Re: Optimizing Authentication - periodic re-authentication

Rahman <reshad@yahoo.com> Thu, 01 February 2024 01:38 UTC

Return-Path: <reshad@yahoo.com>
X-Original-To: rtg-bfd@ietfa.amsl.com
Delivered-To: rtg-bfd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 898CAC14F69A for <rtg-bfd@ietfa.amsl.com>; Wed, 31 Jan 2024 17:38:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.216
X-Spam-Level:
X-Spam-Status: No, score=-1.216 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, MIME_HTML_ONLY_MULTI=0.001, MIME_QP_LONG_LINE=0.001, MPART_ALT_DIFF=0.79, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Iwwu99D9P0r0 for <rtg-bfd@ietfa.amsl.com>; Wed, 31 Jan 2024 17:38:22 -0800 (PST)
Received: from sonic303-3.consmr.mail.bf2.yahoo.com (sonic303-3.consmr.mail.bf2.yahoo.com [74.6.131.42]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53B7CC14F5F8 for <rtg-bfd@ietf.org>; Wed, 31 Jan 2024 17:38:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1706751500; bh=E7ygq9f4kDXxcZpdRskr245ZKXmO6PwM1tbLY1mWxBU=; h=From:Subject:Date:References:Cc:In-Reply-To:To:From:Subject:Reply-To; b=XZvFje79zHjs9dkt3SRG5ElEC9YxyUW/mDjJ54FMggigESXbCe4BV4OVeestKV6OaciQ3omkf0tt4AKIpg+05TXXckwmG8PPtJ6Cl/KK21s1LragX0mRxlhVWYDFF1TON8EeCRfKRTQwTswAWQXZ4DX5qMi4uLeRnfxro2ZHm4XGk+HWIGkru/MBgitASm3h7D+24+BUDq7vf9eDc8yQ3ac65TR2Qy4t3XfR8xMXFFwV0kgn/TYP12eduaW1bpfyL/06KBh5CValkyJzj1D+Cqgx6oNp4oE+w7xWLCc3344bZwSfkSAoyZp8Pg/w+xOtUe0jE97Xjz6KaFTiWayw/w==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1706751500; bh=9fM+TojtRQ1AADroAJzmfCwEeWVwiSg6ZpnKAstWjD7=; h=X-Sonic-MF:From:Subject:Date:To:From:Subject; b=mMmAD60RdfuBCXDbS7XSxeS9WYL0cmM+1ZDa98vndvDCMCTqCn4VxD76U548YpIfcXlivkrYHNfmfUo01P2U2jGQRAQz9G2epFDvxNt8xdDnemhbaKVJtrBjsYDUpde0NbJTBkXX+TxGBy3v82E5OWil8U6qLzRBHUfcPQXa3gVzezktGVP5l0N9EaPl917C1aMWClzubcJQAuJnwbZLsTwrjgav6ErkbOCCMujHDHodrEfH3w0HwsSsMDwSI7UCfLaojOqmcP0Wp9+nCRjqVf/QCho8VwOzzKF9rMqFzoghKhRBVB7h6YlyCeRZ6k+A5A50Ur2SsUgjrAnTTpxqJQ==
X-YMail-OSG: OYGKw_gVM1nT.SkvwfQ.9k1qTKinosg8yDIcj6xuSA_7HdSdIAo5FYFznT044Z6 ljSAXl8XhdSDZ_X284ZX0nvsGHWZiZ8Z8O6IFyUC6v2jpRm3BEwvRxAj_1AH5E5ioK2vrIC8IhNJ Z90d3WeUvYpHYQ23l8cbwULhVoVV6aUabhvKluOeEe1tC.De0XAWkwG6tE2GUiP2hXQ8kIjArpuH ILi0YhARLyFixaz6VxntMFZqQMeXznpXGkbOYgOkze7b6uhOaQe4VAJ6NsUSnNQNIdzZTamnmGvd i_em4vnhXR8bwf9i5krBT8cTu70YwUimeD_bpiMXPq9LbasD_OaJD9cmaMGDip9MVNmt9VEy5UcN OZC7MRvtRMk1uMRfFRG6pRedjNQG1Fb9ziMFWxWj5p1sLk1jDYmZxvBgM8mi0uxmdDyinNX0Skfp rBYkPLM6j2Vwns7OUqgL3L0eCVndr7fLK5KYaHVNxDVoLDzEDVPUT.qvDbhOE.TLvR9djfnejQJM 4GyccKjQTbhvBpzRS_Yq9Un3twtv5.FmmmU2eqGU.aAWQ9v4_OebFw0icOUYEvBSfB3FEgCNlzZG DRkBYMXwJmL_IMnej2YlOps89gscnNORB84OpQJz3C5NWa8AItExDKbAtsw2tE2hNCRo_P8uAXCL cJA20GMrQR8HiiNyzfO8SckD95_23lLMn1YksqajcLlAjuAApj94u7X1eIxgLyHvg2l1YabWKLqH WfL8GTZDRpriOijsaUDnNOhgzdUYIcq28ylq3xeMjdwr3m0LkW6g2jZ6QQLXlzVS2rJHCyWOsSaS etef_ogNNnsTRhXDZLy6hfAylZ_hLpxv4hZsqqa3VWx457khDjJgPL6mgdsULyDVxh_U41NrDxF_ vBs17P2dY.Yy9zS2rKP908HYglldN8O55zVGI3._qpqqBys7FucTYS68S4zaGx6w129j.lGNwzwl 9k83mGY1odPaLRZPciUcN1wzH.Ds_tAjlYzKLrArdpUPksqaexjElB589CPSqNctnYDeAkgC4YpM gga56xQNNlNdDuHUAozLnStfJL5xXQsnAFI8bIdX9.SHxRiVOLYB_lV485Z4DRfZjdJ8fMzGaO8k