Re: [nfsv4] I-D Action: draft-ietf-nfsv4-integrity-measurement-06.txt

David Noveck <davenoveck@gmail.com> Mon, 23 September 2019 17:19 UTC

Return-Path: <davenoveck@gmail.com>
X-Original-To: nfsv4@ietfa.amsl.com
Delivered-To: nfsv4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 02746120025 for <nfsv4@ietfa.amsl.com>; Mon, 23 Sep 2019 10:19:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MDxT33RumcwM for <nfsv4@ietfa.amsl.com>; Mon, 23 Sep 2019 10:19:37 -0700 (PDT)
Received: from mail-oi1-x22d.google.com (mail-oi1-x22d.google.com [IPv6:2607:f8b0:4864:20::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B72561200F4 for <nfsv4@ietf.org>; Mon, 23 Sep 2019 10:19:37 -0700 (PDT)
Received: by mail-oi1-x22d.google.com with SMTP id t84so8254667oih.10 for <nfsv4@ietf.org>; Mon, 23 Sep 2019 10:19:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=zohgNJD11Wgn5sIoPIDGxec6QNl+Kk3hVLpQ8OAjdFA=; b=taSODOAfOHLiBaGhOZsc7Rj5i/TT2C7OhIMzOwEQAFPBEAtomGt37Fl8eiEgB99drS KF90mffTqkLucX8XBM8ktobghVbTgxQg9oKq/3gLNxcx2vf3NZTQCSPLkaxNjHEgnH2Y wsbfgDeADuvjJYDfNDlj9TlTYvRO8bfj0kZb7fvIZnLITV/ESnDCubPeo1MmmYb2Ocf8 ++jMKCfmmZQTE6tFHaOR5j3auh+Wu6IBLPEoXmFmiWCwekXKqdvn1vWknp3mU6E5PNg9 DnV0GILB/3MnB0gyUodLQTH1RMkAfoVLlzpW+7YfHoxDryg5mlBNEI4pMAMB7HOpWjqy xI9Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=zohgNJD11Wgn5sIoPIDGxec6QNl+Kk3hVLpQ8OAjdFA=; b=A/rR5vZ1ttIgWs39TAXdB6jv0Ba82DKM+p3DuutrEaLv/VT5zmj7OPUioKF8DkI+Dl v4tpQCx1Zp+itudB4SyE2h7+4+TWDMggQUYYYrHCvp8knunI/ncIp5leKsTdXJW12LrT C3Lk7DHcevapNnlAAIQ3gA4QxaYfFzStYy0fIGo7Kmk6ZYrzf5YENpK8ltcklD9jMj+M AwaHvEiMO2XrFk8I4w8CJ0yIDGyceAUl9D6t7aeRxUrXqjpm8528eemINjBZnY6i1mYx K09BLkv8PCbMfWa4Vxa3MUWPaupeuNDkKY40TrAiVvegvPWmsG5QmKIIoZ/jmiKF9Wo0 oEgA==
X-Gm-Message-State: APjAAAVXjRJn0sNOmpQQAeA7LsXpqHInwOPd0Owm010+RKFlIRquaxb3 UPlO3dndbd+juAAFw4hs1GjcAdGlSYHd9pZ6+sE=
X-Google-Smtp-Source: APXvYqxdw+2FrvUB/8eTw9RN0+1KMR2KPFoRlwBCHgKrweU8vQYtRqeVMfeAMCdEkYLpk0FsbTHSDgXe3d6zJ1wAmlI=
X-Received: by 2002:aca:5856:: with SMTP id m83mr979004oib.90.1569259175835; Mon, 23 Sep 2019 10:19:35 -0700 (PDT)
MIME-Version: 1.0
References: <156919386717.1348.4052993311401417839@ietfa.amsl.com> <9BFB101A-F1E8-45C8-A85E-74DB434CE658@oracle.com> <CADaq8jdS+MUgV6kQ7hGH8vh47Akejc4N0djHerU5VFKGRW6oSw@mail.gmail.com> <A455DB96-4C40-491C-A0EB-A602FE64766F@oracle.com>
In-Reply-To: <A455DB96-4C40-491C-A0EB-A602FE64766F@oracle.com>
From: David Noveck <davenoveck@gmail.com>
Date: Mon, 23 Sep 2019 13:19:24 -0400
Message-ID: <CADaq8jfBCoJ=dx5uGGJZhdH7x3Ca3HWEPsi19KVPJW9dKok4Yw@mail.gmail.com>
To: Chuck Lever <chuck.lever@oracle.com>
Cc: NFSv4 <nfsv4@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000bc7e0d05933b9f84"
Archived-At: <https://mailarchive.ietf.org/arch/msg/nfsv4/XXoQgcr8K7atEHL9goBgozC4acM>
Subject: Re: [nfsv4] I-D Action: draft-ietf-nfsv4-integrity-measurement-06.txt
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nfsv4/>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Sep 2019 17:19:42 -0000

