Re: [Teas] Eric Rescorla's No Objection on draft-ietf-teas-lsp-diversity-08: (with COMMENT)

Dieter Beller <Dieter.Beller@nokia.com> Tue, 31 October 2017 17:58 UTC

Return-Path: <dieter.beller@nokia.com>
X-Original-To: teas@ietfa.amsl.com
Delivered-To: teas@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89A2613F58A; Tue, 31 Oct 2017 10:58:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.977
X-Spam-Level:
X-Spam-Status: No, score=-3.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.723, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZmlEI56fC1M7; Tue, 31 Oct 2017 10:58:20 -0700 (PDT)
Received: from EUR02-VE1-obe.outbound.protection.outlook.com (mail-eopbgr20124.outbound.protection.outlook.com [40.107.2.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E87EF13F5A7; Tue, 31 Oct 2017 10:58:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=QPYtrZ0HVfePotw+WHQTVdMeoxFu4ifQ4aGsp8R/2qw=; b=oXQvwusG9nERiELm0QmRyS4hYsG/AaZ2MxBPZoj8qO+v1nnyGn9fy5iSHmcPWUDm2nonaVoLRDZH7xK6qrHsl8vN8rhy0z20SQ6LnP8i5BuzZcDmt8VU6rLjXVMnvb6lDQ9c8DBzz8IwxlxJ4Nc+EL3RXdbq/wq/EeUw9hFzQxA=
Received: from [192.168.2.101] (94.216.238.3) by HE1PR07MB3418.eurprd07.prod.outlook.com (2603:10a6:7:2d::33) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.197.4; Tue, 31 Oct 2017 17:58:15 +0000
To: Eric Rescorla <ekr@rtfm.com>, The IESG <iesg@ietf.org>
Cc: draft-ietf-teas-lsp-diversity@ietf.org, teas-chairs@ietf.org, lberger@labn.net, teas@ietf.org
References: <150412445206.21557.275657217562057272.idtracker@ietfa.amsl.com>
From: Dieter Beller <Dieter.Beller@nokia.com>
Organization: Nokia
Message-ID: <6536d44e-576c-8c40-48f5-6dc2629fb54b@nokia.com>
Date: Tue, 31 Oct 2017 18:58:11 +0100
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <150412445206.21557.275657217562057272.idtracker@ietfa.amsl.com>
Content-Type: text/html; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-Originating-IP: [94.216.238.3]
X-ClientProxiedBy: VI1P189CA0006.EURP189.PROD.OUTLOOK.COM (2603:10a6:802:2a::19) To HE1PR07MB3418.eurprd07.prod.outlook.com (2603:10a6:7:2d::33)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: b6583e30-20a8-42ab-5b08-08d52088f618
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081)(4534020)(4602075)(2017052603238); SRVR:HE1PR07MB3418;
X-Microsoft-Exchange-Diagnostics: 1; HE1PR07MB3418; 3:mHE33USHtd4hql8pwsreB6clfqfGA5rQr5FOxJnHUMgnucq34XkDkdccH/5spUsXyUYaCI23yjoYjrxgt18sLk2q8Mau5eGS6wZ3RxrmXj0aNt4WPLQ6Hna87clyEIs+ttvCgP/20nxqghv42Y9wRGv1JI92coaY37gBIJehHt6YoJBwT8FjXeknQJtNW+Bo4UKqvD8Zb/55kvNPeHClvGlBKdIs9m9a7o3wItQRhEMnUyUYuL5e1rsI+nA5DQ96; 25:ASGmbViDHBmZhwd2e2EugLxclABlRDl30yINBAKgtOmtyIe560mnDRj5py9y2FXq+RqP39/sR7XuHKcOsFEL9frffpAP0WKAK2Nnyy19E//jDgsWFmuhANZlOayhFw08NTPVf3jk93tq3ZM2NlV7mqjiKJKXwJOxsWjP6V649dV29LWCdwOhOmq+d2A+VYJCW0yvDbZ8+IF19I4CjTuUdhsf3fIpHsZ+x5w1VP1hHWmnB8Q21O9Ky3oqL9PYUg+eO5iFZygTqe4qi36sxnh4BQpqsHowEvKyEAxApJR3FFSGmeIXXSZJwwJ05Imrss+8GgmGZnr794cnuQUjRLXrkg==; 31:qw5YExZoonVGn6i6IIeoUWnxFQ8BCHXusxKPC21IKhzgzBGP0K8AwKDn6kXXYxwfiaG6aNOlqt0ZsCQclD2kZbOUP+ybO2a5P8LrJnOCJA0QtoAiTqojSRa6J7zU7FG8vzWLdjJi+R3d6YsVymB00pWpJH+SPy+ksZc7bfhtlzaMxrAaBSFMAnEMuvntEV2kfjoM5iPxSOWuLdoVTapJjqZsNnk1MWOnhMNykX4D+j0=
