[pcp] FW: New Version Notification for draft-ietf-pcp-authentication-07.txt

"Zhangdacheng (Dacheng)" <zhangdacheng@huawei.com> Tue, 30 December 2014 09:43 UTC

Return-Path: <zhangdacheng@huawei.com>
X-Original-To: pcp@ietfa.amsl.com
Delivered-To: pcp@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E2281ACEEE for <pcp@ietfa.amsl.com>; Tue, 30 Dec 2014 01:43:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Cu3RvuOpOYQq for <pcp@ietfa.amsl.com>; Tue, 30 Dec 2014 01:43:26 -0800 (PST)
Received: from lhrrgout.huawei.com (lhrrgout.huawei.com [194.213.3.17]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B027E1A0041 for <pcp@ietf.org>; Tue, 30 Dec 2014 01:43:25 -0800 (PST)
Received: from 172.18.7.190 (EHLO lhreml404-hub.china.huawei.com) ([172.18.7.190]) by lhrrg02-dlp.huawei.com (MOS 4.3.7-GA FastPath queued) with ESMTP id BNL33274; Tue, 30 Dec 2014 09:43:24 +0000 (GMT)
Received: from nkgeml409-hub.china.huawei.com (10.98.56.40) by lhreml404-hub.china.huawei.com (10.201.5.218) with Microsoft SMTP Server (TLS) id 14.3.158.1; Tue, 30 Dec 2014 09:43:22 +0000
Received: from NKGEML507-MBS.china.huawei.com ([169.254.6.3]) by nkgeml409-hub.china.huawei.com ([10.98.56.40]) with mapi id 14.03.0158.001; Tue, 30 Dec 2014 17:43:18 +0800
From: "Zhangdacheng (Dacheng)" <zhangdacheng@huawei.com>
To: "pcp@ietf.org" <pcp@ietf.org>
Thread-Topic: New Version Notification for draft-ietf-pcp-authentication-07.txt
Thread-Index: AQHQJBQNU5pXtVQlfkK63gUFR29kNJyn4CEw
Date: Tue, 30 Dec 2014 09:43:18 +0000
Message-ID: <C72CBD9FE3CA604887B1B3F1D145D05EA9DF5903@nkgeml507-mbs.china.huawei.com>
Accept-Language: zh-CN, en-US
Content-Language: zh-CN
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.111.98.139]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-CFilter-Loop: Reflected
Archived-At: http://mailarchive.ietf.org/arch/msg/pcp/ukKxrtuq5HD48y1hGztWC17Ut-k
Subject: [pcp] FW: New Version Notification for draft-ietf-pcp-authentication-07.txt
X-BeenThere: pcp@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: PCP wg discussion list <pcp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/pcp>, <mailto:pcp-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/pcp/>
List-Post: <mailto:pcp@ietf.org>
List-Help: <mailto:pcp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/pcp>, <mailto:pcp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Dec 2014 09:43:28 -0000

Hi, all:

We have made a new version of the PCP Auth document according to the comments we got since the last IETF meeting. The main changes include:

1)Addressed comments given by Dave Thaler in http://research.microsoft.com/en-us/um/people/dthaler/draft-ietf-pcp-authentication-06.pdf
2)It was decided in the PCP WG meeting that PA-acknowledgement will be sent if response cannot be generated immediately
3)Added that EAP-TEAP SHOULD be supported.
4)Removed traffic key and used transport key throughout the specification.
5Add discussions about ID indicator matching
6)Add a new type of error message for downgrade attacks.
7) Give clear definition of PA messages and Com PCP messages

So, could you please take a look at the draft and let us know if there is any additional comments?

Happy new year!

Cheers

Dacheng


> -----Original Message-----
> From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> Sent: Tuesday, December 30, 2014 5:36 PM
> To: Zhangdacheng (Dacheng); Zhangdacheng (Dacheng); Tirumaleswar Reddy;
> Tirumaleswar Reddy; Sam Hartman; Margaret Wasserman; Sam Hartman;
> Margaret Wasserman
> Subject: New Version Notification for draft-ietf-pcp-authentication-07.txt
> 
> 
> A new version of I-D, draft-ietf-pcp-authentication-07.txt
> has been successfully submitted by Dacheng Zhang and posted to the IETF
> repository.
> 
> Name:		draft-ietf-pcp-authentication
> Revision:	07
> Title:		Port Control Protocol (PCP) Authentication Mechanism
> Document date:	2014-12-30
> Group:		pcp
> Pages:		28
> URL:
> http://www.ietf.org/internet-drafts/draft-ietf-pcp-authentication-07.txt
> Status:
> https://datatracker.ietf.org/doc/draft-ietf-pcp-authentication/
> Htmlized:       http://tools.ietf.org/html/draft-ietf-pcp-authentication-07
> Diff:
> http://www.ietf.org/rfcdiff?url2=draft-ietf-pcp-authentication-07
> 
> Abstract:
>    An IPv4 or IPv6 host can use the Port Control Protocol (PCP) to
>    flexibly manage the IP address and port mapping information on
>    Network Address Translators (NATs) or firewalls, to facilitate
>    communication with remote hosts.  However, the un-controlled
>    generation or deletion of IP address mappings on such network devices
>    may cause security risks and should be avoided.  In some cases the
>    client may need to prove that it is authorized to modify, create or
>    delete PCP mappings.  This document describes an in-band
>    authentication mechanism for PCP that can be used in those cases.
>    The Extensible Authentication Protocol (EAP) is used to perform
>    authentication between PCP devices.
> 
> 
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> The IETF Secretariat