Re: [Netconf] [SPAM?] RE: LC on subscribed-notifications-10

Randy Presuhn <randy_presuhn@alumni.stanford.edu> Sun, 18 March 2018 22:16 UTC

Return-Path: <randy_presuhn@alumni.stanford.edu>
X-Original-To: netconf@ietfa.amsl.com
Delivered-To: netconf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B826712D7EF for <netconf@ietfa.amsl.com>; Sun, 18 Mar 2018 15:16:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nsiIypSJtYbw for <netconf@ietfa.amsl.com>; Sun, 18 Mar 2018 15:16:20 -0700 (PDT)
Received: from mail-pf0-f179.google.com (mail-pf0-f179.google.com [209.85.192.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22D6A126B72 for <netconf@ietf.org>; Sun, 18 Mar 2018 15:16:20 -0700 (PDT)
Received: by mail-pf0-f179.google.com with SMTP id u5so6268665pfh.6 for <netconf@ietf.org>; Sun, 18 Mar 2018 15:16:20 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=t4tpe/UT8zjTvYc4R9pCH1OgfQaifkgOwMV2SxTgJAQ=; b=LwOph0oryBU5A+tG6YPRJ+hksFfClYpJI1Dw0rnCLWy5BzKa7CPzFvAKBbcsQML/xS jxj2JT+MVjf5zjEKbNF7CoZPTqJkB+G6gZ2H59X/VxZL7CAKXgzhZ1XHc62ED3VoXeT+ D2vjLjBZlNuB8/UiNM+amYgJ8QNJaKHMNNrZPmssE1hyL+IR6DNYGRjJ2W3AG3v7FllA r2vmnbYHimW7px1LSEpvSQTVKWzxN35ijHZ8goW+AP1iMrlCtpQhrXlT+KPV/dqoddp2 rg8ZiMwrhupt43B22eDByZiKeqQjNXo3GXfhuxuT/pIPCYUiHcKeuEj8Sr1vqNN6tAnJ lVew==
X-Gm-Message-State: AElRT7GrOdJY59JLdFBcVxylRFxuJd1wM6/79cHj4y9nekH2qW4RIMjz 5Oe7qJZSmM1Pk4bqchPSnymCzp9gWQo=
X-Google-Smtp-Source: AG47ELtnhjqUKew9NX9n/h3wnP+YaTmbGgkFyXRe6ykx8rVuY5nC6X+ql9+yK01+KRVIUMggJiTXIQ==
X-Received: by 10.99.56.68 with SMTP id h4mr7320118pgn.230.1521411379209; Sun, 18 Mar 2018 15:16:19 -0700 (PDT)
Received: from [192.168.1.102] (c-24-130-218-233.hsd1.ca.comcast.net. [24.130.218.233]) by smtp.gmail.com with ESMTPSA id c4sm23564821pgt.24.2018.03.18.15.16.18 for <netconf@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 18 Mar 2018 15:16:18 -0700 (PDT)
To: netconf@ietf.org
References: <8d4f4193c6694fe387d284d7b74c9b09@XCH-RTP-013.cisco.com> <20180314.093900.1449292548839197417.mbj@tail-f.com> <379cfb19a5c64753a067a2ae42f65a82@XCH-RTP-013.cisco.com> <20180314.145841.72164558423482638.mbj@tail-f.com> <9b8cf6b9e6114e00800525db71505023@XCH-RTP-013.cisco.com> <CABCOCHSzcFg81LZPRhV5toN2x48AqbPk8CCt4Y-4B_GT1OrHkg@mail.gmail.com> <041f01d3be9f$c73a2370$55ae6a50$@clemm.org>
From: Randy Presuhn <randy_presuhn@alumni.stanford.edu>
Message-ID: <3cf17c80-ec49-b134-b034-4f71b0c0457a@alumni.stanford.edu>
Date: Sun, 18 Mar 2018 15:16:17 -0700
User-Agent: Mozilla/5.0 (Windows NT 6.0; rv:52.0) Gecko/20100101 Thunderbird/52.6.0
MIME-Version: 1.0
In-Reply-To: <041f01d3be9f$c73a2370$55ae6a50$@clemm.org>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/netconf/xkuv_OHCbvmqNSz_4P6WCrXmx9E>
Subject: Re: [Netconf] [SPAM?] RE: LC on subscribed-notifications-10
X-BeenThere: netconf@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Network Configuration WG mailing list <netconf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netconf>, <mailto:netconf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netconf/>
List-Post: <mailto:netconf@ietf.org>
List-Help: <mailto:netconf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netconf>, <mailto:netconf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 18 Mar 2018 22:16:22 -0000

Hi -

On 3/18/2018 2:59 AM, alex@clemm.org wrote:
> Yes.  Conceptually, it is cleanest to apply the filter on the event 
> contents with each update.  At the same time, in the interest of 
> performance, Andy and others have raised the issue of performance 
> penalty if every update has to be subjected to a filter.  One option is 
> for an implementation to simply reject a subscription if there is a 
> chance that it might contain information that would have to be filtered 
> (i.e. do the NACM check at the time the subscription is created), and in 
> case of NACM changes later that might affect subscriptions, to terminate 
> the subscription (and let users resubscribe).

This would increase the cost of NACM configuration changes (probably
not a big deal, but it means hooks between NACM and the notification
subsystem are needed so NACM would be able to let the notification
stuff know it needs to re-evaluate some of its subscriptions) and
would potentially leak information to other users about the fact that
the security administrator is making NACM configuration changes, even
if nothing is happening that would otherwise expose the fact that
the change has taken place.

Randy