Re: [Anima-bootstrap] bootstrap over CoAP

Brian E Carpenter <brian.e.carpenter@gmail.com> Sat, 09 July 2016 18:52 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: anima-bootstrap@ietfa.amsl.com
Delivered-To: anima-bootstrap@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 36BCA12D1B8 for <anima-bootstrap@ietfa.amsl.com>; Sat, 9 Jul 2016 11:52:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.8
X-Spam-Level:
X-Spam-Status: No, score=-0.8 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AdP5GtUCGs9M for <anima-bootstrap@ietfa.amsl.com>; Sat, 9 Jul 2016 11:52:54 -0700 (PDT)
Received: from mail-wm0-x22a.google.com (mail-wm0-x22a.google.com [IPv6:2a00:1450:400c:c09::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0433D12B039 for <anima-bootstrap@ietf.org>; Sat, 9 Jul 2016 11:52:54 -0700 (PDT)
Received: by mail-wm0-x22a.google.com with SMTP id f126so48559079wma.1 for <anima-bootstrap@ietf.org>; Sat, 09 Jul 2016 11:52:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:to:references:cc:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=R/SHg0ekjdfI8lK4GWMyusyXAgt36hvDrGywi7XOGzw=; b=Jruw6OczkMCkFn2kQF0kkVE2dj5Joj//CJeqGIiiftmedAhV/drYodL0tcE6KKugLf 6j6L9e6Qg3pS5MWnqWjXEVxHPJTa3QgK8tWLLmDt2YBJcMXJODOOYDHE571IcjtpzEXp 0+8m5wu6Ze3I35VExRnl9XhN0erQyPtH9t4P6/EaSCsISFKpicxOfALEK75WH/9x0je1 JyosaeLn+UuHjJXrCRvpj86RHAhwF+bVMAGURNjAcJ9CTCgJjlmJxpSL7cTfD986ZVmA 5G+Q1VeBz6TaSEOGqEBDMRL34v9V7s3WVlRCYzj9m2FODf+DMDfM7iZ/AVcR1se30hzX doKg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-transfer-encoding; bh=R/SHg0ekjdfI8lK4GWMyusyXAgt36hvDrGywi7XOGzw=; b=f5V01ITu6oeCaaaE29B+wpubh+iTg62gxnMaZUNc3Qv2bK1pqFwO4jFzgg/nuakk9W dlX1Dv0TO2AMp+WgT/Jdz6wAJrb3HkVBChyCfTUHpszOhFzKz8DSw1MPCdcjm6HXxG3b rPfN5PJ0Y5DdwhE6hcaPI3u59tLkTUc3K3YmokPzuZK7ArAbCj7+auGMwzuosgRs+5yG JdknTnbEoXvSniiDDr5XqvpZajvhVY4m4N9zqx9pc1pOQMJG8ALOMXi3Cs8ZlrLCDr4d jgbEAV9N704+sBrJ4lhi3SgC2+kJ3fZddaKiqB6kNogmudrxiKAvGjAN0MhzDAwnqJYs hqww==
X-Gm-Message-State: ALyK8tLHck5X12LaECwzNJph2wWuc440MHzjPfQr0MwHCKNtfOl8Spp4k5+3NgXdRtQ0Sw==
X-Received: by 10.28.183.134 with SMTP id h128mr3709328wmf.7.1468090372235; Sat, 09 Jul 2016 11:52:52 -0700 (PDT)
Received: from [10.0.1.29] (cpc66883-mort6-2-0-cust696.19-2.cable.virginm.net. [92.233.126.185]) by smtp.gmail.com with ESMTPSA id xs9sm1803757wjc.11.2016.07.09.11.52.50 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 09 Jul 2016 11:52:51 -0700 (PDT)
To: Carsten Bormann <cabo@tzi.org>
References: <3A2F4C70-4960-4592-9314-6EC53B53CC94@cisco.com> <5d5623cd-fe4b-e443-da5d-6a43ffb9b5c6@gmail.com> <57810029.2070408@tzi.org>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <17d1c08e-e9c6-d017-58ba-85989d56273d@gmail.com>
Date: Sun, 10 Jul 2016 06:52:50 +1200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
In-Reply-To: <57810029.2070408@tzi.org>
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima-bootstrap/skt2BFVUhjVCPJcJ8gcnwrlJ8LM>
Cc: "Max Pritikin \(pritikin\)" <pritikin@cisco.com>, "anima-bootstrap@ietf.org" <anima-bootstrap@ietf.org>
Subject: Re: [Anima-bootstrap] bootstrap over CoAP
X-BeenThere: anima-bootstrap@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Mailing list for the bootstrap design team of the ANIMA WG <anima-bootstrap.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima-bootstrap>, <mailto:anima-bootstrap-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima-bootstrap/>
List-Post: <mailto:anima-bootstrap@ietf.org>
List-Help: <mailto:anima-bootstrap-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima-bootstrap>, <mailto:anima-bootstrap-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Jul 2016 18:52:55 -0000

On 10/07/2016 01:46, Carsten Bormann wrote:
>> 1. Is CoAP/DTLS protected against corrupt packets? (Assuming we are
>> talking about UDP/IPv6 there will at least be the UDP checksum.)
> 
> DTLS ciphersuites usually authenticate the packets (and protect against
> replay), so there will be very strong protection.

Good, that's what I hoped to hear.

> 
>> 2. In the fragmentation scenario, what happens when a fragment is
>> corrupted or lost?
> 
> I'm not sure I understood that part of the draft*), but generally CoAP
> is designed so you can avoid fragmentation 

That isn't what the draft seems to say, though. However, it's clearly talking
about application-layer fragmentation to avoid IP fragmentation.

> (and use the segmentation
> provided by draft-ietf-core-block instead); the latter has per-segment
> reliability (acknowledgements and retransmits).   DTLS may require
> fragmentation during its handshake; this is mitigated if you can use a
> PSK (symmetric) or, if you need asymmetric, ECC-based ciphersuite, which
> allows the packets to stay well below 1280 bytes.

Right. So the app layer chops the message into <1280 byte pieces, and one
of them is lost...?

Regards
    Brian

> 
> Grüße, Carsten
> 
> *) We just had an interesting exchange in the CoRE WG where some people
> weren't aware of the terminology that differentiates fragmentation and
> segmentation; I apologize for sticking to that.
>