Re: [Isis-wg] [karp] FW: I-D Action: draft-chunduri-karp-is-is-gap-analysis-02.txt

Uma Chunduri <uma.chunduri@ericsson.com> Mon, 08 October 2012 20:12 UTC

Return-Path: <uma.chunduri@ericsson.com>
X-Original-To: isis-wg@ietfa.amsl.com
Delivered-To: isis-wg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D9C0321F87FC; Mon, 8 Oct 2012 13:12:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RkgCm1AVaN1M; Mon, 8 Oct 2012 13:12:44 -0700 (PDT)
Received: from imr3.ericy.com (imr3.ericy.com [198.24.6.13]) by ietfa.amsl.com (Postfix) with ESMTP id 2CC4421F8702; Mon, 8 Oct 2012 13:12:44 -0700 (PDT)
Received: from eusaamw0711.eamcs.ericsson.se ([147.117.20.178]) by imr3.ericy.com (8.13.8/8.13.8) with ESMTP id q98KBZWQ013534 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 8 Oct 2012 15:12:43 -0500
Received: from EUSAACMS0701.eamcs.ericsson.se ([169.254.1.44]) by eusaamw0711.eamcs.ericsson.se ([147.117.20.178]) with mapi; Mon, 8 Oct 2012 16:12:23 -0400
From: Uma Chunduri <uma.chunduri@ericsson.com>
To: "Les Ginsberg (ginsberg)" <ginsberg@cisco.com>, "isis-wg@ietf.org" <isis-wg@ietf.org>, "karp@ietf.org" <karp@ietf.org>
Date: Mon, 08 Oct 2012 16:12:22 -0400
Thread-Topic: [karp] [Isis-wg] FW: I-D Action: draft-chunduri-karp-is-is-gap-analysis-02.txt
Thread-Index: AQH0YYvFe90q5LpjwaYD4fWye8XnA5dej//QgAJEdcCAAYOT4A==
Message-ID: <D1D8138DDF34B34B8BC68A11262D10792B6128DAA2@EUSAACMS0701.eamcs.ericsson.se>
References: <20121005180149.3032.42028.idtracker@ietfa.amsl.com> <125001cda3a9$a0e69940$e2b3cbc0$@olddog.co.uk> <F3ADE4747C9E124B89F0ED2180CC814F1182E43B@xmb-aln-x02.cisco.com>
In-Reply-To: <F3ADE4747C9E124B89F0ED2180CC814F1182E43B@xmb-aln-x02.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [Isis-wg] [karp] FW: I-D Action: draft-chunduri-karp-is-is-gap-analysis-02.txt
X-BeenThere: isis-wg@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF IS-IS working group <isis-wg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/isis-wg>
List-Post: <mailto:isis-wg@ietf.org>
List-Help: <mailto:isis-wg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/isis-wg>, <mailto:isis-wg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Oct 2012 20:12:45 -0000

Les,

Your point is valid and it is relevant to mention the what ever current recovery mechanism we have in the face of the attack. 
This is precisely one of the  goals of the document and we will take this comment.

-- 
Uma C. 

PS: The link you mentioned below is regarding the partial deployment issue you pointed out (with ESN TLV draft) and you know 
we are working with you on that as we speak.



-----Original Message-----
From: karp-bounces@ietf.org [mailto:karp-bounces@ietf.org] On Behalf Of Les Ginsberg (ginsberg)
Sent: Sunday, October 07, 2012 1:46 PM
To: isis-wg@ietf.org; karp@ietf.org
Subject: Re: [karp] [Isis-wg] FW: I-D Action: draft-chunduri-karp-is-is-gap-analysis-02.txt

The draft fails to mention (Section 2.3.1(2)) that the mechanisms defined in the IS-IS base specification (ISO 10589) provide for efficient recovery from all LSP replay attacks - including inter-session replay. 
This is particularly disappointing in that this point has been discussed at some length in the context of  draft-chunduri-isis-extended-sequence-no-tlv. Please see:

http://www.ietf.org/mail-archive/web/isis-wg/current/msg03023.html


   Les


> -----Original Message-----
> From: isis-wg-bounces@ietf.org [mailto:isis-wg-bounces@ietf.org] On 
> Behalf Of Adrian Farrel
> Sent: Saturday, October 06, 2012 3:02 AM
> To: isis-wg@ietf.org
> Subject: [Isis-wg] FW: I-D Action: 
> draft-chunduri-karp-is-is-gap-analysis-
> 02.txt
> 
> Heads up
> 
> > -----Original Message-----
> > From: i-d-announce-bounces@ietf.org 
> > [mailto:i-d-announce-bounces@ietf.org]
> > On Behalf Of internet-drafts@ietf.org
> > Sent: 05 October 2012 19:02
> > To: i-d-announce@ietf.org
> > Subject: I-D Action: draft-chunduri-karp-is-is-gap-analysis-02.txt
> >
> >
> > A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> >
> >
> > 	Title           : KARP IS-IS security gap analysis
> > 	Author(s)       : Uma Chunduri
> >                           Albert Tian
> >                           Wenhu Lu
> > 	Filename        : draft-chunduri-karp-is-is-gap-analysis-02.txt
> > 	Pages           : 12
> > 	Date            : 2012-10-05
> >
> > Abstract:
> >    This document analyzes the threats applicable for Intermediate system
> >    to Intermediate system (IS-IS) routing protocol and security gaps
> >    according to the KARP Design Guide.  This document also provides
> >    specific requirements to address the gaps with both manual and auto
> >    key management protocols.
> >
> >
> > The IETF datatracker status page for this draft is:
> > https://datatracker.ietf.org/doc/draft-chunduri-karp-is-is-gap-analy
> > sis
> >
> > There's also a htmlized version available at:
> > http://tools.ietf.org/html/draft-chunduri-karp-is-is-gap-analysis-02
> >
> > A diff from the previous version is available at:
> > http://www.ietf.org/rfcdiff?url2=draft-chunduri-karp-is-is-gap-analy
> > sis-02
> >
> >
> > Internet-Drafts are also available by anonymous FTP at:
> > ftp://ftp.ietf.org/internet-drafts/
> >
> > _______________________________________________
> > I-D-Announce mailing list
> > I-D-Announce@ietf.org
> > https://www.ietf.org/mailman/listinfo/i-d-announce
> > Internet-Draft directories: http://www.ietf.org/shadow.html or 
> > ftp://ftp.ietf.org/ietf/1shadow-sites.txt
> 
> _______________________________________________
> Isis-wg mailing list
> Isis-wg@ietf.org
> https://www.ietf.org/mailman/listinfo/isis-wg
_______________________________________________
karp mailing list
karp@ietf.org
https://www.ietf.org/mailman/listinfo/karp