Re: [MMUSIC] Alvaro Retana's No Objection on draft-ietf-mmusic-rtsp-nat-evaluation-15: (with COMMENT)
Magnus Westerlund <magnus.westerlund@ericsson.com> Mon, 18 May 2015 09:57 UTC
Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id C67D01A8855;
Mon, 18 May 2015 02:57:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001]
autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id x9u_bi9D2jJi; Mon, 18 May 2015 02:57:04 -0700 (PDT)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id DA1511A883B;
Mon, 18 May 2015 02:57:03 -0700 (PDT)
X-AuditID: c1b4fb2d-f794d6d000004501-2b-5559b76e9fb3
Received: from ESESSHC016.ericsson.se (Unknown_Domain [153.88.253.125])
by sessmg23.ericsson.net (Symantec Mail Security) with SMTP id
EF.4B.17665.E67B9555; Mon, 18 May 2015 11:57:02 +0200 (CEST)
Received: from [127.0.0.1] (153.88.183.153) by smtp.internal.ericsson.com
(153.88.183.68) with Microsoft SMTP Server id 14.3.210.2; Mon, 18 May 2015
11:57:01 +0200
Message-ID: <5559B76C.9000607@ericsson.com>
Date: Mon, 18 May 2015 11:57:00 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64;
rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: "Alvaro Retana (aretana)" <aretana@cisco.com>, The IESG <iesg@ietf.org>
References: <20150512213044.30495.51553.idtracker@ietfa.amsl.com>
<555333B1.6050607@ericsson.com> <D178BC33.AFEDA%aretana@cisco.com>
In-Reply-To: <D178BC33.AFEDA%aretana@cisco.com>
Content-Type: text/plain; charset="windows-1252"; format=flowed
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrMLMWRmVeSWpSXmKPExsUyM+JvrW7e9shQg2d7BCz+/tzKaHHh7nUm
ixl/JjJbTF3+mMWBxWPK742sHkuW/GTy+HL5M1sAcxSXTUpqTmZZapG+XQJXxu69e5gLLopX
dM6wbmDcLdTFyMkhIWAi0fTyMAuELSZx4d56ti5GLg4hgaOMEhv+/oJyljNKPP/4nh2kildA
W+LRx6esIDaLgKrEqSlHwWw2AQuJmz8a2UBsUYEoiYlfD7FA1AtKnJz5BMwWEfCWOPzuGzvI
UGaBRYwSE9ubwRqEBdIlfpy7zAyxrQVo27rVQA4HB6eAvkTfgRIQk1nAXuLB1jKQcmYBeYnm
rbOZQWwhoHsamjpYJzAKzkKybhZCxywkHQsYmVcxihanFhfnphsZ66UWZSYXF+fn6eWllmxi
BIbywS2/dXcwrn7teIhRgINRiYc3gT8yVIg1say4MvcQozQHi5I4r1dXSKiQQHpiSWp2ampB
alF8UWlOavEhRiYOTqkGRuO/e6usmVSfFuQZZPvohxctay95PYHfJICR13rvYvv2nPI6o3mJ
E9Kcdqiwapcf2qd3wot/2aUV6dN3b5ITcSnO4p6bbdbxKMe6Ut+S58qSOEvJzrmX9k2y/Xij
sN16IcPkk26qTw4e71XcPEuu9JSI66EtxSszt2vkz17ubbnxSMASswhbJZbijERDLeai4kQA
hTxQwkYCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/mmusic/7YuXYxZ1lk_fuDgYg--fa1epKss>
Cc: "draft-ietf-mmusic-rtsp-nat-evaluation.all@tools.ietf.org"
<draft-ietf-mmusic-rtsp-nat-evaluation.all@tools.ietf.org>,
"mmusic \(E-mail\)" <mmusic@ietf.org>
Subject: Re: [MMUSIC] Alvaro Retana's No Objection on
draft-ietf-mmusic-rtsp-nat-evaluation-15: (with COMMENT)
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>,
<mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>,
<mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 May 2015 09:57:05 -0000
Alvaro Retana (aretana) skrev den 2015-05-13 15:11: > On 5/13/15, 7:21 AM, "Magnus Westerlund" <magnus.westerlund@ericsson.com> > wrote: > > Magnus: > > Hi! > >>> >>> >>> >>> 2. Section 8 (Security Considerations) mentions the fact that "three way >>> latching as well as ICE mitigates these security issues and performs the >>> important return-routability check". Please add a reference to this >>> important check. I looked at RFC5245 (ICE), but could not find that >>> check described (just connectivity checks); is that what you're referring >>> to with a different name? >>> >> >> So the word return-routability check (really procedure) comes from >> mobile IPv6. The point of these checks is that each side does perform a >> check that I can send you a packet with a token, and you prove that you >> received it by echoing it back. Thus, preventing off-path attacks. In >> ICE this is done by the double sided connectivity checks. >> >> I suggest the following clarifications: >> >> >> In Section 4.3.6: >> The ICE >> connectivity checks with their random transaction IDs from the server >> to the client servers as return-routability check and prevents off- >> path attacker to succeed with address spoofing. Similar to Mobile >> IPV6's return routability procedure (Section 5.2.5 of [RFC3775]). > > For ICE, I would suggest pointing at RFC5245. A small nit on the text > (serves, not servers). > > NEW> > The ICE > connectivity checks [RFC5245] with their random transaction IDs from the > server > to the client serves as return-routability check and prevents off- > path attacker to succeed with address spoofing. > <NEW > Thanks, I think that is unnecessary, as Section 4.3 is "ICE" and the earlier sub-sections contains the pointers to what ICE is. /Magnus > > >> >> >> >> In Section 4.6.5 >> >> The client to server nonce and its echoing back does not protect >> against on-patch attacker, including malicious clients. However, the >> server to client nonce and its echoing back prevents malicious >> clients to divert the media stream by spoofing the source address and >> port, as it can't echo back the nonce in these cases. Similar to >> the Mobile IPv6 return routability procedure (Section 5.2.5 of >> [RFC3775]) >> >> This way, the term is known to the reader by the time they come to the >> summary in the end. > > Looks good. > > Thanks! > > Alvaro. > > > -- Magnus Westerlund ---------------------------------------------------------------------- Services, Media and Network features, Ericsson Research EAB/TXM ---------------------------------------------------------------------- Ericsson AB | Phone +46 10 7148287 Färögatan 6 | Mobile +46 73 0949079 SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com ----------------------------------------------------------------------
- Re: [MMUSIC] Alvaro Retana's No Objection on draf… Magnus Westerlund
- Re: [MMUSIC] Alvaro Retana's No Objection on draf… Alvaro Retana (aretana)
- Re: [MMUSIC] Alvaro Retana's No Objection on draf… Magnus Westerlund