
From nobody Wed Nov  1 03:05:48 2017
Return-Path: <j.schoenwaelder@jacobs-university.de>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EC05B1395F0; Wed,  1 Nov 2017 03:05:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IWC6Zs7gqLuS; Wed,  1 Nov 2017 03:05:40 -0700 (PDT)
Received: from atlas5.jacobs-university.de (atlas5.jacobs-university.de [212.201.44.20]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62BF2139567; Wed,  1 Nov 2017 03:05:40 -0700 (PDT)
Received: from localhost (demetrius5.irc-it.jacobs-university.de [10.70.0.222]) by atlas5.jacobs-university.de (Postfix) with ESMTP id 67F2DF6B; Wed,  1 Nov 2017 11:05:38 +0100 (CET)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from atlas5.jacobs-university.de ([10.70.0.217]) by localhost (demetrius5.jacobs-university.de [10.70.0.222]) (amavisd-new, port 10032) with ESMTP id rAHxX4n1KQnp; Wed,  1 Nov 2017 11:05:38 +0100 (CET)
Received: from hermes.jacobs-university.de (hermes.jacobs-university.de [212.201.44.23]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "hermes.jacobs-university.de", Issuer "Jacobs University CA - G01" (verified OK)) by atlas5.jacobs-university.de (Postfix) with ESMTPS; Wed,  1 Nov 2017 11:05:38 +0100 (CET)
Received: from localhost (demetrius3.jacobs-university.de [212.201.44.48]) by hermes.jacobs-university.de (Postfix) with ESMTP id 53B7220111; Wed,  1 Nov 2017 11:05:38 +0100 (CET)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from hermes.jacobs-university.de ([212.201.44.23]) by localhost (demetrius3.jacobs-university.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id 6zRSuJVdOp6v; Wed,  1 Nov 2017 11:05:37 +0100 (CET)
Received: from elstar.local (elstar.jacobs.jacobs-university.de [10.50.231.133]) by hermes.jacobs-university.de (Postfix) with ESMTP id 2D64B20110; Wed,  1 Nov 2017 11:05:37 +0100 (CET)
Received: by elstar.local (Postfix, from userid 501) id 03D2D4146993; Wed,  1 Nov 2017 11:04:09 +0100 (CET)
Date: Wed, 1 Nov 2017 11:04:09 +0100
From: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
To: mohamed.boucadair@orange.com
Cc: "yang-doctors@ietf.org" <yang-doctors@ietf.org>, "draft-ietf-opsawg-nat-yang.all@ietf.org" <draft-ietf-opsawg-nat-yang.all@ietf.org>,  "opsawg@ietf.org" <opsawg@ietf.org>
Message-ID: <20171101100409.n6sycvnj5km4jrdk@elstar.local>
Reply-To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
Mail-Followup-To: mohamed.boucadair@orange.com, "yang-doctors@ietf.org" <yang-doctors@ietf.org>, "draft-ietf-opsawg-nat-yang.all@ietf.org" <draft-ietf-opsawg-nat-yang.all@ietf.org>,  "opsawg@ietf.org" <opsawg@ietf.org>
References: <150912805550.22087.2939629492652644040@ietfa.amsl.com> <787AE7BB302AE849A7480A190F8B93300A060DB1@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <20171030162210.ni72dxxmc45o3cak@elstar.local> <787AE7BB302AE849A7480A190F8B93300A063187@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <787AE7BB302AE849A7480A190F8B93300A063187@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
User-Agent: NeoMutt/20170714 (1.8.3)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/LDuMpAftvpFiXWvQCVhWPUWCX-M>
Subject: Re: [OPSAWG] Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Nov 2017 10:05:43 -0000

On Tue, Oct 31, 2017 at 09:55:46AM +0000, mohamed.boucadair@orange.com wrote:
> > >  That said, there are a number of details where I doubt
> > > > the model is correct and things where I believe things are incomplete.
> > > > Given that there are many different NAT functions, I also expected to
> > > > see usage of YANG features.
> > >
> > > [Med] We used to make use of "features", but there was a comment during
> > the WG call for adoption that requested us to make use of identities,
> > instead.
> > 
> > But these are not the same thing.
> 
> [Med] You are right. Sorry for not being clear. 
> 
> What I meant is that the module used, for example, "if-feature nat64" and so on to refer to NAT flavors. We replaced those with "when" statements that points to the actual capabilities of an implementation. 
> Another change we made, is that we used to have "Boolean" to indicate the support of a given tarnation scheme (e.g., nat64-support, nat44-support), but we updated those to make use of identities. 

I do not recall having seen these when expressions. But even if there
were when expressions, this does not the same as features. A when
expression puts a constraint on a valid configuration, a feature
expresses that not all parts of a model may be implemented. This is
implementation time partitioning vs. configuration time partitioning.
 
>  If I am not a nat64, then apparently
> > several objects to not apply to me.
> 
> [Med] Yes. We tried to cover this by "when" statements. 
> 
>  This is what features allow you to
> > express. Perhaps someone wanted identities for something different, I
> > do not know. I think it is reasonable to assume that not all NAT
> > implementations will support all types of NATs that the model supports
> > and hence the model should reflect this.
> > 
> 
> [Med] The module indicates what a given implementation has to support based on its capabilities. This is handled by means of "when" statements.   

This seems to be a mis-understanding of what when expressions do. See
above for the explanation.

> > > > - What is the vrf-routing-instance identity good for?
> > >
> > > [Med] This is used to bind a NAT function to an external VRF routing
> > instance. Please check https://www.ietf.org/mail-
> > archive/web/opsawg/current/msg05117.html
> > >
> > 
> > I very much doubt that an identity identifies a VRF instance. I am not
> > questioning the need to identify a VRF, I am questioning that the
> > solution put in place achieves this.
> 
> [Med] Thank you for clarifying. This is actually a good point. The options we considered are as follows: 
> 
> (1) Use an Identity to avoid struggling with semantics of how a VRF can be defined.
> (2) Point to draft-ietf-rtgwg-ni-model, likely (?) as a normative reference. 
> (3) Remove the VRF thing from the draft; future extensions can be defined.
> 
> Given that "VRFs" are not required for all NATs and some reviewers asked to add VRFs in addition to interfaces, we went for option (1). Having a dependency on a YANG module under development is not justified for all implementations. 
>

But (1) is broken as far as I can tell. You either work out with the
routing guys how to properly refer to a VRF or you better leave this
out.

> > If leafs are not configurable, then they should be config false.
> 
> [Med] I will revert config to false as we used to have in previous versions. As I said earlier, pyang will cry. I don't know how to fix that. 
>

Then ask for help including the error message. Marking something that
is conceptually "config false" as "config true" is pretty misleading.

> [Med] The current module allows for implementations that support many translation flavors. In particular, it allows for a same NAT instance to enable many features in the same time.
> 
> There is no need to indicate explicitly the translation scheme(s) to enable because this will be implicitly deduced from the configuration parameters. For example: 
> - an implementation supplied with an external IPv4 address pool only, will automatically behave in the base NAT mode.
> - an implementation supplied with an external IPv4 address pool and port-related parameters will behave in the NAPT mode.
> - an implementation supplied with an external IPv4 address pool, port-related parameters, and NAT64 prefixes will behave in the statefull NAT64 mode
> - an implementation supplied with an external IPv4 address pool, port-related parameters, dst-nat-enable=true, and dst-ip-address-pool will behave in the NAPT mode + destination NAT
> 
> and so on. 

As long as this is clear from the specification. One option you may
consider is to use presence containers that can carry the bit when to
enable / disable a specific NAT function. (Although personally, I am
not such a big fan of presence containers, perhaps since I am not a
fan of side effects in general).
 
> > > [Med] Yes.
> > >
> > > >
> > > > - logging-info
> > > >
> > > >   Is this information complete? Perhaps it is for plain syslog
> > > >   (without any security) but I doubt the info is complete for the
> > > >   other transports mentioned, at least not for FTP. And surely, if you
> > > >   want to protect the logging information, then you will neeed way
> > > >   more parameters. And what does 'retrieving' logging entries mean?  I
> > > >   assume with syslog and ipfix you push log messages. I am less sure
> > > >   about FTP. Perhaps less is more and simply provide support for
> > > >   syslog and leave the other options for extensions. You have a choice
> > > >   in place, so not need to go and deal with all possible complexity
> > > >   here.
> > > >
> > >
> > > [Med] It is out of scope of specify the exact logging information. Those
> > considerations are out of scope. We only focus on the protocol and the
> > server information.
> > 
> > I think my comment was saying that the information is not sufficient to
> > talk to a server.
> 
> [Med] It is only about the minimal set of information. The information is not complete on purpose. Protocol-specific information is out of scope of this document. 

I am not sure it is valuable to have a standards-track specification
for something that is incomplete up the point that it can't be used if
implemented without annotations and extensions, i.e., the whole thing
can't be interoperable unless there is a standards-track extension. So
I would rather not standardize this at all and wait until someone is
willing to work out the details.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>


From nobody Mon Nov  6 06:58:12 2017
Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 951B713FC32; Mon,  6 Nov 2017 06:58:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.619
X-Spam-Level: 
X-Spam-Status: No, score=-2.619 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 57M0RoXi3epD; Mon,  6 Nov 2017 06:58:04 -0800 (PST)
Received: from orange.com (mta240.mail.business.static.orange.com [80.12.66.40]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9233C13FC2F; Mon,  6 Nov 2017 06:58:04 -0800 (PST)
Received: from opfedar00.francetelecom.fr (unknown [xx.xx.xx.11]) by opfedar26.francetelecom.fr (ESMTP service) with ESMTP id 04A531C0B0B; Mon,  6 Nov 2017 15:58:03 +0100 (CET)
Received: from Exchangemail-eme2.itn.ftgroup (unknown [xx.xx.31.34]) by opfedar00.francetelecom.fr (ESMTP service) with ESMTP id D491E180052; Mon,  6 Nov 2017 15:58:02 +0100 (CET)
Received: from OPEXCLILMA3.corporate.adroot.infra.ftgroup ([fe80::60a9:abc3:86e6:2541]) by OPEXCLILM6F.corporate.adroot.infra.ftgroup ([fe80::bd00:88f8:8552:3349%17]) with mapi id 14.03.0361.001; Mon, 6 Nov 2017 15:58:02 +0100
From: <mohamed.boucadair@orange.com>
To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
CC: "yang-doctors@ietf.org" <yang-doctors@ietf.org>, "draft-ietf-opsawg-nat-yang.all@ietf.org" <draft-ietf-opsawg-nat-yang.all@ietf.org>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
Thread-Index: AQHTT09nb4Xo03k7b0eBVGOEwFdqM6L8ajgAgAAc3gCAARxwQIABnpyAgAgbCIA=
Date: Mon, 6 Nov 2017 14:58:02 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B93300A07212C@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
References: <150912805550.22087.2939629492652644040@ietfa.amsl.com> <787AE7BB302AE849A7480A190F8B93300A060DB1@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <20171030162210.ni72dxxmc45o3cak@elstar.local> <787AE7BB302AE849A7480A190F8B93300A063187@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <20171101100409.n6sycvnj5km4jrdk@elstar.local>
In-Reply-To: <20171101100409.n6sycvnj5km4jrdk@elstar.local>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.168.234.2]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/UUT45mrGystPXsl4bnThi2UQ7N0>
Subject: Re: [OPSAWG] Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Nov 2017 14:58:11 -0000

Hi Juergen,

Thank you for the follow-up and for the suggestions.=20

I made the following changes to address your comments:

- Revert back to the use of features.
- Leave out the logging container for a future extension.
- Remove the "VRF" part from the module, but maintain an extensible design =
to easily support VRF in the future. =20

FWIW, the updated version of the module which integrates those comments is =
available at:=20
https://github.com/boucadair/draft-ietf-opsawg-nat-yang/blob/master/ietf-na=
t%402017-11-06.yang=20

Unless you have any further comment, I'm planning to submit this version ea=
rly next week.=20

Cheers,
Med

> -----Message d'origine-----
> De=A0: Juergen Schoenwaelder [mailto:j.schoenwaelder@jacobs-university.de=
]
> Envoy=E9=A0: mercredi 1 novembre 2017 11:04
> =C0=A0: BOUCADAIR Mohamed IMT/OLN
> Cc=A0: yang-doctors@ietf.org; draft-ietf-opsawg-nat-yang.all@ietf.org;
> opsawg@ietf.org
> Objet=A0: Re: Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
>=20
> On Tue, Oct 31, 2017 at 09:55:46AM +0000, mohamed.boucadair@orange.com
> wrote:
> > > >  That said, there are a number of details where I doubt
> > > > > the model is correct and things where I believe things are
> incomplete.
> > > > > Given that there are many different NAT functions, I also expecte=
d
> to
> > > > > see usage of YANG features.
> > > >
> > > > [Med] We used to make use of "features", but there was a comment
> during
> > > the WG call for adoption that requested us to make use of identities,
> > > instead.
> > >
> > > But these are not the same thing.
> >
> > [Med] You are right. Sorry for not being clear.
> >
> > What I meant is that the module used, for example, "if-feature nat64"
> and so on to refer to NAT flavors. We replaced those with "when"
> statements that points to the actual capabilities of an implementation.
> > Another change we made, is that we used to have "Boolean" to indicate
> the support of a given tarnation scheme (e.g., nat64-support, nat44-
> support), but we updated those to make use of identities.
>=20
> I do not recall having seen these when expressions. But even if there
> were when expressions, this does not the same as features. A when
> expression puts a constraint on a valid configuration, a feature
> expresses that not all parts of a model may be implemented. This is
> implementation time partitioning vs. configuration time partitioning.
>=20
> >  If I am not a nat64, then apparently
> > > several objects to not apply to me.
> >
> > [Med] Yes. We tried to cover this by "when" statements.
> >
> >  This is what features allow you to
> > > express. Perhaps someone wanted identities for something different, I
> > > do not know. I think it is reasonable to assume that not all NAT
> > > implementations will support all types of NATs that the model support=
s
> > > and hence the model should reflect this.
> > >
> >
> > [Med] The module indicates what a given implementation has to support
> based on its capabilities. This is handled by means of "when" statements.
>=20
> This seems to be a mis-understanding of what when expressions do. See
> above for the explanation.
>=20
> > > > > - What is the vrf-routing-instance identity good for?
> > > >
> > > > [Med] This is used to bind a NAT function to an external VRF routin=
g
> > > instance. Please check https://www.ietf.org/mail-
> > > archive/web/opsawg/current/msg05117.html
> > > >
> > >
> > > I very much doubt that an identity identifies a VRF instance. I am no=
t
> > > questioning the need to identify a VRF, I am questioning that the
> > > solution put in place achieves this.
> >
> > [Med] Thank you for clarifying. This is actually a good point. The
> options we considered are as follows:
> >
> > (1) Use an Identity to avoid struggling with semantics of how a VRF can
> be defined.
> > (2) Point to draft-ietf-rtgwg-ni-model, likely (?) as a normative
> reference.
> > (3) Remove the VRF thing from the draft; future extensions can be
> defined.
> >
> > Given that "VRFs" are not required for all NATs and some reviewers aske=
d
> to add VRFs in addition to interfaces, we went for option (1). Having a
> dependency on a YANG module under development is not justified for all
> implementations.
> >
>=20
> But (1) is broken as far as I can tell. You either work out with the
> routing guys how to properly refer to a VRF or you better leave this
> out.
>=20
> > > If leafs are not configurable, then they should be config false.
> >
> > [Med] I will revert config to false as we used to have in previous
> versions. As I said earlier, pyang will cry. I don't know how to fix that=
.
> >
>=20
> Then ask for help including the error message. Marking something that
> is conceptually "config false" as "config true" is pretty misleading.
>=20
> > [Med] The current module allows for implementations that support many
> translation flavors. In particular, it allows for a same NAT instance to
> enable many features in the same time.
> >
> > There is no need to indicate explicitly the translation scheme(s) to
> enable because this will be implicitly deduced from the configuration
> parameters. For example:
> > - an implementation supplied with an external IPv4 address pool only,
> will automatically behave in the base NAT mode.
> > - an implementation supplied with an external IPv4 address pool and
> port-related parameters will behave in the NAPT mode.
> > - an implementation supplied with an external IPv4 address pool, port-
> related parameters, and NAT64 prefixes will behave in the statefull NAT64
> mode
> > - an implementation supplied with an external IPv4 address pool, port-
> related parameters, dst-nat-enable=3Dtrue, and dst-ip-address-pool will
> behave in the NAPT mode + destination NAT
> >
> > and so on.
>=20
> As long as this is clear from the specification. One option you may
> consider is to use presence containers that can carry the bit when to
> enable / disable a specific NAT function. (Although personally, I am
> not such a big fan of presence containers, perhaps since I am not a
> fan of side effects in general).
>=20
> > > > [Med] Yes.
> > > >
> > > > >
> > > > > - logging-info
> > > > >
> > > > >   Is this information complete? Perhaps it is for plain syslog
> > > > >   (without any security) but I doubt the info is complete for the
> > > > >   other transports mentioned, at least not for FTP. And surely, i=
f
> you
> > > > >   want to protect the logging information, then you will neeed wa=
y
> > > > >   more parameters. And what does 'retrieving' logging entries
> mean?  I
> > > > >   assume with syslog and ipfix you push log messages. I am less
> sure
> > > > >   about FTP. Perhaps less is more and simply provide support for
> > > > >   syslog and leave the other options for extensions. You have a
> choice
> > > > >   in place, so not need to go and deal with all possible
> complexity
> > > > >   here.
> > > > >
> > > >
> > > > [Med] It is out of scope of specify the exact logging information.
> Those
> > > considerations are out of scope. We only focus on the protocol and th=
e
> > > server information.
> > >
> > > I think my comment was saying that the information is not sufficient
> to
> > > talk to a server.
> >
> > [Med] It is only about the minimal set of information. The information
> is not complete on purpose. Protocol-specific information is out of scope
> of this document.
>=20
> I am not sure it is valuable to have a standards-track specification
> for something that is incomplete up the point that it can't be used if
> implemented without annotations and extensions, i.e., the whole thing
> can't be interoperable unless there is a standards-track extension. So
> I would rather not standardize this at all and wait until someone is
> willing to work out the details.
>=20
> /js
>=20
> --
> Juergen Schoenwaelder           Jacobs University Bremen gGmbH
> Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
> Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>


From natelesser@masterpeaceltd.com  Mon Nov  6 13:52:39 2017
Return-Path: <natelesser@masterpeaceltd.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6AC0913FB8F for <opsawg@ietfa.amsl.com>; Mon,  6 Nov 2017 13:52:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.7
X-Spam-Level: 
X-Spam-Status: No, score=-4.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=masterpeaceltd.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QEV6z4juaU2U for <opsawg@ietfa.amsl.com>; Mon,  6 Nov 2017 13:52:37 -0800 (PST)
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (mail-dm3nam03on0131.outbound.protection.outlook.com [104.47.41.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 85FB113FB5B for <opsawg@ietf.org>; Mon,  6 Nov 2017 13:52:37 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=masterpeaceltd.onmicrosoft.com; s=selector1-masterpeaceltd-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=0+ab2nnfRnNw4xwNYpXN6sAynUqC9X6MZtH8XkkXwz8=; b=UNxoBrm1ZqI0cbXcv12zkaL+HiPUEEqWAthQcgErAEMfiVZfC8DCfTu7hn7VPCAAVSpQUibOiAxGjUkRCOAACSLNbfOvT0KZyewJ9GI8jWq2PO/TSVUYKwTVv9rEn10zLlcyKLrqwItl28RYeC7kspAsZ+HnsEA7FuqDUImNawE=
Received: from SN1PR11MB0591.namprd11.prod.outlook.com (10.163.135.26) by CY4PR11MB1399.namprd11.prod.outlook.com (10.173.17.13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.178.6; Mon, 6 Nov 2017 21:52:35 +0000
Received: from SN1PR11MB0591.namprd11.prod.outlook.com ([10.163.135.26]) by SN1PR11MB0591.namprd11.prod.outlook.com ([10.163.135.26]) with mapi id 15.20.0197.019; Mon, 6 Nov 2017 21:52:35 +0000
From: Nate Lesser <natelesser@masterpeaceltd.com>
To: "opsawg@ietf.org" <opsawg@ietf.org>
CC: Drew Cohen <drewcohen@masterpeaceltd.com>
Thread-Topic: LC comments on draft-ietf-opsawg-mud-13
Thread-Index: AQHTV0ltdB71LEjV402RZkUcobfC0g==
Date: Mon, 6 Nov 2017 21:52:35 +0000
Message-ID: <SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: spf=none (sender IP is ) smtp.mailfrom=natelesser@masterpeaceltd.com; 
x-originating-ip: [207.244.64.22]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR11MB1399; 6:A0tRGnfaQF3qFUANoeN43Y7G02QgKB3xSovJgsQTd60GV8hSwuj4LSkpUYWkAWe7jFpY6KosbgqpdefBV3EYmo+olvI4KYLm8mzdHkxWzAiJZvKj6t7JG+Rbo0IyHOERXuAgj0SA5325myLQcLSeAQMNFh2aQQXQysUlXBOb8IWegiDv4i5SM4tq6/qi2HmDi/q7Fl+r156MByBi5hGVKhuAkBa1UE3/IpPJIhTIk+UXWJrZjh2rB5odz0VijcPy3wVvz9+iFhp+tEWpyFYYmAEUMIAog7UZedSIWkEt9O06Q2JsToEIXG9XZnBUhGvbkpP37z1cJR8GtCEC8sFJAJV3Q4ldEEe0IQyCSNmhzrc=; 5:0gOswfPWkQ8rskuMDtcBO68l8n3KDjYEmtl41fELjo6FJL7IISdgDZJbyr0fPNsyn9RGw5jppZ8dsJ+Ey5/7smhHcIoOvdICaDc/mSpbQHSk9XBaUae0u2o8vXJAbrUVLEk/6RjC7hUtUxEq6QqU5DFXuJwvX52vFhSy2moeSVQ=; 24:7F9heX/lJNeEPreOCOn+LEs1UQv+EkaENQ7W7rJW6zCKjXbyxJnK8kW6lED0O98ESaOWVEvSfwsc2hEoQHu/HGJEv3hvDyD/lgd5Xk4xLgg=; 7:OwFkUoEKAwurMPnjeuHj4n1DEAv5reafSRobL5mIpyL3uHl54SugdjM3Fw3i3lcYxjx9TZPtfKg9mdfetebiA6bjTMpWmO6WviSTfJwvzZ1dMug0MF8wC409kYvQaiMKDjVoL7LWNRkDN12zVa3LxqLthAK3sUbmIo4JNmm/XE907Rs+z+GG320w85hSgzJcDH2LmMmB1XyChIy2z7uMtEEhRXk7dF+EmFRimg7LYlOz96erqfOKVbqteA8CmFrN
x-ms-exchange-antispam-srfa-diagnostics: SSOS;SSOR;
x-forefront-antispam-report: SFV:SKI; SCL:-1; SFV:NSPM; SFS:(10019020)(346002)(376002)(39830400002)(199003)(189002)(230783001)(77096006)(33656002)(50986999)(54356999)(66066001)(86362001)(19627405001)(106356001)(101416001)(2351001)(105586002)(6436002)(7736002)(6506006)(8676002)(606006)(81156014)(8936002)(74316002)(6606003)(1730700003)(81166006)(2900100001)(53386004)(107886003)(53936002)(9686003)(6306002)(54896002)(55016002)(236005)(4326008)(189998001)(5640700003)(99286004)(478600001)(68736007)(14454004)(316002)(25786009)(5660300001)(6116002)(3846002)(102836003)(2501003)(6916009)(7696004)(2906002)(97736004)(3660700001)(3280700002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR11MB1399; H:SN1PR11MB0591.namprd11.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  A:1; MX:1; LANG:en; 
x-ms-office365-filtering-correlation-id: 63bf6159-1cd2-450f-5dbf-08d52560b097
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(4534020)(4602075)(4603075)(4627115)(201702281549075)(2017052603249); SRVR:CY4PR11MB1399; 
x-ms-traffictypediagnostic: CY4PR11MB1399:
x-exchange-antispam-report-test: UriScan:;
x-microsoft-antispam-prvs: <CY4PR11MB1399A0A59AF223A67A8F0FA0A7500@CY4PR11MB1399.namprd11.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(10201501046)(93006095)(93001095)(3231021)(3002001)(100000703101)(100105400095)(6041248)(2016111802025)(20161123555025)(20161123560025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123558100)(20161123564025)(6043046)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY4PR11MB1399; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY4PR11MB1399; 
x-forefront-prvs: 048396AFA0
received-spf: None (protection.outlook.com: masterpeaceltd.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_SN1PR11MB0591DB230AA6F77135B96785A7500SN1PR11MB0591namp_"
MIME-Version: 1.0
X-OriginatorOrg: masterpeaceltd.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 63bf6159-1cd2-450f-5dbf-08d52560b097
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Nov 2017 21:52:35.1028 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f4d79cdd-e99c-4840-b0f1-892526875643
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR11MB1399
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/9q-Ow5_-3tjuoVLbQbtt0nnxsz8>
X-Mailman-Approved-At: Wed, 08 Nov 2017 17:59:59 -0800
Subject: [OPSAWG] LC comments on draft-ietf-opsawg-mud-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Nov 2017 21:53:40 -0000

--_000_SN1PR11MB0591DB230AA6F77135B96785A7500SN1PR11MB0591namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hello operations and management area working group!

On behalf of MasterPeace solutions, I am submitting the following comment t=
o the IETF draft-ietf-opsawg-mud-13. We suggest allowing MUD files to inclu=
de both device and application policies in addition to network policies.

We would be happy to discuss this comment at your convenience.

Best wishes,


----
Nate Lesser
Managing Director, MasterPeace Launch Pad
443.259.9785 (o)
917.686.9611 (c)

www.mplaunchpad.com<http://www.mplaunchpad.com>

--_000_SN1PR11MB0591DB230AA6F77135B96785A7500SN1PR11MB0591namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top:0;margi=
n-bottom:0;} --></style>
</head>
<body dir=3D"ltr">
<div id=3D"divtagdefaultwrapper" style=3D"font-size: 12pt; color: rgb(0, 0,=
 0); font-family: Calibri, Helvetica, sans-serif, Helvetica, EmojiFont, &qu=
ot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, NotoColorEmoji, &qu=
ot;Segoe UI Symbol&quot;, &quot;Android Emoji&quot;, EmojiSymbols;" dir=3D"=
ltr">
<p></p>
<span id=3D"ms-rterangepaste-start"></span>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">Hello operations and management area&nbsp;worki=
ng group!</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">&nbsp;</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">On behalf&nbsp;of MasterPeace solutions, I am s=
ubmitting the following comment to the&nbsp;IETF&nbsp;draft-ietf-opsawg-mud=
-13.&nbsp;We
 suggest allowing MUD files to include both device and application policies=
 in addition to network policies.</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">&nbsp;</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">We would be happy to discuss this comment at yo=
ur convenience.&nbsp;</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">&nbsp;</span></font></span></font></div>
<div style=3D"color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, &quo=
t;Segoe UI&quot;, &quot;Segoe WP&quot;, Tahoma, Arial, sans-serif, serif, E=
mojiFont; font-size: 15px; margin: 0px;">
<font size=3D"2" style=3D"font-family: Calibri, sans-serif, serif, EmojiFon=
t;"><span style=3D"font-size: 11pt;"><font size=3D"3" color=3D"black"><span=
 style=3D"font-size: 12pt;">Best wishes,</span></font></span></font></div>
<span id=3D"ms-rterangepaste-end"></span>
<p><br>
</p>
<div id=3D"Signature">
<div id=3D"divtagdefaultwrapper" dir=3D"ltr" style=3D"font-size:12pt; color=
:rgb(0,0,0); font-family:Calibri,Arial,Helvetica,sans-serif,EmojiFont,&quot=
;Apple Color Emoji&quot;,&quot;Segoe UI Emoji&quot;,NotoColorEmoji,&quot;Se=
goe UI Symbol&quot;,&quot;Android Emoji&quot;,EmojiSymbols">
<p><span style=3D"color:rgb(33,33,33); font-size:15px">----</span><br style=
=3D"color:rgb(33,33,33); font-size:15px">
<span style=3D"color:rgb(33,33,33); font-size:15px">Nate Lesser&nbsp;</span=
><br style=3D"color:rgb(33,33,33); font-size:15px">
<span style=3D"color:rgb(33,33,33); font-size:15px">Managing Director, Mast=
erPeace Launch Pad</span><br style=3D"color:rgb(33,33,33); font-size:15px">
<span style=3D"color:rgb(33,33,33); font-size:15px">443.259.9785 (o)</span>=
<br style=3D"color:rgb(33,33,33); font-size:15px">
<span style=3D"color:rgb(33,33,33); font-size:15px">917.686.9611 (c)</span>=
<br>
</p>
<p><span style=3D"color:rgb(33,33,33); font-size:15px"><a href=3D"http://ww=
w.mplaunchpad.com" class=3D"OWAAutoLink" id=3D"LPNoLP">www.mplaunchpad.com<=
/a></span></p>
</div>
</div>
</div>
</body>
</html>

--_000_SN1PR11MB0591DB230AA6F77135B96785A7500SN1PR11MB0591namp_--


From nobody Wed Nov  8 20:29:04 2017
Return-Path: <lear@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4431E129C5C for <opsawg@ietfa.amsl.com>; Wed,  8 Nov 2017 20:29:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.519
X-Spam-Level: 
X-Spam-Status: No, score=-14.519 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z2ouq_WET-9O for <opsawg@ietfa.amsl.com>; Wed,  8 Nov 2017 20:28:56 -0800 (PST)
Received: from bgl-iport-1.cisco.com (bgl-iport-1.cisco.com [72.163.197.25]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC782129C59 for <opsawg@ietf.org>; Wed,  8 Nov 2017 20:28:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=10368; q=dns/txt; s=iport; t=1510201735; x=1511411335; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=0cwN4Zc5nJyDAqwIFRFporzK8eKAsd4zG2L+ng0OxSo=; b=cl8Dm+Vw0zRVwjqkmiiK6sUyo96vjB/YKxDJ4u//CB2+bWZ1mkGeVnY7 a75UQwrSifc0qM4hB1VS/HI9Hgszl6+86+45amFXQ7sF+vyQz4zj1M9Y1 yhDuV8Pa0zW4RIbiW5+JEhOUC30wLBb1yKnEUGnO7uXqqeGoKbx0TOJnH I=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0B6AQAS2QNa/xjFo0hZAxkBAQEBAQEBA?= =?us-ascii?q?QEBAQEHAQEBAQGCRAGBU24ng32LE5AHJpEEhUiCEQcDGAEKhElPAoU8FwEBAQE?= =?us-ascii?q?BAQEBAWsohR8BAQEDAQEhJiULEAsYKgICJzAGAQoCBgIBAReKCBCqD4InJop1A?= =?us-ascii?q?QEBAQEBAQEBAQEBAQEBAQEBAQEBDg+DMIVtC4J2hTYmgk6CYwWSc48nhEOCI44?= =?us-ascii?q?Yi3mHP5YhgTkgATaBcTQhCB0VSYJkCYReOTaMCgEBAQ?=
X-IronPort-AV: E=Sophos;i="5.44,367,1505779200";  d="asc'?scan'208,217";a="78344669"
Received: from vla196-nat.cisco.com (HELO bgl-core-3.cisco.com) ([72.163.197.24]) by bgl-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Nov 2017 04:28:49 +0000
Received: from [10.232.4.170] ([10.232.4.170]) by bgl-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id vA94Snsa031929; Thu, 9 Nov 2017 04:28:49 GMT
To: Nate Lesser <natelesser@masterpeaceltd.com>, "opsawg@ietf.org" <opsawg@ietf.org>
Cc: Drew Cohen <drewcohen@masterpeaceltd.com>
References: <SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11.prod.outlook.com>
From: Eliot Lear <lear@cisco.com>
Message-ID: <c0293093-5f42-8c02-4848-bcb70e9799b3@cisco.com>
Date: Thu, 9 Nov 2017 09:58:46 +0530
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11.prod.outlook.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="QGDtQiXmLI2Knek6tEcPLwxHQsQLVVFff"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/ZYins_VfWvoe2IRHMCZgPMc5dUU>
Subject: Re: [OPSAWG] LC comments on draft-ietf-opsawg-mud-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Nov 2017 04:29:03 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--QGDtQiXmLI2Knek6tEcPLwxHQsQLVVFff
Content-Type: multipart/mixed; boundary="pJ3cwnufFfiRlVohJswN9QEADhuHKdA3G";
 protected-headers="v1"
From: Eliot Lear <lear@cisco.com>
To: Nate Lesser <natelesser@masterpeaceltd.com>,
 "opsawg@ietf.org" <opsawg@ietf.org>
Cc: Drew Cohen <drewcohen@masterpeaceltd.com>
Message-ID: <c0293093-5f42-8c02-4848-bcb70e9799b3@cisco.com>
Subject: Re: [OPSAWG] LC comments on draft-ietf-opsawg-mud-13
References: <SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11.prod.outlook.com>
In-Reply-To: <SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11.prod.outlook.com>

--pJ3cwnufFfiRlVohJswN9QEADhuHKdA3G
Content-Type: multipart/alternative;
 boundary="------------72BE74651A36717D5CC152B3"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------72BE74651A36717D5CC152B3
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi Drew,


The model can be augmented to cover application policies.=C2=A0 A separat=
e
document would be needed for that, but I am happy to work with you on
that, if you like.


