Re: [Pce] [Lsr] Lars Eggert's Discuss on draft-ietf-lsr-pce-discovery-security-support-11: (with DISCUSS and COMMENT)

"Acee Lindem (acee)" <acee@cisco.com> Tue, 04 October 2022 17:52 UTC

Return-Path: <acee@cisco.com>
X-Original-To: pce@ietfa.amsl.com
Delivered-To: pce@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 05AE2C14F75F; Tue, 4 Oct 2022 10:52:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.606
X-Spam-Level:
X-Spam-Status: No, score=-9.606 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=KYUzCR8Z; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=gKHgvYDq
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9TV71PbiwvqD; Tue, 4 Oct 2022 10:52:47 -0700 (PDT)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A59F8C14F613; Tue, 4 Oct 2022 10:52:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=13126; q=dns/txt; s=iport; t=1664905966; x=1666115566; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=DvlpwRXnEmkKLq7a5WFpStXRR/AM3AsWIaDaYU5Oqcw=; b=KYUzCR8ZBXKLsbmHTy0CWPdAkRmuPXVvGCGIUUJxBcX5DMPCptE9odKH rjivWKEamocZv+J9bVu/PeeRQJI+NQPn8bhD/n88xoxtXJlqvDsLTnjaj uD8XfM/8YKxeEmIrN9NuRyiIDPf1h+NfdPe01hRZkACSmNRHDQxYnC0cL A=;
X-IPAS-Result: A0AYAAB/cjxjmI0NJK1QBAYbAQEBAQEBAQEFAQEBEgEBAQMDAQEBQIE7BgEBAQsBgVFSfwJZOkUCAYRLg0wDhFBfiBcDkGqKfoEsFIERA1QLAQEBDQEBNA4EAQGBU4MyAhaEWAIlNAkOAQIEAQEBAQMCAwEBAQEBAQMBAQUBAQECAQcEFAEBAQEBAQEBHRkFDhAnhWgNCQUBAYYyAQEBAQIBEhERDAEBJRIBDwIBCA4KAgIfBwICAjAVEAIEAQ0FCRmCWwGCbQMNIwMBD506AYE/AoofeoEygQGCCAEBBgQEgTgBFUGDAhiCOAmBESwBgzGFGoMiFAmBbIIzJxyCDYEUAScMEIJnPoJiAQEDgSgBBwQGAgEICBCDVjiCLpQ2hSccOAMZKx1BAwtCNAMVAxQDBSEHAxkPIw0NBBYHDAMDBSUDAgIbBwICAwIGEwUCAk00CAQIBCskDwUCBy8FBC8CHgQFBhEIAhYCBgQEBAQVAhAIAggmFwcTGBsZAQVZDgkhHA4aDQUGEwMgbwUKOA8oLgFpKx0bCoEMKigVAwQEAwIGEwMDIgIQKjEUBCkTEi0HK3MJAgMiZgUDAwQoLAMJIR8HKCQ8B1g6AQQDAhAiPQYDCQMCIll2AjERFQUDDRkmCAUjFxwECDwCBQZUEwIKEgMTDwYnSg9KmBeBT4EXCQE9AS8THzYEIgsOGAQeLQkjBF8MGAMOARgOA5JYB4MQRqtcCoNdizyOe4YCBC6DdoxRmD+XDSCCK4pzlHgLhQECBAIEBQIOAQEGgWE6a3BwFWUBgggBATIJSBkPjiAMDQkVgzuFFIVKdQILLgIGAQoBAQMJh3GCSAEB
IronPort-PHdr: A9a23:vHYSyxS+jjCu7oKcnbY4smIeoNpso7vLVj580XJvo75Nc6H2+ZPkM QSf4Ph2l1bGUM3d7O4MkOvZta3sGAliqZaMuXwPatpAAhkCj8hFkwkpGsXQD0r9IbbjZDA7G 8IXUlhj8jm7PEFZFdy4aUfVpyi57CUZHVP0Mg8mTtk=
