Re: [sidr] WGLC on draft-ietf-sidr-bgpsec-threats-02

"Murphy, Sandra" <Sandra.Murphy@sparta.com> Wed, 15 August 2012 17:56 UTC

Return-Path: <Sandra.Murphy@sparta.com>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF8D921F85A2 for <sidr@ietfa.amsl.com>; Wed, 15 Aug 2012 10:56:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.539
X-Spam-Level:
X-Spam-Status: No, score=-102.539 tagged_above=-999 required=5 tests=[AWL=0.059, BAYES_00=-2.599, HTML_MESSAGE=0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id duly5bB05Bds for <sidr@ietfa.amsl.com>; Wed, 15 Aug 2012 10:56:19 -0700 (PDT)
Received: from M4.sparta.com (M4.sparta.com [157.185.61.2]) by ietfa.amsl.com (Postfix) with ESMTP id 1AF4421F859A for <sidr@ietf.org>; Wed, 15 Aug 2012 10:56:18 -0700 (PDT)
Received: from Beta5.sparta.com (beta5.sparta.com [157.185.63.21]) by M4.sparta.com (8.14.4/8.14.4) with ESMTP id q7FHuFj3000803; Wed, 15 Aug 2012 12:56:16 -0500
Received: from Hermes.columbia.ads.sparta.com ([157.185.80.107]) by Beta5.sparta.com (8.13.8/8.13.8) with ESMTP id q7FHuFar014594; Wed, 15 Aug 2012 12:56:15 -0500
Received: from HERMES.columbia.ads.sparta.com ([fe80::e4a8:a383:2128:c0e5]) by Hermes.columbia.ads.sparta.com ([fe80::e4a8:a383:2128:c0e5%21]) with mapi id 14.01.0355.002; Wed, 15 Aug 2012 13:56:10 -0400
From: "Murphy, Sandra" <Sandra.Murphy@sparta.com>
To: Brian Dickson <brian.peter.dickson@gmail.com>
Thread-Topic: [sidr] WGLC on draft-ietf-sidr-bgpsec-threats-02
Thread-Index: Ac16N6Ae407rtL9CRxWS182ULJwIzgATI8aAACJa2qM=
Date: Wed, 15 Aug 2012 17:56:09 +0000
Message-ID: <24B20D14B2CD29478C8D5D6E9CBB29F625F5FF30@Hermes.columbia.ads.sparta.com>
References: <24B20D14B2CD29478C8D5D6E9CBB29F625F5604B@Hermes.columbia.ads.sparta.com>, <CAH1iCiorpj6N55B9RQCvWcTgEbUZ+Vgcr4Hhc-+h8A93U8HbHA@mail.gmail.com>
In-Reply-To: <CAH1iCiorpj6N55B9RQCvWcTgEbUZ+Vgcr4Hhc-+h8A93U8HbHA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.185.63.137]
Content-Type: multipart/alternative; boundary="_000_24B20D14B2CD29478C8D5D6E9CBB29F625F5FF30Hermescolumbiaa_"
MIME-Version: 1.0
Cc: "sidr@ietf.org" <sidr@ietf.org>
Subject: Re: [sidr] WGLC on draft-ietf-sidr-bgpsec-threats-02
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Aug 2012 17:56:20 -0000

Brian, I can see that you think that some people brought up some issues some time ago on some previous version(s) that have not been addressed.

Unfortunately, that's not clear enough for the chairs or authors to take action.

It would help if you could provide more specifics.

--Sandy, speaking as wg co-chair

________________________________
From: Brian Dickson [brian.peter.dickson@gmail.com]
Sent: Tuesday, August 14, 2012 5:20 PM
To: Murphy, Sandra
Cc: sidr@ietf.org
Subject: Re: [sidr] WGLC on draft-ietf-sidr-bgpsec-threats-02

I have reviewed the draft.

It remains vague and incomplete, in the Residual Threats section. This, despite extensive discussion (since the -00 version) on the list regarding very specific, very real, residual threats.

It not only fails to discuss them, it fails to enumerate them.

The extensive discussion is in the archives, and contains substantive comments from at least 1/4 active participants in SIDR, including those with the greatest degree of operational and/or implementation experience.

I would request that the WGLC be retracted until the authors decide to address those previous comments.

Chairs: There should not be a need to re-raise the particulars - if the authors got shot down before, and fail to include text or address the complaints, I fail to see why they are submitting this, or the chair(s) are doing a WGLC.

The objective of a threats model should be to model the threats, and identify known weaknesses. If it is substantially incomplete, it is not ready to go. It fails to accomplish its _only_ goal.

Excluding threats from this doc, because the solution does not address them, is beyond ridiculous. It is laughable.

Sorry if this offends the authors. The authors' work is at issue, not the authors themselves. They are fine and upstanding individuals. This ID, in its current form, however, is, IMHO, junk.

Brian

On Tue, Aug 14, 2012 at 12:19 PM, Murphy, Sandra <Sandra.Murphy@sparta.com<mailto:Sandra.Murphy@sparta.com>> wrote:
The authors have indicated that they believe the draft

Threat Model for BGP Path Security
draft-ietf-sidr-bgpsec-threats-02
http://tools.ietf.org/html/draft-ietf-sidr-bgpsec-threats-02

is ready for a working group last call.

This starts the two week working group last call.  It will end on Aug 28.  Please review the draft and send comments to the list.

--Sandy
_______________________________________________
sidr mailing list
sidr@ietf.org<mailto:sidr@ietf.org>
https://www.ietf.org/mailman/listinfo/sidr