Re: RFC 5006 and draft-ietf-v6ops-rogue-ra-01

Tim Chown <tjc@ecs.soton.ac.uk> Thu, 10 June 2010 21:45 UTC

Return-Path: <owner-v6ops@ops.ietf.org>
X-Original-To: ietfarch-v6ops-archive@core3.amsl.com
Delivered-To: ietfarch-v6ops-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D3D563A67CF for <ietfarch-v6ops-archive@core3.amsl.com>; Thu, 10 Jun 2010 14:45:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u-8f25CDy0LE for <ietfarch-v6ops-archive@core3.amsl.com>; Thu, 10 Jun 2010 14:45:30 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 670FC3A67C1 for <v6ops-archive@lists.ietf.org>; Thu, 10 Jun 2010 14:45:30 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-v6ops@ops.ietf.org>) id 1OMpXF-000JNm-Mo for v6ops-data0@psg.com; Thu, 10 Jun 2010 21:43:37 +0000
Received: from [2001:630:d0:f102::25e] (helo=falcon.ecs.soton.ac.uk) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.71 (FreeBSD)) (envelope-from <tjc@ecs.soton.ac.uk>) id 1OMpXC-000JNH-Ho for v6ops@ops.ietf.org; Thu, 10 Jun 2010 21:43:35 +0000
Received: from falcon.ecs.soton.ac.uk (localhost.ecs.soton.ac.uk [127.0.0.1]) by falcon.ecs.soton.ac.uk (8.13.8/8.13.8) with ESMTP id o5ALhUNs021538 for <v6ops@ops.ietf.org>; Thu, 10 Jun 2010 22:43:30 +0100
X-DKIM: Sendmail DKIM Filter v2.8.2 falcon.ecs.soton.ac.uk o5ALhUNs021538
DKIM-Signature: v=1; a=rsa-sha1; c=simple/simple; d=ecs.soton.ac.uk; s=200903; t=1276206210; bh=iCkqcFCD5lUiMr2dArltJ9X+FF0=; h=Mime-Version:Subject:From:In-Reply-To:Date:References:To; b=o6nsYgxHTJD0kHcLQCIskuqNEt+lVCMaxC06Ma3J/IQcp4oK8SMKp7XojgsaKaoAs 3CrcdWLizGL9qJDVkOafB5UC9vx2dlqjd+U5d1KrFCbnKleX5ayul055qOUhgu5qry DajJzrbj3LKUxCc6sQuNCW52ZqyaowiWLo+mt7mw=
Received: from gander.ecs.soton.ac.uk (gander.ecs.soton.ac.uk [2001:630:d0:f102::25d]) by falcon.ecs.soton.ac.uk (falcon.ecs.soton.ac.uk [2001:630:d0:f102::25e]) envelope-from <tjc@ecs.soton.ac.uk> with ESMTP id m59MhU0540051207x7 ret-id none; Thu, 10 Jun 2010 22:43:30 +0100
Received: from [192.168.1.12] (host213-123-213-183.in-addr.btopenworld.com [213.123.213.183]) (authenticated bits=0) by gander.ecs.soton.ac.uk (8.13.8/8.13.8) with ESMTP id o5ALhNt5010159 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO) for <v6ops@ops.ietf.org>; Thu, 10 Jun 2010 22:43:24 +0100
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Apple Message framework v1078)
Subject: Re: RFC 5006 and draft-ietf-v6ops-rogue-ra-01
From: Tim Chown <tjc@ecs.soton.ac.uk>
In-Reply-To: <4C115718.2090709@dougbarton.us>
Date: Thu, 10 Jun 2010 22:43:23 +0100
Content-Transfer-Encoding: quoted-printable
Message-ID: <EMEW3|e9cf131f7f21a5d2a8c2390e8683597dm59MhU03tjc|ecs.soton.ac.uk|0038CB1E-FA5D-4272-A585-E2B7F17B2B9F@ecs.soton.ac.uk>
References: <291B137B-7316-49A9-8C19-A606DCFCD019@wisc.edu> <5A07BF4F-33AB-4DB5-847B-EA1DF944C9C3@ecs.soton.ac.uk> <EMEW3|561d2bae90c9ddf8f65add274697b1eem58ESQ03tjc|ecs.soton.ac.uk|5A07BF4F-33AB-4DB5-847B-EA1DF944C9C3@ecs.soton.ac.uk> <A2C63160-0157-43E1-BCF7-2CC96B673AE7@cisco.com> <801675CF-788A-4583-9F2C-9362859DFBD6@cisco.com> <C1E1C597-CC56-48F0-AFD0-35C4496DBED5@ecs.soton.ac.uk> <EMEW3|dd6df153f280868f3fff0a6658747efcm59DXr03tjc|ecs.soton.ac.uk|C1E1C597-CC56-48F0-AFD0-35C4496DBED5@ecs.soton.ac.uk> <4C115718.2090709@dougbarton.us> <0038CB1E-FA5D-4272-A585-E2B7F17B2B9F@ecs.soton.ac.uk>
To: v6ops@ops.ietf.org
X-Mailer: Apple Mail (2.1078)
X-ECS-MailScanner: Found to be clean, Found to be clean
X-smtpf-Report: sid=m59MhU054005120700; tid=m59MhU0540051207x7; client=relay,ipv6; mail=; rcpt=; nrcpt=1:0; fails=0
X-ECS-MailScanner-Information: Please contact the ISP for more information
X-ECS-MailScanner-ID: o5ALhUNs021538
X-ECS-MailScanner-From: tjc@ecs.soton.ac.uk
Sender: owner-v6ops@ops.ietf.org
Precedence: bulk
List-ID: <v6ops.ops.ietf.org>

On 10 Jun 2010, at 22:20, Doug Barton wrote:
> 
> Speaking as a DNS person, I can do a LOT more harm on your network if I can successfully direct your clients onto my malicious name server than rerouting their prefix information, and the name server hack will be much harder to detect.

Doug, would be good to make these comments on the ietf@ietf.org list where final comments on the RFC5006-bis text are being sought, at the very least wrt the Security Considerations.

Tim