Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]

Brian E Carpenter <brian.e.carpenter@gmail.com> Tue, 20 September 2016 22:42 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0A78712B4EA for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:42:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FrKn6-V8tqHH for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:42:21 -0700 (PDT)
Received: from mail-pf0-x229.google.com (mail-pf0-x229.google.com [IPv6:2607:f8b0:400e:c00::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0336912B3C2 for <6man@ietf.org>; Tue, 20 Sep 2016 15:42:21 -0700 (PDT)
Received: by mail-pf0-x229.google.com with SMTP id q2so11758545pfj.3 for <6man@ietf.org>; Tue, 20 Sep 2016 15:42:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:to:references:cc:from:organization:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding; bh=4pPkaNtypoZ6I30/ajROJSwe+pKZCRX9xI6nvIgQhC0=; b=1KLFtYisHKy8Zo4LhntQvMZeYe3P5jBFMyyiwt1C3ZEUfgoe6KxRVs1a25WDvM2cS5 CJFWMnzRI2EnvK2gUiboGVKH9t7k9n308XSC2v0BvPnzEcXqyDIn5lI6yriCHFurdEqS JDLjpi/cgORO05+nLW/+fMXow275CtoTnNabcDBwVlj1PKz623cUOTKQRF2AyV1D13DF LgOFowp018EC4yj7Mv2bdaE2HTAMk9j0zubWnl9GGRFNpmCrwus5dRkoYe4awoB0csQE 2XDThdj1/TorjqU0aB+HW8XJBy1lJ2Sav8/FMkZB04QSKwMueV6I0VIa6s5J6swCU42G PYxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:cc:from:organization :message-id:date:user-agent:mime-version:in-reply-to :content-transfer-encoding; bh=4pPkaNtypoZ6I30/ajROJSwe+pKZCRX9xI6nvIgQhC0=; b=EIWMYkCBTMQIPbTlGg7bBd0CS7OoLYvugS8Abd2FXYravtAjj5at2zhpDx5EsavEdj h7atjmXRfwRhaKnv2aFWCG4fbFfkRZvRzaKjZ8mTv4oGybfYJNu05cQ9h5JOjoCPXmQh LSbwpDQ4rJznmHaPdsdPRo6oNKG8Wf6IJdxMsQmkGFeT4damDCktik2gXTOf2FtAOWqq RiM4yhfwWe/UfJoGieedeFlv/wb/zqrWmK01VefWSPH4VyzmAUQx+e6tGP3Ssk1bAtdN WxMRQE9IRSkstSL1ZnSGkkv91JFbfGmNg4Q4hQpRC71x/61rdDzHGHIGo7ThqYT7mmyP w4Hg==
X-Gm-Message-State: AE9vXwNrsy5buLJooS2fXwyE8TEYyPaHeyiyXrdo+fMt/y9Xn9rliMJ+Wtwez5AH2e8YOg==
X-Received: by 10.98.23.197 with SMTP id 188mr37378590pfx.96.1474411340619; Tue, 20 Sep 2016 15:42:20 -0700 (PDT)
Received: from ?IPv6:2001:df0:0:2006:c0da:ac17:5f6d:8e76? ([2001:df0:0:2006:c0da:ac17:5f6d:8e76]) by smtp.gmail.com with ESMTPSA id sa1sm15412570pac.34.2016.09.20.15.42.17 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 20 Sep 2016 15:42:19 -0700 (PDT)
Subject: Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
To: Tim Chown <Tim.Chown@jisc.ac.uk>, "huitema@huitema.net" <huitema@huitema.net>
References: <C75A2D0E-7808-4460-ABC0-AD612484663A@jisc.ac.uk> <C453AB9B-3FF4-4706-B5C2-8D747906C088@gmail.com> <a653fe9d-3290-3874-b2e5-298aa93e844e@gmail.com> <E1beqnb-0005Wh-7t@mx43.antispamcloud.com> <F5C4DCD9-002D-4767-9BCB-E7E4366E793D@jisc.ac.uk> <e80cda24-7fed-42f0-92a0-a6507e8455f4@gmail.com>
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
Message-ID: <20e13576-6292-599c-7383-4be716e802e9@gmail.com>
Date: Wed, 21 Sep 2016 10:42:21 +1200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.3.0
MIME-Version: 1.0
In-Reply-To: <e80cda24-7fed-42f0-92a0-a6507e8455f4@gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/3FVnjNRDqXFm_D_qfPlbcSp5VGk>
Cc: "6man@ietf.org" <6man@ietf.org>, Bob Hinden <bob.hinden@gmail.com>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2016 22:42:24 -0000

