Re: [radext] draft-ietf-dhc-dhcpv6-radius-opt-10

"Jim Schaad" <ietf@augustcellars.com> Thu, 04 April 2013 17:12 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BEA0D21F8EDE for <radext@ietfa.amsl.com>; Thu, 4 Apr 2013 10:12:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6ixmBetLT9wF for <radext@ietfa.amsl.com>; Thu, 4 Apr 2013 10:12:50 -0700 (PDT)
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171]) by ietfa.amsl.com (Postfix) with ESMTP id 5658C21F8E2E for <radext@ietf.org>; Thu, 4 Apr 2013 10:12:50 -0700 (PDT)
Received: from Philemon (mail.augustcellars.com [50.34.17.238]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp1.pacifier.net (Postfix) with ESMTPSA id EDF272CA2B; Thu, 4 Apr 2013 10:12:49 -0700 (PDT)
From: Jim Schaad <ietf@augustcellars.com>
To: 'Alan DeKok' <aland@deployingradius.com>, 'Jouni Korhonen' <jouni.nospam@gmail.com>
References: <B51C71CC-654D-43F3-A50A-321C171CD562@gmail.com> <515D7B4D.7090201@deployingradius.com>
In-Reply-To: <515D7B4D.7090201@deployingradius.com>
Date: Thu, 04 Apr 2013 10:12:13 -0700
Message-ID: <011701ce3157$8d1c4900$a754db00$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQHeMUCySghpWabMjAXlQ7CQqOxydwChOzqJmKFCjMA=
Content-Language: en-us
Cc: radext@ietf.org, draft-ietf-dhc-dhcpv6-radius-opt@tools.ietf.org
Subject: Re: [radext] draft-ietf-dhc-dhcpv6-radius-opt-10
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/radext>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Apr 2013 17:12:50 -0000

> -----Original Message-----
> From: radext-bounces@ietf.org [mailto:radext-bounces@ietf.org] On Behalf
> Of Alan DeKok
> Sent: Thursday, April 04, 2013 6:08 AM
> To: Jouni Korhonen
> Cc: radext@ietf.org; draft-ietf-dhc-dhcpv6-radius-opt@tools.ietf.org
> Subject: Re: [radext] draft-ietf-dhc-dhcpv6-radius-opt-10
> 
> Jouni Korhonen wrote:
> > draft-ietf-dhc-dhcpv6-radius-opt-10 has recently passed WGLC in DHC
> > WG. RADEXT WG is solicited for review. We can provide input as part of
> > the IETF LC once it is started.  Remember to CC the RADEXT so we can
> > keep  track of the (possible) comments better.
> 
>   A quick review:
> 
> 4.  DHCPv6 RADIUS option
> 
>     option-len       Length of the option-data in octets
> 
> Q: Can it encode more than 256 octets of RADIUS attributes?  If so, what
> happens then?
> 
> 
>    ... Only the attributes listed in the IANA Registry of 'RADIUS
>    attributes permitted in DHCPv6 RADIUS option' SHOULD be included in
>    the OPTION_RADIUS.
> 
>  That should be a MUST.  There's no sense in permitting non-RADIUS traffic
in
> this option.

Alan, I have not looked at the registry in question yet, however should
there be the ability to send vender defined traffic?

Jim

> 
> 
> 
> 8.  Security Considerations
> 
>    Known security vulnerabilities of the DHCPv6 and RADIUS protocol MAY
> 
> 
>   Using "MAY" here is probably wrong.  It should be "may".
> _______________________________________________
> radext mailing list
> radext@ietf.org
> https://www.ietf.org/mailman/listinfo/radext