Re: [Roll] Reviews request for draft-ietf-roll-enrollment-priority

"Pascal Thubert (pthubert)" <pthubert@cisco.com> Mon, 25 January 2021 14:23 UTC

Return-Path: <pthubert@cisco.com>
X-Original-To: roll@ietfa.amsl.com
Delivered-To: roll@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 104213A13B0; Mon, 25 Jan 2021 06:23:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.718
X-Spam-Level:
X-Spam-Status: No, score=-7.718 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=SMrdsrY4; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=HfseTILi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JNIuYvGrqv1r; Mon, 25 Jan 2021 06:23:50 -0800 (PST)
Received: from rcdn-iport-1.cisco.com (rcdn-iport-1.cisco.com [173.37.86.72]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9E7143A13AF; Mon, 25 Jan 2021 06:23:46 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=23232; q=dns/txt; s=iport; t=1611584626; x=1612794226; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=FZHVydUKdIiCEsFXYjI8wgOAu9uDI+3tLFtCL82xH3I=; b=SMrdsrY40K9Glx3Ly55bFdPIP1Re9A5fEavyT7FJQzr+OyoX+Ki3Fj+0 WgNqaHhQ6njIzoCm8JXK/b3NEhjxZb323Q/8cJR0fPa4PB1pLoF0A3WlN 6NdB0WYFz2aBjVufddQ3xjkX5R23qqi8hgVue6jyDCtMvvJVb5s9pEXBG o=;
IronPort-PHdr: 9a23:mrYuoRS5yVa2LVCj4XR4zpinCdpsv++ubAcI9poqja5Pea2//pPkeVbS/uhpkESQBN+J6v9YhazRqa+zEWAD4JPUtncEfdQMUhIekswZkkQmB9LNEkz0KvPmLklYVMRPXVNo5Te3ZE5SHsutZlDOrDu19zFBUhn6PBB+c+LyHIOahs+r1ue0rpvUZQgAhDe0bb5oahusqgCEvcgNiowkIaE0mRY=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CzBgA20w5g/5JdJa1iHAEBAQEBAQcBARIBAQQEAQGCD4EjMCkoB3ZbLy+EQINIA44NA5kXgUKBEQNUCwEBAQ0BAScGAgQBAYMVgTUCF4FhAiU4EwIDAQELAQEFAQEBAgEGBHGFYQELhXMBAQEEIwoTAQE3AQ8CAQYCEQQBASsCAgIwHQgCBA4FCIMfgX5XAy4BDpZkkGsCiiV2gTKDBQEBBoFHQYMZGIISAwaBOIJ3hAQBhBuCJyYbgUE/gRFDUYIFPmsZAYFYAQECAQGBITwrgmw0giyCQilBBFECBAWBVDYSBZNBhzUrjBGRPwqCd4kwgiaHVohlgyuKNJUZhHePJ4sfkWkYhDYCBAIEBQIOAQEGgW0jgVdwFYMkUBcCDY1+I4ElAQcIB4I1hRSFRHQCCyoCBgEJAQEDCXyLGQEB
X-IronPort-AV: E=Sophos;i="5.79,373,1602547200"; d="scan'208,217";a="845303719"
Received: from rcdn-core-10.cisco.com ([173.37.93.146]) by rcdn-iport-1.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 25 Jan 2021 14:23:05 +0000
Received: from XCH-RCD-002.cisco.com (xch-rcd-002.cisco.com [173.37.102.12]) by rcdn-core-10.cisco.com (8.15.2/8.15.2) with ESMTPS id 10PEN1U8003498 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 25 Jan 2021 14:23:03 GMT
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by XCH-RCD-002.cisco.com (173.37.102.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 25 Jan 2021 08:23:01 -0600
Received: from xhs-rcd-001.cisco.com (173.37.227.246) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 25 Jan 2021 09:23:00 -0500
