Re: [spring] [Int-area] FW: New Version Notification for draft-raviolli-intarea-trusted-domain-srv6-00.txt
Brian E Carpenter <brian.e.carpenter@gmail.com> Fri, 31 March 2023 19:02 UTC
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: spring@ietfa.amsl.com
Delivered-To: spring@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4FA03C151711; Fri, 31 Mar 2023 12:02:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4KGMqeI9uC-m; Fri, 31 Mar 2023 12:02:16 -0700 (PDT)
Received: from mail-pj1-x1031.google.com (mail-pj1-x1031.google.com [IPv6:2607:f8b0:4864:20::1031]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9644FC152577; Fri, 31 Mar 2023 12:00:58 -0700 (PDT)
Received: by mail-pj1-x1031.google.com with SMTP id p3-20020a17090a74c300b0023f69bc7a68so24357562pjl.4; Fri, 31 Mar 2023 12:00:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; t=1680289258; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=GhB1GEMGtvaH+rAG4Qj8bMLQYXMYGVBp+nSFYaTKvUI=; b=q4LfAMJRfE9+CqDfpaFk9Vp8pKTFx6w8BjRcT5JsJsSHFZvZjTQkI5ydH48pat5APu 8Z0POazH9qIPuaiigkpSQbSoeM3uCfbRcqtqengqjYIWeOHqn1CJGokwKm6ONZ/KuY4h wSeF0s/6UUDbhxSUPxhbslHdaYjOaVTR0T4BPN7qtxGDo5QLCZl6Ng1tLT7u9R+i+EX2 sH1s+6OtaXRZbV17HHbvFMf8ANDnZAM+lHZkQaANFGCw1TEroDcaQE0wDcQVtTPc7jdU UqvHPyFIxKMRWYVbi2/7WdR6LXYGFxuDhGEALY9Zfrhswwk0zA91bHEJFi0bLoEt74yT qUdw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1680289258; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=GhB1GEMGtvaH+rAG4Qj8bMLQYXMYGVBp+nSFYaTKvUI=; b=rQpQYeBInSwVaP3d3wuZNKdzgRzAfTok5NjqZQCIwIm02D1CNDyezfn02pmecdOdJA 3kNSF0gI9lMo7klpkd8ws1UdyzlFah7EqqrJcD2p64YFI3+RsEy1p3W0xbcMxzgak2Ad oWCtGGZdLmj9FNtuS2pTNWkawu8km4xjoAulxZeAn2kdn+j94AnqMT/xxbvhi9nHG4R2 3gZOOs3go1b9zIAIFrBliJ6QJNbvO2EQVqiVvFLOdPGQff/MWZO1K2wV+q5Avprgrz0c U6v/kPND3SVNZMlUGHF5uG7KUCA9TzH8HuICv6ydklUX+F8dOoIBb2EzY7LOBeY8o0Sd HWxg==
X-Gm-Message-State: AO0yUKUmiE+w/etGA+twcSItD6RrKoAY0r6i7q937LgF2kg9ImjINMVS kcQUJbmtfD/L3HlSFFRDkejN2w1Pyvb/BA==
X-Google-Smtp-Source: AK7set84/jEyrkBQWkkZJHy4a0Y+X1ac5OR2K2n8iHH1sFggUMWAD/tPHBpGDUYb44DZn/54FUV45w==
X-Received: by 2002:a05:6a20:baa5:b0:dc:e183:26cc with SMTP id fb37-20020a056a20baa500b000dce18326ccmr25964440pzb.23.1680289257871; Fri, 31 Mar 2023 12:00:57 -0700 (PDT)
Received: from ?IPV6:2406:e003:1184:f001:9991:d1ad:8c20:42bd? ([2406:e003:1184:f001:9991:d1ad:8c20:42bd]) by smtp.gmail.com with ESMTPSA id q15-20020a62ae0f000000b0062d7b360eafsm2169552pff.62.2023.03.31.12.00.54 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Mar 2023 12:00:57 -0700 (PDT)
Message-ID: <63276c1a-33d7-7cdc-28ad-6c627ae75a67@gmail.com>
Date: Sat, 01 Apr 2023 08:00:53 +1300
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.10.0
Content-Language: en-US
To: Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org>, Krzysztof Szarkowicz <kszarkowicz=40juniper.net@dmarc.ietf.org>, Kireeti Kompella <kireeti.ietf@gmail.com>
Cc: "spring@ietf.org" <spring@ietf.org>, "int-area@ietf.org" <int-area@ietf.org>, Andrew Alston - IETF <andrew-ietf=40liquid.tech@dmarc.ietf.org>, "Dr. Tony Przygienda" <tonysietf@gmail.com>
References: <072001d9611c$622fd220$268f7660$@olddog.co.uk> <B752E544-9E57-4DC8-8C34-5C17D7D9AF10@gmail.com> <CA+wi2hNGhkpysxHWiv25ZgdRMm22TWnNJ49PkWfyO0QficRnTQ@mail.gmail.com> <6F3EACD5-5AAC-477A-BB26-F50C4C115BB7@juniper.net> <BL0PR05MB531667C442FBEE791CD5B2ECAE8F9@BL0PR05MB5316.namprd05.prod.outlook.com> <BL0PR05MB5316D8BDF208FC6361D37934AE8F9@BL0PR05MB5316.namprd05.prod.outlook.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
In-Reply-To: <BL0PR05MB5316D8BDF208FC6361D37934AE8F9@BL0PR05MB5316.namprd05.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: base64
Archived-At: <https://mailarchive.ietf.org/arch/msg/spring/VIBoPEmmRsM2Bt5OIdbH5RJnSgs>
Subject: Re: [spring] [Int-area] FW: New Version Notification for draft-raviolli-intarea-trusted-domain-srv6-00.txt
X-BeenThere: spring@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Source Packet Routing in NetworkinG \(SPRING\)" <spring.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spring>, <mailto:spring-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spring/>
List-Post: <mailto:spring@ietf.org>
List-Help: <mailto:spring-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spring>, <mailto:spring-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 Mar 2023 19:02:21 -0000
On 01-Apr-23 06:18, Ron Bonica wrote:
> On second thought, if we had the new ethertype, we wouldn’t need the new /16!
