Re: [netmod] Alternative approach to draft-ma-netmod-immutable-flag-00
Andy Bierman <andy@yumaworks.com> Wed, 23 March 2022 21:32 UTC
Return-Path: <andy@yumaworks.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id A04BA3A10E8
for <netmod@ietfa.amsl.com>; Wed, 23 Mar 2022 14:32:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.797
X-Spam-Level:
X-Spam-Status: No, score=-6.797 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_HI=-5,
SPF_HELO_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_PERMERROR=0.01,
URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=yumaworks-com.20210112.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id D0y4--HVbMsa for <netmod@ietfa.amsl.com>;
Wed, 23 Mar 2022 14:32:34 -0700 (PDT)
Received: from mail-yw1-x1129.google.com (mail-yw1-x1129.google.com
[IPv6:2607:f8b0:4864:20::1129])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id DE8653A10DA
for <netmod@ietf.org>; Wed, 23 Mar 2022 14:32:33 -0700 (PDT)
Received: by mail-yw1-x1129.google.com with SMTP id
00721157ae682-2e5e9025c20so32215997b3.7
for <netmod@ietf.org>; Wed, 23 Mar 2022 14:32:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=yumaworks-com.20210112.gappssmtp.com; s=20210112;
h=mime-version:references:in-reply-to:from:date:message-id:subject:to
:cc; bh=BwCur0usWbb+tFnQ6hfxe12jzZlW/4i7Uge7T/nDw3A=;
b=WDgGWtOXsttK+qBQhGWWABSIvdeRt4O3bN0kaADk4oFaXlRZ6LsAk6Ma9dYWlKswS/
ertG4nzVnBE/B6pW8+DNfWMS0n/Hx/klEkekpum4wxt4CFHnqmvWgRUPpwGe1SbQ0Or8
qpZ+KEB2WpvMtn7Zcbx0hY3ni62g2K3ZDM3mveY/G4grTu5GGNUGtI3rzysSZdep/TrV
vcGYFxjEuw7b+eCBP2SeH5WbU/Z4VRxlKkQF72kHp64HhMiYoKzIk8PhxjFjaeeaaucf
njG17cLAIjLCAI3Gqb5Axw5QjRrx7HqHELJg0+gvF0anaq8sHAswu3uUlfYl/wf51LjK
5Qrg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=x-gm-message-state:mime-version:references:in-reply-to:from:date
:message-id:subject:to:cc;
bh=BwCur0usWbb+tFnQ6hfxe12jzZlW/4i7Uge7T/nDw3A=;
b=0nmAYswFkxUbA+rkk6kKPTcNRX3+BoZhUN5sfzcBjoYdmRH432UCAW79t8trfWwvWN
hioB+XlNC7I3kkYLnU1Vl9FiGHDBALuIrrs+vFYbSuKNDb0kWERbgj4OncEfcgy1Dk9R
zEcvMaSts09ZJRMuHNrW3heKZQuxKupbEJCkKkpKcuwPL22TZsK8LVOQhYLF1lNSLhkT
lZp2cdC37NK5VD+ejukVf/DVsLYCjZZo6EJAoNwOQ5E5Bc3ttAmJqWaxXIimC5OqDjQE
feMLHJwYAYxEKJ3nfooq8sL4aKBLqRuZ19oOjFia/s71vUS2ACptXKNubwm8jqDfifQF
JW4w==
X-Gm-Message-State: AOAM530oY2ydS2BNAFQndGERyAvY8BAtkiqom0x2/Wpw5wcAIZprDbPc
K6UR0NAaWdlD8F0hFgTuY1CUu7E8hhp6AtqF3HdFllOW6aw=
X-Google-Smtp-Source: ABdhPJzYRsaGbtJHoh/2YpbtqPBKWobcXlb4RpCsHJnNElpG+O28b49WWIw9TfiZieE9odmx+fxXQr/LmTcbyFOdMBc=
X-Received: by 2002:a81:5dd6:0:b0:2d6:3041:12e0 with SMTP id
r205-20020a815dd6000000b002d6304112e0mr2072265ywb.331.1648071152531; Wed, 23
Mar 2022 14:32:32 -0700 (PDT)
MIME-Version: 1.0
References: <CABCOCHRqZgCfH0j5XnEt0aK0fwVCaxe_aSHCAZn3jb0QLrDuKw@mail.gmail.com>
<VI1PR0701MB2351A430BA5F2EEFE96CE094F0189@VI1PR0701MB2351.eurprd07.prod.outlook.com>
In-Reply-To: <VI1PR0701MB2351A430BA5F2EEFE96CE094F0189@VI1PR0701MB2351.eurprd07.prod.outlook.com>
From: Andy Bierman <andy@yumaworks.com>
Date: Wed, 23 Mar 2022 14:32:21 -0700
Message-ID: <CABCOCHSY6CN7Xf05RtTF0jm1S6gLd1umr5BtG3pkkeCBu47Jyw@mail.gmail.com>
