
From nobody Wed Aug  3 07:53:35 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10A5212D1E7 for <dots@ietfa.amsl.com>; Wed,  3 Aug 2016 07:53:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.808
X-Spam-Level: 
X-Spam-Status: No, score=-15.808 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.287, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tQVsY3NMV5Ry for <dots@ietfa.amsl.com>; Wed,  3 Aug 2016 07:53:31 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B828912D5D0 for <dots@ietf.org>; Wed,  3 Aug 2016 07:53:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3186; q=dns/txt; s=iport; t=1470236001; x=1471445601; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=EtFVW/eQz0VOV1uiNJmE4VxikvVgQMJ6EZ+X3r9KnTE=; b=CcuIQz1YZUhkucZtLWU+TuDiVrS2ZrHoGJr7UESkdBEu8Am+OxgIFCao 1gYSZ+MXvXYRK4Hj9LoiMtDfJjO0HveA5WbVE8v27te9i+ZhcVhZ1juN3 t+hEWXvQQ4WYmw6l9HImRAM10sxKNYtY/Janomom5G3yZHy6E46Twv26D M=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0AsAgAwBKJX/4QNJK1cg0VWfAe5J4F9J?= =?us-ascii?q?IV5AoFLOBQBAQEBAQEBXSeEXgEBBAEBATg0FwQCAQgRAQMBAR8JBycLFAMGCAE?= =?us-ascii?q?BBAESCBOIDggOvkEBAQEBAQEBAQEBAQEBAQEBAQEBAQEXBYYqhE2EKoVxBY4Xh?= =?us-ascii?q?VqFQwGOd4FyhFuIeoZkhUyDdgEeNoN6boddfwEBAQ?=
X-IronPort-AV: E=Sophos;i="5.28,466,1464652800"; d="scan'208";a="131858588"
Received: from alln-core-10.cisco.com ([173.36.13.132]) by rcdn-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 03 Aug 2016 14:53:21 +0000
Received: from XCH-ALN-019.cisco.com (xch-aln-019.cisco.com [173.36.7.29]) by alln-core-10.cisco.com (8.14.5/8.14.5) with ESMTP id u73ErKWS018341 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 3 Aug 2016 14:53:20 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-019.cisco.com (173.36.7.29) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Wed, 3 Aug 2016 09:53:20 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Wed, 3 Aug 2016 09:53:20 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "Roman D. Danyliw" <rdd@cert.org>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: Feedback on draft-reddy-dots-transport-05
Thread-Index: AdHg2ONm9kzKOwTrQzS76ljpZPMKMAMvIYEg
Date: Wed, 3 Aug 2016 14:53:20 +0000
Message-ID: <37a87cc75feb41e49a501679056c280d@XCH-RCD-017.cisco.com>
References: <359EC4B99E040048A7131E0F4E113AFC0104E1A3A3@marathon>
In-Reply-To: <359EC4B99E040048A7131E0F4E113AFC0104E1A3A3@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.80.145]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/dSRwC2JG7wq9vXy4e9iaPPL4SWc>
Subject: Re: [Dots] Feedback on draft-reddy-dots-transport-05
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 03 Aug 2016 14:53:33 -0000

Hi Roman,

Thanks for the review. Please see inline for responses.

> -----Original Message-----
> From: Dots [mailto:dots-bounces@ietf.org] On Behalf Of Roman D. Danyliw
> Sent: Monday, July 18, 2016 6:33 PM
> To: dots@ietf.org
> Subject: [Dots] Feedback on draft-reddy-dots-transport-05
>=20
> Hello!
>=20
> WG chair hat off ...
>=20
> In reading through draft-reddy-dots-transport-05 I have the following
> feedback:
>=20
> (1) I'd recommend including language somewhere in the draft describing
> which set of use cases in the WG UC draft are satisfied.

Sure, will update.

>=20
> (2) Section 1, I'd recommend citing the reference to NETCONF.
>=20
> (3) Section 3, Solution Overview, enumerated list under paragraph two, I
> worry some of this text overlaps with the UC and architecture documents. =
 As
> it is a subset of what these other documents state, a reader might be con=
fused
> on how many use cases this protocol solves per my comment #1 above.

Agreed (this draft was written before architecture draft).=20
Removed enumerated list under paragraph two and referred to UC and architec=
ture documents.

>=20
> (4) Section 4, third sentence.  I'd recommend s/The DOTS client must know=
 a
> DOTS server's domain name/ The DOTS client MUST know a DOTS server's
> domain name/.
>=20
> (5) Section 5.1, second from last paragraph.  It's nit.  s/JSON [RFC7159]
> payloads is/JSON [RFC7159] payloads are/

Will update draft to address all the above comments.

>=20
> (6) Section 5.2.1, policy-id, In defining this policy-id, is that the sam=
e as a
> unique request id for each mitigation ?

Yes.

>=20
> (7) policy-id, Policy-id is defined as a "number".  Should it be "integer=
"?  Using
> a floating point number would seem unintuitive to use here.

Changed to Integer.

>=20
> (8) Section 5.2.1, target-ip, How should multiple IPs be specified?  Coul=
d a
> prefix be used?  Figure 6 helps, but IMO it should be formally specified.
>=20
> (9) Section 5.2.1, target-port, How should multiple ports be specified? F=
igure 6
> helps, but IMO it should be formally specified.

Yes, will formally specify formats for IP addresses, prefixes and ports.

>=20
> (10) Section 5.2.1, A reference to an "Empty Acknowledgement" is made.
> What is the format of such a message ?

Empty Acknowledgement is defined in CoAP, added reference.

>=20
> (11) Figure 9, There is a typo in the policy-data example, s/target-
> prtoocol/target-protocol/.
>=20
> (12) Section 7, I recommend citing the relevant drafts collectively refer=
enced
> as "(D)TLS RFCs".
>=20
> (13) Section 7, bullet #2, I recommend s/the DOTS client may want to
> probe/the DOTS client MAY probe/.

Fixed above comments.

>=20
> (14) Section 9, IANA Considerations.  I recommend creating IANA registrie=
s to
> maintain the enumerated values of fields like 'status' and 'attack-status=
'.  This
> would allow future extensibility.

Agreed, will update.

-Tiru

>=20
> Roman
>=20
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots


From nobody Sun Aug  7 23:46:12 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3ED9F127058 for <dots@ietfa.amsl.com>; Sun,  7 Aug 2016 23:46:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.768
X-Spam-Level: 
X-Spam-Status: No, score=-15.768 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id upTjiptxtOFG for <dots@ietfa.amsl.com>; Sun,  7 Aug 2016 23:46:09 -0700 (PDT)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1C57120727 for <dots@ietf.org>; Sun,  7 Aug 2016 23:46:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5753; q=dns/txt; s=iport; t=1470638769; x=1471848369; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=BKQDPLhSSQnGGFIzHkybDIo/KU5YzS16V2kjULZbbSM=; b=KBM4VQ5QQ4IkTRpn7dqmgF52P58e9MSXiJDnmHhUPVnSF9+QcOKj0802 hVSh06pzxamd5fqk88mcscV4/wTd65A9WEokP3UlfTvVHwLsZx5i6PhtM Gh0Yq2GY3V6yx2QNUmz8UjRVJjmxejw90+qzbZw+/lhgcJC+thM4i/BC+ A=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0BXAgCQKahX/4YNJK1dg0VWfAe5CIF9J?= =?us-ascii?q?IV5AoExOBQBAQEBAQEBXSeEXgEBBAEBATg0CQcHBAIBCBEEAQEBHgkHJwsUCAE?= =?us-ascii?q?IAgQBEgiIIQgOwlYBAQEBAQEBAQEBAQEBAQEBAQEBAQEchiqETYQcAQ2FcQWOG?= =?us-ascii?q?IVdhUQBhhyIZoFyToQNiH2GZIVQg3cBHjaCEhyBTG6FegElIH8BAQE?=
X-IronPort-AV: E=Sophos;i="5.28,488,1464652800"; d="scan'208";a="137387763"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by rcdn-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 08 Aug 2016 06:46:08 +0000
Received: from XCH-ALN-020.cisco.com (xch-aln-020.cisco.com [173.36.7.30]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id u786k8Hb023518 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 8 Aug 2016 06:46:08 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-020.cisco.com (173.36.7.30) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Mon, 8 Aug 2016 01:46:07 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Mon, 8 Aug 2016 01:46:07 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: kaname nishizuka <kaname@nttv6.jp>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] FW: New Version Notification for draft-reddy-dots-transport-05.txt
Thread-Index: AQHR11jVVEDsCwAAOkiBthaVHADSf6ALBdQQgBlqbACAGkrkcA==
Date: Mon, 8 Aug 2016 06:46:07 +0000
Message-ID: <f00f640674e24663ac738f759898bc2e@XCH-RCD-017.cisco.com>
References: <20160706073427.7900.59549.idtracker@ietfa.amsl.com> <50de5af611944788898536433cc1dfbd@XCH-RCD-017.cisco.com> <e5c1665f-4a5b-dc52-602f-66aab2e310d6@nttv6.jp>
In-Reply-To: <e5c1665f-4a5b-dc52-602f-66aab2e310d6@nttv6.jp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.93.112]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/Y9RVgzeBarZoIWr9CFSJ-CdW-58>
Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-transport-05.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Aug 2016 06:46:11 -0000

