Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
Brian E Carpenter <brian.e.carpenter@gmail.com> Tue, 20 September 2016 22:42 UTC
Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0A78712B4EA for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:42:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FrKn6-V8tqHH for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:42:21 -0700 (PDT)
Received: from mail-pf0-x229.google.com (mail-pf0-x229.google.com [IPv6:2607:f8b0:400e:c00::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0336912B3C2 for <6man@ietf.org>; Tue, 20 Sep 2016 15:42:21 -0700 (PDT)
Received: by mail-pf0-x229.google.com with SMTP id q2so11758545pfj.3 for <6man@ietf.org>; Tue, 20 Sep 2016 15:42:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:to:references:cc:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=4pPkaNtypoZ6I30/ajROJSwe+pKZCRX9xI6nvIgQhC0=; b=1KLFtYisHKy8Zo4LhntQvMZeYe3P5jBFMyyiwt1C3ZEUfgoe6KxRVs1a25WDvM2cS5 CJFWMnzRI2EnvK2gUiboGVKH9t7k9n308XSC2v0BvPnzEcXqyDIn5lI6yriCHFurdEqS JDLjpi/cgORO05+nLW/+fMXow275CtoTnNabcDBwVlj1PKz623cUOTKQRF2AyV1D13DF LgOFowp018EC4yj7Mv2bdaE2HTAMk9j0zubWnl9GGRFNpmCrwus5dRkoYe4awoB0csQE 2XDThdj1/TorjqU0aB+HW8XJBy1lJ2Sav8/FMkZB04QSKwMueV6I0VIa6s5J6swCU42G PYxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-transfer-encoding; bh=4pPkaNtypoZ6I30/ajROJSwe+pKZCRX9xI6nvIgQhC0=; b=EIWMYkCBTMQIPbTlGg7bBd0CS7OoLYvugS8Abd2FXYravtAjj5at2zhpDx5EsavEdj h7atjmXRfwRhaKnv2aFWCG4fbFfkRZvRzaKjZ8mTv4oGybfYJNu05cQ9h5JOjoCPXmQh LSbwpDQ4rJznmHaPdsdPRo6oNKG8Wf6IJdxMsQmkGFeT4damDCktik2gXTOf2FtAOWqq RiM4yhfwWe/UfJoGieedeFlv/wb/zqrWmK01VefWSPH4VyzmAUQx+e6tGP3Ssk1bAtdN WxMRQE9IRSkstSL1ZnSGkkv91JFbfGmNg4Q4hQpRC71x/61rdDzHGHIGo7ThqYT7mmyP w4Hg==
X-Gm-Message-State: AE9vXwNrsy5buLJooS2fXwyE8TEYyPaHeyiyXrdo+fMt/y9Xn9rliMJ+Wtwez5AH2e8YOg==
X-Received: by 10.98.23.197 with SMTP id 188mr37378590pfx.96.1474411340619; Tue, 20 Sep 2016 15:42:20 -0700 (PDT)
Received: from ?IPv6:2001:df0:0:2006:c0da:ac17:5f6d:8e76? ([2001:df0:0:2006:c0da:ac17:5f6d:8e76]) by smtp.gmail.com with ESMTPSA id sa1sm15412570pac.34.2016.09.20.15.42.17 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 20 Sep 2016 15:42:19 -0700 (PDT)
Subject: Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
To: Tim Chown <Tim.Chown@jisc.ac.uk>, "huitema@huitema.net" <huitema@huitema.net>
References: <C75A2D0E-7808-4460-ABC0-AD612484663A@jisc.ac.uk> <C453AB9B-3FF4-4706-B5C2-8D747906C088@gmail.com> <a653fe9d-3290-3874-b2e5-298aa93e844e@gmail.com> <E1beqnb-0005Wh-7t@mx43.antispamcloud.com> <F5C4DCD9-002D-4767-9BCB-E7E4366E793D@jisc.ac.uk> <e80cda24-7fed-42f0-92a0-a6507e8455f4@gmail.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <20e13576-6292-599c-7383-4be716e802e9@gmail.com>
Date: Wed, 21 Sep 2016 10:42:21 +1200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.3.0
MIME-Version: 1.0
In-Reply-To: <e80cda24-7fed-42f0-92a0-a6507e8455f4@gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/3FVnjNRDqXFm_D_qfPlbcSp5VGk>
Cc: "6man@ietf.org" <6man@ietf.org>, Bob Hinden <bob.hinden@gmail.com>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2016 22:42:24 -0000
I realised that we probably have to discuss this further. There are two places where rfc2460bis explicitly allows a covert channel because of No Next Header: > 4.5. Fragment Header ... > The Fragmentable Part consists of the rest of the packet after the > upper-layer header or after any header (i.e., initial IPv6 header > or extension header) that contains a Next Header value of No Next > Header. ... > 4.7. No Next Header > > The value 59 in the Next Header field of an IPv6 header or any > extension header indicates that there is nothing following that > header. If the Payload Length field of the IPv6 header indicates the > presence of octets past the end of a header whose Next Header field > contains 59, those