
From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 16:38:12 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A1723E0680 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 16:38:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.599
X-Spam-Level: 
X-Spam-Status: No, score=-110.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IJxFTWmiYYln for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 16:38:11 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 678A3E066E for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 16:38:08 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id B685414A19F; Thu, 12 May 2011 23:38:03 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 5546914A190 for <ietf-ssh@netbsd.org>; Thu, 12 May 2011 23:37:59 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Authentication-Results: mail.NetBSD.org (amavisd-new); dkim=pass header.i=clonvick@cisco.com
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id nJny2RvsbiNU for <ietf-ssh@netbsd.org>; Thu, 12 May 2011 23:37:58 +0000 (UTC)
Received: from sj-iport-3.cisco.com (sj-iport-3.cisco.com [171.71.176.72]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client CN "sj-iport-3.cisco.com", Issuer "Cisco SSCA" (not verified)) by mail.netbsd.org (Postfix) with ESMTPS id 6AF9714A185 for <ietf-ssh@netbsd.org>; Thu, 12 May 2011 23:37:58 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=clonvick@cisco.com; l=2228; q=dns/txt; s=iport; t=1305243478; x=1306453078; h=date:from:to:subject:message-id:mime-version:content-id; bh=Es/IvbO10IPDq7ZpXbq8yhbi8W+8Ii4q6V51UcvNtvQ=; b=HTl5tNzd2NX0NANYiKg2Scjif0Pg+bqp/tGgA6M3N8VB51/Xa43sS3mW XW8HZEHDcQMANB/ONw3TCbgbUrUl13pCL8tvBnMrmowLMzagw1528BoGy r7Dd4OF1yPrkTse2+pEIOU8fj9UbZN9aj4pvKriFdgeHVrXkgOY9l28gT U=;
X-Files: None : None
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AkQIAFFezE2rRDoJ/2dsb2JhbACXfwEBjXh3qRSBHZ4chhUEhkqYOw
X-IronPort-AV: E=Sophos;i="4.64,360,1301875200";  d="txt'?scan'208";a="314525766"
Received: from mtv-core-4.cisco.com ([171.68.58.9]) by sj-iport-3.cisco.com with ESMTP; 12 May 2011 22:29:46 +0000
Received: from sjc-cde-032.cisco.com (sjc-cde-032.cisco.com [171.69.29.20]) by mtv-core-4.cisco.com (8.14.3/8.14.3) with ESMTP id p4CMTkKc015217 for <ietf-ssh@netbsd.org>; Thu, 12 May 2011 22:29:46 GMT
Date: Thu, 12 May 2011 15:29:46 -0700 (PDT)
From: Chris Lonvick <clonvick@cisco.com>
To: ietf-ssh@netbsd.org
Subject: I-D Action:draft-kwatsen-reverse-ssh-00.txt (fwd)
Message-ID: <Pine.GSO.4.63.1105121528390.11760@sjc-cde-032.cisco.com>
MIME-Version: 1.0
Content-Type: MULTIPART/Mixed; boundary=NextPart
Content-ID: <Pine.GSO.4.63.1105121528391.11760@sjc-cde-032.cisco.com>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--NextPart
Content-Type: TEXT/PLAIN; CHARSET=US-ASCII; format=flowed
Content-ID: <Pine.GSO.4.63.1105121528392.11760@sjc-cde-032.cisco.com>

Hi,

Just forwarding this along.

Thanks,
Chris

---------- Forwarded message ----------
Date: Thu, 12 May 2011 15:15:02 -0700
From: Internet-Drafts@ietf.org
To: i-d-announce@ietf.org
Subject: I-D Action:draft-kwatsen-reverse-ssh-00.txt

A New Internet-Draft is available from the on-line Internet-Drafts directories.

 	Title           : Reverse Secure Shell (Reverse SSH)
 	Author(s)       : K. Watsen
 	Filename        : draft-kwatsen-reverse-ssh-00.txt
 	Pages           : 16
 	Date            : 2011-05-12

This memo presents a technique for a SSH (Secure Shell) server to
initiate the underlying TCP connection to the SSH client.  This role
reversal is necessary in cases where the SSH client would otherwise
be unable to initiate an SSH connection to the SSH server, such as a
device "calling home" on its first boot.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-kwatsen-reverse-ssh-00.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.
--NextPart
Content-Type: MESSAGE/EXTERNAL-BODY; site=ftp.ietf.org; access-type=anon-ftp; directory=internet-drafts; name=draft-kwatsen-reverse-ssh-00.txt
Content-ID: <Pine.GSO.4.63.1105121528393.11760@sjc-cde-032.cisco.com>
Content-Description: 

--NextPart
Content-Type: TEXT/PLAIN; CHARSET=US-ASCII
Content-ID: <Pine.GSO.4.63.1105121528394.11760@sjc-cde-032.cisco.com>
Content-Description: 
Content-Disposition: attachment

_______________________________________________

I-D-Announce mailing list

I-D-Announce@ietf.org

https://www.ietf.org/mailman/listinfo/i-d-announce

Internet-Draft directories: http://www.ietf.org/shadow.html

or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


--NextPart--

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 17:38:06 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E95AE0782 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 17:38:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.91
X-Spam-Level: 
X-Spam-Status: No, score=-104.91 tagged_above=-999 required=5 tests=[AWL=1.689, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qPKNzsBljQrO for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 17:38:06 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 2E75EE0780 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 17:38:06 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id A84F914A217; Fri, 13 May 2011 00:38:02 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 7BA4414A1E5 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:38:00 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id eH6UA2xTv2-l for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:37:59 +0000 (UTC)
Received: from boreas.isi.edu (boreas.isi.edu [128.9.160.161]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id CE91B14A1DA for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:37:59 +0000 (UTC)
Received: from [128.9.160.166] (abc.isi.edu [128.9.160.166]) (authenticated bits=0) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id p4D0baL8008945 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NOT); Thu, 12 May 2011 17:37:36 -0700 (PDT)
Message-ID: <4DCC7D50.9080308@isi.edu>
Date: Thu, 12 May 2011 17:37:36 -0700
From: Joe Touch <touch@isi.edu>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10
MIME-Version: 1.0
To: Kent Watsen <kwatsen@juniper.net>
CC: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net>
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On 5/12/2011 4:31 PM, Kent Watsen wrote:
>
> Since the SECSH working group has concluded, the Security Area Directors, Sean and Stephen, recommended posting an announcement regarding this individual submission to the SAAG and IETF-SSH mailing lists.
>
>
>     http://tools.ietf.org/html/draft-kwatsen-reverse-ssh-00
>
>     Abstract
>
>        This memo presents a technique for a SSH (Secure Shell) server to
>        initiate the underlying TCP connection to the SSH client.  This role
>        reversal is necessary in cases where the SSH client would otherwise
>        be unable to initiate an SSH connection to the SSH server, such as a
>        device "calling home" on its first boot.
>
>
> I come from the NETCONF and NETMOD working groups, and this
> submissionhas been developed primarily to support NETCONF, though
> it's applicable to any SSH-based protocol and actually has little to
> do with NETCONF at all, which is why it is brought here for your
> consideration.
>
> FWIW, Juniper has implemented a variant of this proposal, called "outbound-ssh", on almost all its platforms for nearly 5 years now.  The solution presented in this I-D, being fully transparent to the SSH protocol, has been shown to be easy to implement across various operating systems and programming languages.

Any clue what port they're using for this? There doesn't appear to be 
one currently allocated.

Also, there are separate ports for SSH (22) and netconf over SSH (830) - 
does this mean this proposal would need a reverse port for every 
SSH-based service?

Joe

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 19:08:41 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33CC3130014 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 19:08:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.063
X-Spam-Level: 
X-Spam-Status: No, score=-103.063 tagged_above=-999 required=5 tests=[AWL=-0.464, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YdFsyv636sB9 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 19:08:40 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 6C44DE0593 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 19:08:40 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id C056614A20A; Fri, 13 May 2011 02:08:36 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 6DDDA14A1EC for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:08:34 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id NJeHGbsDRhLL for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:08:33 +0000 (UTC)
Received: from vapor.isi.edu (vapor.isi.edu [128.9.64.64]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id BE5C414A1BD for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:08:33 +0000 (UTC)
Received: from [128.9.160.166] (abc.isi.edu [128.9.160.166]) (authenticated bits=0) by vapor.isi.edu (8.13.8/8.13.8) with ESMTP id p4D17C6t014670 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NOT); Thu, 12 May 2011 18:07:12 -0700 (PDT)
Message-ID: <4DCC8440.80109@isi.edu>
Date: Thu, 12 May 2011 18:07:12 -0700
From: Joe Touch <touch@isi.edu>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10
MIME-Version: 1.0
To: Kent Watsen <kwatsen@juniper.net>
CC: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net>
In-Reply-To: <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On 5/12/2011 6:01 PM, Kent Watsen wrote:
>
>> Any clue what port they're using for this? There doesn't appear to be
>> one currently allocated.
>
> Juniper is using port 7104, I think, but there is no need to
> maintain that compatibility since the message format presented in
> this submission is not backward compatible with their's. For
> instance, Juniper's existing format only supports one host-key,
> whereas this this proposal supports all the host-keys the SSH server
> has.

Understood; I was asking because it sounded like Juniper was using a 
port they hadn't registered ;-( That should be fixed...

