Re: Does RFC9000 allow endpoints to reuse CIDs when NAT rebinding happens?
Eric Kinnear <ekinnear@apple.com> Tue, 26 September 2023 17:25 UTC
Return-Path: <ekinnear@apple.com>
X-Original-To: quic@ietfa.amsl.com
Delivered-To: quic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC433C152565 for <quic@ietfa.amsl.com>; Tue, 26 Sep 2023 10:25:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.409
X-Spam-Level:
X-Spam-Status: No, score=-4.409 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=apple.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uSiqtn-NRFce for <quic@ietfa.amsl.com>; Tue, 26 Sep 2023 10:25:34 -0700 (PDT)
Received: from ma-mailsvcp-mx-lapp02.apple.com (ma-mailsvcp-mx-lapp02.apple.com [17.32.222.23]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADEEBC151088 for <quic@ietf.org>; Tue, 26 Sep 2023 10:25:34 -0700 (PDT)
Received: from rn-mailsvcp-mta-lapp04.rno.apple.com (rn-mailsvcp-mta-lapp04.rno.apple.com [10.225.203.152]) by ma-mailsvcp-mx-lapp02.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPS id <0S1L00HHQSEHLJ30@ma-mailsvcp-mx-lapp02.apple.com> for quic@ietf.org; Tue, 26 Sep 2023 10:25:33 -0700 (PDT)
X-Proofpoint-ORIG-GUID: XUwEzM-WJ9h1V8J5-3NF36JqWSxxjkm5
X-Proofpoint-GUID: XUwEzM-WJ9h1V8J5-3NF36JqWSxxjkm5
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.619, 18.0.980 definitions=2023-09-26_13:2023-09-26, 2023-09-26 signatures=0
X-Proofpoint-Spam-Details: rule=interactive_user_notspam policy=interactive_user score=0 mlxlogscore=291 phishscore=0 adultscore=0 malwarescore=0 suspectscore=0 mlxscore=0 spamscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2309180000 definitions=main-2309260151
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=apple.com; h=content-type : mime-version : subject : from : in-reply-to : date : cc : content-transfer-encoding : message-id : references : to; s=20180706; bh=a0TINiYfkZLWaU6scwKtO6riRO1C/EYPLDlMpdqjm9c=; b=SHzRPo7QAoRY/roQm6mchOZMk6rZGy0M5ABydbh59H9TDHW1kFi52a3kxnBPs0KiEAce WVGBYfPFzPBzoceJpHFClEyibta+PFt3nIpy66eXM63iZBLaVUkPCib5TGnkQjtW8OsQ +kBgXMj1L/T0bUvLJ1Ati5LfftZ73rjrl8+52YUz40otSrZwSDKMB3Q9DXXnIVbzuVCl cc959KbDWCJpRm0P692faobEeJinnhNR0jjjNZmeaxeKC2M/W938MPa0xlfX66amFwWX QyFvqo8hjZcXwJi06p0N8UA6hwA065aMgRi8dBBbvDIYWq2HF2KnjCeXkJ6K8mBfh0q0 EQ==
Received: from rn-mailsvcp-mmp-lapp02.rno.apple.com (rn-mailsvcp-mmp-lapp02.rno.apple.com [17.179.253.15]) by rn-mailsvcp-mta-lapp04.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPS id <0S1L00F7ASEHU8T0@rn-mailsvcp-mta-lapp04.rno.apple.com>; Tue, 26 Sep 2023 10:25:29 -0700 (PDT)
Received: from process_milters-daemon.rn-mailsvcp-mmp-lapp02.rno.apple.com by rn-mailsvcp-mmp-lapp02.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) id <0S1L00Q00S8V0H00@rn-mailsvcp-mmp-lapp02.rno.apple.com>; Tue, 26 Sep 2023 10:25:29 -0700 (PDT)
X-Va-A:
X-Va-T-CD: 012260c5ffda1ff83a892b471b943b56
X-Va-E-CD: 53771a983c404f7de32c339a1d945e23
X-Va-R-CD: 038a1ffc4c0760f7981d2525c85dab25
X-Va-ID: 458daa32-87fc-4289-bd02-38631ffa1da6
X-Va-CD: 0
X-V-A:
X-V-T-CD: 012260c5ffda1ff83a892b471b943b56
X-V-E-CD: 53771a983c404f7de32c339a1d945e23
X-V-R-CD: 038a1ffc4c0760f7981d2525c85dab25
X-V-ID: a4a8d005-15da-45f9-b386-06ccd8531976
X-V-CD: 0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.619, 18.0.980 definitions=2023-09-26_13:2023-09-26, 2023-09-26 signatures=0
Received: from smtpclient.apple (ekinnear1.scv.apple.com [17.192.40.106]) by rn-mailsvcp-mmp-lapp02.rno.apple.com (Oracle Communications Messaging Server 8.1.0.23.20230328 64bit (built Mar 28 2023)) with ESMTPSA id <0S1L010KQSEH7P00@rn-mailsvcp-mmp-lapp02.rno.apple.com>; Tue, 26 Sep 2023 10:25:29 -0700 (PDT)
Content-type: text/plain; charset="utf-8"
MIME-version: 1.0 (Mac OS X Mail 16.0 \(3774.100.2.1.4\))
Subject: Re: Does RFC9000 allow endpoints to reuse CIDs when NAT rebinding happens?
