Re: [secdir] SECDIR review of draft-ietf-bess-pta-flags-02.txt

Eric C Rosen <erosen@juniper.net> Mon, 25 April 2016 17:40 UTC

Return-Path: <erosen@juniper.net>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA35E12B029; Mon, 25 Apr 2016 10:40:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sPllnPlb1sbM; Mon, 25 Apr 2016 10:40:38 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0127.outbound.protection.outlook.com [65.55.169.127]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B7D7312B018; Mon, 25 Apr 2016 10:40:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=GGnbIHRVgSXI516TjZMZE731I4rgDU4I1ghF0+pRV3I=; b=VcIsB+V9mCuwzq/vLjuyJMjrpmhodu8zOkoThcjuPIIWvpgJtwbHGA6m+BIhdiHthQu9XCvK/n7LR8FBgpMtxJbaEKCS1MIGiTt0j0uhdgPGTDxIszhnbn8wRoihMMReTh5l7TSjD/iudaLPKo1jG/uFQSzlQhMOOZfmVmBppLY=
Authentication-Results: juniper.net; dkim=none (message not signed) header.d=none;juniper.net; dmarc=none action=none header.from=juniper.net;
Received: from [172.29.35.186] (66.129.241.12) by BLUPR05MB786.namprd05.prod.outlook.com (10.141.209.145) with Microsoft SMTP Server (TLS) id 15.1.466.19; Mon, 25 Apr 2016 17:40:31 +0000
To: Christian Huitema <huitema@huitema.net>, iesg@ietf.org, secdir@ietf.org, draft-ietf-bess-pta-flags.all@ietf.org
References: <033501d19e81$1697ec40$43c7c4c0$@huitema.net>
From: Eric C Rosen <erosen@juniper.net>
Message-ID: <e1c75234-498c-4db2-a76f-faf86ccef7fc@juniper.net>
Date: Mon, 25 Apr 2016 13:40:26 -0400
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.0
MIME-Version: 1.0
In-Reply-To: <033501d19e81$1697ec40$43c7c4c0$@huitema.net>
Content-Type: text/plain; charset="windows-1252"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [66.129.241.12]
X-ClientProxiedBy: CY1PR12CA0032.namprd12.prod.outlook.com (10.160.137.42) To BLUPR05MB786.namprd05.prod.outlook.com (10.141.209.145)
X-MS-Office365-Filtering-Correlation-Id: 0da52cb5-5674-47cb-641a-08d36d30b38f
X-Microsoft-Exchange-Diagnostics: 1; BLUPR05MB786; 2:BN3sAqL3ZPltXY3MUd7fS806mz2R6Q0xFwpABCON5r0XR3FNJHrrdLmpFWffWGuGPNEEgRiGSbwgGSGOSF9utVPX0OoZYbA4xRSn3bua7JnWAI2w6hOjIyjF/HqRpUZkwca5wz7473Y7phjmFkUsesF1TKaqswRA4jHm+wy6+0LqpER8/pwNvdQlWTyeoEcS; 3:V6FaVJqx2qRX1ijabstYOaLLjXhnTSBHlxLDvqht4C/jM84nx4hLjFKY2EAZtkI9CmdbcZiKEd4ItZh0KonxuaStgTrCp+LngwqMMQ1nkq2eeu7vM+EYBQTn7bsEajYf
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BLUPR05MB786;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR05MB786; 25:ir80/aUmjHFgA4NMhJ5bakE8MFdHuv2kD5HiWMI21quknbnHNCYzuq9z4jpGzsVvrBIIZxuSESGq+JGDqQMguZK/g2/CjpNplTxppeFnJDue/lDJ4fSCroRE/clNfUTfVwIGIBYmOTubmtiPLg3dcj8BzwVXWUcW6GrK5rNAVVr1FHw0Wz0XN1iD9AatQbr+a2KXdp6LeGUvnWhhvPsFTXArhujsTlDTyRXFzgNptV+w6XllhOKcHvh2B7aojoyHPXKiVVCokIGKALIRr2TCTXn5C/IuYgnktuNIjfR7Vz7j15epZhxtdFRl2cC/yY94y0HAROi2HD0l4OmvCgHqwCcDKiIQfOKzGUX6kN9RAWtHDfG7vQf5E/02R1UE0s3tqjVnFKI6pcqxJvsHEINfnDDsne09NEi1O0H4bxW0nrS07SedfEGX3YkMoqBmrvaG1t4HxeJT8H3spq6ojGxdbi5gbILCgp85yqfk/FCPhyFPUE3wlbOfE6KcLANS9UNez8IAjU2mJfvMkbl0iGbayG5Tmrp7EwQJVeOOFh9YEn+39DXDq4LzQ8/GZmEPPgPSi1NdpEztRiQ8xSUee7FAKctsKPWwl9Hds3MNT9bTGsRBjb8yV2mShQttpCpk10DjPeinK46n42DdDKY0UtZuow==
