Re: [TLS] [OPSEC] Call For Adoption: draft-wang-opsec-tls-proxy-bp
"Eric Wang (ejwang)" <ejwang@cisco.com> Fri, 31 July 2020 18:41 UTC
Return-Path: <ejwang@cisco.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DEE93A0CAB; Fri, 31 Jul 2020 11:41:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.619
X-Spam-Level:
X-Spam-Status: No, score=-9.619 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=LOo4N9Rb; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=WBb5Zsc/
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4_WPOJ8F_1-P; Fri, 31 Jul 2020 11:41:14 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EA7A3A0CA8; Fri, 31 Jul 2020 11:41:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6271; q=dns/txt; s=iport; t=1596220874; x=1597430474; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=eiS6tQr3kAs7zDW9wuJaLiyg70wBf6Jm+EUIBRFCBt0=; b=LOo4N9RbCcDyVlRYl1tU8cP+oijZWoJ2m6V3JWWai0UIuZ9R9zbZWur6 VEpT73WjOzuxDq2sG3kgyUno66JQFCNpKUTnULUFbGud/9MX7Zn5qJin6 Mof2m328i8/f82hZpQ+3oQIZM2QnjyWSPi1RaUt5aOFckZXT7WAKitmz4 g=;
IronPort-PHdr: 9a23:Kyr4XxWZf83KIsEfw3LmYhGYDKTV8LGuZFwc94YnhrRSc6+q45XlOgnF6O5wiEPSBNyHuf1BguvS9avnXD9I7ZWAtSUEd5pBH18AhN4NlgMtSMiCFQXgLfHsYiB7eaYKVFJs83yhd0QAHsH4ag7dp3Sz6XgZHRCsfQZwL/7+T4jVicn/3uuu+prVNgNPgjf1Yb57IBis6wvLscxDiop5IaF3wRzM8XY=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AHCgCuZCRf/4UNJK1gHQEBAQEJARIBBQUBggqBUlEHb1gvLAqEK4NGA40piiiJc4RsgUKBEQNVCwEBAQwBARgBCgoCBAEBhEwCF4IcAiQ4EwIDAQELAQEFAQEBAgEGBG2FXAyFcgIEAQEQCwYdAQEsCwEPAgEIBAoxAwICAh8GCxQRAQEEAQ0FIoMEAYF+TQMuAQ6mUAKBOYhhdoEygwEBAQWCSoJYDQuCDgMGgTiCcINfgQGBOYQFGoIAgTgMEIJNPoIaQgEBAoEoARIBIIMXM4ItknOGXZtwTgqCYJULhHkDHoJ7iUyTMJIjjRSOOYNWAgQCBAUCDgEBBYFqI2dwcBU7KgGCPj4SFwINjh+DcYUUhUJ0AjUCBgEHAQEDCXyPEgGBEAEB
X-IronPort-AV: E=Sophos;i="5.75,419,1589241600"; d="scan'208,217";a="805966194"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by rcdn-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 31 Jul 2020 18:41:13 +0000
Received: from XCH-RCD-005.cisco.com (xch-rcd-005.cisco.com [173.37.102.15]) by alln-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id 06VIfDkT011818 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Fri, 31 Jul 2020 18:41:13 GMT
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by XCH-RCD-005.cisco.com (173.37.102.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Fri, 31 Jul 2020 13:41:12 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Fri, 31 Jul 2020 13:41:12 -0500
Received: from NAM10-BN7-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Fri, 31 Jul 2020 13:41:12 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RoZff3FX5vB4gL45zq9OgVz26V1tkr1aKUCbyOWklf34o97V74uuVBTyPqqgP1Un2LIcxK4/plgus120EFcSJ9NecePqXijzgja5bO77HrlPVJGnMenvx8r1HGa1AF/YObyJMP8LAjy6or67JOtTQTSFXsdx27JbBDlOt7HRGFpg4W2Ws2TE8aHgHuJ+aBne1Xup/dI8enpiVXxlbPGrdxH4d2r8wizITwelgknFTE0jTv69qeCS0pDJjfaJpzdiYK+B8BG1jZmz5zWEnpnxVX0q0lcjCYO1dB58/61owRrkD0S0KepvtRL/NI1BsOHYHi2V1tOxFhybakHWYDtC8g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eiS6tQr3kAs7zDW9wuJaLiyg70wBf6Jm+EUIBRFCBt0=; b=WhfbG1qp5JgVdw8JUrHr+o9bQST1NNE/PNqvFbJKuNDMX15Q7en4k4KgXkkowk1DfRtDmK4kAlKVBv9u1PSk+sX1DfANcWtuOss3lLcUJju1c4+/OadXey77xTdLNRBOzVI34BdTu8Snv2ETwDNU+xe7/K40W2ACXnOo4huZIQvibx8l194DCGqVHAIq45Ilrt4tPiYuFMz1Gj6VeQdnDCsII6tOmnlUbsrWneLerg6SK0mPhVQSd/AMKyXIhZyBGQqQngt6sEkiy89bmHfBUiHdymwETFpf34FYkXYisgWrsBxx8QJcYuEK0J13NlFBSG9Il4jggvrc1zdXmYof9g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=eiS6tQr3kAs7zDW9wuJaLiyg70wBf6Jm+EUIBRFCBt0=; b=WBb5Zsc/DftRUJap7np0VOr8TJamSCAgNLblnZ71ek1vZXs59GKo4mz4JtHHzIYUTKNTRmKcGPPGjuNWUpfkV2EOgWmzexibKpdr7hG3Xu5a5od1YT3Uco1e/ezURD69UllyrJN0N5AavuWlfoL/EqyRnUvZC/4EmwjLnQIreKo=
Received: from BYAPR11MB2789.namprd11.prod.outlook.com (2603:10b6:a02:cc::11) by BYAPR11MB2789.namprd11.prod.outlook.com (2603:10b6:a02:cc::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3216.26; Fri, 31 Jul 2020 18:41:11 +0000
