Re: [Detnet] Secdir last call review of draft-ietf-detnet-mpls-over-udp-ip-06

"Black, David" <David.Black@dell.com> Thu, 01 October 2020 19:35 UTC

Return-Path: <David.Black@dell.com>
X-Original-To: detnet@ietfa.amsl.com
Delivered-To: detnet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A8FC3A005C; Thu, 1 Oct 2020 12:35:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=dell.com header.b=j3/Q4nuy; dkim=pass (1024-bit key) header.d=dell.onmicrosoft.com header.b=AABvcGLj
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KCAzoBm2kkIx; Thu, 1 Oct 2020 12:35:48 -0700 (PDT)
Received: from mx0a-00154904.pphosted.com (mx0a-00154904.pphosted.com [148.163.133.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0CA963A003F; Thu, 1 Oct 2020 12:35:47 -0700 (PDT)
Received: from pps.filterd (m0170389.ppops.net [127.0.0.1]) by mx0a-00154904.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 091JM5Vq001548; Thu, 1 Oct 2020 15:35:41 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dell.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=smtpout1; bh=R1REqzhthhYwq8hL6AbQJqZEbcxvlwyFuhuBdCMEUkw=; b=j3/Q4nuy7Vhgi2cglhmL8yRW8sRKcqFggORP8Wzd5WYHWnegnNg6Fuiyn2ddm0/PUaaM 0LP1thxHfaJQ/qeAkPHl6kbYlnoxeVGojAuIURsN2HM1go7AsHzNSVejg2tuk2rhSDSd qdu26/4hudPKgZ/7oXxBfy4i/TB+tlkwQP+P0t0YpTgU/w01o6XMNEhuXZhIUgEC7VVD 5VXwdQIq1W164ExSZ8OxhnwnjmHRxjceGGs5cLi/F+qcskgXz+GE47tYmGdxeuPU2uIi oZNes8jyTshvGzNmYXQtmq5CtcOf2M/8ZWZdVQJ0/mBgahMqwjNLtV8V3rr1NflmYqRA nA==
Received: from mx0b-00154901.pphosted.com (mx0b-00154901.pphosted.com [67.231.157.37]) by mx0a-00154904.pphosted.com with ESMTP id 33t1nm363e-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 01 Oct 2020 15:35:41 -0400
Received: from pps.filterd (m0134318.ppops.net [127.0.0.1]) by mx0a-00154901.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 091JYtbX051679; Thu, 1 Oct 2020 15:35:40 -0400
Received: from nam04-sn1-obe.outbound.protection.outlook.com (mail-sn1nam04lp2053.outbound.protection.outlook.com [104.47.44.53]) by mx0a-00154901.pphosted.com with ESMTP id 33wmkj0pr7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 01 Oct 2020 15:35:40 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=GVwfgFgp6XjnkuQAJIPiPA5N4/Sd1M152RJ6Fv382Wb/Arfnl4nqXC7218B/V8rT0Gco0w7vemry+f/5LLNwY2My7RcvoTcNCiEx4BpJy+KndqOG5MhBys/aYkuVeg6LKy7edV+vikbQiSPMnevVjCRByDL8wb6UPIKZ4ufhXvfjiDjkFRNqnDAGl4YayQVxlJGOd4hy5j1kqGl/ihpkMNw/rTcoi9SbirkNArqhqGT1la1SlneJMHFBozO0IXFZ3PJYH5F2sSuIGNZB2U4ifZAanL8xsKhsTbElX2cFniUOO93fFn2DCvnEyD0ajkHCGV4KQYoheTMivbVP9AMNgQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R1REqzhthhYwq8hL6AbQJqZEbcxvlwyFuhuBdCMEUkw=; b=Tex8w4UcIByQ4J9QZE2DGQTvkORedE0jX8jPlxUzasARZ4wQm1mn0GIgR8kuIvYreF6ny/BvKEJJktzjT4tJJLPgsj0ykImCXr0tjfSoNVerXd1xwWH34SouI1gsrUywqVq1Dmq53jLAry8DXhFRWBfRvzQ/CApeTHsrHXL6zCfXoDvDIRbfTLVGATvLQgZPceqwt6ayEjZ8r/7kxsp25bRjwoAsNIW2Ci3MvdQg2L8JFukVQDEoApDeup6wPflsApJSfT7/wdfTwzPFu/b3q0hzdIh4GqLSpA9LIuRbxlhgVRvMI3DBo4WGcdyhydz1ULn/xpBb7QajNPbb8ceR7A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=dell.com; dmarc=pass action=none header.from=dell.com; dkim=pass header.d=dell.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Dell.onmicrosoft.com; s=selector1-Dell-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R1REqzhthhYwq8hL6AbQJqZEbcxvlwyFuhuBdCMEUkw=; b=AABvcGLjwpjpbHdiyEjhZW87a4+b8BZ3edw9q/J4+bFR9KiXOuhdsPtrtg8G7h3ZmnImlTzY5YUaqYb2scZXZ/8fIGr1wUlHK6n/AH/Njhw58E5ru+ZU4aYMTlQiHI/xRT5fdi89+1FXM7M2gJT7YlpvM8tqiOvK8gUtMEiamb4=
Received: from MN2PR19MB4045.namprd19.prod.outlook.com (2603:10b6:208:1e4::9) by MN2PR19MB4061.namprd19.prod.outlook.com (2603:10b6:208:1ef::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3433.34; Thu, 1 Oct 2020 19:35:36 +0000
Received: from MN2PR19MB4045.namprd19.prod.outlook.com ([fe80::b423:5f36:f591:2fcd]) by MN2PR19MB4045.namprd19.prod.outlook.com ([fe80::b423:5f36:f591:2fcd%6]) with mapi id 15.20.3433.034; Thu, 1 Oct 2020 19:35:36 +0000
From: "Black, David" <David.Black@dell.com>
To: Stewart Bryant <stewart.bryant@gmail.com>, "Grossman, Ethan A." <eagros@dolby.com>
CC: "secdir@ietf.org" <secdir@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "detnet@ietf.org" <detnet@ietf.org>, "draft-ietf-detnet-mpls-over-udp-ip.all@ietf.org" <draft-ietf-detnet-mpls-over-udp-ip.all@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>, "Black, David" <David.Black@dell.com>
Thread-Topic: [Detnet] Secdir last call review of draft-ietf-detnet-mpls-over-udp-ip-06
Thread-Index: AQHWmAVHkKliTan2Cky0cNPan4qVfamDISEw
Date: Thu, 01 Oct 2020 19:35:36 +0000
Message-ID: <MN2PR19MB404579FE42A2EA751B56381783300@MN2PR19MB4045.namprd19.prod.outlook.com>
References: <160097130665.26261.15986068503995393539@ietfa.amsl.com> <BY5PR06MB6611BE0705F79CB6C4FE8883C4390@BY5PR06MB6611.namprd06.prod.outlook.com> <3D90BF69-C0F5-4538-B029-D6D189463100@gmail.com>
