
From internet-drafts@ietf.org  Thu Feb 14 04:21:59 2013
Return-Path: <internet-drafts@ietf.org>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E88D21F8501; Thu, 14 Feb 2013 04:21:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.584
X-Spam-Level: 
X-Spam-Status: No, score=-102.584 tagged_above=-999 required=5 tests=[AWL=0.015, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lnUhd+9eCf8n; Thu, 14 Feb 2013 04:21:58 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 883F921F8718; Thu, 14 Feb 2013 04:21:58 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.40
Message-ID: <20130214122158.11214.56507.idtracker@ietfa.amsl.com>
Date: Thu, 14 Feb 2013 04:21:58 -0800
Cc: karp@ietf.org
Subject: [karp] I-D Action: draft-ietf-karp-crypto-key-table-05.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Feb 2013 12:21:59 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Keying and Authentication for Routing Pro=
tocols Working Group of the IETF.

	Title           : Database of Long-Lived Symmetric Cryptographic Keys
	Author(s)       : Russell Housley
                          Tim Polk
                          Sam Hartman
                          Dacheng Zhang
	Filename        : draft-ietf-karp-crypto-key-table-05.txt
	Pages           : 12
	Date            : 2013-02-14

Abstract:
   This document specifies the information contained in a conceptual
   database of long-lived cryptographic keys used by many different
   security protocols.  The database is designed to support both manual
   and automated key management.  In addition to describing the schema
   for the database, this document describes the operations that can be
   performed on the database as well as the requirements for the
   security protocols that wish to use the database.  In many typical
   scenarios, the security protocols do not directly use the long-lived
   key, but rather a key derivation function is used to derive a short-
   lived key from a long-lived key.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-karp-crypto-key-table

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-karp-crypto-key-table-05

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-karp-crypto-key-table-05


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From internet-drafts@ietf.org  Wed Feb 20 15:57:38 2013
Return-Path: <internet-drafts@ietf.org>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE69A21E8054; Wed, 20 Feb 2013 15:57:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.574
X-Spam-Level: 
X-Spam-Status: No, score=-102.574 tagged_above=-999 required=5 tests=[AWL=0.025, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nWpX-R1QIV54; Wed, 20 Feb 2013 15:57:38 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4881121E8055; Wed, 20 Feb 2013 15:57:38 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.40
Message-ID: <20130220235738.29317.96918.idtracker@ietfa.amsl.com>
Date: Wed, 20 Feb 2013 15:57:38 -0800
Cc: karp@ietf.org
Subject: [karp] I-D Action: draft-ietf-karp-crypto-key-table-06.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Feb 2013 23:57:38 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Keying and Authentication for Routing Pro=
tocols Working Group of the IETF.

	Title           : Database of Long-Lived Symmetric Cryptographic Keys
	Author(s)       : Russell Housley
                          Tim Polk
                          Sam Hartman
                          Dacheng Zhang
	Filename        : draft-ietf-karp-crypto-key-table-06.txt
	Pages           : 11
	Date            : 2013-02-20

Abstract:
   This document specifies the information contained in a conceptual
   database of long-lived cryptographic keys used by many different
   security protocols.  The database is designed to support both manual
   and automated key management.  In addition to describing the schema
   for the database, this document describes the operations that can be
   performed on the database as well as the requirements for the
   security protocols that wish to use the database.  In many typical
   scenarios, the security protocols do not directly use the long-lived
   key, but rather a key derivation function is used to derive a short-
   lived key from a long-lived key.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-karp-crypto-key-table

