Re: Securing BGP sessions (Issue#41)

Mahesh Jethanandani <[email protected]> Fri, 13 Dec 2019 15:09:32 -0800
Newsgroups gmane.ietf.idr
Message-ID <[email protected]>
--===============5671765615780352938==
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_D71AFA81-297C-4CBB-BC06-BD5F3DA539E4"


--Apple-Mail=_D71AFA81-297C-4CBB-BC06-BD5F3DA539E4
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hi Acee,

> On Dec 13, 2019, at 10:47 AM, Acee Lindem (acee) <[email protected]> =
wrote:
>>=20
>>=20
>> Well it doesn't help at all.... Normally, the usage of IPsec (AH, =
ESP, algorithms, key exchange, etc.) would be specified in some =
document. For example, IPsec usage by OSPFv3 is specified in RFC 4552. =
Granted, it is a lot simpler for BGP than OSPFv3 since BGP is strictly =
P2P but specification would still seem to necessary.=20
>=20
>    You are right. It should be some document. That document in my mind =
is the YANG model for IPsec/IKE, something we need to ask the SEC ADs =
about. You would agree that what needs to be defined is not BGP =
specific, and therefore does not belong in the BGP model.
>=20
>    Much like TCP-AO and TCP-MD5 I expect this other document to define =
a grouping that the BGP model imports and uses to define what is needed =
to setup IPsec.
>=20
> Actually I disagree with you - TCP MD5 and TCP-AO are more than =
adequately documented.=20
>=20
>   MD5 - https://datatracker.ietf.org/doc/rfc2385/ =
<https://datatracker.ietf.org/doc/rfc2385/>
>   TCP-AO - https://datatracker.ietf.org/doc/rfc5925/ =
<https://datatracker.ietf.org/doc/rfc5925/>

What you are pointing to me is the document that describes how the two =
technologies can be used to secure BGP. I am aware of those RFCs. The =
document I am looking for is a YANG model that defines a grouping for =
MD5 and TCP-AO that the BGP model can import and use.=20

>=20
> It is only IPsec transport mode that isn't described. Also, I don't =
know of anyone who supports this so I'm wondering why it is in the =
discussion for this version of the BGP YANG model.

I will let Jeff comment on this.

Cheers.

>=20
> Thanks,
> Acee
>=20
>=20
>    Cheers.
>=20
>>=20
>> Thanks,
>> Acee
>>=20
>>=20
>>> For IPsec protection of BGP, where are the details specified?=20
>>> Thanks,
>>> Acee
>>>=20
>>> On 12/10/19, 7:35 PM, "Idr on behalf of Mahesh Jethanandani" =
<[email protected] on behalf of [email protected]> wrote:
>>>=20
>>>  This is the second thread in the list of issues that were discussed =
in IETF 106 w.r.t. to BGP YANG model. This particular thread is to =
discuss the issue of defining how BGP sessions are going to be secured.
>>>=20
>>>  As stated in Singapore, the model is being defined to secure BGP =
sessions using=20
>>>  - TCP AO
>>>  - TCP MD5
>>>  - IPSec
>>>=20
>>>  In case there was a question of why MD5, it is because there are =
existing implementations that are choosing to stay with MD5, regardless =
of the issues that have been raised about MD5. The model therefore has =
to support such implementations.
>>>=20
>>>  The model will use the ietf-key-chain model=E2=80=99s (RFC 8177) =
key-chain-ref to refer to an instance of the key chain. By doing that it =
will make use of the key rollover capability defined in that model, and =
for static key configuration by setting the end time to infinite in the =
key chain. The BGP model will leave the case of IPSec as TBD for now, =
and fill it when/if the IPSec YANG model is defined.
>>>=20
>>>  Questions/Concerns?
>>>=20
>>>  Mahesh Jethanandani
>>>  [email protected]
>>>=20
>>>=20
>>>=20
>>>  _______________________________________________
>>>  Idr mailing list
>>>  [email protected]
>>>  https://www.ietf.org/mailman/listinfo/idr
>>>=20
>>>=20
>>=20
>>   Mahesh Jethanandani
>>   [email protected]
>>=20
>>=20
>>=20
>>=20
>>=20
>=20
>    Mahesh Jethanandani
>    [email protected]


