Re: [tsvwg] Éric Vyncke's Discuss on draft-ietf-tsvwg-rfc6040update-shim-21: (with DISCUSS and COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Tue, 05 December 2023 15:02 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: tsvwg@ietfa.amsl.com
Delivered-To: tsvwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 80E00C14F5F3; Tue, 5 Dec 2023 07:02:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.605
X-Spam-Level:
X-Spam-Status: No, score=-14.605 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z6rLzgFLjk1n; Tue, 5 Dec 2023 07:02:02 -0800 (PST)
Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0C5EDC14F5E2; Tue, 5 Dec 2023 07:02:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=37719; q=dns/txt; s=iport; t=1701788522; x=1702998122; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=lDGT+p0JFvDHqqLDZNBvLnM8Jp0c9/9GtHbV0QWDb4I=; b=Q7RsO6fb13K/5kZb6aHwIcpZCtPrPJHSZC8xpFw0qb3TlV7WKqPRRAvA gMyQnNovCj6AT1+GOvriBQLgIFQOerVX7uibqZCb6GEQdlsrDiD5Vv0wW KCo9IXC5u/BU8J074fY3QluTWdAFbnEyU9tcl1mWkba3kwcXfvz1eFWkZ c=;
X-CSE-ConnectionGUID: z06zGxxGQZOiPXDUC9yHuA==
X-CSE-MsgGUID: lycf+MCkTNqUxdme420SoQ==
X-IPAS-Result: A0ANAADrOW9lmJhdJa1aGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQFAJYEZAQEBAQEBCwGBNTFSeQJZKhJIA4YygWkDhS2IZgOLXIVfjFeBEQNWDwEBAQ0BAT0HBAEBg0+BNwKHKQImNwYOAQIEAQEBAQMCAwEBAQEBAQECAQEFAQEBAgEHBBQBAQEBAQEBAR4ZBQ4QJ4VoDYZFAQEBAQMSZxACAQgOAwMBAiEBAgQHIREUCQgCBAENBQgODIJeAYIWFAMxAwEQoX8BgUACiih4gTSBAYIVBYE8AgELAgJAAa4JDYJUgUgBh28EGgFoZoFjgiiENScbgUlEgRVCgmg+gh9CAQEDgSgBEgEHHB4WCBCDRoIvBIZTggQVLgcygQkMCYEDgykpgRACg2GLMFwiR3AdAwcDfw8rBwQtGwcGCRQYFSMGUQQoIQkTEj4EgygKfz8PDhGCPiICBzY2GUiCWxUGOzkRdRAqBBQXaiAIBGobEx43ERIXDQMIdB0CMjwDBQMEMwoSDQshBRRCA0IGSQsDAhoFAwMEgTMFDR4CEBoGDCcDAxJJAhAUAzsDAwYDCzEDMFVEDE8DEVofNgk8DwwfAhseDScjAixCAxEFEgIWAyQWBDYRCQsoAy8GOAITDAYGCV4mFgkEJwMIBAMQMQNEHUADC209NRQbBQRkWQWgAw+BNIFDEFsGASIbJgQiDwEJEAcBBBBUGDAdCAkCHgQCAQ4DDhk6A5I8CQIIgxYBi1SEFYotkz8/bwqED4wCjxeGKReEAYFWix2RZ4ZHZJhCII1Ig3aRMggPCYR/AgQCBAUCDgEBBjWBRCRrcHAVO4IzAQEBMQlJGQ+NfjsfiBk7imV2EikCBwEKAQEDCQGKAV8BAQ
IronPort-PHdr: A9a23:TVrQLBKbV5bw+ST+ztmcuaoyDhhOgF28FhQe5pxijKpBbeH/uZ/jJ 0fYo/5qiQyBUYba7qdcgvHN++D7WGMG6Iqcqn1KbpFWVhEEhMlX1wwtCcKIEwv6edbhbjcxG 4JJU1o2t2qjPx1tEd3lL0bXvmX06DcTHhvlMg8gK/rkHIXRguy81vu5/NvYZAAbzDa4aKl5e Q2/th6Z9tFDmJZrMK831hrPrzNEev8Dw2RuKBPbk0P359y7+9ho9CE4hg==
