Re: [regext] Warren Kumari's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)

"Hollenbeck, Scott" <shollenbeck@verisign.com> Tue, 31 July 2018 11:07 UTC

Return-Path: <shollenbeck@verisign.com>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A0C0130E6F; Tue, 31 Jul 2018 04:07:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=verisign.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RcrSEQeVyenF; Tue, 31 Jul 2018 04:07:56 -0700 (PDT)
Received: from mail4.verisign.com (mail4.verisign.com [69.58.187.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BBDCD130E03; Tue, 31 Jul 2018 04:07:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=verisign.com; l=5408; q=dns/txt; s=VRSN; t=1533035276; h=from:to:cc:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version:subject; bh=DvdeTWnVU0pieZsYlIyEcE/fK8FXTaLftiCg/mI8w8Y=; b=SrfzyAFRgT8R9cwiMAWH9YUUhRqnFPDOqksUmw5ijKJ12vbosTQX8oTg ngHtvM48ZznOxyweqE6IOLbqsSYe7mS39dLn59ckc7QgmpKsbFhY6hM12 drWS4X8gXu2ErAaZU6leFmzY3WM9vUzURZdql09tRzZLSD6f7bwYy8KwX We3BklvySHqH5I+UxuxNPNIHJiDLi+e8UZ4QkETsmAUdohKvHNlaIihAL easCbHyKg7RbbC795RVk+FkDk0YM/SMfOYfFvp2DabfuU3VMV5kbxuYMP B7oL8YDJgucx2FsO0MtXJUDkFbIY2RvXm/cS3nqUjQxCAZIdKD7qS/X+K w==;
X-IronPort-AV: E=Sophos;i="5.51,427,1526356800"; d="scan'208";a="5345857"
IronPort-PHdr: 9a23:i3JP8xIEaXzXCvUkmdmcpTZWNBhigK39O0sv0rFitYgXKPT7rarrMEGX3/hxlliBBdydt6oazbKO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZLebxlJiTanfb9+MAi9oBnMuMURnYZsMLs6xAHTontPdeRWxGdoKkyWkh3h+Mq+/4Nt/jpJtf45+MFOTav1f6IjTbxFFzsmKHw65NfqtRbYUwSC4GYXX3gMnRpJBwjF6wz6Xov0vyDnuOdxxDWWMMvrRr0vRz+s87lkRwPpiCcfNj427mfXitBrjKlGpB6tvgFzz5LIbI2QMvd1Y6HTcs4ARWdZXshfSTFPAp+yYYUMAeoOP+dYoJXyqVQBtha+GRKjBOHzxjNUmnP736s32PkhHwHc2wwgGsoDvHrWotXyMKcSVf66zK/Twjrdc/xW2i/x45XVfB89pvGMQa5wfcTMwkQoDAPFjlKQqYjhPzyL0OQCqHaU4PZjVe+0lW4otRtxojm0xscthYnJgJgZxUzD9SV82Ys4I8CzRkB8Yd6hCpRQtieaOpN3Qsw8X2Fotjw2yrocuZ60eiUB1ZcpxwbHZvCab4SE+A/vWeSfLDtimX5oeLyyiwy9/EWk0uHwS9W43ExXoidHjtXArG0B2hPQ58SdV/dw/V+t2TiR2A3Q9u1JJEU5mKjHJJI92LE9k4cfvljfESLzmEj5kbGZdksh9+Ws9uvof6vpq5mBPIFukA7+KL4hmsmnDOQ9NQgBQnaU9Pyn1L3m4U35WLJKjuAqkqXBsJDVO8AbpqmhDgJIzogt8wuzADe+3toXnHYLMExJdAiZj4f1PFHOOuj4Ae2ljFuxijtr2erGPqbnApnXMnfDl7Lhca58605a1gUz0chS649IBr0bPf7+WEH8uMbFAhI5PQG42enqBdFl2oMbQ22PA6uZMK3IsV+P4+IiO/KMZI8SuDb5L/gq+fjugmQnllABfqmkxoUXZ26iHvRnOEWZYHXsgtEbHWgWuQo+SfTmiEeeXj5Le3ayQ6U86yk1CY28F4fDXJ6igLqa0Se4A51WY3pJCkqNEXvycYWLResMYjqIIsB9ijwESaShS4g52BGvqgD60LVnI/HV+iIGqZLj2sJ55+rJlRE97TZ0FdiS03mRT2FomWMFXyI53Lplrkxz1lePyKl4jOJEFdxd/v9JSBk1NZHCwO11F9D+QxjBccqTR1a+W9mmBio+TtAvzNASf0ZxAsmigQrM3yexAr8aiaCLBJIu/qLbxXjxKN53y2za26k5k1kmXsxPOHW8hqFh+AjcGYHIk1mAm6m2daQTxi/N9H2YzWeVvUFXThJwUavfUXAYfEvWoszz5lneQL+2FbQnLgxBxNaYKqRUZd3mk1pHROv4NdTffW2xh2mwCQyPxrOWY4rgY38d0znFCEgYjwAT+m6LNRQ/BiekuW7REDxuFVXhYkPq6uR+qnK7TlQowA2QdUJuy6C5+gMWha/Ud/RGlP0bsT07pjNcH0u41sjXTdyNu0UrNPFDaMkn7VFv1n/cvhZ8eJqtM/YmzhRRcglssGvv2gl5TIJanodg5CcrwRF9AaOVzF0HcCmXi8PeILrSfyPS+xSrZqjc11rdlJ6t8aAT9L5w/07juwWtG0wo/n5k+8dYyXqH55rMSgEVVMSiAQ4M6xFmquSCMWEG7ITO2CgpaPHsvw==
X-IPAS-Result: A2GpAwAYQmBb/zGZrQpcGgEBAQEBAgEBAQEIAQEBAYQxgScKg3SWVYMuDpIvgWYLIwuEPgIXgyw4FAECAQEBAQEBAgEBAoEFDII1JAEOLxw9AQEBAQEBJwEBAQEBASMCRCwBAQEBAgEjETgNBQcEAgEIEQQBAQMCHwcCAgIwFQgIAgQBDQUIgxmBdxerWoEuikQFgQuIEIFCPoESgxKDGwIBAgGBKgESAQktgmqCVQKHd4oaiAQDBgKGFYkZgVCEHYJxhTeKU4dBAgQCBAUCFIFYgQNYEQhwgzmCTYhIhT5vAY1VgR+BGwEB
Received: from BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) by BRN1WNEX02.vcorp.ad.vrsn.com (10.173.153.49) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1466.3; Tue, 31 Jul 2018 07:07:51 -0400
Received: from BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde]) by BRN1WNEX02.vcorp.ad.vrsn.com ([fe80::7c0a:1cc:5def:9dde%4]) with mapi id 15.01.1466.003; Tue, 31 Jul 2018 07:07:51 -0400
From: "Hollenbeck, Scott" <shollenbeck@verisign.com>
To: "'warren@kumari.net'" <warren@kumari.net>, "'iesg@ietf.org'" <iesg@ietf.org>
CC: "'draft-ietf-regext-rdap-object-tag@ietf.org'" <draft-ietf-regext-rdap-object-tag@ietf.org>, "Gould, James" <jgould@verisign.com>, "'regext-chairs@ietf.org'" <regext-chairs@ietf.org>, "'regext@ietf.org'" <regext@ietf.org>, "'tim.chown@jisc.ac.uk'" <tim.chown@jisc.ac.uk>
Thread-Topic: [EXTERNAL] Warren Kumari's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)
Thread-Index: AQHUKCOAIp/mhYGj30asUVpuO3oz0qSpK3ZA
Date: Tue, 31 Jul 2018 11:07:51 +0000
Message-ID: <fd7b0f69e9c34ae685034b4a1957ecdd@verisign.com>
References: <153296860192.827.8824953027965906564.idtracker@ietfa.amsl.com>
In-Reply-To: <153296860192.827.8824953027965906564.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.170.148.18]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/cyfOR2o6gjextxudsNsCUIIHmSU>
Subject: Re: [regext] Warren Kumari's No Objection on draft-ietf-regext-rdap-object-tag-04: (with COMMENT)
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 Jul 2018 11:07:58 -0000

