Re: [sidr] AD Review of sidr-origin-validation-signaling-09

"John G. Scudder" <jgs@juniper.net> Wed, 30 November 2016 14:07 UTC

Return-Path: <jgs@juniper.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C1FC129573 for <sidr@ietfa.amsl.com>; Wed, 30 Nov 2016 06:07:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zC-5eInKfFlE for <sidr@ietfa.amsl.com>; Wed, 30 Nov 2016 06:07:26 -0800 (PST)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0135.outbound.protection.outlook.com [104.47.34.135]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A35321298B9 for <sidr@ietf.org>; Wed, 30 Nov 2016 06:06:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=nKK3YJQvvEnZT+pqjDMCVTT3D4cAVzwDsb/vNO0sffM=; b=MXG8b09h+PjPiW/pUF2a/yskt9CyXCJD11M0HqWq+8EefVi632WqqsYMf/mD5Pu2BRfrKg8DNYlrFDezL1aRJOXo0ejSB9hCKuwfVMqn1wM+jwMLgc7z/Z+pNlyMTiyFLpbgo1GBjCTWzsw4jQX5aEvpi7YUIuJFrQJb+Y+4/Pc=
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=jgs@juniper.net;
Received: from [172.29.33.83] (66.129.241.12) by SN2PR05MB2510.namprd05.prod.outlook.com (10.166.213.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.761.5; Wed, 30 Nov 2016 14:06:28 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: "John G. Scudder" <jgs@juniper.net>
In-Reply-To: <m260n5hywb.wl-randy@psg.com>
Date: Wed, 30 Nov 2016 09:06:21 -0500
Content-Transfer-Encoding: quoted-printable
Message-ID: <1E8CFD67-61BA-4CD3-8A96-CF38D283BD08@juniper.net>
References: <88A45E79-880B-4F82-9FAA-80C05627A49F@cisco.com> <917E9000-8F1F-4E4F-BDEC-767E3510A71A@juniper.net> <yj9od1hdrah8.wl%morrowc@ops-netman.net> <F173D66B-3A4F-4C96-BFE2-02D83D8EB17B@juniper.net> <yj9oa8chr6to.wl%morrowc@ops-netman.net> <m260n5hywb.wl-randy@psg.com>
To: Randy Bush <randy@psg.com>
X-Mailer: Apple Mail (2.3124)
X-Originating-IP: [66.129.241.12]
X-ClientProxiedBy: DM3PR13CA0005.namprd13.prod.outlook.com (10.164.193.15) To SN2PR05MB2510.namprd05.prod.outlook.com (10.166.213.19)
X-MS-Office365-Filtering-Correlation-Id: 78ca20aa-a4b3-4c30-2633-08d4192a14fd
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:SN2PR05MB2510;
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 3:lneUAFILZtcGxgbHoqc1llwEhD1z3K1eK9R1ZlPdcdG+gYg3rlvX2lhvLWCFln3Oi+8gPluIWjkwemhhjPVYwtxHX0jCj4Os9gZcFtJv0qsYFXPcAZk2F86awXC4P8hdaRPqBfjOvlt3xRJjB3X4EWReLDCrDJFalkh7+hf4sY98AB7qGE4jzzezLuRyAa9ginrkQ4uBLCPyVJLs/60PIPccuqFW3O/4PzNk1G7/U3/jrTDH35MEjpzthgb1doVZv8pbJ4iEnsMBoNYdYxqSvA==
