[manet] AODVv2 Security Considerations discussion thread

Lotte Steenbrink <lotte.steenbrink@fu-berlin.de> Fri, 22 April 2016 21:31 UTC

Return-Path: <lotte.steenbrink@fu-berlin.de>
X-Original-To: manet@ietfa.amsl.com
Delivered-To: manet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9965812E3D5 for <manet@ietfa.amsl.com>; Fri, 22 Apr 2016 14:31:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.197
X-Spam-Level:
X-Spam-Status: No, score=-5.197 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.996, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LAn9F-CrG-oI for <manet@ietfa.amsl.com>; Fri, 22 Apr 2016 14:31:04 -0700 (PDT)
Received: from outpost1.zedat.fu-berlin.de (outpost1.zedat.fu-berlin.de [130.133.4.66]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2BA2112E396 for <manet@ietf.org>; Fri, 22 Apr 2016 14:31:04 -0700 (PDT)
Received: from inpost2.zedat.fu-berlin.de ([130.133.4.69]) by outpost.zedat.fu-berlin.de (Exim 4.85) with esmtps (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256) (envelope-from <lotte.steenbrink@fu-berlin.de>) id <1atifG-002DYu-E8>; Fri, 22 Apr 2016 23:31:02 +0200
Received: from x4dbabaf0.dyn.telefonica.de ([77.186.186.240] helo=[192.168.1.2]) by inpost2.zedat.fu-berlin.de (Exim 4.85) with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (envelope-from <lotte.steenbrink@fu-berlin.de>) id <1atifG-000xeZ-5n>; Fri, 22 Apr 2016 23:31:02 +0200
From: Lotte Steenbrink <lotte.steenbrink@fu-berlin.de>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Date: Fri, 22 Apr 2016 23:31:01 +0200
To: Mobile Ad Hoc Networks mailing list <manet@ietf.org>
Message-Id: <6E2BB485-BF11-4050-9F75-0E2605ABBC96@fu-berlin.de>
Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\))
X-Mailer: Apple Mail (2.3112)
X-Originating-IP: 77.186.186.240
Archived-At: <http://mailarchive.ietf.org/arch/msg/manet/A9w-8Dq3FaR2u4qi8hhSDgdn2_o>
Subject: [manet] AODVv2 Security Considerations discussion thread
X-BeenThere: manet@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Mobile Ad-hoc Networks <manet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/manet>, <mailto:manet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/manet/>
List-Post: <mailto:manet@ietf.org>
List-Help: <mailto:manet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/manet>, <mailto:manet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Apr 2016 21:31:05 -0000

Hi all,
in [1], Thomas has suggested starting a new thread to discuss AODVv2s security considerations. I think that’s a good idea, so here it goes.

In case it’s helpful, previous security consideration discussions can be found here: 

https://mailarchive.ietf.org/arch/msg/manet/WxpVkfPSTERUquFi8uAMu7UqWC8 (and consecutive e-mails)

Also in [1],Thomas mentioned he’s missing the influence of BCP72 and BCP107. BCP72 was used as a basis when we reordered the security considerations, but that doesn’t mean we didn’t oversee anything. If anyone wants to provide pointers as to what we’ve missed, by all means, please share it with us.
Regarding BCP107, I think that’s a good point. However, I don’t think I’m qualified to do it justice, so I’m just mentioning it again for completeness and in the hope that someone else who knows what they’re doing might pick it up :)

Any other comments regarding the security considerations are also very welcome, obviously.

With kind regards,
Lotte

[1] https://mailarchive.ietf.org/arch/msg/manet/Oc_fMxVIzD_9Y0R2SvQ_S4DeDZU