>> Also, there are separate ports for SSH (22) and netconf over SSH
>> (830) - does this mean this proposal would need a reverse port for
>> every SSH-based service?
>
> No, this submission only asks IANA to assign a single port, to
> bootstrap the SSH protocol. Once the SSH session is up, the SSH client
> can open any number of SSH channels for tty, sftp, netconf,
> port-forwarding, etc.

Netconf over ssh uses a different port, as noted above.

> This solution is NOT expected to work with a standard 'ssh' client.
> The reason for why the SSH server has been configure to connect to the
> SSH client is domain specific. The expectation is that a custom
> application is developed (using standard SSH client libraries) for the
> purpose.

What's the reason for not solving this by having the client just listen 
on the SSH server port?

Joe

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 21:21:37 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 19EF8E07B3 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:21:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qxOc1Z9T0d1I for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:21:36 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 6946CE0681 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 21:21:36 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 004BF14A209; Fri, 13 May 2011 04:21:32 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id A984314A1FD; Fri, 13 May 2011 04:21:32 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 316C314A20E for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:58:36 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id i928PrQ3DXra for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:58:35 +0000 (UTC)
Received: from exprod7og113.obsmtp.com (exprod7og113.obsmtp.com [64.18.2.179]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 6E02314A109 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 00:58:35 +0000 (UTC)
Received: from P-EMHUB02-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob113.postini.com ([64.18.6.12]) with SMTP ID DSNKTcyCOx3Zz1P/QaaZXjuhBJT9bLpz1J0C@postini.com; Thu, 12 May 2011 17:58:35 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB02-HQ.jnpr.net ([fe80::88f9:77fd:dfc:4d51%11]) with mapi; Thu, 12 May 2011 16:31:04 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Date: Thu, 12 May 2011 16:31:02 -0700
Subject: draft-kwatsen-reverse-ssh submission for review
Thread-Topic: draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwQ/KfZsPkIbzpDSPSTwl+b7uFoaA==
Message-ID: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

Since the SECSH working group has concluded, the Security Area Directors, S=
ean and Stephen, recommended posting an announcement regarding this individ=
ual submission to the SAAG and IETF-SSH mailing lists. =20


   http://tools.ietf.org/html/draft-kwatsen-reverse-ssh-00

   Abstract

      This memo presents a technique for a SSH (Secure Shell) server to
      initiate the underlying TCP connection to the SSH client.  This role
      reversal is necessary in cases where the SSH client would otherwise
      be unable to initiate an SSH connection to the SSH server, such as a
      device "calling home" on its first boot.


I come from the NETCONF and NETMOD working groups, and this submission has =
been developed primarily to support NETCONF, though it's applicable to any =
SSH-based protocol and actually has little to do with NETCONF at all, which=
 is why it is brought here for your consideration.

FWIW, Juniper has implemented a variant of this proposal, called "outbound-=
ssh", on almost all its platforms for nearly 5 years now.  The solution pre=
sented in this I-D, being fully transparent to the SSH protocol, has been s=
hown to be easy to implement across various operating systems and programmi=
ng languages.


PS: I just subscribed to both the SAAG and IETF-SSH lists - cheers!

Thanks,
Kent

--
Kent Watsen
JSBU/DBU Architect
Juniper Networks


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 21:25:18 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 60887E06B1 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:25:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BiVpSnvbXO-g for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:25:18 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 89641E068D for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 21:25:17 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id BFB3714A0D5; Fri, 13 May 2011 04:25:06 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 67BE914A0CA; Fri, 13 May 2011 04:25:06 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id AF5C514A20D for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:53:19 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id dsCCPUQuEw7P for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:53:19 +0000 (UTC)
Received: from exprod7og127.obsmtp.com (exprod7og127.obsmtp.com [64.18.2.210]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id DA9F114A1B9 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 02:53:18 +0000 (UTC)
Received: from P-EMHUB02-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob127.postini.com ([64.18.6.12]) with SMTP ID DSNKTcydE00i1VWPqxT1Et5NAn96BmSRl2xW@postini.com; Thu, 12 May 2011 19:53:18 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB02-HQ.jnpr.net ([fe80::88f9:77fd:dfc:4d51%11]) with mapi; Thu, 12 May 2011 19:49:56 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Joe Touch <touch@isi.edu>
CC: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Date: Thu, 12 May 2011 19:49:53 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRCim4y3Ua8se1RJOAkdje3gnNLQABzrWA
Message-ID: <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu>
In-Reply-To: <4DCC8440.80109@isi.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

PiBVbmRlcnN0b29kOyBJIHdhcyBhc2tpbmcgYmVjYXVzZSBpdCBzb3VuZGVkIGxpa2UgSnVuaXBl
ciB3YXMgdXNpbmcgDQo+IGEgcG9ydCB0aGV5IGhhZG4ndCByZWdpc3RlcmVkIDstKCBUaGF0IHNo
b3VsZCBiZSBmaXhlZC4uLg0KDQpJbmRlZWQsIGFuZCB0aGF0IGlzIGV4YWN0bHkgd2hhdCB3ZSdy
ZSB0cnlpbmcgdG8gZG8gd2l0aCB0aGlzIHN1Ym1pc3Npb24uICBPdXIgcHJldmlvdXMgYXR0ZW1w
dCB0byBoYXZlIElBTkEgYXNzaWduIGEgcG9ydCBmb3IgdGhpcyBlbmRlZCB3aXRoIHRoZWlyIHJl
Y29tbWVuZGF0aW9uIHRvIGJyaW5nIGl0IHRvIElFVEYgZm9yIHN0YW5kYXJkaXphdGlvbi4gIEl0
J3MgdGFrZW4gYXdoaWxlLCBidXQgaGVyZSB3ZSBhcmUuDQoNCg0KDQo+IE5ldGNvbmYgb3ZlciBz
c2ggdXNlcyBhIGRpZmZlcmVudCBwb3J0LCBhcyBub3RlZCBhYm92ZS4NCg0KVGhlIG5lZWQgZm9y
IHRoZSBwb3J0IDgzMCBhc3NpZ25tZW50IHdhcyBvbmx5IHRvIGZhY2lsaXRhdGUgZmlsdGVyaW5n
LiAgQXMgUkZDIDQ3NDIgc2F5czoNCg0KICAgSW4gb3JkZXIgdG8gYWxsb3cgTkVUQ09ORiB0cmFm
ZmljIHRvIGJlIGVhc2lseSBpZGVudGlmaWVkIGFuZA0KICAgZmlsdGVyZWQgYnkgZmlyZXdhbGxz
IGFuZCBvdGhlciBuZXR3b3JrIGRldmljZXMsIE5FVENPTkYgc2VydmVycyBNVVNUDQogICBkZWZh
dWx0IHRvIHByb3ZpZGluZyBhY2Nlc3MgdG8gdGhlICJuZXRjb25mIiBTU0ggc3Vic3lzdGVtIG9u
bHkgd2hlbg0KICAgdGhlIFNTSCBzZXNzaW9uIGlzIGVzdGFibGlzaGVkIHVzaW5nIHRoZSBJQU5B
LWFzc2lnbmVkIFRDUCBwb3J0DQogICA8ODMwPi4gIFNlcnZlcnMgU0hPVUxEIGJlIGNvbmZpZ3Vy
YWJsZSB0byBhbGxvdyBhY2Nlc3MgdG8gdGhlIG5ldGNvbmYNCiAgIFNTSCBzdWJzeXN0ZW0gb3Zl
ciBvdGhlciBwb3J0cy4NCg0KSSBzdXBwb3NlIElFVEYgbWF5IGZlZWwgYSBzaW1pbGFyIG5lZWQg
dG8gZmFjaWxpdGF0ZSBmaWx0ZXJpbmcgb24gYSBwZXIgU1NILWJhc2VkIHNlcnZpY2UsIGJ1dCBJ
IHdvdWxkbid0IHJlY29tbWVuZCB0aGlzIGFzIHBvcnQtYmFzZWQgZmlsdGVyaW5nIGlzIG5vIGxv
bmdlciBwcmFjdGljYWwgKGUuZy4gY29uc2lkZXIgdGhlIG51bWJlciBvZiBIVFRQLWJhc2VkIHBy
b3RvY29scykuICBBcHBsaWNhdGlvbi1iYXNlZCBmaXJld2FsbHMgd2l0aCBkZWVwLWluc3BlY3Rp
b24gY2FwYWJpbGl0eSBhcmUgbmVlZGVkIHRoZXNlIGRheXMuICBJbiBlaXRoZXIgY2FzZSwgdG8g
dGhlIG9yaWdpbmFsIHF1ZXN0aW9uLCB0aGVyZSBpc27igJl0IGEgKm5lZWQqIGZvciBtb3JlIHRo
YW4gb25lIElBTkEgYXNzaWduZWQgcG9ydCwgc2luY2UgU1NIIGFscmVhZHkgaGFzIGEgbWVjaGFu
aXNtIGJ1aWx0IGludG8gaXQgZm9yIHRoZSBjbGllbnQgdG8gc2VsZWN0IHdoaWNoIHByb3RvY29s
L3N1YnN5c3RlbSB0byBydW4gb24gYSBjaGFubmVsLg0KDQoNCg0KPiBXaGF0J3MgdGhlIHJlYXNv
biBmb3Igbm90IHNvbHZpbmcgdGhpcyBieSBoYXZpbmcgdGhlIGNsaWVudCBqdXN0IGxpc3RlbiAN
Cj4gb24gdGhlIFNTSCBzZXJ2ZXIgcG9ydD8NCg0KQmVjYXVzZSB0aGVuIGl0IHdvdWxkIGJlIGV4
cGVjdGVkIHRvIGJlIHRoZSBTU0ggc2VydmVyLiAgQXMgZGlzY3Vzc2VkIGluIHRoZSBJbnRyb2R1
Y3Rpb24sIGEgZ29hbCBvZiB0aGlzIGRyYWZ0IGlzIHRvIGVuc3VyZSB0aGUgZGV2aWNlIGlzIGFs
d2F5cyB0aGUgU1NIIHNlcnZlciBhbmQgdGhlIGFwcGxpY2F0aW9uIGlzIGFsd2F5cyB0aGUgU1NI
IGNsaWVudC4gIFdlIGRvbid0IHdhbnQgdG8gZGlzdHVyYiB3aGljaCBwZWVyIGlzIHdoaWNoIGFz
IGZhciBhcyB0aGUgU1NIIFRyYW5zcG9ydCwgQXV0aGVudGljYXRpb24sIGFuZCBDb25uZWN0aW9u
IHByb3RvY29scyBhcmUgY29uY2VybmVkLg0KDQoNClRoYW5rcywNCktlbnQNCg0KDQo=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 21:29:56 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C91A713001B for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:29:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LHNEYhvcTNaW for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 21:29:56 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id BCB8A13001A for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 21:29:55 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 95EEF14A21A; Fri, 13 May 2011 04:29:54 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 48E1A14A212; Fri, 13 May 2011 04:29:54 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 5975C14A20E for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 01:01:38 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id mNzarZe6hWCL for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 01:01:37 +0000 (UTC)
Received: from exprod7og125.obsmtp.com (exprod7og125.obsmtp.com [64.18.2.28]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 96CEB14A1EB for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 01:01:37 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob125.postini.com ([64.18.6.12]) with SMTP ID DSNKTcyC5kR2kT/ryRa88eYyj8KoUViB+Kmf@postini.com; Thu, 12 May 2011 18:01:37 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB01-HQ.jnpr.net ([fe80::fc92:eb1:759:2c72%11]) with mapi; Thu, 12 May 2011 18:01:08 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Joe Touch <touch@isi.edu>
CC: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Date: Thu, 12 May 2011 18:01:03 -0700
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRCT2XJ6PSpkunTnGaX8Meag/D4g==
Message-ID: <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu>
In-Reply-To: <4DCC7D50.9080308@isi.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

