
From nobody Tue May 23 10:00:50 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 69C88129568; Tue, 23 May 2017 10:00:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.799
X-Spam-Level: 
X-Spam-Status: No, score=0.799 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mmQ2CnPwQmdc; Tue, 23 May 2017 10:00:41 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5987D129BBD; Tue, 23 May 2017 10:00:41 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4NH0cUJ004037 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 23 May 2017 19:00:39 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4NH0crh026073; Tue, 23 May 2017 19:00:38 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id A5F9CEB205; Tue, 23 May 2017 19:00:38 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id dVtN2NK-c13d; Tue, 23 May 2017 19:00:37 +0200 (CEST)
Received: from lanthane.pps.univ-paris-diderot.fr (unknown [172.23.36.54]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 95CA4EB204; Tue, 23 May 2017 19:00:36 +0200 (CEST)
Received: from localhost ([::1] helo=lanthane.irif.fr) by lanthane.pps.univ-paris-diderot.fr with esmtp (Exim 4.89) (envelope-from <jch@irif.fr>) id 1dDDAi-0002gc-BH; Tue, 23 May 2017 19:00:36 +0200
Date: Tue, 23 May 2017 19:00:36 +0200
Message-ID: <7i7f1733uz.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Ted Lemon <mellon@fugue.com>
Cc: Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Tue, 23 May 2017 19:00:39 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Tue, 23 May 2017 19:00:38 +0200 (CEST)
X-Miltered: at korolev with ID 59246AB6.002 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59246AB6.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59246AB6.002 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59246AB6.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59246AB6.002 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59246AB6.001 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/OrSUswZAfESfrVdD2cEsLl_FvE0>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 17:00:44 -0000

CC-ing the Babel list, at least Matthieu is interested and not subscribed
to h-b-s.

> To be honest, I do not know where the discussion has landed at this
> point.  One of the key requirements for me to write any code is that
> there be a conclusion on how to do unicast hellos.

Ted, please assume that we (the Babel community) will do the Babel
security work in a reasonably timely manner.  What somebody needs to do is
work out the HNCP-related details, notably signalling the requirement for
auth on a given link and the authentication keys.

> Can anybody else on the team talk about what's going on there?

Will reply to David's mail.

-- Juliusz


From nobody Tue May 23 10:05:21 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DEBE1129BB7; Tue, 23 May 2017 10:05:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xuKy9h5ddZWG; Tue, 23 May 2017 10:05:19 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7393C129BBD; Tue, 23 May 2017 10:05:18 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4NH5CuO005673 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 23 May 2017 19:05:12 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4NH58wt027232; Tue, 23 May 2017 19:05:08 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 38698EB200; Tue, 23 May 2017 19:05:08 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id gIaeDe2Fhjwb; Tue, 23 May 2017 19:05:07 +0200 (CEST)
Received: from lanthane.pps.univ-paris-diderot.fr (unknown [172.23.36.54]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id AD877EB204; Tue, 23 May 2017 19:05:04 +0200 (CEST)
Received: from localhost ([::1] helo=lanthane.irif.fr) by lanthane.pps.univ-paris-diderot.fr with esmtp (Exim 4.89) (envelope-from <jch@irif.fr>) id 1dDDF2-0002gw-Ds; Tue, 23 May 2017 19:05:04 +0200
Date: Tue, 23 May 2017 19:05:04 +0200
Message-ID: <7i60gr33nj.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: David Schinazi <dschinazi@apple.com>
Cc: Ted Lemon <mellon@fugue.com>, Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org, Antonin =?ISO-8859-1?Q?D=E9ci?= =?ISO-8859-1?Q?mo?= <antonin.decimo@gmail.com>
In-Reply-To: <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Tue, 23 May 2017 19:05:12 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Tue, 23 May 2017 19:05:12 +0200 (CEST)
X-Miltered: at korolev with ID 59246BC8.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59246BC4.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59246BC8.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59246BC4.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59246BC8.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59246BC4.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/a1bIZcIUHAb8pY_LROmCpY3XJzI>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 17:05:21 -0000

> 1) The community agrees that we want to support them

I think there's a fair number of people who are.  I, for one, would like
to see them defined, although I'm not sure if they are really necessary --
I don't see an attack model that targets Hellos specifically.

> 2) The community hasn't yet come to a consensus on how to encode them,
> proposals included a new TLV, a flag in the existing TLV, and a sub-TLV.

I don't think we considered sub-TLVs, although this might be an option now
that we have mandatory bits.

> While the Homenet Babel profile could technically be achieved without
> unicast hellos, I think they expand our options, and since they are at the
> top of the Babel WG's agenda, it's worth waiting for them.

Agreed.

Antonin Décimo (in copy of this mail) will be doing an internship on Babel
this July.  The plan is to have him implement a prototype of
Stenberg-Schinazi security for Babel (unicast everything, protect using
DTLS).

My current plan is to ask him to do without unicast Hellos for now (this
means that Hellos will be unprotected), although it's up to Antonin --
perhaps he'll want to work on unicast Hellos first.

-- Juliusz


From nobody Tue May 23 10:09:25 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E539129BDA; Tue, 23 May 2017 10:09:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Jf8HEtormbt5; Tue, 23 May 2017 10:09:18 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 45E4A129BD7; Tue, 23 May 2017 10:09:18 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4NH9AJ8007213 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 23 May 2017 19:09:10 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4NH9AmY028558; Tue, 23 May 2017 19:09:10 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id CF37FEB205; Tue, 23 May 2017 19:09:10 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id wwfA_CZUWBXG; Tue, 23 May 2017 19:09:09 +0200 (CEST)
Received: from lanthane.pps.univ-paris-diderot.fr (unknown [172.23.36.54]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id D1B11EB200; Tue, 23 May 2017 19:09:09 +0200 (CEST)
Received: from localhost ([::1] helo=lanthane.irif.fr) by lanthane.pps.univ-paris-diderot.fr with esmtp (Exim 4.89) (envelope-from <jch@irif.fr>) id 1dDDIz-0002gz-Iw; Tue, 23 May 2017 19:09:09 +0200
Date: Tue, 23 May 2017 19:09:09 +0200
Message-ID: <7i4lwb33gq.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: David Schinazi <dschinazi@apple.com>
Cc: Ted Lemon <mellon@fugue.com>, Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Tue, 23 May 2017 19:09:10 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Tue, 23 May 2017 19:09:10 +0200 (CEST)
X-Miltered: at korolev with ID 59246CB6.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59246CB6.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59246CB6.001 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59246CB6.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59246CB6.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59246CB6.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/N4bgXLOnkNVcqTJrQVsp-NBLC4Y>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 17:09:20 -0000

> I think we were waiting for proponents of each alternative to write code.

Oh, I missed this bit.

I was going to bully everyone into working on that, but then Gwendoline
and Matthieu convinced me to add mandatory bits to the spec, so I've been
working on that, as I'd like the mandatory bits work to be ready before we
introduce more changes.

FWIW, mandatory bits are implemented in both babeld and sbabeld, and I've
got the spec written down.  Unfortunately, I did it in an obsolete git
branch, so I need to do some merging and wordsmithing before I can push.
(Automatic git merges on natural language documents are not quite reliable.)

-- Juliusz


From nobody Tue May 23 11:06:07 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6B1AF129C5D for <babel@ietfa.amsl.com>; Tue, 23 May 2017 11:06:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.002
X-Spam-Level: 
X-Spam-Status: No, score=-0.002 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JMZ9w1Y0bs-f for <babel@ietfa.amsl.com>; Tue, 23 May 2017 11:06:05 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 21245129C56 for <babel@ietf.org>; Tue, 23 May 2017 11:06:04 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4NI63Rp028335 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <babel@ietf.org>; Tue, 23 May 2017 20:06:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4NI63Xi013489 for <babel@ietf.org>; Tue, 23 May 2017 20:06:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 1246AEB201 for <babel@ietf.org>; Tue, 23 May 2017 20:06:03 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id VgnZJ9M8zpqX for <babel@ietf.org>; Tue, 23 May 2017 20:06:02 +0200 (CEST)
Received: from lanthane.pps.univ-paris-diderot.fr (unknown [172.23.36.54]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 0C1DAEB207 for <babel@ietf.org>; Tue, 23 May 2017 20:06:00 +0200 (CEST)
Received: from localhost ([::1] helo=lanthane.irif.fr) by lanthane.pps.univ-paris-diderot.fr with esmtp (Exim 4.89) (envelope-from <jch@irif.fr>) id 1dDEC0-0002nG-Mm for babel@ietf.org; Tue, 23 May 2017 20:06:00 +0200
Date: Tue, 23 May 2017 20:06:00 +0200
Message-ID: <7izie31m9j.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Tue, 23 May 2017 20:06:03 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Tue, 23 May 2017 20:06:03 +0200 (CEST)
X-Miltered: at korolev with ID 59247A0B.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59247A0B.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59247A0B.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59247A0B.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59247A0B.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59247A0B.001 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/QgsIJewtGyIxH6bC6T9gw_xu1yo>
Subject: [babel] Mandatory bits in git
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 18:06:06 -0000

Hi,

I think I've managed to get my git branches in order.

A first attempt at mandatory bits is in branch master.  It's not quite
ready yet, I need to read the whole document to see if any other changes
are needed.

My previous attempt at relaxing the definition of AEs is in branch
relax-ae.  If you have a look, you'll see that it is much more messy than
mandatory bits -- one more confirmation that the people who convinced were
right, and I was just a stubborn ass.

Please check, agree, and implement ;-)

-- Juliusz


From nobody Tue May 23 11:55:19 2017
Return-Path: <jehan.tremback@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6BA8129BC6; Tue, 23 May 2017 11:55:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.699
X-Spam-Level: 
X-Spam-Status: No, score=-2.699 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V0hKkwcMFu5H; Tue, 23 May 2017 11:55:12 -0700 (PDT)
Received: from mail-wm0-x230.google.com (mail-wm0-x230.google.com [IPv6:2a00:1450:400c:c09::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AB5C91270AC; Tue, 23 May 2017 11:55:11 -0700 (PDT)
Received: by mail-wm0-x230.google.com with SMTP id b84so36463129wmh.0; Tue, 23 May 2017 11:55:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=nlmZFtI87mNWmncXs/rvaqVjueL4DlOdkxI/dSVQW4o=; b=h2QCCS9KzZ8lzo3Ripd4Wpr4AQfc3E1CspBQHWrYpRRG6g0c7WRQuca+93sX023Nq1 XYZsEF76ylnAS5cFbiWa3tcF3tAc7G0sUBXX8HLxULbUkefHaQStTWSVy9kWqF9U7zTx BNihINbnNbVTDiBbp41glwCqSZULtfmK+0vGSzeDnaUrg5MOH4+SFoJpjTVU8ZsPmN6L AL2O8Axn4jn3p7o2e6h67lhHyBof4YFuThXYPCRTKQVyH83kN8sF1SquN7c6aYbe9sbF zpa5Gv1Zd7+Y2kR3JGomFvvltL7fNT1jj1kqP2QIZldUwqD7834x292Umiagsa1RlpQ2 7SEg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=nlmZFtI87mNWmncXs/rvaqVjueL4DlOdkxI/dSVQW4o=; b=pRD1tvmr+xQHdS7WpmQl2fabiumpZ8u9a6zIlrKBgWL1Qo5sbDgydGr8IOto7ieaf8 aSo33vDA0EJh1UFPbC66KYKG95epYKa65z9g7cevjtsCPGD38gOfwOEGOE/SLtTtxHjL axCiurOoMvIo6qUrI8L10CqYnf8Tfr/n8TWZsia1SWL3bcVs+puhWhxr9an00tW6JEjF gdO0KMAeCVFj/ExdUKMe+NIbMMog6nL/e06zoLA/4Ag/nhxUjUZAtSHoI6Lftkw65x7R NBwBiI0iyDWLo30zI4msLRMdNhxp1/wfuFkStmc1iVGZwdBXUeiJE9H60L1Hg7G2gMdU 3wPg==
X-Gm-Message-State: AODbwcCceGFTEjVC4udG3uyQVaGA5CpGkIO1XSNUgzHlt5BsubKMXuye ytMOq0EKXuLH7JpmkdtNIOQei3D6Zw==
X-Received: by 10.223.150.167 with SMTP id u36mr17065663wrb.184.1495565710092;  Tue, 23 May 2017 11:55:10 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.223.134.131 with HTTP; Tue, 23 May 2017 11:55:09 -0700 (PDT)
In-Reply-To: <7i4lwb33gq.wl-jch@irif.fr>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com> <7i4lwb33gq.wl-jch@irif.fr>
From: Jehan Tremback <jehan.tremback@gmail.com>
Date: Tue, 23 May 2017 11:55:09 -0700
Message-ID: <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com>
To: Juliusz Chroboczek <jch@irif.fr>
Cc: David Schinazi <dschinazi@apple.com>, Mark Townsley <mark@townsley.net>, Ted Lemon <mellon@fugue.com>, homenet-babel-sec@ietf.org, babel@ietf.org
Content-Type: multipart/alternative; boundary="f403045f4e0ce3771a0550358681"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/rpcZkhlISb7D1lzXjeGOptN7Gc0>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 18:55:14 -0000

--f403045f4e0ce3771a0550358681
Content-Type: text/plain; charset="UTF-8"

Hey, I just read through the minutes, wondering if someone has a concise
definition of the threat model we are trying to guard against. I assume
it's to prevent attackers from showing up and sending out bogus routing
messages to bork or DOS the network?

-Jehan

On Tue, May 23, 2017 at 10:09 AM, Juliusz Chroboczek <jch@irif.fr> wrote:

> > I think we were waiting for proponents of each alternative to write code.
>
> Oh, I missed this bit.
>
> I was going to bully everyone into working on that, but then Gwendoline
> and Matthieu convinced me to add mandatory bits to the spec, so I've been
> working on that, as I'd like the mandatory bits work to be ready before we
> introduce more changes.
>
> FWIW, mandatory bits are implemented in both babeld and sbabeld, and I've
> got the spec written down.  Unfortunately, I did it in an obsolete git
> branch, so I need to do some merging and wordsmithing before I can push.
> (Automatic git merges on natural language documents are not quite
> reliable.)
>
> -- Juliusz
>
> _______________________________________________
> Homenet-babel-sec mailing list
> Homenet-babel-sec@ietf.org
> https://www.ietf.org/mailman/listinfo/homenet-babel-sec
>

--f403045f4e0ce3771a0550358681
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hey, I just read through the minutes, wondering if someone=
 has a concise definition of the threat model we are trying to guard agains=
t. I assume it&#39;s to prevent attackers from showing up and sending out b=
ogus routing messages to bork or DOS the network?<div><br></div><div>-Jehan=
</div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Tu=
e, May 23, 2017 at 10:09 AM, Juliusz Chroboczek <span dir=3D"ltr">&lt;<a hr=
ef=3D"mailto:jch@irif.fr" target=3D"_blank">jch@irif.fr</a>&gt;</span> wrot=
e:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><span class=3D"">&gt; I think we were =
waiting for proponents of each alternative to write code.<br>
<br>
</span>Oh, I missed this bit.<br>
<br>
I was going to bully everyone into working on that, but then Gwendoline<br>
and Matthieu convinced me to add mandatory bits to the spec, so I&#39;ve be=
en<br>
working on that, as I&#39;d like the mandatory bits work to be ready before=
 we<br>
introduce more changes.<br>
<br>
FWIW, mandatory bits are implemented in both babeld and sbabeld, and I&#39;=
ve<br>
got the spec written down.=C2=A0 Unfortunately, I did it in an obsolete git=
<br>
branch, so I need to do some merging and wordsmithing before I can push.<br=
>
(Automatic git merges on natural language documents are not quite reliable.=
)<br>
<span class=3D"HOEnZb"><font color=3D"#888888"><br>
-- Juliusz<br>
</font></span><div class=3D"HOEnZb"><div class=3D"h5"><br>
______________________________<wbr>_________________<br>
Homenet-babel-sec mailing list<br>
<a href=3D"mailto:Homenet-babel-sec@ietf.org">Homenet-babel-sec@ietf.org</a=
><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/homenet-babel-sec" rel=3D"=
noreferrer" target=3D"_blank">https://www.ietf.org/mailman/<wbr>listinfo/ho=
menet-babel-sec</a><br>
</div></div></blockquote></div><br></div>

--f403045f4e0ce3771a0550358681--


From nobody Tue May 23 12:01:33 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A10E512EA55 for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:01:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2X_b3ahJObwU for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:01:30 -0700 (PDT)
Received: from mail-qk0-x22a.google.com (mail-qk0-x22a.google.com [IPv6:2607:f8b0:400d:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 23D7F12E870 for <babel@ietf.org>; Tue, 23 May 2017 12:01:12 -0700 (PDT)
Received: by mail-qk0-x22a.google.com with SMTP id u75so137603605qka.3 for <babel@ietf.org>; Tue, 23 May 2017 12:01:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=tjTZPhCETzRhOzOFa2iY+P7MgVOdtR7YIIxHZ49uLk4=; b=CtHumqddossDYE8rIIkgPDXY41mRbvXxhAcpCjkD4L0bmXP0z198pvQ72rA+K0/uTw NLU0dRZiXVRGWd9gcZYggsHXafvGkavvPCnlyZm1So9bFHkEnNniIFFrb7JT2mWMjagk HKX0V1CSzrOh9lqYQg4Pn9XPg+0Gww/JCz6saW7Tcc8fQ0IBuKkCU9+QK6b90QQGx5s7 gALWu6FPrjdRu6E8IqqwlHhdoBt9K/hKYBjws5/kOEnlrFHx3jgLsadqzp8Jypr7RFUr z3W2EyeBUDKLylgm0xI0EcSwf6h6E/kWw7bEzC7crURFEzgntjFNAFt3ZbRYh91AWKWg 1R1g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=tjTZPhCETzRhOzOFa2iY+P7MgVOdtR7YIIxHZ49uLk4=; b=U7JcfuLha5+fg3ziarSY4HAVvjff7dl1zJx3YVRRwbCSI2ouRZuXaKWdIFaOj2oKah jHN4uqVk31N8dU9q0rONzL443KXby6itdbuKuyMbB3VasVASPaEKGrSxNIx/RQgWqjlN d8MbzuH04Qwu7xbwIQUmr1mYzfi+9BoQo9lo4eABAkCZ0A5UAOD38U7iN9Lm2codrAxY rK5jCz6V9Yyizn3DdHD83ZE41t7wgyibepZNODYmz6CLnOnOB9796VBsV2lulkdTVfKl jEE3PaUZz69xP9wFD34LfOMJTIwEoNNcTG9uOxWPZCQSAlvCG2iqoGVhzB4j2rwR3WKy JTqw==
X-Gm-Message-State: AODbwcDzt3kMTjfvZHadO7FFOSzAK6/ztu/HSZ55ZyhgqMkEee6zPiDk hFbtLWxLcDmBVJYo/FeenQ==
X-Received: by 10.55.15.200 with SMTP id 69mr28499011qkp.197.1495566071328; Tue, 23 May 2017 12:01:11 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id u51sm1020226qta.56.2017.05.23.12.01.10 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 23 May 2017 12:01:10 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <19B58F06-EBF3-4F2D-BC99-9A27E9008017@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_8AE6FFF2-2A88-4534-9FF7-182FCD1380A7"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 23 May 2017 15:01:08 -0400
In-Reply-To: <7i7f1733uz.wl-jch@irif.fr>
Cc: Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org
To: Juliusz Chroboczek <jch@irif.fr>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <7i7f1733uz.wl-jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/iEDyOb9XarlHYLfp9nW8I-AFoIQ>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 19:01:32 -0000

--Apple-Mail=_8AE6FFF2-2A88-4534-9FF7-182FCD1380A7
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=us-ascii

On May 23, 2017, at 1:00 PM, Juliusz Chroboczek <jch@irif.fr> wrote:
> Ted, please assume that we (the Babel community) will do the Babel
> security work in a reasonably timely manner.  What somebody needs to do is
> work out the HNCP-related details, notably signalling the requirement for
> auth on a given link and the authentication keys.

Okay, thanks, that's good feedback.   I will focus on that.


--Apple-Mail=_8AE6FFF2-2A88-4534-9FF7-182FCD1380A7
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 23, 2017, at 1:00 PM, Juliusz Chroboczek &lt;<a =
href=3D"mailto:jch@irif.fr" class=3D"">jch@irif.fr</a>&gt; =
wrote:<div><blockquote type=3D"cite" class=3D""><div class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">Ted, please assume =
that we (the Babel community) will do the Babel</span><br =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Menlo-Regular; font-size: 18px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">security work in a reasonably timely manner. =
&nbsp;What somebody needs to do is</span><br style=3D"font-family: =
Menlo-Regular; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">work out the =
HNCP-related details, notably signalling the requirement for</span><br =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Menlo-Regular; font-size: 18px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">auth on a given link and the authentication =
keys.</span></div></blockquote></div><br class=3D""><div class=3D"">Okay, =
thanks, that's good feedback. &nbsp; I will focus on that.</div><div =
class=3D""><br class=3D""></div></body></html>=

--Apple-Mail=_8AE6FFF2-2A88-4534-9FF7-182FCD1380A7--


From nobody Tue May 23 12:04:08 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 734C71274D2 for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:04:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y6nq0L34_dIR for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:04:06 -0700 (PDT)
Received: from mail-qt0-x22d.google.com (mail-qt0-x22d.google.com [IPv6:2607:f8b0:400d:c0d::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EBB59127599 for <babel@ietf.org>; Tue, 23 May 2017 12:04:05 -0700 (PDT)
Received: by mail-qt0-x22d.google.com with SMTP id t26so136709934qtg.0 for <babel@ietf.org>; Tue, 23 May 2017 12:04:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=Edofs60oHDFV8/9s87D4j/p3iS3fS7re2MgBvApeTCg=; b=0xyhBupqW7jTsVFWF8QVKEy/F5MnS0Ch8sTlV618C8CR7sPkF4GM5/E/8qOCVCDg1F vok2IUgzo0hRu/4sC3Io1R32fcHK2lFFJ/zjU96doTBLO1PofWLJHRPLqJvyVLVO6O8D PRddn2jfb6iOMLBTX2J0gGYSvYMGVRHE+p4X2Gv1HLMOnPmXxeKcY7glHFV0Otl1T6Kv yT21EdimtegRLwe+9VNG0LS1CP4WufsUp9apxiT/g3GA106UYYDWDeVyqU3529N/A5IJ aoSFeczfW9il/MnTDi7vVcZhbyv/V5dGXFbv6MXN5J84by58tP5DUClHjrLE0tzQpOU8 89mQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=Edofs60oHDFV8/9s87D4j/p3iS3fS7re2MgBvApeTCg=; b=FzQFPnrNh3vPuHL0Q2J3UVzIuhT+gPw3+chyIN91nn49/hS1AU1g5wZE4eOc2cQY81 YSp1KJXbIgUvp0mQnY0HEyDYv29fjbLcKnTMDiwZ+xbntiJyUpIrS5GYKIzxEWSh980y BlDtzr4/pDdytAzPSnb7lMLgXP715kwsHzgUfejV/lJhjvON3Gl1yTQT69Dio4s0XByq UX6UFPvPmyyf9u2+ElLnGekQk0kzHJBc7ZQIn7GlGnfs10D1pjPkQDGsq9k0tAmJvTkK TIq+bgcRasSTn4PR2TY2pJSKBqYEHGtk4RgQuviFudl1oZcxDE/SiFEbAUEUtpUGxPe7 1Pcg==
X-Gm-Message-State: AODbwcDvsMvHaVr3DW7n834vL+NX5wOEgps8VFQ9EwzImn75xzaYDNAM aHYa6MiAD/ub5R9j
X-Received: by 10.237.53.149 with SMTP id c21mr31213816qte.191.1495566245152;  Tue, 23 May 2017 12:04:05 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.nh.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id u129sm1001558qkf.59.2017.05.23.12.04.04 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 23 May 2017 12:04:04 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <ACA7B53A-A580-4D87-9463-6B27F0409668@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_8DB0740A-06F0-45ED-AE5C-670E21219834"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 23 May 2017 15:04:02 -0400
In-Reply-To: <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com>
Cc: Juliusz Chroboczek <jch@irif.fr>, David Schinazi <dschinazi@apple.com>, Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org
To: Jehan Tremback <jehan.tremback@gmail.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com> <7i4lwb33gq.wl-jch@irif.fr> <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/VqsDQRkH1YlvJLmKm9roVPS4bIY>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 19:04:07 -0000

--Apple-Mail=_8DB0740A-06F0-45ED-AE5C-670E21219834
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 23, 2017, at 2:55 PM, Jehan Tremback <jehan.tremback@gmail.com> =
wrote:
> Hey, I just read through the minutes, wondering if someone has a =
concise definition of the threat model we are trying to guard against. I =
assume it's to prevent attackers from showing up and sending out bogus =
routing messages to bork or DOS the network?

I don't think it's necessarily going to be possible to _prevent_ =
attackers from showing up and sending out bogus routing messages.   =
However, what we probably _can_ do is to be able to know which router =
sent which update, so that we can see, if there is an attack, where it =
is coming from.

It would be good to game this out more, though.   We had a pretty good =
discussion in the meeting, and I think I sent out a summary message =
about it afterwards, but we haven't gone past that.


--Apple-Mail=_8DB0740A-06F0-45ED-AE5C-670E21219834
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 23, 2017, at 2:55 PM, Jehan Tremback &lt;<a =
href=3D"mailto:jehan.tremback@gmail.com" =
class=3D"">jehan.tremback@gmail.com</a>&gt; wrote:<div><blockquote =
type=3D"cite" class=3D""><div class=3D""><span style=3D"font-family: =
Helvetica; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">Hey, I just read through the minutes, =
wondering if someone has a concise definition of the threat model we are =
trying to guard against. I assume it's to prevent attackers from showing =
up and sending out bogus routing messages to bork or DOS the =
network?</span><br =
class=3D"Apple-interchange-newline"></div></blockquote></div><br =
class=3D""><div class=3D"">I don't think it's necessarily going to be =
possible to _prevent_ attackers from showing up and sending out bogus =
routing messages. &nbsp; However, what we probably _can_ do is to be =
able to know which router sent which update, so that we can see, if =
there is an attack, where it is coming from.</div><div class=3D""><br =
class=3D""></div><div class=3D"">It would be good to game this out more, =
though. &nbsp; We had a pretty good discussion in the meeting, and I =
think I sent out a summary message about it afterwards, but we haven't =
gone past that.</div><div class=3D""><br class=3D""></div></body></html>=

--Apple-Mail=_8DB0740A-06F0-45ED-AE5C-670E21219834--


From nobody Tue May 23 12:06:59 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E4CA212EA55 for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:06:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bs28Zo510n6T for <babel@ietfa.amsl.com>; Tue, 23 May 2017 12:06:56 -0700 (PDT)
Received: from mail-qt0-x231.google.com (mail-qt0-x231.google.com [IPv6:2607:f8b0:400d:c0d::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FFEB12E870 for <babel@ietf.org>; Tue, 23 May 2017 12:06:56 -0700 (PDT)
Received: by mail-qt0-x231.google.com with SMTP id f55so136636553qta.3 for <babel@ietf.org>; Tue, 23 May 2017 12:06:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=8GDRO10daeX6waRO005thPcIR872thS6kDG1WrXWeTQ=; b=qiVXhZUDGPswR34O+yenKQVP1boK+P0KXRhdtGg/NhpMeT7Zzuf0MeTObkLwMHSQ1E 5EQyMGsRNINcCIqJyWordCvFFSVjVOKyVrgoyV0bRtJlkqaqvRxhOQXgZn3BYM1JRXwS fF02y4gLa6csoXmFA5JgnzlBLQsqR94bW0ivROnZV/60kBEL1CeZC8C+bOa/ZLld5cwF y9+MqhLmGk5P5YMyTpzN1NNxZPUOmzP13cPrkkQHKq1rRumPrRSMMJo4Ws6d3UdzekHq MOv99E4DXYMJOjThPBsvPUaBvXwaa3UTl5a+eFfn1AFslsjMzWVW+O84O/YIW8Nc24kp oiOQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=8GDRO10daeX6waRO005thPcIR872thS6kDG1WrXWeTQ=; b=pOoOMU+YVWx2lVHxmw1SCwxpv7WxyfRMFD+ZYduOo5VYBIz08aIUuaQI1eykph2zU7 LwnVId7EoQLba//wBbJXcuBIDz3wtLOsbivMwXjKjsuML1amT9vubm8qzI5/4/Imru7t MWkkGKlgrKQRTCaLvpmTObhXQTR4VvP6pH5nG2SHc3zxQ3d4Tq1hepCSt7kNpNOwvtfs 8/0W6rd3bU6tQl7TJSZHQKDMBVYsB8oUeZdxo763dtcXPGsC3tQ8Q+b/hCiUbvdElW/P ecy4eDM1Weveri/riIcKhFSY5GSLOSwBkPF7hYlCnQej+23UoLOFZrAue/AKk+ZzIevK VaAg==
X-Gm-Message-State: AODbwcDwREyonxDE6cI/NbKCBKGqeESq6lMZogX8Jn5sO21Weqzg0U2r XaR4OqT3Y3/6kaGU
X-Received: by 10.200.42.166 with SMTP id b35mr31658843qta.239.1495566415403;  Tue, 23 May 2017 12:06:55 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id q34sm1029362qte.44.2017.05.23.12.06.53 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 23 May 2017 12:06:54 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <246CDF99-F236-44FD-9C9D-7C7E4B63D12A@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_CDA4C15C-EAB4-4F18-9DBA-DBA51C75AECC"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 23 May 2017 15:06:51 -0400
In-Reply-To: <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com>
Cc: Juliusz Chroboczek <jch@irif.fr>, David Schinazi <dschinazi@apple.com>, Mark Townsley <mark@townsley.net>, homenet-babel-sec@ietf.org, babel@ietf.org
To: Jehan Tremback <jehan.tremback@gmail.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com> <7i4lwb33gq.wl-jch@irif.fr> <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/2k6r_kmA9Ij1JzaoeX8lPP_TsSg>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 19:06:58 -0000

--Apple-Mail=_CDA4C15C-EAB4-4F18-9DBA-DBA51C75AECC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 23, 2017, at 2:55 PM, Jehan Tremback <jehan.tremback@gmail.com> =
wrote:
> Hey, I just read through the minutes, wondering if someone has a =
concise definition of the threat model we are trying to guard against. I =
assume it's to prevent attackers from showing up and sending out bogus =
routing messages to bork or DOS the network?


Here are the notes that we took in the break-out session after the main =
meeting:

https://github.com/bhstark2/babel-security/blob/master/chicago-notes.md =
<https://github.com/bhstark2/babel-security/blob/master/chicago-notes.md>

There's also a file there where we were going to put in our thoughts =
about the threat model, so that we could try to come up with an idea of =
what we are all talking about.   However, it looks like nobody's =
actually done anything to that document.


