Re: [Anima] Multicast in the ACP?

Brian E Carpenter <brian.e.carpenter@gmail.com> Wed, 22 April 2015 22:56 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 687AD1B2CD8 for <anima@ietfa.amsl.com>; Wed, 22 Apr 2015 15:56:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4LOny4zzwyhp for <anima@ietfa.amsl.com>; Wed, 22 Apr 2015 15:56:01 -0700 (PDT)
Received: from mail-pd0-x22c.google.com (mail-pd0-x22c.google.com [IPv6:2607:f8b0:400e:c02::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6E5211B2CC3 for <anima@ietf.org>; Wed, 22 Apr 2015 15:56:01 -0700 (PDT)
Received: by pdbnk13 with SMTP id nk13so1115221pdb.0 for <anima@ietf.org>; Wed, 22 Apr 2015 15:56:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:organization:user-agent:mime-version:to :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=zSuyb3D5vlWVPlFsYgmF8V6aAOLuMUWXRSBGTdbOA10=; b=sI5atuH96bzTVfb5AAQHSJfdwAeli4oQOiIjAfKl0oiqbaO/1L/YQc3zTO2sz7LVbe 1X8Sg8AURV80UPQmIGaUVDgunXYuGNB2C/a/3bOkZ/OzFscAbJzLu0Y5dVHmDWTFcvFF EX+DOxAJwZrihw0p5tzA/m34F9VaiTzjx7h3r5kpWHQyFT0XFh+MeKuXKX49oSLLo7ef C7vLtrwSrTaOyehOocYcyaNyvHF/Bj3/uIcThWgG/i/Z5s/vMrI5IPv9xXriGR/AkgXZ 2/3BF0wDA5Ce726sbL8kQ2Y2s8tasxjVm95KnRWtLArEdNrbbTLSJ0Y/CgNJc1XPN545 LbCg==
X-Received: by 10.66.55.104 with SMTP id r8mr46808680pap.75.1429743360976; Wed, 22 Apr 2015 15:56:00 -0700 (PDT)
Received: from ?IPv6:2406:e007:55fb:1:28cc:dc4c:9703:6781? ([2406:e007:55fb:1:28cc:dc4c:9703:6781]) by mx.google.com with ESMTPSA id qd8sm6032637pbc.71.2015.04.22.15.55.58 for <anima@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 22 Apr 2015 15:55:59 -0700 (PDT)
Message-ID: <55382705.3060605@gmail.com>
Date: Thu, 23 Apr 2015 10:56:05 +1200
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: anima@ietf.org
References: <5536EE40.30705@gmail.com> <3AA7118E69D7CD4BA3ECD5716BAF28DF22F5FE63@xmb-rcd-x14.cisco.com> <5537FFEF.9020308@gmail.com> <10795.1429737994@sandelman.ca>
In-Reply-To: <10795.1429737994@sandelman.ca>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/anima/--7JGh67BWisGgLJcAKVzYq4VqA>
Subject: Re: [Anima] Multicast in the ACP?
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Apr 2015 22:56:03 -0000

On 23/04/2015 09:26, Michael Richardson wrote:
> 
> Brian E Carpenter <brian.e.carpenter@gmail.com> wrote:
>     >>> The discovery component of GDNP includes link-local multicast
>     >>> messages.  As far as we know, there is no way to secure these
>     >>> messages, but by definition they are only intended for autonomic
>     >>> nodes, which should all be part of the ACP.
>     >>>
>     >>> So, is there any way to support secure link-local multicast within
>     >>> the ACP?
>     >>
>     >> The ACP as described in draft-behringer-anima-autonomic-control-plane
>     >> is based on a hop by hop tunnel infrastructure. So far those tunnels
>     >> are all point to point. I guess you can send a link-local multicast
>     >> packet through such a tunnel, and it would automatically benefit from
>     >> the security of that tunnel. But of course there is only one other
>     >> node on that "link".
> 
>     > Right, so we would have to specify a "replicast", where the sender
>     > copies the message to each ACP tunnel. That seems like a lot of
>     > overhead.
> 
> http://datatracker.ietf.org/doc/draft-ietf-roll-trickle-mcast/
> describes a way to do multicast across that collection of links... that is if
> we can ever get it through the IESG.

Interesting. That looks like overkill for ACPs that run over non-constrained
networks, but it suggests to me that we need a modular approach, so that it
could be used in networks that call for it.

    Brian