Re: [nfsv4] Comments on draft-ietf-nfsv4-integrity-measurement-07

David Noveck <davenoveck@gmail.com> Mon, 11 November 2019 19:43 UTC

Return-Path: <davenoveck@gmail.com>
X-Original-To: nfsv4@ietfa.amsl.com
Delivered-To: nfsv4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 51BD212097B for <nfsv4@ietfa.amsl.com>; Mon, 11 Nov 2019 11:43:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Nyad1CqXJMTh for <nfsv4@ietfa.amsl.com>; Mon, 11 Nov 2019 11:43:56 -0800 (PST)
Received: from mail-oi1-x236.google.com (mail-oi1-x236.google.com [IPv6:2607:f8b0:4864:20::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 97FD71208B0 for <nfsv4@ietf.org>; Mon, 11 Nov 2019 11:43:54 -0800 (PST)
Received: by mail-oi1-x236.google.com with SMTP id l20so12543069oie.10 for <nfsv4@ietf.org>; Mon, 11 Nov 2019 11:43:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=7Qt8Mz1y8G+M4kxzCjnBa7TGGQ8Wf0AsYmdMlucBwPE=; b=oOU+hnNhy5+IS5GT8LeMzXvfThH7wW0vGJdYVraVg+ijqbWq/5+pwqsW/fZzHhPVA2 p1fI11U0ZgWXxnLZ6sRLTfhHrnn3PrJf4PfMW6lwryP8xIbkyilNxAuJej4PwFFis1PQ sLh/m9wVK1a2Ydja8h5Ir+xqF3y31tHU3sSszUuTer7eTm+f7leylvPu5h0U9kPdRxjj uM1prnlHunhuAw5Q13VkDVljHXhpRw3g6Z99SyaJNfchLFNAzZG/rPx80uX83P1O+lVb 0DMHNJIozgUPxBKY1HEP0Ocnq9rcZHxDN4kVik7behjfsmCOtlRUP/41qMtD3KxkTTxc VBgQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=7Qt8Mz1y8G+M4kxzCjnBa7TGGQ8Wf0AsYmdMlucBwPE=; b=rAeXuwfo1sBOpvNDk6i5vVgwpCdta5AkV0KtT+XQ9ipq1mMlchjvDbYfBD8yw1Ss7i Rur0yV/bgMyrhMo6RK0fH53fCRcQV1vnmfl59ZCvG1O/d08GHao6D/aiiRtGwtQTmtaw rJS1TJVy8Q4gfwqxwX/2Vqe5tSs0QQMkB9cidsuruKQUT8bcViIZOaEShSjFucsDlkOr l4C774YR9ReREXwoDQZ/qtejvD+wNjpp57+h0RqNKMfIrcv8skrF8tDGfrhi+iccuKYC 5hz60SfvSAk0B6srDTK5vmZSo9PBVu6DdcuzDSCspmdXJ1EjTgDq25zEx6ss2Un2xXa4 4SZQ==
X-Gm-Message-State: APjAAAXPBbI2qwgqY6bZR2QPMM1c5GA4cMXr1CW52fU1YByQPlvzJpGl wyfEbzA/fMyr3XMb0W76BTRvdh58Do/iib8VjOk=
X-Google-Smtp-Source: APXvYqxGF0AZkGUNFDCjKBYLuLrsFL4sAYz8IukMQVmNVNVmuJcu+B1eeigN0SGOKbn54gyzHvfk3c+V0B0cCJHSXU4=
X-Received: by 2002:aca:d17:: with SMTP id 23mr581133oin.136.1573501433679; Mon, 11 Nov 2019 11:43:53 -0800 (PST)
MIME-Version: 1.0
References: <CAFt6BakApq=FJWs+r-jwxvTdXYs9yOg9KS47no93kdnp2gZ_+Q@mail.gmail.com> <9BEBDE7A-522A-4A6B-8132-D9C3A8A4922C@oracle.com> <CAFt6Ba=q=vSt+wtcHsi59gWnwFpuUaDqQue7f=GFSUvd25uV+g@mail.gmail.com> <BFDF314F-B913-4C4A-BAB4-C09FA840F4F6@oracle.com> <CADaq8jc_gM0SWe9weRJYp7s7xjtN9kihbVnUiBN61hF2LUJjzQ@mail.gmail.com> <FD12C92F-BBF4-4174-B896-48738C02B78E@oracle.com> <CAFt6BanwC4uu=9SpZQdiGjFswzkC3cSWPzGia34qBT5W+uuMNw@mail.gmail.com> <5B51BB44-F39D-4EF6-9E1E-3EF958F90260@oracle.com> <20191031192409.GJ88302@kduck.mit.edu> <67D69A00-D231-4845-A840-F3D67D629554@oracle.com> <CAFt6BanShDjwD3SftuDUvChFq9zOU5h1UC2y=W+3bVm++jAEKA@mail.gmail.com> <479C7409-9DCF-4C11-84AB-2E3729D96B22@oracle.com> <CADaq8jfMXjewirgvyCgh3D+yXQSNEX3HbWMCnz=XYCKk5T=6iA@mail.gmail.com> <00F112E6-F869-4624-A68E-9C909AB3B653@oracle.com>
In-Reply-To: <00F112E6-F869-4624-A68E-9C909AB3B653@oracle.com>
From: David Noveck <davenoveck@gmail.com>
Date: Mon, 11 Nov 2019 14:43:42 -0500
Message-ID: <CADaq8jckJQ2GZw-wEY-TLhqWhXcom1QNn8oTLL6TSNZy+4OHzg@mail.gmail.com>
To: Chuck Lever <chuck.lever@oracle.com>
Cc: spencer shepler <spencer.shepler@gmail.com>, NFSv4 <nfsv4@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000000213780597175a30"
Archived-At: <https://mailarchive.ietf.org/arch/msg/nfsv4/nA0EHneUTi4JoeA_0aKRR-dHz50>
Subject: Re: [nfsv4] Comments on draft-ietf-nfsv4-integrity-measurement-07
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nfsv4/>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Nov 2019 19:43:58 -0000

On Fri, Nov 8, 2019, 10:12 AM Chuck Lever <chuck.lever@oracle.com> wrote:

>
>
> > On Nov 7, 2019, at 6:13 PM, David Noveck <davenoveck@gmail.com> wrote:
> >
>

> It appears that draft-ietf-nfsv4-integrity-measurement can't move
> forward without some description of the IMA metadata format.
>

It is my understanding that you already plan to do that in -08.


> My preference would be that the Linux community is responsible for
> the process and document(s) that describe their own format.


That's very sensible but that doesn't mean it's going to happen.

Failing
> that, a description can be added to integrity-measurement, as I
> recently proposed.
>

Understood.


> To make an IANA registry a sensible thing to do, at least one more
> independent integrity metadata format will have to be identified.
>

I think one has already been identified.  To make this scheme work, there
will need to have a common metadata format implemented.

Once it is implemented, it will need to be specified, leaving you with
following tasks:

   - Identifying a victim to provide it.
   - Figuring out when/where it will be provided.

The virtue of the IANA registry is that it gives you the ability to defer
these tasks.


> I will see what can be done.
>
> --
> Chuck Lever
>
>
>
>