Re: [GROW] Eric Rescorla's No Objection on draft-ietf-grow-bgp-reject-08: (with COMMENT)

Job Snijders <job@ntt.net> Wed, 07 June 2017 23:34 UTC

Return-Path: <job@instituut.net>
X-Original-To: grow@ietfa.amsl.com
Delivered-To: grow@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2F4DD128CD5 for <grow@ietfa.amsl.com>; Wed, 7 Jun 2017 16:34:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CZvFa2WhdREi for <grow@ietfa.amsl.com>; Wed, 7 Jun 2017 16:34:55 -0700 (PDT)
Received: from mail-yb0-f176.google.com (mail-yb0-f176.google.com [209.85.213.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9E71C1293E3 for <grow@ietf.org>; Wed, 7 Jun 2017 16:34:54 -0700 (PDT)
Received: by mail-yb0-f176.google.com with SMTP id f192so6211138yba.2 for <grow@ietf.org>; Wed, 07 Jun 2017 16:34:54 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=xpfuIPgehsqyY7Rhi8j2BWQX+x6Z4SHrpEDbJe4FmjI=; b=i91XKHjzLf3BDOhDNMlZAVywjPiz5zzCOd8u3o7uKVaHJclMJXhHDlFYN4MyMPsqGe WBceA8XrusLHUMFe+LZ1Mbfe9ye2pRo3zIDyxj4ppF8RAbGg5RqQYsT1zIokT2UZkVBz kh/WiT2whqAI5m9R0BeT1jm4KAmrKulBXxLpDP1ouY9QJDCqHzPE6ppTVh+9wlOFAFWm BZdLcd9nYU9TdgS5aE54wSKm1nw7svRUcjh9S9qrSNcC1qBzeHeScdPY9uGvc9m1pR6E uPzp3EYBy2J00r/5to1W24CCeRCrLluJ70JaXrgPKZxZHEey1nVwfu6/9UUYYiwiobZO qd6w==
X-Gm-Message-State: AODbwcAXJbpoMtw1CZ7iQxcHJZW7GWlC5AKKFWpk7KUlXEOU5jN2in3T P41k6SPpYdQDEJAq
X-Received: by 10.37.171.113 with SMTP id u104mr9190360ybi.78.1496878493608; Wed, 07 Jun 2017 16:34:53 -0700 (PDT)
Received: from localhost ([2620:0:ce0:101:e085:5675:3ffb:1aa5]) by smtp.gmail.com with ESMTPSA id x18sm1093400ywg.3.2017.06.07.16.34.52 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 07 Jun 2017 16:34:52 -0700 (PDT)
Date: Wed, 07 Jun 2017 16:34:51 -0700
From: Job Snijders <job@ntt.net>
To: Eric Rescorla <ekr@rtfm.com>
Cc: The IESG <iesg@ietf.org>, draft-ietf-grow-bgp-reject@ietf.org, Christopher Morrow <christopher.morrow@gmail.com>, aretana@cisco.com, grow-chairs@ietf.org, grow@ietf.org
Message-ID: <20170607233451.v6qtyxoxo364vowy@dhcp-222-168.meetings.nanog.org>
References: <149677140103.3863.5658765780389706738.idtracker@ietfa.amsl.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <149677140103.3863.5658765780389706738.idtracker@ietfa.amsl.com>
X-Clacks-Overhead: GNU Terry Pratchett
User-Agent: NeoMutt/20170306 (1.8.0)
Archived-At: <https://mailarchive.ietf.org/arch/msg/grow/VeSkeDNiZbhI-b24lZoJxalAZi0>
Subject: Re: [GROW] Eric Rescorla's No Objection on draft-ietf-grow-bgp-reject-08: (with COMMENT)
X-BeenThere: grow@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Grow Working Group Mailing List <grow.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/grow>, <mailto:grow-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/grow/>
List-Post: <mailto:grow@ietf.org>
List-Help: <mailto:grow-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/grow>, <mailto:grow-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jun 2017 23:34:57 -0000

Hi Eric,

On Tue, Jun 06, 2017 at 10:50:01AM -0700, Eric Rescorla wrote:
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
> 
> I am having a little trouble reading Appendix A.
> 
> If I understand correctly, the idea is:
> 
> - In version N, you have a behavior X
> - In version N+1, you introduce a setting S with default value S=X
> - In version N+2 you change the default to S=!X
> 
> However, the text says that "installations upgraded from release N+1
> will adhere to the previous insecure behavior"
> 
> Do you need to say that in N+1, you save the value S=X so that in N+1,
> it continues to apply?

If in N+1 you save S=X, then in N+2, if S is defined as X, behaviour X
will apply. If S is not defined, or defined otherwise (like with a fresh
install, not an upgrade), you will have !X behaviour.

It kind of depends on the implementation and configuration paradigm
whether this advice can be applicable, hence why we flagged it as "This
appendix is non-normative."

Kind regards,

Job