[saag] Re: [nasr] Re: Re: Re: Re: NASR BOF Follo w-Up
Henk Birkholz <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
On 15.04.25 19:18, Watson Ladd wrote: > On Mon, Apr 14, 2025 at 10:50 PM Liuchunchi(Peter) > <[email protected]> wrote: >> So this may yield two major trust assumptions: >> >> >> >> [My device] Operators have administrative control over all devices in his domain, regardless of vendors. >> [Truthful intention] Operators extract real router configurations out of truthful intention, using whatever best techniques available. >> >> >> >> [Ongoing techniques] Extraction techniques, we have to-be-RFC TPM-CHARRA draft that conducts YANG-based extraction. There is WIP YANG-provenance draft that confirms YANG config coming from a right source. There is WIP multiple-verifiers draft that works with many vendors in one single domain. >> >> >> >> Is this trust assumption and scope-narrowing statement good for you? > > But at this point what is this doing that RANCID doesn't? Why do we > need transit proofs and all that, if we're never exiting a domain? RANCID has been doing a great job for decades, but by would you believe that a network device is exposing its actual (potential latent) and operational state to you? All devices could already lie to you because they are compromised. If your are an organization that could be subject to audits or some other forms of accreditation or accountability, than maybe you would like to show that acquired data about your systems is authentic and also auditable after the fact. That can include critical data flows in side your domain or to its "edges" (following the assumption that a healthy network device will not forward transfer units over non-endorsed or otherwise secured interconnects). _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]