Re: [Sidrops] [GROW] Any credence to AS_SET in the *middle* between AS_SEQUENCEs?

"Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> Thu, 21 July 2022 12:48 UTC

Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1C3BDC13194F; Thu, 21 Jul 2022 05:48:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.689
X-Spam-Level:
X-Spam-Status: No, score=-3.689 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.582, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.999, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nist.gov
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kgGSpLFi-Qw0; Thu, 21 Jul 2022 05:48:21 -0700 (PDT)
Received: from GCC02-DM3-obe.outbound.protection.outlook.com (mail-dm3gcc02on2114.outbound.protection.outlook.com [40.107.91.114]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4DC50C13195B; Thu, 21 Jul 2022 05:47:03 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RO7o4mAtIjB1rBRYjPP+NgwtIbFnq4HUSACnnKUfqr7ORdGN9OiA4Lcz0PqJBnB5ifebyiD+qLhDdi45ta5ksSOJONATvGPPHcjRkC3VigGjIuFX207U3d1a3nWB9W1H4VsAD7DDV205uQZGAZ2gGNxhowTq5bS1qx0QQJDFMYwqBaijLukEe9Ucr9kTeJDcDDg53AJBuMjuWHyVBEBu+xPuVOfU/e/Fnn1VEwJYhkEIsMeyQOeuHslqQfLicnyFM/Jgkh9fuHK1HqrY6ww1CgHDlR6lNs9V03HpGGwi1xHZZhbc7/yWO99wT0g/JTxNNeHZB3e4r5PrxUYXLNd9Gg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=2JG5jB4WAGYreTi8WqYofL6lQbomXZqShJ0lB9Sr03M=; b=lhyE1tbPATQjp+Wf0M+bxuotVZ0+0K8e4Ta6oE3WiW0uW/irLh/SFcTPW6LYLdTuhT7lsiyniUHl9KGj3cyKK6SLCIUGKmF95+2JYsj8rPUWTNnGsnevBziDKc80zquJPNU5aoZcYNqbK1I+1J/WUa0bEKcVE0geNvgmAYq2oLG7l3FINy+9QDBKE8xt7EHt8fqPo8ncSCv8pAoyDBKI/JORO1orV7xRMGbadWN1mVkVAT24uUG0iAz7TBS39ogYUTBSChMS/9SNAqFQZFDAYH7a8byUrVq00VI7EI46PXMJtfGyAp8hOeSP+3lWXtV9RZ384QA775wYrAW5mp9ZrQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nist.gov; dmarc=pass action=none header.from=nist.gov; dkim=pass header.d=nist.gov; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nist.gov; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2JG5jB4WAGYreTi8WqYofL6lQbomXZqShJ0lB9Sr03M=; b=iamzKr+fGVpCi83X9IgwYYz08XJ7PLZM3+IWXU56tuIa5rmJ4A2HNCbsAQvPQPmObVfDAWX255bah6TayB/vG7VdiSZwJQlEoYG0eVqcdQvSe+brYZv8bi8Wn38qxGxlf1HF8c33ZXEjf4iHlb/lsdOfNdDxYP7MZ9GtRrgfScQ=
Received: from SA1PR09MB8142.namprd09.prod.outlook.com (2603:10b6:806:171::8) by SA1PR09MB7389.namprd09.prod.outlook.com (2603:10b6:806:17c::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5458.19; Thu, 21 Jul 2022 12:46:59 +0000
Received: from SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::e468:3642:30f4:8f64]) by SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::e468:3642:30f4:8f64%4]) with mapi id 15.20.5438.025; Thu, 21 Jul 2022 12:46:59 +0000
From: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
To: Nick Hilliard <nick@foobar.org>, Job Snijders <job@fastly.com>
CC: GROW WG <grow@ietf.org>, "draft-ietf-sidrops-aspa-verification@ietf.org" <draft-ietf-sidrops-aspa-verification@ietf.org>, "sidrops@ietf.org" <sidrops@ietf.org>
Thread-Topic: [GROW] Any credence to AS_SET in the *middle* between AS_SEQUENCEs?
Thread-Index: AQHYm6b3nHaOc2w6EUSXBKZiVD7GSq2IgsKAgAAQ6QCAAB5/gIAADoEX
Date: Thu, 21 Jul 2022 12:46:59 +0000
Message-ID: <SA1PR09MB814208AAECEB913FA60589BC84919@SA1PR09MB8142.namprd09.prod.outlook.com>
References: <SA1PR09MB8142D357A98BFAAF206C387C848F9@SA1PR09MB8142.namprd09.prod.outlook.com> <66814cfa-8425-8063-9193-272bc8b28291@foobar.org> <CAMFGGcDRhaLVi9ESK3+C-pB7rdts2-WTKXFhMSCjuvFFGQ=Cqw@mail.gmail.com> <185958bf-ddfd-8e69-a086-a29290ec13e7@foobar.org>
In-Reply-To: <185958bf-ddfd-8e69-a086-a29290ec13e7@foobar.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
suggested_attachment_session_id: 68c49f23-18bd-9e01-4974-ad4914ab5cb6
