Re: [sidr] AD Review of sidr-origin-validation-signaling-09
"John G. Scudder" <jgs@juniper.net> Wed, 30 November 2016 02:08 UTC
Return-Path: <jgs@juniper.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D2A12129407; Tue, 29 Nov 2016 18:08:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mXzhXSmvtA-Q; Tue, 29 Nov 2016 18:08:23 -0800 (PST)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0115.outbound.protection.outlook.com [104.47.38.115]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14A0D1293EC; Tue, 29 Nov 2016 18:08:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=zGSDFy+0LvB8cNes86HdY70mSyp5wrhJAHxlpNmVBqo=; b=RIDq6c9X2kwV9kYEUK62WFvKiKddk8PNu06c0iu2Cjw8QHi63M4J80uFjcqmBsXvdXkOcyfJNtzOZnTrfYmInDup5+Ouycx4/yXJXmxLoq9wqXOwq1fqfLdzHGWl+Py4dGRy7UmUJQedTH4ShRcJ3VJNg++UNWZsfWQnpkSoWek=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=jgs@juniper.net;
Received: from [172.29.33.83] (66.129.241.12) by CO2PR05MB2501.namprd05.prod.outlook.com (10.166.95.147) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.761.5; Wed, 30 Nov 2016 02:08:19 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: "John G. Scudder" <jgs@juniper.net>
In-Reply-To: <yj9od1hdrah8.wl%morrowc@ops-netman.net>
Date: Tue, 29 Nov 2016 21:08:11 -0500
Content-Transfer-Encoding: quoted-printable
Message-ID: <F173D66B-3A4F-4C96-BFE2-02D83D8EB17B@juniper.net>
References: <88A45E79-880B-4F82-9FAA-80C05627A49F@cisco.com> <917E9000-8F1F-4E4F-BDEC-767E3510A71A@juniper.net> <yj9od1hdrah8.wl%morrowc@ops-netman.net>
To: Chris Morrow <morrowc@ops-netman.net>
X-Mailer: Apple Mail (2.3124)
X-Originating-IP: [66.129.241.12]
X-ClientProxiedBy: BLUPR17CA0013.namprd17.prod.outlook.com (10.164.14.151) To CO2PR05MB2501.namprd05.prod.outlook.com (10.166.95.147)
X-MS-Office365-Filtering-Correlation-Id: be994d4e-463f-443e-bf8e-08d418c5c1ce
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:CO2PR05MB2501;
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 3:+X6AGuE7qqo0Vm5PvcC3urQVg27GF24ZPyGL8U65JG4VDs4kBhE+qiF0aV9saqnqcoecN4RxVZqLMzx0rm/H+bmGjR1KUrGgzekxL7d1g8YMxAzmNtmJwr7dPqs8klP9FrB7kJ9Il4/leM6Hidcot+pGAVhOovYvVSgVJv/c9h7Keq4SBk/s5ZU/wfkD72LTbrnmZXaYS81FqxJz7ou0SkGskQmcmV7MABpb440dqCmGyPGwpOdzZY2GQLhB5VyKuuzXFkxqIc+2HPo+2C3QYA==; 25:ilkK+Qk2uYThmxocyk/upjU7TT+NbrSvGlYKQIWg2Q/0AIFcoMiEmQQF/66Lb9iDzqsZu9LnJfmNinNT4Uxrn039ibR5goBI/E4b4uQHwnJMtDiEPDxfldvvOFjT3pJZ/L7ZpydKo8rOg6mG5WOlXMSksHxri45kJyEYqBHCqdf6+tk0d91/4xGgpyaeufdCr6mfagwFvOHIU+1JMA9+XYKh6ia1XuieFhKWIqrSV4uigI1Tver2yeaYeaSyv2b0Vor11bnLN3aH2i2bprvn7gpbRZ5735t8Hj906UktgmJsjVOSa5IsMGnHBsqnKo27X1l+MZa54nVPhaz8jlhbgRYPtCacA9c1ssEbdDtGhe4QlDyoLAr5wugSwX4tLz8X+Rnq8R2oXybKL7F1WabMykG4k493hYZ/gOIjpH+sQltmdlGvegJuSx3RncVubXKPhu8TtlXU3ZPLTuaVHQTSMg==
