From sacadmin Wed Aug  6 11:21:11 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m76ILBfo020053
	for <psarc@sac.eng.sun.com>; Wed, 6 Aug 2008 11:21:11 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m76IL68t023290;
	Wed, 6 Aug 2008 12:21:07 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5600I0LYZ5LO00@nwk-avmta-2.sfbay.sun.com>; Wed,
 06 Aug 2008 11:21:05 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5600FKYYZ4QI30@nwk-avmta-2.sfbay.sun.com>; Wed,
 06 Aug 2008 11:21:04 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m76IL4GI004057; Wed,
 06 Aug 2008 18:21:04 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5600C01YAG6U00@mail-amer.sun.com> (original mail from Aarti.Pai@Sun.COM)
 ; Wed, 06 Aug 2008 12:21:04 -0600 (MDT)
Received: from [129.145.154.105] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K56006HVYYV1E80@mail-amer.sun.com>; Wed,
 06 Aug 2008 12:20:56 -0600 (MDT)
Date: Wed, 06 Aug 2008 11:20:55 -0700
From: Aarti Pai <Aarti.Pai@sun.com>
Subject: Meeting Minutes for PSARC - 08/06/2008 - Labeled IPsec Phase 1
 (2008/252)
Sender: Aarti.Pai@sun.com
To: psarc@sun.com
Cc: Bill Sommerfeld <William.Sommerfeld@sun.com>,
        Jennifer Bauer <Jennifer.Bauer@sun.com>, labeledipsec-core@sun.com
Reply-to: Aarti.Pai@sun.com
Message-id: <4899EB87.2050808@Sun.COM>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_pZKiwgl5WvcgwEqwj0sDuQ)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.12 (X11/20080228)
Status: RO
Content-Length: 2474

This is a multi-part message in MIME format.

--Boundary_(ID_pZKiwgl5WvcgwEqwj0sDuQ)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

Minutes/Audio for PSARC - 08/06/2008  are now available:

- Open ARC Business:  
http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.html
    Audio:  
http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.arcbiz.open.mp3

- Open Inception Case:  Labeled IPsec Phase 1 (2008/252 
<http://sac.eng/arc/PSARC/2008/252/>)    Minutes: 
http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception
    Audio:  
http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception.mp3

Please contact me directly if you require any corrections/modifications
to these minutes.

Aarti


--Boundary_(ID_pZKiwgl5WvcgwEqwj0sDuQ)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
  <title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
Minutes/Audio for PSARC - 08/06/2008&nbsp; are now available:
<br>
<br>
- Open ARC Business:&nbsp;
<a class="moz-txt-link-freetext" href="http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.html">http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.html</a><br>
&nbsp;&nbsp;&nbsp; Audio:&nbsp;
<a class="moz-txt-link-freetext" href="http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.arcbiz.open.mp3">http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.arcbiz.open.mp3</a><br>
<br>
- Open Inception Case:&nbsp; Labeled IPsec Phase 1 (<a
 href="http://sac.eng/arc/PSARC/2008/252/">2008/252</a>)<span
 class="sacbody"></span>&nbsp;&nbsp;&nbsp; Minutes:
<a class="moz-txt-link-freetext" href="http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception">http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception</a><br>
&nbsp;&nbsp;&nbsp; Audio:&nbsp;
<a class="moz-txt-link-freetext" href="http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception.mp3">http://sac.sfbay.sun.com/Archives/Minutes/PSARC/2008/20080806.2008.252.inception.mp3</a><br>
<br>
Please contact me directly if you require any corrections/modifications
<br>
to these minutes.
<br>
<br>
Aarti
<br>
<br>
</body>
</html>

