Re: [Sidrops] WG Adoption call for draft-borchert-sidrops-bgpsec-validation-signaling-01 (9/16-9/30)

"Roque Gagliano (rogaglia)" <rogaglia@cisco.com> Wed, 25 September 2019 15:11 UTC

Return-Path: <rogaglia@cisco.com>
X-Original-To: sidrops@ietfa.amsl.com
Delivered-To: sidrops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 280C3120025 for <sidrops@ietfa.amsl.com>; Wed, 25 Sep 2019 08:11:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.501
X-Spam-Level:
X-Spam-Status: No, score=-14.501 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=WYkGggea; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=QDhcowtS
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tjKKJJ3b99hA for <sidrops@ietfa.amsl.com>; Wed, 25 Sep 2019 08:11:18 -0700 (PDT)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B39DE120026 for <sidrops@ietf.org>; Wed, 25 Sep 2019 08:11:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=6340; q=dns/txt; s=iport; t=1569424278; x=1570633878; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=2QsoJALpwG4LW1cvDHGLj5FsrM4zc75n5XftA/74Ia8=; b=WYkGggea59e1TEtAOa7ePN34E1W2L/lRxlfxfjpOEJHi412cT91/XiAU xtiwraW9nM0FdH2ZjoNmKu2ujh4Wyq+HmX3lY+cGQA1BXvO2FwciVCDx/ CwlqY7w3dXw/elj+5V0nImp2hxBKyGO8UsufYiIUcPX7fCBhmw0xXJWpu Y=;
IronPort-PHdr: 9a23:LfeBZRDP3DU/c742NTAwUyQJPHJ1sqjoPgMT9pssgq5PdaLm5Zn5IUjD/qs03kTRU9Dd7PRJw6rNvqbsVHZIwK7JsWtKMfkuHwQAld1QmgUhBMCfDkiuNvnlZiM+Hc1qX15+9Hb9Ok9QS47z
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AJAAC5gotd/5BdJa1lGgEBAQEBAgEBAQEMAgEBAQGBUwUBAQEBCwGBSlADbVYgBAsqhCKDRwOEUoYnglyXdIEugSQDVAkBAQEMAQEYCwoCAQGDekUCF4MTIzQJDgIDCQEBBAEBAQIBBQRthS0MhUoBAQEBAwEBEAsGEQwBASwLAQsEAgEIEQQBAQMCHwcCAgIlCxUICAIEAQ0FFAcHgwABgWoDHQECDKQ2AoE4iGFzgTKCfQEBBYUSGIIXAwaBDCgBjAsYgUA/gREnH4JMPoJhAQECgXaCdDKCJoxrCg6CV4dglVoKgiKVChuCNpZ1jhuBPJdZAgQCBAUCDgEBBYFSOA0dgS5wFTsqAYJBUBAUgU44gzqFFIU/cwEBgSeMBiuCJwEB
X-IronPort-AV: E=Sophos;i="5.64,548,1559520000"; d="scan'208";a="631148342"
Received: from rcdn-core-8.cisco.com ([173.37.93.144]) by rcdn-iport-7.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 25 Sep 2019 15:11:16 +0000
Received: from XCH-ALN-001.cisco.com (xch-aln-001.cisco.com [173.36.7.11]) by rcdn-core-8.cisco.com (8.15.2/8.15.2) with ESMTPS id x8PFBGbj028010 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 25 Sep 2019 15:11:16 GMT
Received: from xhs-aln-002.cisco.com (173.37.135.119) by XCH-ALN-001.cisco.com (173.36.7.11) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 25 Sep 2019 10:11:15 -0500
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1473.3; Wed, 25 Sep 2019 10:11:14 -0500
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (64.101.32.56) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1473.3 via Frontend Transport; Wed, 25 Sep 2019 11:11:14 -0400