IronPort-Data: A9a23:IoRSwasWp6H3yOY+uDl0CgSC0+fnVO5eMUV32f8akzHdYApBsoF/q tZmKW7QOf2CYmH3c912OYngp0pX68PWz4M1TQI6qns8FHgXgMeUXt7xwmUckM+xwmwvaGo9s q3yv/GZdJhcokf0/0vrav67xZVF/fngqoDUUIYoAQgsA145IMsdoUg7wbRg2tY02YPR7z6l4 LseneWOYDdJ5BYsWo4kw/rrRMRH5amaVJsw5zTSVNgT1LPsvyB94KE3ecldG0DFrrx8RYZWc QpsIIaRpQs19z91Yj+sfy2SnkciGtY+NiDW4pZatjTLbhVq/kQPPqgH2PU0VHkHjzaqmu5N7 otQhJK3cV4NZaPwobFIO/VYO3kW0axu8bvDJz20ttaeih2AeHr3yPIoB0YzVWEa0r8oWicVq 7pBc3ZUMknra+GemNpXTsFljckuBMLqJ4gY/HpnyFk1CN53Hc2YGf+QtIQwMDEYt4NCOP3id 8YlaR0saz7OfkByAVs7B8dr9AuvriCvL2IHwL6PnoI+73LSxQpZ17zhPN3aPNeNA9hW9m6dq 3jP+yLiAhAAPc6e0T2Y6Fq0gevemD//HokbfJW4//hsjUa7yXYeBBkbTx2yvZGRkkWzc9NSN 0JS/TAhxYA271aDT9ThUVu/unHslhoHQZ9bE+Q78hqly6fI7UCeHGdsZjJbYdI68c47WTJv0 kST2sviCHljsaaeTmyQ7KbRtj65JDIUMX5HfjIcVQwf//HirZ09yBXVQb5LEaOugfX0FC3+h TeQo0AWg7wJluYG2Kq250yBhCijzrDLQRUd5BjRX3qo9EV/aZLNWmCzwVHf6fAFJ4GDQxzR+ nMFgMOZqusJCPlhiRBhXs0wIuGt5NWADgH630NeEZ4ZrhD29UKaKNU4DC5FGG9lNcMNeDnMa UDVuB9M6JI7AJdMRfIqC25WI5l3pZUMBegJRdiPNYMXPcYZmBuvuXAwOxHBhggBhWB2yckC1 YGnndFA5JrwIY1jyDewLwv2+eB2nnllrY8/qGyS8vhK+bOaYHjQQrAfPR7eKOs496iD5g7S9 r6z1vdmKT0CAYUSgQGOrub/yGzmy1BgX/gaTOQMLIa+zvJOQj1JNhMo6epJl3ZZt6pUjPzU2 Xq2R1VVzlHy7VWed1vWOio6OO+2BM4uxZ7eAcDKFQv3s5TESdv/hJrzi7NsFVXa3LU5lKUtH 6VtlzuoXaoRItg4x9jtRcCt8NM9HPharQmPJCGiKCMuZIJtQhehxzMXVlWHycX6NQLu7ZFWi +T5jmvzGMNfLyw8V5y+QKz0kDuMUY01xbgas73geIcDIS0BMeFCdkTMsxPAC5hXeE2cnGvHi G57w34w/IHwnmP8y/GR7YjskmtjO7IW8pZyd4UD0YuLCA==
IronPort-HdrOrdr: A9a23:7ixxm6xL/uB9KhRmG3VFKrPxjuskLtp133Aq2lEZdPULSKKlfp GV88jziyWZtN9IYgBdpTiBUJPwJU81bfZOkMYs1MSZLXbbUQyTXc9fBOrZsnHd8kjFl9K1up 0QC5SWZOeAb2SSyPyKnTVQcOxQgeVvkprY/ts2pk0FJWoBBsEQjDuRSDzraHGeLzM2YqbRYa Dsn/av0ADQH0j/AP7LY0UtbqzmnZnmhZjmaRkJC1oM8w+Vlw6l77b8Dlyxwgoeeykn+8ZjzU H11yjCoomzufCyzRHRk0XJ6Y5NpdfnwtxfQOSRl8kuLCn2gArAXvUjZ1TChkF2nAic0idvrD D+mWZmAy210QKWQoiBm2qp5+An6kd215at8y7BvZKpm72GeNtzMbsxuWseSGqD16Ll1+sMjZ 6iGAmixsBq5Fr77VfAD5KjbWAbqmOk5XUliuIdlHpZTM8Xb6JQt5UW+AdPHI4HBz+S0vFtLA BCNrCU2B9tSyLTU1nJ+m10hNC8VHU6GRmLBkAEp8yOyjBT2HR01VERysATlmoJsMtVcegI28 3UdqBz0L1eRM4faqxwQO8HXMusE2TIBRbBKnibL1jrHLwOf3jNt5n06rMo4/zCQu1D8LIi3J DaFF9Iv287fEzjTcWIwZ1Q6xjIBH6wWDz8o/sukaSReoeMM4YDHRfzPGzGyfHQ0cn3KverLs qOBA==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.95,158,1661817600"; d="scan'208";a="945322293"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 04 Oct 2022 17:52:44 +0000
Received: from mail.cisco.com (xfe-aln-002.cisco.com [173.37.135.122]) by alln-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id 294HqiSl003659 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Tue, 4 Oct 2022 17:52:44 GMT
Received: from xfe-rtp-003.cisco.com (64.101.210.233) by xfe-aln-002.cisco.com (173.37.135.122) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9; Tue, 4 Oct 2022 12:52:44 -0500