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 31:Ha0EGy+dV2ofpCJAu+gproqfh+FV8eq8TmX18swrUfEh+VhN6kS/yHt7f03NOqResjtA5Czoy/R9r9mImgoLdLyjlejNsQScSpnpsan+ISDNOAniGpnoZ/wqwX79ywf0uj6PL5eMa28QbEe2F/RpS7Z7wFeSbimAJ9biWQMrHzSTLAX4THQlntDMlwXeyNSxATokArY5iPNjI/fZXfZ39Hy5zX7d82telVvLxUoAOPFsrParMyfKEm25vexdV37yUjHCog9z/jHESpiKgUqXZNSJjs8Bcd8BPInrzFrkIj8=; 20:f9x4QOhTLXjxts8hA5Y6Ijp0NX/ZjqijgSZoUUEBv6+BjgkjcDWOlZZ7qkUtFnc2wEoJU025JInEx50FfVJHierQuSsdd8jcZAHTYzlJvzA6AyL7PaglMJHh/czVXKSChU+jWsDGQJ7HK1eAHJ1ZnDUwPFX9743YnqlQavazkXfgrXLVE/Huj6lDAb6+s1UJz0RJYzXrrGL8cmvltT1dA5PwGiIMJ79PDNutL9IKInDCs1LT39kit4CHh/51Lsc4OO0hfVoZ/asADi4MDG+k6rx8E5ekmD2C3u0acPhVnapCC6ID0ihyzW837cHAAytRsgFI/RzHEEyBouMdlnyapc+zXDGhXWK/eBpZFQmUtlMcg8crGgXZ+FNtdU509MvAxomizNVBpl0gEmJw7Chrqsiylp/bRy2RyOLuD9oCAEr1Sc5X+x3TZ9+C14E+iBIIF/9V58a0uHIB/N3rpb5qYM3y/fZCPWaBq+W0ANpLKyqMpHWJcJ06yMc/LXGHCAbM0vAqM/WY9cB11QDjeFoPpJrf0tuKZ+tXcGiEZDGeazdL2rgQ1qM3ujNYo+17EmnIpdEmsg/OlR8yCyAFiC6PW7JUGx4/UlV13OldsatwRVE=
X-Microsoft-Antispam-PRVS: <CO2PR05MB2501124BD064D885584F9555AA8C0@CO2PR05MB2501.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(6055026)(6041248)(20161123560025)(20161123562025)(20161123555025)(20161123564025)(6072148); SRVR:CO2PR05MB2501; BCL:0; PCL:0; RULEID:; SRVR:CO2PR05MB2501;
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 4:iJf1Ck5BxGi6n81p84QIgkHqh8z0a87v/6isxTA4jggVF3KHGj0OIeM1VgdvKxgvJT2AjDZtHfvGRP+lwSA4c4cji82SpuDDL8xj5cb4FOiS+YHU3weMcrF6qJkjL0uok0gvcx38ncYDiPKSSQ4D9sEomeLvd2Tu7Ljmed1ATEy6hgoOLthmsZjoFo5Z1xXunHK5ibTQJnUQhA0kryM7mJENEJX95/hDHPPMiYhzzC+W3Y7G2Z3VSHqsOt3LnIJNnO6Tk+eHFVb3wpn3vXh97jTKqXTvnJgFcrZWdO3gJJ1f2VJwpmn3uDG/ozeWl4KwVw391Yz1z6x2cXNs22tvjAs13EIpODlPr928DX/ANXohvUnd4PK+DPA80xNe+do+9qqjSmrm1j7uKHSfZwMsMDtW/tVKmKJ7BjABDwILEa/y2Ag6TacGusrIacpx5za7D1Inc/VDBSoZdz/qDcXs2coUUc+EClKeKlyVURta2ESAd5cYStmVRIb074SNxqwOOMBzh//KdTnWtkfxnaCCiDKpDaZTLNXpW2nFdbynRV1GPOLwVtszmVbhxPgr0/mbyWZjNhkI68rMlQhCTvVaJg==
X-Forefront-PRVS: 0142F22657
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(6049001)(7916002)(199003)(377454003)(24454002)(189002)(76176999)(57306001)(229853002)(82746002)(38730400001)(101416001)(6116002)(23726003)(3846002)(86362001)(50986999)(66066001)(97756001)(8676002)(81156014)(47776003)(110136003)(189998001)(6916009)(5660300001)(2950100002)(6666003)(68736007)(50226002)(50466002)(230783001)(81166006)(77096006)(733004)(6486002)(46406003)(39450400002)(42186005)(39410400001)(92566002)(105586002)(8746002)(97736004)(106356001)(305945005)(4326007)(83716003)(2906002)(7736002)(36756003)(33656002)(7846002)(104396002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:CO2PR05MB2501; H:[172.29.33.83]; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