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-karp-crypto-key-table-06

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-karp-crypto-key-table-06


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From hartmans@mit.edu  Fri Feb 22 10:00:33 2013
Return-Path: <hartmans@mit.edu>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9EC7F21F87C5 for <karp@ietfa.amsl.com>; Fri, 22 Feb 2013 10:00:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.821
X-Spam-Level: 
X-Spam-Status: No, score=-102.821 tagged_above=-999 required=5 tests=[AWL=-0.222, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CeX+b2MDcEqH for <karp@ietfa.amsl.com>; Fri, 22 Feb 2013 10:00:33 -0800 (PST)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) by ietfa.amsl.com (Postfix) with ESMTP id 212B821F87B1 for <karp@ietf.org>; Fri, 22 Feb 2013 10:00:31 -0800 (PST)
Received: from carter-zimmerman.suchdamage.org (c-98-216-0-82.hsd1.ma.comcast.net [98.216.0.82]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS id DDC1520161 for <karp@ietf.org>; Fri, 22 Feb 2013 12:55:46 -0500 (EST)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id BE0D5447B; Fri, 22 Feb 2013 13:00:28 -0500 (EST)
From: Sam Hartman <hartmans-ietf@mit.edu>
To: karp@ietf.org
Date: Fri, 22 Feb 2013 13:00:28 -0500
Message-ID: <tsl621kfcub.fsf@mit.edu>
User-Agent: Gnus/5.110009 (No Gnus v0.9) Emacs/22.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Subject: [karp] karp-ops-model: VRFs
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Feb 2013 18:00:33 -0000

Hi.
dacheng and I are working through karp-ops-model updates.
Section 3.4 of draft-ietf-karp-ops-model discusses VRFs and the key
table.
It says that probably the right answer is that each VRF should have a
key table but more analysis is required.

When i wrote that more analysis might be required I was mostly thinking
about inter-VRF routing.
I've thought more about this, but it seems like most of the use cases I
can think of fall into two categories:

1) A routing peering relationship within a VRF. There you want the VRF's
key table

2) A service provider routing peering that exchanges routes for multiple
VRFs. There you want a key from the non-virtual VRF used by the service
provider.

I've convinced myself if that in the vast majority of cases it's fine to
model the key table as per-VRF.
So, unless there are objections I'll update the text to make this as a
conceptual recommendation.
Obviously the specific details are left up to the implementation and
this text will not be stating any normative requirements.

--Sam

From internet-drafts@ietf.org  Mon Feb 25 13:28:35 2013
Return-Path: <internet-drafts@ietf.org>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E859521F90B2; Mon, 25 Feb 2013 13:28:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.534
X-Spam-Level: 
X-Spam-Status: No, score=-102.534 tagged_above=-999 required=5 tests=[AWL=0.065, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PlnfrN7BuuiK; Mon, 25 Feb 2013 13:28:34 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58C8121F90C4; Mon, 25 Feb 2013 13:28:34 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.40
Message-ID: <20130225212834.15626.15818.idtracker@ietfa.amsl.com>
Date: Mon, 25 Feb 2013 13:28:34 -0800
Cc: karp@ietf.org
Subject: [karp] I-D Action: draft-ietf-karp-ops-model-05.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 21:28:35 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Keying and Authentication for Routing Pro=
tocols Working Group of the IETF.

	Title           : Operations Model for Router Keying
	Author(s)       : Sam Hartman
                          Dacheng Zhang
	Filename        : draft-ietf-karp-ops-model-05.txt
	Pages           : 23
	Date            : 2013-02-25

Abstract:
   Developing an operational and management model for routing protocol
   security that works across protocols will be critical to the success
   of routing protocol security efforts.  This document discusses issues
   and begins to consider development of these models.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-karp-ops-model

