Re: [OSPF] AD review of draft-ietf-ospf-node-admin-tag-04

"Acee Lindem (acee)" <acee@cisco.com> Tue, 22 September 2015 19:30 UTC

Return-Path: <acee@cisco.com>
X-Original-To: ospf@ietfa.amsl.com
Delivered-To: ospf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C7731ACD98; Tue, 22 Sep 2015 12:30:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.51
X-Spam-Level:
X-Spam-Status: No, score=-14.51 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uKbfqhFPL7GN; Tue, 22 Sep 2015 12:30:42 -0700 (PDT)
Received: from rcdn-iport-2.cisco.com (rcdn-iport-2.cisco.com [173.37.86.73]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5184A1ACD92; Tue, 22 Sep 2015 12:30:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=14227; q=dns/txt; s=iport; t=1442950242; x=1444159842; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=nctCO7Rie3ZHUMQuywtV6hEd8l2mBRaNa8aoj4VUcdA=; b=QvkFBu7vXaxyDjEW7iKlOaVM9eaWQzw/tBe+6ysDDAyQa1JVAQ3t5bmR m0jZchXAIsEtME2MEffw1PcYCdRis7kqUt3plClIj/v5RfkramvzD3s2j 0IyFXQYP0/ky0y4l2D2prkhUikQKz/ito0gc4S7u7SoopnBafcwnzKraK M=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AEAgAgqwFW/5RdJa1dgldNgT0GvVQBDYdzAhyBLjgUAQEBAQEBAYEKhCQBAQEEI2YCAQgOAwMBAigDAgICHxEUCQgCBAESiBkDErcLjycNhGoBAQEBAQEBAQIBAQEBAQEBG4twglCBZUcYgmmBQwWSPoMpAYsZgW+BToQ2jV6HQR8BAUKEAXGIJkKBBQEBAQ
X-IronPort-AV: E=Sophos; i="5.17,574,1437436800"; d="scan'208,217"; a="34267962"
Received: from rcdn-core-12.cisco.com ([173.37.93.148]) by rcdn-iport-2.cisco.com with ESMTP; 22 Sep 2015 19:30:41 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by rcdn-core-12.cisco.com (8.14.5/8.14.5) with ESMTP id t8MJUfBt013893 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 22 Sep 2015 19:30:41 GMT
Received: from xch-aln-003.cisco.com (173.36.7.13) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Tue, 22 Sep 2015 14:30:40 -0500
Received: from xhc-aln-x10.cisco.com (173.36.12.84) by xch-aln-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1104.5 via Frontend Transport; Tue, 22 Sep 2015 14:30:40 -0500
Received: from xmb-aln-x06.cisco.com ([169.254.1.127]) by xhc-aln-x10.cisco.com ([173.36.12.84]) with mapi id 14.03.0248.002; Tue, 22 Sep 2015 14:30:40 -0500
From: "Acee Lindem (acee)" <acee@cisco.com>
To: Alia Atlas <akatlas@gmail.com>, OSPF List <ospf@ietf.org>, "draft-ietf-ospf-node-admin-tag@ietf.org" <draft-ietf-ospf-node-admin-tag@ietf.org>
Thread-Topic: [OSPF] AD review of draft-ietf-ospf-node-admin-tag-04
Thread-Index: AQHQ9Wi9kAg4Y2m6EUyUor8EP2sEbJ5JO10A///E8AA=
Date: Tue, 22 Sep 2015 19:30:39 +0000
Message-ID: <D2272216.30E2B%acee@cisco.com>
References: <CAG4d1rdCDNrk+Hn0SkSx1LeRfSUHr+LLSJ8LR-k5ui6WUm0h3A@mail.gmail.com> <CAG4d1rfOa9M8adSxocHka0wYL7wZbUP94ujGC9CW16QOiSBEfA@mail.gmail.com>
In-Reply-To: <CAG4d1rfOa9M8adSxocHka0wYL7wZbUP94ujGC9CW16QOiSBEfA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [173.36.7.24]
Content-Type: multipart/alternative; boundary="_000_D227221630E2Baceeciscocom_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/ospf/nM8sWTgU_XwwyWeQW57M4E-CSYA>
Subject: Re: [OSPF] AD review of draft-ietf-ospf-node-admin-tag-04
X-BeenThere: ospf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: The Official IETF OSPG WG Mailing List <ospf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ospf>, <mailto:ospf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ospf/>
List-Post: <mailto:ospf@ietf.org>
List-Help: <mailto:ospf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ospf>, <mailto:ospf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Sep 2015 19:30:44 -0000

