Re: [regext] Opsdir last call review of draft-ietf-regext-unhandled-namespaces-07

"Gould, James" <jgould@verisign.com> Tue, 16 February 2021 13:56 UTC

Return-Path: <jgould@verisign.com>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A5A73A0CE9; Tue, 16 Feb 2021 05:56:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pkntvFQCw9Il; Tue, 16 Feb 2021 05:56:44 -0800 (PST)
Received: from mail5.verisign.com (mail5.verisign.com [69.58.187.31]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7C6793A0B93; Tue, 16 Feb 2021 05:56:43 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=14772; q=dns/txt; s=VRSN; t=1613483805; h=from:to:cc:date:message-id:content-id: content-transfer-encoding:mime-version:subject; bh=dKBcwfJ7sRJ+bxnkL+k23i3gGkmSvKnG3Va/7AaynwY=; b=p1NaRdMmfx/G4IHnmnAcdWMGjkGnLbF5eBk6tGuECy+LdSuTiusFq50F WlHCQVU/IE81PUfAA0IiTA19wT7uSmJMo1QJ1iTnajcAVXCtzg1owkvHw eG2S1MpDmfKQgBzagOBpNIm94QPgILhMeEKo9+m21pa2IOmRseGrjNmjI /8vVlqmzW3tMzwxYLyzvU1MYLx2Ic0dAHana2tx7mntpnuzo8Wadb+dTJ Vw9kMoAgImW5PbwLL+i1E5fXL105cVvX+DxfUyIGeS9uJGhLt8CALMGMt YLfqHdn5D6i/ZgxICK+O6DcxDO+wvkdPd5gcdyyavV2aSJsbEPlPn4FFw w==;
IronPort-SDR: lURdKvxq3AaZH86yAx9KK1epl5We6sei5Kd4Xg28UVOkPjCDDl827LFEbawPAd8uqyh5Yxmghv WgmU/GDJAA6dsb+GTBVBYKRQMLTCFPFhG5L7o/mP4K3cWgXWq+s0HICGJhotKE/PlVIYoSdzZg JL9MpHbBnYJSEH9o2yvIoIXWcSZAM3X8k5GYJEgcvKukoRJ/gAP7jYISTBBuQjitGAFK1IO28i 2uJIw5JbefJvxZUQXm5K+CDI6EPnpjQDlrGVu9kLFVS5bWxLFMSz2ftK/L+xhCO8uCGCV5AdRk C5I=
X-IronPort-AV: E=Sophos;i="5.81,183,1610427600"; d="scan'208";a="5118255"
Received: from BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) by BRN1WNEX01.vcorp.ad.vrsn.com (10.173.153.48) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2176.2; Tue, 16 Feb 2021 08:56:41 -0500
Received: from BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d]) by BRN1WNEX01.vcorp.ad.vrsn.com ([fe80::a89b:32d6:b967:337d%4]) with mapi id 15.01.2176.002; Tue, 16 Feb 2021 08:56:41 -0500
From: "Gould, James" <jgould@verisign.com>
To: "bill.wu@huawei.com" <bill.wu@huawei.com>, "ops-dir@ietf.org" <ops-dir@ietf.org>
CC: "draft-ietf-regext-unhandled-namespaces.all@ietf.org" <draft-ietf-regext-unhandled-namespaces.all@ietf.org>, "last-call@ietf.org" <last-call@ietf.org>, "regext@ietf.org" <regext@ietf.org>
Thread-Topic: [EXTERNAL] RE: Opsdir last call review of draft-ietf-regext-unhandled-namespaces-07
Thread-Index: AQHXBGuN5OxgMZU9Q0qMVWSKloDIfg==
Date: Tue, 16 Feb 2021 13:56:41 +0000
Message-ID: <F71FEDDE-07F8-4031-BB12-0BC196208F83@verisign.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.41.20091302
x-originating-ip: [10.170.148.18]
Content-Type: text/plain; charset="utf-8"
Content-ID: <9903AFB95670B743A6778908CD00D56E@verisign.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/aN7ODf7YB1q3zyzopFzsUJjI_vg>
Subject: Re: [regext] Opsdir last call review of draft-ietf-regext-unhandled-namespaces-07
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 16 Feb 2021 13:56:46 -0000

Qin,

My responses are included below.

-- 
 
JG



James Gould
Fellow Engineer
jgould@Verisign.com <applewebdata://13890C55-AAE8-4BF3-A6CE-B4BA42740803/jgould@Verisign.com>

703-948-3271
12061 Bluemont Way
Reston, VA 20190

Verisign.com <http://verisigninc.com/>

On 2/14/21, 10:03 PM, "Qin Wu" <bill.wu@huawei.com> wrote:

    Caution: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. 

