Re: I-D Action: draft-smith-6man-in-flight-eh-insertion-harmful-00.txt

Brian E Carpenter <brian.e.carpenter@gmail.com> Sun, 13 October 2019 00:36 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 68B131200EF for <ipv6@ietfa.amsl.com>; Sat, 12 Oct 2019 17:36:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9sYlh8HHOzlD for <ipv6@ietfa.amsl.com>; Sat, 12 Oct 2019 17:36:36 -0700 (PDT)
Received: from mail-pg1-x535.google.com (mail-pg1-x535.google.com [IPv6:2607:f8b0:4864:20::535]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 01E861200DF for <ipv6@ietf.org>; Sat, 12 Oct 2019 17:36:35 -0700 (PDT)
Received: by mail-pg1-x535.google.com with SMTP id t3so7932736pga.8 for <ipv6@ietf.org>; Sat, 12 Oct 2019 17:36:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=fAdDK4WkVY+4BdsBCnVp3GCIXZ8mFVF7EBPA32e6V7w=; b=bKDojRjzA7G8o1ZStDXeSCZg8UTcqGE9KKPOPTiSPiN67k2YUKFk1NGMQJ/qKDl7Km Adyuzdyaelsr86gAERj+fxuTTta3P2TilZToSftxSgED3iA81HgEMSu05XosyfQ6/x42 Wfqtump36A4jgrc0b8Q717wtcUf2gr3lA8RP12uImLrlukjuJk4jbker9V7wZlrOxXK0 bnjP+HtygTli8JmadG1ypoD30BAaVkwUEkMlqJcb9jFtlGY3xJVgF8Uc3+mpyvRCRkw0 wLYlPZKSVhdwN9GDUY1Bwx6lt++/72fArKyA+kR6P9+9JqRO+MBAYbgghexzQMeyOLz6 h1ow==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=fAdDK4WkVY+4BdsBCnVp3GCIXZ8mFVF7EBPA32e6V7w=; b=G8vDoD7EThn4N8oy3IWPJEq6zcvqfH5CulHDNI8B6Cl1024tn7KfCbpyfj8MlClnBS tpAHa9yLFGn7Xf8hiRsO5RYKUVV2yEZQkJ0ZJBAd/J2VdhFP3F34yaTY0dRidNTf9HeP xHofTn0+aD6iQ9LEqoHCgjKxevMYp6P756cLRkKlIyy63qzixJtEJbOkhuARNgtVPnKI yY+7wnqsIbYqX2QWqRG7GXJUaMB6+l5C0mtaQMvS5f0B4IdC3SVtgOXNfZry7a0DHs3b 5Sq5CXZITdY5zk48qS0/TjVWKikG4tE3Mm/aKZTKsut57QXT8XMuNFifvo70cixEpIN/ /pZw==
X-Gm-Message-State: APjAAAV+H6gm3xdHrnWSdj0HNqCdLKbdqZOoh/DCeHhnn5L3oqaTsgmR SUnKbKF+pQVy6ZGq8u2fGZ94xMk7
X-Google-Smtp-Source: APXvYqwxUX/AznMZx75tE87VxBQ58/LAiRpJTz3LfH8NaUKVScASMxCgo4gPKaVSyOPujIGzd0MTkA==
X-Received: by 2002:a17:90a:356a:: with SMTP id q97mr26488497pjb.50.1570926994871; Sat, 12 Oct 2019 17:36:34 -0700 (PDT)
Received: from [192.168.178.30] (233.148.69.111.dynamic.snap.net.nz. [111.69.148.233]) by smtp.gmail.com with ESMTPSA id v1sm16721051pjd.22.2019.10.12.17.36.32 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 12 Oct 2019 17:36:34 -0700 (PDT)
Subject: Re: I-D Action: draft-smith-6man-in-flight-eh-insertion-harmful-00.txt
To: Nick Hilliard <nick@foobar.org>
Cc: Mark Smith <markzzzsmith@gmail.com>, 6man <ipv6@ietf.org>
References: <157059901123.30422.11220423219059958820@ietfa.amsl.com> <362b80f7-fedc-7227-2931-0006e6b81812@gmail.com> <f2548b48-2d8d-01f0-f05c-0027a5cdeb91@foobar.org>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Message-ID: <57b3a7bd-3dc3-d8be-0ac4-7218abdd94d8@gmail.com>
Date: Sun, 13 Oct 2019 13:36:31 +1300
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <f2548b48-2d8d-01f0-f05c-0027a5cdeb91@foobar.org>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/-O-K8TB4NM7PsUZFKEhpGONxgrQ>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 13 Oct 2019 00:36:37 -0000

On 13-Oct-19 13:08, Nick Hilliard wrote:
> Brian E Carpenter wrote on 12/10/2019 23:15:
>> EH insertion for packets that traverse the open Internet is certainly harmful and violates RFC 8200
> 
> How does the packet know whether it's the open internet or a controlled 
> domain?

The packet is too dumb to know anything ;-). My question is how each node it traverses knows. Indeed, Mark's draft describes a scenario where the controlled domain argument breaks, because the exit node might not know that the packet had suffered EH insertion. The draft-voyer- scenario is not like that, because the affected IPv6 headers are created locally and identifiable as such.

   Brian