Re: [Syslog] Fwd: I-D Action: draft-ciphersuites-in-sec-syslog-00.txt

tom petch <ietfc@btconnect.com> Sat, 11 December 2021 12:45 UTC

Return-Path: <ietfc@btconnect.com>
X-Original-To: syslog@ietfa.amsl.com
Delivered-To: syslog@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 365AF3A0786 for <syslog@ietfa.amsl.com>; Sat, 11 Dec 2021 04:45:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=btconnect.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tvq5b7f-C4o5 for <syslog@ietfa.amsl.com>; Sat, 11 Dec 2021 04:45:00 -0800 (PST)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2094.outbound.protection.outlook.com [40.107.22.94]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4DFFA3A0788 for <syslog@ietf.org>; Sat, 11 Dec 2021 04:44:59 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FZiA9hBh15Vu64Ie14o4bi0gSt7LNQXE+jZEdGqHTfC60MFucoGegY5UF5YX57Q6A2Ss/ZNc1Meda9ywQKunRCilVEb+8y62JAnQZ9FZqpz8NCfI9kITj5oSgaLKjIDoUyAuRQQgJ1U7o6tgi+jGY1v6RtTZAhmSRzqzy7uvbzFvw/x5u/UHT45rbihRWFeiEu8imPVSte5/dl3ETOQGld59SuSezp1k5jYTeXlQcEvC+Ph41ZTYp2OH/rdfGJlbTunfWNng40YIlprJZaQG7iK0a86n7cOeRgJhdkfOJW5cv9M8Ux08P2en5Bzm8g1Pa09vHfy6Zj0/jKTHbqlEaw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SkibEEunHpoe/ZEX9GRIRu4gVChCw0tHuHG6PvzxoQ0=; b=g4C3Wt5BJxMrJBM0pxd9XBHsaTazLZNAu33DcQf6E0lIukS/gd9QsDOipIeOZJgBCQfZUwFmeceEzJwrrogQbjJZImtHBiBZUHFITxy6fMV90zSK5wBIHTrVORpBJkNeF/98kUhG+alUNCMWD83AazaSI36gTzD0VpnUukXjsvK7e7pgg740JvtYJfbmjRBuJNitotz4r3YSRGUI1bnjxSZcSO8BUg0ijo41B7R2NBBEulHaah42td+191b4LwWE2nN21I3XBj3HAKDKIcGKpFu264yh+aglHnzJNffqRZbaRnw3a9WE0sl/61oza37XIA/a3Q20C18kTPexaaScuA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=btconnect.com; dmarc=pass action=none header.from=btconnect.com; dkim=pass header.d=btconnect.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=btconnect.onmicrosoft.com; s=selector2-btconnect-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SkibEEunHpoe/ZEX9GRIRu4gVChCw0tHuHG6PvzxoQ0=; b=INsKGSOY8vNgVZYa9w4cl+W+nKIvDpP/7LL36XeKyM/7yF+pJiS9BmIPYWT4WM2/+PQ1/YCYVX4hNmotWMqrd55w/ZZV3onyz1rAOkqqzSWxK56P5UQwrPcI2Olw9QO1G0kIxBEQZhGxU7XLlqfvKk5JoKuih7WrdFVNhavoGhM=
Received: from AM7PR07MB6248.eurprd07.prod.outlook.com (2603:10a6:20b:134::11) by AM6PR07MB5191.eurprd07.prod.outlook.com (2603:10a6:20b:61::29) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4801.8; Sat, 11 Dec 2021 12:44:53 +0000
Received: from AM7PR07MB6248.eurprd07.prod.outlook.com ([fe80::89f3:ef4c:9336:3848]) by AM7PR07MB6248.eurprd07.prod.outlook.com ([fe80::89f3:ef4c:9336:3848%3]) with mapi id 15.20.4801.011; Sat, 11 Dec 2021 12:44:53 +0000
From: tom petch <ietfc@btconnect.com>