Hi Kaname,

Yes, DOTS data channel should also cover pre-provisioning. As per our discu=
ssion at IETF, will remove DOTS channel from this draft, and create a new d=
raft and pick specific sections and JSON attributes from draft-nishizuka-do=
ts-inter-domain-mechanism and include pre-provisioning.=20

Please see inline

> -----Original Message-----
> From: kaname nishizuka [mailto:kaname@nttv6.jp]
> Sent: Friday, July 22, 2016 12:22 PM
> To: Tirumaleswar Reddy (tireddy) <tireddy@cisco.com>; dots@ietf.org
> Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-
> transport-05.txt
>=20
> Hi Tiru,
>=20
> I have a comment on section 6.  DOTS Data Channel.
>=20
>   * Data channel is for bulk data exchanges
>   * Rough Consensus @ Design Team Meeting: Data channel is for pre-
> provisioning

Yup.

>=20
> I think we need 2 types of filtering.
> 1. filtering which limit the scope of mitigation
>   * example
>       - if an organization have other sites from which only legitimate tr=
affic in
> coming and is afraid of false positive, the sites should be treated as a
> exception of mitigation with white-list.

Yes, white-list rules can also be created using the DOTS data channel discu=
ssed in the draft (see traffic-rate attribute defined in DOTS data channel)=
.=20

>       - if a service is working only on port 80, traffic destined to othe=
r port can
> be dropped without any consideration.

Yes, the above rule can also be provisioned during peacetime using the DOTS=
 data channel proposed in the draft.

>   * this type of filtering may be installed in pre-provisioning phase (on=
 data
> channel)
>        - can be changed even while it is under attack

What is the use case for changing these type of filters during the attack ?

>=20
>   Also there should be a limitation on a request
>   * requests from DOTS clients should be limited

It's an implementation detail, what do you suggest needs to be discussed in=
 this draft ?

>       - request for blocking, rate-limiting, etc.. can be another attack =
vector if the
> request is spoofed.

DOTS client has to authenticate to the DOTS server, how will DOTS requests =
be spoofed ?

>       - limitation on possible range of target (=3DIP addresses/prefixes)=
 should be
> pre-defined per customer basis.
>       - installed in pre-provisioning phase (on data channel)

Agreed.

>=20
>   [note]:this filtering is required without regard to protection methods

I did not get the above line, please clarify.

>=20
> 2. filtering instruction for mitigation
>   * filtering of traffic is one of protection methods taken by mitigators

Okay.

>   * DOTS client can request filtering of traffic with desired action (blo=
cking,
> rate-limiting...)
>   * instructed while it is under attack (on signaling channel)

DOTS signaling channel does not signal filtering rules, it's the job of DOT=
S data channel.

>=20
> Data model of Filtering Rules described in section 6 (DOTS Data Channel)
> looks like type 2 of filtering.

No, Filtering rules can be provisioned either before or during the attack.
I will update the draft to clarify, currently the draft is only high-lighti=
ng the example of black-list rules provisioned during an attack.

-Tiru

> So I think it looks like for signaling channel.
>=20
>=20
> best regards,
> kaname nishizuka
>=20
>=20
> On 2016/07/06 9:46, Tirumaleswar Reddy (tireddy) wrote:
> > Added new section https://tools.ietf.org/html/draft-reddy-dots-transpor=
t-
> 05#section-8 to discuss about mutual authentication of DOTS Agents &
> authorization of DOTS clients. Comments and suggestions are welcome.
> >
> > Cheers,
> > -Tiru
> >
> > -----Original Message-----
> > From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> > Sent: Wednesday, July 06, 2016 1:04 PM
> > To: Prashanth Patil (praspati); Dan Wing (dwing); Mike Geller
> > (mgeller); Robert Moskowitz; Mohamed Boucadair; Tirumaleswar Reddy
> > (tireddy)
> > Subject: New Version Notification for
> > draft-reddy-dots-transport-05.txt
> >
> >
> > A new version of I-D, draft-reddy-dots-transport-05.txt has been
> > successfully submitted by Tirumaleswar Reddy and posted to the IETF
> > repository.
> >
> > Name:		draft-reddy-dots-transport
> > Revision:	05
> > Title:		Co-operative DDoS Mitigation
> > Document date:	2016-07-06
> > Group:		Individual Submission
> > Pages:		26
> > URL:            https://www.ietf.org/internet-drafts/draft-reddy-dots-t=
ransport-
> 05.txt
> > Status:         https://datatracker.ietf.org/doc/draft-reddy-dots-trans=
port/
> > Htmlized:       https://tools.ietf.org/html/draft-reddy-dots-transport-=
05
> > Diff:           https://www.ietf.org/rfcdiff?url2=3Ddraft-reddy-dots-tr=
ansport-05
> >
> > Abstract:
> >     This document specifies a mechanism that a DOTS client can use to
> >     signal that a network is under a Distributed Denial-of-Service (DDo=
S)
> >     attack to an upstream DOTS server so that appropriate mitigation
> >     actions are undertaken (including, blackhole, drop, rate-limit, or
> >     add to watch list) on the suspect traffic.  The document specifies
> >     both DOTS signal and data channels.  Happy Eyeballs considerations
> >     for the DOTS signal channel are also elaborated.
> >
> >
> >
> >
> > Please note that it may take a couple of minutes from the time of
> > submission until the htmlized version and diff are available at tools.i=
etf.org.
> >
> > The IETF Secretariat
> >
> > _______________________________________________
> > Dots mailing list
> > Dots@ietf.org
> > https://www.ietf.org/mailman/listinfo/dots


From nobody Mon Aug  8 08:06:09 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E9AD712D62C for <dots@ietfa.amsl.com>; Mon,  8 Aug 2016 08:06:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.768
X-Spam-Level: 
X-Spam-Status: No, score=-15.768 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G-H5fvxJizPt for <dots@ietfa.amsl.com>; Mon,  8 Aug 2016 08:06:06 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C9D4A128E19 for <dots@ietf.org>; Mon,  8 Aug 2016 08:06:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2636; q=dns/txt; s=iport; t=1470668766; x=1471878366; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=HW0HRKViNjVk8e7lNjZoXDiG5VSVfXHTlMraMUno0uI=; b=MSJIbjExURYAuX6QQZ8i//WiEdFrm6f8bgh0SefpTGs+P2aqQ2EowCGg L+qrNLlXe/GMHfBIRcQ4o5b7Hitp84TejKfKYyvhxjIzx1YZezQW1f/sk lWrJ1WEyIhwD/rj40iXTcO5AN9eIRwg/KdhPpc5ukJiQ6mlHYhWBhkJ5B E=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0ATAgA8n6hX/51dJa1dg0VWfAe5DIF9J?= =?us-ascii?q?IV5AhyBIDgUAQEBAQEBAV0cC4ReAQEFIxFDDgQCAQgRBAEBAwIjAwICAjAUAQg?= =?us-ascii?q?IAgQTCIgpDrIckBYBAQEBAQEBAQEBAQEBAQEBAQEBAQEcgQGFKYRNhB0NgxeCW?= =?us-ascii?q?gWOGIshAYYciGaBck6EDYh9jDSDdwEeNoN6boYbRX8BAQE?=
X-IronPort-AV: E=Sophos;i="5.28,490,1464652800"; d="scan'208";a="135365815"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 08 Aug 2016 15:06:05 +0000
Received: from XCH-ALN-016.cisco.com (xch-aln-016.cisco.com [173.36.7.26]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id u78F65g2003690 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dots@ietf.org>; Mon, 8 Aug 2016 15:06:06 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-016.cisco.com (173.36.7.26) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Mon, 8 Aug 2016 10:06:05 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Mon, 8 Aug 2016 10:06:05 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-reddy-dots-transport-06.txt
Thread-Index: AQHR8YXg8D9eQLMsxkCiMoMtto+9GKA/KYkQ
Date: Mon, 8 Aug 2016 15:06:04 +0000
Message-ID: <c910ccd581a3485c9061dd1c07aee356@XCH-RCD-017.cisco.com>
References: <147066851767.23073.16383945391467733518.idtracker@ietfa.amsl.com>
In-Reply-To: <147066851767.23073.16383945391467733518.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.70.79]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/NeF_iIL_xleiMIvaeG-6TB0sU8U>
Subject: Re: [Dots] New Version Notification for draft-reddy-dots-transport-06.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Aug 2016 15:06:08 -0000