To: =?UTF-8?Q?Bal=C3=A1zs_Lengyel?= <balazs.lengyel@ericsson.com>
Cc: NetMod WG <netmod@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000009c965905dae9776a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/uJ4iQ8H5GpbMxkMr872UoqE3QXE>
Subject: Re: [netmod] Alternative approach to
draft-ma-netmod-immutable-flag-00
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>,
<mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>,
<mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Mar 2022 21:32:39 -0000
On Wed, Mar 23, 2022 at 2:16 PM Balázs Lengyel <balazs.lengyel@ericsson.com> wrote: > Hello Andy, > > I also propose an extension. (see my mail Review of > draft-ma-netmod-immutable-flag-00) > > In Ericsson we saw no need for exceptions, but do see the need for > applying it to descendant nodes. Typically we need to protect a full > subtree. > > > > Why do you need the exceptions? Could you provide some use-case examples ? > I think create/delete-only and modify-only access modes are used the most, after no-access. Applying to descendant nodes may be better, or may require more work to undo the extension used in an ancestor node. This impacts the extension usage within a grouping. Regards Balazs > Andy > > > *From:* netmod <netmod-bounces@ietf.org> *On Behalf Of *Andy Bierman > *Sent:* Wednesday, 23 March, 2022 21:10 > *To:* NetMod WG <netmod@ietf.org> > *Subject:* [netmod] Alternative approach to > draft-ma-netmod-immutable-flag-00 > > > > Hi, > > > > IMO the problem should be viewed as a refinement to the > > access control policy of the device. A standard mechanism > > such as a YANG extension would be better than a growing > > mix of proprietary solutions. > > > > We have such a YANG extension called "user-write" that is widely deployed. > > A simple boolean is not fine enough granularity, so a bits type is > > needed instead to allow control of create, update, and delete access > operations. > > > > > > > https://www.yumaworks.com/pub/latest/yangauto/yumapro-yangauto-guide.html#ncx-user-write > <https://protect2.fireeye.com/v1/url?k=31323334-501d5122-313273af-454445555731-876c03f0bc610d95&q=1&e=c875257e-41f5-45d6-a9e9-871e5ebb4243&u=https%3A%2F%2Fwww.yumaworks.com%2Fpub%2Flatest%2Fyangauto%2Fyumapro-yangauto-guide.html%23ncx-user-write> > > > > > > Andy > > >
- [netmod] Alternative approach to draft-ma-netmod-… Andy Bierman
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel
- Re: [netmod] Alternative approach to draft-ma-net… Andy Bierman
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel
- Re: [netmod] Alternative approach to draft-ma-net… Kent Watsen
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel
- Re: [netmod] Alternative approach to draft-ma-net… Andy Bierman
- Re: [netmod] Alternative approach to draft-ma-net… maqiufang (A)
- Re: [netmod] Alternative approach to draft-ma-net… Andy Bierman
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel
- Re: [netmod] Alternative approach to draft-ma-net… Andy Bierman
- Re: [netmod] Alternative approach to draft-ma-net… Balázs Lengyel