Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

"Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> Fri, 09 June 2023 23:07 UTC

Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DFA13C151547; Fri, 9 Jun 2023 16:07:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=nist.gov
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UKrUzu63kc_j; Fri, 9 Jun 2023 16:07:06 -0700 (PDT)
Received: from GCC02-BL0-obe.outbound.protection.outlook.com (mail-bl0gcc02on20712.outbound.protection.outlook.com [IPv6:2a01:111:f400:7d05::712]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B1AAC151556; Fri, 9 Jun 2023 16:07:06 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=N5Ejxt5ZLQXzMed5XXi9QC/xDzFNCtf/fTlAR0lzC/UDOMHLTTgKie9GT7CRQTIYdBQG5rSMzuWGhhFsK3OFM3NWjbYEgDsKOImOhaC3K7CibVYx00pbA919p4uo+5wfNPY19u9DkTXKmZXo7q1kzFYhFVfIy6LNkh42W55l7jL+A76YTV7cx5uPXVVw+s2dwIVTxaK4uGp9/1/7cKGOT5JJDvC6P77yjyymreNNBsFWMXMWunFErIKv7K+fpErkt3lQPbcVZ3tnuyMTKYRGBzItwWeeeJPT2fbzlpfxi9rKrdsKx8MHQvwk3bDE8i9VvPPh0FJcQGliHHDkTTRaoQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=D/Gm3UsESo3SxUyWqFR0GsSQjYO35Orf02XYx4l80gs=; b=U0N/XoFiKf2sj1jFIQXf1XIfu4mVA7xqaKNhLG7py36Tcm+sI9AP9ISC3T1uoskYW/As0txrq091MS3NYPbWuEeEs2QRDMyXRfocI8Qi0QbAtmtOb1xarMx3n489vzCct2G/c5USLewdLFvW2Q1JQo0QoFvq8DAUVVZPJIKBUrB80KxR0VCBk108HASTDtWQCUlgPEEb3jblpA7O0gbSoNvL/IcpKQ7MnUyHzFOky79W9e3h9/YmhqTk1PjIuZq4aZ1hYmHkK4ZGbwVMq1eQ1WrJR2JagjR4YQQrSYKJNZ1VUyu38VpzfPERDe3rTXKAeEoYsJJhaQo74GbMHrbyXw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nist.gov; dmarc=pass action=none header.from=nist.gov; dkim=pass header.d=nist.gov; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nist.gov; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=D/Gm3UsESo3SxUyWqFR0GsSQjYO35Orf02XYx4l80gs=; b=UHhMWnpwig30w22bw5Oex7lOY7Y3TvAvlvLo/3RpJeuovqsb1EntFloKPwHv91IIe2xdS2CKMgP76bcB9P5gbovZsF+kLvPND5HqixSJ10vbxjTE5x+EbNbuUQ0EM18JogOxOruF9gWPLd3FHWHRtSJGmjaszxDSlnnpoqeGrBxDw1arkWOIY0yDahvu4dIfH5fKpvRk0L/0U2811c3FGYnk/nGJGon600pG6mBOgG6cIhVxyZrzQumer5lf17fYgbIrksD3bbRFLDpC1FZBoAjXi4gPlX/Ml13zwTpcum6pwL7usGWzcc2Dzp7CJuy/8QUur8BWM/tHFCmYGJ4/LA==
Received: from SA1PR09MB8142.namprd09.prod.outlook.com (2603:10b6:806:171::8) by PH8PR09MB9981.namprd09.prod.outlook.com (2603:10b6:510:182::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6455.44; Fri, 9 Jun 2023 23:07:00 +0000
Received: from SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::226a:790b:a85c:d03e]) by SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::226a:790b:a85c:d03e%4]) with mapi id 15.20.6455.043; Fri, 9 Jun 2023 23:06:59 +0000
From: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
To: Claudio Jeker <cjeker@diehard.n-r-g.com>
CC: Job Snijders <job@fastly.com>, "sidrops@ietf.org" <sidrops@ietf.org>, "draft-ietf-sidrops-aspa-profile@ietf.org" <draft-ietf-sidrops-aspa-profile@ietf.org>
Thread-Topic: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
Thread-Index: AQHZmvFmUMbgsO9/80GQ4HaXp55OWa+DEHcQ
Date: Fri, 09 Jun 2023 23:06:59 +0000
Message-ID: <SA1PR09MB81421ED5894AC97C8C433D918451A@SA1PR09MB8142.namprd09.prod.outlook.com>
References: <SA1PR09MB8142F5C0AB365A535AE849E28451A@SA1PR09MB8142.namprd09.prod.outlook.com> <ZINWc2lsffKypBnc@diehard.n-r-g.com>
In-Reply-To: <ZINWc2lsffKypBnc@diehard.n-r-g.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nist.gov;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SA1PR09MB8142:EE_|PH8PR09MB9981:EE_
