Re: [v6ops] Implementation Status of PREF64

Fernando Gont <fernando.gont@edgeuno.com> Thu, 30 September 2021 08:33 UTC

Return-Path: <fernando.gont@edgeuno.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2BBD3A0819 for <v6ops@ietfa.amsl.com>; Thu, 30 Sep 2021 01:33:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=edgeuno.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0_yZ8j4kRBwd for <v6ops@ietfa.amsl.com>; Thu, 30 Sep 2021 01:32:56 -0700 (PDT)
Received: from NAM11-BN8-obe.outbound.protection.outlook.com (mail-bn8nam11on2125.outbound.protection.outlook.com [40.107.236.125]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB8913A07F8 for <v6ops@ietf.org>; Thu, 30 Sep 2021 01:32:55 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aAtkEeW4daW27fPVXxfls7K+WOXN/nVVH4bR0AoVDZlqbl/roix9lsG4kM+/3SyJ3tTMZ2UYXSsHyYbRi/iRiuDDO2FYRvD573shcEcLJD8xve8K2YHkhh0vC0v7g2h6EOAIFxJaFqfMMzeYaSzJQdO2TBcpaqb4LyguTntGHhF8QkxowICByNvrYH0I8NxxMvGiFlEICBmQsDV56bvnUxiagBXam9UXPAEvGVmFku3in4Fy+4IL5Qb19oUnBclM8IqN+CuwsQ2oYd5BDzoirj9hzejINODBWZ4BdnsWr9vhaEw27YZ4ydWsF6aIHFgOrucJ/WdV1+lFa7XhfArqdQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=lBUJWWbXY9mTt164SYIVfDvtnwrcrFi9MR7NnmNooGE=; b=aceXb0sPFr5wOhytc01sU7kUtThKp9qc5h3H3FXnCevJAiO/1eu02FzdvS9DW2xc0iU+singObGxVrnmoZXOmtGdmOIN96/EQoUb3zu4PB5vqX8DGAPp7gf8JgJlsiQ9L7F6jj9jAwAlfQZGeclqpbUg+06i2FN1JJZgPUysnOvcvb7PHBDnYTDWdYtfAkGGSaB3ULV0iUKOyq3k/I8VSnvWL4LVIJpP9Km+Fuf4C2FBlDdTflqTxqn/Xesw/oWZuw0PU5Wt31wjzZ4IXMYbSICIj6v6LN4bphjpZ6qKxUJOVasFENI2N0dyv/RppNXmIOpG0wbBJ0h37g05IYHQjA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=edgeuno.com; dmarc=pass action=none header.from=edgeuno.com; dkim=pass header.d=edgeuno.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=edgeuno.onmicrosoft.com; s=selector1-edgeuno-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=lBUJWWbXY9mTt164SYIVfDvtnwrcrFi9MR7NnmNooGE=; b=fNFt44gM5iQ++ZoDC8KfyPV1UpBXG1wvfxQRGfPmY2tGJl4Ql1k79KCVAP8UlNT8psAtwCA5TnyS3nCKsf2aIOnUi8sUIdaWTmVREbzZRBaBVjpUqA08COaS0WkcYnhuf+xLRxz7wLCBq3k8L9q53FO/GuT/5HR7ZFy4VZMAI6E=
Authentication-Results: edgeuno.com; dkim=none (message not signed) header.d=none;edgeuno.com; dmarc=none action=none header.from=edgeuno.com;
Received: from BY3PR05MB8578.namprd05.prod.outlook.com (2603:10b6:a03:3cd::10) by SJ0PR05MB8645.namprd05.prod.outlook.com (2603:10b6:a03:386::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4566.8; Thu, 30 Sep 2021 08:32:53 +0000
Received: from BY3PR05MB8578.namprd05.prod.outlook.com ([fe80::5d1a:6f5:58a5:87e1]) by BY3PR05MB8578.namprd05.prod.outlook.com ([fe80::5d1a:6f5:58a5:87e1%9]) with mapi id 15.20.4544.006; Thu, 30 Sep 2021 08:32:53 +0000
To: Lorenzo Colitti <lorenzo=40google.com@dmarc.ietf.org>, Gert Doering <gert@space.net>
Cc: V6 Ops List <v6ops@ietf.org>, JORDI PALET MARTINEZ <jordi.palet=40consulintel.es@dmarc.ietf.org>
References: <6E95834D-12B3-447B-8326-8EDE9DC6FFB1@delong.com> <CAO42Z2zA-4cK489nxKsWUN8vvU0eAiz-jS0e-_eWPg+OmP8wLw@mail.gmail.com> <DDA36020-90CC-471B-83AD-3D98950F1164@delong.com> <CAO42Z2wdoSdJDOB2Zo0=ZK0ecOARRsdg2nbHZGSDOhryPbLfDw@mail.gmail.com> <F2BD0A42-E9AD-45DD-999A-638E73BE1177@delong.com> <CAKD1Yr2K3Gd3JD=NJFOoH6GYgs-8ACxRQB9-sKJ7cbF4_hxsow@mail.gmail.com> <0B533C71-5DB0-410D-A5A3-7E8FD559F214@delong.com> <CAKD1Yr3NoYfNT7+OVJoCCdgdif6AHHw29tNCPttS=-NuRZKv3w@mail.gmail.com> <DM6PR02MB692426B0EEDDC2C4D78D8EC0C3A89@DM6PR02MB6924.namprd02.prod.outlook.com> <EFC78F4B-873B-42EE-8DC5-04C29758B0D0@consulintel.es> <YVNhdioAbeO9p2/G@Space.Net> <CAKD1Yr2+Y59v81mPBn4Y3u0LRX7TzahbnaF1hVUZ+NSf0Jj_4g@mail.gmail.com>
