Re: ESSID ietf-nat64-unencrypted at IETF 100

Alexandre Petrescu <alexandre.petrescu@gmail.com> Tue, 14 November 2017 07:32 UTC

Return-Path: <alexandre.petrescu@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3850129481 for <ipv6@ietfa.amsl.com>; Mon, 13 Nov 2017 23:32:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.633
X-Spam-Level:
X-Spam-Status: No, score=-2.633 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_ADSP_CUSTOM_MED=0.001, FREEMAIL_FROM=0.001, NML_ADSP_CUSTOM_MED=0.9, RCVD_IN_DNSWL_MED=-2.3, SPF_SOFTFAIL=0.665] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nvrGcu4wyxcS for <ipv6@ietfa.amsl.com>; Mon, 13 Nov 2017 23:32:48 -0800 (PST)
Received: from oxalide-smtp-out.extra.cea.fr (oxalide-smtp-out.extra.cea.fr [132.168.224.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3C52F1294A8 for <ipv6@ietf.org>; Mon, 13 Nov 2017 23:32:48 -0800 (PST)
Received: from pisaure.intra.cea.fr (pisaure.intra.cea.fr [132.166.88.21]) by oxalide-sys.extra.cea.fr (8.14.7/8.14.7/CEAnet-Internet-out-4.0) with ESMTP id vAE7Wks3005254 for <ipv6@ietf.org>; Tue, 14 Nov 2017 08:32:46 +0100
Received: from pisaure.intra.cea.fr (localhost [127.0.0.1]) by localhost (Postfix) with SMTP id 636E4200CEC for <ipv6@ietf.org>; Tue, 14 Nov 2017 08:32:46 +0100 (CET)
Received: from muguet1.intra.cea.fr (muguet1.intra.cea.fr [132.166.192.6]) by pisaure.intra.cea.fr (Postfix) with ESMTP id 50CA4200808 for <ipv6@ietf.org>; Tue, 14 Nov 2017 08:32:46 +0100 (CET)
Received: from [132.166.84.93] ([132.166.84.93]) by muguet1.intra.cea.fr (8.15.2/8.15.2/CEAnet-Intranet-out-1.4) with ESMTP id vAE7WjuK005773 for <ipv6@ietf.org>; Tue, 14 Nov 2017 08:32:45 +0100
Subject: Re: ESSID ietf-nat64-unencrypted at IETF 100
To: ipv6@ietf.org
References: <acd854c7-8bd2-781e-6d0d-b15bb62c48e2@gmail.com>
From: Alexandre Petrescu <alexandre.petrescu@gmail.com>
Message-ID: <553998cf-e802-23ec-c1b5-2b57b5c297e1@gmail.com>
Date: Tue, 14 Nov 2017 08:32:44 +0100
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <acd854c7-8bd2-781e-6d0d-b15bb62c48e2@gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: fr
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/HM5M1rKpzFfXWmafufsOUujIkT0>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 07:32:50 -0000

I Can connect ok to ietf-nat64-unencrypted.

Here is my feedback:

I use VPN to check emails, and the email checking and sending is much 
slower than when I do it on ietf-legacy100, or on Terminal Room Ethernet.

It has intermittency and 'hiccups'.  Sometimes the VPN gets disconnected.

Alex

Le 14/11/2017 à 07:03, Alexandre Petrescu a écrit :
> Hi,
> 
> I have problems connecting to the IPv6-only ESSID "ietf-v6only".
> 
> It is a problem of certificates.
> 
> I have this problem on Windows since several IETF meetings; it may not 
> be related in particular to IPv6.
> 
> The message in the window below says: "The server 
> services.meeting.ietf.org presented a certifcate valid emitted by 
> Starfield CA, but that is not configured as a valid anchor to approve 
> this profile".
> 
> I dont thave this kind of certification refusal problem on 
> ietf-legacy100 ESSID (and all earlier ietf-legacy), neither on 
> ietf-nat64-unencrypted.
> 
> This ietf-nat64-unencrypted is now appearing first time at IETF.  I 
> suppose people realized there was a problem with certs and created an 
> 'unencrypted' version.  That's not a best practice to fix security :-)
> 
> And yes, my VPN FortiClient works ok on ietf-nat64-unencrypted.
> 
> 
> 
> 
> Alex
> 
> 
> 
> 
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> --------------------------------------------------------------------
>