DQoNCkFueSBjbHVlIHdoYXQgcG9ydCB0aGV5J3JlIHVzaW5nIGZvciB0aGlzPyBUaGVyZSBkb2Vz
bid0IGFwcGVhciB0byBiZQ0Kb25lIGN1cnJlbnRseSBhbGxvY2F0ZWQuDQoNCkp1bmlwZXIgaXMg
dXNpbmcgcG9ydCA3MTA0LCBJIHRoaW5rLCBidXQgdGhlcmUgaXMgbm8gbmVlZCB0byBtYWludGFp
biB0aGF0IGNvbXBhdGliaWxpdHkgc2luY2UgdGhlIG1lc3NhZ2UgZm9ybWF0IHByZXNlbnRlZCBp
biB0aGlzIHN1Ym1pc3Npb24gaXMgbm90IGJhY2t3YXJkIGNvbXBhdGlibGUgd2l0aCB0aGVpcidz
LiAgRm9yIGluc3RhbmNlLCBKdW5pcGVyJ3MgZXhpc3RpbmcgZm9ybWF0IG9ubHkgc3VwcG9ydHMg
b25lIGhvc3Qta2V5LCB3aGVyZWFzIHRoaXMgdGhpcyBwcm9wb3NhbCBzdXBwb3J0cyBhbGwgdGhl
IGhvc3Qta2V5cyB0aGUgU1NIIHNlcnZlciBoYXMuDQoNCg0KQWxzbywgdGhlcmUgYXJlIHNlcGFy
YXRlIHBvcnRzIGZvciBTU0ggKDIyKSBhbmQgbmV0Y29uZiBvdmVyIFNTSCAoODMwKSAtDQpkb2Vz
IHRoaXMgbWVhbiB0aGlzIHByb3Bvc2FsIHdvdWxkIG5lZWQgYSByZXZlcnNlIHBvcnQgZm9yIGV2
ZXJ5DQpTU0gtYmFzZWQgc2VydmljZT8NCg0KTm8sIHRoaXMgc3VibWlzc2lvbiBvbmx5IGFza3Mg
SUFOQSB0byBhc3NpZ24gYSBzaW5nbGUgcG9ydCwgdG8gYm9vdHN0cmFwIHRoZSBTU0ggcHJvdG9j
b2wuICBPbmNlIHRoZSBTU0ggc2Vzc2lvbiBpcyB1cCwgdGhlIFNTSCBjbGllbnQgY2FuIG9wZW4g
YW55IG51bWJlciBvZiBTU0ggY2hhbm5lbHMgZm9yIHR0eSwgc2Z0cCwgbmV0Y29uZiwgcG9ydC1m
b3J3YXJkaW5nLCBldGMuDQoNClRoaXMgc29sdXRpb24gaXMgTk9UIGV4cGVjdGVkIHRvIHdvcmsg
d2l0aCBhIHN0YW5kYXJkICdzc2gnIGNsaWVudC4gIFRoZSByZWFzb24gZm9yIHdoeSB0aGUgU1NI
IHNlcnZlciBoYXMgYmVlbiBjb25maWd1cmUgdG8gY29ubmVjdCB0byB0aGUgU1NIIGNsaWVudCBp
cyBkb21haW4gc3BlY2lmaWMuICBUaGUgZXhwZWN0YXRpb24gaXMgdGhhdCBhIGN1c3RvbSBhcHBs
aWNhdGlvbiBpcyBkZXZlbG9wZWQgKHVzaW5nIHN0YW5kYXJkIFNTSCBjbGllbnQgbGlicmFyaWVz
KSBmb3IgdGhlIHB1cnBvc2UuDQoNClRoYW5rcywNCktlbnQNCg==

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Thu May 12 23:58:12 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F9E6E06F3 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 23:58:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.249
X-Spam-Level: 
X-Spam-Status: No, score=-103.249 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d-JFS1q7jovS for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Thu, 12 May 2011 23:58:11 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id B9A8AE06F2 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Thu, 12 May 2011 23:58:06 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 6350714A1E3; Fri, 13 May 2011 06:58:03 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 0D28714A1DB; Fri, 13 May 2011 06:58:03 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 60D8B14A1E9 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 05:37:36 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id eHMfHTpAdSQw for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 05:37:35 +0000 (UTC)
Received: from hermes.jacobs-university.de (hermes.jacobs-university.de [212.201.44.23]) by mail.netbsd.org (Postfix) with ESMTP id 8AD2714A1DF for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 05:37:35 +0000 (UTC)
Received: from localhost (demetrius2.jacobs-university.de [212.201.44.47]) by hermes.jacobs-university.de (Postfix) with ESMTP id 4EF1F20BFD; Fri, 13 May 2011 06:33:37 +0200 (CEST)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from hermes.jacobs-university.de ([212.201.44.23]) by localhost (demetrius2.jacobs-university.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id mtw-QpJiLJ6V; Fri, 13 May 2011 06:33:36 +0200 (CEST)
Received: from elstar.local (elstar.jacobs.jacobs-university.de [10.50.231.133]) by hermes.jacobs-university.de (Postfix) with ESMTP id 968BD20BFC; Fri, 13 May 2011 06:33:35 +0200 (CEST)
Received: by elstar.local (Postfix, from userid 501) id 930D11876F04; Fri, 13 May 2011 06:33:34 +0200 (CEST)
Date: Fri, 13 May 2011 06:33:34 +0200
From: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
To: Kent Watsen <kwatsen@juniper.net>
Cc: Joe Touch <touch@isi.edu>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Message-ID: <20110513043334.GA5184@elstar.local>
Reply-To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
Mail-Followup-To: Kent Watsen <kwatsen@juniper.net>, Joe Touch <touch@isi.edu>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
User-Agent: Mutt/1.5.21 (2010-09-15)
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On Thu, May 12, 2011 at 07:49:53PM -0700, Kent Watsen wrote:
 
> The need for the port 830 assignment was only to facilitate filtering.  As RFC 4742 says:
> 
>    In order to allow NETCONF traffic to be easily identified and
>    filtered by firewalls and other network devices, NETCONF servers MUST
>    default to providing access to the "netconf" SSH subsystem only when
>    the SSH session is established using the IANA-assigned TCP port
>    <830>.  Servers SHOULD be configurable to allow access to the netconf
>    SSH subsystem over other ports.
> 
> I suppose IETF may feel a similar need to facilitate filtering on a per SSH-based service, but I wouldn't recommend this as port-based filtering is no longer practical (e.g. consider the number of HTTP-based protocols).  Application-based firewalls with deep-inspection capability are needed these days.  In either case, to the original question, there isn’t a *need* for more than one IANA assigned port, since SSH already has a mechanism built into it for the client to select which protocol/subsystem to run on a channel.
> 

