[saag] Re: [nasr] Re: Re: Re: Re: NASR BOF Follo w-Up
Luigi IANNONE <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hi, From: Eric Rescorla <[email protected]> Sent: Sunday, April 6, 2025 10:53 PM To: Michael Richardson <[email protected]> Cc: [email protected]; IETF SAAG <[email protected]> Subject: [nasr] Re: [saag] Re: Re: Re: NASR BOF Follow-Up On Sun, Apr 6, 2025 at 12:41 PM Michael Richardson <[email protected]<mailto:mcr%[email protected]>> wrote: Eric Rescorla <[email protected]<mailto:[email protected]>> wrote: > However, it's not clear to me that that's true in this case, because > unlike media players, network devices are highly configurable and a > large number of the configuration directives might impact the relevant > security claims. Thus, determining whether an element is policy > conformant is a matter of knowing not just what code it is running > but the state of every relevant configuration directive. One could > imagine this working at least three ways: I think you are making routers sound way more complicated than they are. 1. 90% of directives have little to no affect. (I have one toe in the routing/operations space. I'm ASN26227) Perhaps, but they still need to be individually examined in order to to determine that. Has someone done that? [LI] I do not think that the need is to attest the router as a whole. I is more about what is relevant for the flow that is using NASR service. [LI] Taking the example of POT in the context of SFC, you may want an attestation that the function is the one you need/want and a proof that the traffic went through the function. In this case you do not need to attest every single knob of the router (which agreed would be a daunting, if not impossible). L. _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]