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-karp-ops-model-05

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-karp-ops-model-05


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From hartmans@mit.edu  Mon Feb 25 13:37:45 2013
Return-Path: <hartmans@mit.edu>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7A6F821E80B6 for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 13:37:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.753
X-Spam-Level: 
X-Spam-Status: No, score=-102.753 tagged_above=-999 required=5 tests=[AWL=-0.154, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mhq4IjBcp3gg for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 13:37:45 -0800 (PST)
Received: from mail.painless-security.com (mail.painless-security.com [23.30.188.241]) by ietfa.amsl.com (Postfix) with ESMTP id D526321E80DA for <karp@ietf.org>; Mon, 25 Feb 2013 13:37:38 -0800 (PST)
Received: from carter-zimmerman.suchdamage.org (c-98-216-0-82.hsd1.ma.comcast.net [98.216.0.82]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (Client CN "laptop", Issuer "laptop" (not verified)) by mail.painless-security.com (Postfix) with ESMTPS id DCE2420118 for <karp@ietf.org>; Mon, 25 Feb 2013 16:32:44 -0500 (EST)
Received: by carter-zimmerman.suchdamage.org (Postfix, from userid 8042) id 5D26D447B; Mon, 25 Feb 2013 16:37:35 -0500 (EST)
From: Sam Hartman <hartmans-ietf@mit.edu>
To: karp@ietf.org
Date: Mon, 25 Feb 2013 16:37:35 -0500
Message-ID: <tsl1uc4xeg0.fsf@mit.edu>
User-Agent: Gnus/5.110009 (No Gnus v0.9) Emacs/22.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Subject: [karp] I think draft-ietf-karp-ops-model is ready for WGLC
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 21:37:45 -0000

I think I've addressed comments from last meeting including comments
from Russ and other comments at the mic.  I think this is ready for a
WGLC.  I suspect we'll find areas needing clarification during that
WGLC, but I think we're ready to collect those comments.

From uma.chunduri@ericsson.com  Mon Feb 25 14:50:41 2013
Return-Path: <uma.chunduri@ericsson.com>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1183C21E80F6 for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 14:50:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zBD9EaiDxkYM for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 14:50:40 -0800 (PST)
Received: from usevmg20.ericsson.net (usevmg20.ericsson.net [198.24.6.45]) by ietfa.amsl.com (Postfix) with ESMTP id 5F94521E80F2 for <karp@ietf.org>; Mon, 25 Feb 2013 14:50:40 -0800 (PST)
X-AuditID: c618062d-b7f0d6d00000097e-28-512beabfe2bd
Received: from EUSAAHC008.ericsson.se (Unknown_Domain [147.117.188.96]) by usevmg20.ericsson.net (Symantec Mail Security) with SMTP id 2C.82.02430.FBAEB215; Mon, 25 Feb 2013 23:50:39 +0100 (CET)
Received: from EUSAAMB105.ericsson.se ([147.117.188.122]) by EUSAAHC008.ericsson.se ([147.117.188.96]) with mapi id 14.02.0318.004; Mon, 25 Feb 2013 17:50:39 -0500
From: Uma Chunduri <uma.chunduri@ericsson.com>
To: "karp@ietf.org" <karp@ietf.org>
Thread-Topic: New Version Notification for draft-chunduri-karp-kmp-router-fingerprints-02.txt
Thread-Index: AQHOE6XN5PVa5ql9U0eM0LzLwNTAFpiLLTsg
Date: Mon, 25 Feb 2013 22:50:38 +0000
Message-ID: <1B502206DFA0C544B7A604691520086305F41EB0@eusaamb105.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [147.117.188.134]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprHLMWRmVeSWpSXmKPExsUyuXRPgu7+V9qBBg//WVrs/baG0YHRY8mS n0wBjFFcNimpOZllqUX6dglcGSdfRBfs5a84/nEySwPjVJ4uRk4OCQETiRWT57BC2GISF+6t Z+ti5OIQEjjCKHFseg8rhLOcUWLKqoWMIFVsAnoSH6f+ZO9i5OAQEVCWOPA1AyQsLBAncfX8 Y2YQW0QgXuLSh6esELaRxJIFr9lAbBYBVYlrbWtYQGxeAV+JCet/M4HYjECLv59aA2YzC4hL 3HoynwniIAGJJXvOM0PYohIvH/+DOlRZYsmT/SwQ9XoSN6ZOYYOwtSWWLXzNDDFfUOLkzCcs ExiFZyEZOwtJyywkLbOQtCxgZFnFyFFanFqWm25ksIkRGMbHJNh0dzDueWl5iFGag0VJnDfI 9UKAkEB6YklqdmpqQWpRfFFpTmrxIUYmDk6pBsambWWZcts570U+u8Ibclzvblsmr0m1w1lt 7x6umJa5v/P2XFjF+Ku0ifXFxtyCCfs2ZeS8vV2xa8d2fWnPPHePSXUdOTyW6p/fhZStiM1q s07ti3bcqqZZyTrVk/cip0ZowaqDT9exfFO5nPr1/KWlZ5yUdZ89mjnhpWusfe6M/b2tLJ0x Z5VYijMSDbWYi4oTARmVgTMxAgAA
Subject: [karp] FW: New Version Notification for draft-chunduri-karp-kmp-router-fingerprints-02.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 22:50:41 -0000

