Re: [core] Disclosing Implementation Information: draft-bormann-t2trg-rel-impl-01.txt

Klaus Hartke <klaus.hartke@ericsson.com> Sun, 29 March 2020 12:08 UTC

Return-Path: <klaus.hartke@ericsson.com>
X-Original-To: core@ietfa.amsl.com
Delivered-To: core@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B5C9C3A03FC for <core@ietfa.amsl.com>; Sun, 29 Mar 2020 05:08:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.201
X-Spam-Level:
X-Spam-Status: No, score=-0.201 tagged_above=-999 required=5 tests=[DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bs6Dm0_wuK3H for <core@ietfa.amsl.com>; Sun, 29 Mar 2020 05:08:53 -0700 (PDT)
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (mail-eopbgr140077.outbound.protection.outlook.com [40.107.14.77]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 35E353A03F8 for <core@ietf.org>; Sun, 29 Mar 2020 05:08:53 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FtpLEZFQzEFCFfOKgwvC6/8OC++yRy83j2330IRnyMPJESLh8FmQcU16JSyAxyBi4b5cU6+Kat5o/jAk9ni4DG8t16sBCQxooPeh+9PF5ZL3JJsEAwF7Iw7y83HHcNHQkIa3r+4vVaVPfA+kfVjcgrS6DnoD8QjwLm2RexxM4kb3Vb+mdw/3OnfmDYMxgsZnTsfT4d5AzsJAkBZZyqdY0Tmv1sPZsW/8f9ryLyRh6DqjGy94Xo/ZP8l04mTZi0rHgLv3YkotSQqyTdB32RvuVPLJxg+F8zC43zgrVmXc19EtgnIwdQifPW9EndPkq6hDOOm3LXDGhUo5el/ocIl/eA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=F2QD24C0NIUzdB+GWKebjdxWOhVmwVHzNT8cxeOTqJY=; b=YiWi+jy3lTt7U+uJZO442rf+j+Vf9VFeBB2sGd2LtGiuHgnHSGMUerVIuLEFe03giBhRXqGXb2cPA343Uz91LQVagFJaXFBKemrGaOOMUVhtRaCXKs5BGV0QnRf3Z5OcuhRMIflQkkQ5nDHdCWbxfeKHNtfKq9U1PnSvC+LE0VosMuE9W0volrnK94rtvOR3A4snmj6ZyK6WJYZZewp519ghZGojbNylp6+YeonHpky41wtCJslhXRpnuVDvG/j4i3th3N4R8+xSa+FSYjV6sRhhIRsts6GXhCTkpFb9xns3q7j4G+VG3iGgH8h5Uifj95DXcQZHLbXgTEPVboylAA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=F2QD24C0NIUzdB+GWKebjdxWOhVmwVHzNT8cxeOTqJY=; b=kiRADioUvE0LQSXS1jmTU3H8fASmL12Xdb+1IsSHTO/dryYqW2Q33iAMZTk86BgpmiyIZDBp/8QqKqm0D7CaDdCul0XQzPqvwFWnDdQ7m7H80qaB3RGvS3VoAS+wPTky+QxoYac/PMk9mTuqdf+sOkU65rN/kuAphBkMZZVuMD4=
Received: from HE1PR07MB4346.eurprd07.prod.outlook.com (20.176.162.138) by HE1PR07MB4395.eurprd07.prod.outlook.com (20.176.165.161) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2878.12; Sun, 29 Mar 2020 12:08:50 +0000
Received: from HE1PR07MB4346.eurprd07.prod.outlook.com ([fe80::28b5:c698:a287:d4c1]) by HE1PR07MB4346.eurprd07.prod.outlook.com ([fe80::28b5:c698:a287:d4c1%5]) with mapi id 15.20.2856.019; Sun, 29 Mar 2020 12:08:50 +0000
From: Klaus Hartke <klaus.hartke@ericsson.com>
To: Carsten Bormann <cabo@tzi.org>, "t2trg@irtf.org" <t2trg@irtf.org>, "core@ietf.org WG" <core@ietf.org>
Thread-Topic: [core] Disclosing Implementation Information: draft-bormann-t2trg-rel-impl-01.txt
Thread-Index: AQHWBFMj0F/Fe0cdqkuCeWtPUwBOlKhfeuAg
Date: Sun, 29 Mar 2020 12:08:50 +0000
Message-ID: <HE1PR07MB4346BBD0DC88E28D1CAD1D4DE6CA0@HE1PR07MB4346.eurprd07.prod.outlook.com>
References: <158532472527.24402.7156077840539978248@ietfa.amsl.com> <C1A0817E-8243-49A7-9CEA-BD38270C5028@tzi.org>
In-Reply-To: <C1A0817E-8243-49A7-9CEA-BD38270C5028@tzi.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=klaus.hartke@ericsson.com;
x-originating-ip: [145.14.112.90]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: b9897aa0-8d0e-4401-0eeb-08d7d3d9f154
x-ms-traffictypediagnostic: HE1PR07MB4395:
x-microsoft-antispam-prvs: <HE1PR07MB43952CF17037299779F3308FE6CA0@HE1PR07MB4395.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 035748864E
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR07MB4346.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(10009020)(4636009)(39860400002)(366004)(346002)(376002)(396003)(136003)(7696005)(5660300002)(26005)(33656002)(186003)(8676002)(86362001)(53546011)(66946007)(76116006)(66476007)(66556008)(64756008)(66446008)(52536014)(19627235002)(6506007)(71200400001)(110136005)(316002)(2906002)(44832011)(55016002)(9686003)(478600001)(81156014)(8936002)(81166006); DIR:OUT; SFP:1101;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: AJAnYEK2LgCcpwBtMPX8cCjqbvHs/CNlNJywJPVHifPv0R+0zrVZyTXGEtYr/iCL2Uss2HZx6Y5s2chz4ZExQHNNIVWClE+GpVmNUxHM3DxbnLOgLbxbGXGXAIDLM/KWQRra8UnXOF5P8T0rS9hk/FqUmfcLJB/jgwumIFrkAxchm04tHZrfCXhR2Nam4FklcBao7pnsXSCeejwyNaJdsGnYCsaRt0XRV99iLr31JjcvN3M1Ce8Ngqi8Xkz18cnYtvpOWwxMGvqce6733sIIRXDOHQSj/9uSGkLGUQ7IhjZeexNomFDmQQgKvnNGfHlynjHtq2ABYp+eimDyj3oSUgr45DgUevcTSVj6Jm02/oEtpUaEkBG45IYeQduPhN6HhSM4fmF5X9yY3lOtTBOeI5ZOI42pVA5Ngtt5WIlwF1vNL+A+CwqhtxWOrzIXAkgj
x-ms-exchange-antispam-messagedata: J3FZdPI/pEa8/mcaFuO9HUaQ89IIxcmlayXezsGDGerXwueqtP0DQq83/++lds572E1mVnnucvsk3QUcge6dp6BnktbQ3CwDAWr2QOZTkvtym+WvsRf0FgNDhgerRZE50M79lCrSRGnvGiFtCUoGYA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: b9897aa0-8d0e-4401-0eeb-08d7d3d9f154
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Mar 2020 12:08:50.5596 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: mer4DbiqU8SWkDGdt3N+p4CieZ7ZIXEOJLWuizh8brSbfcvRwOhz56w0gmtg1HKNZ0jYTWRtlMG7Kb0wchybRA3rjkcFm7ElWKGR7/fAvgo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB4395
Archived-At: <https://mailarchive.ietf.org/arch/msg/core/4Fd0SifudO4IMLa3OUJbgiN2Bk0>
Subject: Re: [core] Disclosing Implementation Information: draft-bormann-t2trg-rel-impl-01.txt
X-BeenThere: core@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Constrained RESTful Environments \(CoRE\) Working Group list" <core.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/core>, <mailto:core-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/core/>
List-Post: <mailto:core@ietf.org>
List-Help: <mailto:core-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/core>, <mailto:core-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Mar 2020 12:08:55 -0000

