Re: [Idr] WG Last Call on Extened Message Support

<bruno.decraene@orange.com> Thu, 14 February 2019 09:47 UTC

Return-Path: <bruno.decraene@orange.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 69E5413106C for <idr@ietfa.amsl.com>; Thu, 14 Feb 2019 01:47:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NZlyx4fkav5Z for <idr@ietfa.amsl.com>; Thu, 14 Feb 2019 01:47:13 -0800 (PST)
Received: from orange.com (mta136.mail.business.static.orange.com [80.12.70.36]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E1C812D4E9 for <idr@ietf.org>; Thu, 14 Feb 2019 01:47:13 -0800 (PST)
Received: from opfednr03.francetelecom.fr (unknown [xx.xx.xx.67]) by opfednr25.francetelecom.fr (ESMTP service) with ESMTP id 440Wl331H9zCrpd; Thu, 14 Feb 2019 10:47:11 +0100 (CET)
Received: from Exchangemail-eme6.itn.ftgroup (unknown [xx.xx.13.70]) by opfednr03.francetelecom.fr (ESMTP service) with ESMTP id 440Wl32HHFzDq7J; Thu, 14 Feb 2019 10:47:11 +0100 (CET)
Received: from OPEXCAUBM43.corporate.adroot.infra.ftgroup ([fe80::b846:2467:1591:5d9d]) by OPEXCAUBM33.corporate.adroot.infra.ftgroup ([fe80::c911:d24e:cc19:afa7%21]) with mapi id 14.03.0435.000; Thu, 14 Feb 2019 10:47:11 +0100
From: bruno.decraene@orange.com
To: Randy Bush <randy@psg.com>
CC: Susan Hares <shares@ndzh.com>, "idr@ietf.org" <idr@ietf.org>
Thread-Topic: [Idr] WG Last Call on Extened Message Support
Thread-Index: AQHUw+Qj1bTPsyO86K1JuAQ7q/LpfaXe91yg
Date: Thu, 14 Feb 2019 09:47:10 +0000
Message-ID: <3465_1550137631_5C65391F_3465_424_1_53C29892C857584299CBF5D05346208A489D4177@OPEXCAUBM43.corporate.adroot.infra.ftgroup>
References: <007b01d4b7c6$5b002210$11006630$@ndzh.com> <16873_1548768802_5C505622_16873_491_9_53C29892C857584299CBF5D05346208A489AE8F1@OPEXCAUBM43.corporate.adroot.infra.ftgroup> <m27ee3jrqr.wl-randy@psg.com>
In-Reply-To: <m27ee3jrqr.wl-randy@psg.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.114.13.247]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/8xRjaWzE1dSmj-plFdHdF2TajnM>
Subject: Re: [Idr] WG Last Call on Extened Message Support
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Feb 2019 09:47:15 -0000

Dear Randy,

> -----Original Message-----
> From: Randy Bush [mailto:randy@psg.com] 
> Sent: Wednesday, February 13, 2019 10:36 PM
> 
> dear reviewer #2:
> 
> excuse, this has been in an edit buffer for weeks.

No problem. Thanks for the reply.
 
> > [I-D.ietf-sidr-bgpsec-protocol<https://tools.ietf.org/html/draft-ietf-idr-bgp-extended-messages-27#ref-I-D.ietf-sidr-bgpsec-protocol>
> > is now RFC 8205 (thanks for updating the reference). It has removed the normative/any reference to
> > draft-ietf-idr-bgp-extended-messages. So presumably BGP Sec does not need draft-ietf-idr-bgp-extended-messages. 
> > Can we have an update on this?
> 
> extended-messages authors had $dayjobs and did not have the stamina for
> the level of dos in the sidr wg.  they were desperate to get bgpsec our
> the door and idr was holding them hostage.  and it's not like bgpsec is
> just around the corner.
> 
> > Can the introduction of draft-ietf-idr-bgp-extended-messages be
> > updated to introduce on the real reasons/needs?
> 
> would you like it if we threw in bgp-ls?  no extra charge.

