Re: [Ntp] New Version Notification for draft-gont-ntp-port-randomization-02.txt

"Dieter Sibold" <dsibold.ietf@gmail.com> Sun, 21 July 2019 22:58 UTC

Return-Path: <dsibold.ietf@gmail.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 434E81200C7 for <ntp@ietfa.amsl.com>; Sun, 21 Jul 2019 15:58:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yKXXrD-dDgwx for <ntp@ietfa.amsl.com>; Sun, 21 Jul 2019 15:58:08 -0700 (PDT)
Received: from mail-wm1-x32f.google.com (mail-wm1-x32f.google.com [IPv6:2a00:1450:4864:20::32f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F44912001E for <ntp@ietf.org>; Sun, 21 Jul 2019 15:58:08 -0700 (PDT)
Received: by mail-wm1-x32f.google.com with SMTP id s15so12173850wmj.3 for <ntp@ietf.org>; Sun, 21 Jul 2019 15:58:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version; bh=uUfKQQ1T4f0sldP1A4uZdav5dwf1RDMWAtFcaKNpfTs=; b=CVu6+OUVL9V66fjilN3qMdYLletJJK6MYtWP1nKj1xiNDsJVO94/t+1+KJfgggQAeG /lYa5OLxqgovnJin/q2Kx6dFjgEQ+jkY7bUjpkX5QbEFzS3BfSVApsxZb/GnSdwXpXso BaPkSM1a0fptstQBH1v/vGlwm/11L4RYDcI27+DZRK5nbATyj2Cbqamez8BGKcyiMril 1zSO5EaOX4wAIADgh+4kIVKBSXyqMyrzKpGCpZwzCmi9MVzhmGICNgmmo0pH7fA5mKHu ckLFbI7Edd2rHQjJ9f5K2QA08FjJc8yVmZiY0eO2yHPkKrd9uc5jAX0O1m6M9PQCGDM9 p3IA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version; bh=uUfKQQ1T4f0sldP1A4uZdav5dwf1RDMWAtFcaKNpfTs=; b=A/Kvr42GqtBIW4p7m2AAr+a+Q5swKnDESdM7h0XMiPUGsNLv4vF2XPzmVgTBu0giPU xSo0vJ3CBPkDiJcRrwBMfIwwfFz19Kz8uthuGBUpPqq63RceTcxhMLcfwiUL/6LJIPpX 3MJeQUkAME9QYD/IDCKLWa6XKhofC3J1jgprAzjC73qo2WgIlUEcB6QU0v8r/04jSLoD qAYLIXXfeYoM8oTCS0lw0dVZf86lStzXXByeEAgc+atnijIQWEWwNw+9CzVJOtwmuHWY lZncsmjmaR5ZifeXqDlcxJ/fLrWpSno2o5y2Gu/8lZIIJwLd0JSpxodumvC3YNQSgO3Y SlmQ==
X-Gm-Message-State: APjAAAU6cByGy3Z9mgJKwnDUsRw/g5rbDDASVtpDCLMpQ1uj02A2foL2 FADalLELsn48EQFmfBm2fiY=
X-Google-Smtp-Source: APXvYqzBZWa6YovAG7usIhNpw4ro/FKZW6T+4M3HaooF7xtA1rSQgCrdh0EoU5MCIZh8onilvdKhdQ==
X-Received: by 2002:a05:600c:254b:: with SMTP id e11mr56055723wma.171.1563749887017; Sun, 21 Jul 2019 15:58:07 -0700 (PDT)
Received: from [192.168.111.101] (p2E501817.dip0.t-ipconnect.de. [46.80.24.23]) by smtp.gmail.com with ESMTPSA id e3sm33119917wrs.37.2019.07.21.15.58.05 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 21 Jul 2019 15:58:06 -0700 (PDT)
From: "Dieter Sibold" <dsibold.ietf@gmail.com>
To: "Fernando Gont" <fgont@si6networks.com>
Cc: ntp@ietf.org, odonoghue@isoc.org
Date: Mon, 22 Jul 2019 00:58:04 +0200
X-Mailer: MailMate (1.12.5r5635)
Message-ID: <E9B4D47E-6A6F-4CEE-90E0-4604CAE3B427@gmail.com>
In-Reply-To: <9d098ba6-3995-7ace-5543-a97ed8fc6564@si6networks.com>
References: <156225909789.12042.16125322482082094709.idtracker@ietfa.amsl.com> <9d098ba6-3995-7ace-5543-a97ed8fc6564@si6networks.com>
MIME-Version: 1.0
Content-Type: text/plain; format=flowed
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/JPdP4GaYPXLUxwUy09QF1TRUB1c>
Subject: Re: [Ntp] New Version Notification for draft-gont-ntp-port-randomization-02.txt
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 21 Jul 2019 22:58:11 -0000