>
> They serve the same function
However, a new special-purpose prefix is rather trivial to deploy compared with a new Ethertype.
Brian
>
> Ron
>
> *From:* Ron Bonica
> *Sent:* Friday, March 31, 2023 1:05 PM
> *To:* Krzysztof Szarkowicz <kszarkowicz=40juniper.net@dmarc.ietf.org>; Kireeti Kompella <kireeti.ietf@gmail.com>
> *Cc:* Adrian Farrel <adrian@olddog.co.uk>; Andrew Alston - IETF <andrew-ietf=40liquid.tech@dmarc.ietf.org>; int-area@ietf.org; spring@ietf.org; Dr. Tony Przygienda <tonysietf@gmail.com>
> *Subject:* RE: [spring] [Int-area] FW: New Version Notification for draft-raviolli-intarea-trusted-domain-srv6-00.txt
>
> +1
>
> If we allocate a /16 for SRv6 USIDs, as proposed in https://www.ietf.org/archive/id/draft-ietf-6man-sids-02.txt <https://www.ietf.org/archive/id/draft-ietf-6man-sids-02.txt>,
>
> we can allow that prefix only when the new ethertype is used.
>
> Ron
>
> *From:* spring <spring-bounces@ietf.org <mailto:spring-bounces@ietf.org>> *On Behalf Of *Krzysztof Szarkowicz
> *Sent:* Wednesday, March 29, 2023 5:30 AM
> *To:* Kireeti Kompella <kireeti.ietf@gmail.com <mailto:kireeti.ietf@gmail.com>>
> *Cc:* Adrian Farrel <adrian@olddog.co.uk <mailto:adrian@olddog.co.uk>>; Andrew Alston - IETF <andrew-ietf=40liquid.tech@dmarc.ietf.org <mailto:andrew-ietf=40liquid.tech@dmarc.ietf.org>>; int-area@ietf.org <mailto:int-area@ietf.org>; spring@ietf.org <mailto:spring@ietf.org>; Dr. Tony Przygienda <tonysietf@gmail.com <mailto:tonysietf@gmail.com>>
> *Subject:* Re: [spring] [Int-area] FW: New Version Notification for draft-raviolli-intarea-trusted-domain-srv6-00.txt
>
> *[External Email. Be cautious of content]*
>
> SRv6 packet might have SRH, but might not have SRH. Especially with uSID, you can craft a decent SR-TE SRv6 packet without SRH. So I think, Kireetis’ comments should apply to all SRv6 packets (with/without SRH).
>
> —
>
> Krzysztof
>
> On 2023 -Mar-29, at 17:57, Tony Przygienda <tonysietf@gmail.com <mailto:tonysietf@gmail.com>> wrote:
>
> Though I would like to cheer for Kireeti's 2. as well I think the point of SHOULD is more realistic (for now) as Joel points out ...
>
> As to ethertype, I think grown-ups in the room were since long time drily observing that a new IP version would have been appropriate after enough contortions-of-it's-an-IPv6-address-sometimes-and-sometimes-not-and-sometimes-only-1/4 were performed with drafts whose authors' list length sometimes rivaled pages of content ;-) I think this ship has sailed and that's why after some discussions with Andrew we went the ether type route as more realistic. Additionally, yes, lots encaps (not encodings) carrying SRv6 should get new codepoints if we are really serious about trusted domains here.