> -----Original Message-----
> From: Warren Kumari <warren@kumari.net>
> Sent: Monday, July 30, 2018 12:37 PM
> To: The IESG <iesg@ietf.org>
> Cc: draft-ietf-regext-rdap-object-tag@ietf.org; Gould, James
> <jgould@verisign.com>; regext-chairs@ietf.org; Gould, James
> <jgould@verisign.com>; regext@ietf.org; tim.chown@jisc.ac.uk
> Subject: [EXTERNAL] Warren Kumari's No Objection on draft-ietf-regext-
> rdap-object-tag-04: (with COMMENT)
>
> Warren Kumari has entered the following ballot position for
> draft-ietf-regext-rdap-object-tag-04: No Objection
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
>
> Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
>
>
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-regext-rdap-object-tag/
>
>
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> Thank you for writing this - it solves a useful purpose, and is clear and
> easy to read.
>
> I had 2 comments / questions - please also see Tim Chown'sOpsDir review
> for a useful nit.
>
> Section  2.  Object Naming Practice
> The entire 'HYPHEN-MINUS' selection makes me slightly twitchy - the
> argument that it was chosen because it is commonly already used as a
> separator feels like it cuts both ways - the fact that 'Handles can
> themselves contain HYPHEN-MINUS characters' already seems to argue that a
> different separator should have been chosen to minimize the chance of
> collisions / people getting this wrong.  I get that the document says "the
> service provider identifier is found following the last HYPHEN-MINUS
> character in the tagged identifier", and would feel more comfortable if
> some of the examples contained more than one hyphen to make this clearer.

Thanks for the review, Warren. We actually had quite a debate in the WG about the separator character (witness the change log). I could change one of the examples in Section 2 if that would be helpful.

> Section 7. Security Considerations
> 'The transport used to access the IANA registries can be more secure by
> using TLS [RFC5246], which IANA supports.' I'm confused by this sentence
> in the Security Considerations section - more secure than what, not using
> TLS? Why isn't this something like "The transport used to access the IANA
> registries SHOULD (or MUST) be over TLS"?

Benjamin also had a comment about this text. I proposed this change in my reply to him:

OLD:
This practice helps to ensure that end users will get RDAP data from an authoritative source using a bootstrap method to find authoritative RDAP servers, reducing the risk of sending queries to non-authoritative sources.
The method has the same security properties as the RDAP protocols themselves.
The transport used to access the IANA registries can be more secure by using TLS [RFC5246], which IANA supports.

NEW:
This practice uses IANA as a well-known, central trusted authority to provide the property of allowing users to get RDAP data from an authoritative source, reducing the risk of sending queries to non-authoritative sources and divulging query information to unintended parties.  Additional privacy protection can be gained by using TLS [RFC5246] to provide data confidentiality when retrieving registry information from IANA.

Better? I hesitate to say "The transport used to access the IANA registries SHOULD (or MUST) be over TLS" because that's not something the RDAP client controls - it's controlled by IANA's web server (which, in fact, is currently redirecting http connections to https).

Scott