsson.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, The IESG <iesg@ietf.org>
CC: "draft-ietf-sfc-nsh-integrity@ietf.org" <draft-ietf-sfc-nsh-integrity@ietf.org>, "sfc-chairs@ietf.org" <sfc-chairs@ietf.org>, "sfc@ietf.org" <sfc@ietf.org>, "gregimirsky@gmail.com" <gregimirsky@gmail.com>
Thread-Topic: Zaheduzzaman Sarker's No Objection on draft-ietf-sfc-nsh-integrity-06: (with COMMENT)
Thread-Index: AQHXd9MGZ6YQ3JB9xEC80kobg/6Ve6tAvpKAgABUlwA=
Date: Tue, 13 Jul 2021 14:09:06 +0000
Message-ID: <232E3C7F-E4E6-456F-8E02-B9FF61D4B9A9@ericsson.com>
References: <162617261371.15907.6050785043086194503@ietfa.amsl.com> <3763_1626174382_60ED73AE_3763_126_1_787AE7BB302AE849A7480A190F8B9330353BE5BA@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
In-Reply-To: <3763_1626174382_60ED73AE_3763_126_1_787AE7BB302AE849A7480A190F8B9330353BE5BA@OPEXCAUBMA2.corporate.adroot.infra.ftgroup>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.50.21061301
authentication-results: orange.com; dkim=none (message not signed) header.d=none;orange.com; dmarc=none action=none header.from=ericsson.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 1c5276bf-a5c5-4403-f1a6-08d94607c739
x-ms-traffictypediagnostic: HE1PR0701MB2169:
x-microsoft-antispam-prvs: <HE1PR0701MB21691B8310DC7309446AA76F9F149@HE1PR0701MB2169.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: sCKTRvy9y1dASUJADj6yTSqEgS1t3/5euknaM5XIbY256jVSzLA4ycXohqjceStykKNdUkR2JVkxE2P924pZlxopdBnZeDLnhdYUINpgJkjrhGgH3F3sYOo64IPKdPdhej+t0kAZ4iHUmSi8YKGDoUVkN5e8zpVouJIkhZHjJu+IYHv7qxasfzrVJ+qp6iOMSkmz4+No6QBhWtA2wu7VkHPN2NNlmMECbo/kf25MNQ6oiRkwVElaHGEjLCIUyL/60tazgatH+Ntctwp1nI2AgJzrC22ml0dJtWW75utUaLMrSD48CDQ5rlKbh0SG8xyYIsLWLvKm80JoqVdsrXNrV7kNJ844IIBCFDqIHdktsOQZohEzx3W2gik4uNcTG/TH7kLklPETmBHbxL8hiN2eXCR2SvJ8BPvuBX7h2OSus9YYgQ34Jn/U6wpUr8Q+al8wy4ylNFU+C78loKn5Mju/ktL1vXQpzXEzFmE6xnj9y4YUkhdNq+KzxeQ3zZnUBJqetUvKxfnrKLrFIeQ3QY2TfUiB90orsDS4B+BEaT5aZVxoTDZdapFgc8+vUdbRsT1AxYxDaO5v1ByHEXM+U0pet0VeIAtpxBXZs25HauFrkRB7luHMQ64Z3/qqeMe3Gl2UCB0Tr06212QDGFvmhEa56okHKLIUYRctNm3gG/oqtDd4CND3+/ry2WsvICsIUjFaqBxW9+XzQqN56/hVm3J240wjpfPrGrepQMtCPx5g7E/ajbwj0JO4RfbVznQnKzcH6GvxEeEUOaRCvJE8oIpzCgouIWzeUQ6IN0iHde6kFA+MD0GSE6IV4qflZ4ykF2KWpFNH3MlPx0iZgMRayijH/Q==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR07MB4187.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(136003)(366004)(346002)(39860400002)(376002)(83380400001)(6506007)(38100700002)(2906002)(64756008)(76116006)(66946007)(478600001)(122000001)(5660300002)(966005)(86362001)(33656002)(6486002)(36756003)(26005)(110136005)(4326008)(6512007)(71200400001)(66446008)(8676002)(44832011)(66476007)(2616005)(186003)(8936002)(66556008)(54906003)(316002)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?utf-8?B?WHZ3QjRtZ0o2aVBveWVGNmgraEI0clRxWnptc1R0cGZ0NDNET0ZWczVrVEoz?= =?utf-8?B?Z1RqaG8yYkQ5U1pnNnJEVGwyc2NzbEY3R1ZiTnBoUHNNT1AvY2ZnMzRmLzVU?= =?utf-8?B?TWtFK2x1dTU4OExBanFOUmhaR2FWUDNrYW1za1ZQUG10RjZvQ1RibTZ4Ly9y?= =?utf-8?B?R1V4NUZnYmpqOVNDQ3Q1bXI1MlFSMGhGTGtKeWJIODIwdm14UUg0eXA4SlhW?