Re: [secdir] secdir review of draft-ietf-mpls-rsvp-te-no-php-oob-mapping-08

"Adrian Farrel" <adrian@olddog.co.uk> Mon, 22 August 2011 13:58 UTC

Return-Path: <adrian@olddog.co.uk>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A558521F8B4B; Mon, 22 Aug 2011 06:58:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.592
X-Spam-Level:
X-Spam-Status: No, score=-2.592 tagged_above=-999 required=5 tests=[AWL=0.007, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o9MUva3ZqoBt; Mon, 22 Aug 2011 06:58:09 -0700 (PDT)
Received: from asmtp2.iomartmail.com (asmtp2.iomartmail.com [62.128.201.249]) by ietfa.amsl.com (Postfix) with ESMTP id E0C0A21F8B4A; Mon, 22 Aug 2011 06:58:08 -0700 (PDT)
Received: from asmtp2.iomartmail.com (localhost.localdomain [127.0.0.1]) by asmtp2.iomartmail.com (8.13.8/8.13.8) with ESMTP id p7MDx8b3029125; Mon, 22 Aug 2011 14:59:08 +0100
Received: from 950129200 (dsl-sp-81-140-15-32.in-addr.broadbandscope.com [81.140.15.32]) (authenticated bits=0) by asmtp2.iomartmail.com (8.13.8/8.13.8) with ESMTP id p7MDx7xx029119 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Mon, 22 Aug 2011 14:59:08 +0100
From: Adrian Farrel <adrian@olddog.co.uk>
To: 'Barry Leiba' <barryleiba@computer.org>, secdir@ietf.org
References: <CALaySJLyNKHp0_QzaTbbX0FB9RASprJ2cknZQjp_=RqFgno4LQ@mail.gmail.com>
In-Reply-To: <CALaySJLyNKHp0_QzaTbbX0FB9RASprJ2cknZQjp_=RqFgno4LQ@mail.gmail.com>
Date: Mon, 22 Aug 2011 14:59:07 +0100
Message-ID: <065801cc60d3$a9d77f20$fd867d60$@olddog.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQL7uy7LvXWYMvZs8RqlX4lyiECh2pLKL5qg
Content-Language: en-gb
Cc: draft-ietf-mpls-rsvp-te-no-php-oob-mapping.all@tools.ietf.org, iesg@ietf.org
Subject: Re: [secdir] secdir review of draft-ietf-mpls-rsvp-te-no-php-oob-mapping-08
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: adrian@olddog.co.uk
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Aug 2011 13:58:09 -0000

Since the authors and document shepherd haven't responded, and since Stephen
mentions the review in Comment, I will take on responding...

> I have one minor question; in section 2.2 is this:
> 
>       An Ingress LSR sets the OOB mapping indication flag to signal the
>       Egress LSR that binding of RSVP-TE LSP to an application and
>       payload identification is being signaled out-of-band. This flag
>       MUST NOT be modified by any other LSRs in the network. LSRs other
>       than the Egress LSRs SHOULD ignore this flag.
> 
> On that last "SHOULD": what does it mean for any other LSR *not* to
> ignore the flag?  That is, what can they do?  How can they not ignore
> it, since there's no defined behaviour for them to do with it?

There is a difference between not being told to do something, and being told to
not do something.

It would be extreme, IMHO, to say that a transit LSR MUST ignore the flag.
The fact that there is no behavior required of the transit LSR and nothing that
pertains to the LSP that can be thought of for the LSR to do, is not reason to
forbid the LSR from looking at the flag, saying "Ooooh, that's interesting", and
sending a message to its third cousin in Baltimore to gossip about the fact.
In the same way that a router "SHOULD" ignore the source IP address on a packet
when it routes it, there is no reason to prohibit examination of the field.

Cheers,
Adrian