Re: statement regarding keepalives

Kent Watsen <kwatsen@juniper.net> Fri, 20 July 2018 15:14 UTC

Return-Path: <kwatsen@juniper.net>
X-Original-To: tsv-area@ietfa.amsl.com
Delivered-To: tsv-area@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF175131053; Fri, 20 Jul 2018 08:14:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level:
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IuIn6D7Td961; Fri, 20 Jul 2018 08:14:50 -0700 (PDT)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CB767130DCC; Fri, 20 Jul 2018 08:14:50 -0700 (PDT)
Received: from pps.filterd (m0108163.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w6KFEES5032359; Fri, 20 Jul 2018 08:14:49 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : content-id : content-transfer-encoding : mime-version; s=PPS1017; bh=An1C10Y1QqlMxQG4TYwTWSGsC7Zr6ZXR6h/c+41CnaQ=; b=2AIakvvHFPzCcLctOV56juP/EXjEMIqZlTac+p+JpiuhtIAo5gdbzReCZtEvofggwZkB lkcS4GyWu2eW5PvwtYTeUKwzW9+XJRcPctAE73pqnNsh8bP6+wMZZ7tAjCn4rM6iuBfw fxlp0/EdTnUfvAaOMkn5b1JXcCgPvsZU4O39VeGx6QAok4/LfWT/KAB3xl6UNx91yQ5o 8Ox83sDI3c5T6hpBeQRlnCi1GKmNJ9E8Tu687n//Y8RjeTCX1qA8CuPmwH8qxHFT+UUx 6Kzlbt8k2Njx4k6p3vijRAnsSov2HUh1GI9jM7lp7UgJsx+wcn8KN5TmAcXBfEohv7zE RQ==
Received: from nam02-bl2-obe.outbound.protection.outlook.com (mail-bl2nam02lp0085.outbound.protection.outlook.com [207.46.163.85]) by mx0b-00273201.pphosted.com with ESMTP id 2kbf7a8an8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Fri, 20 Jul 2018 08:14:49 -0700
Received: from BYAPR05MB4230.namprd05.prod.outlook.com (52.135.200.153) by BYAPR05MB4151.namprd05.prod.outlook.com (52.135.199.160) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.995.9; Fri, 20 Jul 2018 15:14:47 +0000
Received: from BYAPR05MB4230.namprd05.prod.outlook.com ([fe80::9006:fad3:993d:25fe]) by BYAPR05MB4230.namprd05.prod.outlook.com ([fe80::9006:fad3:993d:25fe%2]) with mapi id 15.20.0973.016; Fri, 20 Jul 2018 15:14:47 +0000
From: Kent Watsen <kwatsen@juniper.net>
To: Mikael Abrahamsson <swmike@swm.pp.se>
CC: "tsv-area@ietf.org" <tsv-area@ietf.org>, "tsvwg-ads@tools.ietf.org" <tsvwg-ads@tools.ietf.org>, "tls-ads@ietf.org" <tls-ads@ietf.org>, "netconf-chairs@ietf.org" <netconf-chairs@ietf.org>
Subject: Re: statement regarding keepalives
Thread-Topic: statement regarding keepalives
Thread-Index: AQHUGkG/LZoJEIu3uky/qk612ULG36SYCm6A///2yoA=
Date: Fri, 20 Jul 2018 15:14:47 +0000
Message-ID: <B50DC954-CBB6-41C5-BE3A-F1DECD6046A5@juniper.net>
References: <D3326DE0-3F31-4045-B945-82B3F417BE4B@juniper.net> <alpine.DEB.2.20.1807201340240.14354@uplift.swm.pp.se>
In-Reply-To: <alpine.DEB.2.20.1807201340240.14354@uplift.swm.pp.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.20.0.170309
x-originating-ip: [66.129.241.13]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; BYAPR05MB4151; 6:la/drGINWaEQzAg8zvI8Wipa+Y9bkYvCs+RloJM8YkbG06ou/HtP6HpKtRUZsU+eDGS2Ef6LYBQGD/kkGpDHx2GOaJwQkeQ949qumISX9h+wIodQco5qRMaWxzVm0ZLEVAhI8sxSoOTPZogkbInDGY7kmtj5h1ej89aidv6TcX8AbfOz8jwoctm6CTyZ9vzzwtO7v/irFgaDO/YB8uYcKC2V0neghTJpGxMQjX8uC99ZHbkYKbB1e9jWfh8pZgYzmOSixdTsscMLsvW6mqkBoWXIlakxCsfCSyChsMapetvv3dH3yYxjRErtLBjmVaT9Ut6gyrlvmt8r0NsWAihXPSFnLwl/qNSYZX5oPXo24q1wsg43XV1LzJ0VBtPD7drYSmz2pgPd+2HwF5WQOOXmI2c+7GC9A+JY5RnPF8q+6GwpiBb8A+1J2oytHdP89F+MirC3/79nf6jb3w3Sp0UnQA==; 5:lb1/b89gMnPmOiI8KVk4ds+BwC2IiXT8HCEKrx2YXSMe6IPx2FuKctEjeRW/IjcMPQJJl4YUH/nXeRgc3fS5mgdXovyVNNx7sjV2L7wW/K9GXtYGWB20GEkBIfOEv690ON9Wmu3pelCzqucLIqSCKtUdUC4leAuTtG3qF/h4Gd4=; 7:XXZIfKG+3JBBZ7gjTe8d4DlIhwu3gi/TNdaZrR4tVhGkO6hMk0z7amvkZjRlg/Vr87RtRurSJnetb8NaaTo4+NKrstO/T4cz2RVoe+RbIdqOmuXEhL3ULhRaJsd67kMWwMvoKVvtWUTapQod57DEqWJ+NClNuzaXx0QCCj1Pc9XVS2Jp1Oo/PS3gahwpJPQIWvpq9aQnG4/laKzCNYb6rviimxenntxxOscXvGIqMvO8DhqvMskMcJoSe9Ch63zb
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: b7f04e19-7292-4441-da3a-08d5ee538825
