Re: [manet-dlep-rg] DLEP session establishment

"Taylor, Rick" <Rick.Taylor@cassidian.com> Wed, 13 November 2013 10:14 UTC

Return-Path: <rick.taylor@cassidian.com>
X-Original-To: manet-dlep-rg@ietfa.amsl.com
Delivered-To: manet-dlep-rg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C462B11E811A for <manet-dlep-rg@ietfa.amsl.com>; Wed, 13 Nov 2013 02:14:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.381
X-Spam-Level:
X-Spam-Status: No, score=-2.381 tagged_above=-999 required=5 tests=[AWL=0.218, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vPBpvkIrgKL4 for <manet-dlep-rg@ietfa.amsl.com>; Wed, 13 Nov 2013 02:13:58 -0800 (PST)
Received: from mail-dotnet3.eads.net (mail-dotnet3.eads.net [193.56.40.75]) by ietfa.amsl.com (Postfix) with ESMTP id B80E311E8110 for <manet-dlep-rg@ietf.org>; Wed, 13 Nov 2013 02:13:57 -0800 (PST)
Received: from unknown (HELO fr-gate1.mailhub.intra.corp) ([53.154.16.33]) by mail-dotnet3.eads.net with ESMTP; 13 Nov 2013 11:13:57 +0100
Received: from f8561vs5.main.fr.ds.corp ([10.37.8.21]) by fr-gate1.mailhub.intra.corp with Microsoft SMTPSVC(5.0.2195.7381); Wed, 13 Nov 2013 11:12:05 +0100
Received: from f8562vs4.main.fr.ds.corp ([10.37.8.22]) by f8561vs5.main.fr.ds.corp with Microsoft SMTPSVC(6.0.3790.4675); Wed, 13 Nov 2013 11:12:04 +0100
Received: from SUCNPTEXC01.com.ad.uk.ds.corp ([10.80.73.70]) by f8562vs4.main.fr.ds.corp with Microsoft SMTPSVC(6.0.3790.4675); Wed, 13 Nov 2013 11:12:04 +0100
Received: from SUCNPTEXM01.COM.AD.UK.DS.CORP ([fe80::2543:10a0:fd02:b894]) by SUCNPTEXC01.com.ad.uk.ds.corp ([::1]) with mapi id 14.02.0318.004; Wed, 13 Nov 2013 10:12:03 +0000
From: "Taylor, Rick" <Rick.Taylor@cassidian.com>
To: Teco Boot <teco@inf-net.nl>, Stan Ratliff <sratliff@cisco.com>
Thread-Topic: [manet-dlep-rg] DLEP session establishment
Thread-Index: AQHO4D+8Lu+cUJt000eBBao4C+k0hpoi7H8g
Date: Wed, 13 Nov 2013 10:12:03 +0000
Message-ID: <B177F831FB91F242972D0C35F6A0733106FB081B@SUCNPTEXM01.com.ad.uk.ds.corp>
References: <72FB622921C13746AD6349E70A8D9F307D9192F7@EXC-MBX03.tsn.tno.nl> <CAK=bVC85XAXR3Zkwq+JwELF-dvgrKwbowWCvwvnjeVn7VStnbw@mail.gmail.com> <72FB622921C13746AD6349E70A8D9F307D9193CD@EXC-MBX03.tsn.tno.nl> <5A8A5085482DA84995F4E70F5093AB50268E6C@XCH-BLV-503.nw.nos.boeing.com> <B2BA430A-F4E6-4DED-A7BB-7282A22802B7@inf-net.nl> <D02397F1-9D1B-4B36-81D0-4585ACDBA34A@gmail.com> <5D184300-2D97-4EC1-8D91-76D4A79B2BDA@inf-net.nl> <DDAE98C5-520E-4F8F-9F9B-2AB9A15A70EF@cisco.com> <0541163b-2d1c-4afd-ad06-ba9a25744310@SUCNPTEXC01.COM.AD.UK.DS.CORP> <B177F831FB91F242972D0C35F6A0733106FB0425@SUCNPTEXM01.com.ad.uk.ds.corp> <14B5C326-6499-439D-BC23-BB39A376825C@cisco.com> <CAGnRvuoxD_dxdoD_8qbHhq--6AF=2B7wNFEE5Xz=vKNwnBhhZw@mail.gmail.com> <9EB171E6-62E6-4136-BFDB-6FEB8DF23B74@cisco.com> <cb165b80-275e-45ff-ae0e-8ca5354a3568@SUCNPTEXC01.COM.AD.UK.DS.CORP>
In-Reply-To: <cb165b80-275e-45ff-ae0e-8ca5354a3568@SUCNPTEXC01.COM.AD.UK.DS.CORP>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.80.23.75]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginalArrivalTime: 13 Nov 2013 10:12:04.0272 (UTC) FILETIME=[CD143300:01CEE058]
X-TM-AS-Product-Ver: SMEX-8.0.0.4194-6.500.1024-20288.003
X-TM-AS-Result: No--10.589000-0.000000-31
X-TM-AS-User-Approved-Sender: Yes
X-TM-AS-User-Blocked-Sender: No
Cc: Henning Rogge <hrogge@googlemail.com>, "DLEP Research Group (manet-dlep-rg@ietf.org)" <manet-dlep-rg@ietf.org>
Subject: Re: [manet-dlep-rg] DLEP session establishment
X-BeenThere: manet-dlep-rg@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DLEP Radio Group <manet-dlep-rg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/manet-dlep-rg>, <mailto:manet-dlep-rg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/manet-dlep-rg>
List-Post: <mailto:manet-dlep-rg@ietf.org>
List-Help: <mailto:manet-dlep-rg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/manet-dlep-rg>, <mailto:manet-dlep-rg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2013 10:14:02 -0000

