Re: [OPSEC] [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06
Ole Troan <otroan@employees.org> Wed, 05 December 2018 14:53 UTC
Return-Path: <otroan@employees.org>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5ACBE126C01; Wed, 5 Dec 2018 06:53:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ez2oQgNknLXA; Wed, 5 Dec 2018 06:53:39 -0800 (PST)
Received: from bugle.employees.org (accordion.employees.org [198.137.202.74]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B27CD1271FF; Wed, 5 Dec 2018 06:53:39 -0800 (PST)
Received: from astfgl.hanazo.no (30.51-175-112.customer.lyse.net [51.175.112.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by bugle.employees.org (Postfix) with ESMTPSA id AA55FFECC0A9; Wed, 5 Dec 2018 14:53:38 +0000 (UTC)
Received: from [IPv6:::1] (localhost [IPv6:::1]) by astfgl.hanazo.no (Postfix) with ESMTP id CC9CEAA92D6; Wed, 5 Dec 2018 15:53:35 +0100 (CET)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 12.1 \(3445.101.1\))
From: Ole Troan <otroan@employees.org>
In-Reply-To: <20181205135723.GN1543@Space.Net>
Date: Wed, 05 Dec 2018 15:53:35 +0100
Cc: Joe Touch <touch@strayalpha.com>, draft-ietf-opsec-ipv6-eh-filtering.all@ietf.org, Mark Andrews <marka@isc.org>, David Farmer <farmer@umn.edu>, OPSEC <opsec@ietf.org>, tsv-art <tsv-art@ietf.org>, IETF-Discussion Discussion <ietf@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <54C715AE-8931-4FA9-AA01-2311EB0055F0@employees.org>
References: <CAL9jLaYfysKm7qrG=+jq7zV=5ODnSX-tAhBAiTU7SzYF-YmcGw@mail.gmail.com> <728C6048-896E-4B12-B80B-2091D7373D16@strayalpha.com> <CAL9jLaYHVdHr+rVoWeNtXTXgLxbTaX8V9gn3424tvsLW60Kvow@mail.gmail.com> <5E70C208-0B31-4333-BB8C-4D45E678E878@isc.org> <CAN-Dau0go6_Puf0A9e7KBpk0ApJBUvcxYtezxnwNc-8pKJ3PwQ@mail.gmail.com> <4D69FA8E-FB8A-4A16-9CA6-690D8AE33C9E@strayalpha.com> <20181205122142.GJ1543@Space.Net> <F17C4944-09EC-4AAC-84A0-B660E36AAE89@strayalpha.com> <20181205133821.GL1543@Space.Net> <B6280E0C-6B20-43C1-BB34-170FB06F1EF7@strayalpha.com> <20181205135723.GN1543@Space.Net>
To: Gert Doering <gert@space.net>
X-Mailer: Apple Mail (2.3445.101.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/PTnNp4Dp4NJl49T-sPRdG94JebQ>
Subject: Re: [OPSEC] [Tsv-art] Tsvart last call review of draft-ietf-opsec-ipv6-eh-filtering-06
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 05 Dec 2018 14:53:45 -0000
Gert, >> Vendors are not required to lie when claiming IPv6 support. > > So you prefer that vendors just do not deliver IPv6 at all? > > Let me repeat that: what you want will not be paid by the marketplace. > > Chained EHs are a relict from a time when everybody was nice and > cooperative, bandwith was sparse, routers used CPUs to forward packets, > and money came from governments to research networks in huge amounts. > > This is not today's Internet anymore. > > You can accept that or not, but nothing you can say will magically make > the necessary amount of money and development resources (let alone > "interest") appear to build and deploy routers that can do what you want > all across the Internet. This is the exact reason we have layering in the Internet protocols. IPv6 routers are not meant to parse further into packets then the IPv6 header (with one exception (1)). That network devices find it hard to parse deep into user’s traffic is a feature. I find the argument that we should then change upper layer protocols to accommodate that, hard to digest. I agree with Joe, this isn’t a security issue. Ole (1) The exception is the HBH header which is intended as a hook for forwarding devices to do further processing of the packet. To Joe’s point, RFC8200 specifies that the header is to be ignored unless the device is specifically configured to handle the header. There is obviously no security risk for the router itself in ignoring the NH=0 and forwarding the packet. There might be a risk if and when an actual HBH option is specified. But that specification should have security considerations.