VGhpcyByZXZpc2lvbiBhZGRyZXNzZXMgY29tbWVudHMgZnJvbSBSb21hbi4gQ29tbWVudHMgYW5k
IHN1Z2dlc3Rpb25zIGFyZSB3ZWxjb21lLiANCg0KLVRpcnUNCg0KPiAtLS0tLU9yaWdpbmFsIE1l
c3NhZ2UtLS0tLQ0KPiBGcm9tOiBpbnRlcm5ldC1kcmFmdHNAaWV0Zi5vcmcgW21haWx0bzppbnRl
cm5ldC1kcmFmdHNAaWV0Zi5vcmddDQo+IFNlbnQ6IE1vbmRheSwgQXVndXN0IDgsIDIwMTYgODoz
MiBQTQ0KPiBUbzogUHJhc2hhbnRoIFBhdGlsIChwcmFzcGF0aSkgPHByYXNwYXRpQGNpc2NvLmNv
bT47IE1pa2UgR2VsbGVyIChtZ2VsbGVyKQ0KPiA8bWdlbGxlckBjaXNjby5jb20+OyBNb2hhbWVk
IEJvdWNhZGFpcg0KPiA8bW9oYW1lZC5ib3VjYWRhaXJAb3JhbmdlLmNvbT47IFRpcnVtYWxlc3dh
ciBSZWRkeSAodGlyZWRkeSkNCj4gPHRpcmVkZHlAY2lzY28uY29tPjsgRGFuIFdpbmcgKGR3aW5n
KSA8ZHdpbmdAY2lzY28uY29tPg0KPiBTdWJqZWN0OiBOZXcgVmVyc2lvbiBOb3RpZmljYXRpb24g
Zm9yIGRyYWZ0LXJlZGR5LWRvdHMtdHJhbnNwb3J0LTA2LnR4dA0KPiANCj4gDQo+IEEgbmV3IHZl
cnNpb24gb2YgSS1ELCBkcmFmdC1yZWRkeS1kb3RzLXRyYW5zcG9ydC0wNi50eHQgaGFzIGJlZW4g
c3VjY2Vzc2Z1bGx5DQo+IHN1Ym1pdHRlZCBieSBUaXJ1bWFsZXN3YXIgUmVkZHkgYW5kIHBvc3Rl
ZCB0byB0aGUgSUVURiByZXBvc2l0b3J5Lg0KPiANCj4gTmFtZToJCWRyYWZ0LXJlZGR5LWRvdHMt
dHJhbnNwb3J0DQo+IFJldmlzaW9uOgkwNg0KPiBUaXRsZToJCUNvLW9wZXJhdGl2ZSBERG9TIE1p
dGlnYXRpb24NCj4gRG9jdW1lbnQgZGF0ZToJMjAxNi0wOC0wOA0KPiBHcm91cDoJCUluZGl2aWR1
YWwgU3VibWlzc2lvbg0KPiBQYWdlczoJCTI5DQo+IFVSTDogICAgICAgICAgICBodHRwczovL3d3
dy5pZXRmLm9yZy9pbnRlcm5ldC1kcmFmdHMvZHJhZnQtcmVkZHktZG90cy10cmFuc3BvcnQtDQo+
IDA2LnR4dA0KPiBTdGF0dXM6ICAgICAgICAgaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9k
b2MvZHJhZnQtcmVkZHktZG90cy10cmFuc3BvcnQvDQo+IEh0bWxpemVkOiAgICAgICBodHRwczov
L3Rvb2xzLmlldGYub3JnL2h0bWwvZHJhZnQtcmVkZHktZG90cy10cmFuc3BvcnQtMDYNCj4gRGlm
ZjogICAgICAgICAgIGh0dHBzOi8vd3d3LmlldGYub3JnL3JmY2RpZmY/dXJsMj1kcmFmdC1yZWRk
eS1kb3RzLXRyYW5zcG9ydC0wNg0KPiANCj4gQWJzdHJhY3Q6DQo+ICAgIFRoaXMgZG9jdW1lbnQg
c3BlY2lmaWVzIGEgbWVjaGFuaXNtIHRoYXQgYSBET1RTIGNsaWVudCBjYW4gdXNlIHRvDQo+ICAg
IHNpZ25hbCB0aGF0IGEgbmV0d29yayBpcyB1bmRlciBhIERpc3RyaWJ1dGVkIERlbmlhbC1vZi1T
ZXJ2aWNlIChERG9TKQ0KPiAgICBhdHRhY2sgdG8gYW4gdXBzdHJlYW0gRE9UUyBzZXJ2ZXIgc28g
dGhhdCBhcHByb3ByaWF0ZSBtaXRpZ2F0aW9uDQo+ICAgIGFjdGlvbnMgYXJlIHVuZGVydGFrZW4g
KGluY2x1ZGluZywgYmxhY2tob2xlLCBkcm9wLCByYXRlLWxpbWl0LCBvcg0KPiAgICBhZGQgdG8g
d2F0Y2ggbGlzdCkgb24gdGhlIHN1c3BlY3QgdHJhZmZpYy4gIFRoZSBkb2N1bWVudCBzcGVjaWZp
ZXMNCj4gICAgYm90aCBET1RTIHNpZ25hbCBhbmQgZGF0YSBjaGFubmVscy4gIEhhcHB5IEV5ZWJh
bGxzIGNvbnNpZGVyYXRpb25zDQo+ICAgIGZvciB0aGUgRE9UUyBzaWduYWwgY2hhbm5lbCBhcmUg
YWxzbyBlbGFib3JhdGVkLg0KPiANCj4gDQo+IA0KPiANCj4gUGxlYXNlIG5vdGUgdGhhdCBpdCBt
YXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZyb20gdGhlIHRpbWUgb2Ygc3VibWlzc2lvbg0K
PiB1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQgZGlmZiBhcmUgYXZhaWxhYmxlIGF0IHRv
b2xzLmlldGYub3JnLg0KPiANCj4gVGhlIElFVEYgU2VjcmV0YXJpYXQNCg0K


From nobody Thu Aug 18 03:02:08 2016
Return-Path: <kaname@nttv6.jp>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B92C112D8AB for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 03:02:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.149
X-Spam-Level: 
X-Spam-Status: No, score=-3.149 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-1.247, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uAyhXSpd9kKw for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 03:02:02 -0700 (PDT)
Received: from guri.nttv6.jp (guri.nttv6.jp [IPv6:2402:c800:ff06:a::4]) by ietfa.amsl.com (Postfix) with ESMTP id 7B1D112D8A8 for <dots@ietf.org>; Thu, 18 Aug 2016 03:02:02 -0700 (PDT)
Received: from z.nttv6.jp (z.nttv6.jp [IPv6:2402:c800:ff06:6::f]) by guri.nttv6.jp (NTTv6MTA) with ESMTP id BE8604E67D; Thu, 18 Aug 2016 19:02:00 +0900 (JST)
Received: from SR2-nishizuka.local (fujiko.nttv6.jp [IPv6:2402:c800:ff06:136::141]) by z.nttv6.jp (NTTv6MTA) with ESMTP id AC2C73AC83; Thu, 18 Aug 2016 19:02:00 +0900 (JST)
To: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>, "dots@ietf.org" <dots@ietf.org>
References: <20160706073427.7900.59549.idtracker@ietfa.amsl.com> <50de5af611944788898536433cc1dfbd@XCH-RCD-017.cisco.com> <e5c1665f-4a5b-dc52-602f-66aab2e310d6@nttv6.jp> <f00f640674e24663ac738f759898bc2e@XCH-RCD-017.cisco.com>
From: kaname nishizuka <kaname@nttv6.jp>
Message-ID: <0cc9e275-8cfa-b172-1cae-11b79e7c84fb@nttv6.jp>
Date: Thu, 18 Aug 2016 19:02:02 +0900
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
In-Reply-To: <f00f640674e24663ac738f759898bc2e@XCH-RCD-017.cisco.com>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/rFdZ2GIag4UTwByNuwHQGlhOCx4>
Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-transport-05.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Aug 2016 10:02:06 -0000

Hi Tiru,


On 2016/08/08 15:46, Tirumaleswar Reddy (tireddy) wrote:
> Hi Kaname,
>
> Yes, DOTS data channel should also cover pre-provisioning. As per our discussion at IETF, will remove DOTS channel from this draft, and create a new draft and pick specific sections and JSON attributes from draft-nishizuka-dots-inter-domain-mechanism and include pre-provisioning.
OK, That's great.

