Re: [bess] John Scudder's Discuss on draft-ietf-bess-srv6-services-11: (with DISCUSS and COMMENT)

John Scudder <jgs@juniper.net> Fri, 18 February 2022 22:19 UTC

Return-Path: <jgs@juniper.net>
X-Original-To: bess@ietfa.amsl.com
Delivered-To: bess@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD7123A1519; Fri, 18 Feb 2022 14:19:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.675
X-Spam-Level:
X-Spam-Status: No, score=-2.675 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.576, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=Rgz8WSeA; dkim=pass (1024-bit key) header.d=juniper.net header.b=DI6rP6Xp
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S-pLDSU0JhhV; Fri, 18 Feb 2022 14:19:46 -0800 (PST)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B14243A1510; Fri, 18 Feb 2022 14:19:43 -0800 (PST)
Received: from pps.filterd (m0108161.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.1.2/8.16.1.2) with ESMTP id 21IMFe6n003805; Fri, 18 Feb 2022 14:19:42 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=PPS1017; bh=l/zJgKu9pM2HX7hKSBNV1A9MFw7JDwzHIFo3KKV2gQA=; b=Rgz8WSeAy0lF448GdCjgmhM80Xlm3nQgbJARtJ3eMpaav9qaZKl0/ziSJjSXhxFxjuMH KDqIEKbi+mt3etGbtxOYbwXswdlMi4nwxQigIQ/8AkhsRZVwe2MG6S74ovNBE70I3tBZ QASwFalTYieliT6+Z/OpgEyYsxHejwPE4/1z+jtMjq2E/XrDpBIc5aSTv7T88kWbkV3v kXDw2cfC3s13Fa0huOAnmgl2BDZ+YEZwCRyxyQZqz4UvnBYQEQobGIfLU4GKsafcYLUd xVK0pkvMFANv5dY1UMt+9PN5qTtCbyf8y9GEt9gghkZcFOEvcywH8O4qAg/FuyVZJWli kw==
Received: from nam12-bn8-obe.outbound.protection.outlook.com (mail-bn8nam12lp2176.outbound.protection.outlook.com [104.47.55.176]) by mx0b-00273201.pphosted.com (PPS) with ESMTPS id 3eam3h0063-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 18 Feb 2022 14:19:42 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=TSCrOGFaYXoyEVI6u+VWnPN3HB/5eVP1LYzIqB4wZFCVfISHmFPBseYurP2hTR1R6TK5E/dfVn7UyfMnWhGdEygXiJtlM5I2hilJQGbhDS4QMSIdW0eAVH2uK9pD7wxcpZ7drcGME7zLL0GQOX0fHxbv1pKQieHE9HGqp8JzNADZM7cdwCa4b/icjt62H7IZ5AX6gM26Vvat6r/mCqurASykZnbyZsSJb3xMPVE9YWroQoHxewOW6VkXOQHjaTbf8L5rH5h6vVtZm9QMn2sZ+q9tFAM3u9Wh6fUP1haGDQtCWUtQgtqXs/SCFa8LXihA6FlM6BhntBtI1o4SHJFOXQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=l/zJgKu9pM2HX7hKSBNV1A9MFw7JDwzHIFo3KKV2gQA=; b=Ze44fS3wWikB79tBE2y75nai1sqavefA/16pPlxku6qDSpqEf1YdDmUc5+W0dOCh9NnMdtByIhAsyRVJpBvOTL7L8PNM7KhEPD/ZkseVavspNNRdu96JaHFucsJdzoKQWjsSsNisifLRUd4vG4qkfBUyoR3YOV8kOfF9gqOb652fMSpsGVv+e0D0WL1r1IDcWLW1hAy+rV6pcR3H0WWWgOL9txCQrfe635mYDLUfcM7oi9ArwI9w4lpr4J9NucJKfSpOpM/pUWj49RbgjY+YJYu0Zfy9GGsbc2HmbMnyl5QMBhk0fvZqCdBywKawiRr9EjK+jft70H17y1ZNvH6i9Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=l/zJgKu9pM2HX7hKSBNV1A9MFw7JDwzHIFo3KKV2gQA=; b=DI6rP6Xp/y6rA2gP+2TicFPpJVZgVIPYjAE5VBBZDDn4XNhl4lK22VzvTxiw/q0WHJP1wNbdfTD6jo3LBP1NL/7apj73txVwwgWXNWj9ICsmKEPzzCsxSDppud1p2puEi+kjA7trEMDlZMyKD38XnLxsyTGqvAZKb6itV5pM79I=
Received: from MN2PR05MB6109.namprd05.prod.outlook.com (2603:10b6:208:c4::20) by SN6PR05MB5823.namprd05.prod.outlook.com (2603:10b6:805:f5::30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5017.13; Fri, 18 Feb 2022 22:19:39 +0000
Received: from MN2PR05MB6109.namprd05.prod.outlook.com ([fe80::1cf9:4765:c8df:81b7]) by MN2PR05MB6109.namprd05.prod.outlook.com ([fe80::1cf9:4765:c8df:81b7%5]) with mapi id 15.20.5017.012; Fri, 18 Feb 2022 22:19:39 +0000
From: John Scudder <jgs@juniper.net>
To: Ketan Talaulikar <ketant.ietf@gmail.com>
