Re: [Netconf] WG LC for draft-ietf-netconf-rfc6536bis

Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de> Fri, 05 May 2017 05:43 UTC

Return-Path: <j.schoenwaelder@jacobs-university.de>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF04C1293F9 for <netconf@ietfa.amsl.com>; Thu, 4 May 2017 22:43:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.663
X-Spam-Level:
X-Spam-Status: No, score=0.663 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, RP_MATCHES_RCVD=-0.001, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FGxf44jjl2Ij for <netconf@ietfa.amsl.com>; Thu, 4 May 2017 22:43:35 -0700 (PDT)
Received: from atlas5.jacobs-university.de (atlas5.jacobs-university.de [212.201.44.20]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B262F1273B1 for <netconf@ietf.org>; Thu, 4 May 2017 22:43:32 -0700 (PDT)
Received: from localhost (demetrius5.irc-it.jacobs-university.de [10.70.0.222]) by atlas5.jacobs-university.de (Postfix) with ESMTP id 1ED1377; Fri, 5 May 2017 07:43:30 +0200 (CEST)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from atlas5.jacobs-university.de ([10.70.0.217]) by localhost (demetrius5.jacobs-university.de [10.70.0.222]) (amavisd-new, port 10032) with ESMTP id zJ4cX5rTvZwJ; Fri, 5 May 2017 07:43:29 +0200 (CEST)
Received: from hermes.jacobs-university.de (hermes.jacobs-university.de [212.201.44.23]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "hermes.jacobs-university.de", Issuer "Jacobs University CA - G01" (verified OK)) by atlas5.jacobs-university.de (Postfix) with ESMTPS; Fri, 5 May 2017 07:43:29 +0200 (CEST)
Received: from localhost (demetrius1.jacobs-university.de [212.201.44.46]) by hermes.jacobs-university.de (Postfix) with ESMTP id C1AAE2005E; Fri, 5 May 2017 07:43:29 +0200 (CEST)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from hermes.jacobs-university.de ([212.201.44.23]) by localhost (demetrius1.jacobs-university.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id v-KkLx7IMkhA; Fri, 5 May 2017 07:43:29 +0200 (CEST)
Received: from elstar.local (elstar.jacobs.jacobs-university.de [10.50.231.133]) by hermes.jacobs-university.de (Postfix) with ESMTP id 2427420053; Fri, 5 May 2017 07:43:28 +0200 (CEST)
Received: by elstar.local (Postfix, from userid 501) id 474CF3F3996C; Fri, 5 May 2017 07:43:28 +0200 (CEST)
Date: Fri, 05 May 2017 07:43:28 +0200
From: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
To: Andy Bierman <andy@yumaworks.com>
Cc: Alexander Clemm <alexander.clemm@huawei.com>, Netconf <netconf@ietf.org>
Message-ID: <20170505054328.GA9029@elstar.local>
Reply-To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
Mail-Followup-To: Andy Bierman <andy@yumaworks.com>, Alexander Clemm <alexander.clemm@huawei.com>, Netconf <netconf@ietf.org>
References: <A13E62FA-AB96-4164-98D5-3CC1D04A78E8@gmail.com> <E236AC6C-4B6D-43B1-8092-0B8AA3F4D6AA@gmail.com> <644DA50AFA8C314EA9BDDAC83BD38A2E0DF956E8@SJCEML701-CHM.china.huawei.com> <CABCOCHT9fNKHn=qgFsQ0mznByArCpqsAz4m4jjjPE7M243UjeA@mail.gmail.com> <644DA50AFA8C314EA9BDDAC83BD38A2E0DF9584C@SJCEML701-CHM.china.huawei.com> <CABCOCHRgaTpxXJ0nOgbHx4Hbz6FgfTahN3T2OedfC6gnbnAN0A@mail.gmail.com> <20170504191415.GF8393@elstar.local> <CABCOCHT5_Up8v5m_0b7Fx9siMTATZPeL9tbC_Pciw1gUyCsTiQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CABCOCHT5_Up8v5m_0b7Fx9siMTATZPeL9tbC_Pciw1gUyCsTiQ@mail.gmail.com>
User-Agent: Mutt/1.6.0 (2016-04-01)
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/j0rMa28oQzYp_EvcNHYkZMQCPPA>
Subject: Re: [Netconf] WG LC for draft-ietf-netconf-rfc6536bis
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Network Configuration WG mailing list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 May 2017 05:43:37 -0000

On Thu, May 04, 2017 at 01:02:39PM -0700, Andy Bierman wrote:
> On Thu, May 4, 2017 at 12:14 PM, Juergen Schoenwaelder <
> j.schoenwaelder@jacobs-university.de> wrote:
> 
> > On Thu, May 04, 2017 at 11:28:48AM -0700, Andy Bierman wrote:
> >
> > > there is no text about candidate vs. running vs. startup.
> > > The NACM rules apply to all of them the same.
> > > I could add text that says there is no consideration for specific
> > > datastores.
> > > Most rules apply to the schema tree. Data rules apply to instance data
> > > but they apply to all instances in all datastores).  I can make this
> > clear
> > > in the next revision
> >
> > Does NACM apply to an I2RS datastore? Just checking before a generic
> > all datastores quantifier is put in place. Perhaps it is safer to say
> > where we know NACM applies and leave the rest to be defined later.
> >
> >
> It applies to all datastores.
> The datastore may not support all the CRUD operations that NACM supports.
> The subset that does apply is enforced.
>
> The other variant (the datastore supports more operations than the
> NACM CRUDX model supports) is not covered.
> 
> So NACM should be careful to say new operations not covered by CRUDX
> are out of scope.
> 
> IMO the  I2RS user priority enforcement is part of the protocol, not NACM,
> similar to NETCONF enforcing data-missing on a delete operation.
> 

Do we allow for the possibility to have datastores that use a
different access control model, if ever needed?

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1 | 28759 Bremen | Germany
Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>