IronPort-Data: A9a23:gVdgcKL+BOs/onnJFE+RGpUlxSXFcZb7ZxGr2PjKsXjdYENShGMPy GBLX22APvyNNDH9fdwlbtu19hsBvcOBytU2TFMd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcYZsCCea/0/xWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVvR0 T/Oi5eHYgT8gWYpajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKmWDNrfnL wpr5OjRElLxp3/BOPv8+lrIWhFirorpAOS7oiE+t55OLfR1jndaPq4TbJLwYKrM4tmDt4gZJ N5l7fRcReq1V0HBsLx1bvVWL81xFb8epq3oMWiQiP60znX2X0bHkuROEWhjaOX0+s4vaY1P3 eYTJDZIZReZiqfvhrm6UeJrwM8kKaEHPqtG5Somlm6fXK1gGM2ZK0nJzYcwMDMYi95fG/3da uISaCFka1LLZBgn1lI/Uc9kwrn52SCmG9FegFaErqR0xkPQ8Cpo7ajhNdeJIISxQvwAyy50o UqdojymWUtFXDCF8hKZ6WyziarEnSr6Qpk6FbCk+LhtmlL77mAJARMKEFq2vff8llWgRN0aM UIfpHJy9bUq+EW3Q5zmXxy9iH+JohBaXMBfe8Um8x+SxYLV7hqXQG8eQVZpadE9u+c3SCAkk FiTkLvU6SdHqraZTzeW8a2Z6Gr0MikOJmhEbigBJecY3zX9iJNr0ADgXsZMKZySj+XFNQzbk iGqsQFr0t3/kvU3/6m8+FnGhRelqZ7IUhM5623rsoSNsFsRiGmNOdTA1LTL0cusOrp1WbVog ZTps9KV4OZLBpaXmWnUBu4MB7quof2CNVUwYGKD/bF/q1xBGFb6Iei8BQ2Swm81a67onhe1O ifuVft5vsM7AZdTRfYfj3iNI8or17P8Mt/uS+rZaNFDCrAoK1feo3gyOxDBhT21+KTJrU3ZE cnCGSpLJShDYZmLMBLvHo/xLJdyn39hmzuLLXwF50//jur2iIGppUctawbWMbtjs8toUS3e8 s1UMIOR2g5DXejlKijR+sh7ELz5BSZTOHwCkOQOLrTrClM/QAkJUqaNqZt/INYNt/oOyY/1E oSVBxUwJKzX3yOXcG1nqxlLNdvSYHqIhStkZ3N9Zw/5gSdLjETGxP53SqbbtIIPrYRL5fV1V PICPc6HB5xypv7volzxsbGVQFReSSmW
IronPort-HdrOrdr: A9a23:hjjtaaCrYvoiAm7lHejlsseALOsnbusQ8zAXPh9KOH9om52j9/ xGws576fatskduZJhBo7y90KnpewK7yXcH2/hhAV7CZnirhILGFvAZ0WKP+UyFJ8S6zJ8j6U 4CSdkwNDSTNykGsS+S2mDReLhQoqjjzEnrv5aj854Hd3ASV0gU1XYDNu/tKDwPeOApP+tfKL OsouB8i36Lf3MRYs6nBn8DcdTiirTw/q7OUFotPTJizBOBow+JxdfBfiRw2C1wbxp/hZMZtU TVmQ3w4auu99uhzAXH6mPV55NK3PP819pqHqW3+4koAwSprjztSJVqWrWEsjxwivqo8kwWnN 7FpAplF9hv6knWYnq+rXLWqkndOXcVmjzfIG2j8D7eSP/CNXYH4g169MVkmy7imggdVRdHoe R2NiyixsNq5Fj77VTADpDzJmJXfwyP0DQfeSp5tQ0FbWPYA4Uh9bA37QdbFowNEzn9751iGO 5yDNvE7PITal+CaWvF11Mfi+BEc05DVytueHJy8vC9wnxThjR03kEYzMsQkjMJ8488UYBN46 DBPr5znL9DQ8cKZeYlbd1xDPefGyjIW1bBIWiSKVPoGOUOPG/MsYf+5PEw6PuxcJIFwZMukN DKUU9et2Q1Z0XyYPf+lqFj41TIWiGwTD7twsZR69xwvaD9XqPiNWmZRFUng6Kb0oMi6w3gKo GO0b5tcovexDHVaPR0NiXFKuxvFUU=
X-Talos-CUID: 9a23:usbpcmt1Wk7Ajq+wU1Ni2+I26Is3KiPP42fADHaKLmdReJGoYg6B2L5Nxp8=
X-Talos-MUID: 9a23:4FYTwgz2iKSHzjt9+yVcujpK74uaqKC/A05OtL4Fh++dCDx8PjrB1myMRbZyfw==
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-1.cisco.com ([173.37.93.152]) by rcdn-iport-9.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 05 Dec 2023 15:02:00 +0000
Received: from rcdn-opgw-4.cisco.com (rcdn-opgw-4.cisco.com [72.163.7.165]) by rcdn-core-1.cisco.com (8.15.2/8.15.2) with ESMTPS id 3B5F1uKP025971 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 5 Dec 2023 15:02:00 GMT