Received: from BYAPR11MB2789.namprd11.prod.outlook.com ([fe80::9913:ef92:7ce3:8870]) by BYAPR11MB2789.namprd11.prod.outlook.com ([fe80::9913:ef92:7ce3:8870%6]) with mapi id 15.20.3216.033; Fri, 31 Jul 2020 18:41:11 +0000
From: "Eric Wang (ejwang)" <ejwang@cisco.com>
To: Jen Linkova <furry13@gmail.com>, OPSEC <opsec@ietf.org>, "tls@ietf.org" <tls@ietf.org>
CC: OpSec Chairs <opsec-chairs@ietf.org>
Thread-Topic: [OPSEC] Call For Adoption: draft-wang-opsec-tls-proxy-bp
Thread-Index: AdZd8qs4MVhjKcpfSaSC3eC5PK0rEQCniF8AAbZWrwA=
Date: Fri, 31 Jul 2020 18:41:11 +0000
Message-ID: <F1A69FD6-9136-4830-8111-03C4C791C349@cisco.com>
References: <DM6PR05MB634890A51C4AF3CB1A03DA0BAE7A0@DM6PR05MB6348.namprd05.prod.outlook.com> <CAFU7BAS=ymUPTAGB_fOSrHTG0OajV1n5M1-yOBWxvGam-a89AA@mail.gmail.com>
In-Reply-To: <CAFU7BAS=ymUPTAGB_fOSrHTG0OajV1n5M1-yOBWxvGam-a89AA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3445.104.15)
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [128.107.241.168]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: e9bd908a-6bf9-4594-2429-08d835814c02
x-ms-traffictypediagnostic: BYAPR11MB2789:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <BYAPR11MB2789494A47ECCFB8E254B4CCD04E0@BYAPR11MB2789.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:6108;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 90YhlUZxQY18Ea/p1GwleKOnNfvAgPc+bSSaATRMs7/wO8NazzNsZ5L7klSymqZol6IVqVOgy1TvWqYhPEDuCccEM8bAmT27aHESLPtzur9PKiINr5nCjTm5x4AyN/jj84Y059KOaDfYKpHq4X8aas8Ky0H+epe1K68c/ns7N/Kd4eHiDCA897DOqnkS94ND+1A1xyIVHenePVVlEn/2PjYBNQ2uMjiuDfxxDpKDwsbXBdj5laenqfLpW7i/RJJIVq2FvjrSlUkQwIWOKjTQ6bqgeZpYt2GAsXmHO8QiIaSewbfhhfUreCcjVclVkKvS5pC/VDOvaT5gGqqi3dXba1WfYgPBuHMQIoWayfbrA2DqgLR3d6L/rstg0ONrY7oKkTKEj+AT4gf+Rx+XdRax9Q==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR11MB2789.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(136003)(39860400002)(366004)(396003)(346002)(376002)(86362001)(2906002)(8936002)(8676002)(316002)(4326008)(33656002)(36756003)(71200400001)(110136005)(53546011)(91956017)(64756008)(6486002)(66946007)(66446008)(966005)(66556008)(5660300002)(26005)(186003)(6512007)(6506007)(2616005)(478600001)(76116006)(66476007); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: CEWK1N0MtNFgBxgTBMN3ALq3Z7tIAW2Em4hxu55suXOkn+plsRD4kE/SlSNEtCpDSdQIYDSOuljc4IduWNeiBgnW55vftNrnkmaAEisJmVrDzVjaiwnpH8kdi3Acey/077/XmLKiGRCPkTNzpyWTqUKILvYMniPjka91D7ZXghs9Ae/dI6mlssGmpEzT5mVe1kWivcNJjBt2RVPlEcCagHRYSuuhpofoApgTVbCNfD0zek20xrsCafEBhTKthYSg4dMP93ktbA/rXGKE4CCb6gcAt7k/FPMpKXM0+dMOF5ndg6MiPa1/ooK4+E60H3oArbLDR/iSb0ZcHZ9BgM6oGl6q9akKW3zjEJ44+a3L7Y1QfXKNUfLQt1XcM+/DGwKNmXmAcZHxkvgCU2ya7b16QGkuFy1t8Tai9BSd9LqyMX7PUZ5LHChq2hR6RAOsAKAloY58mkWu8StrZq2ux8KUDgnrseSZWEJ139yOnesg2NtMZALJ/XkklTPItysplCSM
Content-Type: multipart/alternative; boundary="_000_F1A69FD691364830811103C4C791C349ciscocom_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR11MB2789.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: e9bd908a-6bf9-4594-2429-08d835814c02
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Jul 2020 18:41:11.2798 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: H8uXINiMGYL/2Pf5YgaYPfSePrMOg8ZuTCK7Wn7zft8skhgk8SuHsjaKp6SsdPYQPseB7IylO2ksk3czUKZTLw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB2789
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.15, xch-rcd-005.cisco.com
X-Outbound-Node: alln-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/tls/X6BaDZjjMgzmg_63eISOVAeWvxc>
Subject: Re: [TLS] [OPSEC] Call For Adoption: draft-wang-opsec-tls-proxy-bp
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 Jul 2020 18:41:17 -0000