Eliot


On 11/7/17 3:22 AM, Nate Lesser wrote:
> Hello operations and management area=C2=A0working group!
> =C2=A0
> On behalf=C2=A0of MasterPeace solutions, I am submitting the following
> comment to the=C2=A0IETF=C2=A0draft-ietf-opsawg-mud-13.=C2=A0We suggest=
 allowing MUD
> files to include both device and application policies in addition to
> network policies.
> =C2=A0
> We would be happy to discuss this comment at your convenience.=C2=A0
> =C2=A0
> Best wishes,
>
>
> ----
> Nate Lesser=C2=A0
> Managing Director, MasterPeace Launch Pad
> 443.259.9785 (o)
> 917.686.9611 (c)
>
> www.mplaunchpad.com <http://www.mplaunchpad.com>
>
>
>
> _______________________________________________
> OPSAWG mailing list
> OPSAWG@ietf.org
> https://www.ietf.org/mailman/listinfo/opsawg


--------------72BE74651A36717D5CC152B3
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf=
-8">
  </head>
  <body text=3D"#000000" bgcolor=3D"#FFFFFF">
    <p>Hi Drew,</p>
    <p><br>
    </p>
    <p>The model can be augmented to cover application policies.=C2=A0 A
      separate document would be needed for that, but I am happy to work
      with you on that, if you like.</p>
    <p><br>
    </p>
    <p>Eliot<br>
    </p>
    <br>
    <div class=3D"moz-cite-prefix">On 11/7/17 3:22 AM, Nate Lesser wrote:=
<br>
    </div>
    <blockquote type=3D"cite"
cite=3D"mid:SN1PR11MB0591DB230AA6F77135B96785A7500@SN1PR11MB0591.namprd11=
=2Eprod.outlook.com">
      <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Du=
tf-8">
      <style type=3D"text/css" style=3D"display:none;"><!-- P {margin-top=
:0;margin-bottom:0;} --></style>
      <div id=3D"divtagdefaultwrapper" style=3D"font-size: 12pt; color:
        rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif,
        Helvetica, EmojiFont, &quot;Apple Color Emoji&quot;, &quot;Segoe
        UI Emoji&quot;, NotoColorEmoji, &quot;Segoe UI Symbol&quot;,
        &quot;Android Emoji&quot;, EmojiSymbols;" dir=3D"ltr">
        <span id=3D"ms-rterangepaste-start"></span>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">Hello
                  operations and management area=C2=A0working group!</spa=
n></font></span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">=C2=A0</span></font></span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">On
                  behalf=C2=A0of MasterPeace solutions, I am submitting t=
he
                  following comment to
                  the=C2=A0IETF=C2=A0draft-ietf-opsawg-mud-13.=C2=A0We su=
ggest allowing
                  MUD files to include both device and application
                  policies in addition to network policies.</span></font>=
</span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">=C2=A0</span></font></span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">We
                  would be happy to discuss this comment at your
                  convenience.=C2=A0</span></font></span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">=C2=A0</span></font></span></font></div>
        <div style=3D"color: rgb(33, 33, 33); font-family:
          wf_segoe-ui_normal, &quot;Segoe UI&quot;, &quot;Segoe
          WP&quot;, Tahoma, Arial, sans-serif, serif, EmojiFont;
          font-size: 15px; margin: 0px;">
          <font style=3D"font-family: Calibri, sans-serif, serif,
            EmojiFont;" size=3D"2"><span style=3D"font-size: 11pt;"><font=

                size=3D"3" color=3D"black"><span style=3D"font-size: 12pt=
;">Best
                  wishes,</span></font></span></font></div>
        <span id=3D"ms-rterangepaste-end"></span>
        <p><br>
        </p>
        <div id=3D"Signature">
          <div id=3D"divtagdefaultwrapper" dir=3D"ltr"
            style=3D"font-size:12pt; color:rgb(0,0,0);
            font-family:Calibri,Arial,Helvetica,sans-serif,EmojiFont,&quo=
t;Apple
            Color Emoji&quot;,&quot;Segoe UI
            Emoji&quot;,NotoColorEmoji,&quot;Segoe UI
            Symbol&quot;,&quot;Android Emoji&quot;,EmojiSymbols">
            <p><span style=3D"color:rgb(33,33,33); font-size:15px">----</=
span><br
                style=3D"color:rgb(33,33,33); font-size:15px">
              <span style=3D"color:rgb(33,33,33); font-size:15px">Nate
                Lesser=C2=A0</span><br style=3D"color:rgb(33,33,33);
                font-size:15px">
              <span style=3D"color:rgb(33,33,33); font-size:15px">Managin=
g
                Director, MasterPeace Launch Pad</span><br
                style=3D"color:rgb(33,33,33); font-size:15px">
              <span style=3D"color:rgb(33,33,33); font-size:15px">443.259=
=2E9785
                (o)</span><br style=3D"color:rgb(33,33,33);
                font-size:15px">
              <span style=3D"color:rgb(33,33,33); font-size:15px">917.686=
=2E9611
                (c)</span><br>
            </p>
            <p><span style=3D"color:rgb(33,33,33); font-size:15px"><a
                  href=3D"http://www.mplaunchpad.com" class=3D"OWAAutoLin=
k"
                  id=3D"LPNoLP" moz-do-not-send=3D"true">www.mplaunchpad.=
com</a></span></p>
          </div>
        </div>
      </div>
      <br>
      <fieldset class=3D"mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap=3D"">_______________________________________________
OPSAWG mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:OPSAWG@ietf.org">OPS=
AWG@ietf.org</a>
<a class=3D"moz-txt-link-freetext" href=3D"https://www.ietf.org/mailman/l=
istinfo/opsawg">https://www.ietf.org/mailman/listinfo/opsawg</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------72BE74651A36717D5CC152B3--

--pJ3cwnufFfiRlVohJswN9QEADhuHKdA3G--

--QGDtQiXmLI2Knek6tEcPLwxHQsQLVVFff
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2

iQEcBAEBCAAGBQJaA9l/AAoJEIe2a0bZ0nozBdwIALXImlEYo3qYWk8GyqACB6vz
C+6NEvfWd/ZKONI3XjGYYjzDt5KUs7eMpK1gJXOKLHYCDBhEhSowiA+1qstdx7BI
w0ddAQIzV90FTIElmOuYQ77sy4oh4mxyOKF7xD3XWXfjNeW1WgRm4prj8jDPzSYK
5oCg9fK7UjkIFNgFgKVPAftaCMkr2rb7GGb5837RFABJNkMF1XPinNmt0IE9egTO
/XxaTuMCKLexsu8HGWOMzPqBDUrsvve8Xv/jMNL+axGufaADnNX106eNjWbrlz6g
whgVdnoJ3q2YwPBUppkykPnCR9L6fcGSJG6S846Rvw9M49HY4E9/H49r2fDtcaM=
=c7Rq
-----END PGP SIGNATURE-----

--QGDtQiXmLI2Knek6tEcPLwxHQsQLVVFff--


From nobody Wed Nov  8 21:33:29 2017
Return-Path: <zhoutianran@huawei.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ABCBA12954C; Wed,  8 Nov 2017 21:33:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.22
X-Spam-Level: 
X-Spam-Status: No, score=-4.22 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QKrDnzrTm-pN; Wed,  8 Nov 2017 21:33:27 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 571A912773A; Wed,  8 Nov 2017 21:33:24 -0800 (PST)
Received: from 172.18.7.190 (EHLO LHREML713-CAH.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id DSG16114; Thu, 09 Nov 2017 05:33:22 +0000 (GMT)
Received: from NKGEML414-HUB.china.huawei.com (10.98.56.75) by LHREML713-CAH.china.huawei.com (10.201.108.36) with Microsoft SMTP Server (TLS) id 14.3.361.1; Thu, 9 Nov 2017 05:33:21 +0000
Received: from NKGEML515-MBS.china.huawei.com ([169.254.5.148]) by nkgeml414-hub.china.huawei.com ([10.98.56.75]) with mapi id 14.03.0361.001; Thu, 9 Nov 2017 13:33:18 +0800
From: Tianran Zhou <zhoutianran@huawei.com>
To: "opsawg@ietf.org" <opsawg@ietf.org>, "OPS-AREA@ietf.org" <OPS-AREA@ietf.org>
CC: opsawg-chairs <opsawg-chairs@ietf.org>, "ops-ads@ietf.org" <ops-ads@ietf.org>
Thread-Topic: OPSAWG agenda posted
Thread-Index: AdNZHGh9QaE4G1jfRFCDjDYCc2NWCg==
Date: Thu, 9 Nov 2017 05:33:17 +0000
Message-ID: <BBA82579FD347748BEADC4C445EA0F21A6CE2CCB@NKGEML515-MBS.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.111.156.116]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Reflected
X-Mirapoint-Virus-RAPID-Raw: score=unknown(0), refid=str=0001.0A020206.5A03E8A2.00BB, ss=1, re=0.000, recu=0.000, reip=0.000,  cl=1, cld=1, fgs=0, ip=169.254.5.148, so=2013-06-18 04:22:30, dmn=2013-03-21 17:37:32
X-Mirapoint-Loop-Id: c58e6cb9a43013b525a953e56da076e6
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/H2V1Jg_vJYDxwPN1x6Q4zSf3XIk>
Subject: [OPSAWG] OPSAWG agenda posted
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Nov 2017 05:33:29 -0000

Hi OPSA WG and OPS area,

We have posted the meeting agenda.
https://datatracker.ietf.org/meeting/100/materials/agenda-100-opsawg/

Look forward to meeting with you on Tuesday.

The authors please send your slides to the chairs.

Thanks,
OPSA WG Co-Chairs


From nobody Sun Nov 12 22:35:24 2017
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E3EA12008A; Sun, 12 Nov 2017 22:35:17 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.65.1
Auto-Submitted: auto-generated
Precedence: bulk
Cc: The IESG <iesg@ietf.org>, draft-ietf-opsawg-service-model-explained@ietf.org, opsawg-chairs@ietf.org, Tianran Zhou <zhoutianran@huawei.com>, opsawg@ietf.org, zhoutianran@huawei.com, warren@kumari.net, rfc-editor@rfc-editor.org
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <151055491738.21486.14929224241439113667.idtracker@ietfa.amsl.com>
Date: Sun, 12 Nov 2017 22:35:17 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/nW3haSjQzdwjcEmv5lSBpx3y2_c>
Subject: [OPSAWG] Document Action: 'Service Models Explained' to Informational RFC (draft-ietf-opsawg-service-model-explained-05.txt)
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 06:35:17 -0000

The IESG has approved the following document:
- 'Service Models Explained'
  (draft-ietf-opsawg-service-model-explained-05.txt) as Informational RFC

This document is the product of the Operations and Management Area Working
Group.

The IESG contact persons are Warren Kumari and Benoit Claise.

A URL of this Internet Draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsawg-service-model-explained/





Technical Summary

  This document describes service models as used within the IETF, and
   also shows where a service model might fit into a Software Defined
   Networking architecture.  Note that service models do not make any
   assumption of how a service is actually engineered and delivered for
   a customer; details of how network protocols and devices are
   engineered to deliver a service are captured in other models that are
   not exposed through the Customer-Provider Interface.

Working Group Summary

   There was debate on the "network service model" concept in RFC 8199 . 
   This was solved by coordinating the cross WG discussion with NETMOD 
   during both the WG adoption call and WG LC. 

Document Quality
   
   This document has received extensive input and review. It has already 
   been used to direct L2SM and L3SM work. 

   One of the authors of a closely related document RFC8199 (Benoit Claise)
   reviewed this document and provided very useful comments, to align the 
   document and terms -- there have been integrated. Much
   of the discussion is somewhat over my head, and so I'm relying on his
   expert opinion.
   
Personnel

  Document Shepherd: Tianran Zhou
  "Responsible" AD: Warren Kumari
   


From nobody Sun Nov 12 23:02:50 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id DE5E3128B27; Sun, 12 Nov 2017 23:02:39 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: opsawg@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.65.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151055655985.21338.6502465132306696240@ietfa.amsl.com>
Date: Sun, 12 Nov 2017 23:02:39 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/ZIj2PRnktVP0k53DILXY5Brg79I>
Subject: [OPSAWG] I-D Action: draft-ietf-opsawg-nat-yang-08.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 07:02:40 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operations and Management Area Working Group WG of the IETF.

        Title           : A YANG Data Model for Network Address Translation (NAT) and Network Prefix Translation (NPT)
        Authors         : Mohamed Boucadair
                          Senthil Sivakumar
                          Christian Jacquenet
                          Suresh Vinapamula
                          Qin Wu
	Filename        : draft-ietf-opsawg-nat-yang-08.txt
	Pages           : 92
	Date            : 2017-11-12

Abstract:
   For the sake of network automation and the need for programming
   Network Address Translation (NAT) function in particular, a data
   model for configuring and managing the NAT is essential.  This
   document defines a YANG module for the NAT function.

   NAT44, Network Address and Protocol Translation from IPv6 Clients to
   IPv4 Servers (NAT64), Customer-side transLATor (CLAT), Stateless IP/
   ICMP Translation (SIIT), Explicit Address Mappings for Stateless IP/
   ICMP Translation (SIIT EAM), and IPv6 Network Prefix Translation
   (NPTv6) are covered in this document.

Editorial Note (To be removed by RFC Editor)

   Please update these statements with the RFC number to be assigned to
   this document:

      "This version of this YANG module is part of RFC XXXX;"

      "RFC XXXX: A YANG Data Model for Network Address Translation (NAT)
      and Network Prefix Translation (NPT)";

      "reference: RFC XXXX"


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsawg-nat-yang/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-opsawg-nat-yang-08
https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-nat-yang-08

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsawg-nat-yang-08


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Sun Nov 12 23:08:05 2017
Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C5E5D12948F; Sun, 12 Nov 2017 23:08:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.398
X-Spam-Level: 
X-Spam-Status: No, score=-5.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kozaBWclIePp; Sun, 12 Nov 2017 23:08:01 -0800 (PST)
Received: from orange.com (mta135.mail.business.static.orange.com [80.12.70.35]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5E7281200C1; Sun, 12 Nov 2017 23:08:00 -0800 (PST)
Received: from opfednr04.francetelecom.fr (unknown [xx.xx.xx.68]) by opfednr24.francetelecom.fr (ESMTP service) with ESMTP id D35BF403C4; Mon, 13 Nov 2017 08:07:58 +0100 (CET)
Received: from Exchangemail-eme2.itn.ftgroup (unknown [xx.xx.31.75]) by opfednr04.francetelecom.fr (ESMTP service) with ESMTP id ACA3C40068; Mon, 13 Nov 2017 08:07:58 +0100 (CET)
Received: from OPEXCLILMA3.corporate.adroot.infra.ftgroup ([fe80::60a9:abc3:86e6:2541]) by OPEXCLILMA4.corporate.adroot.infra.ftgroup ([fe80::65de:2f08:41e6:ebbe%18]) with mapi id 14.03.0361.001; Mon, 13 Nov 2017 08:07:58 +0100
From: <mohamed.boucadair@orange.com>
To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
CC: "yang-doctors@ietf.org" <yang-doctors@ietf.org>, "draft-ietf-opsawg-nat-yang.all@ietf.org" <draft-ietf-opsawg-nat-yang.all@ietf.org>, "opsawg@ietf.org" <opsawg@ietf.org>
Thread-Topic: Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
Thread-Index: AQHTT09nb4Xo03k7b0eBVGOEwFdqM6L8ajgAgAAc3gCAARxwQIABnpyAgAgbCICACp8/4A==
Date: Mon, 13 Nov 2017 07:07:57 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B93300A07763D@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
References: <150912805550.22087.2939629492652644040@ietfa.amsl.com> <787AE7BB302AE849A7480A190F8B93300A060DB1@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <20171030162210.ni72dxxmc45o3cak@elstar.local> <787AE7BB302AE849A7480A190F8B93300A063187@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <20171101100409.n6sycvnj5km4jrdk@elstar.local> <787AE7BB302AE849A7480A190F8B93300A07212C@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
In-Reply-To: <787AE7BB302AE849A7480A190F8B93300A07212C@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.168.234.6]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/DIhRqstwdfffEel0zPlXd7iQjmU>
Subject: Re: [OPSAWG] Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 07:08:04 -0000

Hi Juergen, all,=20

An updated version integrating your comments is available online:=20
https://datatracker.ietf.org/doc/draft-ietf-opsawg-nat-yang/=20

Major changes are:=20
- use of features
- remove the logging configuration parameters=20
- update the security section
- add a section to discuss the relationship with the NAT MIB
=20
Cheers,
Med

> -----Message d'origine-----
> De=A0: mohamed.boucadair@orange.com [mailto:mohamed.boucadair@orange.com]
> Envoy=E9=A0: lundi 6 novembre 2017 15:58
> =C0=A0: Juergen Schoenwaelder
> Cc=A0: yang-doctors@ietf.org; draft-ietf-opsawg-nat-yang.all@ietf.org;
> opsawg@ietf.org
> Objet=A0: RE: Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
>=20
> Hi Juergen,
>=20
> Thank you for the follow-up and for the suggestions.
>=20
> I made the following changes to address your comments:
>=20
> - Revert back to the use of features.
> - Leave out the logging container for a future extension.
> - Remove the "VRF" part from the module, but maintain an extensible desig=
n
> to easily support VRF in the future.
>=20
> FWIW, the updated version of the module which integrates those comments i=
s
> available at:
> https://github.com/boucadair/draft-ietf-opsawg-nat-yang/blob/master/ietf-
> nat%402017-11-06.yang
>=20
> Unless you have any further comment, I'm planning to submit this version
> early next week.
>=20
> Cheers,
> Med
>=20
> > -----Message d'origine-----
> > De=A0: Juergen Schoenwaelder [mailto:j.schoenwaelder@jacobs-university.=
de]
> > Envoy=E9=A0: mercredi 1 novembre 2017 11:04
> > =C0=A0: BOUCADAIR Mohamed IMT/OLN
> > Cc=A0: yang-doctors@ietf.org; draft-ietf-opsawg-nat-yang.all@ietf.org;
> > opsawg@ietf.org
> > Objet=A0: Re: Yangdoctors early review of draft-ietf-opsawg-nat-yang-06
> >
> > On Tue, Oct 31, 2017 at 09:55:46AM +0000, mohamed.boucadair@orange.com
> > wrote:
> > > > >  That said, there are a number of details where I doubt
> > > > > > the model is correct and things where I believe things are
> > incomplete.
> > > > > > Given that there are many different NAT functions, I also
> expected
> > to
> > > > > > see usage of YANG features.
> > > > >
> > > > > [Med] We used to make use of "features", but there was a comment
> > during
> > > > the WG call for adoption that requested us to make use of
> identities,
> > > > instead.
> > > >
> > > > But these are not the same thing.
> > >
> > > [Med] You are right. Sorry for not being clear.
> > >
> > > What I meant is that the module used, for example, "if-feature nat64"
> > and so on to refer to NAT flavors. We replaced those with "when"
> > statements that points to the actual capabilities of an implementation.
> > > Another change we made, is that we used to have "Boolean" to indicate
> > the support of a given tarnation scheme (e.g., nat64-support, nat44-
> > support), but we updated those to make use of identities.
> >
> > I do not recall having seen these when expressions. But even if there
> > were when expressions, this does not the same as features. A when
> > expression puts a constraint on a valid configuration, a feature
> > expresses that not all parts of a model may be implemented. This is
> > implementation time partitioning vs. configuration time partitioning.
> >
> > >  If I am not a nat64, then apparently
> > > > several objects to not apply to me.
> > >
> > > [Med] Yes. We tried to cover this by "when" statements.
> > >
> > >  This is what features allow you to
> > > > express. Perhaps someone wanted identities for something different,
> I
> > > > do not know. I think it is reasonable to assume that not all NAT
> > > > implementations will support all types of NATs that the model
> supports
> > > > and hence the model should reflect this.
> > > >
> > >
> > > [Med] The module indicates what a given implementation has to support
> > based on its capabilities. This is handled by means of "when"
> statements.
> >
> > This seems to be a mis-understanding of what when expressions do. See
> > above for the explanation.
> >
> > > > > > - What is the vrf-routing-instance identity good for?
> > > > >
> > > > > [Med] This is used to bind a NAT function to an external VRF
> routing
> > > > instance. Please check https://www.ietf.org/mail-
> > > > archive/web/opsawg/current/msg05117.html
> > > > >
> > > >
> > > > I very much doubt that an identity identifies a VRF instance. I am
> not
> > > > questioning the need to identify a VRF, I am questioning that the
> > > > solution put in place achieves this.
> > >
> > > [Med] Thank you for clarifying. This is actually a good point. The
> > options we considered are as follows:
> > >
> > > (1) Use an Identity to avoid struggling with semantics of how a VRF
> can
> > be defined.
> > > (2) Point to draft-ietf-rtgwg-ni-model, likely (?) as a normative
> > reference.
> > > (3) Remove the VRF thing from the draft; future extensions can be
> > defined.
> > >
> > > Given that "VRFs" are not required for all NATs and some reviewers
> asked
> > to add VRFs in addition to interfaces, we went for option (1). Having a
> > dependency on a YANG module under development is not justified for all
> > implementations.
> > >
> >
> > But (1) is broken as far as I can tell. You either work out with the
> > routing guys how to properly refer to a VRF or you better leave this
> > out.
> >
> > > > If leafs are not configurable, then they should be config false.
> > >
> > > [Med] I will revert config to false as we used to have in previous
> > versions. As I said earlier, pyang will cry. I don't know how to fix
> that


From nobody Mon Nov 13 19:56:51 2017
Return-Path: <dougm.work@gmail.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 94183128796 for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 19:56:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AX1yZbvxVvlz for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 19:56:43 -0800 (PST)
Received: from mail-oi0-x235.google.com (mail-oi0-x235.google.com [IPv6:2607:f8b0:4003:c06::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 422AD1242EA for <opsawg@ietf.org>; Mon, 13 Nov 2017 19:56:43 -0800 (PST)
Received: by mail-oi0-x235.google.com with SMTP id e142so5030823oih.2 for <opsawg@ietf.org>; Mon, 13 Nov 2017 19:56:43 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:from:date:message-id:subject:to; bh=6zV5mx4EdwkMT2fVYqCOBo8IHwxiLXXSOg4Xx9nhtOA=; b=U2Exj0CXWNrNA0y+G6mdVA2x4WNEO1wM7l/NGxtharT24Z873hYyPDGi0RWsUC1tlS CV/Pzi+67+8ux6DJXt4jTuAX39A9zKc2z1NMoqnte2P64wbYGrbP7SGbgGHr7xrFSkAU VAUsPjp+h7Y0CLwNWQOXBxqBV0UngBr1eF9OC7rt8TL4AxRz3IbwzQenJUdPcqZOtlaL ss0Jw0leYUnnR4ZP09+jbONAO+eFqPIAvjIQpESpxvfUD79+6ej5DSQ+YMlC5PKbZ+0x yyfunjvESfhugfxyOygjFXYcCkimTndYSHCkZWbM6uJ+5m1B4TLjQccdc749s3ne6Ng5 9zlg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=6zV5mx4EdwkMT2fVYqCOBo8IHwxiLXXSOg4Xx9nhtOA=; b=LdDkuqg0GO34q+PxxCGFmSvg7rw6ACSDH9QLVD4zQKlewwUZXj9nUtnolAAGMNhEhS Cr+sJKnTyQg4o12SAUBBV+JPQ42BNQxIDPjFj4XZXeZpHyMk4Y0CmvUxuyUWmH6BvNs6 qpYV+ML28v8KNaxDslbrxl2gE+ybJP5dSi4CgWClRaXn8BxFvZvw+kr4trNNjgEoSF5y oft++ULuJ/2RroCnz+tPGnY6Yrp/JT+LCL7sqXYlrMsCEkXpcYv832Q8CmLyXxKeayrw eMQbtPchXYfLeFoVz3vU4dqGqu9xon1SOgfXLln2DzarTosiWOj5+Lqp17rUhali+8EZ 4oeg==
X-Gm-Message-State: AJaThX6dBFyRlEHyxqpABM17kXQ96RtxvdN0w8IHjTKFba2Va6S7+YUu pTtMEXBV4yGeaBN4E6hySDVQTLpeqeGzXDYFRpmbxQ==
X-Google-Smtp-Source: AGs4zMZumUZWAgloA0E+uPjcj2SCN0XAkodh/ordMl7Lmo5D9fmI5aWR5rzdtydlGub6fAZIuLt6v6M9jYWsGetXGws=
X-Received: by 10.202.94.9 with SMTP id s9mr6599160oib.196.1510631802401; Mon, 13 Nov 2017 19:56:42 -0800 (PST)
MIME-Version: 1.0
Received: by 10.74.116.90 with HTTP; Mon, 13 Nov 2017 19:56:21 -0800 (PST)
From: Doug Montgomery <dougm.work@gmail.com>
Date: Mon, 13 Nov 2017 22:56:21 -0500
Message-ID: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
To: opsawg@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/ekVctlpesntUQVQKvCeZea2KN6E>
Subject: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 03:56:47 -0000

https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-mud-13#section-14

The deployment considerations section notes:

"Because MUD consists of a number of architectural building blocks, it
is possible to assemble different deployment scenarios.  One key
aspect is where to place policy enforcement.  In order to protect the
Thing from other Things within a local deployment, policy can be
enforced on the nearest switch or access point.  In order to limit
unwanted traffic within a network, it may also be advisable to
enforce policy as close to the Internet as possible.  In some
circumstances, policy enforcement may not be available at the closest
hop."

Some side conversation came up yesterday in opsec as to how one can
ensure that a MUD ACL is *only* applied to the traffic of the device
that emitted the MUD URL?

In particular in cases where the ACL can't be placed/bound to a
specific device MAC/port on the first hop switch/AP, how do we ensure
that the default "deny any" behavior of flows out of profile does not
affect other systems.

For example the first MUD ACL capable switching / routing device is on
the upstream side of a NAT.

Likewise, is it required that MUD profiles fully specify source/dest
addresses in ACLs so that loosely specified ACLs don't collateral
damage to flows from other systems?

Is it possible for a piece of malware to emit a MUD URL that purposely
gets an ACL applied to systems other than the one that emitted the
URL?

I am not saying I know this is a problem, it is just a question that
came up in side discussions, that I don't know the answer to.

At a minimum, saying something in the deployment consideration section
about how we protect against accidental / malicious misapplication of
MUD-profiles would be useful.

-- 
DougM at NIST


From nobody Mon Nov 13 22:33:52 2017
Return-Path: <lear@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68364127337 for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 22:33:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LSnbGng3Rb9I for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 22:33:49 -0800 (PST)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13CB012717E for <opsawg@ietf.org>; Mon, 13 Nov 2017 22:33:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2122; q=dns/txt; s=iport; t=1510641229; x=1511850829; h=subject:to:references:from:message-id:date:mime-version: in-reply-to; bh=SuhhHD8Ks96Rq58iGJEr50Bu3l7GvRTMzSS4eVGkS98=; b=jqvO+VKJ0HYFMOSTjQXhBtPxJEy4CwBvzr9auPq7aB+iwyjkeUlCe1UG QhIgLpBJ5kOQsavG1fIP1lmFDn3ZDZvhZM9lEqGIY9EwJ8b/30NEN9MHl ELZyAzqamRSX08opM9CkWl5lB9zs5ZK/ae35WrJnzi7CHwys+h4rp0/BG U=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0CVAQC8jQpa/5tdJa1bGQEBAQEBAQEBA?= =?us-ascii?q?QEBAQcBAQEBAYM2gVKEJZlOgX2WUIIRBwOFOwKEZkEWAQEBAQEBAQEBayiFHwE?= =?us-ascii?q?FI2YJAhgqAgJXBgEMCAEBih6NTJ1ogieLEQEBAQEBAQEDAQEBAQEBARIPgzSCB?= =?us-ascii?q?4NngwGFBYMngmMFknyPMYRHgiSOGoF8igGHRZYogTkmAy6BcjQhCB0Vgy6EazS?= =?us-ascii?q?JEAEBAQ?=
X-IronPort-AV: E=Sophos;i="5.44,393,1505779200";  d="asc'?scan'208";a="31070696"
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 14 Nov 2017 06:33:45 +0000
Received: from [10.70.233.66] ([10.70.233.66]) by rcdn-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id vAE6XiUb000685; Tue, 14 Nov 2017 06:33:44 GMT
To: Doug Montgomery <dougm.work@gmail.com>, opsawg@ietf.org
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
From: Eliot Lear <lear@cisco.com>
Message-ID: <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
Date: Tue, 14 Nov 2017 14:33:11 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="obngwoSDubToVJq8hGMn0XDEoRphLgoIo"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/rFipvSM5q8rvk896hpp2LNTJygQ>
Subject: Re: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 06:33:50 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--obngwoSDubToVJq8hGMn0XDEoRphLgoIo
Content-Type: multipart/mixed; boundary="c7e7BLWNdtpIiCjggpcSJ1P8Qcod1jm11";
 protected-headers="v1"
From: Eliot Lear <lear@cisco.com>
To: Doug Montgomery <dougm.work@gmail.com>, opsawg@ietf.org
Message-ID: <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
Subject: Re: [OPSAWG] Preventing MUD slides
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
In-Reply-To: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>

--c7e7BLWNdtpIiCjggpcSJ1P8Qcod1jm11
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US

Hi Doug,


On 11/14/17 11:56 AM, Doug Montgomery wrote:
> Is it possible for a piece of malware to emit a MUD URL that purposely
> gets an ACL applied to systems other than the one that emitted the
> URL?