My thoughts:

The principle of keeping the modem code as small and light as possible is good.  In general modems are not only getting bigger and smarter, they are also getting physically smaller and lower power.  Routers however are not getting so small so quickly, so even though there are full TCP stacks in many radios, we should not force a full server implementation on them.

So, Lets keep the 3-way handshake we have discussed, but make the router the advertiser/server:


   Router                                        Modem
   ===================================================

1) TCP Listen()

2) UDP Peer_Discovery ------------------------------->
     + Version TLV
     + TCP address:port

3)                                       TCP Connect()

4) <-------------------------------- Peer_Initialize()
                                      + Version TLV
                                      + Ident TLV
                                      + Mandatory TLVs

5) Peer_Initialize_Ack ------------------------------>
     + Status TLV
     + Ident TLV

I withdraw my suggestion about cookies.  As Teco has pointed out, just do security properly (TLS or IPSec or whatever).  Putting in a lightweight/half-baked authentication process in the protocol may lead some implementers to assume this provides security.

I have also suggested just Version TLV and TCP endpoint address in the UDP discovery packet to save space.  This should allow a listening modem to decide whether to start a session with a router before TCP connect.

At step 5, the router has the opportunity to send a negative ACK, by including an error Status TLV in the Peer_Inialize_Ack and then shutdown the connection.  This captures Teco's SHOULD condition "The router SHOULD NOT start a session with a modem that does not advertise mandatory metric TLVs"

Would it help to have a state machine in the draft?

Comments?

Rick Taylor
The information contained within this e-mail and any files attached to this e-mail is private and in addition may include commercially sensitive information. The contents of this e-mail are for the intended recipient only and therefore if you wish to disclose the information contained within this e-mail or attached files, please contact the sender prior to any such disclosure. If you are not the intended recipient, any disclosure, copying or distribution is prohibited. Please also contact the sender and inform them of the error and delete the e-mail, including any attached files from your system. Cassidian Limited, Registered Office : Quadrant House, Celtic Springs, Coedkernew, Newport, NP10 8FZ Company No: 04191036 http://www.cassidian.com