Re: [OPSEC] Éric Vyncke's No Objection on draft-ietf-opsec-urpf-improvements-03: (with COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Sat, 31 August 2019 06:39 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 028DE1200E3; Fri, 30 Aug 2019 23:39:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Level:
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=i04rpE+f; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=X6k6Uhzl
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LS2r0cYAwPOm; Fri, 30 Aug 2019 23:39:16 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C8BDC1200DE; Fri, 30 Aug 2019 23:39:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3458; q=dns/txt; s=iport; t=1567233555; x=1568443155; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=sVbkq9WAvuW1lkthtKAiijgzauF6otLO7y5xm6ZDoi8=; b=i04rpE+fgcDQ0kRyWHiYn7QrUN9P4LKl0mXhRYt+MUWmYmVuVz999q3j uPNIUKw/ulq3ZoV1KSEuhuLovKWj6/uEiHrGzqbS8ABMG4Mw+Q3Zxei8N SHu7V1DC/4gWfsQUpGn6W11gkT2BCjf7vMxg5ZL+SR2AEg6e9O6Us1Lyh M=;
IronPort-PHdr: =?us-ascii?q?9a23=3A4irA7RWT4s3gTtllsrHer2zUeMvV8LGuZFwc94?= =?us-ascii?q?YnhrRSc6+q45XlOgnF6O5wiEPSA92J8OpK3uzRta2oGXcN55qMqjgjSNRNTF?= =?us-ascii?q?dE7KdehAk8GIiAAEz/IuTtank3AtVEX1xo13q6KkNSXs35Yg6arw=3D=3D?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0CuAAB0FWpd/49dJa1mGgEBAQEBAgE?= =?us-ascii?q?BAQEHAgEBAQGBZ4FFKScDbVYgBAsqhCGDRwOKdYI3mBGBQoEQA1QJAQEBDAE?= =?us-ascii?q?BJQgCAQGEPwIXgkkjOBMCAwgBAQQBAQECAQYEbYUuDIVLAgEDEhERDAEBKQk?= =?us-ascii?q?FAQ8CAQgaAiYCAgIwFQULAgQBDQUigwABJgGBQwMdAQIMojECgTiIYXOBMoJ?= =?us-ascii?q?8AQEFhQsYghYDBoEMKIt4GIFAP4ERJwwTgkw+gmECAgEXgS8YF4J0MoImjnc?= =?us-ascii?q?znG0Kgh+GcI1nG4IyhzaEHIpfgzeKO4dzkFECBAIEBQIOAQEFgWchgVhwFTs?= =?us-ascii?q?qAYJBgkI4gzqFFIU/cwGBKI4WAQE?=
X-IronPort-AV: E=Sophos;i="5.64,449,1559520000"; d="scan'208";a="618276214"
Received: from rcdn-core-7.cisco.com ([173.37.93.143]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 31 Aug 2019 06:39:14 +0000
Received: from XCH-RCD-008.cisco.com (xch-rcd-008.cisco.com [173.37.102.18]) by rcdn-core-7.cisco.com (8.15.2/8.15.2) with ESMTPS id x7V6dE8I029461 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Sat, 31 Aug 2019 06:39:14 GMT
Received: from xhs-aln-001.cisco.com (173.37.135.118) by XCH-RCD-008.cisco.com (173.37.102.18) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 31 Aug 2019 01:39:14 -0500
Received: from xhs-aln-003.cisco.com (173.37.135.120) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Sat, 31 Aug 2019 01:39:13 -0500
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-003.cisco.com (173.37.135.120) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Sat, 31 Aug 2019 01:39:13 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=IAMD4AOv5tzN6sbenZZdP/2omgp1n/d/YhLi2JDrmcOL201Nidu45uLasa2QeR103yaRJ7IqoIrWZZwKh+F8MNxGuDGfoBcVEd794Uh9RlFOi+Bl/r3TQic2eZzy5zTvE7o7uZnE+JWII5UgWzJ1O2UPa9ERqv515lUB6SS3a1OUpsyC+I28EymMdcvEJuYsgjGzyY1Q0OWkkBXgKst7mo2dQ4IouTWymD7oIV1ZEIun0ahjGT8celofZpM2lBrz1FHOJlfqisuPv1F/KUd+IgzqvhL4lZWGvG8ZEC++SuO1bjGL8VrVvhD8noS9Z0fPYkByNXQaLt0dlbWQns3BmQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=sVbkq9WAvuW1lkthtKAiijgzauF6otLO7y5xm6ZDoi8=; b=TSfGYxTxJF/GcNFB+aHapUoR2kVy84JWcyXOIft2UzidvDeZ4/J5iiklqRbAC/WrUQBh3dzBUfmwVc7xJXqdIfgVIVnJIiCExNtFGH/7xMeaAEdvvslfn+ZCLEXuJl75r6r3zD3ezaf4JLRCrzpmAPoRsnUitNGIWjZo0zONwqjCApxvOGeobOWqlaK2m9KZYGpODtjjegNRrFMPWQdUrHu4eNv05TQ1+U/5bIoboiVixnD09vYSV2qia0E1naVAINNoCAgRRe/FpvTezJcodwg1asC8ohQel4wsyB4nbfUW+/Wt4/19Sn+d9HZn2Prm25wouLD+iWY3EfEeV6gRdw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=sVbkq9WAvuW1lkthtKAiijgzauF6otLO7y5xm6ZDoi8=; b=X6k6UhzlwIX5r5yWEOBacYgsfKYQkL64uCCV5tUlASTGOB3WufQVSaZ+sZ+8KWhezHT+uMKCu8Bz0V74iZK7m8bUksiXZp2Qx40+gcTIy99XgCQ55VfZdNWXn+QBfORJE3Vh4r1F1TLslrYSQQI0GBtEE2yfqxLhsXfpLwYlrCA=
Received: from MN2PR11MB4144.namprd11.prod.outlook.com (20.179.150.210) by MN2PR11MB3904.namprd11.prod.outlook.com (10.255.180.79) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2220.20; Sat, 31 Aug 2019 06:39:11 +0000
