[ptth] Re: Tweaks to PTTH Charter

Mike Blanche <mike-ietf@blanche.org> Thu, 13 August 2026 07:33 UTC

Return-Path: <mike@blanche.org>
X-Original-To: ptth@mail2.ietf.org
Delivered-To: ptth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E6CE61290092C for <ptth@mail2.ietf.org>; Thu, 13 Aug 2026 00:33:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786606408; bh=r0J/VgNPUnc/qUbtetYdBdU8dT6SCOkDxLdOURtVx68=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=KfomFuOuWFO6/VzsvfeJ7HbSftZqJ4noMAQ+Qal3cbSelD2YLItQlY5Kgp98qpcQd rY6Ucj0srYO5NluSuoIDM98ANMch7YJoHRk8BexSbzL15+goLCJFpDfhGrMChEn54G K4zUut3+C5pyK+PeEl6P1xD/V+D9IlNbpjllDYHk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=blanche-org.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aDy15MBlec9K for <ptth@mail2.ietf.org>; Thu, 13 Aug 2026 00:33:27 -0700 (PDT)
Received: from mail-oi1-x232.google.com (mail-oi1-x232.google.com [IPv6:2607:f8b0:4864:20::232]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D9D9512900921 for <ptth@ietf.org>; Thu, 13 Aug 2026 00:33:27 -0700 (PDT)
Received: by mail-oi1-x232.google.com with SMTP id 5614622812f47-4a427e628a9so111982b6e.0 for <ptth@ietf.org>; Thu, 13 Aug 2026 00:33:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786606407; cv=none; d=google.com; s=arc-20260327; b=rd8iTbm935C2Cduxync8q59OEa40yCllIGbViBX4bRdDC098yhIzktxJ0bHbWBFkGP s8dXROcd4QFDa8EVJimYnqNQ90DdA/FiYirsg5Ch6dL0VN9+Y00TKV0Xht++atWwzRQB Tl20F9w0cjVeJN+EUaicR0V3X0ZgS9WRRwiL5fV1/QaDcMidhXtQv19kaIPffsrqhZX2 o8nu7y2TCtRQ5IWKt2XQ5IzWrLw1zwXKk0wb4Fb8HspdsWRL8TVmidDueuHs1CcxcP1k 6XTM5RUKprejOVV6gh/UiqsLf26xeefZ8H5jCcU5Bd1vcPYAyIGL7rghf1e+2SIfXYqd evmg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=r0J/VgNPUnc/qUbtetYdBdU8dT6SCOkDxLdOURtVx68=; fh=BuajDr6Tc5BSmEykgRYlL2Zuz0bBFi1gZ7Xe4GccjUE=; b=gsRmUdmAK9BVVFfzo44zlrgHcntk+83MLoOX19loWMBwmZuOP8Gbwt7UloAO1K1vvI rwpyRCR4AnWgHwFC0CKyMe2XA2Xf8JiyH1i+LMhll8ZPNgsG9eF8bH7Gm0KtDSwCfvSM v8rHep665pDZgyxwVL+4ZAUAi/pvdw4n/cf8tPKpTL12csSR35ThRLgfmzYgtOxQ3xvX mA3pdL06V0Hps0oKIC/VzLj3wItOPrlcP4oVuaYJRPtmyP7WbWIt8+REF48yy8Msb9+/ OuYNS6YPAj5aKRr7Vhoc9lbpXEt1DllSUJrYQvtnMCxrVKVtYii53esnEdr7IR4SP2A1 c40A==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=blanche-org.20251104.gappssmtp.com; s=20251104; t=1786606407; x=1787211207; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=r0J/VgNPUnc/qUbtetYdBdU8dT6SCOkDxLdOURtVx68=; b=etZjzjIs133ReW887WOyXkyW94PTube7l+2OEVfn64GxG9K7/c8tYM3yYpF/WuuGlI vBjUsZvANAoKLJUZNWExQ0MCpaqPvJ9PCpwZ5g35jSXhz8/a3SMD+POhxiVK2O3woX4g 13APqwR2J8nKSsIix/4AWyU6m6Qr0gxht6ILYl48/KG3zqBnRMgZ7JoX1LIalzFis3Ny Ve0Xj4gRBRfNihX7nRMs5BZ/CdnK0VJWHeTgy70Z6NB5oQnPMxZ5ur61OA0+jtXn7led NuU/7Sl0VUpIsEnamZGNnSbW7ab4hETdqRowX2HmHWYouby3kXIGOL7hWK7uJa1bFGum cQxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786606407; x=1787211207; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=r0J/VgNPUnc/qUbtetYdBdU8dT6SCOkDxLdOURtVx68=; b=i3XjzebCLMckFk8Eww+a/48AwOxaPuPnCyKnmgUmyW7x4hyfW9f2xS8pcq6gnDWP3f Cq/BOqFOlsKWK8dsHb1DQuvtN98uKSvX0b5UEL3UvkxuPjCWbABZ2ei4+LHAWPfn8OAC bgK9riyBmDAiyivt5MI9kVXy7df5ZLPy1ApQqF3158eGWKXd3KaZZrh6+CLeKisK1r9J AIU1+uhxZTao5QxCyyXfRdcD0GOvwzNNRzkbGE9X/VcSmGTwxynXuMR4kA4NtIP+7c0Q zHfeiZg4HYCt7REoE+yPatfGPdTg14VyQRkVpugM9W7gHVZ36gSUgt3PXFqvBORMeb4W yHzw==