--Boundary_(ID_pZKiwgl5WvcgwEqwj0sDuQ)--

From sacadmin Thu Jan 22 09:21:06 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n0MHL6SZ025539
	for <psarc@sac.eng.sun.com>; Thu, 22 Jan 2009 09:21:06 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n0MHL4NK014444
	for <@sunmail2sca.sfbay.sun.com:psarc@sun.com>; Thu, 22 Jan 2009 09:21:05 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KDV00C0BUV45D00@nwk-avmta-1.sfbay.Sun.COM> for psarc@sun.com
 (ORCPT psarc@sun.com); Thu, 22 Jan 2009 09:21:04 -0800 (PST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KDV00AHNUV32220@nwk-avmta-1.sfbay.Sun.COM> for psarc@sun.com
 (ORCPT psarc@sun.com); Thu, 22 Jan 2009 09:21:03 -0800 (PST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n0MHL3GP013563	for
 <psarc@sun.com>; Thu, 22 Jan 2009 17:21:03 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0KDV00A01UI8MZ00@mail-amer.sun.com> (original mail from Aarti.Pai@Sun.COM)
 for psarc@sun.com (ORCPT psarc@sun.com); Thu, 22 Jan 2009 10:21:03 -0700 (MST)
Received: from aarti-pais-macbook-pro.local ([129.150.37.41])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0KDV00G5WUURPA90@mail-amer.sun.com> for psarc@sun.com
 (ORCPT psarc@sun.com); Thu, 22 Jan 2009 10:20:52 -0700 (MST)
Date: Thu, 22 Jan 2009 09:20:51 -0800
From: Aarti Pai <Aarti.Pai@sun.com>
Subject: Commitment materials for 2008/252 -Labeled IPsec phase 1
Sender: Aarti.Pai@sun.com
To: psarc@sun.com
Message-id: <4978AAF3.6000009@Sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.16 (Macintosh/20080707)
Status: RO
Content-Length: 318

These materials arrived on time. This case is on the agenda next week.

sac% pwd
/shared/sac/Archives/CaseLog/arc/PSARC/2008/252
sac% ls -l commitment.materials
total 284
-r--r--r--   1 sommerfe staff     127701 Jan 21 17:27 phase1-0.6.pdf
-r--r--r--   1 sommerfe staff      15991 Jan 21 17:25 txipsec-phase1-20q.txt


From sacadmin Wed Jan 28 08:17:41 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n0SGHepx002838
	for <psarc@sac.eng.sun.com>; Wed, 28 Jan 2009 08:17:41 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n0SGHVrx017151;
	Wed, 28 Jan 2009 16:17:38 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KE60010TVXBPW00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 28 Jan 2009 08:17:35 -0800 (PST)
Received: from dm-east-01.east.sun.com ([129.148.9.192])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KE600F42VX6TX80@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 28 Jan 2009 08:17:30 -0800 (PST)
Received: from localhost.east.sun.com (vroom.SFBay.Sun.COM [10.7.251.192])
	by dm-east-01.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n0SGHSf3008972; Wed, 28 Jan 2009 11:17:29 -0500 (EST)
Received: from localhost.east.sun.com (localhost [127.0.0.1])
	by localhost.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n0SGHOK7003650;
 Wed, 28 Jan 2009 08:17:24 -0800 (PST)
Received: (from sommerfeld@localhost)	by localhost.east.sun.com
 (8.14.3+Sun/8.14.3/Submit) id n0SGHNYW003649; Wed,
 28 Jan 2009 08:17:24 -0800 (PST)
Date: Wed, 28 Jan 2009 08:17:22 -0800
From: Bill Sommerfeld <sommerfeld@sun.com>
Subject: Re: Commitment materials for 2008/252 -Labeled IPsec phase 1
In-reply-to: <4978AAF3.6000009@Sun.com>
To: Aarti Pai <Aarti.Pai@sun.com>
Cc: psarc@sun.com
Message-id: <1233159442.2963.1.camel@localhost>
MIME-version: 1.0
X-Mailer: Evolution 2.24.2
Content-type: text/plain; charset=ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4978AAF3.6000009@Sun.com>
X-Authentication-warning: localhost.east.sun.com: sommerfeld set sender to
 sommerfeld@sun.com using -f
Status: RO
Content-Length: 169

FYI, my initial answers to the commitment issues present in the issues
file as of a few minutes ago can be found in "issue-answers-commitment"
in the case directory.




