Re: [Anima] Adoption call for draft-friel-anima-brski-cloud-04, ends April 20th 2021

Brian E Carpenter <brian.e.carpenter@gmail.com> Wed, 07 April 2021 23:32 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 336D03A2E2B; Wed, 7 Apr 2021 16:32:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q2Vua123JAmL; Wed, 7 Apr 2021 16:32:14 -0700 (PDT)
Received: from mail-pj1-x102a.google.com (mail-pj1-x102a.google.com [IPv6:2607:f8b0:4864:20::102a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA0933A2E2A; Wed, 7 Apr 2021 16:32:10 -0700 (PDT)
Received: by mail-pj1-x102a.google.com with SMTP id k23-20020a17090a5917b02901043e35ad4aso2128986pji.3; Wed, 07 Apr 2021 16:32:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=fWhU56LyxQjpozKojlWIc6cnghNSTTnAGs94sJyXq5U=; b=PHijnQr3pTwBJMf2yr2SJRI8KUW7zqTgL7WoUaHwRxIJspj1bdQeLjkmDkYSqmpNbr S02fjy/JC2ZHs2UR2DjY40Euryfn7hpFHjgwCAjeccA+RweB4nJKkNUzmOHRP5fuml+c dKwMKhJ4QGvttzy8kEplwdOijFNTWs9PXGTAT/gAJYes3zA9GSfc2+MFYQEz1ArujHks yH28OCTv7QSH4NDP9OE+eY6YI4mAWg5Yezo06zcm4NpVzhvGrLtuOWHyW41/jBawfSyO LV6/81FuBEg6fYuIRxhkadej8eg2rVUzlfYknIkQc319HRqigQ7+Cc3qSaZmeQB+/Nt5 olng==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=fWhU56LyxQjpozKojlWIc6cnghNSTTnAGs94sJyXq5U=; b=bz1xe95/25nFMlJJbRb/U/xRzQ6TMMdXUjuSlqYbS2vZwX6ImFioyYCCDCcbnKdeBT IWfGN3AiZa9ZHqWUp/MifSW7k2peGT8oMS+TpNXc7OkmcqQ6SvMTou8gEvK7/75ejm14 X3aGTKKJr3SnYZwFStRnZzlTzeMCrUBzjF+XrQjW2lC+2szi+DQtbSaWSgTjFvb24Eqh OqVWyMK1JeIZsvqwYWpZQPOBEqwfmrLW286ea0GH2Onz1U2F9TLJ/rm5pnLrII1VQf4q cIxyRJTF19DSFNk3e6rev88IoX1PLv2WyDnjFI/uJldwjxYoGu9Vz5h9rMftTZZ0RYzg 2yHA==
X-Gm-Message-State: AOAM530YRUcALXIfYO9l5BwCakAfAQX47QYF9PxdOysdv9L43QjCDXh4 /Ti5EecUYOYD4fttTFp9bSNJ4Mjlv8N6rw==
X-Google-Smtp-Source: ABdhPJymGIV5DjitPMMEYibdpJWPv/oa2hD7u8wFS4MnqAKSgakcPAo8B9ia7x14dT0jmL1gy4kgLQ==
X-Received: by 2002:a17:90a:7847:: with SMTP id y7mr5728665pjl.65.1617838328396; Wed, 07 Apr 2021 16:32:08 -0700 (PDT)
Received: from [130.216.38.19] (sc-cs-567-laptop.uoa.auckland.ac.nz. [130.216.38.19]) by smtp.gmail.com with ESMTPSA id f6sm16195170pgd.61.2021.04.07.16.32.05 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 07 Apr 2021 16:32:07 -0700 (PDT)
To: Sheng Jiang <jiangsheng@huawei.com>, "anima@ietf.org" <anima@ietf.org>
Cc: "anima-chairs@ietf.org" <anima-chairs@ietf.org>, "Rob Wilton (rwilton)" <rwilton@cisco.com>, "tte@cs.fau.de" <tte@cs.fau.de>, "draft-friel-anima-brski-cloud@ietf.org" <draft-friel-anima-brski-cloud@ietf.org>
References: <45700ca322fb427eb7d4af7c7556f15c@huawei.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <ef61d0c0-ce37-1afb-63f5-b059316242b3@gmail.com>
Date: Thu, 08 Apr 2021 11:32:02 +1200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.1
MIME-Version: 1.0
In-Reply-To: <45700ca322fb427eb7d4af7c7556f15c@huawei.com>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/MH9raw6GDiE7tnpM6q23NQKEqSQ>
Subject: Re: [Anima] Adoption call for draft-friel-anima-brski-cloud-04, ends April 20th 2021
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Apr 2021 23:32:18 -0000

Hi everybody,

I think adoption is appropriate. I do have a few comments towards the next version.

1) This model is rather different from the basic ANIMA model, which was designed for nodes that start out with nothing but an IPv6 address. As the draft says:

>> The assumption is that the pledge already has network connectivity prior to connecting to the cloud registrar. The pledge must have an IP address, must be able to make DNS queries, and must be able to send HTTP requests to the cloud registrar.

I think there should be some discussion right at the beginning of the Introduction about this fundamental difference. The reason that ACP and BRSKI use GRASP flooding for discovery is to avoid any dependency on DNS or the wider Internet. You could use the BRSKI and ACP mechanisms in a disconnected network fragment and build up connectivity from there. (For example, if the pledge hears no RA messages that give it DNS or Internet connectivity, one could invent a GRASP objective like "Connectivity" that could be used to find a router or RADIUS server willing to help.)

2) 

>>  1.2. Target Use Cases
>> 
>> Two high level use cases are documented here. There are more details provided in sections Section 4.1 and Section 4.2.

This is not easy to read. It really needs to summarise the two cases in a few words. Otherwise, most readers will immediately jump to the two sections, as I did. Proposal:

Two high level use cases are documented here (voucher request redirected to local registrar, or handled directly by cloud registrar). There are more details provided in sections Section 4.1 and Section 4.2.

3) Security Considerations is a very big [[ TODO ]]. I would prefer to see some content  in the WG draft as soon as possible.

Regards
   Brian Carpenter

On 07-Apr-21 22:00, Sheng Jiang wrote:
> Hi, dear ANIMAer,
> 
>  
> 
> This message starts a two-week adoption call on draft-friel-anima-brski-cloud-04, it ends on April 20^th , 2021.
> 
>  
> 
> draft-friel-anima-brski-cloud has been presented to the WG since September 2019 and the WG showed good interest and had discussions. It was presented several times and had no opposition. The draft is clearly in scope of ANIMA charter and milestones. Giving the dependent BRSKI has passed the IESG evaluation, the chairs feel that it may be the right time to call the adoption.
> 
>  
> 
> We therefore are asking the ANIMA working group for adoption of the following work:
> 
>  
> 
> Title:    BRSKI Cloud Registrar
> 
> Name:     draft-friel-anima-brski-cloud-04
> 
> Authors:  O. Friel, R. Shekh-Yusef and M. Richardson
> 
> URL:      https://datatracker.ietf.org/doc/draft-friel-anima-brski-cloud/
> 
> IPR:      No IPR disclosures have been submitted directly on draft-richardson-anima-voucher-delegation
> 
>  
> 
> This document is intended to become a standards track ANIMA WG document.
> 
>  
> 
> Please express your support or rejection. If you think this document should _not_ be adopted, please also explicitly indicate the reasons.
> 
>  
> 
> Regards,
> 
>  
> 
> Sheng
> 
> 
> _______________________________________________
> Anima mailing list
> Anima@ietf.org
> https://www.ietf.org/mailman/listinfo/anima
>