=20
Dear All,

We presented this Atlanta and updated the document with the feedback commen=
ts we got from Tero Kivinen.

Any other comments are welcome.

--=20
Uma C.=20


-----Original Message-----
From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]=20
Sent: Monday, February 25, 2013 2:17 PM
To: Uma Chunduri
Cc: Albert Tian; Ari Ker=E4nen
Subject: New Version Notification for draft-chunduri-karp-kmp-router-finger=
prints-02.txt


A new version of I-D, draft-chunduri-karp-kmp-router-fingerprints-02.txt
has been successfully submitted by Uma Chunduri and posted to the IETF repo=
sitory.

Filename:	 draft-chunduri-karp-kmp-router-fingerprints
Revision:	 02
Title:		 KARP KMP: Simplified Peer Authentication
Creation date:	 2013-02-25
Group:		 Individual Submission
Number of pages: 13
URL:             http://www.ietf.org/internet-drafts/draft-chunduri-karp-km=
p-router-fingerprints-02.txt
Status:          http://datatracker.ietf.org/doc/draft-chunduri-karp-kmp-ro=
uter-fingerprints
Htmlized:        http://tools.ietf.org/html/draft-chunduri-karp-kmp-router-=
fingerprints-02
Diff:            http://www.ietf.org/rfcdiff?url2=3Ddraft-chunduri-karp-kmp=
-router-fingerprints-02

Abstract:
   This document describes the usage of Router Fingerprint
   Authentication (RFA) with public keys as a potential peer
   authentication method with KARP pair wise and group Key Management
   Protocols (KMPs).  The advantage of RFA is, it neither requires out-
   of-band, mutually agreeable symmetric keys nor a full PKI based
   system (trust anchor or CA certificates) for mutual authentication of
   peers with KARP KMP deployments.  Usage of Router Fingerprints give a
   significant operational improvement from symmetric key based systems
   and yet provide a secure authentication technique.