--Apple-Mail=_CDA4C15C-EAB4-4F18-9DBA-DBA51C75AECC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 23, 2017, at 2:55 PM, Jehan Tremback &lt;<a =
href=3D"mailto:jehan.tremback@gmail.com" =
class=3D"">jehan.tremback@gmail.com</a>&gt; wrote:<div><blockquote =
type=3D"cite" class=3D""><div class=3D""><span style=3D"font-family: =
Helvetica; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">Hey, I just read through the minutes, =
wondering if someone has a concise definition of the threat model we are =
trying to guard against. I assume it's to prevent attackers from showing =
up and sending out bogus routing messages to bork or DOS the =
network?</span><br =
class=3D"Apple-interchange-newline"></div></blockquote></div><div =
class=3D""><br class=3D""></div>Here are the notes that we took in the =
break-out session after the main meeting:<div class=3D""><br =
class=3D""><div class=3D""><a =
href=3D"https://github.com/bhstark2/babel-security/blob/master/chicago-not=
es.md" =
class=3D"">https://github.com/bhstark2/babel-security/blob/master/chicago-=
notes.md</a></div></div><div class=3D""><br class=3D""></div><div =
class=3D"">There's also a file there where we were going to put in our =
thoughts about the threat model, so that we could try to come up with an =
idea of what we are all talking about. &nbsp; However, it looks like =
nobody's actually done anything to that document.</div><div class=3D""><br=
 class=3D""></div></body></html>=

--Apple-Mail=_CDA4C15C-EAB4-4F18-9DBA-DBA51C75AECC--


From nobody Tue May 23 22:56:36 2017
Return-Path: <dschinazi@apple.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E782126FDC for <babel@ietfa.amsl.com>; Tue, 23 May 2017 22:56:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.402
X-Spam-Level: 
X-Spam-Status: No, score=-2.402 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C-hy3ydnvENA for <babel@ietfa.amsl.com>; Tue, 23 May 2017 22:56:32 -0700 (PDT)
Received: from mail-in5.apple.com (mail-out5.apple.com [17.151.62.27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5C981200F3 for <babel@ietf.org>; Tue, 23 May 2017 22:56:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=apple.com; s=mailout2048s; c=relaxed/simple; q=dns/txt; i=@apple.com; t=1495605392; h=From:Sender:Reply-To:Subject:Date:Message-id:To:Cc:MIME-version:Content-type: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-reply-to:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=NLm5bZLO6fjvX7KFb3XLrrxbpL5XjmGC9SiMhQu5zrY=; b=lQYDT70zggFPOFwM3rrw/olWVrXXzcp3mV1bHvMzagNAqMQFxTaYhuZkZzrw95hL TY48cwiIy8u0vwL0blcnZtyfiC00iieHyy8X/Wys0tocAQvdh7h1JypmXXhAWmSS U6M3zigw/Kmkl4aKXY2zCSI9JW3KKeYEI8LSq5pCKe7FmXbx6xOxC5EPN32MDdXN kxiBnccF94AzEOa9Od01rDzeMWKnOxakf4AT7J6mM2TSagSioRveyen/a6+uQtXZ qaODUbR7yXbasvjPsMy+hIQUeR9SlgMfne6dIH75acRQA22zeZlc2t+f+Xw0mXct /KIzDxotbbupPIt7bhczIg==;
Received: from relay7.apple.com (relay7.apple.com [17.128.113.101]) (using TLS with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mail-in5.apple.com (Apple Secure Mail Relay) with SMTP id 8C.29.01595.09025295; Tue, 23 May 2017 22:56:32 -0700 (PDT)
X-AuditID: 11973e13-caa429a00000063b-33-59252090eab8
Received: from kencur (kencur.apple.com [17.151.62.38]) by relay7.apple.com (Apple SCV relay) with SMTP id A4.6C.18088.F8025295; Tue, 23 May 2017 22:56:32 -0700 (PDT)
MIME-version: 1.0
Content-type: multipart/alternative; boundary="Boundary_(ID_lV+R/LniKiO05TfERhOusA)"
Received: from [17.153.40.221] (unknown [17.153.40.221]) by kencur.apple.com (Oracle Communications Messaging Server 8.0.1.2.20170210 64bit (built Feb 10 2017)) with ESMTPSA id <0OQG00GQ30I62970@kencur.apple.com>; Tue, 23 May 2017 22:56:31 -0700 (PDT)
Sender: dschinazi@apple.com
From: David Schinazi <dschinazi@apple.com>
Message-id: <CC2493D0-E661-4D4A-ADA9-B19DD37075CB@apple.com>
Date: Tue, 23 May 2017 22:56:29 -0700
In-reply-to: <7izie31m9j.wl-jch@irif.fr>
Cc: babel@ietf.org
To: Juliusz Chroboczek <jch@irif.fr>
References: <7izie31m9j.wl-jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrELMWRmVeSWpSXmKPExsUi2FCYqjtBQTXS4GSrksWWRd0sFvNbl7E5 MHksWfKTyWPxlreMAUxRXDYpqTmZZalF+nYJXBlLlp1mLlgtW7F+4hfWBsYtkl2MnBwSAiYS x9r/s3YxcnEICaxhkti9/CArTKLpcj8bRGIFo8TPfX3MIAleAUGJH5PvsYDYzAJhErPffoYq amaSeDDpBBNIQlhAWqLrwl2gSRwcbAJaEgfWGEH02kjc63vNDlGiJXF77hewmSwCqhLPt3ex gJRzCmhInJlfDjFeSOLMtRlgq0QEVCSWT3sG1iokoC6xeu9zFog7ZSVuzb7EDHKChMARNolJ yw6zTGAUmoXk1FlIToWwtSS+P2oFinMA2fISB8/LQoQ1JZ7d+8QOYWtLPHl3gXUBI9sqRqHc xMwc3cw8U73EgoKcVL3k/NxNjKBImG4nvIPx9CqrQ4wCHIxKPLwJDiqRQqyJZcWVuYcYpTlY lMR5K+OBQgLpiSWp2ampBalF8UWlOanFhxiZODilGhhrrpWbtPBrRe1QnWeac4/1R4/+dGfR +G3x3wMTRI6cs9o95W3Fzry5YRpzyvZfUM5cnTrh39RvkrPnNHzRvWDzW2zKAtnXdrLy5fuX vH3ZMzF//qSLM9ONtq+5oixuYNY9v/3Ft113/bt+FcX73WV/Pi3pEM9Mx8AOE42siVfWx85U 2RW6U/+iEktxRqKhFnNRcSIAtvGNbmUCAAA=
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrDIsWRmVeSWpSXmKPExsUiON1OTXeCgmqkQd9ndosti7pZLOa3LmNz YPJYsuQnk8fiLW8ZA5iiuGxSUnMyy1KL9O0SuDKWLDvNXLBatmL9xC+sDYxbJLsYOTkkBEwk mi73s3UxcnEICaxglPi5r48ZJMErICjxY/I9FhCbWSBMYvbbz1BFzUwSDyadYAJJCAtIS3Rd uMvaxcjBwSagJXFgjRFEr43Evb7X7BAlWhK3534Bm8kioCrxfHsXC0g5p4CGxJn55RDjhSTO XJsBtkpEQEVi+bRnYK1CAuoSq/c+Z4G4U1bi1uxLzBMY+WchuW4WkusgbC2J749ageIcQLa8 xMHzshBhTYln9z6xQ9jaEk/eXWBdwMi2ilGgKDUnsdJcL7GgICdVLzk/dxMjKHAbClN3MDYu tzrEKMDBqMTDm+CgEinEmlhWXJl7iFGCg1lJhNdETDVSiDclsbIqtSg/vqg0J7X4EONERqAf JzJLiSbnA+MqryTe0MTEwMTY2MzY2NzEnJbCSuK8WQlARwqkJ5akZqemFqQWwRzFxMEp1cC4 qiW6eb4n4x0JjcwAfdGzmS+3BrTbbEiWcDDTlhBgPrR/6h8+W9Ytmy/3vWta4tGaWyTpk3ls l+pyk58xuwqeGv3e4He8fGeos8UFbonvgYGn9AQO7Ze+uvXB1U+btoa7tfRc8Wp6tJnz30uJ R2vjbq3t7pY6cORjNFepwNwy+/tLi6afFr+pxFKckWioxVxUnAgAK7Iuis8CAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/fxthEJaC4rwmxj32wZbEHH_Yoi8>
Subject: Re: [babel] Mandatory bits in git
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 05:56:34 -0000

--Boundary_(ID_lV+R/LniKiO05TfERhOusA)
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT

Juliusz,

Mandatory bits do seem to fit very nicely into the spec.
https://github.com/jech/babel-drafts/commit/7eaf03906716a2c4af999d421123a279332eb8f3 <https://github.com/jech/babel-drafts/commit/7eaf03906716a2c4af999d421123a279332eb8f3>

I'll try to find time to add this to our implementation soon.

Thanks for writing this up!

David


> On May 23, 2017, at 11:06, Juliusz Chroboczek <jch@irif.fr> wrote:
> 
> Hi,
> 
> I think I've managed to get my git branches in order.
> 
> A first attempt at mandatory bits is in branch master.  It's not quite
> ready yet, I need to read the whole document to see if any other changes
> are needed.
> 
> My previous attempt at relaxing the definition of AEs is in branch
> relax-ae.  If you have a look, you'll see that it is much more messy than
> mandatory bits -- one more confirmation that the people who convinced were
> right, and I was just a stubborn ass.
> 
> Please check, agree, and implement ;-)
> 
> -- Juliusz
> 
> _______________________________________________
> babel mailing list
> babel@ietf.org
> https://www.ietf.org/mailman/listinfo/babel


--Boundary_(ID_lV+R/LniKiO05TfERhOusA)
Content-type: text/html; CHARSET=US-ASCII
Content-transfer-encoding: quoted-printable

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">Juliusz,<div class=3D""><br class=3D""></div><div =
class=3D"">Mandatory bits do seem to fit very nicely into the =
spec.</div><div class=3D""><a =
href=3D"https://github.com/jech/babel-drafts/commit/7eaf03906716a2c4af999d=
421123a279332eb8f3" =
class=3D"">https://github.com/jech/babel-drafts/commit/7eaf03906716a2c4af9=
99d421123a279332eb8f3</a></div><div class=3D""><br class=3D""></div><div =
class=3D"">I'll try to find time to add this to our implementation =
soon.</div><div class=3D""><br class=3D""></div><div class=3D"">Thanks =
for writing this up!</div><div class=3D""><br class=3D""></div><div =
class=3D"">David</div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""><div><blockquote type=3D"cite" class=3D""><div =
class=3D"">On May 23, 2017, at 11:06, Juliusz Chroboczek &lt;<a =
href=3D"mailto:jch@irif.fr" class=3D"">jch@irif.fr</a>&gt; =
wrote:</div><br class=3D"Apple-interchange-newline"><div class=3D""><div =
class=3D"">Hi,<br class=3D""><br class=3D"">I think I've managed to get =
my git branches in order.<br class=3D""><br class=3D"">A first attempt =
at mandatory bits is in branch master. &nbsp;It's not quite<br =
class=3D"">ready yet, I need to read the whole document to see if any =
other changes<br class=3D"">are needed.<br class=3D""><br class=3D"">My =
previous attempt at relaxing the definition of AEs is in branch<br =
class=3D"">relax-ae. &nbsp;If you have a look, you'll see that it is =
much more messy than<br class=3D"">mandatory bits -- one more =
confirmation that the people who convinced were<br class=3D"">right, and =
I was just a stubborn ass.<br class=3D""><br class=3D"">Please check, =
agree, and implement ;-)<br class=3D""><br class=3D"">-- Juliusz<br =
class=3D""><br =
class=3D"">_______________________________________________<br =
class=3D"">babel mailing list<br class=3D""><a =
href=3D"mailto:babel@ietf.org" class=3D"">babel@ietf.org</a><br =
class=3D"">https://www.ietf.org/mailman/listinfo/babel<br =
class=3D""></div></div></blockquote></div><br =
class=3D""></div></body></html>=

--Boundary_(ID_lV+R/LniKiO05TfERhOusA)--


From nobody Wed May 24 01:31:22 2017
Return-Path: <kerneis@google.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E4BF312714F for <babel@ietfa.amsl.com>; Wed, 24 May 2017 01:31:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XCw5NIxdlaIw for <babel@ietfa.amsl.com>; Wed, 24 May 2017 01:31:20 -0700 (PDT)
Received: from mail-ua0-x232.google.com (mail-ua0-x232.google.com [IPv6:2607:f8b0:400c:c08::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 201821201FA for <babel@ietf.org>; Wed, 24 May 2017 01:31:20 -0700 (PDT)
Received: by mail-ua0-x232.google.com with SMTP id e28so92736151uah.0 for <babel@ietf.org>; Wed, 24 May 2017 01:31:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=1ZEf7vGB4+2VQctasZPPWglXBc6g6QtCL1fYnYxcQXw=; b=JSbXP6jv53IbMTYzimYIspYpplnH9HTHgfNVcmP4gfoA4U+b7zcCNOahLxqlV4DtcQ 0Z2VGA+5EbwV9kWUiQ9rk8WnqSPUy831gqiSvbswP3gnP+HRj0llz7QxfHGRN5H61zpi jcOeWUYf30hZWn0X8zRhRsaDj6s6+9TAxTxvXUHxH7GZkGwIcJhEhXh8kbKT6Gtooq2d HK0rNL6BE8dNB+bDAi5SfJZfmTnCeAaDEydSNmiHVMDrJcMDx7Z6KoW958trq1Raz4mu 9Fek9psCESPReHsJMaW/6nsSGATnXNlVYpLVI1zVomrwKnAYB7LVeQ9qikYvwqCRj5Tm K1lQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=1ZEf7vGB4+2VQctasZPPWglXBc6g6QtCL1fYnYxcQXw=; b=T7UPY74vSSPyi2iWlmlbn/1bz9pN41JDIN5KS2e1LpuZC0w7p/xBT/0Yjf/L3ta2Tp xcJNCgrHDnYsaYrWuYa/hCU466VxVdM0AsoZQM9BiQjA5q/ZrHxPnDUcGzdNRA4rcxkH 9GUXoSDXF3DekN4IPMDdhpHZs6gi5cKoJw60S6wuSZMNqnUS/KCmkDsjWrcpZGYffxQg ZINsUS56nntYlSRWzr+LapfL3xJkgOGAC/kmCaZjJK0tkrXYmImMNEkvNJiRLalugbLK euQtLfLAZKLXxqX4Q8qEl+MSyHPY8iuimtcHSb7As7CPXUDIPXnpL+xQ4qz8YbJ4jBE8 /IZQ==
X-Gm-Message-State: AODbwcCwVp/WKtj8LAsiugPBGnGc+OZmDIlFseRL0KXwaBrUtfAX3Z6J FhkjBr4w/AWhkn2jDN2lvmuOZ1507RtM
X-Received: by 10.176.4.80 with SMTP id 74mr7173577uav.115.1495614679200; Wed, 24 May 2017 01:31:19 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.103.88.26 with HTTP; Wed, 24 May 2017 01:30:38 -0700 (PDT)
In-Reply-To: <CC2493D0-E661-4D4A-ADA9-B19DD37075CB@apple.com>
References: <7izie31m9j.wl-jch@irif.fr> <CC2493D0-E661-4D4A-ADA9-B19DD37075CB@apple.com>
From: Gabriel Kerneis <kerneis@google.com>
Date: Wed, 24 May 2017 10:30:38 +0200
Message-ID: <CAL0WyWwasycXxRgtyQgPyw+sxs-Kye0yeq0VNOVX7NOA8LuNBQ@mail.gmail.com>
To: David Schinazi <dschinazi@apple.com>
Cc: Juliusz Chroboczek <jch@irif.fr>, Babel at IETF <babel@ietf.org>
Content-Type: multipart/alternative; boundary="001a114a2410ad17be055040edaf"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/SCpswv_M_AA2Ws7y9QAfdWYEy_8>
Subject: Re: [babel] Mandatory bits in git
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 08:31:22 -0000

--001a114a2410ad17be055040edaf
Content-Type: text/plain; charset="UTF-8"

On Wed, May 24, 2017 at 7:56 AM, David Schinazi <dschinazi@apple.com> wrote:

> Juliusz,
>
> Mandatory bits do seem to fit very nicely into the spec.
> https://github.com/jech/babel-drafts/commit/7eaf03906716a2c4af999d421123a2
> 79332eb8f3
>

Agreed. Nits:

   - I think you meant "most-significant bit" instead of "most-specific
   bit".
   - missing a closing ")" after "see <xref target="update"/>".
   - you changed "address family" to "address encoding", not sure if that
   was intended or not.


Gabriel

--001a114a2410ad17be055040edaf
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">On W=
ed, May 24, 2017 at 7:56 AM, David Schinazi <span dir=3D"ltr">&lt;<a href=
=3D"mailto:dschinazi@apple.com" target=3D"_blank">dschinazi@apple.com</a>&g=
t;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0=
px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div =
style=3D"word-wrap:break-word">Juliusz,<div><br></div><div>Mandatory bits d=
o seem to fit very nicely into the spec.</div><div><a href=3D"https://githu=
b.com/jech/babel-drafts/commit/7eaf03906716a2c4af999d421123a279332eb8f3" ta=
rget=3D"_blank">https://github.com/jech/babel-<wbr>drafts/commit/<wbr>7eaf0=
3906716a2c4af999d421123a2<wbr>79332eb8f3</a></div></div></blockquote><div><=
br></div><div>Agreed. Nits:</div><div><ul><li>I think you meant &quot;most-=
significant bit&quot; instead of &quot;most-specific bit&quot;.</li><li>mis=
sing a closing &quot;)&quot; after &quot;see &lt;xref target=3D&quot;update=
&quot;/&gt;&quot;.</li><li>you changed &quot;address family&quot; to &quot;=
address encoding&quot;, not sure if that was intended or not.</li></ul></di=
v><div><br></div><div>Gabriel</div></div><br></div></div>

--001a114a2410ad17be055040edaf--


From nobody Wed May 24 04:57:01 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E9521298A1 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 04:57:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.799
X-Spam-Level: 
X-Spam-Status: No, score=0.799 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6_gpRAuZFXCr for <babel@ietfa.amsl.com>; Wed, 24 May 2017 04:56:58 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62AFC1296CD for <babel@ietf.org>; Wed, 24 May 2017 04:56:58 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OBusHX029390 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 24 May 2017 13:56:54 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4OBusg1006143; Wed, 24 May 2017 13:56:54 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 8DB69EB200; Wed, 24 May 2017 13:56:54 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id Gsp5wpiuFMni; Wed, 24 May 2017 13:56:53 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 6614FEB204; Wed, 24 May 2017 13:56:53 +0200 (CEST)
Date: Wed, 24 May 2017 13:56:53 +0200
Message-ID: <874lwacvsq.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Gabriel Kerneis <kerneis@google.com>
Cc: Babel at IETF <babel@ietf.org>
In-Reply-To: <CAL0WyWwasycXxRgtyQgPyw+sxs-Kye0yeq0VNOVX7NOA8LuNBQ@mail.gmail.com>
References: <7izie31m9j.wl-jch@irif.fr> <CC2493D0-E661-4D4A-ADA9-B19DD37075CB@apple.com> <CAL0WyWwasycXxRgtyQgPyw+sxs-Kye0yeq0VNOVX7NOA8LuNBQ@mail.gmail.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 24 May 2017 13:56:54 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 24 May 2017 13:56:54 +0200 (CEST)
X-Miltered: at korolev with ID 59257506.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59257506.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59257506.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59257506.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59257506.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59257506.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/IiC3bVAZCIKd1jTnWHljpNg3FIM>
Subject: Re: [babel] Mandatory bits in git
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 11:57:00 -0000

> * you changed "address family" to "address encoding", not sure if that was
>   intended or not.

Yes, althoug I should have made a different commit for that.  The use of
per-AF compression state is a bug in RFC 6126; the state should clearly be
per-AE.

Per-AF compression state could in principle give better compression
ratios, but I don't see how that could be pulled off in practice.
However, it means that you cannot extend the AE space for a known AF -- if
you add a new AE that encodes IPv6 addresses, than all implementations
that handle IPv6 must know about it.

I don't think that's likely to be a flaw in practice, but per-AE is the
correct thing, so let's do it.  That's the only piece that remains of my
aborted attempt at making AEs more flexible -- mandatory bits seem much
simpler and cleaner to me now.  Full credit to all the people who bullied
me into listening.

-- Juliusz


From nobody Wed May 24 05:22:43 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E428129B4C for <babel@ietfa.amsl.com>; Wed, 24 May 2017 05:22:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sFyHBUhgNg5T for <babel@ietfa.amsl.com>; Wed, 24 May 2017 05:22:40 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 290CA129B05 for <babel@ietf.org>; Wed, 24 May 2017 05:22:40 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OCMcm4009814 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <babel@ietf.org>; Wed, 24 May 2017 14:22:38 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4OCMcVL015645 for <babel@ietf.org>; Wed, 24 May 2017 14:22:38 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 8454FEB200 for <babel@ietf.org>; Wed, 24 May 2017 14:22:38 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id dY86pd7IJVsZ for <babel@ietf.org>; Wed, 24 May 2017 14:22:37 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 7F57AEB201 for <babel@ietf.org>; Wed, 24 May 2017 14:22:37 +0200 (CEST)
Date: Wed, 24 May 2017 14:22:37 +0200
Message-ID: <87y3tmbg1e.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 24 May 2017 14:22:38 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 24 May 2017 14:22:38 +0200 (CEST)
X-Miltered: at korolev with ID 59257B0E.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59257B0E.002 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59257B0E.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 59257B0E.002 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59257B0E.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59257B0E.002 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/RLhbZ4skM0temfVPgyi_te506Js>
Subject: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 12:22:41 -0000

I don't think it's a good idea to put a Mandatory sub-TLV in Next Hop or
Router-ID, since these two TLVs are used for establishing state, and the
state must be correlated for different implementations.  However, we need
to specify the behaviour if for some reason we receive one of these with
an unknown mandatory sub-TLV.

The current text and implementation does the simple thing, and ignores
such TLVs alltogether -- so only Update carries the exception to mandatory
handling (which is unavoidable in that case if we wish to use compression
effectively).  Please shout if you see any reason for the other possible
behaviour.

-- Juliusz


From nobody Wed May 24 05:47:28 2017
Return-Path: <boutier@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EA3C12E05C for <babel@ietfa.amsl.com>; Wed, 24 May 2017 05:47:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4FtMndBXa7tb for <babel@ietfa.amsl.com>; Wed, 24 May 2017 05:47:25 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC9841287A0 for <babel@ietf.org>; Wed, 24 May 2017 05:47:24 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OClNkb026191 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <babel@ietf.org>; Wed, 24 May 2017 14:47:23 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4OClMBU028472 for <babel@ietf.org>; Wed, 24 May 2017 14:47:23 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id D9522EB204 for <babel@ietf.org>; Wed, 24 May 2017 14:47:22 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id wSK3XA-y2WzZ; Wed, 24 May 2017 14:47:21 +0200 (CEST)
Received: from mac-matthieu.lan (AAubervilliers-652-1-190-89.w86-218.abo.wanadoo.fr [86.218.77.89]) (Authenticated sender: boutier) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id B9F76EB200; Wed, 24 May 2017 14:47:21 +0200 (CEST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Matthieu Boutier <boutier@irif.fr>
In-Reply-To: <87y3tmbg1e.wl-jch@irif.fr>
Date: Wed, 24 May 2017 14:47:21 +0200
Cc: babel@ietf.org
Content-Transfer-Encoding: 7bit
Message-Id: <D1FCE601-9DB8-4B86-8251-4F20BD42E300@irif.fr>
References: <87y3tmbg1e.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3124)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 24 May 2017 14:47:23 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 24 May 2017 14:47:23 +0200 (CEST)
X-Miltered: at korolev with ID 592580DB.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592580DA.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592580DB.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<boutier@irif.fr>
X-j-chkmail-Enveloppe: 592580DA.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<boutier@irif.fr>
X-j-chkmail-Score: MSGID : 592580DB.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592580DA.001 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/JebvfdNG4sXyQENC4oCE1cMQRiY>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 12:47:26 -0000

> The current text and implementation does the simple thing, and ignores
> such TLVs alltogether -- so only Update carries the exception to mandatory
> handling

Next Hop and Router-ID only update state, instead of Updates which also
carry route information.  So it is possible to just update state with
two successive Next Hop or Router-ID TLVs (the first without mandatory
sub-TLV).   If an extension want to put mandatory sub-TLV to Next Hop
and Router-ID while preserving state, it can do it.  So I would say:
keep doing the simple thing.

Matthieu


From nobody Wed May 24 06:02:52 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3C9C12E04F for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:02:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FXFh6NQDaDwV for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:02:49 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D954A12E3AE for <babel@ietf.org>; Wed, 24 May 2017 06:02:43 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OD2gVX001471 for <babel@ietf.org>; Wed, 24 May 2017 15:02:42 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 34A8CEB205 for <babel@ietf.org>; Wed, 24 May 2017 15:02:42 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 8psRXqZqFSHm; Wed, 24 May 2017 15:02:41 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 034BEEB200; Wed, 24 May 2017 15:02:41 +0200 (CEST)
Date: Wed, 24 May 2017 15:02:40 +0200
Message-ID: <87mva2be6n.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Matthieu Boutier <boutier@irif.fr>
Cc: babel@ietf.org
In-Reply-To: <D1FCE601-9DB8-4B86-8251-4F20BD42E300@irif.fr>
References: <87y3tmbg1e.wl-jch@irif.fr> <D1FCE601-9DB8-4B86-8251-4F20BD42E300@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 15:02:42 +0200 (CEST)
X-Miltered: at korolev with ID 59258472.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59258472.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59258472.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/6NBDTxvJWCOoI6GkxSf_NasNr7E>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 13:02:51 -0000

> Next Hop and Router-ID only update state, instead of Updates which also
> carry route information.  So it is possible to just update state with
> two successive Next Hop or Router-ID TLVs (the first without mandatory
> sub-TLV).

You've got a sick mind ;-)

-- Juliusz


From nobody Wed May 24 06:42:59 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C57651293FD for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:42:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.601
X-Spam-Level: 
X-Spam-Status: No, score=-0.601 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rWDDAX1vyL_r for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:42:56 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 245281243F3 for <babel@ietf.org>; Wed, 24 May 2017 06:42:56 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1495633372; bh=kkLzBBdTBawdfjNyiomx7x1AykzK2bmye3FLbU3j+b4=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=rVp+8k0UzoOMFt1r1fdNKhOU/v2uBjxi9I8lC08cCJHOHEzocq9eohwynCYAorIpy gHumqlKDHlucZx/GgMvJ7kKmovKRw4hFSgacRxczVsLNm63lFztYzze6C0p3wrTzql 1O1MDB3pVvn86RlZzKaqCsFnriKAyc0DggmS0WiS29U2gU2MRd3P3YJTjVU+YATrZo 70bN39Hz6JF4usvy2IzoOiiD/xkD0CtME+U48T2MGt7LORUsB77dEKzNkOoSq32JgJ u4J18+u02PCFCkpmaXQ6U3dPe75kO14fTI2tqAMMAMqTEKcAX4iJyrsbEq0NjxBj06 6j0VqyaoBAyIQ==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87y3tmbg1e.wl-jch@irif.fr>
Date: Wed, 24 May 2017 15:42:50 +0200
In-Reply-To: <87y3tmbg1e.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Wed, 24 May 2017 14:22:37 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87zie2gylh.fsf@alrua-x1>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/yiHHaSESGoSlp6bK69saZ8ylOIQ>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 13:42:58 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

> The current text and implementation does the simple thing, and ignores
> such TLVs alltogether -- so only Update carries the exception to
> mandatory handling (which is unavoidable in that case if we wish to
> use compression effectively). Please shout if you see any reason for
> the other possible behaviour.

Why is special-casing updates the simple thing? If an update is the only
thing that requires updating parser state no matter the sub-TLV, it has
to be special-cased and TLV parsing has to be interleaved with sub-TLV
parsing. Whereas if there is consistency, it can all be the same
code-path.

I.e., if the spec says to always update parser state, I can do something
like:

bool read_tlv(tlv_data[]) {
  return tlv_header_valid(tlv_data) \
     && tlv_parser[tlv_data.type].parse(tlv_data) \ // updates parser state
     && read_subtlvs(tlv_data); // return false if an unknown mandatory sub-TLV is found
}

versus:

bool read_tlv(tlv_data[]) {
  if(!tlv_header_valid(tlv_data])
    return false;

  if(tlv_data.type == TYPE_UPDATE) {
    return tlv_parser[tlv_data.type].parse(tlv_data) && read_subtlvs(tlv_data);
  } else {
    return read_subtlvs(tlv_data) && tlv_parser[tlv_data.type].parse(tlv_data);
  }
}


(in this pseudo-code example all these functions are assumed to have
side effects that does something useful with the parsed TLV information;
haven't actually gotten around to implementing sub-TLVs for real yet)

-Toke


From nobody Wed May 24 06:56:33 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7D8BA12EAEA for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:56:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cLCoduV_x-08 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 06:56:30 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3660D129AA0 for <babel@ietf.org>; Wed, 24 May 2017 06:56:30 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4ODuSZe032007; Wed, 24 May 2017 15:56:28 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 82E53EB200; Wed, 24 May 2017 15:56:28 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id rL9FTsddx6TZ; Wed, 24 May 2017 15:56:27 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 7C25FEB204; Wed, 24 May 2017 15:56:27 +0200 (CEST)
Date: Wed, 24 May 2017 15:56:27 +0200
Message-ID: <87h90abbp0.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>
Cc: babel@ietf.org
In-Reply-To: <87zie2gylh.fsf@alrua-x1>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 15:56:28 +0200 (CEST)
X-Miltered: at korolev with ID 5925910C.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925910C.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925910C.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/TajQdzj7efvFoJdGE82gWrCNOz4>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 13:56:31 -0000

>> The current text and implementation does the simple thing, and ignores
>> such TLVs alltogether -- so only Update carries the exception to
>> mandatory handling (which is unavoidable in that case if we wish to
>> use compression effectively). Please shout if you see any reason for
>> the other possible behaviour.

> Why is special-casing updates the simple thing? If an update is the only
> thing that requires updating parser state no matter the sub-TLV, it has
> to be special-cased and TLV parsing has to be interleaved with sub-TLV
> parsing.

I agree, it depends on the implementation.  In my implementation (that
doesn't build a parse tree, but interleaves parsing and updating data
structures), special-casing updates is the simple thing.  I suppose that
if you're building a parse tree, then the two are roughly similar.

As I've said, I don't have any strong preferences either case, so if
anyone has any usage scenarios for mandatory sub-TLVs on Next Hop or
Router-Id TLVs, I'm listening.  The one thing I think would be a mistake
would be to leave this case underspecified, so we need to make a call.

-- Juliusz


From nobody Wed May 24 07:04:04 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 847DA129A9F for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:04:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.5
X-Spam-Level: 
X-Spam-Status: No, score=-0.5 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wguC5EeSv61g for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:04:01 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2E28D127F0E for <babel@ietf.org>; Wed, 24 May 2017 07:04:00 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OE3xIo004896 for <babel@ietf.org>; Wed, 24 May 2017 16:03:59 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 647BDEB200 for <babel@ietf.org>; Wed, 24 May 2017 16:03:59 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 6uNmf699LK_r for <babel@ietf.org>; Wed, 24 May 2017 16:03:58 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 34585EB207 for <babel@ietf.org>; Wed, 24 May 2017 16:03:58 +0200 (CEST)
Date: Wed, 24 May 2017 16:03:58 +0200
Message-ID: <87fufubbch.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 16:03:59 +0200 (CEST)
X-Miltered: at korolev with ID 592592CF.006 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592592CF.006 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592592CF.006 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/qOMd_UhxZdYxc1FETAolf6JkPUc>
Subject: [babel] Changed requirements for requests
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:04:02 -0000

Folks,

I've just changed the specification of when requests MUST be sent.
Roughly speaking:

  - forwarding seqno requests is now a MUST (it used to be a SHOULD);
    https://github.com/jech/babel-drafts/commit/9bc1d5064dc63d59fe1a82901d94d5de2b5f4d28
  
  - originating seqno requests to all neighbours used to be a MUST; it is
    now MUST to at least one advertising neighbour (if any), SHOULD
    to all neighbours advertising the prefix, and MAY to any other
    neighbours.
    https://github.com/jech/babel-drafts/commit/a0e82cf0e252e30746ed8525b5557bb4eac8e7ff

If you're forwarding requests (as you formerly SHOULD and now MUST),
you're still compliant, but you have more latitude for optimisation,
especially if you're using unicast.  Please check.