CC: The IESG <iesg@ietf.org>, "draft-ietf-bess-srv6-services@ietf.org" <draft-ietf-bess-srv6-services@ietf.org>, "bess-chairs@ietf.org" <bess-chairs@ietf.org>, BESS <bess@ietf.org>, "Bocci, Matthew (Nokia - GB)" <matthew.bocci@nokia.com>
Thread-Topic: John Scudder's Discuss on draft-ietf-bess-srv6-services-11: (with DISCUSS and COMMENT)
Thread-Index: AQHYI322mbek+dF3+EGw0XVWK3Fiw6yXZ0uAgAJ89QA=
Date: Fri, 18 Feb 2022 22:19:39 +0000
Message-ID: <9F0B1CC7-80ED-428A-BB6B-86F2D0A95A87@juniper.net>
References: <164504757419.5632.9536270153833731412@ietfa.amsl.com> <CAH6gdPxTtVfh02odMdreGnnsD8fnY2rPDqPhU9cucSOuU=bxNw@mail.gmail.com>
In-Reply-To: <CAH6gdPxTtVfh02odMdreGnnsD8fnY2rPDqPhU9cucSOuU=bxNw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Apple Mail (2.3654.120.0.1.13)
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: a5c211bd-78c1-4857-0313-08d9f32cc101
x-ms-traffictypediagnostic: SN6PR05MB5823:EE_
x-ms-exchange-atpmessageproperties: SA|SL
x-microsoft-antispam-prvs: <SN6PR05MB5823E4530F31E1ECCFDD3719AA379@SN6PR05MB5823.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ZEaMG1CR1LfNCQa2JEzB+Aslo9LgAVjI4IV8ww2oQcT0A55sTyDUOddSgnbzd5TWZm8wK/QNC4yJ30VshyHdMYqWBefneNrRpjXCCQ+3jUIqAW5nd3VxnwQ6gEoc0TtkKeNNSe38xZ1FEqCBiIr5gwUPuDhG+Kj+XyP79wXg8pOH0vNedDtige7oE+smdGn9/4BWGboAf6JMze1sjEIY3pOdPAzVSyHgINzTz+zgkXrj9ZVj49ceD7BOw9Mfg52vrAHDR3rus98scPAEvKcyQ3s1lipwFyerEVpqg7OCa0LPBRg9I5DSdwDZAEsn/ivchZQwx/G4+CF3kdoxT/+B0R+5y3gaU/FGdjQgK6nahe8HqEk0pA8DMm3/8CxnCCsY45VVgXPFDAWZljo60JP7TcNH4oD2YWTuovBe2x6VdYEgSVCWGmklmKqGYALkO+JXfqV3QuldTiSiLIxsFBBHAjZh/x74HSufPNK9Hw/JmECfh5tGWJTYbDuqUWzxBRLyf/7vj3OPa4937rYaUfXj0oOqd4lhKrzRRJSeT2pQ41QoY3dPSOCOTvWC0U+D3UBufop161qokheNYitm7w4V/UcRURcTTYHzpw0QOFnW8nCoqiQL6OpTdK7zpemTPNnnMkMhIMTgJvRuaq4kLRH8oGel5dBYP0CAYGdA9LwToJOV9fzJLKvIdM1ay9QgGckc1V/EvG7Ie9veaCYctu097ADi32b7XYkuR2tRkmi0lT3fszmdm4jI/7xxJnYEo8M9zX856D82CfEm59yFp6gAlLKgu0S/CEx79wqzdJoUl8U=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR05MB6109.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(91956017)(76116006)(2906002)(66574015)(83380400001)(86362001)(33656002)(64756008)(8676002)(66446008)(38100700002)(66476007)(66556008)(54906003)(38070700005)(66946007)(4326008)(6916009)(5660300002)(316002)(53546011)(6512007)(6506007)(71200400001)(36756003)(508600001)(122000001)(8936002)(6486002)(26005)(2616005)(186003)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: =?utf-8?B?Q1VPOUxhUm9BU1lUcmJqWkhKZTlLdzM2SmdKN1JMTlhMbWZFUVRjbXhlMTBz?= =?utf-8?B?blI4YWl3YzgxN0dyeU11UjdlWDFDc0MvUmV1clQxYmNLdnBVUjVTWmZJNDFP?= =?utf-8?B?SVRyVnlmM3NTc2xPNWxsa3k1Q1ptWHNXcTFHbXowdEpVYXFpd2FGaWtjTVJq?= =?utf-8?B?eHZGYlZiS2pQNFg0akVYU3R6K1ovbTUrT0ovTUl1ZExRVThsUmZlQXJ1U0th?= =?utf-8?B?UW5keUhEMGMvS2Z0REo5WlVVckJmUXRuU2szQ2RpazFwRXB5cHVvcm1rR1h2?= =?utf-8?B?NFRtNEdxS0xTOGZFRFBZbWZzQXJvS2tFTDRaZWZmRXE4ZDA1YnlKTGZTc2pM?= =?utf-8?B?RnZpU2Y1MWU1aUFzeW93SDYwT1psQWR4eCs3NHdyci9GQTNKRkJqbnlrMzBw?= =?utf-8?B?SHlQT0NEZDZyVit3dExYWHpHdEhnOUtTdFVacEUvMStESEZHcDA1UzZCNHFz?= =?utf-8?B?bHNiZ3RIK1EvcGpsSlIvdmNmOFJ6MHRvUlNtanpkT2pJTVBneWJRLzUwQnph?= =?utf-8?B?bmFEYkpoMmJkU052TTZ5dys5NzdEMm5sUmpNdk41U3BOdEFWcllGakMrMDBS?= =?utf-8?B?YmY3aFRncUVjOVZEdnZsSE0weVgrTlhZNzNKQm8vcEdpY0d2VWF5c0JwZkgz?= =?utf-8?B?UEUxZmV0UDlvdDczTkR1ck5FellUSDZ5VFoyZzVueUFsb0xyTmZZclNXWlRi?= =?utf-8?B?NjJ3em1CRmhVY2txOGdOVmpJZnBKQy85OXF3dmEyRlVseHR3NWN3UkVqNE9K?