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 25:UjRL4XyKfOUT5we9LN56XipgFLDB9K8NwlLlhg+IJMfqxf6UoASHT1Ny+K9h3fl4ivoh/bUcoCFxL+w46YB6zHP++kdOPT4zrgT7ugOaoa5zwGKLAgLEhluFBcVoBfblh8WT2fqrifHVQGMGUOeZNg6DJg98Vv5JPMyzsJH9Z6AWTqCqi1eMA3XzezJdL/8XT7vNfeVNh3eFrQMOnx8L1y39AzPCO4TJ1jRIfW09ZVJs49jhwK9lbK/yCP12Z6XaKuk9CEBieufx14XXNgwU083L5bb9Z1Nw8ehaAd2tkvS2bJrBewLKlHf6QKXVLkeSDK+1l/cE1VH1GK4/Aj7wfTIBjL720hbJJYOiDUBd4gnWT6s94SUDUTIx4Gbs9BEXJks1YhH3DMiGubrQ3hqCioGOMU/tFXhWCRZAtvRRbkLfPifIMkb+oNRSFwaPSTmouls2xGMsX2AO0QRX4/8zNtL8mmA+Ebyp1YcZIyY8qcfxpRpjBqv4not9vqX0F27R5D2+FuAzfRe7NCg+qO0FqqKzYYtHPTbhPwJLfzW/HUCQeb34CiTONwuT6nRjjwM81X5PiJALRnoeshfONF684WvlkzXvXliiiLx039joaApmv31M7io40EVBWZEnjxUI4yVRMrgsDsRJP2tuv8UVQ2hCKiKojueabyO/cKfVGM6+pcEjB9y79HeMhD59F2qWg5+H4VtZrQZXHEWpBtO4fxJ9ipRS6TSn38SrmXr3LMTKmqTGMI9qZ/INVdDRfHAvPbX5LUkh+O6NEXwpPJmLZSvKaSHEHMiZLr6tHFmP1oc=
X-LD-Processed: bea78b3c-4cdb-4130-854a-1d193232e5f4,ExtAddr
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 31:unPNcNCisYvKyJ914dJpaPPGVrSXG6JLSTzyyuUicS67RIRr5Arqfjr6dVXm5nK2+i2VyMYSpTaHzvGY6GsT6CrAyesU3fG3YJPqQ5RskrKwfkDrexSiS1vnrN/jmst1/kD6hcilysYgVFXHOfV2r0Ujx/vnA2hNRRETWh+fIX8o/Ur4laCh2JG2vHRHcr+WeMZEEQorEmzKeC/xQbXYpwxelTdMtY2Pi7Kvlh70BJojFg4hLr2egGGxsi4NbGD75NsokC88F2N4ucMG1sModceIT3b8yHK9Cwgm3LLHfb4=; 20:lZU41YRyHDALvFDL4ZFciAxfdLxULf8hg0TDxJ6MdQs4N3YbtwwITDHdxl2BWRtU6GYN0bDXq4Vr7BrfO+VY8DV/fuRHm5jfbS8eEVQR/JkA2gA5T2GvME1CKbNiVlr+vCcA/u3o94NfMg51Oj/kPyUPS9Uhn+jr8M4WWeMnm9wC5JjselYApnPLNInc0qIEUQYJ33OR7UUwQw61FLbYgwwaicWgzANKRAG2e5omBQbpd+OhPX1aB1bTnsk+l2w4io1+dv9wsRJKCp4DudABK1aiiPIOXKYr+EUSrwxKtfwlErFlm7+d29aioinKtMQoy6FnPAUjeDf9abRMAZnFwB3wRD2lwd5KobjkpOaFhRDYcp7RPS61VeA0S1dFOXhl4YU576pg0uDlQdZPt6rMed1jIJOvrX1oS6kjUjnYagj3sac3DgIkS4dxIVwdm19VgISK8YD/jJNvWTO5NJiVnSXwEiXwgh+bETDXh1e7wJIXZPStyNtEuK2Q89oD5Zg4H4y+1ZzRehyRUilYTRO+ic8blOR8pBnB94v8VU3yr4YoRNqm3sPdVtc4VSX1J5dBfcy/HV9Ewr5EJi2twUOhUOECnTXpBnTHAUxjAbaJFxE=
X-Microsoft-Antispam-PRVS: <SN2PR05MB2510704D44AA6135E1A1B9EBAA8C0@SN2PR05MB2510.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6055026)(6041248)(20161123558021)(20161123564025)(20161123560025)(20161123555025)(20161123562025)(6072148); SRVR:SN2PR05MB2510; BCL:0; PCL:0; RULEID:; SRVR:SN2PR05MB2510;
