Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc-forcerenew-nonce-03
Ted Lemon <Ted.Lemon@nominum.com> Tue, 14 February 2012 13:52 UTC
Return-Path: <Ted.Lemon@nominum.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF07C21F869D; Tue, 14 Feb 2012 05:52:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -105.625
X-Spam-Level:
X-Spam-Status: No, score=-105.625 tagged_above=-999 required=5 tests=[AWL=-0.830, BAYES_00=-2.599, HTML_MESSAGE=0.001, LONGWORDS=1.803, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MVobxRrWo+0S; Tue, 14 Feb 2012 05:52:53 -0800 (PST)
Received: from exprod7og109.obsmtp.com (exprod7og109.obsmtp.com [64.18.2.171]) by ietfa.amsl.com (Postfix) with ESMTP id AD0C721F8602; Tue, 14 Feb 2012 05:52:50 -0800 (PST)
Received: from shell-too.nominum.com ([64.89.228.229]) (using TLSv1) by exprod7ob109.postini.com ([64.18.6.12]) with SMTP ID DSNKTzpnL5yiqIkdgypuBVSLf6UZjEJ4Esot@postini.com; Tue, 14 Feb 2012 05:52:51 PST
Received: from archivist.nominum.com (archivist.nominum.com [64.89.228.108]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "*.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by shell-too.nominum.com (Postfix) with ESMTP id 11D6C1B82FC; Tue, 14 Feb 2012 05:52:47 -0800 (PST)
Received: from webmail.nominum.com (cas-02.win.nominum.com [64.89.228.132]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "mail.nominum.com", Issuer "Go Daddy Secure Certification Authority" (verified OK)) by archivist.nominum.com (Postfix) with ESMTPS id F38CF190052; Tue, 14 Feb 2012 05:52:46 -0800 (PST) (envelope-from Ted.Lemon@nominum.com)
Received: from MBX-01.WIN.NOMINUM.COM ([64.89.228.133]) by CAS-02.WIN.NOMINUM.COM ([64.89.228.132]) with mapi id 14.01.0339.001; Tue, 14 Feb 2012 05:52:41 -0800
From: Ted Lemon <Ted.Lemon@nominum.com>
To: Maglione Roberta <roberta.maglione@telecomitalia.it>
Thread-Topic: Gen-ART LC Review of draft-ietf-dhc-forcerenew-nonce-03
Thread-Index: AQHM5SWUy8EqSdK3C0aOhQFr8l21aJY2slwAgAG8tQCAA3NmAIAA3poAgAA6lIA=
Date: Tue, 14 Feb 2012 13:52:40 +0000
Message-ID: <F96A644A-5ABF-47E8-A519-FA6A252FA03B@nominum.com>
References: <A57C4722-5E13-451E-ACB4-CAA8064FA68B@nostrum.com> <282BBE8A501E1F4DA9C775F964BB21FE3EC1467FB2@GRFMBX704BA020.griffon.local> <CEA6CD8F-7DCD-448C-8C31-EC64FD9902A3@nominum.com> <F184B794-3D1D-4A5A-860E-288DF2600DD6@nostrum.com> <282BBE8A501E1F4DA9C775F964BB21FE3EC1467FC5@GRFMBX704BA020.griffon.local>
In-Reply-To: <282BBE8A501E1F4DA9C775F964BB21FE3EC1467FC5@GRFMBX704BA020.griffon.local>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [192.168.1.10]
Content-Type: multipart/alternative; boundary="_000_F96A644A5ABF47E8A519FA6A252FA03Bnominumcom_"
MIME-Version: 1.0
Cc: Ben Campbell <ben@nostrum.com>, The IETF <ietf@ietf.org>, "gen-art@ietf.org Review Team" <gen-art@ietf.org>, "draft-ietf-dhc-forcerenew-nonce.all@tools.ietf.org" <draft-ietf-dhc-forcerenew-nonce.all@tools.ietf.org>, Ullio Mario <mario.ullio@telecomitalia.it>, "Henderickx, Wim (Wim)" <wim.henderickx@alcatel-lucent.com>
Subject: Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc-forcerenew-nonce-03
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Feb 2012 13:52:59 -0000
On Feb 14, 2012, at 5:23 AM, Maglione Roberta wrote: Please let me know if you have additional comments. Thanks! I think you should change this text in the introduction: The mandatory authentication was originally motivated by a legitimate security concern whereby in some network environments DHCP messages can be spoofed and an attacker could more accurately guess the timing of DHCP renewal messages by first sending a FORCERENEW message. However, in some networks native security mechanisms already provide sufficient protection against spoofing of DHCP traffic. An example of such network is a Broadband Forum TR-101 [TR-101i2] compliant access network. In such environments the mandatory coupling between FORCERENEW and DHCP Authentication [RFC3118] can be relaxed and a lighter authentication mechanism can be used for the FORCERENEW message. To this: [paragraph break] The motivation for making authentication mandatory in DHCPFORCERENEW was to prevent an off-network attacker from taking advantage of DHCPFORCERENEW to accurately predict the timing of a DHCP renewal. Without DHCPFORCERENEW, DHCP renewal timing is under the control of the client, and an off-network attacker has no way of predicting when it will happen, since it doesn't have access to the exchange between the DHCP client and DHCP server. However, the requirement to use the DHCP authentication described in RFC3118 is more stringent than is required for this use case, and has limited adoption of DHCPFORCERENEW. RFC3315 defines an authentication protocol using a nonce to prevent off-network attackers from successfully causing clients to renew. Since the off-network attacker doesn't have access to the nonce, it can't trick the client into renewing at a time of its choosing.
- [Gen-art] Gen-ART LC Review of draft-ietf-dhc-for… Ben Campbell
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ben Campbell
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Maglione Roberta
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ted Lemon
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ben Campbell
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ben Campbell
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ted Lemon
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ben Campbell
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Maglione Roberta
- Re: [Gen-art] Gen-ART LC Review of draft-ietf-dhc… Ted Lemon
- [Gen-art] Followup Gen-ART Review on draft-ietf-d… Ben Campbell