I would say, =E2=80=9Cit depends=E2=80=9D.=C2=A0 If you have either a por=
t- or session-based
mechanism at L2 and below, then it is possible to keep one device from
speaking for another.=C2=A0 Similarly, if a device is purported to have
CHANGED its MUD URL, then I would be suspicious, especially if that
device is appearing to be something completely different from what it was=
=2E

Eliot


--c7e7BLWNdtpIiCjggpcSJ1P8Qcod1jm11--

--obngwoSDubToVJq8hGMn0XDEoRphLgoIo
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2

iQEcBAEBCAAGBQJaCo4nAAoJEIe2a0bZ0nozFwwH/0YNeEoEA2wwyPxZIxTUGL7F
ct74qBMYr36QGOv3C5OZxwz9C1/tp4PHGWCZ0Ds9t5D2zTUzu2KfQJplRbsOk4JE
hNEswtb2uU5jTcV0CDKyUidG0cWOdYdYHBkZLT8GKEHRDmctP/4ZWqgpK3KzCSuI
Wdxp1NSPjxN5F9wRhNaCKQAqGbuw+n68YJSQKmyQ0MOmtfpYxt6SwclNhufn5834
44s+VeR3Dqq6JNMMQYzdEDGJEDxEQ48+eyiPVgzGzaA9By4dDIbyKClXTRM6qEZ7
H4D7cOkkedIJ4sYOp+u00sujKG3CfRkTMgIx8rAP7PZ4vwCACk4lGDc9aRd9xag=
=3aQl
-----END PGP SIGNATURE-----

--obngwoSDubToVJq8hGMn0XDEoRphLgoIo--


From nobody Mon Nov 13 23:20:52 2017
Return-Path: <dougm.work@gmail.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34F31128961 for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 23:20:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j4trPH7BREwK for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 23:20:50 -0800 (PST)
Received: from mail-ot0-x233.google.com (mail-ot0-x233.google.com [IPv6:2607:f8b0:4003:c0f::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B609E1294AB for <opsawg@ietf.org>; Mon, 13 Nov 2017 23:20:37 -0800 (PST)
Received: by mail-ot0-x233.google.com with SMTP id s12so9489353otc.0 for <opsawg@ietf.org>; Mon, 13 Nov 2017 23:20:37 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=Q//GduBxuZLf+XGKd29RT0/0GwY61hQDia8ygY4hhoo=; b=eQaJqVWDW2dNhplkbdmZDvBlikzsvI6VVvVZHYrfZyGXvF+adYrIZl4ekYrPJiixMG w2iYN8baHEHOrPuyPJNYNd74KuP7659T4/QVyZ1+DYX+s6s0YukVIs1h10oikTYnqBQw SmxbQM+Tcwc+Hpi5/KsAkXyzPkcqG4/rcPW7r3xf1GWRf7NzGj+yJPlc5eorwqUStAym CxOsH/AJChrMSr1ePnHBCVGHWb3w3AQd/RGxtlHUBSM/uPnHTSC4KIJhM6RcmGjHxn11 +8ld1+ImwM9KonuRze1O6CyPq6PhrP3Eqt2x09+4zARCTV/Y8RVcX/bAZMMK6wRcIxED ftnw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=Q//GduBxuZLf+XGKd29RT0/0GwY61hQDia8ygY4hhoo=; b=UYfcyQdFamCL98RpLv4xI7zAf3P20znafK0nEvz8RXJUSLbiHISS97umbkHq3rn17K 7f3jzbEsH+zjNwrlnEW2sUVdaBJxIkl4NIFYCd3zpjD70snEd4jF2OEqS6YPZbcSZUiz wdbwmW5pl2b8g4XGzPt1RCPNEg2Nn32WsO4G25ei+ClsOw/QWL4oxLypqdcw0Qd1h2SA gtSekns/Y5wYA2mIvwTfQ+pko31GQLTeXRYiktd8GQURHt8H5kwrkSQcLvpIEeytDGdG p3X1khZRUrhW3kON3R/VMUgewnL/7k1S0GVime5HhK6jfvZ6cNkNma0cJONk1zgmu56d 3YmA==
X-Gm-Message-State: AJaThX5flKFkf79hWQxVdL3fRuly21v+aZeQSzmsSSoNivz+tCZdJ8Ei ycmq+Ps15eURsZ/KkL3sV37YEHtq7sQdnESc24w=
X-Google-Smtp-Source: AGs4zMbSCf0Z0SrmK+Ej0fEZA42w4VbTXi7Re31aY5AiF6s0gPRbqpqBfRcbrNnVI4pwJATVbuv0vsOrwua9Xq4+L9k=
X-Received: by 10.157.48.175 with SMTP id s47mr7716619otc.497.1510644037042; Mon, 13 Nov 2017 23:20:37 -0800 (PST)
MIME-Version: 1.0
Received: by 10.74.116.90 with HTTP; Mon, 13 Nov 2017 23:20:16 -0800 (PST)
In-Reply-To: <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com> <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
From: Doug Montgomery <dougm.work@gmail.com>
Date: Tue, 14 Nov 2017 02:20:16 -0500
Message-ID: <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>
To: Eliot Lear <lear@cisco.com>
Cc: opsawg@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/pXlau1WcuCPwO1hrIzcfpNh2zFY>
Subject: Re: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 07:20:51 -0000

Hi Eliot,

I think there is a subtle/difficult semantic here that each MUD ACL is
designed to be strictly bound to a particular end device.  If the
content of the specific ACL is capable of unambiguously establishing
that binding no matter where it is deployed topologically, then you
are OK.

If you can't establish that unambiguous binding, or if you can make
the binding ambiguous on purpose, there might be an issue.

So, I don't think the issue is one device spoofing another at L2 etc.

Let's say I have a CPE that supports MUD controlled ACLs but I have a
switch behind that, that does not support MUD ACLs.  There are two
things attached to that second switch. Thing2 has some malware on it
that is willing to emit a MUD URL to a purposely malicious MUD profile
that effectively tries to block all outbound traffic (src =3D
192.168.*.*, dst =3D any, action =3D drop).

Is there something in the design that stops malicious thing2 from doing thi=
s?

The idea that the network operator will inspect all of these by
non-automated means doesn't seem to scale well with the assumption
that the number and variety of devices will be very large.

If the network operator is the home user, I don't think this will
scale for other reasons.

dougm





On Tue, Nov 14, 2017 at 1:33 AM, Eliot Lear <lear@cisco.com> wrote:
> Hi Doug,
>
>
> On 11/14/17 11:56 AM, Doug Montgomery wrote:
>> Is it possible for a piece of malware to emit a MUD URL that purposely
>> gets an ACL applied to systems other than the one that emitted the
>> URL?
>
> I would say, =E2=80=9Cit depends=E2=80=9D.  If you have either a port- or=
 session-based
> mechanism at L2 and below, then it is possible to keep one device from
> speaking for another.  Similarly, if a device is purported to have
> CHANGED its MUD URL, then I would be suspicious, especially if that
> device is appearing to be something completely different from what it was=
.
>
> Eliot
>



--=20
DougM at Work


From nobody Mon Nov 13 23:47:20 2017
Return-Path: <lear@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 45053129481 for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 23:47:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R3mx0djKwXEY for <opsawg@ietfa.amsl.com>; Mon, 13 Nov 2017 23:47:18 -0800 (PST)
Received: from bgl-iport-1.cisco.com (bgl-iport-1.cisco.com [72.163.197.25]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4EA94126C23 for <opsawg@ietf.org>; Mon, 13 Nov 2017 23:47:17 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3093; q=dns/txt; s=iport; t=1510645637; x=1511855237; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=WN2T4N+q/3XFffbEXwixH9alzlJqQmGiCu3n7MDQe9o=; b=d8hN9i+3YKx7eDhZf6/u/6vPr5xx2JhPumfU6ljjGmXTxmMTQN9KG9/0 5/0bVNI+37GdnGnV8JWUvB6/jEA5cfM2HroyhjIZRewpqQPbqwMJYjR2p 1WzRjZ/7LeI/YbuGeim5E4+UgV349jsJvVkxnqb38YxwiVU8PV0H1qrL2 Q=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0B0AQAungpa/xjFo0hbGQEBAQEBAQEBA?= =?us-ascii?q?QEBAQcBAQEBAYUIhCWLE5ASJpZQghEHA4U7AoUnFgEBAQEBAQEBAWsohR8BBSM?= =?us-ascii?q?EUhALGCoCAlcGDQgBAYoeqy+BbTqLEQEBAQEBAQEBAQEBAQEBAQEBAQEQD4M0h?= =?us-ascii?q?W4LgnaILIJjBZJ8jzGER4IkjhqLfYdFliiBOSYJKIFyNCEIHRWDLoRrNIkQAQE?= =?us-ascii?q?B?=
X-IronPort-AV: E=Sophos;i="5.44,393,1505779200";  d="asc'?scan'208";a="78764581"
Received: from vla196-nat.cisco.com (HELO bgl-core-2.cisco.com) ([72.163.197.24]) by bgl-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 14 Nov 2017 07:47:14 +0000
Received: from [10.70.233.66] ([10.70.233.66]) by bgl-core-2.cisco.com (8.14.5/8.14.5) with ESMTP id vAE7lClH029930; Tue, 14 Nov 2017 07:47:13 GMT
To: Doug Montgomery <dougm.work@gmail.com>
Cc: opsawg@ietf.org
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com> <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com> <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>
From: Eliot Lear <lear@cisco.com>
Message-ID: <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com>
Date: Tue, 14 Nov 2017 15:46:33 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="2So0AHWC7S5MqE6inIlRG7h30wj8w3OQB"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/DEE0wk8dGckBam5n5s825kUL5RY>
Subject: Re: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 07:47:19 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--2So0AHWC7S5MqE6inIlRG7h30wj8w3OQB
Content-Type: multipart/mixed; boundary="RCwhCTWbhxr79ijl1KtnIr870sq0GBTQa";
 protected-headers="v1"
From: Eliot Lear <lear@cisco.com>
To: Doug Montgomery <dougm.work@gmail.com>
Cc: opsawg@ietf.org
Message-ID: <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com>
Subject: Re: [OPSAWG] Preventing MUD slides
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
 <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
 <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>
In-Reply-To: <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>

--RCwhCTWbhxr79ijl1KtnIr870sq0GBTQa
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US

Hi Doug,


On 11/14/17 3:20 PM, Doug Montgomery wrote:
> Hi Eliot,
>
> I think there is a subtle/difficult semantic here that each MUD ACL is
> designed to be strictly bound to a particular end device.  If the
> content of the specific ACL is capable of unambiguously establishing
> that binding no matter where it is deployed topologically, then you
> are OK.

This is the role of the MUD controller.=C2=A0 The MUD ACL refers, if you
will, to This-> or Me.=C2=A0 The MUD file doesn't get to specify who This=
->
or Me is.=C2=A0 The controller's job is to fill that in with the device's=

information, and to scope the policy to that device.

I think this might be worth making more clear.
>
> If you can't establish that unambiguous binding, or if you can make
> the binding ambiguous on purpose, there might be an issue.
>
> So, I don't think the issue is one device spoofing another at L2 etc.
>
> Let's say I have a CPE that supports MUD controlled ACLs but I have a
> switch behind that, that does not support MUD ACLs.  There are two
> things attached to that second switch. Thing2 has some malware on it
> that is willing to emit a MUD URL to a purposely malicious MUD profile
> that effectively tries to block all outbound traffic (src =3D
> 192.168.*.*, dst =3D any, action =3D drop).
>
> Is there something in the design that stops malicious thing2 from doing=
 this?
Does the above address your point?

Eliot



--RCwhCTWbhxr79ijl1KtnIr870sq0GBTQa--

--2So0AHWC7S5MqE6inIlRG7h30wj8w3OQB
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2

iQEcBAEBCAAGBQJaCp9ZAAoJEIe2a0bZ0noz7AIIAJvrFDAO7P5ol7zBbed3J4KZ
/p457EFpJkZtoHSwi4Q99Rn0GafqDfA/vWS0rRL+h4dhQj4zx5sh7tWaneFWmxbT
1AGjaXvpQmN+QTBNI4pO9n5L0Dl8sjMj1/BQdij4181VtN0X8zq88ZTcWxVCqSS3
ej5gjlibSyGMcsQoP3HnjuuR33F6SI7HB2yJmjyWUQW8Q0iV+P1D13iErmwR2kXf
0/9jsR9mtCJU3VNNMBhZTp8AFP0ojrSR2djIWZW2u2+H5xREHKfGfQ5+ua+S+8ue
VhCzQc+vd866J5kqoEyUpD/Kf3yyA3lpQNDJS31a1Q/HefBeyQ6V8mQN90lqKrs=
=8AEW
-----END PGP SIGNATURE-----

--2So0AHWC7S5MqE6inIlRG7h30wj8w3OQB--


From nobody Tue Nov 14 01:52:27 2017
Return-Path: <dougm.work@gmail.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6F065128D8B for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 01:52:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level: 
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j6_wXQmlQAI3 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 01:52:25 -0800 (PST)
Received: from mail-oi0-x22c.google.com (mail-oi0-x22c.google.com [IPv6:2607:f8b0:4003:c06::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5AD3C1293EC for <opsawg@ietf.org>; Tue, 14 Nov 2017 01:52:25 -0800 (PST)
Received: by mail-oi0-x22c.google.com with SMTP id e142so5481969oih.2 for <opsawg@ietf.org>; Tue, 14 Nov 2017 01:52:25 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=fZNfCPmkQnHKLnN1aJgz+RzkWTGbv1DcPc/nvzeuuhY=; b=OoB+JKQYE9Dzx3y+fwQXHfBEUTlEp06A7QAJjp5GCiAzq6ngwwvTaDU1qXHRCIft2k LzdoJzgAaS3MWRmEHgLifJxABnVx4VLXJkIuATxk8ljNavTivc6dpYEUyizyqLYpG8Bk 5lI/FiwEvR7plq7mSCywlFsKWiTGALPje7w2j76xlGJz72JQkE+1yR3eigybrXCWF0e+ jcUW3Evlw5vF3qJ+NXkZZev1zGyKraC192bGull3k8/+g6bnPPkftCvbGhwmswDNpdmA nllYd+1XZywtmMFXeWQvdwRoxHdc8NllNebLIxWy0UVBYKHDDdJdsKMWGMO/j5LhwntG tpZA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=fZNfCPmkQnHKLnN1aJgz+RzkWTGbv1DcPc/nvzeuuhY=; b=mmtW1D2bx5fP3HVyJ+eAdI4AWoSR4gkTpPieY9o3yc+KSkvALLhs38BosY+XAsEbj0 qyd2jik/fI4MbXisbedbULBLMOkM0ypBjdP+TfWINDS+BjmlB4TTAlmib4i6kmOrI6vm LGv6wCfzjkRMrhDGpK6AMQ59G3ayTFkgSDubmH/8PyP5yDzkbwon+DfAvr5B8bQpmUnd j3hRwTY0oSllZWGn8z/nLERqm2rjB5aORY95h9UVwfcbRLPecHq0QeT4/KYqy0HvxbYs VMHDW+4WZWIn0l7hEB2RNEMqvDH/07xilUnVZeBiiDErlSCq//iwKhrKx9WbZ/Z/AX5L umJg==
X-Gm-Message-State: AJaThX6ohAvS7/rFYM3cvPQ/o+pzbr+Fcvx5l1yW1G7HpFCQwYNqfEgl WKpfYJ2AxGwwgek90uqKG71fLlpyutAu2eoM9g0=
X-Google-Smtp-Source: AGs4zMbgZcHzf+31c1iNM9WuNFWgo5ZMy7EwgJ6Ttmrpb0qfpJELmGaEA1gdJXfBeirCRsTTT13tz3Oa9p19XOghPGM=
X-Received: by 10.202.245.204 with SMTP id t195mr2056803oih.304.1510653144636;  Tue, 14 Nov 2017 01:52:24 -0800 (PST)
MIME-Version: 1.0
Received: by 10.74.116.90 with HTTP; Tue, 14 Nov 2017 01:52:04 -0800 (PST)
In-Reply-To: <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com>
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com> <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com> <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com> <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com>
From: Doug Montgomery <dougm.work@gmail.com>
Date: Tue, 14 Nov 2017 04:52:04 -0500
Message-ID: <CAMaMmnnGjVWhfd6GC6NsDd=+85VNcbL7azMQfLOg4PVCq9s8Lw@mail.gmail.com>
To: Eliot Lear <lear@cisco.com>
Cc: opsawg@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/oSpcRBFYyYAnCIRNu78liOh7_FI>
Subject: Re: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 09:52:26 -0000

Eliot,

No actually, it seems to reduce the problem to an unspecified
function.  I get the late/local binding of various components of the
MUD ACL.

We are prototyping a controller, so we need to figure these gory
details.  If we assume every switch is MUD ACL capable, we can bind
MUD ACLs to specific ports/MACs.   If they are not, and if the first
MUD capable switch is upstream of a NAT, it becomes unclear how to
stop erroneous or malicious MUD profiles from potentially having
unintended effects.

Maybe we should link up and talk about it.

dougm

On Tue, Nov 14, 2017 at 2:46 AM, Eliot Lear <lear@cisco.com> wrote:
> Hi Doug,
>
>
> On 11/14/17 3:20 PM, Doug Montgomery wrote:
>> Hi Eliot,
>>
>> I think there is a subtle/difficult semantic here that each MUD ACL is
>> designed to be strictly bound to a particular end device.  If the
>> content of the specific ACL is capable of unambiguously establishing
>> that binding no matter where it is deployed topologically, then you
>> are OK.
>
> This is the role of the MUD controller.  The MUD ACL refers, if you
> will, to This-> or Me.  The MUD file doesn't get to specify who This->
> or Me is.  The controller's job is to fill that in with the device's
> information, and to scope the policy to that device.
>
> I think this might be worth making more clear.
>>
>> If you can't establish that unambiguous binding, or if you can make
>> the binding ambiguous on purpose, there might be an issue.
>>
>> So, I don't think the issue is one device spoofing another at L2 etc.
>>
>> Let's say I have a CPE that supports MUD controlled ACLs but I have a
>> switch behind that, that does not support MUD ACLs.  There are two
>> things attached to that second switch. Thing2 has some malware on it
>> that is willing to emit a MUD URL to a purposely malicious MUD profile
>> that effectively tries to block all outbound traffic (src =
>> 192.168.*.*, dst = any, action = drop).
>>
>> Is there something in the design that stops malicious thing2 from doing this?
> Does the above address your point?
>
> Eliot
>
>



-- 
DougM at Work


From nobody Tue Nov 14 06:57:31 2017
Return-Path: <lear@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41D64124C27 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 06:57:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ANwThsdyRZrr for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 06:57:28 -0800 (PST)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 81D48124D6C for <opsawg@ietf.org>; Tue, 14 Nov 2017 06:57:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3971; q=dns/txt; s=iport; t=1510671448; x=1511881048; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=P20hEvWSAfNpEoBOuQMzlaK9hF0uxwN/UYUiNzCFogg=; b=PLme2a4R/n/BzW2CDPf7j0qYCsCIhNt4GKUGaVywU8q97gwfD4Q+2kPC c45omBzevlb5e+AdDx9CDZaqqojMSUP70BFnU3o93OLGhEU3l4dcP6Puz y2K87LP+kZrJ1SkerCHmoV60wEy0FE2kieMCt91ojQ7X+1g/pk7QHwe5I A=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0CQAQB8Awta/4YNJK1SChkBAQEBAQEBA?= =?us-ascii?q?QEBAQEHAQEBAQGDNoFShCWbTZZXghEHA4U7AoUAQRYBAQEBAQEBAQFrKIUeAQE?= =?us-ascii?q?BAQIBI00JBQsLGCoCAlcGDQgBAYoXCKsdgieLEwEBAQEBAQEBAQEBAQEBAQEBE?= =?us-ascii?q?g+DNIIHg2cLgnaEbYNAgmMFkwKGGokYhEeCJY4ai32HRZYrgTkmAi+BczQhCB0?= =?us-ascii?q?Vgy6EazSJOgEBAQ?=
X-IronPort-AV: E=Sophos;i="5.44,395,1505779200";  d="asc'?scan'208";a="320499695"
Received: from alln-core-12.cisco.com ([173.36.13.134]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 14 Nov 2017 14:57:26 +0000
Received: from [10.70.233.66] ([10.70.233.66]) by alln-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id vAEEvPEv030830; Tue, 14 Nov 2017 14:57:26 GMT
To: Doug Montgomery <dougm.work@gmail.com>
Cc: opsawg@ietf.org
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com> <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com> <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com> <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com> <CAMaMmnnGjVWhfd6GC6NsDd=+85VNcbL7azMQfLOg4PVCq9s8Lw@mail.gmail.com>
From: Eliot Lear <lear@cisco.com>
Message-ID: <d14e6add-efd7-6755-2fc4-bdd05c84913f@cisco.com>
Date: Tue, 14 Nov 2017 22:56:38 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <CAMaMmnnGjVWhfd6GC6NsDd=+85VNcbL7azMQfLOg4PVCq9s8Lw@mail.gmail.com>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="iJD4tWOmbUdoiva4xfU71mrfkumIW0rWR"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/iKRrWkWlEMuNZUgrQFKe0dYFLE0>
Subject: Re: [OPSAWG] Preventing MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 14:57:30 -0000

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--iJD4tWOmbUdoiva4xfU71mrfkumIW0rWR
Content-Type: multipart/mixed; boundary="IcHBLlSjhD4tm2qkPgXWG1GQ8uLxfjCAX";
 protected-headers="v1"
From: Eliot Lear <lear@cisco.com>
To: Doug Montgomery <dougm.work@gmail.com>
Cc: opsawg@ietf.org
Message-ID: <d14e6add-efd7-6755-2fc4-bdd05c84913f@cisco.com>
Subject: Re: [OPSAWG] Preventing MUD slides
References: <CAMaMmnkNQERy7R_3pZbResSXhT-vcg1neCoTMNB1n+B=jY-hfw@mail.gmail.com>
 <1b30d6fc-b559-f558-f382-ef2920cd42a2@cisco.com>
 <CAMaMmn=LZk+LDdQTUZoZPqC3BN=M77YgZdh1kjQO9smfBB=zbQ@mail.gmail.com>
 <a963b4d4-5934-ce40-b2fb-986fe1a519c5@cisco.com>
 <CAMaMmnnGjVWhfd6GC6NsDd=+85VNcbL7azMQfLOg4PVCq9s8Lw@mail.gmail.com>
In-Reply-To: <CAMaMmnnGjVWhfd6GC6NsDd=+85VNcbL7azMQfLOg4PVCq9s8Lw@mail.gmail.com>

--IcHBLlSjhD4tm2qkPgXWG1GQ8uLxfjCAX
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US

Hi Doug,


On 11/14/17 5:52 PM, Doug Montgomery wrote:
> Eliot,
>
> No actually, it seems to reduce the problem to an unspecified
> function.  I get the late/local binding of various components of the
> MUD ACL.
I think you get how to fill in those functions in a great number of
cases, especially for consumer.=C2=A0 So for instance...

>
> We are prototyping a controller, so we need to figure these gory
> details.  If we assume every switch is MUD ACL capable, we can bind
> MUD ACLs to specific ports/MACs.

Yes.=C2=A0 Or if you can do session management for wireless you are in
reasonably good shape as well.

>    If they are not, and if the first
> MUD capable switch is upstream of a NAT, it becomes unclear how to
> stop erroneous or malicious MUD profiles from potentially having
> unintended effects.

I never seriously considered trying to implement MUD across a NAT.[*]

The principle here is that you really must have a means to identify the
packet flow with a particular end point.=C2=A0 This is simplest when all
packets flowing through a given point are for that end point.=C2=A0 It is=

harder when you are dealing with a single shared medium.=C2=A0 And it is
imperfect =E2=80=93 to say the least =E2=80=93 if one is attempting to pr=
event east-west
infection, although you can still provide some protection north/south.=C2=
=A0
To deploy north of a NAT one could consider flowing all traffic in the
home over a softwire, but that has its own attendant headaches with
efficiencies, latency, and jitter if you are also intending to address
east/west.

Another way of looking at it is this:

MUD does not create new in-path mechanism.=C2=A0 However, if you can spec=
ify
a static policy somehow on an enforcement point, then it should be
"MUDable" in some form.=C2=A0 MUD just provides a vehicle to specify the
configuration of, say, iptables or IOS/JunOS config or the like.

Eliot

>
> Maybe we should link up and talk about it.

Would be delighted.

Eliot

[*] Set the WayBack Machine to the 1990s and you would find an earlier
version of Eliot writing RFC 1627 and screaming "NAT is Evil", and so
this is a throwback to that ;-)




--IcHBLlSjhD4tm2qkPgXWG1GQ8uLxfjCAX--

--iJD4tWOmbUdoiva4xfU71mrfkumIW0rWR
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2

iQEcBAEBCAAGBQJaCwQnAAoJEIe2a0bZ0nozzxgH/i3qMOf9SmexIYQHxv23MzKO
aFQRtz9S62DCUHvBt43apEAZOcaWo+KvMuVYKxU9OxZOCAue4J9UqB1vWkJ6I3om
tYdJFJAOw3OukiIJ6zAT0AwmkruGnMeW8QdnypfoAUmfaHT3H3ktubJC9sBxjmI+
dFwWVEYZusrLvZWTp8omGneU4khwj+LZeGNLMkgwdh1f3NNVxaaaGjSMldAxyoF0
oUM1F0GMN7Ie/1mAqJLf9zOnMqZng1+Kp/NIezRYajKe2kmtS0f+evGsODdSKthp
HEyXjsc8PydaWDa4MHqYPPjpr0Nd7jSqiWmz4cBbnhP/yZ+F6tAHoFFkDLW6+jU=
=HEJ8
-----END PGP SIGNATURE-----

--iJD4tWOmbUdoiva4xfU71mrfkumIW0rWR--


From nobody Tue Nov 14 17:22:38 2017
Return-Path: <jclarke@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7C254129418 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 17:22:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4uwF2GRiSt52 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 17:22:35 -0800 (PST)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 99A9512940B for <opsawg@ietf.org>; Tue, 14 Nov 2017 17:22:35 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=125; q=dns/txt; s=iport; t=1510708955; x=1511918555; h=to:from:subject:message-id:date:mime-version: content-transfer-encoding; bh=8u2JpK3ElTVzFSOa2O9d90tQyKsn8M/i3qGBXxKCFkg=; b=YQ2p0UWKnv1iqObAU9/eJOtnJLsXtsS78Y/wOYEtCR4NdU+IWZe8FZDx zDvzaLnfeuiNKODO0/QmlRc/iV9dOib+O0vI96qUvqjE2hXau3dTNzKbq iftEgSVPJSpA6octYQibqurwlr1cRzFNEOKaDqEet9RpGJpTEI0nQbOoR M=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0D6AQAzlgta/40NJK1dGQEBAQEBAQEBA?= =?us-ascii?q?QEBAQcBAQEBAYM2gVKEJZlQgVeZDgqKPkMUAQEBAQEBAQEBax0LhUiBCwImAl8?= =?us-ascii?q?NCAEBih+rBYInixYBAQEHAgElgQ+CJYIHgVWCEguCdogtgmMFkwOPMZUGgXwBi?= =?us-ascii?q?gCHRZYrgTk2IYFzVSUVgy6EfCOJIAEBAQ?=
X-IronPort-AV: E=Sophos;i="5.44,397,1505779200"; d="scan'208";a="31547713"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 15 Nov 2017 01:22:34 +0000
Received: from [10.24.11.192] ([10.24.11.192]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id vAF1MX3l000788 for <opsawg@ietf.org>; Wed, 15 Nov 2017 01:22:34 GMT
To: "opsawg@ietf.org" <opsawg@ietf.org>
From: Joe Clarke <jclarke@cisco.com>
Organization: Cisco
Message-ID: <a791837c-a4b6-8583-1e4b-79b8b30d9a0f@cisco.com>
Date: Tue, 14 Nov 2017 20:22:32 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/EYNnZY8y6BMfDAFjHEHgQrEfiZI>
Subject: [OPSAWG] New MUD slides
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 01:22:36 -0000

Eliot submitted the right slide deck (i.e., what he talked about
yesterday).  I updated the meeting materials site.

Joe


From nobody Tue Nov 14 21:40:56 2017
Return-Path: <jclarke@cisco.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3BC5C128DF2 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 21:40:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hA8rESmawG9i for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 21:40:54 -0800 (PST)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B6D81243F6 for <opsawg@ietf.org>; Tue, 14 Nov 2017 21:40:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=237; q=dns/txt; s=iport; t=1510724454; x=1511934054; h=to:from:subject:message-id:date:mime-version: content-transfer-encoding; bh=70IAgyWdp8Ukw0q6Z2RnfO9IdGX6UiWI9FAgGlUEYcQ=; b=lqE4QPGQH7CbFoqb/xgxw4Ne5N5980v92jG1Sznj6xjT+TMIf31jYEQE JlerLqcTggJjCdfxT7iVsVtPVntwAZXcv3mrFoVjeVZkp3zKwSfRaXC3+ umBWtArXh/LY3o8Ss7lCCZTmR2WGA5eUs4fwQU+DvwUJafmn7g8TWMMlG 4=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0CpAABx0gta/5tdJa1dGQEBAQEBAQEBA?= =?us-ascii?q?QEBAQcBAQEBAYM2gVKEJYofjzGYVIIRCoo+PxgBAQEBAQEBAQFrHQuFSIELAiY?= =?us-ascii?q?CXw0IAQEQig+qY4InixoBAQEHAgElgQ+CJYIHgVWCEguCdoEwhn2CQyAFkwOPM?= =?us-ascii?q?YF0kxKBfAEYhgiDYIdFcJU7gTkfOIFzVSUVgy6EfCOJHQEBAQ?=
X-IronPort-AV: E=Sophos;i="5.44,398,1505779200"; d="scan'208";a="31724577"
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by alln-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 15 Nov 2017 05:40:53 +0000
Received: from [10.24.101.203] ([10.24.101.203]) by rcdn-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id vAF5epRd022216 for <opsawg@ietf.org>; Wed, 15 Nov 2017 05:40:53 GMT
To: "opsawg@ietf.org" <opsawg@ietf.org>
From: Joe Clarke <jclarke@cisco.com>
Organization: Cisco
Message-ID: <f69a0291-932e-f3ea-2444-c38267d8dc97@cisco.com>
Date: Wed, 15 Nov 2017 00:40:52 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/UcGl2nDW5zzgiMVFFctok1u3CYk>
Subject: [OPSAWG] Request for document shepherd for draft-ietf-opsawg-ipfix-bgp-community
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 05:40:55 -0000

As Ignas mentioned in yesterday's meeting, we're looking for a document
shepherd for draft-ietf-opsawg-ipfix-bgp-community, specifically one who
is an operator.

If you are interested, please let the chairs know.  Thank you.

