RE: Dumb question about routing headers

Ron Bonica <rbonica@juniper.net> Mon, 25 May 2020 03:56 UTC

Return-Path: <rbonica@juniper.net>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EADD43A0AB9 for <ipv6@ietfa.amsl.com>; Sun, 24 May 2020 20:56:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=r7hSDuFF; dkim=pass (1024-bit key) header.d=juniper.net header.b=bM5Q+iEb
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GmlV5AnX5d6L for <ipv6@ietfa.amsl.com>; Sun, 24 May 2020 20:56:21 -0700 (PDT)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 71A403A0AB8 for <ipv6@ietf.org>; Sun, 24 May 2020 20:56:21 -0700 (PDT)
Received: from pps.filterd (m0108160.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 04P3pwow023000; Sun, 24 May 2020 20:56:20 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=PPS1017; bh=NOFmRsKK1ZLKAUa21QLVM8lPGNxygXhfgDgBYcjTQ8o=; b=r7hSDuFFWlESDehPjJ7ERch8CUzZA4xqg6FLozMdvsa9eV+j/mj9F14eHah6gVkkrAw1 QdWTFxQpzVlki9G5lkmMi2oEVVQvGLXgqRJHKrm9+VxcvYNOUb/lFZdnOi28Vj4mk175 hNYHUhzDM//Rbk4myqw6vtdZndeSmj+Sc+AMFm+ZjQR2xkXFNRumU73v3JuKFJCErkJ1 TZ+tvR6poyJDO2xnHmUwWqevVvacAFw3ZGDViDJoTrq8lUyV0dNvcWgprLNyUFx8N0K7 drR/2gjwmUjGKtzjxNdVglzUSqoXXIluMglV5PmjsymvxvaglR0wj5Uoa7Z+sxUOPNYJ 6w==
Received: from nam10-mw2-obe.outbound.protection.outlook.com (mail-mw2nam10lp2105.outbound.protection.outlook.com [104.47.55.105]) by mx0b-00273201.pphosted.com with ESMTP id 3171rhj25y-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 24 May 2020 20:56:20 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=WdMZyM9Zqsk4G4wIgojsCVPy8jGIy6veY0mvrL6fQdWsBzL8W7KKr/hSpVh3fTGsW2Qq+hoip0UwVIuKGETkhCGIyd0MT+hgLM/0MnashD+ba0R011Z4PP5yjdDFCpslXFZIiKVoXMp8C7gAHFqav+39rPYfasDL146zEGlqxiobMT6B4NDqD/6mUpHr02bMVH4fBNaB3VubCYPzZj3MlGsMmvCgpV9JNB56x1/RuBriJaJqDckLQ345FpBCXykRLE9Q6UFG0TzMgKUhkY4u8n/OIT67CVW4d/4K/fA/j3qO+NGUBbZPv6G9WepvzZQp19jDnKMi0giMkB4QQbFqPQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NOFmRsKK1ZLKAUa21QLVM8lPGNxygXhfgDgBYcjTQ8o=; b=ERi60vc+QGCMWjdYXjd7NogJcuOqLH5M8oGt+LPYVLs/gQBwSxBvkxtbkUuwMnnwzN7IOTCS/KRLwGfpQg9HDdqcDmTwLAYJ8VVs6QvCgn/i2zBbpjCuYAaPsXy63vvThVlZjnnuzOWiuk3acohsU3yOjn0xlRPmUFaU2BeRJRTGfhdqLsd/O02J+m6yv1ARk3Gk2mf1WFYpMSFi0CL52dQsPkTYi7fMxUrSLFTjt6GXNsdkZToGuX+pstuvM2192BNW9XA4u0iRHWodoId3Wl7OYc9xfTqifsqk1ZXN2BJfeq6PsUq/FFsNGH2/Iczbo7I1jllYCl0yl8hxqV+rMg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NOFmRsKK1ZLKAUa21QLVM8lPGNxygXhfgDgBYcjTQ8o=; b=bM5Q+iEbLZDlhXuINeVvrWTPJ583dlksZ87H6GT3SXjNmJZjPlp0RI5kE6cRfsSqa7Y84Bo3IZpalUAk4RmDQEO5t/g/fyvXtgMQf8Yor1sJNIQ9TuNXBkWg2y8Xnx2wdva8nDugjhaDv+djSx2OAZWrtMU4ZEknVuZohIBsY1o=
Received: from DM6PR05MB6348.namprd05.prod.outlook.com (2603:10b6:5:122::15) by DM6PR05MB5612.namprd05.prod.outlook.com (2603:10b6:5:c::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3045.9; Mon, 25 May 2020 03:56:17 +0000
Received: from DM6PR05MB6348.namprd05.prod.outlook.com ([fe80::c020:3bf5:7230:75e3]) by DM6PR05MB6348.namprd05.prod.outlook.com ([fe80::c020:3bf5:7230:75e3%4]) with mapi id 15.20.3045.014; Mon, 25 May 2020 03:56:17 +0000
From: Ron Bonica <rbonica@juniper.net>
To: Mark Smith <markzzzsmith@gmail.com>, Brian E Carpenter <brian.e.carpenter@gmail.com>
CC: 6man <ipv6@ietf.org>
Subject: RE: Dumb question about routing headers
Thread-Topic: Dumb question about routing headers
Thread-Index: AQHWMg8Z2v4s/pQT+kis0flaeCgFI6i3vo4AgABt65A=
Date: Mon, 25 May 2020 03:56:17 +0000
Message-ID: <DM6PR05MB6348D1ED11E539E6EC0176D4AEB30@DM6PR05MB6348.namprd05.prod.outlook.com>
References: <4cf28892-12a9-7376-c378-4af46f7002c2@gmail.com> <CAO42Z2y7qWVMBmhKw4_AmjS8+xCbZJBKJ5q95+VtccaEe1B3Cg@mail.gmail.com>