= =?utf-8?B?WXZQenhoNXBvSDBkZXV6dUMzSHM5WjVpMWllYXpVS0hIZ2FoUWV4RHFzTmQ5?= =?utf-8?B?TytZRjVubnp0UHhkZFREemZwT3ZOcnNQWE83NzAyZ2YvTVNGTkRaU2JRTjIz?= =?utf-8?B?djR5UlR1eDNHZUh6d0IzZmhzajAyMUhrbEIrVkZmVUNWQjRSZ24yL0tTOWxG?= =?utf-8?B?cVF6ajNybGR3aE5UQ1ZtTFZhenZVZE1EYlBjbjVlTGkyZkN1SmE4bjJmay9h?= =?utf-8?B?QXhpQlZ1dGprUDlTZzNjSXFaUnJQOGI1SmJvdXJZMTYzclI5SURuZEhRdTdD?= =?utf-8?B?TnZFcDlxMHBQbXlvdnZxZTRwcS9zZkx0K0V0U1lodlUyM0ZwUHhwODhQTzEz?= =?utf-8?B?a05XL2ZLSzZwQ016TExHaFlQYVEzNUwwVSszb01ENCt5VlgzZkQ3aFU3dkYv?= =?utf-8?B?T05DaC8xZU1Way8waHVTUDQwdHQ2UXZ5amhLV3BZMlVEQThaTWs3c3czd1dB?= =?utf-8?B?bTFvZkN6WlhERHVLZVVyZzJHYXdMNmJpNTN4THlOMlhiSXYySG9wdmlndHVn?= =?utf-8?B?T2VJTmZ6bU0yUG5uV1FZR3R2WkVydDZwTUlGZW5kN0h2TW5FUWs5WGxFdlUw?= =?utf-8?B?Vm8wdnZhcWxRL3NvMkJDWTBZM09XeG1Cc2h1clJFWjhWaExIRnJMcVppWEVP?= =?utf-8?B?bXpEbnVHK2RjaDlFSXRZRjZNd2xQZkFQd0ZrdXBvNVE2M1Q3Z2M5VzBpakx1?= =?utf-8?B?K29USTI4UWZsblFNQUNJdEFVbE9yZ0ZrOHg5cVZHbUlTYTBiaWpQb05GTzVn?= =?utf-8?B?Nm5McUNKNW13SXVqeUlkRUhqWTFka1l4cER5eFJrWEJ1S0pBN1NYUE5zeGV2?= =?utf-8?B?ZUR2RUdydHlhL1lGcUFtV2dNallMYVg4ams4elZjOWY5N3k5S2xTV0R2ZGdZ?= =?utf-8?B?MDB1S2xWaGdnUU1jMnBIWGNJcXdpVDFHVlg2RWdCZTVMZFlBakowdmg4L0Rj?= =?utf-8?B?T3U4STlFR3RveHhZNkI5WlRYY0hrQUV5c0NDSjJPR2xXMGZQZzd4Z2pEVGEr?= =?utf-8?B?Y0FyTHJURWVJS3ZpZ3I2SWJiNWVicnB1cnZmWmY2ek8zcUxFZHJtUHlZV1Iy?= =?utf-8?B?TlpGUGo0b0JnKzJRU2l3MXROeWN6Mko1N2xMVjBaY01KeVNvSGhXNEFaVHdE?= =?utf-8?B?UzFZMzE5L1BvY2x2Y0dRRzI2WkxVYS9uVW53aENlNW9qcERkWUxBU2U3WFZF?= =?utf-8?B?cFFOTUpKdnN3L2ltOW9Mb3dtWGxRVms0YWJjSzNGQmsvdnZ3SmxCbHliV1dW?= =?utf-8?B?aVl3NnFMUWtLcmtoQ29PekduNjdpUzRlS2dUWHdveURrR0ZWNDQzQWZuWXFI?= =?utf-8?Q?aMS5SuG4C6HLpEtgWr/9zCznI?=
Content-Type: text/plain; charset="utf-8"
Content-ID: <B8E6F750584C434DA9262FA1ADE85CDE@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR05MB6109.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: a5c211bd-78c1-4857-0313-08d9f32cc101
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Feb 2022 22:19:39.0877 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: d8V9F09Vgmk0lpCFHTnGbRBpEQy7Wkn08eMTtqJO5CKVK0p1Vt8JduU8L9EOysRE
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR05MB5823
X-Proofpoint-ORIG-GUID: efsbtZdcZ5Z212yPHYnNtHotfuC8cvRZ
X-Proofpoint-GUID: efsbtZdcZ5Z212yPHYnNtHotfuC8cvRZ
X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.816,Hydra:6.0.425,FMLib:17.11.62.513 definitions=2022-02-18_10,2022-02-18_01,2021-12-02_01
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 adultscore=0 lowpriorityscore=0 suspectscore=0 mlxscore=0 phishscore=0 bulkscore=0 priorityscore=1501 spamscore=0 impostorscore=0 mlxlogscore=999 malwarescore=0 clxscore=1015 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2201110000 definitions=main-2202180137
Archived-At: <https://mailarchive.ietf.org/arch/msg/bess/-DFPK8OWHAZDzf2RkaZT0yIgiNM>
Subject: Re: [bess] John Scudder's Discuss on draft-ietf-bess-srv6-services-11: (with DISCUSS and COMMENT)
X-BeenThere: bess@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: BGP-Enabled ServiceS working group discussion list <bess.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bess>, <mailto:bess-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bess/>
List-Post: <mailto:bess@ietf.org>
List-Help: <mailto:bess-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bess>, <mailto:bess-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Feb 2022 22:19:52 -0000