X-CSE-ConnectionGUID: GYuj8S0aSduQtezK5AwAYg==
X-CSE-MsgGUID: MaeTlpT6SB6x3kFc7hifOg==
Authentication-Results: rcdn-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com; spf=Pass smtp.mailfrom=evyncke@cisco.com; dmarc=pass (p=quarantine dis=none) d=cisco.com
X-IronPort-AV: E=Sophos;i="6.04,252,1695686400"; d="scan'208,217";a="14190632"
Received: from mail-dm3nam02lp2040.outbound.protection.outlook.com (HELO NAM02-DM3-obe.outbound.protection.outlook.com) ([104.47.56.40]) by rcdn-opgw-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 05 Dec 2023 15:01:56 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=eFEmjJnaY+7xpUryqimQZIAsolw8K/8UmGSPOwERY0OACBIHBcOWumb6vOwO+qab0kCqytPzlBPKBJCbbqu5BFBtLsKHSNaf2famtxlx8UrzdDki2DM4RpH0OjdfS/CfSXWMPJk66HHIw7scYEga7eccauUnhBdpNFVHvKlk4vV6PpwzlIjsd0VYhn1Bjvd1BvyGKbL7L/Axeb/O3r3VYccv5/Am7dj7r+R0dDTMY9FrSZ3n8j4i+CwuNecbbySp2ZaGgpzFi8A/tKNRHqfjsdYzUXs6puaFCCtPm71D+M748lCTJkqbs5E2vdHJFRjuIPyaajotPKIgiecpKWmsmw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=YAt5eXysz1GA0WZnAYSPLfHQkeWoQSWf7lzRqJrm8Ug=; b=R17K4H1XIUm5pTLA6Je5JUk01n4J1DRxipfV0Vy9/S5vLHOJSeyvUKHldi9bW4cNMvRpWPbqt80SppCtEC7cYJFRHED2QZxvOz6iWQJ2ixKrQNT4qKx0ZvfvgZ/KzqHL80PiCiXINU//xAlNvdSkvkbtmM4s63jGkaR8antICQriSFWzUssLBIKFoC7GXd++JnPCCZD3iRrkVof7eXD2CN9AaTwMnKayNmcZ/S9wGoFaGQv1wXDAkYstPGqO03+Osnp8ONJBZ2JtfdEvvo2RldRLJXFx4cJYtSiZ1vE+R6euDe9yrGLC/ikGD6YpE1H71aQAX8LhffY3I9QggLAHiw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by DM4PR11MB6165.namprd11.prod.outlook.com (2603:10b6:8:ae::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7046.34; Tue, 5 Dec 2023 15:01:54 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::4354:3cc:1204:95d6]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::4354:3cc:1204:95d6%4]) with mapi id 15.20.7046.032; Tue, 5 Dec 2023 15:01:54 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Bob Briscoe <ietf@bobbriscoe.net>, The IESG <iesg@ietf.org>
CC: "gorry@erg.abdn.ac.uk" <gorry@erg.abdn.ac.uk>, "tsvwg@ietf.org" <tsvwg@ietf.org>, "draft-ietf-tsvwg-rfc6040update-shim@ietf.org" <draft-ietf-tsvwg-rfc6040update-shim@ietf.org>, "tsvwg-chairs@ietf.org" <tsvwg-chairs@ietf.org>, "d3e3e3@gmail.com" <d3e3e3@gmail.com>
Thread-Topic: [tsvwg] Éric Vyncke's Discuss on draft-ietf-tsvwg-rfc6040update-shim-21: (with DISCUSS and COMMENT)
