[netconf] Re: Question about NACM username for configured-subscription receivers

Andy Bierman <andy@yumaworks.com> Tue, 18 August 2026 21:05 UTC

Return-Path: <andy@yumaworks.com>
X-Original-To: netconf@mail2.ietf.org
Delivered-To: netconf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 15B6912BEB04A for <netconf@mail2.ietf.org>; Tue, 18 Aug 2026 14:05:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787087109; bh=Oa4XVWZsipTzVcK3pyoVRdNTmOvLLBLFlyFgg5d50/8=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=PIB55Hi+iQhoyjJKPIH9sLFLmWClTx4GF/bD671twgYlM6dRxTgAY/n6kcqIc9FmQ +BpPqjWVPYAbKB5J7CAZ7QZRCSk02EUK2ndJintsMcTeHXjgb/Ju/Lfmlhc7z8LUbn Oq8hWiTKAXRlfquZa3DingOSggQ6Tb1IXUf0EDII=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.089
X-Spam-Level:
X-Spam-Status: No, score=-2.089 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=yumaworks.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fNv1iIy0hP9O for <netconf@mail2.ietf.org>; Tue, 18 Aug 2026 14:05:07 -0700 (PDT)
Received: from mail-yw1-x112d.google.com (mail-yw1-x112d.google.com [IPv6:2607:f8b0:4864:20::112d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 61B0312BEB035 for <netconf@ietf.org>; Tue, 18 Aug 2026 14:05:07 -0700 (PDT)
Received: by mail-yw1-x112d.google.com with SMTP id 00721157ae682-81f08502c4bso411647b3.2 for <netconf@ietf.org>; Tue, 18 Aug 2026 14:05:07 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787087107; cv=none; d=google.com; s=arc-20260327; b=MC5JewIsN8JjIxoJlRYAxHYpQ5RGsfwkxqm4pvAmR3987IOyFD8kejL9o8IyPSfnD6 Eb62Myn2UFbEiLRBKdwBQCums9ExfkBGTvcveMxWfSSJWchh4Vo7q0FE1CZ9yBKzc5Rj BGUFb99kBkgumGx17jHUYmh9I+heaOTyYJ0Uhkg55w5WElS7fiGlZ05kf6ep98gl0s5Y I8vrIdWZRSeZduxr88WOua50FsRnCXWhr68vv6eZwNVIwzASMTO7T8ZvHxZxUXmyZIHH w9w5o1eADaVwDWTHXFUspCZ0WTe9aF6YRgGc2QGLNlfQS3YEt+4DKB55LH4jsF5QxHmM ekzQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=WXxEDCFY0YVCLhkiMV5QrJW6zcvSZ1ayzt478laaDBg=; fh=HHPjltBnGwUUIZMVM9o7Fpg1VZGsLLCgfRSyA4Yx+HE=; b=qtfkCnBXg0QI7ye4tao0Ie6TvOlsLK3KXhEReCPRTCzHfI27XkRbO4RZ8VvZm1RDVT VE5aLy7Kg64twhhuu49/TMSL9Ozh3uSmlK/sDaCDEnK26v82M/r6AnR14NFpD5LDMgmM 3PxjIYBHvNAUMZlappCW61hEzZi0Xucv2qWoIpQvSgS2VT6+gL04P+cHJA5609/pCgm3 JCbAWXidJusAwX0YBEICdcyQ+gvlwsJmKGvdvpt8h+vI739tfE9qVGYmNKvQ6oDnsLO9 Z0o/yQvO1Er8cv9cKaqe4zCNxTIq+Tjq6TmzrVXeeChzy+JibzD4Xz6RteJlAsopOTxx 3qLQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yumaworks.com; s=google; t=1787087107; x=1787691907; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=WXxEDCFY0YVCLhkiMV5QrJW6zcvSZ1ayzt478laaDBg=; b=wEY6YjJeZvvBRhvqYdb8IrNhsR5xJ8TJNJh8/SVprsl0BHHs3765vIpWunnrWkTUtO yxS7Ys5BTsXuMeaw4LjKT3ZulTjSGKBqkoyWazUFbK786JHDrwsEgdUyakW35zX5he+h jpz1mp1LaQavkdH+JR8S0dABWRLvU1fHa5gP+eSuDV85QQLtvz/ZQS4o00WyVsLyptOg BVncLIG1ew5n8wrZydSMu2Bhx7VRepkuRC8y1EjexggvimANDsGUtH/RbD8mklLV4v7p 7TG3ou5X3Tq07lIhaIFCW85IXybI2rBh82Our8mMVFMO2QpFScYP0kSNjKGqAL10IoTT 4h1A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787087107; x=1787691907; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=WXxEDCFY0YVCLhkiMV5QrJW6zcvSZ1ayzt478laaDBg=; b=HMbgbysDUdb7vcUBhnEQSl1QDueCPIqBzexLQvp2ex1gBr8mSZyI/bIJ3SaBkqSdvR OZrMVZtchM6tpK6BySBTVB6bxIQPmrFH6VgzwLFUrJADc8tY/gkbT3HteYs3gFljkoH9 cJ9ExXj/DuKpQMStIAoQEdO8vKqEMdjeXdXfEzM0f2BTQvhbOv8p4VmQof2s4Hh0D74X UzcX3lFdgiQW7RKzMbmQugqZkRVhfJcd+u9us8sPreTe156JHpUZkzmQG9yTQrQQz/ig 4K/PTAHXc0voJTmeuBUskjIq50T5OKvLmcId7oEAPX8R8MeXTLXdjMRUNUlgVGi3KgG4 rw4A==
X-Forwarded-Encrypted: i=1; AHgh+RrmYblM3gedeYDYBeoxZ8za6X70rtUB2JU/vVVbcxyVAN62vggTIXDArdaWNvVdharebaI1Bipy@ietf.org
X-Gm-Message-State: AOJu0YxKlmAHx165fVMviRe6EtWBpQf2NkOozZKq5JznvmXb+7frX7HK wSzQH5zYq2GMkPzzFzrdK0Dj5jC2psFYdmREgA4lW+bkr/BT0O64jmSUG/5aJJF78koyIBZOcmF bDWnwC7zQhhAh+LYQ+9QUnxRWmNtWVfhhud1Rb6EeeCBKiPwgyEYXqCrvqQ==
X-Gm-Gg: AR+sD1034pI+yGZD/NUPDnjlOvE9FIaxT6QeaCe+8paA7drb5AwK6NknF2NEvhSo5M8 A9vyMYsSpO39I3ZxitpXIQ0+XSxTn0zjgXSaYvQrE7JgpKrdVadL2pW/tUhfAo/0eZg6DAkBIGp NQYqhbW5NZi2eZBePT7uEQYb8V/E/mVvY17phqvt5LKGxNzzlIGTsBUqD9Pj0+/WHPEc+yRlDGD gd5CN9MilgnvBkNw6ft/Ypfj3Kq059CGejK3k02MvqMU/qKbjJKreqFBAOGHREQi7NaI9zcojf5 STWYN1zsG+qzvyGTMB2FBBSXzN8GXUaUwWf92T5c+y9Z
X-Received: by 2002:a05:690c:9a0a:b0:834:7de:52b1 with SMTP id 00721157ae682-844e4af5048mr880417b3.2.1787087106501; Tue, 18 Aug 2026 14:05:06 -0700 (PDT)
MIME-Version: 1.0
References: <D7779BF5-33F5-4F93-93AA-2DDBF35D16CC@cesnet.cz> <CABCOCHQdNtfz1Tp_UUZb6soBQ4BCVZEvRHa2QbTffTgH5xLsMg@mail.gmail.com> <010001a01623de0b-9d477e39-ace4-4a71-82ff-73fb7e3cc3d8-000000@email.amazonses.com>
In-Reply-To: <010001a01623de0b-9d477e39-ace4-4a71-82ff-73fb7e3cc3d8-000000@email.amazonses.com>
From: Andy Bierman <andy@yumaworks.com>
Date: Tue, 18 Aug 2026 14:04:54 -0700
X-Gm-Features: AcwNN1Xokyr3kUEFwayCzf6MFpsqAsUViTVGk7LHOi9gXb8TH-27_eSPiX2hq0k
Message-ID: <CABCOCHSLLxJ5xVrvGWq22TEqdRuJORGggdpiEJixVgBn-LCDVw@mail.gmail.com>
To: Kent Watsen <kent+ietf@watsen.net>
Content-Type: multipart/alternative; boundary="0000000000002a7d65065958a414"
Message-ID-Hash: IBS4MPCFRVV5YI552NSTWX3ZUYJ3KBJN
X-Message-ID-Hash: IBS4MPCFRVV5YI552NSTWX3ZUYJ3KBJN
X-MailFrom: andy@yumaworks.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-netconf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Roman Janota <Roman.Janota=40cesnet.cz@dmarc.ietf.org>, "netconf@ietf.org" <netconf@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [netconf] Re: Question about NACM username for configured-subscription receivers
List-Id: NETCONF WG list <netconf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/Vo5ZABsJOsXTeFPf2Plgno_Y6o4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Owner: <mailto:netconf-owner@ietf.org>
List-Post: <mailto:netconf@ietf.org>
List-Subscribe: <mailto:netconf-join@ietf.org>
List-Unsubscribe: <mailto:netconf-leave@ietf.org>

On Tue, Aug 18, 2026 at 11:30 AM Kent Watsen <kent+ietf@watsen.net> wrote:

> > I think this is an open issue, and you have captured all the important
> points.
>
> I agree that it's an open-issue, but only to the extent that a
> clarification is required.  An Errata on RFC 8639 is appropriate.
>
>
> > I think our server code uses 'system' (i.e. no NACM user name, and no
> NACM enforcement).
>
> IMO, this is the correct (read: long-term) behavior.  That is, the
> access-control need only apply at the time a subscription (whether dynamic
> or configure) is created, not at the time a notification is being sent, as
> it would affect performance to have such logic in the fast path.
>
> The NACM check is there for client retrieval. but not for notifications

https://datatracker.ietf.org/doc/html/rfc8341#section-3.4.6

   If the user is authorized to receive the notification
   event type, then it is also authorized to receive any data it

contains.

But NACM could have:
  --read-default=deny
  -- explicit rules to permit reading the push-update and
push-change-update events

No check is done (in our server) on the user that configures /subscriptions
to make sure
they have read access to these event types. Does this have to be done?
Reject the edit request if not?

NACM does require that the user is authorized to receive the event-type,
and this check is skipped if the user is 'system'.  Is that a problem?



> > If the NACM user-name was saved (or configured?) in the subscription,
> then the behavior
> > would be more consistent with dynamic subscriptions.
>
> Per above, I don't think saving the username that created the configured
> subscription is necessary.
>
>
Agreed. This is not done for anything else in the config.


>
> Kent // contributor
>
>
Andy