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=S98QDkrbeKNmxjY/SVEFw9WfTQJxE7JiYrq1J6Wldj20ldLwC+7q2UrZranHtXLVrGbyg73/de7aR2iV43KcVpCYWAISBmVWefiKrftcc/QWIeVDbjmnnVymZclmBkmuIiY+/RZJSjzVCASeFuh2DeDeCiGlIuv+9vwuoavSRwaLrRMZswS0BG52uQCwSF0tm6BMvIej+am6NL/QYq96RA6i3axx45VtONbDfP/TfvgRV4y1daZnmlIfYmwmARmr14FTy+BhXihSP5aCPDzHCyFbeDjNntwf77sxs2l6SABFKMCuHSUJuVGLI78dwV2JafaSe1yeb4Eq+tQkTbB9dA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2QsoJALpwG4LW1cvDHGLj5FsrM4zc75n5XftA/74Ia8=; b=McQ5jEbChptrSy1ZlsnE8SkbT83DnbS9OzFmTqdZnKq7si+jQ6vLAmceX0qvcKC7FejSfiROWWzqJnvPEV89mS1oj0/Qm76+ohqZoA6mo8hMBY3JQcq/bEx4eEADfQPaiAvD3vRJ+9yJok/EDdiANDMH+1cO+YkvCeJw1d8Rqi2etH5TBRJ+yWZ9CW+RRkn/u/CkkGvDfJFLqUcm6PXApYyBcuT0k7H2ngn5CfvAXQjEpyrmnQP2EcIji5JPKVdMKilmHZoDCSDHr8f0n31hMX013T/NvfNN+Ea7bZl9PimukOzasHqhqt157Id6b9Wu7zzx+lxFtzc8CLlHBXSGZg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2QsoJALpwG4LW1cvDHGLj5FsrM4zc75n5XftA/74Ia8=; b=QDhcowtSUNaDGcW2JcLhiSl+NwlpUgBYJFmgRkx7i0nsZiqsiHdHTSVmwpGZMCjNjgIkxvOjcrvKLhskycOuCiOOZtgGzqKdh7XK2tpvfspiPGKeb6WhcnCPmpQZzbZoXZuP8s1gH17cj45FgLY+ioHSL+K9+JZkRAZFQvveP+s=
Received: from MN2PR11MB3663.namprd11.prod.outlook.com (20.178.253.96) by MN2PR11MB4254.namprd11.prod.outlook.com (52.135.38.157) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2284.26; Wed, 25 Sep 2019 15:11:13 +0000
Received: from MN2PR11MB3663.namprd11.prod.outlook.com ([fe80::9c4b:65c5:bfd3:ceb0]) by MN2PR11MB3663.namprd11.prod.outlook.com ([fe80::9c4b:65c5:bfd3:ceb0%7]) with mapi id 15.20.2284.023; Wed, 25 Sep 2019 15:11:13 +0000
From: "Roque Gagliano (rogaglia)" <rogaglia@cisco.com>
To: "Borchert, Oliver (Fed)" <oliver.borchert=40nist.gov@dmarc.ietf.org>, "Jakob Heitz (jheitz)" <jheitz@cisco.com>, "Montgomery, Douglas (Fed)" <dougm=40nist.gov@dmarc.ietf.org>, Randy Bush <randy@psg.com>, Keyur Patel <keyur@arrcus.com>
CC: "sidrops@ietf.org" <sidrops@ietf.org>, "Borchert, Oliver (Fed)" <oliver.borchert@nist.gov>
Thread-Topic: [Sidrops] WG Adoption call for draft-borchert-sidrops-bgpsec-validation-signaling-01 (9/16-9/30)
Thread-Index: AQHVbMKiBubipeZ/d0GMV+4UPfWKYKcuza8A///bQYCADJgpcIABQZkAgAAsPYA=
Date: Wed, 25 Sep 2019 15:11:13 +0000
Message-ID: <C026C2CA-F091-4B87-B7DF-2C3461A465F7@cisco.com>
References: <0BBFA8C1-A13D-4CC9-A72D-ABAE797F2E4F@arrcus.com> <m28sqouepr.wl-randy@psg.com> <875A2007-9546-4CE3-AD32-15D4E7F7C29E@nist.gov> <BN8PR11MB3746439C06B460A7BD009758C0840@BN8PR11MB3746.namprd11.prod.outlook.com> <DM6PR09MB3019425FBE11F93DF9747CD898870@DM6PR09MB3019.namprd09.prod.outlook.com>
In-Reply-To: <DM6PR09MB3019425FBE11F93DF9747CD898870@DM6PR09MB3019.namprd09.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1d.0.190908
authentication-results: spf=none (sender IP is ) smtp.mailfrom=rogaglia@cisco.com;
x-originating-ip: [2001:420:44cb:1300:5ddc:61c0:e0ca:e885]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 42afef95-7084-46a7-fe39-08d741ca9afd