                                                                           =
      =20


The IETF Secretariat


From uma.chunduri@ericsson.com  Mon Feb 25 14:53:10 2013
Return-Path: <uma.chunduri@ericsson.com>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33BF621F91D5 for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 14:53:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uyrDEvfrVoca for <karp@ietfa.amsl.com>; Mon, 25 Feb 2013 14:53:09 -0800 (PST)
Received: from usevmg21.ericsson.net (usevmg21.ericsson.net [198.24.6.65]) by ietfa.amsl.com (Postfix) with ESMTP id 707E921F91AC for <karp@ietf.org>; Mon, 25 Feb 2013 14:53:09 -0800 (PST)
X-AuditID: c6180641-b7faf6d00000096b-48-512beb54c8a3
Received: from EUSAAHC006.ericsson.se (Unknown_Domain [147.117.188.90]) by usevmg21.ericsson.net (Symantec Mail Security) with SMTP id 3B.42.02411.45BEB215; Mon, 25 Feb 2013 23:53:09 +0100 (CET)
Received: from EUSAAMB105.ericsson.se ([147.117.188.122]) by EUSAAHC006.ericsson.se ([147.117.188.90]) with mapi id 14.02.0318.004; Mon, 25 Feb 2013 17:53:08 -0500
From: Uma Chunduri <uma.chunduri@ericsson.com>
To: "karp@ietf.org" <karp@ietf.org>
Thread-Topic: New Version Notification for draft-chunduri-karp-using-ikev2-with-tcp-ao-04.txt
Thread-Index: AQHOE6c5Xkig6H2wZUuGFnSIbtHjX5iLLcoA
Date: Mon, 25 Feb 2013 22:53:07 +0000
Message-ID: <1B502206DFA0C544B7A604691520086305F41EC7@eusaamb105.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [147.117.188.134]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprPLMWRmVeSWpSXmKPExsUyuXRPlG7oa+1Ag4ZdzBZ7v61hdGD0WLLk J1MAYxSXTUpqTmZZapG+XQJXxtQzzcwFCwQqVs85yNLAeIuni5GTQ0LARGLp5RdsELaYxIV7 64FsLg4hgSOMEp0zjkI5yxklmiZ9YASpYhPQk/g49Sd7FyMHh4iAssSBrxkgYWGBeIn3jzeD DRIRSJDYdnA9I4RtJLFtfy+YzSKgKnFn3i9mEJtXwFfiz7cV7CA2I9Di76fWMIHYzALiEree zGeCOEhAYsme88wQtqjEy8f/WCFsZYklT/azQNTrSCzY/YkNwtaWWLbwNdR8QYmTM5+wTGAU noVk7CwkLbOQtMxC0rKAkWUVI0dpcWpZbrqR4SZGYCAfk2Bz3MG44JPlIUZpDhYlcd5Q1wsB QgLpiSWp2ampBalF8UWlOanFhxiZODilGhh7n02MlowX0des0M1c5frv1GqvUzKvKxsEmsVM KxduzLnkUn7qViRr9ioeaY+K9Xas/H3vG0VeVfB9VnV5L7Fj0/bK2v7w9NtvdGK6V6h/nbv8 02HLUstuIZF/xYslxH/EFG1bUnlASux2knVAevg8DXOOtbIK/S94b7KJ6T6cUrorR2/nXiWW 4oxEQy3mouJEAP1S1AIyAgAA
Subject: [karp] FW: New Version Notification for draft-chunduri-karp-using-ikev2-with-tcp-ao-04.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Feb 2013 22:53:10 -0000

This document has been updated to=20
      - generalize the Gatekeeper functionality for other pairwise RPs
      - and removed IKEv2 changes as it's in other draft

Welcome feedback on this document.=20
      =20
Authors

-----Original Message-----
From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]=20
Sent: Monday, February 25, 2013 2:27 PM
To: Uma Chunduri
Cc: Albert Tian; touch@isi.edu
Subject: New Version Notification for draft-chunduri-karp-using-ikev2-with-=
tcp-ao-04.txt


A new version of I-D, draft-chunduri-karp-using-ikev2-with-tcp-ao-04.txt
has been successfully submitted by Uma Chunduri and posted to the IETF repo=
sitory.

Filename:	 draft-chunduri-karp-using-ikev2-with-tcp-ao
Revision:	 04
Title:		 A framework for RPs to use IKEv2 KMP
Creation date:	 2013-02-25
Group:		 Individual Submission
Number of pages: 17
URL:             http://www.ietf.org/internet-drafts/draft-chunduri-karp-us=
ing-ikev2-with-tcp-ao-04.txt
Status:          http://datatracker.ietf.org/doc/draft-chunduri-karp-using-=
ikev2-with-tcp-ao
Htmlized:        http://tools.ietf.org/html/draft-chunduri-karp-using-ikev2=
-with-tcp-ao-04
Diff:            http://www.ietf.org/rfcdiff?url2=3Ddraft-chunduri-karp-usi=
ng-ikev2-with-tcp-ao-04

Abstract:
   This document describes a mechanism to secure pairwise Routing
   Protocol associations using the IKEv2 Key Management Protocol (KMP).
   Most of the pairwise Routing Protocols (RPs) are TCP-based but the
   framework described here is applicable to other pairwise RPs, which
   not necessarily use the TCP at transport layer.  A Gatekeeper
   mechanism is introduced to allow all pairwise RPs to coordinate with
   IKEv2 Protocol to pass the policy, get the keying material and to
   maintain the security associations.  The Gatekeeper also allows
   pairwise RPs which use TCP-AO to coordinate with IKEv2 without
   fundamental modification to either.

