Re: [secdir] draft-ietf-nfsv4-rpcsec-gssv3-13

Benjamin Kaduk <kaduk@MIT.EDU> Wed, 09 December 2015 22:51 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6E351A92B3 for <secdir@ietfa.amsl.com>; Wed, 9 Dec 2015 14:51:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r-WaAzWKhmoA for <secdir@ietfa.amsl.com>; Wed, 9 Dec 2015 14:51:26 -0800 (PST)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 748471A8A92 for <secdir@ietf.org>; Wed, 9 Dec 2015 14:51:26 -0800 (PST)
X-AuditID: 12074423-f797f6d0000023d0-4d-5668b06d5843
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id 14.7E.09168.D60B8665; Wed, 9 Dec 2015 17:51:25 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id tB9MpOIn030231 for <secdir@ietf.org>; Wed, 9 Dec 2015 17:51:24 -0500
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id tB9MpLY7024909 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <secdir@ietf.org>; Wed, 9 Dec 2015 17:51:24 -0500
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id tB9MpLKl018221; Wed, 9 Dec 2015 17:51:21 -0500 (EST)
Date: Wed, 09 Dec 2015 17:51:20 -0500
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "secdir@ietf.org" <secdir@ietf.org>
In-Reply-To: <CABrd9SS-VoJnauz-T-P4w420VNqo6qt6vCfwb9JfsN7ZpZqnmQ@mail.gmail.com>
Message-ID: <alpine.GSO.1.10.1512091748180.26829@multics.mit.edu>
References: <CABrd9SS-VoJnauz-T-P4w420VNqo6qt6vCfwb9JfsN7ZpZqnmQ@mail.gmail.com>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrEIsWRmVeSWpSXmKPExsUixCmqrZu7ISPMYOVVPosPCx+yODB6LFny kymAMYrLJiU1J7MstUjfLoEr49ymbawF81grjn//zNjA2MPSxcjJISFgInFsYg8rhC0mceHe erYuRi4OIYHFTBKTv11lhnCOMUq8OfqbBcK5ziTxZvVLsHYhgXqJ8xMXgbWzCGhJXHi2mgnE ZhNQkZj5ZiMbiC0ioC7x9fxWsLiwgJnEqietQHEODk6BQImLB5hBwrwCjhLvt2xnhBgZIPHv 6DawclEBHYnV+6ewQNQISpyc+QTMZgZatXz6NpYJjAKzkKRmIUktYGRaxSibklulm5uYmVOc mqxbnJyYl5dapGuml5tZopeaUrqJERR87C7KOxj/HFQ6xCjAwajEw3vBJT1MiDWxrLgy9xCj JAeTkijvnXUZYUJ8SfkplRmJxRnxRaU5qcWHGCU4mJVEeEM7gXK8KYmVValF+TApaQ4WJXHe uV98w4QE0hNLUrNTUwtSi2CyMhwcShK8C9YDNQoWpaanVqRl5pQgpJk4OEGG8wANXw1Sw1tc kJhbnJkOkT/FqMux4MfttUxCLHn5ealS4rxpINcJgBRllObBzQEnjd1Mqq8YxYHeEuZdAlLF A0w4cJNeAS1hAlry5Uo6yJKSRISUVANjriHDd9HHyvYih40UmC0m6f1fVh62tU3Q8NuF+2d7 W8PZLf+FfNIr+e181yvfPM5pSkBtw75HJ5ceseGWP17+bJn7j53z+TaEPObUtS6Ya3fFvYE9 TOGZ/plTLz7mp0UzMAZevZRm3/mQT2Ith9P6c0eNSng8le6syL+y3ekxL0+H6aaCp+1KLMUZ iYZazEXFiQCLb/ND9QIAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/secdir/3sXs7T_9BSa5AUqjjXESFp2N66k>
Subject: Re: [secdir] draft-ietf-nfsv4-rpcsec-gssv3-13
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Dec 2015 22:51:27 -0000

On Wed, 9 Dec 2015, Ben Laurie wrote:

> This is _NOT_ a proper review, and hence only to secdir.
>
> I've take a good look at this thing, and its a rather complicated addition
> to an already rather complicated protocol.
>
> I don't feel qualified to make a good assessment of it, I suggest you find
> someone more expert on the protocols to review.

To add to this, previous versions of this document included critical
security flaws.  The latest version has attempts to fix those flaws, but I
do not think anyone has done a proper security review since then.

(At the moment, it looks like I will not have enough free time to do a
re-review.)

-Ben