Re: [DNSOP] fragmentation itself (Re: FYI: draft-andrews-dnsop-defeat-frag-attack)

Tim Wicinski <tjw.ietf@gmail.com> Mon, 15 July 2019 14:50 UTC

Return-Path: <tjw.ietf@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7CB4A120172 for <dnsop@ietfa.amsl.com>; Mon, 15 Jul 2019 07:50:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vCHu3KArhBIC for <dnsop@ietfa.amsl.com>; Mon, 15 Jul 2019 07:50:41 -0700 (PDT)
Received: from mail-ot1-x335.google.com (mail-ot1-x335.google.com [IPv6:2607:f8b0:4864:20::335]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8555D1201CA for <dnsop@ietf.org>; Mon, 15 Jul 2019 07:50:41 -0700 (PDT)
Received: by mail-ot1-x335.google.com with SMTP id b7so17214979otl.11 for <dnsop@ietf.org>; Mon, 15 Jul 2019 07:50:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=7hsez9KVwDHr4TckqYC1GbAbQGo24/3GCUXtlS2rL1Q=; b=Y0SRurAqTY3qu/eZjvqmL5YZ/DPC8vkyVy1qsilNeytn1IJmc5B4y6UfTEsIIV8CXd lQPZa8nwGeA27tJB91rSk2FVpH5/Dmt9Wfh5sMiAJURqnnvLclr30pcqRdmWg6IzGkQR fkA1dX6VBYkk3WUNQgldglgeeSWcypJjd+uyCx2REiXwcv15DGx7cffgueHFzkDocvPD 1cyTQdU5ooSvTxOk2wfJOHLo/hnEqNLSIoSBzi54eR/3w2JQT+efx3YMMMyLohWOIdmQ 5uJUd3iKNoHeyE4GYf4Gw8Wq4VxCV6B767YUx8YeMCkxKlUntpAnHpz+CgUr4jGy2rsN +5DQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=7hsez9KVwDHr4TckqYC1GbAbQGo24/3GCUXtlS2rL1Q=; b=qBN3BeYDr1WOU922fxg5r3MLj4s9kuKNIFj0sogpED0TjciKuyl8XhgfoZjB0eHKDK qW9c9OhpNkRU+Eom0iTFZ5faITwoqIcvOzATlclA2Tq6WRF2asW7YhWGbyBdnEZUMvuV D0v/rzFiAjsn3BYj3+W3ROhx7VGgcpZRlVHjKFMgCKuGm3FGb4T6Y+Q4n9Lk6s1CfRW4 aXNg79gDkSA6lmzFMp6YLiQzsWX4ihkKQDOWia4WG1FMfo7c77UWQr/10sQCUpUyHjBs hfkFw8TGQRSEOuAE3t4EZwCSZ2ay9RvMLwWY3Za5TpmpC7tqt7K5Mh64LPayDBw+N4vX wncQ==
X-Gm-Message-State: APjAAAVleQ2/Z5VXgqO+VIVuAsrkugAPOHENs6sxdP0AQH91kcCZjUXf LfxjE3szEJlr/UcM/u25dIUiDSkwJr8oKocqu9piD/V8
X-Google-Smtp-Source: APXvYqyUrfcIJBkeUO8hSKbEQAi5oMji+xQnleMS5Ltm+BS+q1R2M9lUJdwTosrkNP84GnWwmpoJt9bPZDY62XAgfyI=
X-Received: by 2002:a05:6830:1250:: with SMTP id s16mr11210808otp.158.1563202240847; Mon, 15 Jul 2019 07:50:40 -0700 (PDT)
MIME-Version: 1.0
References: <01BAC484-5E62-4573-A162-F3BD4F0DCF34@isc.org> <7E608829-535A-4540-A30F-607434F0E28D@isc.org> <CADyWQ+G8O_UOUxeu5CKbu6AoN-Q680BOn3NfOmB9R+9=0-6Ypw@mail.gmail.com> <10784891.sH38upkJ4Y@linux-9daj>
In-Reply-To: <10784891.sH38upkJ4Y@linux-9daj>
From: Tim Wicinski <tjw.ietf@gmail.com>
Date: Mon, 15 Jul 2019 10:50:29 -0400
Message-ID: <CADyWQ+Ff0DCoun+1nU61F80c+q32jwBN06SSZKYdLSNxhhBBww@mail.gmail.com>
To: Paul Vixie <paul@redbarn.org>
Cc: dnsop <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000472451058db96220"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/6TzbpvjhSpHTouEe0sKQTz7As38>
Subject: Re: [DNSOP] fragmentation itself (Re: FYI: draft-andrews-dnsop-defeat-frag-attack)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Jul 2019 14:50:47 -0000

The chairs can work with kazunori on a Monday night discussion (okay, I'll
sign up).

On Mon, Jul 15, 2019 at 10:49 AM Paul Vixie <paul@redbarn.org> wrote:

> On Monday, 15 July 2019 13:35:33 UTC Tim Wicinski wrote:
> > The chairs felt that fujiwara-san's draft was one that needed in person
> > discussion in Montreal.
>
> hopefully kazunori will suggest a bar bof for monday night. i leave
> tuesday
> morning and so will miss the WG meeting. my own concern is more for packet
> size than for fragmentation itself. i'd like to explain my concerns to
> $somebody.
>
> > Also, if folks did not see his presentation at OARC, here are the slides:
> >
> >
> https://indico.dns-oarc.net/event/31/contributions/692/attachments/660/1115/
> > fujiwara-5.pdf
>
> possibly to be argued, but to be not dismissed. as i wrote up-thread, the
> state mass of fragmentation, harshest on receivers but also present on
> transmitters, means the original EDNS0 spec ought to have said "SHOULD be
> of a
> size that allows the full packet with all headers to fit the local
> interface
> MTU and next-hop MTU" and possibly also "MAY set the DF bit if capable of
> hearing and interpreting ICMP messages".
>
> --
> Paul
>
>
>