Re: [nfsv4] Adoption call for draft-dnoveck-nfsv4-security

Thomas Haynes <loghyr@gmail.com> Tue, 18 October 2022 17:32 UTC

Return-Path: <loghyr@gmail.com>
X-Original-To: nfsv4@ietfa.amsl.com
Delivered-To: nfsv4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF459C1524BC; Tue, 18 Oct 2022 10:32:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.107
X-Spam-Level:
X-Spam-Status: No, score=-6.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MwqaXg64-8qn; Tue, 18 Oct 2022 10:32:18 -0700 (PDT)
Received: from mail-pg1-x533.google.com (mail-pg1-x533.google.com [IPv6:2607:f8b0:4864:20::533]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 65509C1524DD; Tue, 18 Oct 2022 10:32:18 -0700 (PDT)
Received: by mail-pg1-x533.google.com with SMTP id e129so13903278pgc.9; Tue, 18 Oct 2022 10:32:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:from:to:cc:subject:date:message-id:reply-to; bh=YAjBi5L4AqrU+bdMxzjbib+tznsnCLh0eGCRhGmkD5g=; b=ai6nDtQaPWYg9bvE8zKA+oBSMdUzWZH38kjJxiSWZOST/9SHU5OIAnwe/m+h+0L8h6 +CE5O3a8NfYBZPpqldg1whk9YLwG9OzKHnaAXIMEHR+YtRERrkxjJ+zBnlYi4WTn5JsZ 4R/O5zMV/cEe0tCqpCzcGATjFP57hY4YRkYP/4ujhM65bLph99qvmLiE7a5ebbtGr/o8 WRdF+bR9AzwY+dEYMzklhulw8Z/F46nrlJxvcZc9RC3LqpsuI9mJiB4SqKnXEzwQLli0 7CgPKIr/GpJPV9u2/7NLcvHHyICBgj321NedvdeQ7532/O1DCJWYfTnV/Aoa7HcZQzRJ WGHQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=references:to:cc:in-reply-to:date:subject:mime-version:message-id :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=YAjBi5L4AqrU+bdMxzjbib+tznsnCLh0eGCRhGmkD5g=; b=SUmjR6v6CLPevLx8/bWROXTWWuQKiOcXesdlwoqJe0wgvZkgaLkuY7bsVj5jYzql74 xEUav3upUuzSroZmmZ+i3bQhux5mWm5pc3wqddSwk7yRhpOV8R8OlXlnI/Tx2NnwusPz Isc2mB3zP1AzVn+gblmCqigXUixBBVouWR5hu1n9jcfOlZRa8oNxkvlVISzBlH9qOccw aI+df14TljSQDK3XvZIKguAFCfQZ77Ti7EC/LnhGj/dzbTFg6cRBQFjUEEXxXuM7l/84 dhYpT8bfzOeV0YUhxJ6Djdc/yJftEbq5lWXyeyjVWZThbwB9F5Ejx9aHxWN8p6iP955I cQOQ==
X-Gm-Message-State: ACrzQf1ykN6q67aTs5zTzBnEoseboKHFOpVKgin7I3OIsFF2mDB+BUAh 0iAcJlG+c2aNJ1k6JvBOu7s=
X-Google-Smtp-Source: AMsMyM7vJ4+AJUYkGI6wfTX+03VGNX3c/PXWirGgMdHsMY7E7OHecE11oY6aVjyTO5j+5sx6P0AJeg==
X-Received: by 2002:a63:534e:0:b0:44e:12bf:2df8 with SMTP id t14-20020a63534e000000b0044e12bf2df8mr3523533pgl.143.1666114337477; Tue, 18 Oct 2022 10:32:17 -0700 (PDT)
Received: from smtpclient.apple (c-69-181-124-201.hsd1.ca.comcast.net. [69.181.124.201]) by smtp.gmail.com with ESMTPSA id a9-20020a1709027e4900b0017f8094a52asm9061870pln.29.2022.10.18.10.32.15 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 18 Oct 2022 10:32:16 -0700 (PDT)
From: Thomas Haynes <loghyr@gmail.com>
Message-Id: <F5F9FAC8-3507-431B-8D1D-5667477D65E8@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_8DEFE911-EE31-4720-ADA5-632C5E26CD2A"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
Date: Tue, 18 Oct 2022 10:32:13 -0700
In-Reply-To: <CADaq8jfZP6GTQQXZZ_01xK1wNNn85-wko7kMu+7qG2nfK7G5aw@mail.gmail.com>
Cc: NFSv4 <nfsv4@ietf.org>, nfsv4-chairs <nfsv4-chairs@ietf.org>, nfsv4-ads@ietf.org
To: David Noveck <davenoveck@gmail.com>
References: <CADaq8jfi1ApVZeJ6LsGSPY=kRXQ2W_NZ9ixwcOnJJ-A_RH4SPA@mail.gmail.com> <E93D76F0-3604-41ED-A240-60D93C2FA107@gmail.com> <CADaq8jfZP6GTQQXZZ_01xK1wNNn85-wko7kMu+7qG2nfK7G5aw@mail.gmail.com>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/nfsv4/x0Sx2GrojR9F93s-C6BbcIFc5iI>
Subject: Re: [nfsv4] Adoption call for draft-dnoveck-nfsv4-security
X-BeenThere: nfsv4@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: NFSv4 Working Group <nfsv4.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/nfsv4/>
List-Post: <mailto:nfsv4@ietf.org>
List-Help: <mailto:nfsv4-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/nfsv4>, <mailto:nfsv4-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2022 17:32:19 -0000


> On Oct 17, 2022, at 9:43 AM, David Noveck <davenoveck@gmail.com> wrote:
> 
> 
> 
> On Thu, Oct 13, 2022 at 10:41 PM Thomas Haynes <loghyr@gmail.com <mailto:loghyr@gmail.com>> wrote:
> 
> 
> > On Oct 13, 2022, at 11:07 AM, David Noveck <davenoveck@gmail.com <mailto:davenoveck@gmail.com>> wrote:
> > 
> > This is an adoption call for draft-dnoveck-nfsv4-security.
> > 
> > This document describes nfsv4 security for all nfsv4 minor versions.  It was written as part of rfc5661bis effort and is intended to result in a standards-track document.  PAs stated in the abstract:
> 
> 
> Who has agreed to do the changes in their implemementations? I.e., security is important, but which vendors have agreed to make changes in their v4.0, v4.1, and v4.2 product implementations?
> 
> Nobody, but none are required.   Continuing to rely on old ways of doing things is considered a valid reason to bypass any recommendations to do things more securely.
>  


So suddenly all existing implementations are no longer compliant?

Also, what happens if there are issues in the new specification that would be flushed out with working code?

We have pushed out too many “features” without any implementation. (And I include myself in that “we”.)

Adopting this draft as a WG item without any corresponding implementations is a non-starter for me.