From storycrafter@gmail.com Tue Aug 25 12:57:11 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n7PJvB2J004263
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 25 Aug 2009 12:57:11 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n7PJv1OO036722;
	Tue, 25 Aug 2009 13:57:10 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KOY00L0V7F9KC00@nwk-avmta-2.sfbay.sun.com>; Tue,
 25 Aug 2009 12:57:09 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KOY00I5R7F8ER30@nwk-avmta-2.sfbay.sun.com>; Tue,
 25 Aug 2009 12:57:08 -0700 (PDT)
Received: from relay14i.sun.com
 (ip124.net129179-4.block1.us.syntegra.com [129.179.4.124])
 by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n7PJg1cG028190;
 Tue, 25 Aug 2009 19:57:08 +0000 (GMT)
Received: from mmp11es.mmp.us.syntegra.com ([160.41.208.11] [160.41.208.11])
 by relay14i.sun.com with ESMTP id BT-MMP-104956; Tue,
 25 Aug 2009 19:57:07 +0000 (Z)
Received: from relay15i.sun.com (relay15i.sun.com [129.179.4.125])
 by mmp11es.mmp.us.syntegra.com with ESMTP id BT-MMP-12816019; Tue,
 25 Aug 2009 19:57:07 +0000 (Z)
Received: from mail-ew0-f205.google.com ([209.85.219.205] [209.85.219.205])
 by relay1i.sun.com with ESMTP id BT-MMP-624104; Tue,
 25 Aug 2009 19:57:07 +0000 (Z)
Received: by ewy1 with SMTP id 1so3412036ewy.6 for <multiple recipients>; Tue,
 25 Aug 2009 12:57:01 -0700 (PDT)
Received: by 10.210.142.6 with SMTP id p6mr6719091ebd.85.1251230207315; Tue,
 25 Aug 2009 12:56:47 -0700 (PDT)
Received: from ?172.16.202.89?
 (68-252-106-20.ded.ameritech.net [68.252.106.20]) by mx.google.com with ESMTPS
 id 5sm1151928eyf.7.2009.08.25.12.56.44 (version=TLSv1/SSLv3 cipher=RC4-MD5)
 ; Tue, 25 Aug 2009 12:56:45 -0700 (PDT)
Date: Tue, 25 Aug 2009 14:56:41 -0500
From: Mark Martin <storycrafter@gmail.com>
Subject: Opinion for review 2008/252  Labeled IPsec phase 1
In-reply-to: <4A397055.8060809@gmail.com>
To: PSARC-ext@sun.com
Cc: william.sommerfield@sun.com, Kais.Belgaied@sun.com
Message-id: <4A9441F9.7040705@gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma;        h=domainkey-signature:received:received:message-id:date:from
 :user-agent:mime-version:to:cc:subject:references:in-reply-to
 :content-type:content-transfer-encoding;
 bh=QgTnwNANHpcw8g+51eD3ttC4U1GUNPmGYw2AfM9bQG8=;
 b=dMwuaof/74jP+Uu7apwEH+MjBOEZU+pzCCZwmb7WBKHPgabRsq65VBq++lAXbiOtPu
 YDcxVR7DuE0UU/oM0w8q/3fCm0TW/pBO+1/8MAr1ZseDd+MQJZrKH/xxm0l7RGw8gBn3
 JV10VEHFtuRV6w6C6oh6GVuJy9KB+Cl8RkZcg=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:user-agent:mime-version:to:cc:subject
 :references:in-reply-to:content-type:content-transfer-encoding;
 b=jzLfnipjolallOskR4yYEik6cKDzOJPvCL+KDWZgX4yUY38YxPINLprDdHbU5hV+a/
 P83lMn6+fKH22fyP/VsPnjJ7druSxQz5+/Ysn4k/XtGWxsg27kc9lU69j9YMeksZ0Xy+
 VkLqeMzrIPnE+kFJxDSewzjuDzmmW3ha/ib74=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
References: <4A397055.8060809@gmail.com>
User-Agent: Thunderbird 2.0.0.22 (Windows/20090605)
Status: RO
Content-Length: 3973

This ran for a week (or longer) over on opensolaris-arc.  
http://mail.opensolaris.org/pipermail/opensolaris-arc/2009-June/016505.html

I'm re-distilling on this alias to ensure proper aging and body. 

I'd appreciate feedback.  I'll set the timer for next Wednesday, 2009-09-02.

The text is available at: 
http://cr.opensolaris.org/~devnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt 
<http://cr.opensolaris.org/%7Edevnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt>

It is also attached here (inline):


   Sun
   Microsystems              Systems Architecture Committee
_________________________________________________________________

Subject:	Labeled IPsec phase 1

Submitted by:	Bill Sommerfeld

File:		PSARC/2008/252/opinion.txt

Date:		June 17th, 2009.

Committee:	Kais Belgaied (opinion written by Mark Martin), James Carlson,
		Mark Carlson, Richard Matthews, Sebastien Roy, Gary Winiger
		
Product Approval Committee:
		Solaris PAC
		solaris-pac-opinion@sun.com

1.  Summary

The current labeled networking technologies in Trusted Extensions assume that
the underlying network will not misroute or manipulate packets in flight between
parties. This project proposes to augment labeled networking to allow IPsec to
be used instead of or in addition to the existing CIPSO security option, with
the IPsec SADB augmented to associate sensitivity labels with each security
association.

2.  Decision & Precedence Information

The project is approved as specified in reference [1].

The project may be delivered in a patch release of Solaris.