X-MS-TrafficTypeDiagnostic: HE1PR07MB3418:
Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=dieter.beller@nokia.com;
X-Microsoft-Exchange-Diagnostics: 1; HE1PR07MB3418; 20:/bxpplqE3e8QVWhpSmusQXw/9gCuIT4ZWIOr/ei52iFp9h7ksTdDjKT6rV5vv2vl8h4LF9eUwiCMe6afjUvsMMM9/JBDDbB0t+JT2/4QngPelWGfJbKBYsToM47tv2VIh0viXLRQZPNtl4qmol7J1FLgt99ZVpSD/5Ec4rKUGiY8W6e0R9q1AwCCXgv/T5PV25L7zEoDBIhPY+pGjdEYaXv2OeVpsQtWTEHysmynDWNIJylHeTlqWx3RMAMKuU67RoIyKDJqGFH32PYmSAgBJk3UD5YF89YbnYZ4p+xhEIPOM4VMo2MsfDsnwRsQUSQyvYKAMsR4o/NOP0HyNo1A7dLWFCyOrPzLLlelf2bZ/ECrOWKVSMYE1sT75QFmQ46sU7KUCBqznrzShUNEYQn3iW/cofJXMU+BJwAH1NgsDTP0H5TL/JqScz+lOdCEyjLQ/MbXrJtw/u4i93X+OHiSStTKViNrN46xd8ba1CGzOnOPHfi7DNGSo90YHNp3+62L; 4:y6Qt4iBMtOQrqD7ZRox55TrGanX4+78UMQsAZFX9i0uz7zHiCZfwUtQ/qZmzgufr7XdFh+m+8dEiFwWy1/+SuCgnXKAYIo15dceZ7g1ToAgacWnShORW/kV0Kdv4WX6unlP/XNJfnejzdoSGsKuIthhwOOA3OBwL0aICMFV6a8dPCQkVM9cyqZbyKU6aggTOlfc4NN3kMjn0WoOYs4MYR4RKKfjInQBt3T6wEkhrJsn4ESmu+RecKzomsSVij2q5I/zeV67QEsBiGMS0uETahXNJWlqUdab/KBmOA+mUKzgiwJH1alFaL6m7AP2ITph1II5mya2gqSBoueaidRlspNoW8P0J0QbDpfTYWARCMxGwrQLbN4PdEtrO0vz109BB
X-Exchange-Antispam-Report-Test: UriScan:(120809045254105)(192374486261705)(17755550239193);
X-Microsoft-Antispam-PRVS: <HE1PR07MB341800B1DDF96C608B66897DE25E0@HE1PR07MB3418.eurprd07.prod.outlook.com>
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(5005006)(8121501046)(93006095)(93001095)(3231020)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123555025)(20161123564025)(20161123558100)(20161123562025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:HE1PR07MB3418; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:HE1PR07MB3418;
X-Forefront-PRVS: 04772EA191
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(6049001)(376002)(39860400002)(346002)(189002)(24454002)(199003)(106356001)(105586002)(33646002)(50466002)(65956001)(66066001)(68736007)(6666003)(77096006)(6486002)(64126003)(65826007)(65806001)(2950100002)(97736004)(5660300001)(3846002)(6246003)(16576012)(316002)(230700001)(4326008)(31696002)(86362001)(110136005)(53936002)(6116002)(58126008)(23676003)(2906002)(229853002)(36756003)(606006)(966005)(189998001)(53546010)(6306002)(16526018)(117156002)(230783001)(25786009)(236005)(54896002)(478600001)(83506002)(31686004)(54356999)(76176999)(50986999)(8936002)(101416001)(81166006)(7736002)(23846002)(8676002)(81156014); DIR:OUT; SFP:1102; SCL:1; SRVR:HE1PR07MB3418; H:[192.168.2.101]; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