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-001.cisco.com (173.37.227.246) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 25 Jan 2021 08:22:59 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Dm1IQtki398nDsMZjoPph+f9Rd0Z/hjZtVwSsoqPEHFsZz0z3O99im8BiGEZEG142KR3spRQzljKhvZMc62vBLV++AwYsj2o6BL3QfmT1aAKwfznQQQThz1p24VTVfm2PmsKoEBXoznnEREFlTRKYCD9XHX8gtYpIQl0Sz59DdtOuw/8UajAhvskK6hELZiesN2/ivWZ+SC6zIqCadNOSqOJVC0zTDCAxCoaGRLje8uQEIMREgxavHd00BMzLYuJVcxzPDel0YzZrCulqJtQnjRbveqB+BVKGxawj28PRx4Vq967b722NJvlRfLjSR1AHg4jSNJmM0bkWGrEttLKUQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FZHVydUKdIiCEsFXYjI8wgOAu9uDI+3tLFtCL82xH3I=; b=BXF2UszvUG90J28mhEuAJ4GWeuXace1hniWUegIM0Tl9RTqHRGPXA6vVJtSN2sgxdsaDNOSXPbZEaXOEBgWCT5XxoahTpEQCi5rXWd42RyKlwCS2uV3j8iF4LFJ3fuJFQ/wjilBpKsWsOA6wdsNVlm5e9qk/EXuNBALthYhuxTkC/F6oakV+m1tVBGFi5QmcTZnrnXfwWwrkGaxR5SkBjOH9Kkmt5SSnTylcJQHDaSPPCOmnJ+EyI8BP668RTjiaP9N85pzWJS42AB0wjRG9zCHdLzrErB9IaT91vfPhV3RCJMDoLV+9JQHK8wxO56y51fpwsOxrPyANvNHJF8wtZg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=FZHVydUKdIiCEsFXYjI8wgOAu9uDI+3tLFtCL82xH3I=; b=HfseTILizO05MUtcz3AYMKVkklKD+IEJfX8jCxkPIdKbhKX5b/1v7exY07kJyex95A4QhxGIE+2A2YCtsVKbKXt4YCq9XjuYokCXnl2g+OW4Ef1M9efh6pABsEzV8BPFEbvKcMxhX/grelA6r5iwBOjODJZXLKL2CaKBh8DCsmI=
Received: from CO1PR11MB4881.namprd11.prod.outlook.com (2603:10b6:303:91::20) by CO1PR11MB5075.namprd11.prod.outlook.com (2603:10b6:303:9e::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3784.14; Mon, 25 Jan 2021 14:22:59 +0000
Received: from CO1PR11MB4881.namprd11.prod.outlook.com ([fe80::14a1:29eb:e708:d7e6]) by CO1PR11MB4881.namprd11.prod.outlook.com ([fe80::14a1:29eb:e708:d7e6%6]) with mapi id 15.20.3784.017; Mon, 25 Jan 2021 14:22:58 +0000
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: "draft-ietf-roll-enrollment-priority@ietf.org" <draft-ietf-roll-enrollment-priority@ietf.org>
CC: Routing Over Low power and Lossy networks <roll@ietf.org>
Thread-Topic: [Roll] Reviews request for draft-ietf-roll-enrollment-priority
Thread-Index: AQHW8X95Ic3wGW2Gv0miaKWF5v0vgqo4Fd7A
Date: Mon, 25 Jan 2021 14:22:33 +0000
Deferred-Delivery: Mon, 25 Jan 2021 14:22:21 +0000
Message-ID: <CO1PR11MB488100F0532F285C180EB65DD8BD9@CO1PR11MB4881.namprd11.prod.outlook.com>
References: <CAP+sJUd81tEzcYy=TDru+58Sj1+d68biD2WJ2c0NO3ehXmNe6Q@mail.gmail.com>
In-Reply-To: <CAP+sJUd81tEzcYy=TDru+58Sj1+d68biD2WJ2c0NO3ehXmNe6Q@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2a01:cb1d:4ec:2200:49ea:6363:d4b7:11bc]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: c2712afc-9a8b-4115-1e21-08d8c13cb744
x-ms-traffictypediagnostic: CO1PR11MB5075:
x-microsoft-antispam-prvs: <CO1PR11MB50753473FE1A5605920A7880D8BD9@CO1PR11MB5075.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: qS6HhuDv9PAFx9UyRrGe61wibf3tkWYtmVuN8/J12z3UYvAt2zD9avm0h3EMkoCPmM7wsCua8HwAZHn/JNxgwccwTX6hO4cdT8m9oYByaF3an5ZN3VfQK5JT012iaC+c0t3EsPpwK7hhK15oSuy2Xd8sO1XmzfuSIeMeur8bSscuMEvuaFbZ+Jb54OPSXX2fLOrc1mbsbYN5ghBDs3JJ4UnMHLT0UKTGpHNMI5F9QXn7XSJpNVvT4u7kz/2SdjCLF8ZI4pYK1xNFSyznEj5wykkfWCPK+4esdIwIZxHQZs94G5l8PyE/+kz8Z2w6SvpjQyQ3xolWIjSpnxKrobj1yfs88x8QccoI0HZFfEK+LosPv6Pr0qpy/dAf9qpqCDYYpXSs13t8KAE0OKNsVv1J9BwYD7LAteLTUKlyTdTh2ddyB54KYE9IN5bSB8sKB7ZI/LlzpjuZGOe7sByS9U59tA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO1PR11MB4881.