= =?utf-8?B?cU5LQW1pS242N0I0YjNUL1cwRHJmaHVzbVIvcFFFZkJtbWRQWXlkYVprYkNO?= =?utf-8?B?N3dtaTQyMmJRaDBSNXhwemJtT291SGpvUTdkeTVBQks1WjdZaDJvZVd3Sk1t?= =?utf-8?B?a0x6Mm85N1VrcUxHQk5wRkJucWY1eHdMRmgxQ0pRY21vMnJpbitVcVFJcDBt?= =?utf-8?B?UU4zcS9oMUJZYXU4b0d0VDVVamozUEVER2c3dlR5WjFUd1ZuekNtUlJGOEVN?= =?utf-8?B?SGZ1ZjA2VTBlNnFXcTdNMFhrNVo3T0ZtUllRa1pZRGdlWHlncDg1ZTBYcTBm?= =?utf-8?B?aDRYTEkrWGFKZ0FscTh6d0Jva1ZQRTE1bjh2aXRMKy8wbk9kMnlxdGFtNmRt?= =?utf-8?B?eE1MRE1rclNGbWo2QktwTlVEcStYcnNTbUFYeVNSajhxbXZldURoVzh4WnlF?= =?utf-8?B?aXFPMS9KZkwrWjRaNXdrcUoyQzJQY0tHYlF1Um8waStpcnFxZnRxQ1huMUhr?= =?utf-8?B?YWVURHp2L2tJRUNFcjk5UVk4dVdGbVJrUTdWdVZOUmFQc1JCYmdqeVU1YTJ0?= =?utf-8?B?aTZtOGEyN2FpbTVIYlVRRTQ3TjNJR0VTdnpMWENvOU5HM21hUHRydWNhQTFC?= =?utf-8?B?WEdPVE9NMU81TGtHMTRnUk42VkFDK1Zlb1dHVkwxZVB2NkY0RE5FT0J4MGFC?= =?utf-8?B?S29SYmlQRmR6N1BpM3VrV3AxM1ZzNHd6Y1NTZjhzOUxtbmQ3b3VQUGJUUDJx?= =?utf-8?B?NjFHWHVGQS9WWU03MHpOY1preGxQSUswWUovcndZZ2xhTGlveWQrWTA0SnJH?= =?utf-8?B?bkNUWmNCSWhSeUZQa3NyOGNiYWNIaG5OclRyb1dNTlYyMnVRd1A2MlBjZ3E3?= =?utf-8?B?ZS9JMFNUWWVuUjQzTW5ZT0M2Qkh5c1FaN1lucjZaWCtCZHFoTlNITEQ2U0M3?= =?utf-8?B?MzJyTGxheG81bng1Q2lnenZab0s1VkFKZTJONWFhY1R5RU51VGNMWFc1SWFr?= =?utf-8?B?VDFaUmJuV0tKSHBiVTM0YTVueSs0ZHZWSlFJeDZTeXQxdEIvSVR3U0EwL24y?= =?utf-8?B?a1NvUVUwU00zN096RjF4U2UyeEdnSkh2SFlaaHlqWndXRVNKMDlLRWQwQUNF?= =?utf-8?B?d2p6ZWs5T2MzMFNZT3pjYW4xQmtIeCtUWTFwYnA2TnVUMlhEY1FKMDBFUnRP?= =?utf-8?B?TGdOcUdrdVdiSXlzT1V1YmdBMStaQzVRc1l0ZFF1SHRYdlhaWkkyZDI2VW1Y?= =?utf-8?B?Q25JNDVTTjNLSmtoMzhmYlJCdWdXY3ViQStCU2JySEpHVTl5NnZVSHB6WlJK?= =?utf-8?B?WHUxZjkxTG80bnU4MFV5SXlieWFoVXFwTWMrcVpCVDd3OXlub2thbU5OaXBF?= =?utf-8?B?b092WnVHUzgvcTdMeXZ6WGQ5dGpURy85VWxnVGJ0MGFLYmNnN2dOWWlObXM1?= =?utf-8?B?SFN6UE1HaG94SnhGSzQxeXF0WlozYXNUczBLdzQ1WXRMUmp0UmNxdkdxRU9x?= =?utf-8?B?TW1nQzQ2VzRURVhYUHE3Z1A3SW5IZUoycldjdmJNM0JNV3FjUU9qVXMwSFlN?= =?utf-8?Q?nQZS5v7bIP3vxIoXBRteLq4eHhunZImHch28bKg?=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <AE36289F417D924BBE5FD67B4DEA4721@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR07MB4187.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1c5276bf-a5c5-4403-f1a6-08d94607c739
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Jul 2021 14:09:06.9215 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: +LzoImBnO5Iks3JG9bNOqHf3c29tZmRh3wRLYnW9iHHjvhmQOo4Wq2nEQ4kRsbGQ34azBj8+/6Z0KmL5lkMU6u47ElQ4B3zmemxOrKhNnB0ugaeBCHKRNU0J5V9xfiHj
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0701MB2169
Archived-At: <https://mailarchive.ietf.org/arch/msg/sfc/2Z9XcsXLvAO8bc-Illmyv71Dq0M>
Subject: Re: [sfc] Zaheduzzaman Sarker's No Objection on draft-ietf-sfc-nsh-integrity-06: (with COMMENT)
X-BeenThere: sfc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Network Service Chaining <sfc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sfc>, <mailto:sfc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sfc/>
List-Post: <mailto:sfc@ietf.org>
List-Help: <mailto:sfc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sfc>, <mailto:sfc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Jul 2021 14:09:18 -0000