--Apple-Mail=_D71AFA81-297C-4CBB-BC06-BD5F3DA539E4
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" class=3D"">Hi =
Acee,<br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On Dec 13, 2019, at 10:47 AM, Acee Lindem =
(acee) &lt;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:</div><div class=3D""><blockquote =
type=3D"cite" style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; orphans: auto; text-align: start; text-indent: =
0px; text-transform: none; white-space: normal; widows: auto; =
word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
class=3D""><br class=3D"">Well it doesn't help at all.... Normally, the =
usage of IPsec (AH, ESP, algorithms, key exchange, etc.) would be =
specified in some document. For example, IPsec usage by OSPFv3 is =
specified in RFC 4552. Granted, it is a lot simpler for BGP than OSPFv3 =
since BGP is strictly P2P but specification would still seem to =
necessary.<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D""></blockquote><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">&nbsp;&nbsp;&nbsp;You are right. It should be some document. =
That document in my mind is the YANG model for IPsec/IKE, something we =
need to ask the SEC ADs about. You would agree that what needs to be =
defined is not BGP specific, and therefore does not belong in the BGP =
model.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" =
class=3D"">&nbsp;&nbsp;&nbsp;Much like TCP-AO and TCP-MD5 I expect this =
other document to define a grouping that the BGP model imports and uses =
to define what is needed to setup IPsec.</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Actually I disagree with you - TCP MD5 and TCP-AO are more =
than adequately documented.<span =
class=3D"Apple-converted-space">&nbsp;</span></span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">&nbsp;&nbsp;MD5 -<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"https://datatracker.ietf.org/doc/rfc2385/" style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" =
class=3D"">https://datatracker.ietf.org/doc/rfc2385/</a><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">&nbsp;&nbsp;TCP-AO -<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"https://datatracker.ietf.org/doc/rfc5925/" =
class=3D"">https://datatracker.ietf.org/doc/rfc5925/</a><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" =
class=3D""></div></blockquote><div><br class=3D""></div>What you are =
pointing to me is the document that describes how the two technologies =
can be used to secure BGP. I am aware of those RFCs. The document I am =
looking for is a YANG model that defines a grouping for MD5 and TCP-AO =
that the BGP model can import and use.&nbsp;</div><div><br =
class=3D""><blockquote type=3D"cite" class=3D""><div class=3D""><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">It is only IPsec transport mode =
that isn't described. Also, I don't know of anyone who supports this so =
I'm wondering why it is in the discussion for this version of the BGP =
YANG model.</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""></div></blockquote><div><br class=3D""></div>I will =
let Jeff comment on this.</div><div><br =
class=3D""></div><div>Cheers.</div><div><br class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D""><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Thanks,</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">Acee</span><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><span style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none; float: none; display: inline !important;" =
class=3D"">&nbsp;&nbsp;&nbsp;Cheers.</span><br style=3D"caret-color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br style=3D"caret-color: rgb(0, 0, =
0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><blockquote type=3D"cite" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
text-decoration: none;" class=3D""><br class=3D"">Thanks,<br =
class=3D"">Acee<br class=3D""><br class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D"">For IPsec protection of BGP, where are the =
details specified?<span class=3D"Apple-converted-space">&nbsp;</span><br =
class=3D"">Thanks,<br class=3D"">Acee<br class=3D""><br class=3D"">On =
12/10/19, 7:35 PM, "Idr on behalf of Mahesh Jethanandani" &lt;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a> =
on behalf of <a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a>&gt; wrote:<br class=3D""><br =
class=3D"">&nbsp;This is the second thread in the list of issues that =
were discussed in IETF 106 w.r.t. to BGP YANG model. This particular =
thread is to discuss the issue of defining how BGP sessions are going to =
be secured.<br class=3D""><br class=3D"">&nbsp;As stated in Singapore, =
the model is being defined to secure BGP sessions using<span =
class=3D"Apple-converted-space">&nbsp;</span><br class=3D"">&nbsp;- TCP =
AO<br class=3D"">&nbsp;- TCP MD5<br class=3D"">&nbsp;- IPSec<br =
class=3D""><br class=3D"">&nbsp;In case there was a question of why MD5, =
it is because there are existing implementations that are choosing to =
stay with MD5, regardless of the issues that have been raised about MD5. =
The model therefore has to support such implementations.<br class=3D""><br=
 class=3D"">&nbsp;The model will use the ietf-key-chain model=E2=80=99s =
(RFC 8177) key-chain-ref to refer to an instance of the key chain. By =
doing that it will make use of the key rollover capability defined in =
that model, and for static key configuration by setting the end time to =
infinite in the key chain. The BGP model will leave the case of IPSec as =
TBD for now, and fill it when/if the IPSec YANG model is defined.<br =
class=3D""><br class=3D"">&nbsp;Questions/Concerns?<br class=3D""><br =
class=3D"">&nbsp;Mahesh Jethanandani<br class=3D"">&nbsp;<a =
href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a><br class=3D""><br class=3D""><br =
class=3D""><br =
class=3D"">&nbsp;_______________________________________________<br =
class=3D"">&nbsp;Idr mailing list<br class=3D"">&nbsp;<a =
href=3D"mailto:[email protected]" class=3D"">[email protected]</a><br =
class=3D"">&nbsp;<a href=3D"https://www.ietf.org/mailman/listinfo/idr" =
class=3D"">https://www.ietf.org/mailman/listinfo/idr</a><br class=3D""><br=
 class=3D""><br class=3D""></blockquote><br class=3D"">&nbsp;&nbsp;Mahesh =
Jethanandani<br class=3D"">&nbsp;&nbsp;<a =
href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a><br class=3D""><br class=3D""><br =
class=3D""><br class=3D""><br class=3D""><br class=3D""></blockquote><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none;" class=3D""><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;" class=3D"">&nbsp;&nbsp;&nbsp;Mahesh =
Jethanandani</span><br style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none;" class=3D""><span style=3D"caret-color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: =
none; float: none; display: inline !important;" =
class=3D"">&nbsp;&nbsp;&nbsp;<a href=3D"mailto:[email protected]" =
class=3D"">[email protected]</a></span></div></blockquote></div><br =
class=3D""></body></html>=

--Apple-Mail=_D71AFA81-297C-4CBB-BC06-BD5F3DA539E4--


--===============5671765615780352938==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Idr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/idr

--===============5671765615780352938==--