Re: [v6ops] IPv6-Only Preferred DHCPv4 option

Jen Linkova <furry13@gmail.com> Wed, 04 December 2019 21:40 UTC

Return-Path: <furry13@gmail.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 934D712004C; Wed, 4 Dec 2019 13:40:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.748
X-Spam-Level:
X-Spam-Status: No, score=-1.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iP3iuZkzdlQQ; Wed, 4 Dec 2019 13:40:11 -0800 (PST)
Received: from mail-qk1-x730.google.com (mail-qk1-x730.google.com [IPv6:2607:f8b0:4864:20::730]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4598B120033; Wed, 4 Dec 2019 13:40:11 -0800 (PST)
Received: by mail-qk1-x730.google.com with SMTP id d124so1435753qke.6; Wed, 04 Dec 2019 13:40:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=IY+8xJ+TPb41+qwCJgVlEg37ypZjQ354ynM9eXaVuuw=; b=diqsCcux3gOUuXZPaaIOBqKuQbxMmUAKZhtr6lgDM53sAMhRE6674fCw5yHpNE4WT5 WknLe41HvB+s+eq16fFYpalJLNb7Wykhj39QNncsrAme7QJeLXiEiJuH6CSQwMEY8wr7 d99103D1h0FojfmUVu/F1Y4K8ZIoE3J0ervf0DCSTZa2Tp+z0jEz94EzF/SgrGhgUFnR F9sX+ST/9i/JJs3LUSbuw2tTNXcLSmAWRJNSep8p9mPFs1EYbO+ARMEaZdvpYZAkrA2m 35I6pAr44plByKFYS79wA6vR86EYJsN0OX6SN6C4P3T72xvf6INikfz18FG+TeAmDsmI lQ3A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=IY+8xJ+TPb41+qwCJgVlEg37ypZjQ354ynM9eXaVuuw=; b=qGyjlTWZhCTLdg/7cJeKAtJmBrZyrTzxwTanYRkkWSLPYuYrNXGU2QFVmpCOemmwyk xnEYhaxZO6vuaxYrcdw5PhXneL0FUl1TCoVn9xAb3Majq+jZpqvyFuJt9PCVE9aWe7lA sM6B38AujjuhcyviqVifMIK9Jo2avu+ROFrPuacy3RoE1nyGXI99NnwK9ci5lFZTHi7t Cx3gX82GmvG/lY1tqC9A+0WJopUAWuoIdKwmjFYIJG3/6IdZrbDie0slaVYZou3MCKN+ BkOSMcaEtrbgf38KTiSUigLndViXJtYu9FbHRq89zfIHXKGOwPGiFkG9pcnJcJKdzn5F dIDw==
X-Gm-Message-State: APjAAAUKnPjE5luyxIQ28rXy6UEhoWIGoyQkGebP/4/xk/FIsTb698YT X8Z1pGrdh/jwjuPNv8eH66Wk4D1bvexO2FeXy/U+Qw==
X-Google-Smtp-Source: APXvYqxy7BkXBkxLIxfbr6Dqq3BmRWmvZVBhKTW5Ky/kL+JL4Mv2siCQzjHbM/NA4Br1Lij9gOYYY47V2RXYxlmiIac=
X-Received: by 2002:a37:9fce:: with SMTP id i197mr5050786qke.466.1575495610062; Wed, 04 Dec 2019 13:40:10 -0800 (PST)
MIME-Version: 1.0
References: <CAFU7BAR1JLUZps=CAqJfeQtUf-xQ88RYvgYrPCP+QP0Ter7YFg@mail.gmail.com> <8736e0gqu2.fsf@miraculix.mork.no>
In-Reply-To: <8736e0gqu2.fsf@miraculix.mork.no>
From: Jen Linkova <furry13@gmail.com>
Date: Thu, 05 Dec 2019 08:39:58 +1100
Message-ID: <CAFU7BATL6i0Eu7xj=3u-wd-dswMeOFXbqynVWqjEfhddBisQig@mail.gmail.com>
To: Bjørn Mork <bjorn@mork.no>
Cc: dhcwg@ietf.org, draft-link-dhc-v6only@ietf.org, V6 Ops List <v6ops@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/eQfylEPFMwVZ3oMM8YlUcfa8SzQ>
Subject: Re: [v6ops] IPv6-Only Preferred DHCPv4 option
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Dec 2019 21:40:13 -0000

On Thu, Dec 5, 2019 at 12:31 AM Bjørn Mork <bjorn@mork.no> wrote:
> Why can't the client just release the IPv4 address when it finds it has
> IPv6 connectivity?  This would also avoid the problems you introduce
> when the network falsely claims IPv6 support.

One reason has been mentioned by Lorenzo: releasing an IPv4 address is
disruptive to applications (point taken, we'll update the draft text
to make it clear).
Another reason is that it would bring back all objections we heard
about IPv6-only RA flag: 'an attacker sends an IPv6 packet - and
IPv4-only network might not have IPv6 security in place - and breaks
IPv4'. What we are proposing is that DHCP server must be explicitly
configured as 'this network/pool is IPv4-as-a-service' so to do any
harm
the attacker needs to deploy a rogue DHCP - in which case your IPv4 is
trouble anyway.

-- 
SY, Jen Linkova aka Furry