IETF Plenary Session Wednesday, 20 July 2016 Berlin, Germany Minutes by Mary Barnes 1. Welcome Jari Arkko welcomed the community to the IETF 96 Plenary. Jari noted the NOC's new network monitoring service - have implemented BCP 38 in the IETF network. Jari recognized the host. 2. Host Presentation Slides: https://www.ietf.org/proceedings/96/slides/slides-96-ietf-plenary-16.pdf Tom Walsh and Alia Atlas from Juniper welcomed the IETF to Berlin. Tom thanked the other Juniper employees that helped with the event. Kevin Walker (security CTO) will be speaking on advancing cybersecurity through NGP during lunch on Thursday in Potsdam 1 13:00-13:45. Jari recognized Juniper with a plaque. 3. Brief updates on hot topics 3.1. IETF-wide issues Slides: Jari noted that the material is available in the reports online: There are a lot of other reports: RFC-Editor, Secretariat, IANA, NOC, Hackathon. He also noted the chair's blog. The IETF 96 Hackathon had 150+ participants including things like TLS 1.3. Hackathon slides: Participants: 1348, 283 newcomers (IETF-93 had 1387 onsite), 300 remote participants Jari provided an overview on how to follow what the IESG does. Jari provided a brief discussion of expectations on professional behaviour at the IETF. He noted several experiments including facilitators for IETF discussion list, Hackathon space at the lounge area and later meeting start time. 3.2. Administrative topics IAOC/IAD Slides: IETF Trust Slides: Ray Pelletier provided a brief meeting snapshot and mentioned tech talk on Thursday. Ray thanked Juniper and Tom Walsh, Alia Atlas and Ross Callon. He noted various sponsors for Hackathon, Bits 'n Bites, Network, code sprinters, NOC, Verilan and Meetecho. Leslie Daigle mentioned a new lawsuit in which the Internet Society is a defendant relating to IETF activities. She provided an update on IETF-100. IAOC is seeking input to improve guidance for selecting meeting venues, including output of MTGVENUE WG. IAOC transparency update: IAOC did a BCP 101 compliance review at their retreat. She mentioned issues around Hotel contracts and what information could be provided to the community. IAOC believes that providing this information could weaken the IAOC's negotiation capabilities. Leslie provided an update on IAOC committees which are constituted annually. IAOC is currently looking for committee volunteers. She noted that more detailed slides are available in the proceedings. Tobias Gondrom provided the IETF Trust report. Lou Berger elected as trust treasurer. Jorge Contreras confirmed as trust attorney. Changes for the trust this year: the most important change is preparing to assume the responsibility for the IANA IPR. IETF trust is willing to hold intellectual property rights. Tobias mentioned several IANA related preparatory activities. IETF trust is filing for 501(c) status (tax exempt) under US regulations. Trust financial statements will now be separate from IETF statements. Reports are issued monthly. Tobias noted new policies that have been adopted - Conflict of Interest policy and records retention policy. He noted that a consulting agreement has been made with Scott Bradner (pro bono capacity). 3.3. NomCom Update and requests Slides: Lucy Lynch provided details on the constituency of the 2016-2017 Nomcom. In addition, she highlighted the open positions, indicating those who are not willing to be reconsidered for their position which is a total of 6. Dates for the selection cycle were provided - nominations open August 25th, 2016 and close October 8th, 2016. 3.4 RFC Editor update Slides: Heather Flanagan provided a short version of the update of the RFC Format - drafts are done, RFPs to go out after this IETF with coding to start at the end of this year. She noted that all these docs will go through a bis process - issues to be captured in github. 3.5. IRTF Update Slides: Lars Eggert noted that there is a long report that is part of the IRTFOPEN meeting from earlier this week. He provided a summary of all the meetings held this week. Lars noted that he is stepping down next March. There are currently 5 candidates under consideration by the IAB - please send comments by this Friday. He highlighted the Applied Networking Research Prize winners at IETF-96: Dario Rossi and Samuel Jero were the winners and they provided presentations of their research. There have been 5 years of ANRPs - 26 award winners overall - roughly 6 awards per year. Lars described a new activity - Applied Networking Research Workshop - first one co-located with IETF-96 (on Sat. July 16). The next workshop is planned for IETF-99. 