3.  Interfaces

                      Interfaces Exported

    Interface           Classification      Comments
    ike config file     Committed           /etc/inet/ike/config
    PF_KEY extensions   Committed

4.  Opinion

4.1.  The "wire-label" keyword

Members of the committe noted that the "wire-label" keyword has the potential
for confusion. It can be used to control two different and possibly independent
things: the choice of outer labels on IKE and AH/ESP traffic. Those labels can
conceivably each be entirely missing, computed based on the label ranges of the
peers (either max or min), hard-coded to some particular value, or driven by the
label of the invoking zone.

There are at least 25 distinct choices for the two policies combined, perhaps
more if we get really creative. The single keyword approach means that you need
to have subkeywords that somehow indicate how each of this traffic will be
handled. That would make a lot of sense if there were only a handful of
operationally meaningful combinations.

Depending on the amount of "meaningful combinations", or the most meaningful of
those combinations, the "omit/omit" setting may be obvious as a way to get out
of the CIPSO mire, but it seems all of the others require detailed understanding
of the policies that sites have and (likely) the limitations of the other
vendor's equipment they're using.

It is strongly suggested to control them separately, and introduce a single
simplified control in the future if particular combinations turn out to be
common enough to warrant it. This last point was not felt strongly enough to be
listed as a TCA

5.  Minority Opinion(s)

None.

6.  Advisory Information

None.

7.  Appendices

7.1.  Appendix A: Technical Changes Required

None.

7.2.  Appendix B: Technical Changes Advised

None.

7.3.  Appendix C: Reference Material

Unless stated otherwise, path names are relative to the case directory
PSARC/2008/097.

1    Onepager
     File: 20080409_bill.sommerfeld

2    Inception minutes
     File: inception.materials/20080806.2008.252.inception
	 
3    Commmitment minutes
	 File: 	commitment.materials/20090128.2008.252.commitment

4    Issues
     File: issues

5    PSARC 20 Questions.
     File: commitment.materials/txipsec-phase1-20q.txt

6    Security 
     File: inception.materials/txipsec-phase1-security.txt



PSARC/2008/252               Copyright 2008 Sun Microsystems



From John.Fischer@sun.com Tue Aug 25 13:37:22 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n7PKbLAM005177
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 25 Aug 2009 13:37:21 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n7PKbCBP006681;
	Wed, 26 Aug 2009 04:37:20 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KOY0020B9A7JG00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 25 Aug 2009 13:37:19 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KOY001IT9A58E10@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 25 Aug 2009 13:37:18 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
 by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n7PKbHdr008615; Tue,
 25 Aug 2009 20:37:17 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KOY00J008RJ4P00@mail-amer.sun.com>; Tue, 25 Aug 2009 14:37:17 -0600 (MDT)
Received: from [192.168.0.102] ([unknown] [76.20.56.47])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KOY005ZN99V4XD0@mail-amer.sun.com>; Tue,
 25 Aug 2009 14:37:08 -0600 (MDT)
Date: Tue, 25 Aug 2009 13:34:54 -0700
From: John Fischer <John.Fischer@sun.com>
Subject: Re: Opinion for review 2008/252  Labeled IPsec phase 1
In-reply-to: <4A9441F9.7040705@gmail.com>
Sender: John.Fischer@sun.com
To: Mark Martin <storycrafter@gmail.com>
Cc: PSARC-ext@sun.com, Kais.Belgaied@sun.com, william.sommerfield@sun.com
Reply-to: John.Fischer@sun.com
Message-id: <4A944AEE.6040103@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A397055.8060809@gmail.com> <4A9441F9.7040705@gmail.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 4651

Mark,

Was the last point that wasn't considered a TCA Advisory?
If so then it should go into section 6.  Reading the opinion
it sure seems like that is where it ought to end up.

