Re: [manet] Alexey Melnikov's Discuss on draft-ietf-manet-dlep-26: (with DISCUSS and COMMENT)

Rick Taylor <rick@tropicalstormsoftware.com> Thu, 15 December 2016 15:16 UTC

Return-Path: <rick@tropicalstormsoftware.com>
X-Original-To: manet@ietfa.amsl.com
Delivered-To: manet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE3921296E1; Thu, 15 Dec 2016 07:16:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.797
X-Spam-Level:
X-Spam-Status: No, score=-4.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-2.896, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tMQTrXdc4z3r; Thu, 15 Dec 2016 07:16:27 -0800 (PST)
Received: from mail.tropicalstormsoftware.com (mail.tropicalstormsoftware.com [188.94.42.120]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CB0DB129645; Thu, 15 Dec 2016 07:15:51 -0800 (PST)
Received: from tss-server1.home.tropicalstormsoftware.com ([fe80::753b:fa82:5c0:af0d]) by tss-server1.home.tropicalstormsoftware.com ([fe80::753b:fa82:5c0:af0d%10]) with mapi; Thu, 15 Dec 2016 15:15:08 +0000
From: Rick Taylor <rick@tropicalstormsoftware.com>
To: "aamelnikov@fastmail.fm" <aamelnikov@fastmail.fm>, "hrogge@gmail.com" <hrogge@gmail.com>
Thread-Topic: [manet] Alexey Melnikov's Discuss on draft-ietf-manet-dlep-26: (with DISCUSS and COMMENT)
Thread-Index: AQHSVJxQuXSWkPgmk0meQl1pSW0OMqEFJscAgACCnYCAAxBmgIAABtAA////dgCAAF4kgIAABLSA
Date: Thu, 15 Dec 2016 15:15:27 +0000
Message-ID: <1481814927.2566.30.camel@tropicalstormsoftware.com>
References: <148156334986.22491.1152871712874859894.idtracker@ietfa.amsl.com> <CALtoyonu77P8O2r4zHvD5kBF7+yFc8Fxqe0BoEzeM6BsdoMZZg@mail.gmail.com> <79D48CEB-2CFC-43A8-8D01-5C5CB1778966@fastmail.fm> <CAGnRvupMRvpFq7EVfR4+QX88PG8fMnX49bAZ0_L9tm1a6sYX8g@mail.gmail.com> <9B802ACF-84EF-4C47-92F8-122CA724C71A@fastmail.fm> <CAGnRvuqKEwSU0nnkufzetGGUVzPSFjNOF6wrW=CRqc=t0x4dsQ@mail.gmail.com> <1481813917.419436.820073297.68E45D5D@webmail.messagingengine.com>
In-Reply-To: <1481813917.419436.820073297.68E45D5D@webmail.messagingengine.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Content-Type: text/plain; charset="utf-8"
Content-ID: <a82b8e8b-57db-4221-8ea7-e2fb9dd27ab7>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/manet/JCj0lJnEh_aT54nL5U8a2Ksvazk>
Cc: "manet@ietf.org" <manet@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, "draft-ietf-manet-dlep@ietf.org" <draft-ietf-manet-dlep@ietf.org>, "manet-chairs@ietf.org" <manet-chairs@ietf.org>
Subject: Re: [manet] Alexey Melnikov's Discuss on draft-ietf-manet-dlep-26: (with DISCUSS and COMMENT)
X-BeenThere: manet@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Mobile Ad-hoc Networks <manet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/manet>, <mailto:manet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/manet/>
List-Post: <mailto:manet@ietf.org>
List-Help: <mailto:manet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/manet>, <mailto:manet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Dec 2016 15:16:29 -0000

On Thu, 2016-12-15 at 14:58 +0000, Alexey Melnikov wrote:
> On Thu, Dec 15, 2016, at 09:21 AM, Henning Rogge wrote:
> > 
> > On Thu, Dec 15, 2016 at 10:23 AM, Alexey Melnikov
> > <aamelnikov@fastmail.fm> wrote:
> > > 
> > > Hi,
> > > 
> > > > 
> > > > On 15 Dec 2016, at 08:59, Henning Rogge <hrogge@gmail.com>
> > > > wrote:
> > > > 
> > > > On Tue, Dec 13, 2016 at 11:11 AM, Alexey Melnikov
> > > > <aamelnikov@fastmail.fm> wrote:
> > > > > 
> > > > > Hi Stan,
> > > > > 
> > > > > All your answers look good to me. But I think credential
> > > > > validation might need a bit more thought/discussion in the
> > > > > WG. Maybe you can specify how preconfigured IP or MAC
> > > > > addresses can be checked in X.509 certificates? (Just an
> > > > > idea, not necessarily saying that it is the right or the only
> > > > > way of doing this)
> > > > I raised the point of the certificate problem ages ago as an
> > > > argument
> > > > to DROP TLS from DLEP completely.
> > > Even unauthenticated TLS is better than no TLS, so I would rather
> > > the document continues to recommend it.
> > What kind of security does unauthenticated TLS provide against an
> > attacker that sits on your local LAN segment?
> I am not really concerned about that, but I am concerned about VPN or
> virtualized environment where router is across the globe from the
> modem.

This was why we put in the text in the security considerations stating
that those environments need all security provided by whatever Layer-2
tunnelling protocols are used.  However, we had several discuss's
suggesting that this wasn't enough...

> 
> > 
> > Its not that DLEP carry
> > any "secret" data...
> That is the question really. If the date is exposed outside of LAN,
> does
> it contain no sensitive information?
> > I have spoken with a few radio vendors and from what I got none of
> > them considers to implement TLS. Nobody sees any advantage of it,
> > but
> > everyone sees a huge cost. Cost in terms of performance (Flow
> > control
> > is delay dependent), cost in terms of complexity, costs in terms of
> > interoperability.
> > 
> > Henning Rogge
> _______________________________________________
> manet mailing list
> manet@ietf.org
> https://www.ietf.org/mailman/listinfo/manet