Received-SPF: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 23:XXWle5cTBi6I2Q2J8S6dQk/nR3h/e6jlsCqQwdWVynvvfeWZEBz+6cMY+ddKaxS6GxA2GJVVeUi9b5tLKzckGhihVh0zNtssV2AophyqWVvwDBFNbkJ7PjC7cla3Umzd3zEMCkhEzZ8rrnwzDSLbX2SPXmIqKvkSTheFWKAQGVMuCmVOCLY5uCddQ/OTMeGxHrVkAqTbcZRyRsUfTZcoWqPklHS2ox3ovW2iEMIO9TsXXi0th6tPrw0hpowbmsKu13sPMQMAx/crB1NSEL1codx1Aaa+1NKJMfsqUauL4t3X7nm5pqa2OCgbSvVJWJS5+vJApkyXPc0zBNMZM4UgBt+TVxVe/I00j7Td0eUxH/V7QqbBgyh/BJdxEpHMfjb+v4+Y1ZfKNAWVr9u+D7eAQe491rjOmvaDZLZGOVyzpsdYwttRHbQUmvnzqsoExyBhnHBxS6QMwVpECAWoMD/+KwvrlQaWaAvqK0gt6wo+iWQcDi26gdp4OrUE5/c2a+tb87bbQS6w0wI46ejVxBzV+uHAChGPrW6pvDps1FWeKazlXgyknSLoVCvyAXLhAaCaUzk6z/1O+G7CnwQ885oxWZ7IEOaKmXW0m7Y6gewzysRx9rpBxNW32a38Iji2cfnp+tpJNziVy2bCAa4Gf9fUWWtLzVn4GkFUWtRQy0uYiN5GUzbA7Pv1M9Hx3lZVYHHcE5z2s6tBvqAkY7t45sYMO7DGWPoIAvjdSf3K8Nnhp/1uJCUptb3JG95ORVdmCl2zKZe5+s6k+diC3F78ufW3o9Nr09JocwtLFJr+jtA+mzEeB76sXhtLyJTRCmNzqb3m02b6gm274LH5aw+F/70xdlZLfSSPZdz5jpYB6sTIKQVjYYXRwxbbBgf/V46MuOZVkl0RAMRkUOtrKyfw7ACY8famHgrhgb32WrQIWAwDihDkpLhrqTW1vTpvDXMkFu75su7k2o+Q01iOGsB64zlHGYf8a5CjcJgc1WIQXGsI4Is4zSwryvJLrUxid5PX2W6DHp9UbMrVgI51yJpVnWYK871DRoFzhVsekw4olnObqauCICfPbKd93pMvk6qpBa+8ssCRnqJmKzwF6pcBRkhJiyFd+XvQ7SIdCPd852haTM7Dzd38SoZQk9JEUjAsES1LRUh0PB80VElnypa8CBLrzLJ+9tDvy627TP5bvCpdy5c6IRxV4kuimEts2nQ80wcLmSscUl83AaaI3C0ALEnPpg5UPE+yhy3XpYbwHGLEmQBCq8Cu+SAKNSXKv6UlWLCTx3cYFtVH09c4s65hzGigwnDCtG+2ajW/xsmwKpYhN+yZ/QnPy3iUcu32k38dFCXZ
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 6:Yol9O9YACs0u9MyuOwQbHyXIqveMpfM7IvMLTheP71nQTfzwpuMe6QCnCQ5yYkWXBrAFxC0I2Ag/HE16ZPt93gCS9qAklraxKXiDH8MdkguNsksLxQ2mwD9TQOUcADzdDyxpsUUGGlAjHl+BtONbB10CI16rRlblWPtNQ9UXgfLJ0gF4NXecf34aPJqyqwjuCYNseN+lO/GWMBF5lqhNJB7N81kAXuhElfBrCvOn3r1mofgmOzQd6mOMbNAC4sov4Fhrl/Eo27vvbUcibVK0cbIZg80U69vpzRWg5Sm0JDIWZQJYdEMKEcEOqnwIf+Y10DGwUvrSmT6cgPbOsYixBN7+DHTT9IwFGwXfGBsz0VgdC4bCsLjRd32KHMmSPj9KCEe/9NmY5qLy31IoCIXfk8Lljz8rezYX45FT98RcMPXQ6OSS/8H785krRqm/PL1ZSPdVOVXGVYvmw46Nf2a8LwohTULKxLG/vUAo8wNw7RXvCpRj6vEpAx3DTar6CUdr; 5:1WeQL98eaWEdnnWTQoD7FyxlDyEV2qCoY0FK2gVRAPDb3mjPdS4X7BddPN4oY2fHAEULgFD9xDtoKJc3O+Q4F2D8JJbVFir4EMLM4YBS6kJFyiTfP7smtq/51jr2NH3MFDeymabkYEimwxMzyVuE/Q==; 24:aTcikBV/mtxpyfIBezITYRnMZGGmPhD12p+lyfr2wp1IVena3PHCvBmPwaW2Wbpn68P3iGSAyc0XNRHBs9Pw7w9RL/Tt9b6C1kHb1j4BY04=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; CO2PR05MB2501; 