Re: [dhcwg] dhc-lifetime-02: minimum value

Ted Lemon <mellon@fugue.com> Tue, 31 August 2004 17:17 UTC

Received: from megatron.ietf.org (megatron.ietf.org [132.151.6.71]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA06441; Tue, 31 Aug 2004 13:17:15 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1C2C0w-0002Wc-2N; Tue, 31 Aug 2004 13:01:46 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1C2Blr-0006gn-QX for dhcwg@megatron.ietf.org; Tue, 31 Aug 2004 12:46:11 -0400
Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA03778 for <dhcwg@ietf.org>; Tue, 31 Aug 2004 12:46:09 -0400 (EDT)
Received: from toccata.fugue.com ([204.152.186.142]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1C2Bns-00008A-Lm for dhcwg@ietf.org; Tue, 31 Aug 2004 12:48:17 -0400
Received: from [10.0.2.8] (neubayern.net [66.93.162.100]) by toccata.fugue.com (Postfix) with ESMTP id B443A1B22C5 for <dhcwg@ietf.org>; Tue, 31 Aug 2004 11:44:38 -0500 (CDT)
Mime-Version: 1.0 (Apple Message framework v619)
In-Reply-To: <20040831121401.GN2203@sverresborg.uninett.no>
References: <20040825151559.GJ5677@sverresborg.uninett.no> <200408270854.10485.jdq@lucent.com> <20040831121401.GN2203@sverresborg.uninett.no>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Message-Id: <419E9784-FB6D-11D8-8C0B-000D93C4B69A@fugue.com>
Content-Transfer-Encoding: 7bit
From: Ted Lemon <mellon@fugue.com>
Subject: Re: [dhcwg] dhc-lifetime-02: minimum value
Date: Tue, 31 Aug 2004 09:46:07 -0700
To: dhcwg@ietf.org
X-Mailer: Apple Mail (2.619)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 9182cfff02fae4f1b6e9349e01d62f32
Content-Transfer-Encoding: 7bit
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: dhcwg.ietf.org
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
Sender: dhcwg-bounces@ietf.org
Errors-To: dhcwg-bounces@ietf.org
Content-Transfer-Encoding: 7bit

On Aug 31, 2004, at 5:14 AM, Stig Venaas wrote:
> I agree sort of. For the protocol, I like the idea of totally ignoring
> option with invalid value though, which means using the default. The
> server implementation should perhaps give the administrator a warning,
> or send 600 rather than the configured value.
>
> We could also do what you suggest though. Other opinions?

There are cases where if any low value for this option is sent out over 
and over again by the server, it will cause operational problems.   But 
this isn't something we can easily prevent without being too 
restrictive, and I think you have to be really well-placed on a network 
(i.e., on the DHCP server's network) to get much amplification out of a 
DoS attack based on this.   In fact, when I think of how to come up 
with such a DoS attack, it seems like it would actually be very 
difficult.   So I think the real risk here is that the server 
administrator will configure a too-low value, so I think the right way 
to address this is to say that servers SHOULD warn the server 
administrator through an appropriate mechanism if the administrator 
tries to configure a too-low value for this option.

I think if you try to specify this on the protocol level, you're just 
making needless trouble for yourself, and not getting any benefit from 
it.


_______________________________________________
dhcwg mailing list
dhcwg@ietf.org
https://www1.ietf.org/mailman/listinfo/dhcwg