Re: [Anima] Is this how BRSKI/IPIP works?
Eliot Lear <lear@cisco.com> Sun, 16 July 2017 17:50 UTC
Return-Path: <lear@cisco.com>
X-Original-To: anima@ietfa.amsl.com
Delivered-To: anima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D5A0C124C27 for <anima@ietfa.amsl.com>; Sun, 16 Jul 2017 10:50:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.503
X-Spam-Level:
X-Spam-Status: No, score=-14.503 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cWOoGSP8xC6B for <anima@ietfa.amsl.com>; Sun, 16 Jul 2017 10:50:16 -0700 (PDT)
Received: from aer-iport-4.cisco.com (aer-iport-4.cisco.com [173.38.203.54]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5086D120724 for <anima@ietf.org>; Sun, 16 Jul 2017 10:50:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3269; q=dns/txt; s=iport; t=1500227416; x=1501437016; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=2ZROXsMvipIbE+ELPBJWhHdGoS3sKO9paOT1rVXJgsA=; b=It21Pkbv0zTXNRG/hOb2DhnKHWB1uV2eMSnMEMoVQ2a3DDVNsiIc7GBa TWURDjxBikHX/UWfXNu0OAo97DdGaJPxtdlp6n5c1PONCO950fLMjOYMx gt1enfMvixC5xyPGXaRmNQKBbp88EZ5V58zoGynoVvhBsuVTNP+WSur4u E=;
X-Files: signature.asc : 481
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0DZAgB+pmtZ/xbLJq1cGgEBAQECAQEBAQgBAQEBlFCQSSKYFQeFQAKENBQBAgEBAQEBAQFrKIUYAQEBAQIBI1YQCw4KFRUCAlcGDQgBAYojCK1qgiaLEgEBAQEBAQEBAgEBAQEBAQESD4MohS4rC4JuhEZjglSCYQEEnzSELIIdjU2LLocBlVc2IYEKMSEIGxWHYT6GTYI/AQEB
X-IronPort-AV: E=Sophos;i="5.40,370,1496102400"; d="asc'?scan'208";a="656125567"
Received: from aer-iport-nat.cisco.com (HELO aer-core-4.cisco.com) ([173.38.203.22]) by aer-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 16 Jul 2017 17:50:12 +0000
Received: from [10.61.216.24] ([10.61.216.24]) by aer-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id v6GHoB6e026037; Sun, 16 Jul 2017 17:50:11 GMT
To: Toerless Eckert <tte@cs.fau.de>
Cc: Brian E Carpenter <brian.e.carpenter@gmail.com>, Anima WG <anima@ietf.org>
References: <467b3a9b-6fe0-c01f-6165-18e6e290a28c@gmail.com> <20170706033719.GF14122@faui40p.informatik.uni-erlangen.de> <827f69e7-4730-7bd2-c0ac-987e94adc61d@gmail.com> <20170706070938.GG14122@faui40p.informatik.uni-erlangen.de> <c885cdc9-0ec9-98fd-858d-07c66bb84e25@cisco.com> <20170716172448.GA23525@faui40p.informatik.uni-erlangen.de>
From: Eliot Lear <lear@cisco.com>
Message-ID: <d007edab-3b2f-ceb2-8538-e10b33ced919@cisco.com>
Date: Sun, 16 Jul 2017 19:50:11 +0200
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <20170716172448.GA23525@faui40p.informatik.uni-erlangen.de>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="dvSrEd9ErugwvbsO28PsrwgwJOFwOBJd9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/anima/jjtxJOBPIUnhITZStSR21VktjKc>
Subject: Re: [Anima] Is this how BRSKI/IPIP works?
X-BeenThere: anima@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Autonomic Networking Integrated Model and Approach <anima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/anima>, <mailto:anima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/anima/>
List-Post: <mailto:anima@ietf.org>
List-Help: <mailto:anima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/anima>, <mailto:anima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 16 Jul 2017 17:50:19 -0000
On 7/16/17 7:24 PM, Toerless Eckert wrote: > Sorry, cathing up late with the thread. > > Thanks, Eliot. Thats good information. The MAC address based limited > link-local address space is a problem for devices running a proxy. > Do you have an idea about some class of devices that has the issue > that you describe and that could be proxies ? Sure. Just about any device that does a poor job of randomization or have a low amount of entropy. And that, I'm afraid, is a very large swathe of stuff. But again, I think the diagram Brian drew out indicates the problem to be with autonomic node, not the border device, and there the problem will be assuredly more pronounced. > > I know about these crazy LED lightbulbs that actually build a mesh > network. Is that what you where alluding to ? > > But would those type of devices really be able to do all the > security stuff of ANIM/BRSKI ? Good question. I do think that lightbulbs are likely to do okay with this stuff, but smaller devices will probably not, simply as a matter of COGS. There are different forms of sensor networks in which the devices are highly constrained. It may be possible to pre-store a certain amount of entropy, which can ease some of this, but in those cases developers will need to be economical. The use of different forms of interface addresses, including CGAs needs to take into account this parameter. Eliot
- [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear
- Re: [Anima] Is this how BRSKI/IPIP works? Brian E Carpenter
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Eliot Lear (elear)
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Michael Richardson
- Re: [Anima] Is this how BRSKI/IPIP works? Toerless Eckert
- Re: [Anima] Is this how BRSKI/IPIP works? Max Pritikin (pritikin)