RE: Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
"Christian Huitema" <huitema@huitema.net> Tue, 20 September 2016 22:58 UTC
Return-Path: <huitema@huitema.net>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 21F2812B4D2 for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:58:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6GZSVprDXYjo for <ipv6@ietfa.amsl.com>; Tue, 20 Sep 2016 15:58:21 -0700 (PDT)
Received: from mx43-out1.antispamcloud.com (mx43-out1.antispamcloud.com [138.201.61.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 48A2312B00D for <6man@ietf.org>; Tue, 20 Sep 2016 15:58:21 -0700 (PDT)
Received: from xsmtp02.mail2web.com ([168.144.250.215]) by mx43.antispamcloud.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.86) (envelope-from <huitema@huitema.net>) id 1bmTzW-0004TL-Lo for 6man@ietf.org; Wed, 21 Sep 2016 00:58:19 +0200
Received: from [10.5.2.31] (helo=xmail09.myhosting.com) by xsmtp02.mail2web.com with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.63) (envelope-from <huitema@huitema.net>) id 1bmTzT-0003PT-IL for 6man@ietf.org; Tue, 20 Sep 2016 18:58:16 -0400
Received: (qmail 19971 invoked from network); 20 Sep 2016 22:58:15 -0000
Received: from unknown (HELO huitema2) (Authenticated-user:_huitema@huitema.net@[131.107.174.4]) (envelope-sender <huitema@huitema.net>) by xmail09.myhosting.com (qmail-ldap-1.03) with ESMTPA for <6man@ietf.org>; 20 Sep 2016 22:58:15 -0000
From: Christian Huitema <huitema@huitema.net>
To: 'Brian E Carpenter' <brian.e.carpenter@gmail.com>, 'Tim Chown' <Tim.Chown@jisc.ac.uk>
References: <C75A2D0E-7808-4460-ABC0-AD612484663A@jisc.ac.uk> <C453AB9B-3FF4-4706-B5C2-8D747906C088@gmail.com> <a653fe9d-3290-3874-b2e5-298aa93e844e@gmail.com> <E1beqnb-0005Wh-7t@mx43.antispamcloud.com> <F5C4DCD9-002D-4767-9BCB-E7E4366E793D@jisc.ac.uk> <e80cda24-7fed-42f0-92a0-a6507e8455f4@gmail.com> <20e13576-6292-599c-7383-4be716e802e9@gmail.com>
In-Reply-To: <20e13576-6292-599c-7383-4be716e802e9@gmail.com>
Date: Tue, 20 Sep 2016 15:58:13 -0700
Message-ID: <049301d21392$78346ba0$689d42e0$@huitema.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQIWDCza4qrUryuXgLYO87BNhjn6ZAJFc42RAUVJnykBYGeuIQFo69HaAnJUTnkC5AfBKZ+dtcLw
Content-Language: en-us
Subject: RE: Security Considerations for Next Header value 59 [was Re: Review of draft-ietf-6man-rfc2460bis-05]
X-Filter-ID: s0sct1PQhAABKnZB5plbIVbU93hg6Kq00BjAzYBqWlUcW8ntawmIBRrYFzUH2lbvx1wTMkEUUoeb KIhkyzl2dGUIJ4+1eY4p39xvoO6YmYk0HbLcIXRK+rCYHS2Pxr4sUvWQm1ERVuodk8O3ETzMD+o2 4Y0k7wzmZgYNE282gmA5tabMjz/Nh2SJgvPeArf6dcmtTcWSOKD5RASVzg27iqvOPVJ3SnRg7eM0 KERedRd5kYwBFjHSX1ySASMY7Q8kVWau65pVsnZkx/s3iU5HXZFVgpT1b21uZVckGp0ccOY/32e+ 5fVqy4sN42wuoCbdmH1gZeWXJLsO6P2DBgM/q/i885J4uw2WezmviQauN2SLBDMrD7q/cJogwbqz suokGZF4dHDvKOr394oq9u2X8AZIe8Pggnek1xH/TgvWD0MaKXvNWrRcSD72jROfhu6vZJ0Q4x+0 GOxZvoENDONKwZkjGlUCvU6ZAmJB8zrNH9DxX8G2bApANEDRnSX/sJx0Uf5/xO8dap3thvg9e/eV ioOoT5f9zNwjlArtXM+EHVJ52x4j7SJ9+yFYhxTTZdKAmJdDwLTy7ggkbtiREBmTEN9TLrF9l3It GfA/WrnALV46n/TYyQX4QewGgUaWBSqGlrtXw1c9IHjJjxHw61Bw8RquN6UIEUbDp4qQeYkcvTCl J+6wa7BDiaF6UX6W4Pbk
X-Report-Abuse-To: spam@mx99.antispamcloud.com
X-Originating-IP: 168.144.250.215
X-SpamExperts-Domain: xsmtpout.mail2web.com
X-SpamExperts-Username: 168.144.250.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=168.144.250.0/24@xsmtpout.mail2web.com
X-SpamExperts-Outgoing-Class: ham
X-SpamExperts-Outgoing-Evidence: Combined (0.09)
X-Recommended-Action: accept
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/_yCanT0ir3JLm1IRRHBur3gn-u0>
Cc: 6man@ietf.org, 'Bob Hinden' <bob.hinden@gmail.com>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 20 Sep 2016 22:58:23 -0000