To: Chris Lonvick <lonvick.ietf@gmail.com>, "syslog@ietf.org" <syslog@ietf.org>, "sean@sn3rd.com" <sean@sn3rd.com>, Joe Salowey <joe@salowey.net>, Arijit Bose <arijit.bose@hitachienergy.com>
Thread-Topic: [Syslog] Fwd: I-D Action: draft-ciphersuites-in-sec-syslog-00.txt
Thread-Index: AQHX7h2OCKx79twsg0SVRRPspa1bgawtOzto
Date: Sat, 11 Dec 2021 12:44:53 +0000
Message-ID: <AM7PR07MB6248D3FC0415A872CD204DBCA0729@AM7PR07MB6248.eurprd07.prod.outlook.com>
References: <163917706473.14037.18043022518803073486@ietfa.amsl.com> <928a9aa6-7585-55ed-051b-ad68073a947a@gmail.com>
In-Reply-To: <928a9aa6-7585-55ed-051b-ad68073a947a@gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-Hashtags: #NewslettersPlus
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
suggested_attachment_session_id: c8162dc8-c690-fd99-be37-a41d5769185b
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=btconnect.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: c73f229c-f20a-4cb5-545b-08d9bca40778
x-ms-traffictypediagnostic: AM6PR07MB5191:EE_
x-microsoft-antispam-prvs: <AM6PR07MB5191559DC267F9E9CE3428B0A0729@AM6PR07MB5191.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: TKul3oWZhfXqnmpmhWgRd9r+4kUTu4GtMuKO3z4BFxMX+h6ZwCIldgV8YAA44n31Y940cMLnZYaOueKCYbsvnmxiZ2GpQ+WsVVd6+gxOzJhC05HqjO8Y64hF8F2/gwqVHwKffTi/jpj8hLjBlX67dba2zlC/ThQ2NUnQB1CXW6vBOIIvufRIdrECgJnRmztlDn//bGMh44V2s9QiP+jyYag+KWRAI44pGKQkXRuty7IYE0Pt00VxsoYU7m1qQzoJqvK/HeU79YBEUhhY2hkv6PG/ejmacqAvzwdhgIqfz6FF7pO/k9Gvvk7GY5nyLIaZzLXsZ5DUJHrCNXmMh185JFedHMVJaZtgNLMygWZ0mDvBqKkNtcpyVZx0VIKo/08/cpTjKa9K0HDFyu5YbUVe1DobQSzmOeKsjGry2BuYHgDdN5maExDnTcG+MrAr2a1WXLuhXQZc1KoS8RubQFREzKwOvdtZC2qpMppgXKDjhUF3dbwniQgB9kKiAfjh97ntzs38WT/Fy/o0kte1jnP/ZHK3S2L4B4DwgWmNt9pwZDCzCRX75PJnj51M/Vd0zfTdR5f9N+cmtS2fmgzrW8yV+pbwhDXzCjLGjKix0w/Rg4wye2qp2qplkSbfBWJhyXHWm8Y5gUghSryY8d5zNsuSYjTT+by2ac1ecWn/xlp4WUqv2H9mP8PbmIpze3Cg5wOfyjQc19miGANHplZlkre8t4QCMHQAkDVgf3dgCXeKotP7FQXlF4psOmi+vqU74KwC86tBekp0EYMfkcGfIBgtTOTBGGGT2evUHyQCIH8rh+OTOqa39n3IA/PHmUpiuWB8Ti2t1zdo7bTcZXfi3Qs/g98v+lxPGiL7UGXNnT0e4uU=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM7PR07MB6248.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(55016003)(122000001)(52536014)(66476007)(7696005)(5660300002)(71200400001)(8676002)(82960400001)(6506007)(4001150100001)(38070700005)(186003)(9686003)(86362001)(38100700002)(53546011)(966005)(66574015)(2906002)(76116006)(8936002)(508600001)(316002)(33656002)(66946007)(64756008)(26005)(66446008)(83380400001)(110136005)(66556008)(91956017)(586874003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EOCbyu9cvctxE92ocpMOxhJ67aiawn42Cqrg2HBhFNtBIYKBOsdlllvXGJppqVfonTfm2gZ7MdJKlX2e6qITRTkdDIpZsQfrSn0KNMykcBVvfS9z2izHUi28RPTj4XHk3nAuiyzSsrd6nb5fgvBYIF6Jb6ksdDMNvollue0Lz+fGB5xXOMKgMBrdrUDPxG9P9HaKkDeXuGV6MGXp6L/rYKPS2PZFv6PmSKH3kuDLFQCqRX+B3JhNrypEW8HhEcgOhZCXWJcsu+iWsv+yW8SSL4yMZCjfCFWEqFFVQh3BvSL1h39TLoFodgnTc33n/9EggHAUUIfN5nnCH69Wj47qpHYm0qno/QXZC6yU0mhoBdbj0YLYH7/rmlLEm5yQv0c48bUxOt5OuOHIXTiellzAIwgWbX8GV5CHV6UHGZgnWXoR1g4C2iWp4qNNAYcOwwOpIFu/NiDVdKIpGCeYuGds+F8pUDBgddx4KFxENkgDNteFY/8WuNpPrnAqgnIrG2oMD9R2ZvMHxRrMsJvtLV6qPmrORLafmcEUOWMNWnlEg2N2mBnqieJOLT0GFm0bDnqvJs07nhBtwUa73RxvtqYSCVcFYVUTek37BTcQyo1UpUbVss4T0IrkC0TA0cDWF6FajKXlo9E6/VmQEjctR8sqgnjcaxtFglK82GPfwPUnlH9YbrTE7xvza9GIZPf5cY4Dfqcrbc0vDKdhnT8aPFdUIzTHW7XpwP4x67yYFd/cnjrpzh/+TzSCoM9yFT15QQTpWzuBEPOM3aQDhEHkX4fLRrqwCbXNRoppVqFpnQg8diPUMgmtB5WISanRrbMvARj0hdxI/kQyf+tAVfXCWQVovyhd4oM+Y5t2ZczsMJJeybILQJVTA8XXfb6OCx+QTxn0JvgXyRwoWMkoTLTX6xQfkpgKZ051+pJzxJl2vYYM3sinqYDgtUKeadDSBp4sZz3QhQn7ScIKAzOnBOeFHYN2l8BwoSC8yqiOI8QsZ4h7qXKkY/isgcY3IWw0UJA1zYVonHHwOVSSmM76+0ka9+PAvLelw6xVItKy17Ev/HqBg1igWUA6frwhQn6vxJeFPN76GLheo+1kD/nRiNM8mpfb25L+YR3TX9fNeWzCVVXULx6NZFMi68pHdLUbHoxwR7QWfejV9OQaH9sWRD9dP5+fhnh89Tx/f8hQPZEkyHpAKQrdYiFC5Am9aSxkXmkHjMZtIrLRAVSJzyBiWvIAjFXSVBUuEXDk2y31huaDRurWlxTypNRBXtsXars55OB/MXkE6GV5j2WAtNqKSYtUYuSm0XITzxVd1gXbkGX4JZ9tc5iqkvy3rR8El7Te6VzFgg+OC2TFZ3Hk46PXD7h/3RX/39HKmPh59idBC5NkM871AILIyh2Qu+lPWsuSLhdofEudZUkRJ02UGYoKQ83ImxR4vAOatlYu9ATVCLf84itjMifAgMEaO3CLHNRDIDbOWlWIcUKPYxAR2fO0FdqZgGABA03MuQnJU4ItHFYdoXD0g8cVDJbL1v1L2J/EYsd6GtDE+UeD3RT2t9V9Vng3PzElFULLYQ/ZnbKIl12J8N/NF528S9osoISZxjiGU/Ii5B+jBWM1QkBTklb/kC+t9x7cGA==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: btconnect.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: AM7PR07MB6248.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c73f229c-f20a-4cb5-545b-08d9bca40778
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Dec 2021 12:44:53.4682 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cf8853ed-96e5-465b-9185-806bfe185e30
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: k4WkPgMmh5FoVH0MNU0jKKsnFrpUwnFhiIw7pHCis6bLtDBAmyzyveNxeAESzPfFuOviNzM1wHCn2kzV7W53aw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM6PR07MB5191
Archived-At: <https://mailarchive.ietf.org/arch/msg/syslog/8xGNzvC55KU0xZyISFTxfqoftcA>
Subject: Re: [Syslog] Fwd: I-D Action: draft-ciphersuites-in-sec-syslog-00.txt
X-BeenThere: syslog@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Issues in Network Event Logging <syslog.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/syslog>, <mailto:syslog-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/syslog/>
List-Post: <mailto:syslog@ietf.org>
List-Help: <mailto:syslog-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/syslog>, <mailto:syslog-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 11 Dec 2021 12:45:05 -0000