                                                                           =
      =20


The IETF Secretariat


From bew@cisco.com  Wed Feb 27 22:37:39 2013
Return-Path: <bew@cisco.com>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7F4CF21F8B37 for <karp@ietfa.amsl.com>; Wed, 27 Feb 2013 22:37:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.588
X-Spam-Level: 
X-Spam-Status: No, score=-110.588 tagged_above=-999 required=5 tests=[AWL=0.011, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 33E8uR+pYGeL for <karp@ietfa.amsl.com>; Wed, 27 Feb 2013 22:37:39 -0800 (PST)
Received: from mtv-iport-3.cisco.com (mtv-iport-3.cisco.com [173.36.130.14]) by ietfa.amsl.com (Postfix) with ESMTP id 11BD321F8B15 for <karp@ietf.org>; Wed, 27 Feb 2013 22:37:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=189; q=dns/txt; s=iport; t=1362033459; x=1363243059; h=from:content-transfer-encoding:subject:message-id:date: to:mime-version; bh=1uDKY6AkU0FvMNPKm8apA6/T+foC3WD6xhtm85HfLZg=; b=TEEb13ayG2JQqM3LuTDILYytzUimzYhZYLbBhO6B4r7V9jGaML37pV84 bLuf0betVun+Jdmxqv7V5M1yA1JbmS6wTYCNISNEBccGkiFxj+Tu7Ywr7 eaKKwsOg7poNLLc+KlGYxc+I45xTUEmT9plUya6RzLZjgL0rMlJpZu/2n k=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Aj4FABX6LlGrRDoJ/2dsb2JhbABFhgi9IRZzgkMdgX0TiBKgK6EujUOEN2EDiGqNV5BqgymBUQ
X-IronPort-AV: E=Sophos;i="4.84,753,1355097600"; d="scan'208";a="71065356"
Received: from mtv-core-4.cisco.com ([171.68.58.9]) by mtv-iport-3.cisco.com with ESMTP; 28 Feb 2013 06:37:38 +0000
Received: from stealth-10-32-244-213.cisco.com (stealth-10-32-244-213.cisco.com [10.32.244.213]) by mtv-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id r1S6bbAZ032275 for <karp@ietf.org>; Thu, 28 Feb 2013 06:37:38 GMT
From: Brian Weis <bew@cisco.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Message-Id: <D083A749-D358-4733-9F09-55F6B295E0C8@cisco.com>
Date: Wed, 27 Feb 2013 22:37:54 -0800
To: "karp@ietf.org" <karp@ietf.org>
Mime-Version: 1.0 (Mac OS X Mail 6.2 \(1499\))
X-Mailer: Apple Mail (2.1499)
Subject: [karp] Call for IETF 86 agenda items (KARP)
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Feb 2013 06:37:39 -0000

The KARP WG will be meeting 1PM EDT Tuesday Afternoon in Orlando. If you =
have a topic for the meeting please email the chairs =
(karp-chairs@tools.ietf.org).

