RE: [dhcwg] dhcpv6-24: Reconfigure

"Bound, Jim" <Jim.Bound@hp.com> Wed, 15 May 2002 19:31 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA19251 for <dhcwg-archive@odin.ietf.org>; Wed, 15 May 2002 15:31:29 -0400 (EDT)
Received: (from daemon@localhost) by optimus.ietf.org (8.9.1a/8.9.1) id PAA24472 for dhcwg-archive@odin.ietf.org; Wed, 15 May 2002 15:31:43 -0400 (EDT)
Received: from optimus.ietf.org (localhost [127.0.0.1]) by optimus.ietf.org (8.9.1a/8.9.1) with ESMTP id PAA23993; Wed, 15 May 2002 15:30:05 -0400 (EDT)
Received: from ietf.org (odin [132.151.1.176]) by optimus.ietf.org (8.9.1a/8.9.1) with ESMTP id PAA23963 for <dhcwg@ns.ietf.org>; Wed, 15 May 2002 15:30:03 -0400 (EDT)
Received: from zmamail04.zma.compaq.com (zmamail04.zma.compaq.com [161.114.64.104]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA19144 for <dhcwg@ietf.org>; Wed, 15 May 2002 15:29:47 -0400 (EDT)
Received: from tayexg12.americas.cpqcorp.net (tayexg12.americas.cpqcorp.net [16.103.130.103]) by zmamail04.zma.compaq.com (Postfix) with ESMTP id 003DA5B54; Wed, 15 May 2002 15:30:00 -0400 (EDT)
Received: from tayexc13.americas.cpqcorp.net ([16.103.130.26]) by tayexg12.americas.cpqcorp.net with Microsoft SMTPSVC(5.0.2195.2966); Wed, 15 May 2002 15:30:00 -0400
x-mimeole: Produced By Microsoft Exchange V6.0.5762.3
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Subject: RE: [dhcwg] dhcpv6-24: Reconfigure
Date: Wed, 15 May 2002 15:30:00 -0400
Message-ID: <9C422444DE99BC46B3AD3C6EAFC9711B020B8693@tayexc13.americas.cpqcorp.net>
Thread-Topic: [dhcwg] dhcpv6-24: Reconfigure
Thread-Index: AcH8NHBJFXPJU2rsQMe/2xhLcfhIuAAElwjg
From: "Bound, Jim" <Jim.Bound@hp.com>
To: "Thomas Narten" <narten@us.ibm.com>, <dhcwg@ietf.org>
X-OriginalArrivalTime: 15 May 2002 19:30:00.0600 (UTC) FILETIME=[E7907980:01C1FC46]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by optimus.ietf.org id PAA23969
Sender: dhcwg-admin@ietf.org
Errors-To: dhcwg-admin@ietf.org
X-Mailman-Version: 1.0
Precedence: bulk
List-Id: <dhcwg.ietf.org>
X-BeenThere: dhcwg@ietf.org
Content-Transfer-Encoding: 8bit

I am fine with this if my coauthors are and the wg.
/jim

> -----Original Message-----
> From: Thomas Narten [mailto:narten@us.ibm.com]
> Sent: Wednesday, May 15, 2002 1:06 PM
> To: dhcwg@ietf.org
> Subject: [dhcwg] dhcpv6-24: Reconfigure
> 
> 
> One IESG member has asked:
> 
> > 19. DHCP Server-Initiated Configuration Exchange
> 
> > reconfigure messages provide such a wonderful opportunity for
> > attack.  and they are sent unicast "using an IPv6 unicast address
> > of sufficient scope belonging to the DHCP client."
> 
> > possibly, the server could have intially provided a nonce that the
> > client retains for validation.  but this precludes redundant server
> > setups etc.
> 
> My response:
> 
> An interesting suggestion. Actually, it may not preclude this.  The
> idea behind the Reconfigure is that the server that has state about
> clients sends unicast Reconfigures to that client. It is not intended
> to be used to allow any old DHC server to prod a client. So requiring
> that the server also include a nonce may be OK. 
>  
> Question to the WG: should this be added? It would add some additional
> defense against improper Reconfigure.
> 
> Thoughts?
>  
> Thomas
> 
> _______________________________________________
> dhcwg mailing list
> dhcwg@ietf.org
> https://www1.ietf.org/mailman/listinfo/dhcwg
> 

_______________________________________________
dhcwg mailing list
dhcwg@ietf.org
https://www1.ietf.org/mailman/listinfo/dhcwg