Hi,

Thanks for the responses. See below my reflections inline below.

BR
Zahed

On 2021-07-13, 13:06, "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com> wrote:

    Hi Zahed, 

    Thanks for the review. 

    Please see inline. 

    Cheers,
    Med

    > -----Message d'origine-----
    > De : Zaheduzzaman Sarker via Datatracker [mailto:noreply@ietf.org]
    > Envoyé : mardi 13 juillet 2021 12:37
    > À : The IESG <iesg@ietf.org>
    > Cc : draft-ietf-sfc-nsh-integrity@ietf.org; sfc-chairs@ietf.org;
    > sfc@ietf.org; gregimirsky@gmail.com; gregimirsky@gmail.com
    > Objet : Zaheduzzaman Sarker's No Objection on draft-ietf-sfc-nsh-
    > integrity-06: (with COMMENT)
    > 
    > Zaheduzzaman Sarker has entered the following ballot position for
    > draft-ietf-sfc-nsh-integrity-06: No Objection
    > 
    > When responding, please keep the subject line intact and reply to
    > all email addresses included in the To and CC lines. (Feel free to
    > cut this introductory paragraph, however.)
    > 
    > 
    > Please refer to https://www.ietf.org/iesg/statement/discuss-
    > criteria.html
    > for more information about DISCUSS and COMMENT positions.
    > 
    > 
    > The document, along with other ballot positions, can be found here:
    > https://datatracker.ietf.org/doc/draft-ietf-sfc-nsh-integrity/
    > 
    > 
    > 
    > --------------------------------------------------------------------
    > --
    > COMMENT:
    > --------------------------------------------------------------------
    > --
    > 
    > Thanks for the efforts on this specification.
    > 
    > I have following non-blocking comments those I believe would improve
    > the document if addressed --
    > 
    > * I agree with Alvaro and Lars's comment about updating 8300. Would
    > like to get
    > response(s) to their comments.

    [Med] Already replied to those. 

Thanks, watching the thread.

    > 
    > * I think it will be helpful to explicitly mention if integrity and
    > confidentiality by the transport encapsulation is needed or not when
    > this specification is in use. This specification definitely says
    > that one does not need to relay on the service provided by the
    > transport encapsulation but it does not says that those services are
    > not longer required.

    [Med] We don't say so because this is deployment-specific. One may deploy hSFC (RFC8459) with transport security to interconnect lower-level domains, but use this spec within a lower-level domain. 

Ok, then can we write something along the lines you have written here? This might actual help the why not updating 8300 discussion as well.

    > 
    > * Section 1 : says -
    >     "This specification fills that gap.  Concretely, this document
    > adds
    >    integrity protection and optional encryption of sensitive
    > metadata
    >    directly to the NSH (Section 4);"
    > 
    >   Does this specification extends the use of NSH in multiple SFC
    > domain?

    [Med] No, we don't as we adhere to RFC7665 and RFC8300. 

    Future documents may define an updated 7665 to describe the inter-domain case. This spec may solve some of the inherent issues, but it is out of scope to discuss those in this I-D.

    Till this happens, the scope is still what is recorded in RFC7665: 

    ==
       The architecture described herein is assumed to be applicable to a
       single network administrative domain.  While it is possible for the
       architectural principles and components to be applied to inter-domain
       SFCs, these are left for future study.
    ==

OK. I have seen the update where you mention about the gaps that will resolve my question as well.

     My
    >   little understanding of NSH says it is SFC domain specific and
    > within one SFC
    >   domain the devices a vetted to be trusted. I think it will be very
    > helpful to
    >   add zest from the section 3.2.1. of I-D.arkko-farrell-arch-model-t
    > here.
    > 
    > * Section 6 :
    > 
    >    The epoch is 1970-01-01T00:00Z in UTC time.  Note this epoch
    > value
    >       is different from the one used in Section 6 of [RFC5905].
    > 
    >    It would be great if we can add the implications of the
    > difference. Now I
    >    don't know what it means.
    > 
    > 

    [Med] The implication is basically what is mentioned under wraparound bullet: "The next wraparound will occur in the year 2106". If we maintained the epoch in RFC5905, the wraparound would be in 2036. Tweaked the text to mention this. Thanks. 

Ok.



    _________________________________________________________________________________________________________________________

    Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
    pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
    a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
    Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

    This message and its attachments may contain confidential or privileged information that may be protected by law;
    they should not be distributed, used or copied without authorisation.
    If you have received this email in error, please notify the sender and delete this message and its attachments.
    As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
    Thank you.