[saag] Re: 回复: FW: Interests on Initiati ng the standardization work related to "Zero Trust"?
"Xueting Li" <[email protected]> Mon, 5 Jan 2026 11:04:50 +0800
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hi Usama, Thank you for your valuable comments and references—they help clarify the positioning of our document and we greatly appreciate your engagement. Below is our response to your points: 1. Core Differences from the Two SEAT Drafts Your referenced drafts [1][2] focus on communication-layer device state verification (via TLS post-handshake attestation) to supplement TLS with device/software integrity checks. Our document targets network-layer trust mechanism reconstruction: Scope: Addresses systemic risks of the perimeter-centric model (lateral movement, control/management plane vulnerabilities) by extending zero trust to the entire network, not just endpoint communication. Verification Object: Validates all network entities and interactions (internal communications, control messages, management operations), not just individual device runtime states. Goal: Transforms the "hard shell, soft interior" network into a resilient system with dynamic trust assessment—an architecture upgrade, not just a protocol supplement. 2. Response to Specific Comments Sec.8 Performance Overhead: Included as unaddressed latency/load may degrade availability or prompt disabling security controls, creating gaps—aligning with IETF’s focus on operational risks impacting security. Missing Reference Details: We have supplemented it in the new version. 3. Document Update We’ve released a new version of the draft: draft-li-zt-consideration-01, which adds detailed descriptions of management plane risks (e.g., API/orchestration vulnerabilities) to strengthen the problem statement. URL: https://www.ietf.org/archive/id/draft-li-zt-consideration-01.txt Thank you again for your constructive feedback. We welcome further feedback on the updated draft. Best regards, Xueting China Telecom [email protected] 发件人: Muhammad Usama Sardar 发送时间: 2025-12-31 16:31 收件人: Xueting Li; saag 抄送: wangaijun 主题: Re: [saag] 回复: FW: Interests on Initiating the standardization work related to "Zero Trust"? Hi Xueting and Aijun, On 31.12.25 03:58, Xueting Li wrote: We warmly welcome your comments, suggestions, and involvement. Please feel free to share your feedback. I appreciate that you warmly welcome further comments, but I kindly ask you to warmly address them as well. How is it addressing my questions/concerns in [0]? In particular, see network infrastructure integrity [1]. Your goal seems to be "continuous, dynamic verification" which can be done by post-handshake attestation [2*]. Sec.8: I don't understand what performance overhead has got to do with security consideration? References are missing important details, e.g., author names and links. And why is it standards track? -Usama [0] https://mailarchive.ietf.org/arch/msg/saag/5yJGI21NKtUz18jD-AQbF7pJdok/ [1] https://www.ietf.org/archive/id/draft-mihalcea-seat-use-cases-00.html#section-3.3 [2*] https://tls-attestation.github.io/exported-attestation/draft-fossati-seat-expat.html * Apologies for mentioning the editors' draft. We will roll out the updates in the corresponding draft early next year. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]