Note that this makes sbabeld non-compliant, so some more word-smithing is
needed.  The idea is that you MUST forward a request if you might
advertise a route for that prefix, but I'm not sure how to specify that.

-- Juliusz


From nobody Wed May 24 07:05:40 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5465512EAF8 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:05:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CPMXvit1gIxU for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:05:33 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4889D129B31 for <babel@ietf.org>; Wed, 24 May 2017 07:05:33 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OE5V7w005893; Wed, 24 May 2017 16:05:31 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 96F33EB205; Wed, 24 May 2017 16:05:31 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id gQFPSyn6WgHs; Wed, 24 May 2017 16:05:30 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 82A81EB201; Wed, 24 May 2017 16:05:30 +0200 (CEST)
Date: Wed, 24 May 2017 16:05:30 +0200
Message-ID: <87efvebb9x.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>
Cc: babel@ietf.org
In-Reply-To: <87h90abbp0.wl-jch@irif.fr>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 16:05:31 +0200 (CEST)
X-Miltered: at korolev with ID 5925932B.002 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925932B.002 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925932B.002 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/fMFo7CVGvU6YCU7FU2DfDc5BfyQ>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:05:39 -0000

> I suppose that if you're building a parse tree, then the two are roughly
> similar.

Hmm, I'm no longer so sure about that; it might actually be significantly
simpler.  Is that your case, Toke?

David, Markus, please chime in.

-- Juliusz


From nobody Wed May 24 07:07:00 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AAD0312EAEA for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:06:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TWtcKWRZ2Pec for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:06:57 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAA51129AF1 for <babel@ietf.org>; Wed, 24 May 2017 07:06:55 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1495634812; bh=O7jg4XCKhy+/cQNgf7HoXIJuAiyMJmkIQHZrE+IZ1K0=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=PyUmxebm4wQQKTxdrKCg+lsPAFdvsYixIYM19XQL7h4Wz2CKn4Fmo7ueTP6DaiN2V dZAj3lGPGViKGZn+N/Vi/4wSOCAFfttbCdGCLI36BiIFY0ZhMamOP64TpYmOPwkTRS 2H3Ohyj/idHl2iqt09ihW1/LtR1PRAemtD06vY3I+OTu2MaU+DBqY+60LOMATaYzGd HjG+9DAR9mSHnnvmy7u9iyWSK4bTJX+SDOEeR+wYm+U/yvNJVhghUNYiIhBwo4FyDi K+a9G8Z/15Kb0Oncl+HIltKKOC9fzXc6HhkT+aeJlbmhi+gITPLFZCNQubnAWYT90L oNmcmNBRs+mwA==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr>
Date: Wed, 24 May 2017 16:06:50 +0200
In-Reply-To: <87h90abbp0.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Wed, 24 May 2017 15:56:27 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87fufucps5.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/IfFoRfEudiG-xj4dnZtPH3qcjtY>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:06:59 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

> As I've said, I don't have any strong preferences either case, so if
> anyone has any usage scenarios for mandatory sub-TLVs on Next Hop or
> Router-Id TLVs, I'm listening.

Specifying source addresses for the next hop? Extending the router-ID
size? Not sure these are actually something you'd want to do, just the
only things that came to mind...

> The one thing I think would be a mistake would be to leave this case
> underspecified, so we need to make a call.

This I can agree with :)

-Toke


From nobody Wed May 24 07:19:57 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E68E7129508 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:19:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xA_IYVYKsnGz for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:19:54 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E2AF4128B88 for <babel@ietf.org>; Wed, 24 May 2017 07:19:53 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1495635590; bh=fn2RnG+rAtIIVm1ZTjtCKICnhQxIsqh78guMh4fyevg=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=rKtAz2PM9IqMcucnpirDN1kEsYx8og7BYi2PaH5KHORJtQzCDpVcQdL0Z4QBXUooJ v3UUsJS/aYL8yIclNKpIS42lAf9D81FVKgubn7LdjW+/Y1XsDiHycUchR1XagE1TDO GrTxwu4XrNkNT4uZ0R4tfYhWpu6iEYOX1PPGJDJMn29IltT5ssjS5kIUcvoxOamUcY MseQV5qPKDAbdI4BmKhd+xSG6IE4zcDNOwyswRddRRO03Ii1gFO0wSMDdJ/x1s4dVZ TyG82/XARjuvGl+FCouoBODRgHo5CtEzpuCD52GQywpJFDMdo9MeB66k+tBwSIdCQN 9pN+AN72Fe1yQ==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr>
Date: Wed, 24 May 2017 16:19:50 +0200
In-Reply-To: <87efvebb9x.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Wed, 24 May 2017 16:05:30 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <878tlmcp6h.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/5g9TOYEukjDptaroF1Wf5fWIcFA>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:19:56 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

>> I suppose that if you're building a parse tree, then the two are roughly
>> similar.
>
> Hmm, I'm no longer so sure about that; it might actually be
> significantly simpler. Is that your case, Toke?

I'm not building a parse tree, I'm just doing two-pass parsing (first
pass reads wire data into an internal data structure while updating
parser state, second pass does protocol handling). The pseudo-code
example I posted before is not actually that far off from the actual C
function:

static inline int
babel_read_tlv(struct babel_tlv *hdr,
               union babel_msg *msg,
               struct babel_parse_state *state)
{
  if ((hdr->type <= BABEL_TLV_PADN) ||
      (hdr->type >= BABEL_TLV_MAX) ||
      !tlv_data[hdr->type].read_tlv)
    return PARSE_IGNORE;

  if (TLV_LENGTH(hdr) < tlv_data[hdr->type].min_length)
    return PARSE_ERROR;

  memset(msg, 0, sizeof(*msg));
  return tlv_data[hdr->type].read_tlv(hdr, msg, state);
}


What I was planning to do was just add a babel_read_subtlv() function
that would be called after the last line, which could just return
PARSE_IGNORE on unknown mandatory sub-TLVs (which would cause the
first-pass parser to drop the whole TLV).


I know this is very specific to the way I implemented things, but from
a high-level PoV, I'd agree with Markus that being consistent is better
than special-casing.

-Toke


From fingon@kapsi.fi  Wed May 24 07:07:39 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8735E12EAF5 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:07:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YPtF42eXmZGP for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:07:37 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7B6412EAFB for <babel@ietf.org>; Wed, 24 May 2017 07:07:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=8v0uFPX39qRp90uCfKAnpUYUd7yb0NUTGAZFyAWeWik=;  b=N79vIPekjYO6u9QGPRdjWE057igjKjfXkVnWLnumBws9Aw0DPOEX/YECTFsSTuFIWdpVD7Y4mHQtkCjrg61XMMQA7baXRFTic5MLcOfpqTaEP+vBO0bzB8cqVaUj7ok08qKIv/0/XgwoDti8cSZsuKSJwG3URrX41E1qEvMwxk28YG8k13bCi9Ik7Hy12WbyDDj6YgX1K59IdgsyGvyKuXbhQdQMsyEIaVGsncB7Fl/bKqRaZsI11sqH6FaFZBHCGCF6WbcBK9moWDzxoGG3JxLEwUa97O9dN3b4aD/uxqT8+PF/ofZbnBy3dKahH4oVBjX2Wjq/B32gkbLd3Qnkew==;
Received: from a91-155-69-187.elisa-laajakaista.fi ([91.155.69.187] helo=poro.lan) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dDWwi-0007ew-OU; Wed, 24 May 2017 17:07:28 +0300
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <87efvebb9x.wl-jch@irif.fr>
Date: Wed, 24 May 2017 17:07:28 +0300
Cc: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>, babel@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 91.155.69.187
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/5H-IOTvumIlqsLdVLOHr0ApdMxQ>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:20:55 -0000

On 24 May 2017, at 17.05, Juliusz Chroboczek <jch@irif.fr> wrote:
>> I suppose that if you're building a parse tree, then the two are =
roughly
>> similar.
> Hmm, I'm no longer so sure about that; it might actually be =
significantly
> simpler.  Is that your case, Toke?
>=20
> David, Markus, please chime in.

On ideological level, I would prefer just to say that _regardless_ of =
TLV type mandatory bit in sub-TLVs works in a specific way. One might =
additionally note that in case of update TLVs (at least) it is a bad =
idea, but it would keep the design simple and easy to understand (and =
implement).

Cheers,

-Markus=


From fingon@kapsi.fi  Wed May 24 07:09:24 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE764129508 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:09:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.2
X-Spam-Level: 
X-Spam-Status: No, score=-1.2 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x_vcUfi20W8m for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:09:23 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC035129B2E for <babel@ietf.org>; Wed, 24 May 2017 07:09:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=3Vt9zaEWZcYDrQXvfUFqp0YprCDt5Vn7Zhz2VbxJZZk=;  b=AknE1SlykYue4Tbzlyx3cRups6xXaZMhj8+7pO2pqiXHQxTg6sJHl5D9VWvMu6ppHCW8AC19ulDcoOyaoo1DxwFiIDqgjNSG9D9GNye+1tXLtjUeVVJQiiv1pSbNU8lvJZ9iXk5dw3jV0z1yUKEzxtY+tKYDUWXi02fGWUs5NKqsvtL7LKknUwdB46xbBXHPyi6UYs0ckf2TU3HyceMpmilcSC3OlyCbjYeF9CfK55F5B4Q3uop4Oou4RGu418/I7Z+yFguUbTjZr6+fk2TlOxN21RlloRcIpBWArtbC8Ijyg4VwMOi04ldn4SDe7HnYC3sAF+vkYZJucnIeixe9DQ==;
Received: from a91-155-69-187.elisa-laajakaista.fi ([91.155.69.187] helo=poro.lan) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dDWyY-0008GO-2A; Wed, 24 May 2017 17:09:22 +0300
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <87mva2be6n.wl-jch@irif.fr>
Date: Wed, 24 May 2017 17:09:21 +0300
Cc: Matthieu Boutier <boutier@irif.fr>, babel@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <A3005A31-FFF7-4B32-AE20-28369951E94E@iki.fi>
References: <87y3tmbg1e.wl-jch@irif.fr> <D1FCE601-9DB8-4B86-8251-4F20BD42E300@irif.fr> <87mva2be6n.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 91.155.69.187
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/TRThCZTc0wxJUVDwLjlcE6KqIQY>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:20:58 -0000

On 24 May 2017, at 16.02, Juliusz Chroboczek <jch@irif.fr> wrote:
>> Next Hop and Router-ID only update state, instead of Updates which =
also
>> carry route information.  So it is possible to just update state with
>> two successive Next Hop or Router-ID TLVs (the first without =
mandatory
>> sub-TLV).
> You=E2=80=99ve got a sick mind ;-)

Haha. High five, Mathieu; I was thinking of the same example but figured =
I did not want to bring it up this morning.

In general I do not like constraining functionality arbitrarily, as long =
as not constraining has well understood outcome (and I believe that is =
the case here).

Cheers,

-Markus=


From nobody Wed May 24 07:25:32 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C4F28129AF1 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:25:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wk6PBQwgncTN for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:25:29 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5BB2B129AA0 for <babel@ietf.org>; Wed, 24 May 2017 07:25:29 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OEPRA8018121 for <babel@ietf.org>; Wed, 24 May 2017 16:25:27 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id BD52FEB200 for <babel@ietf.org>; Wed, 24 May 2017 16:25:27 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id c3inygoToapb for <babel@ietf.org>; Wed, 24 May 2017 16:25:26 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 6FFFDEB206 for <babel@ietf.org>; Wed, 24 May 2017 16:25:26 +0200 (CEST)
Date: Wed, 24 May 2017 16:25:26 +0200
Message-ID: <878tlmbacp.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
In-Reply-To: <87fufubbch.wl-jch@irif.fr>
References: <87fufubbch.wl-jch@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 16:25:27 +0200 (CEST)
X-Miltered: at korolev with ID 592597D7.004 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592597D7.004 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592597D7.004 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/-6gD4y9ESB20sFGXu967SECruM4>
Subject: Re: [babel] Changed requirements for requests
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:25:31 -0000

> Note that this makes sbabeld non-compliant, so some more word-smithing is
> needed.  The idea is that you MUST forward a request if you might
> advertise a route for that prefix, but I'm not sure how to specify that.

https://github.com/jech/babel-drafts/commit/5396e8a979cfe4f37086af2f8b2f51e9df50fa72


From nobody Wed May 24 07:37:32 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E413212EAEB for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:37:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P047l_I3nW_d for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:37:29 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A9641129B49 for <babel@ietf.org>; Wed, 24 May 2017 07:37:28 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OEbQWN025610; Wed, 24 May 2017 16:37:26 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id EA03EEB204; Wed, 24 May 2017 16:37:26 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 4thrG0o_fKk0; Wed, 24 May 2017 16:37:25 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id CFDA5EB205; Wed, 24 May 2017 16:37:23 +0200 (CEST)
Date: Wed, 24 May 2017 16:37:23 +0200
Message-ID: <8760gqb9ss.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Markus Stenberg <markus.stenberg@iki.fi>
Cc: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>, babel@ietf.org
In-Reply-To: <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 16:37:27 +0200 (CEST)
X-Miltered: at korolev with ID 59259AA6.003 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59259AA6.003 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 59259AA6.003 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/AfporW_er6rLmD9qqVv3D94CRic>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:37:30 -0000

I'm slowly starting to agree with you guys.

Markus said:

> On ideological level, I would prefer just to say that _regardless_ of
> TLV type mandatory bit in sub-TLVs works in a specific way.

So that would mean saying that all the parser state (default prefix,
router-id, next hop) are updated even for ignored sub-TLVs, whatever the
TLV?  You appear to be agreeing with Toke.

Toke said:

> Specifying source addresses for the next hop?

I'm not sure what the proper semantics would be, here: do you want the
next hop to be taken into account if the receiver doesn't understand the
extension?

> Extending the router-ID size?

I'm not sure how that would work.  You'd probably want the whole set of
updates to be dropped if the receiver cannot grok the larger router-id, so
you'd really want to put a mandatory sub-TLV on all updates.

A similar idea would be putting the source prefix in the Router-ID.  So
instead of the Matthieu's current encoding:

  router-id
  update (mandatory source-prefix=A)
  update (mandatory source-prefix=A)

you'd have the slightly more economic

  router-id (mandatory source-prefix=A)
  update
  update

Again, you'd want the whole block of updates to be ignored if the
router-id is not understood, so that idea's not gonna fly without some
very complex semantics.

-- Juliusz


From nobody Wed May 24 07:49:35 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54447129AF7 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:49:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bRQB679AqxHP for <babel@ietfa.amsl.com>; Wed, 24 May 2017 07:49:32 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADD98127873 for <babel@ietf.org>; Wed, 24 May 2017 07:49:32 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1495637365; bh=xddAX7erzTIond5wws0kLjVZBwKIvlFfsMQoMJyTXFM=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=TL5StN7cDWWIilCJA6GPvVuSl+1eIyQXKgVN5Pq7XyJLjk1PvwxgIXKPXBOHFMbLT ZZitI7XdM7F+JmqQd9kGvKKa4Du/T3L107kXDsEYynLbN3MZKV7i6eQ2XKKttN6c/H mpT63bY0+qnN207FmWFeMS5qSloNoT/BGUjJPbUBrdLLW9Gv4+N/xl5EB5I0opw76q ccr0ca5vsqn3WyerBxw5vEtFiIzaddgJveD6yiYmSvR+jxVqiqNab57Yqa/WcMqgfw m7OilS1GSo+USmC0v7x4EQgjqnyLC6bbZgwFKRHGc52fCkebpMVNfAgwWj0CQTpbYX BISQ3HqZV3PeA==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: Markus Stenberg <markus.stenberg@iki.fi>,  babel@ietf.org
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr>
Date: Wed, 24 May 2017 16:49:23 +0200
In-Reply-To: <8760gqb9ss.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Wed, 24 May 2017 16:37:23 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87shjus424.fsf@alrua-karlstad>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/i8TtiBCRnw01pwQ09gQVjGkf7Yc>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 14:49:34 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

> I'm slowly starting to agree with you guys.

Wooh ;)

> Toke said:
>
>> Specifying source addresses for the next hop?
>
> I'm not sure what the proper semantics would be, here: do you want the
> next hop to be taken into account if the receiver doesn't understand
> the extension?

I was thinking along the lines of being able to express "this next-hop
is only available from this source prefix (due to, e.g., firewall
rules)". Something like:

nexthop (sub-tlv: only from source-prefix A)
nexthop (sub-tlv: only from source-prefix B)

where the implementation would pick the right one, and an implementation
that didn't understand the sub-tlv would ignore both.

Not sure how useful this is in practice, but why rule it out? :)

-Toke


From nobody Wed May 24 08:06:43 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4BD15129B41 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 08:06:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 31V13kpeBMUp for <babel@ietfa.amsl.com>; Wed, 24 May 2017 08:06:39 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 097D0126FB3 for <babel@ietf.org>; Wed, 24 May 2017 08:06:38 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OF6b8q009597; Wed, 24 May 2017 17:06:37 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 6052AEB200; Wed, 24 May 2017 17:06:37 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id OZ7a3A2G3M3P; Wed, 24 May 2017 17:06:36 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 5DAF7EB207; Wed, 24 May 2017 17:06:36 +0200 (CEST)
Date: Wed, 24 May 2017 17:06:36 +0200
Message-ID: <87wp969tvn.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>
Cc: babel@ietf.org
In-Reply-To: <87shjus424.fsf@alrua-karlstad>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87shjus424.fsf@alrua-karlstad>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 17:06:37 +0200 (CEST)
X-Miltered: at korolev with ID 5925A17D.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925A17D.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925A17D.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/eY9X14wYaNlNbOvqCdQHFyjuD7k>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 15:06:42 -0000

> I was thinking along the lines of being able to express "this next-hop
> is only available from this source prefix (due to, e.g., firewall
> rules)". Something like:

> nexthop (sub-tlv: only from source-prefix A)
> nexthop (sub-tlv: only from source-prefix B)

> where the implementation would pick the right one, and an implementation
> that didn't understand the sub-tlv would ignore both.

Hmm... so that would require the current semantics, the one you've been
arguing against?

-- Juliusz


From nobody Wed May 24 10:01:25 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0AC9012EB74 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:01:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BCta7hY32ysz for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:01:22 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6800512EB73 for <babel@ietf.org>; Wed, 24 May 2017 10:01:22 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OH1Il3002112; Wed, 24 May 2017 19:01:18 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id A13E5EB200; Wed, 24 May 2017 19:01:18 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 8xGXrbvRZeVL; Wed, 24 May 2017 19:01:12 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 4A243EB204; Wed, 24 May 2017 19:01:10 +0200 (CEST)
Date: Wed, 24 May 2017 19:01:10 +0200
Message-ID: <87lgpm9okp.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Markus Stenberg <markus.stenberg@iki.fi>
Cc: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>, babel@ietf.org
In-Reply-To: <8760gqb9ss.wl-jch@irif.fr>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 19:01:20 +0200 (CEST)
X-Miltered: at korolev with ID 5925BC5E.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925BC5E.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925BC5E.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/rCfQk7X2F_OTopj6RVAlWfTJ9vg>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 17:01:24 -0000

> I'm slowly starting to agree with you guys.

After further thought, I agree.

  https://github.com/jech/babel-drafts/commit/f216118f5751a8c95e59c8333b989f21da9da246

Both my implementations updated to comply, it's a trivial change (just
swap updating the parser state with checking for unknown mandatory sub-TLVs).

-- Juliusz




From nobody Wed May 24 10:08:35 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: babel@ietf.org
Delivered-To: babel@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id A4B801200CF; Wed, 24 May 2017 10:08:33 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: babel@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.51.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <149564571365.8628.11699978121196879342@ietfa.amsl.com>
Date: Wed, 24 May 2017 10:08:33 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/I1s6Zs17NHDP_i_3npXxr7FWBsM>
Subject: [babel] I-D Action: draft-ietf-babel-rfc6126bis-02.txt
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 17:08:33 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Babel routing protocol of the IETF.

        Title           : The Babel Routing Protocol
        Author          : Juliusz Chroboczek
	Filename        : draft-ietf-babel-rfc6126bis-02.txt
	Pages           : 52
	Date            : 2017-05-24

Abstract:
   Babel is a loop-avoiding distance-vector routing protocol that is
   robust and efficient both in ordinary wired networks and in wireless
   mesh networks.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-babel-rfc6126bis/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-babel-rfc6126bis-02
https://datatracker.ietf.org/doc/html/draft-ietf-babel-rfc6126bis-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-babel-rfc6126bis-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed May 24 10:22:08 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D11712EB52 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:22:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ltO4FD_0GKE2 for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:22:04 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2B31129BC5 for <babel@ietf.org>; Wed, 24 May 2017 10:22:03 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OHM2vv009847 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 24 May 2017 19:22:02 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4OHM1sg009814; Wed, 24 May 2017 19:22:02 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id EFA06EB200; Wed, 24 May 2017 19:22:01 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id zAXpoB-XqIBq; Wed, 24 May 2017 19:22:00 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 9C9B6EB204; Wed, 24 May 2017 19:22:00 +0200 (CEST)
Date: Wed, 24 May 2017 19:22:00 +0200
Message-ID: <87h90a9nlz.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org, babel-users@lists.alioth.debian.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 24 May 2017 19:22:02 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 24 May 2017 19:22:02 +0200 (CEST)
X-Miltered: at korolev with ID 5925C13A.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 5925C139.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925C13A.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 5925C139.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925C13A.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 5925C139.001 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/eDggzT8l7BhlPKj3OX2_cnTZlSg>
Subject: [babel] draft-ietf-babel-rfc6126bis-02
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 17:22:06 -0000

Dear all,

I've just published a new version of the Babel protocol specification:

  https://tools.ietf.org/html/draft-ietf-babel-rfc6126bis-02

This version containts some fairly major changes, the most notable being
the addition of mandatory bits to the extension subprotocol.  There have
also been some fairly technical changes to the procedures for sending of
requests, which should not invalidate any existing implementations.

The mandatory bit makes the protocol more easily extensible by making it
possible to explicitly encode the fact that an extension is not backwards
compatible.  It has greatly simplified the packet format of Matthieu
Boutier's source-specific extension [1], and is used by Gwendoline
Chouasne's TOS-specific extension [2].

[1] https://github.com/boutier/babeld/tree/dev
[2] https://github.com/Gwendocg/babeldToS

Both babeld and sbabeld have support for mandatory bits in their
"mandatory" branches.  I'll wait a few days to see if there are any flaws
in this proposal, then merge into trunk.  Please consider implementing
mandatory bits if you have an implementation of Babel.

The backwards compatibility of this change is reasonably strong, but
somewhat weaker than what we at Babel Towers have been doing previously.
More exactly:

  - new implementations of Babel will interoperate with old
    implementations as long as the former don't use any extensions that
    the latter don't understand;
  - new implementations of Babel that use the new extensions (new-style
    source-specific routing, TOS-specific routing) will not interoperate
    with old implementations, and might even create routing loops.

We will refrain from deploying the new extensions until all implementations
have acquired support for mandatory bits.

Please read.  Please think it over.  Please comment.

-- Juliusz


From nobody Wed May 24 10:38:28 2017
Return-Path: <bs7652@att.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 22BC9129435; Wed, 24 May 2017 10:38:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4
X-Spam-Level: 
X-Spam-Status: No, score=-4 tagged_above=-999 required=5 tests=[BAYES_05=-0.5,  RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5zqXBrzNYtED; Wed, 24 May 2017 10:38:19 -0700 (PDT)
Received: from mx0a-00191d01.pphosted.com (mx0b-00191d01.pphosted.com [67.231.157.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 97D011201F8; Wed, 24 May 2017 10:38:19 -0700 (PDT)
Received: from pps.filterd (m0083689.ppops.net [127.0.0.1]) by m0083689.ppops.net-00191d01. (8.16.0.17/8.16.0.17) with SMTP id v4OHEurP045996; Wed, 24 May 2017 13:38:11 -0400
Received: from alpi154.enaf.aldc.att.com (sbcsmtp6.sbc.com [144.160.229.23]) by m0083689.ppops.net-00191d01. with ESMTP id 2ane46h3ug-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 24 May 2017 13:38:11 -0400
Received: from enaf.aldc.att.com (localhost [127.0.0.1]) by alpi154.enaf.aldc.att.com (8.14.5/8.14.5) with ESMTP id v4OHcAGh014562; Wed, 24 May 2017 13:38:10 -0400
Received: from alpi132.aldc.att.com (alpi132.aldc.att.com [130.8.217.2]) by alpi154.enaf.aldc.att.com (8.14.5/8.14.5) with ESMTP id v4OHc0f3014402 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 24 May 2017 13:38:02 -0400
Received: from GAALPA1MSGHUBAC.ITServices.sbc.com (GAALPA1MSGHUBAC.itservices.sbc.com [130.8.218.152]) by alpi132.aldc.att.com (RSA Interceptor); Wed, 24 May 2017 17:37:46 GMT
Received: from GAALPA1MSGUSRBF.ITServices.sbc.com ([169.254.5.82]) by GAALPA1MSGHUBAC.ITServices.sbc.com ([130.8.218.152]) with mapi id 14.03.0319.002; Wed, 24 May 2017 13:37:46 -0400
From: "STARK, BARBARA H" <bs7652@att.com>
To: Ted Lemon <mellon@fugue.com>, Jehan Tremback <jehan.tremback@gmail.com>
CC: "babel@ietf.org" <babel@ietf.org>, Mark Townsley <mark@townsley.net>, David Schinazi <dschinazi@apple.com>, Juliusz Chroboczek <jch@irif.fr>, "homenet-babel-sec@ietf.org" <homenet-babel-sec@ietf.org>
Thread-Topic: [Homenet-babel-sec] Security Design Team - July is coming!
Thread-Index: AQHS0/fEja6OLFFKFkuUjXij+MO+KqIDwBsQ
Date: Wed, 24 May 2017 17:37:46 +0000
Message-ID: <2D09D61DDFA73D4C884805CC7865E6114DB71BCB@GAALPA1MSGUSRBF.ITServices.sbc.com>
References: <5255AA16-3DA8-418B-8533-B87F1CA78A72@townsley.net> <168E460A-29A7-4AA1-9232-6A777F8F93DE@fugue.com> <A1A2DC72-FAB0-4E9E-826A-7F15A4110D70@apple.com> <7i4lwb33gq.wl-jch@irif.fr> <CABG_PfQ77XKSHyYrxWcadqOnrbvnO6VgiL6SWbxB2fdjyZOyxg@mail.gmail.com> <246CDF99-F236-44FD-9C9D-7C7E4B63D12A@fugue.com>
In-Reply-To: <246CDF99-F236-44FD-9C9D-7C7E4B63D12A@fugue.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [135.70.92.28]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-RSA-Inspected: yes
X-RSA-Classifications: public
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:, , definitions=2017-05-24_12:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_policy_notspam policy=outbound_policy score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 impostorscore=0 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1703280000 definitions=main-1705240082
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/V04heBUd3GFwaNo5Wb3PcUQJ7bQ>
Subject: Re: [babel] [Homenet-babel-sec] Security Design Team - July is coming!
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 17:38:21 -0000

> Here are the notes that we took in the break-out session after the main m=
eeting:
> https://github.com/bhstark2/babel-security/blob/master/chicago-notes.md=20
> There's also a file there where we were going to put in our thoughts abou=
t the threat model, so that we could try to come up with an idea of what we=
 are all talking about. =A0 However, it looks like nobody's actually done a=
nything to that document.

Please let me know if I should add anyone to this github.
BTW, I'm on vacation this week and will not be particularly responsive duri=
ng this time.
Barbara


From nobody Wed May 24 10:49:06 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E138C126BFD for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:49:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.501
X-Spam-Level: 
X-Spam-Status: No, score=-0.501 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8ilE7TiRt-7J for <babel@ietfa.amsl.com>; Wed, 24 May 2017 10:49:02 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60E1D120046 for <babel@ietf.org>; Wed, 24 May 2017 10:49:02 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OHn0pX018055 for <babel@ietf.org>; Wed, 24 May 2017 19:49:00 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 8C270EB200 for <babel@ietf.org>; Wed, 24 May 2017 19:49:00 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id vY_kBrO1QDnC for <babel@ietf.org>; Wed, 24 May 2017 19:48:59 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 773A6EB204 for <babel@ietf.org>; Wed, 24 May 2017 19:48:59 +0200 (CEST)
Date: Wed, 24 May 2017 19:48:59 +0200
Message-ID: <87fufu9md0.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 24 May 2017 19:49:00 +0200 (CEST)
X-Miltered: at korolev with ID 5925C78C.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925C78C.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925C78C.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/lyiqAQ65a4jdUwbb54O5Q3qBOeE>
Subject: [babel] Remaining work for rfc6126bis
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 17:49:04 -0000

Dear all,

-02 contains most of what I had planned for rfc6126bis; I, for one, would
not be overly disappointed if this version were submitted for publication
as an RFC.

I think the only remaining protocol change that we want to consider at
this stage are extensions to the Hello-ing mechanism, notably unicast and
interval-less hellos.  There are various possibilities:

  - use the Reserved field of the Hello TLV (preferred by David S.);
  - define a new TLV (preferred by Markus S.);
  - define a mandatory sub-TLV of the Hello TLV.

Other than that, I believe some purely editorial changes are still
required, I'll go through my (very messy at this stage) notes at some
point.  Plus I need to acknowledge everyone who participated without
missing anyone.

Other WG work required:

  - change the IANA registries to reflect mandatory bits (Donald, how do
    I do that?);
  - work on the applicability document (grr, it bores me to death);
  - finalise the data model.

There's some non-WG work that's required for further progress:

  - make all implementations known to Man (includes women) grok mandatory
    bits, and bully everyone to deploy the new versions;
  - document the new extensions (new format of source-specific, TOS-specific)
    and make sure they don't suck (Matthieu, Gwendoline, that's you);
  - work on Stenberg-Schinazi style security for Babel (Antonin, that's you).

-- Juliusz


From nobody Wed May 24 12:32:38 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C058B12025C for <babel@ietfa.amsl.com>; Wed, 24 May 2017 12:32:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hS7nJn_g4_JZ for <babel@ietfa.amsl.com>; Wed, 24 May 2017 12:32:35 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BA82312940C for <babel@ietf.org>; Wed, 24 May 2017 12:32:34 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4OJWWT3008925 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 24 May 2017 21:32:32 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4OJWT0X001692; Wed, 24 May 2017 21:32:29 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 0FA9CEB204; Wed, 24 May 2017 21:32:29 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id kgT76E8ZcwKs; Wed, 24 May 2017 21:32:28 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 0A892EB201; Wed, 24 May 2017 21:32:27 +0200 (CEST)
Date: Wed, 24 May 2017 21:32:27 +0200
Message-ID: <87zie28304.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Markus Stenberg <markus.stenberg@iki.fi>
Cc: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>, babel@ietf.org
In-Reply-To: <87lgpm9okp.wl-jch@irif.fr>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87lgpm9okp.wl-jch@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 24 May 2017 21:32:33 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 24 May 2017 21:32:32 +0200 (CEST)
X-Miltered: at korolev with ID 5925DFD0.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 5925DFCD.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5925DFD0.001 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 5925DFCD.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5925DFD0.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 5925DFCD.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/MJ7BzF-vDrycfSWHmZlGy6xUxJs>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 May 2017 19:32:37 -0000

>> I'm slowly starting to agree with you guys.

