Re: [Ntp] NTPv5 draft

"Salz, Rich" <rsalz@akamai.com> Mon, 30 November 2020 23:44 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8C15B3A10A6 for <ntp@ietfa.amsl.com>; Mon, 30 Nov 2020 15:44:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mqHklLypchU9 for <ntp@ietfa.amsl.com>; Mon, 30 Nov 2020 15:44:37 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 684BE3A11FA for <ntp@ietf.org>; Mon, 30 Nov 2020 15:44:37 -0800 (PST)
Received: from pps.filterd (m0122331.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 0AUNiFdP010215; Mon, 30 Nov 2020 23:44:35 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=LHMmZNaK+xooPLoFHVcnQjADlajFZdXKN5pCjXLoDyE=; b=j6oSp5wMOXsS02aeBavP4GotRm9WxLKELKGJRXeU/pnaev7oyutARgfpPh7J/jQQywZq gp9j8OI4p/ldtaFzW+REf4pGLpbT8xDWTu6hp0Lg96fDvSHezpafJJDjQcu+dOiZB/kE c7i1hyLV7YrRbZ63Bkgpu+B4E0Wl2fty7iR7qXx+8d13AEt/MTFcUVpsUsAtO5e2Yniy +U1QQ10VCo+AcsoCVy1WSQyHWUfxxsyzvLZMZDMcWr2yTpdF23Il7iP6aYZKkBO2W8nP sDP7hirqDUMKMd5IrhSWa+UlFdpZk0TmzWvBGiSjh2EGKf+Yg6zTCnE3GUupoxCQ5Ozh uQ==
Received: from prod-mail-ppoint7 (a72-247-45-33.deploy.static.akamaitechnologies.com [72.247.45.33] (may be forged)) by mx0b-00190b01.pphosted.com with ESMTP id 353ca56718-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 30 Nov 2020 23:44:35 +0000
Received: from pps.filterd (prod-mail-ppoint7.akamai.com [127.0.0.1]) by prod-mail-ppoint7.akamai.com (8.16.0.42/8.16.0.42) with SMTP id 0AUNYf3R005663; Mon, 30 Nov 2020 18:44:35 -0500
Received: from email.msg.corp.akamai.com ([172.27.165.118]) by prod-mail-ppoint7.akamai.com with ESMTP id 353js2s4p6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Mon, 30 Nov 2020 18:44:34 -0500
Received: from USTX2EX-DAG1MB1.msg.corp.akamai.com (172.27.165.119) by ustx2ex-dag1mb5.msg.corp.akamai.com (172.27.165.123) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 30 Nov 2020 17:44:34 -0600
Received: from USTX2EX-DAG1MB1.msg.corp.akamai.com ([172.27.165.119]) by ustx2ex-dag1mb1.msg.corp.akamai.com ([172.27.165.119]) with mapi id 15.00.1497.008; Mon, 30 Nov 2020 17:44:34 -0600
From: "Salz, Rich" <rsalz@akamai.com>
To: Doug Arnold <doug.arnold@meinberg-usa.com>, Dieter Sibold <dsibold.ietf@gmail.com>, Miroslav Lichvar <mlichvar@redhat.com>
CC: "ntp@ietf.org" <ntp@ietf.org>
Thread-Topic: [Ntp] NTPv5 draft
Thread-Index: AQHWx0y7t3+6ZsqoV0yhBezViWgzB6nhoeQA///FxgA=
Date: Mon, 30 Nov 2020 23:44:32 +0000
Message-ID: <DCB6C97C-3CC3-4A75-B633-2A35E17573C3@akamai.com>
References: <20201111161947.GG1559650@localhost> <AA848C67-CFB7-43FC-B190-FD3911360373@gmail.com> <49B3601E-C6A9-4B9E-BE9D-7FD69CCC54DC@meinberg-usa.com>
In-Reply-To: <49B3601E-C6A9-4B9E-BE9D-7FD69CCC54DC@meinberg-usa.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.43.20110804
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.27.164.43]
Content-Type: text/plain; charset="utf-8"
Content-ID: <ACD28027FD65CC45B8F64F00D9F3C53F@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.312, 18.0.737 definitions=2020-11-30_12:2020-11-30, 2020-11-30 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 malwarescore=0 bulkscore=0 suspectscore=0 mlxscore=0 spamscore=0 phishscore=0 mlxlogscore=544 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2011300146
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.312, 18.0.737 definitions=2020-11-30_12:2020-11-30, 2020-11-30 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 spamscore=0 suspectscore=0 impostorscore=0 lowpriorityscore=0 clxscore=1011 priorityscore=1501 phishscore=0 malwarescore=0 mlxlogscore=451 mlxscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2011300148
X-Agari-Authentication-Results: mx.akamai.com; spf=${SPFResult} (sender IP is 72.247.45.33) smtp.mailfrom=rsalz@akamai.com smtp.helo=prod-mail-ppoint7
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/KWcqlH2ABwdziBW20QNJ5pNZLW0>
Subject: Re: [Ntp] NTPv5 draft
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Nov 2020 23:44:39 -0000

>    I think that there is a possibility of a non safety-critical closed network application of ntp that does not need security.

I am strongly opposed to this for three and a half reasons:
1. The use-case is not known, so we should assume that NTPv4 is good enough.
1.5 If this is not the case, those who need this need to make the argument to this WG.
2. Security should no longer be optional for IETF protocols.
3. "Closed network" is increasingly unlikely; we're seeing more things "in the cloud" for example.