[secdir] Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04

Shawn Emery <shawn.emery@oracle.com> Wed, 20 February 2013 08:01 UTC

Return-Path: <shawn.emery@oracle.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost []) by ietfa.amsl.com (Postfix) with ESMTP id 1AF3C21F893E; Wed, 20 Feb 2013 00:01:17 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id AKpsYEcvNCdE; Wed, 20 Feb 2013 00:01:16 -0800 (PST)
Received: from aserp1040.oracle.com (aserp1040.oracle.com []) by ietfa.amsl.com (Postfix) with ESMTP id 6A4CB21F888B; Wed, 20 Feb 2013 00:01:16 -0800 (PST)
Received: from acsinet21.oracle.com (acsinet21.oracle.com []) by aserp1040.oracle.com (Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.1) with ESMTP id r1K81BXR013490 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Wed, 20 Feb 2013 08:01:12 GMT
Received: from acsmt358.oracle.com (acsmt358.oracle.com []) by acsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id r1K81BcE022034 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 20 Feb 2013 08:01:11 GMT
Received: from abhmt101.oracle.com (abhmt101.oracle.com []) by acsmt358.oracle.com ( with ESMTP id r1K81AOo019521; Wed, 20 Feb 2013 02:01:10 -0600
Received: from [] (/ by default (Oracle Beehive Gateway v4.0) with ESMTP ; Wed, 20 Feb 2013 00:01:09 -0800
Message-ID: <5124827A.3070407@oracle.com>
Date: Wed, 20 Feb 2013 00:59:54 -0700
From: Shawn Emery <shawn.emery@oracle.com>
User-Agent: Mozilla/5.0 (X11; SunOS i86pc; rv:10.0.11) Gecko/20121204 Thunderbird/10.0.11
MIME-Version: 1.0
To: secdir@ietf.org
References: <5112164C.3060009@oracle.com>
In-Reply-To: <5112164C.3060009@oracle.com>
X-Forwarded-Message-Id: <5112164C.3060009@oracle.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Source-IP: acsinet21.oracle.com []
Cc: draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt.all@tools.ietf.org, The IESG <iesg@ietf.org>
Subject: [secdir] Review of draft-ietf-dhc-dhcpv6-client-link-layer-addr-opt-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Feb 2013 08:01:17 -0000

I have reviewed this document as part of the security directorate's 
ongoing effort to review all IETF documents being processed by the IESG. 
These comments were written primarily for the benefit of the security 
area directors. Document editors and WG chairs should treat these 
comments just like any other last call comments.

This internet-draft describes a way to provide a client link-layer 
addresses in DHCPv6 Relay-Forward messages..

The security considerations section does exist and discusses an attack 
scenario involving rogue relay agents and clients where a DHCPv6 node 
could spoof the address of a separate DHCPv4 node.  Subsequently if a 
Dynamic DNS update is made then a dual-stack node could be made to 
connect to the DHCPv6 client instead of the DHCPv4 client.  To thwart 
such an attack the draft recommends that administrators configure IPsec 
between the DHCP server(s) and the relay agents.  Besides the security 
considerations of DHCP in general, I think that this document adequately 
covers the feature being introduced.

General comments:


Editorial comments:

s/will help above mentioned scenarios/will help with the scenarios 
mentioned above/
s/used in wide/used in a wide/