________________________________________
From: Syslog <syslog-bounces@ietf.org> on behalf of Chris Lonvick <lonvick.ietf@gmail.com>
Sent: 10 December 2021 23:27
To: syslog@ietf.org; sean@sn3rd.com; Joe Salowey; Arijit Bose
Subject: [Syslog] Fwd: I-D Action: draft-ciphersuites-in-sec-syslog-00.txt

Hi Folks,

As Tom and Jurgen noted, Arijit Kumar Bose did send some notes to the Syslog mailing list. By the time I had snapped to, the system had timed most of them out. I finally got that last one approved and forwarded to the mailing list.

Arijit (and the IEC WG15) rightly notes that the RFCs are using deprecated cipher suits and the DTLS RFC is using a deprecated version.


<tp>

Chris et al

This is flawed.  The use of DTLS1.0 was noted by a security AD a long time ago and is now deprecated  and the syslog RFC have been updated accordingly so anyone saying that syslog uses a deprecated version is wrong; they need to understand the IETF process.

I tracked the work on the TLS list and even posted to that list the fact that the syslog RFC were missing.  I was ignored so I tried again at IETF Last Call and this time got them included (Ignoring me does not make me give up:-)

So your I-D needs to reflect the existing update.  Reinventing the wheel will likely cause confusion amongst subsequent ADs.

Tom Petch

Sean, Joe, and I worked out a -00 draft to address these issues. Like all -00 IDs, it's open to comments. :-) We know that there are some larger efforts underway to address TLS, DTLS and cipher suites. We're not going to try to do that here. Rather, we'd like to update RFCs 5425 and 6012 to get them compliant with current standards with a minimal impact to current implementations.

Sean is going to run this by the secdispatch group to see if they can make a recommendation on where this may be best addressed and discussed. I'm sure that we'll get some good input from the group here on the Syslog mail list, so please send in your comments and let's get these two RFCs updated to using current best practices.

Best regards and have a great weekend,
Chris


-------- Forwarded Message --------
Subject:        I-D Action: draft-ciphersuites-in-sec-syslog-00.txt
Date:   Fri, 10 Dec 2021 14:57:44 -0800
From:   internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>
Reply-To:       internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>
To:     i-d-announce@ietf.org<mailto:i-d-announce@ietf.org>



A New Internet-Draft is available from the on-line Internet-Drafts directories.


Title : Updates to the Cipher Suites in Secure Syslog
Authors : Chris Lonvick
Sean Turner
Joe Salowey
Filename : draft-ciphersuites-in-sec-syslog-00.txt
Pages : 8
Date : 2021-12-10

Abstract:
This document updates the cipher suites in RFC 5425, Transport Layer
Security (TLS) Transport Mapping for Syslog, and RFC 6012, Datagram
Transport Layer Security (DTLS) Transport Mapping for Syslog. It
also updates the transport protocol in RFC 6012.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ciphersuites-in-sec-syslog/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ciphersuites-in-sec-syslog-00.html


Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org<mailto:I-D-Announce@ietf.org>
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt