Re: [Sidrops] Robert Wilton's No Objection on draft-ietf-sidrops-ov-egress-02: (with COMMENT)

"Rob Wilton (rwilton)" <rwilton@cisco.com> Tue, 07 April 2020 08:07 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F17593A18C0; Tue, 7 Apr 2020 01:07:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.6
X-Spam-Level:
X-Spam-Status: No, score=-9.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=DglHwLp0; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=l6j2GgL8
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3nAqV2BfiK7h; Tue, 7 Apr 2020 01:07:41 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 406CE3A18BE; Tue, 7 Apr 2020 01:07:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2698; q=dns/txt; s=iport; t=1586246861; x=1587456461; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=W7/jgvBAbJUv51QncVw71vWD+G2mM0xLSlfYzKTRLWo=; b=DglHwLp0P7zxHZufYf3miM3LvwSzLuAZkGNJItswuaMNXhrqxlJw3to+ Z6z6gDnO+Uw8u9MsskkHIz/7cB+m/mN8xqqs/+qREraYqKWgsWaQLSi2D PLJf03HyKW17ATlQLWzimqFQSldoX/5zE5oz9/rW5b/Lphw5/WReIxyFH U=;
IronPort-PHdr: 9a23:KRC4XRdDm9YTRde/91G3QDJ7lGMj4e+mNxMJ6pchl7NFe7ii+JKnJkHE+PFxlwGRD57D5adCjOzb++D7VGoM7IzJkUhKcYcEFnpnwd4TgxRmBceEDUPhK/u/dTM7GNhFUndu/mqwNg5eH8OtL1A=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0A2DAD+M4xe/40NJK1mHgELHIFwC4FUUAWBRCAECyoKh1YDimdOghGYIIEugSQDVAoBAQEMAQEtAgQBAYREAoJKJDYHDgIDAQELAQEFAQEBAgEFBG2FVgyFcAEBAQECARIVEwYBATcBCwQCAQgRBAEBHxAyHQgCBA4FCBqFUAMOIAEDpHYCgTmIYoF0M4J/AQEFhTgYgg0JgTiMMxqBQT+BEUOCTT6EUINCgiyQSZB1j2QKgj2Sc4RUnAKrXAIEAgQFAg4BAQWBWQ4kgVdwFRqDClAYDY4dOIM7ilV0gSmLYi2BBAGBDwEB
X-IronPort-AV: E=Sophos;i="5.72,353,1580774400"; d="scan'208";a="749894134"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by rcdn-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 07 Apr 2020 08:07:40 +0000
Received: from XCH-ALN-003.cisco.com (xch-aln-003.cisco.com [173.36.7.13]) by alln-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id 03787e88001285 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 7 Apr 2020 08:07:40 GMT
Received: from xhs-aln-003.cisco.com (173.37.135.120) by XCH-ALN-003.cisco.com (173.36.7.13) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Tue, 7 Apr 2020 03:07:40 -0500
Received: from xhs-aln-001.cisco.com (173.37.135.118) by xhs-aln-003.cisco.com (173.37.135.120) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Tue, 7 Apr 2020 03:07:39 -0500
Received: from NAM11-BN8-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Tue, 7 Apr 2020 03:07:39 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HZM6cBZPFANDfiqD7p1Htv9Z8jzEV6CghsAU3NW6rpGf8tHTfGGtA6z7GWNoWAdnJMM0vyQh6eaEQpY7dHKruaPD0O8bCRPvpRREmbwj6VupNaUzJSN0ksAe5WuhI1T3Ept60OeBB0WnhXhZQrGip7r7J4UCFguof11xX0eygNxkGttLfRdX7CxC/zpK+kIgfH9zgScVrO6+RO9sc9CjVK8j6wxdNj98obKQK/352Q66BtgFvOhMsYvggqvTmKSOv1bKr8qoets70tR/qs0GHaxI3s8LjcByPlWCEGetD8cw5we5g8oskDHTXJt9kjn6yvI1FwmHNnwRDeNvjRtLYA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cgXEYGz471Qa+y6ETt6rB/Q2icjcchlX7IjLNPBRGwM=; b=ka2B4F5itrxaWOoNL8n7f+eusvOJ8TaoLSGmmIakVbkHDcgJ20gsvPxYI7Auv2Wo1fNh/SWZczlmR2cZp1p3pnsgFZSVFJUYrCHSoJKBMs+ihAY6eyvCw5avJUWz/61QeXr/d2UX3aRPEh75eZxVBPLqFqsD45oBhEziA7O/R56Vmvrq5k/XoiheVGzCo1RZYm3r61Bh0WnuSixlE7L5xcrbZPpQ1yD2FJIYBni6ue6jSnIf/AUbDiXsjrHL+YGg0t8HZ2pbnf4VWOPItDZ+YSF5oc52Y0vJjxnrPld7nW9WddmyD5JXPlk4Kn9S0jE1ENJVYNpEJHrWQTWs9c2h1Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cgXEYGz471Qa+y6ETt6rB/Q2icjcchlX7IjLNPBRGwM=; b=l6j2GgL8MMx7TzkpsFST6/zVUb4w6boJEyLLoUIbnbseB7c+OSW8XVgq0Gp2rSuPDh17mgB93OhK6oFZkOWuCA6NVBILdg+c1HRur/I34pioVt9Jpj/G4B0hHFMh7dwebcldTYO1g/g30ljnMU+S+nte1XY47Cy3eFxTFRN8iPM=