x88qBNr8T5PZxE_ftI9dw85vjZrmBkTvY6w0.mTcwhqcwiUVCft88taBQhXdBai4kU3F0I6OoHpb ulNihSgzkol0NP3dpEuDOR2etWsP1_XE9fC54gQQET4gHYlcmd.Wg9Dr.0jpHA37xTvsNaqTC1j6 kIh7NP9qra1PN_PNSUVsCmJOmMveqL6QX6ZucLNRKySedo17ZQCLjAYksIfg_ld4cBxpKT73T.f1 0FOpgV2yK_zeUiT7SrkpY4.61glux90ngULNd19Tyxl6y_xPazkHFzkorNL_USlThhuqPRa_UdQu EatO1vRvoLk1FNpKmWTpJJiaKSQuc3Z59quATG8asHmvQRrDSBdS1O_p.aWFryIhEZ3xNQfI2YrX RW_V.sufzQVw11nl5oPmyFbMpQrGitraJ1d.JytBPA787TSjuou3d5gOdNcaJ5CyzBzPNIHHFKCl bpBwxZQll89nA6a7hSns31Qn82s9p.PqWQJLqdFGHLb2pulXegek1PnR1DVE6zcyO4tiXuRsQJK4 nVCwX39_RGJfNsFJPtyvRvcWPY.lVqbZOTWW7MWo.1rNWPh_mpd06kmyySpA4bujFuCYh4_GxHhZ zZJsJ_LDDSNRhVnwxIz6CbnujSJbZFEJqGmJdkV9UasgaT9RveG8xactuhmJtP8j9C7lW4uuNT48 DZPlADUO4og6f3fhl4ue.utiC1w4pBgp.FNDJ_mcdnL7RXexp2WxQ.FCLSD22KdeKJYgVsdI8beP sEQWc68xgo5GoCY2nl54v82KI83YYnk3mmql2XtdFeHhMAHPZqdzLjJ5ZDjbrgoI3eIPO.jqhECM esmybxi6pjrMVQpVRXAoJdGKaZ6NF0rkxFuz_6RlpFT_yTTtXB4G1krX9WnRGrrkQaMDHD8gss1S UrlpEzpEFKZAUMNYWduj1.91GbKDTUQZNf1pg1v.JkXVIWbY.VIxaNiYhht4ymIs5HfW2GlIVRr6 bEdaDfeGQnLQWA8Iju.OHPx0KAWD5lFtFXvIiKMn0XNyb6FqrzXsLqVXkKvfYWegVuy8BuHaMDW. MHYbIJI0ReHyx6piZfaLirYiYGCJ.cg9QOemql7w_SpUfl.4g86NE9wxhCnOsn1dDQM.6xHpEs3h lbN8e3_zw2o8TwNCC_REzIphDoavlwx5I_.VH
X-Sonic-MF: <reshad@yahoo.com>
X-Sonic-ID: d6dc1865-be76-428e-b6a3-ab69a8ff74ef
Received: from sonic.gate.mail.ne1.yahoo.com by sonic303.consmr.mail.bf2.yahoo.com with HTTP; Thu, 1 Feb 2024 01:38:20 +0000
Received: by hermes--production-gq1-5c57879fdf-kht2b (Yahoo Inc. Hermes SMTP Server) with ESMTPA ID 2afe66eaf62552a7c8583f1752ca939a; Thu, 01 Feb 2024 01:38:14 +0000 (UTC)
Content-Type: multipart/alternative; boundary="Apple-Mail-51F5623F-FA5C-4129-9203-090C5874BBE7"
Content-Transfer-Encoding: 7bit
From: Rahman <reshad@yahoo.com>
Mime-Version: 1.0 (1.0)
Subject: Re: Optimizing Authentication - periodic re-authentication
Date: Wed, 31 Jan 2024 17:38:03 -0800
Message-Id: <8B34FDE7-C8EC-4792-A14A-1D76AA0A215A@yahoo.com>
References: <9491CBCF-AAEA-4CF0-A07C-CB2E270EB125@pfrc.org>
Cc: draft-ietf-bfd-optimizing-authentication@ietf.org, rtg-bfd@ietf.org
In-Reply-To: <9491CBCF-AAEA-4CF0-A07C-CB2E270EB125@pfrc.org>
To: Jeffrey Haas <jhaas@pfrc.org>
X-Mailer: iPhone Mail (21C66)
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtg-bfd/HvE_vPDhMjXWX0f7KbFsima-mxg>
X-BeenThere: rtg-bfd@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "RTG Area: Bidirectional Forwarding Detection DT" <rtg-bfd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtg-bfd/>
List-Post: <mailto:rtg-bfd@ietf.org>
List-Help: <mailto:rtg-bfd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Feb 2024 01:38:23 -0000

Hi,

My only comment is we should be explicit about the action taken when we detect that the session has been compromised (no F received).

Regards,
Reshad.

Sent from my iPhone

On Jan 31, 2024, at 11:06 AM, Jeffrey Haas <jhaas@pfrc.org> wrote:

Reshad,

On Jan 30, 2024, at 12:28 AM, Rahman <reshad@yahoo.com> wrote:

Jeff, good catch.

We can document both ways, ie we can let implementations decide which of the 2 methods below they prefer? Or is the concern that this will cause a DISCUSS?

Mahesh has proposed the fix for the next rev in this pull request:


-- Jeff