>
> And folks who went the MPLS curve know that none of this is new, same curve was walked roughly (though smoother, no'one was tempted to "hide label stack in extension headers" ;-) and it would go a long way if deploying secure SRv6 becomes as simple as *not* switching on "address family srv6" on an interface until needed and then relying on BGP-LU (oops ;-) to build according lookup FIBs for SRv6 instead of going in direction of routers becoming massive wildcard matching and routing header processing firewalls ...
>
> --- tony
>
> On Wed, Mar 29, 2023 at 4:33 PM Kireeti Kompella <kireeti.ietf@gmail.com <mailto:kireeti.ietf@gmail.com>> wrote:
>
> On Mar 28, 2023, at 11:24, Adrian Farrel <adrian@olddog.co.uk <mailto:adrian@olddog.co.uk>> wrote:
>
> [Spring cc’ed because, well, you know, SR. I wonder whether 6man and 6ops should care as well.]
>
> SPRING cc’ed because, you know, replying to Adrian’s email. Agree that 6man and 6ops [sh|w]ould be interested.
>
> tl;dr
>
> I think this is a good initiative and worth discussion. Thanks
>
> for the draft.
>
> Agree. In particular:
>
> 1. There is an acknowledged security problem. Might be worth summarizing, as it is central to this draft, but an example is in rfc 8402/section 8. Section 3 of this draft (“The SRv6 Security Problem”) doesn’t actually describe the security problem; Section 5 does, briefly.
>
> 2. The solution (using a new EtherType, SRv6-ET) is a good one. It’s sad that this wasn’t done from the get-go, as the solution is a bit “evil bit”-ish. I’d prefer to see ALL SRv6 packets (i.e., those containing SRH) use SRv6-ET. Boundary routers SHOULD drop packets with SRv6-ET that cross the boundary in either direction; all routers MUST drop packets with SRH that don’t have SRv6-ET. Yeah, difficult, but the added security is worth it.
>
> 3. Ease of secure deployment is a major consideration; this draft is a big step in that direction.
>
> 4. As Adrian said, several nits. Will send separately to authors.
>
> Kireeti
>
> _______________________________________________
> spring mailing list
> spring@ietf.org <mailto:spring@ietf.org>
> https://www.ietf.org/mailman/listinfo/spring <https://urldefense.com/v3/__https:/www.ietf.org/mailman/listinfo/spring__;!!NEt6yMaO-gk!GGgCymh1gmvxc7ibG9cWpBOm73ewlZbNJjAA4xw8KNZFBMd9ROvcdT5tCSooD-OCMYFWheicbBfDrzfTkoY7bGn7W65rg0E$>
>
> _______________________________________________
> spring mailing list
> spring@ietf.org <mailto:spring@ietf.org>
> https://www.ietf.org/mailman/listinfo/spring <https://www.ietf.org/mailman/listinfo/spring>
>
>
> Juniper Business Use Only
>
>
> _______________________________________________
> Int-area mailing list
> Int-area@ietf.org
> https://www.ietf.org/mailman/listinfo/int-area
- Re: [spring] [Int-area] FW: New Version Notificat… Adrian Farrel
- Re: [spring] [Int-area] New Version Notification … Stewart Bryant
- Re: [spring] [Int-area] FW: New Version Notificat… Andrew Alston - IETF
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Andrew Alston - IETF
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Kireeti Kompella
- Re: [spring] [Int-area] FW: New Version Notificat… Tony Przygienda
- Re: [spring] [Int-area] FW: New Version Notificat… Krzysztof Szarkowicz
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Mark Smith
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Mark Smith
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Muthu Arul Mozhi Perumal
- Re: [spring] [Int-area] FW: New Version Notificat… Brian E Carpenter
- Re: [spring] [Int-area] FW: New Version Notificat… Robert Raszuk
- Re: [spring] [Int-area] FW: New Version Notificat… Joel Halpern
- Re: [spring] [Int-area] FW: New Version Notificat… Joel Halpern
- Re: [spring] [Int-area] FW: New Version Notificat… Muthu Arul Mozhi Perumal
- Re: [spring] [Int-area] FW: New Version Notificat… Tony Przygienda
- Re: [spring] [Int-area] FW: New Version Notificat… 徐小虎
- Re: [spring] [Int-area] FW: New Version Notificat… Brian E Carpenter
- Re: [spring] [Int-area] FW: New Version Notificat… Ron Bonica
- Re: [spring] [Int-area] FW: New Version Notificat… Ron Bonica
- Re: [spring] [Int-area] FW: New Version Notificat… Brian E Carpenter
- Re: [spring] [Int-area] FW: New Version Notificat… Tony Przygienda
- Re: [spring] [Int-area] FW: New Version Notificat… Brian E Carpenter
- Re: [spring] [Int-area] FW: New Version Notificat… Andrew Alston - IETF
- Re: [spring] [Int-area] FW: New Version Notificat… Tony Przygienda
- Re: [spring] [Int-area] FW: New Version Notificat… Ron Bonica