The subsystem is selected through the encrypted channel, something
difficult to filter on.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1, 28759 Bremen, Germany
Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 02:46:31 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 934D9E074C for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 02:46:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6fAAO27pgyJC for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 02:46:31 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id BAA97E0731 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 02:46:30 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 24C1414A12D; Fri, 13 May 2011 09:46:24 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 0E19914A120 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 09:46:21 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id F4JpSHOzFSPh for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 09:46:20 +0000 (UTC)
Received: from mail.btconnect.com (c2bthomr11.btconnect.com [213.123.20.129]) by mail.netbsd.org (Postfix) with ESMTP id 02B6F14A0E1 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 09:46:19 +0000 (UTC)
Received: from mail.btconnect.com (c2bthomr09.ncs.ibs-infra.bt.com [10.87.69.230]) by c2bthomr11.btconnect.com (MOS 3.10.10a-GA) with ESMTP id ACZ72302; Fri, 13 May 2011 09:39:38 +0100 (BST)
Received: from host217-43-155-221.range217-43.btcentralplus.com (HELO pc6) ([217.43.155.221]) by c2bthomr09.btconnect.com with SMTP id CWM22165; Fri, 13 May 2011 09:18:10 +0100 (BST)
Message-ID: <012b01cc113d$b72da180$4001a8c0@gateway.2wire.net>
From: "t.petch" <ietfc@btconnect.com>
To: "Kent Watsen" <kwatsen@juniper.net>, "Joe Touch" <touch@isi.edu>
Cc: <saag@ietf.org>, <ietf-ssh@NetBSD.org>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Date: Fri, 13 May 2011 09:16:40 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Mirapoint-IP-Reputation: reputation=Fair-1, source=Queried, refid=tid=0001.0A0B0302.4DCCE941.0072, actions=tag
X-Junkmail-Premium-Raw: score=9/50, refid=2.7.2:2011.5.13.73916:17:9.535, ip=217.43.155.221, rules=__HAS_MSGID, __OUTLOOK_MSGID_1, __SANE_MSGID, __TO_MALFORMED_2, __BOUNCE_CHALLENGE_SUBJ, __BOUNCE_NDR_SUBJ_EXEMPT, __MIME_VERSION, __CT, __CT_TEXT_PLAIN, __CTE, __HAS_X_PRIORITY, __HAS_MSMAIL_PRI, __HAS_X_MAILER, USER_AGENT_OE, __OUTLOOK_MUA_1, __USER_AGENT_MS_GENERIC, TO_IN_SUBJECT, __ANY_URI, __URI_NO_WWW, __URI_NO_PATH, BODY_SIZE_1100_1199, BODYTEXTP_SIZE_3000_LESS, __MIME_TEXT_ONLY, RDNS_GENERIC_POOLED, BODY_SIZE_5000_LESS, RDNS_SUSP_GENERIC, __OUTLOOK_MUA, RDNS_SUSP, BODY_SIZE_2000_LESS, BODY_SIZE_7000_LESS
X-Junkmail-Status: score=10/50, host=c2bthomr09.btconnect.com
X-Junkmail-Signature-Raw: score=unknown, refid=str=0001.0A0B0207.4DCCE942.021D,ss=1,fgs=0, ip=0.0.0.0, so=2010-07-22 22:03:31, dmn=2009-09-10 00:05:08, mode=multiengine
X-Junkmail-IWF: false
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

----- Original Message -----
From: "Kent Watsen" <kwatsen@juniper.net>
To: "Joe Touch" <touch@isi.edu>
Cc: <saag@ietf.org>; <ietf-ssh@NetBSD.org>
Sent: Friday, May 13, 2011 4:49 AM

> > What's the reason for not solving this by having the client just listen
> > on the SSH server port?
>
> Because then it would be expected to be the SSH server.  As discussed in the
Introduction, a goal of this draft is to ensure the device is always the SSH
server and the application is always the SSH client.  We don't want to disturb
which peer is which as far as the SSH Transport, Authentication, and Connection
protocols are concerned.
>

I do :-)

SSH does not authenticate the user or the application, it authenticates SSH.

The proper solution is channel binding in which case it does not matter who
is SSH client and who is SSH server, and the existing SSH technology can
be reused unaltered.

Incidentally, I think that this discussion needs a home, be it ietf-ssh or
whatever;
having more than one makes a mess of mailing lists.

Tom Petch

>
> Thanks,
> Kent
>
>
>


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 09:03:02 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 42912E069B for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 09:03:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FL3HasWmeLUQ for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 09:03:01 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 8ADE4E0685 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 09:03:01 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 2280D14A0FE; Fri, 13 May 2011 16:02:58 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id DCEDD14A0FB for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:02:55 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id wOconJlVGqJs for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:02:55 +0000 (UTC)
Received: from nitro.isi.edu (nitro.isi.edu [128.9.208.207]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id DED1014A0EF for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:02:54 +0000 (UTC)
Received: from [192.168.1.93] (pool-71-105-81-169.lsanca.dsl-w.verizon.net [71.105.81.169]) (authenticated bits=0) by nitro.isi.edu (8.13.8/8.13.8) with ESMTP id p4DF2DH4024676 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NOT); Fri, 13 May 2011 08:02:23 -0700 (PDT)
Message-ID: <4DCD47F5.5000102@isi.edu>
Date: Fri, 13 May 2011 08:02:13 -0700
From: Joe Touch <touch@isi.edu>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10
MIME-Version: 1.0
To: Kent Watsen <kwatsen@juniper.net>
CC: "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-MailScanner-ID: p4DF2DH4024676
X-ISI-4-69-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On 5/12/2011 7:49 PM, Kent Watsen wrote:
>> Understood; I was asking because it sounded like Juniper was using
>> a port they hadn't registered ;-( That should be fixed...
>
> Indeed, and that is exactly what we're trying to do with this
> submission. Our previous attempt to have IANA assign a port for this
> ended with their recommendation to bring it to IETF for standardization.
> It's taken awhile, but here we are.

Sure. In the meantime, Juniper shouldn't be using an unassigned port
number in a public distribution, though. ;-)

>> Netconf over ssh uses a different port, as noted above.
>
> The need for the port 830 assignment was only to facilitate filtering.

Yes. And will the need for a reverse port create a similar need for 
every such current SSH-based port assignment to have a corresponding 
reverse-channel port assignment? That would be undesirable...

>> What's the reason for not solving this by having the client just listen
>> on the SSH server port?
>
> Because then it would be expected to be the SSH server.

Well, seems to me that if the server is initiating the connection, then 
it *is* a server (where I define server as "host that listens on a 
registered port").

The particular roles of who checks what certificate should be negotiated 
in-band, IMO.

Joe

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 09:58:52 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AAD08E0823 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 09:58:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.988
X-Spam-Level: 
X-Spam-Status: No, score=-9.988 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_MISMATCH_ORG=0.611, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NQ061-POgu6v for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 09:58:52 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 4968FE07E4 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 09:58:52 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 6D69E14A10F; Fri, 13 May 2011 16:58:48 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 1742114A105 for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 16:58:47 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id brFN0QlUsXdJ for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 16:58:46 +0000 (UTC)
Received: from Sparkle.Rodents-Montreal.ORG (Sparkle.Rodents-Montreal.ORG [216.46.5.7]) by mail.netbsd.org (Postfix) with ESMTP id 0A23C14A0F6 for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 16:58:45 +0000 (UTC)
Received: (from mouse@localhost) by Sparkle.Rodents-Montreal.ORG (8.8.8/8.8.8) id MAA01162; Fri, 13 May 2011 12:58:45 -0400 (EDT)
Date: Fri, 13 May 2011 12:58:45 -0400 (EDT)
From: der Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <201105131658.MAA01162@Sparkle.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
X-Composition-Start-Date: Fri, 13 May 2011 12:56:41 -0400 (EDT)
To: saag@ietf.org, ietf-ssh@netbsd.org
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7E4A75AB@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <20110513043334.GA5184@elstar.local> <84600D05C20FF943918238042D7670FD3E7E4A75AB@EMBX01-HQ.jnpr.net>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> PS: Per Tom's comment, I've BCC-ed the "ietf-ssh" list to bring this
> discussion to one list.  I'm choosing the SAAG list primarily because
> it is an official IETF list.  Hope this is OK with all.

For what it may be worth, I'd say the SSH list is better for discussing
the technical aspects of the draft as it relates to SSH; the SAAG list
(or maybe even some other IETF list; I hardly know them all) is perhaps
better for discussing meta-issues such as what ports to use.

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 10:07:31 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3F74EE07DF for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 10:07:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YZW0DnZJQi4T for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 10:07:31 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id ACD45E07DC for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 10:07:30 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 497C114A115; Fri, 13 May 2011 17:07:27 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 54B4714A113 for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 17:07:24 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id td1aC467hFHM for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 17:07:23 +0000 (UTC)
Received: from exprod7og127.obsmtp.com (exprod7og127.obsmtp.com [64.18.2.210]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 1C1B914A0FC for <ietf-ssh@netbsd.org>; Fri, 13 May 2011 17:07:22 +0000 (UTC)
Received: from P-EMHUB03-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob127.postini.com ([64.18.6.12]) with SMTP ID DSNKTc1k7k6THTK/ePKUiOpp9+raBerpHMD3@postini.com; Fri, 13 May 2011 10:07:23 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB03-HQ.jnpr.net ([::1]) with mapi; Fri, 13 May 2011 10:04:15 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: der Mouse <mouse@Rodents-Montreal.ORG>, "saag@ietf.org" <saag@ietf.org>, "ietf-ssh@netbsd.org" <ietf-ssh@netbsd.org>
Date: Fri, 13 May 2011 10:04:13 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRjwmhxRUHtWr4Q46puHQnnZBBfgAAEV9Q
Message-ID: <84600D05C20FF943918238042D7670FD3E7E4A7612@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net>	<4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <20110513043334.GA5184@elstar.local> <84600D05C20FF943918238042D7670FD3E7E4A75AB@EMBX01-HQ.jnpr.net> <201105131658.MAA01162@Sparkle.Rodents-Montreal.ORG>
In-Reply-To: <201105131658.MAA01162@Sparkle.Rodents-Montreal.ORG>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

OK, then let's flip it the other way - sorry about that

Anyone responding to my last email, please put ietf-ssh back into the "To" =
line and BCC saag

Mea culpa!