    Hi, James:
    -----邮件原件-----
    发件人: Gould, James [mailto:jgould@verisign.com] 
    发送时间: 2021年2月8日 22:42
    收件人: Qin Wu <bill.wu@huawei.com>; ops-dir@ietf.org
    抄送: draft-ietf-regext-unhandled-namespaces.all@ietf.org; last-call@ietf.org; regext@ietf.org
    主题: Re: Opsdir last call review of draft-ietf-regext-unhandled-namespaces-07

    Qin,

    Thank you for your review and feedback.  I provide responses to your feedback below.  Let me know if you have any additional questions or feedback.

    Thanks,

    -- 

    JG



    James Gould
    Fellow Engineer
    jgould@Verisign.com <applewebdata://13890C55-AAE8-4BF3-A6CE-B4BA42740803/jgould@Verisign.com>

    703-948-3271
    12061 Bluemont Way
    Reston, VA 20190

    Verisign.com <http://secure-web.cisco.com/19TSnduBY1Wx59Dbgu-4L-lLfR4DP-BSCDN2JzSzzgd7LJ7CwfZS8WNBlJfV1LnJ2zfz9ppArvyM2ZbvGYUy6C7s7l4KFbibH2ZrAIEtp7Ja59jeObV2DCOCLRMT2Eh8eLg6V6v_0Inh747hYsZ4CVYB0GeCJuLPhSC7Uk_h5q23npGJpL5CNG2ncnLYX9ZGzbppm-E7IKnEbN1zldrT6sBV9yMek3oJyglwZRvqcanA0i9eHYqpZKIdVMmj1mRym/http%3A%2F%2Fverisigninc.com%2F>

    On 2/6/21, 6:58 AM, "Qin Wu via Datatracker" <noreply@ietf.org> wrote:

        Reviewer: Qin Wu
        Review result: Has Issues

        I have reviewed this document as part of the Operational directorate's ongoing
        effort to review all IETF documents being processed by the IESG.  These
        comments were written with the intent of improving the operational aspects of
        the IETF drafts. Comments that are not addressed in last call may be included
        in AD reviews during the IESG review.  Document editors and WG chairs should
        treat these comments just like any other last call comments.

        This document defines Extensible Provison Protocol (EPP) extension for
        unhandled namespace information conveyed to the client. It allows the server
        return unhandled namespace information that the client can process later. 
        I think this document is well documented, however I do have a few questions for
        clarification. 

        Major issue: Not found 
        Minor issues:

     1.Section 1: I am not sure how unhandled namespace information exchanging between the client and the
        service is compliant with the negotiated services defined in [RFC5730]. Why
        error response is not best choice to return this unhandled namespace
        information for later handling.

    JG - Very good question. The first part of your question is associated with how the unhandled namespace information is returned back, which make it compliant with the negotiated services defined in RFC 5730.  The unhandled namespace information is returned in element (e.g., <extValue> <value> element) that is not processed by the XML parser so it won't cause a client-side XML parser error and is not located in a portion of the response (e.g., under <resData> for an object-level extension or under <extension> for a command-response extension) that would be a compliance issue with the RFC 5730 negotiated services.  For the second part of your question, why not return an error response, we need to look at the use case that raised this issue in the first place.  EPP includes a poll queue in RFC 5730 that enables the server to insert notifications (poll messages) for asynchronous consumption by the client using an ordered queue.  The poll queue is dequeued by the client one message at a time by receiving the message and acknowledging the receipt of the message with the server.  While working on the Change Poll Extension (https://secure-web.cisco.com/1SIHw-7FotJrwbBHXf3RV0YV-QaI5RQTW8RnWsxWnYy4S0KHvO2g9m0MbEa2b6jJ6ssJzUQWhxJWHOg0vieTXz-_Yju04yCXxN5rb7VpXiP-pw2nvjyy7J6naFF8qDeeNQuTr5SZ76U_f4nKPjrRCfeidamHqgEAy8x861LwvHw32BGjf-OU1qriPrqWQIs52dyM1aMz_a5Gr-b_IBjYT69mgkaPEL73ydjw63rEPVJhz-HV5QDhFU-8HhIxjnyn-/https%3A%2F%2Ftools.ietf.org%2Fhtml%2Frfc8590), the question came up what occurs if the new poll message is in the queue, but the client does not support it?  If the lack of client support resulted in an error, the change poll message would represent a poison message that would halt the consumption of the poll queue messages.  Returning the message without consideration of the client services is a compliance issue and returning an error would result in a poison message, which was the driver to come up with a solution.  The EPP protocol already provided a mechanism to return XML information that is not processed by the XML parser, which enabled returning the poll message with the XML information and a signal that a service is not supported by the client that solved the compliance and the poison message issue.  This approach could also be used to optionally return the information and the unsupported service signal in general EPP responses.  The working group did discuss other options, such as changing the order of the messages in the queue, but the unhandled namespace approach was the simplest and most effective approach discussed to solve the problem.

    [Qin]: Good clarification, would it be great to add some explanation text in the introduction section, motivation part.