> Please see inline
>
>> -----Original Message-----
>> From: kaname nishizuka [mailto:kaname@nttv6.jp]
>> Sent: Friday, July 22, 2016 12:22 PM
>> To: Tirumaleswar Reddy (tireddy) <tireddy@cisco.com>; dots@ietf.org
>> Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-
>> transport-05.txt
>>
>> Hi Tiru,
>>
>> I have a comment on section 6.  DOTS Data Channel.
>>
>>    * Data channel is for bulk data exchanges
>>    * Rough Consensus @ Design Team Meeting: Data channel is for pre-
>> provisioning
> Yup.
>
>> I think we need 2 types of filtering.
>> 1. filtering which limit the scope of mitigation
>>    * example
>>        - if an organization have other sites from which only legitimate traffic in
>> coming and is afraid of false positive, the sites should be treated as a
>> exception of mitigation with white-list.
> Yes, white-list rules can also be created using the DOTS data channel discussed in the draft (see traffic-rate attribute defined in DOTS data channel).
>
>>        - if a service is working only on port 80, traffic destined to other port can
>> be dropped without any consideration.
> Yes, the above rule can also be provisioned during peacetime using the DOTS data channel proposed in the draft.
>
>>    * this type of filtering may be installed in pre-provisioning phase (on data
>> channel)
>>         - can be changed even while it is under attack
> What is the use case for changing these type of filters during the attack ?
One, human make mistakes.
Two, white-list type of filtering rule could need to be more specific in order to filter out the attack more precisely.


>>    Also there should be a limitation on a request
>>    * requests from DOTS clients should be limited
> It's an implementation detail, what do you suggest needs to be discussed in this draft ?
OK, it's an implementation detail.
I just wanted to point out that the DOTS server should not accept all of the filtering request from the DOTS client without checking the CIDR block of the DOTS clients' domain.

>>        - request for blocking, rate-limiting, etc.. can be another attack vector if the
>> request is spoofed.
> DOTS client has to authenticate to the DOTS server, how will DOTS requests be spoofed ?
As described above, the DOTS client can spoof the prefixes of filtering request (not the DOTS client's address itself) in order to block traffic not to its domain but to other organization.

>>        - limitation on possible range of target (=IP addresses/prefixes) should be
>> pre-defined per customer basis.
>>        - installed in pre-provisioning phase (on data channel)
>> 	
> Agreed.
>
>>    [note]:this filtering is required without regard to protection methods
> I did not get the above line, please clarify.
It was meant to say that "The range of target (=IP addresses/prefixes) in the requests from DOTS clients should be checked by DOTS server. It is independent of the protection methods the DOTS server will take."


>> 2. filtering instruction for mitigation
>>    * filtering of traffic is one of protection methods taken by mitigators
> Okay.
>
>>    * DOTS client can request filtering of traffic with desired action (blocking,
>> rate-limiting...)
>>    * instructed while it is under attack (on signaling channel)
> DOTS signaling channel does not signal filtering rules, it's the job of DOTS data channel.
>
>> Data model of Filtering Rules described in section 6 (DOTS Data Channel)
>> looks like type 2 of filtering.
> No, Filtering rules can be provisioned either before or during the attack.
> I will update the draft to clarify, currently the draft is only high-lighting the example of black-list rules provisioned during an attack.
Okay, I'll see that.

regards,
kaname

> -Tiru
>
>> So I think it looks like for signaling channel.
>>
>>
>> best regards,
>> kaname nishizuka
>>
>>
>> On 2016/07/06 9:46, Tirumaleswar Reddy (tireddy) wrote:
>>> Added new section https://tools.ietf.org/html/draft-reddy-dots-transport-
>> 05#section-8 to discuss about mutual authentication of DOTS Agents &
>> authorization of DOTS clients. Comments and suggestions are welcome.
>>> Cheers,
>>> -Tiru
>>>
>>> -----Original Message-----
>>> From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
>>> Sent: Wednesday, July 06, 2016 1:04 PM
>>> To: Prashanth Patil (praspati); Dan Wing (dwing); Mike Geller
>>> (mgeller); Robert Moskowitz; Mohamed Boucadair; Tirumaleswar Reddy
>>> (tireddy)
>>> Subject: New Version Notification for
>>> draft-reddy-dots-transport-05.txt
>>>
>>>
>>> A new version of I-D, draft-reddy-dots-transport-05.txt has been
>>> successfully submitted by Tirumaleswar Reddy and posted to the IETF
>>> repository.
>>>
>>> Name:		draft-reddy-dots-transport
>>> Revision:	05
>>> Title:		Co-operative DDoS Mitigation
>>> Document date:	2016-07-06
>>> Group:		Individual Submission
>>> Pages:		26
>>> URL:            https://www.ietf.org/internet-drafts/draft-reddy-dots-transport-
>> 05.txt
>>> Status:         https://datatracker.ietf.org/doc/draft-reddy-dots-transport/
>>> Htmlized:       https://tools.ietf.org/html/draft-reddy-dots-transport-05
>>> Diff:           https://www.ietf.org/rfcdiff?url2=draft-reddy-dots-transport-05
>>>
>>> Abstract:
>>>      This document specifies a mechanism that a DOTS client can use to
>>>      signal that a network is under a Distributed Denial-of-Service (DDoS)
>>>      attack to an upstream DOTS server so that appropriate mitigation
>>>      actions are undertaken (including, blackhole, drop, rate-limit, or
>>>      add to watch list) on the suspect traffic.  The document specifies
>>>      both DOTS signal and data channels.  Happy Eyeballs considerations
>>>      for the DOTS signal channel are also elaborated.
>>>
>>>
>>>
>>>
>>> Please note that it may take a couple of minutes from the time of
>>> submission until the htmlized version and diff are available at tools.ietf.org.
>>>
>>> The IETF Secretariat
>>>
>>> _______________________________________________
>>> Dots mailing list
>>> Dots@ietf.org
>>> https://www.ietf.org/mailman/listinfo/dots


From nobody Thu Aug 18 03:40:48 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BAA1112D916 for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 03:40:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.768
X-Spam-Level: 
X-Spam-Status: No, score=-15.768 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z3gNN363nyqo for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 03:40:45 -0700 (PDT)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5426412D90E for <dots@ietf.org>; Thu, 18 Aug 2016 03:40:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=7922; q=dns/txt; s=iport; t=1471516845; x=1472726445; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=UJ4mMIQMQ744/qKy0u3oD0uOyry6uAVgYmsrWOLzsJQ=; b=VS9wKHcR3eVjOo7NwmGSYyz/yps0/GaEB23inp9eYE2jv1oTXyaYwokg +NJDmNhKEbUvmp1L62f4LzZDaRosAnqvEQuZHtGytNzjAl6J4h8A+GrNs 6L4+Ds8JfiGID8PEA8JiDJbmXA9x2WSdVFLQujgCkEVMoz6N6fo96MVdK U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0A/AgDij7VX/51dJa1eg0NWfAe3V4F9J?= =?us-ascii?q?oV3AoFqOBQCAQEBAQEBAV4nhF4BAQUBATg0CQ4EAgEIEQEDAQEBHgkHJwsUAwU?= =?us-ascii?q?BCAIEARIIiCkOvDgBAQEBAQEBAQEBAQEBAQEBAQEBAQEchiqDSoEDhBwBDYVxB?= =?us-ascii?q?Y4dhWCFRwGGH4J/hXiBck6EDokChmeFVIN3AR42ghIcgUxuAQGFZgElIH8BAQE?=
X-IronPort-AV: E=Sophos;i="5.28,539,1464652800"; d="scan'208";a="141830530"
Received: from rcdn-core-6.cisco.com ([173.37.93.157]) by rcdn-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 18 Aug 2016 10:40:40 +0000
Received: from XCH-ALN-016.cisco.com (xch-aln-016.cisco.com [173.36.7.26]) by rcdn-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id u7IAeeRv029243 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 18 Aug 2016 10:40:40 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-016.cisco.com (173.36.7.26) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Thu, 18 Aug 2016 05:40:39 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Thu, 18 Aug 2016 05:40:39 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: kaname nishizuka <kaname@nttv6.jp>, "dots@ietf.org" <dots@ietf.org>
Thread-Topic: [Dots] FW: New Version Notification for draft-reddy-dots-transport-05.txt
Thread-Index: AQHR11jVVEDsCwAAOkiBthaVHADSf6ALBdQQgBlqbACAGkrkcIAQWR0A//+yUQA=
Date: Thu, 18 Aug 2016 10:40:39 +0000
Message-ID: <ee626821b8bf4f2a8109184d26b985db@XCH-RCD-017.cisco.com>
References: <20160706073427.7900.59549.idtracker@ietfa.amsl.com> <50de5af611944788898536433cc1dfbd@XCH-RCD-017.cisco.com> <e5c1665f-4a5b-dc52-602f-66aab2e310d6@nttv6.jp> <f00f640674e24663ac738f759898bc2e@XCH-RCD-017.cisco.com> <0cc9e275-8cfa-b172-1cae-11b79e7c84fb@nttv6.jp>
In-Reply-To: <0cc9e275-8cfa-b172-1cae-11b79e7c84fb@nttv6.jp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.56.209]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/JUEhYEl3TXtpetZ3Ly6usE2gis0>
Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-transport-05.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Aug 2016 10:40:48 -0000

