[nfsv4] Some important history re bis effort
David Noveck <davenoveck@gmail.com> Fri, 05 July 2024 13:45 UTC
Return-Path: <davenoveck@gmail.com>
X-Original-To: nfsv4@ietfa.amsl.com
Delivered-To: nfsv4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 78315C14F6FF for <nfsv4@ietfa.amsl.com>; Fri, 5 Jul 2024 06:45:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DTcQPvypz3K5 for <nfsv4@ietfa.amsl.com>; Fri, 5 Jul 2024 06:45:07 -0700 (PDT)
Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E5AB2C169435 for <nfsv4@ietf.org>; Fri, 5 Jul 2024 06:45:07 -0700 (PDT)
Received: by mail-qt1-x830.google.com with SMTP id d75a77b69052e-445033fbc24so12075821cf.3 for <nfsv4@ietf.org>; Fri, 05 Jul 2024 06:45:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1720187107; x=1720791907; darn=ietf.org; h=cc:to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=fOFYWzmYfzt/ZRqsmh69+WRnvRSPg3HuuXHXT9ObJuY=; b=Qfjz+ZSqf2e0NuYm9ih5SG+3dr0Cq2hJsIf0XbZMPVcDrsEmkKBaNZhwLyoz6QkiV+ jHvVAPskIG34KQ7xSVardZ8qYnS/4s1VLewbVHcMfxXIRtq4/WSsmRC9LKtyb3FXnD4o mapoIG/emLhN+jUrJzKAfEsRUilSMtIS2CpXM3zEEsh7Np+5cSAXipqXn32cGf6CrMXI XDlpkLMpgsUuKEEkj5TVXR0HYZHEPdmYbKVQb7rO1YZXuqA31LIO9gWVnnuxvW6xS7Lu FsmzFQ5BuCdKphBiXxQqKvYZVFtOzcUfHdWwAPUy2qJ+IFgcgSih79vCgqWkBAp2gHNP pKiw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1720187107; x=1720791907; h=cc:to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=fOFYWzmYfzt/ZRqsmh69+WRnvRSPg3HuuXHXT9ObJuY=; b=UBUsdSRGWrO4xGdPKT0POgwAWycUAVhLsEyxIbHmtZRneh8SP3+s2Iw+GDSUCjK4eJ 4/QSd3p3thFLOPiivKtDTQ7WA7tIcMBPiBqXS3FU+Wq5c2E/nsnikQmui0obQn6IGImu lWXfLq8Kjq/rzTkCbWIj3RK4L7kt8u3Z9rmVW5Y55brOmUhcAxHLlP2Vm8pA3ME4W0eQ lr9Hlaak+k2m0/dQ6LEUWTCnq0aoCu81WWKU5yJN2dzmp1IYT0IalHRcckt5Q21P+I36 wwu5dVDks6dQcWJX963A5+8aLS14cR+pc5fvTFJwzEad2DSLgR3kB9ItLOv/ps0/79Q6 +TNw==
X-Gm-Message-State: AOJu0YysQ+/DnO2HAoCy4GBQiTPhrhkdLvj4jltxcZxmRR9kLHby9sa0 Dil0Un8LcMlZTARLgNvrd52H3NP/D6jhLV/PGfC7qFFt4GDPZf73SOGvTgIy8kYMdYAz6pjoMvu eJw37bkYEiVIDCwEEe6Bq9LXw2Bg=
X-Google-Smtp-Source: AGHT+IHaz84B12JEQE/Pr7GYutjFkh7Nnh+JOsK8+M1fDuT9nUzCmaWbxQmXY5aHB9+E1dmQB6Fm5m98gWOl1ZNdhkU=
X-Received: by 2002:a05:6214:2627:b0:6b5:e688:3662 with SMTP id 6a1803df08f44-6b5ed01ebd9mr60001996d6.29.1720187106698; Fri, 05 Jul 2024 06:45:06 -0700 (PDT)
MIME-Version: 1.0
From: David Noveck <davenoveck@gmail.com>
Date: Fri, 05 Jul 2024 09:44:55 -0400
Message-ID: <CADaq8jcdRn0ZSQOAXbQOSQmLXYLPp-D0iZA2BfESCCOjCDyTWg@mail.gmail.com>
To: Thomas Haynes <loghyr@hammerspace.com>, Chris Inacio <inacio@cert.org>, Brian Pawlowski <beepee@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000713247061c8045b9"
Message-ID-Hash: SNRTBTHVZEKQ6MTVK33KXVWAELUBVORM
X-Message-ID-Hash: SNRTBTHVZEKQ6MTVK33KXVWAELUBVORM
X-MailFrom: davenoveck@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-nfsv4.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: NFSv4 <nfsv4@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [nfsv4] Some important history re bis effort
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/nfsv4/IlKBS5Y_Cj7QwNxt58jiUp9yqVU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nfsv4>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Owner: <mailto:nfsv4-owner@ietf.org>
List-Post: <mailto:nfsv4@ietf.org>
List-Subscribe: <mailto:nfsv4-join@ietf.org>
List-Unsubscribe: <mailto:nfsv4-leave@ietf.org>