Thanks,

John

Mark Martin wrote:
> This ran for a week (or longer) over on opensolaris-arc.  
> http://mail.opensolaris.org/pipermail/opensolaris-arc/2009-June/016505.html
> 
> I'm re-distilling on this alias to ensure proper aging and body.
> I'd appreciate feedback.  I'll set the timer for next Wednesday, 
> 2009-09-02.
> 
> The text is available at: 
> http://cr.opensolaris.org/~devnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt 
> <http://cr.opensolaris.org/%7Edevnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt> 
> 
> 
> It is also attached here (inline):
> 
> 
>   Sun
>   Microsystems              Systems Architecture Committee
> _________________________________________________________________
> 
> Subject:    Labeled IPsec phase 1
> 
> Submitted by:    Bill Sommerfeld
> 
> File:        PSARC/2008/252/opinion.txt
> 
> Date:        June 17th, 2009.
> 
> Committee:    Kais Belgaied (opinion written by Mark Martin), James 
> Carlson,
>         Mark Carlson, Richard Matthews, Sebastien Roy, Gary Winiger
>        
> Product Approval Committee:
>         Solaris PAC
>         solaris-pac-opinion@sun.com
> 
> 1.  Summary
> 
> The current labeled networking technologies in Trusted Extensions assume 
> that
> the underlying network will not misroute or manipulate packets in flight 
> between
> parties. This project proposes to augment labeled networking to allow 
> IPsec to
> be used instead of or in addition to the existing CIPSO security option, 
> with
> the IPsec SADB augmented to associate sensitivity labels with each security
> association.
> 
> 2.  Decision & Precedence Information
> 
> The project is approved as specified in reference [1].
> 
> The project may be delivered in a patch release of Solaris.
> 
> 
> 3.  Interfaces
> 
>                      Interfaces Exported
> 
>    Interface           Classification      Comments
>    ike config file     Committed           /etc/inet/ike/config
>    PF_KEY extensions   Committed
> 
> 4.  Opinion
> 
> 4.1.  The "wire-label" keyword
> 
> Members of the committe noted that the "wire-label" keyword has the 
> potential
> for confusion. It can be used to control two different and possibly 
> independent
> things: the choice of outer labels on IKE and AH/ESP traffic. Those 
> labels can
> conceivably each be entirely missing, computed based on the label ranges 
> of the
> peers (either max or min), hard-coded to some particular value, or 
> driven by the
> label of the invoking zone.
> 
> There are at least 25 distinct choices for the two policies combined, 
> perhaps
> more if we get really creative. The single keyword approach means that 
> you need
> to have subkeywords that somehow indicate how each of this traffic will be
> handled. That would make a lot of sense if there were only a handful of
> operationally meaningful combinations.
> 
> Depending on the amount of "meaningful combinations", or the most 
> meaningful of
> those combinations, the "omit/omit" setting may be obvious as a way to 
> get out
> of the CIPSO mire, but it seems all of the others require detailed 
> understanding
> of the policies that sites have and (likely) the limitations of the other
> vendor's equipment they're using.
> 
> It is strongly suggested to control them separately, and introduce a single
> simplified control in the future if particular combinations turn out to be
> common enough to warrant it. This last point was not felt strongly 
> enough to be
> listed as a TCA
> 
> 5.  Minority Opinion(s)
> 
> None.
> 
> 6.  Advisory Information
> 
> None.
> 
> 7.  Appendices
> 
> 7.1.  Appendix A: Technical Changes Required
> 
> None.
> 
> 7.2.  Appendix B: Technical Changes Advised
> 
> None.
> 
> 7.3.  Appendix C: Reference Material
> 
> Unless stated otherwise, path names are relative to the case directory
> PSARC/2008/097.
> 
> 1    Onepager
>     File: 20080409_bill.sommerfeld
> 
> 2    Inception minutes
>     File: inception.materials/20080806.2008.252.inception
>      3    Commmitment minutes
>      File:     commitment.materials/20090128.2008.252.commitment
> 
> 4    Issues
>     File: issues
> 
> 5    PSARC 20 Questions.
>     File: commitment.materials/txipsec-phase1-20q.txt
> 
> 6    Security     File: inception.materials/txipsec-phase1-security.txt
> 
> 
> 
> PSARC/2008/252               Copyright 2008 Sun Microsystems
> 
> 
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org