Received: from MN2PR11MB4366.namprd11.prod.outlook.com (2603:10b6:208:190::17) by MN2PR11MB3551.namprd11.prod.outlook.com (2603:10b6:208:ea::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2878.20; Tue, 7 Apr 2020 08:07:38 +0000
Received: from MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::3:2164:a8e2:33b3]) by MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::3:2164:a8e2:33b3%5]) with mapi id 15.20.2878.018; Tue, 7 Apr 2020 08:07:38 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: Randy Bush <randy@psg.com>
CC: "keyur@arrcus.com" <keyur@arrcus.com>, "sidrops@ietf.org" <sidrops@ietf.org>, "draft-ietf-sidrops-ov-egress@ietf.org" <draft-ietf-sidrops-ov-egress@ietf.org>, "sidrops-chairs@ietf.org" <sidrops-chairs@ietf.org>, The IESG <iesg@ietf.org>, "nathalie@ripe.net" <nathalie@ripe.net>, "warren@kumari.net" <warren@kumari.net>
Thread-Topic: Robert Wilton's No Objection on draft-ietf-sidrops-ov-egress-02: (with COMMENT)
Thread-Index: AQHWDDrtB/dYhjXXtE6Xu3DmkQLpKqhsZIeAgADo7VA=
Date: Tue, 07 Apr 2020 08:07:37 +0000
Message-ID: <MN2PR11MB4366F98509BC8EA03D8E24A6B5C30@MN2PR11MB4366.namprd11.prod.outlook.com>
References: <158619498278.23732.2401194914615255069@ietfa.amsl.com> <m2tv1wa3la.wl-randy@psg.com>
In-Reply-To: <m2tv1wa3la.wl-randy@psg.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=rwilton@cisco.com;
x-originating-ip: [82.15.79.32]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 0dd2017b-ed9a-4e14-710d-08d7dacabcc9
x-ms-traffictypediagnostic: MN2PR11MB3551:
x-microsoft-antispam-prvs: <MN2PR11MB355115C55765DD00B6A91171B5C30@MN2PR11MB3551.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:6790;
x-forefront-prvs: 036614DD9C
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4366.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(10009020)(4636009)(346002)(396003)(366004)(136003)(39860400002)(376002)(4326008)(33656002)(8676002)(9686003)(71200400001)(81156014)(86362001)(8936002)(55016002)(66946007)(76116006)(66476007)(64756008)(478600001)(52536014)(66556008)(5660300002)(2906002)(81166006)(6916009)(6506007)(7696005)(54906003)(26005)(316002)(66446008)(186003)(53546011); DIR:OUT; SFP:1101;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: JbewWapRM7DQruWAt78+AnFuZe317J17MeYGtzf4o1eLALjndJqmgaUgB5p9++XCByIn5JE/kPeg5QGoDd5UoiJMLbIX6HhK4ms02MybvJ+YjzIMkCcAFwSU54pgtqs094HNytpw8X9r72I6bYcT17eYz0yHWw2XZDSdyiVq33KFn8bR97iPaBee5nIzpOXUor/Bn8P2YTzXofogmywrLPotUu8FN610TKphZtymXh+IpnxKpKP0SOnDPKfHrjMAgV69QoK70dn5yFejAu40Al0F+mcMUTEGcqhSfWifuLcyrLgRrfpJUiApcyuAW8M3z2tW/GJdNLn3uqTJkOhgc38O9m3KM3wGDtSxlyubX6ImcxQPhSxnL0RE8TZ5vdMh/IQv/gBCoamhrpvFSaAA+E0rbkA5otnkrYmkX7vR0DoA46Inl/FoGt7RxyFhWkGa
x-ms-exchange-antispam-messagedata: Nrw1wu+w4fM7vf2Ca/w9L7IPuM33aPXhCEJwaSxi9OVUALqhH8I32sZBD2Py4C+wwl1ttYkdlsp0oVxiKaoYoiUxKG6ZkjRaju1f3QRyohtOrPgBQ8i8F6EVT8wUqVloxwG6npftcbO5DlHN8Vni5w==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 0dd2017b-ed9a-4e14-710d-08d7dacabcc9
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Apr 2020 08:07:37.9752 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: YQCi0EIumhhWmdzcjlAUbxuCLuulGbMl8PLHBxvHNtt/jbQNHh/IIaXKJ28NZPkww+7S7Xm6cSjS/gV9ELt5Rg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB3551
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.13, xch-aln-003.cisco.com
X-Outbound-Node: alln-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/VNxikMZK8wNRL8lGTek9QXjVKVs>
Subject: Re: [Sidrops] Robert Wilton's No Objection on draft-ietf-sidrops-ov-egress-02: (with COMMENT)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Apr 2020 08:07:43 -0000