> After further thought, I agree.

Another advantage is that tools like tcpdump can parse Babel without
taking mandatory bits into account.  Definitely the right thing.

-- Juliusz


From nobody Thu May 25 04:44:46 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 018361294D4 for <babel@ietfa.amsl.com>; Thu, 25 May 2017 04:44:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.698
X-Spam-Level: 
X-Spam-Status: No, score=0.698 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aivFbvahpExg for <babel@ietfa.amsl.com>; Thu, 25 May 2017 04:44:42 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 43F81127BA3 for <babel@ietf.org>; Thu, 25 May 2017 04:44:42 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1495712674; bh=21C3h7myhbNTK8CUsO/weC1+fxpqNHLhWNWk9J2OyDk=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=EBV/cQQLF5icI7Yq9uG+mdGL1bO0rx+HL/yy2h3F5ZMXj7pYJieDtJD78ZimsPTf4 hOX4/6yHKMJh/y8ky98gRCv3IxFcDc2qJv0bU8NagY3wcAXQDoVoI4hTlzVbow8Oiz KGscbttgPIZVzarp1n9c8F+Q+GLfboQ1qMRLoEw+OO/iHQaJuoIWFa7zZVJwn88c7l xG3MnpxxP2XW415NcCJvasFUYD6fWOGplmCxX8FIS6wiTwYwZTIHGrdhHGoVBrhexZ 3yocU6Vfvf9O3VI3J/ea2OpT+ZPUy0tcUsrS4/ldC8Skqo/k29ZvkUQM6/TdINRhgk Ezg8ylF9FPIoA==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87shjus424.fsf@alrua-karlstad> <87wp969tvn.wl-jch@irif.fr>
Date: Thu, 25 May 2017 13:44:32 +0200
In-Reply-To: <87wp969tvn.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Wed, 24 May 2017 17:06:36 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87o9uhrwin.fsf@alrua-karlstad>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/EVOikJBiUVa8PCfJw3Q3OYqk_QE>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 May 2017 11:44:45 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

>> I was thinking along the lines of being able to express "this next-hop
>> is only available from this source prefix (due to, e.g., firewall
>> rules)". Something like:
>
>> nexthop (sub-tlv: only from source-prefix A)
>> nexthop (sub-tlv: only from source-prefix B)
>
>> where the implementation would pick the right one, and an implementation
>> that didn't understand the sub-tlv would ignore both.
>
> Hmm... so that would require the current semantics, the one you've
> been arguing against?

Yeah, realise that. As I said, not sure if it is actually useful; more
of a thought experiment to come up with a reason. I do still think being
consistent is better :)

-Toke


From nobody Thu May 25 05:03:41 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 62ACF12940B for <babel@ietfa.amsl.com>; Thu, 25 May 2017 05:03:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.799
X-Spam-Level: 
X-Spam-Status: No, score=0.799 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U8EjeqoHja33 for <babel@ietfa.amsl.com>; Thu, 25 May 2017 05:03:38 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4C8B612426E for <babel@ietf.org>; Thu, 25 May 2017 05:03:38 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4PC3aVJ002840; Thu, 25 May 2017 14:03:36 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 8A937EB200; Thu, 25 May 2017 14:03:36 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id kUwZVgx2Qhqy; Thu, 25 May 2017 14:03:35 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 75CCDEB206; Thu, 25 May 2017 14:03:35 +0200 (CEST)
Date: Thu, 25 May 2017 14:03:35 +0200
Message-ID: <87r2zdta7c.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>
Cc: babel@ietf.org
In-Reply-To: <87o9uhrwin.fsf@alrua-karlstad>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87shjus424.fsf@alrua-karlstad> <87wp969tvn.wl-jch@irif.fr> <87o9uhrwin.fsf@alrua-karlstad>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Thu, 25 May 2017 14:03:36 +0200 (CEST)
X-Miltered: at korolev with ID 5926C818.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 5926C818.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 5926C818.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/ckO4UBJFviLCg9-DXTzBREixhz0>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 May 2017 12:03:40 -0000

> I do still think being consistent is better :)

Consistency is the straightjacket of small minds.

The main insight your comments gave me is that there are two layers: the
parser, which happens to be stateful and implements compression, and the
rest of Babel, which is layered above the parser.  Clearly, you want the
parser to build the same parse tree whichever options are implemented, so
the parser must ignore mandatory bits.  (In particular, tcpdump and
wireshark only do parsing, and you want them to be implementable
deterministically without reference to a specific set of extensions.)

To put it differently: suppose Babel were reformulated to use the PacketBB
packet format, or XML, or JSON, or protobuf, or whatever other horror the
"let's specify first and implement someday" community has come up with
today.  Then the whole stateful parsing layer would go away, but you'd
want the handling of mandatory bits to remain unchanged.

The reason I was confused is that I've been interleaving parsing and
acting on the result in my implementation, so the distinction between the
two layers wasn't obvious to me.  I hope I've managed to make it clear in
the current version of the draft, but there's obviously room for improvement.

-- Juliusz


From nobody Fri May 26 07:26:09 2017
Return-Path: <boutier@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ABA221294E9 for <babel@ietfa.amsl.com>; Fri, 26 May 2017 07:26:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.5
X-Spam-Level: 
X-Spam-Status: No, score=-0.5 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8D3ojl2EX12N for <babel@ietfa.amsl.com>; Fri, 26 May 2017 07:26:05 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 655A0126D74 for <babel@ietf.org>; Fri, 26 May 2017 07:26:05 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4QEQ3qP015328 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Fri, 26 May 2017 16:26:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4QEQ3rP005633; Fri, 26 May 2017 16:26:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 28D7EEB205; Fri, 26 May 2017 16:26:03 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id goVUOPFMSLPX; Fri, 26 May 2017 16:26:01 +0200 (CEST)
Received: from [192.168.1.30] (chl77-1-88-181-65-42.fbx.proxad.net [88.181.65.42]) (Authenticated sender: boutier) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 0BFDCEB201; Fri, 26 May 2017 16:26:01 +0200 (CEST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Matthieu Boutier <boutier@irif.fr>
In-Reply-To: <87h90a9nlz.wl-jch@irif.fr>
Date: Fri, 26 May 2017 16:26:00 +0200
Cc: babel@ietf.org, babel-users@lists.alioth.debian.org
Content-Transfer-Encoding: 7bit
Message-Id: <70ED4D66-B6BF-4D29-B24F-32A2C6779789@irif.fr>
References: <87h90a9nlz.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3124)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Fri, 26 May 2017 16:26:03 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Fri, 26 May 2017 16:26:03 +0200 (CEST)
X-Miltered: at korolev with ID 59283AFB.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 59283AFB.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 59283AFB.001 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<boutier@irif.fr>
X-j-chkmail-Enveloppe: 59283AFB.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<boutier@irif.fr>
X-j-chkmail-Score: MSGID : 59283AFB.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 59283AFB.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/alSjytHBK3iRMkS6z5AfkUofBto>
Subject: [babel] source sub-tlv
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 May 2017 14:26:08 -0000

Hello,

Here is my code for source-specific extension of Babel using sub-TLV.

    https://github.com/boutier/babeld/tree/dev

* Packet format

The sub-TLV format is [ type | length | src-plen | src-prefix].  For now,
I use the value 250 for the sub-tlv source prefix.

* Source-specific wildcard requests

At this point, wildcard requests were treated separately.  Legacy
wildcard requests send classical routes only, and source-specific
wildcard requests send specific routes only.  The objective was to
let unchanged the behaviour "send routes specified by 6126 on a 6126's
request".  To have all routes, you had to send one wildcard request and
one wildcard source-specific request.

The current implementation does not change this behaviour.  To have all
routes, you must send one wildcard request (wildcard request without
source sub-TLV) and one source-specific wildcard request (request with
source sub-TLV).

If we keep this behaviour and mix tos-specific routes, we will have
to send 4 wildcard requests to have all routes.  I see two reasonable
options:

  - only keep (legacy) wildcard requests, and reply with a full dump.

  - send one request with all sub-TLVs you know but without mandatory
    bit, and reply to all options you know about.

The second is slightly more complex to implement, but may reduce
overhead when a legacy implementation requests a dump to an extended
one.  It also implies that mandatory and non-mandatory extension shares
the same space.

You may also want to give guidelines for futures extensions in 6126bis
about this kind of problems.

Any thoughts?

Matthieu


From nobody Sun May 28 14:18:50 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A832129413; Sun, 28 May 2017 14:18:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.799
X-Spam-Level: 
X-Spam-Status: No, score=0.799 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cAl9cVY7INdQ; Sun, 28 May 2017 14:18:47 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A138C1200CF; Sun, 28 May 2017 14:18:46 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4SLIh5F024905 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Sun, 28 May 2017 23:18:44 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4SLIhNe006645; Sun, 28 May 2017 23:18:43 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 89CB6EB200; Sun, 28 May 2017 23:18:43 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id Z_1ZdCkQrqP1; Sun, 28 May 2017 23:18:42 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 90174EB204; Sun, 28 May 2017 23:18:42 +0200 (CEST)
Date: Sun, 28 May 2017 23:18:42 +0200
Message-ID: <87d1ask7d9.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: homenet-babel-sec@ietf.org
CC: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Sun, 28 May 2017 23:18:44 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Sun, 28 May 2017 23:18:43 +0200 (CEST)
X-Miltered: at korolev with ID 592B3EB3.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592B3EB3.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592B3EB3.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592B3EB3.001 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592B3EB3.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592B3EB3.001 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/cA3TGYgjS4Wsd3Ld_V-WFBT_PU4>
Subject: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 21:18:49 -0000

Dear Ted, dear list,

(Babel list in copy of this mail.)

There are two facets to Homenet security: HNCP and Babel.  We, at Babel
towers, are planning to implement Stenberg-style security for Babel during
the month of July (earlier is not possible due to my prospective interns
having to sit their exams).  When we're done, we can compare this aproach
to the existing HMAC security, and see which of the two approaches is more
suitable for Homenet.

For the Babel work to be useful for Homenet security, HNCP needs to be
extended with two features:

  - the ability to signal other HNCP nodes that a given link requires
    authentication and/or encryption, and to securely signal any private
    keys;
  - the ability to protect HNCP traffic over an untrusted link.

Pierre has mentioned that HNCP already supports all or most of that, but
somebody needs to write down the relevant protocol bits and check whether
everything is implemented.

I'd much prefer that this work be done before we start extending Babel,
since having the HNCP bits ready would help us ensure that we're meeting
all of the Homenet requirements.

I'm leaving for a short holiday tomorrow, so please don't worry if I'm not
very responsive during the next week.  I've got exams the week after, so
please don't worry if I'm not very responsive the week after that.  Pleae
expect me to be my usual annoyingly chatty and opinionated self in two
weeks' time.

Regards,

-- Juliusz


From nobody Sun May 28 14:31:08 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F157F129494 for <babel@ietfa.amsl.com>; Sun, 28 May 2017 14:31:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hh22z5jbGKv8 for <babel@ietfa.amsl.com>; Sun, 28 May 2017 14:31:05 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79EC2120046 for <babel@ietf.org>; Sun, 28 May 2017 14:31:05 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4SLV3X8026304 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for <babel@ietf.org>; Sun, 28 May 2017 23:31:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4SLV3UP007801 for <babel@ietf.org>; Sun, 28 May 2017 23:31:03 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id D0D97EB201 for <babel@ietf.org>; Sun, 28 May 2017 23:31:03 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id gMbql1l1kfa3 for <babel@ietf.org>; Sun, 28 May 2017 23:31:02 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id C62E3EB200 for <babel@ietf.org>; Sun, 28 May 2017 23:31:02 +0200 (CEST)
Date: Sun, 28 May 2017 23:31:02 +0200
Message-ID: <87bmqck6sp.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: babel@ietf.org
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Sun, 28 May 2017 23:31:03 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Sun, 28 May 2017 23:31:03 +0200 (CEST)
X-Miltered: at korolev with ID 592B4197.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592B4197.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592B4197.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592B4197.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592B4197.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592B4197.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/oeuZyGAE2XCLoeHQwrs3b0qLE8E>
Subject: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 21:31:07 -0000

Dear list,

As I may have mentioned before, we at Babel Towers are planning to work on
Stenberg-style security for Babel during the month of July.  While we can
start the work without unicast Hellos (Hellos will be unprotected, big
deal, and RTT estimation will break), it would of course be better if we
had a complete design for unicast Hellos so that we can implement both at
the same time.

We did discuss some of the issues about unicast Hellos back in Chicago,
and at the risk of boring my audience, please allow me to reiterate (my
understanding of) our conclusions:

  1. There are two natural ways of encoding unicast Hellos: by using the
     Reserved field of the existing Hello, or by defining a new TLV.  The
     latter has a more graceful failure mode in the presence of legacy
     implementations, the former seems more elegant to some.  Since we're
     already breaking compatibility with the Mandatory bit, I'm okay with
     either choice.  (There is also one unnatural way -- using a carefully
     crafted sub-TLV -- but I don't think we're going to do that.)

  2. There is some confusion about the meaning of Interval in the presence
     of unicast Hellos: does it carry a promise of sending another Hello
     of any type, or does it carry a promise of sending a Hello of the
     same type.  If the latter, then I can see a need for an interval-less
     Hello.  (Interval=0 is a reasonable way to encode that.)

  3. The majority opinion appears that Unicast Hellos carry a Seqno, just
     like multicast ones.  My proposal to make them Seqno-less was soundly
     trashed.

  4. Unicast Hellos require new link-quality estimation algorithms.  In
     the spirit of RFC 6126, I intend that said algorithms will not be
     normative -- implementation advice will be given in the relevant
     appendix to the spec.  I am volunteering to do some serious
     experimentation.

As mentioned in a previous mail, I'll be only marginally available until
9 June, but fairly active after that date.  I would be overwhelmed with
joy if people could write down and implement their proposals by that date.

-- Juliusz


From nobody Sun May 28 14:54:04 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2A195129493; Sun, 28 May 2017 14:54:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.1
X-Spam-Level: 
X-Spam-Status: No, score=0.1 tagged_above=-999 required=5 tests=[BAYES_50=0.8,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001,  RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id n5T0rU9LSO6U; Sun, 28 May 2017 14:54:01 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20C3A12941C; Sun, 28 May 2017 14:54:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=JZu79AjDKRt5ivCiLe50xDssK8aYKqOqqm7d7yKkiqc=;  b=kGhEkipZIaupZCaU7F3hJrepbngQLhNGsxD5ie0ajyr15wUrzyOT8kbhpEF2QgLvioQbJyrMAEJRMTm44Cbukov4Ib7YbdcgzLzZvCkgAQiSFKxsVEf8zGxxySgaigh4HhVuNP/v8Dsbr74e0zbC+WziuTBng4t48GUA81UJ8oHMlMU452Ti89L8ART4M+kwHuK+ZyKvn0amK0lqra1CZDR2QCo2m1KEA5UA7MmUqYb50KIkA5eO6UHggKoIvQ0VD/tJW4KEce8Vji22beC3x/U63Z9MeqkLSDkk7F2X3SK0Hunz8jx3xEye1KkDiJJpAmmGbK3Rv6qItXQH70DO/w==;
Received: from a91-155-69-187.elisa-laajakaista.fi ([91.155.69.187] helo=poro.lan) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dF68K-0007Q0-PD; Mon, 29 May 2017 00:53:56 +0300
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <87d1ask7d9.wl-jch@irif.fr>
Date: Mon, 29 May 2017 00:53:56 +0300
Cc: homenet-babel-sec@ietf.org, babel@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 91.155.69.187
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/ei0x7to3p_jpnVjiDD2sE8ETf74>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 21:54:03 -0000

On 29 May 2017, at 0.18, Juliusz Chroboczek <jch@irif.fr> wrote:
> There are two facets to Homenet security: HNCP and Babel.  We, at =
Babel
> towers, are planning to implement Stenberg-style security for Babel =
during
> the month of July (earlier is not possible due to my prospective =
interns
> having to sit their exams).  When we're done, we can compare this =
aproach
> to the existing HMAC security, and see which of the two approaches is =
more
> suitable for Homenet.
>=20
> For the Babel work to be useful for Homenet security, HNCP needs to be
> extended with two features:
>=20
>  - the ability to signal other HNCP nodes that a given link requires
>    authentication and/or encryption, and to securely signal any =
private
>    keys;

HNCP supports negotiating network-wide shared keys for arbitrary =
services (such as RPs). If my hncp_proto.h has valid values, TLV to look =
for is number 42, ironically enough.

hnetd the implementation does not implement this yet, as I am not =
convinced it is a good idea. I welcome merge requests though if someone =
wants to implement it. (it is one of the few missing parts of the spec =
from hnetd)

>  - the ability to protect HNCP traffic over an untrusted link.

hnetd supports this and it has even been tested at some point in distant =
past. No idea of current status of the code, as I nowadays use the =
Python HNCP implementation and not the C one.=20

> Pierre has mentioned that HNCP already supports all or most of that, =
but
> somebody needs to write down the relevant protocol bits and check =
whether
> everything is implemented.
>=20
> I'd much prefer that this work be done before we start extending =
Babel,
> since having the HNCP bits ready would help us ensure that we're =
meeting
> all of the Homenet requirements.

I am not holding my breath on my motivation to add support for the =
shared keys in HNCP to hnetd, as I still believe in security-by-l2-zones =
design that I am running in my home and not l3+ security for each =
protocol. However, I welcome merge requests on github :) (or very hefty =
bribe, smirk, but I am working on some other tinfoil hat stuff at the =
moment.)

Cheers,

-Markus


From nobody Sun May 28 15:28:26 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10283128AB0; Sun, 28 May 2017 15:28:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Lp2wM49InZoF; Sun, 28 May 2017 15:28:19 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2A58126BFD; Sun, 28 May 2017 15:28:18 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4SMSGQm003235 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 29 May 2017 00:28:16 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4SMSG78015355; Mon, 29 May 2017 00:28:16 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 6478CEB204; Mon, 29 May 2017 00:28:16 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id H45yQa0Hz9Jt; Mon, 29 May 2017 00:28:15 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 7795AEB201; Mon, 29 May 2017 00:28:13 +0200 (CEST)
Date: Mon, 29 May 2017 00:28:13 +0200
Message-ID: <878tlgk45e.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Markus Stenberg <markus.stenberg@iki.fi>
Cc: homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Mon, 29 May 2017 00:28:17 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Mon, 29 May 2017 00:28:16 +0200 (CEST)
X-Miltered: at korolev with ID 592B4F00.002 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592B4F00.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592B4F00.002 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592B4F00.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592B4F00.002 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592B4F00.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/Bs2if2br5lJDHDpYj6yLGgiRucA>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 22:28:20 -0000

> I am not holding my breath on my motivation to add support for the
> shared keys in HNCP to hnetd, as I still believe in security-by-l2-zones
> design that I am running in my home and not l3+ security for each protocol.

As you know, you've convinced me.

> (or very hefty bribe,

Please share with your friends.

-- Juliusz


From nobody Sun May 28 16:13:15 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1C00E126BF7 for <babel@ietfa.amsl.com>; Sun, 28 May 2017 16:13:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IoicDsOr3BbA for <babel@ietfa.amsl.com>; Sun, 28 May 2017 16:13:05 -0700 (PDT)
Received: from mail-qt0-x22d.google.com (mail-qt0-x22d.google.com [IPv6:2607:f8b0:400d:c0d::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C89E12949E for <babel@ietf.org>; Sun, 28 May 2017 16:13:05 -0700 (PDT)
Received: by mail-qt0-x22d.google.com with SMTP id c13so39647571qtc.1 for <babel@ietf.org>; Sun, 28 May 2017 16:13:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=OBIzOo4BMy993W8I0kRRuLRLvApQBaa70eU3OIHFhUc=; b=1VCvIpjTdvn9YrfSozdcFHBsNOG3+lH+3LXjy87DqeLruZUBU4aFKH42pQBTP7i7gQ +wgCcowz+S0Bty0yXwc/Vf0iD7iy7huATWmuGYr8hdI6zpi9pjclo7Pj4bXupKdYOdPa 5S0eekmDsHIaG2aqykuPDNSOBoplIA2qANa5/Hi8XGiYGd6xwBoni3zXtqWmtdKarQVU yEvI37MOzrgpdThafdRoFOLNnATp23zF9OFSLf3bzwE/YmZ4s/obqUPBN9saPEZozXQL cNtBXZK+rcSAQLLVNhBY0RVO+G5Bq7JLq0F2MdMeKeH9HbO95uqQm9M5sfq1offW/5d1 xgWw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=OBIzOo4BMy993W8I0kRRuLRLvApQBaa70eU3OIHFhUc=; b=XYiVItBMZlRslY/giUexqasry+4w7dTLOhk6reGithQxTgROXfBtIw23zSIucMLAhL 3q7TvQn2w4mi4qVpYZnGQyP5bjQs6fs8B4JVNI0RsxHn2WnXkg9wMQ1fnfaR77kPXgFr O9gwMt2uUrth/K7g7ISI9nW0zeZeYTcrpWSGaGjjuqn31XLuMO2ty9ljyE1GXjL59w1q mhuSHpd3zOqbhKsOV4u8C9Ju+Pi5IlmYy9oj0JgYrMVXm75nYBVnDqi2Q5Rud06V9NmX dELcDOKh16P0dQk8aq9A6m36RWNx1CbQ1TG+cZ46tmwPca8NFb/shTpA3IZ1BnvFp1q0 phyw==
X-Gm-Message-State: AODbwcCW+CgyWdK7Uk1BEOsnF8A6D9mnQZVwRGQDxHwf560Rj5/UNzI1 YqHpjpDxcq5I56Fa
X-Received: by 10.237.58.227 with SMTP id o90mr15005357qte.134.1496013184392;  Sun, 28 May 2017 16:13:04 -0700 (PDT)
Received: from [10.0.20.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id n14sm5316367qtf.33.2017.05.28.16.13.02 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 28 May 2017 16:13:03 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <EFD2D40B-0FE8-4948-9337-0E26A13F110C@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_403570D2-0700-430A-AA3E-0BE3F77F6626"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Sun, 28 May 2017 19:13:01 -0400
In-Reply-To: <87d1ask7d9.wl-jch@irif.fr>
Cc: homenet-babel-sec@ietf.org, babel@ietf.org
To: Juliusz Chroboczek <jch@irif.fr>
References: <87d1ask7d9.wl-jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/4R8YDd9cn8lLIaI4q8D_oWwjG-8>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 23:13:08 -0000

--Apple-Mail=_403570D2-0700-430A-AA3E-0BE3F77F6626
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 28, 2017, at 5:18 PM, Juliusz Chroboczek <jch@irif.fr> wrote:
> I'm leaving for a short holiday tomorrow, so please don't worry if I'm =
not
> very responsive during the next week.  I've got exams the week after, =
so
> please don't worry if I'm not very responsive the week after that.  =
Pleae
> expect me to be my usual annoyingly chatty and opinionated self in two
> weeks' time.

Deadlines are good.   I will do my best (and might bug Markus, if he's =
willing).


--Apple-Mail=_403570D2-0700-430A-AA3E-0BE3F77F6626
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 28, 2017, at 5:18 PM, Juliusz Chroboczek &lt;<a =
href=3D"mailto:jch@irif.fr" class=3D"">jch@irif.fr</a>&gt; =
wrote:<div><blockquote type=3D"cite" class=3D""><div class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">I'm leaving for a =
short holiday tomorrow, so please don't worry if I'm not</span><br =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Menlo-Regular; font-size: 18px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">very responsive during the next week. &nbsp;I've =
got exams the week after, so</span><br style=3D"font-family: =
Menlo-Regular; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">please don't worry =
if I'm not very responsive the week after that. &nbsp;Pleae</span><br =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Menlo-Regular; font-size: 18px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">expect me to be my usual annoyingly chatty and =
opinionated self in two</span><br style=3D"font-family: Menlo-Regular; =
font-size: 18px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; =
float: none; display: inline !important;" class=3D"">weeks' =
time.</span></div></blockquote></div><br class=3D""><div =
class=3D"">Deadlines are good. &nbsp; I will do my best (and might bug =
Markus, if he's willing).</div><div class=3D""><br =
class=3D""></div></body></html>=

--Apple-Mail=_403570D2-0700-430A-AA3E-0BE3F77F6626--


From nobody Sun May 28 16:14:55 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C45D12949B for <babel@ietfa.amsl.com>; Sun, 28 May 2017 16:14:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ekNebyg7lt98 for <babel@ietfa.amsl.com>; Sun, 28 May 2017 16:14:52 -0700 (PDT)
Received: from mail-qt0-x22d.google.com (mail-qt0-x22d.google.com [IPv6:2607:f8b0:400d:c0d::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 24937126BF7 for <babel@ietf.org>; Sun, 28 May 2017 16:14:52 -0700 (PDT)
Received: by mail-qt0-x22d.google.com with SMTP id f55so39649658qta.3 for <babel@ietf.org>; Sun, 28 May 2017 16:14:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=vmdzlcbPTJHNK3oXNHLPbmNvlO8ZAITB/7eUbx6MrlU=; b=mPsrz3lvX7X22/CIHzN6y7qoKVvbijlh18iDXVjvGX/cj9BL+J7anyxceAM2K9mVqs b964FScx3o5KhIwWCfBAMlHLFQNBu0fqt9JUuYBlQhvU2oF45wqNQF59II+ZZaRUiVrb yiSVmdpih24FbhG44kfAZJtJ7YLMdFNjiiVhoX4rSRPIfSKUdXZlrvJEhS/mK6D51p3Q MDllSLwI3zXbbd562BIEuCRmb6VDo30ioLQwRRhs+pWfQMgAFDQia9Z1bPqYEBJ46FJ+ Y0cnVVy9hmtriuKG75spowNthGCHvgidHNShX8WyVCcf+e8mnXjRVWdEKMrO5S8gGxZq ZdYA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=vmdzlcbPTJHNK3oXNHLPbmNvlO8ZAITB/7eUbx6MrlU=; b=csLHz/NzCpObbHOvZXlD2G4J1y/FLuSjHZWlc0OXykgD+WbQVdnUFQDK5YCYNKp2cl EP6Wk5R6t9Guogooi7cr1oKgt+Man6GRpTiVE5Pcp3ztuSzBIqI/Fl6CkDNqt53HLaXt NfsAhcZ2eJZ0spRcHvFOJOTzO4/HL/noxgpUoWobLqXknMRGoruGjO80Ga0CM+Tmw2U9 hqLDqU/W1PS2dZOVZWrWZq+kDPkUfa/E7Cpy7la5jOE2jlaEHbJtyavsVIAZ274j4ZQ5 xfscVM7z18yl7DFphUYHU9nBuJE6l5vLviONUsT2xT5yQMh5TSgzxnEfvo+9TC5wse2/ mdHQ==
X-Gm-Message-State: AODbwcBMW82dLUudyP/YNd5WMIa5PsK/Z3UmnnRFwY3k273B1r90v3tT 1TsU/G6dBeMezLbW
X-Received: by 10.200.55.29 with SMTP id o29mr14652555qtb.120.1496013291349; Sun, 28 May 2017 16:14:51 -0700 (PDT)
Received: from [10.0.20.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id n3sm4319058qkd.21.2017.05.28.16.14.50 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 28 May 2017 16:14:50 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_E69714F6-D9F1-41EF-AC34-9EEF938646DC"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Sun, 28 May 2017 19:14:48 -0400
In-Reply-To: <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi>
Cc: Juliusz Chroboczek <jch@irif.fr>, homenet-babel-sec@ietf.org, babel@ietf.org
To: Markus Stenberg <markus.stenberg@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/lOAGQzP4BhnIM9hqlQveWquq-kI>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 May 2017 23:14:53 -0000

--Apple-Mail=_E69714F6-D9F1-41EF-AC34-9EEF938646DC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 28, 2017, at 5:53 PM, Markus Stenberg <markus.stenberg@iki.fi> =
wrote:
> HNCP supports negotiating network-wide shared keys for arbitrary =
services (such as RPs). If my hncp_proto.h has valid values, TLV to look =
for is number 42, ironically enough.
>=20
> hnetd the implementation does not implement this yet, as I am not =
convinced it is a good idea. I welcome merge requests though if someone =
wants to implement it. (it is one of the few missing parts of the spec =
from hnetd)

The idea is to have key pairs, not network wide keys (this is why =
Juiliusz needs unicast hellos in Babel).   Network wide keys are =
useless.


--Apple-Mail=_E69714F6-D9F1-41EF-AC34-9EEF938646DC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 28, 2017, at 5:53 PM, Markus Stenberg &lt;<a =
href=3D"mailto:markus.stenberg@iki.fi" =
class=3D"">markus.stenberg@iki.fi</a>&gt; wrote:<br =
class=3D""><div><blockquote type=3D"cite" class=3D""><span =
style=3D"font-family: Menlo-Regular;" class=3D"">HNCP supports =
negotiating network-wide shared keys for arbitrary services (such as =
RPs). If my hncp_proto.h has valid values, TLV to look for is number 42, =
ironically enough.</span><br class=3D""><div class=3D""><br =
style=3D"font-family: Menlo-Regular; font-size: 18px; font-style: =
normal; font-variant-caps: normal; font-weight: normal; letter-spacing: =
normal; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Menlo-Regular; font-size: 18px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">hnetd the implementation does not implement this =
yet, as I am not convinced it is a good idea. I welcome merge requests =
though if someone wants to implement it. (it is one of the few missing =
parts of the spec from hnetd)</span></div></blockquote></div><br =
class=3D""><div class=3D"">The idea is to have key pairs, not network =
wide keys (this is why Juiliusz needs unicast hellos in Babel). &nbsp; =
Network wide keys are useless.</div><div class=3D""><br =
class=3D""></div></body></html>=

--Apple-Mail=_E69714F6-D9F1-41EF-AC34-9EEF938646DC--


From nobody Sun May 28 18:19:34 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA55E1294CC; Sun, 28 May 2017 18:19:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F6kWjhfPrMKJ; Sun, 28 May 2017 18:19:27 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE6841294C9; Sun, 28 May 2017 18:19:26 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4T1JOti017858 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 29 May 2017 03:19:24 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4T1JKWq028251; Mon, 29 May 2017 03:19:23 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 00ACEEB201; Mon, 29 May 2017 03:19:19 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id VmagnQIRK0fI; Mon, 29 May 2017 03:19:19 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 89355EB204; Mon, 29 May 2017 03:19:12 +0200 (CEST)
Date: Mon, 29 May 2017 03:19:12 +0200
Message-ID: <87shjoihnz.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Ted Lemon <mellon@fugue.com>
Cc: Markus Stenberg <markus.stenberg@iki.fi>, homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Mon, 29 May 2017 03:19:24 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Mon, 29 May 2017 03:19:24 +0200 (CEST)
X-Miltered: at korolev with ID 592B771C.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592B7718.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592B771C.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592B7718.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592B771C.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592B7718.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/unLWYZUseb3vQsp-D1F0So9scZE>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 01:19:29 -0000

> The idea is to have key pairs, not network wide keys

If it can be done without too much complexity, sure.