Joe


From nobody Tue Nov 14 22:01:06 2017
Return-Path: <ibagdona.ietf@gmail.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 51F411294F5 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 22:01:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level: 
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aDmLXSzDVFxV for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 22:01:03 -0800 (PST)
Received: from mail-it0-x22e.google.com (mail-it0-x22e.google.com [IPv6:2607:f8b0:4001:c0b::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 999B81294F0 for <opsawg@ietf.org>; Tue, 14 Nov 2017 22:01:03 -0800 (PST)
Received: by mail-it0-x22e.google.com with SMTP id f187so489861itb.1 for <opsawg@ietf.org>; Tue, 14 Nov 2017 22:01:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-transfer-encoding:content-language; bh=h6/jXQGdqGzC/eIuCYOGPmfpV8TVxsxAbMMZSHbsVnA=; b=lyMWzZ4l1VP7rAAgHN6q1s5CVyU5O3KMdQXH50gGuEXVnAxujoaQlziidLoTPCMtOu VjRLjzgl3ayajHXh6BbeCss3546bGwDBX8bHVyFWZlcfcOzQWOmqbgQ2I5UCHIC9hZ0S Wb7VRkQU1FIPjmDb7mkBcE8MD1C6oBoAiqphzdCwDJQMJpDQFMuJw4BF0oP3Z6Nyl2tF /amk28s/kVfoKbKkooV9dO6MIWoS4UHBoid5yxjnLtLeUcPzE86EXKDqAu4yaIJST0cW CSO4U8zYj4qm8QWSxzvwkP7DWaqN8QZein6pQhg8KTtDBcJIvraSkMRxmmO3b0WaxhtD 0Amw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=h6/jXQGdqGzC/eIuCYOGPmfpV8TVxsxAbMMZSHbsVnA=; b=aPkXdXmmvaBodxlGFDZ/dOotosgkSLIPfNHB2lgr2qPY97fQ3ww85Mf10LuokriSG6 pM3VVMWPMamLEjfrXzkyZPPS2+O2FaCZh8PGZyI8rTMuNFo9xL1v+JwVnGmxv1uZMkHt Q/vekgM+zvR90Qf22jGPf4p3txBo8nz3sZ/2ATnVGstL5I/+Rq1I6uWziX4Mr1qjucPR z01dMhrxqwlzXc+Bv2eJJ/fMJQqWIgZDRcsxz/AqCL2VDQEtD2djkzOjTdDFI9sMexe2 6NggLPqb0iBJ0MueCUyjOf56uyvUTvRxBeSAZ7YsQqF31zJjUF7sORCMy/4z9Ajz90hV 3XiA==
X-Gm-Message-State: AJaThX4+lzq1aOM6VBtZ4HglYEhjMoYFoVEKLUwX22nYKg1ORIgyZ5gW 3Zez/OJiymb9iGw9YBXS9jlj1BIg
X-Google-Smtp-Source: AGs4zMYvtqNnhLdxo2uxUCAaaDHWkWUTzSPBQf3XdUnp/vXhAphdSuHFoRmQo/fWBWccn1vp3OXecQ==
X-Received: by 10.36.163.200 with SMTP id p191mr16240610ite.27.1510725662726;  Tue, 14 Nov 2017 22:01:02 -0800 (PST)
Received: from [31.133.137.192] (dhcp-89c0.meeting.ietf.org. [31.133.137.192]) by smtp.gmail.com with ESMTPSA id a17sm9473770ioe.55.2017.11.14.22.01.00 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 14 Nov 2017 22:01:01 -0800 (PST)
To: Joe Clarke <jclarke@cisco.com>, "opsawg@ietf.org" <opsawg@ietf.org>
References: <f69a0291-932e-f3ea-2444-c38267d8dc97@cisco.com>
From: Ignas Bagdonas <ibagdona.ietf@gmail.com>
Message-ID: <6fa18eea-6a02-0c42-903a-b825097fe0ae@gmail.com>
Date: Wed, 15 Nov 2017 06:00:57 +0000
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <f69a0291-932e-f3ea-2444-c38267d8dc97@cisco.com>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Content-Language: en-GB
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/3hDTIYyGWPjipKh5xFvPUVI3ojg>
Subject: Re: [OPSAWG] Request for document shepherd for draft-ietf-opsawg-ipfix-bgp-community
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 06:01:05 -0000

A clarification addition - it is not a hard requirement for shepherd to 
be associated with an operator, it is a strong wish though as the 
document would benefit from being guided through the publication process 
by someone who would be a potential user of the proposed mechanism. In 
addition, any other review, especially by potential users of the 
proposed mechanism would be really appreciated.

Thank you Joe for raising this.

Ignas



On 15/11/2017 05:40, Joe Clarke wrote:
> As Ignas mentioned in yesterday's meeting, we're looking for a document
> shepherd for draft-ietf-opsawg-ipfix-bgp-community, specifically one who
> is an operator.
>
> If you are interested, please let the chairs know.  Thank you.
>
> Joe
>
> _______________________________________________
> OPSAWG mailing list
> OPSAWG@ietf.org
> https://www.ietf.org/mailman/listinfo/opsawg


From nobody Tue Nov 14 22:33:33 2017
Return-Path: <li_zhenqiang@hotmail.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D517C1294A2 for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 22:33:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.124
X-Spam-Level: 
X-Spam-Status: No, score=-1.124 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0GqMOJqmtkBv for <opsawg@ietfa.amsl.com>; Tue, 14 Nov 2017 22:33:30 -0800 (PST)
Received: from APC01-SG2-obe.outbound.protection.outlook.com (mail-oln040092253093.outbound.protection.outlook.com [40.92.253.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA713128B88 for <opsawg@ietf.org>; Tue, 14 Nov 2017 22:33:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=XMARVakH6/VZCU2QZwYhOvEYkIU6lK2axDtyJTmx/z4=; b=OsMyfKs+p3IWRs1hl1E9+6R8FZiv/AFIASBcfGP8dtd0y9XMCJqQPYrN3JGVB3lN3GcNut8tx5cTZO0k4C8E/6glhGDK7u60yKH+5NjX2TE0x76sV9XkNrkrzwlnWHXnJmCvp1UFYPIdHhFjO+Tmj136k0xPOyHsDxpsUolbkS450bILpJwt7sJlYZ83V6fKWzGuGzhbxs3ALBFOauXDTS/qLz5VIjhNSSH8dXwB+1OoyiUta8RBe/0Ijx7x0XaPiG3QzR+A+EYWbaBoBB/5uB7qkrFKuoqwv5F7WtjhVPxPiAu0SCDIUKXPylCL1xVY6JbZ1JFmrcwQc5VDigC7SA==
Received: from HK2APC01FT053.eop-APC01.prod.protection.outlook.com (10.152.248.58) by HK2APC01HT062.eop-APC01.prod.protection.outlook.com (10.152.249.71) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.20.156.4; Wed, 15 Nov 2017 06:33:26 +0000
Received: from KL1PR0601MB1494.apcprd06.prod.outlook.com (10.152.248.59) by HK2APC01FT053.mail.protection.outlook.com (10.152.249.8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.20.178.5 via Frontend Transport; Wed, 15 Nov 2017 06:33:26 +0000
Received: from KL1PR0601MB1494.apcprd06.prod.outlook.com ([fe80::9cf9:94bc:1d27:7c3d]) by KL1PR0601MB1494.apcprd06.prod.outlook.com ([fe80::9cf9:94bc:1d27:7c3d%14]) with mapi id 15.20.0218.015; Wed, 15 Nov 2017 06:33:26 +0000
From: li zhenqiang <li_zhenqiang@hotmail.com>
To: Ignas Bagdonas <ibagdona.ietf@gmail.com>, Joe Clarke <jclarke@cisco.com>,  opsawg <opsawg@ietf.org>
Thread-Topic: Re: [OPSAWG] Request for document shepherd for draft-ietf-opsawg-ipfix-bgp-community
Thread-Index: AQHTXdujDwEDbCm1A0qaFDOPGVpy9w==
Date: Wed, 15 Nov 2017 06:33:25 +0000
Message-ID: <KL1PR0601MB149488CABC8CE73E99F8E8DFFC290@KL1PR0601MB1494.apcprd06.prod.outlook.com>
References: <f69a0291-932e-f3ea-2444-c38267d8dc97@cisco.com>, <6fa18eea-6a02-0c42-903a-b825097fe0ae@gmail.com>
Accept-Language: zh-CN, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=hotmail.com;
x-incomingtopheadermarker: OriginalChecksum:F2AF66893164EE05BD703851C98EA9F3936E47A957D24F8510D2D9740E993C28; UpperCasedChecksum:BC690A3BBEA9739DA0B63F4A9852DCAAAF243958C23B3C68BE1EF81D9BC37DA5; SizeAsReceived:7207; Count:45
x-ms-exchange-messagesentrepresentingtype: 1
x-tmn: [Yy1Khqy5oU4WpujClTGok74pR88yBr95]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; HK2APC01HT062; 6:ehnlUsKRvh0R/dI1du2uW2qAq1iiJW7bY7+IFaW8iHql86L9Y7+lkTLsDkmpXfTWlXGYbcJWgp8rMv1zyiiGKUMHxsm/th70qCeQEhXVgdI4LfBBenfptZM9liXJxwvvVAtZnIn/q1smxxIMAAkUGQYx9JISR8X+Q1y2fQrcMYVjn6In1VqbLkKqefawFEvsVI0E5ELn6YcoUeFPnZ9fZ6bE7vOeiAM1bLNxXKLqNY3/MlzTG9REnAoV8Rvvd7QfIM15mmFl7YwwBNuEOOG98PWW7eF7g6MYwqt04TEC551tmXLSzKopUC/FBXsZWsfE9jI5Ae6SfNpJE+9Y+Bu4Iw==; 5:/iZgbJvNosNS8G3bN2IeyBREtEs9gcv8LCq+VFNlrwwYr+7z1xC79zCIJ5PTypSew7L0fBmRkha86brDsLg+vZT9k7NfhBM/rrZKqR8aYzWwOfleFmDHQ7RT0j4SvtLSqPpmFjkeuWOEQpoJ+Hc9Xg==; 24:Sg23RI03nyyVYWvyhH7QcbNxtTKEgAcHU9Vq5hs484tnKcz4v+v9e3iN+ADhlsV9T9pgT4kBgeIxn4BnqOC6s6LzwKyPI5R4KO3thF5OGt8=; 7:r1A1a/2/SKksoL2x810oDbNejpgev9pHTNCmx2+j54paUfcV8dWhLJPLAOc3GadT+5D9XVDgy94i4qpY28crcqVwXu5q80B9OOMRxj3BGhEQraMTW9NAoD9WsyNpXCMdNVQqDBaL/CvEgbVmzzqmVEVF7ojjWEf3OV3097BTznkg07oVXDwDzBCIBXyxZHN9Gb0Y0ulvQvy8YwZDScZIJaBxFQlJKfwweYFNnjCrJBU=
x-incomingheadercount: 45
x-eopattributedmessage: 0
x-ms-office365-filtering-correlation-id: 77bb1bc8-a672-48ef-d41f-08d52bf2c595
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(201702061074)(5061506573)(5061507331)(1603103135)(2017031320274)(2017031324274)(2017031323274)(2017031322404)(1603101448)(1601125374)(1701031045); SRVR:HK2APC01HT062; 
x-ms-traffictypediagnostic: HK2APC01HT062:
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(444000031); SRVR:HK2APC01HT062; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:HK2APC01HT062; 
x-forefront-prvs: 0492FD61DD
x-forefront-antispam-report: SFV:NSPM; SFS:(7070007)(98901004); DIR:OUT; SFP:1901; SCL:1; SRVR:HK2APC01HT062; H:KL1PR0601MB1494.apcprd06.prod.outlook.com; FPR:; SPF:None; LANG:; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_KL1PR0601MB149488CABC8CE73E99F8E8DFFC290KL1PR0601MB1494_"
MIME-Version: 1.0
X-OriginatorOrg: hotmail.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 77bb1bc8-a672-48ef-d41f-08d52bf2c595
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Nov 2017 06:33:25.9336 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Internet
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HK2APC01HT062
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/5PB-is4-iCO9UyB_WNIQMFwnn74>
Subject: Re: [OPSAWG] Request for document shepherd for draft-ietf-opsawg-ipfix-bgp-community
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 06:33:32 -0000

--_000_KL1PR0601MB149488CABC8CE73E99F8E8DFFC290KL1PR0601MB1494_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Thank you, chairs. And I will update the draft soon after this busy week.

________________________________
li_zhenqiang@hotmail.com

From: Ignas Bagdonas<mailto:ibagdona.ietf@gmail.com>
Date: 2017-11-15 14:00
To: Joe Clarke<mailto:jclarke@cisco.com>; opsawg@ietf.org<mailto:opsawg@iet=
f.org>
Subject: Re: [OPSAWG] Request for document shepherd for draft-ietf-opsawg-i=
pfix-bgp-community
A clarification addition - it is not a hard requirement for shepherd to
be associated with an operator, it is a strong wish though as the
document would benefit from being guided through the publication process
by someone who would be a potential user of the proposed mechanism. In
addition, any other review, especially by potential users of the
proposed mechanism would be really appreciated.

Thank you Joe for raising this.

Ignas



On 15/11/2017 05:40, Joe Clarke wrote:
> As Ignas mentioned in yesterday's meeting, we're looking for a document
> shepherd for draft-ietf-opsawg-ipfix-bgp-community, specifically one who
> is an operator.
>
> If you are interested, please let the chairs know.  Thank you.
>
> Joe
>
> _______________________________________________
> OPSAWG mailing list
> OPSAWG@ietf.org
> https://www.ietf.org/mailman/listinfo/opsawg

_______________________________________________
OPSAWG mailing list
OPSAWG@ietf.org
https://www.ietf.org/mailman/listinfo/opsawg

--_000_KL1PR0601MB149488CABC8CE73E99F8E8DFFC290KL1PR0601MB1494_
Content-Type: text/html; charset="iso-8859-1"
Content-ID: <05872F763AE00945BB3F2FEBB40D820E@apcprd06.prod.outlook.com>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style>body { line-height: 1.5; }blockquote { margin-top: 0px; margin-botto=
m: 0px; margin-left: 0.5em; }body { font-size: 10.5pt; font-family: ????; c=
olor: rgb(0, 0, 0); line-height: 1.5; }</style>
</head>
<body>
<div><span></span>Thank you, chairs. And I will update the draft soon after=
 this busy week.</div>
<div><br>
</div>
<hr style=3D"width: 210px; height: 1px;" color=3D"#b5c4df" size=3D"1" align=
=3D"left">
<div><span>
<div style=3D"MARGIN: 10px; FONT-FAMILY: verdana; FONT-SIZE: 10pt">
<div>li_zhenqiang@hotmail.com</div>
</div>
</span></div>
<blockquote style=3D"margin-Top: 0px; margin-Bottom: 0px; margin-Left: 0.5e=
m">
<div>&nbsp;</div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<div style=3D"PADDING-RIGHT: 8px; PADDING-LEFT: 8px; FONT-SIZE: 12px;FONT-F=
AMILY:tahoma;COLOR:#000000; BACKGROUND: #efefef; PADDING-BOTTOM: 8px; PADDI=
NG-TOP: 8px">
<div><b>From:</b>&nbsp;<a href=3D"mailto:ibagdona.ietf@gmail.com">Ignas Bag=
donas</a></div>
<div><b>Date:</b>&nbsp;2017-11-15&nbsp;14:00</div>
<div><b>To:</b>&nbsp;<a href=3D"mailto:jclarke@cisco.com">Joe Clarke</a>; <=
a href=3D"mailto:opsawg@ietf.org">
opsawg@ietf.org</a></div>
<div><b>Subject:</b>&nbsp;Re: [OPSAWG] Request for document shepherd for dr=
aft-ietf-opsawg-ipfix-bgp-community</div>
</div>
</div>
<div>
<div>A clarification addition - it is not a hard requirement for shepherd t=
o </div>
<div>be associated with an operator, it is a strong wish though as the </di=
v>
<div>document would benefit from being guided through the publication proce=
ss </div>
<div>by someone who would be a potential user of the proposed mechanism. In=
 </div>
<div>addition, any other review, especially by potential users of the </div=
>
<div>proposed mechanism would be really appreciated.</div>
<div>&nbsp;</div>
<div>Thank you Joe for raising this.</div>
<div>&nbsp;</div>
<div>Ignas</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>On 15/11/2017 05:40, Joe Clarke wrote:</div>
<div>&gt; As Ignas mentioned in yesterday's meeting, we're looking for a do=
cument</div>
<div>&gt; shepherd for draft-ietf-opsawg-ipfix-bgp-community, specifically =
one who</div>
<div>&gt; is an operator.</div>
<div>&gt;</div>
<div>&gt; If you are interested, please let the chairs know.&nbsp; Thank yo=
u.</div>
<div>&gt;</div>
<div>&gt; Joe</div>
<div>&gt;</div>
<div>&gt; _______________________________________________</div>
<div>&gt; OPSAWG mailing list</div>
<div>&gt; OPSAWG@ietf.org</div>
<div>&gt; https://www.ietf.org/mailman/listinfo/opsawg</div>
<div>&nbsp;</div>
<div>_______________________________________________</div>
<div>OPSAWG mailing list</div>
<div>OPSAWG@ietf.org</div>
<div>https://www.ietf.org/mailman/listinfo/opsawg</div>
</div>
</blockquote>
</body>
</html>

--_000_KL1PR0601MB149488CABC8CE73E99F8E8DFFC290KL1PR0601MB1494_--


From nobody Wed Nov 15 23:48:56 2017
Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 380D2128BB7 for <opsawg@ietfa.amsl.com>; Wed, 15 Nov 2017 23:48:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.618
X-Spam-Level: 
X-Spam-Status: No, score=-2.618 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LIs9F1uOjPvv for <opsawg@ietfa.amsl.com>; Wed, 15 Nov 2017 23:48:51 -0800 (PST)
Received: from orange.com (mta239.mail.business.static.orange.com [80.12.66.39]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1A861287A0 for <opsawg@ietf.org>; Wed, 15 Nov 2017 23:48:50 -0800 (PST)
Received: from opfedar05.francetelecom.fr (unknown [xx.xx.xx.7]) by opfedar25.francetelecom.fr (ESMTP service) with ESMTP id A5698120EEF; Thu, 16 Nov 2017 08:48:49 +0100 (CET)
Received: from Exchangemail-eme2.itn.ftgroup (unknown [xx.xx.31.32]) by opfedar05.francetelecom.fr (ESMTP service) with ESMTP id 85B4560060; Thu, 16 Nov 2017 08:48:49 +0100 (CET)
Received: from OPEXCLILMA3.corporate.adroot.infra.ftgroup ([fe80::60a9:abc3:86e6:2541]) by OPEXCLILM32.corporate.adroot.infra.ftgroup ([fe80::8924:188:2124:a046%19]) with mapi id 14.03.0361.001; Thu, 16 Nov 2017 08:48:49 +0100
From: <mohamed.boucadair@orange.com>
To: "opsawg@ietf.org" <opsawg@ietf.org>
CC: "Mahesh Jethanandani (mjethanandani@gmail.com)" <mjethanandani@gmail.com>
Thread-Topic: Yangdoctors early review of draft-ietf-softwire-dslite-yang-02
Thread-Index: AdNeEEwa3+st5dtyQzeLVA1NKw2GhAAVReEAABIs7QA=
Date: Thu, 16 Nov 2017 07:48:48 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B93300A07B603@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
References: <787AE7BB302AE849A7480A190F8B93300A07ACDC@OPEXCLILMA3.corporate.adroot.infra.ftgroup> <D500C3F8-A809-4553-89BA-319EBDA09BDE@gmail.com>
In-Reply-To: <D500C3F8-A809-4553-89BA-319EBDA09BDE@gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.168.234.6]
Content-Type: multipart/alternative; boundary="_000_787AE7BB302AE849A7480A190F8B93300A07B603OPEXCLILMA3corp_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/PNsTA18OG-TV-SXHHbyCqBAExKI>
Subject: [OPSAWG] TR: Yangdoctors early review of draft-ietf-softwire-dslite-yang-02
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 07:48:54 -0000

--_000_787AE7BB302AE849A7480A190F8B93300A07B603OPEXCLILMA3corp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