-----Original Message-----
From: saag-bounces@ietf.org [mailto:saag-bounces@ietf.org] On Behalf Of der=
 Mouse
Sent: Friday, May 13, 2011 12:59 PM
To: saag@ietf.org; ietf-ssh@netbsd.org
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review

> PS: Per Tom's comment, I've BCC-ed the "ietf-ssh" list to bring this
> discussion to one list.  I'm choosing the SAAG list primarily because
> it is an official IETF list.  Hope this is OK with all.

For what it may be worth, I'd say the SSH list is better for discussing
the technical aspects of the draft as it relates to SSH; the SAAG list
(or maybe even some other IETF list; I hardly know them all) is perhaps
better for discussing meta-issues such as what ports to use.

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B
_______________________________________________
saag mailing list
saag@ietf.org
https://www.ietf.org/mailman/listinfo/saag

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 11:19:05 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC5A7E07EF for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 11:19:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DIAhOxUoDvKN for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 11:19:05 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 2D7A9E07EC for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 11:19:05 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 760FD14A146; Fri, 13 May 2011 18:19:01 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 5900E14A145 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 18:18:59 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id HJ80LgjXj9js for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 18:18:58 +0000 (UTC)
Received: from exprod7og127.obsmtp.com (exprod7og127.obsmtp.com [64.18.2.210]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 2BE4614A144 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 18:18:57 +0000 (UTC)
Received: from P-EMHUB03-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob127.postini.com ([64.18.6.12]) with SMTP ID DSNKTc12BZ2URQsrd7ja+GKUfZToT6P0DFb4@postini.com; Fri, 13 May 2011 11:18:58 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB03-HQ.jnpr.net ([::1]) with mapi; Fri, 13 May 2011 11:17:52 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Derek Fawcus <dfawcus@cisco.com>, t.petch <ietfc@btconnect.com>
CC: Joe Touch <touch@isi.edu>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>
Date: Fri, 13 May 2011 11:17:49 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRVTyRWuh7ROWERNqZgHBi+PGf5AAMeFXw
Message-ID: <84600D05C20FF943918238042D7670FD3E7E4A776F@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <012b01cc113d$b72da180$4001a8c0@gateway.2wire.net> <20110513100446.GB11309@gpk-lds-007.cisco.com>
In-Reply-To: <20110513100446.GB11309@gpk-lds-007.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> dfawcus@cisco.com writes:=20
>
> The ssh protocols are largely symmetrical,  as I recall it should be poss=
ible
> to flip roles once transport has completed,  but before userauth or conne=
ction
> are started.

If the application (using nomenclature from the draft) logs into the device=
 via userauth, then it follows that the device has to be the peer that pres=
ents its host-key during the diffie-helman key exchange.  Thus the role-fli=
p has to occur either before the transport protocol begins, as proposed by =
this draft, or at the very beginning of the transport protocol (i.e. tap in=
to the reserved uint32 in the SSH_MSG_KEXINIT message). =20

Whether the roles are negotiated in-band or flipped prior to the start of t=
he SSH protocol, the goal is for the device to always be the SSH server and=
 the application to always be the SSH client.


PS: BCC-ing SAAG list, per der Mouse's suggestion

Thanks,
Kent


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 14:02:38 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 25BDFE0880 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 14:02:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.583
X-Spam-Level: 
X-Spam-Status: No, score=-102.583 tagged_above=-999 required=5 tests=[AWL=0.016, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sCPJ1iDurbvA for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 14:02:38 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 90130E0857 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 14:02:37 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 7382014A166; Fri, 13 May 2011 21:02:34 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 214E514A160 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 21:02:29 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id qW820V6I+iJC for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 21:02:28 +0000 (UTC)
Received: from hoffman.proper.com (IPv6.Hoffman.Proper.COM [IPv6:2001:4870:a30c:41::81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 6637314A15B for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 21:02:27 +0000 (UTC)
Received: from [10.20.30.150] (75-101-30-90.dsl.dynamic.sonic.net [75.101.30.90]) (authenticated bits=0) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id p4DL2Dwk069534 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Fri, 13 May 2011 14:02:13 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: text/plain; charset=us-ascii
From: Paul Hoffman <paul.hoffman@vpnc.org>
In-Reply-To: <4DCD47F5.5000102@isi.edu>
Date: Fri, 13 May 2011 14:02:13 -0700
Cc: Kent Watsen <kwatsen@juniper.net>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu>
To: Joe Touch <touch@isi.edu>
X-Mailer: Apple Mail (2.1084)
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

[[ I think both mailing lists should remain on the mail. The issues =
relate to both. ]]

On May 13, 2011, at 8:02 AM, Joe Touch wrote:

>>> Netconf over ssh uses a different port, as noted above.
>>=20
>> The need for the port 830 assignment was only to facilitate =
filtering.
>=20
> Yes. And will the need for a reverse port create a similar need for =
every such current SSH-based port assignment to have a corresponding =
reverse-channel port assignment? That would be undesirable...

+1. A single reverse-port protocol that has a way to say "and I'm going =
to be doing X protocol" would be a much better design.

>>> What's the reason for not solving this by having the client just =
listen
>>> on the SSH server port?
>>=20
>> Because then it would be expected to be the SSH server.
>=20
> Well, seems to me that if the server is initiating the connection, =
then it *is* a server (where I define server as "host that listens on a =
registered port").

Fully agree. The design of this draft sounds like it can be summarized =
as "an entity that is normally a client becomes a server for a short =
period while it gets information from the entity that is normally a =
server". At the point that the was-a-client becomes a short-term server, =
why not make it a real SSH server?

> The particular roles of who checks what certificate should be =
negotiated in-band, IMO.


That sounds right to me.

--Paul Hoffman


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Fri May 13 22:46:51 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8B08E0699 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 22:46:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X1uL+omomOxC for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Fri, 13 May 2011 22:46:50 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 6AA58E065D for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Fri, 13 May 2011 22:46:50 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 81D3F14A1EE; Sat, 14 May 2011 05:46:46 +0000 (UTC)
Delivered-To: ietf-ssh@netbsd.org
Received: by mail.netbsd.org (Postfix, from userid 1347) id 32DE314A1EC; Sat, 14 May 2011 05:46:46 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id C8CF714A113 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:49:42 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id wZBKtk4F-b7u for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:49:42 +0000 (UTC)
Received: from exprod7og127.obsmtp.com (exprod7og127.obsmtp.com [64.18.2.210]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 02F8614A110 for <ietf-ssh@NetBSD.org>; Fri, 13 May 2011 16:49:41 +0000 (UTC)
Received: from P-EMHUB03-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob127.postini.com ([64.18.6.12]) with SMTP ID DSNKTc1hI7/sipKu70r9ABFNBo8QfVuTAyOs@postini.com; Fri, 13 May 2011 09:49:42 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB03-HQ.jnpr.net ([::1]) with mapi; Fri, 13 May 2011 09:42:02 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
CC: Joe Touch <touch@isi.edu>, "saag@ietf.org" <saag@ietf.org>
Date: Fri, 13 May 2011 09:42:00 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRJu7D/iwEip/+RsiWtQa8a6CrfgAXG3ZQ
Message-ID: <84600D05C20FF943918238042D7670FD3E7E4A75AB@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <20110513043334.GA5184@elstar.local>
In-Reply-To: <20110513043334.GA5184@elstar.local>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