From storycrafter@gmail.com Wed Aug 26 07:14:03 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n7QEE3Bq000483
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 26 Aug 2009 07:14:03 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n7QEE1ox045632;
	Wed, 26 Aug 2009 08:14:02 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KOZ00F01M7CBI00@brm-avmta-1.central.sun.com>; Wed,
 26 Aug 2009 08:14:00 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KOZ008R8M7C4X70@brm-avmta-1.central.sun.com>; Wed,
 26 Aug 2009 08:14:00 -0600 (MDT)
Received: from relay13i.sun.com
 (ip123.net129179-4.block1.us.syntegra.com [129.179.4.123])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n7QEBE72002008; Wed,
 26 Aug 2009 14:14:00 +0000 (GMT)
Received: from mmp14es.mmp.us.syntegra.com ([160.41.208.14] [160.41.208.14])
 by relay13i.sun.com with ESMTP id BT-MMP-175314; Wed,
 26 Aug 2009 14:13:38 +0000 (Z)
Received: from relay13i.sun.com (relay13i.sun.com [129.179.4.123])
 by mmp14es.mmp.us.syntegra.com with ESMTP id BT-MMP-564911; Wed,
 26 Aug 2009 14:13:36 +0000 (Z)
Received: from wa-out-1112.google.com ([209.85.146.181] [209.85.146.181])
 by relay1i.sun.com with ESMTP id BT-MMP-4456643; Wed,
 26 Aug 2009 14:12:45 +0000 (Z)
Received: by wa-out-1112.google.com with SMTP id m38so33298waf.8 for <multiple
 recipients>; Wed, 26 Aug 2009 07:12:29 -0700 (PDT)
Received: by 10.114.29.16 with SMTP id c16mr9923643wac.142.1251295949839; Wed,
 26 Aug 2009 07:12:29 -0700 (PDT)
Received: from ?172.16.202.89?
 (68-252-106-20.ded.ameritech.net [68.252.106.20]) by mx.google.com with ESMTPS
 id l28sm1024105waf.18.2009.08.26.07.12.27 (version=TLSv1/SSLv3 cipher=RC4-MD5)
 ; Wed, 26 Aug 2009 07:12:28 -0700 (PDT)
Date: Wed, 26 Aug 2009 09:12:26 -0500
From: Mark Martin <storycrafter@gmail.com>
Subject: Re: Opinion for review 2008/252  Labeled IPsec phase 1
In-reply-to: <4A944AEE.6040103@sun.com>
To: John.Fischer@sun.com
Cc: PSARC-ext@sun.com, Kais.Belgaied@sun.com
Message-id: <4A9542CA.9080406@gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma;        h=domainkey-signature:received:received:message-id:date:from
   :user-agent:mime-version:to:cc:subject:references:in-reply-to
 :content-type:content-transfer-encoding;
 bh=TPA7n7pNcoPJndBhkn1CiYkoQOSr/p/w4hGDOfwa9zo=;
 b=Cy/6jNWJ+4ikuosp+KHV/dVmGmglUsm8b3iXptkK2viC0w3JMxVF7BiviHX10Rw4g3
 pWLapR/O9M5ziToaK9rtmRNZopk+95MTilO7UouZ8wtDb1EFOljEVX3rZdET3CYc1HAk
 l4Ac5oDa8tdDK/OPKAE50C5gX8m+d0G6moaP0=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:user-agent:mime-version:to:cc:subject
 :references:in-reply-to:content-type:content-transfer-encoding;
 b=M/68eztsO4PsUc9e7ldJi/9qcMKBH+GTYaEHvyC0T+P9/Fi6PzMwGObTwpGAZiA61z
 49pEfBcrljHGyHg8i+SOFxZlkVDjLQ30N1KOHgaSD9XdffTIJ5y6e8PCPe6eoNSlO3TD
 8cJsaq887dLqW1EUydYpSVxWoOrCo2jdmFQcc=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
References: <4A397055.8060809@gmail.com> <4A9441F9.7040705@gmail.com>
 <4A944AEE.6040103@sun.com>
User-Agent: Thunderbird 2.0.0.23 (Windows/20090812)
Status: RO
Content-Length: 5181

John Fischer wrote:
> Mark,
>
> Was the last point that wasn't considered a TCA Advisory?
> If so then it should go into section 6.  Reading the opinion
> it sure seems like that is where it ought to end up.
I think I can recall who made that comment (or it's almost certainly in 
the record).  I think the last line is clear that the author of the 
comment didn't feel it warranted official section 6 status.  The text 
used was the exact text from the issue.    If you feel like promoting it 
(as it were) as advice, I'll be happy to reword that last paragraph into 
a TCA.