Thread-Index: AQHaJKFHyAxDyQHULEuvDdNCLes7NrCZD+8pgADJVwCAAPTMuQ==
Date: Tue, 05 Dec 2023 15:01:54 +0000
Message-ID: <PH0PR11MB4966B6284C9235AAA2DFE555A985A@PH0PR11MB4966.namprd11.prod.outlook.com>
References: <170115584746.29426.10484446828614575033@ietfa.amsl.com> <b522a540-e19c-4266-9b1e-6631dc5b89e0@bobbriscoe.net> <PH0PR11MB4966A229E5DEED754DC481E7A986A@PH0PR11MB4966.namprd11.prod.outlook.com> <19d852f4-499b-4f03-8582-e3e70f078026@bobbriscoe.net>
In-Reply-To: <19d852f4-499b-4f03-8582-e3e70f078026@bobbriscoe.net>
Accept-Language: fr-BE, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR11MB4966:EE_|DM4PR11MB6165:EE_
x-ms-office365-filtering-correlation-id: 97ee34cd-b42e-46b4-141e-08dbf5a31e60
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: /sTwN4Ky8S/FbT3fCPh0Z0TlqQ/Yp3GS1oImYSGSduJPssp98tOdHWtLli6zSSz5qJ1nF7W2goD50asD8gNx8clCBXN5E3l+e694CfLer3+YoTOCbpympb/OXvO16l0Y3IU3chRfCbNUlmXDaKYePfz8VXcxNCR3b6/jvFXLxBgk8w3TQVX9f0SO6uMoiH9owAIywkkclRK17FpML5dwoa4i+bIsEMQQS1+UqU7F4xnyDtOmWurElC/VjoH4TdidyydoxQLc8Q+3gXSBY1C2ynwnwtgv5wF3zu5vuzbf6+CWUckb/hW99p0sDk7aLySrQO/tOsIwGWaQZEgaVLPdbo9JObwRsmEK+MMD942BWtxUJneV6AllF1lLdau+0l14f/q0pkfJxiT6UhZxYF4e828UJtNnfTVlivwWvBQmrU0v3cS6p3ZA/CnCZdnh06v72lyelvkOUKA/rLH2iwQhavakWHNvH0VackMvHXouKIr7vVqeIEsGAiGT5SbcdnL4V7jFQr8Ihki4vTUEdKUOvYM+bBR3/Lvqi+aeg5u7J/jEQD9Hsky5b7J1R+60rMfMSom3RYnh7uPw2CpGCl3NqKkSuLuIgXbAp6dhUtkoDt0qXP59G6Lmu1b2zIIvbxPFzj0XNkc9OfiVPjxRADI4Dw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB4966.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(39860400002)(136003)(376002)(396003)(366004)(346002)(230922051799003)(186009)(64100799003)(1800799012)(451199024)(4001150100001)(2906002)(33656002)(110136005)(224303003)(316002)(66446008)(66556008)(54906003)(64756008)(66476007)(166002)(38070700009)(76116006)(86362001)(66946007)(52536014)(55016003)(41300700001)(4326008)(8936002)(5660300002)(38100700002)(122000001)(966005)(83380400001)(478600001)(66574015)(71200400001)(7696005)(9686003)(53546011)(6506007); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: SaF99t6f95DPwVlk42uJRQEuFxsflwB/wABqaehPJqP/RkfziOb/Th/3x+1wXddIsk4FTzfi3Ot/JiHYf9qE0paITVWxV3EIBPJyEZLFc/UHtrMlqTmOaGmr7fnmtDDhaBGud1lQkLZYd7tqygWFVkCxPhQmyz+RL3ptUPx3Q0H8i3EJJt/1DQieWUM/XRJCgxMBcoBZZuSxY/kjib6+L27zuEutKhP63i+ln4Si+/62Cuj+qGzY+Q61DNqLDXqTeTG7hYhaDDLfgXRbAzbzsTTQrBGX3I0PKhU5wx1/4i2xxyJcqxjFdO2Yj+1+G82Pu3jh3N8LZkuffW4drcVtgUfwtv3vd1dwHtUeQKIWdXo24RwJgUE3ICAIBYoQUy2m+Qwexi2+tACSVKPSs6EPZwIClesv8BnelEofkZITQdaylkjR9nGPpjGh5x+1cy30UReZld9EHOXhYon5lKfoDQnTPJjP6EA86vJkmNplkrXsYId9OerHrc2IYlwdIUynrB0rge5rQJClEO6NLEjv7LMpQaWVsfgf5t5mh6DL+Z6npiqz8SW6gC86p95qtDDaw/HW9pY7gyrjKiqa8uShYWshhwzj9JdsFWGOScCyIUsfnbqqMVhUJShPlCu+PxBtXyAmvfpNmKwJoQEkhlFMm/JTDtbr7upJP1Ob2CSeR9iC5DlxwadQIQgBLUVsTNnNdak1JnKEROm8eCDqm9NbVL/gQfmnGWD8ibf+6z0PjHZdFi0dI7qvQ79FiDrN6LMEePUqNL1zaCPiNLHLy0r1C689mSZJq5CyjCf2++Zt+qpC4XQ/dS1tdAdeDcQwpC6l+DnxfT77sGeOpVfwoesJZSyfzTRWN/U8e1RFtzbl05ruIn57bznnWpr+B7IOiKZih/n9A6VOygpNCtQNrKuc2MltKYgw5mzPSD9wQ2VdJ+AXJiT5mIYOJmozMivWFeh4BYtfVIZ4uISLToWIgUxQqrBrThOlXcOf4qe4k9vjzp3auWR8mESC5sKfgYEUWI57WGiVeTD8KOUVLfhWg/ahY22LI37Ywr3woYcVZpCJucAEljhxLwOXXQpea4iJzBo2tRgv/nBi9h8IhxyQDthKw6ufzWGeywiwG/7epJoWXHFCyqmUjJNqEr53S+aFbzhCz4Rdj34O1wo+9pxw6RjKeBm5uHDG+CiLLLfHBhBvIpcmf+cHwXz6ZPdAyTwsBicgewDdLF5NLJyXEzks2Kd2jhQCOQkPqcSU3Hy4rb/fsLOksV/4zh8IFZZWBKvICokcADTT9048oUU1Jd6GaGZ6iwPKUVc7PuY6CVFDIDxPyubnFJydXdP2BdKtmCdjr2HC70HMYdekDtzku9iqH6KCbFHEQuQ51A8joHbxQJ/l4eXdQDcU1SdIVM9RmznGsjmc+xe2YbbDZWRyCkXWq8J09Krm1OLKALSzO+/KqZcy75kaHjC6raHCKLGjFLW7+Yc7BxYYA3vsBobTNEcK8m9EZ+a8MIk2Ru6KBUvSKl7vy2O3pj3uOwrD+IPvbIJ6IkcRvj9NZwPxyksmXeFfsle8M0CgWhLcTRudm4nSRat64iZyT3TW1xmWTy+TG0n5gfR3lSN+ObcVtAwIVEF+no5BWMsBIag6CuOEN65KcHJ+rYWEUSTtjylKsKkYp94YMgMpyDBAms1F9g1cQXOHUM3GLg==
Content-Type: multipart/alternative; boundary="_000_PH0PR11MB4966B6284C9235AAA2DFE555A985APH0PR11MB4966namp_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 97ee34cd-b42e-46b4-141e-08dbf5a31e60
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Dec 2023 15:01:54.1033 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: J4iPeGQRW1MNai5G8xorQr78DJkNSAVgTVRcjuM4yF2Lo4+TL45Hf7HUIQbIy+AUjAZEraLsoZEMDQKvCK9sMA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM4PR11MB6165
X-Outbound-SMTP-Client: 72.163.7.165, rcdn-opgw-4.cisco.com
X-Outbound-Node: rcdn-core-1.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/tsvwg/YGc5jXtqOTaCz93PTMVASXbgYFU>
Subject: Re: [tsvwg] Éric Vyncke's Discuss on draft-ietf-tsvwg-rfc6040update-shim-21: (with DISCUSS and COMMENT)
X-BeenThere: tsvwg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Transport Area Working Group <tsvwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tsvwg/>
List-Post: <mailto:tsvwg@ietf.org>
List-Help: <mailto:tsvwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tsvwg>, <mailto:tsvwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Dec 2023 15:02:06 -0000