X-Forwarded-Encrypted: i=1; AHgh+RpcKQvoqNWrj5mTuh/RzXUykYVWG2ljqq1HI7lDQZcVxE1svR78jaEDAeFFL4A4lsxBRDG2@ietf.org
X-Gm-Message-State: AOJu0Yx2AArmKAq6OdWBUYBsjiDtvdOoGmRvtRN7XkcVwCDN2aiVIryj o3MEdZvOMwiniEcBAMZgsxwRZd+Ej5qdKy7vYW51zuXsp451ek6Ch4HCx4aPN/nZmIh1uLBf8ep p1o/hmxF52nDW5q3rJVDfXB49nnKjeaaTg4YgzOrqQg==
X-Gm-Gg: AR+sD13t7uZbvf0ZVcniAcHX58cK9sDCuqNix8NRxZHeaG3WA+oNQz7OFVRYmNI+VZT ktdLFiOvHVs+3VQZb39JDdimEKD6s9ClRhwpkXVMU+1j/ZBWQmzOFjxUgXY91JU8hvoAPtQ2oqY ZxL/TBspe8OJeq7Mocf2PwAEnUOa06uNpmbgOD7MiuzAkZ3uMdFX6WpvEJELBqWSz1rv6WhHK4M 8AanN4IuhREquC271pfDM3jecqE9uO4GQ57/EkOCDZUcQfcZ3th/uTvwIBtjjoDRYBGToPI5O0R XLzWEJ5+woQ9tcoY7M4FU9Pi1ktMSRvwa5zawa0dFSgV+uybAPb61y5hModukCNoJZTdEDfgCqx ZpK7EGRXXuKnC
X-Received: by 2002:a05:6808:23d1:b0:495:feaa:9e3b with SMTP id 5614622812f47-4b22781fc0bmr3017969b6e.7.1786606407112; Thu, 13 Aug 2026 00:33:27 -0700 (PDT)
MIME-Version: 1.0
References: <CAPDSy+7c+JEWhXYTFbcazX+=US7WqA=T_bgtMYnm3UpY2G7Kaw@mail.gmail.com> <a8f51f05-6fdc-4d44-96d4-81af1f0ac9fc@betaapp.fastmail.com> <CANatvzyX5aOGy+7kkFDLo9DeJYyWp9YC498hjw8_niAZJtOd-Q@mail.gmail.com> <CAPDSy+4c5iiZTs8PECfwTCKWoQtq1PFEi3GTWm9o8HcJ3EjTCw@mail.gmail.com> <CAJFrNPDkoTrFZv=XmyGPRLs7SOL_iZkC3t0bU43T9iBG7d19Mw@mail.gmail.com> <CAPDSy+7mL2A40SwWgyXf88AD_B9XDv1ZkD=-TJFcnzoTt+Bjuw@mail.gmail.com>
In-Reply-To: <CAPDSy+7mL2A40SwWgyXf88AD_B9XDv1ZkD=-TJFcnzoTt+Bjuw@mail.gmail.com>
From: Mike Blanche <mike-ietf@blanche.org>
Date: Thu, 13 Aug 2026 08:32:47 +0100
X-Gm-Features: AUfX_mzaVJ8ryZ6glfEfnwURiVR9BHfTjPFvlm4TQ603rsOVmapPxvgoa_VgDKA
Message-ID: <CAJFrNPCNkQD+D66yJjuY0i-ZCN5aWvPhZrAEStnf_XCyUbSWdg@mail.gmail.com>
To: David Schinazi <dschinazi.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000003fe8e70658e8b8c5"
Message-ID-Hash: VN53HJDNUTZ3U6VQAT2HZWRATNK53LAU
X-Message-ID-Hash: VN53HJDNUTZ3U6VQAT2HZWRATNK53LAU
X-MailFrom: mike@blanche.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Kazuho Oku <kazuhooku@gmail.com>, Martin Thomson <mt@lowentropy.net>, 🥔 <ptth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ptth] Re: Tweaks to PTTH Charter
List-Id: "Discusses situations where the transport client/server roles and the HTTP client/server roles are reversed; the transport client is the HTTP server and vice versa." <ptth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ptth/PqcwV4mwRlQXLx30BNdmrjTbwR8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ptth>
List-Help: <mailto:ptth-request@ietf.org?subject=help>
List-Owner: <mailto:ptth-owner@ietf.org>
List-Post: <mailto:ptth@ietf.org>
List-Subscribe: <mailto:ptth-join@ietf.org>
List-Unsubscribe: <mailto:ptth-leave@ietf.org>

