[saag] Re: 回复: FW: Interests on Initiati ng the standardization work related to "Zero Trust"?

"Xueting Li" <[email protected]> Mon, 5 Jan 2026 11:04:50 +0800
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hi Usama,
Thank you for your valuable comments and references—they help clarify the positioning of our document and we greatly appreciate your engagement. Below is our response to your points:

1. Core Differences from the Two SEAT Drafts
Your referenced drafts [1][2] focus on communication-layer device state verification (via TLS post-handshake attestation) to supplement TLS with device/software integrity checks. Our document targets network-layer trust mechanism reconstruction:
Scope: Addresses systemic risks of the perimeter-centric model (lateral movement, control/management plane vulnerabilities) by extending zero trust to the entire network, not just endpoint communication.
Verification Object: Validates all network entities and interactions (internal communications, control messages, management operations), not just individual device runtime states.
Goal: Transforms the "hard shell, soft interior" network into a resilient system with dynamic trust assessment—an architecture upgrade, not just a protocol supplement. 
2. Response to Specific Comments
Sec.8 Performance Overhead: Included as unaddressed latency/load may degrade availability or prompt disabling security controls, creating gaps—aligning with IETF’s focus on operational risks impacting security.
Missing Reference Details: We have supplemented it in the new version.
3. Document Update
We’ve released a new version of the draft: draft-li-zt-consideration-01, which adds detailed descriptions of management plane risks (e.g., API/orchestration vulnerabilities) to strengthen the problem statement.
URL: https://www.ietf.org/archive/id/draft-li-zt-consideration-01.txt

Thank you again for your constructive feedback. We welcome further feedback on the updated draft.

Best regards,
Xueting 
China Telecom


[email protected]
 
发件人: Muhammad Usama Sardar
发送时间: 2025-12-31 16:31
收件人: Xueting Li; saag
抄送: wangaijun
主题: Re: [saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"?
Hi Xueting and Aijun,

On 31.12.25 03:58, Xueting Li wrote:
We warmly welcome your comments, suggestions, and involvement. Please feel free to share your feedback.
I appreciate that you warmly welcome further comments, but I kindly ask you to warmly address them as well. How is it addressing my questions/concerns in [0]? In particular, see network infrastructure integrity [1]. 
Your goal seems to be "continuous, dynamic verification" which can be done by post-handshake attestation [2*].

Sec.8: I don't understand what performance overhead has got to do with security consideration? 
References are missing important details, e.g., author names and links.
And why is it standards track?

-Usama

[0] https://mailarchive.ietf.org/arch/msg/saag/5yJGI21NKtUz18jD-AQbF7pJdok/
[1] https://www.ietf.org/archive/id/draft-mihalcea-seat-use-cases-00.html#section-3.3
[2*] https://tls-attestation.github.io/exported-attestation/draft-fossati-seat-expat.html

* Apologies for mentioning the editors' draft. We will roll out the updates in the corresponding draft early next year.

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]