3.6. IETF funding update Slides: Kathy Brown (ISOC CEO) provided background on the endowment, which is now called the IETF endowment. Kathy noted that they have been tried to re-energize the activity. The aim of the endowment is to provide long term support to IETF. There is no intended change in the way that ISOC currently funds IETF. This is a long term fund where a principal is established upon which the earnings can be used towards IETF financial needs. Kathy noted 4 new contributions totaling $3 million. The total is now $4.1 million. The goal is $20 million. Contributions starting at $75.00 are welcome: www.sustainIETF.org. Kathy recognized the 4 contributors: - AFRNIC (Daniel Shaw) - ARIN (John Curran) - RIPE NCC (Christian Hoffman) - Internet Society (Gonzalo Camarillo) Each of the representatives made a short statement. 4. IETF 97 Welcome Slides: Yi Zhao provided an overview of IETF-97 meeting in Seoul. Yi thanked the co-host (CNNIC) and noted additional opportunities for sponsorship. He also highlighted the Hackathon which will be Saturday & Sunday, 12-13 November. 5. "Tech" topic: Keep it Simple - the Cost of (too many) Standards Slides: Ross Callon introduced a presentation he had given in the Routing area this week, which is likely applicable to other areas. He noted that this is entirely his personal impressions. Ross stated that we are seeing too many options and multiple ways to do the same thing. He provided an example - VPNs and Encapsulations. There are connection oriented approaches and connectionless approaches, leading to lack of interoperability. He provided details on what causes these challenges going between networks. Ross provided his perspective on the Internet being the largest "machine" ever made - it couldn't have been done by a single vendor or service provider. It requires real and effective standards. Ross suggested that IETF needs to avoid "frivolous" standards and he suggested this can't be done topdown. He ended with: "We all need to take up the challenge to do what is best for the Internet and its technologies." Jari noted the number of IETF meetings Ross has attended (89) and gave Ross a plaque. 6. IAB Open Mic Session The IAB convened on the stage. Andrew Sullivan noted the "black tie" wing of the IAB (Heather Flanagan and Lee Howard). * Mikael Abrahamsson: Human issue around "How is crypto going to work end to end?" came up a few years ago. Did anything happen after that? Andrew Sullivan: There remain some challenges. We have a Privacy and Security program. Ted Hardie: Focus has been more on how to make the pieces of the stack work together. Interfacing with StackEvo, noting MARNEW workshop. ACCORD came out of that. 2 pieces of human factors: 1) key management 2) how do we make this comprehensible to those that are using this technology? Ted gave Tesla as an example. He noted the program works with W3C. The presentation layer hasn't really been a focus. Russ Housley: We have seen an uptake where people are using more techniques to encrypt email. It's still too hard to get a cert. But there is more uptake automatically (e.g., QUIC). Joe Hildebrand: Have made some progress on getting a cert easy (e.g., ACME). If you look at the amount of encryption before and after "Let's Encrypt" came online - there is an increase in the curve. Mike: Are we satisfied with this? Are we increasing the work here? What is the future plan? Andrew: If we were satisfied with the Internet, we'd just go home. Of course we're not satisfied - it is hard. We shouldn't have to explain certs to anybody. If we look at work in ACME, we are making progress. Not as fast as we'd like, but there is a trend. To Ted's point, we're not exactly user interface people. We may not be a position to influence. Mike: most of the freeware I use doesn't really work or interop right. Even if we do it right here and no one is implementing it, then it's not useful. Is there anyone else we can work with to get the infrastructure that we need to have to get this to work? Ted: Work with the Internet Society Deploy 360. If you have ideas on programs that are outreach or educational, you can take those to the IAB or directly to ISOC. Lars: If you have suggestions, then please share. Mike: Send an email? Joe: Yes, just send us an email and we'll find a place to get work done. * Don Hollander: You said there were huge issues in the internationalization area. What are the issues and what's being done about them? Ted: Internationalization has been an IAB program for some time. At the moment it's restricted to focus on how to deal with the Unicode consortium haven taken context into account for characters. A glyph may be used in one context that's different when it's used in another language. Most uses on the Internet (usernames, passwords, etc.) don't come with a context. Two routes to resolve ambiguity: 1) fail 2) limit (artificially) which method