Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt

Fernando Gont <fernando.gont@edgeuno.com> Fri, 11 June 2021 05:21 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D8A3A3A292C for <ipv6@ietfa.amsl.com>; Thu, 10 Jun 2021 22:21:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wiRqByKGhVZP for <ipv6@ietfa.amsl.com>; Thu, 10 Jun 2021 22:21:15 -0700 (PDT)
Received: from NAM12-MW2-obe.outbound.protection.outlook.com (mail-mw2nam12on2119.outbound.protection.outlook.com [40.107.244.119]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B6E83A292B for <ipv6@ietf.org>; Thu, 10 Jun 2021 22:21:15 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=koAKsmSDgNJRYtenq3GBPMMIPALOO6+wRuWhSiMU2kZv+qsmy+RMwlQ4e7gmRaZZNHOR61v0WvTPkoNVn5u/z4YmD1PcF5FChkXKuMCHJLUS9lPAd4u2+xVNNlckxA/HwolAI83DLKrvPVKNSEp6V6qeIgJjNr+BDEHYACmJnz0sNjAuRaYXnI+Cc/5jAF6fh/RYySqxNWHUc3Z4ziRKC7RCWSMkD9mZ9QaqsB2XOsYsb9tc9c6s4l0jgZ7BtRLobtYjcvRG6Yt6UgxzqxzvNDG+vpaOto2b60Yhjg1vi6ohLt4Nl6fWDzo/fBnsS6958B9urR2gwMUM74fLdOM28Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=A1gonxpkq1+YFsGA+1cxVpoGPTc4hVlgJWhnV3lS4lw=; b=LvUL+OKitleFfLQ6JhINvjYXsRJCEqsQUjVpDnRqtZ4yWL30YBruVnp4GqaXCn02ul8G3Td4yxkGGI6yeUfPhjeFcubFjWSHeQcqEpqTLT4ddDbUjzcYPniyaMoR9HdSpghvitl6RU8ny0hqRFOShjSlZHijQifwiMq9yVjxiN9MqVpAdI6bjlmlXCNC0RwRKIOhp1xpBHevQ3BmGHCZ5G5kCJNqbIK2syNKgSa5/dv4MXrCTVjXFZAN2PXQxm0cfR+hbvvZWEDEZN/3CgiNjvRqRCF5i9pK+LfwjQXuVw0cKp2Td0MRsbaXlZntplwgrTEdRk8ZKN7i18eFBjdqVQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=A1gonxpkq1+YFsGA+1cxVpoGPTc4hVlgJWhnV3lS4lw=; b=cN/LxC6SkEPV96Z19dTPV+dWUbhbeOnILAoBG6Yrp4ZO3bNZBY+YNITGmLG+XbudcybaH3umWjKMmhXwU/1uKIx1XwuBZMQrk6CThK//AzAImWghgXPrOsTgE8Cejhzen9OYPB8ASuw1MflR9VhojSmmI3cnGcrda/Dt5PZSiV0=
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com (2603:10b6:a03:2eb::6) by BYAPR05MB6565.namprd05.prod.outlook.com (2603:10b6:a03:eb::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4242.12; Fri, 11 Jun 2021 05:21:04 +0000
Received: from SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148]) by SJ0PR05MB7514.namprd05.prod.outlook.com ([fe80::59c9:fcf7:eeea:1148%9]) with mapi id 15.20.4242.012; Fri, 11 Jun 2021 05:21:03 +0000
From: Fernando Gont <fernando.gont@edgeuno.com>
To: "pthubert=40cisco.com@dmarc.ietf.org" <pthubert=40cisco.com@dmarc.ietf.org>
CC: "brian.e.carpenter@gmail.com" <brian.e.carpenter@gmail.com>, "gorry@erg.abdn.ac.uk" <gorry@erg.abdn.ac.uk>, "bob.hinden@gmail.com" <bob.hinden@gmail.com>, "ipv6@ietf.org" <ipv6@ietf.org>, "tom@herbertland.com" <tom@herbertland.com>
Subject: Re: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Topic: New Version Notification for draft-hinden-6man-hbh-processing-01.txt
Thread-Index: AQHXXn7qO96AsvT4FkS1hVkPsR81LKsORiUA
Date: Fri, 11 Jun 2021 05:21:03 +0000