Received: from NAM11-BN8-obe.outbound.protection.outlook.com (64.101.32.56) by xfe-rtp-003.cisco.com (64.101.210.233) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9 via Frontend Transport; Tue, 4 Oct 2022 13:52:44 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=g7q6RmEsn9dFoMMsV6QsqeHQjiSikwQJ+eLI8NjabtVyeqR49yI2uJPXgQFfoz3mnnYNhFg7MZe8BxSTPR9RqAt10KfpUYSP3u5aUWJZQKMc4Ozo8L/v7RlDhpIpX130IjQQt5cMxepH+8VqHDlhXF/tuVbBRWzpqcwmXQAMsRSzk31Gn9x/rZ78TXAUsr57mN49aPnSZQW+Q/jF3NFQDCH11pPR0OuKibGYMjEi+HO5s6B1A8WzseSCJNMUk9GY5S0q3A9mUtEzZ0XcY3W/mwqL8cO8mdBHctpzZNStE3ycPEjn5/qN6DgY2g6oXPhO4EY0NBzxu1zZLzQxCscsQQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=DvlpwRXnEmkKLq7a5WFpStXRR/AM3AsWIaDaYU5Oqcw=; b=N7uD6N4NxbdpP7bzUJpIHFwEfHyGDQ1RKH+df3nxQe2ZjJ/iTV9yC/oqmJELCGAg3M5RvokaDBvs7M2Y36EMqqfD+mIoaIjP24igLZECJ1gZDtLp/VbBLtQxuQJ4yFm0itEIO+7fYwYsoY7eNoUbKkgvb8UAVnOYd7ZHxIvCLD5A7pCGUyoemvoGB2qB5ppfSU6ZTWs3G0o/0BFtxNqMdf4DVW/ILLsdH7iHjG2kZwa3E1d0prHcmDIcKepFiDpD0si9sqgXn+O69R7YOg3a4KT5ZPLNu3826P3pI4lvC9w1ONiShBy34NbNZnEbJI8YPhgitDMipyO1R2l7Rd+xwg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=DvlpwRXnEmkKLq7a5WFpStXRR/AM3AsWIaDaYU5Oqcw=; b=gKHgvYDqeT/waW+3jWTc2r/Me4JYf+jj0bVyiyAumKNF9duttA3FZCtqblmTqP7pY16Y/Gy3Pni8u4Wiq7d26PvociWycbCGN/blAAYSAjdpzGfXecCFA7MqGyjhv+QZk9ID88z9x7Iip1U7qS7VZPKdci5ov/nPi4elbtgAi/Q=
Received: from BYAPR11MB2757.namprd11.prod.outlook.com (2603:10b6:a02:cb::16) by BL1PR11MB5977.namprd11.prod.outlook.com (2603:10b6:208:384::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5676.24; Tue, 4 Oct 2022 17:52:42 +0000
Received: from BYAPR11MB2757.namprd11.prod.outlook.com ([fe80::138f:535:2fee:84b4]) by BYAPR11MB2757.namprd11.prod.outlook.com ([fe80::138f:535:2fee:84b4%7]) with mapi id 15.20.5676.031; Tue, 4 Oct 2022 17:52:42 +0000
From: "Acee Lindem (acee)" <acee@cisco.com>
To: John Scudder <jgs@juniper.net>, Lars Eggert <lars@eggert.org>
CC: The IESG <iesg@ietf.org>, "draft-ietf-lsr-pce-discovery-security-support@ietf.org" <draft-ietf-lsr-pce-discovery-security-support@ietf.org>, "lsr-chairs@ietf.org" <lsr-chairs@ietf.org>, lsr <lsr@ietf.org>, "pce@ietf.org" <pce@ietf.org>, Hannes Gredler <hannes@gredler.at>, "Les Ginsberg (ginsberg)" <ginsberg@cisco.com>, "JP Vasseur (jvasseur)" <jvasseur@cisco.com>, "meral.shirazipour@polymtl.ca" <meral.shirazipour@polymtl.ca>, Adrian Farrel <adrian@olddog.co.uk>
Thread-Topic: [Lsr] Lars Eggert's Discuss on draft-ietf-lsr-pce-discovery-security-support-11: (with DISCUSS and COMMENT)
Thread-Index: AQHY1Mf+IrMisCCzyUys/qIYKYLaD63+hBAA///DggA=
Date: Tue, 04 Oct 2022 17:52:42 +0000
Message-ID: <5967FEDA-7517-45CF-89E7-C3B900CEEBB0@cisco.com>
References: <166454083729.58860.322901814330533722@ietfa.amsl.com> <FE562068-8588-4998-965F-84B931CC3224@juniper.net>
In-Reply-To: <FE562068-8588-4998-965F-84B931CC3224@juniper.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.65.22091101
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: BYAPR11MB2757:EE_|BL1PR11MB5977:EE_
x-ms-office365-filtering-correlation-id: 3048614d-57c7-4ebf-df0e-08daa6313c83
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: PCczsA7w96ZsIqOO0NBf4dYmRGekAw6+fV/IaDVcYbGt9BkoUmTBPyfH6+LYTd0TGkvAnzyIsTY260/gtXpkMquN4MlCKxR8hjHCeRtfH53cVt4TlKcg7e70mSX0GYPwZ5ODDxDV1Gq095ja7vx9uBcLPGDAks4NNWh2LGa9tyROVAnh0IYO4P9ckHRKBQcJIX9N8C0EXqeiuPYfEawggQ0c1p/ZFAgMH0aWsQ+inD2MG0/3GPOWBSY/8pgSw7Ri34KCIwvrTJO/dl2cMgkEaG9CL7i61dD0VhD++TqzBLQRXCbZ+tm7xgxn8rrM7zZQ0pByhFbHbpcDXUd9Zc3l1ou098p/QxwQEcBFpSVRu0DXOLLmd0KR+7RkpJeOBEcQ0oWqGTAqqkfJ7C50n2/sJYIFYl1/+CLkpe46TO4ztJw37Zwmsc08oDGbmSp2AcmNOry0yJ7HuicnQOpPHEzlX6pFmay+S9/qIQzg0PJ8eWF4Aj5VdO6EUc2aMc6Dyj5bze1jYGg+hks3kAzcxwaPXXOcD41XMYLdBAr9bXgJcaL8MmPStE0JnSXwc94PLvblRFtDmHhO2XUQhcZrqLfp6HyZcUFlxWD886555dsOyHsSkA1Z1WBJ5jHhgiikRMTeTlyJTHn9QQb0VBO0g7tWYb9bs8f0sIDRmHfO/bjjMkvqECrWmfJeDwwdO0YWsy4Ap0ke0ua6Gk+hbyG6a3BIwYnfXKWqr6bcktmF8l6wkzxluwUXNgqNgUPBHaCUtZelB3GKNcSpDXiY0hH7kophpHti2u3fTSYbFzCWTSdUaE+octQOkRemJi3JKrvUGFH8/xEzL4wPqkxSc7VpDeDlmrUB3tLmScupqh6dw26QF2k=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR11MB2757.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(366004)(396003)(376002)(39860400002)(346002)(136003)(451199015)(15650500001)(2906002)(38070700005)(8936002)(5660300002)(7416002)(76116006)(4326008)(33656002)(110136005)(91956017)(83380400001)(66574015)(36756003)(66946007)(122000001)(54906003)(316002)(66446008)(38100700002)(66556008)(41300700001)(66476007)(8676002)(64756008)(26005)(6512007)(478600001)(186003)(2616005)(966005)(53546011)(6486002)(71200400001)(86362001)(6506007)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: gHTwQSVE3qCbPkoinNj8mYhP3hQWVHySPLrY1QatR6Ujkwl6a2BBjlaMHDfIn5r3aXfQWbESMdipniJLVZojC/hukZ/fR6t05D4fTUroWWhI+BW6DeUIo6Gk0ACtCjMXIZxN19bbJV9AkEQYqa+wOi5SqtYepoEkGk/4OSlg01s3Nta+sJtUDlxOO7QSoALpbB9TbItC6yBxLrHdcyhipmYnViFvNe0vH5qJIrPAB4pk/SNd453OZ9dF0+7KKFuJroUxMV7JABZBKZGLsDk39XmdS5MGyaMsZZR1iZICuGVKM9JmkAymukzP+FEcm3/HnatVhb+wuNS6Q48JpRKNAgSUETJ9fIuauLye7juzo3MzUi1O6hDkA9B6icgM2Io0UJCidxbrprQvMRq0wonv7MmkOs7RM2IWZRJB2FnsiFBcWuhO4z3OmbavTgm2S+3CQqhKHkkHL79qVZdNZvT/51Yi8jOX0Wx6/DfNNEnq61I9qkSTJ0lvs0AFga5AhKRIFWAffRaol1NFfnYm8PgKLD3N4HJfweVe74y4vQmuyhkM9d/lC+5fux4JZeozXH40vL6pb4BTOoAqEhINGEBU/ntWrLzD2qtnIIjxjqh5Glfhn47xkGXu87hil56BqlJ8bspIQmKrzVM6TR4OYZl5Gj7zfk7qE6+g1sM7VZriYj8lBOUTwI86aqeW+3E8r2m560BkjTOsgsrEXtUere4Jy7sX7EhefPumi2svSWMIbc/fDUoXlOzAQjVf7j5BR1i+pjrF4F4+kGw1mDbqdokmKnv9oFKr523fzir3qSfNZemHvf3nFZ/7bBoJHDDs/bvuHJF0q+3RCMDhCfdFw0MXKWC3Mo8Stszzw3zChgq5cF32TeUz25Ps8XSekQCcV9q50zRk3rdbo0ABEYhwSXi46xHYGpUQJnMiMyklM+gLXIUL0+zyraWA9pa81GxU+pC0QvBi++vS4nBq16PGsYPO9xIMjwOgTcc1sfQB30qdTqPz2w8/HvcFzAEAZtO6bfrW8uO26htDo+DeUkT5q0Fh/2H7bwkWvE1/d+44/DT0gXefA1ezLEFHscqoA6/aN0WChzeNaiJWzovSF1TBG+G0x+bmmnN8Cp08mEpR5MNj8FPXpbOzpHQGxP2HeGD0Mwj7/VOAwz5di7Zpzanqx6X2m5YPRXl/FlVXD1z81OrDWsKNgE0MdRaJJVWIDH9XVY3zpUYf0M6KgNLYuIUubOEN9wUVDGOtMphrNkSwSkp+XBjaRGKiAkc6XWnZ83SABncCUtG1Fp4ZPvrPRkPFu8QFDeShIMFMm79Cgn9OaRtdRDqqMD3gMJbqNUiBLy0K6OtbfVZJQ5S9/7PC3bH57QPFV/vNywIImKLrTpuQTMTbi6/hEm1hMu8U45Dnur2CddSGb+0HiHlYrZQKvXf34UBzmThiRpMOgnAqxun3hbwmIgGl6imOhAu4AHgREL4t/WbgFUHFOAClePPPpFvBY3v7OBz+ngmgENs6P9Ag6J+nIpYwZ3TLckjpaY01a239AfITQ+/YCePo5oX6+kiXw3/q2dLhkZI5nEUkjBymcOYK+G/C7nhA7SNFXd1N+oCihe+Q
Content-Type: text/plain; charset="utf-8"
Content-ID: <C7312E464F36F14195855C9CF744C642@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR11MB2757.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 3048614d-57c7-4ebf-df0e-08daa6313c83
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Oct 2022 17:52:42.4761 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Kv3jC4j9lu7evQAB08SR2/UiGLbdsKjP1aIy8QQrwoYVhDT2ziRawD0rhchCoO8S
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL1PR11MB5977
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.135.122, xfe-aln-002.cisco.com
X-Outbound-Node: alln-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/pce/sZVf5DAN0hfsqXlLs8KEd6G8WIk>
Subject: Re: [Pce] [Lsr] Lars Eggert's Discuss on draft-ietf-lsr-pce-discovery-security-support-11: (with DISCUSS and COMMENT)
X-BeenThere: pce@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Path Computation Element <pce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pce>, <mailto:pce-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/pce/>
List-Post: <mailto:pce@ietf.org>
List-Help: <mailto:pce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pce>, <mailto:pce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 04 Oct 2022 17:52:51 -0000

