RE: I-D Action: draft-bonica-6man-ext-hdr-update-01.txt

Ron Bonica <rbonica@juniper.net> Mon, 09 March 2020 16:23 UTC

Return-Path: <rbonica@juniper.net>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 141C03A13B7 for <ipv6@ietfa.amsl.com>; Mon, 9 Mar 2020 09:23:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=oDo8woWw; dkim=pass (1024-bit key) header.d=juniper.net header.b=IIRvlsOQ
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vI291EoFxpo3 for <ipv6@ietfa.amsl.com>; Mon, 9 Mar 2020 09:23:17 -0700 (PDT)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC75C3A1367 for <ipv6@ietf.org>; Mon, 9 Mar 2020 09:23:17 -0700 (PDT)
Received: from pps.filterd (m0108160.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 029GC4Ot000790; Mon, 9 Mar 2020 09:23:16 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-transfer-encoding : mime-version; s=PPS1017; bh=PwKS+Ll9iX3RNIMeoQoIMGy6P0RFWO8h6G3SEt/JmuE=; b=oDo8woWw8HSm7sThq+SkTLqfxjopAj44lyPRqN5Mnn5nSIrkhlN3ycTbCWKtiOgmbbnv VW9aHdhZ5POWTzqEXnxtNy5njxTqnSrhIcxZvlg7qReAAwkObhLxjuN32L1YqETtC1ih R1B36AbkChdbqCNBag2F8+zT+rosxTxeDp7pG8EuurY3xJRq9AWHCbwi8uPoKSUhzVrH Sh/h1LNljTLMCbXaHFOLMhwNHLStEzdM1v1kLRcHJTxxXL9Gl6rRFbK0hQQ6ZKeSXjwc aBVfBVm9+aD57izIenJpBQDo0mDgOZvO/7os+DB7970mvTMQ1RfckpI3DJ8cBAli1Mbz Mg==
Received: from nam12-dm6-obe.outbound.protection.outlook.com (mail-dm6nam12lp2172.outbound.protection.outlook.com [104.47.59.172]) by mx0b-00273201.pphosted.com with ESMTP id 2ymadqayr9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 09 Mar 2020 09:23:16 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=lgyDdZHku7sKMR3YBKGhJK0W1k4cT9ZFpM9OVpNcS2xjyPbMTNWTB5XuZYU/HR3IOGSMNJyc7M0h9Xph2uQRD+iyB90xmPslCv7RaMKXd91NgbpMq6g2R561sAMf+MQBXZn+6XyHUR5fqk/a12okNEBuKiEkn9JDjezYZ3w/rX7sL0Q3c0stlJlUVZamSSTFx4QC7D0RCDzmtfzn6ABi5k7AV+sIyNfFKybr9wZRLe8QKdwDaArfWegV4XEbT0ItMXzv9MYPRCTAIHc6ydh/KAKwaeh1Oz2t8CG4pXd7wBIspT+fIas6FNWulKF+DciPmcv/c1pltGd0O9pxohvo8g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=PwKS+Ll9iX3RNIMeoQoIMGy6P0RFWO8h6G3SEt/JmuE=; b=VFHFbgE6mMcy56PdHKEq62p59zQxA/125FGMZPlpgAbXEuO9yat+TppIFSln9B6sm2rsWs06PFAwbZbxW/+Rt0wvWkDpTroDfmP5XX7OfQO6HV8RHr2yAEmQVkQBFiYFFtGl3II4opWsYIWGP/m/wVxyAKKMbWJ1Fu754rw+ZjErAAMn6CabauORYYpsN9HVgWtVHzAHfOpEkjPVv2FYUhyTe02Z6p3EJGjvR5stMGb0H5HJyFLIEWVVDe42OejpFM4WzS9r5T9J731P858lTFriE+1ViN+3gLAGUO2EYr205xu/Uru/hfgeS6yfiImj/L2wSL9tw0uM2aaAuBexGA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;bh=PwKS+Ll9iX3RNIMeoQoIMGy6P0RFWO8h6G3SEt/JmuE=; b=IIRvlsOQClUa5j/db9awKpTOIIiKA9KUz9Vn3Cbymb8VxJZXuu2mWfDASnlVQZhVRohfEDR8GylVHNF5N73kmr1qv0g1WLGD2t9FrsE1pSiUJmEAEUJNFMvJnOdbLRN2iL2c/v/Pq5eGu8oc0v0KcKtQ7PLZ4Mf11czx26wMQNc=
Received: from DM6PR05MB6348.namprd05.prod.outlook.com (2603:10b6:5:122::15) by DM6PR05MB5641.namprd05.prod.outlook.com (2603:10b6:5:5f::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2814.9; Mon, 9 Mar 2020 16:23:14 +0000
Received: from DM6PR05MB6348.namprd05.prod.outlook.com ([fe80::cdd:ea54:f213:7e02]) by DM6PR05MB6348.namprd05.prod.outlook.com ([fe80::cdd:ea54:f213:7e02%5]) with mapi id 15.20.2814.007; Mon, 9 Mar 2020 16:23:14 +0000
From: Ron Bonica <rbonica@juniper.net>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, 6man <ipv6@ietf.org>
Subject: RE: I-D Action: draft-bonica-6man-ext-hdr-update-01.txt
Thread-Topic: I-D Action: draft-bonica-6man-ext-hdr-update-01.txt
Thread-Index: AQHV9cm262njbO+xZ0mffJ7LnGDgmKhAa9hA
Date: Mon, 09 Mar 2020 16:23:14 +0000
Message-ID: <DM6PR05MB6348498594DCE0BB96C81243AEFE0@DM6PR05MB6348.namprd05.prod.outlook.com>