Message-ID: <7c7a73ba2730696e40acd65c44036d2c0a17f9c2.camel@edgeuno.com>
References: <162265842779.4095.2393609365780372735@ietfa.amsl.com> <E5A31CCD-104D-4B92-9730-4FCFBF191F46@gmail.com> <17adf4b21d428d051e390574e976e3f61aee33c0.camel@edgeuno.com> <CALx6S368ZavS5Ggv28XB1mW41sZML0Vv=DvBPMooFFhbWdpKUg@mail.gmail.com> <4e1c6c6a-1512-755e-a4e5-723e83b74b4c@gmail.com> , <d2847bc077d1775b07642587758962dcb80e7690.camel@edgeuno.com> <F6288093-7141-4190-8541-DF96C0DE0CF7@cisco.com>
In-Reply-To: <F6288093-7141-4190-8541-DF96C0DE0CF7@cisco.com>
Accept-Language: es-AR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Evolution 3.36.5-0ubuntu1
authentication-results: dmarc.ietf.org; dkim=none (message not signed) header.d=none; dmarc.ietf.org; dmarc=none action=none header.from=edgeuno.com;
x-originating-ip: [186.19.8.47]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: bc82b800-feb0-4fff-e6ac-08d92c98b566
x-ms-traffictypediagnostic: BYAPR05MB6565:
x-microsoft-antispam-prvs: <BYAPR05MB6565109BB802463CE7B8CCFFE5349@BYAPR05MB6565.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:1824;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: JMn0kIGkPvgzHWTn1SURTQRfmlOQKkJu79jX3diQyG5QcFOjMdmtRUhppDJBcHUKD6CiZNRfx1vW8vHabv03kyyYyS0EKW8GaXrMvVhnWVq2Imxk5Jaq/vwW/3gfXGy/n09gyJSEx7lNyx3tLjDO1r7VRdkNRAbrJeAEYM49xbetHuu7mdJ8TTN8iHpTOgo286d5B1N5twW+I4zwwanajmWOKGL9hY6it88ZtzqWuL0hDZ2tSEWh0g8XljnIxzuwEnx62Kh64gvtZlx0pYk1yDjMo6W5Z47NkNz3yk44kQdJ/VYV95WENhcE647yjHLAkUqtiGwG5tjoQA0LwWuwWFr6UMZUoN0yIEU99CODFSyCghs6pnY4XXzR45jPBWyuZypZFiUw+PzP2jkwBfjXpcOjdcDxg/v5HDFr3SHbnSqfKrmvIr0rEZjNaoYohbC/+1VMyhAHbzNtAyaG+hNgfC5DGZYRvEoMTiQ+VaRpdeJ7WNcGu2CAxyFb02aPht50NnNAjlDCzEu2RwamIVBfqGYC1PW++Aa7FpKyxXoUM/Q3TGK6FqgAGhn9tp0qdr5HQvunps0TjxVjpTLIyqHt9Z3zKFvWazTUXs/DO3e2t/JW44Caw4JEG2Qg48DKDCymXMxBhMC7+B0croqIhJgn9GYONY7h5duDb3PY0alHmwxueu5L6NH9HHUU4h5Ivpo06POMjMrbAGsMhhpD7DlJUA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SJ0PR05MB7514.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(366004)(396003)(39840400004)(136003)(376002)(346002)(316002)(2616005)(86362001)(36756003)(54906003)(15650500001)(966005)(8936002)(2906002)(478600001)(44832011)(186003)(26005)(6486002)(4326008)(5660300002)(71200400001)(8676002)(66476007)(66556008)(64756008)(66446008)(6506007)(6512007)(76116006)(91956017)(66946007)(38100700002)(122000001)(83380400001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Hi81kRztGFdIipXoSmlsK9QZMVpGfRItKt7nynFGUO0mMjXmQo6BQ14UVKx3ebwjghhTCqLBASQ6w2n0UKVQ3LwYb+YegKs9qaqxFVyUAOo9u7v42GogNO0Ibc2qSkVn4Uk6ve6xr3WScwBrPrb2N5TyFensmmTu4Z3hkb20A1tdCZvRYHykbE40z28Cki+CsIaFqtdNP4LG6y6KC0DjR54NKk8Ef98SHOnUkG4N1yXMZRNS88lI+btOki5YD5kNnQUrSsode/o0CUNsFpLrBoumQTOtKCPH/s/5DkprJh+ywd2Y0AYmFymh4CXq2EwqkXay8+YfnwSiGNkmPVzsPfwnk9sohouTY8quTlfCYMCQ0B+KQ0vEzTo0nr+R5QbUAgZ14AHLs2YVuF6UpRrshuE1VCMAuKS1533zBQl5qPe6jFtgzrlx46EzXfoAac6dffoEy63jGC96I7u0KpBsDYie50597HBwQBHAd1rFY38eiZXdFXZg7ikyQIrp8OBxK9QPqkSkxrUliZPqFlt4HLt1CHzd38XC6z059XEcVfkQUZPja1aKji1VBgKNZWo2i5dYMsvpncIDSCzHE4EuIu57KSX/UOWX13ahScVYbo7XeizwSRcMqdBmTKJT0lpjKllQzobDZOJhV8W1D1MwEv2o4aERkXsLxlYs5rA85pvlbP42UksDAs3h3vEVXgqB329embWyxILuYKa6rcsCgwrWwI832gH5nIPmeKp+qVtQ7Qs/XvPrwti6QIAQo8pyFAZ1Ned7G+XTBOXVVe+OF8QH+ZHmAVIIbT5GyofUVHXiarBlwvwx34ec8roetHXghopTDm7qwulE46ZlW/cEX/Hjjrn4uSZx4GSXhql6dnnDLJ+JcDus4ndLwVhHes7zUbk3BIpO4BN60SH2U7TrQVqS4d3nk7Ykkn7of7QkX/ecRzUwwGAcOB34PRazs5H957CyRlCJFqSi5iFEXlRkznQcqIzw4v0gYipZzAcAUkEN6dFA5BH6oaELK8c5cCp4TEp7NigPjDdQMEJzC2CijGj7/qKFcc/oMS3BwmZifssIA7Z5f6RqcoxU6yxaVP4WsBB4qnLOfMvSPIcq3lcYwzIYAFCEgXfiHz7DWx4GISK2YE3yUawfgPfN4+vKKO9q9tzx17BITkUg1Re9jxWZF1prQTXX9EhSvUSgpCeI6YRN1U0cgsWPxuK8XxDaHqCHvrKjBErSalYbl6kFlFdBVbSeInOEFqMmTPGJU9GRL8CP+QoUq7OxTUUo/rV/HaNyf+1M/PxfnNx8EDYrOs1W3dbt0u1OSYGTpHTvEjhDLxX/3HJ/fZv77FjyXLHRk1ZT
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <C4BAA8ADDF69B44FA3D6883219925B22@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR05MB7514.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: bc82b800-feb0-4fff-e6ac-08d92c98b566
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Jun 2021 05:21:03.6122 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Ep9QSY0cCky7yPxoSB0fn6OWB8fZj/wf1Zb/VtBONN+en2ysoC1PZK7UMbaeyUdFxyCK+gn1bbjAmZKQbM7+yQJt/IfAvZo84sRPBVtEeCI=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB6565
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/aQXExfkkOo3kzS_dtVFIRnqXgwI>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Jun 2021 05:21:21 -0000

Hi, Pascal,

On Fri, 2021-06-11 at 05:00 +0000, Pascal Thubert (pthubert) wrote:
> This might need a solution be similar to the MTU problem; e.g.,
> during PMTUD a node might add the HbH Options that it needs to check
> that the options make it through…

Aside from a bunch of other evil details:

WHat if, say, you employ this solution at, say, connection-
establishment time, find that EHs actually "work" towards your
destination, but them, sometime later, the path to your
destinationchanges, and you find out that EHs no longer work?

     Abort the transaction/connections? 
     "Migrate" from EH-based mechansim to the fall back mechanism?
     Anything else?

What about the impact on e.g. RTT for connection-establishment? What
about the complexity of the mechanism? How many bugs/vulns before every
implementation gets it right?

Truth #3 of https://datatracker.ietf.org/doc/html/rfc1925 comes to
mind...

Thanks!

Regards,
-- 
Fernando Gont
Director of Information Security
EdgeUno, Inc.
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531