Re: Call for Community Feedback: Retiring IETF FTP Service

Robert Moskowitz <rgm-ietf@htt-consult.com> Tue, 17 November 2020 20:44 UTC

Return-Path: <rgm-ietf@htt-consult.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DE5003A0980 for <ietf@ietfa.amsl.com>; Tue, 17 Nov 2020 12:44:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cKpxO6s5grUy for <ietf@ietfa.amsl.com>; Tue, 17 Nov 2020 12:44:45 -0800 (PST)
Received: from z9m9z.htt-consult.com (z9m9z.htt-consult.com [23.123.122.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 238193A097E for <ietf@ietf.org>; Tue, 17 Nov 2020 12:44:45 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by z9m9z.htt-consult.com (Postfix) with ESMTP id 55C066267D; Tue, 17 Nov 2020 15:44:43 -0500 (EST)
X-Virus-Scanned: amavisd-new at htt-consult.com
Received: from z9m9z.htt-consult.com ([127.0.0.1]) by localhost (z9m9z.htt-consult.com [127.0.0.1]) (amavisd-new, port 10024) with LMTP id GUtKu-+YLR4R; Tue, 17 Nov 2020 15:44:40 -0500 (EST)
Received: from lx140e.htt-consult.com (unknown [192.168.160.29]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by z9m9z.htt-consult.com (Postfix) with ESMTPSA id D582262653; Tue, 17 Nov 2020 15:44:39 -0500 (EST)
Subject: Re: Call for Community Feedback: Retiring IETF FTP Service
To: Roman Danyliw <rdd@cert.org>, Jared Mauch <jared@puck.nether.net>
Cc: Keith Moore <moore@network-heretics.com>, "ietf@ietf.org" <ietf@ietf.org>
References: <27b80ed2-76fb-aee7-f22d-de56019e9aa9@nostrum.com> <a8bdd67a-13ea-4433-aa38-9cfd48ea28da@network-heretics.com> <0e875497-9986-a0d9-8354-3eac26b7f882@nostrum.com> <a02e15f2-34fb-4124-7ba0-c0ee0070b39f@network-heretics.com> <6a29096e-c76e-9bde-388c-bf411b235346@nostrum.com> <6ff3c8a8-57c9-a278-51ce-ce24fd2dfc0e@network-heretics.com> <01RS3W7DNPHA005PTU@mauve.mrochek.com> <27622517-8EC3-44D1-BB21-1F2071BCA2C2@cable.comcast.com> <5dc7b0d1-d565-92c5-293e-093040596f35@network-heretics.com> <4b46fe4f-0b5b-dbf4-9bd5-f0a4a6ee30c9@nostrum.com> <20201117160155.GB2146486@puck.nether.net> <fd4c8fde412341e0b190004874fcbaac@cert.org>
From: Robert Moskowitz <rgm-ietf@htt-consult.com>
Message-ID: <77ab1b2d-072b-1cc5-d5a8-4c451acbd9c7@htt-consult.com>
Date: Tue, 17 Nov 2020 15:44:38 -0500
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.4.0
MIME-Version: 1.0
In-Reply-To: <fd4c8fde412341e0b190004874fcbaac@cert.org>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/16bID-QlGDdvr498PphLeXgJGiI>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Nov 2020 20:44:47 -0000


On 11/17/20 11:10 AM, Roman Danyliw wrote:
> Hi Jared!
>
>> -----Original Message-----
>> From: ietf <ietf-bounces@ietf.org> On Behalf Of Jared Mauch
>> Sent: Tuesday, November 17, 2020 11:02 AM
>> To: Adam Roach <adam@nostrum.com>
>> Cc: Keith Moore <moore@network-heretics.com>; ietf@ietf.org
>> Subject: Re: Call for Community Feedback: Retiring IETF FTP Service
>>
>> On Tue, Nov 17, 2020 at 09:57:34AM -0600, Adam Roach wrote:
>>> On 11/17/20 09:45, Keith Moore wrote:
>>>> Are those web browsers that are deprecating FTP also deprecating
>>>> HTTP without TLS?
>>>
>>> Yes.
>>>
>>> https://blog.mozilla.org/security/2015/04/30/deprecating-non-secure-ht
>>> tp/
>>>
>>> https://www.chromium.org/Home/chromium-security/marking-http-as-non-
>> se
>>> cure
>> 	There's a difference between preferring https vs http and pulling http
>> support entirely.  There's many devices that will never get https, upgrades or
>> certificates.
> I can see this point in the abstract.  Can you help me in the specific -- what is the expected configuration of device accessing IETF resources which is not HTTPS capable?

Old CPE firewalls that proxy the user request and cannot support http?  
But with other services all moving to https, I suspect they are rapidly 
being upgraded.

Initial proxy authentication is a problem, though.