Perhaps

An implementer could leverage an approach described as "the N+1 and
N+2 release strategy".  In release N+1, the implementer introduces a
new configuration parameter to configure "egbp insecure-mode".  Upon
installation of release N+1, if the value is not configured, an
"insecure" value will be automatically generated and saved to the
configuration, and an implementer could begin to display informational
warnings to the operator that certain parts of the configuration are
incomplete.  Thus, In release N+1, operators of the BGP implementation
become aware that a configurable value exists in the implementation,
and can prepare accordingly.  In release N+2 or later, the default
value becomes "secure".

As a result, any new installation of release N+2 will adhere to this
document.  Installations upgraded from version release N+1 will
adhere to the previous insecure behavior, if no modification was made
to the "ebgp insecure-mode" configuration parameter. Note that versions
upgraded directly from N to N+2 will change their behavior from
"insecure" to "secure".


On Thu, Jun 8, 2017 at 4:13 AM, Job Snijders <[email protected]> wrote:

>
> On Wed, 7 Jun 2017 at 19:06, Eric Rescorla <[email protected]> wrote:
>
>> On Thu, Jun 8, 2017 at 1:34 AM, Job Snijders <[email protected]> wrote:
>>
>>> Hi Eric,
>>>
>>> On Tue, Jun 06, 2017 at 10:50:01AM -0700, Eric Rescorla wrote:
>>> > ----------------------------------------------------------------------
>>> > COMMENT:
>>> > ----------------------------------------------------------------------
>>> >
>>> > I am having a little trouble reading Appendix A.
>>> >
>>> > If I understand correctly, the idea is:
>>> >
>>> > - In version N, you have a behavior X
>>> > - In version N+1, you introduce a setting S with default value S=X
>>> > - In version N+2 you change the default to S=!X
>>> >
>>> > However, the text says that "installations upgraded from release N+1
>>> > will adhere to the previous insecure behavior"
>>> >
>>> > Do you need to say that in N+1, you save the value S=X so that in N+1,
>>> > it continues to apply?
>>>
>>> If in N+1 you save S=X, then in N+2, if S is defined as X, behaviour X
>>> will apply.
>>
>>
>> Well, yes.
>>
>>
>>
>>> If S is not defined, or defined otherwise (like with a fresh
>>> install, not an upgrade), you will have !X behaviour.
>>>
>>
>> Yes.
>>
>> My question is whether in the N+1/N+2 paradigm you are proposing that in
>> N+1 you save S=X.
>>
>
>
> Yes.
>
> Do you have a proposed sentence that should be added if this isn't clear?
>
> Kind regards,
>
> Job
>
_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow

Reply via email to