7:xmuZfwnDn808Af1BVXOolsqO0D1F+RFh4evtIvwjuF2m57b8IkHiBYeyDxhZ7C+bHEQVleLTCoqcITaqwGfSOTBWuecwog3T1eY6xguZOHeLAfC8teUMWZLsuOGViYgPRL8BfsUYi9eXNRKyXgtxy61ll5jEp3pA86DUUwmFkGboxL9199QBqcqFifWqdlnFYV9HgUgdzZbF3+muegwJZcYd3U1toGMCQK0/EOFroEFaXedQFXsEoWtFTDIp6OCA4ykn4wTRQiRF1xC0Bdrx4VjmL+C5P7d9eOFHSmmODxG6Kbcf2CQGpF6K/eJwql6/bDlZiyb1RClnaEyut7qODY75zjbWgV9SYgks7pbU/xcwLD8WMICCQVHYn54aKd2WJwEmieROhsLmL4wRSs0HgWS5SrEy94U6vMl1NiBUq66P39psz05YW7QlATIiplwRsu3JmSTDKa7JxhXnSEyvdQ==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Nov 2016 02:08:19.3398 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO2PR05MB2501
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidr/EjLb87p9Y4A59U863qppeburTps>
Cc: "sidr@ietf.org" <sidr@ietf.org>, "sidr-chairs@ietf.org" <sidr-chairs@ietf.org>, "draft-ietf-sidr-origin-validation-signaling@ietf.org" <draft-ietf-sidr-origin-validation-signaling@ietf.org>, "Sandra L. Murphy" <sandy@tislabs.com>
Subject: Re: [sidr] AD Review of sidr-origin-validation-signaling-09
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Nov 2016 02:08:25 -0000
On Nov 29, 2016, at 9:02 PM, Chris Morrow <morrowc@ops-netman.net> wrote: > Of course, just wiping out the prefixes in flight Right, exactly. The OV "attack" is just a baroque version of underclaiming, only it's an inferior version because there's a greater audit trail. > and stitching back > together the tcp session... same effect. Not sure why you have to stitch back together the TCP session? I thought you were supposing the "attacker" was the edge node, it can just apply an export policy towards the core. --John
- [sidr] AD Review of sidr-origin-validation-signal… Alvaro Retana (aretana)
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush
- Re: [sidr] AD Review of sidr-origin-validation-si… Alvaro Retana (aretana)
- Re: [sidr] AD Review of sidr-origin-validation-si… John G. Scudder
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush
- Re: [sidr] AD Review of sidr-origin-validation-si… Chris Morrow
- Re: [sidr] AD Review of sidr-origin-validation-si… John G. Scudder
- Re: [sidr] AD Review of sidr-origin-validation-si… Chris Morrow
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush
- Re: [sidr] AD Review of sidr-origin-validation-si… John G. Scudder
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush
- Re: [sidr] AD Review of sidr-origin-validation-si… Chris Morrow
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush
- Re: [sidr] AD Review of sidr-origin-validation-si… John G. Scudder
- Re: [sidr] AD Review of sidr-origin-validation-si… Alvaro Retana (aretana)
- Re: [sidr] AD Review of sidr-origin-validation-si… Randy Bush