Re: [Ntp] NTPv5: big picture

"Salz, Rich" <rsalz@akamai.com> Mon, 04 January 2021 16:41 UTC

Return-Path: <rsalz@akamai.com>
X-Original-To: ntp@ietfa.amsl.com
Delivered-To: ntp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B5223A0E6D for <ntp@ietfa.amsl.com>; Mon, 4 Jan 2021 08:41:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.449
X-Spam-Level:
X-Spam-Status: No, score=-0.449 tagged_above=-999 required=5 tests=[DKIMWL_WL_HIGH=-0.25, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=akamai.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qqpXsvz7Y01c for <ntp@ietfa.amsl.com>; Mon, 4 Jan 2021 08:41:34 -0800 (PST)
Received: from mx0b-00190b01.pphosted.com (mx0b-00190b01.pphosted.com [IPv6:2620:100:9005:57f::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6F0FE3A0E6B for <ntp@ietf.org>; Mon, 4 Jan 2021 08:41:34 -0800 (PST)
Received: from pps.filterd (m0122330.ppops.net [127.0.0.1]) by mx0b-00190b01.pphosted.com (8.16.0.43/8.16.0.43) with SMTP id 104GcnGS030639; Mon, 4 Jan 2021 16:41:33 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=akamai.com; h=from : to : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=jan2016.eng; bh=NIUrpMw5qg2L4Byhr5ja7LB4iuJnRmzvybqwFdqT8ts=; b=gAmUWd8HEdz0gUlBZbI4wnaBPkLPpfofB0kHH8asJPexg7OfETaJBmWE2S+PW04v9ize p2gKcP6cqX+Hv77glhQhQw+9zc+CErSI6qpsm5bqMVo1R6fZ1yfOistojvaB6CPPXcyo +5uvWCntWdiUJhhw6ZhXFgSPfAIatPFc3C/B4csGnYftazHJACpNIPNYr/1yTX3SXFQG Cjk/JbNF/u9/QOD2YQ7n2eeQNVsuhUQOTEBus67CbZkweXH5yCVCNqXM4JHuASDimwtY vxOVDx/RVl90s0H+OwNJyBDq4v1J97r683hwHoZR2X+H2OrNHFWbW8VBBf2QE1wfUQ4B fg==
Received: from prod-mail-ppoint5 (prod-mail-ppoint5.akamai.com [184.51.33.60] (may be forged)) by mx0b-00190b01.pphosted.com with ESMTP id 35thc5bkw5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Mon, 04 Jan 2021 16:41:33 +0000
Received: from pps.filterd (prod-mail-ppoint5.akamai.com [127.0.0.1]) by prod-mail-ppoint5.akamai.com (8.16.0.43/8.16.0.43) with SMTP id 104GZ4sg007812; Mon, 4 Jan 2021 08:41:32 -0800
Received: from email.msg.corp.akamai.com ([172.27.123.33]) by prod-mail-ppoint5.akamai.com with ESMTP id 35tqpevkb9-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Mon, 04 Jan 2021 08:41:32 -0800
Received: from USMA1EX-DAG1MB5.msg.corp.akamai.com (172.27.123.105) by usma1ex-dag3mb3.msg.corp.akamai.com (172.27.123.58) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 4 Jan 2021 11:41:32 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com (172.27.123.101) by usma1ex-dag1mb5.msg.corp.akamai.com (172.27.123.105) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 4 Jan 2021 11:41:31 -0500
Received: from USMA1EX-DAG1MB1.msg.corp.akamai.com ([172.27.123.101]) by usma1ex-dag1mb1.msg.corp.akamai.com ([172.27.123.101]) with mapi id 15.00.1497.010; Mon, 4 Jan 2021 11:41:31 -0500
From: "Salz, Rich" <rsalz@akamai.com>
To: Doug Arnold <doug.arnold@meinberg-usa.com>, Hal Murray <hmurray@megapathdsl.net>, NTP WG <ntp@ietf.org>
Thread-Topic: [Ntp] NTPv5: big picture
Thread-Index: AQHW3+mArsQojbubskqCLBGYi67snKoTRmWA//+7GwCABP1NgP//sjIA
Date: Mon, 04 Jan 2021 16:41:30 +0000
Message-ID: <6744C499-C7B8-4A65-BDD9-6A66FCB10B1E@akamai.com>
References: <20210101025440.ECE3340605C@ip-64-139-1-69.sjc.megapath.net> <0DF4D79B-29BA-4DB0-A3D6-EE3B6AE807DF@meinberg-usa.com> <993FEEB5-F498-472E-813E-E684E273612F@akamai.com> <5BC1FA05-AD4D-4DC2-834B-2FBE27D55EB0@meinberg-usa.com>
In-Reply-To: <5BC1FA05-AD4D-4DC2-834B-2FBE27D55EB0@meinberg-usa.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.44.20121301
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [172.27.118.139]
Content-Type: text/plain; charset="utf-8"
Content-ID: <1759D350DE4FAF47B5A1296967766C5D@akamai.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.343, 18.0.737 definitions=2021-01-04_10:2021-01-04, 2021-01-04 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 spamscore=0 phishscore=0 malwarescore=0 suspectscore=0 mlxlogscore=999 bulkscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2101040107
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.343, 18.0.737 definitions=2021-01-04_10:2021-01-04, 2021-01-04 signatures=0
X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 mlxscore=0 clxscore=1015 malwarescore=0 impostorscore=0 suspectscore=0 mlxlogscore=967 priorityscore=1501 lowpriorityscore=0 adultscore=0 spamscore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2009150000 definitions=main-2101040108
X-Agari-Authentication-Results: mx.akamai.com; spf=${SPFResult} (sender IP is 184.51.33.60) smtp.mailfrom=rsalz@akamai.com smtp.helo=prod-mail-ppoint5
Archived-At: <https://mailarchive.ietf.org/arch/msg/ntp/hy1tt_dTV50NMobS9X5hZdAcVZE>
Subject: Re: [Ntp] NTPv5: big picture
X-BeenThere: ntp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <ntp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ntp>, <mailto:ntp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ntp/>
List-Post: <mailto:ntp@ietf.org>
List-Help: <mailto:ntp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ntp>, <mailto:ntp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Jan 2021 16:41:36 -0000

>    The original question was what does ntpv5 have, that ntpv4 doesn't.  Are you wanting more security work beyond what nts adds to ntpv4?

I want it integrated into the protocol.  This probably means, for example, that the concept of extensions that aren't part of the integrity and privacy guarantees are no longer possible.

Are you okay with assuming NTPv5 starts with "assume NTS" ?