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 4:CDwIyczbRrT/HXFwFx3KpqT7lpu2VaLRzNmB13a6P6/ijo5dcmopZ84jglWUcJoPH41923i/i8PBVn0LEdFSpzEZWeS4/DjF97IwyGaD2J1WD1gfI5Q/GNl/OGn5rXVNCqSnhByQQE9hHzYkITDEdF5NHanad//xHso5GbzXF2QY1pZrTc24V137nCgmrGnOFVM4V2oZv1zkS1CC80STAggwPKBAvGnDUwSln5YXURk3kDmbR0pUk25Phe+YsIpd7X5F5+0tuUyhXyr68RbcXbXfeUB3slMIfW1jgsl1x5KOfz5Zar7jCl/SDg0z7NbUwrcODhaQyb5kMThO+7ZOQC6Utvg6KLzzcT/fyU4WE6Y8qZVomNQZO67ivAm++wwvGE6OAYHsgvbbaF/2XJ+KKr18f6RKQ6SSr4PDDjDmanMxR3stT7BA/AMP3UUePfltnx+q3Q9WlQmpWBjPxvBkhI0U5Peh/GACCutLnY0P5/hVuJnxIhFGS3iPuCN1OXZjoNi9fN8VmfNBgdZXsT61m9fSy60MT/nVcZhzCYHkRc7xrvpiQkGq+R2HCv+AE+8ERGhwEgaTiyWk/XQxDQctEU1t4+DGcilpDbws99sL2Dwuh0zN2H6Khi5bAiaLITLt
X-Forefront-PRVS: 0142F22657
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(6049001)(7916002)(199003)(377454003)(24454002)(189002)(77096006)(39410400001)(82746002)(46406003)(97756001)(38730400001)(97736004)(81166006)(8746002)(83716003)(8676002)(81156014)(50226002)(6666003)(50466002)(23726003)(47776003)(57306001)(68736007)(93886004)(3846002)(6116002)(2906002)(230783001)(6486002)(86362001)(2950100002)(110136003)(7736002)(7846002)(66066001)(4326007)(6916009)(42186005)(305945005)(33656002)(5660300001)(92566002)(189998001)(50986999)(36756003)(105586002)(101416001)(733004)(229853002)(106356001)(76176999)(39450400002)(42262002)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:SN2PR05MB2510; H:[172.29.33.83]; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
Received-SPF: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 23:YwYFCLacQqYCqJBd05Bz+Q5U6DeltUuZ13isv+Cb8jyq8Ub33V7Wfve9cSOD+KIYtnh/0fh8M17GF9BCZVG3POgLXRUV0cTLEw2uKONX115fVHQbgX7EnLtlTjTqlTw5dbqcM56ybaPeJnRuWIqBLhvU4o43eVE/wENNgjYEPeUJCoiqhblLgfRu8lrYpXwDQwSQNrADIitjuVtELp8DuhBxybqcIBx4hlj+sfYW8ne1F2C2ydQKO+Jh79Usk6UHHSEO9BukFoOryoGNnEwsTE2PQOFbHkHXrD0NjCQtN4vJD9bF4OLGfG4u0wc4+YR3vX69bhb+5BUw2L8jbc8KugjJSgWcol3CnKoqThreIE7hRkho/nPC9PaFliWQT2giUZZye/Jl45i/kc5icBX4z2wf3wPECbV5xI/rsc2w24Qv1RsyuuE8o5AUOYAiH6MsrRDmoI9lN7sEyRwvmhqSBTD0LEsnorc3BpvXYnXKiGT6cwsGsji7sO9hwMPAuq9f77XwV3A7nEbbmBQP4/QCZKdfQjdp2a+f+ZKOrFCRha71bjSJvU/0uxlM4ExRW9BrCYwta04gD2Oc2lKDKrVQRdCyLJe5U1uW6Sb4pefNtT6tQJVGHiej/6GD7jP2Ox0pu7HGjOu5k+ah5R4av6KHg7PbqAhuOrw58fnkY+B0jvHeZdOTCa67MdysJo/h2y9mENKkuIUZ0K9R9ra+EQ603jg9L5eqJgSsspBZfaawkFe7hq5wYWl6qNs2NRtaAokNMOuptqZ/sS5PhFR/Ex4SOOW5+7QrFhdmFm5CnhpqeNtwUcVsQdgYs8xqOC4yAr6i4JSfXWOKNrinTEhqiAsF/Qzuo27VKwm28Ga+GNo9EHJ6SjJN5/3SoNX1HAkRofZ0yGVautty4gDr5XYIouyL1H+nfu908U5PGsS33dAF8dvwAkfLXi46Gaed+Cwgyqr/MggStoTuWJoqlnVnUI82HGCOafmuPnChYjq4QflLDk+xto8xSojxjy74iuAAnb4MbT2oRhVSRG9TFHrxL8DRw8beosV3Bo4jcjI6zuS0FSI0niFayndO17EKlIt+sZGnUXktVy2bqw1hfmFyoP/AAe6+uJRnJSuycKhBr82MwBZ2VOpKSEygEbzoze3T1zKb6IH1qFZBHIMvMmKAsrX7va/sJi+Ui8bbWJWjHtjIrCUXFu2ezMuv7b3XD9Z+sXtGkJRc4QY7fKPinALY+eOZ7h3t0i9EokUwFaNkAf3zPj0ai23h9STaSH+ey6v/vixEPEQuNotEA/oPa9O4VrR8dr1bXJ/OkBX2PDzfkSEhfwidk7d5ZwvdEm/LUwGwHEhY2jFi6WQFjJ2l5LQbLIfD9A==
