Re: [radext] Extended IDs

Peter Deacon <peterd@iea-software.com> Wed, 13 December 2017 05:58 UTC

Return-Path: <peterd@iea-software.com>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C25AD126DFE for <radext@ietfa.amsl.com>; Tue, 12 Dec 2017 21:58:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Nfx7qBVcvrzm for <radext@ietfa.amsl.com>; Tue, 12 Dec 2017 21:58:47 -0800 (PST)
Received: from aspen.iea-software.com (www.iea-software.com [70.89.142.193]) by ietfa.amsl.com (Postfix) with ESMTP id 67122124BE8 for <radext@ietf.org>; Tue, 12 Dec 2017 21:58:47 -0800 (PST)
Received: from smurf (unverified [10.0.3.195]) by aspen.iea-software.com (Rockliffe SMTPRA 7.0.6) with ESMTP id <B0006062049@aspen.iea-software.com>; Tue, 12 Dec 2017 21:58:47 -0800
Date: Tue, 12 Dec 2017 21:58:50 -0800
From: Peter Deacon <peterd@iea-software.com>
To: "Naiming Shen (naiming)" <naiming@cisco.com>
cc: "radext@ietf.org" <radext@ietf.org>
In-Reply-To: <313FEFCE-FD61-4394-804D-91BAE98CA687@cisco.com>
Message-ID: <alpine.WNT.2.21.1.1712121947300.2252@smurf>
References: <fef698a5-9802-c9be-04d7-1e869651c988@restena.lu> <dfd0ff02-c9e8-7253-4fb4-1e6def3e93b2@restena.lu> <933E6F70-A7C1-4168-9AC9-F925EF78D9E2@jisc.ac.uk> <AE2036D0-1294-45B5-A0D7-16F91E0B4248@cisco.com> <alpine.WNT.2.21.1.1712121615090.2252@smurf> <EE3BB1A7-EAD9-4BE1-9EA2-B780580E5C95@cisco.com> <alpine.WNT.2.21.1.1712121704430.2252@smurf> <B41EF4CD-309C-4E0F-BE7A-B77A244DA421@cisco.com> <alpine.WNT.2.21.1.1712121824110.2252@smurf> <313FEFCE-FD61-4394-804D-91BAE98CA687@cisco.com>
User-Agent: Alpine 2.21.1 (WNT 202 2017-01-01)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/radext/fqekmwOJBhWRP_4B3iNrxWSP614>
Subject: Re: [radext] Extended IDs
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext/>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Dec 2017 05:58:48 -0000

On Wed, 13 Dec 2017, Naiming Shen (naiming) wrote:

> If you insist misconfiguration is the greatest thing we have to deal with,

Decision to expand on original remarks in response to call for adoption 
was result of your inquiry:

"Third, if assume an operation completely messed up, and leaking this 
extended-ID towards the home-server, I still need to see a good example on 
what the harm is that, and why this can not be debugged. The draft I agree 
needs to add some text on various cases and how to debug those in each of 
them."

Otherwise I am happy with the relative strength of my remarks in their 
original context.

> then I can imagine you misconfigurae your server ip address and proxy ip address,
> and packets will not be returned, how to you troubleshoot that? if you do

If when manually switched on in an environment where it should not be the 
result is not working at all that would be perfectly fine.  Unfortunatly 
as I have shown this is not the case with extended-id.

In this aspect of consideration ORA clearly has an advantage both in 
ability to detect and report failure and nature of failure itself.

> have ways, and this draft also have ways. Can you imaging an operator
> insist to do a manual configuration without check the status of the server,

Yes absolutely.  This will defiantly occur.  Status-server is not 
universally supported.

regards,
Peter