to construct a glyph is permissible. IAB issued a statement around this and asked IANA to hold what Unicode version was permissible at version 7.3 - Unicode is now at version 9. We are taking another swing at this now. Andrew: We have reconstituted the program a little. We had a BoF in Dallas on this topic and it didn't yield the results we wanted. If you know people that are interested in this problem and want to work on this problem, let us know. This is an urgent problem. Most people that aren't on the Internet today don't use Latin characters. The problem is because Unicode code points were developed for a different problem. Dave Thaler: The BOF Andrew mentioned was called the Locale-free UniCode IDentifiers (LUCID) BoF if you want to find it in the proceedings. * Tom Herbert: If you look at Ross' list of protocols, most are over UDP. Why is this? UDP does not benefit end hosts. It's overhead, you have to deal with checksum, etc. The reason we are doing this is middleboxes. Question is whether this is a concern? Are we going to wind up with an Internet that's mostly UDP. Joe Hildebrand: the problem is not only middleboxes. It's also in OS APIs. If TCP is limited in the kinds of things you can do with it, then you're left with UDP. Dave Thaler: this is not a new problem. A few years ago we were having this same discussion with everything over HTTP instead. The Stack Evolution (previously IP Evolution) Program has been looking at this problem. Brian Trammell: The reason it is interesting to move the waist is because if you run over HTTP, then you're also running over TCP. The idea of pushing this down to UDP is because it's not in the way in this case. You can deal with a process in a host. It gives you the ability to take these identifiers, due to use of NAT, ports are part of forwarding identifier. We can recognize this and use UDP to get around it. We're really talking about taking packets that have different properties - it's not the same old UDP - it looks like UDP to the wire. The set of protocols Ross showed are a different problem. In Ross' list, UDP is for tunnels. Suggest that people come to PLUS - idea is to use shim layer to resolve ambiguity. Tom: don't want to use UDP just to get through firewall. Example, IPv6 flow label for ICMP. Can fix aspects of this problem. * Janardhan Iyengar: Most traffic goes over UDP or TCP. The fact that we can't deploy other transport protocols (really UDP is a way to build a transport protocol) is due to a number of problems - not just middle boxes. It's a reaction to state of deployed world. Don't see this as a problem. It's natural and should have been anticipated. Think about things in a functional way and not just a layered protocol way. UDP is a demux protocol. Transport protocol is what sits on top of UDP. * Peter Lothberg: Looking at traffic growth. What will it look like in 2020? Right now, guessing and simulating, making assumptions. All the equipment in the core won't be there 7 years from now. If IETF had some sort of target. Why can't we look forward? What kind of protocols? What kind of requirements? Don't build tomorrow's Internet based on yesterday's problem. * Stuart Cheshire: Have heard this statement a lot with regards to UDP only being used to get through firewalls and NATs - disagree with this. It's a demux layer. If we follow RFC 7934, maybe we can have an address per process. Until then, we need a demux layer. Joe: if we had a demux layer with TCP and UDP, we might have been able to do ICMP in band. * Phillip Hallam-Baker: I hear two types of complaints. 1) there are these middleboxes in the network and they futz with my packets in an undesirable way 2) I'm trying to get my middlebox to work and people are creating packets that my middlebox can't futz with. Unless you are wanting an APP, I don't want your middlebox there - no HTTP caching and no redirection. I just want a pipe from A to B. Going to UDP is an excellent way to solve part of the problem and encrypting packets should do the rest. Lee Howard: sympathetic to that point of view. But, if you turn it the other way, people build networks for their own services - e.g., content. There are all kinds of reasons to build middleboxes. Brian Trammell: PLUS BoF tomorrow morning * 7. IAOC Open Mic Session The IAOC convened on the stage. * Lee Howard: I was talking to somebody online whose not here this week who looked at meeting statistics. In the past, they've included the number of women. Do we know how many are here this time? Ray Pelletier: Declined to answer: 114. Female: 130. Male: 1150 * Stewart Bryant: Can you look at the parameters being fed into cookie consumption algorithm? Leslie: I think there's some psychology involved - e.g., people taking too many (because they're there). * 8. IESG Open Mic Session The IESG convened on stage: * Lars Eggert: Noted diversity on IESG. Andrew: There was a message to the IETF list on the diversity topic today and IAOC committees. * Michael Richardson: It's time to run experiments to address meeting time problem. Maybe ADs need to be more stringent. Suggest each WG gets one hour and then consider if more time is necessary. Appreciated the extra rooms. Trying to think of a system where you could book your meeting for one hour and then continue if you need it. Lacking cross area review with current model. Missing opportunities to interact due to exhaustion. Stephen Farrell: How many people would prefer more unstructured time? Kathleen Moriarty: we had discussed some of this with regards to inclusivity. This could be problematic with newcomers. Need to figure a way to enable them to do work. Alia Atlas: One thing done at the IESG retreat was to have breakouts. Wondering if something like that could help. Would like to see chairs try some of these creative things. Spencer Dawkins: None of the people on IESG were placed there for meeting logistic planning skills. Appreciate Michael's suggest. IESG has been discussing this - interested in hearing other suggestions from the community. It's worth pointing out that we are having a meaningful conversation about doing large scale plenaries. Inclusivity is important. * Robert Sparks: I would like Stephen to reframe the question about more free time. The last several meetings IAOC and secretariat have been looking to find space for ad hoc meetings. We would benefit greatly from having fewer directly organized meetings and more ad hoc. But, need to consider remote participation. Spencer: We've been talking about running meetings not just going through drafts. Mentioned QUIC and the fact that it hits multiple areas. Need multi-disciplinary meeting. * Mark Nottingham: Since we're on this topic, last December the IESG put out a statement about virtual and interim meetings. When we did HTTP 2.0, we had 7 interim meetings. We had to keep that high pace up. Under the policy that came out in December would that model be allowed? Purpose of meeting physically is to get to know people - developing shared mindspace helps when you are working at distances. Benoit: Intent of statement was to give you tools if you wanted to. You don't have to do everything virtual. Alissa: That wasn't the intent of that statement. We want WGs to meet as often as they need to. Stephen: I don't think you entirely did misread it. There is some tension amongst IESG about this. * Lars Eggert: I like Michael's suggestion to take some of the stress off the week. Give WG extra time if they have successful interims (or whatever milestone/objective). 2nd point: we don't have a WG called MTGPLAN. Joel Jaeggli: There's two things about scheduling: 1) between time we begin scheduling and when we post agenda is about one month. Get 40-50 hours freed up by the time we start. So, it's misleading to look at initial set of meeting requests. 2) we have this experiment to address local conditions (e.g., 10am start) - what to do with your hour in the morning? Gives folks time to meet in the morning. Spencer Dawkins: I see people complain about 10 am start (losing 5 hours of IETF time). It's what we do with the situation we're in. * Charles Nevile: A few observations. Meetings that last for more than one hour, show a tendency to degenerate. Free meeting time is valuable if you have a way to publish what you're going to do - important for visibility. 10 minutes drinks breaks are insane. * Jim Galvin: We heard about 10% of physical attendees being female. 30% (IESG) leadership are female. * Phillip Hallam-Baker: I like idea of using github. But, with github don't know what credentials to use. There's no information available on WG pages. Thinks there needs to be some controls around it. Github info should be on the charter page. Finally, want a complete chain of discussion and actions archived so it can be subpoenaed. Want backups maintained. Jari: Agree WGs should point to relevant materials, how to access, history, etc. This is a new thing and it will evolve. Stephen: agree with overlying point. But, don't think primary motivation should be for patent litigation. Alia: We've been experimenting with doing this differently in various WGs We're still in the process of discussing and describing how to use the tools and make it available. * Pat Thaler: I don't really care about meeting start time. * Unidentified IETFer: Let's put all our docs in one repository. Subpoenable by which jurisdiction? * Lee Howard: In a BoF earlier, talking about a charter and it was on github and it wasn't accessible via v6 only network.