Re: [dhcwg] DHCP and DHCPv6 options for LWM2M services

Ted Lemon <mellon@fugue.com> Fri, 13 January 2017 14:33 UTC

Return-Path: <mellon@fugue.com>
X-Original-To: dhcwg@ietfa.amsl.com
Delivered-To: dhcwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D455129C4C for <dhcwg@ietfa.amsl.com>; Fri, 13 Jan 2017 06:33:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9mC1byaGRlbU for <dhcwg@ietfa.amsl.com>; Fri, 13 Jan 2017 06:33:06 -0800 (PST)
Received: from mail-qt0-x235.google.com (mail-qt0-x235.google.com [IPv6:2607:f8b0:400d:c0d::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4C099129C4D for <dhcwg@ietf.org>; Fri, 13 Jan 2017 06:33:06 -0800 (PST)
Received: by mail-qt0-x235.google.com with SMTP id x49so48583875qtc.2 for <dhcwg@ietf.org>; Fri, 13 Jan 2017 06:33:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=KYziiwn5TxWvJahTmI8kepELg6pBSCUBA3/8G0NY7sU=; b=x+jxkNaF+bEO7RV84ok8Ihv3t1jjv6SAv4u7Q62+vwXPlMHuVwKnap5KoxWEDzBgqd s3HBpOf8xp7a2punDTphnqVQYvnJpcm8PgChbtI+wgFAZd84G1y6NozcUHjdPaB52QXt OoJ8gZLEvX0MCsTeJ5RXIejYZqxJsHrB2C6Wqcywxhrhv0T6SY5ZepkQBtEMY0tmNHqW r3bEHuncrzjIPrHE8PewDHBsfDV5X1KODf53rYTwMrCcVUo+9u9GjsMuKLATfCFW+qNN EBVKEjhcmF0EhTuz9xR+0z0KumQDP8wWvPRmvs3AQGig/ph4jGX8QmMZJNZjLDfw8jQX U9ng==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=KYziiwn5TxWvJahTmI8kepELg6pBSCUBA3/8G0NY7sU=; b=Jn2ufrLA+qgQhonje4o03VLYFkDnAaqzS71v4qDyns0sq6+y0gd4C+DCMXkHoosVJ9 Fiz9F9FIz/saObQ+1Z16UUfeqmUE1sccTSbUNMC8aWLTdo5UGQ6JXPjt8DwuAaAv0/5j UYNij5dLX5BbHEQjQB741OEsSUNuyQ97h1jbKWvlKYDnewAtH5iwunsQLmhZW89c1E0Z JBfw3vwTdViicpNw2QWmn7YfqoMAbQ1qtxuOzEjwsXZcjFU334TJMWMcC8t5Ox6M6tD+ Bs+KeS/yz4Zd4V8Fi8/JAXp4xYz9uIei9PDunYdgd3aGTub348lp9LONqQhofw/Kx8Jj e7tQ==
X-Gm-Message-State: AIkVDXJQCbrlWSPPApeRE0PtYmhkohHLCHEkUT3JGP2f/LGsOdAMWQHxsnsC7dbLt2STZQ==
X-Received: by 10.237.36.238 with SMTP id u43mr19165829qtc.51.1484317985403; Fri, 13 Jan 2017 06:33:05 -0800 (PST)
Received: from [192.168.1.228] (c-73-167-64-188.hsd1.nh.comcast.net. [73.167.64.188]) by smtp.gmail.com with ESMTPSA id z189sm9240346qkb.42.2017.01.13.06.33.03 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 13 Jan 2017 06:33:04 -0800 (PST)
From: Ted Lemon <mellon@fugue.com>
Message-Id: <3E13F21E-2024-4B41-A16D-6900AECA972A@fugue.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_58F54C62-FFFA-42F6-A7B3-67C397103704"
Mime-Version: 1.0 (Mac OS X Mail 10.2 \(3259\))
Date: Fri, 13 Jan 2017 09:33:02 -0500
In-Reply-To: <HE1PR0701MB19142F6D9362309DFD0084B0DE780@HE1PR0701MB1914.eurprd07.prod.outlook.com>
To: Srinivasa Rao Nalluri <srinivasa.rao.nalluri@ericsson.com>
References: <HE1PR0701MB191453938CCDD842F97014F3DE640@HE1PR0701MB1914.eurprd07.prod.outlook.com> <0827A698-2AF7-4D16-87BE-A86BC8E44C63@fugue.com> <HE1PR0701MB19142F6D9362309DFD0084B0DE780@HE1PR0701MB1914.eurprd07.prod.outlook.com>
X-Mailer: Apple Mail (2.3259)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dhcwg/RpakO9PeR46q-y2iMrA7tdiYRCQ>
Cc: Amit Gupta X <amit.x.gupta@ericsson.com>, "dhcwg@ietf.org" <dhcwg@ietf.org>, Ari Keränen <ari.keranen@ericsson.com>, Jaime Jiménez <jaime.jimenez@ericsson.com>, Jan Melen <jan.melen@ericsson.com>
Subject: Re: [dhcwg] DHCP and DHCPv6 options for LWM2M services
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: <dhcwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcwg/>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Jan 2017 14:33:08 -0000

On Jan 13, 2017, at 1:45 AM, Srinivasa Rao Nalluri <srinivasa.rao.nalluri@ericsson.com> wrote:
> Idea is to trust your DHCP server to give valid certificate. Otherwise we have risk.

Right, but on what basis do you trust the DHCP server?   There is no authentication, and no pre-established trust relationship if there were authentication.