Hi Kaname,

Please see inline

> -----Original Message-----
> From: kaname nishizuka [mailto:kaname@nttv6.jp]
> Sent: Thursday, August 18, 2016 3:32 PM
> To: Tirumaleswar Reddy (tireddy) <tireddy@cisco.com>; dots@ietf.org
> Subject: Re: [Dots] FW: New Version Notification for draft-reddy-dots-
> transport-05.txt
>=20
> Hi Tiru,
>=20
>=20
> On 2016/08/08 15:46, Tirumaleswar Reddy (tireddy) wrote:
> > Hi Kaname,
> >
> > Yes, DOTS data channel should also cover pre-provisioning. As per our
> discussion at IETF, will remove DOTS channel from this draft, and create =
a new
> draft and pick specific sections and JSON attributes from draft-nishizuka=
-dots-
> inter-domain-mechanism and include pre-provisioning.
> OK, That's great.
>=20
> > Please see inline
> >
> >> -----Original Message-----
> >> From: kaname nishizuka [mailto:kaname@nttv6.jp]
> >> Sent: Friday, July 22, 2016 12:22 PM
> >> To: Tirumaleswar Reddy (tireddy) <tireddy@cisco.com>; dots@ietf.org
> >> Subject: Re: [Dots] FW: New Version Notification for
> >> draft-reddy-dots- transport-05.txt
> >>
> >> Hi Tiru,
> >>
> >> I have a comment on section 6.  DOTS Data Channel.
> >>
> >>    * Data channel is for bulk data exchanges
> >>    * Rough Consensus @ Design Team Meeting: Data channel is for pre-
> >> provisioning
> > Yup.
> >
> >> I think we need 2 types of filtering.
> >> 1. filtering which limit the scope of mitigation
> >>    * example
> >>        - if an organization have other sites from which only
> >> legitimate traffic in coming and is afraid of false positive, the
> >> sites should be treated as a exception of mitigation with white-list.
> > Yes, white-list rules can also be created using the DOTS data channel
> discussed in the draft (see traffic-rate attribute defined in DOTS data c=
hannel).
> >
> >>        - if a service is working only on port 80, traffic destined to
> >> other port can be dropped without any consideration.
> > Yes, the above rule can also be provisioned during peacetime using the
> DOTS data channel proposed in the draft.
> >
> >>    * this type of filtering may be installed in pre-provisioning
> >> phase (on data
> >> channel)
> >>         - can be changed even while it is under attack
> > What is the use case for changing these type of filters during the atta=
ck ?
> One, human make mistakes.
> Two, white-list type of filtering rule could need to be more specific in =
order to
> filter out the attack more precisely.

Okay, but it may not be possible to setup and exchange bulk-data using DOTS=
 data channel during a DDOS attack.

>=20
>=20
> >>    Also there should be a limitation on a request
> >>    * requests from DOTS clients should be limited
> > It's an implementation detail, what do you suggest needs to be discusse=
d in
> this draft ?
> OK, it's an implementation detail.
> I just wanted to point out that the DOTS server should not accept all of =
the
> filtering request from the DOTS client without checking the CIDR block of=
 the
> DOTS clients' domain.

Yes, the mechanism for enforcement is not in the scope of this doc. DOTS se=
rvers can use pre-provisioning as part of the configuration for the custome=
r or can also use dynamic mechanisms like RPKI.
It's already covered in the architecture doc (https://tools.ietf.org/html/d=
raft-ietf-dots-architecture-00#section-2.2.2).=20

>=20
> >>        - request for blocking, rate-limiting, etc.. can be another
> >> attack vector if the request is spoofed.
> > DOTS client has to authenticate to the DOTS server, how will DOTS reque=
sts
> be spoofed ?
> As described above, the DOTS client can spoof the prefixes of filtering r=
equest
> (not the DOTS client's address itself) in order to block traffic not to i=
ts domain
> but to other organization.
>=20
> >>        - limitation on possible range of target (=3DIP
> >> addresses/prefixes) should be pre-defined per customer basis.
> >>        - installed in pre-provisioning phase (on data channel)
> >>
> > Agreed.
> >
> >>    [note]:this filtering is required without regard to protection
> >> methods
> > I did not get the above line, please clarify.
> It was meant to say that "The range of target (=3DIP addresses/prefixes) =
in the
> requests from DOTS clients should be checked by DOTS server. It is
> independent of the protection methods the DOTS server will take."

Got it.

Cheers,
-Tiru

>=20
>=20
> >> 2. filtering instruction for mitigation
> >>    * filtering of traffic is one of protection methods taken by
> >> mitigators
> > Okay.
> >
> >>    * DOTS client can request filtering of traffic with desired action
> >> (blocking,
> >> rate-limiting...)
> >>    * instructed while it is under attack (on signaling channel)
> > DOTS signaling channel does not signal filtering rules, it's the job of=
 DOTS
> data channel.
> >
> >> Data model of Filtering Rules described in section 6 (DOTS Data
> >> Channel) looks like type 2 of filtering.
> > No, Filtering rules can be provisioned either before or during the atta=
ck.
> > I will update the draft to clarify, currently the draft is only high-li=
ghting the
> example of black-list rules provisioned during an attack.
> Okay, I'll see that.
>=20
> regards,
> kaname
>=20
> > -Tiru
> >
> >> So I think it looks like for signaling channel.
> >>
> >>
> >> best regards,
> >> kaname nishizuka
> >>
> >>
> >> On 2016/07/06 9:46, Tirumaleswar Reddy (tireddy) wrote:
> >>> Added new section
> >>> https://tools.ietf.org/html/draft-reddy-dots-transport-
> >> 05#section-8 to discuss about mutual authentication of DOTS Agents &
> >> authorization of DOTS clients. Comments and suggestions are welcome.
> >>> Cheers,
> >>> -Tiru
> >>>
> >>> -----Original Message-----
> >>> From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> >>> Sent: Wednesday, July 06, 2016 1:04 PM
> >>> To: Prashanth Patil (praspati); Dan Wing (dwing); Mike Geller
> >>> (mgeller); Robert Moskowitz; Mohamed Boucadair; Tirumaleswar Reddy
> >>> (tireddy)
> >>> Subject: New Version Notification for
> >>> draft-reddy-dots-transport-05.txt
> >>>
> >>>
> >>> A new version of I-D, draft-reddy-dots-transport-05.txt has been
> >>> successfully submitted by Tirumaleswar Reddy and posted to the IETF
> >>> repository.
> >>>
> >>> Name:		draft-reddy-dots-transport
> >>> Revision:	05
> >>> Title:		Co-operative DDoS Mitigation
> >>> Document date:	2016-07-06
> >>> Group:		Individual Submission
> >>> Pages:		26
> >>> URL:            https://www.ietf.org/internet-drafts/draft-reddy-dots=
-
> transport-
> >> 05.txt
> >>> Status:         https://datatracker.ietf.org/doc/draft-reddy-dots-tra=
nsport/
> >>> Htmlized:       https://tools.ietf.org/html/draft-reddy-dots-transpor=
t-05
> >>> Diff:           https://www.ietf.org/rfcdiff?url2=3Ddraft-reddy-dots-=
transport-05
> >>>
> >>> Abstract:
> >>>      This document specifies a mechanism that a DOTS client can use t=
o
> >>>      signal that a network is under a Distributed Denial-of-Service (=
DDoS)
> >>>      attack to an upstream DOTS server so that appropriate mitigation
> >>>      actions are undertaken (including, blackhole, drop, rate-limit, =
or
> >>>      add to watch list) on the suspect traffic.  The document specifi=
es
> >>>      both DOTS signal and data channels.  Happy Eyeballs consideratio=
ns
> >>>      for the DOTS signal channel are also elaborated.
> >>>
> >>>
> >>>
> >>>
> >>> Please note that it may take a couple of minutes from the time of
> >>> submission until the htmlized version and diff are available at
> tools.ietf.org.
> >>>
> >>> The IETF Secretariat
> >>>
> >>> _______________________________________________
> >>> Dots mailing list
> >>> Dots@ietf.org
> >>> https://www.ietf.org/mailman/listinfo/dots