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989117)(4534165)(4627221)(201703031133081)(201702281549075)(8990107)(5600053)(711020)(48565401081)(2017052603328)(7153060)(7193020); SRVR:BYAPR05MB4151;
x-ms-traffictypediagnostic: BYAPR05MB4151:
x-microsoft-antispam-prvs: <BYAPR05MB4151B6E56E9815FB0E751C2CA5510@BYAPR05MB4151.namprd05.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(5005006)(8121501046)(3231311)(944501410)(52105095)(3002001)(93006095)(93001095)(10201501046)(6055026)(149027)(150027)(6041310)(20161123558120)(20161123562045)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(6072148)(201708071742011)(7699016); SRVR:BYAPR05MB4151; BCL:0; PCL:0; RULEID:; SRVR:BYAPR05MB4151;
x-forefront-prvs: 073966E86B
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(346002)(136003)(366004)(396003)(39860400002)(376002)(189003)(199004)(7116003)(305945005)(106356001)(8936002)(66066001)(478600001)(97736004)(6486002)(81166006)(81156014)(2900100001)(6436002)(446003)(8676002)(6916009)(5250100002)(256004)(6116002)(86362001)(11346002)(14454004)(82746002)(3846002)(54906003)(58126008)(99286004)(68736007)(76176011)(33656002)(186003)(53936002)(6512007)(2906002)(7736002)(105586002)(6506007)(3480700004)(316002)(486006)(25786009)(6246003)(102836004)(83716003)(2616005)(4326008)(26005)(476003)(5660300001)(229853002)(36756003); DIR:OUT; SFP:1102; SCL:1; SRVR:BYAPR05MB4151; H:BYAPR05MB4230.namprd05.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-microsoft-antispam-message-info: 71PgQsmgRbfv9IZXoxtruktJB2Tt3fzzxESghQSMclx5jDFIH0zdc+zjFXvuZuvpPNOHZGO0Fhfcws+KNHgKjU1U6EFurJd2ifwcJF9ZcJkLg/W3zMHFqh+u6dlCw1kbb2U8Nwk5igXKp4aUFH6XD6vAZ+EQkPDW8Zpge9wdqN6OhD4cswVDncYVXL0iwpnotiTs+SmmoTzrm0GM+w3oXHGM2w00Wd9x136klSC1PtxlvZgw25AiuR5vFE6JJFxlfxS4sGy7hGDiQPA20yhO3LGWK8SQKWkf4cPiLUzN+w29fkudPdlnfO8pgDNUSqShRYkeR1iXls8GdR+0MADW+u1Hyd1+gPkovg7npO+sCT8=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <2863E150C9BCE2438BCB9142B93999B5@namprd05.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: b7f04e19-7292-4441-da3a-08d5ee538825
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Jul 2018 15:14:47.5734 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB4151
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-07-20_04:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=682 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1806210000 definitions=main-1807200171
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsv-area/OFNOGDg8gld_fJtV3JUTbIjXnGo>
X-BeenThere: tsv-area@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF Transport and Services Area Mailing List <tsv-area.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsv-area>, <mailto:tsv-area-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsv-area/>
List-Post: <mailto:tsv-area@ietf.org>
List-Help: <mailto:tsv-area-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsv-area>, <mailto:tsv-area-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 20 Jul 2018 15:14:54 -0000

> ...but still don't put off people turning on TCP keepalives "because
> the IETF doesn't recommend that", and thus they do nothing at all and
> the problem just persists.

No disagreement with what you and others have written, but note that 
the proposed statement only recommends not using TCP keepalives in
the presence of a crypto layer on top of the TCP-layer.

Perhaps the statement could be refined, something along the lines 
of, in cases when there is a crypto layer, to recommend not using,
or at least relying on, TCP keepalives, *unless* higher-level
keepalives have stopped working.

To be clear, the statement as written, though not stated explicitly,
recommends TCP keepalives, in cases where they make sense.

Kent