Re: [quicwg/base-drafts] Increase resilience to spoofed Version Negotiation packets (#524)
Martin Thomson <notifications@github.com> Wed, 17 May 2017 16:38 UTC
Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 676DD12EB58 for <quic-issues@ietfa.amsl.com>; Wed, 17 May 2017 09:38:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.801
X-Spam-Level:
X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rxo3tVW8VNEY for <quic-issues@ietfa.amsl.com>; Wed, 17 May 2017 09:38:06 -0700 (PDT)
Received: from o6.sgmail.github.com (o6.sgmail.github.com [192.254.113.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 61CAB128C81 for <quic-issues@ietf.org>; Wed, 17 May 2017 09:32:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=DCRmCuCjvjY8uaDUakAjFwRlQPY=; b=AW/BBXaolUVF8YTx RRy+tLHi92wjP59DZ6LxNddhHlJp2xue6MS8eehpX2brZkkgl8rg8TMCz3pKReHQ c2bY4lZt4jiR3N9n9u25aL8AzT1OSi9IsDqB9Y47rtXh8Mi8CWAj6hBAqslWndv0 QP2wDCT1BRMqVJ72NQyYjZehiWs=
Received: by filter0971p1mdw1.sendgrid.net with SMTP id filter0971p1mdw1-19991-591C7B09-38 2017-05-17 16:32:09.408969843 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0005p1iad1.sendgrid.net (SG) with ESMTP id GJk0dHmTQWK8VGJfRCPtyQ for <quic-issues@ietf.org>; Wed, 17 May 2017 16:32:09.394 +0000 (UTC)
Date: Wed, 17 May 2017 09:32:09 -0700
From: Martin Thomson <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4ab0d53d7309b2c3426dbe58292ea30ca7971fa27fc92cf0000000115343d0992a169ce0d99fec5@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/pull/524/review/38691864@github.com>
In-Reply-To: <quicwg/base-drafts/pull/524@github.com>
References: <quicwg/base-drafts/pull/524@github.com>
Subject: Re: [quicwg/base-drafts] Increase resilience to spoofed Version Negotiation packets (#524)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_591c7b093dd69_43c33ff328e5dc3c24187"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: martinthomson
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak0GugzKWbqodpeUTy8YrdIS7DHzeB0pzTBwMn RRj7yduw6ifWgfzQ3IvHOp4tXtwCYAEWUL69CEmpt8ZWYIAbGnA2uud7okaOigSMTF2KQDK3JzREFf hWIjRKXEQN0OSuG6FtwMNms1cbiHR3nHa2fBf/el2XARdrY4el3jY7EoLgil3UokvgR4kK18TlTXf6 o=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/ru-Le32Isuw9bFR7-PWTRu1y0S0>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 May 2017 16:38:08 -0000
martinthomson commented on this pull request. > @@ -1228,6 +1235,18 @@ client MUST terminate with a QUIC_VERSION_NEGOTIATION_MISMATCH error code if version negotiation occurred but it would have selected a different version based on the value of the supported_versions list. +If the client receives a Version Negotiation packet and these validation checks +subsequently fail, it is likely that the client received a spoofed Version +Negotiation packet. A client MAY attempt to create a new connection and ignore +any Version Negotiation packets that match those that caused the connection to +fail. + +Note: + +: The client cannot rely on the version list from the transport parameters. Ack, I'll correct that. > @@ -1228,6 +1235,18 @@ client MUST terminate with a QUIC_VERSION_NEGOTIATION_MISMATCH error code if version negotiation occurred but it would have selected a different version based on the value of the supported_versions list. +If the client receives a Version Negotiation packet and these validation checks +subsequently fail, it is likely that the client received a spoofed Version +Negotiation packet. A client MAY attempt to create a new connection and ignore If there is a disagreement between transport parameters and version negotiation, then something is broken. I don't think that it matters if it is due to spoofing or a bug. > -uses on every packet it sends. Packets MUST continue to use long headers and -MUST include the new negotiated protocol version. +A client MUST discard a Version Negotiation packet that does not contain Packet +Number and Version fields that match those fields in a packet that the client +previously sent. This doesn't guarantee that the Version Negotiation packet is +genuine, but it reduces the chances that the packet is spoofed. + +A client that receives a valid Version Negotiation packet selects an acceptable +protocol version from those listed by the server. The client then reattempts to +create a connection using that version. Though the contents of a packet might +not change in response to version negotiation, a client MUST choose a new packet +number it uses on every packet it sends. + +If the server does not list an acceptable version, the client MAY ignore the +Version Negotiation packet. This might reduce the likelihood that a spoofed +Version Negotiation packet can be used to disrupt connection establishment. I'll cut this paragraph. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/quicwg/base-drafts/pull/524#discussion_r117023206
- [quicwg/base-drafts] Increase resilience to spoof… Martin Thomson
- Re: [quicwg/base-drafts] Increase resilience to s… Mike Bishop
- Re: [quicwg/base-drafts] Increase resilience to s… janaiyengar
- Re: [quicwg/base-drafts] Increase resilience to s… janaiyengar
- Re: [quicwg/base-drafts] Increase resilience to s… janaiyengar
- Re: [quicwg/base-drafts] Increase resilience to s… Martin Thomson
- Re: [quicwg/base-drafts] Increase resilience to s… janaiyengar
- Re: [quicwg/base-drafts] Increase resilience to s… Martin Thomson
- Re: [quicwg/base-drafts] Increase resilience to s… MikkelFJ
- Re: [quicwg/base-drafts] Increase resilience to s… Martin Thomson
- Re: [quicwg/base-drafts] Increase resilience to s… Martin Thomson