> -----Original Message-----
> From: iesg <iesg-bounces@ietf.org> On Behalf Of Randy Bush
> Sent: 06 April 2020 19:09
> To: Robert Wilton via Datatracker <noreply@ietf.org>
> Cc: keyur@arrcus.com; sidrops@ietf.org; draft-ietf-sidrops-ov-
> egress@ietf.org; sidrops-chairs@ietf.org; The IESG <iesg@ietf.org>;
> nathalie@ripe.net; warren@kumari.net
> Subject: Re: Robert Wilton's No Objection on draft-ietf-sidrops-ov-egress-
> 02: (with COMMENT)
> 
> > 1) In the first sentence of the introduction: Is it really correct
> > that the "This document does not change semantics of [RFC6811]
> > RPKI-based origin validation"?  Given that the 4th paragraph in the
> > introduction then states that "This document clarifies ..."
> 
> the document adds, not modifies.
[RW] 

Okay.  Possibly pulling the 4th paragraph about updating into the first paragraph would make the document more clear as to how it is treats/updates RFC6811, but I'm also okay if you want to leave the introduction as is.


> 
> > 2) I wasn't entirely sure that section 2 (Suggested Reading) is
> > required at all, given that this is effectively what section 8.1 and
> > 8.2 is listing anyway, but equally I'm okay if the section is left in.
> 
> yes, the Suggested Reading kinda duplicates many References.  yet we still
> get requests to enumerate all the bgp features which modify AS and other
> disgusting bgp knobs.  it was hoped that a bit of rtfm would help.  there
> is an underlying problem that there are many knobs which are not in rfcs;
> and it is not clear that they are even enumerable.
> 
> > 3) The security section is terse, and I agree that this doesn't
> > introduce any new security issues.  But I was wondering if the purpose
> > of this clarification is to improve security with more reliable
> > filtering, and if so, would it be helpful to have a sentence in the
> security section that states that?
> 
>    This document does not create security considerations beyond those of
>    [RFC6811] and [RFC8481].  By facilitating more correct validation, it
>    attempts to improve BGP reliability.
[RW] 

LGTM.


> 
> i hesitated to say increses 'security', as origin validation is more
> accident reduction than a real security mechanism.  this distinction is
> too oft misunderstood.
> 
> > 1) In the first sentence of the introduction "of [RFC6811] of
> > RPKI-based origin validation" -> "of [RFC6811] RPKI-based origin
> validation"?
> 
> actually, i looked at the title of 6811, and <blush>  the text is now
> 
>     [RFC6811], BGP prefix origin validation.
> 
> thanks!
> 
> randy

Thanks,
Rob