As authors we appreciate all the constructive comments on the draft. Based on the feedback, we will revise the scope of the document to cover “plain” TLS proxy only (removing “selective proxying”). We will circulate a new revision when it is ready. Best, -Eric (on behalf of the authors) On Jul 22, 2020, at 6:30 PM, Jen Linkova <furry13@gmail.com<mailto:furry13@gmail.com>> wrote: One thing to add here: the chairs would like to hear active and explicit support of the adoption. So please speak up if you believe the draft is useful and the WG shall work on getting it published. On Mon, Jul 20, 2020 at 3:35 AM Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org<mailto:rbonica=40juniper.net@dmarc.ietf.org>> wrote: Folks, This email begins a Call For Adoption on draft-wang-opsec-tls-proxy-bp. Please send comments to opsec@ietf.org<mailto:opsec@ietf.org> by August 3, 2020. Ron Juniper Business Use Only _______________________________________________ OPSEC mailing list OPSEC@ietf.org<mailto:OPSEC@ietf.org> https://www.ietf.org/mailman/listinfo/opsec -- SY, Jen Linkova aka Furry _______________________________________________ OPSEC mailing list OPSEC@ietf.org<mailto:OPSEC@ietf.org> https://www.ietf.org/mailman/listinfo/opsec
- [TLS] Call For Adoption: draft-wang-opsec-tls-pro… Ron Bonica
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Jen Linkova
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Tobias Mayer (tmayer)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Nancy Cam-Winget (ncamwing)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Stephen Farrell
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Blumenthal, Uri - 0553 - MITLL
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Ira McDonald
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Stephen Farrell
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Nancy Cam-Winget (ncamwing)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Blumenthal, Uri - 0553 - MITLL
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Ben Schwartz
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Nick Harper
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Blumenthal, Uri - 0553 - MITLL
- Re: [TLS] [EXTERNAL] Re: [OPSEC] Call For Adoptio… Andrei Popov
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Roelof duToit
- Re: [TLS] [OPSEC] [EXTERNAL] Re: Call For Adoptio… Roelof duToit
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Stephen Farrell
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Roelof duToit
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Ashutosh Singh
- Re: [TLS] Call For Adoption: draft-wang-opsec-tls… Martin Thomson
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Arnaud.Taddei.IETF
- Re: [TLS] Call For Adoption: draft-wang-opsec-tls… Eric Rescorla
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… tom petch
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Watson Ladd
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Nick Harper
- Re: [TLS] Call For Adoption: draft-wang-opsec-tls… Rob Sayre
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Martin Thomson
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Stephen Farrell
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Rescorla
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Stephen Farrell
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Carrick Bartle
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Rescorla
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Rob Sayre
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Rob Sayre
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Paul Brears
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Töma Gavrichenkov
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Töma Gavrichenkov
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Töma Gavrichenkov
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Salz, Rich
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Töma Gavrichenkov
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Nick Harper
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Ben Smyth
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Eric Wang (ejwang)
- Re: [TLS] [OPSEC] Call For Adoption: draft-wang-o… Rob Sayre