Thanks David for the quick response:

On the "tools" line - absolutely you don't want to be tied to a particular
solution - but with the current wording, I don't think the IETF
standardises "tools"? Can we use something like "mechanisms" instead, and
keep the rest?

On the threat model and security issues - there may be more to document
than can reasonably fit in the security considerations section of the
protocol document. Because PTTH reverses traditional transport roles by
serving incoming requests over outbound connections, it subverts standard
perimeter security assumptions, creates potential issues with
firewalls/middleboxes, and introduces security challenges around the
directional ambiguity of PTTH requests. This may be worth its own draft to
show these issues have been considered and addressed; if so, I think it's
worth calling out in the charter.

Thanks and I hope that is helpful.

Mike

On Wed, 12 Aug 2026 at 16:57, David Schinazi <dschinazi.ietf@gmail.com>
wrote:

> Hi Mike, and thanks for reviewing the charter.
>
> 1) Our intent here was to be sufficiently vague that it doesn't lock us
> into any specific part of the solution space. For example, going into the
> detail of "protocol mechanisms" might preclude the option of using a file
> format to accomplish that. (I'm not saying that a file format is a good
> idea, just that we want to make such decisions in the WG not in the charter)
>
> 2) The charter initially mentioned security considerations, but that was
> redundant - all IETF documents need to include security considerations, so
> there's no point in repeating that in every WG charter.
>
> Does that address your questions?
>
> Thanks,
> David
>
> On Wed, Aug 12, 2026 at 6:45 AM Mike Blanche <mike-ietf@blanche.org>
> wrote:
>
>>
>> Hi all,
>>
>> Thanks for the discussion on this and for improving the draft charter. I
>> like the direction this is going. I have a couple of
>> suggestions/questions/comments:
>>
>> 1) in the scope, one of the items is "Tools that can help guide routing
>> of requests from transport-layer servers to transport-layer clients". I
>> think I know what this is (which backend should receive which HTTP
>> request?) but the use of "guide routing" is also perhaps too informal -
>> could this benefit from being clearer? e.g.:
>>
>> "Protocol mechanisms that allow the transport-layer server to route
>> incoming HTTP requests to the appropriate transposed connection."
>> "Metadata and signaling required to map request rules (e.g., by URL path)
>> to a specific transport-layer client."
>>
>> 2) Since PTTH effectively punches holes in firewalls, the scope should
>> include a comprehensive threat model and security considerations. I'm sure
>> this was coming anyway, but I think it is good to specify it in the charter.
>>
>> Thanks,
>>
>> Mike
>>
>>
>> On Wed, 5 Aug 2026 at 20:25, David Schinazi <dschinazi.ietf@gmail.com>
>> wrote:
>>
>>> Thanks Martin and Kazuho. I've merged the PRs (with a small tweak).
>>> Latest version available at:
>>> https://github.com/ietf-wg-ptth/charter/blob/main/charter.md