From nobody Thu Aug 18 07:25:38 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CFFA112DF4C for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 07:25:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.768
X-Spam-Level: 
X-Spam-Status: No, score=-15.768 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rzu2KQ4IlqUT for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 07:25:36 -0700 (PDT)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 343FC12DF45 for <dots@ietf.org>; Thu, 18 Aug 2016 07:25:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2648; q=dns/txt; s=iport; t=1471530336; x=1472739936; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=eSwdr/9J/Ei3BV+Pgr4c2EKE9hg3COZPGVvNEKi1kHA=; b=EM3NofNOsJZuzpGjgQqDm6F9Jjv3UFWxrVnGucjjoAoQ/OagElELYwzi 3pJ4jE59QQIZG5V0IvM3AVdfSukZ8bpM0bI3SJ4zaFPfyd5/MxAGmo902 oZew1KswdbzxsyAPW7UPfaJVCHh+3shSXvKE4x6vL+WoaBzt1u88OInpT Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0BHAgCoxLVX/40NJK1dg0NWfAe3V4F9J?= =?us-ascii?q?oV3AhyBUTgUAgEBAQEBAQFeHAuEXgEBBSMRQw4EAgEIEQQBAQMCIwMCAgIwFAE?= =?us-ascii?q?GAQEFAwIEEwiIKQ6rQpAWAQEBAQEBAQEBAQEBAQEBAQEBAQEBHIEBhSmETYdBg?= =?us-ascii?q?loFjh2LJwGGH4h3gXJOhA6JAow7g3cBHjaDem4Bhi1/AQEB?=
X-IronPort-AV: E=Sophos;i="5.28,539,1464652800"; d="scan'208";a="312471689"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 18 Aug 2016 14:25:35 +0000
Received: from XCH-RCD-018.cisco.com (xch-rcd-018.cisco.com [173.37.102.28]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id u7IEPZ0o025677 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dots@ietf.org>; Thu, 18 Aug 2016 14:25:35 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-RCD-018.cisco.com (173.37.102.28) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Thu, 18 Aug 2016 09:25:34 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Thu, 18 Aug 2016 09:25:34 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-reddy-dots-data-channel-00.txt
Thread-Index: AQHR+VvWNffkGDxaOUqwMENfR7rywaBOxctQ
Date: Thu, 18 Aug 2016 14:25:34 +0000
Message-ID: <dd53470df50742918aa26de794dfea41@XCH-RCD-017.cisco.com>
References: <147153009650.22055.3525989457253684923.idtracker@ietfa.amsl.com>
In-Reply-To: <147153009650.22055.3525989457253684923.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.56.209]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/PjDl5aR0Y3P1Iri7ZQGOfSdnBn8>
Subject: [Dots] FW: New Version Notification for draft-reddy-dots-data-channel-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Aug 2016 14:25:38 -0000

VGhlIGRvY3VtZW50IHNwZWNpZmllcyBET1RTIGRhdGEgY2hhbm5lbCB0byBwZXJmb3JtIHRoZSBm
b2xsb3dpbmcgdGFza3M6DQoNCipGaWx0ZXIgbWFuYWdlbWVudCAoYmxhY2stbGlzdHMgYW5kIHdo
aXRlLWxpc3RzKQ0KKkRPVFMgc2lnbmFsIGNoYW5uZWwgc2Vzc2lvbiBjb25maWd1cmF0aW9uDQoq
Q3JlYXRlcyBhbGlhc2VzLCBmb3IgcmVzb3VyY2VzIGZvciB3aGljaCBtaXRpZ2F0aW9uIG1heSBi
ZSByZXF1ZXN0ZWQNCg0KQ29tbWVudHMgYW5kIHN1Z2dlc3Rpb25zIGFyZSB3ZWxjb21lLg0KDQpD
aGVlcnMsDQotVGlydQ0KDQotLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0KRnJvbTogaW50ZXJu
ZXQtZHJhZnRzQGlldGYub3JnIFttYWlsdG86aW50ZXJuZXQtZHJhZnRzQGlldGYub3JnXSANClNl
bnQ6IFRodXJzZGF5LCBBdWd1c3QgMTgsIDIwMTYgNzo1MiBQTQ0KVG86IERhbiBXaW5nIChkd2lu
ZykgPGR3aW5nQGNpc2NvLmNvbT47IEthbmFtZSBOaXNoaXp1a2EgPGthbmFtZUBudHR2Ni5qcD47
IE1vaGFtZWQgQm91Y2FkYWlyIDxtb2hhbWVkLmJvdWNhZGFpckBvcmFuZ2UuY29tPjsgVGlydW1h
bGVzd2FyIFJlZGR5ICh0aXJlZGR5KSA8dGlyZWRkeUBjaXNjby5jb20+OyBMaWFuZyBYaWEgPGZy
YW5rLnhpYWxpYW5nQGh1YXdlaS5jb20+DQpTdWJqZWN0OiBOZXcgVmVyc2lvbiBOb3RpZmljYXRp
b24gZm9yIGRyYWZ0LXJlZGR5LWRvdHMtZGF0YS1jaGFubmVsLTAwLnR4dA0KDQoNCkEgbmV3IHZl
cnNpb24gb2YgSS1ELCBkcmFmdC1yZWRkeS1kb3RzLWRhdGEtY2hhbm5lbC0wMC50eHQNCmhhcyBi
ZWVuIHN1Y2Nlc3NmdWxseSBzdWJtaXR0ZWQgYnkgVGlydW1hbGVzd2FyIFJlZGR5IGFuZCBwb3N0
ZWQgdG8gdGhlIElFVEYgcmVwb3NpdG9yeS4NCg0KTmFtZToJCWRyYWZ0LXJlZGR5LWRvdHMtZGF0
YS1jaGFubmVsDQpSZXZpc2lvbjoJMDANClRpdGxlOgkJRGlzdHJpYnV0ZWQgRGVuaWFsLW9mLVNl
cnZpY2UgT3BlbiBUaHJlYXQgU2lnbmFsaW5nIChET1RTKSBEYXRhIENoYW5uZWwNCkRvY3VtZW50
IGRhdGU6CTIwMTYtMDgtMTgNCkdyb3VwOgkJSW5kaXZpZHVhbCBTdWJtaXNzaW9uDQpQYWdlczoJ
CTIyDQpVUkw6ICAgICAgICAgICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvaW50ZXJuZXQtZHJhZnRz
L2RyYWZ0LXJlZGR5LWRvdHMtZGF0YS1jaGFubmVsLTAwLnR4dA0KU3RhdHVzOiAgICAgICAgIGh0
dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvZG9jL2RyYWZ0LXJlZGR5LWRvdHMtZGF0YS1jaGFu
bmVsLw0KSHRtbGl6ZWQ6ICAgICAgIGh0dHBzOi8vdG9vbHMuaWV0Zi5vcmcvaHRtbC9kcmFmdC1y
ZWRkeS1kb3RzLWRhdGEtY2hhbm5lbC0wMA0KDQoNCkFic3RyYWN0Og0KICAgVGhlIGRvY3VtZW50
IHNwZWNpZmllcyBhIERpc3RyaWJ1dGVkIERlbmlhbC1vZi1TZXJ2aWNlIE9wZW4gVGhyZWF0DQog
ICBTaWduYWxpbmcgKERPVFMpIGRhdGEgY2hhbm5lbCB1c2VkIGZvciBidWxrIGV4Y2hhbmdlIG9m
IGRhdGEgbm90DQogICBlYXNpbHkgb3IgYXBwcm9wcmlhdGVseSBjb21tdW5pY2F0ZWQgdGhyb3Vn
aCB0aGUgRE9UUyBzaWduYWwgY2hhbm5lbA0KICAgdW5kZXIgYXR0YWNrIGNvbmRpdGlvbnMuICBU
aGlzIGlzIGEgY29tcGFuaW9uIGRvY3VtZW50IHRvIHRoZSBET1RTDQogICBzaWduYWwgY2hhbm5l
bCBzcGVjaWZpY2F0aW9uLg0KDQogICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgDQoNCg0KUGxlYXNl
IG5vdGUgdGhhdCBpdCBtYXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZyb20gdGhlIHRpbWUg
b2Ygc3VibWlzc2lvbiB1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQgZGlmZiBhcmUgYXZh
aWxhYmxlIGF0IHRvb2xzLmlldGYub3JnLg0KDQpUaGUgSUVURiBTZWNyZXRhcmlhdA0KDQo=