Bob

Top replies:
- thank you for clarifying “shim” in the context of this I-D
- I confirm that NHRP is used to build GRE tunnels mesh

Regards

-éric

From: Bob Briscoe <ietf@bobbriscoe.net>
Date: Tuesday, 5 December 2023 at 01:23
To: Eric Vyncke (evyncke) <evyncke@cisco.com>, The IESG <iesg@ietf.org>
Cc: gorry@erg.abdn.ac.uk <gorry@erg.abdn.ac.uk>, tsvwg@ietf.org <tsvwg@ietf.org>, draft-ietf-tsvwg-rfc6040update-shim@ietf.org <draft-ietf-tsvwg-rfc6040update-shim@ietf.org>, tsvwg-chairs@ietf.org <tsvwg-chairs@ietf.org>, d3e3e3@gmail.com <d3e3e3@gmail.com>
Subject: Re: [tsvwg] Éric Vyncke's Discuss on draft-ietf-tsvwg-rfc6040update-shim-21: (with DISCUSS and COMMENT)
Eric, pls see [BB2]
On 04/12/2023 12:35, Eric Vyncke (evyncke) wrote:
Hello Bob,

Thanks for your reply.

See below for EV>

From: Bob Briscoe <ietf@bobbriscoe.net><mailto:ietf@bobbriscoe.net>
Date: Friday, 1 December 2023 at 22:56
To: Eric Vyncke (evyncke) <evyncke@cisco.com><mailto:evyncke@cisco.com>, The IESG <iesg@ietf.org><mailto:iesg@ietf.org>
Cc: gorry@erg.abdn.ac.uk<mailto:gorry@erg.abdn.ac.uk> <gorry@erg.abdn.ac.uk><mailto:gorry@erg.abdn.ac.uk>, tsvwg@ietf.org<mailto:tsvwg@ietf.org> <tsvwg@ietf.org><mailto:tsvwg@ietf.org>, draft-ietf-tsvwg-rfc6040update-shim@ietf.org<mailto:draft-ietf-tsvwg-rfc6040update-shim@ietf.org> <draft-ietf-tsvwg-rfc6040update-shim@ietf.org><mailto:draft-ietf-tsvwg-rfc6040update-shim@ietf.org>, tsvwg-chairs@ietf.org<mailto:tsvwg-chairs@ietf.org> <tsvwg-chairs@ietf.org><mailto:tsvwg-chairs@ietf.org>, d3e3e3@gmail.com<mailto:d3e3e3@gmail.com> <d3e3e3@gmail.com><mailto:d3e3e3@gmail.com>
Subject: Re: [tsvwg] Éric Vyncke's Discuss on draft-ietf-tsvwg-rfc6040update-shim-21: (with DISCUSS and COMMENT)
Eric, Thank you for your review. Pls see [BB] (where no comment on any point means accepted)...
On 28/11/2023 07:17, Éric Vyncke via Datatracker wrote:

