Re: [tcpm] draft-zimmermann-tcpm-undeployed

Joe Touch <touch@isi.edu> Tue, 21 October 2014 17:45 UTC

Return-Path: <touch@isi.edu>
X-Original-To: tcpm@ietfa.amsl.com
Delivered-To: tcpm@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1EEFE1A6F32 for <tcpm@ietfa.amsl.com>; Tue, 21 Oct 2014 10:45:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ecxFPHnyS3y8 for <tcpm@ietfa.amsl.com>; Tue, 21 Oct 2014 10:45:20 -0700 (PDT)
Received: from boreas.isi.edu (boreas.isi.edu [128.9.160.161]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 896201A6F10 for <tcpm@ietf.org>; Tue, 21 Oct 2014 10:45:20 -0700 (PDT)
Received: from [128.9.160.211] (mul.isi.edu [128.9.160.211]) (authenticated bits=0) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id s9LHiTw3008628 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Tue, 21 Oct 2014 10:44:29 -0700 (PDT)
Message-ID: <54469B7C.4080004@isi.edu>
Date: Tue, 21 Oct 2014 10:44:28 -0700
From: Joe Touch <touch@isi.edu>
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
MIME-Version: 1.0
To: "Zimmermann, Alexander" <Alexander.Zimmermann@netapp.com>, Pasi Sarolahti <pasi.sarolahti@iki.fi>
References: <24059_1413799841_5444DFA1_24059_161_1_FEF952E9-DC04-42BC-932A-D9E97BA1A193@netapp.com> <61E1E847-C0D4-489A-8448-BC6A1306A6EC@iki.fi> <06092CB9-19AE-4D57-98BD-27DA1014E763@netapp.com> <C467928F-B80B-4516-80A4-814F15B4ECEB@iki.fi> <D0A83836-BD0D-4F1F-B8E1-FBCB23645D6D@netapp.com>
In-Reply-To: <D0A83836-BD0D-4F1F-B8E1-FBCB23645D6D@netapp.com>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 8bit
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
Archived-At: http://mailarchive.ietf.org/arch/msg/tcpm/6hH5BnJpnrVm0byg5OkjB6UHD3c
Cc: "tcpm@ietf.org Extensions" <tcpm@ietf.org>
Subject: Re: [tcpm] draft-zimmermann-tcpm-undeployed
X-BeenThere: tcpm@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tcpm>, <mailto:tcpm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tcpm/>
List-Post: <mailto:tcpm@ietf.org>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Oct 2014 17:45:22 -0000


On 10/21/2014 4:47 AM, Zimmermann, Alexander wrote:
...
>> So why is it no longer recommended? The IESG statement also calls for explanation for the transition.
> 
> See for example this thread: http://www.ietf.org/mail-archive/web/ietf/current/msg81410.html
> (or http://marc.info/?t=137611379100002&r=1&w=2)
> 
> 	Wes: „There are probably security issues“
> 	Joe: „There are semantics issues to; see draft-touch-tcp-portnames-00 for information“
> 	Bob Braden: „Indeed, TCPMUX is quite historic… it represents a Road Not Taken“
> 
> Another source is: draft-touch-tcpm-sno-02.txt
> 
> If Joe, Wes or Bob think now that we should not obsolete TCPMUX, fine by me.
> I thought we reflect w/ draft-zimmermann-tcpm-undeployed their (the community)
> opinion. 

It's a huge hole in any sort of firewall, not to mention numerous
specific attacks. I support obsoleting it, but the reason needs to be
clear - severity of vulnerability and lack of deployed clients, NOT lack
of deployed servers with this capability.

I.e., although (x)inetd understands incoming requests, unmodified user
applications can't simply change to port 1 and work; they need to send
the actual service name as user data, and I don't know of any that do that.

Joe