Hi Ketan,

> On Feb 17, 2022, at 3:19 AM, Ketan Talaulikar <ketant.ietf@gmail.com> wrote:
> 
>> 3. As Warren Kumari points out in his DISCUSS, “leaks happen”. Subsequent
>> discussion turned quickly to the assertion that no, they don’t, in VPN address
>> families. Let’s accept that claim for the sake of conversation. It’s still the
>> case that sometimes (often?) routes are distributed from VPN address families
>> into the Global Internet table. When this is done, by default, all the path
>> attributes come along for the ride. Anyone who thinks this is just a
>> hypothetical case might want to look back to (for example) significant network
>> outages that were caused around a decade ago by leakage of BGP Attribute 128
>> (ATTR_SET, RFC 6368) into the global Internet.
>> 
>> The SIDs contained in these if-they-were-to-leak routes potentially give an
>> attacker a means of directing packets into a VPN customer’s internal network.
>> 
> KT> I believe we are getting now into implementation aspects when you bring up handling of attributes during redistribution from VPN tables into the default table.

I don’t think we can sweep this easily under the “it’s an implementation detail” rug — the fact is, AFAIK this *is* what implementations do (redistribute optional transitive attributes from VPN to default tables). This “implementation detail” is not, itself, an issue for draft-ietf-bess-srv6-services. What it is, is a perspective on "Precaution should be taken to ensure that the BGP service information (including associated SRv6 SID) advertised via BGP sessions are limited to peers within this trusted SR domain.” The argument was previously advanced that this is trivially achieved for VPN address families, I’m saying that’s not so, for the reasons given, and therefore the ramifications of leaks of the information you identify as sensitive, need to be considered (at minimum).

> We can add some text in the security considerations to discuss this.

Looking forward to seeing it, thank you.

—John