> (this is why Juiliusz needs unicast hellos in Babel).

I was under the (perhaps mistaken) impression that asymmetric signing can
be done just as well over multicast.  The reasons people want unicast
hellos are multiple:

  - leverage DTLS (Stenberg-style) or IKE (Schinazi-style);
  - run Babel over NBMA (Cullen-style);
  - avoid multicast noise (Taht-Hřiland-style).

Even for Stenberg-Schinazi security, it's not obvious to me why we need
unicast Hellos -- it's only Updates that really need to be protected, if
an attacker manages to fake a Hello he'll only be able to disrupt the
link-quality estimation algorithm (which is only a DoS vector).

And Margaret is doing NBMA in RFC 6126 just fine, by sending unicast
Hellos simultaneously to all neighbours and hence avoiding seqno
desyncrhonisation.

In short -- if we don't get unicast Hellos into 6126bis, I'll be happy
enough.  If we do, and they're done well, I'll be happier.

> Network wide keys are useless.

Depends on the size of the network, I guess.

-- Juliusz


From nobody Sun May 28 18:27:22 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 356F31294D2 for <babel@ietfa.amsl.com>; Sun, 28 May 2017 18:27:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UYVwChQZookT for <babel@ietfa.amsl.com>; Sun, 28 May 2017 18:27:14 -0700 (PDT)
Received: from mail-qt0-x22e.google.com (mail-qt0-x22e.google.com [IPv6:2607:f8b0:400d:c0d::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D11EB1294D8 for <babel@ietf.org>; Sun, 28 May 2017 18:27:13 -0700 (PDT)
Received: by mail-qt0-x22e.google.com with SMTP id v27so40648124qtg.2 for <babel@ietf.org>; Sun, 28 May 2017 18:27:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=M3Tko8p1VpsQgx/+0FEAj9Npjrey4uFYPc4W4zbp190=; b=yJyI27pXM3dKtbfcexju69G4GuICSNdrgHMHVs/uZ4K46Zi60y1bdC8gkLIa5/nthS DHlWHsygQ3zAl8SC5cyVXnhNr2V/1JwF9kgnefF0M9OyQqQxwNQcwQOPfycdhZiNCY8/ Vf7zZjthiHOLdsG1GQc2l7l9L6sOokpMpWRBsH2YmyOcMPi1gZLomPo1KlkWrPSNdeBM EAWm67ehH5c/g+sMwsLWPVesFg175JQU3Oqs0JAhGMZvBkrUxGmdovs6mY60KTZDFrMj 9Br4ti2Q/hMQSHibbQXNIo8C8+HpA4dKSfBjcPSZWkapf8pDMi3sRG7i1zNM7TN7Nn7L 8joQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=M3Tko8p1VpsQgx/+0FEAj9Npjrey4uFYPc4W4zbp190=; b=ZsFJTSIEu73SzhzWpbJb1h+717JQ+Tc74Z0fVNbrRPVELRgKwsRXYmgJQjOJfFPcgE zmMTcUbwdpcw3Xm+JJbVcMfACvwp5qv5mbgRTA2kImazS78S5QSkSFVH2l+wA5DiLQaZ dr1KPUJYrR3K5+cOnOBB0obO4fcZdRTE3S89TPgRQRqyOZ7239jd1ZGaozoGieDgYmsg Eza+JwcGJ3csJI973DROBmlYfipz+K048icVfyZoTKoAI0MTXbaui5ox3YTV0mPQqKbW HA3VBN9HnXhRm76EgvOImEeJbwt+e7a3b5td1UX2UNGyVIvrb9SEEidP3hUinW1kCJok wkSA==
X-Gm-Message-State: AODbwcA4vOEnVx5DzFpRynfrHqL9uu3vMlaOUDsPpnMh1iLTImNvdZ/D IpWuul+AXHyVmTviIQCDDw==
X-Received: by 10.200.55.145 with SMTP id d17mr16921711qtc.57.1496021232963; Sun, 28 May 2017 18:27:12 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.nh.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id n35sm5436997qtc.55.2017.05.28.18.27.11 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 28 May 2017 18:27:12 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Ted Lemon <mellon@fugue.com>
In-Reply-To: <87shjoihnz.wl-jch@irif.fr>
Date: Sun, 28 May 2017 21:27:09 -0400
Cc: Markus Stenberg <markus.stenberg@iki.fi>, homenet-babel-sec@ietf.org, babel@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/3EenJj44pX2SKupp72-gfTO_Lig>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 01:27:16 -0000

> I was under the (perhaps mistaken) impression that asymmetric signing =
can
> be done just as well over multicast.  The reasons people want unicast
> hellos are multiple:

We concluded that asymmetric signing was too expensive, IIRC.

> Even for Stenberg-Schinazi security, it's not obvious to me why we =
need
> unicast Hellos -- it's only Updates that really need to be protected, =
if
> an attacker manages to fake a Hello he'll only be able to disrupt the
> link-quality estimation algorithm (which is only a DoS vector).

I will rely on your expertise here.   However, if the point is to =
identify the attacker, then being able to identify the attacker in a DoS =
attack is just as important.

>> Network wide keys are useless.
>=20
> Depends on the size of the network, I guess.

Yes.   For networks with only two hosts, network-wide keys are =
adequate...

;)


From nobody Mon May 29 01:18:12 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEC2412704B; Mon, 29 May 2017 01:18:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.702
X-Spam-Level: 
X-Spam-Status: No, score=-0.702 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AjstkCx0xF6I; Mon, 29 May 2017 01:18:08 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA2D9120454; Mon, 29 May 2017 01:18:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=F5KtVRYdBV37G1Enj58E8+Ee98994Na0nyJaPuUHBeM=;  b=E9ZtDEAxUcTZKKVMsybRJLRh3kB/L3oWUZQIrEVE7CevD4EfrLTWrHYcAzWCcYkQbgGWd0SK1HjKn9DN6iV1Ue29NhxszQUvgrS1uwo5kTSJm3Rhn1VDIz2SzaruDRoskKZFLr0/ruSQ5mgl76SRSxhiy8EVHefFUcjLMe0lWFpKQEJXPP0GJadclm6pnOWs46SKLZZHRCS1+Y21QTZVBadtfml1BCQ68AvPN6K/J08Tqy6OHtEHq+cs2xdIUIvfExE12qoNWhpgqj0L2s5af1ShqoijB9tvCSUjKJI9eJQ1jhuqcvw4YBxoewHSPh7+7EhF6//HbqwPSVEi7xNwOQ==;
Received: from hel-gw.ssh.com ([195.20.116.1] helo=[192.168.200.50]) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dFEsy-00071Y-HG; Mon, 29 May 2017 10:14:40 +0300
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com>
Date: Mon, 29 May 2017 10:14:42 +0300
Cc: Juliusz Chroboczek <jch@irif.fr>, homenet-babel-sec@ietf.org, babel@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr> <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com>
To: Ted Lemon <mellon@fugue.com>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 195.20.116.1
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/oSIn92PiUhKlZJZZN31_J2pZgtE>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 08:18:11 -0000

>>> Network wide keys are useless.
>>=20
>> Depends on the size of the network, I guess.
>=20
> Yes.   For networks with only two hosts, network-wide keys are =
adequate...

My _home_ network has plenty of network-wide shared keys (e.g. SSID =
PSKs) and I do not consider them useless;  while they are low barrier to =
entry, I am not aware of any good alternatives that most of my devices =
would support (and SSID per device is not realistic).

Cheers,

-Markus=


From nobody Mon May 29 02:15:14 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4A7D01200C1; Mon, 29 May 2017 02:15:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GhOkXYIf1fkJ; Mon, 29 May 2017 02:15:05 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5D6F0126557; Mon, 29 May 2017 02:15:04 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4T9F2RF002215; Mon, 29 May 2017 11:15:02 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 5BEEAEB2C1; Mon, 29 May 2017 11:15:02 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id ckJfL7l8F8_Q; Mon, 29 May 2017 11:15:01 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 22BB6EB2CD; Mon, 29 May 2017 11:15:00 +0200 (CEST)
Date: Mon, 29 May 2017 11:15:00 +0200
Message-ID: <877f10owh7.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Markus Stenberg <markus.stenberg@iki.fi>
Cc: Ted Lemon <mellon@fugue.com>, homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr> <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com> <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Mon, 29 May 2017 11:15:02 +0200 (CEST)
X-Miltered: at korolev with ID 592BE696.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592BE696.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592BE696.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/RoP3nzUG9CU9-2SOi7SmEOt6iZk>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 09:15:07 -0000

>>>> Network wide keys are useless.

>>> Depends on the size of the network, I guess.

>> Yes.   For networks with only two hosts, network-wide keys are adequate...

> My _home_ network has plenty of network-wide shared keys (e.g. SSID
> PSKs) and I do not consider them useless; while they are low barrier to
> entry, I am not aware of any good alternatives that most of my devices
> would support 

Yes, I too am somewhat puzzled by Ted's very strong stance about avoding
shared keys, and cannot but wonder if it reflects WG consensus.  However,
it is my (perhaps mistaken) understanding that Stenberg-Schinazi security
gives us asymmetric keying basically for free, as far as additions to the
Babel protocol are concerned, so I suggest waiting for Ted's prototype
before deciding whether the added complexity is acceptable.

> (and SSID per device is not realistic).

Now don't you tempt me.

(Increase the beaconing interval, hack the wifi firmware to store more
keys, use a master SSID with a cool protocol to securely negotiate keys
with individual devices... and watch bitterly as nobody adopts your
protocol.)

-- Juliusz


From nobody Mon May 29 03:24:26 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B05CC124BFA; Mon, 29 May 2017 03:24:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.602
X-Spam-Level: 
X-Spam-Status: No, score=-0.602 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dAAKUEGxUuiS; Mon, 29 May 2017 03:24:16 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B26451242F7; Mon, 29 May 2017 03:24:16 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496053448; bh=B7IoP9aPHxhOJGL9o7lt2azTSXwZoKOz/XahQH6jODI=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=AaJqJeUAiYGJRm15Gh01K0bZe4nmEOlfzjI0Yevsp5mcr1ToEwVJ8N7ERLhbiXd+5 FT9KzTaVyUC5wMVt2wTCCjvKsWVduXSlb7qE3Z7+c6wa7RmviILgbE4i+N4ubt7INz +0KMGFmiWSo97gOsnhI7XsXfqebHqD/ToZ5SuOrDYS8jVTV1i/LAA7RlGyAdeP0d05 OVfqXVwANRYJ28f2ivQYeY4OAMdjVUmswW16AUoOVukB60xK5AqAMbaeNejAUbfKsL u6i8c6QPiCAmUGn7PivjJknuaDN+36Xxrp43t8ZmFORClmq6WVoRR4ST6iDK0w40Ay wqm6Ai1xGJFiw==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: Markus Stenberg <markus.stenberg@iki.fi>, Ted Lemon <mellon@fugue.com>, homenet-babel-sec@ietf.org, babel@ietf.org
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr> <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com> <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi> <877f10owh7.wl-jch@irif.fr>
Date: Mon, 29 May 2017 12:24:06 +0200
In-Reply-To: <877f10owh7.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Mon, 29 May 2017 11:15:00 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87wp909d15.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/FW9iqqGsg71QrYvvCEnesKSU9-I>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 10:24:19 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

> use a master SSID with a cool protocol to securely negotiate keys with
> individual devices...

Aren't you basically describing "enterprise" (802.1X) WPA here?

> and watch bitterly as nobody adopts your protocol.

Apart from enterprises, universities and anyone who bothers to install
freeradius, you mean? ;)

-Toke


From nobody Mon May 29 04:06:17 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0E41A1242F7 for <babel@ietfa.amsl.com>; Mon, 29 May 2017 04:06:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.103
X-Spam-Level: 
X-Spam-Status: No, score=-0.103 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JCFnUQTaD9rP for <babel@ietfa.amsl.com>; Mon, 29 May 2017 04:06:14 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 756A4120721 for <babel@ietf.org>; Mon, 29 May 2017 04:06:14 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496055966; bh=r385/Y6PTXFrB3HsyQb7aXKrcocLQDnXkEm5g71eCpo=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=b2kVkybgriWd36GcMx7z5TgejMuykQmqOOjSBEylmwQlKfrr/sCyPF6errgAQYYzV eWyeG4Zit75XzNZJK6FmSUVNeJLJrztz2zIFnBdQ+yV67PWAwAFitMYHgK1YcDLLv0 9c45qzLbBWicjsSiW97DIYY/BEmN0GTudN/EkUDas6FBnpghoXalH59ioV/E8XOPk0 KrUZxqMO7blxu/MOAv88ZAhP7HHlsgles0sgYgEcWkg7ElIsmn54OAE8RXyyqoa4YU J4VZ1e4uajdVRRfaE7oYAETKAW3pUmIxPu4UqT7a245+Ps1vqTyFF4uH0WXwhxrBpi B705UkHHlRpFQ==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87bmqck6sp.wl-jch@irif.fr>
Date: Mon, 29 May 2017 13:06:04 +0200
In-Reply-To: <87bmqck6sp.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Sun, 28 May 2017 23:31:02 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <874lw3apnn.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/WiyVln2wm8Iz62GlUYTf3KpMoSY>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 11:06:16 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

> As mentioned in a previous mail, I'll be only marginally available
> until 9 June, but fairly active after that date. I would be
> overwhelmed with joy if people could write down and implement their
> proposals by that date.

I've recently started hacking on Babel in Bird again. Unicast mode is
high on my list (right after getting dual-stack operation to work), but
no promises I'll get around to it before June 9th...

-Toke


From nobody Mon May 29 05:49:07 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4C51129568 for <babel@ietfa.amsl.com>; Mon, 29 May 2017 05:49:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u38GTkIMmVli for <babel@ietfa.amsl.com>; Mon, 29 May 2017 05:49:02 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2AB8B129418 for <babel@ietf.org>; Mon, 29 May 2017 05:49:02 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4TCn01g017680 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Mon, 29 May 2017 14:49:00 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4TCmxHn024427; Mon, 29 May 2017 14:49:00 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id DCC75EB206; Mon, 29 May 2017 14:48:59 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id C06Rsp6_lfQt; Mon, 29 May 2017 14:48:59 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id E321BEB201; Mon, 29 May 2017 14:48:58 +0200 (CEST)
Date: Mon, 29 May 2017 14:48:58 +0200
Message-ID: <87shjnomkl.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>
Cc: babel@ietf.org
In-Reply-To: <874lw3apnn.fsf@alrua-kau>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Mon, 29 May 2017 14:49:00 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Mon, 29 May 2017 14:49:00 +0200 (CEST)
X-Miltered: at korolev with ID 592C18BC.001 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592C18BB.002 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592C18BC.001 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592C18BB.002 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592C18BC.001 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592C18BB.002 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/XchZfTls5T1hn6bn9EEvMWoxAFU>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 12:49:07 -0000

> (right after getting dual-stack operation to work)

Bird supports that nowadays?  Cool.

-- Juliusz


From nobody Mon May 29 06:01:45 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 327BB12932A for <babel@ietfa.amsl.com>; Mon, 29 May 2017 06:01:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level: 
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 46kfwJBMT55L for <babel@ietfa.amsl.com>; Mon, 29 May 2017 06:01:42 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7D07212778D for <babel@ietf.org>; Mon, 29 May 2017 06:01:42 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496062899; bh=SGfFrjK0O2gtxnAHKZclMm+fekbkgTXEibU/R5wOzQk=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=gVjTTgMMZZbAmTZqY1x05nRZoI093957i3od5f9Fzo4aXFWYVqPcBa/a30oYM/bki D6xaRswWl3eXhqzdPenMoVr3MeaFc0X58HbJpWbpHF1Kvu75huPhIJ0U9n4+FNo3B7 3XE/YsVM0tq6KX1xKXbE/SZT9g2pJHDV0iUw3QOmKSfNaYIfhiYQffl2cWGr6PrXHv Ixoty/zlZfmLQDcsoIz5yeEFoWtppl+HHElHZdbQqj0P1BzBYSRimN3dzVCv9u3G+u frQ/EmUHxe2hskHMnO/2NnPlBGM0uF6NzY+rdbRCOHT3UZ1+9o1XX950W4yUFQKbbR IC4jxKBLvnh3g==
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr>
Date: Mon, 29 May 2017 15:01:37 +0200
In-Reply-To: <87shjnomkl.wl-jch@irif.fr> (Juliusz Chroboczek's message of "Mon, 29 May 2017 14:48:58 +0200")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87vaoj95qm.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/cjXnS1BQmQ2xz1-0rPpeZtm0Vh4>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 13:01:44 -0000

Juliusz Chroboczek <jch@irif.fr> writes:

>> (right after getting dual-stack operation to work)
>
> Bird supports that nowadays?  Cool.

The 2.0-pre releases add support for this to the core (int-new branch of
the Bird git repo). I'm in the process of making the Babel protocol
support it as well...

-Toke


From nobody Mon May 29 06:22:40 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CCC3128854 for <babel@ietfa.amsl.com>; Mon, 29 May 2017 06:22:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B6UVts1imeKi for <babel@ietfa.amsl.com>; Mon, 29 May 2017 06:22:38 -0700 (PDT)
Received: from mail-qk0-x231.google.com (mail-qk0-x231.google.com [IPv6:2607:f8b0:400d:c09::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5F77E129572 for <babel@ietf.org>; Mon, 29 May 2017 06:22:31 -0700 (PDT)
Received: by mail-qk0-x231.google.com with SMTP id u75so47830563qka.3 for <babel@ietf.org>; Mon, 29 May 2017 06:22:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=PXipNigPfuCUjcKt13iGIHrN78IRfBI5AeB2b9WwqJ0=; b=sRNxfOOR8gqKHg6o1f08L2P4qlAQLFEJQrfhtiuvdVAYkae12lS6ZvoFawh2LZFqua ChHEGUmbRxCvVXsoHapj7wjgVTlARAQbus0EKGjaId4YutQtXGm1djw6H4x2hlwdtHvJ IOy2/lHPoNT5nOXoyUW5m1tkpfias5OuNFIzHv33b+n6T6QNZG843stbSTgJ2voD+c7/ w/h9md3Li0nmZ7/fkptPTpSUXXUvnflaDjBy6iE0lI9VZW0x6/dbbhQihoGW/eyuMRSe X7RMl9TJ8vu3P6oe49FVl/cjiPF9/Q1IDFngANd1d8gA43oPhcbJTOGsEpj2xsNryAnW 8Q5Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=PXipNigPfuCUjcKt13iGIHrN78IRfBI5AeB2b9WwqJ0=; b=dY3YB3sifErxUofq28dbAu6bgksZD8gkAibv/7MQ7Oot0m6W2vdbIOsJzlyHOU2fdC 9aCDjfnW+83Nd3FeJdNI/qLOEOqkC0hAS1LPmBvcmOkX1RHHyFBSHL1C+o/xKVtRDRQb bsejhvobGMNfg21qBc+gqjXu6f6NS87jmAgVbP2OU55B6JwqW1vp7hJM1cm0pvvA7+Zc uQLx0lOq3Hzks5PsMlzPYJSRgEaGiDgzcUaRy3AJ3XjyhJypYhDEXsixPF3r0G8+G5n3 4Byh1uRHvIA0DyygJnbnR2Z+HzFB86XykyFU07P6CHIjRaYMmjIdy0HyMLv52Jp8bPVt BT1w==
X-Gm-Message-State: AODbwcCgprlktjFgBvOx4M7/ISkHwZViw5TdSOS5hC1P4e8qG2TapC6q 5o3Em+9wIpQdNgt3
X-Received: by 10.55.161.209 with SMTP id k200mr2510831qke.28.1496064150570; Mon, 29 May 2017 06:22:30 -0700 (PDT)
Received: from [10.0.30.228] (c-73-167-64-188.hsd1.ma.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id a126sm6291752qkc.15.2017.05.29.06.22.26 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 29 May 2017 06:22:27 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <EE254C72-2E3C-4316-B0A0-9B9133E2F3C6@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_6526D244-397F-4D7F-9643-F38CFCC106FA"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Mon, 29 May 2017 09:22:24 -0400
In-Reply-To: <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi>
Cc: Juliusz Chroboczek <jch@irif.fr>, homenet-babel-sec@ietf.org, babel@ietf.org
To: Markus Stenberg <markus.stenberg@iki.fi>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr> <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com> <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/YMkn_6I8mbgKEFOyC3-TOE5rvKU>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 13:22:39 -0000

--Apple-Mail=_6526D244-397F-4D7F-9643-F38CFCC106FA
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 29, 2017, at 3:14 AM, Markus Stenberg <markus.stenberg@iki.fi> =
wrote:
> My _home_ network has plenty of network-wide shared keys (e.g. SSID =
PSKs) and I do not consider them useless; while they are low barrier to =
entry, I am not aware of any good alternatives that most of my devices =
would support (and SSID per device is not realistic).

Shared pre-shared-keys are useful if the need for trust is minimal.   We =
use them all the time at IETF, and my home network uses WPA2/PSK, not =
WPA2/enterprise.   But the point is that there is no expectation of =
privacy or authenticity in this case.

In the case we are talking about, a shared key doesn't work because if =
any device on the network is pwned, it can masquerade as any other =
device to escape detection.   You or I could do a fault isolation =
process to figure out which device has been pwned, but we can't expect =
homenet users to be able to do that.


--Apple-Mail=_6526D244-397F-4D7F-9643-F38CFCC106FA
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 29, 2017, at 3:14 AM, Markus Stenberg &lt;<a =
href=3D"mailto:markus.stenberg@iki.fi" =
class=3D"">markus.stenberg@iki.fi</a>&gt; wrote:<div><blockquote =
type=3D"cite" class=3D""><div class=3D""><span style=3D"font-family: =
Menlo-Regular; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">My _home_ network has plenty of =
network-wide shared keys (e.g. SSID PSKs) and I do not consider them =
useless; while they are low barrier to entry, I am not aware of any good =
alternatives that most of my devices would support (and SSID per device =
is not realistic).</span></div></blockquote></div><br class=3D""><div =
class=3D"">Shared pre-shared-keys are useful if the need for trust is =
minimal. &nbsp; We use them all the time at IETF, and my home network =
uses WPA2/PSK, not WPA2/enterprise. &nbsp; But the point is that there =
is no expectation of privacy or authenticity in this case.</div><div =
class=3D""><br class=3D""></div><div class=3D"">In the case we are =
talking about, a shared key doesn't work because if any device on the =
network is pwned, it can masquerade as any other device to escape =
detection. &nbsp; You or I could do a fault isolation process to figure =
out which device has been pwned, but we can't expect homenet users to be =
able to do that.</div><div class=3D""><br class=3D""></div></body></html>=

--Apple-Mail=_6526D244-397F-4D7F-9643-F38CFCC106FA--


From nobody Mon May 29 07:02:55 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 05A5F1293E3; Mon, 29 May 2017 07:02:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v8oHNIjRsBoz; Mon, 29 May 2017 07:02:44 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE2C91201FA; Mon, 29 May 2017 07:02:43 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4TE2fYE027743; Mon, 29 May 2017 16:02:41 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 4CD47EB2C1; Mon, 29 May 2017 16:02:41 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id sSfsY30bf57y; Mon, 29 May 2017 16:02:40 +0200 (CEST)
Received: from trurl.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id C7BDBEB2CD; Mon, 29 May 2017 16:02:37 +0200 (CEST)
Date: Mon, 29 May 2017 16:02:37 +0200
Message-ID: <87inkjoj5u.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Ted Lemon <mellon@fugue.com>
Cc: Markus Stenberg <markus.stenberg@iki.fi>, homenet-babel-sec@ietf.org, babel@ietf.org
In-Reply-To: <EE254C72-2E3C-4316-B0A0-9B9133E2F3C6@fugue.com>
References: <87d1ask7d9.wl-jch@irif.fr> <B67775FF-31CB-42F6-ABDF-BD47BEA1DB56@iki.fi> <1F8BA8E0-7518-4288-B679-749906B1B19F@fugue.com> <87shjoihnz.wl-jch@irif.fr> <416AD4BB-7A24-41D4-9C91-96B23BE65EF3@fugue.com> <EC469E5B-4E9A-4A6F-818F-EA52E654DE4C@iki.fi> <EE254C72-2E3C-4316-B0A0-9B9133E2F3C6@fugue.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Mon, 29 May 2017 16:02:41 +0200 (CEST)
X-Miltered: at korolev with ID 592C2A01.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592C2A01.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592C2A01.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/KTuIUZn0uUw3jHZZQdyKeU960e0>
Subject: Re: [babel] What's up with HNCP security?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 14:02:45 -0000

> In the case we are talking about, a shared key doesn't work because if any
> device on the network is pwned, it can masquerade as any other device to
> escape detection. You or I could do a fault isolation process to figure out
> which device has been pwned, but we can't expect homenet users to be able to
> do that.

I think we're all well aware of the advantages of per-device keys.  I think
we're also well aware that there are tradeoffs between functionality and
complexity, and that sometimes it is worth giving up on features in order
to keep complexity at a manageable level.  (Radius, sheesh.)

I think we'd need a prototype in order to make an informed judgement.

-- Juliusz


From nobody Mon May 29 10:09:59 2017
Return-Path: <tonysietf@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B9CB71241FC for <babel@ietfa.amsl.com>; Mon, 29 May 2017 10:09:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.299
X-Spam-Level: 
X-Spam-Status: No, score=-1.299 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GHjSYc05_dKj for <babel@ietfa.amsl.com>; Mon, 29 May 2017 10:09:56 -0700 (PDT)
Received: from mail-wm0-x22b.google.com (mail-wm0-x22b.google.com [IPv6:2a00:1450:400c:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7DEEB1200C5 for <babel@ietf.org>; Mon, 29 May 2017 10:09:56 -0700 (PDT)
Received: by mail-wm0-x22b.google.com with SMTP id 7so62990872wmo.1 for <babel@ietf.org>; Mon, 29 May 2017 10:09:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to;  bh=A7Uj+4d0yzLU3k66DSahXiVN8IwX0ELujaSwuhOWMD8=; b=qWLz05D+bz8ejO9ra1MZCmXIvQmF+OtSV9C9tQdpWQa+SUs6OpgdfhE+kTBFL8MXrK Mu9A9YgdP0HG3aFHTvHy07iFfFB2X9pUuuXNHtfs+uM9+wg/HNlFeiTDcj0iwxAD8aai uy9aAwJHSKogz0JLAGIcc6gh9wRsoRXY4Fnq/70ePwlggCO7pwwDMvL7RvCwlf33hM2O zISflluX2tEigQ927XF79TDHvTUTdR+5OXNUyZiraIyP0FaQdvDxugtXy5mgGh+S6pRW UdQcqCJ8WmLLPZ6VDmPNwxJKdE54ODnel1ObjJ/FjCZU0w8/60ifN8frEifsomnaVooE fbrA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=A7Uj+4d0yzLU3k66DSahXiVN8IwX0ELujaSwuhOWMD8=; b=MdIInQRv0s+M1Gxou71xskp43MScdNzh+5SDCBV73vsZMUxOm1lj5ifD1HYO6Z6TzE QpM+KaIrnXxZa5rN0XcukwmUv+BSwc1XlWOkPly1j8N7DtYPvo5C2lq9EiL1IvLHhTP1 tDdUV92mQ0b9G7DwvLc47ik6ujh4QTYOr4C5BXbfuhee/BkJZs5BnKzl0aJCnCG5OZg8 bkfRPx8ACyV0abfaETPp8U6Y2epYCk+sw6v5OW1y85cYh8iAFMpRNC1pu9ILVnvZclCl WdM1wvuGoEcpOZ547cEXRsWkyHcBZsDqW8iKwReSIXiSyJGOtzPpN2qU64bxl2UZ8s+z zTBA==
X-Gm-Message-State: AODbwcD26WA70lN9bPoDEUaxBpwmbhSyi22LdchvN2aASut+SK6OXOOd +IYg0R7R2wuvjy3swcTTikvkCZohG3BH
X-Received: by 10.80.151.131 with SMTP id e3mr13879797edb.61.1496077794836; Mon, 29 May 2017 10:09:54 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.80.159.37 with HTTP; Mon, 29 May 2017 10:09:14 -0700 (PDT)
In-Reply-To: <mailman.2034.1496053459.4563.babel@ietf.org>
References: <mailman.2034.1496053459.4563.babel@ietf.org>
From: Tony Przygienda <tonysietf@gmail.com>
Date: Mon, 29 May 2017 10:09:14 -0700
Message-ID: <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com>
To: Babel at IETF <babel@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c0e481c84858f0550acc1b4"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/XREK3Bv9stfYn3f61KA-bobOQ-E>
Subject: Re: [babel] babel Digest, Vol 21, Issue 9
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 17:09:58 -0000

--94eb2c0e481c84858f0550acc1b4
Content-Type: text/plain; charset="UTF-8"

>
> > Network wide keys are useless.
>
> Depends on the size of the network, I guess.
>


>From experience, I would dissuade you from pursuing a "network wide-key
approach" to secure a routing protocol (in terms of node associations, i.e.
adjacencies). Routing protocol is the substrate on which very often things
like X.509 run (or Radius or any other key infra "du jour"). In case you
loose the protocol nodes due to bugs, unexpected behavior, key expiration
and so on you loose the infra and with that you may never recover the
routing since key infra cannot reach the nodes anymore ... Key
roll-over/withdrawal/repudiation are especially tricky.