-28 looks good to me.
 
> > §3 says "A peer which does not advertise this capability MUST NOT send BGP
> >    Extended Messages, and BGP Extended Messages MUST NOT be sent to it."
> > 
> > Fine. Text in §4 should probably be aligned with the above .e.g.
> > 
> > OLD: A BGP speaker
> >    MAY send Extended Messages to its peer only if it has received the
> >    Extended Message Capability from that peer.
> > 
> > NEW:
> > A BGP speaker
> >    MAY send Extended Messages to its peer only if it has sent and received the
> >    Extended Message Capability to and from that peer.
> 
> the intent was to allow simplexity, use of extended messages in one
> direction only.  in retrospect, this may be too subtle/clever.  it could
> be as you suggest if no one wants simplexity.

Both options works for me. My comment was that §3 and §4 did not seemed aligned on this point.
-28 looks good to me.
 
> > "   Applications generating information which might be encapsulated
> >    within BGP messages MUST limit the size of their payload to take the
> >    maximum message size into account."
> > 
> > I don't see what new behavior is been defined here. If there is none, I would suggest to remove this sentence
> 
> it was added to reaffirm what to you is obvious.  unless you really
> object, i see no harm in leaving it.

Whether this is obvious or not, this is true/applicable at least from RFC 4271. IOW, this draft does not change the point that the BGP message is limited in size.
Ok for leaving it.

> >    A BGP announcement will, in the normal case, propagate throughout the
> >    BGP speaking Internet; and there will undoubtedly be BGP speakers
> >    which do not have the Extended Message capability.  Therefore,
> >    putting an attribute which can not be decomposed to 4096 octets or
> >    less in an Extended Message is a likely path to routing failure.
> > 
> > The issue is not specific to attributes bigger than 4096 octets, but to BGP message whose length is bigger than 4096, irrespective of the size of each attribute.
> > Please elaborate on what you mean by "an attribute which can not be decomposed to 4096 octets"
> 
> a prefix announcement with 200 researcher-invents-massive-attribute? :)
> [ nanog joke ]

1) Taking the large community example, [RFC8092], this attribute could be bigger than 4096 octets. How would you handle this?
2) The problem is not limited to attribute bigger than 4096 octets. If you have one NLRI having an attribute of 2100 octets and an attribute of 2000 octets, how do you handle this?

> 
> > ---
> > "   It is RECOMMENDED that BGP protocol developers and implementers are
> >    conservative in their application and use of Extended Messages."
> > 
> > What does this mean exactly? That they don't use this extension? That they don't use this extension unless XX_TO BE SPECIFIED_XX?
> > 
> > ---
> >   Future protocol specifications will need to describe how to handle
> >    peers which can only accommodate 4096 octet messages.
> > 
> > Why is this limited to future specifications? A priori, using existing BGP mechanism (AFI/SAFI, attributes, * communities) one could exceed the size of 4096 octets. How does the BGP speaker supposed to behave in this case? This should be described in this specification. Note that this is not a case of error handling, as every BGP speaker is behaving as specified.

That is my main comment.

Thanks,
--Bruno

> > ----
> > Depending on the above specification, a section describing the operational consequences in a network (such as the Internet, BGP Enabled ServiceS/VPN networks) is probably needed. Possible consequences could be BGP NLRI being removed in the middle of such network, or (extended) community (such as Route Targets) been removed. Both having significant consequences on the availability provided by the network.
> > 
> > ---
> > §4
> > OLD: The Extended Message Capability only applies to all messages except for the OPEN message.
> > Probably
> > NEW: The Extended Message Capability applies to all message types except for the OPEN message (type 1).
> > ----
> > §8
> > 
> > "This extension to BGP does not change BGP's underlying security issues »
> > 
> > Before evaluating this, I think this document should first specified how a BGP messages bigger than 4096 octets is handled when it needs to be sent to a received not supporting this extension.
> > 
> > Nits:
> > OLD : to reduce compexity
> > NEW : to reduce complexity
> 
> i took some edits, tyvm.
> 
> randy

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.