From nobody Thu Aug 18 07:47:19 2016
Return-Path: <tireddy@cisco.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 62E3812DE6A for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 07:47:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.768
X-Spam-Level: 
X-Spam-Status: No, score=-15.768 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.247, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4XRaje6VdYqh for <dots@ietfa.amsl.com>; Thu, 18 Aug 2016 07:47:14 -0700 (PDT)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9214512D83B for <dots@ietf.org>; Thu, 18 Aug 2016 07:47:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2702; q=dns/txt; s=iport; t=1471531634; x=1472741234; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=bjSCiOzCo9j41JqgpAl9GygJI5xtjaVsjpmWEL4Wpzs=; b=KJQz7lUCXwH4WxfW6O4iBwjZzJ0nO4pXV+YlhPapLYxOuUciHMLkjp6g hnJwVEGCEbO4Xb6kFyu8f2TeE/kp/qw/OxasDr4f/nbXocQAKgYg05r63 WptjeOaATgD9i7yNShhTybN9/jtpfYkzSywGA30tOWycbEYGV9MbOYMjT Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0BHAgBoybVX/5NdJa1dg0NWfAe3V4F9J?= =?us-ascii?q?oV3AhyBSjgUAgEBAQEBAQFeHAuEXgEBBSMRQw4EAgEIEQQBAQMCIwMCAgIwFAE?= =?us-ascii?q?GAQEFAwIEEwiIKQ6rQJAWAQEBAQEBAQEBAQEBAQEBAQEBAQEBHIEBhSmETYQdD?= =?us-ascii?q?YMXgloFjh2LJwGGH4h3gXJOhA6JAow7g3cBHjaDem4BhWhFfwEBAQ?=
X-IronPort-AV: E=Sophos;i="5.28,539,1464652800"; d="scan'208";a="312482988"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by alln-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 18 Aug 2016 14:47:13 +0000
Received: from XCH-RCD-020.cisco.com (xch-rcd-020.cisco.com [173.37.102.30]) by rcdn-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id u7IElDDU030364 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL) for <dots@ietf.org>; Thu, 18 Aug 2016 14:47:13 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-RCD-020.cisco.com (173.37.102.30) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Thu, 18 Aug 2016 09:47:08 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1210.000; Thu, 18 Aug 2016 09:47:08 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: New Version Notification for draft-reddy-dots-signal-channel-00.txt
Thread-Index: AQHR+V5PvI2vbta0AECcotooCqxTz6BOy6mw
Date: Thu, 18 Aug 2016 14:47:08 +0000
Message-ID: <c00c7e192e994cf9b0cf47510e0b3148@XCH-RCD-017.cisco.com>
References: <147153115975.21989.1598429574685524185.idtracker@ietfa.amsl.com>
In-Reply-To: <147153115975.21989.1598429574685524185.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.56.209]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/3Y70tZQ_qbT-MlpRmiTv22YeULc>
Subject: [Dots] FW: New Version Notification for draft-reddy-dots-signal-channel-00.txt
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Aug 2016 14:47:17 -0000

VGhlIGRvY3VtZW50IHNwZWNpZmllcyBET1RTIHNpZ25hbCBjaGFubmVsLCBpdCByZXBsYWNlcyBk
cmFmdC1yZWRkeS1kb3RzLXRyYW5zcG9ydC4NCk1ham9yIGNoYW5nZSBpcyByZW1vdmVkIERPVFMg
ZGF0YSBjaGFubmVsIGZyb20gdGhpcyBkcmFmdA0KDQotVGlydQ0KDQotLS0tLU9yaWdpbmFsIE1l
c3NhZ2UtLS0tLQ0KRnJvbTogaW50ZXJuZXQtZHJhZnRzQGlldGYub3JnIFttYWlsdG86aW50ZXJu
ZXQtZHJhZnRzQGlldGYub3JnXSANClNlbnQ6IFRodXJzZGF5LCBBdWd1c3QgMTgsIDIwMTYgODow
OSBQTQ0KVG86IFByYXNoYW50aCBQYXRpbCAocHJhc3BhdGkpIDxwcmFzcGF0aUBjaXNjby5jb20+
OyBNb2hhbWVkIEJvdWNhZGFpciA8bW9oYW1lZC5ib3VjYWRhaXJAb3JhbmdlLmNvbT47IFRpcnVt
YWxlc3dhciBSZWRkeSAodGlyZWRkeSkgPHRpcmVkZHlAY2lzY28uY29tPjsgRGFuIFdpbmcgKGR3
aW5nKSA8ZHdpbmdAY2lzY28uY29tPg0KU3ViamVjdDogTmV3IFZlcnNpb24gTm90aWZpY2F0aW9u
IGZvciBkcmFmdC1yZWRkeS1kb3RzLXNpZ25hbC1jaGFubmVsLTAwLnR4dA0KDQoNCkEgbmV3IHZl
cnNpb24gb2YgSS1ELCBkcmFmdC1yZWRkeS1kb3RzLXNpZ25hbC1jaGFubmVsLTAwLnR4dA0KaGFz
IGJlZW4gc3VjY2Vzc2Z1bGx5IHN1Ym1pdHRlZCBieSBUaXJ1bWFsZXN3YXIgUmVkZHkgYW5kIHBv
c3RlZCB0byB0aGUgSUVURiByZXBvc2l0b3J5Lg0KDQpOYW1lOgkJZHJhZnQtcmVkZHktZG90cy1z
aWduYWwtY2hhbm5lbA0KUmV2aXNpb246CTAwDQpUaXRsZToJCURpc3RyaWJ1dGVkIERlbmlhbC1v
Zi1TZXJ2aWNlIE9wZW4gVGhyZWF0IFNpZ25hbGluZyAoRE9UUykgU2lnbmFsIENoYW5uZWwNCkRv
Y3VtZW50IGRhdGU6CTIwMTYtMDgtMTgNCkdyb3VwOgkJSW5kaXZpZHVhbCBTdWJtaXNzaW9uDQpQ
YWdlczoJCTIzDQpVUkw6ICAgICAgICAgICAgaHR0cHM6Ly93d3cuaWV0Zi5vcmcvaW50ZXJuZXQt
ZHJhZnRzL2RyYWZ0LXJlZGR5LWRvdHMtc2lnbmFsLWNoYW5uZWwtMDAudHh0DQpTdGF0dXM6ICAg
ICAgICAgaHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtcmVkZHktZG90cy1z
aWduYWwtY2hhbm5lbC8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rvb2xzLmlldGYub3JnL2h0
bWwvZHJhZnQtcmVkZHktZG90cy1zaWduYWwtY2hhbm5lbC0wMA0KDQoNCkFic3RyYWN0Og0KICAg
VGhpcyBkb2N1bWVudCBzcGVjaWZpZXMgYSBtZWNoYW5pc20gdGhhdCBhIERPVFMgY2xpZW50IGNh
biB1c2UgdG8NCiAgIHNpZ25hbCB0aGF0IGEgbmV0d29yayBpcyB1bmRlciBhIERpc3RyaWJ1dGVk
IERlbmlhbC1vZi1TZXJ2aWNlIChERG9TKQ0KICAgYXR0YWNrIHRvIGFuIHVwc3RyZWFtIERPVFMg
c2VydmVyIHNvIHRoYXQgYXBwcm9wcmlhdGUgbWl0aWdhdGlvbg0KICAgYWN0aW9ucyBhcmUgdW5k
ZXJ0YWtlbiAoaW5jbHVkaW5nLCBibGFja2hvbGUsIGRyb3AsIHJhdGUtbGltaXQsIG9yDQogICBh
ZGQgdG8gd2F0Y2ggbGlzdCkgb24gdGhlIHN1c3BlY3QgdHJhZmZpYy4gIFRoZSBkb2N1bWVudCBz
cGVjaWZpZXMNCiAgIHRoZSBET1RTIHNpZ25hbCBjaGFubmVsIGluY2x1ZGluZyBIYXBweSBFeWVi
YWxscyBjb25zaWRlcmF0aW9ucy4gIFRoZQ0KICAgc3BlY2lmaWNhdGlvbiBvZiB0aGUgRE9UUyBk
YXRhIGNoYW5uZWwgaXMgZWxhYm9yYXRlZCBpbiBhIGNvbXBhbmlvbg0KICAgZG9jdW1lbnQuDQoN
CiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICAgICAgICAgICAgICAgICAgICANCg0KDQpQbGVhc2Ugbm90ZSB0aGF0IGl0IG1heSB0
YWtlIGEgY291cGxlIG9mIG1pbnV0ZXMgZnJvbSB0aGUgdGltZSBvZiBzdWJtaXNzaW9uIHVudGls
IHRoZSBodG1saXplZCB2ZXJzaW9uIGFuZCBkaWZmIGFyZSBhdmFpbGFibGUgYXQgdG9vbHMuaWV0
Zi5vcmcuDQoNClRoZSBJRVRGIFNlY3JldGFyaWF0DQoNCg==