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(5600167)(711020)(4605104)(1401327)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7193020); SRVR:MN2PR11MB4254;
x-ms-traffictypediagnostic: MN2PR11MB4254:
x-ms-exchange-purlcount: 1
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <MN2PR11MB4254B7D6B7105CD146DE3F44D8870@MN2PR11MB4254.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-forefront-prvs: 01713B2841
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(366004)(346002)(39860400002)(136003)(376002)(396003)(199004)(13464003)(189003)(66574012)(102836004)(36756003)(6306002)(6436002)(33656002)(45080400002)(11346002)(46003)(446003)(2616005)(6506007)(476003)(486006)(86362001)(561944003)(53546011)(6246003)(99286004)(91956017)(76116006)(66446008)(64756008)(66946007)(66476007)(5660300002)(66556008)(6116002)(81156014)(305945005)(81166006)(966005)(25786009)(4326008)(186003)(6512007)(71200400001)(229853002)(7736002)(2906002)(8936002)(14454004)(58126008)(76176011)(256004)(110136005)(6486002)(54906003)(478600001)(316002)(8676002)(71190400001)(14444005); DIR:OUT; SFP:1101; SCL:1; SRVR:MN2PR11MB4254; H:MN2PR11MB3663.namprd11.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: cisco.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: OUVagXUrnibf4FD9e6YrJS9mQhDM2SLrOPLOstIpk7dlVK5EMo3NX8cKeW7qhY3qMYWFDifh4o0boiektBcFv8x5PY2kHs2CjI2PPU6x9OYH4m1ZuP529wkhnG+VEz/riM/lbjUkjryBCC01UpfhLfCrq7h4gBFsghaBzUlXI2+tOBqJkP9zfNOfBdzsTz4WkKIuY39n5FPn5I5HMfML5SV3+Vvqnm4nmLYuaMSBwkvx2E+0O8hJ5M8kioQkC8KRnSv4jNi5ZR5u9cz17LI8cl14wk667hi0CClEGpsRuVjS600SlSsxvqOQJ7sJSj0kOUTVKOvAdOn7rmQdEvv60gtEJ8WWzpUPZWPjNuG8ODBXGCZ1Dy1ev+IN3vITQ2VOuisuuQx07jXui2ANjIFHGgqLJH1AtbfVr6e0bI6f3kq4QUUaeO+A/WbHzgRoX8bqQ/JL6ayYT8Ke8iJlg8nIJw==
Content-Type: text/plain; charset="utf-8"
Content-ID: <4D21377866784C48A71AEC12F05FBAFF@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: 42afef95-7084-46a7-fe39-08d741ca9afd
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Sep 2019 15:11:13.3711 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 5MsYba1ZyU5VT80byIJFlDlpRvxPwR7iGLL+IeqCu2LsOngIkTPhfdF5hEEdeYIjDg3SZZMcqKLmrpqkeDqVRA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4254
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.11, xch-aln-001.cisco.com
X-Outbound-Node: rcdn-core-8.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/rpCcFPUVAbHXMpxfIl_PdFtBYdw>
Subject: Re: [Sidrops] WG Adoption call for draft-borchert-sidrops-bgpsec-validation-signaling-01 (9/16-9/30)
X-BeenThere: sidrops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidrops>, <mailto:sidrops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops/>
List-Post: <mailto:sidrops@ietf.org>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidrops>, <mailto:sidrops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Sep 2019 15:11:21 -0000