RGVhciBhbGwsDQoNCknigJltIHNoYXJpbmcgdGhlc2UgY29tbWVudHMgZnJvbSBNYWhlc2ggKG9u
IGFub3RoZXIgZG9jdW1lbnQpLCBidXQgd2hpY2ggaGF2ZSB0aGUgZm9sbG93aW5nIGltcGxpY2F0
aW9ucyBvbiB0aGUgTkFUIFlBTkcgbW9kdWxlOg0KDQotIENpdGUgSS1ELmlldGYtbmV0bW9kLXlh
bmctdHJlZS1kaWFncmFtcyBpbnN0ZWFkIG9mIGluY2x1ZGluZyB0aGUgZGVzY3JpcHRpb24gb2Yg
dGhlIHN5bWJvbHMuIEktRC5pZXRmLW5ldG1vZC15YW5nLXRyZWUtZGlhZ3JhbXMgd2lsbCBiZSBj
aXRlZCBhcyBhbiBpbmZvcm1hdGlvbmFsIHJlZmVyZW5jZS4NCi0gUmVtb3ZlIHJlZmVyZW5jZSB0
byBjaGFpcnMgaW4gdGhlIFlBTkcgbW9kdWxlLg0KLSBBZGQgYW4gZXhwbGljaXQgbm9kZSB0byBj
b25maWd1cmUgYSBOQVQgdHlwZQ0KDQpDaGVlcnMsDQpNZWQNCg0KRGUgOiBNYWhlc2ggSmV0aGFu
YW5kYW5pIFttYWlsdG86bWpldGhhbmFuZGFuaUBnbWFpbC5jb21dDQpFbnZvecOpIDogamV1ZGkg
MTYgbm92ZW1icmUgMjAxNyAwMDo1OQ0Kw4AgOiBCT1VDQURBSVIgTW9oYW1lZCBJTVQvT0xODQpD
YyA6IHlhbmctZG9jdG9yc0BpZXRmLm9yZzsgc29mdHdpcmVzQGlldGYub3JnOyBkcmFmdC1pZXRm
LXNvZnR3aXJlLWRzbGl0ZS15YW5nLmFsbEBpZXRmLm9yZzsgTmV0TW9kIFdHIENoYWlyczsgQmVu
b2l0IENsYWlzZQ0KT2JqZXQgOiBSZTogWWFuZ2RvY3RvcnMgZWFybHkgcmV2aWV3IG9mIGRyYWZ0
LWlldGYtc29mdHdpcmUtZHNsaXRlLXlhbmctMDINCg0KTWVkLA0KDQpTZWUgaW5saW5lLg0KDQpP
biBOb3YgMTUsIDIwMTcsIGF0IDg6NTAgUE0sIG1vaGFtZWQuYm91Y2FkYWlyQG9yYW5nZS5jb208
bWFpbHRvOm1vaGFtZWQuYm91Y2FkYWlyQG9yYW5nZS5jb20+IHdyb3RlOg0KDQpIaSBNYWhlc2gs
DQoNClRoYW5rIHlvdSBmb3IgdGhlIGZlZWRiYWNrLg0KDQpQbGVhc2Ugc2VlIGlubGluZS4NCg0K
Q2hlZXJzLA0KTWVkDQoNCg0KLS0tLS1NZXNzYWdlIGQnb3JpZ2luZS0tLS0tDQpEZSA6IE1haGVz
aCBKZXRoYW5hbmRhbmkgW21haWx0bzptamV0aGFuYW5kYW5pQGdtYWlsLmNvbV0NCkVudm95w6kg
OiBtYXJkaSAxNCBub3ZlbWJyZSAyMDE3IDIzOjU5DQrDgCA6IEJPVUNBREFJUiBNb2hhbWVkIElN
VC9PTE4NCkNjIDogeWFuZy1kb2N0b3JzQGlldGYub3JnPG1haWx0bzp5YW5nLWRvY3RvcnNAaWV0
Zi5vcmc+OyBzb2Z0d2lyZXNAaWV0Zi5vcmc8bWFpbHRvOnNvZnR3aXJlc0BpZXRmLm9yZz47IGRy
YWZ0LWlldGYtc29mdHdpcmUtDQpkc2xpdGUteWFuZy5hbGxAaWV0Zi5vcmc8bWFpbHRvOmRzbGl0
ZS15YW5nLmFsbEBpZXRmLm9yZz47IE5ldE1vZCBXRyBDaGFpcnM7IEJlbm9pdCBDbGFpc2UNCk9i
amV0IDogUmU6IFlhbmdkb2N0b3JzIGVhcmx5IHJldmlldyBvZiBkcmFmdC1pZXRmLXNvZnR3aXJl
LWRzbGl0ZS15YW5nLTAyDQoNCk1vaGFtZWQsDQoNCkkgcmVhbGl6ZSB0aGF0IEkgYW0gcmVzcG9u
ZGluZyB0byBhbiBlYXJsaWVyIHRocmVhZCB0aGFuIHRoZSBvbmUgeW91IGFza2VkDQp5b3VyIHF1
ZXN0aW9uIG9uLCBzbyBsZXQgbWUgYWRkcmVzcyB0aGUgcXVlc3Rpb24gdGhhdCB5b3UgYXNrZWQg
b24gdGhhdA0KdGhyZWFkIGZpcnN0Lg0KDQpZZXMsIHRoZSBuZXRtb2QgdHJlZSBkaWFncmFtcyBk
cmFmdCBpcyBub3QgYW4gUkZDLCBhbmQgeWFuZy1kb2N0b3JzIGRvDQpyZWNvbW1lbmQgdGhhdCBh
dXRob3JzIG9mIGRyYWZ0cyB3aXRoIFlBTkcgbW9kdWxlIHJlZmVyZW5jZSB0aGUgbmV0bW9kDQp0
cmVlIGRpYWdyYW0gZHJhZnQgcmF0aGVyIHRoYW4gY3V0IGFuZCBwYXN0ZSBkZXNjcmlwdGlvbiBv
ZiB0aGUgdHJlZQ0Kc3ltYm9scyBpbnRvIHRoZWlyIGRyYWZ0cy4gVG8gdGhlIHF1ZXN0aW9uIG9m
IHdoZXRoZXIgdGhhdCByZWZlcmVuY2UgY2FuDQpiZSBpbmZvcm1hdGl2ZSBvciBkb2VzIGl0IGhh
dmUgdG8gYmUgbm9ybWF0aXZlLCBJIHdvdWxkIGFncmVlIHRoYXQgaXQgaGFzDQp0byBiZSBub3Jt
YXRpdmUuIEkgcmVhbGl6ZSB0aGF0IG1pZ2h0IGltcGFjdCB0aGUgcHVibGljYXRpb24gb2YgdGhl
IGRyYWZ0LA0Kc28gSSBhbSBpbmNsdWRpbmcgdGhlIGNoYWlycyBvZiBORVRNT0QgV0coYW5kIG9u
ZSBvZiB0aGUgYXV0aG9ycykgdG8gZ2V0DQphbiBpZGVhIG9mIHdoZW4gdGhleSB0aGluayB0aGUg
ZHJhZnQgY291bGQgYmUgcHVibGlzaGVkIGFzIGFuIFJGQy4NCg0KW01lZF0gV2UgbmVlZCBndWlk
YW5jZSBob3cgdG8gcHJvY2VlZCBnaXZlbiB0aGF0IHdlIGRvIGhhdmUgdHdvIGRyYWZ0cyBpbiB0
aGUgc29mdHdpcmUgV0cgdGhhdCBhcmUgaW1wYWN0ZWQgKHRoaXMgb25lIHBhc3NlZCB0aGUgV0dM
Qywgd2hpbGUgdGhlIHNlY29uZCBvbmUgd2lsbCBiZSBvbiB0aGUgV0dMQyBzb29uKS4gQlRXLCBh
biBhcmd1bWVudCBJIGhlYXJkIHJlY2VudGx5IGlzIHRoYXQgdGhlIG5ldG1vZCBkb2N1bWVudCBj
YW4gYmUgY2l0ZWQgYXMgaW5mb3JtYXRpdmUgZ2l2ZW4gdGhhdCB0aGUgdHJlZSBzdHJ1Y3R1cmUg
aXRzZWxmIGlzIG5vdCBub3JtYXRpdmUuDQoNCkkgZGlkIGJyaW5nIHVwIHRoZSBxdWVzdGlvbiB5
ZXN0ZXJkYXkgaW4gTkVUTU9ELCBhbmQgeWVzIHRoZSBjb25zZW5zdXMgaW4gTkVUTU9EIGlzIHRv
IG1vdmUgdGhlIHRyZWUgZGlhZ3JhbSBkb2N1bWVudCBmcm9tIFN0YW5kYXJkcyBUcmFjayB0byBJ
bmZvcm1hdGlvbmFsLCB3aGVyZSBpdCBjYW4gdGhlbiBiZSBjaXRlZCBhcyBpbmZvcm1hdGlvbmFs
Lg0KDQoNCg0KDQpCdXQgYmVmb3JlIHlvdSBydXNoIGludG8gcHVibGljYXRpb24sIEkgdG9vayBh
bm90aGVyIGxvb2sgYXQgdGhlIC0wOA0KdmVyc2lvbiBvZiB0aGUgZHJhZnQsIGFuZCBJIGhhdmUg
YWRkaXRpb25hbCBjb25jZXJucyBhYm91dCB0aGUgZHJhZnQgYW5kDQp0aGUgWUFORyBtb2R1bGUg
aW4gaXQsIHRoYXQgSSBiZWxpZXZlIHdhcnJhbnQgYW5vdGhlciBsb29rLg0KDQpNaW5vciBjb21t
ZW50cw0KDQotIFBsZWFzZSByZW1vdmUgcmVmZXJlbmNlIHRvIGNoYWlycyBpbiB0aGUgWUFORyBt
b2R1bGUuIEFsbCB3ZSByZWNvbW1lbmQNCmFyZSB0aGUgYXV0aG9ycy9lZGl0b3JzLg0KDQpbTWVk
XSBEb25lLg0KDQoNCi0gUGxlYXNlIGFkZCBhIG5vdGUgZm9yIHRoZSBSRkMgZWRpdG9yIHRvIHJl
cGxhY2Ug4oCcUkZDIFhYWFjigJ0gd2l0aCB0aGUgUkZDDQpudW1iZXIgd2hlbiB0aGUgZHJhZnQg
aXMgcHVibGlzaGVkLg0KDQpbTWVkXSBUaGVyZSBpcyBhbHJlYWR5IHRoaXMgbm90ZSBpbiB0aGUg
ZHJhZnQ6DQoNCj09PQ0KRWRpdG9yaWFsIE5vdGUgKFRvIGJlIHJlbW92ZWQgYnkgUkZDIEVkaXRv
cikNCg0KICBQbGVhc2UgdXBkYXRlIHRoZXNlIHN0YXRlbWVudHMgd2l0aCB0aGUgUkZDIG51bWJl
ciB0byBiZSBhc3NpZ25lZCB0bw0KICB0aGlzIGRvY3VtZW50Og0KDQogIG8gICJUaGlzIHZlcnNp
b24gb2YgdGhpcyBZQU5HIG1vZHVsZSBpcyBwYXJ0IG9mIFJGQyBYWFhYOyINCg0KICBvICAiUkZD
IFhYWFg6IFlBTkcgRGF0YSBNb2R1bGVzIGZvciBEdWFsLVN0YWNrIExpdGUgKERTLUxpdGUpIjsN
Cg0KICBvICAicmVmZXJlbmNlOiBSRkMgWFhYWCINCj09PQ0KDQoNCi0gVGhlIGluZGVudGF0aW9u
cyBpbiB0aGUgWUFORyBtb2R1bGUgYXJlIHN0aWxsIG5vdCBjb25zaXN0ZW50LiBQbGVhc2UgZml4
DQp0aGVtLg0KDQpbTWVkXSBPSy4NCg0KDQoNCkFkZGl0aW9uYWwgY29tbWVudHM6DQotIFRoZSBZ
QU5HIG1vZHVsZSBtYWtlcyBtdWx0aXBsZSByZWZlcmVuY2VzIHRvIHN1YnNjcmliZXItbWFzayBh
cyBhIHdheSB0bw0KdW5pcXVlbHkgaWRlbnRpdHkgYSBzdWJzY3JpYmVyLiBUaGF0LCBhcyB5b3Ug
c2F5IGlzIGRlcml2ZWQgZnJvbSB0aGUgTkFUDQptb2R1bGUuIEJ1dCB0aGUgTkFUIG1vZHVsZSBo
YXMgbm8gc3Vic2NyaWJlci1tYXNrLiBJdCBoYXMgc3Vic2NyaWJlci1tYXNrLQ0KdjYuIElzIHRo
YXQgd2hhdCB5b3UgbWVhbnQgdG8gcmVmZXIgdG8/DQoNCltNZWRdIFllcy4NCg0KUGxlYXNlIHVw
ZGF0ZSB0aGUgbW9kZWwvZHJhZnQgaW4gdGhhdCBjYXNlLg0KDQoNCg0KRG9lcyBpdCBtZWFuIHlv
dSBuZWVkIGENCg0Kc3Vic2NyaWJlci1tYXNrIGZvciB2NiBvbmx5Pw0KDQpbTWVkXSBZZXMuIFRo
ZSB0d28gdXNlIGNhc2VzIGZvciB0aGlzIG1hc2sgYXJlIERTLUxpdGUgYW5kIE5BVDY0LCB3aGlj
aCBpbnZvbHZlIElQdjYgYWRkcmVzc2VzLg0KDQpUaGUgTkFUIFlBTkcgbW9kdWxlcyBpbmNsdWRl
cyB0aGUgZm9sbG93aW5nOg0KDQogICAgICAgICAgICJUaGUgc3Vic2NyaWJlciBtYXNrIGlzIGFu
IGludGVnZXIgdGhhdCBpbmRpY2F0ZXMNCiAgICAgICAgICAgIHRoZSBsZW5ndGggb2Ygc2lnbmlm
aWNhbnQgYml0cyB0byBiZSBhcHBsaWVkIG9uDQogICAgICAgICAgICB0aGUgc291cmNlIElQdjYg
YWRkcmVzcyAoaW50ZXJuYWwgc2lkZSkgdG8NCiAgICAgICAgICAgICAgICAgICAgICAgXl5eXl5e
Xl5eXl5eDQogICAgICAgICAgICB1bmFtYmlndW91c2x5IGlkZW50aWZ5IGEgdXNlciBkZXZpY2Ug
KGUuZy4sIENQRSkuDQoNCg0KDQotIEFsc28sIHlvdSBhdWdtZW50IHRoZSBOQVQgbW9kdWxlIGF0
IHRoZSBub2RlIG5hdDpwb2xpY3kuIEJ1dCBzdWJzY3JpYmVyLQ0KbWFzay12NiBpcyBhIGNoaWxk
IG9mIG5hdDpuYXQtcG9saWN5Lg0KDQpbTWVkXSBJcyB0aGVyZSBhbnkgcHJvYmxlbSB3aXRoIHRo
aXM/DQoNClllcy4gVG8gdGhlIGV4dGVudCB0aGF0IHlvdSBjYW5ub3QgYXVnbWVudCBhIG5vZGUg
dGhhdCBkb2VzIG5vdCBleGlzdCBpbiB0aGUgdHJlZS4gV2hhdCBpcyBtb3JlIHRyb3VibGluZyB0
byBtZSBpcyB0aGF0IHlvdSBzYXkgbm9uZSBvZiB0aGUgdG9vbHMgaGF2ZSBjYXVnaHQgaXQuIElu
IHRoZSBvdXRwdXQgeW91IHNob3cgYmVsb3csIGl0IGlzIG5vdCBjbGVhciB3aGljaCBOQVQgbW9k
dWxlIHlvdSBhcmUgdXNpbmcsIGFuZCB3aGVyZSBpdCB3YXMgZmV0Y2hlZCBmcm9tLg0KDQoNCg0K
DQotIEFuZCwgbmF0Om5hdC1wb2xpY3kgaXMgYSBsaXN0IHdpdGggYSBrZXkgb2YgcG9saWN5LWlk
LiBCdXQgeW91IGhhdmUgbm8NCnBvbGljeS1pZCBkZWZpbmVkIGluIHlvdXIgbW9kdWxlLiBIb3cg
ZG8geW91IHJlZmVyZW5jZSB0aGUgcGFydGljdWxhcg0KbmF0Om5hdC1wb2xpY3kgd2l0aG91dCBh
IGtleT8gV2FzIHRoaXMgbW9kZWwgY29tcGlsZWQvdmFsaWRhdGVkIGFnYWluc3QNCnRoZSBsYXRl
c3QgTkFUIG1vZHVsZT8NCg0KW01lZF0gVGhpcyBpcyBkZXJpdmVkIGZyb20gdGhlIG5hdDpuYXB0
NDQsIHdoaWNoIGlzIGF1Z21lbnRlZCB3aXRoIERTLUxpdGUgc3BlY2lmaWNzLg0KDQpJIGNvbmZp
cm0gdGhhdCB0aGUgbW9kdWxlIHdhcyBzdWNjZXNzZnVsbHkgdmFsaWRhdGVkOg0KDQo9PT09PT09
PT0NCnh5bSAwLjQ6DQpFeHRyYWN0aW5nICdpZXRmLWRzbGl0ZS1hZnRyQDIwMTctMTEtMTQueWFu
ZzxtYWlsdG86aWV0Zi1kc2xpdGUtYWZ0ckAyMDE3LTExLTE0Lnlhbmc+Jw0KICBSZW1vdmVkIDAg
ZW1wdHkgbGluZXMNCkV4dHJhY3RpbmcgJ2lldGYtZHNsaXRlLWI0QDIwMTctMTEtMTMueWFuZzxt
YWlsdG86aWV0Zi1kc2xpdGUtYjRAMjAxNy0xMS0xMy55YW5nPicNCiAgUmVtb3ZlZCAwIGVtcHR5
IGxpbmVzDQoNCg0KaWV0Zi1kc2xpdGUtYjRAMjAxNy0xMS0xMy55YW5nPG1haWx0bzppZXRmLWRz
bGl0ZS1iNEAyMDE3LTExLTEzLnlhbmc+Og0KcHlhbmcgMS43LjM6IHB5YW5nIC0tdmVyYm9zZSAt
LWlldGYgLXAge2xpYnN9IHttb2RlbH06DQpObyB2YWxpZGF0aW9uIGVycm9ycw0KDQp5YW5nbGlu
dCAwLjEzLjc5OiB5YW5nbGludCAtLXZlcmJvc2UgLXAge3JmY2xpYn0gLXAge2RyYWZ0bGlifSAt
cCB7dG1wbGlifSB7bW9kZWx9IC1pOg0KTm8gdmFsaWRhdGlvbiBlcnJvcnMNCg0KDQppZXRmLWRz
bGl0ZS1hZnRyQDIwMTctMTEtMTQueWFuZzxtYWlsdG86aWV0Zi1kc2xpdGUtYWZ0ckAyMDE3LTEx
LTE0Lnlhbmc+Og0KcHlhbmcgMS43LjM6IHB5YW5nIC0tdmVyYm9zZSAtLWlldGYgLXAge2xpYnN9
IHttb2RlbH06DQpObyB2YWxpZGF0aW9uIGVycm9ycw0KDQp5YW5nbGludCAwLjEzLjc5OiB5YW5n
bGludCAtLXZlcmJvc2UgLXAge3JmY2xpYn0gLXAge2RyYWZ0bGlifSAtcCB7dG1wbGlifSB7bW9k
ZWx9IC1pOg0KTm8gdmFsaWRhdGlvbiBlcnJvcnMNCj09PT09PT09PT09DQoNCkkgY2FuIGFkZCBh
biBleHBsaWNpdCAid2hlbiIgc3RhdGVtZW50IHRoYXQgd2lsbCBsb29rIGxpa2U6DQoNCiAgIHdo
ZW4gIi9uYXQ6bmF0L25hdDppbnN0YW5jZXMvbmF0Omluc3RhbmNlL25hdDp0eXBlPSduYXB0NDQn
IjsNCg0KVGhpcyB3aWxsIHJlcXVpcmUgdXBkYXRpbmcgdGhlIE5BVCBZQU5HIG1vZHVsZSB0byBz
cGVjaWZ5IGV4cGxpY2l0bHkgYSBOQVQgVHlwZS4NCg0KDQotIFlvdSBhdWdtZW50IG5hdDptYXBw
aW5nLWVudHJ5LCB3aGljaCBpcyBhbHNvIGEgbGlzdCB3aXRoIGEga2V5IG9mDQrigJhpbmRleOKA
mS4gV2hlcmUgYXJlIHlvdSBkZXJpdmluZyDigJhpbmRleOKAmSBmcm9tPw0KDQpbTWVkXSBJZGVt
IGFzIGFib3ZlLg0KDQoNCi0gYjQtaXB2NC1hZGRyZXNzIGhhcyBhIGRlZmF1bHQgdmFsdWUgb2Yg
MTkyLjAuMC4yLCBhbmQgeW91IGhhdmUgYSBub3RlDQp0aGF0IHRoZSBtYXNrIGlzIC8yOS4gQXJl
IGFsbCBpcHY0IGFkZHJlc3NlcyBjb25maWd1cmVkIHdpdGggLzI5IG1hc2s/IElmDQpub3QsIGhv
dyBpcyBuZXRtYXNrIGluZGljYXRlZCB0byB0aGUgZGV2aWNlPw0KDQpbTWVkXSBUaGlzIGlzIGFi
b3V0IGFuIElQdjQgYWRkcmVzcy4gVGhlIG1hc2sgaXMgbm90IHJlcXVpcmVkIHRvIGJlIGNvbmZp
Z3VyZWQuIFRoaXMgYWRkcmVzcyBjYW4gYmUgcGlja2VkIGZyb20gdGhlIC8yOSByZXNlcnZlZCBi
bG9jay4NCg0KDQoNClNlZSBhZGRpdGlvbmFsIGNvbW1lbnRzIGlubGluZS4NCg0KQ2hlZXJzLg0K
DQoNCk9uIE9jdCA5LCAyMDE3LCBhdCAzOjM0IFBNLCBtb2hhbWVkLmJvdWNhZGFpckBvcmFuZ2Uu
Y29tPG1haWx0bzptb2hhbWVkLmJvdWNhZGFpckBvcmFuZ2UuY29tPiB3cm90ZToNCg0KRGVhciBN
YWhlc2gsDQoNClRoYW5rIHlvdSB2ZXJ5IG11Y2ggZm9yIHRoZSBkZXRhaWxlZCByZXZpZXcuIE11
Y2ggYXBwcmVjaWF0ZWQuDQoNCkl0IHNlZW1zIHRoYXQgeW91IHJldmlld2VkIC0wMiBvZiB0aGUg
ZHJhZnQsIHdoaWxlIHRoZSBsYXRlc3QgdmVyc2lvbiBpcw0KLTA2IChodHRwczovL2RhdGF0cmFj
a2VyLmlldGYub3JnL2RvYy9kcmFmdC1pZXRmLXNvZnR3aXJlLWRzbGl0ZS15YW5nLykuDQoNCg0K
QXMgeW91IGNhbiBzZWUgYmVsb3csIGFsbW9zdCBhbGwgdGhlIGNvbW1lbnRzIGRvIG5vdCBhcHBs
eSBmb3IgLTA2Lg0KDQpQbGVhc2Ugc2VlIGlubGluZS4NCg0KQ2hlZXJzLA0KTWVkDQoNCg0KLS0t
LS1NZXNzYWdlIGQnb3JpZ2luZS0tLS0tDQpEZSA6IE1haGVzaCBKZXRoYW5hbmRhbmkgW21haWx0
bzptamV0aGFuYW5kYW5pQGdtYWlsLmNvbV0NCkVudm95w6kgOiBzYW1lZGkgNyBvY3RvYnJlIDIw
MTcgMDI6MTcNCsOAIDogeWFuZy1kb2N0b3JzQGlldGYub3JnPG1haWx0bzp5YW5nLWRvY3RvcnNA
aWV0Zi5vcmc+DQpDYyA6IHNvZnR3aXJlc0BpZXRmLm9yZzxtYWlsdG86c29mdHdpcmVzQGlldGYu
b3JnPjsgZHJhZnQtaWV0Zi1zb2Z0d2lyZS1kc2xpdGUteWFuZy5hbGxAaWV0Zi5vcmc8bWFpbHRv
OmRyYWZ0LWlldGYtc29mdHdpcmUtZHNsaXRlLXlhbmcuYWxsQGlldGYub3JnPjsNCmlldGZAaWV0
Zi5vcmc8bWFpbHRvOmlldGZAaWV0Zi5vcmc+DQpPYmpldCA6IFlhbmdkb2N0b3JzIGVhcmx5IHJl
dmlldyBvZiBkcmFmdC1pZXRmLXNvZnR3aXJlLWRzbGl0ZS15YW5nLTAyDQoNClJldmlld2VyOiBN
YWhlc2ggSmV0aGFuYW5kYW5pDQpSZXZpZXcgcmVzdWx0OiBPbiB0aGUgUmlnaHQgVHJhY2sNCg0K
RG9jdW1lbnQgcmV2aWV3ZWQ6IGRyYWZ0LWlldGYtc29mdHdpcmUtZHNsaXRlLXlhbmctMDIuIERv
IG5vdCBrbm93IHdoeQ0KSQ0KDQp3YXMNCmFzc2lnbmVkIC0wMiB2ZXJzaW9uIHdoZW4gSSBub3cg
bm90aWNlIHRoYXQgdGhlcmUgYXJlIHNldmVyYWwgMDMNCnZlcnNpb25zDQoNCnN1Ym1pdHRlZCBh
bGwgdGhlIHdheSB1cCB0byAtMDYuDQoNClN0YXR1czogT24gdGhlIFJpZ2h0IFRyYWNrLg0KDQpJ
IGFtIG5vdCBhbiBleHBlcnQgaW4gRFMtTGl0ZS4gVGhpcyByZXZpZXcgaXMgbG9va2luZyBhdCB0
aGUgZHJhZnQgZnJvbQ0KYQ0KDQpZQU5HDQpwZXJzcGVjdGl2ZS4gV2l0aCB0aGF0IHNhaWQsIEkg
aGF2ZSBtYXJrZWQgaXQgYXMg4oCcT24gdGhlIFJpZ2h0IFRyYWNr4oCdDQpiZWNhdXNlDQpvZiBz
b21lIG9mIHRoZSBwb2ludHMgZGlzY3Vzc2VkIGJlbG93LiBUaGUgYXV0aG9ycyBhcmUgZW5jb3Vy
YWdlZCB0bw0Kc3BlbmQNCg0KdGltZQ0KbG9va2luZyBhdCBvdGhlciBtb2RlbHMgZm9yIGV4YW1w
bGVzIG9uIGhvdyB0byB3cml0ZSB0aGUgbW9kZWwsIHJlYWQNClJGQzYwODcsDQpHdWlkZWxpbmVz
IGZvciBZQU5HIGRvY3VtZW50cy4NCg0KU3VtbWFyeToNCg0KVGhpcyBkb2N1bWVudCBkZWZpbmVz
IGEgWUFORyBkYXRhIG1vZGVsIGZvciB0aGUgRFMtTGl0ZSBBZGRyZXNzIEZhbWlseQ0KVHJhbnNp
dGlvbiBSb3V0ZXIgKEFGVFIpIGFuZCBCYXNpYyBCcmlkZ2luZyBCcm9hZEJhbmQgKEI0KSBlbGVt
ZW50cyAuDQoNCk92ZXJhbGwgQ29tbWVudHM6DQoNClRoZSBkcmFmdCBzaG91bGQgcmVmZXIgdG8g
WUFORyAxLjEgKFJGQyA3OTUwKSBpbnN0ZWFkIG9mIFJGQzYwMjAuDQoNCltNZWRdIENhbiBmaXgg
dGhpcyBvbmUuDQoNCg0KDQpUaGUgZHJhZnQgaXMgbm90IE5NREEgY29tcGxpYW50LiBJdCBjYXJy
aWVzIGEgc2VwYXJhdGUgLXN0YXRlIGNvbnRhaW5lcg0KdGhhdA0KbmVlZHMgdG8gYmUgY29sbGFw
c2VkIGludG8gb25lIHNpbmdsZSBjb250YWluZXIuIEZvciBleGFtcGxlLCBpdA0KY2Fycmllcw0K
DQpjb250YWluZXJzIHN1Y2ggYXMgYWZ0ci1jdXJyZW50LWNvbmZpZyB3aGljaCBzZWVtcyB0byBi
ZSBjYXJyeWluZyBzdGF0ZQ0KaW5mb3JtYXRpb24gZm9yIHRoZSBsZWFmcyBpbiBkc2xpdGUtY29u
ZmlnLg0KDQpbTWVkXSBUaGVyZSBhcmUgbm8gc3VjaCBjb250YWluZXJzIGluIC0wNi4NCg0KDQoN
CklzIGl0IGdpdmVuIHRoYXQgYSBzZXJ2ZXIgd2lsbCBpbXBsZW1lbnQgYm90aCBBRlRSIGFuZCBC
ND8NCltNZWRdIE5vLg0KDQpJZiBub3QsIHRoZW4NCg0KcGxlYXNlDQpkZWZpbmUgZmVhdHVyZSBz
dGF0ZW1lbnRzIGFuZCB1c2UgaWYtZmVhdHVyZSBmb3IgZWFjaCBwYXJ0IChBRlRSIGFuZA0KQjQp
LA0KDQpzbw0KaW1wbGVtZW50b3JzIGNhbiBjaG9vc2Ugd2hhdCBwYXJ0IG9mIHRoZSBtb2RlbCBp
cyBpbXBsZW1lbnRlZC4NCg0KW21qXSBJIGRvIG5vdCBzZWUgdGhpcyBjb21tZW50IGFkZHJlc3Nl
ZC4NCg0KW01lZF0gVGhpcyBpcyBlYXN5IHRvIGZpeC4gQWN0dWFsbHksIEkgaW50ZXJwcmV0ZWQg
bm8gZm9sbG93LXVwIGZyb20geW91ciBzaWRlIGFzIGhhdmluZyBzZXBhcmF0ZSBtb2R1bGVzIGlz
IGFsc28gZmluZSB3aXRoIHlvdS4NCg0KRmVhdHVyZXMgYWxsb3cgcGxhdGZvcm1zIHRvIGlkZW50
aWZ5IHBhcnRzIG9mIHRoZSBtb2RlbCB0aGF0IHRoZXkgYXJlIGNhcGFibGUgb2Ygc3VwcG9ydGlu
Zywgd2hpbGUgYXQgdGhlIHNhbWUgdGltZSByZW1vdmluZyBwYXJ0cyB0aGF0IGFyZSBub3Qgc3Vw
cG9ydGVkLiBQbGF0Zm9ybXMgY2FuIGRldmlhdGUgYSBtb2RlbCBhbmQgc2F5IHdoYXQgdGhleSBk
byBub3Qgc3VwcG9ydCBwYXJ0cyBvZiB0aGUgbW9kZWwsIGJ1dCB3ZSB1c3VhbGx5IHJlc2VydmUg
dGhhdCBmb3IgdGhlIGNhc2Ugd2hlcmUgdGhlcmUgaXMgbm8gKGhhcmR3YXJlKSBzdXBwb3J0IGZv
ciBhIGdpdmVuIGZlYXR1cmUuDQoNCk1haGVzaCBKZXRoYW5hbmRhbmkNCm1qZXRoYW5hbmRhbmlA
Z21haWwuY29tPG1haWx0bzptamV0aGFuYW5kYW5pQGdtYWlsLmNvbT4NCg0K

