Re: [v6ops] [saag] ITU-T SG17 IPv6 security work items liaison

Stephen Farrell <stephen.farrell@cs.tcd.ie> Tue, 14 June 2011 00:01 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C4ED321F8479; Mon, 13 Jun 2011 17:01:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.137
X-Spam-Level:
X-Spam-Status: No, score=-106.137 tagged_above=-999 required=5 tests=[AWL=-0.138, BAYES_00=-2.599, J_CHICKENPOX_13=0.6, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bF9AVgqOyG62; Mon, 13 Jun 2011 17:01:28 -0700 (PDT)
Received: from scss.tcd.ie (hermes.cs.tcd.ie [134.226.32.56]) by ietfa.amsl.com (Postfix) with ESMTP id C8A9321F8478; Mon, 13 Jun 2011 17:01:27 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by hermes.scss.tcd.ie (Postfix) with ESMTP id EADA1171C57; Tue, 14 Jun 2011 01:01:23 +0100 (IST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; h= content-transfer-encoding:content-type:in-reply-to:references :subject:mime-version:user-agent:from:date:message-id:received :received:x-virus-scanned; s=cs; t=1308009683; bh=5brO03To29fhYd a07P2lJXC4KlbotzYy3H/AyOFPMvI=; b=qZt/PET7ZAxj8DkKgTGHIbGJ9tTFzM LKMYDCrZHssLdzupGCVfsRd7F6o0i9OrdgEZgCXBQa5YPb14k/Cv/CaaAoGh5N0l BPrSZx4k+LxZnLdYQ9jQ2a4J0uAHW6s/+6G9RelCis4qK5goaj5htY1CUTjnC5O3 zW9tG/n7Ki513g1FWAVLDpdSK5fXpJpoiF6Y7zE0kL6wyBZEe1VXRiiI9yZea2gB 7Guc0YOoX+BgSvxsQdYj1Wfcmbm0fppenhd4WHrLnIuwoOxHt5g7CTueKATRBLPF 48lEEW+Jr0FFL+tAVKthdOAcKJOgVKo5rMWGQNcn57Za3tHhiWPN24mg==
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from scss.tcd.ie ([127.0.0.1]) by localhost (scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10027) with ESMTP id UIGQ1gVqZRlH; Tue, 14 Jun 2011 01:01:23 +0100 (IST)
Received: from [10.87.48.10] (unknown [86.42.18.245]) by smtp.scss.tcd.ie (Postfix) with ESMTPSA id 6417A171C2D; Tue, 14 Jun 2011 01:01:23 +0100 (IST)
Message-ID: <4DF6A4D2.9060306@cs.tcd.ie>
Date: Tue, 14 Jun 2011 01:01:22 +0100
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.17) Gecko/20110424 Lightning/1.0b2 Thunderbird/3.1.10
MIME-Version: 1.0
To: Russ Housley <housley@vigilsec.com>
References: <4DEA6323.4070302@cs.tcd.ie> <4DF69899.2050606@cs.tcd.ie> <D4359E14-EFD7-4780-9EB1-02F4AFF9A35D@vigilsec.com>
In-Reply-To: <D4359E14-EFD7-4780-9EB1-02F4AFF9A35D@vigilsec.com>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 8bit
Cc: v6ops@ietf.org, ipv6@ietf.org, "saag@ietf.org" <saag@ietf.org>
Subject: Re: [v6ops] [saag] ITU-T SG17 IPv6 security work items liaison
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jun 2011 00:01:28 -0000

Thanks Russ, will make those changes.
S.

On 14/06/11 00:57, Russ Housley wrote:
> Stephen:
> 
> Comments below.
> 
> Russ
> 
> 
>> From:  IETF Security Area
>> To: Study Group 17, Questions 2 and 3
>> Title: Work on Security of IPv6
>>
>> FOR ACTION
>>
>> The IETF thanks Study Group 17 for its liaison LS-206 "Liaison on IPv6
>> security issues".  As the world transitions to IPv6, new opportunities
>> and challenges and challenges arise.  SG17's new focus on deployment and
> 
> s/and challenges and challenges/and challenges/
> s/new//
> 
>> implementation considerations reflects this reality.   We would like to
>> bring to your attention the following work which we believe may prove a
>> useful basis for both X.ipv6-secguide and X.mgv6:
>>
>>    * RFC 4294 – "IPv6 Node Requirements" (N.B., this work is currently
>>      under revision)
> 
> Why not just reference the bis document?
> 
>>    * draft-ietf-6man-node-req-bis (work in progress) – "IPv6 Node
>>      Requirements RFC 4294-bis"
>>    * RFC 4864 – "Local Network Protection for IPv6"
>>    * RFC 6092 – "Recommended Simple Security Capabilities in Customer
>>      Premise Equipment (CPE) for Providing Residential IPv6 Internet
>>      Service"
>>    * RFC 6105 – "IPv6 Router Advertisement Guard"
>>    * RFC 6106 – "IPv6 Router Advertisement Options for DNS
>>      Configuration", §7 in particular.
>>
>> As you are aware, every RFC contains a Security Considerations section.
>> In developing either a implementation or deployment guide, contributors
>> are strongly encouraged to review the RFCs and Internet-Drafts that
>> support any underlying function.
>>
>> In addition, we bring to your attention the following IETF Working
>> Groups that are working on security-related work of IPv6:
>>
>> Working Group  Purpose                     Mailing list address
>> Name
>>
>> 6man           IPv6 Maintenance            ipv6@ietf.org
>> savi           Source Address Validation   savi@ietf.org
>>               Improvements
>> dhc            Dynamic Host Configuration  dhcwg@ietf.org
>> v6ops          IPv6 Operations             v6ops@ietf.org
>> opsec          Operational Security        opsec@ietf.org
>>               Capabilities for an IP
>>               Network
>>
>> In addition to the above working groups, the Security Area of the IETF
>> maintains a mailing list for general discussion, saag@ietf.org.  We
>> encourage and invite open and informal discussion in these or other
>> relevant IETF fora on this very important topic. As with all IETF
>> working groups, any and all interested parties can choose to directly
>> contribute via the mailing lists above.
>>
>> As in other areas, the Security Area of the IETF invites SG17 to bring
>> any new-found concerns about IETF protocols to our attention so that as
>> and when we revise our documents we can make appropriate amendments to
>> IETF protocols. In particular, as this planned work matures, we would
>> welcome hearing about it in more detail, perhaps via an invited
>> presentation at a saag meeting or via review of draft documents as may
>> be appropriate.
> 
>