Re: [secdir] sector review of draft-ietf-pcp-server-selection-07
"Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com> Mon, 05 January 2015 06:24 UTC
Return-Path: <tireddy@cisco.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CC281A1BD2; Sun, 4 Jan 2015 22:24:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level:
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rgf9kggOZTy0; Sun, 4 Jan 2015 22:24:57 -0800 (PST)
Received: from alln-iport-6.cisco.com (alln-iport-6.cisco.com [173.37.142.93]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 46D6D1A1BFA; Sun, 4 Jan 2015 22:24:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3630; q=dns/txt; s=iport; t=1420439097; x=1421648697; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=QlB6arKEKiRkJOsaEZ2VMd6Ya+Eca+d9838eHc3Wghc=; b=hhZ3GXN+CFyHgPT6Lw45z3OcyVBQINKil23ZRAAJ08D+kzrEiJrpdVr8 HVuMJuM9HJ+Tej8smV7QSrohd/zpusnrTWr2KWcRW+2+uijtdoRfsIJ5j KkCu+9g9s21zyQYpuVx08jLVmo3HCd0Q9x/4LfjIzKplwxH+i5OUi3aOz w=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AnMFACgtqlStJA2N/2dsb2JhbABcgwaBKgSDAcBziBYCHGgWAQEBAQF9hAwBAQEDASMRUQQCAQYCEQQBAQMCBh0DAgICMBQBCAgCBAESCIgcCItNnGiTMgEBAQEBAQEBAQEBAQEBAQEBAQEBAReBIY4lFiIGgmIugRMBBI4VigCCZY1eIoNubwGBRH4BAQE
X-IronPort-AV: E=Sophos;i="5.07,698,1413244800"; d="scan'208";a="110294516"
Received: from alln-core-8.cisco.com ([173.36.13.141]) by alln-iport-6.cisco.com with ESMTP; 05 Jan 2015 06:24:56 +0000
Received: from xhc-aln-x11.cisco.com (xhc-aln-x11.cisco.com [173.36.12.85]) by alln-core-8.cisco.com (8.14.5/8.14.5) with ESMTP id t056OuO6012351 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 5 Jan 2015 06:24:56 GMT
Received: from xmb-rcd-x10.cisco.com ([169.254.15.160]) by xhc-aln-x11.cisco.com ([173.36.12.85]) with mapi id 14.03.0195.001; Mon, 5 Jan 2015 00:24:56 -0600
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: Chris Inacio <inacio@cert.org>, "secdir@ietf.org" <secdir@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>, "draft-ietf-pcp-server-selection.all@tools.ietf.org" <draft-ietf-pcp-server-selection.all@tools.ietf.org>
Thread-Topic: sector review of draft-ietf-pcp-server-selection-07
Thread-Index: AQHQJ+uaAUxKUQpnyUK05uEkCW52tJyxD3qw
Date: Mon, 05 Jan 2015 06:24:55 +0000
Message-ID: <913383AAA69FF945B8F946018B75898A35526351@xmb-rcd-x10.cisco.com>
References: <0FD1DF78-8EEC-44F2-B715-9CD7405C07D6@cert.org>
In-Reply-To: <0FD1DF78-8EEC-44F2-B715-9CD7405C07D6@cert.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.65.66.17]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/hPLXTGZCMmgTYANg8CnBjYA1B5I
X-Mailman-Approved-At: Mon, 05 Jan 2015 02:10:24 -0800
Subject: Re: [secdir] sector review of draft-ietf-pcp-server-selection-07
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Jan 2015 06:24:59 -0000
Hi Chris, Thanks for the review. Please see inline > -----Original Message----- > From: Chris Inacio [mailto:inacio@cert.org] > Sent: Sunday, January 04, 2015 12:27 PM > To: secdir@ietf.org; iesg@ietf.org; draft-ietf-pcp-server- > selection.all@tools.ietf.org > Subject: sector review of draft-ietf-pcp-server-selection-07 > > > > I have reviewed this document as part of the security directorate’s ongoing > effort to review all IETF documents being processed by the IESG. These > comments were written with the intent of improving security requirements > and considerations in IETF drafts. Comments not addressed in last call may > be included in AD reviews during the IESG review. Document editors and WG > chairs should treat these comments just like any other last call comments. > > Generally the document is in good shape, and I would like to see one minor > issue at least commented upon. > > I have a single security related comment on this draft; the last sentence of > section 3: > > > For efficiency, the PCP client SHOULD use the same Mapping Nonce for > > requests sent to all IP addresses belonging to the same PCP server. > > Normally, I would simply say this is a crazy recommendation. But after > looking a little into what the Nonce is used for in the PCP protocol, I am > slightly less distraught. This Nonce does not appear to necessarily provide > any huge amount of security except allowing the client to generate a unique > token per PCP server. Presumably there is a general MITM attack on the PCP > protocol related to the Nonce as a transaction ID which is prevented by using > other security protocols, TLS, etc. (And another well known attack with the > THIRD_PARTY option and lack of authentication…) Therefore, this Nonce is > critical as a synchronization point between the client and the potential PCP > server. It would be nice (assuming all that is correct) to make that clear in > the document, especially with a recommendation to reuse the Nonce. We will add the following text to Security considerations section to address this comment: The Mapping Nonce value only provides protection against off-path attacks and PCP authentication [I-D.ietf-pcp-authentication] must be used to defend against man-in-the-middle attack. > > > Nits: > > In Figure 1, the lines are not aligned to the “+” on the diagrams. > > In Figure 3, “rtr1” is missing a “+” on the right side connection from the top. Thanks, will fix the above nits in next revision. Cheers, -Tiru > > > -- > Chris Inacio > inacio@cert.org > >
- [secdir] sector review of draft-ietf-pcp-server-s… Chris Inacio
- Re: [secdir] sector review of draft-ietf-pcp-serv… mohamed.boucadair
- Re: [secdir] sector review of draft-ietf-pcp-serv… Tirumaleswar Reddy (tireddy)
- Re: [secdir] sector review of draft-ietf-pcp-serv… Prashanth Patil (praspati)
- Re: [secdir] sector review of draft-ietf-pcp-serv… Ted Lemon
- Re: [secdir] sector review of draft-ietf-pcp-serv… Prashanth Patil (praspati)