JG - In re-reviewing the introduction, one motivation that could be expanded is poison poll message.  There is already a reference to poll messages in the introduction, so how about adding the second sentence below after the existing first sentence.  This would be included in draft-ietf-regext-unhandled-namespaces-08 that would be posted after addressing all of the feedback.  

An unhandled namespace is a significant issue for the processing of [RFC5730] poll messages, since poll messages are inserted by the server prior to knowing the supported client services, and the client needs to be capable of processing all poll messages.  
Returning an unhandled namespace poll message is not compliant with the negotiated services defined in [RFC5730] and returning an error makes the unhandled namespace poll message a poison message by halting the processing of the poll queue.

        2. Section 3.1/Section 3.2
        For Unhandled Object-Level Extension in section 3.1 and Unhandled
        Command-Response Extension in section 3.2, I see Template unhandled namespace
        response example for an unsupported command-response extension is same as
        Template unhandled namespace response example for an unsupported object-level
        extension, which make me confused, I am wondering how do we distinguish
        Unhandled Object-Level Extension from Unhandled Command-Response Extension in
        the XML snippet example. Can you clarify this?

    JG - The most important signal is that the client lacks support for a particular service defined by the namespace URI, whether it be for a unsupported object-level extension or an unsupported command-response extension.  A client can leverage the referenced NAMESPACE-URI to map up to the type of service defined in the EPP Greeting of the server.  All of the object-level extension namespace URIs are identified using an <objURI> element in the EPP Greeting and all of the command-response extension namespace URIs are identified using a <extURI> element in the EPP Greeting.  

    [Qin]: Okay, I understand now.

        3. When we say converting from an object response to a general EPP response by
        the server, does it mean the [NAMESPACE-XML] variable should be replaced by the
        object-level extension XML. Where these [NAMESPACE-XML] variable are stored in
        the server? Do we need to maintain the mapping between [NAMESPACE-XML] variable
        and object-level extension XML? Can you clarify this?

    JG - What's meant by that is an object-level EPP response includes a <resData> element containing the object-level extension XML referenced by [NAMESPACE-XML].  The object-level extension XML referenced by [NAMESPACE-XML] is moved under a <extValue> <value> element, which is not processed by the XML parser, and the <resData> element is removed from the response.  From the client perspective the response will not look like an object-level extension response, but simply as a general EPP response.  Take a look at how the transfer query response is formatted in RFC 5731 (https://secure-web.cisco.com/1V8PNcRAkxe9s2CjPCSqXPzxtPEbMsuxzzv8dOoYwPqeNI0EJIJnK8bHmmsUm6x7O5-bAFGMIJbENW0O1frUU5XSmVQpFnRrq1Wfz6XRco_lhHmauB3iRe911EFG1R0P-qwexNP5MiJCoukjisryLKbZFSXU9eiD39YZziCizBVR-UqBQCmF7XMJfMOoIHEmhp_XDPus1g46yYE9lDpoUVieNE_OjjRIqH8tNp6MeQJ6mFyqeO32iK59cYhd2Y7XS/https%3A%2F%2Ftools.ietf.org%2Fhtml%2Frfc5731%23section-3.1.3 ) and how it's converted in the example of section 3.1 (https://secure-web.cisco.com/1LfjiyJsyZr_d2LgJ5ZV9bICDS7ouIsBchsRaeWkr5VstuWi4Cx4D08i8KHYsuFM7mMePg579CXJZM2fVTvSUzhhjrDmWnCu9IlmRbLuPZbeMOhJax6Ipf4FeYsg_eQWxhKh8Bmus9OmSSdqeQthoN9Y8BMbDn1beJpYxTOJNz0K_yEYZSyQsY3lgYBwT7I1X3B6rq6UrKhSzOQ5bfzia33O6-DQurpj1Uwqe4ntGWvJlkgdASFpKkaIJECEnUTfV/https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-ietf-regext-unhandled-namespaces-07%23section-3.1).  The <domain:trnData> element is moved from under the <resData> element to under a <extValue> <value> element and the <resData> element is removed.        

    [Qin]: I understand that, I feel you didn't answer my last question? Where the mapping between [NAMESPACE-XML] variable and object-level extension XML is maintained? In the server side or in the client side? Otherwise, it is not clear to me how [NAMSPACE-XML] included in the wrapper <resdata></resdata> is replaced with [NAMSPACE-XML] wrapped in <extvalue><value></value></extvalue>, who does that? Client or Server, probably it should be the server.
    Or there is no [NAMESPACE-XML] variable existed in the real implementation, it is just alias name for something we want to carry in the response with unhandled namespace?

JG - The [NAMESPACE-XML] is defined as " XML content associated with a login service namespace URI.  An example is the <domain:infData> element content in [RFC5731]." In section 1.1.  It a variable to refer to the block of XML that is moved by the server when creating the response based on the login services provided by the client.