Re: [sfc] IETF WG state changed for draft-ietf-sfc-proof-of-transit

"Vengada Prasad Govindan (venggovi)" <venggovi@cisco.com> Thu, 25 June 2020 11:01 UTC

Return-Path: <venggovi@cisco.com>
X-Original-To: sfc@ietfa.amsl.com
Delivered-To: sfc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BC173A0922 for <sfc@ietfa.amsl.com>; Thu, 25 Jun 2020 04:01:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=BhoxrxJi; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=fjIoeuQb
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VnZlgEtMDL9o for <sfc@ietfa.amsl.com>; Thu, 25 Jun 2020 04:01:48 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEA2C3A0921 for <sfc@ietf.org>; Thu, 25 Jun 2020 04:01:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2968; q=dns/txt; s=iport; t=1593082907; x=1594292507; h=from:to:subject:date:message-id: content-transfer-encoding:mime-version; bh=V1ntvGH2eJsl8D9wSbrkp8JDwU/oVqMrB3/GB/MiLu0=; b=BhoxrxJidbuuVsjY4Mqay9jjf3ZJ1S06fBjfd7t9m1qIMpCKG8Hj2lWk Lwk5rD8djKLSovmUcVf3h8MumjEId3XaIWUI+mpCq57veYZN2Vvzhq3FX BMEWMENByqfN3CRzv0U3UxTwXE2vDCo/jnWlsQNR+9HbgaafgkHktGuTD c=;
IronPort-PHdr: 9a23:Q3PP2xMOY2zkGhc/eCYl6mtXPHoupqn0MwgJ65Eul7NJdOG58o//OFDEvKw33l7EQYud7OhL2KLasKHlDGoH55vJ8HUPa4dFWBJNj8IK1xchD8iIBQyeTrbqYiU2Ed4EWApj+He2YklYBMi4YEfd8TW+6DcIEUD5Mgx4bu3+Bo/ViZGx0Oa/s53eaglFnnyze7R3eR63tg7W8MIRhNhv
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BZCgBmg/Re/5xdJa1lHgEBCxIMQIMcUQdvWC8sCodgA41GmFeCUgNVCwEBAQwBARgLCgIEAQGERwKCGwIkOBMCAwEBCwEBBQEBAQIBBgRthVsBC4VyAQEBBAEBEAsdBgEBLAwLBgEIEQQBAQEeNwsdCQEEEwgTB4MFgksDLQEBDqdSAoE5iGF0gTSDAQEBBYFGQYMdGIIOAwaBOIJngkxGhmsagUE/gVSCGDU+glwBAQMBgTMqg0WCLbRuCoJbiEWGJopngnGJJZJtkT2KGJAYhBwCBAIEBQIOAQEFgWoigVZwFTuCaVAXAg2OHoNxhRSFQnQ3AgYIAQEDCXyOEoE0AYEQAQE
X-IronPort-AV: E=Sophos;i="5.75,279,1589241600"; d="scan'208";a="788288509"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by rcdn-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 25 Jun 2020 11:01:46 +0000
Received: from XCH-RCD-005.cisco.com (xch-rcd-005.cisco.com [173.37.102.15]) by rcdn-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 05PB1kEp030374 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL) for <sfc@ietf.org>; Thu, 25 Jun 2020 11:01:46 GMT
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by XCH-RCD-005.cisco.com (173.37.102.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 25 Jun 2020 06:01:46 -0500
Received: from xhs-rtp-003.cisco.com (64.101.210.230) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 25 Jun 2020 06:01:45 -0500
Received: from NAM11-CO1-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-003.cisco.com (64.101.210.230) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 25 Jun 2020 07:01:45 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FZT18UEApvW8xKVzOkkVgzmOBYwyWOg/MX3BOw4Txq0A8yb3Ri+IHQoUV528AJMaWp3Gf1JjtrxwW5uJOXKwbeFFLqeqjLv/CSZajsBIolirEeZ3WZdi3SFo1ByUrGwCOHq5674eOIbog0vHbcL5gi13I45MaPq8LaOxGrQ22Oh/X+8z8X4ojh6xL72+YSlgTeCJbsjeT1hTVSd/gW+rRX/gXpzrbHT1ISLruaellpBNBW94QT61AEAM613vG5tjE82EMbXj2SplAVSCx/Pvu39LbG88SLc3Ub6QOFK3GdTltS0t2nH2K7zuPZVuq0zXLQqXWz0OMiT7b/Cpqfqqjw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=H3pfvQO9+cB/K46Wp+D3nIfTv38OnX+XPqvO4fQU+jU=; b=WAK8Uad1XFa/geCK0omxhG2a51nXtr2RtHFAanud/+wqha4EZRfmxgivW4ZU5YkbbLWabxRRFmZn9247Z7PLjBOCZCzpFVWeo396OtEMEdiO0St2SD5wayiwjx49iZIi/yTw5r1hZdUc06Yw0Ie/zCXCdiX7Fgkt6er+AHN+LHVDjzxwcUU54xPe/pxA57Aw68mcmE8f7imoQJyKYwjtXEGPbd7X8GEwnwNSjfKpKvqfgbyqHm2BuuBpiryhVX7ixoctc+xwgptXy5HGjo/mN/fz77N6fRVI8Ugr7aYaZq8qHVNVn/EHuGh6pQ0m/uq060PLj01CUDfC2xeZGZKAPg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=H3pfvQO9+cB/K46Wp+D3nIfTv38OnX+XPqvO4fQU+jU=; b=fjIoeuQbdGNVF7Bh1Iu9eUMsifgNZocieBHcUxkaOA/h75NsDVeg08LDyPUmcFhp8KfuMC2cWR2airw0nDcrxctFMaN7+dtg7YDeBpBtsfMnu3PMX6yLJyuw2WCC9HO0/m83Jppevmcf1g+HgPdBYLxloTCQEYN3Y63MStzuLNY=
