[netmod] Eric Rescorla's Discuss on draft-ietf-netmod-schema-mount-11: (with DISCUSS)

Eric Rescorla <ekr@rtfm.com> Wed, 10 October 2018 03:10 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: netmod@ietf.org
Delivered-To: netmod@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id BC847130E67; Tue, 9 Oct 2018 20:10:51 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Eric Rescorla <ekr@rtfm.com>
To: The IESG <iesg@ietf.org>
Cc: netmod-chairs@ietf.org, netmod@ietf.org, joelja@gmail.com, draft-ietf-netmod-schema-mount@ietf.org, Kent Watsen <kwatsen@juniper.net>, Lou Berger <lberger@labn.net>, Joel Jaeggli <joelja@gmail.com>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.86.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <153914105176.10625.9957580509164313779.idtracker@ietfa.amsl.com>
Date: Tue, 09 Oct 2018 20:10:51 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/gUZ6YagBVCyllq8sT3I6q9sUmx8>
Subject: [netmod] Eric Rescorla's Discuss on draft-ietf-netmod-schema-mount-11: (with DISCUSS)
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Oct 2018 03:10:52 -0000

Eric Rescorla has entered the following ballot position for
draft-ietf-netmod-schema-mount-11: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-netmod-schema-mount/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------

Rich version of this review at:
https://mozphab-ietf.devsvcdev.mozaws.net/D3506



DETAIL
S 4.
>   
>      It is worth emphasizing that the nodes specified in
>      "parent-reference" leaf-list are available in the mounted schema only
>      for XPath evaluations.  In particular, they cannot be accessed there
>      via network management protocols such as NETCONF [RFC6241] or
>      RESTCONF [RFC8040].

What are the security implications of this XPath reference outside the
mount jail? Specifically, how does it interact with the access control
for the enclosing module.