Re: [MMUSIC] Alvaro Retana's No Objection on draft-ietf-mmusic-rtsp-nat-evaluation-15: (with COMMENT)

Magnus Westerlund <magnus.westerlund@ericsson.com> Mon, 18 May 2015 09:57 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C67D01A8855; Mon, 18 May 2015 02:57:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level:
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x9u_bi9D2jJi; Mon, 18 May 2015 02:57:04 -0700 (PDT)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA1511A883B; Mon, 18 May 2015 02:57:03 -0700 (PDT)
X-AuditID: c1b4fb2d-f794d6d000004501-2b-5559b76e9fb3
Received: from ESESSHC016.ericsson.se (Unknown_Domain [153.88.253.125]) by sessmg23.ericsson.net (Symantec Mail Security) with SMTP id EF.4B.17665.E67B9555; Mon, 18 May 2015 11:57:02 +0200 (CEST)
Received: from [127.0.0.1] (153.88.183.153) by smtp.internal.ericsson.com (153.88.183.68) with Microsoft SMTP Server id 14.3.210.2; Mon, 18 May 2015 11:57:01 +0200
Message-ID: <5559B76C.9000607@ericsson.com>
Date: Mon, 18 May 2015 11:57:00 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.6.0
MIME-Version: 1.0
To: "Alvaro Retana (aretana)" <aretana@cisco.com>, The IESG <iesg@ietf.org>
References: <20150512213044.30495.51553.idtracker@ietfa.amsl.com> <555333B1.6050607@ericsson.com> <D178BC33.AFEDA%aretana@cisco.com>
In-Reply-To: <D178BC33.AFEDA%aretana@cisco.com>
Content-Type: text/plain; charset="windows-1252"; format=flowed
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrMLMWRmVeSWpSXmKPExsUyM+JvrW7e9shQg2d7BCz+/tzKaHHh7nUm ixl/JjJbTF3+mMWBxWPK742sHkuW/GTy+HL5M1sAcxSXTUpqTmZZapG+XQJXxu69e5gLLopX dM6wbmDcLdTFyMkhIWAi0fTyMAuELSZx4d56ti5GLg4hgaOMEhv+/oJyljNKPP/4nh2kildA W+LRx6esIDaLgKrEqSlHwWw2AQuJmz8a2UBsUYEoiYlfD7FA1AtKnJz5BMwWEfCWOPzuGzvI UGaBRYwSE9ubwRqEBdIlfpy7zAyxrQVo27rVQA4HB6eAvkTfgRIQk1nAXuLB1jKQcmYBeYnm rbOZQWwhoHsamjpYJzAKzkKybhZCxywkHQsYmVcxihanFhfnphsZ66UWZSYXF+fn6eWllmxi BIbywS2/dXcwrn7teIhRgINRiYc3gT8yVIg1say4MvcQozQHi5I4r1dXSKiQQHpiSWp2ampB alF8UWlOavEhRiYOTqkGRuO/e6usmVSfFuQZZPvohxctay95PYHfJICR13rvYvv2nPI6o3mJ E9Kcdqiwapcf2qd3wot/2aUV6dN3b5ITcSnO4p6bbdbxKMe6Ut+S58qSOEvJzrmX9k2y/Xij sN16IcPkk26qTw4e71XcPEuu9JSI66EtxSszt2vkz17ubbnxSMASswhbJZbijERDLeai4kQA hTxQwkYCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/mmusic/7YuXYxZ1lk_fuDgYg--fa1epKss>
Cc: "draft-ietf-mmusic-rtsp-nat-evaluation.all@tools.ietf.org" <draft-ietf-mmusic-rtsp-nat-evaluation.all@tools.ietf.org>, "mmusic \(E-mail\)" <mmusic@ietf.org>
Subject: Re: [MMUSIC] Alvaro Retana's No Objection on draft-ietf-mmusic-rtsp-nat-evaluation-15: (with COMMENT)
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 May 2015 09:57:05 -0000

Alvaro Retana (aretana) skrev den 2015-05-13 15:11:
> On 5/13/15, 7:21 AM, "Magnus Westerlund" <magnus.westerlund@ericsson.com>
> wrote:
>
> Magnus:
>
> Hi!
>
>>>
>>>
>>>
>>> 2. Section 8 (Security Considerations) mentions the fact that "three way
>>> latching as well as ICE mitigates these security issues and performs the
>>> important return-routability check".  Please add a reference to this
>>> important check.  I looked at RFC5245 (ICE), but could not find that
>>> check described (just connectivity checks); is that what you're referring
>>> to with a different name?
>>>
>>
>> So the word return-routability check (really procedure) comes from
>> mobile IPv6. The point of these checks is that each side does perform a
>> check that I can send you a packet with a token, and you prove that you
>> received it by echoing it back. Thus, preventing off-path attacks. In
>> ICE this is done by the double sided connectivity checks.
>>
>> I suggest the following clarifications:
>>
>>
>> In Section 4.3.6:
>>     The ICE
>>     connectivity checks with their random transaction IDs from the server
>>     to the client servers as return-routability check and prevents off-
>>     path attacker to succeed with address spoofing.  Similar to Mobile
>>     IPV6's return routability procedure (Section 5.2.5 of [RFC3775]).
>
> For ICE, I would suggest pointing at RFC5245.  A small nit on the text
> (serves, not servers).
>
> NEW>
>    The ICE
>    connectivity checks [RFC5245] with their random transaction IDs from the
> server
>    to the client serves as return-routability check and prevents off-
>    path attacker to succeed with address spoofing.
> <NEW
>

Thanks,

I think that is unnecessary, as Section 4.3 is "ICE" and the earlier 
sub-sections contains the pointers to what ICE is.

/Magnus



>
>
>>
>>
>>
>> In Section 4.6.5
>>
>>     The client to server nonce and its echoing back does not protect
>>     against on-patch attacker, including malicious clients.  However, the
>>     server to client nonce and its echoing back prevents malicious
>>     clients to divert the media stream by spoofing the source address and
>>     port, as it can't echo back the nonce in these cases.  Similar to
>>     the Mobile IPv6 return routability procedure (Section 5.2.5 of
>>     [RFC3775])
>>
>> This way, the term is known to the reader by the time they come to the
>> summary in the end.
>
> Looks good.
>
> Thanks!
>
> Alvaro.
>
>
>


-- 

Magnus Westerlund

----------------------------------------------------------------------
Services, Media and Network features, Ericsson Research EAB/TXM
----------------------------------------------------------------------
Ericsson AB                 | Phone  +46 10 7148287
Färögatan 6                 | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------