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(396003)(366004)(346002)(136003)(39860400002)(376002)(33656002)(7696005)(86362001)(71200400001)(6666004)(9686003)(64756008)(66476007)(66574015)(5660300002)(76116006)(2906002)(316002)(52536014)(166002)(966005)(4326008)(66446008)(186003)(6916009)(66556008)(8676002)(53546011)(6506007)(450100002)(83380400001)(55016002)(66946007)(8936002)(478600001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: bsNx2R94XoC/zf4z6zZD+8Cmo9+W8iXtSPXVJEpj9qeYCQa6dJQQTSh9jWcc46aqpqNjj0m6dStC0lBRT5IoZyxZbwz7bKC3hHkm6cfgOxeS9iIXLa/rJaBw1pGL9r/tR+Cd106K/kxdS1SOi+lOi3z5+kTdCbmgJ1gEiZPRuiro0N4NnxtQszPZosrbHkkgIhV6ZigqCLr17LgxxRJaOipSkv49fCh5QO2usNbQMjXTsb145RwDDdMgAjSDtniX4vsZ0g/AjhXo7VgnlPmd9unDREpaKSOGBlytshMo89kliFs7vz/Ch/FLP9p0WiRSvqllrOPxKxMoc7qwX+fz6J8Yxdx2J+3WvYClOhiwW+8DI02t8khDypudYPzxUDLp5+2/QhfgQ04a7LhOiDJrgDjuozqjG1/ruIcCIv/qdEhcTxzLAkIzPqRgPWxo/zAuRRD5gpbWfPeAZIp8bqEE+JwnHf2ft2DaKOVYcwBebCSUv40RGxqNLQsj4mJ480o+7WIY7TSxPXl440gF82gj83fwGUCX9whmyUx1KSaM9q5Vy2mJaa26zoajHILHJQqyWccEjAfoX+JPSzFKFA7cXdXCboJ57IsjQ712KTOgvIdI6IeVSRuwKCYpzL2e3w1LJLoXbJ0BMyEEqFjIr74NuuXxR0athVM3W0Se51MjrUg7qgtk2DGuQkeN2+ujyABHHowXvh4RSHdk5BmmwbPrZbJ5CTqKlnX2/RGSw8bW0tSVO4ts1AaxZGKHtfd4veggdQNOroEQQSfBX2xMYdPQpVqIP6F8WSOme+yZokY1FWrUAKwHlzjgp0YksA4gK2Pkb5WK8ZqRednD2nUN9A//oP1BYaJqjJ86z04Wgtip3oUs2a16t4UeHbFaD7S7f0pwFjZZJL4L855pJgsGo+W47ZzUncaOQ3gEWUm5HWZzmTMBqL26zym/QdPjeMT368SQ8ryw6LfRaN3xqaJNtoJUXbpAVra7olrMyV88DeaCCWFrtepYFPfL6artDYyuuEPGdLXYzFChLxwmz50kDvC4X2ilzvNXTK1+Q2DDLlan9mGpkezuWji2MueCEUXYCMC2hnZRyTh4A6KtnytzFMerExuVVrFT9P51+yUTdEA5Zl3Qf3kb+zXqWrwA8baajQ2q
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_CO1PR11MB488100F0532F285C180EB65DD8BD9CO1PR11MB4881namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO1PR11MB4881.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: c2712afc-9a8b-4115-1e21-08d8c13cb744
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jan 2021 14:22:58.8215 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: GfSE44qN7RHlFk9716tKz8Rh8TNN79z5gCdmEtUQlFJ0AYy6+EnqOG64IVtZZuuKOkErpnQ2djJjAc0NZ8a48w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR11MB5075
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.12, xch-rcd-002.cisco.com
X-Outbound-Node: rcdn-core-10.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/roll/CyfG-4dzIqm9r6W1DvNplxqqhXI>
Subject: Re: [Roll] Reviews request for draft-ietf-roll-enrollment-priority
X-BeenThere: roll@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Routing Over Low power and Lossy networks <roll.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/roll>, <mailto:roll-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/roll/>
List-Post: <mailto:roll@ietf.org>
List-Help: <mailto:roll-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/roll>, <mailto:roll-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2021 14:23:58 -0000