Received-SPF: None (protection.outlook.com: nokia.com does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1;HE1PR07MB3418;23:nUJMgcjGT8GEhWnEqlbo3Gi/+XVzIDYEnj7WnW3NKeUQOp7DHfxXG90lDfuz3BHP9A5/YmsaDw/XEa5fmbLuwIl0JU1Zq1j8PEWqYQO8w+qucHD2W8U0HaDzN5a8NVhWRZVxi7wlbXR0FeQRez2Fzr9LThYGMW2TCTonMnjTKzhYp+4laNokiNp/gpR/YEQ1S+9/yvkATJvYdDPksnfC0HzSWPRZfJ3UpP1BDFEsJF1cPmE+ub9ZE9QIOu8d0L0KdGGi2bH8bjksnweSl8rQNtrxOBxOXeYtmG/+ZZG9gIPkgYrgjEAh+0r+CdKf10Ff2CM/juvszwsDb3xkzFk+K6mR5ybMljUbI5/1X6kNsj0QY2YmvoNp63AHYQ1bssJfEWjRmUd1Tz5d9VpAtUCx7qu+jIv365pzJVQqULkbpQFrwMWY5jJ9ZSFg+HmkTIOLVtQLY/mhbzclr/jBOh6sA+ZknasTQqENPi2skwOoOX5nC5TKVj0jIgQVzyIB+bJPwuL4a+Tq11i8s1rcTQGa6bSbrpZStQEYXAp6Lgp695XCBNsVEjF0tR9aPZhwFqze9/J8RomIMEdQSWl9/pgBA0K6tBFmc4pdk0jdM1t2Z2NwtXHy1CGWs4dTKQ74Ck4OhC43pQXX8DzmXwh2twK0L0+9l1RasxS9d1tuT4oc+R7Vg2cxraobR/9O6LwbYtxUd0++rKyEou+T2KPKrWZNUP5wLe1ORvqM5DNErnESVLVaSoX2lHchhqoJMcsDlGMgpU1HdRHOXxEQTcfiJAmiZJ5KH8XqGqcuo+SsguFQWaR4vkXd0h5I4/L7erPRcSexkhfZ7uEucYRjBMAzjXi54EpNBps3LMyTLXdUkEqLsporFIT85eIQCV1hbj9jYrIQW7L6uqNhYAgc9QWWzceg97bgXSqqEc00jDCuD09aCzVwCR1gR2xV3RTvNhZYW5cla+ED/lJhNoGYEDaV/7EySp82L1dJcvNDsgreBKrk8ND1ONPYwRhBabGXEH7GZ5AcIzsHt8r1fQoI6vlFQEo6FByDo8IgHoRzuRxPDTtCXuFT/hJlko5IPMLqwwd4+R2TRcPyCt5eo3SfdiWOH2QLgr2XwSbQjOpKT7hMTFMZKMNAhc2GSzQaJtMFDi2KcHMEM9P9Y+54XPiKi0O3kotx503jMPRUODFvgljnhCKvoFlyBQam7KKIPoW/aLEphBGLvNC1DjY4fOfAxxr4co8Lyh6hi2t51eY0ASqJhm+wYVanvdbuqWQ1tCjncQfrmpUkz9LoB690jJ7hTu/dR7xUz94LpdIWH4lwCG5cnRN0r8hjyevPJ9/RRkNbItL22YpZaYfhIZXz3S7IXLfSluj4dtHkj5OBsKp7meKGRiuvFOjEEgPblAQ7HO4d0L8NWLuPYQHtve7rSwvGXcsTw6WRYA==
X-Microsoft-Exchange-Diagnostics: 1; HE1PR07MB3418; 6:ifTkQerKy3sCyzpZtAz2wC4Ij/DgQ58IcMXdWiOygmDFmydVz4IeGV/2EH/JD6VtjTMsNU8eZfLOze+RgMOMGbpkwn3l/8+lD3Ilq+VjUPSvqhY4pHn0tUl0QToRaQ9lUNdyS5V+/EL++YUjMuW8aW/lcM1QTT4jDOwEv+L4HxwhWCEi4jiYI13OLJNuwk6AHDGn0bx7UWn4G379+bDBBvgm6EU5saf+AlWJtrdkd5P5twi19zHaKmM5vhw/CniUUOfTi0O8zFKxgj54oOpJT+4qZRVva5piKaHlS0nJzEQIUWOdBebpnI7vK80C/HcoerGMxWLFiq5q8Y31VUHY/I8JJ9BhSjkhVl23/e0MHE8=; 5:pcFNZwilx/P6von+Bs06zSd6GqEmjN5j6I0eVGOciR0yOCY93arNhPL0tO+W+o6qEFQDfkUb7t2jIKTFsjESs5p73fFoS//waIsBH9NJ2V0Akn7gEvwzTGgSv7WxTWu568BkQo0vSPlwNQdZ8N+kikkEhsOld24Ua1aVVqxW3Yk=; 24:LfDKLmDxoAJ//uQkPECe4Q2a4rlAyMP247guH58JR1HV+1AmSdL69GBkbL98eJz2bB4ympZAd1rRKKfpzzCwGcEbgW0UtmobyCvduwwLuXY=; 7:7JWTPZJZhs+26gRQjWj/pge3fTj6rIL2qqUlTc62QM55GiphVq9K4kbB8mbLqP646fUlvg/mb9+GRB7UcWSPa3he0erJR+4eXXub3bQ1cmtlFiwS48s+GWkcCyCzUcvKlImbAXXf1bLXkMwcMpgp+A2tUaXj4O18UtuHAGQrvKPrsy+6cwb/UC5qMyLQCo/Alwb8+ukAKbP20+dX2OjQnm5TgI1RKAMmoXvtE4JQAhbFSOo1SzSTJc3Dn4U/5paV
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 31 Oct 2017 17:58:15.3444 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b6583e30-20a8-42ab-5b08-08d52088f618
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB3418
Archived-At: <https://mailarchive.ietf.org/arch/msg/teas/7Sw_sVHKm_i5dNWUyvEZ84NXUbs>
Subject: Re: [Teas] Eric Rescorla's No Objection on draft-ietf-teas-lsp-diversity-08: (with COMMENT)
X-BeenThere: teas@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Traffic Engineering Architecture and Signaling working group discussion list <teas.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/teas>, <mailto:teas-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/teas/>
List-Post: <mailto:teas@ietf.org>
List-Help: <mailto:teas-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/teas>, <mailto:teas-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 Oct 2017 17:58:22 -0000