x-ms-office365-filtering-correlation-id: 8199f5a0-814a-4466-c611-08db693e3adb
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: WVSJJGYJBffZneqVg2pt5HtO26cD+W1lZWCuwLyhv8OrdLWO6sSvV9XgkvLaq1dFc0RboFwNkq3Unur5aS2v3lZyvbN9Moa1JR9Qqc7O/4FwILia3LYxwJduPrQU6LA0B+yXeh5K9mCjs4CbOKmdZ5KZEgRgQO3zZf7kRitDQh7uWDwp7GeW/6P3Mn42Ek8Lbhmev6vxZaNCjigYXnqCoStj8Yc8SUWKjOheN9/JkWXJOtoxLfzr9/Ykk6HlyRkihpjgUMit+iUOANm2SBcuNplDsd39d/nXHz5BV4y9QuOV3BcVSb1wVKdiW4+uREIgEg+yBa5hTMfIjQNquejqT1ykxzHi94lh4zrZy1L3p/PqA6cZ/rFiFwFFwicCmRF9kJZnnJF31qMPMS9re0fkRRZvqr1B0PBH82Wzqj8AJ6HPbQRlAsa4d57FpNwpmvZGGLSYclhGXJlcNyrcwTJ2jwXNC/KbkhBX3q2Nro0bVmoHInhwHznC4wPz7KVRkQiNrEeuue2JgaC8++/pD9xlhtOUi0s5a/bLyFKhFcjXSYXt7S5qnaoubo+wYmMmWPNyMLJdtVpgvhkFuJFQwij4cxqGq95vNMibzGizcE6Z7BvVCb7DxG/vdJo6fanNtxml
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR09MB8142.namprd09.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(366004)(451199021)(186003)(53546011)(6506007)(9686003)(26005)(38100700002)(7696005)(83380400001)(498600001)(54906003)(71200400001)(82960400001)(4326008)(76116006)(6916009)(66556008)(66446008)(55016003)(122000001)(66476007)(64756008)(66946007)(8676002)(8936002)(52536014)(5660300002)(86362001)(33656002)(2906002)(38070700005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: hj4djg3hmV9/bCcitojVtgWy9+BRyBqo6hmM5RPJuKIplqVDzAstLrSDkIBBXuNsPeFu84cYiW4+jyHo1Bfhl1Q5vxe9xZhyLEaLYrwHLfCx0K0I8PgbcaXG9YiJWUWTs14lGXnUEFf3mWavAkSmapBwZzRRo69lj0Ibl5RrEwsimw1XUhY1lYUWUyqNp3Dyciws+TcbqIXtihe8RqvNSH4JCOH4k+sVXoR1Im4Mibh1ETCQymVCJnbAuz2D1MIgSfMjjELjjlM0kdiYu8QWX21Bu0OVXcS2iEmKTd91uTst0eBfV35R7levxxzTgfkQnsvXQMlg7St67I5cCAuYcBhTHFrdEMEAqXSbpJ+bjpG/srtOkpCR1uDy9s1o5nG5g1YIQWoOyJ2lDQqo6bQTrHbs8NlzXaJKkjEe96bWnih3h/71Vku46Qx8L3mNqS4TlfxA9JVMErqgCshVArT9ck08uOdryn3Ay22bzoki0/QX50T0sfWwSV70qafwFXxdPyR9oWApui9mJ7+U+tkNEJbtA6B+Cpoh0DZ873TIAXXnrv4o2D0l6xt8u4ozVRLQAmeY2IfVSPk2h+C7/K3DiakPNql87/o8U7Hqtl+DFcek+KbjbWl7h/9vG272S65MEaqZr6eVECX0jY47PXhS4gmodThzhcnpCOcWRWKj9EpE59WlBadRYN2/79MYgmvqmPDHp/oZ5hVPFOwUawj/NJh+vhh0iU3UZqX7YEsMF++XZm8aqxYsj1ih/mg9LuF7hy61ozzz//KAbhSHyLKSo/KXO8bbAg0NdNOPbFMa8txDLG4aeBXt/FjvEmXRidD2SYQisWwm8AWM3wtnZVhKIxvgAt77vb6ZVcthCDfEpTK4H89x2T51fJ6n1xvQAQQlsjq7EZ9yFXoeBiaUqX+H1itp3HOk1nrovF0qFPAYV4zGTfORujM8ft/UmiUjx+PrWnab8mr/NcN6+JsdCv6xx3PikNYdcukESO7KgwU8xDSpxikC1j/hqblGNG9M0SUPh7XIeceV/Yyr8kLwT81UY+0xXzP/etsMKMPXJpCS7HNqNX6olSS5vQU5LGBbYRed7ICOHSFaqT6i3oEcSEsY7UZL+QiDuoYvQBiFepZjVCfjP6aCsVuCVUyrtSZmSVB3RTlT1hBEHWJj6vOYabNt8I4MSDchOgsz6MGQOnHdAXA2yghr5JD9Vsi50pMvpAtkuHN2RPVPLjhX18mJ9NfcZQ3rYjuzctrnZL3t8ffNuGGr1lDczXX+l0waSBpY10DkR3dbiHRcUIQSYXc3oxtt4QYiNqp1L7AHzObUtt2QR2uGcS49k8c7UqfmKo/WQPLRXS5MKdYunZCdm4uvOPbEiIyp0qep5lP8IjQw+uUVmjSU1e85HJ52WmKIj/FCrUQu/VERJtSYFMg1jmC8qfxx3wgbIlURLuNTi5ufGKYd1ICm9Rgpr8zg+RUDA198auYwzqG2BSX7S9ezHBAB22PnVqizDMfSXGBfgNfCtyShdSKKFOoGL+wrMXqz+34Xyn/5TqSGTOdsm6viQZe+X3HhtOeE9O23CMV/YGgutk8gObw=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR09MB8142.namprd09.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8199f5a0-814a-4466-c611-08db693e3adb
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Jun 2023 23:06:59.9238 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH8PR09MB9981
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/a1zumfzn5R_ZvTh0mtP1gjvF2k4>
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Jun 2023 23:07:11 -0000