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 6:kyJqWy15/zFUscrlATCZTbs31m+Nv+VUc9VwpIQMFY2hTqlWRhgMznPDHi+ADCfG8BIP5SkyiQQZnFNeEXeyihxtwq0QPZuo7rAfdv/17MEwvaeKR36d3yROq20/UXx0rBhm3MHfGkLwZzC2XOCK7cPmAEqw0sKEmxF0XZCuoLcCKGkhyeTrs3sfqxnV9bqqiygIbQytaPRKRSRwTUFJCBsZuTTlMpPJhO4ie3PmHPRFRsaUuRWLyZK8jsORtILHqF5PQjkEaxN749BxuhCO1YLc8jCxSXy+pvVLIUYEBsfQv1qxj+3fbwgfXfi9/gAKXOLf8nxmMAKVjHX1u6u21yCpPvR7pmSCAfa6Ma118dBtQbub2KPf/yUWhIwr3Tuw5PfBSgYCf6xwrQ9wE/3Dx3+tBHLswf+/6XIP2pOttNBuTzCYMK6H6oNMs90YbqvNf6M6105TLtv7QBDbzu4BIYbVJFWVFQ0Ju2DR/BFC5uKmQeK2D805A42lgq9wQG6j; 5:cjuZeUSjOWx3k42vNS5BTGXYsZh6CYs2R1Yk1cIarSYcbeWlKeveDF7d80dFt/Gm2H+7bi5Vtl4UeyXhFNXigVe+MEZ6VLGmohuKI5+oQ0pxZYkxn2CQ2RnLPXXg/Cw1XXcuOKcMKz+/G5kR09sMUg==; 24:vNQMOFNuwGlh1E6dJUHtlqbt/Mgxe70KK5NQ0Dqti8DFCg++rRUjWyPDiJEznIsVpTSabeloh6lskSc93m09f1Lx5bm2g8WNbm9Hl5JZKr0=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; SN2PR05MB2510; 7:EWdAcHdDifrz2xbw+t1AXjU22whgoF0L7DBuJqpNCCxW4uzAGQ/otZzkhcFWFk8dcyFsViXww6DCnYN8pDL6KvNQ/HRbP36sR8NHY1W5uB6e8XXq06ZWUGSgs+Gmj18Ahv6jpcPiBbGaEbjKjJUXYXUOosp9UG6k2LGcEOF8tsYFrbY/F3JJtf7H2FPRoBFidq9PhjK5u94Mtdpsg7XA7DNd7iOyNHpknk9mXsZJ+QdK2W9WnR08kXDNW1YrRJsq1BY/8QJhcPS6C06FJQsjUJNdDEb1hELZ4X8rBmep76PmvFptOtPxJq7l+nk1FYRVRwhLfw2+9rnDAAm//aV6uhKs0KJSQ1+ZNutPf9Tu3eZkwYD3FijMcshIRb9LBemd+odlCi55BG3/blZoN7QdSI96ebjpcKLI7jzequME529DIY/o+Sz5WvMw58ZYOos7IlXWSU6vvSmxzJB/0T6OAg==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Nov 2016 14:06:28.9581 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN2PR05MB2510
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidr/cdZtzQRDDCBEmJQV1AcmaXRBcpk>
Cc: Chris Morrow <morrowc@ops-netman.net>, sidr wg list <sidr@ietf.org>
Subject: Re: [sidr] AD Review of sidr-origin-validation-signaling-09
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidr/>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Nov 2016 14:07:35 -0000

On Nov 30, 2016, at 8:37 AM, Randy Bush <randy@psg.com> wrote:
> the point is the tcp 'stream' does not have to be hacked in any way.
> the hack is at a layer above.

I agree. I also agree with your earlier

On Nov 29, 2016, at 8:40 PM, Randy Bush <randy@psg.com> wrote:
> none of this is new. 

I guess I will wait for Alvaro to answer, but so far I'm not seeing the need for anything more than a couple lines that remind the reader of the basic (in)security properties of BGP, maybe an RFC 4272 reference.

--John