Re: IPv6 header insertion in a controlled domain

Sander Steffann <sander@steffann.nl> Sun, 08 December 2019 18:05 UTC

Return-Path: <sander@steffann.nl>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59EB6120020 for <ipv6@ietfa.amsl.com>; Sun, 8 Dec 2019 10:05:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level:
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=steffann.nl
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bL4Y5SWzc4xE for <ipv6@ietfa.amsl.com>; Sun, 8 Dec 2019 10:05:23 -0800 (PST)
Received: from mail.sintact.nl (mail.sintact.nl [83.247.10.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0751A120019 for <ipv6@ietf.org>; Sun, 8 Dec 2019 10:05:22 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mail.sintact.nl (Postfix) with ESMTP id 0281749; Sun, 8 Dec 2019 19:05:20 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=steffann.nl; h= x-mailer:references:in-reply-to:date:date:subject:subject :mime-version:content-type:content-type:message-id:from:from :received:received; s=mail; t=1575828318; bh=+4AfZPBCwZWW/hGIZve phM2v4erQpfAtbu8CKUbYxdQ=; b=VW7mO+esElXBgejCpHpuGgyKDFP/L5wh0Sg qiAWOo+Xzon6sMVBa5dT3MxvkFwQJnaxXC8jaWGQS8sVYSvtGozvmdOgOUvHswzj ILXDpzaCPvTGY50PE23TnqC0i17O68cHPKQgAGA89Ar7ZYsrHwz7o9TJ8KsPY1Bf MKPzhAok=
X-Virus-Scanned: Debian amavisd-new at mail.sintact.nl
Received: from mail.sintact.nl ([127.0.0.1]) by localhost (mail.sintact.nl [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id Yd3OhthD7p-Y; Sun, 8 Dec 2019 19:05:18 +0100 (CET)
Received: from [IPv6:2a02:a213:a300:ce80:48c4:a854:5031:6d89] (unknown [IPv6:2a02:a213:a300:ce80:48c4:a854:5031:6d89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mail.sintact.nl (Postfix) with ESMTPSA id AF4023C; Sun, 8 Dec 2019 19:05:17 +0100 (CET)
X-Clacks-Overhead: GNU Terry Pratchett
From: Sander Steffann <sander@steffann.nl>
Message-Id: <DCE8F651-7BB7-4186-9599-5FC185900C7D@steffann.nl>
Content-Type: multipart/signed; boundary="Apple-Mail=_B7178E9C-5D16-4FCB-B171-FD23779ACF08"; protocol="application/pgp-signature"; micalg="pgp-sha256"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3594.4.19\))
Subject: Re: IPv6 header insertion in a controlled domain
Date: Sun, 08 Dec 2019 19:05:16 +0100
In-Reply-To: <B0BCB469-9152-43E1-BCEF-5C8A300F7EA2@employees.org>
Cc: Gyan Mishra <hayabusagsm@gmail.com>, 6man WG <ipv6@ietf.org>
To: Ole Troan <otroan@employees.org>
References: <CALx6S3588ja9AZzBQ0dqwx0j-ki6A5tusye+odQKPyAyF+hEww@mail.gmail.com> <10E890EA-3278-44EE-881E-EBC91D419587@employees.org> <88287cb0-c0c3-f990-4dd7-338df87c7fb2@joelhalpern.com> <4E76C386-FB1E-4E48-814D-BB626466BEE3@employees.org> <CAO42Z2ze7tmkGh=E-YrPuJHMeD8V6EuxgjjaJ33iz+Ms3abNsA@mail.gmail.com> <ED9B7C60-ACDE-4107-A121-AE2DAEA6B640@employees.org> <CABNhwV0EGiMaX0Qkyk+_zqZfiaAS_RP_ewVEctgdSnMuJ3MBPw@mail.gmail.com> <8AE06652-D6DB-444D-A8BB-7924181C83E4@employees.org> <CABNhwV1Ym5xtDY+vo8haaaObhMayE+ejkUbm4Sq9A5axCQwopA@mail.gmail.com> <160F2740-7571-44D9-8995-5D2F23989DF6@employees.org> <CABNhwV1Jdw3xwfGSJbQbF1e7ZtfL_pEsmSRC6KkRbdK+4EAygQ@mail.gmail.com> <B0BCB469-9152-43E1-BCEF-5C8A300F7EA2@employees.org>
X-Mailer: Apple Mail (2.3594.4.19)
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/C8459ODF2qPM0D5UsetrtpXvl1M>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Dec 2019 18:05:25 -0000

Hi,

> A more likely outcome is to declare that AH isn't supported in this case.

I don't think we should standardise any standard that has such a restriction, considering the importace of security these days. So if this is indeed the outcome I would consider that a blocker.

Cheers,
Sander