Re: [Captive-portals] User equipment identification

David Bird <dbird@google.com> Fri, 03 July 2020 23:05 UTC

Return-Path: <dbird@google.com>
X-Original-To: captive-portals@ietfa.amsl.com
Delivered-To: captive-portals@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D57B73A080A for <captive-portals@ietfa.amsl.com>; Fri, 3 Jul 2020 16:05:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.599
X-Spam-Level:
X-Spam-Status: No, score=-17.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9h-2majY00ck for <captive-portals@ietfa.amsl.com>; Fri, 3 Jul 2020 16:05:24 -0700 (PDT)
Received: from mail-io1-xd2a.google.com (mail-io1-xd2a.google.com [IPv6:2607:f8b0:4864:20::d2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1449F3A0809 for <captive-portals@ietf.org>; Fri, 3 Jul 2020 16:05:24 -0700 (PDT)
Received: by mail-io1-xd2a.google.com with SMTP id i25so33930110iog.0 for <captive-portals@ietf.org>; Fri, 03 Jul 2020 16:05:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=/xOkujr3kmfPIi4PqpEFNEOd350nZVlAn+22/PASfxQ=; b=R86BL5ADrYKNpuR/T3SEMHh8in+IqLbVl1EgyZ5yml7xNq6BNXgKZ+Z+lxSRBrCEf6 fyCBCiWn1NK/1QGhg0crVrhgRuVx4CbR5KNS3g2t9INkSLukX1GLwAXHac4/LDF2nQ9Q xFmQzRWEWk6M6aTyCYLNXlVExeDLJA4zfodE4ZPnXCrDNiEl/L9hwMLRKG6iBjKm6iDL mnCPrHu7f/BC9fvfmrpFCBOOHoM+q5m5kSwPkKnJTNsdGcMdqarbB/ksy/sMAbzzXttN ATNQPMGy3VVeKuV6vS/1LSEjmtKMVNjj83u4GZFSWGFrOa0LBbQMN0li8fW7X4XeDnUf wN5w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=/xOkujr3kmfPIi4PqpEFNEOd350nZVlAn+22/PASfxQ=; b=tG4/QcTNm5HWgNW3+iDZGrEEXaVw3pnJkR9nZis+qVhER2Dsi/T62nAMkVPxk+Fc5Q zPTPG2JxfF/Ak/9k0SiDzeuv7w8QIdSjznhWhhEl+kJ+BI2bvtzkqVdIlSfTI6O0dVvl yzYWRV3irvbj8wal5AWo7JzN/a9mUIRWE4wgD4mcuACq2qFm77y79SNKii21HgsfOIzU nuy8axkh3xednXY20ajnJuPKAGY+yexnACmpwEPOjOJHSUX6Fi+jU7XwYnUT3+lDLaQz o1QoFUATtHejlXPu3sKvJvuJLzmath07lCtKowmBKzNDlcs0+HK1CmwrrW5rfqzQNogo GHPw==
X-Gm-Message-State: AOAM530OiZaXYRYsy834DRs3otzcTDKvosDFVtlqBe1D0UCAcfgFcoED nsY2AwO/XT28fthe7OkaIzlG5tMkrXB+lQMNASjb2rCa
X-Google-Smtp-Source: ABdhPJyCckkHHqnZxvMI/qlFffyjXAL9RAqfWrln3j64gbwHNE4CpVL1GdTFtX/bVBle2TJppMcKtxyKLG5J+A6rR8k=
X-Received: by 2002:a02:cd91:: with SMTP id l17mr40385022jap.88.1593817523029; Fri, 03 Jul 2020 16:05:23 -0700 (PDT)
MIME-Version: 1.0
References: <3018282E-F85A-49B0-91DF-0BB629165F80@onway.ch> <CADo9JyUangfyLvbnBUnjQwQbMNsDMKQMhXHSSXaFPuAZM+PgyA@mail.gmail.com>
In-Reply-To: <CADo9JyUangfyLvbnBUnjQwQbMNsDMKQMhXHSSXaFPuAZM+PgyA@mail.gmail.com>
From: David Bird <dbird@google.com>
Date: Fri, 3 Jul 2020 16:05:12 -0700
Message-ID: <CADo9JyV-2C6YCtS4PnEGYq_3Mwq6A+LJu=4COEU4uLmjBm1TuA@mail.gmail.com>
To: Michael Schneider <michael.schneider@onway.ch>
Cc: "captive-portals@ietf.org" <captive-portals@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000004c679105a9918f64"
Archived-At: <https://mailarchive.ietf.org/arch/msg/captive-portals/C3trU1J6mP0-6DEFv6yxy1_4Nd8>
Subject: Re: [Captive-portals] User equipment identification
X-BeenThere: captive-portals@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Discussion of issues related to captive portals <captive-portals.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/captive-portals/>
List-Post: <mailto:captive-portals@ietf.org>
List-Help: <mailto:captive-portals-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/captive-portals>, <mailto:captive-portals-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Jul 2020 23:05:26 -0000

Over the years now :) - I've also thought vendors might use something like
"http://<special-hijack-ip>/" with a NAS-non-integrated DHCP/ICMPv6 server,
so that the NAS might redirect to the appropriate
https://api-server/?unique-device-session-identifier.

On Fri, Jul 3, 2020 at 3:13 PM David Bird <dbird@google.com> wrote:

> I believe how to uniquely identify the user device has been distinctly
> left up to the implementers... It will depend on how you implement your
> DHCP and ICMPv6 services and where you reside your API server (e.g. within
> or outside any NATv4). Assuming you have full control of your DHCP server
> and perhaps use RFC 8273 <https://tools.ietf.org/html/rfc8273>, you can
> assign each subscriber a unique identifier during IP/prefix assignment. If
> that is not an option, then the API server probably has only the connecting
> IP address as the unique identifier...
>
> On Fri, Jul 3, 2020 at 1:27 PM Michael Schneider <
> michael.schneider@onway.ch> wrote:
>
>> Hi,
>>
>> I have read the documents about CAPPORT and as a Captive Portal vendor I
>> find the current drafts very reasonable and well thought out. But a
>> question came up when I was thinking about a dual stack user equipment. How
>> does the client behave if it has an IPv4 and an IPv6 address and one of the
>> two addresses is captive=false and the other captive=true. Do you see ways
>> for the enforcement device to match these two addresses and allow both if
>> one of them gets captive=false? Furthermore, a user equipment can hold more
>> than one IPv6 address at a time and/or change it frequently.
>>
>> Many thanks for your advice.
>>
>> Regards,
>> Michael
>>
>> --
>> onway ag
>> Michael Schneider
>> Head of Development
>>
>> Stauffacherstrasse 16, CH-8004 Zürich
>> Tel: +41 55 214 18 35 <+41%2055%20214%2018%2035>
>> michael.schneider@onway.ch
>> www.onway.ch
>>
>> _______________________________________________
>> Captive-portals mailing list
>> Captive-portals@ietf.org
>> https://www.ietf.org/mailman/listinfo/captive-portals
>>
>