Received: from SN6PR11MB3152.namprd11.prod.outlook.com (2603:10b6:805:cd::19) by SA0PR11MB4526.namprd11.prod.outlook.com (2603:10b6:806:96::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3131.21; Thu, 25 Jun 2020 11:01:44 +0000
Received: from SN6PR11MB3152.namprd11.prod.outlook.com ([fe80::1456:1d82:4bce:7bdd]) by SN6PR11MB3152.namprd11.prod.outlook.com ([fe80::1456:1d82:4bce:7bdd%6]) with mapi id 15.20.3109.027; Thu, 25 Jun 2020 11:01:44 +0000
From: "Vengada Prasad Govindan (venggovi)" <venggovi@cisco.com>
To: "sfc@ietf.org" <sfc@ietf.org>
Thread-Topic: [sfc] IETF WG state changed for draft-ietf-sfc-proof-of-transit
Thread-Index: AdZK2SX2LrPrxvKtTuqDAc47v17FHA==
Date: Thu, 25 Jun 2020 11:01:44 +0000
Message-ID: <SN6PR11MB3152DCDD40BFF952C22F0AECCD920@SN6PR11MB3152.namprd11.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [49.205.77.176]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 6663d63f-dcc3-403d-0cda-08d818f725dc
x-ms-traffictypediagnostic: SA0PR11MB4526:
x-microsoft-antispam-prvs: <SA0PR11MB452611632F98C7D9865C5D2ECD920@SA0PR11MB4526.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-forefront-prvs: 0445A82F82
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ePru3UBm3iYf6hZjXOTANmZg8eHz3A3zKwipmteFA4juc8+zmPTRv5PzhYcB72PwZ1aTREFtp5lbleB/oyFLIdbfYO18jYfyINAYMsJrAEshsCxYWRu/X1fd0R9YsUpLEMZd8ZaFrELqgHsoGswXEHfaNrGNwyAKkmrW2zIHSoZjjBDlleq5jVxz7zk0/NGefmj9FJQCMRjjYB7ivumhOsQRZEo/HQ+bcBKvDLmLH9ZH/9DToitPBrLZKpZ9o5sLxFzC7vsrf+xKgP0//FlPd7e6IfU2Eld/YJgSHPG//C1ULUCvVceppw4zlzwfSbIS/OkCc11DCUH0JoTKQmaLcEFsEdHzXVuz/R90MSAdlolH2PdlO8OJXdvlVk2tpKvMp1eYXZafpu4i1YQQmIkVjg==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SN6PR11MB3152.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(136003)(39860400002)(366004)(346002)(376002)(396003)(33656002)(966005)(186003)(7696005)(26005)(66446008)(66946007)(2906002)(76116006)(66556008)(64756008)(66476007)(53546011)(6506007)(316002)(9686003)(52536014)(55016002)(5660300002)(478600001)(71200400001)(83380400001)(6916009)(8676002)(8936002)(86362001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: UHCvYObYgVOBglzEDespL/uBNNBA3Wo80x5OW3seEBfjmBxoZ00sAh7QNIB9ALI3jkVc5FehPyJptxRtoa1K0+1keGdt+F9++rthkerNwnhl9w0/SS3LgJqu1O1wISYzTB/4M+5xJ7lj1b5xKtkhazy2itEKX7etl1TKJpA5xBAkmPQaTR23CzNDJ9AOwPtbXIdl+4qhtKpSPxxzLgXPbfofFhEClEXTvPLhMlo2tc3B4L5sUV1ayZEP9jm5ISA9ITlsvyZtTBhbvKZ3pJsLEjxgd2MJBIr9S5tI51kVuzqx6wQ+yCEVvvKTXC/TPlwGzP3CGgmnwOCTpzhRRqEWm3d6/cLv0cL12RfOp0rziPFiZckz/3rUkSDTPEfNZFU93JmURPxp2Bhh/h4OnAnwdEWn2wO31uyXh/txZ+xi3iUNv8obNLZC7Opv+v44aNBvXOgeI1k98NGDaxXdsB6UfT2/tDVKRnT9rxuKJlZcXzg=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SN6PR11MB3152.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 6663d63f-dcc3-403d-0cda-08d818f725dc
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jun 2020 11:01:44.2582 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: rrxzNzVTqR4eP8R3f2O8KrI7aEyESVeOMA4bij+L295+4ifnMKVC/7To8U73M7Pn8r8+hDAhYNFk+zgdfTwgPA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR11MB4526
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.15, xch-rcd-005.cisco.com
X-Outbound-Node: rcdn-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/sfc/KWZ356npBS0WhmyGN54Tyj9Ylyw>
Subject: Re: [sfc] IETF WG state changed for draft-ietf-sfc-proof-of-transit
X-BeenThere: sfc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Network Service Chaining <sfc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sfc>, <mailto:sfc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sfc/>
List-Post: <mailto:sfc@ietf.org>
List-Help: <mailto:sfc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sfc>, <mailto:sfc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jun 2020 11:01:50 -0000