From nobody Mon Aug 22 12:57:01 2016
Return-Path: <rdd@cert.org>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A751712D177 for <dots@ietfa.amsl.com>; Mon, 22 Aug 2016 12:56:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.32
X-Spam-Level: 
X-Spam-Status: No, score=-4.32 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cert.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kgHO0MDSsvA1 for <dots@ietfa.amsl.com>; Mon, 22 Aug 2016 12:56:58 -0700 (PDT)
Received: from shetland.sei.cmu.edu (shetland.sei.cmu.edu [192.58.107.44]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 06C4E12D5FB for <dots@ietf.org>; Mon, 22 Aug 2016 12:56:57 -0700 (PDT)
Received: from timber.sei.cmu.edu (timber.sei.cmu.edu [10.64.21.23]) by shetland.sei.cmu.edu (8.14.4/8.14.4/1543) with ESMTP id u7MJuuHb001789 for <dots@ietf.org>; Mon, 22 Aug 2016 15:56:56 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1471895816; bh=3bX61WzJM92mUG+lDWF6KYZPVclsBNqSPSV73z4zf2o=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=KYIfbaMsJFej/vflJBokYnMcnKUpJghvKPKp1BZtHHisBcM6+tIsbkFqrFMa1lkSo 72xnCiWYvSBjgSa933AeGHrs8er2THr46aEPUV3jBzf3oxX96ixiu73SkYFbbIDPTA 9GXDxYpSjl5IMyIU2H1vz2j0QzU41QlTFFqqNGYI=
Received: from CASSINA.ad.sei.cmu.edu (cassina.ad.sei.cmu.edu [10.64.28.249]) by timber.sei.cmu.edu (8.14.4/8.14.4/1543) with ESMTP id u7MJuttg019286 for <dots@ietf.org>; Mon, 22 Aug 2016 15:56:55 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASSINA.ad.sei.cmu.edu ([10.64.28.249]) with mapi id 14.03.0279.002; Mon, 22 Aug 2016 15:56:54 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: Virtual Interim Meeting: Tuesday, September 27, 2016
Thread-Index: AdH8rjPZpL5Oy3a7ShSFEwg8gaHpMA==
Date: Mon, 22 Aug 2016 19:56:54 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFC0104E3AF69@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/ct2HMm0rFhqfrhzvr0DIQpTiFQY>
Subject: [Dots] Virtual Interim Meeting: Tuesday, September 27, 2016
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Aug 2016 19:56:59 -0000

Hello WG!

A DOTS virtual interim meeting has been scheduled for Tuesday, September 27=
, 2016  from 1400-1530 UTC.  Thank you to all that responded to the schedul=
ing poll.

=3D=3D[ Date/Time ]=3D=3D
Tuesday, September 27, 2016 from 1400-1530 UTC

Converted to local time:
** San Francisco -- 7:00:00 AM  PDT  UTC-7 hours
** New York -- 10:00:00 AM EDT  UTC-4 hours=20
** UTC -- 2:00:00 PM  UTC  UTC   =20
** London -- 3:00:00 PM  BST  UTC+1 hour =20
** Berlin -- 4:00:00 PM  CEST UTC+2 hours
** Bangkok -- 9:00:00 PM  ICT  UTC+7 hours
** Beijing -- 10:00:00 PM CST  UTC+8 hours=20

=3D=3D[ Agenda ]=3D=3D
TBD.  If you would like time on the agenda, please contact the chairs

=3D=3D[ WebEx Information ]=3D=3D
Meeting URL:
https://ietf.webex.com/ietf/j.php?MTID=3Dm84a8c2f46520bfc038867c113c274cfa

Meeting number: 646 441 945
Meeting password: kfTN2mvh
=20
Dial-in Numbers:
1-877-668-4493 Call-in toll free number (US/Canada)
1-650-479-3208 Call-in toll number (US/Canada)
=3D=3D=3D=3D

Regards,
Roman


From nobody Tue Aug 23 00:37:42 2016
Return-Path: <frank.xialiang@huawei.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ECDBF12D81A for <dots@ietfa.amsl.com>; Tue, 23 Aug 2016 00:37:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.769
X-Spam-Level: 
X-Spam-Status: No, score=-4.769 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AuVCRZYqgPzr for <dots@ietfa.amsl.com>; Tue, 23 Aug 2016 00:37:39 -0700 (PDT)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2F3A312B042 for <dots@ietf.org>; Tue, 23 Aug 2016 00:37:39 -0700 (PDT)
Received: from 172.18.7.190 (EHLO lhreml708-cah.china.huawei.com) ([172.18.7.190]) by lhrrg01-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id CUW04906; Tue, 23 Aug 2016 07:37:37 +0000 (GMT)
Received: from SZXEMA418-HUB.china.huawei.com (10.82.72.36) by lhreml708-cah.china.huawei.com (10.201.5.202) with Microsoft SMTP Server (TLS) id 14.3.235.1; Tue, 23 Aug 2016 08:37:36 +0100
Received: from SZXEMA502-MBS.china.huawei.com ([169.254.4.6]) by SZXEMA418-HUB.china.huawei.com ([10.82.72.36]) with mapi id 14.03.0235.001; Tue, 23 Aug 2016 15:37:28 +0800
From: "Xialiang (Frank)" <frank.xialiang@huawei.com>
To: "Roman D. Danyliw" <rdd@cert.org>
Thread-Topic: Virtual Interim Meeting: Tuesday, September 27, 2016
Thread-Index: AdH8rjPZpL5Oy3a7ShSFEwg8gaHpMAAYlatg
Date: Tue, 23 Aug 2016 07:37:27 +0000
Message-ID: <C02846B1344F344EB4FAA6FA7AF481F12AFAEF0A@SZXEMA502-MBS.china.huawei.com>
References: <359EC4B99E040048A7131E0F4E113AFC0104E3AF69@marathon>
In-Reply-To: <359EC4B99E040048A7131E0F4E113AFC0104E3AF69@marathon>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.221.99.221]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Reflected
X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020206.57BBFD41.010B, ss=1, re=0.000, recu=0.000, reip=0.000,  cl=1, cld=1, fgs=0, ip=169.254.4.6, so=2013-06-18 04:22:30, dmn=2013-03-21 17:37:32
X-Mirapoint-Loop-Id: 939ac3e891b5b5e2ca45c7897b97566b
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/zy9smAbgb0PADyF6EIwv8I64GkU>
Cc: "dots@ietf.org" <dots@ietf.org>
Subject: Re: [Dots] Virtual Interim Meeting: Tuesday, September 27, 2016
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Aug 2016 07:37:41 -0000

Hi Roman,
Thank you for the arrangement, I will attend.


B.R.
Frank

> -----Original Message-----
> From: Dots [mailto:dots-bounces@ietf.org] On Behalf Of Roman D. Danyliw
> Sent: Tuesday, August 23, 2016 3:57 AM
> To: dots@ietf.org
> Subject: [Dots] Virtual Interim Meeting: Tuesday, September 27, 2016
>=20
> Hello WG!
>=20
> A DOTS virtual interim meeting has been scheduled for Tuesday, September =
27,
> 2016  from 1400-1530 UTC.  Thank you to all that responded to the
> scheduling poll.
>=20
> =3D=3D[ Date/Time ]=3D=3D
> Tuesday, September 27, 2016 from 1400-1530 UTC
>=20
> Converted to local time:
> ** San Francisco -- 7:00:00 AM  PDT  UTC-7 hours
> ** New York -- 10:00:00 AM EDT  UTC-4 hours
> ** UTC -- 2:00:00 PM  UTC  UTC
> ** London -- 3:00:00 PM  BST  UTC+1 hour
> ** Berlin -- 4:00:00 PM  CEST UTC+2 hours
> ** Bangkok -- 9:00:00 PM  ICT  UTC+7 hours
> ** Beijing -- 10:00:00 PM CST  UTC+8 hours
>=20
> =3D=3D[ Agenda ]=3D=3D
> TBD.  If you would like time on the agenda, please contact the chairs
>=20
> =3D=3D[ WebEx Information ]=3D=3D
> Meeting URL:
> https://ietf.webex.com/ietf/j.php?MTID=3Dm84a8c2f46520bfc038867c113c274cf
> a
>=20
> Meeting number: 646 441 945
> Meeting password: kfTN2mvh
>=20
> Dial-in Numbers:
> 1-877-668-4493 Call-in toll free number (US/Canada)
> 1-650-479-3208 Call-in toll number (US/Canada) =3D=3D=3D=3D
>=20
> Regards,
> Roman
>=20
> _______________________________________________
> Dots mailing list
> Dots@ietf.org
> https://www.ietf.org/mailman/listinfo/dots

