Re: [DNSOP] Benjamin Kaduk's Discuss on draft-ietf-dnsop-session-signal-12: (with DISCUSS and COMMENT)

Benjamin Kaduk <kaduk@mit.edu> Mon, 30 July 2018 18:16 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73EF3130EBD; Mon, 30 Jul 2018 11:16:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dv3F-7Ji3zPC; Mon, 30 Jul 2018 11:16:55 -0700 (PDT)
Received: from dmz-mailsec-scanner-3.mit.edu (dmz-mailsec-scanner-3.mit.edu [18.9.25.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D9D71130EAA; Mon, 30 Jul 2018 11:15:06 -0700 (PDT)
X-AuditID: 1209190e-2e9ff7000000527b-4e-5b5f55a879fc
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-3.mit.edu (Symantec Messaging Gateway) with SMTP id A4.9B.21115.9A55F5B5; Mon, 30 Jul 2018 14:15:05 -0400 (EDT)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id w6UIExlR024204; Mon, 30 Jul 2018 14:15:01 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id w6UIEtqL003738 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Mon, 30 Jul 2018 14:14:57 -0400
Date: Mon, 30 Jul 2018 13:14:55 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: "Mirja Kuehlewind (IETF)" <ietf@kuehlewind.net>
Cc: The IESG <iesg@ietf.org>, tjw.ietf@gmail.com, dnsop@ietf.org, dnsop-chairs@ietf.org, draft-ietf-dnsop-session-signal@ietf.org
Message-ID: <20180730181455.GH79679@kduck.kaduk.org>
References: <153270509617.32757.1191915890190419981.idtracker@ietfa.amsl.com> <30017004-FF22-40B1-AEB6-97899F2110BD@kuehlewind.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <30017004-FF22-40B1-AEB6-97899F2110BD@kuehlewind.net>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFupjleLIzCtJLcpLzFFi42IRYrdT0V0ZGh9tsLZH2uLN9kksFnffXGax mLd+DZPFjD8TmS1eXP/IbDGtbTOzA5vHzll32T2WLPnJ5NHycSFrAHMUl01Kak5mWWqRvl0C V8aPFT0sBbM5K97MsmlgXM3excjJISFgIvF66XZmEFtIYDGTxMn59V2MXED2RkaJbx0/WCCc q0wS187/YwOpYhFQlZjZ+5YRxGYTUJFo6L4M1i0iYCxxePJ3VhCbWaCLUaKvPQLEFhbIlJg1 +zdYDS/QtqO7/0Bta2WUOHorByIuKHFy5hMWiF4tiRv/XjJ1MXIA2dISy/9xgIQ5BZwk9q/u ZgKxRQWUJfb2HWKfwCgwC0n3LCTdsxC6FzAyr2KUTcmt0s1NzMwpTk3WLU5OzMtLLdI11svN LNFLTSndxAgKak5Jvh2Mkxq8DzEKcDAq8fB6aMVHC7EmlhVX5h5ilORgUhLl/S8PFOJLyk+p zEgszogvKs1JLT7EKMHBrCTCayMDlONNSaysSi3Kh0lJc7AoifPeqwmPFhJITyxJzU5NLUgt gsnKcHAoSfDeDgFqFCxKTU+tSMvMKUFIM3FwggznARq+HqSGt7ggMbc4Mx0if4pRl+PP+6mT mIVY8vLzUqXEefmA6URIAKQoozQPbg4oGUlk7695xSgO9JYwrz3IKB5gIoOb9ApoCRPQEu2Q WJAlJYkIKakGxnrGe/pRPKGJ5yc2fXqwKObEBk/nGv+rjie/TPgqf7Es0Z6Vx/PSVjZJrpub tVMll544WKtnxWa62p4/ac+qKU9ffN/0PcNUcu9djskfO5y7jHOm53y/tIdb7UT+i7lJHvdX LLCZf2ix6e4mJes5eS2PpgeuP+H9ZuPkXn7xSaxGnQYRhssiriuxFGckGmoxFxUnAgC7+wBH IQMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/FG_dDS589102lzmJRBvo6cT7QVM>
Subject: Re: [DNSOP] Benjamin Kaduk's Discuss on draft-ietf-dnsop-session-signal-12: (with DISCUSS and COMMENT)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Jul 2018 18:16:58 -0000

Hi Mirja,

On Mon, Jul 30, 2018 at 08:11:52PM +0200, Mirja Kuehlewind (IETF) wrote:
> Hi Ben, hi all,
> 
> as you summoned an TSV AD...
> 
> > Am 27.07.2018 um 17:24 schrieb Benjamin Kaduk <kaduk@MIT.EDU>:
> > 
> > I should probably leave this to my (transport-area?) colleagues to discuss
> > further, but I'm not sure that the interaction of this mechanism with
> > high-RTT connections is fully covered -- for example, the inactivity
> > timeout in Section 6.4(.x) could behave poorly when the timeout is set to a
> > smaller value than the RTT, as the server would potentially end up starting
> > the "forcibly abort" process (and potentially causing the client to lose
> > for an hour) because the server's timer starts when it sends the DSO
> > response that initiates its idea of the session, and would not recieve
> > graceful shutdown messages from a properly-behaving client in time.
> 
> My understanding is that they require a minimum time-out of 5 second at the server side, which seems reasonably safe to me. However, maybe this could be further clarified or explained in the doc.

I'm happy to defer to your expertise -- thanks!

-Benjamin