Re: REMINDER: 6man w.g. last call for <draft-ietf-6man-maxra-01>

Fernando Gont <fgont@si6networks.com> Fri, 06 January 2017 05:06 UTC

Return-Path: <fgont@si6networks.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2E41F1298C1 for <ipv6@ietfa.amsl.com>; Thu, 5 Jan 2017 21:06:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AM8ScM7SH3U4 for <ipv6@ietfa.amsl.com>; Thu, 5 Jan 2017 21:06:36 -0800 (PST)
Received: from fgont.go6lab.si (fgont.go6lab.si [IPv6:2001:67c:27e4::14]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0AB021298A8 for <ipv6@ietf.org>; Thu, 5 Jan 2017 21:06:35 -0800 (PST)
Received: from [192.168.3.88] (142-135-17-190.fibertel.com.ar [190.17.135.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by fgont.go6lab.si (Postfix) with ESMTPSA id D5D8483770; Fri, 6 Jan 2017 06:06:18 +0100 (CET)
Subject: Re: REMINDER: 6man w.g. last call for <draft-ietf-6man-maxra-01>
To: Suresh Krishnan <suresh.krishnan@ericsson.com>, Tim Chown <Tim.Chown@jisc.ac.uk>, Bob Hinden <bob.hinden@gmail.com>
References: <F21F59C0-6DBD-42A4-B2C3-64E270CCFD76@gmail.com> <D25B7F1D-6925-48FE-B4CA-E8834480A496@gmail.com> <3B76B8CC-8F1F-4FF0-ADAB-656B1819B453@jisc.ac.uk> <E87B771635882B4BA20096B589152EF6440E00CD@eusaamb107.ericsson.se>
From: Fernando Gont <fgont@si6networks.com>
X-Enigmail-Draft-Status: N1110
Message-ID: <ed0c4708-9fab-3ee9-52cb-224c190228f3@si6networks.com>
Date: Fri, 06 Jan 2017 01:23:26 -0300
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.5.1
MIME-Version: 1.0
In-Reply-To: <E87B771635882B4BA20096B589152EF6440E00CD@eusaamb107.ericsson.se>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/sFRn6SWBkCPtiYjVlN39fEhUEk8>
Cc: IPv6 List <ipv6@ietf.org>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Jan 2017 05:06:38 -0000

On 01/06/2017 01:11 AM, Suresh Krishnan wrote:
> Hi Tim,
> 
> On 01/05/2017 06:54 AM, Tim Chown wrote:
>> Hi,
>>
>> Just a brief comment on the Security Considerations.
>>
>> This draft could mention RFC6105; currently it only says that rogue RAs can “easily” be prevented through use of SeND, but in practice RA Guard approaches are the common mitigation.  I’m also not sure the “attack window” changes; there is either a rogue RA or there isn’t, regardless of the true RA interval.
> 
> Adding a reference to RA guard sounds like a good idea. Will do. The attack 
> window is larger because the damage from the rogue RA can persist longer 
> before getting overridden by a legitimate RA. I don't have strong feelings 
> about keeping the "attack window" wording though.

My interpretation of "attack window" is along the lines of "amount of
time the attacker has to do his thing". In this respect the attack
window does not change. What changes is the persistence of the effects
of the attack (for *some* RA-based attacks).

Thanks,
-- 
Fernando Gont
SI6 Networks
e-mail: fgont@si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492