DQo+IFRoZSBzdWJzeXN0ZW0gaXMgc2VsZWN0ZWQgdGhyb3VnaCB0aGUgZW5jcnlwdGVkIGNoYW5u
ZWwsIHNvbWV0aGluZyBkaWZmaWN1bHQgdG8gZmlsdGVyIG9uLg0KDQpUcnVlLiAgVGhvdWdoIHNv
bWUgZmlyZXdhbGxzIGNhbiBiZSBwcm92aWRlZCB0aGUgYmFja2VuZCBzZXJ2ZXIncyBwcml2YXRl
IGtleShzKSBpbiBvcmRlciB0byBpbnNwZWN0IHRoZSB0cmFmZmljLiAgVGhpcyBmZWF0dXJlIGlz
IG1vcmUgcHJldmFsZW50IG9uIGluZHVzdHJpYWwgZmlyZXdhbGxzIHRoYW4gY29uc3VtZXItZ3Jh
ZGUgZmlyZXdhbGxzLg0KDQpPZiBjb3Vyc2UsIHRoZXJlIGlzIGEgY2F0Y2gtMjIgdG8gdGhpcyBp
cyB0aGF0LCBhdCBsZWFzdCBpbiBvdXIgYXBwbGljYXRpb24gb2YgdGhpcyBwcm9wb3NhbCwgdGhl
IGRldmljZSB0aGF0IHRoZSAiY2FsbGluZyBob21lIiBtYW55IHRpbWVzIChidXQgbm90IGFsd2F5
cyAtIHNlZSBkcmFmdCBmb3IgZGV0YWlscykgaXMgdGhlIGdhdGV3YXkgZGV2aWNlIGhhdmluZyB0
aGUgZmlyZXdhbGxpbmcgZnVuY3Rpb25hbGl0eS4NCg0KU3RpbGwsIEkgY29uY3VyIHdpdGggeW91
ciBwcmVtaXNlIHRoYXQgdGhlIHNvbHV0aW9uIHNob3VsZG4ndCBkaXNjYXJkIHRoZSBhYmlsaXR5
IHRvIGRvIHBvcnQtbGV2ZWwgZmlsdGVyaW5nIGZvciBlYWNoIFNTSC1iYXNlZCBwcm90b2NvbCB0
aGF0IGhhcyBiZWVuIHJldmVyc2VkLiAgVGhlIHF1ZXN0aW9uIHJlbWFpbnMsIHRob3VnaCwgaWYg
dGhlcmUgc2hvdWxkIGJlIGEgbmV3IHBvcnQtYXNzaWdubWVudCBmb3IgZWFjaCBTU0gtYmFzZWQg
cHJvdG9jb2wgb3IgaWYgdGhlIGV4aXN0aW5nIHBvcnRzIGFyZSByZXB1cnBvc2VkLg0KDQpXb3Vs
ZCByZXB1cnBvc2luZyBleGlzdGluZyBwb3J0cyBiZSB0b28gYW1iaWd1b3VzLCBkdWUgdG8gdGhl
bSBoYXZpbmcgZHVhbCByb2xlcz8NCg0KDQpQUzogUGVyIFRvbSdzIGNvbW1lbnQsIEkndmUgQkND
LWVkIHRoZSAiaWV0Zi1zc2giIGxpc3QgdG8gYnJpbmcgdGhpcyBkaXNjdXNzaW9uIHRvIG9uZSBs
aXN0LiAgSSdtIGNob29zaW5nIHRoZSBTQUFHIGxpc3QgcHJpbWFyaWx5IGJlY2F1c2UgaXQgaXMg
YW4gb2ZmaWNpYWwgSUVURiBsaXN0LiAgSG9wZSB0aGlzIGlzIE9LIHdpdGggYWxsLg0KDQpUaGFu
a3MsDQpLZW50DQoNCg0K

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon May 23 10:59:54 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 645B7E07AC for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 10:59:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LynpQrHtd56Z for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 10:59:54 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id B1566E07AD for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 23 May 2011 10:59:53 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 56F3314A152; Mon, 23 May 2011 17:59:49 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 09BD014A162 for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 17:59:45 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id l3TGeRLXV4Pq for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 17:59:44 +0000 (UTC)
Received: from exprod7og127.obsmtp.com (exprod7og127.obsmtp.com [64.18.2.210]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 62FB314A0DD for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 17:59:42 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob127.postini.com ([64.18.6.12]) with SMTP ID DSNKTdqgjFYQXD5axBW/anl/Z0AewoUg+9AA@postini.com; Mon, 23 May 2011 10:59:44 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB01-HQ.jnpr.net ([fe80::fc92:eb1:759:2c72%11]) with mapi; Mon, 23 May 2011 10:56:59 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Paul Hoffman <paul.hoffman@vpnc.org>
CC: "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Date: Mon, 23 May 2011 10:56:52 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwRsRCvEVeAj7lsT4e6qoQ50HGnZgD9Apdg
Message-ID: <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu> <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org>
In-Reply-To: <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> I think both mailing lists should remain on the mail. The issues=20
> relate to both.

OK, we'll keep both on, just as the Security ADs originally suggested.



> > Yes. And will the need for a reverse port create a similar need for=20
> > every such  current SSH-based port assignment to have a corresponding=20
> > reverse-channel port assignment? That would be undesirable...
>
> +1. A single reverse-port protocol that has a way to say "and I'm going=20
> to be doing X protocol" would be a much better design.

Sounds a little bit like the tcpmux protocol.  Do you think how SSH opens
channels/subsystems is not good enough?   A proliferation of ports doesn't
sound good, but others expressed a need for ports to support port-based
firewall filters.  How many ssh-based protocols are there currently?  I=20
only know of two (SSH/SCP/SFTP:22 and NETCONF:830) - are there any others? =
=20



> The design of this draft sounds like it can be summarized as "an entity
> that is normally a client becomes a server for a short period while it
> gets information from the entity that is normally a server". At the=20
> point that the was-a-client becomes a short-term server, why not make
> it a real SSH server?

What does this means at a protocol level?  Does the application present a
SSH host-key during DH key exchange and the device logs into the applicatio=
n
via userauth?  - if so, then please realize that this is exactly what we're
trying to prevent.  We want the device to always be the peer that presents
its SSH host key, whether due to the application connecting to its port 22
or because the device connected to the app's Reverse SSH port.   Likewise,
we always want the app to be the peer that userauth's to the device,=20
regardless how the transport was setup.



> > The particular roles of who checks what certificate should be negotiate=
d
> > in-band, IMO.
>
> That sounds right to me.

This would only be necessary if there are no new port assignments as,=20
otherwise, each peer *knows* which role to assume.  For instance, each
peer knows its role if started like this:

  app:     ssh --listen <rssh-port> --handler /usr/local/bin/myapp
  device:  sshd --connect <app>:<rssh-port> --id 234230 --hmackey secret


Otherwise, if there are no new port assignments (i.e. <rssh-port>=3D=3D22),
then we'd have to have in-band negotiation, perhaps by the device=20
sending a special identification string (RFC 4253, section 4.2) like
this?

  SSH-2.0-OpenSSH_5.6 <SP> Reverse SSH <CR> <LF>


If having in-band negotiation, then we should also extend the SSH=20
Protocol to support device identification and automatic authentication
of host keys other than PGP and x.509 certificates, this is the=20
essence of the REVERSE-SSH-CONN-INFO message in the draft.


Thanks,
Kent







From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon May 23 11:42:02 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DF43E07D3 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 11:42:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.589
X-Spam-Level: 
X-Spam-Status: No, score=-102.589 tagged_above=-999 required=5 tests=[AWL=0.010, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WNd26dESgTJN for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 11:42:02 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 3E52EE06AB for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 23 May 2011 11:42:01 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id E426214A181; Mon, 23 May 2011 18:41:57 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 7CBEE14A180 for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 18:41:51 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id YPRDwvb-EzWD for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 18:41:50 +0000 (UTC)
Received: from hoffman.proper.com (IPv6.Hoffman.Proper.COM [IPv6:2001:4870:a30c:41::81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 6AF9914A17F for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 18:41:49 +0000 (UTC)
Received: from [10.20.30.150] (75-101-30-90.dsl.dynamic.sonic.net [75.101.30.90]) (authenticated bits=0) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id p4NIfi2L066805 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Mon, 23 May 2011 11:41:45 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: text/plain; charset=us-ascii
From: Paul Hoffman <paul.hoffman@vpnc.org>
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net>
Date: Mon, 23 May 2011 11:41:44 -0700
Cc: "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu> <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net>
To: Kent Watsen <kwatsen@juniper.net>
X-Mailer: Apple Mail (2.1084)
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On May 23, 2011, at 10:56 AM, Kent Watsen wrote:

>> I think both mailing lists should remain on the mail. The issues=20
>> relate to both.
>=20
> OK, we'll keep both on, just as the Security ADs originally suggested.
>=20
>=20
>=20
>>> Yes. And will the need for a reverse port create a similar need for=20=

>>> every such  current SSH-based port assignment to have a =
corresponding=20
>>> reverse-channel port assignment? That would be undesirable...
>>=20
>> +1. A single reverse-port protocol that has a way to say "and I'm =
going=20
>> to be doing X protocol" would be a much better design.
>=20
> Sounds a little bit like the tcpmux protocol.  Do you think how SSH =
opens
> channels/subsystems is not good enough?   A proliferation of ports =
doesn't
> sound good, but others expressed a need for ports to support =
port-based
> firewall filters. =20

Firewalls should adapt to good protocol design; protocol design should =
not be weakened to work with firewalls. (And I say this as someone who =
likes firewalls.)

> How many ssh-based protocols are there currently?  I=20
> only know of two (SSH/SCP/SFTP:22 and NETCONF:830) - are there any =
others? =20

You say that as if we never expect to have any more, which seems like =
poor planning. For example, many people run VNC and other such protocols =
on other ports. The "ssh -L 15901:localhost:5901 example.com" usage is =
quite common. Making it harder for protocols other than NETCONF to use =
SSH doesn't seem like a good plan at this point.

>> The design of this draft sounds like it can be summarized as "an =
entity
>> that is normally a client becomes a server for a short period while =
it
>> gets information from the entity that is normally a server". At the=20=

>> point that the was-a-client becomes a short-term server, why not make
>> it a real SSH server?
>=20
> What does this means at a protocol level?  Does the application =
present a
> SSH host-key during DH key exchange and the device logs into the =
application
> via userauth?  - if so, then please realize that this is exactly what =
we're
> trying to prevent. =20

I do realize that; I am proposing that what you are trying to prevent is =
in fact fine, and a lot more rational than a "I'm a kind-of-server for =
just a moment" design.

> We want the device to always be the peer that presents
> its SSH host key, whether due to the application connecting to its =
port 22
> or because the device connected to the app's Reverse SSH port.   =
Likewise,
> we always want the app to be the peer that userauth's to the device,=20=

> regardless how the transport was setup.

