Re: Adrian Farrel's No Objection on draft-ietf-6man-ext-transmit-04: (with COMMENT)

Brian E Carpenter <brian.e.carpenter@gmail.com> Fri, 11 October 2013 04:15 UTC

Return-Path: <brian.e.carpenter@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE39D21E8164 for <ipv6@ietfa.amsl.com>; Thu, 10 Oct 2013 21:15:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.561
X-Spam-Level:
X-Spam-Status: No, score=-102.561 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KeGB1dWLXe4s for <ipv6@ietfa.amsl.com>; Thu, 10 Oct 2013 21:15:03 -0700 (PDT)
Received: from mail-pa0-x230.google.com (mail-pa0-x230.google.com [IPv6:2607:f8b0:400e:c03::230]) by ietfa.amsl.com (Postfix) with ESMTP id EAD5C11E811D for <ipv6@ietf.org>; Thu, 10 Oct 2013 21:14:58 -0700 (PDT)
Received: by mail-pa0-f48.google.com with SMTP id bj1so3761039pad.21 for <ipv6@ietf.org>; Thu, 10 Oct 2013 21:14:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:organization:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=3tYMD3MnkH9AArl13Wr7FBPTx0x3MBUWv/kIHinEBj4=; b=UTuBHMEupdgQ8LjC8KWJb0smKaDxXATm04t/6sfQeKLVcp3pSAyfvvCyei+V1VIdn5 CVJIxLEcRyjuraqAUlx7TSH7CY8ZSXhDjMOwRaZiBHO9NWFnAC5qdBYlFuhW0AREcPRc drherF0IiZYmzIzNNCRHLdfm2NkNnK0hVT+TQOOeZjWH9vWEu+Mz8vBnlQWXcbKvLXJG exbz+FVA651hjvKdPStZHuvYxhfR2EMFa2bkvwBR6GEqECeaLhqC6nM4/o2xHfeNPSS9 EgjqHfPhj8YAMCvoW3p9Q0SMyAkObbjIc9TmlbIueUbTWNQjmIML+Rd/d5Leh1r2N6GU XZkQ==
X-Received: by 10.66.119.78 with SMTP id ks14mr19199779pab.140.1381464898649; Thu, 10 Oct 2013 21:14:58 -0700 (PDT)
Received: from [192.168.178.20] (167.201.69.111.dynamic.snap.net.nz. [111.69.201.167]) by mx.google.com with ESMTPSA id sb9sm56784336pbb.0.1969.12.31.16.00.00 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Thu, 10 Oct 2013 21:14:57 -0700 (PDT)
Message-ID: <52577B48.8030901@gmail.com>
Date: Fri, 11 Oct 2013 17:15:04 +1300
From: Brian E Carpenter <brian.e.carpenter@gmail.com>
Organization: University of Auckland
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
MIME-Version: 1.0
To: "Templin, Fred L" <Fred.L.Templin@boeing.com>
Subject: Re: Adrian Farrel's No Objection on draft-ietf-6man-ext-transmit-04: (with COMMENT)
References: <20131007144327.16131.88173.idtracker@ietfa.amsl.com> <Pine.LNX.4.64.1310070914240.13173@shell4.bayarea.net> <52530921.3060202@gmail.com> <Pine.LNX.4.64.1310071315370.13828@shell4.bayarea.net> <52534F31.2020906@gmail.com> <2134F8430051B64F815C691A62D9831811DA86@XCH-BLV-504.nw.nos.boeing.com>
In-Reply-To: <2134F8430051B64F815C691A62D9831811DA86@XCH-BLV-504.nw.nos.boeing.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Cc: "C. M. Heard" <heard@pobox.com>, "6man-chairs@tools.ietf.org" <6man-chairs@tools.ietf.org>, "draft-ietf-6man-ext-transmit@tools.ietf.org" <draft-ietf-6man-ext-transmit@tools.ietf.org>, "ipv6@ietf.org" <ipv6@ietf.org>, Adrian Farrel <adrian@olddog.co.uk>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Oct 2013 04:15:04 -0000

Fred,

On 09/10/2013 04:28, Templin, Fred L wrote:
...
> When Wireshark encounters a header type 253 or 254, it assumes it is
> an unknown extension header of length 8 bytes, then skips ahead and
> attempts to parse anything that follows as additional headers.

They must have just made that up; there's no justification for it.
It could be an unknown extension header of unknown length, or it
could be an unknown payload of unknown length. In real life
I'd expect firewalls to default-drop such packets.

We'll note this issue in the Security Considerations.

    Brian