Re: [tcpm] feedcback on tcp-secure-05: suggested text

Joe Touch <touch@ISI.EDU> Tue, 18 July 2006 21:25 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1G2x4n-0001aT-4G; Tue, 18 Jul 2006 17:25:57 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1G2x4l-0001aJ-EN for tcpm@ietf.org; Tue, 18 Jul 2006 17:25:55 -0400
Received: from vapor.isi.edu ([128.9.64.64]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1G2x4k-0000vp-3e for tcpm@ietf.org; Tue, 18 Jul 2006 17:25:55 -0400
Received: from [128.9.160.144] (nib.isi.edu [128.9.160.144]) by vapor.isi.edu (8.11.6p2+0917/8.11.2) with ESMTP id k6ILOtH02066; Tue, 18 Jul 2006 14:24:55 -0700 (PDT)
Message-ID: <44BD519F.6040905@isi.edu>
Date: Tue, 18 Jul 2006 14:24:47 -0700
From: Joe Touch <touch@ISI.EDU>
User-Agent: Thunderbird 1.5.0.4 (Windows/20060516)
MIME-Version: 1.0
To: Fernando Gont <fernando@gont.com.ar>
Subject: Re: [tcpm] feedcback on tcp-secure-05: suggested text
References: <44B682AB.9010702@isi.edu> <7.0.1.0.0.20060715162015.085dce90@gont.com.ar> <44BB1965.9070305@isi.edu> <20060717180238.GE38453@hut.isi.edu> <20060718181852.GC50683@hut.isi.edu> <44BD430B.50401@cisco.com> <7.0.1.0.0.20060718174534.04c68e68@gont.com.ar>
In-Reply-To: <7.0.1.0.0.20060718174534.04c68e68@gont.com.ar>
X-Enigmail-Version: 0.94.0.0
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: touch@isi.edu
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 7baded97d9887f7a0c7e8a33c2e3ea1b
Cc: Randall Stewart <rrs@cisco.com>, tcpm@ietf.org, Ted Faber <faber@ISI.EDU>
X-BeenThere: tcpm@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: TCP Maintenance and Minor Extensions Working Group <tcpm.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:tcpm@ietf.org>
List-Help: <mailto:tcpm-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tcpm>, <mailto:tcpm-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============0481452820=="
Errors-To: tcpm-bounces@ietf.org


Fernando Gont wrote:
> At 17:22 18/07/2006, Randall Stewart wrote:
> 
>> With the minor tweak of pointing directly to
>> 6.1.1 .. I think what you have proposed is
>> the right set of wording.
> 
> That document discusses ICMP in the context of IPSec'ed connections. If
> the connection is already secured by IPSec, you wouldn't bother about
> "in window" attacks.

Sec 6.1.1 discusses handling untrusted ICMPs. In a non-IPsec
environment, all ICMPs fall into this category.

Joe

_______________________________________________
tcpm mailing list
tcpm@ietf.org
https://www1.ietf.org/mailman/listinfo/tcpm