Re: [Ntp] Last Call: <draft-ietf-ntp-mode-6-cmds-08.txt> (Control Messages Protocol for Use with Network Time Protocol Version 4) to Historic RFC

Brian Haberman <brian@innovationslab.net> Fri, 12 June 2020 17:20 UTC

Return-Path: <brian@innovationslab.net>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 156FC3A0AF9 for <ntp@ietfa.amsl.com>; Fri, 12 Jun 2020 10:20:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=innovationslab-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r8DGzz0lH3pA for <ntp@ietfa.amsl.com>; Fri, 12 Jun 2020 10:20:31 -0700 (PDT)
Received: from mail-qv1-xf32.google.com (mail-qv1-xf32.google.com [IPv6:2607:f8b0:4864:20::f32]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5FE8E3A1167 for <ntp@ietf.org>; Fri, 12 Jun 2020 10:20:23 -0700 (PDT)
Received: by mail-qv1-xf32.google.com with SMTP id fc4so4705090qvb.1 for <ntp@ietf.org>; Fri, 12 Jun 2020 10:20:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=innovationslab-net.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:autocrypt:message-id:date:user-agent :mime-version:in-reply-to; bh=ZSQai19sXdIgv/3If1l6nxytaFHQ1VDAERXBlXburdM=; b=tfImyJJyShsTWGLCGOoXNYi+ifBQDaamO9ZkUaZxfmQ+bMo4g2yAqoPSR9yiWq4zlk AM5wSQIvQHXZ5yRZFdb2rkTZtYwN7MQPQwSwsJEUQ9EH4MIgn7py6VzxPzsXsVhFIE6N uBk/W6PbmFDP4hR9Ru9vOb96dh/xEY4tws4UNyrIpWf03xlxBwJWu/V6ReJoui5/7DKs gsWI43qtwGlxRTMxh0wNjHxNvNtIWtKhhKSzbWCKPIiKQUjxvkwjqasfhCrZBayncwmH +peF9CrdwWuLAyLvec2OuRIRCXPrIy+3YkQvxheMgsB/84TlXtYz5Q0x16T8lJ2Kdb0t eDsw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:autocrypt :message-id:date:user-agent:mime-version:in-reply-to; bh=ZSQai19sXdIgv/3If1l6nxytaFHQ1VDAERXBlXburdM=; b=iL837kgCf6bWOwwqiW5VbNev3y8CJHakMxsg1P6BBhhGM8qzw+N2/4SQkaaYen1CLd ssq1hBUzeOTLIess0TbscPERTXAlU3NaD3eBH+v35baVNeiofDKIsbVQXppZrBlBbzld n/d7NoMJ9bneLu+JU3b9LQALodmplJXzltWfW3slv3pDsEO6xO8PMSEKdgqREtizOLAX 1JbKQWBKZBHnjcssg1U0Y2btGgMIK2OFf8DkicSSyJmFpnQLKUJIhTBUZcl/mzHFOumX tHy7rftYWK66pDyPIU4Q1CeM21MRx5brEdhtMOBWxY9QuOvQmy7U6ORUopl0/HFZWLFy tPwA==
X-Gm-Message-State: AOAM530tSArci77tpaJKiFmonyVJv54u/bn7maRRKnYz8HnrRvX/PL3f tAuDkpkixiWrppimeMUv998zUg==
X-Google-Smtp-Source: ABdhPJzvSOEs7LHmIqUJPTOklLF20FsPXHLIG6hITp4BUnz+x+akaQ+EoPH060CiOuSfUPf5ih5HPQ==
X-Received: by 2002:ad4:438c:: with SMTP id s12mr13992004qvr.200.1591982422432; Fri, 12 Jun 2020 10:20:22 -0700 (PDT)
Received: from LakeHartwell.local ([2601:154:c001:f99e:7c90:3d3e:34c5:9457]) by smtp.gmail.com with ESMTPSA id e16sm5428361qtc.71.2020.06.12.10.20.21 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 12 Jun 2020 10:20:21 -0700 (PDT)
To: Pete Resnick <resnick@episteme.net>, last-call@ietf.org
Cc: ntp@ietf.org, ek.ietf@gmail.com, ntp-chairs@ietf.org, draft-ietf-ntp-mode-6-cmds@ietf.org, Karen O'Donoghue <odonoghue@isoc.org>
References: <159103987149.20717.15985853306560767734@ietfa.amsl.com> <45F5F313-BFC6-48BB-B5A3-D47C48AE87D6@episteme.net>
From: Brian Haberman <brian@innovationslab.net>