In-Reply-To: <3D90BF69-C0F5-4538-B029-D6D189463100@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_Enabled=True; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_SiteId=945c199a-83a2-4e80-9f8c-5a91be5752dd; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_Owner=david.black@emc.com; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_SetDate=2020-10-01T19:28:27.3431644Z; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_Name=External Public; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_Application=Microsoft Azure Information Protection; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_ActionId=f746dcf1-0135-4cdd-8a84-7fd8227feb67; MSIP_Label_17cb76b2-10b8-4fe1-93d4-2202842406cd_Extended_MSFT_Method=Manual
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=dell.com;
x-originating-ip: [72.74.71.221]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 785ffc23-4314-4c30-1b34-08d866412bab
x-ms-traffictypediagnostic: MN2PR19MB4061:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <MN2PR19MB40611F6D15F6860CAC35F05983300@MN2PR19MB4061.namprd19.prod.outlook.com>
x-exotenant: 2khUwGVqB6N9v58KS13ncyUmMJd8q4
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ePg6Ku6P1QgTizbtPiQwxd7rf9F2+Uh0z9e7oeTA2jWqFAEF61Xr3Wpks+GcqKWFYV02l5XZelmU/mqHeIG0Iqc68F7FyocltHi886LV7NOCbP2Yawr8tM2ArAvw6t+5uerZ3VoEx2/p9k+3Sa0UYqPRyMET/N+qjYROYak9UEalf7AA14xUNsKORZE0T0eB1C5beHmvpVp0oVRHHVVQlsiCAfE/lvWnXzPOXvdmUJxXzyyNiz6KTW1KtP0i8AZlLx19ir+ZOFIJ9Yuauh11GtRTYjrZ1kLy9GoMpbk6WBdWzrkSUZD3WP5JSHG9xQRtRgYJsQdxV04lXraW+X01ieEEhceH+G7S9FJ8FcdIJPaBwympwU+jdLYeCAPHzGUgA7rBbwpVRjWk1oB5pa6rGw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR19MB4045.namprd19.prod.outlook.com; PTR:; CAT:NONE; SFS:(39860400002)(136003)(396003)(376002)(346002)(366004)(54906003)(110136005)(8936002)(316002)(33656002)(186003)(26005)(83380400001)(966005)(2906002)(9686003)(107886003)(4326008)(55016002)(8676002)(478600001)(66946007)(66476007)(76116006)(53546011)(66556008)(64756008)(5660300002)(86362001)(7696005)(71200400001)(52536014)(6506007)(786003)(83080400001)(66446008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: oQh3cHAX8OecK5eM5Vw8l7Pi/r68K4UUK4z1usVqtPT+oPa2urRx4XtJ+GS6q2H8HJ3eVWPEVI0fcVF1vlKX7lZ5UkGhCwF9enhZSH73rUcrE8eGW6l2V1t7D0yJ5ViBoIPeH3zm5H8tjiNt8DGCrLX1p1gxZ+8TyqKa5mhRHI3e2yrzCDvZwLDEctgUOpV7G8XYWGXiHtiFoUZPLJazS9kIMNJ+aJAEdO9oCIHwIbur/ybaMZWUFcQ2ha5GAKkuuLuLTlo5DsfAfm5/A+8lt2nrq7JHNohWBKvBOs4LxAfjDDelb5dbxLJXXEPUWtlelHQ8OY2K1W6PHNO87qxc/D/pgQN0mQgwejpBulDnwOH28LJRLe1wBV6rVp8/XtvK4qIkrglmrC7D252spnIpZNxlkedk6V+5cQfTTODbmng6vPc5iZZO8b6UdqNuq/M9ThAwZsdnWWGUtk5naPU1FaM3LeN1i1mA9HT4G3jlpETJwQxkXVOMxr8IMl7CrG4PN6azFdcz0Vjdj8pIKWCy7Xy3InAVfJtXYYtqO2+IjaQLsyBodqcjNhI8+FoPZiNnR89KQcBewH9osXPLswN5mB2PtEPAq7AbAFN4gbL9Ls4zQX0nuAWBPEawuBi4A2qLH/L3yWgM8+VZrQBmAEkgNQ==
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: Dell.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR19MB4045.namprd19.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 785ffc23-4314-4c30-1b34-08d866412bab
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Oct 2020 19:35:36.3142 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 945c199a-83a2-4e80-9f8c-5a91be5752dd
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: +naaxFZWTuKbhIEJd+1957P/3pwkQbm7tJlWoVRprQc+z5WZhwagIYGKg6gFUgbr1Z4OfY1fRbQU+BjTsJRh6A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR19MB4061
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.235, 18.0.687 definitions=2020-10-01_07:2020-10-01, 2020-10-01 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 mlxscore=0 phishscore=0 lowpriorityscore=0 adultscore=0 spamscore=0 mlxlogscore=999 suspectscore=0 clxscore=1011 priorityscore=1501 malwarescore=0 impostorscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2006250000 definitions=main-2010010157
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 bulkscore=0 malwarescore=0 mlxlogscore=999 phishscore=0 spamscore=0 suspectscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2006250000 definitions=main-2010010157
Archived-At: <https://mailarchive.ietf.org/arch/msg/detnet/RVNmBlZ6c0yK27izvcmG1lvCjl8>
Subject: Re: [Detnet] Secdir last call review of draft-ietf-detnet-mpls-over-udp-ip-06
X-BeenThere: detnet@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussions on Deterministic Networking BoF and Proposed WG <detnet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/detnet>, <mailto:detnet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/detnet/>
List-Post: <mailto:detnet@ietf.org>
List-Help: <mailto:detnet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/detnet>, <mailto:detnet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Oct 2020 19:35:50 -0000

