Re: [ntpwg] IPv6 Router Advertisement Option for NTP Configuration

Danny Mayer <mayer@ntp.org> Thu, 17 June 2010 02:14 UTC

Return-Path: <ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org>
X-Original-To: ietfarch-ntp-archives-ahFae6za@core3.amsl.com
Delivered-To: ietfarch-ntp-archives-ahFae6za@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2FFF13A67C1 for <ietfarch-ntp-archives-ahFae6za@core3.amsl.com>; Wed, 16 Jun 2010 19:14:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PD2RTTT7hzbi for <ietfarch-ntp-archives-ahFae6za@core3.amsl.com>; Wed, 16 Jun 2010 19:14:27 -0700 (PDT)
Received: from lists.ntp.org (lists.ntp.org [IPv6:2001:4f8:fff7:1::7]) by core3.amsl.com (Postfix) with ESMTP id 934893A6993 for <ntp-archives-ahFae6za@lists.ietf.org>; Wed, 16 Jun 2010 19:14:24 -0700 (PDT)
Received: from lists.ntp.org (lists.ntp.org [149.20.68.7]) by lists.ntp.org (Postfix) with ESMTP id 5F97386D83E for <ntp-archives-ahFae6za@lists.ietf.org>; Thu, 17 Jun 2010 02:14:27 +0000 (UTC)
X-Original-To: ntpwg@lists.ntp.org
Delivered-To: ntpwg@lists.ntp.org
Received: from mail1.ntp.org (mail1.ntp.org [IPv6:2001:4f8:fff7:1::5]) by lists.ntp.org (Postfix) with ESMTP id CF79686D607 for <ntpwg@lists.ntp.org>; Thu, 17 Jun 2010 02:11:34 +0000 (UTC)
Received: from cust-63-209-227-214.bos-dynamic.gis.net ([63.209.227.214] helo=[10.10.10.101]) by mail1.ntp.org with esmtpsa (TLSv1:CAMELLIA256-SHA:256) (Exim 4.71 (FreeBSD)) (envelope-from <mayer@ntp.org>) id 1OP4ZZ-0008Qj-Q3; Thu, 17 Jun 2010 02:11:30 +0000
Message-ID: <4C198477.8070501@ntp.org>
Date: Wed, 16 Jun 2010 22:12:07 -0400
From: Danny Mayer <mayer@ntp.org>
Organization: NTP
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.9) Gecko/20100317 Thunderbird/3.0.4
MIME-Version: 1.0
To: Tony Li <tony.li@tony.li>
References: <4C176EA5.2070500@ntp.org> <4C177F5B.1090008@pobox.com> <D4B4BAC0-69A5-4EFF-B12D-78C547A908F9@tony.li> <4C1834A5.4040708@ntp.org> <AA523975-0AAC-49E2-B78C-D5F0174215EE@tony.li>
In-Reply-To: <AA523975-0AAC-49E2-B78C-D5F0174215EE@tony.li>
X-Enigmail-Version: 1.0.1
X-SA-Exim-Connect-IP: 63.209.227.214
X-SA-Exim-Rcpt-To: tony.li@tony.li, kodonog@pobox.com, ntpwg@lists.ntp.org, zhangdacheng@huawei.com, rdroms@cisco.com, chenxu0128@huawei.com
X-SA-Exim-Mail-From: mayer@ntp.org
X-SA-Exim-Version: 4.2
X-SA-Exim-Scanned: Yes (on mail1.ntp.org)
Cc: NTP Working Group <ntpwg@lists.ntp.org>, zhangdacheng@huawei.com, Ralph Droms <rdroms@cisco.com>
Subject: Re: [ntpwg] IPv6 Router Advertisement Option for NTP Configuration
X-BeenThere: ntpwg@lists.ntp.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: mayer@ntp.org
List-Id: IETF Working Group for Network Time Protocol <ntpwg.lists.ntp.org>
List-Unsubscribe: <http://lists.ntp.org/options/ntpwg>, <mailto:ntpwg-request@lists.ntp.org?subject=unsubscribe>
List-Archive: <https://lists.ntp.org/pipermail/ntpwg>
List-Post: <mailto:ntpwg@lists.ntp.org>
List-Help: <mailto:ntpwg-request@lists.ntp.org?subject=help>
List-Subscribe: <http://lists.ntp.org/listinfo/ntpwg>, <mailto:ntpwg-request@lists.ntp.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org
Errors-To: ntpwg-bounces+ntp-archives-ahfae6za=lists.ietf.org@lists.ntp.org

On 6/16/2010 3:13 PM, Tony Li wrote:
>> Certainly it's very vague! I cannot even tell how many of the IPv6
>> addresses are going to be sent.
> 
> 
> Well, nothing is certain without specifics, but given the references
to DHCPv6, I'm assuming that they will mirror what's done in DHCP. That
would allow multiple addresses or names.
> 
> You might check out that document: draft-ietf-ntp-dhcpv6-ntp-opt-06.txt
> 

I held up that draft for a time while we argued over security, possible
DDOS attacks, DNS names etc. so I'm all too familiar with that one.

This draft seems to think that there are no security issues which not a
correct assessment. See the dhcpv6 ntp opt document.

>> I have not read the document in full details but I am concerned that it
>> appears that only one IPv6 address will be sent. Since NTP depends on
>> multiple sources to improve accuracy and reliability sending just one is
>> not sufficient. If this is likely to be a site-local address it would be
>> better to have the NTP server set up as a broadcast server and multicast
>> to FF05::101 for clients to pick up. The only thing that the routers
>> then need to do is forward those packets on the network.
>>
>> Even better would be for the admin to set up an ntppool label in their
>> local domain DNS which would point to a list of AAAA addresses or just
>> CNAME to the pool.ntp.org domains. The reference implementation uses the
>> pool option to allow it to set up up to 10 associations from all of
>> those addresses as servers for it.
> 
> 
> It seems like the approach that is taken for DHCP would suffice for this.
> 

So why duplicate the effort? What does Router Advertisement have to
offer that DHCP does not?

> 
>> Furthermore it is not clear why one would do it at the router in the
>> first place and who would be maintain the address and where and what
>> happens when that NTP server is replaced by a different one and who
>> would notice.
> 
> 
> There are those who feel that DHCP isn't the architecturally clean
> way
of providing host configuration and that it should instead be done by
ND.

Hmm, DHCP = Dynamic Host Configuration Protocol. Seems to fit the bill
exactly.

> While I have no wish to re-open that particular hornet's nest here,
I suspect that the author's intention is simply to replicate the DHCP
NTP configuration capabilities within ND.
> 

But the question is why? I'm struggling to understand the point of this.
What is the problem that this draft is trying to solve that is not
already solved another way?

Danny

> Regards,
> Tony
> 
> 
> 

_______________________________________________
ntpwg mailing list
ntpwg@lists.ntp.org
http://lists.ntp.org/listinfo/ntpwg