Re: [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06

Joe Touch <touch@strayalpha.com> Wed, 05 December 2018 01:17 UTC

Return-Path: <touch@strayalpha.com>
X-Original-To: tsv-art@ietfa.amsl.com
Delivered-To: tsv-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04B31130DD0; Tue, 4 Dec 2018 17:17:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.221
X-Spam-Level:
X-Spam-Status: No, score=-1.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_NEUTRAL=0.779] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=strayalpha.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c7NbOXmRxiS8; Tue, 4 Dec 2018 17:17:23 -0800 (PST)
Received: from server217-3.web-hosting.com (server217-3.web-hosting.com [198.54.115.226]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B929B130DC2; Tue, 4 Dec 2018 17:17:23 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=strayalpha.com; s=default; h=To:References:Message-Id: Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version: Content-Type:Sender:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=cO2f3WuaG3vj/jEXiZyEpdH3NgJoZjQ7ZnspymDeHk4=; b=w5ajJ8DhsqkCDTDy6cU70Apk5 UNs9TMtgeY+o4U/9nnLpqoCVTQnBaNe28ZAo2p/dT49DYKKftOg8UvTDNL2M53qe9tv2vXzVrzaLq FAwKH0epWhA0HoTtKW6J3vFhjTZV5Hc4Z+snBZjZTBbdCHYEKtnZ18TUPd8bW47T3XM1OsHzrJcuj x3baZhg54phd9mLLeTYAM8UY6hZcNeM193YlhWq2bIYLigHz8NDtGPNtevUxe17Q+uZ5vIuAzkVm5 CoUvHsg2C2hrQeieoIbbN3YTbPYNhkmo2gL5L4L+Jx+D3ZD7Qmuixwuo0NHWdXTRroOcJWShXcV4t hdLrwGIpg==;
Received: from cpe-172-250-240-132.socal.res.rr.com ([172.250.240.132]:57836 helo=[192.168.1.77]) by server217.web-hosting.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.91) (envelope-from <touch@strayalpha.com>) id 1gULoY-001SkA-C8; Tue, 04 Dec 2018 20:17:23 -0500
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Joe Touch <touch@strayalpha.com>
In-Reply-To: <CACL_3VGeJPzDhS0RVAvpQs9W8b4EODft-qJRwBD6Xxm+X6BZ6A@mail.gmail.com>
Date: Tue, 04 Dec 2018 17:17:21 -0800
Cc: Christopher Morrow <morrowc.lists@gmail.com>, IETF <ietf@ietf.org>, draft-ietf-opsec-ipv6-eh-filtering.all@ietf.org, Nick Hilliard <nick@foobar.org>, OPSEC <opsec@ietf.org>, TSV-ART <tsv-art@ietf.org>, Stewart Bryant <stewart.bryant@gmail.com>
Content-Transfer-Encoding: quoted-printable
Message-Id: <B6C8F695-074C-40BF-A73F-1B0C85F08F71@strayalpha.com>
References: <CACL_3VGeJPzDhS0RVAvpQs9W8b4EODft-qJRwBD6Xxm+X6BZ6A@mail.gmail.com>
To: "C. M. Heard" <heard@pobox.com>
X-Mailer: Apple Mail (2.3445.9.1)
X-OutGoing-Spam-Status: No, score=-0.5
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server217.web-hosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - strayalpha.com
X-Get-Message-Sender-Via: server217.web-hosting.com: authenticated_id: touch@strayalpha.com
X-Authenticated-Sender: server217.web-hosting.com: touch@strayalpha.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-From-Rewrite: unmodified, already matched
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsv-art/HhCEmM_46mCzeMS8ZXWPkgFNMds>
Subject: Re: [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06
X-BeenThere: tsv-art@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Transport Area Review Team <tsv-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsv-art>, <mailto:tsv-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsv-art/>
List-Post: <mailto:tsv-art@ietf.org>
List-Help: <mailto:tsv-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsv-art>, <mailto:tsv-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Dec 2018 01:17:25 -0000

It’s difficult to reconcile the text from other RFCs below with the fact that 8200 kept the 01, 10, and 11 option types.

Joe

> On Dec 4, 2018, at 2:56 PM, C. M. Heard <heard@pobox.com> wrote:
> 
> On Tue, 4 Dec 2018 15:17:33 -0500 Christopher Morrow wrote:
>> A solution might be to have a mode where  a router may just ignore all
>> headers except the src/dst-ip and simply forward all packets, trusting
>> that the conversing adults will sort out problems with unknown/new/
>> experimental headers or with a tortured ordering of headers (for
>> instance).
> 
> Glad to hear you say that, because that's exactly what RFC 7045
> envisions as the default forwarding behavior:
> 
>   Any forwarding node along an IPv6 packet's path, which forwards the
>   packet for any reason, SHOULD do so regardless of any extension
>   headers that are present […]r

This text is in direct contradiction to RFC2460 as per above. 

> 
> Recognizing that processing of Hop-by-Hop Options in the fast path is
> costly, RFC 8200 formally dropped the requirement for every router to
> process them by default:
> 
>   NOTE: While [RFC2460] required that all nodes must examine and
>   process the Hop-by-Hop Options header, it is now expected that nodes
>   along a packet's delivery path only examine and process the
>   Hop-by-Hop Options header if explicitly configured to do so.

That is an expectation of the inadequacy of others. It does not clearly drop the requirement.

> 
> What some of us would like to see is a statement in the draft that it's
> just fine to operate this way (Christian Huitema made that suggestion
> earlier in this thread, and so did I in my detailed last-call comments).
> 
> Mike Heard
> 
> _______________________________________________
> Tsv-art mailing list
> Tsv-art@ietf.org
> https://www.ietf.org/mailman/listinfo/tsv-art