Re: [OPSAWG] [tcpdump-workers] New Version Notification for draft-tuexen-opsawg-pcapng-02.txt
Michael Tuexen <tuexen@fh-muenster.de> Mon, 28 September 2020 20:42 UTC
Return-Path: <tuexen@fh-muenster.de>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D83D23A0B55 for <opsawg@ietfa.amsl.com>; Mon, 28 Sep 2020 13:42:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.624
X-Spam-Level:
X-Spam-Status: No, score=-1.624 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, KHOP_HELO_FCRDNS=0.274, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t6lnTUEDVhL0 for <opsawg@ietfa.amsl.com>; Mon, 28 Sep 2020 13:42:28 -0700 (PDT)
Received: from drew.franken.de (mail-n.franken.de [193.175.24.27]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D30773A0B3C for <opsawg@ietf.org>; Mon, 28 Sep 2020 13:42:27 -0700 (PDT)
Received: from [IPv6:2a02:8109:1140:c3d:6094:2141:35f4:bc86] (unknown [IPv6:2a02:8109:1140:c3d:6094:2141:35f4:bc86]) (Authenticated sender: macmic) by drew.franken.de (Postfix) with ESMTPSA id 98A787439EF5E; Mon, 28 Sep 2020 22:42:23 +0200 (CEST)
From: Michael Tuexen <tuexen@fh-muenster.de>
Message-Id: <DF513F36-9E22-4A4B-A419-840BBDF2FA48@fh-muenster.de>
Content-Type: multipart/signed; boundary="Apple-Mail=_445D4D7E-F13E-48C0-B0C9-0B0288190DA0"; protocol="application/pkcs7-signature"; micalg="sha-256"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
Date: Mon, 28 Sep 2020 22:42:22 +0200
In-Reply-To: <mailman.21.1601324920.2325.tcpdump-workers@lists.tcpdump.org>
Cc: pcap-ng-format@winpcap.org, Michael Richardson <mcr+ietf@sandelman.ca>, Jasper Bongertz <jasper@packet-foo.com>, tcpdump-workers@lists.tcpdump.org, opsawg@ietf.org
To: Guy Harris <gharris@sonic.net>
References: <160131683320.30001.4858487168061369615@ietfa.amsl.com> <31134.1601317608@localhost> <100954A4-FAA0-4E40-B592-5F208DAB5F68@fh-muenster.de> <mailman.21.1601324920.2325.tcpdump-workers@lists.tcpdump.org>
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/ipHxXw2iQ-nrSFq6QbSDDkugZGs>
Subject: Re: [OPSAWG] [tcpdump-workers] New Version Notification for draft-tuexen-opsawg-pcapng-02.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Sep 2020 20:42:31 -0000
Without OPSWG... > On 28. Sep 2020, at 22:23, Guy Harris via tcpdump-workers <tcpdump-workers@lists.tcpdump.org> wrote: > > > From: Guy Harris <gharris@sonic.net> > Subject: Re: New Version Notification for draft-tuexen-opsawg-pcapng-02.txt > Date: 28. September 2020 at 22:23:33 CEST > To: Michael Tuexen <tuexen@fh-muenster.de> > Cc: Michael Richardson <mcr+ietf@sandelman.ca>, pcap-ng-format@winpcap.org, opsawg@ietf.org, Jasper Bongertz <jasper@packet-foo.com>, tcpdump-workers@lists.tcpdump.org, Fulvio Risso <fulvio.risso@polito.it>, Gerald Combs <gerald@wireshark.org> > > > On Sep 28, 2020, at 12:06 PM, Michael Tuexen <tuexen@fh-muenster.de> wrote: > >> Do we want to finally publish that? Up to now, I think the point was to >> find a home where it is substantially discussed and improved... > > For example, unlike pcap, which is not easily changeable (you *can* change it, but that involves adding new magic numbers), pcapng can have new block types and option types. > > There are extensible protocols with RFCs; that's handled with protocol registries: > > https://www.iana.org/protocols > > and with new I-Ds -> RFCs for extensions. We'd have to set up registries for block and option types if we publish an RFC for pcapng. We would *also* want a registry for link-layer header types, for both pcap and pcapng. > > See, for example, RFC 1761 > > https://tools.ietf.org/html/rfc1761 > > which specifies the Sun snoop file format, and RFC 3827: > > https://tools.ietf.org/html/rfc3827 > > which sets up a registry for snoop link-layer header types: > > https://www.iana.org/assignments/snoop-datalink-types/snoop-datalink-types.xhtml#snoop-datalink-types-2 > > and adds some new entries to it. So we can make use of IANA. Shouldn't we write up (I can work on an initial version) of a specification for .pcap. Would you volunteer as a co-author? Establish there the link layer header type IANA registry? We can reuse that for the .pcapng spec... Best regards Michael > > _______________________________________________ > tcpdump-workers mailing list > tcpdump-workers@lists.tcpdump.org > https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers
- Re: [OPSAWG] New Version Notification for draft-t… Michael Richardson
- Re: [OPSAWG] New Version Notification for draft-t… Michael Tuexen
- Re: [OPSAWG] New Version Notification for draft-t… Michael Richardson
- Re: [OPSAWG] [tcpdump-workers] New Version Notifi… Michael Tuexen
- Re: [OPSAWG] New Version Notification for draft-t… Michael Richardson
- Re: [OPSAWG] New Version Notification for draft-t… Carsten Bormann
- Re: [OPSAWG] New Version Notification for draft-t… Qin Wu
- Re: [OPSAWG] New Version Notification for draft-t… Guy Harris
- Re: [OPSAWG] [tcpdump-workers] New Version Notifi… Guy Harris
- Re: [OPSAWG] New Version Notification for draft-t… Guy Harris
- Re: [OPSAWG] New Version Notification for draft-t… Michael Tuexen
- Re: [OPSAWG] New Version Notification for draft-t… Carsten Bormann