Autocrypt: addr=brian@innovationslab.net; keydata= mQINBFm5KgYBEACs2icafejrG19L5DRNFq8Q2O+K+LRxjR4qAElZDnXFXNA2ipFWPeT0J2wa KJ+h9UdfhDm8DzULB553CYm+Q3XF1N56TglkIRMZYc7mYXZEr3x7e4fmX4kD4qMjBLG8cL26 rEe3Q0qaiMGY69/4o5coVMT0qmHjgCH1tkG+L2Y8MKr1gFxS18eO8MVoWe1yDKuyxFSElHGB 3mZn4gcqeCaemPGG3CiVNlp4KnijpNcSgvseXbkQEA4IXEsIvUL8MIwOTXg9Gh5cbtisZpuf +4B0LNMUSqWlqyKd9M3KCMj+dW4vsFytc00Z+GyQ+ArOR9GwTdAwJ5qqVODTvbjKqOR1zolJ 1JxLUtSiv7Lx5x2OrCexPYXkzlTkjG9Imtg2XNh55R/JKMC3KU1NQL3nS9tJXeoRWNgWSZrG MsrbeejbqLVb9LblXNpgLciJ96XHMvYAXX7p4LAwivzSRrVg46vErYIAV6EvDvwVENWW8JCU 0vX5iTGfkEwU4KxCa7WAmmD8yiNspHP1J0uk93Sta5K0PuTi7b+EZlCjdrqOEWLGPv6qXlIu FwLLcCaDs3XdVvwgNM+UFRxFH1aOVQQKCiCOCcNlwgYG1u4ZbD2T6hd/d2tOAKu/MNnQVF7d Cfi2BtSjzglLcY61e37zqTM04BgU+LniZ7V99yneM6DM2UzgkwARAQABtClCcmlhbiBIYWJl cm1hbiA8YnJpYW5AaW5ub3ZhdGlvbnNsYWIubmV0PokCQAQTAQoAKgIbAwUJB4YfgAULCQgH AwUVCgkICwUWAgMBAAIeAQIXgAUCWbkqSAIZAQAKCRBo1jycU9GLYQixD/9UX0uiAvbJ+4dK z3Ne3kUdDK0Lk73RGfFgE/ezsc9I6ED82h+arC8pAoDnBWgzTxugZdbexek983bgMq02XFsG pJf7hudeKnB8UmtjTc0j1UUgi129FYyBmINS2Lz1gpEOygFfbeOGLJK5qZJwD3I3O6yN8SUZ uwahXXd1aEB+d1eGhNqxkjQ+L7vdfTlN662GWog3ROMwUbrg0+QAbn/Vlp2iIYO6VERUZ9Yr GfFJX9b9LKa6AHxzAaqFIix1h2wBiIacpIBGU/4+3+wL5zkCbGSRzoIHW8srllj7ehgwwfNx QevibuZWJ4XpHpIxrtsmBO7ERFk8pN7oiQ9M3b2Cg9OBD5vgxyMCHEKIblWyKz8GLtz5357L ORU1EBWB8BoJPBHz3u7bZE+jH9+w5PpI087Ae78KCDkTNj7o2wbkRoYLmLpMo8DOwAumyy5R 2DuRu0cn5Rw5pFjlJkyfM0Wf80Ml/SINrUORWeqSbsHSX8i+Y0Oyt5JNo9NFbgN0Gn/Qo364 I8cLgbvUAyFHwhnmbHB+QXFCGAy73NOQ+g2fCRPeSbihhYa34ugfmd4oa6W2w805ixzM7iGr P+wDB1dhA7eHKVmoo9Kxvm9VzU+2homYGEROd/H6n0BMvWtp1oFh/JvEgZN6dVLg3p+XX5Zj Ggy568bIY4P5kP7pAxh017kCDQRZuSoGARAAtCWxW1cRne/iGbFuibvB8d3upcbCB7oz4LWk LSE20Db2ymn04ici9V+wBSWX57me5jQdwMi/gzVVZcupbzWTg5Yhv7Qt7CKORJLEKo6nULbb 4aEpdOXD9s7wwx+foFjzjtDOH/JYoB+OEe2oW39VmK6EsIx7ClsLf6+cih5yApZHtmV+2M3J YSxD2kCUE619ITFLAkMf203ap5vJ6DDaaKnVoNhF9qV7jlJEceGqHTBG4KkBX/zNCehMIfhr ViY/B2IWAHeuZ99lnCPx2mehGGa4XLjQauUkY9KB7dOq/ODyt+7SL0dfWrOVf3BnU3C308b4 9YdId8KI4dJ30nfXn6ifTK9STZHZE+Mt1sIVmtEguqMXEk/axZmT14x194c7ZPmU/uCQTE3U y1NFs4Yof50WF1ze0CyN2ycmqx11mHjP5+L23TqcdIWmJG+EtdHUAFpu42kbB0fML3Oc/cEU SmWK3WpF5YPljLM2gyh3RXjuiBnaGoJaKTOj5zXQ2G2l3/ijbn9FbqmFup+R352dxUyakXEP xNe3HdyjfyUcy/RJNeZz/lgUIhkxWQjOOU1RIN41RtCKcF9tJjMwgQvI51QmPvf90/6ab3I/ vwEpjlRb4AbuWfPWe89J+Z3TG97V9sntlMcQ6MGiPLbyFpiXIf2150e6FxZdJtipVwY2d/kA EQEAAYkCJQQYAQoADwUCWbkqBgIbDAUJB4YfgAAKCRBo1jycU9GLYfy0EACYrxb4nWtOnIu0 N7rXXo/0ZjaBTyUhJ6hzy2D7rt3vv/qj2ui+N21ui/yMDS928za/XRfP25qN9A1puioHqN4l SAsxwCC3mT9GJXVXVgivg3MeciqBXoOdnk1hUkP1CTKL3qZ9pSuw8bPlNE7+b1xF7Oce37YH +QRVmBXbGwTxtDTCZ9Js0/IpiUtg9QCfmryB1r/fD0TFb8b9aCBuVeKocWSuX9UXRt7zRGM8 BJwOLvdLdGvV8us1imlBKFLai4L8CPgihuc/s7ZB0r3pgW697hXScWhGHF3OUWbPFVkNyivM xtDcq+9ZlUMrxFbwUEABi8NFwvzwn+YJQqlrPiF4xxsScYpnIlfWEuP6Vpp6Z/u5x+1MNyZb oxNWWaevMVeo3tdRV9F6/YFqucw4JQ9HqlCKQ62sW9+e5SSlxGNlV4j9cchG6a4fAZqxL+pS ks+KitK3ap/R4RUG+nbjLlhCwGJIti8lxvdYAoPqjtwEUmMJv4dIl0/2h1495cwBIi7XeRKZ Rx38TV3G3LCx0J8dFhkyTG5TxUZQFgHjznkIX7bzeSQX72MxT0b/tc38yM71WpAgAY+MlHCT FQRKqIQsH/4MFir+g/oV2uPNGwmg0QEOnv9zZ79JJ/nBmuXC2RwUVTtZgtiZXhaP0afvR0eg WPEzptIZZCSmtBOOYkfsAw==
Message-ID: <9ea6c065-2904-ffd1-4370-17047cec7de9@innovationslab.net>
Date: Fri, 12 Jun 2020 13:20:20 -0400
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:68.0) Gecko/20100101 Thunderbird/68.9.0
MIME-Version: 1.0
In-Reply-To: <45F5F313-BFC6-48BB-B5A3-D47C48AE87D6@episteme.net>
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="UrglmnTmxLZTiotfQSE31fmSMixgJLSgC"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/7jr_YJkgCduIK-ueG6BRFpQTLqw>
X-Mailman-Approved-At: Fri, 12 Jun 2020 12:00:15 -0700
Subject: Re: [Ntp] Last Call: <draft-ietf-ntp-mode-6-cmds-08.txt> (Control Messages Protocol for Use with Network Time Protocol Version 4) to Historic RFC
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Jun 2020 17:20:32 -0000

