Re: [Mip6] Re: FW: I-D ACTION:draft-dupont-ikev2-haassign-01.txt

Alexandru Petrescu <alexandru.petrescu@motorola.com> Thu, 16 March 2006 17:41 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1FJwTG-0002jq-Dn; Thu, 16 Mar 2006 12:41:10 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1FJwTF-0002jk-Bg for mip6@ietf.org; Thu, 16 Mar 2006 12:41:09 -0500
Received: from motgate8.mot.com ([129.188.136.8]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FJwTE-00022j-3p for mip6@ietf.org; Thu, 16 Mar 2006 12:41:09 -0500
Received: from il06exr02.mot.com (il06exr02.mot.com [129.188.137.132]) by motgate8.mot.com (8.12.11/Motgate7) with ESMTP id k2GHuI1g028429; Thu, 16 Mar 2006 10:56:22 -0700 (MST)
Received: from zfr01srv02.crm.mot.com (zfr01srv02.crm.mot.com [10.161.201.8]) by il06exr02.mot.com (8.13.1/8.13.0) with ESMTP id k2GHrsSZ020822; Thu, 16 Mar 2006 11:53:54 -0600 (CST)
Received: from [10.161.201.117] (zfr01-2117.crm.mot.com [10.161.201.117]) by zfr01srv02.crm.mot.com (Postfix) with ESMTP id C28CB865980; Thu, 16 Mar 2006 18:40:34 +0100 (CET)
Message-ID: <4419A312.3050307@motorola.com>
Date: Thu, 16 Mar 2006 18:40:34 +0100
From: Alexandru Petrescu <alexandru.petrescu@motorola.com>
User-Agent: Thunderbird 1.5 (Windows/20051201)
MIME-Version: 1.0
To: Qin Li <liqin@cse.buaa.edu.cn>
Subject: Re: [Mip6] Re: FW: I-D ACTION:draft-dupont-ikev2-haassign-01.txt
References: <200603131837.k2DIaYqE073473@givry.rennes.enst-bretagne.fr> <441835BC.90200@cse.buaa.edu.cn>
In-Reply-To: <441835BC.90200@cse.buaa.edu.cn>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAQAAAAQ=
X-White-List-Member: TRUE
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 1ac7cc0a4cd376402b85bc1961a86ac2
Cc: Francis Dupont <Francis.Dupont@point6.net>, mip6@ietf.org, "DENG, HUI -HCHBJ" <hdeng@hitachi.cn>
X-BeenThere: mip6@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: mip6.ietf.org
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:mip6@ietf.org>
List-Help: <mailto:mip6-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=subscribe>
Errors-To: mip6-bounces@ietf.org

Qin Li wrote:
>> Lastly, as you said in your draft:
>> 
>> http://www.ietf.org/internet-drafts/draft-dupont-mip6-dhaadharmful-01.txt
>> 
>>> The main security issue is in the anycast destination of
>>> requests, and as the mechanism is the first step of
>>> bootstrapping, there is no way to add reasonable security to it.

If that address being an anycast address is the real problem then it 
would be useful to modify its definition and make it non-anycast.

Alex


_______________________________________________
Mip6 mailing list
Mip6@ietf.org
https://www1.ietf.org/mailman/listinfo/mip6