Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: DestinationUnreachable) (#377)
Igor Lubashev <notifications@github.com> Sun, 18 March 2018 19:34 UTC
Return-Path: <noreply@github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2D9711270A0 for <quic-issues@ietfa.amsl.com>; Sun, 18 Mar 2018 12:34:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7
X-Spam-Level:
X-Spam-Status: No, score=-7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KcTFfVnrgzKr for <quic-issues@ietfa.amsl.com>; Sun, 18 Mar 2018 12:34:53 -0700 (PDT)
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2-ext5.iad.github.net [192.30.252.196]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60325126D73 for <quic-issues@ietf.org>; Sun, 18 Mar 2018 12:34:53 -0700 (PDT)
Date: Sun, 18 Mar 2018 12:34:52 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1521401692; bh=snjhp4jPx1gtJeLYoZJtuCBF20BkGPBoaXU6biG/LGE=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=YTSxeOkr9vd8dvQVS3puHIZteQQ/L6aedUXYfQvWpFfKRmnoyk4/LVRWArzSmFxR5 M46bgUIMWd4qYdhDyUDrHc8mTgyZ+mLxsOYB2YwtwYoUt8hnUYfm7ucuXbNf0NeqTD KBd8n0Kyn66wwxeH9SCil/UoiJ0CanzyodduFHXQ=
From: Igor Lubashev <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4abd49876109d8681880c80e1622a4ba983e8b2854792cf0000000116c6815c92a169ce0cb13645@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/377/374037306@github.com>
In-Reply-To: <quicwg/base-drafts/issues/377@github.com>
References: <quicwg/base-drafts/issues/377@github.com>
Subject: Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: DestinationUnreachable) (#377)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5aaebf5c8540b_1af593fa7e9740f3815305d4"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: igorlord
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/imN-GYJycWHfKuFJ0QOK_itqQpQ>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 18 Mar 2018 19:34:55 -0000
**Assumptions** 1. Handshake is powerless against an attacker that can observe a path and, while it cannot interfere with the path, it can deliver a packet back the the sender in less than 1-rtt. 2. It is important to detect path and endpoint problems very quickly at connection establishment, if the sender has alternatives to try (other IPs from DNS, or other protocols, or lower the MTU). **Tools** - _Ignore_. Ignore the signal. - _Accept_. Accept the signal (and act accordingly right away), as long as it is not obviously bogus (you already received a valid ACK for the packet subject to the ICMP error, for example). - _Validate_. Start an immediate path validation with a short timeout, unless the packet is obviously bogus (see above). **ICMP Types** - With "on-path proof". These are ICMP packets that contain a large portion of the packet that triggered them. They prove that the packet came from an on-path box. These are ICMPv6 error packets and ICMP [https://datatracker.ietf.org/doc/rfc4884/](RFC 4884) error packets. - Without "on-path proof". These are ICMP error packets that only contain 8 octets of the original packet past the original IP header. Per Section "8.4.1. Special Considerations for PMTU Discovery" of the Transport draft, the recommendation for adding as much entropy to the IP layer as possible (IP ID, DF flag, etc) should be applied. **Recommendations** 1. Dealing with ICMP "unreachable" (path or port) or "too big" during handshake. For ICMP with "on-path proof", Accept. For ICMP w/o "on-path proof", Accept if can fail over to a different IP (that was not yet tried for this request); otherwise retry one more time. 2. Dealing with ICMP "unreachable" (path or port) not during handshake. Validate. 3. Dealing with ICMP "too big" not during handshake. Accept if it is not requesting an MTU lower than X, where X is relatively low" for ICMP with "on-path proof" and is relatively high for ICMP without "on-path proof". If the requested MTU is lower than X, Validate (via PMTUD techniques). -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/issues/377#issuecomment-374037306
- [quicwg/base-drafts] ICMP and ICMPv6 (Type: Desti… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… MikkelFJ
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… MikkelFJ
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Igor Lubashev
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson
- Re: [quicwg/base-drafts] ICMP and ICMPv6 (Type: D… Martin Thomson