>>>
>>> David
>>>
>>> On Tue, Aug 4, 2026 at 11:51 PM Kazuho Oku <kazuhooku@gmail.com> wrote:
>>>
>>>> Thank you David for updating the draft charter!
>>>>
>>>> I also like the changes proposed by MT.
>>>>
>>>> Specifically, "The authentication of the different actors, by
>>>> integrating existing schemes" this is a good change, as I think we have
>>>> kind of assumed that the worker and the proxy would authenticate _mutually_.
>>>>
>>>> As to the terms (workers), I agree that we do not need to use that in
>>>> the charter. Though, when discussing things at least, I prefer using the
>>>> terms, because in the past we've seen people just say "clients" or
>>>> "servers" without clarifying if they are talking about the role at the
>>>> transport layer or at the HTTP layer, and that has caused confusion.
>>>>
>>>> Anyways the charter is looking good, thank you very much to you all for
>>>> preparing 🥔
>>>>
>>>> 2026年8月5日(水) 12:06 Martin Thomson <mt@lowentropy.net>:
>>>>
>>>>> My feedback is here:
>>>>> https://github.com/ietf-wg-ptth/charter/pull/17
>>>>>
>>>>> I'll copy the substance of the comment here:
>>>>>
>>>>> I noticed that the terms "proxy" and "worker" were not defined.
>>>>> Because I really don't like those terms (we should use existing HTTP terms)
>>>>> and because it was unnecessary, some rewording of the two goals that used
>>>>> those terms was needed.
>>>>>
>>>>> In doing so I realized that the authentication point could be
>>>>> construed as giving license to invent new authentication methods. This
>>>>> should not be the case, though adaptation is probably needed. So say that
>>>>> much and also rule authentication out of scope the same way that identity
>>>>> is.
>>>>>
>>>>> Then it was not clear that we needed to so directly define the request
>>>>> routing piece. Some uses of this protocol will use proprietary mechanisms
>>>>> (because they already exist, say) and that's OK.
>>>>>
>>>>> https://github.com/ietf-wg-ptth/charter/pull/18 addresses awkward
>>>>> phrasing, but is strictly editorial.
>>>>>
>>>>> On Wed, Aug 5, 2026, at 12:22, David Schinazi wrote:
>>>>> > Hi 🥔 enthusiasts,
>>>>> >
>>>>> > I made some tweaks to the charter in response to the BoF discussion
>>>>> in
>>>>> > Vienna. You can find the latest charter here:
>>>>> >
>>>>> > https://github.com/ietf-wg-ptth/charter/blob/main/charter.md
>>>>> >
>>>>> > Please let us know what you think. Our next step is to get this over
>>>>> to
>>>>> > the IESG for their review.
>>>>> >
>>>>> > Thanks,
>>>>> > David
>>>>> > _______________________________________________
>>>>> > ptth mailing list -- ptth@ietf.org
>>>>> > To unsubscribe send an email to ptth-leave@ietf.org
>>>>>
>>>>> _______________________________________________
>>>>> ptth mailing list -- ptth@ietf.org
>>>>> To unsubscribe send an email to ptth-leave@ietf.org
>>>>>
>>>>
>>>>
>>>> --
>>>> Kazuho Oku
>>>>
>>> _______________________________________________
>>> ptth mailing list -- ptth@ietf.org
>>> To unsubscribe send an email to ptth-leave@ietf.org
>>>
>>