 Having a distro of keys across the network to provide "path-security",
i.e. I do not only trust my neighbor but trust the whole chain an update
passed is doable but too expensive to bother for routing (well, BGP will
get there eventually I guess) and benefits from a key infra obviously or
rather cannot be run without some kind of key infra.

my 2c

--- tony

--94eb2c0e481c84858f0550acc1b4
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><div class=3D"gmail_quote">=
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<br>
&gt; Network wide keys are useless.<br>
<br>
Depends on the size of the network, I guess.<br></blockquote><div><br></div=
><div><br></div><div>From experience, I would dissuade you from pursuing a =
&quot;network wide-key approach&quot; to secure a routing protocol (in term=
s of node associations, i.e. adjacencies). Routing protocol is the substrat=
e on which very often things like X.509 run (or Radius or any other key inf=
ra &quot;du jour&quot;). In case you loose the protocol nodes due to bugs, =
unexpected behavior, key expiration and so on you loose the infra and with =
that you may never recover the routing since key infra cannot reach the nod=
es anymore ... Key roll-over/withdrawal/repudiation are especially tricky.=
=C2=A0</div><div><br></div><div>=C2=A0Having a distro of keys across the ne=
twork to provide &quot;path-security&quot;, i.e. I do not only trust my nei=
ghbor but trust the whole chain an update passed is doable but too expensiv=
e to bother for routing (well, BGP will get there eventually I guess) and b=
enefits from a key infra obviously or rather cannot be run without some kin=
d of key infra.=C2=A0</div><div><br></div><div>my 2c=C2=A0</div><div><br></=
div><div>--- tony=C2=A0</div><div>=C2=A0</div></div>
</div></div>

--94eb2c0e481c84858f0550acc1b4--


From nobody Tue May 30 00:28:27 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D08E128DF3 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 00:28:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.702
X-Spam-Level: 
X-Spam-Status: No, score=-0.702 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nA_8r6lV-MjN for <babel@ietfa.amsl.com>; Tue, 30 May 2017 00:28:24 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 080571200B9 for <babel@ietf.org>; Tue, 30 May 2017 00:28:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=NwxPG0+BdxcbcQpns5OfULEqqrd3gUbm7v6Kjur54S0=;  b=AtB4/FU5LkT02czCw2GwmuIsHchF9N+qVy1kFCqjKzvKMJmmd2mxk+KS1C6dnYqEU4zRrgIhDvnr6XDVCoYRTSRO7XvcoEBkyCzmEaro6XChrfPI8UnMCkkI3C+gV3ryvdiyOEVCotRFjH/gFXyJiOGn3p+xh2zvve/9f63UiObcw4P9wEhOHo+Fdm3GcHSSDlsSlIMxX/TwuKExfKAJx9zDBWllFHtoYHO9LXPWzs+65MLo9whlBStY4ZI+0fhOmiEbtroSIGA8BBgbQnw3l7lyVLAh4kL7tAXED8e6HYVkbZNCvM+hHjlvnHTZhQpD21Z0AodTUYHbX5VbAsisQA==;
Received: from a91-155-69-187.elisa-laajakaista.fi ([91.155.69.187] helo=poro.lan) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dFbZj-0008B7-82; Tue, 30 May 2017 10:28:19 +0300
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com>
Date: Tue, 30 May 2017 10:28:18 +0300
Cc: Babel at IETF <babel@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <369567D5-D1B0-4A6B-9DF5-BE90C5C7F0F9@iki.fi>
References: <mailman.2034.1496053459.4563.babel@ietf.org> <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com>
To: Tony Przygienda <tonysietf@gmail.com>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 91.155.69.187
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/DL8JS4zhtN90t-p32-Lzj-PSlYk>
Subject: Re: [babel] babel Digest, Vol 21, Issue 9
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 07:28:26 -0000

Disclaimer: It has been few years since I thought about this hard :)=20

On 29 May 2017, at 20.09, Tony Przygienda <tonysietf@gmail.com> wrote:
> > Network wide keys are useless.
> Depends on the size of the network, I guess.
>=20
> =46rom experience, I would dissuade you from pursuing a "network =
wide-key approach" to secure a routing protocol (in terms of node =
associations, i.e. adjacencies). Routing protocol is the substrate on =
which very often things like X.509 run (or Radius or any other key infra =
"du jour"). In case you loose the protocol nodes due to bugs, unexpected =
behavior, key expiration and so on you loose the infra and with that you =
may never recover the routing since key infra cannot reach the nodes =
anymore ... Key roll-over/withdrawal/repudiation are especially tricky.=20=

>=20
>  Having a distro of keys across the network to provide =
"path-security", i.e. I do not only trust my neighbor but trust the =
whole chain an update passed is doable but too expensive to bother for =
routing (well, BGP will get there eventually I guess) and benefits from =
a key infra obviously or rather cannot be run without some kind of key =
infra.=20

=46rom experience, if you cannot trace the attacker down (i.o.w. the =
state which spreads from the attacker to the whole network) and =
selectively ignore them, life gets hard anyway.

Looking at the solutions I have seen in the wild, roughly in order of =
decreasing security:

a) shared state with verifiable source (some future BGP version, =
hopefully); as you said, probably unrealistic unfortunately here.

b) per-hop keys but non-verifiable shared state (HNCP with DTLS, X with =
IKE+IPsec)

c) global key and non-verifiable shared state (HNCP provided global keys =
to other protocols, manually keyed IPsec, RFC7298 for Babel)

d) ignore the security.

With [a] you know who inserted the bad state. With [b-d], you do not. =
The difference between [b] and [c] is actually not much. You cannot =
trace down the source of shared state change (except very, very =
painfully hop by hop; you can do that in even in [d]).

Quoting Ted Lemon:

> In the case we are talking about, a shared key doesn=E2=80=99t work =
because if any device on the network is pwned, it can masquerade as any =
other device to escape detection.   You or I could do a fault isolation =
process to figure out which device has been pwned, but we can=E2=80=99t =
expect homenet users to be able to do that.

In a distance vector routing protocol, how do you determine who inserted =
that bad route update, regardless of whether transport keying is per-hop =
or network wide?

Babel solution with [a] is much more than just sticking in DTLS =
transport to unicast packets. Or IKE+IPsec.

You essentially need signed state updates if you want to be able to =
trace down bad apples, and ignore them as needed. Otherwise it becomes =
just a matter of trying to secure transport of the updates to some =
degree, and my preferences are roughly inverse to the order of security =
noted above;

[e] if you can secure your lower layer or trust your nodes
[b#2] IPsec if you cannot (and change protocol so it can be secure =
without multicast)
[c] single (or =E2=80=98few=E2=80=99, to account for rollover like in =
RFC7298) keys with simple authentication/confidentiality
[b#1] if you must stick in DTLS (configuration awkward, not that bad =
implementation complexity)
[a] interesting, but serious performance challenges (I did some numbers =
when thinking about HNCP originally, and it did not scale very well even =
for home network usecase).

Cheers,

-Markus=


From nobody Tue May 30 04:18:53 2017
Return-Path: <jkilpatr@redhat.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E3D41242F7 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 04:18:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.28
X-Spam-Level: *
X-Spam-Status: No, score=1.28 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CVfUbpjLQ3gh for <babel@ietfa.amsl.com>; Tue, 30 May 2017 04:18:51 -0700 (PDT)
Received: from mail-wm0-f52.google.com (mail-wm0-f52.google.com [74.125.82.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC87A120454 for <babel@ietf.org>; Tue, 30 May 2017 04:18:50 -0700 (PDT)
Received: by mail-wm0-f52.google.com with SMTP id d127so93423939wmf.0 for <babel@ietf.org>; Tue, 30 May 2017 04:18:50 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=2mCg0T/z+54LPhCOn8n5S4w0gqBu8PljvH3QCGi0Cdk=; b=nLa1hBx2pkXa3REZn89AZDq/7l3QDmKahOhESZpmOPZFQHwen03jf3g9aye5bQgfDV 2VezWpEuqKUGL171BvEBrJeXCMOPe3M4hMl/hGrbwYvzLewEobnteDrU8JvHvsuK+Yr0 eBU+en1aLUbm+eROUggqzy5r3Ko1m2HvHXCm2dLMYF/8ru1rTYV9V5MaOpskco8Er8w6 M8MKFLE9//9vOOYFQ25SwFFY7z1XJsq2u/QOCLMhCpXseE5hhOqtUw5zMa8xvR5jD4pC J8DYN7LNJgcCTSTHqVC98zIWjnC9nKpKBEMUk/6Kdr77J+ALCq8TobRc/HcvFeNtDCNu g+Pg==
X-Gm-Message-State: AODbwcATsonzNrKtOwum3CoPrBwojRReP0XO+NiP6J80RHH6RawmwoLQ lHTXiGusAFMkI2n+HwkGoxGQegtJPvOi
X-Received: by 10.223.139.199 with SMTP id w7mr15823649wra.92.1496143128747; Tue, 30 May 2017 04:18:48 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.28.149.208 with HTTP; Tue, 30 May 2017 04:18:47 -0700 (PDT)
In-Reply-To: <87vaoj95qm.fsf@alrua-kau>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau>
From: Justin Kilpatrick <jkilpatr@redhat.com>
Date: Tue, 30 May 2017 07:18:47 -0400
Message-ID: <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com>
To: =?UTF-8?B?VG9rZSBIw7hpbGFuZC1Kw7hyZ2Vuc2Vu?= <toke@toke.dk>
Cc: Juliusz Chroboczek <jch@irif.fr>, babel@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/Fn85GzdEarsOHIAMsqpa7Lpc1As>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 11:18:52 -0000

I was actually playing with unicast hellos this weekend. I'm pretty
happy with my implementation at this point so I'll try and package it
up and present it.

Out of curiosity do y'all use a VM based test environment? We've got a
netnamespace based one that's very fast and easy to use, but seems to
have some problems with route insertions.

On Mon, May 29, 2017 at 9:01 AM, Toke H=C3=B8iland-J=C3=B8rgensen <toke@tok=
e.dk> wrote:
> Juliusz Chroboczek <jch@irif.fr> writes:
>
>>> (right after getting dual-stack operation to work)
>>
>> Bird supports that nowadays?  Cool.
>
> The 2.0-pre releases add support for this to the core (int-new branch of
> the Bird git repo). I'm in the process of making the Babel protocol
> support it as well...
>
> -Toke
>
> _______________________________________________
> babel mailing list
> babel@ietf.org
> https://www.ietf.org/mailman/listinfo/babel


From nobody Tue May 30 04:43:26 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 10512128D2E for <babel@ietfa.amsl.com>; Tue, 30 May 2017 04:43:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.698
X-Spam-Level: 
X-Spam-Status: No, score=0.698 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NXqgWkoh5KWt for <babel@ietfa.amsl.com>; Tue, 30 May 2017 04:43:22 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 039FA1289B0 for <babel@ietf.org>; Tue, 30 May 2017 04:43:22 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496144594; bh=Xnpjfrd57RStlC+vzCczZe1RYoRETuLGfb0cyGl7gs4=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=FxKDQTLcPwW7iHbC0PcojGg73yPY6sy9pRWn9GFp+4XxMrRqh5SV9Dmapn6UYiZPK UDt/SycE82jNK5dwprO1NL36InsWO37FNjQh6VMYRPyVXZKPKbLZxIOlqZPoXaDDvl 9FstmF3xIqAaEYIexjQcDZyRDo+aiLJF3tdfxtyxG4HQ1iPRmMfolUtOWc4QcN+cyG 08b+sXUjYEyKMAo4cFt+/FVc1ZhO4zJw8LZPykeJlmAKsQh3wwNUsTW5JgGoz6rPVr tAHSebpmWew3JW2G2QDQuKObGaKqvhxoNjzEUely7i8QQE0FIRm/fpebiBVg6QaAna WlEOFYSs9AVKw==
To: Justin Kilpatrick <jkilpatr@redhat.com>
Cc: babel@ietf.org,  Juliusz Chroboczek <jch@irif.fr>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com>
Date: Tue, 30 May 2017 13:43:12 +0200
In-Reply-To: <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> (Justin Kilpatrick's message of "Tue, 30 May 2017 07:18:47 -0400")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87wp8yfu3z.fsf@alrua-x1>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/vSeDgth6alA34UYXTuhAGnz3aC0>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 11:43:24 -0000

Justin Kilpatrick <jkilpatr@redhat.com> writes:

> I was actually playing with unicast hellos this weekend. I'm pretty
> happy with my implementation at this point so I'll try and package it
> up and present it.

Cool! Please do share. Which approach did you take to encoding the
unicast hellos?

> Out of curiosity do y'all use a VM based test environment? We've got a
> netnamespace based one that's very fast and easy to use, but seems to
> have some problems with route insertions.

I have done both. These days, I tend to prefer network namespaces, but I
have not done complicated topologies. I don't suppose you can share your
setup scripts? Would be cool to have a "reference" test environment to
verify implementations...

-Toke


From kilpatrickjustin@gmail.com  Tue May 30 05:59:18 2017
Return-Path: <kilpatrickjustin@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5BDA7127137 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 05:59:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.599
X-Spam-Level: 
X-Spam-Status: No, score=-0.599 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id quzlQtS0M99x for <babel@ietfa.amsl.com>; Tue, 30 May 2017 05:59:16 -0700 (PDT)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 819CA1205F0 for <babel@ietf.org>; Tue, 30 May 2017 05:59:16 -0700 (PDT)
Received: by mail-qt0-x234.google.com with SMTP id c13so69089725qtc.1 for <babel@ietf.org>; Tue, 30 May 2017 05:59:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=t4VdW5ZX5hyAR+VydqIrdrc9Q2qxKGLrN1NGZHQc1mA=; b=G2+jFTunk2P1iClyOSXUuowibIfQEovi//hYNT0640kyNqct8whUQNV5MA9LvSmXFg 2wFC9mOIjOVI68oXdZ8bcqmZCiO3Kb7FO8SZZhgVz+FV7vQzMDVfY52aBcC/MEz8M+It ah+q3y1e4McxL9+K9TJhRknFyBAWZxu4pFv08UluCRtDQL3ymSwbdPC8oaknPDzPwBK/ J9MQKn58orabZU3On9nxfNtlCjyTy1XalB01Jbb4bYxX+35CqfZerwwzu/rk9NIqGs34 NdBzsP9zHpjRUkX9HrUEkLYzcPFKmCRboISxx0ux3ybZFzBNU+sVRF2Qpqi8a7p0Os0z TWJg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=t4VdW5ZX5hyAR+VydqIrdrc9Q2qxKGLrN1NGZHQc1mA=; b=iz37KWAHAGP44Rwx9Hm6HdlgG9NCoMDuKqP7Xn8dXx+1GT3W5ckQCpz6GQ7r/6iBmK JiIEm5DrSZkrvwk6+vU4C5yZgGUqHTjOSJEjWN0CFu0Wm4qWDrlYf4Cbc0gL4B8IWVX2 TYtkmLFVn2K3MvCaFAxtuXDXusX7hQ8yHaWoxOyyW3j4DaAOuE43sM3SEyqO3X1VQWqG c/cq4ZJEI48uyUGsiy/Ttis0HKzRHcFoHZK7fqJDHjroWop7zkohZfP6DlLpOh1LcM4M 7Ql0peJq+/ItwkyRdwIR0jFPFPDesZlB9tt6eG6+4r7L2gBGAkb7gi0wdY/5JuGtWkA6 Yrgg==
X-Gm-Message-State: AODbwcCMmYuwDE+lm80of2yzjYfTHZCIdmPaQLiZZLF5fVro0HL0n5OD X13skanr30rNzgUiYOhogJSd6uKRgA==
X-Received: by 10.200.11.193 with SMTP id p1mr22185566qti.221.1496149155699; Tue, 30 May 2017 05:59:15 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.55.143.68 with HTTP; Tue, 30 May 2017 05:59:15 -0700 (PDT)
In-Reply-To: <87wp8yfu3z.fsf@alrua-x1>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1>
From: justin kilpatrick <kilpatrickjustin@gmail.com>
Date: Tue, 30 May 2017 08:59:15 -0400
Message-ID: <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com>
To: =?UTF-8?B?VG9rZSBIw7hpbGFuZC1Kw7hyZ2Vuc2Vu?= <toke@toke.dk>
Cc: Justin Kilpatrick <jkilpatr@redhat.com>, Juliusz Chroboczek <jch@irif.fr>,  babel@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/5nOanfVM6T7o2Neu4IQMWlqHVIw>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 13:07:11 -0000

First off sorry for the email change, I try to keep to personal email
for personal projects but turns out I was only subbed to this mailing
list at work until today.

> Cool! Please do share. Which approach did you take to encoding the
> unicast hellos?

I created a new TLV, specifically our goal is the verification of
route metrics so I've been trying to extend the hello/IHU mechanism
across multiple hops without being too invasive to the overall code.
So in this case I want to send a hello addressed to a non-neighbor,
I'm not totally sure if you have similar requirements as I'm not
familiar with what Stenberg style security implies, I have the closest
RFC I can find printed to read tonight.

Anyways back on subject, I created a new tlv and then piggybacked on
the existing unicast accumulate functions and a neighbor struct to
build a copy of a normal hello message, at the end I have a custom
flush_unicast() function that sets the destination address to a remote
address then flushes the unicast buffer so that we don't cause any
other confusion. I grab a sequence number and interval from the
interface struct in the neighbor struct I select.

You can see the code here, please excuse the mess and be kind if you
find any glaring flaws [0]

> I have done both. These days, I tend to prefer network namespaces, but I
> have not done complicated topologies. I don't suppose you can share your
> setup scripts? Would be cool to have a "reference" test environment to
> verify implementations...

This is what we're using to test right now [1], I was actually running
into some problems with it not inserting routes into the namespace
routing table this weekend so chances are it need improvement. But it
is nice to have an instant standup test env.


[0] https://github.com/althea-mesh/babeld/blob/experiments/message.c#L1191
[1] https://github.com/sudomesh/network-lab


>
> -Toke
>
> _______________________________________________
> babel mailing list
> babel@ietf.org
> https://www.ietf.org/mailman/listinfo/babel


From nobody Tue May 30 06:48:00 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 24D8C12940F for <babel@ietfa.amsl.com>; Tue, 30 May 2017 06:47:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mO87_M9tVZra for <babel@ietfa.amsl.com>; Tue, 30 May 2017 06:47:56 -0700 (PDT)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6439C128CDC for <babel@ietf.org>; Tue, 30 May 2017 06:47:56 -0700 (PDT)
Received: by mail-qt0-x234.google.com with SMTP id f55so70220214qta.3 for <babel@ietf.org>; Tue, 30 May 2017 06:47:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=pYRLF8rchRdlJ1WhJ+co9sEPi8gpDMHEwr0A/t2M8VM=; b=ofs8DIf1QXdjK2GowTz4UwT5cVkzBhGNiAjRDcRB5G8WWqZwbchxfiBKdnQAxWR7Ug 1nwJpH0OhZwSWpWTL4CkTgRJTSOcsLjWmJQtY967KB7goPsowuoQ6VmG1qCNypN8YSMB FrLLkYILOLRMsw1P0xnYynzk7akz4C4vo24v0g4JhukbbPcOU8YOwVuUuY/G3PKCAyvv JgKkYV9n4mDsBA+D8Ufm8boGAgXxim87Wvhui3REwNuCw4opsSynmasOf7d055dV24Z+ E2rxhQF3EOesf1eP1Ss06dKwGnQlLCOFBf0pWklMvcn/VfMvMH/hkYGJ/AijLJj0O0UT Hfkw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=pYRLF8rchRdlJ1WhJ+co9sEPi8gpDMHEwr0A/t2M8VM=; b=QbuOcAuer8S0/xDV+8fkhTNLiD98HprsFqRnuZvdMjjtt5sz7+/jUoCb4uA3hcRh8E fcooZKUygDgOvmgt+h08rnBbBo9L3fxara1IkV40NhgokVtfYMYT9R7o92X9scbiZSw1 CGd17nWXs16uSyYoEd4rABkPpnwkFxjuH6EIsioyubCNgYjEZUFpPluI2CxuLP8+Jzmt zOo60M5YGIHMbFfYhp6xHB5rV7OnP5+7sYsVzzHuo7dAZu3kpESk/IIBxU3Rva+9Kwy7 IK+r/0/6odFOuHkUGxxXzmCx//mT8+iJcShZkdvuxYnh4ziPytyfjfb8LcWq2yRxMRGb CWuA==
X-Gm-Message-State: AODbwcAoiD7qzl2oD28Rf6v6Ve38oVsH0uyX5xS/28O+QDODwOo5DIjj 8hqXoajiLbqior4h
X-Received: by 10.200.56.243 with SMTP id g48mr22382007qtc.79.1496152075621; Tue, 30 May 2017 06:47:55 -0700 (PDT)
Received: from [10.0.20.228] (c-73-167-64-188.hsd1.nh.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id z29sm7434661qkg.55.2017.05.30.06.47.54 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 30 May 2017 06:47:54 -0700 (PDT)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <C4DAE093-3CA1-451E-AA56-47962CB4D288@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_594F5746-BFD0-4128-82AF-0167EEC34822"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Tue, 30 May 2017 09:47:52 -0400
In-Reply-To: <369567D5-D1B0-4A6B-9DF5-BE90C5C7F0F9@iki.fi>
Cc: Tony Przygienda <tonysietf@gmail.com>, Babel at IETF <babel@ietf.org>
To: Markus Stenberg <markus.stenberg@iki.fi>
References: <mailman.2034.1496053459.4563.babel@ietf.org> <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com> <369567D5-D1B0-4A6B-9DF5-BE90C5C7F0F9@iki.fi>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/4dcQWwiGaqEAU8dTD8QFOZkKDR0>
Subject: Re: [babel] babel Digest, Vol 21, Issue 9
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 13:47:58 -0000

--Apple-Mail=_594F5746-BFD0-4128-82AF-0167EEC34822
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

On May 30, 2017, at 3:28 AM, Markus Stenberg <markus.stenberg@iki.fi> =
wrote:
> With [a] you know who inserted the bad state. With [b-d], you do not. =
The difference between [b] and [c] is actually not much. You cannot =
trace down the source of shared state change (except very, very =
painfully hop by hop; you can do that in even in [d]).

No, you can't, because spoofing.   That's the point of [b].

> [e] if you can secure your lower layer or trust your nodes

I don't think we can do this on a homenet.   Assigning blame, we can =
potentially do.   Effectively controlling access, probably not.   The =
problem is that even if we only allow registered nodes access to layer =
2, all it takes is pwning one such node, and the infection is raging =
uncontrolled.


--Apple-Mail=_594F5746-BFD0-4128-82AF-0167EEC34822
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">On May 30, 2017, at 3:28 AM, Markus Stenberg &lt;<a =
href=3D"mailto:markus.stenberg@iki.fi" =
class=3D"">markus.stenberg@iki.fi</a>&gt; wrote:<div><blockquote =
type=3D"cite" class=3D""><div class=3D""><span style=3D"font-family: =
Menlo-Regular; font-size: 18px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">With [a] you know who inserted the bad =
state. With [b-d], you do not. The difference between [b] and [c] is =
actually not much. You cannot trace down the source of shared state =
change (except very, very painfully hop by hop; you can do that in even =
in [d]).</span></div></blockquote></div><br class=3D""><div class=3D"">No,=
 you can't, because spoofing. &nbsp; That's the point of [b].</div><div =
class=3D""><br class=3D""></div><div class=3D""><blockquote type=3D"cite" =
class=3D""><span style=3D"font-family: Menlo-Regular;" class=3D"">[e] if =
you can secure your lower layer or trust your nodes</span><br =
style=3D"font-family: Menlo-Regular;" class=3D""></blockquote><br =
class=3D""></div><div class=3D"">I don't think we can do this on a =
homenet. &nbsp; Assigning blame, we can potentially do. &nbsp; =
Effectively controlling access, probably not. &nbsp; The problem is that =
even if we only allow registered nodes access to layer 2, all it takes =
is pwning one such node, and the infection is raging =
uncontrolled.</div><div class=3D""><br class=3D""></div></body></html>=

--Apple-Mail=_594F5746-BFD0-4128-82AF-0167EEC34822--


From nobody Tue May 30 07:06:31 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B9821294C4 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:06:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OgP40X3czoCW for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:06:28 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 659F0126C25 for <babel@ietf.org>; Tue, 30 May 2017 07:06:28 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496153181; bh=k3jW3XYxUmolveFgX18UhEl0MswGxmDrb/E4JIonRm8=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=CIZSFsTD8P1OkARovOgtTo7TR4mm9na3uiACyVpuYp8ZJ1XP+hhMp3S0IVdhNgKX9 ErQViqBrM2tk6o4021uMq8a6+H3qXoq/8fhzF0p21Jlsr60VnlGuosaBzeY8X4Dtdj Sy+Qqs7xle/CMYi5kT2S1bE2DTx5CKWIZJ7OGYRkhoWySypdiDATCqPtOKTZb27OuM JqyyvKUKh+IoJwuXmybrj3/nrOncwKalZ6nVYQ1FP6ndexO3dUmYuwc7oQcLqz7lCz rlsz/VdXxur/zcUVccBAypGRb4K0JXghMq5sMsh2DXZXYGNn7EiPOlu0ersh+CAh9f I7eCkdVqi/YHQ==
To: justin kilpatrick <kilpatrickjustin@gmail.com>
Cc: babel@ietf.org,  Juliusz Chroboczek <jch@irif.fr>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com>
Date: Tue, 30 May 2017 16:06:19 +0200
In-Reply-To: <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> (justin kilpatrick's message of "Tue, 30 May 2017 08:59:15 -0400")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87d1aqfnhg.fsf@alrua-x1>
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/nfmKlWIuC9qS9vZb3_nCuWmNQfE>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 14:06:30 -0000

justin kilpatrick <kilpatrickjustin@gmail.com> writes:

>> Cool! Please do share. Which approach did you take to encoding the
>> unicast hellos?
>
> I created a new TLV, specifically our goal is the verification of
> route metrics so I've been trying to extend the hello/IHU mechanism
> across multiple hops without being too invasive to the overall code.
> So in this case I want to send a hello addressed to a non-neighbor,

Ah, right, so this is supposed to be in addition to the normal hello
mechanism?

> I'm not totally sure if you have similar requirements as I'm not
> familiar with what Stenberg style security implies, I have the closest
> RFC I can find printed to read tonight.

This is basically just (as I understand it) a common moniker for
security mechanisms that only work over unicast (such as DTLS and IPSEC
that need separate keys for each pair of hosts communicating). So in
order to work with this, Hellos need to either be unicast, or they will
not be protected.

My motivation for having a unicast hello is slightly different: I want
to be able to run Babel on links that either do not support multicast at
all (such as the Wireguard VPN), or have poorer performance for
multicast traffic (such as WiFi).

Both of these use cases requires a replacement for multicast hellos, but
I was not envisioning them being multihop.

>> I have done both. These days, I tend to prefer network namespaces, but I
>> have not done complicated topologies. I don't suppose you can share your
>> setup scripts? Would be cool to have a "reference" test environment to
>> verify implementations...
>
> This is what we're using to test right now [1], I was actually running
> into some problems with it not inserting routes into the namespace
> routing table this weekend so chances are it need improvement. But it
> is nice to have an instant standup test env.

Ah, that's really neat. I was thinking I'd set up an evaluation scenario
in Core (https://www.nrl.navy.mil/itd/ncs/products/core), but this looks
way more manageable. I'll take it for a spin later and see if I get any
errors (have not noticed anything on my single-namespace tests so far).

-Toke


From nobody Tue May 30 07:27:07 2017
Return-Path: <kilpatrickjustin@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 49658128A32 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:27:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.599
X-Spam-Level: 
X-Spam-Status: No, score=-0.599 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9rrbuN8nnOJQ for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:27:03 -0700 (PDT)
Received: from mail-qt0-x22d.google.com (mail-qt0-x22d.google.com [IPv6:2607:f8b0:400d:c0d::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 733FA126579 for <babel@ietf.org>; Tue, 30 May 2017 07:27:03 -0700 (PDT)
Received: by mail-qt0-x22d.google.com with SMTP id c13so71334029qtc.1 for <babel@ietf.org>; Tue, 30 May 2017 07:27:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=206hqDMgcvxkEFTgP6CAMD8fpQQZAdAy/3PWQus663M=; b=SL/39BU11Qe/UC0A0rlRxPwQUgWuQsGAddfcQHj0WChjYpcjdEf8HWriKszluTGT0c k7q31R6XthOVhr1fCMWrI2021C72n9ps5LKvzUsv8Fapwqlnkg0NPL6Q0VJ40kZNAjHw OAQmujug0gHnvkXdp6g/15qoEenm69geNr9JaHbEiYvLdpy/Z0sjZ0HD3YiiLc8z8BvE L0AceIvjiKtHQBWdWDu4+BEwVtARyNRJ7SH71qehgMFbVQrcCBlJ6DuOWPcUrb6XIipc qoUfSpxeOs5fdpBU+13jjIxitAC4JA3Uc88nB74GqcNjFO4Whdcw/TJRFLsAld7lZHMt m5bQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=206hqDMgcvxkEFTgP6CAMD8fpQQZAdAy/3PWQus663M=; b=D6sAi9x1lnlNJeL1HrKZAbnYoKMjT9l/OsS4TTMl9CnWTD5pAPYuMOuU4jkc5aJzGd fLaGVaHNECglTnTij6O37jz5v+wCTLnaLWAiEAocbmsqB/xM27m8H6ckHWmA6sbRTE1J /G/pHWJHEt+aZIDzd2wRhG5MmGfBdGjEd9WtGHP10J0mJT92GOw2KDj0AMDeUE763Igd pNJs3WJgNn73+wJEMauwjUGcHx1ffJfxLnP+iX3a/JYOhgblkW5Ub0b/RnDgTRwUDAUk 5oqs7jJdj12WNn2BT0c5o7nG4b8Ga8mYTN621lf9go0pA4IFUwxXZYBpKiMSC28+O3xi Tu5w==
X-Gm-Message-State: AODbwcC8eRf44A5qXRKqwT8kyzMDhAYzT92zRuudhhf2CPPwZJmXGOg3 lACQrevAAcgXHUEdbr/2AXJtzvaRfSM3rbs=
X-Received: by 10.200.4.162 with SMTP id s34mr25259442qtg.35.1496154422588; Tue, 30 May 2017 07:27:02 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.55.143.68 with HTTP; Tue, 30 May 2017 07:27:02 -0700 (PDT)
In-Reply-To: <87d1aqfnhg.fsf@alrua-x1>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> <87d1aqfnhg.fsf@alrua-x1>
From: justin kilpatrick <kilpatrickjustin@gmail.com>
Date: Tue, 30 May 2017 10:27:02 -0400
Message-ID: <CABdbigzvYjTASPi-440wfqko7K6vykK81j0eQWmGjAGQLRwB4w@mail.gmail.com>
To: =?UTF-8?B?VG9rZSBIw7hpbGFuZC1Kw7hyZ2Vuc2Vu?= <toke@toke.dk>
Cc: babel@ietf.org, Juliusz Chroboczek <jch@irif.fr>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/e7xUPBuKLWWOLl7Tz-ntoiqhofs>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 14:27:05 -0000

On Tue, May 30, 2017 at 10:06 AM, Toke H=C3=B8iland-J=C3=B8rgensen <toke@to=
ke.dk> wrote:
> justin kilpatrick <kilpatrickjustin@gmail.com> writes:
>
> Ah, right, so this is supposed to be in addition to the normal hello
> mechanism?

In our case yes, we need some of the same security properties to make
sure this packet can go multiple hops and be secure on the other end.
So that's a good place to share effort. We may end up having to modify
some of the metric calculation code too so that we can compute roughly
equal numbers by communicating directly with a remote node as the
network should produce by the 'normal' method of route distribution.

We want to verify some but not all remote routes and use that to rank
neighbors by how many of their routes are trustworthy. A sort of local
reputation system that we outline here [0].

> Both of these use cases requires a replacement for multicast hellos, but
> I was not envisioning them being multihop.

If you don't need multihop functionality you can just remove the
custom flush function. The normal unicast flush function will just
send the packet to the neighbor address.