--_000_787AE7BB302AE849A7480A190F8B93300A07B603OPEXCLILMA3corp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTQgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
SGVsdmV0aWNhOw0KCXBhbm9zZS0xOjIgMTEgNiA0IDIgMiAyIDIgMiA0O30NCkBmb250LWZhY2UN
Cgl7Zm9udC1mYW1pbHk6SGVsdmV0aWNhOw0KCXBhbm9zZS0xOjIgMTEgNiA0IDIgMiAyIDIgMiA0
O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Q2FsaWJyaTsNCglwYW5vc2UtMToyIDE1IDUg
MiAyIDIgNCAzIDIgNDt9DQpAZm9udC1mYWNlDQoJe2ZvbnQtZmFtaWx5OlRhaG9tYTsNCglwYW5v
c2UtMToyIDExIDYgNCAzIDUgNCA0IDIgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0KcC5N
c29Ob3JtYWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGNtOw0KCW1h
cmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTIuMHB0Ow0KCWZvbnQtZmFtaWx5OiJU
aW1lcyBOZXcgUm9tYW4iLCJzZXJpZiI7fQ0KYTpsaW5rLCBzcGFuLk1zb0h5cGVybGluaw0KCXtt
c28tc3R5bGUtcHJpb3JpdHk6OTk7DQoJY29sb3I6Ymx1ZTsNCgl0ZXh0LWRlY29yYXRpb246dW5k
ZXJsaW5lO30NCmE6dmlzaXRlZCwgc3Bhbi5Nc29IeXBlcmxpbmtGb2xsb3dlZA0KCXttc28tc3R5
bGUtcHJpb3JpdHk6OTk7DQoJY29sb3I6cHVycGxlOw0KCXRleHQtZGVjb3JhdGlvbjp1bmRlcmxp
bmU7fQ0KcC5Nc29BY2V0YXRlLCBsaS5Nc29BY2V0YXRlLCBkaXYuTXNvQWNldGF0ZQ0KCXttc28t
c3R5bGUtcHJpb3JpdHk6OTk7DQoJbXNvLXN0eWxlLWxpbms6IlRleHRlIGRlIGJ1bGxlcyBDYXIi
Ow0KCW1hcmdpbjowY207DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZTo4LjBw
dDsNCglmb250LWZhbWlseToiVGFob21hIiwic2Fucy1zZXJpZiI7fQ0KcC5Nc29MaXN0UGFyYWdy
YXBoLCBsaS5Nc29MaXN0UGFyYWdyYXBoLCBkaXYuTXNvTGlzdFBhcmFncmFwaA0KCXttc28tc3R5
bGUtcHJpb3JpdHk6MzQ7DQoJbWFyZ2luLXRvcDowY207DQoJbWFyZ2luLXJpZ2h0OjBjbTsNCglt
YXJnaW4tYm90dG9tOjBjbTsNCgltYXJnaW4tbGVmdDozNi4wcHQ7DQoJbWFyZ2luLWJvdHRvbTou
MDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4wcHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBSb21h
biIsInNlcmlmIjt9DQpzcGFuLmFwcGxlLWNvbnZlcnRlZC1zcGFjZQ0KCXttc28tc3R5bGUtbmFt
ZTphcHBsZS1jb252ZXJ0ZWQtc3BhY2U7fQ0Kc3Bhbi5UZXh0ZWRlYnVsbGVzQ2FyDQoJe21zby1z
dHlsZS1uYW1lOiJUZXh0ZSBkZSBidWxsZXMgQ2FyIjsNCgltc28tc3R5bGUtcHJpb3JpdHk6OTk7
DQoJbXNvLXN0eWxlLWxpbms6IlRleHRlIGRlIGJ1bGxlcyI7DQoJZm9udC1mYW1pbHk6IlRhaG9t
YSIsInNhbnMtc2VyaWYiO30NCnNwYW4uRW1haWxTdHlsZTIwDQoJe21zby1zdHlsZS10eXBlOnBl
cnNvbmFsLXJlcGx5Ow0KCWZvbnQtZmFtaWx5OiJDb3VyaWVyIE5ldyI7DQoJY29sb3I6YmxhY2s7
DQoJZm9udC13ZWlnaHQ6bm9ybWFsOw0KCWZvbnQtc3R5bGU6bm9ybWFsO30NCi5Nc29DaHBEZWZh
dWx0DQoJe21zby1zdHlsZS10eXBlOmV4cG9ydC1vbmx5Ow0KCWZvbnQtc2l6ZToxMC4wcHQ7fQ0K
QHBhZ2UgV29yZFNlY3Rpb24xDQoJe3NpemU6NjEyLjBwdCA3OTIuMHB0Ow0KCW1hcmdpbjo3MC44
NXB0IDcwLjg1cHQgNzAuODVwdCA3MC44NXB0O30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpX
b3JkU2VjdGlvbjE7fQ0KLS0+PC9zdHlsZT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNo
YXBlZGVmYXVsdHMgdjpleHQ9ImVkaXQiIHNwaWRtYXg9IjEwMjYiIC8+DQo8L3htbD48IVtlbmRp
Zl0tLT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0
Ij4NCjxvOmlkbWFwIHY6ZXh0PSJlZGl0IiBkYXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0Pjwv
eG1sPjwhW2VuZGlmXS0tPg0KPC9oZWFkPg0KPGJvZHkgbGFuZz0iRlIiIGxpbms9ImJsdWUiIHZs
aW5rPSJwdXJwbGUiPg0KPGRpdiBjbGFzcz0iV29yZFNlY3Rpb24xIj4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0Nv
dXJpZXIgTmV3JnF1b3Q7O2NvbG9yOmJsYWNrIj5EZWFyIGFsbCwNCjxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MTAuMHB0
O2ZvbnQtZmFtaWx5OiZxdW90O0NvdXJpZXIgTmV3JnF1b3Q7O2NvbG9yOmJsYWNrIj48bzpwPiZu
YnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJF
Ti1VUyIgc3R5bGU9ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q291cmllciBO
ZXcmcXVvdDs7Y29sb3I6YmxhY2siPknigJltIHNoYXJpbmcgdGhlc2UgY29tbWVudHMgZnJvbSBN
YWhlc2ggKG9uIGFub3RoZXIgZG9jdW1lbnQpLCBidXQgd2hpY2ggaGF2ZSB0aGUgZm9sbG93aW5n
IGltcGxpY2F0aW9ucyBvbiB0aGUgTkFUIFlBTkcgbW9kdWxlOiAmbmJzcDs8bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q291cmllciBOZXcmcXVvdDs7Y29s
b3I6YmxhY2siPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtDb3VyaWVyIE5ldyZxdW90Oztjb2xvcjpibGFjayI+LSBDaXRlIEktRC5pZXRmLW5l
dG1vZC15YW5nLXRyZWUtZGlhZ3JhbXMgaW5zdGVhZCBvZiBpbmNsdWRpbmcgdGhlIGRlc2NyaXB0
aW9uIG9mIHRoZSBzeW1ib2xzLiBJLUQuaWV0Zi1uZXRtb2QteWFuZy10cmVlLWRpYWdyYW1zIHdp
bGwgYmUgY2l0ZWQgYXMgYW4gaW5mb3JtYXRpb25hbA0KIHJlZmVyZW5jZS4gPG86cD48L286cD48
L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NvdXJpZXIgTmV3JnF1b3Q7O2Nv
bG9yOmJsYWNrIj4tIFJlbW92ZSByZWZlcmVuY2UgdG8gY2hhaXJzIGluIHRoZSBZQU5HIG1vZHVs
ZS4NCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIGxh
bmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseTomcXVvdDtDb3Vy
aWVyIE5ldyZxdW90Oztjb2xvcjpibGFjayI+LSBBZGQgYW4gZXhwbGljaXQgbm9kZSB0byBjb25m
aWd1cmUgYSBOQVQgdHlwZTxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWls
eTomcXVvdDtDb3VyaWVyIE5ldyZxdW90Oztjb2xvcjpibGFjayI+PG86cD4mbmJzcDs8L286cD48
L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxl
PSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0NvdXJpZXIgTmV3JnF1b3Q7O2Nv
bG9yOmJsYWNrIj5DaGVlcnMsPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0NvdXJpZXIgTmV3JnF1b3Q7O2NvbG9yOmJsYWNrIj5NZWQ8bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBsYW5nPSJFTi1VUyIgc3R5bGU9
ImZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7Q291cmllciBOZXcmcXVvdDs7Y29s
b3I6YmxhY2siPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxkaXYgc3R5bGU9ImJvcmRl
cjpub25lO2JvcmRlci1sZWZ0OnNvbGlkIGJsdWUgMS41cHQ7cGFkZGluZzowY20gMGNtIDBjbSA0
LjBwdCI+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOm5vbmU7Ym9yZGVyLXRvcDpzb2xpZCAj
QjVDNERGIDEuMHB0O3BhZGRpbmc6My4wcHQgMGNtIDBjbSAwY20iPg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PGI+PHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJmb250LXNpemU6MTAuMHB0O2ZvbnQt
ZmFtaWx5OiZxdW90O1RhaG9tYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5EZSZuYnNw
Ozo8L3NwYW4+PC9iPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iZm9udC1zaXplOjEwLjBwdDtm
b250LWZhbWlseTomcXVvdDtUYWhvbWEmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+IE1h
aGVzaCBKZXRoYW5hbmRhbmkgW21haWx0bzptamV0aGFuYW5kYW5pQGdtYWlsLmNvbV0NCjxicj4N
CjxiPkVudm95w6kmbmJzcDs6PC9iPiBqZXVkaSAxNiBub3ZlbWJyZSAyMDE3IDAwOjU5PGJyPg0K
PGI+w4AmbmJzcDs6PC9iPiBCT1VDQURBSVIgTW9oYW1lZCBJTVQvT0xOPGJyPg0KPGI+Q2MmbmJz
cDs6PC9iPiB5YW5nLWRvY3RvcnNAaWV0Zi5vcmc7IHNvZnR3aXJlc0BpZXRmLm9yZzsgZHJhZnQt
aWV0Zi1zb2Z0d2lyZS1kc2xpdGUteWFuZy5hbGxAaWV0Zi5vcmc7IE5ldE1vZCBXRyBDaGFpcnM7
IEJlbm9pdCBDbGFpc2U8YnI+DQo8Yj5PYmpldCZuYnNwOzo8L2I+IFJlOiBZYW5nZG9jdG9ycyBl
YXJseSByZXZpZXcgb2YgZHJhZnQtaWV0Zi1zb2Z0d2lyZS1kc2xpdGUteWFuZy0wMjxvOnA+PC9v
OnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Bh
biBsYW5nPSJFTi1VUyI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1z
b05vcm1hbCI+TWVkLDxvOnA+PC9vOnA+PC9wPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+U2VlIGlubGluZS48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdj4NCjxibG9ja3F1b3RlIHN0eWxl
PSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPk9uIE5vdiAxNSwgMjAxNywgYXQgODo1MCBQTSwgPGEgaHJlZj0ibWFpbHRv
Om1vaGFtZWQuYm91Y2FkYWlyQG9yYW5nZS5jb20iPg0KbW9oYW1lZC5ib3VjYWRhaXJAb3Jhbmdl
LmNvbTwvYT4gd3JvdGU6PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPkhpIE1haGVzaCw8c3BhbiBjbGFzcz0iYXBwbGUt
Y29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PGJyPg0KPGJyPg0KVGhhbmsgeW91IGZvciB0
aGUgZmVlZGJhY2suPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9z
cGFuPjxicj4NCjxicj4NClBsZWFzZSBzZWUgaW5saW5lLjxzcGFuIGNsYXNzPSJhcHBsZS1jb252
ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bhbj48YnI+DQo8YnI+DQpDaGVlcnMsPGJyPg0KTWVkPHNw
YW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxicj4NCjxiciBz
dHlsZT0iZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDtvcnBoYW5zOiBhdXRvO3RleHQtYWxpZ246
c3RhcnQ7d2lkb3dzOiBhdXRvOy13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDt3b3JkLXNw
YWNpbmc6MHB4Ij4NCjxicj4NCjwvc3Bhbj48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiIHN0eWxlPSJtYXJnaW4tYm90dG9tOjEyLjBwdCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6
ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJp
ZiZxdW90OyI+LS0tLS1NZXNzYWdlIGQnb3JpZ2luZS0tLS0tPGJyPg0KRGUmbmJzcDs6IE1haGVz
aCBKZXRoYW5hbmRhbmkgWzxhIGhyZWY9Im1haWx0bzptamV0aGFuYW5kYW5pQGdtYWlsLmNvbSI+
bWFpbHRvOm1qZXRoYW5hbmRhbmlAZ21haWwuY29tPC9hPl08YnI+DQpFbnZvecOpJm5ic3A7OiBt
YXJkaSAxNCBub3ZlbWJyZSAyMDE3IDIzOjU5PGJyPg0Kw4AmbmJzcDs6IEJPVUNBREFJUiBNb2hh
bWVkIElNVC9PTE48YnI+DQpDYyZuYnNwOzo8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNw
YWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOnlhbmctZG9jdG9yc0BpZXRmLm9yZyI+
eWFuZy1kb2N0b3JzQGlldGYub3JnPC9hPjs8c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNw
YWNlIj4mbmJzcDs8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOnNvZnR3aXJlc0BpZXRmLm9yZyI+c29m
dHdpcmVzQGlldGYub3JnPC9hPjsgZHJhZnQtaWV0Zi1zb2Z0d2lyZS08YnI+DQo8YSBocmVmPSJt
YWlsdG86ZHNsaXRlLXlhbmcuYWxsQGlldGYub3JnIj5kc2xpdGUteWFuZy5hbGxAaWV0Zi5vcmc8
L2E+OyBOZXRNb2QgV0cgQ2hhaXJzOyBCZW5vaXQgQ2xhaXNlPGJyPg0KT2JqZXQmbmJzcDs6IFJl
OiBZYW5nZG9jdG9ycyBlYXJseSByZXZpZXcgb2YgZHJhZnQtaWV0Zi1zb2Z0d2lyZS1kc2xpdGUt
eWFuZy0wMjxicj4NCjxicj4NCk1vaGFtZWQsPGJyPg0KPGJyPg0KSSByZWFsaXplIHRoYXQgSSBh
bSByZXNwb25kaW5nIHRvIGFuIGVhcmxpZXIgdGhyZWFkIHRoYW4gdGhlIG9uZSB5b3UgYXNrZWQ8
YnI+DQp5b3VyIHF1ZXN0aW9uIG9uLCBzbyBsZXQgbWUgYWRkcmVzcyB0aGUgcXVlc3Rpb24gdGhh
dCB5b3UgYXNrZWQgb24gdGhhdDxicj4NCnRocmVhZCBmaXJzdC48YnI+DQo8YnI+DQpZZXMsIHRo
ZSBuZXRtb2QgdHJlZSBkaWFncmFtcyBkcmFmdCBpcyBub3QgYW4gUkZDLCBhbmQgeWFuZy1kb2N0
b3JzIGRvPGJyPg0KcmVjb21tZW5kIHRoYXQgYXV0aG9ycyBvZiBkcmFmdHMgd2l0aCBZQU5HIG1v
ZHVsZSByZWZlcmVuY2UgdGhlIG5ldG1vZDxicj4NCnRyZWUgZGlhZ3JhbSBkcmFmdCByYXRoZXIg
dGhhbiBjdXQgYW5kIHBhc3RlIGRlc2NyaXB0aW9uIG9mIHRoZSB0cmVlPGJyPg0Kc3ltYm9scyBp
bnRvIHRoZWlyIGRyYWZ0cy4gVG8gdGhlIHF1ZXN0aW9uIG9mIHdoZXRoZXIgdGhhdCByZWZlcmVu
Y2UgY2FuPGJyPg0KYmUgaW5mb3JtYXRpdmUgb3IgZG9lcyBpdCBoYXZlIHRvIGJlIG5vcm1hdGl2
ZSwgSSB3b3VsZCBhZ3JlZSB0aGF0IGl0IGhhczxicj4NCnRvIGJlIG5vcm1hdGl2ZS4gSSByZWFs
aXplIHRoYXQgbWlnaHQgaW1wYWN0IHRoZSBwdWJsaWNhdGlvbiBvZiB0aGUgZHJhZnQsPGJyPg0K
c28gSSBhbSBpbmNsdWRpbmcgdGhlIGNoYWlycyBvZiBORVRNT0QgV0coYW5kIG9uZSBvZiB0aGUg
YXV0aG9ycykgdG8gZ2V0PGJyPg0KYW4gaWRlYSBvZiB3aGVuIHRoZXkgdGhpbmsgdGhlIGRyYWZ0
IGNvdWxkIGJlIHB1Ymxpc2hlZCBhcyBhbiBSRkMuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWls
eTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+PGJyPg0KW01l
ZF0gV2UgbmVlZCBndWlkYW5jZSBob3cgdG8gcHJvY2VlZCBnaXZlbiB0aGF0IHdlIGRvIGhhdmUg
dHdvIGRyYWZ0cyBpbiB0aGUgc29mdHdpcmUgV0cgdGhhdCBhcmUgaW1wYWN0ZWQgKHRoaXMgb25l
IHBhc3NlZCB0aGUgV0dMQywgd2hpbGUgdGhlIHNlY29uZCBvbmUgd2lsbCBiZSBvbiB0aGUgV0dM
QyBzb29uKS4gQlRXLCBhbiBhcmd1bWVudCBJIGhlYXJkIHJlY2VudGx5IGlzIHRoYXQgdGhlIG5l
dG1vZCBkb2N1bWVudCBjYW4gYmUgY2l0ZWQNCiBhcyBpbmZvcm1hdGl2ZSBnaXZlbiB0aGF0IHRo
ZSB0cmVlIHN0cnVjdHVyZSBpdHNlbGYgaXMgbm90IG5vcm1hdGl2ZS48c3BhbiBjbGFzcz0iYXBw
bGUtY29udmVydGVkLXNwYWNlIj4mbmJzcDs8L3NwYW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0K
PC9kaXY+DQo8L2Jsb2NrcXVvdGU+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4m
bmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPkkgZGlkIGJyaW5n
IHVwIHRoZSBxdWVzdGlvbiB5ZXN0ZXJkYXkgaW4gTkVUTU9ELCBhbmQgeWVzIHRoZSBjb25zZW5z
dXMgaW4gTkVUTU9EIGlzIHRvIG1vdmUgdGhlIHRyZWUgZGlhZ3JhbSBkb2N1bWVudCBmcm9tIFN0
YW5kYXJkcyBUcmFjayB0byBJbmZvcm1hdGlvbmFsLCB3aGVyZSBpdCBjYW4gdGhlbiBiZSBjaXRl
ZCBhcyBpbmZvcm1hdGlvbmFsLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PGJyPg0KPGJyPg0KPG86cD48L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTom
cXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+PGJyIHN0eWxlPSJm
b250LXZhcmlhbnQtY2Fwczogbm9ybWFsO29ycGhhbnM6IGF1dG87dGV4dC1hbGlnbjpzdGFydDt3
aWRvd3M6IGF1dG87LXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4O3dvcmQtc3BhY2luZzow
cHgiPg0KPGJyPg0KPC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2Em
cXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+QnV0IGJlZm9yZSB5b3UgcnVzaCBpbnRvIHB1
YmxpY2F0aW9uLCBJIHRvb2sgYW5vdGhlciBsb29rIGF0IHRoZSAtMDg8YnI+DQp2ZXJzaW9uIG9m
IHRoZSBkcmFmdCwgYW5kIEkgaGF2ZSBhZGRpdGlvbmFsIGNvbmNlcm5zIGFib3V0IHRoZSBkcmFm
dCBhbmQ8YnI+DQp0aGUgWUFORyBtb2R1bGUgaW4gaXQsIHRoYXQgSSBiZWxpZXZlIHdhcnJhbnQg
YW5vdGhlciBsb29rLjxicj4NCjxicj4NCk1pbm9yIGNvbW1lbnRzPGJyPg0KPGJyPg0KLSBQbGVh
c2UgcmVtb3ZlIHJlZmVyZW5jZSB0byBjaGFpcnMgaW4gdGhlIFlBTkcgbW9kdWxlLiBBbGwgd2Ug
cmVjb21tZW5kPGJyPg0KYXJlIHRoZSBhdXRob3JzL2VkaXRvcnMuPG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtm
b250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+
PGJyPg0KW01lZF0gRG9uZS48YnI+DQo8YnIgc3R5bGU9ImZvbnQtdmFyaWFudC1jYXBzOiBub3Jt
YWw7b3JwaGFuczogYXV0bzt0ZXh0LWFsaWduOnN0YXJ0O3dpZG93czogYXV0bzstd2Via2l0LXRl
eHQtc3Ryb2tlLXdpZHRoOiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86
cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXpl
OjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlm
JnF1b3Q7Ij4tIFBsZWFzZSBhZGQgYSBub3RlIGZvciB0aGUgUkZDIGVkaXRvciB0byByZXBsYWNl
IOKAnFJGQyBYWFhY4oCdIHdpdGggdGhlIFJGQzxicj4NCm51bWJlciB3aGVuIHRoZSBkcmFmdCBp
cyBwdWJsaXNoZWQuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2Em
cXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+PGJyPg0KW01lZF0gVGhlcmUgaXMgYWxyZWFk
eSB0aGlzIG5vdGUgaW4gdGhlIGRyYWZ0OjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3Bh
Y2UiPiZuYnNwOzwvc3Bhbj48YnI+DQo8YnI+DQo9PT08YnI+DQpFZGl0b3JpYWwgTm90ZSAoVG8g
YmUgcmVtb3ZlZCBieSBSRkMgRWRpdG9yKTxicj4NCjxicj4NCiZuYnNwOyZuYnNwO1BsZWFzZSB1
cGRhdGUgdGhlc2Ugc3RhdGVtZW50cyB3aXRoIHRoZSBSRkMgbnVtYmVyIHRvIGJlIGFzc2lnbmVk
IHRvPGJyPg0KJm5ic3A7Jm5ic3A7dGhpcyBkb2N1bWVudDo8YnI+DQo8YnI+DQombmJzcDsmbmJz
cDtvICZuYnNwOyZxdW90O1RoaXMgdmVyc2lvbiBvZiB0aGlzIFlBTkcgbW9kdWxlIGlzIHBhcnQg
b2YgUkZDIFhYWFg7JnF1b3Q7PGJyPg0KPGJyPg0KJm5ic3A7Jm5ic3A7byAmbmJzcDsmcXVvdDtS
RkMgWFhYWDogWUFORyBEYXRhIE1vZHVsZXMgZm9yIER1YWwtU3RhY2sgTGl0ZSAoRFMtTGl0ZSkm
cXVvdDs7PGJyPg0KPGJyPg0KJm5ic3A7Jm5ic3A7byAmbmJzcDsmcXVvdDtyZWZlcmVuY2U6IFJG
QyBYWFhYJnF1b3Q7PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9z
cGFuPjxicj4NCj09PTxicj4NCjxiciBzdHlsZT0iZm9udC12YXJpYW50LWNhcHM6IG5vcm1hbDtv
cnBoYW5zOiBhdXRvO3RleHQtYWxpZ246c3RhcnQ7d2lkb3dzOiBhdXRvOy13ZWJraXQtdGV4dC1z
dHJva2Utd2lkdGg6IDBweDt3b3JkLXNwYWNpbmc6MHB4Ij4NCjxicj4NCjwvc3Bhbj48bzpwPjwv
bzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4w
cHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVv
dDsiPi0gVGhlIGluZGVudGF0aW9ucyBpbiB0aGUgWUFORyBtb2R1bGUgYXJlIHN0aWxsIG5vdCBj
b25zaXN0ZW50LiBQbGVhc2UgZml4PGJyPg0KdGhlbS48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48YnI+DQpb
TWVkXSBPSy48YnI+DQo8YnIgc3R5bGU9ImZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7b3JwaGFu
czogYXV0bzt0ZXh0LWFsaWduOnN0YXJ0O3dpZG93czogYXV0bzstd2Via2l0LXRleHQtc3Ryb2tl
LXdpZHRoOiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86cD48L286cD48
L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2Zv
bnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48
YnI+DQpBZGRpdGlvbmFsIGNvbW1lbnRzOjxicj4NCi0gVGhlIFlBTkcgbW9kdWxlIG1ha2VzIG11
bHRpcGxlIHJlZmVyZW5jZXMgdG8gc3Vic2NyaWJlci1tYXNrIGFzIGEgd2F5IHRvPGJyPg0KdW5p
cXVlbHkgaWRlbnRpdHkgYSBzdWJzY3JpYmVyLiBUaGF0LCBhcyB5b3Ugc2F5IGlzIGRlcml2ZWQg
ZnJvbSB0aGUgTkFUPGJyPg0KbW9kdWxlLiBCdXQgdGhlIE5BVCBtb2R1bGUgaGFzIG5vIHN1YnNj
cmliZXItbWFzay4gSXQgaGFzIHN1YnNjcmliZXItbWFzay08YnI+DQp2Ni4gSXMgdGhhdCB3aGF0
IHlvdSBtZWFudCB0byByZWZlciB0bz88bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48YnI+DQpbTWVkXSBZZXMu
PHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48
bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+
Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5QbGVhc2UgdXBk
YXRlIHRoZSBtb2RlbC9kcmFmdCBpbiB0aGF0IGNhc2UuPG86cD48L286cD48L3A+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvcD4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0
O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7
Ij48YnI+DQpEb2VzIGl0IG1lYW4geW91IG5lZWQgYTxiciBzdHlsZT0iZm9udC12YXJpYW50LWNh
cHM6IG5vcm1hbDtvcnBoYW5zOiBhdXRvO3RleHQtYWxpZ246c3RhcnQ7d2lkb3dzOiBhdXRvOy13
ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDt3b3JkLXNwYWNpbmc6MHB4Ij4NCjxicj4NCjwv
c3Bhbj48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3Nh
bnMtc2VyaWYmcXVvdDsiPnN1YnNjcmliZXItbWFzayBmb3IgdjYgb25seT88bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjku
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1
b3Q7Ij48YnI+DQpbTWVkXSBZZXMuIFRoZSB0d28gdXNlIGNhc2VzIGZvciB0aGlzIG1hc2sgYXJl
IERTLUxpdGUgYW5kIE5BVDY0LCB3aGljaCBpbnZvbHZlIElQdjYgYWRkcmVzc2VzLjxicj4NCjxi
cj4NClRoZSBOQVQgWUFORyBtb2R1bGVzIGluY2x1ZGVzIHRoZSBmb2xsb3dpbmc6PHNwYW4gY2xh
c3M9ImFwcGxlLWNvbnZlcnRlZC1zcGFjZSI+Jm5ic3A7PC9zcGFuPjxicj4NCjxicj4NCiZuYnNw
OyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZu
YnNwOyZxdW90O1RoZSBzdWJzY3JpYmVyIG1hc2sgaXMgYW4gaW50ZWdlciB0aGF0IGluZGljYXRl
czxicj4NCiZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZuYnNwOyZu
YnNwOyZuYnNwOyZuYnNwOyZuYnNwO3RoZSBsZW5ndGggb2Ygc2lnbmlmaWNhbnQgYml0cyB0byBi
ZSBhcHBsaWVkIG9uPGJyPg0KJm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5i
c3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7dGhlIHNvdXJjZSBJUHY2IGFkZHJlc3Mg
KGludGVybmFsIHNpZGUpIHRvPGJyPg0KJm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5i
c3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Xl5eXl5eXl5e
Xl5ePGJyPg0KJm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7
Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7dW5hbWJpZ3VvdXNseSBpZGVudGlmeSBhIHVzZXIgZGV2
aWNlIChlLmcuLCBDUEUpLjxicj4NCjxicj4NCjxiciBzdHlsZT0iZm9udC12YXJpYW50LWNhcHM6
IG5vcm1hbDtvcnBoYW5zOiBhdXRvO3RleHQtYWxpZ246c3RhcnQ7d2lkb3dzOiBhdXRvOy13ZWJr
aXQtdGV4dC1zdHJva2Utd2lkdGg6IDBweDt3b3JkLXNwYWNpbmc6MHB4Ij4NCjxicj4NCjwvc3Bh
bj48bzpwPjwvbzpwPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250
LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPi0gQWxzbywgeW91IGF1Z21lbnQgdGhlIE5BVCBtb2R1bGUgYXQgdGhlIG5v
ZGUgbmF0OnBvbGljeS4gQnV0IHN1YnNjcmliZXItPGJyPg0KbWFzay12NiBpcyBhIGNoaWxkIG9m
IG5hdDpuYXQtcG9saWN5LjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0
aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPjxicj4NCltNZWRdIElzIHRoZXJlIGFu
eSBwcm9ibGVtIHdpdGggdGhpcz88c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4m
bmJzcDs8L3NwYW4+PC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPlllcy4gVG8gdGhlIGV4dGVudCB0aGF0IHlvdSBjYW5ub3QgYXVnbWVudCBhIG5v
ZGUgdGhhdCBkb2VzIG5vdCBleGlzdCBpbiB0aGUgdHJlZS4gV2hhdCBpcyBtb3JlIHRyb3VibGlu
ZyB0byBtZSBpcyB0aGF0IHlvdSBzYXkgbm9uZSBvZiB0aGUgdG9vbHMgaGF2ZSBjYXVnaHQgaXQu
IEluIHRoZSBvdXRwdXQgeW91IHNob3cgYmVsb3csIGl0IGlzIG5vdCBjbGVhciB3aGljaCBOQVQg
bW9kdWxlIHlvdSBhcmUgdXNpbmcsDQogYW5kIHdoZXJlIGl0IHdhcyBmZXRjaGVkIGZyb20uPG86
cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48YnI+DQo8
YnI+DQo8bzpwPjwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBz
dHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90Oywm
cXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48YnIgc3R5bGU9ImZvbnQtdmFyaWFudC1jYXBzOiBub3Jt
YWw7b3JwaGFuczogYXV0bzt0ZXh0LWFsaWduOnN0YXJ0O3dpZG93czogYXV0bzstd2Via2l0LXRl
eHQtc3Ryb2tlLXdpZHRoOiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86
cD48L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXpl
OjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlm
JnF1b3Q7Ij4tIEFuZCwgbmF0Om5hdC1wb2xpY3kgaXMgYSBsaXN0IHdpdGggYSBrZXkgb2YgcG9s
aWN5LWlkLiBCdXQgeW91IGhhdmUgbm88YnI+DQpwb2xpY3ktaWQgZGVmaW5lZCBpbiB5b3VyIG1v
ZHVsZS4gSG93IGRvIHlvdSByZWZlcmVuY2UgdGhlIHBhcnRpY3VsYXI8YnI+DQpuYXQ6bmF0LXBv
bGljeSB3aXRob3V0IGEga2V5PyBXYXMgdGhpcyBtb2RlbCBjb21waWxlZC92YWxpZGF0ZWQgYWdh
aW5zdDxicj4NCnRoZSBsYXRlc3QgTkFUIG1vZHVsZT88bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48YnI+DQpb
TWVkXSBUaGlzIGlzIGRlcml2ZWQgZnJvbSB0aGUgbmF0Om5hcHQ0NCwgd2hpY2ggaXMgYXVnbWVu
dGVkIHdpdGggRFMtTGl0ZSBzcGVjaWZpY3MuPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1z
cGFjZSI+Jm5ic3A7PC9zcGFuPjxicj4NCjxicj4NCkkgY29uZmlybSB0aGF0IHRoZSBtb2R1bGUg
d2FzIHN1Y2Nlc3NmdWxseSB2YWxpZGF0ZWQ6PGJyPg0KPGJyPg0KPT09PT09PT09PGJyPg0KeHlt
IDAuNDo8YnI+DQpFeHRyYWN0aW5nICc8L3NwYW4+PGEgaHJlZj0ibWFpbHRvOmlldGYtZHNsaXRl
LWFmdHJAMjAxNy0xMS0xNC55YW5nIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQt
ZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5pZXRm
LWRzbGl0ZS1hZnRyQDIwMTctMTEtMTQueWFuZzwvc3Bhbj48L2E+PHNwYW4gc3R5bGU9ImZvbnQt
c2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1z
ZXJpZiZxdW90OyI+Jzxicj4NCiZuYnNwOyZuYnNwO1JlbW92ZWQgMCBlbXB0eSBsaW5lczxicj4N
CkV4dHJhY3RpbmcgJzwvc3Bhbj48YSBocmVmPSJtYWlsdG86aWV0Zi1kc2xpdGUtYjRAMjAxNy0x
MS0xMy55YW5nIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5pZXRmLWRzbGl0ZS1iNEAy
MDE3LTExLTEzLnlhbmc8L3NwYW4+PC9hPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9u
dC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPic8
YnI+DQombmJzcDsmbmJzcDtSZW1vdmVkIDAgZW1wdHkgbGluZXM8YnI+DQo8YnI+DQo8YnI+DQo8
L3NwYW4+PGEgaHJlZj0ibWFpbHRvOmlldGYtZHNsaXRlLWI0QDIwMTctMTEtMTMueWFuZyI+PHNw
YW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVv
dDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+aWV0Zi1kc2xpdGUtYjRAMjAxNy0xMS0xMy55YW5n
PC9zcGFuPjwvYT48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij46PGJyPg0KcHlhbmcgMS43
LjM6IHB5YW5nIC0tdmVyYm9zZSAtLWlldGYgLXAge2xpYnN9IHttb2RlbH06PGJyPg0KTm8gdmFs
aWRhdGlvbiBlcnJvcnM8YnI+DQo8YnI+DQp5YW5nbGludCAwLjEzLjc5OiB5YW5nbGludCAtLXZl
cmJvc2UgLXAge3JmY2xpYn0gLXAge2RyYWZ0bGlifSAtcCB7dG1wbGlifSB7bW9kZWx9IC1pOjxi
cj4NCk5vIHZhbGlkYXRpb24gZXJyb3JzPGJyPg0KPGJyPg0KPGJyPg0KPC9zcGFuPjxhIGhyZWY9
Im1haWx0bzppZXRmLWRzbGl0ZS1hZnRyQDIwMTctMTEtMTQueWFuZyI+PHNwYW4gc3R5bGU9ImZv
bnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fu
cy1zZXJpZiZxdW90OyI+aWV0Zi1kc2xpdGUtYWZ0ckAyMDE3LTExLTE0Lnlhbmc8L3NwYW4+PC9h
PjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNh
JnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPjo8YnI+DQpweWFuZyAxLjcuMzogcHlhbmcg
LS12ZXJib3NlIC0taWV0ZiAtcCB7bGlic30ge21vZGVsfTo8YnI+DQpObyB2YWxpZGF0aW9uIGVy
cm9yczxicj4NCjxicj4NCnlhbmdsaW50IDAuMTMuNzk6IHlhbmdsaW50IC0tdmVyYm9zZSAtcCB7
cmZjbGlifSAtcCB7ZHJhZnRsaWJ9IC1wIHt0bXBsaWJ9IHttb2RlbH0gLWk6PGJyPg0KTm8gdmFs
aWRhdGlvbiBlcnJvcnM8YnI+DQo9PT09PT09PT09PTxicj4NCjxicj4NCkkgY2FuIGFkZCBhbiBl
eHBsaWNpdCAmcXVvdDt3aGVuJnF1b3Q7IHN0YXRlbWVudCB0aGF0IHdpbGwgbG9vayBsaWtlOjxi
cj4NCjxicj4NCiZuYnNwOyZuYnNwOyZuYnNwO3doZW4gJnF1b3Q7L25hdDpuYXQvbmF0Omluc3Rh
bmNlcy9uYXQ6aW5zdGFuY2UvbmF0OnR5cGU9J25hcHQ0NCcmcXVvdDs7PGJyPg0KPGJyPg0KVGhp
cyB3aWxsIHJlcXVpcmUgdXBkYXRpbmcgdGhlIE5BVCBZQU5HIG1vZHVsZSB0byBzcGVjaWZ5IGV4
cGxpY2l0bHkgYSBOQVQgVHlwZS48c3BhbiBjbGFzcz0iYXBwbGUtY29udmVydGVkLXNwYWNlIj4m
bmJzcDs8L3NwYW4+PGJyPg0KPGJyIHN0eWxlPSJmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsO29y
cGhhbnM6IGF1dG87dGV4dC1hbGlnbjpzdGFydDt3aWRvd3M6IGF1dG87LXdlYmtpdC10ZXh0LXN0
cm9rZS13aWR0aDogMHB4O3dvcmQtc3BhY2luZzowcHgiPg0KPGJyPg0KPC9zcGFuPjxvOnA+PC9v
OnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBw
dDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90
OyI+LSBZb3UgYXVnbWVudCBuYXQ6bWFwcGluZy1lbnRyeSwgd2hpY2ggaXMgYWxzbyBhIGxpc3Qg
d2l0aCBhIGtleSBvZjxicj4NCuKAmGluZGV44oCZLiBXaGVyZSBhcmUgeW91IGRlcml2aW5nIOKA
mGluZGV44oCZIGZyb20/PG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRp
Y2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+PGJyPg0KW01lZF0gSWRlbSBhcyBhYm92
ZS48YnI+DQo8YnIgc3R5bGU9ImZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7b3JwaGFuczogYXV0
bzt0ZXh0LWFsaWduOnN0YXJ0O3dpZG93czogYXV0bzstd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRo
OiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86cD48L286cD48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij4tIGI0LWlw
djQtYWRkcmVzcyBoYXMgYSBkZWZhdWx0IHZhbHVlIG9mIDE5Mi4wLjAuMiwgYW5kIHlvdSBoYXZl
IGEgbm90ZTxicj4NCnRoYXQgdGhlIG1hc2sgaXMgLzI5LiBBcmUgYWxsIGlwdjQgYWRkcmVzc2Vz
IGNvbmZpZ3VyZWQgd2l0aCAvMjkgbWFzaz8gSWY8YnI+DQpub3QsIGhvdyBpcyBuZXRtYXNrIGlu
ZGljYXRlZCB0byB0aGUgZGV2aWNlPzxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPjxicj4NCltNZWRdIFRoaXMg
aXMgYWJvdXQgYW4gSVB2NCBhZGRyZXNzLiBUaGUgbWFzayBpcyBub3QgcmVxdWlyZWQgdG8gYmUg
Y29uZmlndXJlZC4gVGhpcyBhZGRyZXNzIGNhbiBiZSBwaWNrZWQgZnJvbSB0aGUgLzI5IHJlc2Vy
dmVkIGJsb2NrLjxzcGFuIGNsYXNzPSJhcHBsZS1jb252ZXJ0ZWQtc3BhY2UiPiZuYnNwOzwvc3Bh
bj48YnI+DQo8YnIgc3R5bGU9ImZvbnQtdmFyaWFudC1jYXBzOiBub3JtYWw7b3JwaGFuczogYXV0
bzt0ZXh0LWFsaWduOnN0YXJ0O3dpZG93czogYXV0bzstd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRo
OiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86cD48L286cD48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48YnI+DQpT
ZWUgYWRkaXRpb25hbCBjb21tZW50cyBpbmxpbmUuPGJyPg0KPGJyPg0KQ2hlZXJzLjxicj4NCjxi
cj4NCjxicj4NCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxz
cGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1
b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPk9uIE9jdCA5LCAyMDE3LCBhdCAzOjM0IFBNLA0K
PGEgaHJlZj0ibWFpbHRvOm1vaGFtZWQuYm91Y2FkYWlyQG9yYW5nZS5jb20iPm1vaGFtZWQuYm91
Y2FkYWlyQG9yYW5nZS5jb208L2E+IHdyb3RlOjxicj4NCjxicj4NCkRlYXIgTWFoZXNoLDxicj4N
Cjxicj4NClRoYW5rIHlvdSB2ZXJ5IG11Y2ggZm9yIHRoZSBkZXRhaWxlZCByZXZpZXcuIE11Y2gg
YXBwcmVjaWF0ZWQuPGJyPg0KPGJyPg0KSXQgc2VlbXMgdGhhdCB5b3UgcmV2aWV3ZWQgLTAyIG9m
IHRoZSBkcmFmdCwgd2hpbGUgdGhlIGxhdGVzdCB2ZXJzaW9uIGlzPG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtm
b250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+
LTA2ICg8YSBocmVmPSJodHRwczovL2RhdGF0cmFja2VyLmlldGYub3JnL2RvYy9kcmFmdC1pZXRm
LXNvZnR3aXJlLWRzbGl0ZS15YW5nLyI+aHR0cHM6Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2Mv
ZHJhZnQtaWV0Zi1zb2Z0d2lyZS1kc2xpdGUteWFuZy88L2E+KS48YnI+DQo8YnI+DQo8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNl
cmlmJnF1b3Q7Ij48YnI+DQpBcyB5b3UgY2FuIHNlZSBiZWxvdywgYWxtb3N0IGFsbCB0aGUgY29t
bWVudHMgZG8gbm90IGFwcGx5IGZvciAtMDYuPGJyPg0KPGJyPg0KUGxlYXNlIHNlZSBpbmxpbmUu
PGJyPg0KPGJyPg0KQ2hlZXJzLDxicj4NCk1lZDxicj4NCjxicj4NCjxicj4NCjxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDsiPi0tLS0tTWVzc2FnZSBkJ29yaWdpbmUtLS0tLTxicj4NCkRlIDogTWFoZXNoIEpldGhh
bmFuZGFuaSBbPGEgaHJlZj0ibWFpbHRvOm1qZXRoYW5hbmRhbmlAZ21haWwuY29tIj5tYWlsdG86
bWpldGhhbmFuZGFuaUBnbWFpbC5jb208L2E+XTxicj4NCkVudm95w6kgOiBzYW1lZGkgNyBvY3Rv
YnJlIDIwMTcgMDI6MTc8YnI+DQrDgCA6IDxhIGhyZWY9Im1haWx0bzp5YW5nLWRvY3RvcnNAaWV0
Zi5vcmciPnlhbmctZG9jdG9yc0BpZXRmLm9yZzwvYT48YnI+DQpDYyA6IDxhIGhyZWY9Im1haWx0
bzpzb2Z0d2lyZXNAaWV0Zi5vcmciPnNvZnR3aXJlc0BpZXRmLm9yZzwvYT47IDxhIGhyZWY9Im1h
aWx0bzpkcmFmdC1pZXRmLXNvZnR3aXJlLWRzbGl0ZS15YW5nLmFsbEBpZXRmLm9yZyI+DQpkcmFm
dC1pZXRmLXNvZnR3aXJlLWRzbGl0ZS15YW5nLmFsbEBpZXRmLm9yZzwvYT47PGJyPg0KPGEgaHJl
Zj0ibWFpbHRvOmlldGZAaWV0Zi5vcmciPmlldGZAaWV0Zi5vcmc8L2E+PGJyPg0KT2JqZXQgOiBZ
YW5nZG9jdG9ycyBlYXJseSByZXZpZXcgb2YgZHJhZnQtaWV0Zi1zb2Z0d2lyZS1kc2xpdGUteWFu
Zy0wMjxicj4NCjxicj4NClJldmlld2VyOiBNYWhlc2ggSmV0aGFuYW5kYW5pPGJyPg0KUmV2aWV3
IHJlc3VsdDogT24gdGhlIFJpZ2h0IFRyYWNrPGJyPg0KPGJyPg0KRG9jdW1lbnQgcmV2aWV3ZWQ6
IGRyYWZ0LWlldGYtc29mdHdpcmUtZHNsaXRlLXlhbmctMDIuIERvIG5vdCBrbm93IHdoeTxvOnA+
PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250
LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPkk8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8YmxvY2tx
dW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPndhczxicj4NCmFz
c2lnbmVkIC0wMiB2ZXJzaW9uIHdoZW4gSSBub3cgbm90aWNlIHRoYXQgdGhlcmUgYXJlIHNldmVy
YWwgMDM8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hl
bHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij52ZXJzaW9uczxicj4NCjxicj4N
CjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUu
MHB0O21hcmdpbi1ib3R0b206NS4wcHQiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5
bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90OyI+c3VibWl0dGVkIGFsbCB0aGUgd2F5IHVwIHRvIC0wNi48YnI+
DQo8YnI+DQpTdGF0dXM6IE9uIHRoZSBSaWdodCBUcmFjay48YnI+DQo8YnI+DQpJIGFtIG5vdCBh
biBleHBlcnQgaW4gRFMtTGl0ZS4gVGhpcyByZXZpZXcgaXMgbG9va2luZyBhdCB0aGUgZHJhZnQg
ZnJvbTxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvYmxvY2txdW90ZT4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVs
dmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPmE8YnI+DQo8YnI+DQo8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJn
aW4tYm90dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250
LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPllBTkc8YnI+DQpwZXJzcGVjdGl2ZS4gV2l0aCB0aGF0IHNhaWQsIEkgaGF2
ZSBtYXJrZWQgaXQgYXMg4oCcT24gdGhlIFJpZ2h0IFRyYWNr4oCdPGJyPg0KYmVjYXVzZTxicj4N
Cm9mIHNvbWUgb2YgdGhlIHBvaW50cyBkaXNjdXNzZWQgYmVsb3cuIFRoZSBhdXRob3JzIGFyZSBl
bmNvdXJhZ2VkIHRvPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTom
cXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1b3Q7c2Fucy1zZXJpZiZxdW90OyI+c3BlbmQ8YnI+DQo8
YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRv
cDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7
LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPnRpbWU8YnI+DQpsb29raW5nIGF0IG90aGVyIG1vZGVs
cyBmb3IgZXhhbXBsZXMgb24gaG93IHRvIHdyaXRlIHRoZSBtb2RlbCwgcmVhZDxicj4NClJGQzYw
ODcsPGJyPg0KR3VpZGVsaW5lcyBmb3IgWUFORyBkb2N1bWVudHMuPGJyPg0KPGJyPg0KU3VtbWFy
eTo8YnI+DQo8YnI+DQpUaGlzIGRvY3VtZW50IGRlZmluZXMgYSBZQU5HIGRhdGEgbW9kZWwgZm9y
IHRoZSBEUy1MaXRlIEFkZHJlc3MgRmFtaWx5PGJyPg0KVHJhbnNpdGlvbiBSb3V0ZXIgKEFGVFIp
IGFuZCBCYXNpYyBCcmlkZ2luZyBCcm9hZEJhbmQgKEI0KSBlbGVtZW50cyAuPGJyPg0KPGJyPg0K
T3ZlcmFsbCBDb21tZW50czo8YnI+DQo8YnI+DQpUaGUgZHJhZnQgc2hvdWxkIHJlZmVyIHRvIFlB
TkcgMS4xIChSRkMgNzk1MCkgaW5zdGVhZCBvZiBSRkM2MDIwLjxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjwvYmxvY2txdW90ZT4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250
LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMt
c2VyaWYmcXVvdDsiPjxicj4NCltNZWRdIENhbiBmaXggdGhpcyBvbmUuPGJyPg0KPGJyPg0KPGJy
Pg0KPG86cD48L286cD48L3NwYW4+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5
bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssJnF1
b3Q7c2Fucy1zZXJpZiZxdW90OyI+PGJyPg0KVGhlIGRyYWZ0IGlzIG5vdCBOTURBIGNvbXBsaWFu
dC4gSXQgY2FycmllcyBhIHNlcGFyYXRlIC1zdGF0ZSBjb250YWluZXI8YnI+DQp0aGF0PGJyPg0K
bmVlZHMgdG8gYmUgY29sbGFwc2VkIGludG8gb25lIHNpbmdsZSBjb250YWluZXIuIEZvciBleGFt
cGxlLCBpdDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7
LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPmNhcnJpZXM8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwv
c3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90
dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDsiPmNvbnRhaW5lcnMgc3VjaCBhcyBhZnRyLWN1cnJlbnQtY29uZmlnIHdoaWNoIHNlZW1z
IHRvIGJlIGNhcnJ5aW5nIHN0YXRlPGJyPg0KaW5mb3JtYXRpb24gZm9yIHRoZSBsZWFmcyBpbiBk
c2xpdGUtY29uZmlnLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvYmxvY2txdW90ZT4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6
JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPjxicj4NCltNZWRd
IFRoZXJlIGFyZSBubyBzdWNoIGNvbnRhaW5lcnMgaW4gLTA2Ljxicj4NCjxicj4NCjxicj4NCjxv
OnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJm
b250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3Nh
bnMtc2VyaWYmcXVvdDsiPjxicj4NCklzIGl0IGdpdmVuIHRoYXQgYSBzZXJ2ZXIgd2lsbCBpbXBs
ZW1lbnQgYm90aCBBRlRSIGFuZCBCND88bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90
O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5bTWVkXSBOby48YnI+DQo8
YnI+DQpJZiBub3QsIHRoZW48YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5
OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij5wbGVhc2U8YnI+
DQpkZWZpbmUgZmVhdHVyZSBzdGF0ZW1lbnRzIGFuZCB1c2UgaWYtZmVhdHVyZSBmb3IgZWFjaCBw
YXJ0IChBRlRSIGFuZDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNh
JnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYmcXVvdDsiPkI0KSw8YnI+DQo8YnI+DQo8bzpwPjwvbzpw
Pjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4t
Ym90dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNp
emU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2Vy
aWYmcXVvdDsiPnNvPGJyPg0KaW1wbGVtZW50b3JzIGNhbiBjaG9vc2Ugd2hhdCBwYXJ0IG9mIHRo
ZSBtb2RlbCBpcyBpbXBsZW1lbnRlZC48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVv
dGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2Zv
bnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OywmcXVvdDtzYW5zLXNlcmlmJnF1b3Q7Ij48
YnI+DQpbbWpdIEkgZG8gbm90IHNlZSB0aGlzIGNvbW1lbnQgYWRkcmVzc2VkLjxvOnA+PC9vOnA+
PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6
OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7LCZxdW90O3NhbnMtc2VyaWYm
cXVvdDsiPjxicj4NCltNZWRdIFRoaXMgaXMgZWFzeSB0byBmaXguIEFjdHVhbGx5LCBJIGludGVy
cHJldGVkIG5vIGZvbGxvdy11cCBmcm9tIHlvdXIgc2lkZSBhcyBoYXZpbmcgc2VwYXJhdGUgbW9k
dWxlcyBpcyBhbHNvIGZpbmUgd2l0aCB5b3UuPHNwYW4gY2xhc3M9ImFwcGxlLWNvbnZlcnRlZC1z
cGFjZSI+Jm5ic3A7PC9zcGFuPjwvc3Bhbj48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj5GZWF0dXJlcyBhbGxvdyBwbGF0Zm9ybXMgdG8gaWRlbnRpZnkgcGFy
dHMgb2YgdGhlIG1vZGVsIHRoYXQgdGhleSBhcmUgY2FwYWJsZSBvZiBzdXBwb3J0aW5nLCB3aGls
ZSBhdCB0aGUgc2FtZSB0aW1lIHJlbW92aW5nIHBhcnRzIHRoYXQgYXJlIG5vdCBzdXBwb3J0ZWQu
IFBsYXRmb3JtcyBjYW4gZGV2aWF0ZSBhIG1vZGVsIGFuZCBzYXkgd2hhdCB0aGV5IGRvIG5vdCBz
dXBwb3J0IHBhcnRzIG9mIHRoZSBtb2RlbCwNCiBidXQgd2UgdXN1YWxseSByZXNlcnZlIHRoYXQg
Zm9yIHRoZSBjYXNlIHdoZXJlIHRoZXJlIGlzIG5vIChoYXJkd2FyZSkgc3VwcG9ydCBmb3IgYSBn
aXZlbiBmZWF0dXJlLiZuYnNwOzxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNv
Tm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1z
b05vcm1hbCI+TWFoZXNoIEpldGhhbmFuZGFuaTxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PGEgaHJlZj0ibWFpbHRvOm1qZXRoYW5hbmRhbmlAZ21h
aWwuY29tIj5tamV0aGFuYW5kYW5pQGdtYWlsLmNvbTwvYT48bzpwPjwvbzpwPjwvcD4NCjwvZGl2
Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwv
ZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjwvYm9keT4NCjwvaHRtbD4NCg==