Would it make sense to standardize how to exactly express the information about the implementation and version? Being able to find that information seems useful -- but incomplete :-)

And then I'm wondering if there's a risk that we might end up with something like this in the future:

1. Client makes a GET request on the implementation information resource
2. Server returns a string like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
3. Client behaves differently based on the implementation information

Klaus


> -----Original Message-----
> From: core <core-bounces@ietf.org> On Behalf Of Carsten Bormann
> Sent: Friday, March 27, 2020 5:13 PM
> To: t2trg@irtf.org; core@ietf.org WG <core@ietf.org>
> Subject: [core] Disclosing Implementation Information: draft-bormann-t2trg-
> rel-impl-01.txt
>
> In 2018, we had a discussion about providing self-description information that
> tells a client something about the implementation (and version) of the
> server.  So I wrote a brief draft, and I seem to remember everybody nodded,
> but it wasn’t quite clear whether that was because they agreed or because
> they fell asleep.
>
> By now, it has become more clear that disclosure of implementation
> information can be quite useful.  Actually, we already have RFC 8520 (MUD)
> for some very specific information of this kind.  A more free-form version still
> seems useful, and can use Web Linking (RFC 8288) and Link-Format (RFC
> 6690) so the specification itself is quite minimal.
>
> So I have added some security considerations (pointing out, among other
> things, that this disclosure is not always desirable) and cleaned up the text a
> bit.  See links below.
>
> Comments (+1, -1, or actual text) would be welcome, both from T2TRG and
> from CoRE.  It seems the CoRE working group might want to consider working
> group adoption of this draft or a next version, at which time it would
> transition from the RG context to the WG.
>
> Grüße, Carsten