[regext] RDAP versioning draft feedback
Jasdip Singh <jasdips@arin.net> Fri, 01 November 2024 18:27 UTC
Return-Path: <jasdips@arin.net>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C883FC14F6BA for <regext@ietfa.amsl.com>; Fri, 1 Nov 2024 11:27:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=arin365.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3dziIcjR7zdF for <regext@ietfa.amsl.com>; Fri, 1 Nov 2024 11:27:53 -0700 (PDT)
Received: from smtp3.arin.net (smtp3.arin.net [IPv6:2001:500:4:201::53]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8526C14F6B8 for <regext@ietf.org>; Fri, 1 Nov 2024 11:27:52 -0700 (PDT)
Received: from CAS01CHA.corp.arin.net (cas01cha.corp.arin.net [10.1.30.62]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by smtp3.arin.net (Postfix) with ESMTPS id 95646107519A for <regext@ietf.org>; Fri, 1 Nov 2024 14:27:51 -0400 (EDT)
Received: from EOR2201CHA.corp.arin.net (10.1.30.49) by CAS01CHA.corp.arin.net (10.1.30.62) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Fri, 1 Nov 2024 14:27:50 -0400
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (192.136.136.37) by EOR2201CHA.corp.arin.net (10.1.30.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.12 via Frontend Transport; Fri, 1 Nov 2024 14:27:51 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=dKxrVpRu2ZicbJwM+wE8hdSI/dYaFl61HS9cjgIHidUxEaCYmIxTXqzqRwUrQwmyzdLdSToxJ2pJPApMWwPaqnoXLWvI2/p9MwkEqqxTINF9qMjLxXkTkR9m1CzAsx1dZmlWvONsV4KrqjbOr7CfKZnZUc9ybyotzhz5Bj5bKR0DrloNGs5alEx5DX+1O22tYqKNfdT7LdAnTBGw/u+8hFTCLQZSOLhgB53xqqIETwLTrcBzBBjWAVHxpcD3EdVqoOSAZXHP8oyoeekoZ5X7t8r4HYm+m1VnyQH4Gi39TOdgcDLZgWpjenMt2giq0XEIbiPyPbconl6EgG+oFCkEKQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=hecPregL+Zb9OPGAhErEns3x5VjCYgXvaiYbSwpoM5c=; b=q2FtyPssVbdQV8citQxm2vtyLwRQl+a4PR4EJ0wPAw0s4v/YFErvz9JZfTC6/QcgB0pLq5uJnV7Vr31+rOlBlSxSdnWLNl7RGfpM7WtiRheJQ6hNlHSCrIsgagcLP6MMtgbVYT7zJEROZO6Rm3uz7NPqUkUHWzezXgyorlbV5vaLd47z/iEVe7obidjlWNEx0tucrWZYJlTa+welVQjmC5qSrJMTNkAjtRgYthpjFU6MdbJCiLTkGXNyuvETCqDflkjYdSyGNAWEhBVEbNqyP8WubvNeSB60QgdNpcRo0gzwrfU9tyNxssVPh118ke+sQFVMBcQPeG1E6WVZicCT9A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=arin.net; dmarc=pass action=none header.from=arin.net; dkim=pass header.d=arin.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=arin365.onmicrosoft.com; s=selector1-arin365-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=hecPregL+Zb9OPGAhErEns3x5VjCYgXvaiYbSwpoM5c=; b=xD59ojyq8T1E5k0X7mclg3/ZwV0KDJ/aTLLpe1zNIGAgYbWO7Bu42TtYOlm/cfgXqAeTK6CKimsDugjkBWgRhb6V7a0YNSOPC7zyP85BMyTFU/ZQfY/DGSy5Bt7Ct0kK6bdoYYaj+6J5TnNm5+Pf7lEibcZseog4sU1FIN3mZmvUjO5Ao255JiZx9/vP0QDY3T29prFSk/N5OQGbZcJjZqicyFHclJ31pjjeGqoH/KAhYZHNjOScMSTVcP7VFhESf6O7tm12XV4+mKLm2PXaQg0DSmHfefovClDPhAIRwV843tYcxcyeuC4xMLYmk2XcpQkZWhDAcSHtHkUM7Gfm4A==
Received: from PH7PR15MB6084.namprd15.prod.outlook.com (2603:10b6:510:24f::12) by DM4PR15MB6009.namprd15.prod.outlook.com (2603:10b6:8:17f::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8093.32; Fri, 1 Nov 2024 18:27:46 +0000
