RFC: Deprecate the Print-URI and Send-URI operations and related attributes and values

Michael Sweet via ipp <[email protected]>
Newsgroups gmane.ietf.ipp
Message-ID <[email protected]>
All,

The IPP workgroup would like to deprecate the Print-URI and Send-URI operations [STD92] and associated attributes, values, and status codes.  The reasons for these deprecations are primarily security-driven but also reflect 20 years of real-world implementation experience.


The specific issues we have discussed are:

1. Network Access Differences:  Clients and Printers can have different levels of access to networking, which can lead to print jobs failing because the Printer is unable to access a network resource (different networks, missing credentials, etc.) as well as print jobs succeeding because the Printer has access to otherwise protected/restricted network resources (e.g. bypassing personal firewalls). Even for non-malicious content, remote URIs can incur additional costs for network data/bandwidth usage that might otherwise not be accounted for or allowed.

2. Identification/Authentication/Access Control Issues:  Clients cannot always provide a Printer with the necessary credentials to access a remote resource, and sending some types of credentials (e.g. passwords, private keys, etc.) to the Printer poses a security threat.

3. Denial of Service Attacks:  A Client could potentially cause a Denial-of-Service by sending a URI to a malicious network service designed to provide malicious content to the Printer or to delay network transactions in a way that keeps the Printer busy fetching the remote document.

4. Required URI Scheme:  IPP/1.1 [STD92] only requires support for the "ftp" URI scheme/protocol, which is no longer supported by the major web browsers and operating systems out-of-the-box, is not a secure or modern protocol, and is often blocked by firewalls and ISPs.


As for implementation experience, some IPP spooler (Client-side) implementations have made use of these operations to provide access to internal resources without extra copying, for example when printing photos on iOS devices, but otherwise the various Client operating systems do not seem to make use of these operations.  Some Printers *do* support Print-URI and Send-URI for both FTP and HTTP/HTTPS, but there is no evidence that such functionality is in common usage.


Your feedback is greatly appreciated!


--------


The following is the IANA IPP registry template for this change:

Document Status attributes:                         Reference
--------------------------                          ---------
document-access-errors (1setOf text(MAX))           [PWG5100.5]
document-access-errors(deprecated)                  [IPPWG20210616]


Job Status attributes:                              Reference
---------------------                               ---------
job-document-access-errors (1setOf text(MAX))       [STD92]
job-document-access-errors(deprecated)              [IPPWG20210616]


Operation attributes:                               Reference
--------------------                                ---------
document-access (collection | no-value)             [PWG5100.18]
document-access(deprecated)                         [IPPWG20210616]
document-access-error (text(MAX))                   [STD92]
document-access-error(deprecated)                   [IPPWG20210616]


Printer Description attributes:                     Reference
-------------------------------                     ---------
document-access-supported (1setOf keyword)          [PWG5100.18]
document-access-supported(deprecated)               [IPPWG20210616]
reference-uri-schemes-supported (1setOf uriScheme)  [STD92]
reference-uri-schemes-supported(deprecated)         [IPPWG20210616]


Attributes (attribute syntax)
  Keyword Attribute Value                           Reference
  -----------------------                           ---------
document-state-reasons (1setOf type2 keyword)       [PWG5100.5]
  document-access-error                             [PWG5100.5]
  document-access-error(deprecated)                 [IPPWG20210616]

job-state-reasons (1setOf type2 keyword)            [STD92]
  document-access-error                             [STD92]
  document-access-error(deprecated)                 [IPPWG20210616]


Attributes (attribute syntax)
  Enum Value          Enum Symbolic Name            Reference
  ----------          ------------------            ---------
operations-supported (1setOf type2 enum)            [STD92]
  0x0003              Print-URI                     [STD92]
  0x0003(deprecated)  Print-URI                     [IPPWG20210616]
  0x0007              Send-URI                      [STD92]
  0x0007(deprecated)  Send-URI                      [IPPWG20210616]


Operation Name                                      Reference
--------------                                      ---------
Print-URI                                           [STD92]
Print-URI(deprecated)                               [IPPWG20210616]
Send-URI                                            [STD92]
Send-URI(deprecated)                                [IPPWG20210616]


Value    Status Code Name                           Reference
------   -----------------------------------------  ---------
0x0400:0x04FF - Client Error:
  0x0412 client-error-document-access-error         [STD92]
  0x0412(deprecated)                                [REFERENCE]


[PWG5100.5]: https://ftp.pwg.org/pub/pwg/candidates/cs-ippdocobject11-20190521-5100.5.pdf
[PWG5100.18]: https://ftp.pwg.org/pub/pwg/candidates/cs-ippinfra10-20150619-5100.18.pdf
[STD92]: https://tools.ietf.org/html/std92

________________________
Michael Sweet

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp
signature.asc (application/pgp-signature, 874 B)
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQIzBAEBCgAdFiEEkIbDzcZsP1Y8+PQFvmfHXsgfMkQFAmDJ+P0ACgkQvmfHXsgf
MkS3ihAAgzEcpLpGKmvsl3/l5fCVYbCwTuplAouO/f8x4ePl0l8C3UivSyHn9qX2
rw7acit5yxG83DDJRdWCbydld29pXXyK7hEGWQWvqPUWQT38a2j5nvzys3HaEHtm
LLmYYEMkO231xTJh44pyrFVGnFoDMWyKxV/+/KcHIgyvRUpzHVaFs7MryXjuiuDk
r8wqixTfHRB2A+zdAFadtWGtp8aZUS+Tjldek3Yroqg3J+Ocno74G6/XvFudPQro
hwvb+2nM8WQ962RS1HmZ4tp6q4853jn7DRJoDnuWnwPPnyzrrnsd5GwbJtxbUD/t
eF4BjwqwjaBDboNoK0NkO17AmcCDcuNl5rbtCXeQtNgOX/XlsJ4mD0OOm7NAaKKX
BK8V6p2A5fUFGE7ReGegSgMGakqeoVb9Itf9yylWwAK+l5CQiQTsiuSnTm10rkvy
xdyaaYXtCbAfNLeJEqagxiYD8GFuGGbIe7L8i1ru9BSl6ytHuw/2+2RjxARH/ZXB
noIdoTeyi2Lfa7Niuj/LQ02O+7FoBQSC2x5dIpU3/0/Q8QW9lEL2uXq3sZm7J/L0
20Cy5DV/WWyknYC0KN3EC8O7EQmgFR/ByV+5goK6f8Uo5VSjEr9BG33sGWVet/v9
mXqeDojNubiZFmc6REsT7RPMtZud2kl+yMgVzvHF09Ga+O1wx58=
=Tnh6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.