Re: Comments on draft-ietf-nfsv4-integrity-measurement-07
Benjamin Kaduk <[email protected]> Mon, 11 Nov 2019 10:11:13 -0800
| Newsgroups | gmane.ietf.nfsv4 |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Nov 08, 2019 at 10:12:02AM -0500, Chuck Lever wrote: > > > > On Nov 7, 2019, at 6:13 PM, David Noveck <[email protected]> wrote: > > > > > Why isn't the SELinux label work a problem in this regard? > > > > I don't understand Spencer's position well enough to know if he has > > a problem with this, but given that this model has already been adopted > > by the working group for arguably system-level attributes, it is hard for > > me to believe such objections, if they were to exist, would be widely > > shared. > > > > Since adopting a parallel approach for the IMA metadata > > format is compatible with your plans for -08, perhaps you should > > adopt a similar approach (an IANA registry with a specification-required > > policy) for IMA. I know that such things have been suggested in the past > > and seemed at the time like overkill, but, given that there are a number > > of existing formats, and likely there will be a more general format which > > has not been arrived at right now, it might be best to take this step, > > hoping that it will deal with the objections about the lack of a metadata > > format specification even though the Linux community is kind of slow > > about producing one. I think you ould have to add a new fs-scope > > attribute with the id, rather than stick with the local-policy approach, > > but there would b no requirement tat the client check this. > > > > BTW, specification-required and even RFC-required do not require a > > normative specification. With specification-required, the IETF does > > not have to be involved in writing the spec although a designated-expert > > would have to check that it clear enough to enable implementation. > > It appears that draft-ietf-nfsv4-integrity-measurement can't move > forward without some description of the IMA metadata format. My name is not Magnus, but I'm not fully convinced of that yet. > My preference would be that the Linux community is responsible for > the process and document(s) that describe their own format. Failing > that, a description can be added to integrity-measurement, as I > recently proposed. > > To make an IANA registry a sensible thing to do, at least one more > independent integrity metadata format will have to be identified. I'm sure I can find many examples of IANA registries that are created with only one substantive initial entry; why would this one be any different? The point is to have a clear extension point, not (necessarily) to require someone to use it from the start. (Though, perhaps, see also draft-ietf-tls-grease...) -Ben _______________________________________________ nfsv4 mailing list [email protected] https://www.ietf.org/mailman/listinfo/nfsv4