Éric Vyncke has entered the following ballot position for

draft-ietf-tsvwg-rfc6040update-shim-21: Discuss



When responding, please keep the subject line intact and reply to all

email addresses included in the To and CC lines. (Feel free to cut this

introductory paragraph, however.)





Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/

for more information about how to handle DISCUSS and COMMENT positions.





The document, along with other ballot positions, can be found here:

https://datatracker.ietf.org/doc/draft-ietf-tsvwg-rfc6040update-shim/







----------------------------------------------------------------------

DISCUSS:

----------------------------------------------------------------------



# Éric Vyncke, INT AD, comments for draft-ietf-tsvwg-rfc6040update-shim-21



Thank you for the work put into this document.



Please find below one blocking DISCUSS points (easy to address), some

non-blocking COMMENT points (but replies would be appreciated even if only for

my own education), and some nits.



Special thanks to Gorry Fairhurst for the shepherd's detailed write-up

including the WG consensus *but it lacks* the justification of the intended

status.



Other thanks to Donald Eastlake, the Internet directorate reviewer (at my

request), please consider this int-dir review:

https://datatracker.ietf.org/doc/review-ietf-tsvwg-rfc6040update-shim-20-intdir-telechat-eastlake-2023-11-22/

(and I have noticed Bob's reply)



I hope that this review helps to improve the document,



Regards,



-éric



# DISCUSS (blocking)



As noted in https://www.ietf.org/blog/handling-iesg-ballot-positions/, a

DISCUSS ballot is a request to have a discussion on the following topics:



## Wrong BCP14 ...



Section 2 MUST use the correct BCP 14 (I told you that this was trivial)





EV> just to be clear, I am clearing my DISCUSS as soon as a revised I-D is submitted with the right BCP14 template (you probably have authored the I-D using an old template)

----------------------------------------------------------------------

COMMENT:

----------------------------------------------------------------------





# COMMENTS (non-blocking)



## Section 3.1



It is just a comment, no need to reply, but I do not agree with `Digging to

arbitrary depths to find an inner IP header within an encapsulation is strictly

a layering violation`, the encapsulating routing is probably doing the encaps

based on the future inner IP header (routing to a tunnel interface). Anyway,

just a comment.

[BB] I haven't changed this - I think the word 'strictly' conveys the message that this is actually done in practice, while "it cannot be a required behaviour" is reinforced by the later point that there always has to be a max depth to dig down to if you're not actually decapsulating headers but just digging to look.

EV> indeed, this was just a comment, feel really free to ignore it (i.e., no change in the current text) as it is more a conversation to have in front of a drink.



## Section 6



Suggest removing the long expired draft-ietf-intarea-gue (and possibly others).

[BB] Removed. Thx for being decisive on what is not going forward.






Suggest to add RFC 8986 as it also has a Ethernet next-header.

[BB] I've scanned through RFC8986. Generally, it only /uses/ existing encapsulations. But you're right that §10.1 does assign 143 as the next header value for Ethernet. However, not having been involved in the area of L2VPNs, I don't understand how/why this happened so late (2021). IOW, how was Ethernet indicated as the next header in EVPNs before RFC8986? Was the EtherIP assignment used/abused? Whatever, this is just a request for a personal tutorial. Back to the draft....

EV> basic tutorial then ;-) with RFC 8986, there was no need for yet-another-encapsulation (e.g., GENEVE, VXLAN) as it is already in a tunnel. AFAIK, IP protocol 143 is only used by this RFC.