References: <158354206076.2347.5217574891432588007@ietfa.amsl.com> <a7ba91a9-bd80-c657-aed6-d14f57e91c68@gmail.com>
In-Reply-To: <a7ba91a9-bd80-c657-aed6-d14f57e91c68@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled=True; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId=bea78b3c-4cdb-4130-854a-1d193232e5f4;MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Owner=rbonica@juniper.net; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate=2020-03-09T16:23:05.8872901Z; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name=Juniper Business Use Only; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Application=Microsoft Azure Information Protection; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId=1b126658-6241-489f-b2b6-c43909449676; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Extended_MSFT_Method=Automatic
dlp-product: dlpe-windows
dlp-version: 11.4.0.45
dlp-reaction: no-action
x-originating-ip: [108.28.233.91]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 13af0774-dfe9-4b78-4757-08d7c4462b1a
x-ms-traffictypediagnostic: DM6PR05MB5641:
x-microsoft-antispam-prvs: <DM6PR05MB5641DBA660322B3C628B888CAEFE0@DM6PR05MB5641.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:7219;
x-forefront-prvs: 0337AFFE9A
x-forefront-antispam-report: SFV:NSPM; SFS:(10001)(10019020)(4636009)(346002)(136003)(396003)(366004)(376002)(39860400002)(199004)(189003)(5660300002)(316002)(26005)(186003)(7696005)(76116006)(66476007)(66946007)(71200400001)(66556008)(66446008)(64756008)(110136005)(15650500001)(8936002)(53546011)(81156014)(8676002)(81166006)(6506007)(66574012)(478600001)(966005)(9686003)(55016002)(52536014)(86362001)(33656002)(2906002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM6PR05MB5641; H:DM6PR05MB6348.namprd05.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: +pIUHmq7Genf7enJSk/ALgJ8E3mzgqLuxi37FoQHjBoX8EuNVG5kSBFpMummd5FAWM86C2OmG5hcXjG8x/gUg/forZ7hhQPzLdbmPpLznK0ozrv7q3XBZ2ksdE9zhyyVYVN1/yO/s/0wYTvp+twCqX4GCirK5jNcCytufbAhv53XD/FasomvVYFMxuULuhgSC+l7t/42MtvgeYjqVD2VgfXtCZGtJFi+POuIdsSmDgkyna9vwpx6K53pCNKc9278Qg4BxRR301h/u0eEFInKqGE551xppzpWo2xTt6QNEJFaioBbEDTFBLNk5xM5zdf7NRsngTvDAJwRU+XjPnxmCaQqpSM3Ft5SabMTD69nujIDogLWGAzYeVgkNETz7QhidY5sQ/80oF7K7ixX/HcMxEHkC1coOiuK9VOowS0gS8DlTJpMdj6mVhzX8+obqYApxPW2P2kQMmeaPrYHPkYRfr8QVylCCsB2nerA7IDoECKFIrIPmmbrNbd/YMON/AljJpDaepx3ywDqh7uHuvLMAbM3UrahT4+fF+sXdfBx0gKsOLOrZpiiyLLmDTfHAw5R9aUOPvZoWgwvyM9jxtFXDnFRfa3dRbJsfegyGC86oB10DRZpQ3rg88DS79M9G9wI
x-ms-exchange-antispam-messagedata: n6hCslL1sZZSL0220bWGxR5Ofv9lHeXHZDxf++AUBuZioK1X/nIk0QvRxv20ySQhHrDmcs0Gniq/X6GyAA6yz54qK1JfgqeVm6a0RmoSfTw9PaHRXkUCjhgIn4lTWD1P5UnYBoyin1RG+E5YFVrGIw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: 13af0774-dfe9-4b78-4757-08d7c4462b1a
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Mar 2020 16:23:14.5102 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: RdWwU/AoA7JeMmFIluJUkQRK3WEKfNUCTnIoNxh4Y1GQuoi74Lyw2Tsdl1xiyi6wo2YXTS8qDiUoJht42bKXHA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR05MB5641
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.138, 18.0.572 definitions=2020-03-09_06:2020-03-09, 2020-03-09 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 spamscore=0 priorityscore=1501 impostorscore=0 suspectscore=0 clxscore=1015 lowpriorityscore=0 mlxlogscore=999 bulkscore=0 adultscore=0 mlxscore=0 malwarescore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2001150001 definitions=main-2003090107
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/u-A7SE8LNFJu8HGlwNIfN4vQ3xo>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Mar 2020 16:23:20 -0000