Speaking as long-time LSR/OSPF WG Member and Co-author of RFC 4970 and RFC 7770: 

When RFC 5088 was being standardized, there was concern over both advertising non-routing information in OSPF and exceeding the maximum size of an OSPF Router Information LSA which was limited to a single LSA instance per OSPF router (RFC 4970).  The controversial statement below was added to assuage these concerns. With the publication of RFC 7770, an OSPF router can advertise multiple Router Instance LSAs with different instance IDs. At the same time, we have evolved to using Router Instance LSAs for limited capability information associated with routing applications (e.g., PCE). For non-routing information or advertising more information without impacting unicast routing, I'd recommend OSPF-GT (https://datatracker.ietf.org/doc/draft-ietf-lsr-ospf-transport-instance/).  

Thanks,
Acee

On 10/4/22, 1:29 PM, "John Scudder" <jgs@juniper.net> wrote:

    Hi Everyone,

    +Adrian since he appears to have been the shepherd for RFC 5088, which is the root of Lars’ DISCUSS.
    +Hannes, Les, JP, Meral as people who may have more context on the question

    Since I haven’t seen any replies to this DISCUSS yet I did a little digging. The text in question:

       No additional sub-TLVs will be added to the PCED TLV in the future.
       If a future application requires the advertisement of additional PCE
       information in OSPF, this will not be carried in the Router
       Information LSA.

    Was introduced in draft-ietf-pce-disco-proto-ospf-07, September 2007. Checking in the archives, I see one relevant mail thread: https://mailarchive.ietf.org/arch/msg/pce/UERk8vF5e7cFQoblkDAVA74Ojh0/ is the beginning, but then it seems to have been indexed wrong so you should continue from here: https://mailarchive.ietf.org/arch/msg/isis-wg/BpUVKsjr46ha9kbF3jwgKyymEBo/ to pick up Les’s reply as well. There are four relevant messages in total, from Meral Shirazipour, JP Vasseur, Hannes Gredler, and Les Ginsberg.

    Rather than try to summarize I’m going to ask people to go look at the short mail thread for themselves. Perhaps this will jog people’s memories enough to allow a discussion on why we’re opening a registry for new code points that was explicitly defined as being closed.

