[saag] Re: [nasr] Re: Re: Re: Re: NASR BOF Follo w-Up
Eric Rescorla <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBMooNKBGUjc82pRPBnCvBOjQagTe8wOVwgB50iqn0nMcg@mail.gmail.com> |
On Sun, May 25, 2025 at 7:23 PM Meiling Chen <[email protected]> wrote: > Hi Eric, > > * This traffic was sent over an encrypted link > * All traffic to address X will be sent over an encrypted link > [Meiling] What does an encrypted link refer to, who established the link, > and who negotiated encryption with whom? > I don't understand your question. I'm referring to the proposal by Diego that NASR would allow you to ensure the use of MACSEC. > > * This traffic is not being sent to a spanning port or otherwise available > for monitoring > [Meiling] Traffic is forwarded according to expected nodes and ports, and > will not sent to a spanning port. > Expected by the counterparty, correct? > As for monitoring, it depends on the customer's choice, NASR just to > ensure that there will be no monitoring without the user's consent. > Right, and so one such claim is that there is no monitoring. In any case, these all seem like fairly nontrivial properties to guarantee, so I think it's relevant to see some evidence that it's actually practical to mechanically determine whether a given router configuration provides them. -Ekr Meiling > > > *From:* Eric Rescorla <[email protected]> > *Date:* 2025-05-24 00:32 > *To:* Luigi IANNONE <[email protected]> > *CC:* Watson Ladd <[email protected]>; Meiling Chen > <[email protected]>; Henk Birkholz <[email protected]>; > Liuchunchi <[email protected]>; Toerless Eckert > <[email protected]>; [email protected]; IETF SAAG <[email protected]>; Luigi Iannone > <[email protected]> > *Subject:* [nasr] Re: [saag] Re: Re: Re: NASR BOF Follow-Up > > > On Thu, May 22, 2025 at 12:52 AM Luigi IANNONE <[email protected]> > wrote: > >> Hi Watson, >> >> > >> > Correct. Some claims are easy to verify. Most aren't. Statements that >> "the >> > router supports X" aren't really interesting. Statements that "this >> > configuration will never pass your traffic over a bad link" are, but >> are a lot >> > harder to show. >> > >> > > >> >> [LI] Agreed. This is a very claim hard show/attest. >> Note however that this is not what NASR is trying to do. >> NASR is more about router has feature X, Y, and Z which is what I want, >> and that traffic goes through the selected routers that support X, Y and Z. >> NASR is not about proving that traffic does not go somewhere else (proof >> of non-transit is out of scope). >> > > As I understood the presentations, you wanted to make claims like: > > * This traffic was sent over an encrypted link > * All traffic to address X will be sent over an encrypted link > * This traffic is not being sent to a spanning port or otherwise available > for monitoring > > Correct? > > -Ekr > > > > -Ekr > > >> Ciao >> >> L. >> > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]