Re: [OPSEC] [v6ops] IPv6 LL-only as WG document - feedback requested

Mark ZZZ Smith <markzzzsmith@yahoo.com.au> Wed, 15 August 2012 09:42 UTC

Return-Path: <markzzzsmith@yahoo.com.au>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3BC421F877E for <opsec@ietfa.amsl.com>; Wed, 15 Aug 2012 02:42:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.52
X-Spam-Level:
X-Spam-Status: No, score=-1.52 tagged_above=-999 required=5 tests=[AWL=-0.020, BAYES_00=-2.599, FROM_LOCAL_NOVOWEL=0.5, J_CHICKENPOX_13=0.6]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MTIEqJgukz-b for <opsec@ietfa.amsl.com>; Wed, 15 Aug 2012 02:42:00 -0700 (PDT)
Received: from nm38-vm7.bullet.mail.ne1.yahoo.com (nm38-vm7.bullet.mail.ne1.yahoo.com [98.138.229.151]) by ietfa.amsl.com (Postfix) with SMTP id 75C1D21F877D for <opsec@ietf.org>; Wed, 15 Aug 2012 02:41:58 -0700 (PDT)
Received: from [98.138.90.56] by nm38.bullet.mail.ne1.yahoo.com with NNFMP; 15 Aug 2012 09:41:55 -0000
Received: from [98.138.89.174] by tm9.bullet.mail.ne1.yahoo.com with NNFMP; 15 Aug 2012 09:41:55 -0000
Received: from [127.0.0.1] by omp1030.mail.ne1.yahoo.com with NNFMP; 15 Aug 2012 09:41:55 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 507826.48534.bm@omp1030.mail.ne1.yahoo.com
Received: (qmail 39869 invoked by uid 60001); 15 Aug 2012 09:41:55 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com.au; s=s1024; t=1345023714; bh=uYG+K4zsvXGEkYbjZ7k+lExGaJTspkQEOzKok4XlLFg=; h=X-YMail-OSG:Received:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=KKkhb8bqFmJPNdDshsdvtLzspDHyeD/+P9anKAe03TLEvMvgz1xnybpgniEmYWxi1m8lhy9LJtz0D+OYGCxw04huP5gsrzymQRKfJHPS3lKxf5QD8gHJ1/ukYUeeBcr3skwaEY5ys4zj3k1TaSpEc6dQegmX1nyAmqeGXH9i9Z4=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com.au; h=X-YMail-OSG:Received:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=5Eu4Jz/K1XZE3oURnKl0u+qGxqap06rIpti9Tq4OmEbGrl869BylnDtk22pHuGmX3vu+e7A9CgvLG7lp6b0TN7SWO/h/SMjjHLCmYNu/LQ+o6UW9YNyLrW2YgJU0HtkSXFAeVzsztSGWpoblJQLWdTyDN7sd+TUbxio8eXlxZwU=;
X-YMail-OSG: oINOGdkVM1ng3yN4FzeGsfdIXRLhY9lwee0QXF4ZXy76eWx ixzQDybtF1tRJdRMTnWMOWfavxUe6Ej8N7bnI2VOwvy.YCN0WT46IyHSCmBF Ktc45HAvXAYoAvKyDGyku9CMmuEJ6gI_96jN1fulvEzITac1dfPexYitA1pq FGbNi4QjY7GL5Gt7zV8xrWG8M1PEG4Rb8LNekzitQT7RaX4tyukxfNEscIda E5KDj5H_exs8l_Q9upMRjh6hBERdGNfAZOqBcGMXZc_0InFZ8JS0qHf3WP4o zdfhFoRFXR6JxIoqM9gzUINLMFmqvVoIz5qHJZRVs.L1gmCEUpq.7hOjsWJ1 KdYNNFtG.UC7P7ox.R.mVo2b4_7VnaTJGtjs_e0HT4cuKuPcUw3ykugoiaaT cLLrwPL6xm205FAAh3KUDXqhQtwEncdzBZ93_nHKO3pWoIGeqKlvEcR5tgf1 BYoRQtG2v0aXzr_.0Cu.ohEvNwj1QcdOCAlj0_UPErAS.tEmsyQu_uawZzBW SVYg-
Received: from [150.101.221.237] by web32507.mail.mud.yahoo.com via HTTP; Wed, 15 Aug 2012 02:41:54 PDT
X-Mailer: YahooMailWebService/0.8.120.356233
References: <67832B1175062E48926BF3CB27C49B24068549@xmb-aln-x12.cisco.com> <501F8D5F.5000805@gmail.com> <724010AF-C8BA-4D97-BE5D-48A53AAB960A@cisco.com> <502B549A.4010708@gmail.com>
Message-ID: <1345023714.38595.YahooMailNeo@web32507.mail.mud.yahoo.com>
Date: Wed, 15 Aug 2012 02:41:54 -0700
From: Mark ZZZ Smith <markzzzsmith@yahoo.com.au>
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, "Carlos Pignataro (cpignata)" <cpignata@cisco.com>
In-Reply-To: <502B549A.4010708@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailman-Approved-At: Wed, 15 Aug 2012 08:03:50 -0700
Cc: "opsec@ietf.org" <opsec@ietf.org>, "opsec-chairs@ietf.org" <opsec-chairs@ietf.org>, "'draft-behringer-lla-only@tools.ietf.org' (draft-behringer-lla-only@tools.ietf.org)" <draft-behringer-lla-only@tools.ietf.org>, "v6ops v6ops WG (v6ops@ietf.org)" <v6ops@ietf.org>
Subject: Re: [OPSEC] [v6ops] IPv6 LL-only as WG document - feedback requested
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Mark ZZZ Smith <markzzzsmith@yahoo.com.au>
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Aug 2012 09:42:01 -0000

Hi,


----- Original Message -----
> From: Brian E Carpenter <brian.e.carpenter@gmail.com>
> To: Carlos Pignataro (cpignata) <cpignata@cisco.com>
> Cc: "'draft-behringer-lla-only@tools.ietf.org' (draft-behringer-lla-only@tools.ietf.org)" <draft-behringer-lla-only@tools.ietf.org>; "opsec-chairs@ietf.org" <opsec-chairs@ietf.org>; "opsec@ietf.org" <opsec@ietf.org>; "v6ops v6ops WG (v6ops@ietf.org)" <v6ops@ietf.org>
> Sent: Wednesday, 15 August 2012 5:49 PM
> Subject: Re: [v6ops] IPv6 LL-only as WG document - feedback requested
> 
> Carlos,
> 
> On 14/08/2012 22:08, Carlos Pignataro (cpignata) wrote:
>>  Michael, Brian,
>> 
>>  Should "The Suggested Approach" 
> http://tools.ietf.org/html/draft-behringer-lla-only-01#section-2.1 also include 
> some prescriptiveness or specific recommendation regarding the use of RFC 5837, 
> instead of including that solution to interface identification as a 
> "Caveats and Possible Workarounds" only?
> 
> I have no strong opinion on this. Just indicating the existence of 5837
> seems OK, though.
> 
> Looking at the current text, it says that the loopback GUA MUST be used for all
> ICMPv6 messages, which is good, but it also says
> "ICMP error message can also be sourced from the global scope loopback 
> address."

Perhaps it would be better to be even more general, and just say ICMPv6 messages must come from addresses with a scope greater than link local? Restricting to GUAs suggests the idea in this draft can only be used when GUAs are available, yet I'd think it could also be useful in a private, non-Internet connected network too.

<snip>

Regards,
Mark.