[0] http://altheamesh.com/documents/whitepaper.pdf


From nobody Tue May 30 07:50:47 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 05854129564 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:50:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yRSQchGsq7uj for <babel@ietfa.amsl.com>; Tue, 30 May 2017 07:50:44 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2C5FE12955F for <babel@ietf.org>; Tue, 30 May 2017 07:50:44 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496155840; bh=XsOfb6G7yAjTcooNkxSqYRHuPy3kOQy+vPWWPVe8ZTI=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=quHU8v+JBavjPpjpjIqefRcmFHqj4BpHiWITBlzvB6OhcCu5SkIm9dSY0bY/i3joi +FseMgQxonWDnu8WfqXl3Uo7DKds6kKcK6trtA2CFjzYqZiYc0AkZ9GRLI/k8ysHst L5hcrQQt627tXL930CyrZdQafk8uCJu8SPMx/zEmgzjMc0gjds4pdfTc0ActSJBIUr k82bu/OWuxPl/mNa03HKwqhIVqE01qW8mNzVAR8/VX9DEGcGuz6R2QxWaCJh21i1Tx 4PppZ9MhTVlXNRjS6pc6NWk91TJf/P/1wASiO1EHAo6Wr2we6rB7FGXJKeCaFoBGwf b68KVJIjlqDkQ==
To: justin kilpatrick <kilpatrickjustin@gmail.com>
Cc: babel@ietf.org,  Juliusz Chroboczek <jch@irif.fr>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> <87d1aqfnhg.fsf@alrua-x1> <CABdbigzvYjTASPi-440wfqko7K6vykK81j0eQWmGjAGQLRwB4w@mail.gmail.com>
Date: Tue, 30 May 2017 16:50:38 +0200
In-Reply-To: <CABdbigzvYjTASPi-440wfqko7K6vykK81j0eQWmGjAGQLRwB4w@mail.gmail.com> (justin kilpatrick's message of "Tue, 30 May 2017 10:27:02 -0400")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87inkibdq9.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/vrymKAe9s4aVDB_ayRa3W5Ac_Mc>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 14:50:46 -0000

justin kilpatrick <kilpatrickjustin@gmail.com> writes:

> On Tue, May 30, 2017 at 10:06 AM, Toke H=C3=B8iland-J=C3=B8rgensen <toke@=
toke.dk> wrote:
>> justin kilpatrick <kilpatrickjustin@gmail.com> writes:
>>
>> Ah, right, so this is supposed to be in addition to the normal hello
>> mechanism?
>
> In our case yes, we need some of the same security properties to make
> sure this packet can go multiple hops and be secure on the other end.
> So that's a good place to share effort. We may end up having to modify
> some of the metric calculation code too so that we can compute roughly
> equal numbers by communicating directly with a remote node as the
> network should produce by the 'normal' method of route distribution.
>
> We want to verify some but not all remote routes and use that to rank
> neighbors by how many of their routes are trustworthy. A sort of local
> reputation system that we outline here [0].

Right, I see. I assume you'll need some kind of end-to-end verification
in this case, as you're basically trying to protect against malicious
transit nodes (that could just alter the multi-hop hello/IHUs); how are
you going to do that?

Also, from reading the description it was not clear to me exactly what a
"destination" is? If a gateway advertises a prefix (say
2001:db8:100::/64), which address is a node supposed to send its
multi-hop hello to?

>> Both of these use cases requires a replacement for multicast hellos, but
>> I was not envisioning them being multihop.
>
> If you don't need multihop functionality you can just remove the
> custom flush function. The normal unicast flush function will just
> send the packet to the neighbor address.

I'm developing an independent implementation of Babel (in the Bird
routing daemon), so I try not to look at the babeld code; and so I
didn't read your code. But from the white paper, it seems your unicast
hello is something separate from the unicast version of the normal hello
that we have been discussing. I.e., they should have separate TLV
numbers, no?

-Toke


From nobody Tue May 30 08:14:04 2017
Return-Path: <kilpatrickjustin@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E2BD1274D2 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 08:14:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Pk4mqmw97cqI for <babel@ietfa.amsl.com>; Tue, 30 May 2017 08:14:02 -0700 (PDT)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F34E0126E64 for <babel@ietf.org>; Tue, 30 May 2017 08:14:01 -0700 (PDT)
Received: by mail-qt0-x234.google.com with SMTP id t26so72504739qtg.0 for <babel@ietf.org>; Tue, 30 May 2017 08:14:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=vefL+TvzQ/zeQC4f5IbfRVSZUCuRnBUgx+z5zZrH6ek=; b=Mz9CvCabCArzjQubhUlnIlgwTYyDijqZAoDJ0JsurYTK2uumBKZKICpZ5+kaVFm9nk uWmu27E0+5750Grq5s6lECj177QUYC7njGnucv5nlVJX2TOMnjx92mppT2PJhtXtyS1X dEEIEMyiMy9FWteJ8gjNrXjLRujoonMPX5SNQ+3zU46FszxEnbL4lLOlF0W8cF/mE3ar KS5eWAnssIEW6tR2zlNZH7vhrGJTkXWdfl1DHh62XZ4eo0tYqJqMf8/YSZETHhv3WZj5 5XzT2r6aRiEVOblzagbZ4StjFKTdXIaC2H2J2khtdUlrWNnZ8fK4RN/JvlsnycBxqs9P q1yA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=vefL+TvzQ/zeQC4f5IbfRVSZUCuRnBUgx+z5zZrH6ek=; b=XCn5Xn9TayY9wFOtEM4u82OV5B/+cNuG1Qx33S0W+3KHp38fIg4eZzHrzDSRT7Gd1/ 4Tr8TUTaUeQh/t5wmBw/AVEQ11D6hXJYdoaBH1mt2qGDD7w+Gt0BrnIyIpnh/SXIKDvw Jdhz72LW1ulu+4ng/C+klDwTdqz+kkjjIFaNeqqAPEq9JI265iqHTRBK8hrfeYRgWb+y vUmsaORAyvmjQzheve7N4j6swuEFqmsXC/IBSaljGlIyuRuhJ1msLhNSGQA8OlN8lKhG pl882vOyPG+IFLy3RqJNvDb9dILrr8HumjPRoUwFbyDrzCGUHLDJb6aTDtrJV2akh47z e8dg==
X-Gm-Message-State: AODbwcBXf8Z0A/pFxbRWWMshZdY+gAnH7pB0sDA7efoUs60Y+6HqYQgL HiIeQK7CpP2cWDdCoPx/WKdIUquxVA==
X-Received: by 10.200.39.171 with SMTP id w40mr22919140qtw.87.1496157241129; Tue, 30 May 2017 08:14:01 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.55.143.68 with HTTP; Tue, 30 May 2017 08:14:00 -0700 (PDT)
In-Reply-To: <87inkibdq9.fsf@alrua-kau>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> <87d1aqfnhg.fsf@alrua-x1> <CABdbigzvYjTASPi-440wfqko7K6vykK81j0eQWmGjAGQLRwB4w@mail.gmail.com> <87inkibdq9.fsf@alrua-kau>
From: justin kilpatrick <kilpatrickjustin@gmail.com>
Date: Tue, 30 May 2017 11:14:00 -0400
Message-ID: <CABdbigwt96fSdvpXtDUEg69F1Ohe_xF9oMeuRhv1WOPDB+=g8w@mail.gmail.com>
To: =?UTF-8?B?VG9rZSBIw7hpbGFuZC1Kw7hyZ2Vuc2Vu?= <toke@toke.dk>
Cc: babel@ietf.org, Juliusz Chroboczek <jch@irif.fr>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/lfJ4CBtyzFjvYuXpY_HlkRLn8yg>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 15:14:03 -0000

On Tue, May 30, 2017 at 10:50 AM, Toke H=C3=B8iland-J=C3=B8rgensen <toke@to=
ke.dk> wrote:
> Also, from reading the description it was not clear to me exactly what a
> "destination" is? If a gateway advertises a prefix (say
> 2001:db8:100::/64), which address is a node supposed to send its
> multi-hop hello to?

In our case we want to reach the person advertising that prefix, we
really don't care what their exact address is.
In the ideal world we could send packets to Babel node id's but we're
settling on an assumption that if we send
this packet to a destination in the advertised prefix it will be
'eaten' by the babel node on the other end and responded
to correctly. Which probably isn't great networking design.

> I'm developing an independent implementation of Babel (in the Bird
> routing daemon), so I try not to look at the babeld code; and so I
> didn't read your code. But from the white paper, it seems your unicast
> hello is something separate from the unicast version of the normal hello
> that we have been discussing. I.e., they should have separate TLV
> numbers, no?
>
> -Toke

That's easy enough, we already identify it as a multhop hello in it's TLV.

Anyways I think we're starting to diverge from the subject of this
thread and should take further conversations on this topic off list or
to a different on list thread.

- Justin


From nobody Tue May 30 08:32:18 2017
Return-Path: <toke@toke.dk>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1F4B129576 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 08:32:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=toke.dk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I_o1zW1t0lhO for <babel@ietfa.amsl.com>; Tue, 30 May 2017 08:32:14 -0700 (PDT)
Received: from mail.toke.dk (mail.toke.dk [52.28.52.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22E5C1294F8 for <babel@ietf.org>; Tue, 30 May 2017 08:32:14 -0700 (PDT)
From: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=toke.dk; s=20161023; t=1496158327; bh=VKY7+oxurkpQvISygPIUg1uosmiyUI111qWr/T91VHI=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=Nytpp127EneS0rmf0o7lQN3X0jah6STUcdtlbXEjEuLKCPlJCSq6T9/udm0CX1chP T3l+w5ueUFIslpnRnP09rCWanVoeuuOM+IDXYDCEHQ80UQWX0MUl74UDOn/lCXJA5x fu7JjB9VHMS/7QfMPgXwL5yMmLThpyp5yqoqK/+biMgcsfZuSJ/GyAfQ+6XqSAeRSV wyPGLWL+hOCEF0fM3R58P2OmNTxsy9+N47c37OAqmYSiUfnktQTNoP7PMtIHAviGGb hqyk5dENavEnzkd1MyHQqIsL7fNG2Yz5DYKGA6fth+gprjMZPlsx22Ehck0amFTEXP Mp0T4YkKBi4mQ==
To: justin kilpatrick <kilpatrickjustin@gmail.com>
Cc: Juliusz Chroboczek <jch@irif.fr>,  babel@ietf.org
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> <87d1aqfnhg.fsf@alrua-x1> <CABdbigzvYjTASPi-440wfqko7K6vykK81j0eQWmGjAGQLRwB4w@mail.gmail.com> <87inkibdq9.fsf@alrua-kau> <CABdbigwt96fSdvpXtDUEg69F1Ohe_xF9oMeuRhv1WOPDB+=g8w@mail.gmail.com>
Date: Tue, 30 May 2017 17:32:05 +0200
In-Reply-To: <CABdbigwt96fSdvpXtDUEg69F1Ohe_xF9oMeuRhv1WOPDB+=g8w@mail.gmail.com> (justin kilpatrick's message of "Tue, 30 May 2017 11:14:00 -0400")
X-Clacks-Overhead: GNU Terry Pratchett
Message-ID: <87efv6bbt6.fsf@alrua-kau>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/cZ7NL-XFzz6mU93UisLf93He1dc>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 15:32:16 -0000

justin kilpatrick <kilpatrickjustin@gmail.com> writes:

> On Tue, May 30, 2017 at 10:50 AM, Toke H=C3=B8iland-J=C3=B8rgensen <toke@=
toke.dk> wrote:
>> Also, from reading the description it was not clear to me exactly what a
>> "destination" is? If a gateway advertises a prefix (say
>> 2001:db8:100::/64), which address is a node supposed to send its
>> multi-hop hello to?
>
> In our case we want to reach the person advertising that prefix, we
> really don't care what their exact address is. In the ideal world we
> could send packets to Babel node id's but we're settling on an
> assumption that if we send this packet to a destination in the
> advertised prefix it will be 'eaten' by the babel node on the other
> end and responded to correctly. Which probably isn't great networking
> design.

Ah, I see. So "magic", basically ;)

>> I'm developing an independent implementation of Babel (in the Bird
>> routing daemon), so I try not to look at the babeld code; and so I
>> didn't read your code. But from the white paper, it seems your unicast
>> hello is something separate from the unicast version of the normal hello
>> that we have been discussing. I.e., they should have separate TLV
>> numbers, no?
>>
>> -Toke
>
> That's easy enough, we already identify it as a multhop hello in it's
> TLV.

Yup, just wanted to be sure we were on the same page, and that I should
not try to interoperate with your implementation when I get around to
doing unicast hellos...

> Anyways I think we're starting to diverge from the subject of this
> thread and should take further conversations on this topic off list or
> to a different on list thread.

Yeah, having a separate discussion on multi-hop metrics might be useful
at some point :)

-Toke


From nobody Tue May 30 09:49:30 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A0E29129AC6 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 09:49:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.5
X-Spam-Level: 
X-Spam-Status: No, score=-0.5 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nGeh1Q9dfevG for <babel@ietfa.amsl.com>; Tue, 30 May 2017 09:49:26 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 468D0129AC1 for <babel@ietf.org>; Tue, 30 May 2017 09:49:26 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4UGnN5u030253 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Tue, 30 May 2017 18:49:23 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4UGnNwX014600; Tue, 30 May 2017 18:49:23 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 13CF4EB201; Tue, 30 May 2017 18:49:23 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 3TvKUNQc6kHf; Tue, 30 May 2017 18:49:21 +0200 (CEST)
Received: from ijon.irif.fr (host18-109-static.224-95-b.business.telecomitalia.it [95.224.109.18]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 821ABEB206; Tue, 30 May 2017 18:49:19 +0200 (CEST)
Date: Tue, 30 May 2017 18:49:18 +0200
Message-ID: <87zidumgs1.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: justin kilpatrick <kilpatrickjustin@gmail.com>
Cc: babel@ietf.org
In-Reply-To: <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Tue, 30 May 2017 18:49:23 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Tue, 30 May 2017 18:49:23 +0200 (CEST)
X-Miltered: at korolev with ID 592DA293.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592DA293.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592DA293.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<jch@irif.fr>
X-j-chkmail-Enveloppe: 592DA293.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592DA293.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592DA293.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/tfYyU3cA8ikXAz1eM8iPcDCMnbw>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 16:49:29 -0000

> [0] https://github.com/althea-mesh/babeld/blob/experiments/message.c#L1191

I don't see how that code can possibly work.  It passes a router-id in the
address parameter, which is later stuck into the sin_addr field of
a sockaddr_in6.  It also reuses a neighbour's unicast buffer without
flushing it first, which may cause TLVs to be sent to the wrong address.

-- Juliusz


From nobody Tue May 30 10:32:11 2017
Return-Path: <fingon@kapsi.fi>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 117E7129ADE for <babel@ietfa.amsl.com>; Tue, 30 May 2017 10:32:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=kapsi.fi
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ByE7pGirKhSb for <babel@ietfa.amsl.com>; Tue, 30 May 2017 10:32:08 -0700 (PDT)
Received: from mail.kapsi.fi (mail.kapsi.fi [IPv6:2001:1bc8:1004::1:25]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DC742129AE0 for <babel@ietf.org>; Tue, 30 May 2017 10:32:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=kapsi.fi; s=20161220;  h=To:References:Message-Id:Content-Transfer-Encoding:Cc:Date:In-Reply-To:From:Subject:Mime-Version:Content-Type; bh=Avuo3NQENRY7/DgAzvZHJzQHRNZv4GIvwdRVriCPFLs=;  b=jBGa5OTvC7gl1U4CjIw1D5xeFF7KPR7KXpa5VtLNL0hxqQTReLlarzRazeBkIYDAhpP8WBmY5tf6LJzpB9RwUODObiT6CXX0/KXoc4dEwdAQ2FtdYO6pmjAC6nU7iGnbWX+4Y3qDWDjq1qLHWbrFbeNzhTdRbM4t7cYNznCqCGGZGvtyZ/7nDJSXLBxyFnRGUL9tsfyMaOLdFMmJ1XLj3uZhCIeCRFU0YFs5gXQZYsFH9VakD0dKMh0bZr7696h5joVmngbHCxajXTyyGHfDyvMA/vj+8+n0FA9SMd04VewHCYn9FshistJfNugicDSUkR/5KzEURd8K7d7dDYjpgQ==;
Received: from a91-155-69-187.elisa-laajakaista.fi ([91.155.69.187] helo=poro.lan) by mail.kapsi.fi with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from <markus.stenberg@iki.fi>) id 1dFl00-00010V-HN; Tue, 30 May 2017 20:32:04 +0300
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Markus Stenberg <markus.stenberg@iki.fi>
In-Reply-To: <C4DAE093-3CA1-451E-AA56-47962CB4D288@fugue.com>
Date: Tue, 30 May 2017 20:32:04 +0300
Cc: Tony Przygienda <tonysietf@gmail.com>, Babel at IETF <babel@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <F32A83BD-FFAA-484F-ADC5-86FA75C2404B@iki.fi>
References: <mailman.2034.1496053459.4563.babel@ietf.org> <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com> <369567D5-D1B0-4A6B-9DF5-BE90C5C7F0F9@iki.fi> <C4DAE093-3CA1-451E-AA56-47962CB4D288@fugue.com>
To: Ted Lemon <mellon@fugue.com>
X-Mailer: Apple Mail (2.3273)
X-SA-Exim-Connect-IP: 91.155.69.187
X-SA-Exim-Mail-From: markus.stenberg@iki.fi
X-SA-Exim-Scanned: No (on mail.kapsi.fi); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/LZrlzGc9PAK5SYVvlZfzWBnHsXY>
Subject: Re: [babel] babel Digest, Vol 21, Issue 9
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 17:32:10 -0000

On 30 May 2017, at 16.47, Ted Lemon <mellon@fugue.com> wrote:
> On May 30, 2017, at 3:28 AM, Markus Stenberg <markus.stenberg@iki.fi> =
wrote:
>> With [a] you know who inserted the bad state. With [b-d], you do not. =
The difference between [b] and [c] is actually not much. You cannot =
trace down the source of shared state change (except very, very =
painfully hop by hop; you can do that in even in [d]).
> No, you can't, because spoofing.   That=E2=80=99s the point of [b].

If you require signature (with reasonable antireplay) of every update =
TLV (by the origin), how do you spoof it? That was the whole point of =
[a].

[b] is not that, [b] is just per-adjacency encryption and the content of =
stuff _can_ be spoofed as long as you have credential to chat up with =
your next adjacency.

>> [e] if you can secure your lower layer or trust your nodes
> I don't think we can do this on a homenet.   Assigning blame, we can =
potentially do.   Effectively controlling access, probably not.   The =
problem is that even if we only allow registered nodes access to layer =
2, all it takes is pwning one such node, and the infection is raging =
uncontrolled.

You get =E2=80=98infection=E2=80=99 regardless, unless you have e.g. =
strongly authenticated DHCP, DNS, NTP, and everything else.

(HNCP as specified does funny things if you pretend to be upstream, and =
DHCP(v6) is not authenticated.)

Cheers,

-Markus


From nobody Tue May 30 10:45:47 2017
Return-Path: <kilpatrickjustin@gmail.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2A2012969E for <babel@ietfa.amsl.com>; Tue, 30 May 2017 10:45:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.599
X-Spam-Level: 
X-Spam-Status: No, score=-0.599 tagged_above=-999 required=5 tests=[BAYES_05=-0.5, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KaSb0dqhbqfG for <babel@ietfa.amsl.com>; Tue, 30 May 2017 10:45:45 -0700 (PDT)
Received: from mail-qt0-x230.google.com (mail-qt0-x230.google.com [IPv6:2607:f8b0:400d:c0d::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C5A8D129BD1 for <babel@ietf.org>; Tue, 30 May 2017 10:45:44 -0700 (PDT)
Received: by mail-qt0-x230.google.com with SMTP id v27so76109759qtg.2 for <babel@ietf.org>; Tue, 30 May 2017 10:45:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;  h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=aIKqBOthNtUKklj7nLAnV8ZPNmhqOFSLwABj9hGYRms=; b=Or54S8OOv3pObOGx0wQrmo/e/C08lxy7CJbIcSpa5hfAuVRjNF8kRliEweOg+ReZC9 elz99uUcOs+VJY9MO49bD5jqoCxHzfrvtA/nuKL55z0GLxZMfAKlnMizxocTqf2kijbK fKfkig7pVwII4SORBGuLauyrYW9aEXmZX7mDwA0AgwL8102nCh4iw4BeEEAXiKxW7wLB xDf0NFDRdQ1DV3kKq5vUQiHESf6GNy2yOomst3r6zsWkyB+dLzedDrCR3AwVqAEWfLuK p0vtoykibYMXaV2rV5cf4GwPEynF2GgRPjyRAzEt6luGsRx8yOkdBPn2LKK1nb94fGMF jnpg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=aIKqBOthNtUKklj7nLAnV8ZPNmhqOFSLwABj9hGYRms=; b=AAlNhHk1/WjLqO17qoJsjzmUMKhhKgdU7WTVMeEOgK0PXqUEAZW4duenqhJ4gBxWU7 HaP74WtQNON5OBQKxLHV2f7LTro3gvN5OVYzE+KDbuwM/Hpc8Y7IWOQnm65OJ8SU0dFD Sy8i4iC48hbI0J5+K3Tqoj1nBq+93SAkzCe+zkfvPf0NAS6Jj+60PhrnqrGekN3k6S1r CbSVal7dNcyHcFwcVKGEFIMM34UFwW+aMe5+ndz9qYfybNSljRefa2usT4f7BV+mhHU0 upny8p1byt+jJcHE5AW6PtNFvPMFrJDL8cNA0Y28KGfinscU0H7mezBLPrIrqarXYyd1 9ALg==
X-Gm-Message-State: AODbwcCVQJTjMD+08IJzSM80o0fXqrqWBN0Cgx9elZA7PP4ho6TSfSae 1arM60WHmyp4BgkYJYQkIZkbIHaKKQ==
X-Received: by 10.200.1.142 with SMTP id x14mr27356350qtf.26.1496166344011; Tue, 30 May 2017 10:45:44 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.55.143.68 with HTTP; Tue, 30 May 2017 10:45:43 -0700 (PDT)
In-Reply-To: <87zidumgs1.wl-jch@irif.fr>
References: <87bmqck6sp.wl-jch@irif.fr> <874lw3apnn.fsf@alrua-kau> <87shjnomkl.wl-jch@irif.fr> <87vaoj95qm.fsf@alrua-kau> <CANhjow_v0rDwRoS0mSRat9R0cxTmxQeTb6Yf1O=KoVMUwhA=3g@mail.gmail.com> <87wp8yfu3z.fsf@alrua-x1> <CABdbigx5XSg4vqDcYWQ7NXMY=eA0yw6s511wKKTLTP7ZNuDKoQ@mail.gmail.com> <87zidumgs1.wl-jch@irif.fr>
From: justin kilpatrick <kilpatrickjustin@gmail.com>
Date: Tue, 30 May 2017 13:45:43 -0400
Message-ID: <CABdbigxVGLmUAaRL+8K5r7BKW02umTeDE1v2HakB4rADnrLUBQ@mail.gmail.com>
To: Juliusz Chroboczek <jch@irif.fr>
Cc: babel@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/wQMI3D92Sc7s5fHEx6tSduTcbf8>
Subject: Re: [babel] Unicast Hellos?
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 17:45:47 -0000

On Tue, May 30, 2017 at 12:49 PM, Juliusz Chroboczek <jch@irif.fr> wrote:
> I don't see how that code can possibly work.  It passes a router-id in the
> address parameter, which is later stuck into the sin_addr field of
> a sockaddr_in6.  It also reuses a neighbour's unicast buffer without
> flushing it first, which may cause TLVs to be sent to the wrong address.


It's toy code, I did get it working using the neighbor address and was
playing around with looking at router ID's and debugging why routes
where not getting inserted into the netns routing tables when I
stopped for the day with no intent to publish it. Probably should have
cleaned it up before I linked it here.

I do see your point on the buffering logic though, there's no way it
could go multiple hops because I'm not seeing the address right, I
would need to do so in flushbuf not after the bucket check. As for the
bad caching safety trying to trace that now I'm not sure I agree with
you, start unicast runs flush_unicast and I use the
flush_unicast_remote function to close things out properly. Now I
should probably run flush_unicast instead of flushbuff at the start of
the hello function but I don't see where we actually end up with TLV's
in the wrong buffer?

I've never done anything involving networking outside of Python and
Java so it's possible I'm missing something really obvious.


From nobody Tue May 30 11:37:18 2017
Return-Path: <mellon@fugue.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5E9EE129AE7 for <babel@ietfa.amsl.com>; Tue, 30 May 2017 11:37:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YLX8LWtIgSPv for <babel@ietfa.amsl.com>; Tue, 30 May 2017 11:37:15 -0700 (PDT)
Received: from mail-qt0-x22f.google.com (mail-qt0-x22f.google.com [IPv6:2607:f8b0:400d:c0d::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79893129AD4 for <babel@ietf.org>; Tue, 30 May 2017 11:37:15 -0700 (PDT)
Received: by mail-qt0-x22f.google.com with SMTP id c13so77341486qtc.1 for <babel@ietf.org>; Tue, 30 May 2017 11:37:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=VtJwroceRKnbXI3/PI3m4brABu8WUom5KRC4dwSl+Sw=; b=vG+dXYSO4Q4TV5SR1SY8rEq+A6gU81IF66qc3P76l5x9M63mSr0QbrgNQugRAWyx6D nhmvh8kEoLqLQvojzXkBHklb5FeLWDtyU6XdBigUkYcODPUldMme3nmPGs3T/xX8dKo/ dbSMv1z+0a1GQH+4Gt6drGBPQb56DN9WLn6IT7UYQWE5G87D3v+/Qqwx11d26EWNABnA ZLp2BjZNjp0vVYmQZsMeTorbV5QFYsiLujxOI9iVcJfO6ZXGznJERlT07t8hok5ajntb vsCTmub2L3o4V3wrY/kAEXklhufS7zbjmT9PeDMthEw5x0H+YXhA1pisfyE/ERsXorxt jJcw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=VtJwroceRKnbXI3/PI3m4brABu8WUom5KRC4dwSl+Sw=; b=Jdrja4RhEid1Z815VeR961EkAskelMhCmFnmew0Y4E9ryH57c4ggvRZOrFMDGy7/go j6M92FLa8I7Ec+rdVzkjIztE1td8jABBNodsSD0B5CGAvv5cC/N68c0pkTC+a4wTpInZ rUy8eJZd6f/4KdQ5X3UzDEZOx7QE/qFNPH8OprdrBht5IZP7MqIjhIHVAqbld65gxSBl ohVqsfyG1+SbL/Sg/xreYMrlrJ7iaoNclFYe2zDj0nAnFxrM2Y0B1u/1QaRlIgDWgSdh PCvufVrkUrn2K047j0d8jr7h2MEQMPQ83QpPKMFU/IgwkkifOdeEotdOdQpCbVLt/aqW LIUw==
X-Gm-Message-State: AODbwcAisvnlHsNvN5vra+vKYN+YpCcC1cNNJCnGUY/EUmFZz2K53oEB /Ap2jbA47Cj0t1pM
X-Received: by 10.237.54.2 with SMTP id e2mr27354614qtb.218.1496169434585; Tue, 30 May 2017 11:37:14 -0700 (PDT)
Received: from [10.0.20.228] (c-73-167-64-188.hsd1.nh.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id t66sm8673792qkt.42.2017.05.30.11.37.13 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 30 May 2017 11:37:14 -0700 (PDT)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
From: Ted Lemon <mellon@fugue.com>
In-Reply-To: <F32A83BD-FFAA-484F-ADC5-86FA75C2404B@iki.fi>
Date: Tue, 30 May 2017 14:37:12 -0400
Cc: Tony Przygienda <tonysietf@gmail.com>, Babel at IETF <babel@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <95628515-CF7F-43BD-A295-4CE78172F718@fugue.com>
References: <mailman.2034.1496053459.4563.babel@ietf.org> <CA+wi2hNizgKxPcKOyb0RydwDLos+Z2NN2bq+qE8_+dHb2XmnPg@mail.gmail.com> <369567D5-D1B0-4A6B-9DF5-BE90C5C7F0F9@iki.fi> <C4DAE093-3CA1-451E-AA56-47962CB4D288@fugue.com> <F32A83BD-FFAA-484F-ADC5-86FA75C2404B@iki.fi>
To: Markus Stenberg <markus.stenberg@iki.fi>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/78G00QOfoVjeBeyoeL6_Nv6JMcc>
Subject: Re: [babel] babel Digest, Vol 21, Issue 9
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 May 2017 18:37:17 -0000

On May 30, 2017, at 1:32 PM, Markus Stenberg <markus.stenberg@iki.fi> =
wrote:
> If you require signature (with reasonable antireplay) of every update =
TLV (by the origin), how do you spoof it? That was the whole point of =
[a].
>=20
> [b] is not that, [b] is just per-adjacency encryption and the content =
of stuff _can_ be spoofed as long as you have credential to chat up with =
your next adjacency.

Well, I will freely admit that I prefer [a], but I get the sense that =
the babel working group does not, so if all I can get is [b], I do think =
it's better than [c] or [d].   The point of [b] is that yes, you can =
chat up your neighbor, but because you have to sign your communications, =
your neighbor knows that it is _you_ chatting it up.

> You get =E2=80=98infection=E2=80=99 regardless, unless you have e.g. =
strongly authenticated DHCP, DNS, NTP, and everything else.

Yes.   Securing just babel isn't a complete solution.

> (HNCP as specified does funny things if you pretend to be upstream, =
and DHCP(v6) is not authenticated.)

We're working on that...


From nobody Wed May 31 07:55:59 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61C0F129557 for <babel@ietfa.amsl.com>; Wed, 31 May 2017 07:55:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.799
X-Spam-Level: 
X-Spam-Status: No, score=0.799 tagged_above=-999 required=5 tests=[BAYES_50=0.8, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AWiePIyNgFJZ for <babel@ietfa.amsl.com>; Wed, 31 May 2017 07:55:56 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 444D81288B8 for <babel@ietf.org>; Wed, 31 May 2017 07:55:55 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4VEtsMh024935; Wed, 31 May 2017 16:55:54 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 49F64EB206; Wed, 31 May 2017 16:55:54 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id u_qp2hi8S_7l; Wed, 31 May 2017 16:55:53 +0200 (CEST)
Received: from ijon.irif.fr (host18-109-static.224-95-b.business.telecomitalia.it [95.224.109.18]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 8BFDEEB209; Wed, 31 May 2017 16:55:52 +0200 (CEST)
Date: Wed, 31 May 2017 16:55:55 +0200
Message-ID: <87y3tdhy84.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Matthieu Boutier <boutier@irif.fr>
Cc: babel-users@lists.alioth.debian.org, babel@ietf.org
In-Reply-To: <70ED4D66-B6BF-4D29-B24F-32A2C6779789@irif.fr>
References: <87h90a9nlz.wl-jch@irif.fr> <70ED4D66-B6BF-4D29-B24F-32A2C6779789@irif.fr>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 31 May 2017 16:55:54 +0200 (CEST)
X-Miltered: at korolev with ID 592ED97A.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592ED97A.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592ED97A.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/iJyry440nPj3TbTZSKtIg3bM-FA>
Subject: Re: [babel] source sub-tlv
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 14:55:58 -0000

Matthieu, could you please write up a new version of the I-D with your
encoding?  You might want to speak to Gwendoline, since she needs to write
up her TOS-specific encoding.

> If we keep this behaviour and mix tos-specific routes, we will have
> to send 4 wildcard requests to have all routes.  I see two reasonable
> options:

>   - only keep (legacy) wildcard requests, and reply with a full dump.

That's reasonable, although slightly confusing.  (Call that (1).)

>   - send one request with all sub-TLVs you know but without mandatory
>     bit, and reply to all options you know about.

That's not -- it would require allocating a full new set of sub-TLVs.
Plus I find this confusing.  (Call that (2).)

There are two other possibilities:

  3. Send a non-specific wildcard request for non-specific routes,
     a source-specific wildcard request for source-specific routes, etc.

  4. Deprecate wildcard requests -- say that they MAY be replied to, but
     SHOULD NOT be sent by new implementations.

Now wildcard requests are fairly rare -- they are only used to speed up
convergence at boot time, as well as by debugging tools (although we have
no such debugging tools yet -- all debugging tools known to me connect to
the local socket of a node).  So sending four TLVs in a single unicast
packet instead of a single TLV is not prohibitive, and is much simpler
than the alternatives.

