Re: [Gen-art] Gen-ART Telechat review of draft-ietf-ospf-security-extension-manual-keying-09.txt
"Acee Lindem (acee)" <acee@cisco.com> Mon, 03 November 2014 17:35 UTC
Return-Path: <acee@cisco.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 44D6E1A1B9B for <gen-art@ietfa.amsl.com>; Mon, 3 Nov 2014 09:35:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -15.095
X-Spam-Level:
X-Spam-Status: No, score=-15.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.594, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7aZdMl-v7nTL for <gen-art@ietfa.amsl.com>; Mon, 3 Nov 2014 09:35:51 -0800 (PST)
Received: from rcdn-iport-7.cisco.com (rcdn-iport-7.cisco.com [173.37.86.78]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 95B731A1A24 for <gen-art@ietf.org>; Mon, 3 Nov 2014 09:35:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3489; q=dns/txt; s=iport; t=1415036152; x=1416245752; h=from:to:subject:date:message-id:references:in-reply-to: content-id:content-transfer-encoding:mime-version; bh=2uNOZAJox5k3DrhKkbmIS7ZRXhV4WTgP6NZPiaD6Ui0=; b=ZZf/Ctgs+BPAL5HDJcAvNJnW336iUH844WLptgm9rG6xBrbCt1k7VdVr TQfakYovsxQoj4bGiCCGpmcSm6gMXdPU2TMvyOEg0lmRjYme3/X8QRkcK IlFE4IkR9rzjfxh6eo7D7shOrc/TgM7Z0C42TDckbpjisfSU6NjL/ZZRB U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhYFAJi8V1StJA2H/2dsb2JhbABcgw5UWATOBodNAoEjFgEBAQEBfYQDAQEEJxNPAgEIFCIQMiUCBAESiEENx34BAQEBAQEEAQEBAR6REgWESwWSGotngTGDTYohgyiECYIAHhaBRGwBgUeBAwEBAQ
X-IronPort-AV: E=Sophos;i="5.07,308,1413244800"; d="scan'208";a="368852198"
Received: from alln-core-2.cisco.com ([173.36.13.135]) by rcdn-iport-7.cisco.com with ESMTP; 03 Nov 2014 17:35:51 +0000
Received: from xhc-aln-x02.cisco.com (xhc-aln-x02.cisco.com [173.36.12.76]) by alln-core-2.cisco.com (8.14.5/8.14.5) with ESMTP id sA3HZotS023551 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 3 Nov 2014 17:35:50 GMT
Received: from xmb-aln-x06.cisco.com ([169.254.1.61]) by xhc-aln-x02.cisco.com ([173.36.12.76]) with mapi id 14.03.0195.001; Mon, 3 Nov 2014 11:35:50 -0600
From: "Acee Lindem (acee)" <acee@cisco.com>
To: Suresh Krishnan <suresh.krishnan@ericsson.com>, "draft-ietf-ospf-security-extension-manual-keying.all@tools.ietf.org" <draft-ietf-ospf-security-extension-manual-keying.all@tools.ietf.org>, General Area Review Team <gen-art@ietf.org>
Thread-Topic: Gen-ART Telechat review of draft-ietf-ospf-security-extension-manual-keying-09.txt
Thread-Index: AQHP94yc304UbXQIJkisqB+y4j7zWQ==
Date: Mon, 03 Nov 2014 17:35:50 +0000
Message-ID: <D07D24E1.74D3%acee@cisco.com>
References: <54501717.3020703@ericsson.com>
In-Reply-To: <54501717.3020703@ericsson.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.116.152.204]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <EAF3A0A65E8B84439F3410C50AA89718@emea.cisco.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/gen-art/xA_u1NbEpwv0qhCYZX6BNhLeva4
Subject: Re: [Gen-art] Gen-ART Telechat review of draft-ietf-ospf-security-extension-manual-keying-09.txt
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Nov 2014 17:35:53 -0000
Hi Suresh,
Thanks much for your comments. See inline.
On 10/28/14, 3:22 PM, "Suresh Krishnan" <suresh.krishnan@ericsson.com>
wrote:
>I have been selected as the General Area Review Team (Gen-ART)
>reviewer for this draft (for background on Gen-ART, please see
>http://www.alvestrand.no/ietf/gen/art/gen-art-FAQ.html).
>
>Please wait for direction from your document shepherd
>or AD before posting a new version of the draft.
>
>Document: draft-ietf-ospf-security-extension-manual-keying-09.txt
>Reviewer: Suresh Krishnan
>Review Date: 2013/10/28
>IESG Telechat date: 2013/10/30
>
>
>Summary: The draft is almost ready for publication as Proposed Standard
>but has some issues that need to be addressed.
>
>* Section 2
>
>-> There is no reference to snmpEngineBoots in the RFC4222 reference.
>Are you pointing to the wrong document here? I would suggest replacing
>the RFC4222 reference with a reference to RFC2574 Section 2.2 that talks
>about replay protection.
This was wrong. RFC 4222 is a reference that should have been used later
in the draft with respect to packet prioritization. I will update this
reference to RFC 2574.
>
>-> There is another change to the 64-bit authentication field that is
>not described in the text. The 0 field in the beginning is extended from
>16 bits to 24 bits. Can you please add this.
I will add this.
>
>* Section 5
>
>-> It is unclear from this text what the exact change to the
>authentication trailer is. The only logical explanation I could come up
>with is that instead of initializing the field with Apad x times, we
>initialize with the IP source address x times. If my understanding is
>correct please reword the text. Suggested change below.
>
>OLD:
> OSPF routers sending OSPF packets must initialize Apad to the value
> of the IP source address that would be used when sending an OSPFv2
> packet, repeated L/4 times, where L is the length of the hash,
> measured in octets. The basic idea is to incorporate the IP source
> address from the IP header in the cryptographic authentication
> computation so that any change of IP source address in a replayed
> packet can be detected.
>
>NEW:
> Instead of using the hexadecimal constant 0x878FE1F3, OSPF routers
> following this specification MUST initialize Apad to the value
> of the IP source address that would be used when sending an OSPFv2
> packet, repeated L/4 times, where L is the length of the hash,
> measured in octets. The basic idea is to incorporate the IP source
> address from the IP header in the cryptographic authentication
> computation so that any change of IP source address in a replayed
> packet can be detected.
Thanks much - this was wrong and should have been consistent with RFC
7166. Here is the updated text:
OSPF routers sending OSPF packets must initialize the first 4 octets
of Apad to the value of the IP source address that would be used when
sending the OSPFv2 packet. The remainder of Apad will contain
the value of 0x878FE1F3 repeated (L - 4)/4 times, where L is the
length of the hash, measured in octets. The basic idea is to
incorporate the IP source address from the IP header in the
cryptographic authentication computation so that any change of IP
source address in a replayed packet can be detected.
Thanks,
Acee
>
>Thanks
>Suresh
>
>
>
- [Gen-art] Gen-ART Telechat review of draft-ietf-o… Suresh Krishnan
- Re: [Gen-art] Gen-ART Telechat review of draft-ie… Jari Arkko
- Re: [Gen-art] Gen-ART Telechat review of draft-ie… Acee Lindem (acee)
- Re: [Gen-art] Gen-ART Telechat review of draft-ie… Acee Lindem (acee)