Security PROTO writeup

[email protected] Thu, 29 Sep 2005 13:18:49 -0400
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
The PROTO process (cf. draft-ietf-proto-wgchair-doc-shepherding-05.txt)
is being used for the RDDP Security draft.  Here is the PROTO writeup:

               	     DDP/RDMAP Security 
                  draft-ietf-rddp-security-07.txt

Requested Publication Status: Proposed Standard
PROTO shepherd: David L. Black (RDDP WG Chair)
------------------------------------------------------------------------

   1.a) Have the chairs personally reviewed this version of the Internet
        Draft (ID), and in particular, do they believe this ID is ready
        to forward to the IESG for publication?

Yes.

   1.b) Has the document had adequate review from both key WG members
        and key non-WG members?

Yes, primarily from WG members.

        Do you have any concerns about the
        depth or breadth of the reviews that have been performed?

The draft has had limited review outside the WG.

   1.c) Do you have concerns that the document needs more review from a
        particular (broader) perspective (e.g., security, operational
        complexity, someone familiar with AAA, etc.)?

This is a security analysis document.  The Security Area should be
asked to review it sooner rather than later.

   1.d) Do you have any specific concerns/issues with this document that
        you believe the ADs and/or IESG should be aware of?  For
        example, perhaps you are uncomfortable with certain parts of the
        document, or have concerns whether there really is a need for
        it.  In any event, if your issues have been discussed in the WG
        and the WG has indicated it that it still wishes to advance the
        document, detail those concerns in the write-up.

No.

   1.e) How solid is the WG consensus behind this document? Does it
        represent the strong concurrence of a few individuals, with
        others being silent, or does the WG as a whole understand and
        agree with it?

Security expertise and interest exists in a limited portion of the WG.
In general, WG members with security expertise or interest understand
and agree with this document.

   1.f) [... not sent to the WG ...]

   1.g) Have the chairs verified that the document adheres to all of the
        ID nits? (see http://www.ietf.org/ID-Checklist.html).

The ID nits checker says everything is ok.

   1.h) Is the document split into normative and informative references?

Yes.

        Are there normative references to IDs, where the IDs are not
        also ready for advancement or are otherwise in an unclear state?
        (note here that the RFC editor will not publish an RFC with
        normative references to IDs, it will delay publication until all
        such IDs are also ready for publication as RFCs.)

There are two normative references to Internet-Drafts:

o draft-ietf-rddp-ddp - Publication has been requested along with
	this draft.
o draft-ietf-rddp-rdmap - Publication has been requested along with
	this draft.

   1.i) For Standards Track and BCP documents, the IESG approval
        announcement includes a write-up section with the following
        sections:

        *    Technical Summary

        *    Working Group Summary

        *    Protocol Quality

   1.j) Please provide such a write-up.  Recent examples can be found in
        the "protocol action" announcements for approved documents.

-- Technical Summary

   This document analyzes security issues around implementation and 
   use of the Direct Data Placement Protocol(DDP) and Remote Direct 
   Memory Access Protocol (RDMAP). It first defines an architectural 
   model for an RDMA Network Interface Card (RNIC), which can 
   implement DDP or RDMAP and DDP. The document reviews various 
   attacks against the resources defined in the architectural model 
   and the countermeasures that can be used to protect the system. 
   Attacks are grouped into spoofing, tampering, information 
   disclosure, denial of service, and elevation of privilege. 
   Finally, the document concludes with a summary of security 
   services for DDP and RDMAP, such as IPsec.

-- Working Group Summary

   Serious security analysis takes time - this document is no exception.
   There has been extensive review of this document in the WG.  The need
   for the Privileged Resource Manager was initially controversial, but
   the WG now has strong consensus for its necessity.

-- Protocol Quality

   The protocol has been reviewed for the rddp WG by David L. Black.

----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA  01748
+1 (508) 293-7953             FAX: +1 (508) 293-7786
[email protected]        Mobile: +1 (978) 394-7754
----------------------------------------------------