Hi,

I do not believe your proposal of a new state is adequate:
   |   3   | Lookup result = "BGPSec attribute not present or in error"

Looks to me that you want to add more context on the reasons for invalidating an update but that should not be in the "validation state":
	- You could be in "unverified" state because the attribute was not present. 
	- Independently if there was an "error" (whatever it means), the state will still be "invalid" as validation was tried and failed.

Regards,
Roque


On 25.09.19, 17:01, "Sidrops on behalf of Borchert, Oliver (Fed)" <sidrops-bounces@ietf.org on behalf of oliver.borchert=40nist.gov@dmarc.ietf.org> wrote:

    Jakob, 
    
    I agree, adding the BGPsec information into the RFC 8097 communities "reserved" field 
    seems definitely be a good solution and I can easily modify the proposed draft to do that.  
    
    Oliver
    
    -----Original Message-----
    From: Sidrops <sidrops-bounces@ietf.org> On Behalf Of Jakob Heitz (jheitz)
    Sent: Tuesday, September 24, 2019 3:32 PM
    To: Montgomery, Douglas (Fed) <dougm=40nist.gov@dmarc.ietf.org>; Randy Bush <randy@psg.com>; Keyur Patel <keyur@arrcus.com>
    Cc: sidrops@ietf.org
    Subject: Re: [Sidrops] WG Adoption call for draft-borchert-sidrops-bgpsec-validation-signaling-01 (9/16-9/30)
    
    I would be in favor of carving off another byte from the reserved field.
    Redefining the validation state to add the new information instead would confuse older receivers that do not understand the new code points.
    
    In addition, I would add another point to the BGPSec validation state: BGPSec attribute not present or in error.
    
       +-------+------------------------------+
       | Value | Meaning                      |
       +-------+------------------------------+
       |   0   | Lookup result = "Unverified" |
       |   1   | Lookup result = "Valid"      |
       |   2   | Lookup result = "Not valid"  |
       |   3   | Lookup result = "BGPSec attribute not present or in error"
       +-------+------------------------------+
    
    If it were to use a reserved byte of the RFC8097 community, 0 for unverified would work, I think.
    
    Regards,
    Jakob.
    
    -----Original Message-----
    From: Sidrops <sidrops-bounces@ietf.org> On Behalf Of Montgomery, Douglas (Fed)
    Sent: Monday, September 16, 2019 4:02 PM
    To: Randy Bush <randy@psg.com>; Keyur Patel <keyur@arrcus.com>
    Cc: sidrops@ietf.org
    Subject: Re: [Sidrops] WG Adoption call for draft-borchert-sidrops-bgpsec-validation-signaling-01 (9/16-9/30)
    
    Randy,
    
    Are you suggesting keeping the 0x43 0x00 code point, but redefining its validation state byte with additional values and meanings for path validation?
    
    Or carving off another byte from reserved?
    
    Either of those sounds fine and save bits.   
    
    Clearly there would need to be a new spec that that adds the words to do that.
    
    dougm
    --
    Doug Montgomery, Manager Internet  & Scalable Systems Research @ NIST
     
    
    On 9/16/19, 5:13 PM, "Sidrops on behalf of Randy Bush" <sidrops-bounces@ietf.org on behalf of randy@psg.com> wrote:
    
        "This document defines a new BGP non-transitive extended community to
        carry the BGPsec path validation state inside an autonomous system."
        
        given the one in RFC 8097, we need a new one because?
        
        randy
        
        _______________________________________________
     
    
    _______________________________________________
    Sidrops mailing list
    Sidrops@ietf.org
    https://gcc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fsidrops&amp;data=02%7C01%7Coliver.borchert%40nist.gov%7C43f29b9643dc4705595508d74125f6d5%7C2ab5d82fd8fa4797a93e054655c61dec%7C1%7C1%7C637049503640406944&amp;sdata=N1%2ByCkKcQD4zf6sbr9%2B7e5QnwB6wq%2BRIcaHUvYhSLW4%3D&amp;reserved=0
    _______________________________________________
    Sidrops mailing list
    Sidrops@ietf.org
    https://gcc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fsidrops&amp;data=02%7C01%7Coliver.borchert%40nist.gov%7C43f29b9643dc4705595508d74125f6d5%7C2ab5d82fd8fa4797a93e054655c61dec%7C1%7C1%7C637049503640406944&amp;sdata=N1%2ByCkKcQD4zf6sbr9%2B7e5QnwB6wq%2BRIcaHUvYhSLW4%3D&amp;reserved=0
    _______________________________________________
    Sidrops mailing list
    Sidrops@ietf.org
    https://www.ietf.org/mailman/listinfo/sidrops