Re: [GROW] Ben Campbell's Yes on draft-ietf-grow-bgp-gshut-12: (with COMMENT)

Job Snijders <job@ntt.net> Thu, 14 December 2017 17:20 UTC

Return-Path: <job@instituut.net>
X-Original-To: grow@ietfa.amsl.com
Delivered-To: grow@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A7CD9129443 for <grow@ietfa.amsl.com>; Thu, 14 Dec 2017 09:20:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.417
X-Spam-Level:
X-Spam-Status: No, score=-1.417 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oJa7fyHcT3Mt for <grow@ietfa.amsl.com>; Thu, 14 Dec 2017 09:20:53 -0800 (PST)
Received: from mail-wm0-f46.google.com (mail-wm0-f46.google.com [74.125.82.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44F7E12943C for <grow@ietf.org>; Thu, 14 Dec 2017 09:20:53 -0800 (PST)
Received: by mail-wm0-f46.google.com with SMTP id 64so12833410wme.3 for <grow@ietf.org>; Thu, 14 Dec 2017 09:20:53 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=37TAVrW/noubYf2OqaTgqF1MXM69Dkf6ZQsT7FcBadg=; b=R082ljWzC5SuBvaPGYyJkLYLtHdT3S30X9o2i3lOq92eSO3w7SzOahoobNB887AR3M uRA86MK8fMJUcGqg3do6qKBu+t1qghLcH+PIjdtw44n9pNsyaJWwusbOU/XC3LPEyI39 BSt30EPk4bMDSmrYKu/oQFmfWG5XkKLKpq++fg1lROJjDgNnccEKvEzYIUcMYkNF44pA mf6XwBlaXLmCDR2LPUeOQmIBHRd0PfVA+OgFGikrqCMPRGmeRaeQsPZlxWG6DrwRV5H0 +F4u7Ic9EL+/RairCyV+utbTTl9hNDQneIlD90TJYKtidUBIM6d3AwvFP8yhMS7k317N 7HXQ==
X-Gm-Message-State: AKGB3mIymLgjVqAFHaZACg82hpKV5CwGXBl7I5/y73nPt4aiUM74ts42 yX6NPRNvRCBx9cv0kn5EX44ArQ==
X-Google-Smtp-Source: ACJfBot/VshkszdEF6001glcecLwl+NWIjwYvMmzK7xhtiwZEHgqnG/fRgYAzwIUf9LZtHEQAPJUyw==
X-Received: by 10.80.193.9 with SMTP id l9mr13283011edf.176.1513272051623; Thu, 14 Dec 2017 09:20:51 -0800 (PST)
Received: from vurt.meerval.net (vurt.meerval.net. [192.147.168.22]) by smtp.gmail.com with ESMTPSA id k18sm3897459eda.20.2017.12.14.09.20.42 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Thu, 14 Dec 2017 09:20:42 -0800 (PST)
Received: from localhost (vurt.meerval.net [local]) by vurt.meerval.net (OpenSMTPD) with ESMTPA id 8fc30f00; Thu, 14 Dec 2017 17:20:41 +0000 (UTC)
Date: Thu, 14 Dec 2017 17:20:41 +0000
From: Job Snijders <job@ntt.net>
To: "Smith, Donald" <Donald.Smith@CenturyLink.com>
Cc: "bruno.decraene@orange.com" <bruno.decraene@orange.com>, Ben Campbell <ben@nostrum.com>, "grow-chairs@ietf.org" <grow-chairs@ietf.org>, "draft-ietf-grow-bgp-gshut@ietf.org" <draft-ietf-grow-bgp-gshut@ietf.org>, "grow@ietf.org" <grow@ietf.org>, The IESG <iesg@ietf.org>
Message-ID: <20171214172041.GO95845@vurt.meerval.net>
References: <151322570465.6210.17202569330170241275.idtracker@ietfa.amsl.com> <15461_1513262548_5A328DD4_15461_64_1_53C29892C857584299CBF5D05346208A47920D36@OPEXCLILM21.corporate.adroot.infra.ftgroup> <68EFACB32CF4464298EA2779B058889D53D3936E@PDDCWMBXEX503.ctl.intranet>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <68EFACB32CF4464298EA2779B058889D53D3936E@PDDCWMBXEX503.ctl.intranet>
X-Clacks-Overhead: GNU Terry Pratchett
User-Agent: Mutt/1.9.1 (2017-09-22)
Archived-At: <https://mailarchive.ietf.org/arch/msg/grow/XsqBkQBZxYj7dyJzcMY1kBYmc7E>
Subject: Re: [GROW] Ben Campbell's Yes on draft-ietf-grow-bgp-gshut-12: (with COMMENT)
X-BeenThere: grow@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Grow Working Group Mailing List <grow.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/grow>, <mailto:grow-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/grow/>
List-Post: <mailto:grow@ietf.org>
List-Help: <mailto:grow-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/grow>, <mailto:grow-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Dec 2017 17:20:54 -0000

On Thu, Dec 14, 2017 at 05:12:52PM +0000, Smith, Donald wrote:
> I don't see anything around MD5/TCPAO authentication.
> 
> >From https://tools.ietf.org/html/rfc6198
> 
> " Security considerations MUST be addressed by the proposed solutions.
>   In particular, they SHOULD address the issues of bogus g-shut
>   messages and how they would affect the network(s), as well as the
>   impact of hiding a g-shut message so that g-shut is not performed."
> 
> I may have missed it somewhere?

I have trouble parsing this requirements text.

What makes a "bogus g-shut" a "bogus g-shut"?

How is 'hiding' (I interpret this as 'removing the gshut community) a
g-shut any different than the other BGP speaker not supporting g-shut?

How is any of this different than NO_EXPORT or NO_ADVERTISE?

Kind regards,

Job