Re: [core] AD review of draft-ietf-core-echo-request-tag-10

Christian Amsüss <christian@amsuess.com> Fri, 04 September 2020 08:05 UTC

Return-Path: <christian@amsuess.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B27D3A10EA; Fri, 4 Sep 2020 01:05:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tGFpUKyk31kq; Fri, 4 Sep 2020 01:05:04 -0700 (PDT)
Received: from prometheus.amsuess.com (prometheus.amsuess.com [5.9.147.112]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE4423A10E6; Fri, 4 Sep 2020 01:05:03 -0700 (PDT)
Received: from poseidon-mailhub.amsuess.com (unknown [IPv6:2a02:b18:c13b:8010:a800:ff:fede:b1bd]) by prometheus.amsuess.com (Postfix) with ESMTPS id 0D33B407CF; Fri, 4 Sep 2020 10:05:01 +0200 (CEST)
Received: from poseidon-mailbox.amsuess.com (hermes.amsuess.com [10.13.13.254]) by poseidon-mailhub.amsuess.com (Postfix) with ESMTP id C49BB74; Fri, 4 Sep 2020 10:04:59 +0200 (CEST)
Received: from hephaistos.amsuess.com (unknown [IPv6:2a02:b18:c13b:8010:752e:5530:91d4:ca87]) by poseidon-mailbox.amsuess.com (Postfix) with ESMTPSA id E138314B; Fri, 4 Sep 2020 10:04:58 +0200 (CEST)
Received: (nullmailer pid 3696986 invoked by uid 1000); Fri, 04 Sep 2020 08:04:58 -0000
Date: Fri, 04 Sep 2020 10:04:58 +0200
From: Christian Amsüss <christian@amsuess.com>
To: Göran Selander <goran.selander@ericsson.com>, Barry Leiba <barryleiba@computer.org>
Cc: "draft-ietf-core-echo-request-tag.all@ietf.org" <draft-ietf-core-echo-request-tag.all@ietf.org>, "core@ietf.org" <core@ietf.org>
Message-ID: <20200904080458.GA3696849@hephaistos.amsuess.com>
References: <CALaySJJt_U+qF_xwOtJC2BD=oet-stNxoJkMYJfH=Z8BmcLc3g@mail.gmail.com> <1E09C83D-0AC1-42CA-9E2D-E5903FF775D6@ericsson.com> <CALaySJ+eULVaqA-=em1HkoQ2bin4Af2P1N2YxrZWc1sY8z7ymw@mail.gmail.com> <A9E706DB-2C6D-43A6-8EAC-0AE9CF3F78B8@ericsson.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="a8Wt8u1KmwUX3Y2C"
Content-Disposition: inline
In-Reply-To: <A9E706DB-2C6D-43A6-8EAC-0AE9CF3F78B8@ericsson.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/FG_7AD95pwW0R4QStqPe0BoXtws>
Subject: Re: [core] AD review of draft-ietf-core-echo-request-tag-10
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 04 Sep 2020 08:05:07 -0000

Hello Göran,

thanks for handling the comments.

On the topics in this sub-thread, I'm happy with all the changes, and
there's only a single remark left for me to make:

> > It’s not clear to me how a client can comply with this: how can the client
> > possibly know whether the messages it has sent would be considered invalid
> > by the server if they were replayed?  Or is there something I’m not
> > understanding?

In OSCORE, the size (or style) of the replay window *is* fixed for each
security context (and where protocols for establishing an OSCORE context
lack the terminology to express it, defaults to 32 messages). That was
added precisely for this reason.


I've noted that there are a few points in the original mail that have
not been taken up, I'm just going through them and will follow up
shortly (as I don't suppose they fall under the "consider the rest
handled").

Kind regards
Christian

-- 
There's always a bigger fish.
  -- Qui-Gon Jinn