Tuesday, September 20, 2016 3:42 PM, Brian E Carpenter wrote: > ... > I realised that we probably have to discuss this further. There are two > places where rfc2460bis explicitly allows a covert channel because of > No Next Header: > > > 4.5. Fragment Header > ... > > The Fragmentable Part consists of the rest of the packet after the > > upper-layer header or after any header (i.e., initial IPv6 header > > or extension header) that contains a Next Header value of No Next > > Header. > ... > > 4.7. No Next Header > > > > The value 59 in the Next Header field of an IPv6 header or any > > extension header indicates that there is nothing following that > > header. If the Payload Length field of the IPv6 header indicates the > > presence of octets past the end of a header whose Next Header field > > contains 59, those octets must be ignored, and passed on unchanged if > > the packet is forwarded. > > Do we really want to allow this? No. We should be chasing covert channels and eliminating them. AFAIK, our implementation of Teredo does not send any extra bytes after the "no next header." > Do we know whether current firewalls tolerate it? No idea. But they probably should not. I would suggest replacing the text by "If the Payload Length field of the IPv6 header indicates the presence of octets past the end of a header whose Next Header field contains 59, the packet should be rejected." Or something like that. > If we keep this, I think some words about the covert channel are needed > in the Security Considerations. > > And looking at the Security Considerations, I don't think they are > sufficient anyway. At the least we should refer to other work, not > just IPSec. We could add some text about packet length discrepancy. Something like "Firewalls and other devices should detect the presence of a hidden communication channel if the length of the concatenated headers does not match the length of the IPv6 payload. Such packets MAY be rejected." -- Christian Huitema
- Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Next Header value 59 [was Re: Review of draft-iet… Brian E Carpenter
- RE: Next Header value 59 [was Re: Review of draft… huitema
- Re: Next Header value 59 [was Re: Review of draft… Tim Chown
- Re: Next Header value 59 [was Re: Review of draft… Brian E Carpenter
- Re: Next Header value 59 [was Re: Review of draft… Alexandre Petrescu
- Re: Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Re: Review of draft-ietf-6man-rfc2460bis-05 Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 Bob Hinden
- Security Considerations for Next Header value 59 … Brian E Carpenter
- RE: Security Considerations for Next Header value… Christian Huitema
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Security Considerations for Next Header value… Tim Chown
- Re: Security Considerations for Next Header value… Bob Hinden
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Security Considerations for Next Header value… Bob Hinden
- Re: Security Considerations for Next Header value… Brian E Carpenter
- Re: Security Considerations for Next Header value… Fernando Gont
- Re: Review of draft-ietf-6man-rfc2460bis-05 神明達哉
- Re: Security Considerations for Next Header value… otroan
- Re: Security Considerations for Next Header value… otroan
- Re: Security Considerations for Next Header value… otroan
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… Tim Chown
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… Bob Hinden
- Re: Review of draft-ietf-6man-rfc2460bis-05 (60 s… 神明達哉