    Thanks,

    —John

    > On Sep 30, 2022, at 8:27 AM, Lars Eggert via Datatracker <noreply@ietf.org> wrote:
    > 
    > 
    > Lars Eggert has entered the following ballot position for
    > draft-ietf-lsr-pce-discovery-security-support-11: Discuss
    > 
    > When responding, please keep the subject line intact and reply to all
    > email addresses included in the To and CC lines. (Feel free to cut this
    > introductory paragraph, however.)
    > 
    > 
    > Please refer to https://urldefense.com/v3/__https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjt8J-BPa3$
    > for more information about how to handle DISCUSS and COMMENT positions.
    > 
    > 
    > The document, along with other ballot positions, can be found here:
    > https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-ietf-lsr-pce-discovery-security-support/__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjt2I779yk$
    > 
    > 
    > 
    > ----------------------------------------------------------------------
    > DISCUSS:
    > ----------------------------------------------------------------------
    > 
    > # GEN AD review of draft-ietf-lsr-pce-discovery-security-support-11
    > 
    > CC @larseggert
    > 
    > ## Discuss
    > 
    > ### Section 4, paragraph 3
    > ```
    >     Section 4 of [RFC5088] states that no new sub-TLVs will be added to
    >     the PCED TLV, and no new PCE information will be carried in the
    >     Router Information LSA.  This document updates [RFC5088] by allowing
    >     the two sub-TLVs defined in this document to be carried in the PCED
    >     TLV advertised in the Router Information LSA.
    > 
    >     Section 4 of [RFC5089] states that no new sub-TLVs will be added to
    >     the PCED TLV, and no new PCE information will be carried in the
    >     Router CAPABLITY TLV.  This document updates [RFC5089] by allowing
    >     the two sub-TLVs defined in this document to be carried in the PCED
    >     TLV advertised in the Router CAPABILITY TLV.
    > 
    >     This introduction of additional sub-TLVs should be viewed as an
    >     exception to the [RFC5088][RFC5089] policy, justified by the
    >     requirement to discover the PCEP security support prior to
    >     establishing a PCEP session.  The restrictions defined in
    >     [RFC5089][RFC5089] should still be considered to be in place.
    > ```
    > (This is mostly for discussion on the telechat, and I expect to clear
    > during the call.)
    > 
    > Why were 5088/89 so strict on not allowing new sub-TLVs? This seems
    > quite unusual for IETF specs. I'm not arguing that this document
    > can't update those earlier RFCs to allow these new sub-TLVs, but it
    > seems odd to do so and in the same sentence say "the restrictions
    > should still be considered in place."
    > 
    > ### Section 8.2, paragraph 1
    > ```
    >     The PCED sub-TLVs were defined in [RFC5088] and [RFC5089], but they
    >     did not create a registry for it.  This document requests IANA to
    >     create a new registry called "PCED sub-TLV type indicators" under the
    >     "Interior Gateway Protocol (IGP) Parameters" grouping.  The
    >     registration policy for this registry is "IETF Review" [RFC8126].
    >     Values in this registry come from the range 0-65535.
    > ```
    > Should the registration policy not be stricter (e.g., Standards
    > Action?) given that 5088/89 didn't even allow any new values?
    > 
    > 
    > ----------------------------------------------------------------------
    > COMMENT:
    > ----------------------------------------------------------------------
    > 
    > ## Comments
    > 
    > ### Inclusive language
    > 
    > Found terminology that should be reviewed for inclusivity; see
    > https://urldefense.com/v3/__https://www.rfc-editor.org/part2/*inclusive_language__;Iw!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjt1fwrlFS$   for background and more
    > guidance:
    > 
    > * Term `master`; alternatives might be `active`, `central`, `initiator`,
    >   `leader`, `main`, `orchestrator`, `parent`, `primary`, `server`
    > * Term `man`; alternatives might be `individual`, `people`, `person`
    > 
    > ## Nits
    > 
    > All comments below are about very minor potential issues that you may choose to
    > address in some way - or ignore - as you see fit. Some were flagged by
    > automated tools (via https://urldefense.com/v3/__https://github.com/larseggert/ietf-reviewtool__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjtxqHvOEf$  ), so there
    > will likely be some false positives. There is no need to let me know what you
    > did with these suggestions.
    > 
    > ### URLs
    > 
    > These URLs in the document can probably be converted to HTTPS:
    > 
    > * https://urldefense.com/v3/__http://www.unicode.org/unicode/reports/tr36/__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjt9o1UwDk$
    > 
    > ### Grammar/style
    > 
    > #### "Abstract", paragraph 1
    > ```
    > for OSPF and IS-IS respectively. However these specifications lack a method
    >                                  ^^^^^^^
    > ```
    > A comma may be missing after the conjunctive/linking adverb "However".
    > (Also elsewhere.)
    > 
    > #### Section 1, paragraph 5
    > ```
    > ry" instead of the "IGP registry" where as [RFC8623] and [RFC9168] uses the
    >                                  ^^^^^^^^
    > ```
    > Did you mean "whereas"?
    > 
    > #### Section 3.2.2, paragraph 3
    > ```
    > string to be used to identify the key chain. It MUST be encoded using UTF-8.
    >                                   ^^^^^^^^^
    > ```
    > This word is normally spelled as one. (Also elsewhere.)
    > 
    > #### Section 5, paragraph 4
    > ```
    > enable a man-in-the-middle attack. Thus before advertising the PCEP security
    >                                    ^^^^
    > ```
    > A comma may be missing after the conjunctive/linking adverb "Thus".
    > 
    > ## Notes
    > 
    > This review is in the ["IETF Comments" Markdown format][ICMF], You can use the
    > [`ietf-comments` tool][ICT] to automatically convert this review into
    > individual GitHub issues. Review generated by the [`ietf-reviewtool`][IRT].
    > 
    > [ICMF]: https://urldefense.com/v3/__https://github.com/mnot/ietf-comments/blob/main/format.md__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjt8uPawyE$
    > [ICT]: https://urldefense.com/v3/__https://github.com/mnot/ietf-comments__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjtxU9hxDt$
    > [IRT]: https://urldefense.com/v3/__https://github.com/larseggert/ietf-reviewtool__;!!NEt6yMaO-gk!BEvEYiZR6x7lTVrU9AA55g6M1-32P6xLCiZ537k4RWeOwmTjkSrRmf0k6fDyFPdPOpbjtxqHvOEf$
    >