Thanks,
Brian & Joel=

From turners@ieca.com  Thu Feb 28 06:30:53 2013
Return-Path: <turners@ieca.com>
X-Original-To: karp@ietfa.amsl.com
Delivered-To: karp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA9F321F85AF for <karp@ietfa.amsl.com>; Thu, 28 Feb 2013 06:30:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.238
X-Spam-Level: 
X-Spam-Status: No, score=-102.238 tagged_above=-999 required=5 tests=[AWL=0.027, BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dHLIP-qDj6Uv for <karp@ietfa.amsl.com>; Thu, 28 Feb 2013 06:30:53 -0800 (PST)
Received: from gateway15.websitewelcome.com (gateway15.websitewelcome.com [67.18.44.26]) by ietfa.amsl.com (Postfix) with ESMTP id 1B65B21F84B8 for <karp@ietf.org>; Thu, 28 Feb 2013 06:30:53 -0800 (PST)
Received: by gateway15.websitewelcome.com (Postfix, from userid 5007) id AB9AEA4AD5EB8; Thu, 28 Feb 2013 08:30:52 -0600 (CST)
Received: from gator1743.hostgator.com (gator1743.hostgator.com [184.173.253.227]) by gateway15.websitewelcome.com (Postfix) with ESMTP id 9646EA4AD5E4D for <karp@ietf.org>; Thu, 28 Feb 2013 08:30:52 -0600 (CST)
Received: from [108.45.16.214] (port=49733 helo=thunderfish.local) by gator1743.hostgator.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.80) (envelope-from <turners@ieca.com>) id 1UB4VY-0004rU-10; Thu, 28 Feb 2013 08:30:52 -0600
Message-ID: <512F6A1A.4020001@ieca.com>
Date: Thu, 28 Feb 2013 09:30:50 -0500
From: Sean Turner <turners@ieca.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130216 Thunderbird/17.0.3
MIME-Version: 1.0
To: Mahesh Jethanandani <mjethanandani@gmail.com>
References: <B015CEEC-6440-4865-9E45-5D6739CDAEC8@cisco.com> <A22E9FFF-965B-491D-908C-D9CF88531793@gmail.com>
In-Reply-To: <A22E9FFF-965B-491D-908C-D9CF88531793@gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gator1743.hostgator.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ieca.com
X-BWhitelist: no
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: (thunderfish.local) [108.45.16.214]:49733
X-Source-Auth: sean.turner@ieca.com
X-Email-Count: 4
X-Source-Cap: ZG9tbWdyNDg7ZG9tbWdyNDg7Z2F0b3IxNzQzLmhvc3RnYXRvci5jb20=
Cc: karp@ietf.org
Subject: Re: [karp] New Version Notification for draft-mahesh-karp-rsvp-te-analysis-00.txt
X-BeenThere: karp@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion list for key management for routing and transport protocols <karp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/karp>, <mailto:karp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/karp>
List-Post: <mailto:karp@ietf.org>
List-Help: <mailto:karp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/karp>, <mailto:karp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Feb 2013 14:30:54 -0000

Mahesh,

Thanks to you and your co-authors for beating me to this.  Stephen 
Farrell and I actually met with Lou Berger at IETF 85 to lament how RSVP 
is always the last one pick.  We figured if anybody was going to do this 
analysis it's be one of us - very glad we were wrong.

Couple questions (Q#) and some nits (N#):

Q1: I think s2 basically says that RSVP-TE uses RSVP so the rest of the 
draft is just going to talk about RSVP.  If that's the case why not move 
the idea of the 2nd paragraph of s2 to the 2nd to paragraph last in the 
intro. Maybe something like:

   Resource Reservation Protocol (RSVP) is a resource
   reservation setup  protocol designed for an integrated
   services [RFC2205].  RSVP Cryptographic Authentication
   [RFC2747] describes the format and use of RSVP's
   INTEGRITY objects to provide hop-by-hop integrity and
   authentication of RSVP messages.  RSVP-TE [RFC3209]
   is an extension of the RSVP protocol to establish
   Multi-Protocol Label Switching (MPLS) Label Switch
   Paths (LSPs).  RSVP-TE signaling is used to establish
   both intra- and inter-domain TE LSPs.

   NOTE: RSVP is not discussed in this document because
   it is not in scope for the KARP WG.

N1: abstract/intro: expand RSVP and RSVP-TE

N2: abstract: r/[RFC6518]/RFC 6518 (no reference in abstract)

N3: s1: r/suggests/suggested (matches with described)

N4: s1: Maybe instead of "The OPSEC working group ...

