ESSID ietf-v6only at IETF 100

Alexandre Petrescu <alexandre.petrescu@gmail.com> Tue, 14 November 2017 06:03 UTC

Return-Path: <alexandre.petrescu@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BAE7C1293E1 for <ipv6@ietfa.amsl.com>; Mon, 13 Nov 2017 22:03:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.013
X-Spam-Level:
X-Spam-Status: No, score=-1.013 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_ADSP_CUSTOM_MED=0.001, FREEMAIL_FROM=0.001, HTML_IMAGE_ONLY_24=1.618, HTML_IMAGE_RATIO_06=0.001, HTML_MESSAGE=0.001, NML_ADSP_CUSTOM_MED=0.9, RCVD_IN_DNSWL_MED=-2.3, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 13_UU_J8KEiG for <ipv6@ietfa.amsl.com>; Mon, 13 Nov 2017 22:03:17 -0800 (PST)
Received: from cirse-smtp-out.extra.cea.fr (cirse-smtp-out.extra.cea.fr [132.167.192.148]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22051128AB0 for <ipv6@ietf.org>; Mon, 13 Nov 2017 22:03:16 -0800 (PST)
Received: from pisaure.intra.cea.fr (pisaure.intra.cea.fr [132.166.88.21]) by cirse-sys.extra.cea.fr (8.14.7/8.14.7/CEAnet-Internet-out-4.0) with ESMTP id vAE63FhN032980 for <ipv6@ietf.org>; Tue, 14 Nov 2017 07:03:15 +0100
Received: from pisaure.intra.cea.fr (localhost [127.0.0.1]) by localhost (Postfix) with SMTP id 4BDD3200C33 for <ipv6@ietf.org>; Tue, 14 Nov 2017 07:03:15 +0100 (CET)
Received: from muguet2.intra.cea.fr (muguet2.intra.cea.fr [132.166.192.7]) by pisaure.intra.cea.fr (Postfix) with ESMTP id 3DC55200B5C for <ipv6@ietf.org>; Tue, 14 Nov 2017 07:03:15 +0100 (CET)
Received: from [132.166.84.15] ([132.166.84.15]) by muguet2.intra.cea.fr (8.15.2/8.15.2/CEAnet-Intranet-out-1.4) with ESMTP id vAE63Djm003656 for <ipv6@ietf.org>; Tue, 14 Nov 2017 07:03:14 +0100
To: IPv6 <ipv6@ietf.org>
From: Alexandre Petrescu <alexandre.petrescu@gmail.com>
Subject: ESSID ietf-v6only at IETF 100
Message-ID: <acd854c7-8bd2-781e-6d0d-b15bb62c48e2@gmail.com>
Date: Tue, 14 Nov 2017 07:03:12 +0100
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="------------29B710425B42C144932B6D1E"
Content-Language: fr
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/y7O4l0DgdGb_JGlA9CHgNXOu5p4>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 06:03:19 -0000

Hi,

I have problems connecting to the IPv6-only ESSID "ietf-v6only".

It is a problem of certificates.

I have this problem on Windows since several IETF meetings; it may not 
be related in particular to IPv6.

The message in the window below says: "The server 
services.meeting.ietf.org presented a certifcate valid emitted by 
Starfield CA, but that is not configured as a valid anchor to approve 
this profile".

I dont thave this kind of certification refusal problem on 
ietf-legacy100 ESSID (and all earlier ietf-legacy), neither on 
ietf-nat64-unencrypted.

This ietf-nat64-unencrypted is now appearing first time at IETF.  I 
suppose people realized there was a problem with certs and created an 
'unencrypted' version.  That's not a best practice to fix security :-)

And yes, my VPN FortiClient works ok on ietf-nat64-unencrypted.




Alex