Re: [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06

"C. M. Heard" <heard@pobox.com> Tue, 04 December 2018 22:56 UTC

Return-Path: <heard@pobox.com>
X-Original-To: tsv-art@ietfa.amsl.com
Delivered-To: tsv-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 70237128D0C; Tue, 4 Dec 2018 14:56:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level:
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=pobox.com; domainkeys=pass (1024-bit key) header.from=heard@pobox.com header.d=pobox.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NgSA_XzELUpC; Tue, 4 Dec 2018 14:56:50 -0800 (PST)
Received: from pb-smtp20.pobox.com (pb-smtp20.pobox.com [173.228.157.52]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC8C9123FFD; Tue, 4 Dec 2018 14:56:50 -0800 (PST)
Received: from pb-smtp20.pobox.com (unknown [127.0.0.1]) by pb-smtp20.pobox.com (Postfix) with ESMTP id 5547822221; Tue, 4 Dec 2018 17:56:49 -0500 (EST) (envelope-from heard@pobox.com)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=pobox.com; h=mime-version :from:date:message-id:subject:to:cc:content-type; s=sasl; bh=z/3 fm2lfa445V3sR6GciBX8UGls=; b=vL+yl2Ph7HyDhVKRoYvgXW1F8eJpbWjtPDV UuX6wO/fcYYDiA6Sor02qQoPu0zZTgaYjkP+oH1c+M+3+wvfKP5RpUaJHV/w2gPS yJ2+4ck6uHsj5VW/srz63jWH5CO0las7RvcFJxAkpSSI2PfPraKthsgiAjRw32iu HdRCnIOo=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=pobox.com; h=mime-version :from:date:message-id:subject:to:cc:content-type; q=dns; s=sasl; b= hAuBf3xP7T5BanvDOZXaNgDwUODcv7gMQeBhatr6kmDnsFFPGcO7VwH+jtKlWSq/ aExnlkLMSd5r2SW3tWIYdN+FQfK+5IKXW6GaytPk8Gnjd9dFiuagbXmCCNsKspm5 l8BKA8Ts8ZllkogiKIhLu+7KkClYLbxCSWXcxgX+iXY=
Received: from pb-smtp20.sea.icgroup.com (unknown [127.0.0.1]) by pb-smtp20.pobox.com (Postfix) with ESMTP id 4E0FD2221F; Tue, 4 Dec 2018 17:56:49 -0500 (EST) (envelope-from heard@pobox.com)
Received: from mail-it1-f174.google.com (unknown [209.85.166.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pb-smtp20.pobox.com (Postfix) with ESMTPSA id BC64122219; Tue, 4 Dec 2018 17:56:45 -0500 (EST) (envelope-from heard@pobox.com)
Received: by mail-it1-f174.google.com with SMTP id x19so18318741itl.1; Tue, 04 Dec 2018 14:56:45 -0800 (PST)
X-Gm-Message-State: AA+aEWYxytsbsM+uaQilUY6nLHlFuoex3UJL6w6Yy+0vd6/Hbh18BGQJ Vo40MYxyIyijEgp/eR302rR6l937BRbCbjSx96o=
X-Google-Smtp-Source: AFSGD/W2bgjtG2WPTqYoBYYnGwbap2VsUwQX284gbs2b/tHkE2EbYfH+5jUzWNvkxdojpKqnUWSxYE4X5zGhH5vBEnU=
X-Received: by 2002:a02:b529:: with SMTP id l38mr18924506jaj.25.1543964204581; Tue, 04 Dec 2018 14:56:44 -0800 (PST)
MIME-Version: 1.0
From: "C. M. Heard" <heard@pobox.com>
Date: Tue, 04 Dec 2018 14:56:32 -0800
X-Gmail-Original-Message-ID: <CACL_3VGeJPzDhS0RVAvpQs9W8b4EODft-qJRwBD6Xxm+X6BZ6A@mail.gmail.com>
Message-ID: <CACL_3VGeJPzDhS0RVAvpQs9W8b4EODft-qJRwBD6Xxm+X6BZ6A@mail.gmail.com>
To: Christopher Morrow <morrowc.lists@gmail.com>
Cc: Joe Touch <touch@strayalpha.com>, Stewart Bryant <stewart.bryant@gmail.com>, TSV-ART <tsv-art@ietf.org>, OPSEC <opsec@ietf.org>, IETF <ietf@ietf.org>, draft-ietf-opsec-ipv6-eh-filtering.all@ietf.org, Nick Hilliard <nick@foobar.org>
Content-Type: text/plain; charset="UTF-8"
X-Pobox-Relay-ID: DFD2AF30-F817-11E8-9417-F5C31241B9FE-06080547!pb-smtp20.pobox.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsv-art/APbYC6eK9UCQYbDl2DYH5ICun2M>
Subject: Re: [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06
X-BeenThere: tsv-art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Transport Area Review Team <tsv-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsv-art>, <mailto:tsv-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsv-art/>
List-Post: <mailto:tsv-art@ietf.org>
List-Help: <mailto:tsv-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsv-art>, <mailto:tsv-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 04 Dec 2018 22:56:53 -0000

On Tue, 4 Dec 2018 15:17:33 -0500 Christopher Morrow wrote:
> A solution might be to have a mode where  a router may just ignore all
> headers except the src/dst-ip and simply forward all packets, trusting
> that the conversing adults will sort out problems with unknown/new/
> experimental headers or with a tortured ordering of headers (for
> instance).

Glad to hear you say that, because that's exactly what RFC 7045
envisions as the default forwarding behavior:

   Any forwarding node along an IPv6 packet's path, which forwards the
   packet for any reason, SHOULD do so regardless of any extension
   headers that are present [...]

Recognizing that processing of Hop-by-Hop Options in the fast path is
costly, RFC 8200 formally dropped the requirement for every router to
process them by default:

   NOTE: While [RFC2460] required that all nodes must examine and
   process the Hop-by-Hop Options header, it is now expected that nodes
   along a packet's delivery path only examine and process the
   Hop-by-Hop Options header if explicitly configured to do so.

What some of us would like to see is a statement in the draft that it's
just fine to operate this way (Christian Huitema made that suggestion
earlier in this thread, and so did I in my detailed last-call comments).

Mike Heard