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nist.gov;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 8e663afe-ac02-4114-2a6c-08da6b171a34
x-ms-traffictypediagnostic: SA1PR09MB7389:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: R75reo2u3ywao/gogoDxzjGyAZmCs3jO+J7gd+6l/up2FTZMVafx/TrZrkZgPotisYIbORcpqz7ju7YNvhK/TjOeah/fedwvUPhSvkLHTnhuP8z7Ij2tUJCP4YbxcpinlKLxdF9h1RDx47s3/fR/fJT4b+Pc3LpUVAJ98cls+hLvlOXJe1lhLg6SJpaUwecZ3QPpk/Nu41hsZnKQCHqzDOQiQUp+wSz+/C+M/hMLetcYQG0arUYnpA7QNYx+c3BhvZefPftG/MFy3fupV7G7JTg4pm9rx4AybFdAmLSWWHLycAisgDF1/tmfEBNMw4O8Buxom/e/+9o1TdJQZPLsd9RA+cJdFdhvnddXpmBDBwaqQXvcVdzQKrPo4sQ6WeBKHCamZcnZ6BHMPvpUb0gMAZt9NIqhJsF3GOAD19pEUe+45IuOVkRiOxfhIKbn8MLAlURsNbPyyoGbDFfMRfbr4Dhx89eg6FfmZBSTz8DhIEGGx/wR+Jd784Ykzo2peqzoqiGD/BrRaP/cD+RVoFJxf346mEHqXtqq3OWGL5ifrMcnbeCQyszZx64NfuRLJiYwBXsloWmRqHnH89CRqFdEvobvCX0vXFlmozVxbJgxZGSDDWmofZWFaCh+Fm4b6zYLyaKhTdtvJiMq0/azDhBsQPtwL8cJktGyNm/yKacESB0cHNn08ObGMSJC3EF6eG/aTfVQWUr0kkbcmgo5vB0J+UBFkxWfFGK0uVOUjGLFDAcpJG+ld+ngPGfcaPs+h1TiSwb1PwbHFvnZcoPvapKkFCK1ZerkdAPifNp2+IV/GotiXSBLEZ6V1T2grf0PIwf6
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR09MB8142.namprd09.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(366004)(38070700005)(86362001)(83380400001)(38100700002)(4326008)(54906003)(122000001)(82960400001)(64756008)(66446008)(66556008)(66946007)(66476007)(91956017)(8676002)(55016003)(2906002)(8936002)(52536014)(9686003)(5660300002)(6506007)(26005)(7696005)(186003)(110136005)(498600001)(76116006)(71200400001)(33656002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: i5GiIkhwaNoq17uV69iZz41T4xOLwgKDJx76tT9C6i1j2tCKrkR193mKiX+GMr04AOvuhQ1Q/bxKepseprXpcbovAS7tbJp/2MT7SR0Fwe2jLP+pnv+1HDp42Hq6wT4kWZrCckdlCb6816UPM6rq4wMwZaYIhVCSC7f4YYMibazFhtUZUqhQxvp0T7+G+tiSJtQKbNyyO+LLmLgh4F5lSfGHp/yo25nqv1DzrnKhSdWjk/NIhhliY9cy1LYWaYz5+aLePkqX+0PaNZnj7h2pJLTlkFN7ToJhwIdomeBWVOo5CaQPL0WJ0TVnVva6MDlIb/olfWe2f2b7DDVqGihtR9aZvmMrug+2GMTLr4XEfzaaiZ4RThBT3JEwosbrQTrgyZMsWIpIAtlVyAlz6Q15OPOkP8EvL9zN/RwfW1aK+K/A8sm2EjG70bd3zqaxxkTaEqj1G7pXDStxlZi/NWmSS3WB0mCYdzFw89/s1g7a5kJNtS1Ee2sDJalxbLg5RhtWSyMrUZPKQ/BFn+C0rFxg7bESzCfibnA11zhWT+9rH40P3JcigM0Rn1fbgy8p02oMarM3P1nRWrbb6wphO4gvDaapts8ybsoq58qCVE3M05Y6zkfm8wdF6fwXfWdGvs8WxhliSG4NxxR+sVoqbdWoyP94GHz1n3VglFclzlXVkbYY1KwqhU0qn+K1PiQbyy9mbAOpRoZJcmXuMiA8vEQh7LTYJGOU6M0KaFwN+zjA5RrhgP0KEAcxW5GlscJI89bo7jX/++BSBAszcUzcHVtH/KkAf+JLGTptNQxt/D3QsotVyY1wYjuleOMpMXErDMNC021FML4EEeUMv1+n4Uv0ltncymthS3Q2asddWmXZPI5el4SxO1QEVLrqX8XQk+265RNMwvQ3OUtE9Ep1SzxDLm0VDUnEhBlPGd0bVfPEzDXVy0osUoZ0wANGpUDusL1D24B6cASkopz1CFtd9IfFV6z7JwnF3K5nLv6gtpMF0MtZeH0yMxILmrlFuQ4kcs/ZRsRPkY6drG+n2gMcGZA7CVIUIkqyZHv/K/5pWXAnFw/3V4pMzoaAgZxWCpFpx2nVJViBc5ke2lmJMDeWUFQGG4B7fHW3vioErKJXrgnbZdwZpZ+KsKaSvE0pC7Y5Xbtb4Fuvm6IG1HjhKo+W/yo009d6kMBd0qjSyGXaeobT+6snKbjgA60A9sVptulcF1Nk2FgIvFwZwswtrlglPL9U4qtKJecfaoad1W/rSqyXZJdPZuIxoOlPxpfWHNo5wMbXTOWWAX2yHfpN7/WbI2tBN58o3HD/gkk1t2Ow8mzmP+T84jmwxpwe4HcAiTuzBp25lX9N4vdHCDYBPjGT67N8Nn8hMMjPxS2RvUR0juTLzLJJN5x6aGp238jbdyIWDx5/fN/yByAMdfjzGx/OOdGVmaearDzwhmLUuI0bACVSn22q0LrXUm5qjoQfgwpwAVvjgxq/bS5d/MqMaEm0Dqb+LG1Tp2w2xWNw5tw6zUlFncM0bST4drTAhN3/VNdhjFhX52tmlR17/z0eIagtfg8D4Uzlri472MjHDQj6IRFVcpQ=
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR09MB8142.namprd09.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8e663afe-ac02-4114-2a6c-08da6b171a34
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Jul 2022 12:46:59.4080 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR09MB7389
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/YgdgeXxFhb88e_eMv6L76Rzrn00>
Subject: Re: [Sidrops] [GROW] Any credence to AS_SET in the *middle* between AS_SEQUENCEs?
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Jul 2022 12:48:25 -0000

Hi Nick,

>Apart from the deprecation in rfc 6472, there's also rfc6907, which has
>a complex set of rules for handling routes with an origin which is an
>AS_SET.  This complexity is already not good, and of dubious practical
>use.  Replicating something similar to this in ASPA seems like a bad
>idea overall.

I am impressed and pleased you looked into rfc6907! Actually, as you know, rfc6811 is what is implemented in routers currently. And rfc6907 only enumerates use cases. I just looked at all the use cases involving AS_SETs in rfc6907 and they are completely consistent with rfc6811 or vice-versa.

I hope my previous post responding to your and Job's comments is helpful. It clarifies the design philosophy with ASPA which follows parallel principles as in RFC 6811 except for the addition of 'Unverifiable' outcome in the ASPA algorithm with potential diagnostic value. 

>The current approach in -09 of marking the route as Unverifiable seems
>reasonable.  5.3 states that "Unverifiable" SHOULD be treated as
>semantically equivalent to "Invalid".

>So yeah, why not just mark as "Invalid" and be done with it?

Like I said in the previous post: Treating an UPDATE with an AS_SET as always 'Invalid' may be reasonable and simplifies the algorithm description except the diagnostic value of the 'Unverifiable' flavor is lost. But if you feel strongly about this, the authors team can discuss this and get back.

Thanks again.

Sriram