Hi Eric,

my apologies for the late response - it was difficult for me finding time in the last weeks to address the IESG review comments.

Please find the answers to your comments in-line below.

Could you please let us know if your comments are adequately addressed.


Thanks,
Dieter and co-authors


On 30.08.2017 22:20, Eric Rescorla wrote:
Eric Rescorla has entered the following ballot position for
draft-ietf-teas-lsp-diversity-08: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html" rel="nofollow">https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-teas-lsp-diversity/" rel="nofollow">https://datatracker.ietf.org/doc/draft-ietf-teas-lsp-diversity/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I'm not sure that the security considerations here are accurate. Specifically,
the PAS seems like it might potentially leak information about paths, because
if I am able to learn someone else's PAS values, I can tell if they are routed
along the same paths as I am. Is that correct? If so, it seems like it might be
useful to recommend self-encrypting PAS values so that two identical paths
given to separate people have different PAS values.

We do not believe that encryption at the UNI is required because the Path key (PCE approach) or the PAS information is not shared between the core network
and all edge nodes connected to the core network (see Figure 1). It is assumed that only a particular edge node receives a Path key or PAS information for an
LSP that this edge node initiated before requesting another LSP that shall meet certain diversity constraints insid the core network. Path keys and PAS is only
meaningful in the context of a pair or several LSPs oriiginating from the same edge node. These LSPs shall meet diversity constraints inside the core network in
order to avoid that they will all fail together due to a failure in the core network - a typical failure is a link cut.

Moreover, Path key or a PAS are already abstract information and do not allow the edge node to infer any topological information of the core network.


Also, it seems like it S 2.3 would be clearer if you factored out the algorithm
for processing the XRO values from the differential treatment depending on the
L bit. Perhaps you could just have one list and use [SHOULD (L=1), MUST(L=0)]
or something?

A combined list would be an alternative way to describe the processing rules for the L-flag in section2.3.
On the other hand, we believe that nothing is technically wrong with the current description, where two lists are used.
So, we would like to keep the description as is.