Hi Brian,

As always, thanks for the thoughtful review. I will post a new version in the next few hours addressing your comments. Until then, responses inline......

                                                                                           Ron


Juniper Business Use Only

-----Original Message-----
From: Brian E Carpenter <brian.e.carpenter@gmail.com> 
Sent: Monday, March 9, 2020 12:18 AM
To: 6man <ipv6@ietf.org>; Ron Bonica <rbonica@juniper.net>
Subject: Re: I-D Action: draft-bonica-6man-ext-hdr-update-01.txt

Hi,

I'm going to nit-pick the crucial text in the draft, without taking a position on whether it should go forward. I think it's essential to get the text right before we take any sort of decision.

> 2.  Terminology
> 
>    The following terms are used in this document:
> 
>    o  Source node - An IPv6 source node accepts data from an upper-layer
>       protocol, encapsulates it in an IPv6 header, and sends the
>       resulting IPv6 packet to a destination node.

Actually it doesn't encapsulate, it simply prepends the IPv6 header.

[RB] Agree. Fixed in the new version.
 
>    o  Destination node - An IPv6 destination node receives an IPv6
>       packet and delivers its payload to an upper-layer protocol.

If that's what we now mean by "Destination node", we probably need to add a note that the Destination address might not be the address of the Destination node (as stated at https://urldefense.com/v3/__https://tools.ietf.org/html/rfc8200*page-7__;Iw!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzjA6Wr8R8o6JrbszFQY-qsZTh5RyS2SWT2$ ).

[RB] Agree. Fixed in the new version.

> 
>    o  Delivery path - A packet's delivery path is a series of nodes that
>       a packet traverses on route to its destination.  The delivery path
>       includes the destination node.
> 
>    o  Segment - A segment is a series of links and nodes in a packet's
>       delivery path.  The IPv6 Routing header steers packets from
>       segment to segment along the delivery path.  If a packet contains
>       a Routing header, its delivery path can contain multiple segments.
>       If a packet does not contain a Routing header, its delivery path
>       contains only one segment.

Are we sure that statement applies to all past, present and future types of routing header? If so, it should be "An IPv6 Routing header steers...".

[RB] This statement applies for all currently defined types. It's harder to predict the future. But I am hoping that the future is informed by the following text from Section 4.4 of RFC 8200:

" The Routing header is used by an IPv6 source to list one or more
   intermediate nodes to be "visited" on the way to a packet's
   destination.  This function is very similar to IPv4's Loose Source
   and Record Route option."
 
>    o  Segment egress node - A segment egress node terminates a segment.
>       When a packet arrives at a segment egress node, its IPv6
>       Destination Address identifies a resource that belongs to the
>       node.  All destination nodes are also segment egress nodes.

That's a significant change. According to RFC 4291, an IPv6 address is assigned to an interface; nothing to do with "resources". If you want an IPv6 address to identify a resource rather than act as a locator, that's an update to 4291, IMHO.

[RB] Agree. Fixed in the next version. s/resource/interface

> 3.  Updates To RFC 8200
...> 3.2.  Updated Text
> 
>    Source nodes can send packets that include extension headers.
>    Extension headers are not inserted by subsequent nodes along a
>    packet's delivery path.
> 
>    The Hop-by-Hop Options header can be processed by any node in a
>    packet's delivery path.

I have long been disturbed by the word "process". Any node can read the value of any extension header (unless encrypted). Firewalls do it and might drop packets as a result. So "process" can't mean "read".
Maybe it means "modify"? But of course options can only be modified in specified ways (and cannot be changed in length).

[RB] Agree. I think that it is fixed in the next version.

[RB] We need to make a distinction between examination and processing. So, I have added a rule that says, "Extension headers can be examined for various purposes (e.g., Firewall filtering) by any node along a packet's delivery path.