Hi Claudio,

[top comments only]

>...
>If something like this is included it needs to be clear that ASPA only applies to unicast IPv4 and IPv6 (AFI 1 & 2, SAFI = 1).
>...

Yes, I didn't mean to leave out the SAFI. 

>In my opinion the ASPA verification draft is already fairly clear about this:
> ... snip...

True, but the following part is new and may be needed for clarity: "In rare cases, if a CAS considers some Provider ASes to be unique to one address family, it MUST still list the union of all Provider ASes applicable to {AFI 1 (IPv4), SAFI 1} and {AFI 2 (IPv6), SAFI 1}  in the SPAS."

Or, it can be stated more simply as: "The CAS MUST list the union of all Provider ASes applicable to {AFI 1 (IPv4), SAFI 1} and {AFI 2 (IPv6), SAFI 1}  in the SPAS."

(Note: Statement about including non-transparent RS in the SPAS already exists in the verification draft. We'll not lose track of that.)

Sriram
--------------------------


-----Original Message-----
From: Claudio Jeker <cjeker@diehard.n-r-g.com> 
Sent: Friday, June 9, 2023 12:42 PM
To: Sriram, Kotikalapudi (Fed) <kotikalapudi.sriram@nist.gov>
Cc: Job Snijders <job@fastly.com>; sidrops@ietf.org; draft-ietf-sidrops-aspa-profile@ietf.org
Subject: Re: [Sidrops] I-D Action: draft-ietf-sidrops-aspa-profile-15.txt

On Fri, Jun 09, 2023 at 02:55:15PM +0000, Sriram, Kotikalapudi (Fed) wrote:
> Hi Job and all,
> 
> Do we need a statement in the profile document to make it clear what 
> AFIs the ASPA profile specification applies to? Should we make it 
> clear that it does not apply to AFIs other than 1 and 2?
> 
> Suggestion for the wording:
> 
> ---
> The specification of the ASPA profile in this document is applicable only to address families IPv4 (AFI = 1) and IPv6 (AFI = 2). The Set of Provider ASes (SPAS) listed in the ASPA is considered applicable to both AFI = 1 and AFI =2. In rare cases, if a CAS considers some transit providers to be unique to one address family, it MUST still list the union of all transit providers applicable to AFI = 1 and AFI =2 in the SPAS.
> ---
> 
> An alternative is to say nothing about the AFI in the profile document 
> (as currently the case with v-15). Instead, state the above (with 
> somewhat different wording) only in the ASPA verification document?

If something like this is included it needs to be clear that ASPA only applies to unicast IPv4 and IPv6 (AFI 1 & 2, SAFI = 1).
In my opinion the ASPA verification draft is already fairly clear about
this:

 1. Introduction
    The procedures described in this document are applicable only for BGP
    routes with {AFI, SAFI} combinations {AFI 1 (IPv4), SAFI 1} and {AFI 2
    (IPv6), SAFI 1} [IANA-AF]. SAFI 1 represents NLRI used for unicast
    forwarding [IANA-SAF].

 7. AS_PATH Verification Recommendations
    The procedures described in this document MUST be applied to BGP routes
    with {AFI, SAFI} combinations {AFI 1 (IPv4), SAFI 1} and {AFI 2 (IPv6),
    SAFI 1} [IANA-AF]. The procedures MUST NOT be applied to other address
    families by default.

So in my opinion there is no need to complicate the ASPA profile document.

--
:wq Claudio