RFC: Deprecate the Print-URI and Send-URI operations and related attributes and values
Michael Sweet via ipp <[email protected]>
| Newsgroups | gmane.ietf.ipp |
|---|---|
| Message-ID | <[email protected]> |
All, The IPP workgroup would like to deprecate the Print-URI and Send-URI operations [STD92] and associated attributes, values, and status codes. The reasons for these deprecations are primarily security-driven but also reflect 20 years of real-world implementation experience. The specific issues we have discussed are: 1. Network Access Differences: Clients and Printers can have different levels of access to networking, which can lead to print jobs failing because the Printer is unable to access a network resource (different networks, missing credentials, etc.) as well as print jobs succeeding because the Printer has access to otherwise protected/restricted network resources (e.g. bypassing personal firewalls). Even for non-malicious content, remote URIs can incur additional costs for network data/bandwidth usage that might otherwise not be accounted for or allowed. 2. Identification/Authentication/Access Control Issues: Clients cannot always provide a Printer with the necessary credentials to access a remote resource, and sending some types of credentials (e.g. passwords, private keys, etc.) to the Printer poses a security threat. 3. Denial of Service Attacks: A Client could potentially cause a Denial-of-Service by sending a URI to a malicious network service designed to provide malicious content to the Printer or to delay network transactions in a way that keeps the Printer busy fetching the remote document. 4. Required URI Scheme: IPP/1.1 [STD92] only requires support for the "ftp" URI scheme/protocol, which is no longer supported by the major web browsers and operating systems out-of-the-box, is not a secure or modern protocol, and is often blocked by firewalls and ISPs. As for implementation experience, some IPP spooler (Client-side) implementations have made use of these operations to provide access to internal resources without extra copying, for example when printing photos on iOS devices, but otherwise the various Client operating systems do not seem to make use of these operations. Some Printers *do* support Print-URI and Send-URI for both FTP and HTTP/HTTPS, but there is no evidence that such functionality is in common usage. Your feedback is greatly appreciated! -------- The following is the IANA IPP registry template for this change: Document Status attributes: Reference -------------------------- --------- document-access-errors (1setOf text(MAX)) [PWG5100.5] document-access-errors(deprecated) [IPPWG20210616] Job Status attributes: Reference --------------------- --------- job-document-access-errors (1setOf text(MAX)) [STD92] job-document-access-errors(deprecated) [IPPWG20210616] Operation attributes: Reference -------------------- --------- document-access (collection | no-value) [PWG5100.18] document-access(deprecated) [IPPWG20210616] document-access-error (text(MAX)) [STD92] document-access-error(deprecated) [IPPWG20210616] Printer Description attributes: Reference ------------------------------- --------- document-access-supported (1setOf keyword) [PWG5100.18] document-access-supported(deprecated) [IPPWG20210616] reference-uri-schemes-supported (1setOf uriScheme) [STD92] reference-uri-schemes-supported(deprecated) [IPPWG20210616] Attributes (attribute syntax) Keyword Attribute Value Reference ----------------------- --------- document-state-reasons (1setOf type2 keyword) [PWG5100.5] document-access-error [PWG5100.5] document-access-error(deprecated) [IPPWG20210616] job-state-reasons (1setOf type2 keyword) [STD92] document-access-error [STD92] document-access-error(deprecated) [IPPWG20210616] Attributes (attribute syntax) Enum Value Enum Symbolic Name Reference ---------- ------------------ --------- operations-supported (1setOf type2 enum) [STD92] 0x0003 Print-URI [STD92] 0x0003(deprecated) Print-URI [IPPWG20210616] 0x0007 Send-URI [STD92] 0x0007(deprecated) Send-URI [IPPWG20210616] Operation Name Reference -------------- --------- Print-URI [STD92] Print-URI(deprecated) [IPPWG20210616] Send-URI [STD92] Send-URI(deprecated) [IPPWG20210616] Value Status Code Name Reference ------ ----------------------------------------- --------- 0x0400:0x04FF - Client Error: 0x0412 client-error-document-access-error [STD92] 0x0412(deprecated) [REFERENCE] [PWG5100.5]: https://ftp.pwg.org/pub/pwg/candidates/cs-ippdocobject11-20190521-5100.5.pdf [PWG5100.18]: https://ftp.pwg.org/pub/pwg/candidates/cs-ippinfra10-20150619-5100.18.pdf [STD92]: https://tools.ietf.org/html/std92 ________________________ Michael Sweet _______________________________________________ ipp mailing list [email protected] https://www.pwg.org/mailman/listinfo/ipp
signature.asc
(application/pgp-signature, 874 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIzBAEBCgAdFiEEkIbDzcZsP1Y8+PQFvmfHXsgfMkQFAmDJ+P0ACgkQvmfHXsgf MkS3ihAAgzEcpLpGKmvsl3/l5fCVYbCwTuplAouO/f8x4ePl0l8C3UivSyHn9qX2 rw7acit5yxG83DDJRdWCbydld29pXXyK7hEGWQWvqPUWQT38a2j5nvzys3HaEHtm LLmYYEMkO231xTJh44pyrFVGnFoDMWyKxV/+/KcHIgyvRUpzHVaFs7MryXjuiuDk r8wqixTfHRB2A+zdAFadtWGtp8aZUS+Tjldek3Yroqg3J+Ocno74G6/XvFudPQro hwvb+2nM8WQ962RS1HmZ4tp6q4853jn7DRJoDnuWnwPPnyzrrnsd5GwbJtxbUD/t eF4BjwqwjaBDboNoK0NkO17AmcCDcuNl5rbtCXeQtNgOX/XlsJ4mD0OOm7NAaKKX BK8V6p2A5fUFGE7ReGegSgMGakqeoVb9Itf9yylWwAK+l5CQiQTsiuSnTm10rkvy xdyaaYXtCbAfNLeJEqagxiYD8GFuGGbIe7L8i1ru9BSl6ytHuw/2+2RjxARH/ZXB noIdoTeyi2Lfa7Niuj/LQ02O+7FoBQSC2x5dIpU3/0/Q8QW9lEL2uXq3sZm7J/L0 20Cy5DV/WWyknYC0KN3EC8O7EQmgFR/ByV+5goK6f8Uo5VSjEr9BG33sGWVet/v9 mXqeDojNubiZFmc6REsT7RPMtZud2kl+yMgVzvHF09Ga+O1wx58= =Tnh6 -----END PGP SIGNATURE-----