In-Reply-To: <CAO42Z2y7qWVMBmhKw4_AmjS8+xCbZJBKJ5q95+VtccaEe1B3Cg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled=true; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate=2020-05-25T03:56:12Z; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Method=Standard; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name=0633b888-ae0d-4341-a75f-06e04137d755; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId=bea78b3c-4cdb-4130-854a-1d193232e5f4; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId=bd2f72c2-f8ec-45b0-a716-f8bb1f2881dd; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ContentBits=2
dlp-product: dlpe-windows
dlp-version: 11.4.0.45
dlp-reaction: no-action
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=juniper.net;
x-originating-ip: [108.28.233.91]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 5e8edf0d-03f8-4fb5-ba99-08d8005f941a
x-ms-traffictypediagnostic: DM6PR05MB5612:
x-microsoft-antispam-prvs: <DM6PR05MB5612514E50E7C5CF88E5D4A4AEB30@DM6PR05MB5612.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0414DF926F
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: OZZ7il86uu1/HcbwQq70DZ9f/If5stc0S1FUzzBEr0dzepS02a876Rq89/UTKoAttVCDbXm3VG1eCWffNInt154H0el2f0P4KwxqeEVZ+6I4ue2U8eybi9+PmyZ2hjNXFvxBpehWnqVQx26bwIOdeDuPmf17/gUWze5cfjm9iuyz8J+9mFa5Eq8tAZGqMhaIV9f8FwWif1JDJvbm6h7/rlg8IPf6ITVMv0q9WapJV7FJvWLmUGU6M6ONIETa9bLfSsfNejvf1W7+whULBMemkk7i4o5WL9AoJ9HgyXO1KWj/Wd8Eawa9tsyY66lxKVTu2ViGd/i5YJmm1+ZsKYZfwJQDYZP/gChxCpYbj93F3kUPmN0dvLO7IZD1Uq8kQULVsVDsF9S508oTd4RGsJNgvA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR05MB6348.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(376002)(366004)(346002)(39860400002)(396003)(136003)(66446008)(166002)(316002)(76116006)(66946007)(55016002)(66556008)(26005)(9686003)(66476007)(64756008)(4326008)(71200400001)(2906002)(186003)(5660300002)(86362001)(966005)(478600001)(7696005)(52536014)(6506007)(53546011)(8676002)(110136005)(8936002)(33656002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: Eq9nBD8PKrabWab80Me/QiO53TyEECYiQQUj4v8Z945QqgRycxxd8XCCFaBVaNvHN25D1Vcq9wqozZtKG8BKqiBtBlqEGEpphj+FjH6QWAfkdabRszlQdbZEiRdzVQpS48cur7yOTh6s/We2wIGXn/Q6CRpzPIhbsI74b1NntAtOpq7D/VkrhDPKzYrmD5LfJiY4lQWJetzADFl0BAH8gZWN4km77AgnfC15CWZYiktQiXLhAdKmhcs3ByU2bA8TjOBOI3x2X3AMgODrST+MF79jye5D8x53JOnMyUWfdq0SgIRXHf0yKoS76/6Ps6XoJNyr7rS0lZFeig2BOPW894PveZwBXa7g92jC1uBp9ByrNRx6da4rUnNn5BYwVVZt/pULtPQZa92mUwi3gEHVPfGDst/k42MvRNJgAfeBVBBuGjT7/QZ+lNjDql9OaLvzBPH5QhgVFP9rYuT2IOvxZUWzhKKRIElv8Ba6AvBnEVg=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_DM6PR05MB6348D1ED11E539E6EC0176D4AEB30DM6PR05MB6348namp_"
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: 5e8edf0d-03f8-4fb5-ba99-08d8005f941a
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 May 2020 03:56:17.8508 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: JSeUTTfilqSlBzAhzVNprIGOSsONxmOKHmQd8OVZplBW4clPuXglkVGrbWy7Q6XTN7wuIQESDnAktpmgmTyGVQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR05MB5612
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.216, 18.0.676 definitions=2020-05-24_11:2020-05-22, 2020-05-24 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 phishscore=0 suspectscore=0 mlxscore=0 lowpriorityscore=0 adultscore=0 clxscore=1015 malwarescore=0 bulkscore=0 cotscore=-2147483648 impostorscore=0 mlxlogscore=999 spamscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2004280000 definitions=main-2005250029
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/i1LyBYf3F-_VI2h3pApQEXTqcvo>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 May 2020 03:56:23 -0000

