Re: DRAFT Montreal minutes - X#NodeArchitecture comments

William Studenmund <[email protected]>
Newsgroups gmane.ietf.ips
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Aug 17, 2006, at 6:43 AM, Paul Koning wrote:

>  Mallikarjun> Hi Ken, Can you please point me to RFC 3720 text that
>  Mallikarjun> says NotUnderstood is always an error?
>
>  Mallikarjun> The closest I can find is in section 5.2, page 55:
>
> Page 54, second paragraph:
>
>    The constants "None", "Reject", "Irrelevant", and  
> "NotUnderstood" are
>    reserved and MUST ONLY be used as described here.  Violation of  
> this
>    rule is a protocol error (in particular the use of "Reject",
>    "Irrelevant", and "NotUnderstood" as proposed values).
>
> "as described here" is as responses to negotiating keys.  The text
> already explicitly disallows their use as proposals.
>
> A declaration isn't exactly the same as a proposal, but it certainly
> isn't a reply to a proposal, so by the above text "NotUnderstood" is
> prohibited.
>
> The 3720 bug is this: an implementation that doesn't understand a key
> doesn't know whether that key is declarative or negotiated.  If it
> assumes the latter it would have to reply NotUnderstood.  If in fact
> it was a declarative key then by the current text that's a protocol
> violation.
>
> A good way to fix this is to add two rules:
>
> 1. If a key is not understood, it is assumed to be a negotiation
>    key (and a NotUnderstood reply must be sent).
> 2. If a declarative key is sent, and a reply is received from the
>    other end with that key and a value of NotUnderstood, this is
>    a protocol violation only if the key is required to be implemented.
>    If it was not required (i.e., X# keys) then a NotUnderstood
>    reply must be silently ignored.

I like the proposed fix. The two comments I have are:

1) While X# keys are not required to be understood, any future  
"normal" keys we define will also fall into this category for  
existing devices.

2) I note that a device may chose to pretend it doesn't understand a  
key that isn't mandatory, even though it really does. For  
X#NodeArchitecture, a device may answer with differing levels of  
detail. The lowest level may well be to pretend that the key's not  
understood. In such a case, the device MUST fully pretend it doesn't  
understand, and as per rule (1) above, it MUST not offer the key and  
MUST respond with "NotUnderstood."

Note: this is a different behavior from understanding  
X#NodeArchitecture and choosing not to declare a value to the other  
side.

Take care,

Bill
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFE5LpfDJT2Egh26K0RApccAJ9gvQ1wVdAD/U66DkSMUXM8hbLgYACfTXMX
4O7tC0z/Uatk/LfNJP/9+SY=
=uObj
-----END PGP SIGNATURE-----

_______________________________________________
Ips mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/ips
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.