- [OPSEC] Tsvart last call review of draft-ietf-ops… Michael Scharf
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Brian E Carpenter
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Fernando Gont
- Re: [OPSEC] Tsvart last call review of draft-ietf… Fernando Gont
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christian Huitema
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christian Huitema
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Fernando Gont
- Re: [OPSEC] Tsvart last call review of draft-ietf… Fernando Gont
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Eric Rescorla
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Ole Troan
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Benjamin Kaduk
- Re: [OPSEC] Tsvart last call review of draft-ietf… Mark Andrews
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Stewart Bryant
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Stewart Bryant
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Stewart Bryant
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christopher Morrow
- Re: [OPSEC] Tsvart last call review of draft-ietf… C. M. Heard
- Re: [OPSEC] Tsvart last call review of draft-ietf… Christopher Morrow
- Re: [OPSEC] Tsvart last call review of draft-ietf… Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] Tsvart last call review of draft-ietf… Brian E Carpenter
- Re: [OPSEC] Tsvart last call review of draft-ietf… Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] Tsvart last call review of draft-ietf… Christopher Morrow
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christopher Morrow
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christopher Morrow
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Mark Andrews
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … David Farmer
- Re: [OPSEC] Tsvart last call review of draft-ietf… Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Stewart Bryant
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Ole Troan
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Randy Bush
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Ole Troan
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Stewart Bryant
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Ole Troan
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Christian Huitema
- [OPSEC] HbH flags [Tsvart last call review of dra… Brian E Carpenter
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Brian E Carpenter
- [OPSEC] game over, EH [Tsvart last call review of… Brian E Carpenter
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- [OPSEC] ECMP [Tsvart last call review of draft-ie… Brian E Carpenter
- Re: [OPSEC] HbH flags [Tsvart last call review of… Brian E Carpenter
- Re: [OPSEC] game over, EH [Tsvart last call revie… Stephen Farrell
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Fernando Gont
- Re: [OPSEC] game over, EH [Tsvart last call revie… Fernando Gont
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Fernando Gont
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Christopher Morrow
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Christopher Morrow
- Re: [OPSEC] HbH flags [Tsvart last call review of… Christopher Morrow
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] HbH flags [Tsvart last call review of… Gert Doering
- Re: [OPSEC] game over, EH [Tsvart last call revie… Gert Doering
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Brian Trammell (IETF)
- Re: [OPSEC] game over, EH [Tsvart last call revie… Stewart Bryant
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Stewart Bryant
- Re: [OPSEC] HbH flags [Tsvart last call review of… Ole Troan
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Stewart Bryant
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Ole Troan
- Re: [OPSEC] game over, EH [Tsvart last call revie… Stewart Bryant
- Re: [OPSEC] game over, EH [Tsvart last call revie… Gert Doering
- Re: [OPSEC] HbH flags [Tsvart last call review of… Stewart Bryant
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Stewart Bryant
- Re: [OPSEC] game over, EH [Tsvart last call revie… Stewart Bryant
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Gert Doering
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Ole Troan
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Spencer Dawkins at IETF
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Ole Troan
- Re: [OPSEC] HbH flags [Tsvart last call review of… Stewart Bryant
- Re: [OPSEC] HbH flags [Tsvart last call review of… Joe Touch
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Fernando Gont
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Smith, Donald
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Ole Troan
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Fernando Gont
- Re: [OPSEC] game over, EH [Tsvart last call revie… C. M. Heard
- Re: [OPSEC] game over, EH [Tsvart last call revie… Jared Mauch
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Jared Mauch
- Re: [OPSEC] game over, EH [Tsvart last call revie… C. M. Heard
- Re: [OPSEC] game over, EH [Tsvart last call revie… Smith, Donald
- Re: [OPSEC] game over, EH [Tsvart last call revie… Gert Doering
- Re: [OPSEC] game over, EH [Tsvart last call revie… Nico Williams
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Brian E Carpenter
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Nick Hilliard
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Brian E Carpenter
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Nick Hilliard
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Brian E Carpenter
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Eric Rescorla
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Jared Mauch
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Fernando Gont
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Christopher Morrow
- Re: [OPSEC] HbH flags [Tsvart last call review of… Christopher Morrow
- Re: [OPSEC] [Tsv-art] Tsvart last call review of … Gert Doering
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Eric Rescorla
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Jared Mauch
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Eric Rescorla
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Joe Touch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Pete Resnick
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Jared Mauch
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Jared Mauch
- Re: [OPSEC] HbH flags [Tsvart last call review of… Jared Mauch
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Joe Touch
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Nico Williams
- [OPSEC] OT: TCP session lifetime - Re: [Tsv-art] … Jared Mauch
- Re: [OPSEC] OT: TCP session lifetime - Re: [Tsv-a… Nico Williams
- Re: [OPSEC] [Tsv-art] game over, EH [Tsvart last … Eric Rescorla
- Re: [OPSEC] OT: TCP session lifetime - Re: [Tsv-a… Gert Doering
- [OPSEC] Engaging constructively [HbH flags [Tsvar… Alissa Cooper
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Wes Hardaker
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Brian E Carpenter
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Wes Hardaker
- Re: [OPSEC] ECMP [Tsvart last call review of draf… Fernando Gont