Understood. The draft does a reasonable job of matching that design.

>>> The particular roles of who checks what certificate should be =
negotiated
>>> in-band, IMO.
>>=20
>> That sounds right to me.
>=20
> This would only be necessary if there are no new port assignments as,=20=

> otherwise, each peer *knows* which role to assume.  For instance, each
> peer knows its role if started like this:
>=20
>  app:     ssh --listen <rssh-port> --handler /usr/local/bin/myapp
>  device:  sshd --connect <app>:<rssh-port> --id 234230 --hmackey =
secret
>=20
>=20
> Otherwise, if there are no new port assignments (i.e. =
<rssh-port>=3D=3D22),
> then we'd have to have in-band negotiation, perhaps by the device=20
> sending a special identification string (RFC 4253, section 4.2) like
> this?
>=20
>  SSH-2.0-OpenSSH_5.6 <SP> Reverse SSH <CR> <LF>

This assumes that all SSH use is only on the currently-assigned ports. =
That ignores the "-L" use case I gave above, as well as future protocols =
that want to run over SSH.

> If having in-band negotiation, then we should also extend the SSH=20
> Protocol to support device identification and automatic authentication
> of host keys other than PGP and x.509 certificates, this is the=20
> essence of the REVERSE-SSH-CONN-INFO message in the draft.


That is one design; another is "when I am acting like a server, I am =
actually a server". That seems a lot cleaner.

--Paul Hoffman


From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Mon May 23 16:21:24 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B797FE07A9 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 16:21:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hzYwahqZOO1l for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Mon, 23 May 2011 16:21:24 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 325BDE06BF for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Mon, 23 May 2011 16:21:24 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 83C8414A147; Mon, 23 May 2011 23:21:20 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 2F0D414A128 for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 23:21:14 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id U57ARW4VKZ7V for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 23:21:13 +0000 (UTC)
Received: from exprod7og124.obsmtp.com (exprod7og124.obsmtp.com [64.18.2.26]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id E1FD214A100 for <ietf-ssh@NetBSD.org>; Mon, 23 May 2011 23:21:12 +0000 (UTC)
Received: from P-EMHUB02-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob124.postini.com ([64.18.6.12]) with SMTP ID DSNKTdrr6JlkPY75qmrsVkqCJ5Di6RAx7aVW@postini.com; Mon, 23 May 2011 16:21:12 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB02-HQ.jnpr.net ([fe80::88f9:77fd:dfc:4d51%11]) with mapi; Mon, 23 May 2011 16:17:20 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: Paul Hoffman <paul.hoffman@vpnc.org>
CC: "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Date: Mon, 23 May 2011 16:17:08 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwZeRN4w5GXI+PHTxOBxP6WcHTHBgAFHB5w
Message-ID: <84600D05C20FF943918238042D7670FD3E7EF9406E@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu> <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net> <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org>
In-Reply-To: <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> Firewalls should adapt to good protocol design; protocol design should
> not be weakened to work with firewalls. (And I say this as someone who
> likes firewalls.)

Agreed - let's focus on a good protocol design ;)



>> How many ssh-based protocols are there currently?  I only know
>> of two (SSH/SCP/SFTP:22 and NETCONF:830) - are there any others? =20
>
> You say that as if we never expect to have any more, which seems like=20
> poor planning. For example, many people run VNC and other such protocols
> on other ports. The "ssh -L 15901:localhost:5901 example.com" usage is
> quite common. Making it harder for protocols other than NETCONF to use
> SSH doesn't seem like a good plan at this point.

I didn't mean to imply that there wouldn't be more, only that there are
so few now and that new SSH-based protocols can define a reverse-port for
themselves, if it makes sense to them to do so.

I use that port forwarding line with my virtual machines.  It's a good
example because VNC is used to "manage" devices similar to NetConf, so
it's plausible that a device might be configured to init a reverse ssh
connection to support VNC.  In this case, the `ssh` connection goes to
port 22, so reversing it means that the device would connect to the=20
application's rssh port and, once the SSH Connection Protocol (RFC 4254)
is running, the application can send a SSH_MSG_CHANNEL_OPEN/direct-tcpip
request to open a tunnel to the VNC server.




>> What does this means at a protocol level?  Does the application present =
a
>> SSH host-key during DH key exchange and the device logs into the applica=
tion
>> via userauth?  - if so, then please realize that this is exactly what we=
're
>> trying to prevent. =20
>
> I do realize that; I am proposing that what you are trying to prevent is=
=20
> in  fact fine, and a lot more rational than a "I'm a kind-of-server for=20
> just a moment" design.

Thanks, Paul.  I appreciate your endorsement.  At least, I think it is an
endorsement... (I'm not entirely sure per your last comment below)




>> We want the device to always be the peer that presents
>> its SSH host key, whether due to the application connecting to its port =
22
>> or because the device connected to the app's Reverse SSH port.   Likewis=
e,
>> we always want the app to be the peer that userauth's to the device,=20
>> regardless how the transport was setup.
>
> Understood. The draft does a reasonable job of matching that design.
>
>=20
>> This would only be necessary if there are no new port assignments as,=20
>> otherwise, each peer *knows* which role to assume.  For instance, each
>> peer knows its role if started like this:
>>=20
>>  app:     ssh --listen <rssh-port> --handler /usr/local/bin/myapp
>>  device:  sshd --connect <app>:<rssh-port> --id 234230 --hmackey secret
>> =20
>> Otherwise, if there are no new port assignments (i.e. <rssh-port>=3D=3D2=
2),
>> then we'd have to have in-band negotiation, perhaps by the device=20
>> sending a special identification string (RFC 4253, section 4.2) like
>> this?
>>=20
>>  SSH-2.0-OpenSSH_5.6 <SP> Reverse SSH <CR> <LF>
>
>This assumes that all SSH use is only on the currently-assigned ports. Tha=
t ignores the "-L" use >case I gave above, as well as future protocols that=
 want to run over SSH.

FWIW, I personally don't like repurposing the currently-assigned ports=20
because it would be confusing to suddenly not be sure that port 22 was
for a SSH Server and port 830 was for a NetConf server.  I only offered
how we might support in-band negotiation with the identification string
because it seemed folks wanted to explore that option. =20

I like having a single well-known port (like tcpmux/port 1) that can be
used for any SSH-based protocol, leaving it to the client to select which
ones to start via opening channels/subsystems.  For instance, an app can
have simultaneous channels open for Syslog, SNMP, NetConf, VNC, HTTPS,
and TTY.  Which reminds me that I've always wanted an ability for a SSH
Client to get a listing of all the subsystems available on the server,=20
similar to tcpmux's "HELP" command (another draft?)

Another option, that I'm a bit shy to promote, is to have *no* assigned=20
ports.  This is technically feasible since the devices MUST be configured
to connect to the applications (i.e. address, port, id, credentials, etc.).
The devices never connect out of the blue, thus no well-known port is=20
required.  But this strategy would entail applications using unassigned
ports, the very thing that Joe Touch flagged the day I submitted the draft.




>> If having in-band negotiation, then we should also extend the SSH=20
>> Protocol to support device identification and automatic authentication
>> of host keys other than PGP and x.509 certificates, this is the=20
>> essence of the REVERSE-SSH-CONN-INFO message in the draft.
>
>
>That is one design; another is "when I am acting like a server, I am=20
>actually a server". That seems a lot cleaner.

This is the comment I mentioned above is being unsure if it means you
like the current draft or not.  Is the "I am actually a server" statement
satisfied by having an application listening on a Reverse SSH port, where
the entire "protocol" is merely to bootstrap the SSH protocol?



Thanks again,
Kent





From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue May 24 07:51:46 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 462D2E075F for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 24 May 2011 07:51:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.168
X-Spam-Level: 
X-Spam-Status: No, score=-104.168 tagged_above=-999 required=5 tests=[AWL=1.035, BAYES_00=-2.599, MIME_QP_LONG_LINE=1.396, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b+ZXRiXUPeXw for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 24 May 2011 07:51:46 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id D29F3E075D for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue, 24 May 2011 07:51:32 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 3848C14A190; Tue, 24 May 2011 14:51:24 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 126A814A17B for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 14:51:21 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id MGKldKOQm1pU for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 14:51:20 +0000 (UTC)
Received: from boreas.isi.edu (boreas.isi.edu [128.9.160.161]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 4CDED14A178 for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 14:51:20 +0000 (UTC)
Received: from [192.168.1.91] (pool-71-105-81-169.lsanca.dsl-w.verizon.net [71.105.81.169]) (authenticated bits=0) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id p4OEoWaf012638 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT); Tue, 24 May 2011 07:50:41 -0700 (PDT)
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu> <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net> <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF9406E@EMBX01-HQ.jnpr.net>
In-Reply-To: <84600D05C20FF943918238042D7670FD3E7EF9406E@EMBX01-HQ.jnpr.net>
Mime-Version: 1.0 (iPad Mail 8J3)
Content-Type: text/plain; charset=us-ascii
Message-Id: <F9AD17DB-8BB9-4FA7-B926-B7F6B3005C8C@isi.edu>
Content-Transfer-Encoding: quoted-printable
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
X-Mailer: iPad Mail (8J3)
From: Joe Touch <touch@isi.edu>
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
Date: Tue, 24 May 2011 07:50:40 -0700
To: Kent Watsen <kwatsen@juniper.net>
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

On May 23, 2011, at 4:17 PM, Kent Watsen <kwatsen@juniper.net> wrote:
>=20
> I like having a single well-known port (like tcpmux/port 1) that can be
> used for any SSH-based protocol, leaving it to the client to select which
> ones to start via opening channels/subsystems. =20

Why isn't that the current ssh port?