I realised that we probably have to discuss this further. There are two
places where rfc2460bis explicitly allows a covert channel because of
No Next Header:

> 4.5.  Fragment Header
...
>       The Fragmentable Part consists of the rest of the packet after the
>       upper-layer header or after any header (i.e., initial IPv6 header
>       or extension header) that contains a Next Header value of No Next
>       Header.
...
> 4.7.  No Next Header
> 
>    The value 59 in the Next Header field of an IPv6 header or any
>    extension header indicates that there is nothing following that
>    header.  If the Payload Length field of the IPv6 header indicates the
>    presence of octets past the end of a header whose Next Header field
>    contains 59, those octets must be ignored, and passed on unchanged if
>    the packet is forwarded.

Do we really want to allow this? Do we know whether current firewalls
tolerate it?

If we keep this, I think some words about the covert channel are needed
in the Security Considerations.

And looking at the Security Considerations, I don't think they are
sufficient anyway. At the least we should refer to other work, not
just IPSec.

Regards
   Brian

On 01/09/2016 08:32, Brian E Carpenter wrote:
> On 31/08/2016 20:30, Tim Chown wrote:
>> On 30 Aug 2016, at 22:41, huitema@huitema.net<mailto:huitema@huitema.net> wrote:
>>
>> It is used in Teredo. The Teredo bubbles have no payload, hence set payload type to 59.
>>
>> OK, thanks, that seems a reasonable generic use case, even if there’s only one example :)
>>
>> But given it’s not in RFC 7045, anyone kind enough to implement the advice there won’t necessarily include header 59.
> 
> Actually it is mentioned in 7045 but intentionally not listed in the IANA registry:
>    "This list excludes type 59, No Next Header, [RFC2460], which is not
>    an extension header as such."
> 
> Packets with "No Next Header" followed by additional bytes are allowed by RFC2460,
> but would be very suspect to any firewall, I would think.
> 
>     Brian
> 
>>
>> Tim
>>
>> Sent from my Windows 10 phone
>>
>> From: Brian E Carpenter<mailto:brian.e.carpenter@gmail.com>
>> Sent: Tuesday, August 30, 2016 1:40 PM
>> To: Bob Hinden<mailto:bob.hinden@gmail.com>; Tim Chown<mailto:Tim.Chown@jisc.ac.uk>
>> Cc: 6man@ietf.org<mailto:6man@ietf.org>
>> Subject: Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
>>
>> On 31/08/2016 08:19, Bob Hinden wrote:
>>
>> ...
>>>> p.22 is Next Header value 59 used in practice? (Just curious… it was omitted from RFC7045).
>>>
>>> I am not 100% sure, but think it is used.  But it is not something that has been updated.
>>
>> It's a curious case, but we didn't mention it in 7045 or ask IANA to include it in
>> http://www.iana.org/assignments/ipv6-parameters/ipv6-parameters.xhtml#extension-header
>> because, well, it isn't a header and doesn't require any processing. I think
>> that's OK.
>>
>> Regards
>>      Brian
>>
>> --------------------------------------------------------------------
>> IETF IPv6 working group mailing list
>> ipv6@ietf.org<mailto:ipv6@ietf.org>
>> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
>> --------------------------------------------------------------------
>>
>