Re: [quicwg/base-drafts] forbid key discarding before receiving a packet protected with new keys (#4079)
Kazuho Oku <notifications@github.com> Tue, 08 September 2020 12:01 UTC
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F11823A0CC5 for <quic-issues@ietfa.amsl.com>; Tue, 8 Sep 2020 05:01:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.1
X-Spam-Level:
X-Spam-Status: No, score=-3.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z6Id2SIQWaLE for <quic-issues@ietfa.amsl.com>; Tue, 8 Sep 2020 05:01:48 -0700 (PDT)
Received: from out-26.smtp.github.com (out-26.smtp.github.com [192.30.252.209]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D92E3A0C46 for <quic-issues@ietf.org>; Tue, 8 Sep 2020 05:01:48 -0700 (PDT)
Received: from github-lowworker-39b4a70.va3-iad.github.net (github-lowworker-39b4a70.va3-iad.github.net [10.48.16.66]) by smtp.github.com (Postfix) with ESMTP id 799AD5E0F4D for <quic-issues@ietf.org>; Tue, 8 Sep 2020 05:01:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1599566507; bh=Li/po0dWvyU1F0MGLALNf/LailNJ/vh/APqcBlH2E/U=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=uB1U0Vd2t6fbCLxG4VjZLZ3VbPnhGrWkcoC9Q5fA9wZXx/oE2wMTFCt4PgelwCGnK eZuUvZLIqTlNbXLK8HwQhQO+7f9iwYq/m4uTzwkXnP4sU17IsGNaLBJNfoj3zb+q97 zcXqOg9sU3fjgeN+EdVv0iF0ufrl6UvOo90RPq/k=
Date: Tue, 08 Sep 2020 05:01:47 -0700
From: Kazuho Oku <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+AFTOJKYPBML5RXXTHDF32WF5MNJ2XEVBNHHCS6GFAM@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/4079/review/484061184@github.com>
In-Reply-To: <quicwg/base-drafts/pull/4079@github.com>
References: <quicwg/base-drafts/pull/4079@github.com>
Subject: Re: [quicwg/base-drafts] forbid key discarding before receiving a packet protected with new keys (#4079)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5f5772ab6aac3_30c19f0160414"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: kazuho
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/2FsE7IW9HyO6H12LlxU00uCWYfM>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.29
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Sep 2020 12:01:50 -0000
@kazuho commented on this pull request. Thank you for working on the PR. I like the changes to section 6.5. Regarding changes to section 6.1, please see my comments below. > @@ -1496,10 +1496,11 @@ The endpoint that initiates a key update also updates the keys that it uses for receiving packets. These keys will be needed to process packets the peer sends after updating. -An endpoint SHOULD retain old keys so that packets sent by its peer prior to -receiving the key update can be processed. Discarding old keys too early can -cause delayed packets to be discarded. Discarding packets will be interpreted -as packet loss by the peer and could adversely affect performance. +An endpoint MUST retain old keys until it has successfully unprotected a packet +sent using the new keys. An endpoint SHOULD NOT discard old keys immediately +after unprotecting a packet sent using the new keys. Discarding old keys too +early can cause delayed packets to be discarded. Discarding packets will be +interpreted as packet loss by the peer and could adversely affect performance. Regarding the first sentence, I think SHOULD works too, but I agree that MUST is better here. I do not think we need the second sentence, as we state that an endpoint "SHOULD retain no more than 3 PTO" down below. I think the crux of the problem is that the last two sentences that are left unmodified. As correctly pointing out by the issue, the outcome of discarding the keys too early is more than just a performance degradation. Doing so might kill the connection. We should state that clearly, and then the choice of the keyword in the first sentence becomes more of an editorial choice. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/pull/4079#pullrequestreview-484061184
- [quicwg/base-drafts] forbid key discarding before… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Kazuho Oku
- Re: [quicwg/base-drafts] forbid key discarding be… Mike Bishop
- Re: [quicwg/base-drafts] forbid key discarding be… ianswett
- Re: [quicwg/base-drafts] forbid key discarding be… Kazuho Oku
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… Marten Seemann
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson
- Re: [quicwg/base-drafts] forbid key discarding be… ianswett
- Re: [quicwg/base-drafts] forbid key discarding be… Martin Thomson