[saag] Re: [nasr] Re: Re: Re: Re: NASR BOF Follo w-Up

Watson Ladd <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CACsn0c=+2b5-x9FnjZHDFWxs31HUyPyd42==DeyKqXuP2SVssg@mail.gmail.com>
On Wed, Apr 16, 2025 at 5:19 AM Henk Birkholz
<[email protected]> wrote:
>
> On 15.04.25 19:18, Watson Ladd wrote:
> > On Mon, Apr 14, 2025 at 10:50 PM Liuchunchi(Peter)
> > <[email protected]> wrote:
> >> So this may yield two major trust assumptions:
> >>
> >>
> >>
> >> [My device] Operators have administrative control over all devices in his domain, regardless of vendors.
> >> [Truthful intention] Operators extract real router configurations out of truthful intention, using whatever best techniques available.
> >>
> >>
> >>
> >> [Ongoing techniques] Extraction techniques, we have to-be-RFC TPM-CHARRA draft that conducts YANG-based extraction. There is WIP YANG-provenance draft that confirms YANG config coming from a right source. There is WIP multiple-verifiers draft that works with many vendors in one single domain.
> >>
> >>
> >>
> >> Is this trust assumption and scope-narrowing statement good for you?
> >
> > But at this point what is this doing that RANCID doesn't? Why do we
> > need transit proofs and all that, if we're never exiting a domain?
>
> RANCID has been doing a great job for decades, but by would you believe
> that a network device is exposing its actual (potential latent) and
> operational state to you? All devices could already lie to you because
> they are compromised. If your are an organization that could be subject
> to audits or some other forms of accreditation or accountability, than
> maybe you would like to show that acquired data about your systems is
> authentic and also auditable after the fact. That can include critical
> data flows in side your domain or to its "edges" (following the
> assumption that a healthy network device will not forward transfer units
> over non-endorsed or otherwise secured interconnects).

I'm confused. Why does RATS magically solve this problem? You can have
the world's most secure boot chain, and if the software is compromised
it might still lie/you will be mislead about the consequences of the
configuration being in a state because by assumption the software
doesn't behave properly. That's the gap which I think Eric and I think
can't be crossed: going from the configuration to the property, not
getting the config out (which sure, throw RATS at it)




--
Astra mortemque praestare gradatim

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.