Re: [Anima] Is this how BRSKI/IPIP works?
Eliot Lear <lear@cisco.com> Thu, 13 July 2017 20:58 UTC
Return-Path: <lear@cisco.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4311C12EC14 for <anima@ietfa.amsl.com>; Thu, 13 Jul 2017 13:58:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.503
X-Spam-Level:
X-Spam-Status: No, score=-14.503 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P5JA9SYRx818 for <anima@ietfa.amsl.com>; Thu, 13 Jul 2017 13:58:49 -0700 (PDT)
Received: from aer-iport-2.cisco.com (aer-iport-2.cisco.com [173.38.203.52]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C4D261267BB for <anima@ietf.org>; Thu, 13 Jul 2017 13:58:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2770; q=dns/txt; s=iport; t=1499979528; x=1501189128; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=9XcJQvD2/+//QZgalfha1ht4eS6+RUseKZ9OMq5O2g8=; b=GI0cQEfoIpZspk0TfMk5H8imI7qnu8XAbYAgO5RG2uj64b9kRrnD7WXa Q2P7HO8j/ko/JZ/mf8wSlhU6GOJ2GOGatj6RITqBHagL+7wzJnaTEx+fV OAaikoQNafohCnDKeCGnZKbCOs9w8SvQTxp/dhxYkJhg/ROeN+IVBPkYo o=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CMAAC43WdZ/xbLJq1cGQEBAQEBAQEBAQEBBwEBAQEBk1tzkQOWA4IRB4I0gzsChCgYAQIBAQEBAQEBayiFGQEFI1YQCw4KKgICVwYBDAgBAYorrWh+giaLJAEBAQEBAQEBAQEBAQEBAQEBAREPgyiFLiuCeYd9gmEBBJ8whCyCHY1LiymHAJVVHziBCjEhCBsVh2E+iUMBAQE
X-IronPort-AV: E=Sophos;i="5.40,355,1496102400"; d="asc'?scan'208";a="653226186"
Received: from aer-iport-nat.cisco.com (HELO aer-core-3.cisco.com) ([173.38.203.22]) by aer-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 13 Jul 2017 20:58:46 +0000
Received: from [10.61.242.235] ([10.61.242.235]) by aer-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id v6DKwkBk021032; Thu, 13 Jul 2017 20:58:46 GMT
To: Toerless Eckert <tte@cs.fau.de>, Brian E Carpenter <brian.e.carpenter@gmail.com>
Cc: Anima WG <anima@ietf.org>
References: <467b3a9b-6fe0-c01f-6165-18e6e290a28c@gmail.com> <20170706033719.GF14122@faui40p.informatik.uni-erlangen.de> <827f69e7-4730-7bd2-c0ac-987e94adc61d@gmail.com> <20170706070938.GG14122@faui40p.informatik.uni-erlangen.de>
From: Eliot Lear <lear@cisco.com>
Message-ID: <c885cdc9-0ec9-98fd-858d-07c66bb84e25@cisco.com>
Date: Thu, 13 Jul 2017 22:58:45 +0200
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <20170706070938.GG14122@faui40p.informatik.uni-erlangen.de>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="vMRSWKslnwsTnf91DJTsIRwhb1dQRDmIn"
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/1GoAA5PZupWrkb7682IRbLtT5Fg>
Subject: Re: [Anima] Is this how BRSKI/IPIP works?
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Jul 2017 20:58:50 -0000
Hi Toerless, On 7/6/17 9:09 AM, Toerless Eckert wrote: > On Thu, Jul 06, 2017 at 04:34:05PM +1200, Brian E Carpenter wrote: >> It used to be, but the recommendation today is a pseudo-random >> value (RFC7217). In any case it's a software choice. > brand new recommendations do not equate to be expected > standard practice in products. Would be very good to have > folks with practical insight into various products to > provide more information. On this point, I think it's quite likely that we will see a good number of devices fielded that will do a lousy job of PRNG, and so it would be inadvisable for them to implement RFC7217, lest they test their DAD code in ways not really intended. I'm not thinking about iPhones here, but energy harvesting devices like some light switches, and a bunch of, well,... crap. The question is whether you should design for these devices. IMHO "no" is a perfectly valid answer, but I'm still a bit skeptical about the value of 7217 for these class of devices in any event. Eliot
- [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear (elear)
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Max Pritikin (pritikin)