Thanks Alias - Speaking as Document Shepherd…

Authors,

Please let me know if you require any assistance - these all seem like good comments.

From: OSPF <ospf-bounces@ietf.org<mailto:ospf-bounces@ietf.org>> on behalf of Alia Atlas <akatlas@gmail.com<mailto:akatlas@gmail.com>>
Date: Tuesday, September 22, 2015 at 3:02 PM
To: OSPF WG List <ospf@ietf.org<mailto:ospf@ietf.org>>, "draft-ietf-ospf-node-admin-tag@ietf.org<mailto:draft-ietf-ospf-node-admin-tag@ietf.org>" <draft-ietf-ospf-node-admin-tag@ietf.org<mailto:draft-ietf-ospf-node-admin-tag@ietf.org>>
Subject: Re: [OSPF] AD review of draft-ietf-ospf-node-admin-tag-04



On Tue, Sep 22, 2015 at 2:58 PM, Alia Atlas <akatlas@gmail.com<mailto:akatlas@gmail.com>> wrote:
As is customary, I have done my AD review of draft-ietf-ospf-node-admin-tag-04
before requesting IETF Last Call.

First, I'd like to thank the working group and Shraddha, Harish, Hannes, Rob,
Anton, Zhenbin, and Bruno for their hard work on the draft.  However, this short
draft has 7 authors, which is a couple over the author limit for RFCs.  Experience
has shown that it takes much longer to process a draft through AUTH48 and the
other steps necessary (responsiveness to comments, agreement, etc) with a large
number of authors.  While I am willing to be persuaded - on or off list - that all 7
of the current authors are actively editing, I would prefer that a smaller number be
selected as the active editors.

In some cases, a draft represents a multi-vendor effort requiring a significant commitment from more than 5 authors and I’d specifically request a deviation from the author limit. I don’t see this to be the case with this draft.



While that discussion is ongoing, here are my technical comments.  In general,
the draft is in good shape but could use some English grammar editing; I have not
tried to indicate all the places where "the" is missing, for instance.

1) In the abstract: "This optional operational capability allows to
   express and act upon locally-defined network policy which considers
   node properties conveyed by tags."

   What is the subject that "to express and act upon"?  Is it a router?
   Please clean up.

2) In Sec 3.2: "The TLV SHOULD be considered an unordered list."  Perhaps
   "the value contents of the TLV" or something that makes it clearer?

3) In Sec 4.3: " [RFC7490] proposed method of"  should be
   "[RFC7490] defines a method of"

4) In Sec 5, I'm fairly certain that admin tags can leak additional
   information to an IGP snooper.  It would be useful to have some thoughts
   about that.

When you include this, be sure and point out the the attacker would also require knowledge of the policies corresponding to the tags. I’d also point out that the policies and advertised tags are local to the OSPF routing domain as is done in RFC 5530.

Thanks,
Acee


5) In IANA considerations, please duplicated the suggested value (10) that
   was mentioned in Sec 3.1

Thanks again for the hard work.  The sooner we resolve whom the editors are,
the sooner this draft can proceed.  Ideally, if updated by Thursday, it could enter
IETF Last Call and make the IESG telechat on Oct 17.

Oct 15 that is.


Regards,
Alia