--_000_787AE7BB302AE849A7480A190F8B93300A07B603OPEXCLILMA3corp_--


From nobody Thu Nov 16 01:46:35 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 82D19126CD6; Thu, 16 Nov 2017 01:46:29 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: opsawg@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151082558949.28398.8900743316228456893@ietfa.amsl.com>
Date: Thu, 16 Nov 2017 01:46:29 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/jq8iDHw-7Je8ULANfy67aA071Hg>
Subject: [OPSAWG] I-D Action: draft-ietf-opsawg-nat-yang-09.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 09:46:29 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operations and Management Area Working Group WG of the IETF.

        Title           : A YANG Data Model for Network Address Translation (NAT) and Network Prefix Translation (NPT)
        Authors         : Mohamed Boucadair
                          Senthil Sivakumar
                          Christian Jacquenet
                          Suresh Vinapamula
                          Qin Wu
	Filename        : draft-ietf-opsawg-nat-yang-09.txt
	Pages           : 97
	Date            : 2017-11-16

Abstract:
   For the sake of network automation and the need for programming
   Network Address Translation (NAT) function in particular, a data
   model for configuring and managing the NAT is essential.  This
   document defines a YANG module for the NAT function.

   NAT44, Network Address and Protocol Translation from IPv6 Clients to
   IPv4 Servers (NAT64), Customer-side transLATor (CLAT), Stateless IP/
   ICMP Translation (SIIT), Explicit Address Mappings for Stateless IP/
   ICMP Translation (SIIT EAM), and IPv6 Network Prefix Translation
   (NPTv6) are covered in this document.

Editorial Note (To be removed by RFC Editor)

   Please update these statements with the RFC number to be assigned to
   this document:

      "This version of this YANG module is part of RFC XXXX;"

      "RFC XXXX: A YANG Data Model for Network Address Translation (NAT)
      and Network Prefix Translation (NPT)";

      "reference: RFC XXXX"


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsawg-nat-yang/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-opsawg-nat-yang-09
https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-nat-yang-09

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsawg-nat-yang-09


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Nov 17 16:54:41 2017
Return-Path: <meral.shirazipour@ericsson.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 2F997120725; Fri, 17 Nov 2017 16:54:34 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E675D128B27; Fri, 17 Nov 2017 16:54:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level: 
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9Xa389JMUijx; Fri, 17 Nov 2017 16:54:32 -0800 (PST)
Received: from usplmg20.ericsson.net (usplmg20.ericsson.net [198.24.6.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F3410120725; Fri, 17 Nov 2017 16:54:28 -0800 (PST)
X-AuditID: c618062d-8d7ff70000004288-ec-5a0f84c30677
Received: from EUSAAHC003.ericsson.se (Unknown_Domain [147.117.188.81]) by usplmg20.ericsson.net (Symantec Mail Security) with SMTP id FF.A4.17032.4C48F0A5; Sat, 18 Nov 2017 01:54:28 +0100 (CET)
Received: from EUSAAMB104.ericsson.se ([147.117.188.121]) by EUSAAHC003.ericsson.se ([147.117.188.81]) with mapi id 14.03.0352.000; Fri, 17 Nov 2017 19:54:27 -0500
From: Meral Shirazipour <meral.shirazipour@ericsson.com>
To: "draft-mm-wg-effect-encrypt.all@ietf.org" <draft-mm-wg-effect-encrypt.all@ietf.org>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
Thread-Index: AdNgB6yY9jj5oPXlSxirD4NdewN5IQ==
Date: Sat, 18 Nov 2017 00:54:26 +0000
Message-ID: <ABCAA4EF18F17B4FB619EA93DEF7939A4F639544@eusaamb104.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [147.117.188.10]
Content-Type: multipart/alternative; boundary="_000_ABCAA4EF18F17B4FB619EA93DEF7939A4F639544eusaamb104erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrHLMWRmVeSWpSXmKPExsUyuXRPoO6RFv4og597hSyWzp7GbnH11WcW ByaPJUt+MgUwRnHZpKTmZJalFunbJXBlfLnyl7lgvVbF9OlL2RoYD6h2MXJySAiYSDybtIW1 i5GLQ0jgCKNEw5bnbBDOciDn7WUWkCo2AQuJ7b+fg1WJCDQxShw5epwRJCEs4CTxcPZONhBb RMBdYtqu54wQtp7E0UunwJpZBFQlZjyexwxi8wr4Skw7+IEVxGYUEJP4fmoNE4jNLCAucevJ fCaIkwQkluw5zwxhi0q8fPyPFcJWkpi09ByQzQFUny9x4Wg6xEhBiZMzn7BMYBSchWTSLISq WUiqIEp0JBbs/sQGYWtLLFv4mhnGPnPgMROy+AJG9lWMHKXFBTm56UYGmxiBoX5Mgk13B+P9 6Z6HGAU4GJV4eHcX80cJsSaWFVfmHmKU4GBWEuGdsZwvSog3JbGyKrUoP76oNCe1+BCjNAeL kjjvGU/eKCGB9MSS1OzU1ILUIpgsEwenVAOjSqHszoBWR53e8nwbP4/AXD8xxqPXv3172+zQ y/jV59WcvUwxATksV+JV7kaszdVVnfGidZPrOq0Z3XLNv7sXF2Xd7n7i18BQMTl61uzbagml R17Eh3VzJho9327Q7BiQ2v+24HlNXuUjU67uhHPc93sn71HLV+T7pPKa82KDcob6TOk5x5RY ijMSDbWYi4oTAaUIoCdxAgAA
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171118005434.2F997120725@ietfa.amsl.com>
Resent-Date: Fri, 17 Nov 2017 16:54:34 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/QT6xHUpgoYhDcdmEJqv0nYUzhoI>
Subject: [OPSAWG] Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Nov 2017 00:54:34 -0000

--_000_ABCAA4EF18F17B4FB619EA93DEF7939A4F639544eusaamb104erics_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

I am the assigned Gen-ART reviewer for this draft. The General Area Review =
Team (Gen-ART) reviews all IETF documents being processed by the IESG for t=
he IETF Chair.  Please treat these comments just like any other last call c=
omments.
For more information, please see the FAQ at <http://wiki.tools.ietf.org/are=
a/gen/trac/wiki/GenArtfaq>.


Document: draft-mm-wg-effect-encrypt-13
Reviewer: Meral Shirazipour
Review Date: 2017-11-17
IETF LC End Date:  2017-12-04
IESG Telechat date: NA

Summary:
This draft is ready to be published as Informational RFC.

Major issues:
Minor issues:
Nits/editorial comments:
-[Page 33], Section 6, "inlcudes"---->"includes"
-[Page 34], Section 6.2, "soltuions"---->"solutions"
-[Page 35], typo "7.1.  Effect of Encypted ACKs"--->"7.1.  Effect of Encryp=
ted ACKs"
-[Page 37], Section 7.3, point 3 is empty.
-Please change the few occurrences of "middle box" to  "middlebox"

Best Regards,
Meral
---
Meral Shirazipour
Ericsson Research
www.ericsson.com

--_000_ABCAA4EF18F17B4FB619EA93DEF7939A4F639544eusaamb104erics_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">I am the assigned Gen-ART reviewer for this draft. T=
he General Area Review Team (Gen-ART) reviews all IETF documents being proc=
essed by the IESG for the IETF Chair.&nbsp; Please treat these comments jus=
t like any other last call comments.<o:p></o:p></p>
<p class=3D"MsoNormal">For more information, please see the FAQ at &lt;http=
://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq&gt;.
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">Document: draft-mm-wg-effect-en=
crypt-13<o:p></o:p></span></p>
<p class=3D"MsoNormal">Reviewer: Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Review Date: 2017-11-17<o:p></o:p></p>
<p class=3D"MsoNormal">IETF LC End Date:&nbsp; 2017-12-04<o:p></o:p></p>
<p class=3D"MsoNormal">IESG Telechat date: NA<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Summary:<o:p></o:p></p>
<p class=3D"MsoNormal">This draft is ready to be published as Informational=
 RFC.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Major issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Minor issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Nits/editorial comments:<o:p></o:p></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 33], Section 6, &quot;in=
lcudes&quot;----&gt;&quot;includes&quot;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 34], Section 6.2, &quot;=
soltuions&quot;----&gt;&quot;solutions&quot;<o:p></o:p></span></p>
<p class=3D"MsoNormal">-[Page 35], typo &quot;7.1.&nbsp; Effect of Encypted=
 ACKs&quot;---&gt;&quot;7.1.&nbsp; Effect of Encrypted ACKs&quot;<o:p></o:p=
></p>
<p class=3D"MsoNormal">-[Page 37], Section 7.3, point 3 is empty.<o:p></o:p=
></p>
<p class=3D"MsoNormal">-Please change the few occurrences of &#8220;middle =
box&#8221; to&nbsp; &#8220;middlebox&#8221;<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Best Regards,<o:p></o:p></p>
<p class=3D"MsoNormal">Meral<o:p></o:p></p>
<p class=3D"MsoNormal">---<o:p></o:p></p>
<p class=3D"MsoNormal">Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Ericsson Research<o:p></o:p></p>
<p class=3D"MsoNormal">www.ericsson.com<o:p></o:p></p>
</div>
</body>
</html>

--_000_ABCAA4EF18F17B4FB619EA93DEF7939A4F639544eusaamb104erics_--


From nobody Fri Nov 17 23:43:47 2017
Return-Path: <acmorton@att.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 951E41200C1; Fri, 17 Nov 2017 23:43:40 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36E2E126B72; Fri, 17 Nov 2017 23:43:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.62
X-Spam-Level: 
X-Spam-Status: No, score=-2.62 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9ajRfO9eeHHr; Fri, 17 Nov 2017 23:43:38 -0800 (PST)
Received: from mx0a-00191d01.pphosted.com (mx0a-00191d01.pphosted.com [67.231.149.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B31021200C1; Fri, 17 Nov 2017 23:43:38 -0800 (PST)
Received: from pps.filterd (m0049295.ppops.net [127.0.0.1]) by m0049295.ppops.net-00191d01. (8.16.0.21/8.16.0.21) with SMTP id vAI6P7vM010697; Sat, 18 Nov 2017 01:34:35 -0500
Received: from tlpd255.enaf.dadc.sbc.com (sbcsmtp3.sbc.com [144.160.112.28]) by m0049295.ppops.net-00191d01. with ESMTP id 2eaeg4s41v-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sat, 18 Nov 2017 01:34:35 -0500
Received: from enaf.dadc.sbc.com (localhost [127.0.0.1]) by tlpd255.enaf.dadc.sbc.com (8.14.5/8.14.5) with ESMTP id vAI6YYtf022547; Sat, 18 Nov 2017 00:34:34 -0600
Received: from dalint02.pst.cso.att.com (dalint02.pst.cso.att.com [135.31.133.160]) by tlpd255.enaf.dadc.sbc.com (8.14.5/8.14.5) with ESMTP id vAI6YW5Z022542 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Sat, 18 Nov 2017 00:34:32 -0600
Received: from clpi183.sldc.sbc.com (clpi183.sldc.sbc.com [135.41.1.46]) by dalint02.pst.cso.att.com (RSA Interceptor); Sat, 18 Nov 2017 06:34:23 GMT
Received: from sldc.sbc.com (localhost [127.0.0.1]) by clpi183.sldc.sbc.com (8.14.5/8.14.5) with ESMTP id vAI6YNCM008009; Sat, 18 Nov 2017 00:34:23 -0600
Received: from mail-azure.research.att.com (mail-azure.research.att.com [135.207.255.18]) by clpi183.sldc.sbc.com (8.14.5/8.14.5) with ESMTP id vAI6YGtO007804; Sat, 18 Nov 2017 00:34:16 -0600
Received: from exchange.research.att.com (njmtcas2.research.att.com [135.207.255.47]) by mail-azure.research.att.com (Postfix) with ESMTP id F2C46E3CAA; Sat, 18 Nov 2017 01:34:15 -0500 (EST)
Received: from njmtexg5.research.att.com ([fe80::b09c:ff13:4487:78b6]) by njmtcas2.research.att.com ([fe80::d550:ec84:f872:cad9%15]) with mapi id 14.03.0361.001; Sat, 18 Nov 2017 01:34:15 -0500
From: "MORTON, ALFRED C (AL)" <acmorton@att.com>
To: Meral Shirazipour <meral.shirazipour@ericsson.com>, "draft-mm-wg-effect-encrypt.all@ietf.org" <draft-mm-wg-effect-encrypt.all@ietf.org>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
Thread-Index: AdNgB6yY9jj5oPXlSxirD4NdewN5IQAL2l0g
Date: Sat, 18 Nov 2017 06:34:14 +0000
Message-ID: <4D7F4AD313D3FC43A053B309F97543CF4904B16A@njmtexg5.research.att.com>
References: <ABCAA4EF18F17B4FB619EA93DEF7939A4F639544@eusaamb104.ericsson.se>
In-Reply-To: <ABCAA4EF18F17B4FB619EA93DEF7939A4F639544@eusaamb104.ericsson.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [31.133.145.45]
Content-Type: multipart/alternative; boundary="_000_4D7F4AD313D3FC43A053B309F97543CF4904B16Anjmtexg5researc_"
MIME-Version: 1.0
X-RSA-Inspected: yes
X-RSA-Classifications: public
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-11-18_03:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_policy_notspam policy=outbound_policy score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1709140000 definitions=main-1711180092
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171118074340.951E41200C1@ietfa.amsl.com>
Resent-Date: Fri, 17 Nov 2017 23:43:40 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/Ua3k8uhoF31d9_AeEqb4wRBr5Qc>
Subject: Re: [OPSAWG] Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Nov 2017 07:43:40 -0000

--_000_4D7F4AD313D3FC43A053B309F97543CF4904B16Anjmtexg5researc_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Thanks for your review, Meral,
we'll make these changes in -14.

regards,
Al

From: Meral Shirazipour [mailto:meral.shirazipour@ericsson.com]
Sent: Friday, November 17, 2017 7:54 PM
To: draft-mm-wg-effect-encrypt.all@ietf.org; gen-art@ietf.org
Subject: Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
...
Document: draft-mm-wg-effect-encrypt-13
Reviewer: Meral Shirazipour
Review Date: 2017-11-17
IETF LC End Date:  2017-12-04
IESG Telechat date: NA

Summary:
This draft is ready to be published as Informational RFC.

Major issues:
Minor issues:
Nits/editorial comments:
-[Page 33], Section 6, "inlcudes"---->"includes"
-[Page 34], Section 6.2, "soltuions"---->"solutions"
-[Page 35], typo "7.1.  Effect of Encypted ACKs"--->"7.1.  Effect of Encryp=
ted ACKs"
-[Page 37], Section 7.3, point 3 is empty.
-Please change the few occurrences of "middle box" to  "middlebox"

Best Regards,
Meral
---
Meral Shirazipour
Ericsson Research
www.ericsson.com<https://urldefense.proofpoint.com/v2/url?u=3Dhttp-3A__www.=
ericsson.com&d=3DDwQFAg&c=3DLFYZ-o9_HUMeMTSQicvjIg&r=3DOfsSu8kTIltVyD1oL72c=
Bw&m=3DuEjhJp6GHNaj01bTwdhbSK3G6VCzoPIHXwrKvr0OxuA&s=3D-D2mkUrYK5hsyjdM3Q15=
h24XDVARu77iXsMolSzDmvE&e=3D>

--_000_4D7F4AD313D3FC43A053B309F97543CF4904B16Anjmtexg5researc_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Courier New";
	color:black;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black">Thanks for your review, Meral,
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black">we&#8217;ll make these changes in -14.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black">regards,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black">Al<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;c=
olor:black"><o:p>&nbsp;</o:p></span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Meral Sh=
irazipour [mailto:meral.shirazipour@ericsson.com]
<br>
<b>Sent:</b> Friday, November 17, 2017 7:54 PM<br>
<b>To:</b> draft-mm-wg-effect-encrypt.all@ietf.org; gen-art@ietf.org<br>
<b>Subject:</b> Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13<o=
:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span style=3D"color:black">&#8230;</span><o:p></o:p=
></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">Document: draft-mm-wg-effect-en=
crypt-13<o:p></o:p></span></p>
<p class=3D"MsoNormal">Reviewer: Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Review Date: 2017-11-17<o:p></o:p></p>
<p class=3D"MsoNormal">IETF LC End Date:&nbsp; 2017-12-04<o:p></o:p></p>
<p class=3D"MsoNormal">IESG Telechat date: NA<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Summary:<o:p></o:p></p>
<p class=3D"MsoNormal">This draft is ready to be published as Informational=
 RFC.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Major issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Minor issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Nits/editorial comments:<o:p></o:p></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 33], Section 6, &quot;in=
lcudes&quot;----&gt;&quot;includes&quot;<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 34], Section 6.2, &quot;=
soltuions&quot;----&gt;&quot;solutions&quot;<o:p></o:p></span></p>
<p class=3D"MsoNormal">-[Page 35], typo &quot;7.1.&nbsp; Effect of Encypted=
 ACKs&quot;---&gt;&quot;7.1.&nbsp; Effect of Encrypted ACKs&quot;<o:p></o:p=
></p>
<p class=3D"MsoNormal">-[Page 37], Section 7.3, point 3 is empty.<o:p></o:p=
></p>
<p class=3D"MsoNormal">-Please change the few occurrences of &#8220;middle =
box&#8221; to&nbsp; &#8220;middlebox&#8221;<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Best Regards,<o:p></o:p></p>
<p class=3D"MsoNormal">Meral<o:p></o:p></p>
<p class=3D"MsoNormal">---<o:p></o:p></p>
<p class=3D"MsoNormal">Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Ericsson Research<o:p></o:p></p>
<p class=3D"MsoNormal"><a href=3D"https://urldefense.proofpoint.com/v2/url?=
u=3Dhttp-3A__www.ericsson.com&amp;d=3DDwQFAg&amp;c=3DLFYZ-o9_HUMeMTSQicvjIg=
&amp;r=3DOfsSu8kTIltVyD1oL72cBw&amp;m=3DuEjhJp6GHNaj01bTwdhbSK3G6VCzoPIHXwr=
Kvr0OxuA&amp;s=3D-D2mkUrYK5hsyjdM3Q15h24XDVARu77iXsMolSzDmvE&amp;e=3D">www.=
ericsson.com</a><o:p></o:p></p>
</div>
</div>
</body>
</html>

--_000_4D7F4AD313D3FC43A053B309F97543CF4904B16Anjmtexg5researc_--


From nobody Sat Nov 18 00:52:23 2017
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id B08251200C1; Sat, 18 Nov 2017 00:52:16 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 67B38126C3D; Sat, 18 Nov 2017 00:52:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level: 
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eVpIl5AHW4nw; Sat, 18 Nov 2017 00:52:14 -0800 (PST)
Received: from mail-pf0-x22b.google.com (mail-pf0-x22b.google.com [IPv6:2607:f8b0:400e:c00::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3140E1200C1; Sat, 18 Nov 2017 00:52:13 -0800 (PST)
Received: by mail-pf0-x22b.google.com with SMTP id m88so3681379pfi.9; Sat, 18 Nov 2017 00:52:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=ZVqrewH+nR0ZrPnPLYwythYCHguoEC70kYdIiSqLYck=; b=fzQLZN2VdQdM1I13ODG5yMk7xxb1fRQU21DWnMeXBApLy1vmb+APUcovrRa0W5Kkvr 2kN+bSSXjlrxd/kTuo81YJtf+9wSHJzHgTUTo04fL/7rGMI43jJ3crkkGS+cNyBp4Msf KSL298RwsOT7UQu36v/LdEslBDyGCpEgYaVnHix//u9HzfQodJWlsRq71XvNf2u0jsIt yMo9TYcIlEQBWJ7cR7JtCrFK4sXk7kzTqv9bG7YqGiQYsRJIsRoQOl/RuiByfTKNNUU7 pigcT1CrFbWfVO9XjH7DhMaBDHjY2iWmhV+toY+0T5BYzjfjFtIemo+mk8/lox7QOssQ gsSg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=ZVqrewH+nR0ZrPnPLYwythYCHguoEC70kYdIiSqLYck=; b=Ac11symbIfil1nBQzmwLDEXQJud7mgGiDl7t4nQun1y1VgQhLU/chaWm3LjvFwlZBk nYIuWyO0YymADEZUkLy8VN46WMgFmvme9Nupond/KzfsrRtK48h1I7SFVZBYNvoSzGbM jgCLPnlugB0cZSE2x1yJEJ3s0RfyaoftfwC+KbgaHJ/MLeWqi27woDu5HTyTebOlvy8+ I8376Ift6RPpu7AhDn9a5M2Vfc6QtaO79Nenp1HAcZXJoYtJZT/oHnX1yB15wKLut/ud Fp96ZeNIYnKQ3+MfePHe+0+aLC6oiEL6NjlO4S/RyMGXj1KGNAHE1HikRsqKGi8kjF03 bIXg==
X-Gm-Message-State: AJaThX4Dz3lWG0OhNGkCYbAsnPU3MkQEy3iGAYqI914Bzook4iQakFQX zMkfLxmRgsGW5lYuEXjgmsBzY5rN
X-Google-Smtp-Source: AGs4zMYEonr6vA7Ho8NsXfDrbBKug3pwejTLTZG23FbDa2ABhyk7dz/kOMRiiFQQNxEO7vzcagIH8A==
X-Received: by 10.99.120.5 with SMTP id t5mr7545254pgc.138.1510995133465; Sat, 18 Nov 2017 00:52:13 -0800 (PST)
Received: from [192.168.140.101] ([210.176.50.21]) by smtp.gmail.com with ESMTPSA id b127sm8053375pgc.70.2017.11.18.00.52.12 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 18 Nov 2017 00:52:12 -0800 (PST)
Content-Type: multipart/alternative; boundary=Apple-Mail-62E27386-F5D4-4952-A5F9-FFBFDF8B78D2
Mime-Version: 1.0 (1.0)
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
X-Mailer: iPhone Mail (14F89)
In-Reply-To: <4D7F4AD313D3FC43A053B309F97543CF4904B16A@njmtexg5.research.att.com>
Date: Sat, 18 Nov 2017 16:52:11 +0800
Cc: Meral Shirazipour <meral.shirazipour@ericsson.com>, "draft-mm-wg-effect-encrypt.all@ietf.org" <draft-mm-wg-effect-encrypt.all@ietf.org>,  "gen-art@ietf.org" <gen-art@ietf.org>
Content-Transfer-Encoding: 7bit
Message-Id: <68D75D7A-F4BC-4BD6-817E-F7F43EB78553@gmail.com>
References: <ABCAA4EF18F17B4FB619EA93DEF7939A4F639544@eusaamb104.ericsson.se> <4D7F4AD313D3FC43A053B309F97543CF4904B16A@njmtexg5.research.att.com>
To: "MORTON, ALFRED C (AL)" <acmorton@att.com>
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171118085216.B08251200C1@ietfa.amsl.com>
Resent-Date: Sat, 18 Nov 2017 00:52:16 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/7pvf7BDCYI0vFOmhSxxPh1n5Lp0>
Subject: Re: [OPSAWG] Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 18 Nov 2017 08:52:17 -0000

--Apple-Mail-62E27386-F5D4-4952-A5F9-FFBFDF8B78D2
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable



Sent from my mobile device

> On Nov 18, 2017, at 2:34 PM, MORTON, ALFRED C (AL) <acmorton@att.com> wrot=
e:
>=20
> Thanks for your review, Meral,
> we=E2=80=99ll make these changes in -14.