Hi Fernando,
many thanks for the update of your draft. I have the following comments:

- Sec 1, third paragraph, first sentence. From my point of view the 
sentence is ambiguous. Do you want to express that BCP 156 is formally 
updating RFC 5905? I thought this is the intension of this draft. Maybe 
this could be formulated more precisely.

- Sec 3.2, third paragraph, second sentence: I suppose you mean: '... 
that the clock selection and ...' and not '... that the clock select and 
...'.

- Sec 4. I would appreciate if this section would contain a comparison 
of the specification language between RFC 5905 and the proposed new 
language.  This would make it easier for the reader to see the changes 
you introduce.

- Sec 3.2, second paragraph: that the synchronization of the two 
system's clocks may result in a different clock value is a priori not 
very surprising. It is worth mentioning if the two systems are in the 
same network. I suppose this is what you mean. If yes, please clarify.


Greetings
Dieter









Dieter Sibold
dsibold.ietf@gmail.com

On 6 Jul 2019, at 16:16, Fernando Gont wrote:

> Folks,
>
> We have posted a new revision of the ntp port randomization I-D. It
> contains a number of improvements based on the recent discussion, 
> along
> with an analysis of a number of considerations surrounding port
> randomization.
>
> It is available at:
> https://www.ietf.org/internet-drafts/draft-gont-ntp-port-randomization-02.txt
>
> We don't expect this rev to be perfect, but do we think this one is
> ready for the wg to make a decision regarding whether to adopt this
> document as a wg item.
>
> P.S.: If there's anything you think we have missed, please do let us 
> know.
>
> Thanks!
>
> Cheers,
> Fernando
>
>
>
>
> -------- Forwarded Message --------
> Subject: New Version Notification for
> draft-gont-ntp-port-randomization-02.txt
> Date: Thu, 04 Jul 2019 09:51:37 -0700
> From: internet-drafts@ietf.org
> To: Fernando Gont <fgont@si6networks.com>;, Guillermo Gont
> <ggont@si6networks.com>;
>
>
> A new version of I-D, draft-gont-ntp-port-randomization-02.txt
> has been successfully submitted by Fernando Gont and posted to the
> IETF repository.
>
> Name:		draft-gont-ntp-port-randomization
> Revision:	02
> Title:		Port Randomization in the Network Time Protocol Version 4
> Document date:	2019-07-04
> Group:		Individual Submission
> Pages:		10
> URL:
> https://www.ietf.org/internet-drafts/draft-gont-ntp-port-randomization-02.txt
> Status:
> https://datatracker.ietf.org/doc/draft-gont-ntp-port-randomization/
> Htmlized:
> https://tools.ietf.org/html/draft-gont-ntp-port-randomization-02
> Htmlized:
> https://datatracker.ietf.org/doc/html/draft-gont-ntp-port-randomization
> Diff:
> https://www.ietf.org/rfcdiff?url2=draft-gont-ntp-port-randomization-02
>
> Abstract:
>    The Network Time Protocol can operate in several modes.  Some of
>    these modes are based on the receipt of unsolicited packets, and
>    therefore require the use of a service/well-known port as the local
>    port number.  However, in the case of NTP modes where the use of a
>    service/well-known port is not required, employing such well-known/
>    service port unnecessarily increases the ability of attackers to
>    perform blind/off-path attacks.  This document formally updates
>    RFC5905, recommending the use of port randomization for those modes
>    where use of the NTP service port is not required.
>
>
>
>
> Please note that it may take a couple of minutes from the time of 
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> The IETF Secretariat
>
>
> _______________________________________________
> ntp mailing list
> ntp@ietf.org
> https://www.ietf.org/mailman/listinfo/ntp