>    ... The following headers can be processed by
>    any segment egress node, including the destination node:
> 
>    o  Destination Options header.

Same comment.

> 
>    o  Routing header.

Same comment, but it should add that the spec of any type of routing header must specify precisely what modifications are allowed, and the length of the header must not increase.

[RB] Agree. Fixed in new version.
 
>    The following headers can be processed by the destination node only:
> 
>    o  The Fragment header.
> 
>    o  The Authentication header.
> 
>    o  The Encapsulating Security Payload header.

Do we really need to say that? Once the packet enters the destination node there's no issue.

[RB] Maybe not, but does it hurt to mention it?
 
>    Except for the following fields, extension headers are not modified
>    by nodes along a packet's delivery path:

See, "processed" only means anything if something is modified.

[RB] I'm not sure that I agree. Consider a Destination Options header that precedes the Routing header. It contains an option whose chg-bit is 0. It can be processed by any segment endpoint, but modified by none.

>    o  The Segments Left field in the Routing header.
> 
>    o  Type-specific data in the Routing header.

Are we sure that is enough for all future routing header types? (Actually, there's already a spec for which that rule is probably insufficient:
draft-lc-6man-generalized-srh, which adds a "C-SID left" field to the routing header.)

[RB] I think so. In a Routing header, everything that is not one of the first four fields is Type Specific data.
 
>    o  Option Data in the Destination Options header.
> 
>    Extension headers are not deleted by any node along a packet's
>    delivery path, until the packet reaches the destination node (or each
>    of the set of destination nodes, in the case of multicast).

Again, once the packet is inside the destination node, there's nothing to say.

[RB] We need to say something. If we don't people will assume that extension headers can be deleted by any node along a packets delivery path.

Finally, do we need some comment about AH? Should we require specs to state either that they are incompatible with AH, or to state exactly which fields are mutable for AH purposes?

[RB] Maybe, but I am not sure where that belongs in RFC 8200. Maybe Bob can advise.

                                             Ron


Regards
   Brian Carpenter

On 07-Mar-20 13:47, internet-drafts@ietf.org wrote:
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> 
> 
>         Title           : Inserting, Processing And Deleting IPv6 Extension Headers
>         Author          : Ron Bonica
> 	Filename        : draft-bonica-6man-ext-hdr-update-01.txt
> 	Pages           : 5
> 	Date            : 2020-03-06
> 
> Abstract:
>    This document provides guidance regarding the processing, insertion
>    and deletion of IPv6 extension headers.  It updates RFC 8200.
> 
> 
> The IETF datatracker status page for this draft is:
> https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-bon
> ica-6man-ext-hdr-update/__;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-
> vzjA6Wr8R8o6JrbszFQY-qsZTh5RyDiuiux$
> 
> There are also htmlized versions available at:
> https://urldefense.com/v3/__https://tools.ietf.org/html/draft-bonica-6
> man-ext-hdr-update-01__;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzj
> A6Wr8R8o6JrbszFQY-qsZTh5R_RaW2Oy$ 
> https://urldefense.com/v3/__https://datatracker.ietf.org/doc/html/draf
> t-bonica-6man-ext-hdr-update-01__;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZw
> szU62b-vzjA6Wr8R8o6JrbszFQY-qsZTh5R3LzW5-y$
> 
> A diff from the previous version is available at:
> https://urldefense.com/v3/__https://www.ietf.org/rfcdiff?url2=draft-bo
> nica-6man-ext-hdr-update-01__;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU6
> 2b-vzjA6Wr8R8o6JrbszFQY-qsZTh5R2CiHZik$
> 
> 
> Please note that it may take a couple of minutes from the time of 
> submission until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> https://urldefense.com/v3/__ftp://ftp.ietf.org/internet-drafts/__;!!NE
> t6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzjA6Wr8R8o6JrbszFQY-qsZTh5R5vo
> WQxF$
> 
> 
> _______________________________________________
> I-D-Announce mailing list
> I-D-Announce@ietf.org
> https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/i-d-
> announce__;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzjA6Wr8R8o6Jrbs
> zFQY-qsZTh5Ry1oSTA3$ Internet-Draft directories: 
> https://urldefense.com/v3/__http://www.ietf.org/shadow.html__;!!NEt6yM
> aO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzjA6Wr8R8o6JrbszFQY-qsZTh5R3BOnf0P
> $ or 
> https://urldefense.com/v3/__ftp://ftp.ietf.org/ietf/1shadow-sites.txt_
> _;!!NEt6yMaO-gk!Vg0zJoh5Uh0jsqku3JSdZwszU62b-vzjA6Wr8R8o6JrbszFQY-qsZT
> h5R942qJSv$
>