From: Eric Kinnear <ekinnear@apple.com>
In-reply-to: <20230926033738.GC22132@1wt.eu>
Date: Tue, 26 Sep 2023 10:25:19 -0700
Cc: "???(Personal)" <fryang@outlook.com>, Ian Swett <ianswett@google.com>, quic@ietf.org
Content-transfer-encoding: quoted-printable
Message-id: <4B0156AC-FF34-46D2-8EF3-EDB2972B0A41@apple.com>
References: <OS3P286MB05333638A3EB858FAB4B8B4FD9FCA@OS3P286MB0533.JPNP286.PROD.OUTLOOK.COM> <CAKcm_gMfYsWxFLjXt9wBnVma03BQLMgOkF_Kdp09paEhTy4Vdw@mail.gmail.com> <OS3P286MB053391507A417C28F7E31639D9C3A@OS3P286MB0533.JPNP286.PROD.OUTLOOK.COM> <20230926033738.GC22132@1wt.eu>
To: Willy Tarreau <w@1wt.eu>
X-Mailer: Apple Mail (2.3774.100.2.1.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/p11PG-GBVv06aQAci8PHCgW8EvE>
X-BeenThere: quic@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic>, <mailto:quic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic/>
List-Post: <mailto:quic@ietf.org>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic>, <mailto:quic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Sep 2023 17:25:39 -0000
That said, if the server notices that the client is coming from a different address and using the same destination CID, which would not be allowed if the client knew that it was using a different network path, it’s nice if it does change CID. This provides a signal to a client that a NAT rebinding may have occurred, and the client might choose to take action on that in some way.
Since you’re allowed to change CID at any time on the same path, there’s no need for additional text that explicitly allows this, but the most straightforward implementation that just says “yup, you’re on a different remote address, I’ll use a different CID” and doesn’t check whether the remote peer rotated CID is likely the best answer.
Thanks,
Eric
> On Sep 25, 2023, at 8:37 PM, Willy Tarreau <w@1wt.eu> wrote:
>
> On Tue, Sep 26, 2023 at 11:04:40AM +0800, "???(Personal)" wrote:
>> Is it allowed for a server to reuse the current CID when it notices a NAT
>> rebinding? I wonder if the text ("...., in which case it MAY continue to use
>> the current connection ID with the new remote address while still sending
>> from the same local address.") indicates that the server can reuse the
>> current CID?
>
> If the spec says "MAY", then yes, it's allowed to.
>
> Willy
>
- Does RFC9000 allow endpoints to reuse CIDs when N… "杨馥榕(Personal)"
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… Ian Swett
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… "杨馥榕(Personal)"
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… Willy Tarreau
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… Eric Kinnear
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… Christian Huitema
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… "杨馥榕(Personal)"
- RE: Does RFC9000 allow endpoints to reuse CIDs wh… Lubashev, Igor
- Re: Does RFC9000 allow endpoints to reuse CIDs wh… Christian Huitema