Re: [radext] Alissa Cooper's No Objection on draft-ietf-radext-coa-proxy-06: (with COMMENT)

Alissa Cooper <alissa@cooperw.in> Wed, 15 August 2018 20:02 UTC

Return-Path: <alissa@cooperw.in>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7ECBF130DEB; Wed, 15 Aug 2018 13:02:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=cooperw.in header.b=aBEQw37G; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=fMYOcdrL
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1lS3UL2Qn2CN; Wed, 15 Aug 2018 13:02:40 -0700 (PDT)
Received: from wout2-smtp.messagingengine.com (wout2-smtp.messagingengine.com [64.147.123.25]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 70E131310EC; Wed, 15 Aug 2018 13:02:40 -0700 (PDT)
Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.west.internal (Postfix) with ESMTP id 7D2E92B4; Wed, 15 Aug 2018 16:02:39 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute7.internal (MEProxy); Wed, 15 Aug 2018 16:02:39 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cooperw.in; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; bh=G7HMF8aZxBvbtyYXfmDVy2FY/c4wb oSOhLtKCM7ojZw=; b=aBEQw37GIx5mO9Br5NGP++2W302jhGAKomku/ECTMpp9d c8f5fRiuSEXjyadFPbq8ePdvG5uZ1DmPxrOSsB/MGvi6y2gWovZ2+zfQxDSZVNBD uj4BtPCx4HN/YFWdlhuVqclbIy/T04C+rwi7/6NRE/MItz+qQKjmx+V3vqTasn9D tChQmSJrN5o3gSSlIPDPuIwL/lzsY4VwUEcpsQGsn5nI5JXvo7aD/ABpvzBoIfZk FKpQxWWUQWn73Ea5kzLKtI3o//eIowbcbGEAdITDsS8gwDzSZ4X5g5NB3tXmMuk1 ZhcYW4n+7bPqfEpHliitl0/FhXBDdru1+gM00axzQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; bh=G7HMF8 aZxBvbtyYXfmDVy2FY/c4wboSOhLtKCM7ojZw=; b=fMYOcdrLTNBlJVNxtyFLZJ elflzKZ8yxGKgiQN5S706zhw0PCa4ChPSBB4ambXOiwnbzoVN7x2XgrwsWY3eygZ Oi375mxR80/8dkr3gLHTdQ6D8vSYOEp7VsB33jynAIxyGgj/0iOKeBi4yb7YrGi1 hJPPzClJXuqbHk8vyaM9qPmMKoIx9adi8aX7XK+QrE4l40m1gjZT2XQI4QbczkbT pQPKWXUjRdc9kUldOIj9QekYHUjSIVrSAGee2S+AAm5it+RGFszNAsb+6gTCLmDC Xmbhn0P/Mi6rRf1MaA3Pcym8kRUbFhK4yVueY805LbJ0AmALWXA2jkjg0laEa+Vw ==
X-ME-Proxy: <xmx:3oZ0WwPlPGda5cp_SXgsGGIune7I0WIMmjp5ETzDTykzK5hWW4lvTQ> <xmx:3oZ0WwoX_0BeHp3Wp4bVYzKzLj4WFdjuH9_WYqZEk6_HImP8HYa4tw> <xmx:3oZ0W2kM6cPPq-EzJK1tMCLNY4iK002D_snLykfqdmIpmU8-IeU_kg> <xmx:3oZ0Wwy9LVpoXukju0PgTcpKK6kAnWs34CT-VmBTD8bIEi0f71vjJw> <xmx:3oZ0W82aKon8OD96HdNS_IwxHKsea0rTSnNWOFUiJIGyS9p9LumJTQ> <xmx:34Z0W_5EgG4HTTcdqcfW61cy1gGzxZ_oBXVcf9KGv4ovgEtpYQ_c1Q>
X-ME-Sender: <xms:3oZ0WxHMwvvMk8IoX0my-uP1XEFkWWCV1_4O9x-61UCnuqaSXRixMA>
Received: from dhcp-10-150-9-145.cisco.com (unknown [173.38.117.87]) by mail.messagingengine.com (Postfix) with ESMTPA id 0B3D810261; Wed, 15 Aug 2018 16:02:37 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Alissa Cooper <alissa@cooperw.in>
In-Reply-To: <9BC9E9E6-1B18-4BA0-A8BF-CBA95954EBA2@deployingradius.com>
Date: Wed, 15 Aug 2018 16:02:36 -0400
Cc: Eric Rescorla <ekr@rtfm.com>, Winter Stefan <stefan.winter@restena.lu>, radext@ietf.org, IESG <iesg@ietf.org>, draft-ietf-radext-coa-proxy@ietf.org, radext-chairs@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <202C0FD8-8B63-4A14-92B9-299810EDAD19@cooperw.in>
References: <153435801941.3053.15907114318025420750.idtracker@ietfa.amsl.com> <926C796E-1339-488F-812C-27A003DF1D27@deployingradius.com> <CABcZeBNo=D21YhcAKXFp0abO4NGoGPiog1p-+GyW+g_4BYbTgg@mail.gmail.com> <9BC9E9E6-1B18-4BA0-A8BF-CBA95954EBA2@deployingradius.com>
To: Alan DeKok <aland@deployingradius.com>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/e6KeATzdvyIPS6ZI55pc8VDduCc>
Subject: Re: [radext] Alissa Cooper's No Objection on draft-ietf-radext-coa-proxy-06: (with COMMENT)
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext/>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Aug 2018 20:02:50 -0000


> On Aug 15, 2018, at 3:50 PM, Alan DeKok <aland@deployingradius.com> wrote:
> 
> On Aug 15, 2018, at 3:44 PM, Eric Rescorla <ekr@rtfm.com> wrote:
>> 
>> On Wed, Aug 15, 2018 at 12:25 PM, Alan DeKok <aland@deployingradius.com> wrote:
>> On Aug 15, 2018, at 2:33 PM, Alissa Cooper <alissa@cooperw.in> wrote:
>>> S 3.3.
>>> 
>>>>    The new Operator-NAS-Identifier attribute is defined as follows.
>>> 
>>> I suggest adding the depiction of the fields and their lengths in
>>> bytes, as is done in RFC 5580. I was a little confused about whether
>>> the fields in the attribute are just the TLV.
>> 
>>  There are no fields in the Operator-NAS-Identifier attribute.  it's just an opaque blob.
>> 
>> I believe what Alissa means is that it's variable length and therefore must be somehow delimited.
> 
>  The encapsulating RADIUS attribute header has a "Length" field.  That delimits the Operator-NAS-Identifier value.
> 
>  The value itself is (again) just an opaque blob.  The value can have any length, 1 to 32 octets.  There is no intrinsic meaning in any one octet of the value.

Acknowledging my limited recall of how RADIUS attributes are defined, I think what is tripping me up is the definition of the Length field, which says “4 to 23.” If I assume that length is measured in octets, that the type field requires 1 octet, that the length field requires 1 octet, and that the value can be between 1 and 32 octets long, I would conclude that valid length values would be between 3 and 34, not between 4 and 23. Can you clarify why not?

This is I guess the root of why I thought the octet diagram would help.

Alissa  

> 
>  There is no need for the *contents* of the attribute to have any delimitation whatsoever.
> 
>  Alan DeKok.
> 
>