Hello all,

I support progressing this draft to an Experimental RFC. Please consider the following comments (mostly editorial):

1)
Not sure what is implied by the sentence below (Sec 1): 
> A particular set of nodes "to be verified" is either described by a set of shares of a single secret.  

2)
The following sentence (Sec 1) describes about controller nodes and verifier nodes. While the former's role could be easily understood, I am not sure the latter node role is clearly defined. If it does not limit the scope, we may use only one terminology or clarify the difference, if we need to refer about two roles.
> The complete secret set is only known to  the controller and a verifier node, which is typically the ultimate node on a path that performs verification.

3)
Sec 7.9.1
OLD 
 Since these schemes introduce at least additional control requirements, the selection of order verification SHOULD be configurable the Controller management interface
NEW
Since these schemes introduce at least additional control requirements, the selection of order verification SHOULD be configurable BY the Controller management interface

4)
Sec 3.2 has the words Solution Approach duplicated

5)
Not sure if there is a missing reference here (Sec: 3.3.1.3): 
> For a general way to compute the modular multiplicative inverse, see   e.g., the Euclidean algorithm.

6)
General comment: It may be helpful to either have a diagram or a pointer to a diagram pointing out the different roles like Controller, ingress node. Also I am not sure if there is text (other than the section in Security Considerations) that explains that POT should be deployed in a set of nodes under a single administrative domain.

Thanks
Prasad

> > -----Original Message-----
> > From: sfc <sfc-bounces@ietf.org> On Behalf Of Joel M. Halpern
> > Sent: Dienstag, 16. Juni 2020 15:42
> > To: sfc@ietf.org
> > Subject: Re: [sfc] IETF WG state changed for 
> > draft-ietf-sfc-proof-of-transit
> >
> > The chairs are starting the WG last call for 
> > draft-ietf-sfc-proof-of-transit.  Please reply explicitly whether 
> > you think this is ready to go to the IETF for publication as a Experimental RFC.
> > As noted below, the call runs through June 30.
> >
> > Note that silence does not imply consent, so please speak up.
> >
> > Yours,
> > Joel (& Jim)
> >
> > On 6/16/2020 9:32 AM, IETF Secretariat wrote:
> > >
> > > The IETF WG state of draft-ietf-sfc-proof-of-transit has been 
> > > changed to "In WG Last Call" from "WG Document" by Joel Halpern:
> > >
> > > https://datatracker.ietf.org/doc/draft-ietf-sfc-proof-of-transit/
> > >
> > > Comment:
> > > This starts WG last call for this document, ending June 30.
> > >
> >
> > _______________________________________________
> > sfc mailing list
> > sfc@ietf.org
> > https://www.ietf.org/mailman/listinfo/sfc