[dhcwg] secure DHCPv6 interop

Francis Dupont <Francis.Dupont@fdupont.fr> Sun, 19 July 2015 08:35 UTC

Return-Path: <Francis.Dupont@fdupont.fr>
X-Original-To: dhcwg@ietfa.amsl.com
Delivered-To: dhcwg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 076C51A8AC8 for <dhcwg@ietfa.amsl.com>; Sun, 19 Jul 2015 01:35:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.337
X-Spam-Level:
X-Spam-Status: No, score=0.337 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, HELO_EQ_FR=0.35, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HrUQqGhGSKRq for <dhcwg@ietfa.amsl.com>; Sun, 19 Jul 2015 01:35:56 -0700 (PDT)
Received: from givry.fdupont.fr (givry.fdupont.fr [IPv6:2001:41d0:1:6d55:211:5bff:fe98:d51e]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E0ED41A90CC for <dhcwg@ietf.org>; Sun, 19 Jul 2015 01:27:46 -0700 (PDT)
Received: from givry.fdupont.fr (localhost [127.0.0.1]) by givry.fdupont.fr (8.14.3/8.14.3) with ESMTP id t6J8Q8Ba025992 for <dhcwg@ietf.org>; Sun, 19 Jul 2015 10:26:08 +0200 (CEST) (envelope-from dupont@givry.fdupont.fr)
Message-Id: <201507190826.t6J8Q8Ba025992@givry.fdupont.fr>
From: Francis Dupont <Francis.Dupont@fdupont.fr>
To: dhcwg@ietf.org
Date: Sun, 19 Jul 2015 10:26:08 +0200
Sender: Francis.Dupont@fdupont.fr
Archived-At: <http://mailarchive.ietf.org/arch/msg/dhcwg/hHQPxWzxZh5tsC84ct555kSdwcs>
Subject: [dhcwg] secure DHCPv6 interop
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <dhcwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcwg/>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 19 Jul 2015 08:35:57 -0000

(According to Tomek's summary)

One good and one bad news:
 - wide client worked well with the Kea server

 - there are some misunderstanding about the timestamp format: it is
  a 64 bit fixed-point with a 1900-01-01 00:00:00 epoch. Now the I-D
  says NTP format (so 32 bit second counter) when everything came from
  SeND with uses a 48 bit second counter.

(Now my own opinion about the second (aka bad) point)

IMHO the I-D should be fixed to use SeND format, not only because I
proposed to copy the SeND timestamp mechanism in secure DHCPv6 but
because both share the same need (i.e., 16 bit second fraction is fine)
and with a 1900 epoch a 32 bit counter, even unsigned, will wrap too soon
(in 2036 if I computed right).

Regards

Francis.Dupont@fdupont.fr