Dear authors

A few comments and questions:

Intro:
“
[I-D.ietf-6tisch-minimal-security<https://tools.ietf.org/html/draft-ietf-roll-enrollment-priority-03#ref-I-D.ietf-6tisch-minimal-security>] and
   [I-D.ietf-6tisch-dtsecurity-secure-join<https://tools.ietf.org/html/draft-ietf-roll-enrollment-priority-03#ref-I-D.ietf-6tisch-dtsecurity-secure-join>] describe mechanisms by which

“
Is there a plan for the secure join draft?

Section 2:
“

   6LRs that see this DIO Option SHOULD increment their minimum

   enrollment priority if they observe congestion on the channel used

   for enrollment traffic.

“
As described the minimum is that set by the root and propagated unchanged. But if the channel is congested at an ancestor, then the child will not know and accept the enrollment, so the above cannot be achieved. OTOH, if the parent/ancestor could increase the min_priority in the DIO that it propagates, it could inform its descendants not to take more pledges. If we take that path, a child would use either 1) the value of min_priority from its preferred parent or 2) the minimum min_priority across candidate parents. In the case of 2) that might mean use that non-preferred parent for a ratio of traffic. What do you think?

Also:

Considering that the policy to compute the priority increment is unspecified, other global info might be needed by the RPL router. I wonder if it makes sense to place the DODAG size in this option rather than in a metric container as suggested by draft-hushe-roll-dodag-metric-00.

Section 2.1:

Say I want to add a field in the future… What’s the general plan to enhance that option? Push the Length? Do we “must” that the first byte is forever as shown here (please caption the figure) even if the length is > 1? Or should the node ignore the option if length != 1? Or should there be a flag field indicating what’s in like for the Solicited Information option?

Section 3 paragraph 1)

The text below is a cc from https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#name-security-considerations
“
It is worth noting that with [RFC6550<https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#RFC6550>], every node in the LLN is RPL-aware and can inject any RPL-based attack in the network.
“
“
In a general manner, the Security Considerations in [RFC6550<https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#RFC6550>], [RFC7416<https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#RFC7416>] [RFC6775<https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#RFC6775>], and [RFC8505<https://www.ietf.org/archive/id/draft-ietf-roll-unaware-leaves-30.html#RFC8505>] apply to this specification as well.
“
believe that it could be adapted here with a bit of tailorization.

You all keep safe!

Pascal



From: Roll <roll-bounces@ietf.org> On Behalf Of Ines Robles
Sent: samedi 23 janvier 2021 13:00
To: roll <roll@ietf.org>
Subject: [Roll] Reviews request for draft-ietf-roll-enrollment-priority

Dear all,

We are looking reviews for this document:

https://datatracker.ietf.org/doc/draft-ietf-roll-enrollment-priority/

Please let us know if you are willing to help us with that.

Thank you very much in advance,

Ines and Dominique