Hi Tina,

Thank you for clarifying the VRF point.

I don’t think a change is needed as we don’t define the VRF itself but I will 
think further about this.

Cheers,
Med

De : Tina Tsou <tina.t...@tiktok.com>
Envoyé : vendredi 18 avril 2025 19:28
À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucad...@orange.com>
Cc : ops-...@ietf.org; draft-ietf-opsawg-secure-tacacs-yang....@ietf.org; 
last-c...@ietf.org; opsawg@ietf.org
Objet : Re: [External] RE: [OPS-DIR]Opsdir ietf last call review of 
draft-ietf-opsawg-secure-tacacs-yang-09

Bonjour Med,

Replies are inline.
From: mohamed.boucad...@orange.com<mailto:mohamed.boucad...@orange.com>
Date:  2025年4月18日 (周五) 02:18
Subject:  [External] RE: [OPS-DIR]Opsdir ietf last call review of 
draft-ietf-opsawg-secure-tacacs-yang-09
To: "Tina Tsou"<tina.t...@tiktok.com<mailto:tina.t...@tiktok.com>>, 
"ops-...@ietf.org<mailto:ops-...@ietf.org>"<ops-...@ietf.org<mailto:ops-...@ietf.org>>
Cc: 
"draft-ietf-opsawg-secure-tacacs-yang....@ietf.org<mailto:draft-ietf-opsawg-secure-tacacs-yang....@ietf.org>"<draft-ietf-opsawg-secure-tacacs-yang....@ietf.org<mailto:draft-ietf-opsawg-secure-tacacs-yang....@ietf.org>>,
 
"last-c...@ietf.org<mailto:last-c...@ietf.org>"<last-c...@ietf.org<mailto:last-c...@ietf.org>>,
 
"opsawg@ietf.org<mailto:opsawg@ietf.org>"<opsawg@ietf.org<mailto:opsawg@ietf.org>>
Hi Tina,

Thank you for the review.

Please see inline.

Cheers,
Med (as doc editor)

> -----Message d'origine-----
> De : Tina Tsou via Datatracker <nore...@ietf.org<mailto:nore...@ietf.org>>
> Envoyé : vendredi 18 avril 2025 10:18
> À : ops-...@ietf.org<mailto:ops-...@ietf.org>
> Cc : 
> draft-ietf-opsawg-secure-tacacs-yang....@ietf.org<mailto:draft-ietf-opsawg-secure-tacacs-yang....@ietf.org>;
>  last-
> c...@ietf.org<mailto:c...@ietf.org>; opsawg@ietf.org<mailto:opsawg@ietf.org>
> Objet : [OPS-DIR]Opsdir ietf last call review of draft-ietf-opsawg-
> secure-tacacs-yang-09
>
>
> Document: draft-ietf-opsawg-secure-tacacs-yang
> Title: A YANG Data Model for Terminal Access Controller Access-
> Control System Plus (TACACS+)
> Reviewer: Tina Tsou
> Review result: Has Nits
>
> - Consider clarifying the default port for TACACS+ over TLS once
> IANA assigns it.

[Med] We do already have a note for this:

   Please apply the following replacements:
   ...

   *  TBD --> the assigned port number in Section 7 of
      [I-D.ietf-opsawg-tacacs-tls13]

> - Note using TLS requires the device to also implement the relevant
> crypto key/cert models.

[Med] Indeed. This is covered by this text:

   This YANG module uses types and groupings defined in [RFC6991],
   [RFC8341], [RFC8343], [RFC8529], [RFC9640], [RFC9641], [RFC9642], and
   [RFC9645].

> - Think about VRF uniqueness scenario, if needed, adjust the YANG
> unique statement.

[Med] Can you please elaborate on this one? Thanks. [Tina] Allowing identical 
addresses in different VRFs.

> - "port number of TACACS+ server port number" is repetitive

[Med] Good catch. Fixed at 
https://github.com/boucadair/secure-tacacs-yang/pull/17/commits/9966efba1eb36cd6868df141fa690ce41d72b9e2


____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations 
confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce 
message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages 
electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou 
falsifie. Merci.

This message and its attachments may contain confidential or privileged 
information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete 
this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been 
modified, changed or falsified.
Thank you.
_______________________________________________
OPSAWG mailing list -- opsawg@ietf.org
To unsubscribe send an email to opsawg-le...@ietf.org

Reply via email to