Re: I-D Action: draft-ietf-nfsv4-integrity-measurement-06.txt

Chuck Lever <[email protected]>
Newsgroups gmane.ietf.nfsv4
Message-ID <[email protected]>

> On Sep 23, 2019, at 10:19 AM, David Noveck <[email protected]> wrote:
> 
> > The guidance in that section falls into the realm of "compromise between the Linux community and the > specification writer"  
> 
> I gaathered that, but it should not be assumed that the woring group is prepared for the same level of compromise,

Help me understand exactly why the current section is lacking. I don't see
why the exact authorization mechanism must be specified in this document,
since:

a. it doesn't matter for interoperability
b. the mechanism used for updating IMA metadata on
   local files on Linux (the CAP_SYS_ADMIN capability)
   does not exist in NFS; moreover capabilities are
   not defined in a standard
c. authorization is done by policy in other arenas
   (for example, the IP-based access control that is
   implemented by most current NFS servers), thus it
   should be sufficient here too


> even though it should strive to be as helpfu as it can.   Also, it appears that the Linux community cannot make its own mind about how to address this issue so perhaps some intra-community compromise is in order.

See above. It's really not a simple matter of the community shrugging and
punting.


> If that isn't forthcoming, our only option might to approve this as an experimental/informational  RFC and upgrade it when the Linux community gets its act together.

That's a bit unfair. See above: there is a complete mismatch between how
it works on local file systems and what mechanisms are available with NFS.
IMO we are in a position to enable both "close enough" server implementations
and for server implementers to exercise some innovation.

Anticipating the IESG's reaction to this text is probably not going to be
possible or helpful. I'd rather hear their complaints from them. Let's focus
on the WG's concerns first.


> On Mon, Sep 23, 2019 at 12:28 PM Chuck Lever <[email protected]> wrote:
> Context: The guidance in that section falls into the realm of "compromise between the Linux community and the specification writer".
> 
> 
> > On Sep 23, 2019, at 8:23 AM, David Noveck <[email protected]> wrote:
> > 
> > > It's probably ready for (it's first) WGLC. :-) 
> > 
> > I feel that the basic issue with section 4.3.2 has not been 
> > satisfactorily resolved.    I'll send out a mail with the details 
> > in the next few days.
> > 
> > 
> > 
> > On Sun, Sep 22, 2019 at 7:15 PM Chuck Lever <[email protected]> wrote:
> > 
> > 
> > > On Sep 22, 2019, at 4:11 PM, [email protected] wrote:
> > > 
> > > 
> > > A New Internet-Draft is available from the on-line Internet-Drafts directories.
> > > This draft is a work item of the Network File System Version 4 WG of the IETF.
> > > 
> > >        Title           : Integrity Measurement for Network File System version 4
> > >        Author          : Charles Lever
> > >       Filename        : draft-ietf-nfsv4-integrity-measurement-06.txt
> > >       Pages           : 18
> > >       Date            : 2019-09-22
> > > 
> > > Abstract:
> > >   This document specifies an OPTIONAL extension to NFS version 4 minor
> > >   version 2 that enables Linux Integrity Measurement Architecture
> > >   metadata (IMA) to be conveyed between NFS version 4.2 servers and
> > >   clients.  Integrity measurement authenticates the creator of a file's
> > >   content and helps guarantee the content's integrity end-to-end from
> > >   creation to use.
> > > 
> > > 
> > > The IETF datatracker status page for this draft is:
> > > https://datatracker.ietf.org/doc/draft-ietf-nfsv4-integrity-measurement/
> > > 
> > > There are also htmlized versions available at:
> > > https://tools.ietf.org/html/draft-ietf-nfsv4-integrity-measurement-06
> > > https://datatracker.ietf.org/doc/html/draft-ietf-nfsv4-integrity-measurement-06
> > > 
> > > A diff from the previous version is available at:
> > > https://www.ietf.org/rfcdiff?url2=draft-ietf-nfsv4-integrity-measurement-06
> > > 
> > > 
> > > Please note that it may take a couple of minutes from the time of submission
> > > until the htmlized version and diff are available at tools.ietf.org.
> > > 
> > > Internet-Drafts are also available by anonymous FTP at:
> > > ftp://ftp.ietf.org/internet-drafts/
> > 
> > Fresh revision incorporates comments from IETF 105 and Linux
> > Security Summit North America 2019.
> > 
> > It's probably ready for (it's first) WGLC. :-) It's OK if the
> > chair prefers to wait until we have more fully dealt with
> > outstanding RFC 5661 errata.
> > 
> > 
> > --
> > Chuck Lever
> > 
> > 
> > 
> > _______________________________________________
> > nfsv4 mailing list
> > [email protected]
> > https://www.ietf.org/mailman/listinfo/nfsv4
> 
> --
> Chuck Lever
> 
> 
> 
> _______________________________________________
> nfsv4 mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/nfsv4

--
Chuck Lever



_______________________________________________
nfsv4 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/nfsv4
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.