Received: from MN2PR11MB4144.namprd11.prod.outlook.com ([fe80::d5c4:be39:66cb:449b]) by MN2PR11MB4144.namprd11.prod.outlook.com ([fe80::d5c4:be39:66cb:449b%6]) with mapi id 15.20.2199.021; Sat, 31 Aug 2019 06:39:11 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>, The IESG <iesg@ietf.org>
CC: "draft-ietf-opsec-urpf-improvements@ietf.org" <draft-ietf-opsec-urpf-improvements@ietf.org>, Sandra Murphy <sandy@tislabs.com>, "opsec-chairs@ietf.org" <opsec-chairs@ietf.org>, "opsec@ietf.org" <opsec@ietf.org>, Warren Kumari <warren@kumari.net>
Thread-Topic: =?utf-8?B?w4lyaWMgVnluY2tlJ3MgTm8gT2JqZWN0aW9uIG9uIGRyYWZ0LWlldGYtb3Bz?= =?utf-8?Q?ec-urpf-improvements-03:_(with_COMMENT)?=
Thread-Index: AQHVWCw3l+JDCHp1g06ot+mqkOpTCacUtlWAgABIcAA=
Date: Sat, 31 Aug 2019 06:39:11 +0000
Message-ID: <26A374AE-5476-415C-B736-D1A08EA40B05@cisco.com>
References: <156639747640.25777.13888707111707970209.idtracker@ietfa.amsl.com> <BL0PR0901MB45633C640D1CFE014305500584BC0@BL0PR0901MB4563.namprd09.prod.outlook.com>
In-Reply-To: <BL0PR0901MB45633C640D1CFE014305500584BC0@BL0PR0901MB4563.namprd09.prod.outlook.com>
Accept-Language: fr-BE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1c.0.190812
authentication-results: spf=none (sender IP is ) smtp.mailfrom=evyncke@cisco.com;
x-originating-ip: [2001:420:c0c1:36:1cc7:aa56:5f89:fdc7]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 49d88d5b-b560-4711-9a45-08d72dddeeea
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600166)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:MN2PR11MB3904;
x-ms-traffictypediagnostic: MN2PR11MB3904:
x-ms-exchange-purlcount: 1
x-microsoft-antispam-prvs: <MN2PR11MB390465F7952E8898249C7B4FA9BC0@MN2PR11MB3904.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-forefront-prvs: 014617085B
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(396003)(346002)(136003)(376002)(366004)(39860400002)(199004)(189003)(58126008)(102836004)(110136005)(54906003)(6506007)(4326008)(6436002)(86362001)(486006)(6306002)(6512007)(316002)(446003)(224303003)(2906002)(11346002)(46003)(476003)(2616005)(36756003)(6246003)(53936002)(33656002)(6116002)(186003)(256004)(91956017)(76116006)(66946007)(81156014)(8936002)(81166006)(305945005)(66556008)(66476007)(7736002)(64756008)(66446008)(71200400001)(229853002)(71190400001)(5660300002)(6486002)(25786009)(966005)(478600001)(76176011)(99286004)(14454004); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR11MB3904; H:MN2PR11MB4144.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: iX3Ux1KhMX2BUAcLIG47/KH82i60Kj0L6dsUjumNgGVBwHN8LVr5sdNg0LySyXUHXFfWQSaRlOb+DcTDx0idwLON9qiFLVmaXiLwKPPWvmwM8TSHHj0iqcE6Q6JOcwa1xRVkUh4+FzqZ7V2lhv0ITee6gmIuj301F5zoUWYtABA7gU0yG83+Oyjf1SBxD442daLLv3BS7QijUUYnBT+DdEOu20eKdVFe2InuUmjyzsGHj7hEokttYRvQnnut5l0ip2ntxpePImaRfF/+KmKUf8lBbJuwTLUc8ZN3nCL1iImCG1gGy5uWfDbdFbxGlqMU7GB90RacHSwHH33JYt5XAHli2rzbaLSo23nin5FVeQYz37bSfzhIQ+vEEbt5DY1qMOhA49ztqv4EQNIV1mpzHtkiwE6mdsFszaz4TIAzG2U=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <7C63B1E1C094BF49B18802FD126686F3@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 49d88d5b-b560-4711-9a45-08d72dddeeea
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Aug 2019 06:39:11.4189 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 36PRBxY7JhPy3HAsAhZ8FZcK7/3UzzBOn6A2kt0plrrna2wrlpk2Lj1eaef7K2HW5Kp2m6E0EWv0XOsJKeaS4A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB3904
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.18, xch-rcd-008.cisco.com
X-Outbound-Node: rcdn-core-7.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/acYf8llykQx6c7njCyiXgnx4zZ4>
Subject: Re: [OPSEC] =?utf-8?q?=C3=89ric_Vyncke=27s_No_Objection_on_draft-iet?= =?utf-8?q?f-opsec-urpf-improvements-03=3A_=28with_COMMENT=29?=
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Aug 2019 06:39:21 -0000