Received: from PH7PR15MB6084.namprd15.prod.outlook.com ([fe80::50c9:ce00:f231:376e]) by PH7PR15MB6084.namprd15.prod.outlook.com ([fe80::50c9:ce00:f231:376e%4]) with mapi id 15.20.8114.020; Fri, 1 Nov 2024 18:27:46 +0000
From: Jasdip Singh <jasdips@arin.net>
To: "regext@ietf.org" <regext@ietf.org>
Thread-Topic: RDAP versioning draft feedback
Thread-Index: AQHbLH4KqtVDpTIcA0y/5N9792kKBQ==
Date: Fri, 01 Nov 2024 18:27:46 +0000
Message-ID: <PH7PR15MB60841D6CCB6ACA5E9004AEFCC9562@PH7PR15MB6084.namprd15.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-reactions: allow
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=arin.net;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH7PR15MB6084:EE_|DM4PR15MB6009:EE_
x-ms-office365-filtering-correlation-id: aa3cac5c-e813-4de3-00cb-08dcfaa2e213
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|376014|366016|8096899003|38070700018;
x-microsoft-antispam-message-info: cOEu4+vjqi79FrVZbs/6l2pjFuTqrNbN0SuK8OScYEoJdGtYrufTuMg7JsyHI4AYyLCxGclwXLF1z+sLgJewTSL22XEzfCeXRuapYboxhVkzHRUHcjyoItOaIMusWemW236HsIAnvnwWN8KKLDM7ziBDM3aT/ZqMd4M8rCkt1nl9lwnUaHdOT39h3+ohfIq2ql1QFlljFAt3X827zbXzPhyTaWsQNmvYXkCNSMLAoaT1aUpHLrC8z7R5ZvPs+nKgk+QtT9+lZbh5m5laplI1dY+bWfuR2hczJFBzOlACrIsmX9mHbc4taY4Y6RSreHm24a3MwSOTsIrNDqh20cCEPHy5tw/RKuk3/KXX+9T1kld5O9YhUFsWJd1Ti9K/wfcDcOUgDXQJbolNXitCCGqIgElC4ZwSXxNhz11mi5mKvdo8DzSLWxihdei4TU5jYS9oCB86eYx/iK5uqxPAgwWffRKhNDoPWfiGF33vhWfGhiKO6HBdmKYamIpSHpArfN4q/aBCsMR2LlhYijb+Y8gvurU0luLfd9UuHij/LYzAy1aNds2Xrl7PrDsJZaJDz0Tgrm7pkMgnjUD+bfNpkijQ/nOoLTcbpPjKIu2DrO7UEKDJth61NmbfSAZiZSMG65voth/0vNPVOM9vB5215bD0tnZ41EyzK859eo2dKwB7SUE9PcK1hvNvrVruzZPGnYK7O1ClCCO0jMmv2k8a7mfa9scGVh5ff/KcQPWpeH7tk3zgqy5phTis2mn2bUZi/7+P4y56OtgCGkJhUQuCrABM9UL2YQLjH1+vE/1YUEXJvekQtu2U9gP+k2kvl3WloqVOvPAOAPUo03WHj6PRtQSvr3WBBEkdujX16lgwRWSjrww1NI78sNuooCyUIBjl2Qub6XkDtDB4QieTftN7Cx1EuDWf/6lAc6c54qLNzjWzsLO8QkVpK61IfWfWmDFMtRVG+/5qA5WSCfiRUg7sWgCDBTy1CeB4iz9jJebzWwmxnCRqZaGnh9Hp0wotw63QBU3TQVCch8ZWohJNa4wAF1cW1z7AZmFPegKzVisvs6RJw+lEJPXsSbzc0JP+x1u9d4AEb5H/UQbUIvwsO0+DDsI8RAwYZzee6cWxtoVf4r/fZi7Yj7ZF+1GGO+Y/BACySxp5m4sYL70t5UYE2j52f8YCdQTVQWlSGtkp6DOhYS4ITzIYGI6tSMgl6VTiFjKzVUfGP1hprWl56A2Z/tnd1VlTCWNWEjzqZwf3Jon7E0vJcbfbMkA4XcK2s4q6xn2Uxqz2H1TTFD67GyGzsxy599DVohQbPYeKJF4udG4ftFU1kBvSc81zNJM1hdbEr9l0L/jpcAqrmx+yUo/UtCVJQsbNzex0nKAKeIgtuIZO82UnIaQ=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PH7PR15MB6084.namprd15.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(376014)(366016)(8096899003)(38070700018);DIR:OUT;SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: LzPcISjYrHV+55YQqxXQS8F06RAWtJ5n9hSTzfgkpKvhBfHCeY+A2fzaEUS1pf8exr2u5MHpXvQLagt8kF1ucUzjugYZqWvr5tFtzt2ByRg+F6fqfm4c1yYCN+jYIOvPydkraKsu2/Fiq6w4m0vzMXewNSf7I0Yy9vsQcTG0EF5B3Xx/J1BbTsBpjpqgPX7KOqjcvmoTc1/eUHPI7ZJRcUGQECBK8XKsYPSHYAbu+Od/L1HEZKTO+yUhjjTjZ0YzPCZntN//hu7l2aKKEMnCRh6FWI/bnCiJ/EehH3RouJDyC0IJSHe6BP5ekHdfWk1Yx5JMPDUB6eZnHAJ+h0+jOFTinxWjUT9PDwa3nVVEyCEBQ0m9XZHxssjojh9DDg5VafY9+hNWE9TObcetKlxP3wb11puX72EYr5i5sLUcOjkLQfoIdzsFCtwvU1RZb4bFoW5Ugig6UxqbpKiz4FxqAbFI+GwfLb6FuIeAf6ILmG8A//Jh6eVcKYY1bus1E2ajvT5XWhNMJS2Pwbnv6BVRiO5mKMgTG9ZqB/zQT0BXBxX6z3yzGPGEFddf3jzAHAc/8i1BVxhZ5tLkDLGttSK1tYaNwoa/rLgci1rOe7PJG0IEqZ9WfbjczBMAdLKHip0AWqmf9Us0yqU7o/9rPAnJvdA+zTF0W0/5xg+yrvruhVue/oeGglDP3A3k7wVgFmlFGrFseh0ajL3DB050MzDTdzgYGjiJLoKqdv6S72mcTdytJW7t2yNO5tmI5vlGJOl0trhRmFkmsQKPMdOgkV0tS/uKsDaY53ZbF7GbnmyEHYLGqhjxTRxlib2GEaM2Ycp2a7UVy6eUbsnilEHQTmV0j54OQbM5ScJSDmsdMlJ19kkusXT05AnhwhC4pBDv4mWA0Z+tT1NCXvEmklIH9qUxeD9UdUPncgRsG2dBsOie+2OCYV6h6BH6oIwx1xELRBt1+6R9h6HAljlUFvRQkUrwV4N9y41nuH28TXHbdUcjDCC4kV9j2yPFSxUS/X08KfpofHzDH+eZQF6SB640qwl2R78dQKgUCDqJMOMAnFg57+nRtBHdYMT77f+RWYJQDtLkpxSXe9HszvzQaa6H1ILTV1vHfK4+Ulfgny7MleAqALBa6LWTCEyH1GN66eC6z0V3YRTmI/M8kp6HYdddgaeamnZK5S+nwuqR2b3dMyfw/o9Y1IqLQFIFHW6xB0K378iH9gxfWkilvidZ7naR2li6TGUSKny/LJZ5BzyL8+wo3B7lmhcr6zxd0OT4pGiCX/LPAogcox8R/F6+p/lkOmlIkTEb+FUou6/ezTOHmELlcx1CJKXsuCLAftazR3nWr5zoVxsSpko5qFcyMYp0B3VNfTIFuxmw78WApGR/lfub6UsexDIqfXvWkblrdUR3gilfwbrXBqJUBfDeO4JD/9It37oT3Ctj4zcVTeD0/bghzoMS68eSvdUoy4p3/HkDw0KmJ4AZZ0K9ZzrrECfpcX+FnFDKgaG1YDu+ALlCC4UgYFbruUyK35ZJ31WSy6oDpPnGT1n4bcn4IdWB6e7iZRx4wKOHOEXx4v1k7H+0T4+7pd3HIctP+C7SOsz+WflDNRqQH2CHIxWc0pQ33fnX2tJFkA==
Content-Type: multipart/alternative; boundary="_000_PH7PR15MB60841D6CCB6ACA5E9004AEFCC9562PH7PR15MB6084namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH7PR15MB6084.namprd15.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: aa3cac5c-e813-4de3-00cb-08dcfaa2e213
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Nov 2024 18:27:46.4178 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: cad70df5-eb75-43b7-adb3-12798d38d9b7
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: I/atuDjaXJmjbIBcayywU0FxkubBxkY8Ie2v2r/iOMa8myPRuDt4D/MQ0M0y/qFHa4G4B1+fQicWwe+5TQhPiQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR15MB6009
X-OriginatorOrg: arin.net
Message-ID-Hash: NDZMUKXVCD22F3AVKUDO6BD4PNFPNOC2
X-Message-ID-Hash: NDZMUKXVCD22F3AVKUDO6BD4PNFPNOC2
X-MailFrom: jasdips@arin.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-regext.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [regext] RDAP versioning draft feedback
List-Id: Registration Protocols Extensions Working Group <regext.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/Jm3v_QchB_ItIfZM-tK8JVPRciM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Owner: <mailto:regext-owner@ietf.org>
List-Post: <mailto:regext@ietf.org>
List-Subscribe: <mailto:regext-join@ietf.org>
List-Unsubscribe: <mailto:regext-leave@ietf.org>
Hi James, Daniel, Mario, I read the latest draft and to help tighten this spec, have few higher-level comments. VCHAR use: In section 3.1, the ABNF for “versioning” in “extension-version-identifier” is “["-" 1*VCHAR]”. Since the extension version identifiers could be passed in the “extensions” parameter of the RDAP-X media type in the HTTP accept and/or content-type headers, it would be safer to constrict them to what’s allowed in those headers. E.g., for the