Re: [lisp] Eric Rescorla's Discuss on draft-ietf-lisp-rfc6830bis-20: (with DISCUSS and COMMENT)

Dino Farinacci <farinacci@gmail.com> Mon, 15 October 2018 02:20 UTC

Return-Path: <farinacci@gmail.com>
X-Original-To: lisp@ietfa.amsl.com
Delivered-To: lisp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59C8012D4E6; Sun, 14 Oct 2018 19:20:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Oy7KrEsxRACH; Sun, 14 Oct 2018 19:20:09 -0700 (PDT)
Received: from mail-pf1-x434.google.com (mail-pf1-x434.google.com [IPv6:2607:f8b0:4864:20::434]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E7F15129619; Sun, 14 Oct 2018 19:20:08 -0700 (PDT)
Received: by mail-pf1-x434.google.com with SMTP id r9-v6so8858017pff.11; Sun, 14 Oct 2018 19:20:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=1ZS82iD1k3xfpkOZ7ISraVspTcfsWLMPT+jaYTOdx2A=; b=UCGx3Y2sSVuobaU6rpq5clIaKGLS9FLbLuyC/XszQOafitfOQvo3mOgeR1qan78uWM Aw/98J2QTJ5hQbSxHzuUdqaW3+87uEElBlOmsGszQWnCj/tfdkLCXg5Mi6rdOxqMUpF3 rTjU32/6aZGHq3CuztuDheWqEt8jZ14vd1Wxft7JXutwK4YjZ92UQ89azOG/Fp3mkVJm PBCeyjRrDvm6uiOm1Ctp9UzW9qIjMAfbOnoGTOm84+aZpnirNSKiK6xJPUEwAXg3uZd7 IRf4wQfQCyHLDYWGyHG9qhHTU4802bJNnz9OgCMzKSxmhJg+SJhznCd1mB/oOMVEz9oy ZRRA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=1ZS82iD1k3xfpkOZ7ISraVspTcfsWLMPT+jaYTOdx2A=; b=rwrVEDyoCBsVUcBbOKvDOW0pj44/ZlOBrhYUIQzuM6/zMjFzfFGAsVbXoVbqvHFaGc nKCAFgiXk6oTrF41fT8lUlSPelI0z1oHM5t7DyCPld5DJ373ae0Q/BcOkslntM3boMD/ gxa6l7sg2UimVjk+4FqScP0xPimzQDHEtVjE7HaefZUSciOovaKb3X4JkC4BVlBQarif VbnYcggN92eD/bDRFPXbMybYw/OFR6BbQ47IRQP5V/3ioaq+/YXUL+Zykr38749y2uKA dtem+IerjudXdD5ozQ5IatgKSHVtJ7piW1l+dzQg7XeVkIZhPKuQ79qDQhS+E7rKO8N0 ydMg==
X-Gm-Message-State: ABuFfohBtvP7+Plx4XKvhoIzvwtwETiCKEOvbn2kHkgfXIiWznT1xkSm MLs2PzIhFD+5ivmSewzS0cdJlc88
X-Google-Smtp-Source: ACcGV611zYos7qkruQqY61bYePYeQStOwFKqqaHEd/j+CQznRJKaVH0l5oW8EN9ktu4wi54TLLTejg==
X-Received: by 2002:a63:a119:: with SMTP id b25-v6mr14298867pgf.186.1539570008215; Sun, 14 Oct 2018 19:20:08 -0700 (PDT)
Received: from ?IPv6:2603:3024:151c:55f0:91a2:7e75:c023:3751? ([2603:3024:151c:55f0:91a2:7e75:c023:3751]) by smtp.gmail.com with ESMTPSA id e64-v6sm11125727pfe.55.2018.10.14.19.20.06 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 14 Oct 2018 19:20:06 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (1.0)
From: Dino Farinacci <farinacci@gmail.com>
X-Mailer: iPhone Mail (16A404)
In-Reply-To: <CABcZeBM4XotbW6BYbCzHq7SJW7NdVK+fJZom8J=AHwi+dkL5Wg@mail.gmail.com>
Date: Sun, 14 Oct 2018 19:20:05 -0700
Cc: Benjamin Kaduk <kaduk@mit.edu>, IESG <iesg@ietf.org>, draft-ietf-lisp-rfc6830bis@ietf.org, Luigi Iannone <ggx@gigix.net>, lisp-chairs@ietf.org, albert.cabellos@gmail.com, "BRUNGARD, DEBORAH A" <db3546@att.com>, fmaino@cisco.com, "lisp@ietf.org list" <lisp@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <74F9CFAD-6C2E-4BDB-A56B-0186789EE058@gmail.com>
References: <153805068062.26427.10428634331947404660.idtracker@ietfa.amsl.com> <ACFD874F-113E-4AD4-9056-CD3CFA9BA477@gmail.com> <CABcZeBM4XotbW6BYbCzHq7SJW7NdVK+fJZom8J=AHwi+dkL5Wg@mail.gmail.com>
To: Eric Rescorla <ekr@rtfm.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/lisp/230AAfTwxSOxGod8TqQyyR1qB7s>
Subject: Re: [lisp] Eric Rescorla's Discuss on draft-ietf-lisp-rfc6830bis-20: (with DISCUSS and COMMENT)
X-BeenThere: lisp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: List for the discussion of the Locator/ID Separation Protocol <lisp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/lisp>, <mailto:lisp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/lisp/>
List-Post: <mailto:lisp@ietf.org>
List-Help: <mailto:lisp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/lisp>, <mailto:lisp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Oct 2018 02:20:11 -0000

> > Well this is true, but 6833bis discusses RLOC-reachability and there
> > is a RLOC-probe cache that will tell the ITR when it last heard from
> > the RLOC.
> 
> Just to be clear, it's not "last heard from" that you need, but
> rather "last verifiably responded".

Right agree. 

> > > S 16.
> > >>    Map-Versioning is a Data-Plane mechanism used to signal a peering xTR
> > >>    that a local EID-to-RLOC mapping has been updated, so that the
> > >>    peering xTR uses LISP Control-Plane signaling message to retrieve a
> > >>    fresh mapping.  This can be used by an attacker to forge the map-
> > >>    versioning field of a LISP encapsulated header and force an excessive
> > >>    amount of signaling between xTRs that may overload them.
> > > 
> > > Can't I also set a super-high version number, thus gagging updates?
> > 
> > It doesn’t matter the value. All that matters is that it changed and you should do to the mapping system to get an updated RLOC-set.
> 
> Hmm... S 5.1 of 6834-bis suggests that you can just discard it.

Luigi - what do you think. Do we need rewording?

Dino