  This document builds on several previous analysis efforts into routing
  security:

  o [RFC6039] describes issues with existing cryptographic
     protection methods for routing protocols
  o [draft-ietf-karp-ospf-analysis-03] analyzes OSPF security
    according to KARP Design Guide
  o [draft-ietf-karp-routing-tcp-analysis] analyzes TCP based
    protocols including BGP, LDP, PCEP, and MSDP

Q2: s2: Don't we need a section on underlying transport where we can use 
the text from RFC 2205 tell everybody that it runs directly over IP:

  2.1.  Transport Layer

  RSVP operates on top of IPv4 or IPv6, occupying the place of a
  transport protocol in the protocol stack.  However, RSVP does not
  transport application data but is rather an Internet control
  protocol, like ICMP, IGMP, or routing protocols.

  ...

Q3: Do we need to discuss UDP encapsulation?

Q4: s2: How about a new subsection (kind of matches the tcp analysis draft):

  2.2.  Keying mechanisms

   There is no automated key management (AKM) mechanism for RSVP.  If
   implemented manual key management is used.

  and grab the 2nd to last paragraph and stick it in this section.

Q5: s2: Is there a current requirement (that came before the IAB 
workshop) on authenticating RSVP headers and payloads?  In this section 
maybe we just say:

  2.3.  Message Integrity and Node Authentication

   RSVP-TE makes use of the RSVP Cryptographic Authentication
   [RFC2747].  Note that there is currently no RSVP-TE
   specific security mechanism.

   RSVP Cryptographic Authentication defines the use of HMAC-MD5
   for both message integrity and node authentication.  The length
   of the keyed digests is 128 bits and the RSVP checksum can be
   disabled in lieu of message digest.  No algorithm agility is
   supported.

   There is no requirement that the RSVP-TE headers and payload be
   encrypted.

Q6: RSVP discusses user authentication for policy control and secure 
data streams.  Is the policy control stuff used?

N5: I'd also probably just have subsections for:

  2.*  Replay Protection
  2.*  Out-of-Order Protection
  2.*  Denial Of Service Protection

Where the appropriate text from the existing section gets copied.

N6: s3 2nd para: I think the point is that the current mechanism doesn't 
support cryptographic agility:

OLD:

  In RSVP Cryptographic Authentication [RFC2747], only the usage of MD5
  to generate digests for RSVP-TE messages is mentioned.  In order to
  fulfill the requirement of supporting strong algorithms, at least the
  support of SHA-2 needs to be provided.

NEW:

  In RSVP Cryptographic Authentication [RFC2747], only the usage of MD5
  to generate digests for RSVP-TE messages is defined.  In order to
  fulfill the requirement of supporting strong algorithms and
  cryptographic algorithm agility, at least the
  support of SHA-2 and the ability to indicate additional algorithms
  needs to be provided.

spt


On 12/19/12 11:52 PM, Mahesh Jethanandani wrote:
>
>
>>
>> A new version of I-D, draft-mahesh-karp-rsvp-te-analysis-00.txt
>> has been successfully submitted by Mahesh Jethanandani and posted to the
>> IETF repository.
>>
>> Filename:     draft-mahesh-karp-rsvp-te-analysis
>> Revision:     00
>> Title:         Analysis of RSVP-TE Security According to KARP Design Guide
>> Creation date:     2012-12-16
>> WG ID:         Individual Submission
>> Number of pages: 12
>> URL:
>> http://www.ietf.org/internet-drafts/draft-mahesh-karp-rsvp-te-analysis-00.txt
>> Status: http://datatracker.ietf.org/doc/draft-mahesh-karp-rsvp-te-analysis
>> Htmlized: http://tools.ietf.org/html/draft-mahesh-karp-rsvp-te-analysis-00
>>
>>
>> Abstract:
>> This document analyzes RSVP-TE according to guidelines set forth in
>> section 4.2 of KARP Design Guidelines [RFC6518].
>>
>>
>>
>>
>> The IETF Secretariat
>>
>>
>
> Mahesh Jethanandani
> mjethanandani@gmail.com <mailto:mjethanandani@gmail.com>
>
>
>
>
>
> _______________________________________________
> karp mailing list
> karp@ietf.org
> https://www.ietf.org/mailman/listinfo/karp
>