X-Microsoft-Exchange-Diagnostics: 1; BLUPR05MB786; 20:fv7O/7hI6YLMkPC7adyEjpvB9UNmn8xd/XylR2huCwXZOLTqypU65qQ1iyGkxXjE6+8ke3tYv/vutuxjx/bwzzKKSq7PPn15+U8Xl3uMvb1QTCiPRu+MQgbDtw4CHTWuXs4GQwHQclOe3OMOYIbrO5ewJq2Jz6dZ8UdF56IsNka8W9xwXaDw6IblwYrMEUd6LGw4CoR4f/+ON8yyFuLzxUuJ1u4ORuGmJU2SPDMgRtvTGWiYJzuLH7r89+4Eq4i1O2t/yC4wJHLf8MvwgzKePg8lS1p43YIChMMwTwov5Y8GDtKbt90EArM28SMa5tCndp8sEIOImDVK6ZvlYnWQMFdslENGbvS+TvgSYHRGaFWBxA5NfYynKpaSUxIJF56K3wuqXnMLVWVrMqbISkwu7s/JaXZE5fL10EdItTk+slSnOCxyI8ooFM5D5YsjO/Qk1ul9FGlM1GaaXjUUUcRinjdKBxDinzOsg0THHp/Brr67kk4k2Fxqc25YNUxk2ayg; 4:vpotEBXMMRL0uF6nam2DcUM/c6PXqJWTDzYUU14OxiLkedRmnRT0HDv+95AHeKwWiZbYSmFHADKwZ3iSK/VcaYEh/rVWua36kOjsQpGORoDOA//2Ql94iDJxckco3q9yR+GJvvyH7YPt2laI+HRxr9jcND8rcNkk+UlonC4OhyJyP2+xACZaPv3h0AvLD81YDdx7wfM441nzZvF/TGX/uLcbuyvDQIr2xwvLsijgmSsouhE/e9GZSEkuX7pf5B8ZG2YzN7ryQWscLulkLGCtWLAJvATTWxEZysGUMky4p6mRT9q5XThfAJ25G4wKhzxOOmlUr3TwpNqop3qDMh1ICwg3YtDPi1ZBB9g6qM5Tfbm94k310dXZdhiTtxJQ2nJ7T7KSQjyBZENS4JrO+VQZ+eLX3L19R257fxGWPzoOVkA=
X-Microsoft-Antispam-PRVS: <BLUPR05MB786E44E9693B2597D11CA2CD4620@BLUPR05MB786.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(9101521067)(601004)(2401047)(5005006)(8121501046)(10201501046)(3002001)(6055026); SRVR:BLUPR05MB786; BCL:0; PCL:0; RULEID:; SRVR:BLUPR05MB786;
X-Forefront-PRVS: 0923977CCA
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(6049001)(24454002)(377454003)(92566002)(23746002)(81166005)(83506001)(5008740100001)(77096005)(2906002)(5001770100001)(2950100001)(230700001)(3846002)(6116002)(189998001)(107886002)(586003)(2201001)(33646002)(1096002)(31696002)(230783001)(86362001)(66066001)(64126003)(65956001)(42186005)(65806001)(54356999)(5004730100002)(76176999)(36756003)(50986999)(31686004)(47776003)(65826006); DIR:OUT; SFP:1102; SCL:1; SRVR:BLUPR05MB786; H:[172.29.35.186]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR05MB786; 23:TAA0wYhJJHBNlVvRh9VGzQHjCI3vdjN9YqMfwUAb0cg6xYZXnR3e+2l8o3arSjpBW5K47ImQZUqPDnX6qbUMqXMfpYLCUHUOeCjG9XxUpNab/L/k92UejZ3rUGGk0vu8+/E2HLgiNP7eEXAnbtSxDJaAF81qzJIr85u1I9i6Jcy9P61xqjUbOZ7EOfjmqfwkisR16fnZSDqEsmUZ/cUBGXMnBXfGIgFYw7oTS19i8v1odUaEfezGUqTVduad3zoPANxJJa7QWRnvsFJzDXvh0t3WlfguaEdaCRdv8+UncVdOErpBOqBCGKN80uJiGUGpxRlBVZ3wNxIz4/8Z+FdMfaJwC7TJoCGdeiN+iCrzz1mPSpZYNU3CrFx/78ui+KTaaqWXt0ZqiYet7mcCCPdf/DbXbxw9OUBopswicRK929nLN2NnTsghhXPyYK8DgrtTGVKndcnoFGvY9WnwSCyjFBrD4OXClDlOXit791Ql/0l95vhzCK0DF/MdStUUIz9lLpc+XJnMW4lOzKwA5UOBE1QCS+nN4tur/TRoRLP9K29d0IxFrxAd5JxxdBE5PU7mHl0102tDZLdsiLWLzQvtWjGrT79RFfzV+lT/A+67pYdCiTL3PCC+Td3ymz22Wpm7Y8JEUAgXvIb1PPZk9nKITgXUTzx3IYrj5Oo/VSeMGuxTcTB5v2RBXWUw50OgFXwoLfdQY7noF1IKLbOuIsC7XbCNJyYkdy88inTc487IWvVlxxuUbeRJTMXbhBTtICzi/0KN/w2grgaCWI0GSM2XiLQ27lvB4AEhKSJhchSehPDm0ESbyfO8TxFzwixtSnd3GAdHQmdDpG5v3rC9IsHsXCMDph0DAt9nwixeC4qDurahiZlXUdvLs+Dw2zYIliSV7w3uDWZD+25Ir7YZHS4YCz4EY8DQUB+hKs89MP4HhYcFXDmGhNiwdtFHvk+OCskaJVIDByf4zYkzIwL8NvWh3I5UQjUJp6979Mfs30xzAXU6RNLrWWA/1f5wArifbQLGT8RtOMjcpJzmwNSbJWOvkg==
X-Microsoft-Exchange-Diagnostics: 1; BLUPR05MB786; 5:3N3vt/+gcjQqoTyKMXME8Lswwu5UAYSj1mOIEQGEel3gG6fEejTppri2hSHNi+ot8rcJUg9fQMxT56iZyg3lsefeOx7y++JWYshPQ3qxEKw36tT11+qkWX92vIbvBnCc7TX4kEqJr4x8sEEnAmEjj6okMdUEzOOvVWN4IPmdpzQ0/k3m0Js9nBx3521iYdux; 24:nP+NNMulso8LPZjwUG7Hm7WVXOpLBYJQxhVXBO5liVnQobRVN1PsfZMOsW6FDM3O8Dwy4YSzWHc6jFJaVMuREvJyLjB2/3w/w4ckHWEi2P0=; 7:ykIK2C+xe/uyxuYr6dU1dUGsz6J1bxjKrmj47ui0Tdu5x7RquiD6knv6VzyjhmZyGF8KEciazmShcKpUwDOB973IGsGGHobr2oO2pJUAhZCRHOiXLc2RHITUdkz8/Y+UBV/t1QSHJGWmN1+kX3enDHXt3MWVkIXwaKycmo0b0lQC4b7uvpYtH7PzefUmrHQ7XBjxyubJQ83Yc/H9cDJAHg==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Apr 2016 17:40:31.7592 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR05MB786
Archived-At: <http://mailarchive.ietf.org/arch/msg/secdir/i1lXuqBIWUzmDVn43ezlZdTK6jg>
Subject: Re: [secdir] SECDIR review of draft-ietf-bess-pta-flags-02.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Apr 2016 17:40:39 -0000

On 4/24/2016 7:29 PM, Christian Huitema wrote:
> We have thus two possible issues:
>
> 1) A router supports RFC 6514 but does not implement the extension
> mechanism.
> 2) A router supports the extension mechanism, but does not support the
> specific extension.

With regards to case 1, I don't think there's much to say.  A router 
that supports RFC 6514 but not the pta-flags draft will ignore all the 
flags except the one that is defined in RFC 6514.

Similarly, in case 2, a router that doesn't recognize a particular flag 
will ignore it.  However, I can add some text to the draft saying to 
ignore any bits you don't recognize.

If there are mechanisms that require the use of a particular extension, 
those mechanisms won't work properly with routers that don't support the 
necessary extension.  Applications that require such mechanisms either 
need to provide signaling to determine whether all involved routers 
support the necessary extension, or else they need to define procedures 
for interworking with routers that don't support the extension.  I could 
add some text stating this, but I don't think there's much more that can 
be said.