Re: [secdir] Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04

"Gaurav Halwasia (ghalwasi)" <ghalwasi@cisco.com> Wed, 20 February 2013 08:37 UTC

Return-Path: <ghalwasi@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3148721F85E8; Wed, 20 Feb 2013 00:37:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KAYZIo-jzYFu; Wed, 20 Feb 2013 00:37:06 -0800 (PST)
Received: from rcdn-iport-3.cisco.com (rcdn-iport-3.cisco.com [173.37.86.74]) by ietfa.amsl.com (Postfix) with ESMTP id 739B321F85C9; Wed, 20 Feb 2013 00:37:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1745; q=dns/txt; s=iport; t=1361349426; x=1362559026; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=ZB9Z/ZYqaQecuInNhfUhFH77gpb3GOCTJSwdlRRMf3A=; b=llYmnvsxF12KJbMLhCfd3UKOLskXWqKl/dpRyrAxIK1lEB5eSfAi5NHQ j+G7sOPUda5A0CT2OMbLI3thUNFK6d28K8Zmj3J19uPp4WPE1RoW4hzcN sfLZYIRWNVikQnR5F9drANfrwLWqYTXP56FS4MfEVXkUqyU4Q86fo5PM1 w=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AgEFACiKJFGtJXG9/2dsb2JhbABFwFR/FnOCHwEBAQQ6PwwEAgEIEQQBAQsUCQcyFAkIAgQBDQUIiAq/eI5dJgsHBoJZYQOnA4MHgic
X-IronPort-AV: E=Sophos;i="4.84,699,1355097600"; d="scan'208";a="179108229"
Received: from rcdn-core2-2.cisco.com ([173.37.113.189]) by rcdn-iport-3.cisco.com with ESMTP; 20 Feb 2013 08:37:06 +0000
Received: from xhc-rcd-x12.cisco.com (xhc-rcd-x12.cisco.com [173.37.183.86]) by rcdn-core2-2.cisco.com (8.14.5/8.14.5) with ESMTP id r1K8b5n2006005 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 20 Feb 2013 08:37:05 GMT
Received: from xmb-aln-x06.cisco.com ([169.254.1.248]) by xhc-rcd-x12.cisco.com ([173.37.183.86]) with mapi id 14.02.0318.004; Wed, 20 Feb 2013 02:37:05 -0600
From: "Gaurav Halwasia (ghalwasi)" <ghalwasi@cisco.com>
To: Shawn Emery <shawn.emery@oracle.com>, "secdir@ietf.org" <secdir@ietf.org>
Thread-Topic: Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04
Thread-Index: AQHOD0CKRlLRIRzxN0yTVWH3M8pIOZiCbBTg
Date: Wed, 20 Feb 2013 08:37:04 +0000
Message-ID: <90903C21C73202418A48BFBE80AEE5EB22E62942@xmb-aln-x06.cisco.com>
References: <5112164C.3060009@oracle.com> <5124827A.3070407@oracle.com>
In-Reply-To: <5124827A.3070407@oracle.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.142.100.114]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Mailman-Approved-At: Wed, 20 Feb 2013 13:42:53 -0800
Cc: "draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt.all@tools.ietf.org" <draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt.all@tools.ietf.org>, The IESG <iesg@ietf.org>
Subject: Re: [secdir] Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Feb 2013 08:37:07 -0000

Thanks Shawn for review.

We will take care of your Editorial comments in the next revision or at the time of AUTH48 (whichever is earlier.)

Regards
-Gaurav
-----Original Message-----
From: Shawn Emery [mailto:shawn.emery@oracle.com] 
Sent: Wednesday, February 20, 2013 1:30 PM
To: secdir@ietf.org
Cc: draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt.all@tools.ietf.org; The IESG
Subject: Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04

I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. 
These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments.

This internet-draft describes a way to provide a client link-layer addresses in DHCPv6 Relay-Forward messages..

The security considerations section does exist and discusses an attack scenario involving rogue relay agents and clients where a DHCPv6 node could spoof the address of a separate DHCPv4 node.  Subsequently if a Dynamic DNS update is made then a dual-stack node could be made to connect to the DHCPv6 client instead of the DHCPv4 client.  To thwart such an attack the draft recommends that administrators configure IPsec between the DHCP server(s) and the relay agents.  Besides the security considerations of DHCP in general, I think that this document adequately covers the feature being introduced.

General comments:

None.

Editorial comments:

s/will help above mentioned scenarios/will help with the scenarios mentioned above/ s/used in wide/used in a wide/

Shawn.
--