When you previously said that you sent a review which I had ignored, I scanned the wg list archive and got a better sense of the discussion over the last few years: - I did not find any review from you about my documents at the time the interim meetings started, which I believe was July 2023. If I have missed your review somehow, please let us know. If there was such a review, the issues it raises would need to be addressed now, if they have not been addressed before. - I did find some mail that is relevant to the history of the adoption process for the security document. This is of particular interest given the need to resolve the adoption question for the security document. The only relevant material I wound up finding was some mail about my documents that you sent in October 2022 and my responses to that mail. If that was what you were alluding to, then that clears up some of the mystery here, although I'm still unclear about some things. Although I still haven't found any of your mail that I ignored, perhaps my responses did not satisfactorily address the matter from your point of view. If so, we need to address any lingering issues as part of the forthcoming adoption call for the security document that Chris has undertaken to begin at IETF120 or before. The mail in question concerned an adoption call for the security document that began in October 2022. Although the document was not adopted, we never got a clear explanation about why. Since I had responded to your comments and there were no specific issues that I could address, the adoption issue was never satisfactorily addressed and we will have to resume our discussion as part of the new adoption call for the security document that Chris intends to start soon. In your mails, you raised two issues regarding prospective document adoption. Instead of trying to navigate a forest of greater-than signs, let me summarize them and my responses below: - You felt my document somehow forced existing implementations to change and that it was inappropriate for it to do so. My response was that the document was carefully written to not require changes in existing implementations and that I had seen no specifics regarding the claim that this was not the case. The document allowed existing practices to continue while not pretending, as previous specifications had, that this had no negative consequences As I received no specifics in response, I considered the matter closed, although your view of the situation might be different. - You pointed to a lack of implementation experience with the favored approach to avoiding the negative security consequences of using AUTH_SYS in the clear. At that time, work in this area was starting, although Rick reported on his work in some mail sent about that time. Nevertheless, I felt that making document adoption contingent on further implementation would be an unnecessary obstacle and that the working group, having put effort into making rpc-with-tls a Proposed Standard, did not really have the option of sticking with the existing insecure approach to security. In any case, the working group did not have a discussion of this matter at the time as it might have had if the chairs had followed up on the adoption call with a summary of the discussion. As things turned out, Brian was not able to do that at the time and the issue was never handed over to Chris when he became a co-chair soon thereafter. If this issue is still relevant, 21 months later, the implementation situation would be different and there is little reason for the group to wait for further implementation efforts before adoption. If you feel that my summary is not accurate or needs supplementation, please send any necessary corrections/clarifications to wg list. If people think these issues still need to be discussed, we can do so as part of the adoption call, if they have not been resolved before then.
- [nfsv4] Some important history re bis effort David Noveck