> The guidance in that section falls into the realm of "compromise between
the Linux community and the > specification writer"

I gaathered that, but it should not be assumed that the woring group is
prepared for the same level of compromise, even though it should strive to
be as helpfu as it can.   Also, it appears that the Linux community cannot
make its own mind about how to address this issue so perhaps some
intra-community compromise is in order.  If that isn't forthcoming, our
only option might to approve this as an experimental/informational  RFC and
upgrade it when the Linux community gets its act together.

On Mon, Sep 23, 2019 at 12:28 PM Chuck Lever <chuck.lever@oracle.com> wrote:

> Context: The guidance in that section falls into the realm of "compromise
> between the Linux community and the specification writer".
>
>
> > On Sep 23, 2019, at 8:23 AM, David Noveck <davenoveck@gmail.com> wrote:
> >
> > > It's probably ready for (it's first) WGLC. :-)
> >
> > I feel that the basic issue with section 4.3.2 has not been
> > satisfactorily resolved.    I'll send out a mail with the details
> > in the next few days.
> >
> >
> >
> > On Sun, Sep 22, 2019 at 7:15 PM Chuck Lever <chuck.lever@oracle.com>
> wrote:
> >
> >
> > > On Sep 22, 2019, at 4:11 PM, internet-drafts@ietf.org wrote:
> > >
> > >
> > > A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> > > This draft is a work item of the Network File System Version 4 WG of
> the IETF.
> > >
> > >        Title           : Integrity Measurement for Network File System
> version 4
> > >        Author          : Charles Lever
> > >       Filename        : draft-ietf-nfsv4-integrity-measurement-06.txt
> > >       Pages           : 18
> > >       Date            : 2019-09-22
> > >
> > > Abstract:
> > >   This document specifies an OPTIONAL extension to NFS version 4 minor
> > >   version 2 that enables Linux Integrity Measurement Architecture
> > >   metadata (IMA) to be conveyed between NFS version 4.2 servers and
> > >   clients.  Integrity measurement authenticates the creator of a file's
> > >   content and helps guarantee the content's integrity end-to-end from
> > >   creation to use.
> > >
> > >
> > > The IETF datatracker status page for this draft is:
> > >
> https://datatracker.ietf.org/doc/draft-ietf-nfsv4-integrity-measurement/
> > >
> > > There are also htmlized versions available at:
> > > https://tools.ietf.org/html/draft-ietf-nfsv4-integrity-measurement-06
> > >
> https://datatracker.ietf.org/doc/html/draft-ietf-nfsv4-integrity-measurement-06
> > >
> > > A diff from the previous version is available at:
> > >
> https://www.ietf.org/rfcdiff?url2=draft-ietf-nfsv4-integrity-measurement-06
> > >
> > >
> > > Please note that it may take a couple of minutes from the time of
> submission
> > > until the htmlized version and diff are available at tools.ietf.org.
> > >
> > > Internet-Drafts are also available by anonymous FTP at:
> > > ftp://ftp.ietf.org/internet-drafts/
> >
> > Fresh revision incorporates comments from IETF 105 and Linux
> > Security Summit North America 2019.
> >
> > It's probably ready for (it's first) WGLC. :-) It's OK if the
> > chair prefers to wait until we have more fully dealt with
> > outstanding RFC 5661 errata.
> >
> >
> > --
> > Chuck Lever
> >
> >
> >
> > _______________________________________________
> > nfsv4 mailing list
> > nfsv4@ietf.org
> > https://www.ietf.org/mailman/listinfo/nfsv4
>
> --
> Chuck Lever
>
>
>
>