Playing devil's advocate for a moment ...

> I would be rather surprised if anyone tried to run a deterministic application over
> TCP.
> 
> TCP would undo all the temporal determinism and or course it looks after packet
> loss.

... IF the DetNet service defines packet loss as a failure case, i.e., something that can't happen unless something in the network has actually failed and the preferred failure behavior is late delivery rather than non-delivery of impacted data, THEN TCP may be useful/appropriate.  OTOH, use of TCP increases the DetNet attack surface, as (in contrast to UDP), causing a drop or otherwise triggering retransmission becomes a way to attack the DetNet service by increasing the amount of traffic sent into limited reserved network capacity and also by delaying delivery of received data to the deterministic application.

I've lost track of the original context, so I'm not able to suggest specific text and where to add it or make changes.

Thanks, --David

> -----Original Message-----
> From: detnet <detnet-bounces@ietf.org> On Behalf Of Stewart Bryant
> Sent: Thursday, October 1, 2020 11:12 AM
> To: Grossman, Ethan A.
> Cc: secdir@ietf.org; last-call@ietf.org; Stewart Bryant; detnet@ietf.org; draft-
> ietf-detnet-mpls-over-udp-ip.all@ietf.org; Stephen Farrell
> Subject: Re: [Detnet] Secdir last call review of draft-ietf-detnet-mpls-over-udp-
> ip-06
> 
> 
> [EXTERNAL EMAIL]
> 
> 
> 
> > On 24 Sep 2020, at 21:28, Grossman, Ethan A. <eagros@dolby.com> wrote:
> >
> > Thanks Stephen. FWIW it isn't too late to add some text to the DetNet Security
> draft regarding DetNet over UDP, if someone can think up something useful to
> say. I suppose one could simply mention UDP in the same breath as TCP (implying
> that the same general security guidelines apply, if that's our stance).
> > Any thoughts (from anyone)?
> 
> Ethan
> 
> I would be rather surprised if anyone tried to run a deterministic application over
> TCP.
> 
> TCP would undo all the temporal determinism and or course it looks after packet
> loss.
> 
> - Stewart
> 
> 
> 
> _______________________________________________
> detnet mailing list
> detnet@ietf.org
> https://www.ietf.org/mailman/listinfo/detnet