Re: Securing BGP sessions (Issue#41)

Jeff Tantsura <[email protected]> Tue, 10 Dec 2019 16:50:36 -0800
Newsgroups gmane.ietf.idr
Message-ID <7e96a2d8-59b2-4c38-a17d-67335a07defd@Spark>
--===============3400529171439761072==
Content-Type: multipart/alternative; boundary="5df03d64_42963e5a_872b"

--5df03d64_42963e5a_872b
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

+1

I believe the below clearly represent what has been discussed in Singapor=
e.

Cheers,
Jeff
On Dec 10, 2019, 4:34 PM -0800, Mahesh Jethanandani <mjethanandani=40gmai=
l.com>, wrote:
> This is the second thread in the list of issues that were discussed in =
IET=46 106 w.r.t. to BGP YANG model. This particular thread is to discuss=
 the issue of defining how BGP sessions are going to be secured.
>
> As stated in Singapore, the model is being defined to secure BGP sessio=
ns using
> - TCP AO
> - TCP MD5
> - IPSec
>
> In case there was a question of why MD5, it is because there are existi=
ng implementations that are choosing to stay with MD5, regardless of the =
issues that have been raised about MD5. The model therefore has to suppor=
t such implementations.
>
> The model will use the ietf-key-chain model=E2=80=99s (R=46C 8177) key-=
chain-ref to refer to an instance of the key chain. By doing that it will=
 make use of the key rollover capability defined in that model, and for s=
tatic key configuration by setting the end time to infinite in the key ch=
ain. The BGP model will leave the case of IPSec as TBD for now, and fill =
it when/if the IPSec YANG model is defined.
>
> Questions/Concerns=3F
>
> Mahesh Jethanandani
> mjethanandani=40gmail.com
>
>
>
> =5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F
> Idr mailing list
> Idr=40ietf.org
> https://www.ietf.org/mailman/listinfo/idr

--5df03d64_42963e5a_872b
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

<html xmlns=3D=22http://www.w3.org/1999/xhtml=22>
<head>
<title></title>
</head>
<body>
<div name=3D=22messageBodySection=22>
<div dir=3D=22auto=22>+1
<div dir=3D=22auto=22><br /></div>
<div dir=3D=22auto=22>I believe the below clearly represent what has been=
 discussed in Singapore.</div>
</div>
</div>
<div name=3D=22messageSignatureSection=22><br />
<div class=3D=22match=46ont=22>Cheers,
<div>Jeff</div>
</div>
</div>
<div name=3D=22messageReplySection=22>On Dec 10, 2019, 4:34 PM -0800, Mah=
esh Jethanandani &lt;mjethanandani=40gmail.com&gt;, wrote:<br />
<blockquote type=3D=22cite=22 class=3D=22spark=5Fquote=22 style=3D=22marg=
in: 5px 5px; padding-left: 10px; border-left: thin solid =231abc9c;=22>Th=
is is the second thread in the list of issues that were discussed in IET=46=
 106 w.r.t. to BGP YANG model. This particular thread is to discuss the i=
ssue of defining how BGP sessions are going to be secured.<br />
<br />
As stated in Singapore, the model is being defined to secure BGP sessions=
 using<br />
- TCP AO<br />
- TCP MD5<br />
- IPSec<br />
<br />
In case there was a question of why MD5, it is because there are existing=
 implementations that are choosing to stay with MD5, regardless of the is=
sues that have been raised about MD5. The model therefore has to support =
such implementations.<br />
<br />
The model will use the ietf-key-chain model=E2=80=99s (R=46C 8177) key-ch=
ain-ref to refer to an instance of the key chain. By doing that it will m=
ake use of the key rollover capability defined in that model, and for sta=
tic key configuration by setting the end time to infinite in the key chai=
n. The BGP model will leave the case of IPSec as TBD for now, and fill it=
 when/if the IPSec YANG model is defined.<br />
<br />
Questions/Concerns=3F<br />
<br />
Mahesh Jethanandani<br />
mjethanandani=40gmail.com<br />
<br />
<br />
<br />
=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=
=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F=5F<br />
Idr mailing list<br />
Idr=40ietf.org<br />
https://www.ietf.org/mailman/listinfo/idr<br /></blockquote>
</div>
</body>
</html>

--5df03d64_42963e5a_872b--


--===============3400529171439761072==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Idr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/idr

--===============3400529171439761072==--