Thank you Sriram for the updated document.

Just a minor nit: in the terminology section, P2C and C2P are in uppercase but p2p is in lower case. This can be fixed later at the AUTH48 stage

-éric

On 31/08/2019, 06:46, "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> wrote:

    Eric,
    
    Thank you for your comments. Sorry about the delay in replying.
    We have uploaded a new version and have included changes
    reflecting your comments. Please see:
    https://tools.ietf.org/rfcdiff?url2=draft-ietf-opsec-urpf-improvements-04.txt  
    Please also see responses to your comments inline below. 
    
    -- Abstract --
    >The abstract reads like 'promises' but not as a summary of the document. Is
    >there any chance to add 2 lines summarizing the 'how' ?
    >
    
    Added some more wording in the abstract to address your comment.
    We have summarized the 'how' in the intro with a whole paragraph.
    Probably better not to make the abstract overly long.
     
    >-- Section 1.1 --
    >I am sure that by now you know that you have to use RFC 8174 boilerplate ;-)
    >
    
    Yes. Done.
    
    >-- Section 2.2 --
    >For completeness and symmetry with section 2.3, please explain which packets
    >will be dropped.
    >
    
    Good catch. Done.
    
    >-- Section 2.3 --
    >Suggestion: define "RPF list" before first use (even if mostly obvious).
    >
    >Please define "lateral peer" and why it is different to any other "peer".
    >
    
    Added Section 1.1. "Terminology" per your suggestion.
    We've provided definitions of these terms and more there.
    
    
    >-- Section 3.1 --
    >Please define the "cone" used in this section. First time that I ever read this
    >term and the RIPE paper does not explain it either (of course I am not a
    >routing expert).
    >
    
    Definition of customer cone is also included in the Terminology section 1.1.
    
    
    >== NITS ==
    >
    >-- Section 1 --
    >Beside the intro, this section also introduces some terminology wording. May I
    >suggest to have a (sub)section about "terminology" ?
    >
    
    Good suggestion. Done.
    
    >-- Section 2.1 --
    >CMTS was introduced as an acronym but not DSLAM.
    >
    >
    Mention of DSLAM was not essential. So it is removed in the updated version.
    Mention of CMTS, PDN-GW is sufficient in that context
    and they are introduced.
    
    Sriram