> For instance, an app can
> have simultaneous channels open for Syslog, SNMP, NetConf, VNC, HTTPS,
> and TTY.  Which reminds me that I've always wanted an ability for a SSH
> Client to get a listing of all the subsystems available on the server,=20
> similar to tcpmux's "HELP" command (another draft?)

That is what the dns srv records might do, so you could ootentkially use 53 f=
or that. But wouldn't that be a security concern?

> Another option, that I'm a bit shy to promote, is to have *no* assigned=20=

> ports.  This is technically feasible since the devices MUST be configured
> to connect to the applications (i.e. address, port, id, credentials, etc.)=
.
> The devices never connect out of the blue, thus no well-known port is=20
> required.  But this strategy would entail applications using unassigned
> ports, the very thing that Joe Touch flagged the day I submitted the draft=
.

Using only ports from the dynamic range is fine, but won't appease firewall d=
esigners.=20

Using the entire port range, or and single port that is from the assignable r=
ange that hasn't been assigned to you is a problem (and I was concerned with=
 the latter in your submission).

>=20
>>> If having in-band negotiation, then we should also extend the SSH=20
>>> Protocol to support device identification and automatic authentication
>>> of host keys other than PGP and x.509 certificates, this is the=20
>>> essence of the REVERSE-SSH-CONN-INFO message in the draft.
>>=20
>>=20
>> That is one design; another is "when I am acting like a server, I am=20
>> actually a server". That seems a lot cleaner.
>=20
> This is the comment I mentioned above is being unsure if it means you
> like the current draft or not.  Is the "I am actually a server" statement
> satisfied by having an application listening on a Reverse SSH port, where
> the entire "protocol" is merely to bootstrap the SSH protocol?

I'm a server if I listen on the ssh port. On that port you should indicate o=
r negotiate specifics of each side's behavior in-band IMO.=20

Joe=

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Tue May 24 08:55:26 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 69A12E0771 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 24 May 2011 08:55:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.988
X-Spam-Level: 
X-Spam-Status: No, score=-9.988 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_MISMATCH_ORG=0.611, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GHEu7b+HTKpz for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Tue, 24 May 2011 08:55:26 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 1A710E0764 for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Tue, 24 May 2011 08:55:07 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 702B414A179; Tue, 24 May 2011 15:55:02 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id B7F9914A16E for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 15:55:00 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id 7j8nVkzB7aMh for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 15:55:00 +0000 (UTC)
Received: from Sparkle.Rodents-Montreal.ORG (Sparkle.Rodents-Montreal.ORG [216.46.5.7]) by mail.netbsd.org (Postfix) with ESMTP id 6C04814A158 for <ietf-ssh@NetBSD.org>; Tue, 24 May 2011 15:54:59 +0000 (UTC)
Received: (from mouse@localhost) by Sparkle.Rodents-Montreal.ORG (8.8.8/8.8.8) id LAA07708; Tue, 24 May 2011 11:54:36 -0400 (EDT)
Date: Tue, 24 May 2011 11:54:36 -0400 (EDT)
From: der Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <201105241554.LAA07708@Sparkle.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
X-Composition-Start-Date: Tue, 24 May 2011 11:45:48 -0400 (EDT)
To: ietf-ssh@NetBSD.org, saag@ietf.org
Subject: Re: [saag] draft-kwatsen-reverse-ssh submission for review
In-Reply-To: <F9AD17DB-8BB9-4FA7-B926-B7F6B3005C8C@isi.edu>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net> <4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu> <FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net> <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF9406E@EMBX01-HQ.jnpr.net> <F9AD17DB-8BB9-4FA7-B926-B7F6B3005C8C@isi.edu>
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

> I'm a server if I listen on the ssh port.  On that port you should
> indicate or negotiate specifics of each side's behavior in-band IMO.

This sounds like a reasonable point of view to me.

If your reversed ssh runs kex with roles reversed (ie, connection
initiator takes the server's role, presenting its host key and such),
then a passive snooper can tell the difference, so you might as well
trigger the role reversal with a pre-kex extension packet.

If your reversd ssh runs kex normally (initiator takes the client's
role) but reverses things after that, then you can do it with an
extension packet immediately after kex (before, and/or instead of, what
would normally be userauth).

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

From bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org  Wed May 25 15:32:07 2011
Return-Path: <bounces-ietf-ssh-owner-secsh-tyoxbijeg7-archive=lists.ietf.org@NetBSD.org>
X-Original-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Delivered-To: ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6EF71E0808 for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 25 May 2011 15:32:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bbdWfy+CrYnD for <ietfarch-secsh-tyoxbijeg7-archive@ietfa.amsl.com>; Wed, 25 May 2011 15:32:07 -0700 (PDT)
Received: from mail.netbsd.org (mail.NetBSD.org [IPv6:2001:4f8:3:7:230:48ff:fe85:f13c]) by ietfa.amsl.com (Postfix) with ESMTP id 28100E07FB for <secsh-tyoxbijeg7-archive@lists.ietf.org>; Wed, 25 May 2011 15:31:48 -0700 (PDT)
Received: by mail.netbsd.org (Postfix, from userid 605) id 1AEF014A1A7; Wed, 25 May 2011 22:31:46 +0000 (UTC)
Delivered-To: ietf-ssh@NetBSD.org
Received: from localhost (localhost [127.0.0.1]) by mail.netbsd.org (Postfix) with ESMTP id 7FA4814A19C for <ietf-ssh@NetBSD.org>; Wed, 25 May 2011 22:31:44 +0000 (UTC)
X-Virus-Scanned: amavisd-new at NetBSD.org
Received: from mail.netbsd.org ([127.0.0.1]) by localhost (mail.NetBSD.org [127.0.0.1]) (amavisd-new, port 10025) with ESMTP id nkfwMejTR3t6 for <ietf-ssh@NetBSD.org>; Wed, 25 May 2011 22:31:44 +0000 (UTC)
Received: from exprod7og118.obsmtp.com (exprod7og118.obsmtp.com [64.18.2.8]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.netbsd.org (Postfix) with ESMTPS id 2F70214A196 for <ietf-ssh@NetBSD.org>; Wed, 25 May 2011 22:31:42 +0000 (UTC)
Received: from P-EMHUB01-HQ.jnpr.net ([66.129.224.36]) (using TLSv1) by exprod7ob118.postini.com ([64.18.6.12]) with SMTP ID DSNKTd2C5MxlfiDYV/5hkSP3Urp0Dv3Wz3zK@postini.com; Wed, 25 May 2011 15:31:43 PDT
Received: from EMBX01-HQ.jnpr.net ([fe80::c821:7c81:f21f:8bc7]) by P-EMHUB01-HQ.jnpr.net ([fe80::fc92:eb1:759:2c72%11]) with mapi; Wed, 25 May 2011 15:27:13 -0700
From: Kent Watsen <kwatsen@juniper.net>
To: der Mouse <mouse@Rodents-Montreal.ORG>, "ietf-ssh@NetBSD.org" <ietf-ssh@NetBSD.org>, "saag@ietf.org" <saag@ietf.org>
Date: Wed, 25 May 2011 15:27:11 -0700
Subject: RE: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Topic: [saag] draft-kwatsen-reverse-ssh submission for review
Thread-Index: AcwaKvLYFTRU5MWESc6JmKGzTWPjewA92vBw
Message-ID: <84600D05C20FF943918238042D7670FD3E7F4FFF27@EMBX01-HQ.jnpr.net>
References: <84600D05C20FF943918238042D7670FD3E7E4A71B1@EMBX01-HQ.jnpr.net> <4DCC7D50.9080308@isi.edu> <C4048A39-BE54-4574-A743-43EC968DCE21@juniper.net>	<4DCC8440.80109@isi.edu> <84600D05C20FF943918238042D7670FD3E7E4A72FD@EMBX01-HQ.jnpr.net> <4DCD47F5.5000102@isi.edu>	<FBF6F718-1BB1-4E4C-B79E-FD5F341C0C99@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF93B55@EMBX01-HQ.jnpr.net> <F41AE835-14F9-4E97-8F69-7232CDBB246E@vpnc.org> <84600D05C20FF943918238042D7670FD3E7EF9406E@EMBX01-HQ.jnpr.net> <F9AD17DB-8BB9-4FA7-B926-B7F6B3005C8C@isi.edu> <201105241554.LAA07708@Sparkle.Rodents-Montreal.ORG>
In-Reply-To: <201105241554.LAA07708@Sparkle.Rodents-Montreal.ORG>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Sender: ietf-ssh-owner@NetBSD.org
List-Id: ietf-ssh.NetBSD.org
Precedence: list

>> I'm a server if I listen on the ssh port.  On that port you should
>> indicate or negotiate specifics of each side's behavior in-band IMO.
>
>This sounds like a reasonable point of view to me.
>
>If your reversed ssh runs kex with roles reversed (ie, connection
>initiator takes the server's role, presenting its host key and such),
>then a passive snooper can tell the difference, so you might as well
>trigger the role reversal with a pre-kex extension packet.

OK, I'll submit an updated draft for this approach

Thanks,
Kent