I believe Ethernet L2VPNs are outside the scope of rfc6040update-shim. An Ethernet  802.3 MAC header does not fall under the definition of a shim header, 'cos it is self-sufficient as an outer for general forwarding. So an 802.3 header does not have to be added (or removed) at the same time as an outer IP header. And an Ethernet header cannot carry any form of explicit congestion notification {Note 1}.

Therefore, there's no sure way to be able to propagate ECN between a (possible) IP header encapsulated within the Ethernet header and an outer IP header encapsulating the Ethernet header. This could be specified, but it's certainly not just something we could tack on to rfc6040update-shim - it's beyond the stated scope - much more ambitious.

So, do you agree it is OK not to introduce SRv6? Or have I misunderstood?



EV> unsure why it is not a shim, but you are correct there is probably no easy way to propagate ECN in this case. OTOH, skipping the Ethernet header, find its Ethertype, and adjust the following IPv4/IPv6 header (if any)

[BB2] The definition of shim' (for this draft at least) is that it's not a sufficient header to be used for forwarding on its own (as an outer). This then requires an outer to be added to the shim at the same location (because the shim isn't sufficient to forward the PDU to anywhere else). Then even if header compression or encryption, etc. is applied,  the inner header inside the shim(s) and the outer header outside the shim(s) must both have been accessible at some part of the process at one location. it's then likely there will be no difficulty propagating the ECN field between inner & outer.



{Note 1}: Other than 802.1Q in the control plane, but making that work over a L2VPN would be a whole new exercise in itself.








## Section 6.1.2



Please note that NHRP, RFC 2332, is sometimes used to set up GRE tunnels.

[BB] I'm afraid NHRP is completely new to me. If I add it at the start of the list of 4 control plane protocols in the quote below (from "§6.1.2 GRE"), will the subsequent para still be correct, or is NHRP not used to set up IP-in-IP or IPSec tunnels?
EV> NHRP is indeed often used to build GRE tunnels (themselves protected by IPsec in transport mode), this was a common approach before the controller-based SD-WAN paradigm
GRE itself does not support dynamic set-up and configuration of tunnels. However, control plane protocols such as NHRP [RFC2332], Mobile IPv4 (MIP4) [RFC5944<https://www.rfc-editor.org/info/rfc5944>], Mobile IPv6 (MIP6) [RFC6275<https://www.rfc-editor.org/info/rfc6275>], Proxy Mobile IP (PMIP) [RFC5845<https://www.rfc-editor.org/info/rfc5845>] and IKEv2 [RFC7296<https://www.rfc-editor.org/info/rfc7296>] are sometimes used to set up GRE tunnels dynamically.

EV> an Oxford comma is probably required before “and IKEv2”


When these control protocols set up IP-in-IP or IPSec tunnels, it is likely that the resulting tunnels will propagate the ECN field as defined in RFC 6040 or one of its compatible predecessors (RFC 4301 or the full functionality mode of RFC 3168). However, if they use a GRE encapsulation, this presumption is less sound.

[BB2] My question was whether NHRP is used to build these other tunnels (IP-in-IP or IPSec). Because the phrase 'these control protocols' refers to those in the previous list, which now includes NHRP. Therefore I was checking if this last para is still correct.

BTW, I leave the RFC Ed to add Oxford commas. My innate British English writing style doesn't include them. So if I forced myself to add them, it would just end up as an inconsistent mess.

Cheers



Bob



Thanks again


Bob









## Section 6.1.3



Teredo... a glimpse of the past back in 2023 ? More seriously, I do not mind

having this section, but Teredo is no more used. Writing `existing Teredo

deployments safe` in an IETF document looks so weird.



# NITS (non-blocking / cosmetic)



## Use of v4 and v6



While I usually say "v4" or "v6", I strongly suggest to write "IPv4" and "IPv6".






--

________________________________________________________________

Bob Briscoe                               http://bobbriscoe.net/



--

________________________________________________________________

Bob Briscoe                               http://bobbriscoe.net/