Inline.....



Juniper Business Use Only
From: ipv6 <ipv6-bounces@ietf.org> On Behalf Of Mark Smith
Sent: Sunday, May 24, 2020 5:22 PM
To: Brian E Carpenter <brian.e.carpenter@gmail.com>
Cc: 6man <ipv6@ietf.org>
Subject: Re: Dumb question about routing headers

[External Email. Be cautious of content]


On Mon, 25 May 2020, 07:06 Brian E Carpenter, <brian.e.carpenter@gmail.com<mailto:brian.e.carpenter@gmail.com>> wrote:
Is a routing header whose final destination is a multicast address, but whose previous segments are all unicast, valid?


A related question is are multicast addresses within the list if hops to visit valid?

[RB] There is no rule against this, but there certainly should be!

I thought it might not be because you could create a worse version of the RFC 5095 attack.

However, I think the multicast forwarding RPF check prevents that working, so a multicast addresses anywhere in an RH set of hops could be valid.

Haven't thought of a use for it though.

Regards,
Mark.


Regards
   Brian Carpenter

--------------------------------------------------------------------
IETF IPv6 working group mailing list
ipv6@ietf.org<mailto:ipv6@ietf.org>
Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6<https://urldefense.com/v3/__https:/www.ietf.org/mailman/listinfo/ipv6__;!!NEt6yMaO-gk!TM3agGjJI6WbBACEwjhtyimfv81DQPvCiA79nz6PM0jBmaecM5b8V83xwn88fMXA$>
--------------------------------------------------------------------