Yes, thank you for your review, Meral!

Kathleen=20
> =20
> regards,
> Al
> =20
> From: Meral Shirazipour [mailto:meral.shirazipour@ericsson.com]=20
> Sent: Friday, November 17, 2017 7:54 PM
> To: draft-mm-wg-effect-encrypt.all@ietf.org; gen-art@ietf.org
> Subject: Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13
> =E2=80=A6
> Document: draft-mm-wg-effect-encrypt-13
> Reviewer: Meral Shirazipour
> Review Date: 2017-11-17
> IETF LC End Date:  2017-12-04
> IESG Telechat date: NA
> =20
> Summary:
> This draft is ready to be published as Informational RFC.
> =20
> Major issues:
> Minor issues:
> Nits/editorial comments:
> -[Page 33], Section 6, "inlcudes"---->"includes"
> -[Page 34], Section 6.2, "soltuions"---->"solutions"
> -[Page 35], typo "7.1.  Effect of Encypted ACKs"--->"7.1.  Effect of Encry=
pted ACKs"
> -[Page 37], Section 7.3, point 3 is empty.
> -Please change the few occurrences of =E2=80=9Cmiddle box=E2=80=9D to  =E2=
=80=9Cmiddlebox=E2=80=9D
> =20
> Best Regards,
> Meral
> ---
> Meral Shirazipour
> Ericsson Research
> www.ericsson.com

--Apple-Mail-62E27386-F5D4-4952-A5F9-FFBFDF8B78D2
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div><br><br>Sent from my mobile device</di=
v><div><br>On Nov 18, 2017, at 2:34 PM, MORTON, ALFRED C (AL) &lt;<a href=3D=
"mailto:acmorton@att.com">acmorton@att.com</a>&gt; wrote:<br><br></div><bloc=
kquote type=3D"cite"><div>

<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii">=

<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Courier New";
	color:black;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->


<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black">Thanks for your review, Meral,
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black">we=E2=80=99ll make these changes in -14.</span></p></div></div></=
blockquote><div><br></div>Yes, thank you for your review, Meral!<div><br></d=
iv><div>Kathleen&nbsp;<br><blockquote type=3D"cite"><div><div class=3D"WordS=
ection1"><p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New=
&quot;;color:black"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black">regards,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black">Al<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;;co=
lor:black"><o:p>&nbsp;</o:p></span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4=
.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0=
in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot;=
Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-siz=
e:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Meral Shira=
zipour [<a href=3D"mailto:meral.shirazipour@ericsson.com">mailto:meral.shira=
zipour@ericsson.com</a>]
<br>
<b>Sent:</b> Friday, November 17, 2017 7:54 PM<br>
<b>To:</b> <a href=3D"mailto:draft-mm-wg-effect-encrypt.all@ietf.org">draft-=
mm-wg-effect-encrypt.all@ietf.org</a>; <a href=3D"mailto:gen-art@ietf.org">g=
en-art@ietf.org</a><br>
<b>Subject:</b> Gen-ART Last Call review of draft-mm-wg-effect-encrypt-13<o:=
p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span style=3D"color:black">=E2=80=A6</span><o:p></o:=
p></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">Document: draft-mm-wg-effect-enc=
rypt-13<o:p></o:p></span></p>
<p class=3D"MsoNormal">Reviewer: Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Review Date: 2017-11-17<o:p></o:p></p>
<p class=3D"MsoNormal">IETF LC End Date:&nbsp; 2017-12-04<o:p></o:p></p>
<p class=3D"MsoNormal">IESG Telechat date: NA<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Summary:<o:p></o:p></p>
<p class=3D"MsoNormal">This draft is ready to be published as Informational R=
FC.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Major issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Minor issues:<o:p></o:p></p>
<p class=3D"MsoNormal">Nits/editorial comments:<o:p></o:p></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 33], Section 6, "inlcudes=
"----&gt;"includes"<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"FR-CA">-[Page 34], Section 6.2, "soltui=
ons"----&gt;"solutions"<o:p></o:p></span></p>
<p class=3D"MsoNormal">-[Page 35], typo "7.1.&nbsp; Effect of Encypted ACKs"=
---&gt;"7.1.&nbsp; Effect of Encrypted ACKs"<o:p></o:p></p>
<p class=3D"MsoNormal">-[Page 37], Section 7.3, point 3 is empty.<o:p></o:p>=
</p>
<p class=3D"MsoNormal">-Please change the few occurrences of =E2=80=9Cmiddle=
 box=E2=80=9D to&nbsp; =E2=80=9Cmiddlebox=E2=80=9D<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Best Regards,<o:p></o:p></p>
<p class=3D"MsoNormal">Meral<o:p></o:p></p>
<p class=3D"MsoNormal">---<o:p></o:p></p>
<p class=3D"MsoNormal">Meral Shirazipour<o:p></o:p></p>
<p class=3D"MsoNormal">Ericsson Research<o:p></o:p></p>
<p class=3D"MsoNormal"><a href=3D"https://urldefense.proofpoint.com/v2/url?u=
=3Dhttp-3A__www.ericsson.com&amp;d=3DDwQFAg&amp;c=3DLFYZ-o9_HUMeMTSQicvjIg&a=
mp;r=3DOfsSu8kTIltVyD1oL72cBw&amp;m=3DuEjhJp6GHNaj01bTwdhbSK3G6VCzoPIHXwrKvr=
0OxuA&amp;s=3D-D2mkUrYK5hsyjdM3Q15h24XDVARu77iXsMolSzDmvE&amp;e=3D">www.eric=
sson.com</a><o:p></o:p></p>
</div>
</div>


</div></blockquote></div></body></html>=

--Apple-Mail-62E27386-F5D4-4952-A5F9-FFBFDF8B78D2--


From nobody Mon Nov 27 10:57:06 2017
Return-Path: <warren@kumari.net>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 722321292FC for <opsawg@ietfa.amsl.com>; Mon, 27 Nov 2017 10:57:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kumari-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2k6HuIA5pFr1 for <opsawg@ietfa.amsl.com>; Mon, 27 Nov 2017 10:57:03 -0800 (PST)
Received: from mail-wr0-x230.google.com (mail-wr0-x230.google.com [IPv6:2a00:1450:400c:c0c::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 013141292CE for <opsawg@ietf.org>; Mon, 27 Nov 2017 10:57:02 -0800 (PST)
Received: by mail-wr0-x230.google.com with SMTP id k18so22504252wre.1 for <opsawg@ietf.org>; Mon, 27 Nov 2017 10:57:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kumari-net.20150623.gappssmtp.com; s=20150623; h=mime-version:from:date:message-id:subject:to; bh=A6A1EZT4NITyH4SFfx9/5As0P67Mt/d8+DbVShmETp0=; b=UrD5WXV+5rYrAr/QxeXaylM1oY5MGJkTSKi6Sx58BIrhm9xmijRrohIln54bQmc5E5 k0Ukq3b4PzQqto91BuUTW9gFIJnNRPEA4SATy/yfQkCB6IdMXBMTKPN58JsMol/01Ee0 yVWbgPDTD5xsL9zFxUHmH5F0/8bbyxkDJlCvEsl92Hnkw6yEG0fUEzNhHV9H/T0v2vB5 4JzSgnFY+Ic8Xz26WuWudGW6sYQN891uoHRBjpVbsyHb8owdEECrORjrgiQIC0sFqdTl +tJt2UruRRj+GP6w/TD9YT7uM5fqqEu2nBAX5zMOiFmvRQRzCyhfMC8lDw5LZ/S9Q+7m E9Jw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=A6A1EZT4NITyH4SFfx9/5As0P67Mt/d8+DbVShmETp0=; b=JAeSLfwBhW7qu2Nl85f1ieBK83dcU+BxGthBKjErzFvpvYToueevCOStqK4sQ59XWv WQ+RVDVBEi+6FyjTdjEc1YD/rPjX0r3iE17hdJr+NDMaQl+MYKJxY92BFCQNuXRLqNE2 iqD+UGyIAbu32yuKQWO8T7AGFAqwKixSCL8q4VvUBDp2IoW9ZbHA9MJ5OfN0OZuDGqt6 trXHvRKZ5Y8E5+B0Fv9OgW4+2xVhlA6PKWGBs9NuCFbkkarfxtZSVnYRMopeJAKTNIIf juixIJTzIRX/gkiqjZh4z19YIXcQxf4UI1wyWltxCjur7ZAkrfXhP5SNIiZhWKZRoDi4 WlRQ==
X-Gm-Message-State: AJaThX6VhdYRLswmGYteWK7Umz2scfCt69tD8m8PP7ZPt4tN4W7rxLwa xSw3PqK+brhqVu3dfvvOOE1Qff4/4NH7ywOT+3x4NtpStQE=
X-Google-Smtp-Source: AGs4zMY4PF5T4ShRJKTi0BIC3bcsKOhgXBIhKamA1+LmJ8uf4mcWY8yJp0STyG0LS7FYVqOMHpgNuVcoftdDnGmhk6I=
X-Received: by 10.223.170.4 with SMTP id p4mr4882006wrd.109.1511809021006; Mon, 27 Nov 2017 10:57:01 -0800 (PST)
MIME-Version: 1.0
Received: by 10.223.160.149 with HTTP; Mon, 27 Nov 2017 10:56:20 -0800 (PST)
From: Warren Kumari <warren@kumari.net>
Date: Mon, 27 Nov 2017 13:56:20 -0500
Message-ID: <CAHw9_iLUZv4c9QviM7oZ+pp7njLpgifOSxXEuD5scO9SFee5Jw@mail.gmail.com>
To: opsawg@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/dUVaPvLWONluGhecV6SjVQYhAPI>
Subject: [OPSAWG] Reminder to provide feedback on draft-mm-wg-effect-encrypt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Nov 2017 18:57:04 -0000

Hi all,

Just a reminder that this document was discussed in the OpsAWG /
OpsArea meeting and a large number of people said that they would read
and provide feedback on this document (hopefully even on the plane
back to $origin) -- now would be a good time to provide feedback on
the IETF LC if you haven't already.

Document: https://datatracker.ietf.org/doc/draft-mm-wg-effect-encrypt/

LC announcement:
https://www.ietf.org/mail-archive/web/ietf-announce/current/msg17159.html

Slides (reminder):
https://datatracker.ietf.org/meeting/100/materials/slides-100-opsawg-effects-of-pervasive-encryption-slides/

W

-- 
I don't think the execution is relevant when it was obviously a bad
idea in the first place.
This is like putting rabid weasels in your pants, and later expressing
regret at having chosen those particular rabid weasels and that pair
of pants.
   ---maf


From nobody Wed Nov 29 07:31:28 2017
Return-Path: <jclarke@cisco.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 119EC124D37; Wed, 29 Nov 2017 07:31:07 -0800 (PST)
X-Original-To: draft-mm-wg-effect-encrypt.all@ietf.org
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D68881200FC; Wed, 29 Nov 2017 07:31:06 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Joe Clarke <jclarke@cisco.com>
To: <ops-dir@ietf.org>
Cc: draft-mm-wg-effect-encrypt.all@ietf.org, ietf@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151196946679.7944.3160175486224623517@ietfa.amsl.com>
Date: Wed, 29 Nov 2017 07:31:06 -0800
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171129153107.119EC124D37@ietfa.amsl.com>
Resent-Date: Wed, 29 Nov 2017 07:31:07 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/dtT9cTrZwtU-QUvuS125waTucnE>
Subject: [OPSAWG] Opsdir last call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 15:31:07 -0000

Reviewer: Joe Clarke
Review result: Has Nits

I have been requested to review draft-mm-wg-effect-encrypt for the ops
directorate.  This document describes the effects of pervasive encryption on
operators.  The document sets out a rather comprehensive list of network data
(in motion and at rest) use cases and explains how encryption will effect each
of them.  Overall, I feel this document is ready.  As someone that has
supported networks from a troubleshooting perspective for years, I was
especially pleased with the numerous callouts to troubleshooting impacts as
well as deficiencies in application logging.

To that end, it might be useful to specifically point out where vendors have a
role to fill in some of these areas to allow for transit encryption while
providing the necessary hooks for operators to manage and troubleshoot their
network.  Specifically, in many of the troubleshooting scenarios, operators
won't be able to provide truly useful tools to their end users unless the
vendors provide the right level of visibility.

On to some nits.

In section 1.1 you use "end user's" where I think you mean "end users'".

===

Section 2.  Today, Snowden is fairly well-known.  But as this document lives,
maybe the specifics of what he's done may get fuzzy.  Perhaps this could do
with a reference.

===

Sections 5.3 and 6.2: you reference the abbreviation SNI before formally
defining it.  It's more obvious in Section 6.2.



From nobody Wed Nov 29 08:22:24 2017
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 695F5127B57; Wed, 29 Nov 2017 08:22:06 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 39DF9127871; Wed, 29 Nov 2017 08:22:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VEEuuxVbwkqi; Wed, 29 Nov 2017 08:22:05 -0800 (PST)
Received: from mail-pl0-x233.google.com (mail-pl0-x233.google.com [IPv6:2607:f8b0:400e:c01::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F291A127B57; Wed, 29 Nov 2017 08:22:04 -0800 (PST)
Received: by mail-pl0-x233.google.com with SMTP id b12so2373829plm.3; Wed, 29 Nov 2017 08:22:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=PWHBhAq6e15AdBqZYucZHunX7TDVAlbxuVmWgI6CsGQ=; b=NU1FN6iwVPxrCvAX77j56zzhMRugAqlWkz1O9mhUdWna8Jpibk0i8ZwEkqM3Sfuf6Q J9o5KC+1myLpPEy5/zn/XVzBbicef4qzrUg92g9u0jjVH3RJa/9lwowh6gwXOfUodJe9 b7sslnXjRvtQrgOvjuPnZK0DEdMX8hYNIoxs/2FmQlXew/y04MXpLpOABYftXOYEWQcH XRq5qSinKfYdmOmZ5LCSa/frCcN5wYZA5JBYl1L4Z7fPn5/MfnPXFp/q2useG1ZKrDbk dFWmeRdYUNb9MWPv43IxjECRMLPifL06ELfRy50jy2cdZr/JLQqxR82jj7TZ8wPb+4KE /GrQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=PWHBhAq6e15AdBqZYucZHunX7TDVAlbxuVmWgI6CsGQ=; b=rZV4OHPkGgBkGR44ZyXwk+CN0rgU8A16EIeCrFjM3dBDV1FMHJR4hRLAW98tepbhQ3 yLJsFybdTEduPPLP8hEt0BZvLfUw8LCyXwaEExtDnyVl9LE0V0TBSsRuNs9j+po2At0J lFoZLnbchOaROiC6IqSS7cLxk/4Z4bgIB6WukC228Pwcqf4tDxG8Cauypp2WM8brx2Sn 8FVZAYP0S4p3ckup7pR0Wvyp9Rf0dK5IgaQCQbCYWy9S6CaP+Gho79RjGQ14M1XZM5wP oBvDPoF/9whbZKpIfZgXpi0XWMGn0ngKztD/RZOVOBeUO/rdC9Xg5xX0+Z/a7Erl2oJ1 0Z0g==
X-Gm-Message-State: AJaThX5w3TnsqqcLshscPOK0GZxoAvwoPsGPIN++87UYfirkh3mpigE8 TWqnK1X/ohP5qv0SMbFw6AhXs9RdDmt/OVvVGIQ=
X-Google-Smtp-Source: AGs4zMaY3ayz3F0f3L+7XfZj+19jUQI0CH3rZRoexUnrkJwNFCX8i9h77USGTemXBV/CKgAL/COOYFxahZhOVPDW8kU=
X-Received: by 10.84.172.195 with SMTP id n61mr3363663plb.78.1511972524546; Wed, 29 Nov 2017 08:22:04 -0800 (PST)
MIME-Version: 1.0
Received: by 10.100.186.208 with HTTP; Wed, 29 Nov 2017 08:21:24 -0800 (PST)
In-Reply-To: <151196946679.7944.3160175486224623517@ietfa.amsl.com>
References: <151196946679.7944.3160175486224623517@ietfa.amsl.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Date: Wed, 29 Nov 2017 11:21:24 -0500
Message-ID: <CAHbuEH4wanQoMrDZj+kvZjkv+jBUUVfvnsAx2iS+9tFQk4N8iA@mail.gmail.com>
To: Joe Clarke <jclarke@cisco.com>
Cc: ops-dir@ietf.org, draft-mm-wg-effect-encrypt.all@ietf.org,  IETF <ietf@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171129162206.695F5127B57@ietfa.amsl.com>
Resent-Date: Wed, 29 Nov 2017 08:22:06 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/7_hrSB7nJbinQ77xuj1gM0yfgF8>
Subject: Re: [OPSAWG] Opsdir last call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 16:22:06 -0000

Hello Joe,

First, thank you for your helpful review.

On Wed, Nov 29, 2017 at 10:31 AM, Joe Clarke <jclarke@cisco.com> wrote:
> Reviewer: Joe Clarke
> Review result: Has Nits
>
> I have been requested to review draft-mm-wg-effect-encrypt for the ops
> directorate.  This document describes the effects of pervasive encryption on
> operators.  The document sets out a rather comprehensive list of network data
> (in motion and at rest) use cases and explains how encryption will effect each
> of them.  Overall, I feel this document is ready.  As someone that has
> supported networks from a troubleshooting perspective for years, I was
> especially pleased with the numerous callouts to troubleshooting impacts as
> well as deficiencies in application logging.
>
> To that end, it might be useful to specifically point out where vendors have a
> role to fill in some of these areas to allow for transit encryption while
> providing the necessary hooks for operators to manage and troubleshoot their
> network.  Specifically, in many of the troubleshooting scenarios, operators
> won't be able to provide truly useful tools to their end users unless the
> vendors provide the right level of visibility.

Do you have suggested text that we could add to address this gap from
your experience?

>
> On to some nits.
>
> In section 1.1 you use "end user's" where I think you mean "end users'".
>
> ===
>
> Section 2.  Today, Snowden is fairly well-known.  But as this document lives,
> maybe the specifics of what he's done may get fuzzy.  Perhaps this could do
> with a reference.
>
> ===
>
> Sections 5.3 and 6.2: you reference the abbreviation SNI before formally
> defining it.  It's more obvious in Section 6.2.
>

Thanks for catching the nits, we will address them.

Best regards,
Kathleen

>



-- 

Best regards,
Kathleen


From nobody Wed Nov 29 11:46:59 2017
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: opsawg@ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 52853126C22; Wed, 29 Nov 2017 11:46:57 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
CC: draft-ietf-opsawg-capwap-alt-tunnel@ietf.org, opsawg-chairs@ietf.org, Tianran Zhou <zhoutianran@huawei.com>, opsawg@ietf.org, zhoutianran@huawei.com, warren@kumari.net
Reply-To: ietf@ietf.org
Sender: <iesg-secretary@ietf.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <151198481729.7972.10583472312302909306.idtracker@ietfa.amsl.com>
Date: Wed, 29 Nov 2017 11:46:57 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/8XHPABHNtIoYSgirmxzXMqFdUAM>
Subject: [OPSAWG] Last Call: <draft-ietf-opsawg-capwap-alt-tunnel-10.txt> (Alternate Tunnel Encapsulation for Data Frames in CAPWAP) to Experimental RFC
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 19:46:57 -0000

The IESG has received a request from the Operations and Management Area
Working Group WG (opsawg) to consider the following document: - 'Alternate
Tunnel Encapsulation for Data Frames in CAPWAP'
  <draft-ietf-opsawg-capwap-alt-tunnel-10.txt> as Experimental RFC

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2017-12-13. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the beginning of
the Subject line to allow automated sorting.

Abstract


   Control and Provisioning of Wireless Access Points (CAPWAP) defines a
   specification to encapsulate a station's data frames between the
   Wireless Transmission Point (WTP) and Access Controller (AC).
   Specifically, the station's IEEE 802.11 data frames can be either
   locally bridged or tunneled to the AC.  When tunneled, a CAPWAP data
   channel is used for tunneling.  In many deployments encapsulating
   data frames to an entity other than the AC (for example to an Access
   Router (AR)) is desirable.  Furthermore, it may also be desirable to
   use different tunnel encapsulation modes between the WTP and the
   Access Router.  This document defines extension to CAPWAP protocol
   for supporting this capability and refers to it as alternate tunnel
   encapsulation.  The alternate tunnel encapsulation allows 1) the WTP
   to tunnel non-management data frames to an endpoint different from
   the AC and 2) the WTP to tunnel using one of many known encapsulation
   types such as IP-IP, IP-GRE, CAPWAP.  The WTP may advertise support
   for alternate tunnel encapsulation during the discovery and join
   process and AC may select one of the supported alternate tunnel
   encapsulation types while configuring the WTP.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-opsawg-capwap-alt-tunnel/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-opsawg-capwap-alt-tunnel/ballot/


No IPR declarations have been submitted directly on this I-D.





From nobody Thu Nov 30 08:51:00 2017
Return-Path: <jclarke@cisco.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 1CBF51279EB; Thu, 30 Nov 2017 08:50:38 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6ED21200B9; Thu, 30 Nov 2017 08:50:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.521
X-Spam-Level: 
X-Spam-Status: No, score=-14.521 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EI1swbBJsFGl; Thu, 30 Nov 2017 08:50:36 -0800 (PST)
Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 33DFC1279EB; Thu, 30 Nov 2017 08:50:35 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1273; q=dns/txt; s=iport; t=1512060635; x=1513270235; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to:content-transfer-encoding; bh=RaVBbHmcei1FlC+3QWcAIcitg3E8wMasq45uUbGeFW4=; b=T5+0j3PdncnmRxR4HJrnCaiidSeXAs3e3U6JPI1E5WaU8LBEslB0thOm wJw14Aedf3EgWPJxTM3A+1D/4kQvUk+WsszPNmWtEhR9ZQu0Rc5YMUWgm aWQraEk9E5fPJ848/YcnB2Jan4tVF5QMDBhR+tgKIeh4KQJ6/o1+Z//mc U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0D5AQB1NiBa/5FdJa1cGQEBAQEBAQEBA?= =?us-ascii?q?QEBAQcBAQEBAYM8gVSEJpkTgX2WdoIRCoU7AoUhQRYBAQEBAQEBAQFrKIUgAQU?= =?us-ascii?q?jDwFGEAsYAgImAgJXBg0IAQGKHqYfgieKZgEBAQEBAQEBAQEBAQEBAQEBIYEPg?= =?us-ascii?q?jKBZwEhgVaCEoMCiDWCYwWTFI9Hi1+JMowJh0qWRYE6Jg0lgVFMIxWCZIRyI4o?= =?us-ascii?q?6AQEB?=
X-IronPort-AV: E=Sophos;i="5.45,341,1508803200"; d="scan'208";a="37981175"
Received: from rcdn-core-9.cisco.com ([173.37.93.145]) by alln-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 30 Nov 2017 16:50:34 +0000
Received: from [10.118.87.88] (rtp-jclarke-nitro7.cisco.com [10.118.87.88]) by rcdn-core-9.cisco.com (8.14.5/8.14.5) with ESMTP id vAUGoXgf021698; Thu, 30 Nov 2017 16:50:34 GMT
To: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Cc: ops-dir@ietf.org, draft-mm-wg-effect-encrypt.all@ietf.org, IETF <ietf@ietf.org>
References: <151196946679.7944.3160175486224623517@ietfa.amsl.com> <CAHbuEH4wanQoMrDZj+kvZjkv+jBUUVfvnsAx2iS+9tFQk4N8iA@mail.gmail.com>
From: Joe Clarke <jclarke@cisco.com>
Organization: Cisco
Message-ID: <45c14d90-8d3e-c165-54ea-f72dfb282c29@cisco.com>
Date: Thu, 30 Nov 2017 11:50:33 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.5.0
MIME-Version: 1.0
In-Reply-To: <CAHbuEH4wanQoMrDZj+kvZjkv+jBUUVfvnsAx2iS+9tFQk4N8iA@mail.gmail.com>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171130165038.1CBF51279EB@ietfa.amsl.com>
Resent-Date: Thu, 30 Nov 2017 08:50:38 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/_Wx6qfj_lE9qAbexu6c_lK6vYuo>
Subject: Re: [OPSAWG] Opsdir last call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Nov 2017 16:50:38 -0000

On 11/29/17 11:21, Kathleen Moriarty wrote:
>> To that end, it might be useful to specifically point out where vendors have a
>> role to fill in some of these areas to allow for transit encryption while
>> providing the necessary hooks for operators to manage and troubleshoot their
>> network.  Specifically, in many of the troubleshooting scenarios, operators
>> won't be able to provide truly useful tools to their end users unless the
>> vendors provide the right level of visibility.
> 
> Do you have suggested text that we could add to address this gap from
> your experience?

Maybe something along the lines of the following in Section 2.1.2 (or
maybe in a section of its own):

"Vendors must be aware that in order for operators to better
troubleshoot and manage networks with increasing amounts of encrypted
traffic, built-in diagnostics and serviceability must be enhanced to
provide detailed logging and debugging capabilities that, when possible,
can reveal cleartext network parameters.  In addition to traditional
logging and debugging methods, packet tracing and inspection along the
service path will provide operators the necessary visibility to continue
to diagnose problems reported both internally and by their customers."

Joe


From nobody Thu Nov 30 09:15:38 2017
Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: expand-draft-mm-wg-effect-encrypt.all@virtual.ietf.org
Delivered-To: opsawg@ietfa.amsl.com
Received: by ietfa.amsl.com (Postfix, from userid 65534) id 0986E12762F; Thu, 30 Nov 2017 09:15:25 -0800 (PST)
X-Original-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Delivered-To: xfilter-draft-mm-wg-effect-encrypt.all@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B4CF4126D85; Thu, 30 Nov 2017 09:15:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E7QiZUIkqKSZ; Thu, 30 Nov 2017 09:15:23 -0800 (PST)
Received: from mail-pl0-x230.google.com (mail-pl0-x230.google.com [IPv6:2607:f8b0:400e:c01::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7669B12762F; Thu, 30 Nov 2017 09:15:23 -0800 (PST)
Received: by mail-pl0-x230.google.com with SMTP id q7so4637130plk.0; Thu, 30 Nov 2017 09:15:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=yP2VWiCvO5eGB0JQ8kuNm0NrxeEjq+wfMB+YpaCnQww=; b=ErY5QqtcjS7H70L0WYlbcbpumVit4A2hXfEFihg1nzIEaURIVCADR/fy9GOT+eGYs2 xYFrhE7kMW6zpoLSfW1MGNHcHHfNHPOyxa0rLWloZ8gjsUaFDSdVU7uL7S8+2MqAhMDr 8hEU6LvfQ8RsqS14bOjT3kKDN+WfdpHyunoZ7IJG/SwZLr7LUPJ7BdYLdSngpgphzY7d t3PNmqvhy96kzT+yyJ/sK21Pq2008Xt2/Ulf0dRyB9Q7bw7DydkwZb3BNORaWcmDLhdn AmoIYj34MIwrg7PYd48hTzlbq2SMv2Hvk39XxczGfqZjoONTJEuXmCDLJV0SnufypAb1 MgEw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=yP2VWiCvO5eGB0JQ8kuNm0NrxeEjq+wfMB+YpaCnQww=; b=At4wpehpSNGs0hGShGkkQrbPSb308BrmWKRH9nW7vxSjnSqbRuPIMf+QeSYlgCFIvm jLRv6dNDYx/xYhCT7bXWTd+6/9CpuI24wR+mNmx8HBgnLixLai5bdujEIu9KClWPlMWW R/0QAgLwllRchLYXLvE00NxuGyceKOvhsPzzrR/BZJFDplRodfzjCbvJgG3PDtycoi+P 5K0iF03QP3Ewih3L4lWhtNP/f89f4Jkmw5fqquvgIH29/tP1QZMOXd3LW4etfMe1Q61E HXGWFALZQ/HJX9r6UPeT/T0fS6imFAoGahBX9e7aiEvEr9a3UlgigApCNthl2zpjFOvu T66g==
X-Gm-Message-State: AJaThX4lxkMNbqttxnxw3ctlKhMZKcN9mf0m3/mv+yIfFVS982zJogHE 6Ftip9KZ8CKQ5H3xFgTbPCPoyseUhrFEyIRDUrc=
X-Google-Smtp-Source: AGs4zMbNQIYWMIUlNg/+KM4jqI7LP18FeYmE6Tv6ypGYxsKHMzPOf7g2S/iaSjoYV5evyCId/0SankHWM9nJaYfsvek=
X-Received: by 10.159.197.5 with SMTP id bj5mr3353135plb.219.1512062122816; Thu, 30 Nov 2017 09:15:22 -0800 (PST)
MIME-Version: 1.0
Received: by 10.100.186.208 with HTTP; Thu, 30 Nov 2017 09:14:42 -0800 (PST)
In-Reply-To: <45c14d90-8d3e-c165-54ea-f72dfb282c29@cisco.com>
References: <151196946679.7944.3160175486224623517@ietfa.amsl.com> <CAHbuEH4wanQoMrDZj+kvZjkv+jBUUVfvnsAx2iS+9tFQk4N8iA@mail.gmail.com> <45c14d90-8d3e-c165-54ea-f72dfb282c29@cisco.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Date: Thu, 30 Nov 2017 12:14:42 -0500
Message-ID: <CAHbuEH6C8+HgUskSwndj4TK3jdu5cUy7YB+5AAubVust0vzWXA@mail.gmail.com>
To: Joe Clarke <jclarke@cisco.com>
Cc: ops-dir@ietf.org, draft-mm-wg-effect-encrypt.all@ietf.org,  IETF <ietf@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Resent-From: <alias-bounces@ietf.org>
Resent-To: Kathleen.Moriarty@dell.com, acmorton@att.com, Kathleen.Moriarty.ietf@gmail.com, ekr@rtfm.com, Paul Hoffman <paul.hoffman@vpnc.org>, warren@kumari.net, opsawg@ietf.org, paul.hoffman@vpnc.org
Resent-Message-Id: <20171130171526.0986E12762F@ietfa.amsl.com>
Resent-Date: Thu, 30 Nov 2017 09:15:25 -0800 (PST)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/_XjqVFSVv8nGxVOagA-yMUobNhE>
Subject: Re: [OPSAWG] Opsdir last call review of draft-mm-wg-effect-encrypt-13
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Nov 2017 17:15:26 -0000

On Thu, Nov 30, 2017 at 11:50 AM, Joe Clarke <jclarke@cisco.com> wrote:
> On 11/29/17 11:21, Kathleen Moriarty wrote:
>>> To that end, it might be useful to specifically point out where vendors have a
>>> role to fill in some of these areas to allow for transit encryption while
>>> providing the necessary hooks for operators to manage and troubleshoot their
>>> network.  Specifically, in many of the troubleshooting scenarios, operators
>>> won't be able to provide truly useful tools to their end users unless the
>>> vendors provide the right level of visibility.
>>
>> Do you have suggested text that we could add to address this gap from
>> your experience?
>
> Maybe something along the lines of the following in Section 2.1.2 (or
> maybe in a section of its own):
>
> "Vendors must be aware that in order for operators to better
> troubleshoot and manage networks with increasing amounts of encrypted
> traffic, built-in diagnostics and serviceability must be enhanced to
> provide detailed logging and debugging capabilities that, when possible,
> can reveal cleartext network parameters.  In addition to traditional
> logging and debugging methods, packet tracing and inspection along the
> service path will provide operators the necessary visibility to continue
> to diagnose problems reported both internally and by their customers."

Thank you, Joe!

>
> Joe



-- 

Best regards,
Kathleen