I support (3).  Last time I spoke to him, Toke supported (4).  I am
opposed to (2).  I can live with (1).

-- Juliusz


From nobody Wed May 31 08:04:14 2017
Return-Path: <dschinazi@apple.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3045128A32 for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:04:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.303
X-Spam-Level: 
X-Spam-Status: No, score=-4.303 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id B3EXlRD7xCsV for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:04:11 -0700 (PDT)
Received: from mail-in7.apple.com (mail-out7.apple.com [17.151.62.29]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8982412896F for <babel@ietf.org>; Wed, 31 May 2017 08:04:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=apple.com; s=mailout2048s; c=relaxed/simple; q=dns/txt; i=@apple.com; t=1496243051; h=From:Sender:Reply-To:Subject:Date:Message-id:To:Cc:MIME-version:Content-type: Content-transfer-encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-reply-to:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=yB3pMh8TujUPv0JjZZXmBASXvqQNTvrmAklWa+u2RlA=; b=DWgshHNF/IBu5POSYRRY/4N+SrcLKynG5y5A0z7ju4bMlPjSlUVnong0X8aUcV93 i6U4po6XnYVZOD2SbL6jeJ0BHm1BWmVMMzNKyFyvx8Lcke+CK6XYaZHlGl7WCokY BgfOlGQgtAaXWhUNIm0VIxX1bDNoTbPFUjRQvNLpLK8XGWFYbU5aLkXwjZrUGBGC 5CatL/frM2eyA3Thi5AV/O28WnjW0zb9VPv5CoD07OJQly8OfRRfnypbrSWd4Mzg CU4yPddLR9LeZL++rss5TMOKCSRSzvuiQ+9tJlZZe10XLYIjT63/VmnYrOrRSW/C kPu6jZi0tyVMgYXX6M4uDg==;
Received: from relay6.apple.com (relay6.apple.com [17.128.113.90]) (using TLS with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mail-in7.apple.com (Apple Secure Mail Relay) with SMTP id D9.A3.07949.B6BDE295; Wed, 31 May 2017 08:04:11 -0700 (PDT)
X-AuditID: 11973e16-be3ff70000001f0d-c9-592edb6b3607
Received: from nwk-phonehomebzp-sz01 (nwk-phonehomebzp-sz01.apple.com [17.151.62.64]) by relay6.apple.com (Apple SCV relay) with SMTP id 75.AF.09762.A6BDE295; Wed, 31 May 2017 08:04:11 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; CHARSET=US-ASCII
Received: from [17.153.76.33] (unknown [17.153.76.33]) by nwk-phonehomebzp-sz01.apple.com (Oracle Communications Messaging Server 8.0.1.2.20170210 64bit (built Feb 10 2017)) with ESMTPSA id <0OQT00KG5OI7V550@nwk-phonehomebzp-sz01.apple.com>; Wed, 31 May 2017 08:04:10 -0700 (PDT)
Sender: dschinazi@apple.com
From: David Schinazi <dschinazi@apple.com>
In-reply-to: <87y3tdhy84.wl-jch@irif.fr>
Date: Wed, 31 May 2017 08:03:41 -0700
Cc: Matthieu Boutier <boutier@irif.fr>, babel-users@lists.alioth.debian.org, babel@ietf.org
Message-id: <C8B56E38-8E53-415E-87A5-C69F7DAC1D60@apple.com>
References: <87h90a9nlz.wl-jch@irif.fr> <70ED4D66-B6BF-4D29-B24F-32A2C6779789@irif.fr> <87y3tdhy84.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrBLMWRmVeSWpSXmKPExsUi2FAYpZt9Wy/S4NtDSYuvnxtYLLYs6max OPylkcVifusyNgcWjyVLfjJ5LN7yltHjzaE+lgDmKC6blNSczLLUIn27BK6M6TvaWAqeClR8 3L6TvYFxPm8XIyeHhICJxLJ3u1i6GLk4hARWM0nsvfCfFSZx58IXRhBbSOAYo8TEOV4gNq+A oMSPyfeAGjg4mAXkJQ6elwUJMwtoSXx/1Ao1Zz6TxLvLN9lAEsIC0hJdF+6yQtiGElcbOthA etmAGg6sMQIJcwpoSHQ1bgcrZxFQlbiwYQ8LxMxYicv/5zJCrLWReHHvESvEOSUS/1vbmEBs EQEVieXTnrFDnCwrcWv2JWaQGyQE9rBJTNj2gn0Co/AsJGfPQjh7FpKzFzAyr2IUyk3MzNHN zDPXSywoyEnVS87P3cQICvrpdmI7GB+usjrEKMDBqMTDK3BRL1KINbGsuDL3EKM0B4uSOC// fd1IIYH0xJLU7NTUgtSi+KLSnNTiQ4xMHJxSDYyhtxwjnXdz3Fvx2H/Dz1dqtRW7DvTpXIh+ IrXCYF7K05Dj38TftSx5MLXjf+m17L5QkYkfamvUn/Yf3G8xt+Hq5hNFvw7n5BnPkjxzNrlZ qksoodcl956LrOXvdx/DOnNfyapNiJu16M7uQKG1C6q2tPpn352jxeIvLbcnwCAo6sTjYzNX WdkqsRRnJBpqMRcVJwIAlI/uIlsCAAA=
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprFIsWRmVeSWpSXmKPExsUiON3OQTf7tl6kwfx7LBZfPzewWGxZ1M1i cfhLI4vF/NZlbA4sHkuW/GTyWLzlLaPHm0N9LAHMUVw2Kak5mWWpRfp2CVwZ03e0sRQ8Faj4 uH0newPjfN4uRk4OCQETiTsXvjCC2EICxxglJs7xArF5BQQlfky+x9LFyMHBLCAvcfC8LEiY WUBL4vujVqAwF1D5fCaJd5dvsoEkhAWkJbou3GWFsA0lrjZ0sIH0sgE1HFhjBBLmFNCQ6Grc DlbOIqAqcWHDHhaImbESl//PZYRYayPx4t4jVohzSiT+t7YxgdgiAioSy6c9Y4c4WVbi1uxL zBMYBWYhuXQWwqWzkFy6gJF5FaNAUWpOYqWZXmJBQU6qXnJ+7iZGUJA2FEbtYGxYbnWIUYCD UYmHV+CiXqQQa2JZcWXuIUYJDmYlEd6n14BCvCmJlVWpRfnxRaU5qcWHGKuA7p/ILCWanA+M oLySeEMTEwMTY2MzY2NzE3OqCCuJ815dox0pJJCeWJKanZpakFoEs5yJg1OqgTGqfE31ue2T Dz6OUtZ+V8jX//HV43VnVrGtmdzl/vO81D6Fwt97z58JvGriWX6HZb1e/omZ2kpusx5mr9zo 9KHuJ3tYXOveJIGZq44IcAaVCb/9tKFM+tzNl5MDl34olD46/9zk2tO3NJZx1hnv336mL6hB ZcfnZyaTN38y3h6/5snrqt70JasTlFiKMxINtZiLihMBzCgL5K0CAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/csv0fESJP5PaA2FbX1K4ugOfSUc>
Subject: Re: [babel] [Babel-users]  source sub-tlv
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 15:04:13 -0000

I agree with Juliusz here. I support (3), can live with (1),
and am opposed to (2) and (4). Allocating sub-TLVs for
something that can be solved without is overkill, and I think
wildcard requests are really critical to quickly bootstrap a new node.

David


> On May 31, 2017, at 07:55, Juliusz Chroboczek <jch@irif.fr> wrote:
> 
> Matthieu, could you please write up a new version of the I-D with your
> encoding?  You might want to speak to Gwendoline, since she needs to write
> up her TOS-specific encoding.
> 
>> If we keep this behaviour and mix tos-specific routes, we will have
>> to send 4 wildcard requests to have all routes.  I see two reasonable
>> options:
> 
>>  - only keep (legacy) wildcard requests, and reply with a full dump.
> 
> That's reasonable, although slightly confusing.  (Call that (1).)
> 
>>  - send one request with all sub-TLVs you know but without mandatory
>>    bit, and reply to all options you know about.
> 
> That's not -- it would require allocating a full new set of sub-TLVs.
> Plus I find this confusing.  (Call that (2).)
> 
> There are two other possibilities:
> 
>  3. Send a non-specific wildcard request for non-specific routes,
>     a source-specific wildcard request for source-specific routes, etc.
> 
>  4. Deprecate wildcard requests -- say that they MAY be replied to, but
>     SHOULD NOT be sent by new implementations.
> 
> Now wildcard requests are fairly rare -- they are only used to speed up
> convergence at boot time, as well as by debugging tools (although we have
> no such debugging tools yet -- all debugging tools known to me connect to
> the local socket of a node).  So sending four TLVs in a single unicast
> packet instead of a single TLV is not prohibitive, and is much simpler
> than the alternatives.
> 
> I support (3).  Last time I spoke to him, Toke supported (4).  I am
> opposed to (2).  I can live with (1).
> 
> -- Juliusz
> 
> _______________________________________________
> Babel-users mailing list
> Babel-users@lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/babel-users


From nobody Wed May 31 08:15:25 2017
Return-Path: <dschinazi@apple.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 79714126579 for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:15:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.303
X-Spam-Level: 
X-Spam-Status: No, score=-4.303 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LKPJuFxuN9FP for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:15:22 -0700 (PDT)
Received: from mail-in2.apple.com (mail-out2.apple.com [17.151.62.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87BA312896F for <babel@ietf.org>; Wed, 31 May 2017 08:15:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=apple.com; s=mailout2048s; c=relaxed/simple; q=dns/txt; i=@apple.com; t=1496243722; h=From:Sender:Reply-To:Subject:Date:Message-id:To:Cc:MIME-version:Content-type: Content-transfer-encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-reply-to:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=X5ze7JULD5+8ejnFQhbtk1sOxQpK0HV6l5opa7YTZNY=; b=WjsMBaDSLryNRBSu8AuQXtI/kWfTdxOCWHpVAXdEURPNKE3xjLLoZBa1bwR3oTUT WuC31c3b0IcmcuUUCL2nAePd0QlAoQRVfYgOnCV2KrV30e76Lt+r2eVOUSRCdRni y7kqYOoWAxnfj5kB1RpIxcg2PtG5z6MWVtZ3WgEk2P8p2dPQ6cle3fXhUtRLYiH7 6cY/8V+THqow+I+HiHt51SbPMThzCTnL7nSAF0HWqQS6b2BtssbopslVhQ8RcJrs C8KmjksG7552tPv+0RhFcImx22hdYRduknbYpyz6cPGG9Uhf+9ogUlzuqbPbcuik 6X3vHgnC/q3sWj8Xh1HQkA==;
Received: from relay4.apple.com (relay4.apple.com [17.128.113.87]) (using TLS with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mail-in2.apple.com (Apple Secure Mail Relay) with SMTP id F3.D8.12614.A0EDE295; Wed, 31 May 2017 08:15:22 -0700 (PDT)
X-AuditID: 11973e11-167519a000003146-29-592ede0a4332
Received: from koseret (koseret.apple.com [17.151.62.39]) by relay4.apple.com (Apple SCV relay) with SMTP id 4E.12.02523.90EDE295; Wed, 31 May 2017 08:15:22 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; CHARSET=US-ASCII
Received: from [17.153.76.33] (unknown [17.153.76.33]) by koseret.apple.com (Oracle Communications Messaging Server 8.0.1.2.20170210 64bit (built Feb 10 2017)) with ESMTPSA id <0OQT00C9MP1GJM40@koseret.apple.com>; Wed, 31 May 2017 08:15:21 -0700 (PDT)
Sender: dschinazi@apple.com
From: David Schinazi <dschinazi@apple.com>
In-reply-to: <87r2zdta7c.wl-jch@irif.fr>
Date: Wed, 31 May 2017 08:15:15 -0700
Cc: =?utf-8?Q?Toke_H=C3=B8iland-J=C3=B8rgensen?= <toke@toke.dk>, babel@ietf.org
Message-id: <C2B5E108-96E2-422C-B760-42BA9993852C@apple.com>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87shjus424.fsf@alrua-karlstad> <87wp969tvn.wl-jch@irif.fr> <87o9uhrwin.fsf@alrua-karlstad> <87r2zdta7c.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrCLMWRmVeSWpSXmKPExsUi2FAYrst1Ty/SYNE/YYsti7pZLOa3LmOz 2Pp+BbsDs8eSJT+ZPBZvecvoseXQRbYA5igum5TUnMyy1CJ9uwSujAfXetgKzjNXLD04ja2B 8TVTFyMnh4SAicTz10+AbC4OIYHVTBLr1/axwiSaf25lgUisYpRYuOgEWIJXQFDix+R7QAkO DmYBeYmD52VBwswCWhLfH7VC1TczSbz61sIGkhAWkJbounCXFaReWMBRYsonOxCTDaj+wBoj kApOAQ2Jra/2sYDYLAKqEj/uXGaBGOkvsenlXnaIrTYSj+c/ZoUYf5hJYvLp22AJEQEVieXT nrFD3CwrcWv2JWaQIgmBCWwSd540sExgFJ6F5OxZCGfPQnL2AkbmVYxCuYmZObqZeUZ6iQUF Oal6yfm5mxhBwT7dTnAH4/FVVocYBTgYlXh4d5zTixRiTSwrrsw9xCjNwaIkzst/XzdSSCA9 sSQ1OzW1ILUovqg0J7X4ECMTB6dUA+Ou283CF1PuSnssO8Hm8cxEIu/71gMZu76fbUypspbW Ov2rXnj6EacOxevrT7dWzXbI2V7B9etpobuY4ARF3QWXvk3cVtry0S9G13rt2wABc+3w8+8n /LjeGLBg2U6xbRz7OQPartQv0Jg5j/nH76TNbIW31VimF16YLhc24WOn++MD69f9KbNSYinO SDTUYi4qTgQAdMMl/1cCAAA=
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrOLMWRmVeSWpSXmKPExsUiON1OXZfrnl6kQf8lXosti7pZLOa3LmOz 2Pp+BbsDs8eSJT+ZPBZvecvoseXQRbYA5igum5TUnMyy1CJ9uwSujAfXetgKzjNXLD04ja2B 8TVTFyMnh4SAiUTzz60sXYxcHEICqxglFi46wQqS4BUQlPgx+R5QgoODWUBe4uB5WZAws4CW xPdHrVD1zUwSr761sIEkhAWkJbou3GUFqRcWcJSY8skOxGQDqj+wxgikglNAQ2Lrq30sIDaL gKrEjzuXWSBG+ktsermXHWKrjcTj+Y9ZIcYfZpKYfPo2WEJEQEVi+bRn7BA3y0rcmn2JeQKj wCwkl85CuHQWkksXMDKvYhQoSs1JrDTRSywoyEnVS87P3cQICs6GwvAdjP+WWR1iFOBgVOLh FbioFynEmlhWXJl7iFGCg1lJhPfpNaAQb0piZVVqUX58UWlOavEhRmkOFiVx3itrtCOFBNIT S1KzU1MLUotgskwcnFINjKUngb7rqT1ZePPmNdUVphpvfi96zbDw9fLGosO60Q8+8pSvnFNp /FSMN4f9SGcK6/ou8z6jnlTLxarTnXrU71jH1E6ySE66O5FT9+Zke5vG8iMLJmz7UjM36cKE lZt2cBzexrnrlI5ZI5P0NubEnOsbFHJPHz91Me2EidWKW42WR3kMHilyKbEUZyQaajEXFScC AHNSBoVKAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/8YgMRpYYUgEvHqJQzXQr1fryiac>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 15:15:23 -0000

I'm a little late to the party here, but I think I agree with where the discussion landed,
as in treat NextHop and RouterID like any other TLV, fully ignore it in the
presence of an unknown mandatory sub TLV.

> On May 25, 2017, at 05:03, Juliusz Chroboczek <jch@irif.fr> wrote:
> 
>> I do still think being consistent is better :)
> 
> Consistency is the straightjacket of small minds.

I like my specifications in tight straightjackets :)

David


From nobody Wed May 31 08:29:26 2017
Return-Path: <dschinazi@apple.com>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 038921293E3 for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:29:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.303
X-Spam-Level: 
X-Spam-Status: No, score=-4.303 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5SxpNARR1nyh for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:29:24 -0700 (PDT)
Received: from mail-in4.apple.com (mail-out4.apple.com [17.151.62.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8419F1243F6 for <babel@ietf.org>; Wed, 31 May 2017 08:29:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; d=apple.com; s=mailout2048s; c=relaxed/simple; q=dns/txt; i=@apple.com; t=1496244564; h=From:Sender:Reply-To:Subject:Date:Message-id:To:Cc:MIME-version:Content-type: Content-transfer-encoding:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-reply-to:References:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=X6Y8U9HOKWh9oPti9H8OCfu4ztcUSvCwoJp/kxB9zuM=; b=zaywp+dO6zaG5NwdaXW6Ex+srZVlm+YUGZNKCp0MDWK2fjJYTzOWpr5zLacn9umK 8UERH5qByakR/3upNAUabeNi7fiWEKUbyS07GkqJWtlWGmJHJdZDaDKTavggZ3Sr +2Nrl6tG8pimE/eq/26jdh7MvRXo7ATDNXqs3AcPPeTq6iF757hUy8rlgYDeSg2W 8au54Sj2dbYUbU3hAjB+zIVTwdccsRqFmI72YvgIwmc+6GV44Czbir/hGkTLeDK/ cbb0o7cpq9NOVerrkVCrt6jrWClPfuk8leZcFy0qz5MUSASEfnNujcFJeIVl0bK1 e3nnsl7+bnY37fZT10c3pQ==;
Received: from relay8.apple.com (relay8.apple.com [17.128.113.102]) (using TLS with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mail-in4.apple.com (Apple Secure Mail Relay) with SMTP id 4A.38.01052.451EE295; Wed, 31 May 2017 08:29:24 -0700 (PDT)
X-AuditID: 11973e12-7285e9a00000041c-8e-592ee1548403
Received: from nwk-phonehomebzp-sz01 (nwk-phonehomebzp-sz01.apple.com [17.151.62.64]) by relay8.apple.com (Apple SCV relay) with SMTP id 9E.1C.21490.351EE295; Wed, 31 May 2017 08:29:24 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; CHARSET=US-ASCII
Received: from [17.153.76.33] (unknown [17.153.76.33]) by nwk-phonehomebzp-sz01.apple.com (Oracle Communications Messaging Server 8.0.1.2.20170210 64bit (built Feb 10 2017)) with ESMTPSA id <0OQT00KEEPOXV560@nwk-phonehomebzp-sz01.apple.com>; Wed, 31 May 2017 08:29:23 -0700 (PDT)
Sender: dschinazi@apple.com
From: David Schinazi <dschinazi@apple.com>
In-reply-to: <87h90a9nlz.wl-jch@irif.fr>
Date: Wed, 31 May 2017 08:29:19 -0700
Cc: babel@ietf.org, babel-users@lists.alioth.debian.org
Message-id: <16975D69-DAA5-418D-A345-DBD550EE4DB5@apple.com>
References: <87h90a9nlz.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3273)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrILMWRmVeSWpSXmKPExsUi2FCYphvyUC/S4MxHUYuvnxtYLLYs6max mN+6jM2B2WPJkp9MHou3vGX0eHOojyWAOYrLJiU1J7MstUjfLoEr48fLOcwFU0UqTn14zNTA uEugi5GTQ0LAROLein0sXYxcHEICa5gkZu1dwwyTOL35OytE4hijREPvVzaQBK+AoMSPyfeA Ojg4mAXkJQ6elwUJMwtoSXx/1Ao1aD6TxMeL55lAEsIC0hJdF+6yQtiWEsfOrWED6WUDajiw xggkzCmgIbGtaydYOYuAqsSam6fZIWaaS5y99IYJpJxXwEai+QMziCkkoC5xaXYOSIWIgIrE 8mnP2CEulpW4NfsS1PU72CRevnKewCg8C8nNsxBunoXk5gWMzKsYhXITM3N0M/NM9BILCnJS 9ZLzczcxgsJ8up3QDsZTq6wOMQpwMCrx8Apc1IsUYk0sK67MPcQozcGiJM7Ld183UkggPbEk NTs1tSC1KL6oNCe1+BAjEwenVAOj7buAyVkCbyLP13Of//Br3k2mR565/L6n7jX9sF3E/DJp rn6Vy6w9DF/EGFirS7YoM3X5F17Z71XDI1F7/m7qlPXrlOdenrjvt0Eo35xqRo63b+R5nioF L3u+/+mfsgOsb9Ilt0/3zvcw/H5O6xz3B57tzzI3LHtttIZjziRHo5bn5yZrn10zVYmlOCPR UIu5qDgRAKmVMllUAgAA
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprCIsWRmVeSWpSXmKPExsUiON3OQTfkoV6kwc/17BZfPzewWGxZ1M1i Mb91GZsDs8eSJT+ZPBZvecvo8eZQH0sAcxSXTUpqTmZZapG+XQJXxo+Xc5gLpopUnPrwmKmB cZdAFyMnh4SAicTpzd9Zuxi5OIQEjjFKNPR+ZQNJ8AoISvyYfI+li5GDg1lAXuLgeVmQMLOA lsT3R60sEPXzmSQ+XjzPBJIQFpCW6LpwlxXCtpQ4dm4NG0gvG1DDgTVGIGFOAQ2JbV07wcpZ BFQl1tw8zQ4x01zi7KU3TCDlvAI2Es0fmEFMIQF1iUuzc0AqRARUJJZPe8YOcbGsxK3Zl5gn MArMQnLnLIQ7ZyG5cwEj8ypGgaLUnMRKC73EgoKcVL3k/NxNjKDAbChM28HYtNzqEKMAB6MS D6/ARb1IIdbEsuLK3EOMEhzMSiK8n+4ChXhTEiurUovy44tKc1KLDzFWAV0/kVlKNDkfGDV5 JfGGJiYGJsbGZsbG5ibmVBFWEue9skY7UkggPbEkNTs1tSC1CGY5EwenVAOjg9aEoMwV//6x 8PlyCD7c4x8qomsr82Tqm6npz6yP6RxszvGM/ir22T3tzcw9rHmBlmmu+gx/+w6eXH0xvvpy qJIPz4Vn7m4vpL/uUuDnCPH/+ZpbMOzzxhdXRDjniV7cG1QhcI9F8avD/FtXJ7O9+Wosrzj5 +RHVGdtOOm/n0/Tj3LCxeEmHEktxRqKhFnNRcSIAX2+jLqcCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/twKRRidCwqmk_Cco9asS4GcCDs8>
Subject: Re: [babel] [Babel-users] draft-ietf-babel-rfc6126bis-02
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 15:29:26 -0000

Juliusz,

Thanks for making these edits, they look great.
The only real issue is the handling of NextHop and RouterID
with unknown mandatory sub-TLVs, which was discussed on another thread.

I also think Appendix C (Considerations for protocol extensions)
should be changed now that we have mandatory sub-TLVs.
I'll try to contribute text.

David


> On May 24, 2017, at 10:22, Juliusz Chroboczek <jch@irif.fr> wrote:
> 
> Dear all,
> 
> I've just published a new version of the Babel protocol specification:
> 
>  https://tools.ietf.org/html/draft-ietf-babel-rfc6126bis-02
> 
> This version containts some fairly major changes, the most notable being
> the addition of mandatory bits to the extension subprotocol.  There have
> also been some fairly technical changes to the procedures for sending of
> requests, which should not invalidate any existing implementations.
> 
> The mandatory bit makes the protocol more easily extensible by making it
> possible to explicitly encode the fact that an extension is not backwards
> compatible.  It has greatly simplified the packet format of Matthieu
> Boutier's source-specific extension [1], and is used by Gwendoline
> Chouasne's TOS-specific extension [2].
> 
> [1] https://github.com/boutier/babeld/tree/dev
> [2] https://github.com/Gwendocg/babeldToS
> 
> Both babeld and sbabeld have support for mandatory bits in their
> "mandatory" branches.  I'll wait a few days to see if there are any flaws
> in this proposal, then merge into trunk.  Please consider implementing
> mandatory bits if you have an implementation of Babel.
> 
> The backwards compatibility of this change is reasonably strong, but
> somewhat weaker than what we at Babel Towers have been doing previously.
> More exactly:
> 
>  - new implementations of Babel will interoperate with old
>    implementations as long as the former don't use any extensions that
>    the latter don't understand;
>  - new implementations of Babel that use the new extensions (new-style
>    source-specific routing, TOS-specific routing) will not interoperate
>    with old implementations, and might even create routing loops.
> 
> We will refrain from deploying the new extensions until all implementations
> have acquired support for mandatory bits.
> 
> Please read.  Please think it over.  Please comment.
> 
> -- Juliusz
> 
> _______________________________________________
> Babel-users mailing list
> Babel-users@lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/babel-users


From nobody Wed May 31 08:33:09 2017
Return-Path: <jch@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8063B12EADB for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:33:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xDBoGc4oiK15 for <babel@ietfa.amsl.com>; Wed, 31 May 2017 08:33:06 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 428B012EAB2 for <babel@ietf.org>; Wed, 31 May 2017 08:32:43 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4VFWYr2011860; Wed, 31 May 2017 17:32:34 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id F1DA9EB28B; Wed, 31 May 2017 17:32:33 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id EtrIjT8xBQIN; Wed, 31 May 2017 17:32:32 +0200 (CEST)
Received: from ijon.irif.fr (host18-109-static.224-95-b.business.telecomitalia.it [95.224.109.18]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 6DD1DEB2C1; Wed, 31 May 2017 17:32:32 +0200 (CEST)
Date: Wed, 31 May 2017 17:32:34 +0200
Message-ID: <87tw41hwj1.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: David Schinazi <dschinazi@apple.com>
Cc: Toke =?ISO-8859-1?Q?H=F8iland-J=F8rgensen?= <toke@toke.dk>, babel@ietf.org
In-Reply-To: <C2B5E108-96E2-422C-B760-42BA9993852C@apple.com>
References: <87y3tmbg1e.wl-jch@irif.fr> <87zie2gylh.fsf@alrua-x1> <87h90abbp0.wl-jch@irif.fr> <87efvebb9x.wl-jch@irif.fr> <513D2D6A-E00A-4D46-9762-8D57F0E57B22@iki.fi> <8760gqb9ss.wl-jch@irif.fr> <87shjus424.fsf@alrua-karlstad> <87wp969tvn.wl-jch@irif.fr> <87o9uhrwin.fsf@alrua-karlstad> <87r2zdta7c.wl-jch@irif.fr> <C2B5E108-96E2-422C-B760-42BA9993852C@apple.com>
User-Agent: Wanderlust/2.15.9
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Wed, 31 May 2017 17:32:34 +0200 (CEST)
X-Miltered: at korolev with ID 592EE212.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592EE212.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 592EE212.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/W_-lBQCCs-dVxTnmd3RoqUzFUBk>
Subject: Re: [babel] Mandatory sub-TLVs in Next Hop and Router-ID
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 15:33:07 -0000

> I'm a little late to the party here, but I think I agree with where the
> discussion landed, as in treat NextHop and RouterID like any other TLV,
> fully ignore it in the presence of an unknown mandatory sub TLV.

Er... no.  The conclusion is that Next Hop and Router-ID TLVs are honoured
even if ignored due to an unknown mandatory sub-TLV.

The rationale is that the current next hop and router-id are part of the
parser's state, and that the packet is parsed with no reference to
sub-TLVs.  Only after the packet is parsed are some TLVs dropped.  This
way, the produced parse tree is identical no matter which sub-TLVs are
honoured by a given implementation, which makes it possible to build tools
such as tcpdump that need to parse a packet but don't honour any sub-TLVs.

Folks, please read the relevant sections in -02, and let me know if the
current text is not clear in any way.

-- Juliusz


From nobody Wed May 31 09:22:23 2017
Return-Path: <boutier@irif.fr>
X-Original-To: babel@ietfa.amsl.com
Delivered-To: babel@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F2FED129B7F for <babel@ietfa.amsl.com>; Wed, 31 May 2017 09:22:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qqCUDLjJHFnh for <babel@ietfa.amsl.com>; Wed, 31 May 2017 09:22:21 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CCC86128D6F for <babel@ietf.org>; Wed, 31 May 2017 09:22:20 -0700 (PDT)
Received: from potemkin.univ-paris7.fr (potemkin.univ-paris7.fr [IPv6:2001:660:3301:8000::1:1]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/56228) with ESMTP id v4VGMIqf003426 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 31 May 2017 18:22:18 +0200
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by potemkin.univ-paris7.fr (8.14.4/8.14.4/relay2/56228) with ESMTP id v4VGMIlM002157; Wed, 31 May 2017 18:22:18 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 3D2B1EB207; Wed, 31 May 2017 18:22:18 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id 7QGcQX9QYM9E; Wed, 31 May 2017 18:22:17 +0200 (CEST)
Received: from mac-matthieu.lan (AAubervilliers-652-1-221-49.w83-112.abo.wanadoo.fr [83.112.108.49]) (Authenticated sender: boutier) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 2E1CCEB206; Wed, 31 May 2017 18:22:15 +0200 (CEST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Matthieu Boutier <boutier@irif.fr>
In-Reply-To: <87y3tdhy84.wl-jch@irif.fr>
Date: Wed, 31 May 2017 18:22:14 +0200
Cc: babel-users@lists.alioth.debian.org, babel@ietf.org
Content-Transfer-Encoding: 7bit
Message-Id: <BE6E66D1-DC6E-4E30-99BC-836A911CFCE4@irif.fr>
References: <87h90a9nlz.wl-jch@irif.fr> <70ED4D66-B6BF-4D29-B24F-32A2C6779789@irif.fr> <87y3tdhy84.wl-jch@irif.fr>
To: Juliusz Chroboczek <jch@irif.fr>
X-Mailer: Apple Mail (2.3124)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]); Wed, 31 May 2017 18:22:19 +0200 (CEST)
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (potemkin.univ-paris7.fr [194.254.61.141]); Wed, 31 May 2017 18:22:18 +0200 (CEST)
X-Miltered: at korolev with ID 592EEDBA.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-Miltered: at potemkin with ID 592EEDBA.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 592EEDBA.000 from potemkin.univ-paris7.fr/potemkin.univ-paris7.fr/null/potemkin.univ-paris7.fr/<boutier@irif.fr>
X-j-chkmail-Enveloppe: 592EEDBA.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<boutier@irif.fr>
X-j-chkmail-Score: MSGID : 592EEDBA.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Score: MSGID : 592EEDBA.000 on potemkin.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/babel/Xcd5O4RIg_-O5BF0pXdsR6jpgZM>
Subject: Re: [babel] source sub-tlv
X-BeenThere: babel@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "A list for discussion of the Babel Routing Protocol." <babel.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/babel>, <mailto:babel-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/babel/>
List-Post: <mailto:babel@ietf.org>
List-Help: <mailto:babel-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/babel>, <mailto:babel-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 May 2017 16:22:22 -0000

> That's reasonable, although slightly confusing.  (Call that (1).)


6126 says "send a full dump".  What is confusing about sending a full
dump ? :p

>  3. Send a non-specific wildcard request for non-specific routes,
>     a source-specific wildcard request for source-specific routes, etc.

(I found his one is confusing.)

> I support (3).  Last time I spoke to him, Toke supported (4).  I am
> opposed to (2).  I can live with (1).

I support (1).  I'm not so uncomfortable with (3) because nothing prevent
me to send back a full dump on any wildcard request.

Matthieu

