[pcap-ng-format] [tcpdump-workers] New Version Notification for draft-tuexen-opsawg-pcapng-02.txt

Michael Tuexen tuexen at fh-muenster.de
Mon Sep 28 20:42:22 UTC 2020


Without OPSWG...
> On 28. Sep 2020, at 22:23, Guy Harris via tcpdump-workers <tcpdump-workers at lists.tcpdump.org> wrote:
> 
> 
> From: Guy Harris <gharris at sonic.net>
> Subject: Re: New Version Notification for draft-tuexen-opsawg-pcapng-02.txt
> Date: 28. September 2020 at 22:23:33 CEST
> To: Michael Tuexen <tuexen at fh-muenster.de>
> Cc: Michael Richardson <mcr+ietf at sandelman.ca>, pcap-ng-format at winpcap.org, opsawg at ietf.org, Jasper Bongertz <jasper at packet-foo.com>, tcpdump-workers at lists.tcpdump.org, Fulvio Risso <fulvio.risso at polito.it>, Gerald Combs <gerald at wireshark.org>
> 
> 
> On Sep 28, 2020, at 12:06 PM, Michael Tuexen <tuexen at fh-muenster.de> wrote:
> 
>> Do we want to finally publish that? Up to now, I think the point was to
>> find a home where it is substantially discussed and improved...
> 
> For example, unlike pcap, which is not easily changeable (you *can* change it, but that involves adding new magic numbers), pcapng can have new block types and option types.
> 
> There are extensible protocols with RFCs; that's handled with protocol registries:
> 
> 	https://www.iana.org/protocols
> 
> and with new I-Ds -> RFCs for extensions.  We'd have to set up registries for block and option types if we publish an RFC for pcapng.  We would *also* want a registry for link-layer header types, for both pcap and pcapng.
> 
> See, for example, RFC 1761
> 
> 	https://tools.ietf.org/html/rfc1761
> 
> which specifies the Sun snoop file format, and RFC 3827:
> 
> 	https://tools.ietf.org/html/rfc3827
> 
> which sets up a registry for snoop link-layer header types:
> 
> 	https://www.iana.org/assignments/snoop-datalink-types/snoop-datalink-types.xhtml#snoop-datalink-types-2
> 
> and adds some new entries to it.
So we can make use of IANA. Shouldn't we write up (I can work on an initial version) of
a specification for .pcap. Would you volunteer as a co-author?
Establish there the link layer header type IANA registry?

We can reuse that for the .pcapng spec...

Best regards
Michael
> 
> _______________________________________________
> tcpdump-workers mailing list
> tcpdump-workers at lists.tcpdump.org
> https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5257 bytes
Desc: not available
URL: <http://www.winpcap.org/pipermail/pcap-ng-format/attachments/20200928/a25c2797/attachment-0001.bin>


More information about the pcap-ng-format mailing list