octets must be ignored, and passed on unchanged if > the packet is forwarded. Do we really want to allow this? Do we know whether current firewalls tolerate it? If we keep this, I think some words about the covert channel are needed in the Security Considerations. And looking at the Security Considerations, I don't think they are sufficient anyway. At the least we should refer to other work, not just IPSec. Regards Brian On 01/09/2016 08:32, Brian E Carpenter wrote: > On 31/08/2016 20:30, Tim Chown wrote: >> On 30 Aug 2016, at 22:41, huitema@huitema.net<mailto:huitema@huitema.net> wrote: >> >> It is used in Teredo. The Teredo bubbles have no payload, hence set payload type to 59. >> >> OK, thanks, that seems a reasonable generic use case, even if there’s only one example :) >> >> But given it’s not in RFC 7045, anyone kind enough to implement the advice there won’t necessarily include header 59. > > Actually it is mentioned in 7045 but intentionally not listed in the IANA registry: > "This list excludes type 59, No Next Header, [RFC2460], which is not > an extension header as such." > > Packets with "No Next Header" followed by additional bytes are allowed by RFC2460, > but would be very suspect to any firewall, I would think. > > Brian > >> >> Tim >> >> Sent from my Windows 10 phone >> >> From: Brian E Carpenter<mailto:brian.e.carpenter@gmail.com> >> Sent: Tuesday, August 30, 2016 1:40 PM >> To: Bob Hinden<mailto:bob.hinden@gmail.com>; Tim Chown<mailto:Tim.Chown@jisc.ac.uk> >> Cc: 6man@ietf.org<mailto:6man@ietf.org> >> Subject: Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05] >> >> On 31/08/2016 08:19, Bob Hinden wrote: >> >> ... >>>> p.22 is Next Header value 59 used in practice? (Just curious… it was omitted from RFC7045). >>> >>> I am not 100% sure, but think it is used. But it is not something that has been updated. >> >> It's a curious case, but we didn't mention it in 7045 or ask IANA to include it in >> http://www.iana.org/assignments/ipv6-parameters/ipv6-parameters.xhtml#extension-header >> because, well, it isn't a header and doesn't require any processing. I think >> that's OK. >> >> Regards >> Brian >> >> -------------------------------------------------------------------- >> IETF IPv6 working group mailing list >> ipv6@ietf.org<mailto:ipv6@ietf.org> >> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 >> -------------------------------------------------------------------- >> >
- Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Next Header value 59 [was Re: Review of draft-iet… Brian E Carpenter
- RE: Next Header value 59 [was Re: Review of draft… huitema
- Re: Next Header value 59 [was Re: Review of draft… Tim Chown
- Re: Next Header value 59 [was Re: Review of draft… Brian E Carpenter
- Re: Next Header value 59 [was Re: Review of draft… Alexandre Petrescu
- Re: Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Re: Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Security Considerations for Next Header value 59 … Brian E Carpenter
- RE: Security Considerations for Next Header value… Christian Huitema
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Security Considerations for Next Header value… Tim Chown
- Re: Security Considerations for Next Header value… Bob Hinden
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Security Considerations for Next Header value… Bob Hinden
- Re: Security Considerations for Next Header value… Brian E Carpenter
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Review of draft-ietf-6man-rfc2460bis-05 神明達哉
- Re: Security Considerations for Next Header value… otroan
- Re: Security Considerations for Next Header value… otroan
- Re: Security Considerations for Next Header value… otroan
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… Bob Hinden
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… 神明達哉