>
> Thanks,
>
> John
>
> Mark Martin wrote:
>> This ran for a week (or longer) over on opensolaris-arc.  
>> http://mail.opensolaris.org/pipermail/opensolaris-arc/2009-June/016505.html 
>>
>>
>> I'm re-distilling on this alias to ensure proper aging and body.
>> I'd appreciate feedback.  I'll set the timer for next Wednesday, 
>> 2009-09-02.
>>
>> The text is available at: 
>> http://cr.opensolaris.org/~devnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt 
>> <http://cr.opensolaris.org/%7Edevnull/PSARC/2008/252/psarc_2008_252_draft_opinion.txt> 
>>
>>
>> It is also attached here (inline):
>>
>>
>>   Sun
>>   Microsystems              Systems Architecture Committee
>> _________________________________________________________________
>>
>> Subject:    Labeled IPsec phase 1
>>
>> Submitted by:    Bill Sommerfeld
>>
>> File:        PSARC/2008/252/opinion.txt
>>
>> Date:        June 17th, 2009.
>>
>> Committee:    Kais Belgaied (opinion written by Mark Martin), James 
>> Carlson,
>>         Mark Carlson, Richard Matthews, Sebastien Roy, Gary Winiger
>>        Product Approval Committee:
>>         Solaris PAC
>>         solaris-pac-opinion@sun.com
>>
>> 1.  Summary
>>
>> The current labeled networking technologies in Trusted Extensions 
>> assume that
>> the underlying network will not misroute or manipulate packets in 
>> flight between
>> parties. This project proposes to augment labeled networking to allow 
>> IPsec to
>> be used instead of or in addition to the existing CIPSO security 
>> option, with
>> the IPsec SADB augmented to associate sensitivity labels with each 
>> security
>> association.
>>
>> 2.  Decision & Precedence Information
>>
>> The project is approved as specified in reference [1].
>>
>> The project may be delivered in a patch release of Solaris.
>>
>>
>> 3.  Interfaces
>>
>>                      Interfaces Exported
>>
>>    Interface           Classification      Comments
>>    ike config file     Committed           /etc/inet/ike/config
>>    PF_KEY extensions   Committed
>>
>> 4.  Opinion
>>
>> 4.1.  The "wire-label" keyword
>>
>> Members of the committe noted that the "wire-label" keyword has the 
>> potential
>> for confusion. It can be used to control two different and possibly 
>> independent
>> things: the choice of outer labels on IKE and AH/ESP traffic. Those 
>> labels can
>> conceivably each be entirely missing, computed based on the label 
>> ranges of the
>> peers (either max or min), hard-coded to some particular value, or 
>> driven by the
>> label of the invoking zone.
>>
>> There are at least 25 distinct choices for the two policies combined, 
>> perhaps
>> more if we get really creative. The single keyword approach means 
>> that you need
>> to have subkeywords that somehow indicate how each of this traffic 
>> will be
>> handled. That would make a lot of sense if there were only a handful of
>> operationally meaningful combinations.
>>
>> Depending on the amount of "meaningful combinations", or the most 
>> meaningful of
>> those combinations, the "omit/omit" setting may be obvious as a way 
>> to get out
>> of the CIPSO mire, but it seems all of the others require detailed 
>> understanding
>> of the policies that sites have and (likely) the limitations of the 
>> other
>> vendor's equipment they're using.
>>
>> It is strongly suggested to control them separately, and introduce a 
>> single
>> simplified control in the future if particular combinations turn out 
>> to be
>> common enough to warrant it. This last point was not felt strongly 
>> enough to be
>> listed as a TCA
>>
>> 5.  Minority Opinion(s)
>>
>> None.
>>
>> 6.  Advisory Information
>>
>> None.
>>
>> 7.  Appendices
>>
>> 7.1.  Appendix A: Technical Changes Required
>>
>> None.
>>
>> 7.2.  Appendix B: Technical Changes Advised
>>
>> None.
>>
>> 7.3.  Appendix C: Reference Material
>>
>> Unless stated otherwise, path names are relative to the case directory
>> PSARC/2008/097.
>>
>> 1    Onepager
>>     File: 20080409_bill.sommerfeld
>>
>> 2    Inception minutes
>>     File: inception.materials/20080806.2008.252.inception
>>      3    Commmitment minutes
>>      File:     commitment.materials/20090128.2008.252.commitment
>>
>> 4    Issues
>>     File: issues
>>
>> 5    PSARC 20 Questions.
>>     File: commitment.materials/txipsec-phase1-20q.txt
>>
>> 6    Security     File: inception.materials/txipsec-phase1-security.txt
>>
>>
>>
>> PSARC/2008/252               Copyright 2008 Sun Microsystems
>>
>>
>> _______________________________________________
>> opensolaris-arc mailing list
>> opensolaris-arc@opensolaris.org