accept header, a parameter value (per section 5.6.6 of RFC 9110) is “parameter-value = ( token / quoted-string )” where “token” is any VCHAR minus the delimiters (section 5.6.2 of RFC 9110). The reason AFAIU is to help prevent injection attacks. From security angle, good to address this. Rationale for versioning: Section 1 says, “The RDAP Conformance values are identifiers with no standard mechanism to support structured, machine-parseable version signaling by the server.” It’d be good to elaborate with usage scenarios where such structured versioning is a value-add for clients beyond what the opaque (no inner meaning) extension identifiers from STD 95 afford. Let’s say an extension is “foo1”, then “foo99”, and later “foo2” in terms of “versions”. The server announces its support for these non-structured extensions, say, on its web site or through the “rdapConformance” member in a /help response, and the clients can then negotiate a particular non-structured version of this extension using the standard HTTP content negotiation methodology (e.g., using the RDAP-X media type). In the spirit of what-not-to-do, it is fair for a client to ask: Why should I go through the overhead of processing the “versioning_help” member? What value-add does it get me? Is it in some way a better discovery and/or negotiation method for RDAP extensions? Would be good to beef up the rationale for structured versioning. RDAP-X way: To help client implementors, beside the “versioning” query parameter examples, would be good to include one or more RDAP-X examples. /help path segment: Section 3.1.6 of RFC 9082 says, “The help path segment can be used to request helpful information (command syntax, terms of service, privacy policy, rate-limiting policy, supported authentication methods, supported extensions, technical support contact, etc.) from an RDAP server.” Using a new “versioning” query parameter for /help, is this spec updating RFC 9082? Not sure but thought of asking. Further, beside the “versioning” extension version identifier itself, are any other extension version identifiers allowed in the “versioning” query parameter for /help? If not, good to clarify that. Caution with using “versioning” query parameter in non-help path segments: It would be good to beef up the security and privacy considerations for the risks with using “versioning” query parameters in non-help path segments vis-à-vis RDAP redirects and referrals, as the Extensions draft cautions. Thanks, Jasdip
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback Mario Loffredo
- [regext] RDAP versioning draft feedback Jasdip Singh
- [regext] Re: RDAP versioning draft feedback kowalik
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback Jasdip Singh
- [regext] Re: RDAP versioning draft feedback Mario Loffredo
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback Gould, James
- [regext] Re: RDAP versioning draft feedback kowalik@denic.de
- [regext] Re: RDAP versioning draft feedback Gould, James