Re: [quicwg/base-drafts] Connection migration must be negotiated (#1271)

Praveen Balasubramanian <notifications@github.com> Fri, 06 April 2018 18:18 UTC

Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BB494126BF7 for <quic-issues@ietfa.amsl.com>; Fri, 6 Apr 2018 11:18:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.009
X-Spam-Level:
X-Spam-Status: No, score=-2.009 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id af1bc59hmhJ6 for <quic-issues@ietfa.amsl.com>; Fri, 6 Apr 2018 11:18:14 -0700 (PDT)
Received: from o5.sgmail.github.com (o5.sgmail.github.com [192.254.113.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 900DC127137 for <quic-issues@ietf.org>; Fri, 6 Apr 2018 11:18:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=qe4XrP0fsFrHdT6NDYvPsF6og3w=; b=rid1nUO8wEOgu4fQ XzejYnF+iZaedZx7tAlw4OXdOhz1FklgEG/ubvXKg58EAhV5ANrGmuvkKqiVStPu DjuT6+b+wvTKUw/ta/ZS6lV4Luqs2JEPe4azyy8EaTuAaI4X/xzIOqZEuu4HKWOH zS0pK9jYRt5hqdt2z8CyT4DoYiQ=
Received: by filter0793p1mdw1.sendgrid.net with SMTP id filter0793p1mdw1-26225-5AC7B9B3-2E 2018-04-06 18:17:23.640386791 +0000 UTC
Received: from smtp.github.com (out-1.smtp.github.com [192.30.252.192]) by ismtpd0010p1iad1.sendgrid.net (SG) with ESMTP id 2CNCvuiLSBiYt_BV847M9Q for <quic-issues@ietf.org>; Fri, 06 Apr 2018 18:17:23.721 +0000 (UTC)
Date: Fri, 06 Apr 2018 18:17:23 +0000
From: Praveen Balasubramanian <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4abe19cfb6a34cfb40513062ecb86abc8976c4f22ac92cf0000000116df7bb392a169ce129955d7@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/1271/379334910@github.com>
In-Reply-To: <quicwg/base-drafts/issues/1271@github.com>
References: <quicwg/base-drafts/issues/1271@github.com>
Subject: Re: [quicwg/base-drafts] Connection migration must be negotiated (#1271)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5ac7b9b39cdc6_292253faabb252f381987d8"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: pravb
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak3UFuzCKFNQ8A3GVdhrBc0PTaT8Q6/qq+tihm D/+sXnpfzEyoHlpL9RCdP4JJqIyECtuIc/Pk6jTd1n+m0eoZXfsiVbl4T1lDWeQiTyDuCUG7eYk2yB bZZbFuKHIKt6Drfssh15Cn/jeIMG8Un+tFL1SCctiWZOnRLkOa8BzDZ8aAumES7VjSQUq5EK+HMsh8 0=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/qOTFoXz7M9gpVSt1AlS3HndM4Qg>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 06 Apr 2018 18:18:16 -0000

>>My main concern is that implementations, especially server implementations, MUST implement migration support, even if they allow it to be configured "off".
There is unfortunately no way to enforce this. Regardless of server support or infra issue the server must be able to veto this. I also think since QUIC has very poor signaling for DDoS prevention, server infra may dynamically start rejection migrations when under attack.

NAT re-binding can be solved by keep-alives and existing load balancers allow 2-tuple load balancing for UDP which means a NAT-rebinding where the port changes will not suffer the same issue.



-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/1271#issuecomment-379334910