From sac-owner Tue Sep 15 07:29:18 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n8FETHR1007938
	for <sac-review@sac.sfbay.sun.com>; Tue, 15 Sep 2009 07:29:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n8FETBCP007203
	for <@sunmail2sca.sfbay.sun.com:sac-review@Sun.COM>; Tue, 15 Sep 2009 22:29:16 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KQ000I0FO8RD400@nwk-avmta-2.sfbay.sun.com> for sac-review@Sun.COM
 (ORCPT sac-review@Sun.COM); Tue, 15 Sep 2009 07:29:15 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KQ000CA8O8QJV80@nwk-avmta-2.sfbay.sun.com> for
 sac-review@Sun.COM (ORCPT sac-review@Sun.COM); Tue,
 15 Sep 2009 07:29:14 -0700 (PDT)
Received: from [129.146.11.144]
 (sr1-jurassic-01.SFBay.Sun.COM [129.146.11.144])	by
 jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n8FETE9x326561
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <sac-review@sun.com>; Tue, 15 Sep 2009 07:29:14 -0700 (PDT)
Date: Tue, 15 Sep 2009 07:29:14 -0700
From: Kais Belgaied <Kais.Belgaied@sun.com>
Subject: Opinion for SAC review 2008/252  Labeled IPsec phase 1
To: sac-review@sun.com
Message-id: <4AAFA4BA.5060809@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_sWJJgxPTWxm5d0eb/6Gw2w)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (X11/20090311)
Status: RO
Content-Length: 4044

This is a multi-part message in MIME format.

--Boundary_(ID_sWJJgxPTWxm5d0eb/6Gw2w)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

Please review the attached opinion by Sept 22nd, 2009

    Kais.


--Boundary_(ID_sWJJgxPTWxm5d0eb/6Gw2w)
Content-type: text/plain; name=opinion.ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=opinion.ascii

   Sun
   Microsystems              Systems Architecture Committee
_________________________________________________________________

Subject:	Labeled IPsec phase 1

Submitted by:	Bill Sommerfeld

File:		PSARC/2008/252/opinion.txt

Date:		June 17th, 2009.

Committee:	Kais Belgaied (opinion written by Mark Martin), James Carlson,
		Mark Carlson, Richard Matthews, Sebastien Roy, Gary Winiger.
		
Product Approval Committee:
		Solaris PAC
		solaris-pac-opinion@sun.com

1.  Summary

	The current labeled networking technologies in Trusted Extensions
	assume that the underlying network will not misroute or manipulate
	packets in flight between parties. This project proposes to augment
	labeled networking to allow IPsec to be used instead of or in
	addition to the existing CIPSO security option, with the IPsec SADB
	augmented to associate sensitivity labels with each security
	association.

2.  Decision & Precedence Information

	The project is approved as specified in reference [1].

	The project may be delivered in a patch release of Solaris.


3.  Interfaces

                      Interfaces Exported

    Interface           Classification      Comments
    ike config file     Committed           /etc/inet/ike/config
    PF_KEY extensions   Committed

4.  Opinion

4.1.  The "wire-label" keyword

	Members of the committee noted that the "wire-label" keyword has the
	potential for confusion. It can be used to control two different and
	possibly independent things: the choice of outer labels on IKE and
	AH/ESP traffic. Those labels can conceivably each be entirely
	missing, computed based on the label ranges of the peers (either max
	or min), hard-coded to some particular value, or driven by the label
	of the invoking zone.

	There are at least 25 distinct choices for the two policies
	combined, perhaps more if we get really creative. The single keyword
	approach means that you need to have sub-keywords that somehow
	indicate how each of this traffic will be handled. That would make a
	lot of sense if there were only a handful of operationally
	meaningful combinations.

	Depending on the amount of "meaningful combinations", or the most
	meaningful of those combinations, the "omit/omit" setting may be
	obvious as a way to get out of the CIPSO mire, but it seems all of
	the others require detailed understanding of the policies that sites
	have and (likely) the limitations of the other vendor's equipment
	they're using.

5.  Minority Opinion(s)

	None.

6.  Advisory Information

6.1.  Independent Labeling

	The project team is advised to consider controlling the outer labels
	on IKE and AH/ESP traffic (currently controlled via the single
	"wire-label" keyword) using independent flags. If particular
	combinations of label settings are (or become) common, a single
	keyword to select those common settings could be added later.

7.  Appendices

7.1.  Appendix A: Technical Changes Required

	None.

7.2.  Appendix B: Technical Changes Advised

	None.

7.3.  Appendix C: Reference Material

	Unless stated otherwise, path names are relative to the case
	directory PSARC/2008/097.

1    Onepager
     File: 20080409_bill.sommerfeld

2    Inception minutes
     File: inception.materials/20080806.2008.252.inception
	 
3    Commmitment minutes
	 File: 	commitment.materials/20090128.2008.252.commitment

4    Issues
     File: issues

5    PSARC 20 Questions.
     File: commitment.materials/txipsec-phase1-20q.txt

6    Security 
     File: inception.materials/txipsec-phase1-security.txt



PSARC/2008/252               Copyright 2008 Sun Microsystems

--Boundary_(ID_sWJJgxPTWxm5d0eb/6Gw2w)--