Hi Pete,

     While I am responding to your note, I will capture thoughts related
to what others have said so far...

On 6/2/20 1:17 PM, Pete Resnick wrote:
> This use of the "Historic" status seems utterly bizarre to me. It's
> certainly not how it's described in 2026.
> 

It is a bit strange, but was done for a reason...

> 1305 has already been obsoleted by 5905. This document simply gives
> information about what those control messages were and indicates that
> they ought no longer be used. This sounds like a fine candidate for
> Informational status. When 5905 (or it's successors) advance to
> Standard, this document can be included in the STD.
> 
> If eventually you want to move a document to Historic, it would be 1305.
> 
> I don't think publishing this straight to Historic makes sense.
> 

There are two intents with this document.

The first is to capture mode 6 commands that were not defined within RFC
1305, Appendix B. If you compare the command sets, you will see several
additions in this draft. Several people have asked since the publication
of 5905 about some of those commands as they were not documented anywhere.

The second intent is to signal that mode 6/7 commands aren't/shouldn't
be used going forward. If you do a quick search for NTP vulnerabilities,
you will find many that relate to abuse of these commands. Additionally,
I/we received input (e.g., chronyd) no longer use these commands to
accomplish their stated function. That is where making the document
Historic seemed to make sense.

In the grand scheme of things, either Historic or Informational is a
viable document status. I (as document author) did not see consensus for
Standards Track, but that is not my call.

Regards,
Brian