From: Fernando Gont <fernando.gont@edgeuno.com>
Message-ID: <9f6087d1-98e9-4521-902a-fb032e5eb88e@edgeuno.com>
Date: Thu, 30 Sep 2021 05:32:44 -0300
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.13.0
In-Reply-To: <CAKD1Yr2+Y59v81mPBn4Y3u0LRX7TzahbnaF1hVUZ+NSf0Jj_4g@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
X-ClientProxiedBy: CP4P284CA0026.BRAP284.PROD.OUTLOOK.COM (2603:10d6:103:126::17) To BY3PR05MB8578.namprd05.prod.outlook.com (2603:10b6:a03:3cd::10)
MIME-Version: 1.0
Received: from [IPv6:2800:810:464:91e:bccd:3a74:b05b:6086] (2800:810:464:91e:bccd:3a74:b05b:6086) by CP4P284CA0026.BRAP284.PROD.OUTLOOK.COM (2603:10d6:103:126::17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4566.14 via Frontend Transport; Thu, 30 Sep 2021 08:32:51 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 1d6fa653-891b-47ba-41ca-08d983ece53a
X-MS-TrafficTypeDiagnostic: SJ0PR05MB8645:
X-MS-Exchange-Transport-Forked: True
X-Microsoft-Antispam-PRVS: <SJ0PR05MB86450697AF537BC7DC442634E5AA9@SJ0PR05MB8645.namprd05.prod.outlook.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:7691;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: AsvHloh7B985IG8Gw42Hf/ekmSAW/otNkzex+3PVGI8S1KtzwEn5GHZ4jDKXqF77LQBmSpKUHEl+Ut3o7OIQQSXHIDtRlYHCilVhct9P3GTKrIZ0yadrstbQmwkHUccNBiv3Ti3rJQzPLHIPkPd++QcubQVy4dWxa7oxyJWIc3tFKrtJdwW6GN8jYNc+UIa5kgIL+MYRd4Fc4XCFzickmJldJ5g+W7eg15eUS29KvgFKhIpAlE+xOpeW6okgNetuiDrl7+GnL91XDLBjpjkc8nhUQPMYOKwSwzMCbWs0uQwuopFyaJ4B+FmmKo2bovst6Pwyfz904XO4XxC+9OGnerFpNyKIM5ch/qRjkviTkTGy3vmk0Qxg4IAfJ7aIgsSqK5IpTIN7scIqIcS9cnrErr1B1srlDhlc0ia/ZQe7yVyfPw08d/igvq2LjJXYEavvn2NCtamfsm1gm8U+bOBB/1BE/uVfzMyf0cYQiDtTF93ofcWFmJljuXP8D4EPjtUD7ClenUjXEBBy/28AhbZY6akjHAJHA2fPmFp1tTLqVYDb3wY0YFc6lAkSLIAQHxQ2urKhk+jRo8uskBBfe/94bSwqviKZi0/z56+asoAsL70e7CuSq3VDBvvWoPA0Tz6Maf/rTqiUsoV4nfUoIgt6MD/z0PpXM8/t3nGsT/50sueC9zRi3u6QZBQOTihZhCEgOo69uJn8Lv6v5BqaDiA5ysftXlPWtLsZg/vZISo0I/0n/EiK/4tIEuaMs2eixGVKdYYqXSJki/73+pSIsXXGUxGFr60yRozwtIdvbPksScBytK8dod3LJwWYzYMPyIrY
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY3PR05MB8578.namprd05.prod.outlook.com; PTR:; CAT:NONE; SFS:(366004)(8676002)(2616005)(5660300002)(31686004)(86362001)(66476007)(36756003)(6666004)(4326008)(186003)(83380400001)(508600001)(66946007)(2906002)(66556008)(52116002)(38100700002)(8936002)(53546011)(31696002)(316002)(110136005)(6486002)(54906003)(44832011)(45980500001)(43740500002); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: 3kdm32eA7ar1f19flyCGPM/RplquQcQ5x8/ywDa6yUiG49LKdWlmRc2rZpcfUz3Bq0uLVJRDqgf5swjuFwP5kwdsUswU124KamnMtAT635LAIWTRiXSQ6nBGXxSfOlDbseFvPS29oxJ6CjvLjX+XpWH2NpMQmttZ0mYolvIpKOfdFe6W/9pgsGZKfLT6wxxFVyq2gTPec5xk5DjODL/5FnBKuv7eBx8V5fd2fMaBuHbZTefn6K9sR+qdbNl8fUzn3FIlPx9nGBTqPfdhdDgwxYsDrh+hCdbBFQqRiua1OaFPHFxQKcLc42jcSgu3CHxcEsT4EIrLKvPjF3/gC6OiTjWtqr/b1vNPsUAPjVKrr5p0YJnGXa2kTaxrEZQikxXylRLOgM/7aV5BFvC9z6C2Cm6nsBems/ArNPMil+VMSgWhiyCzxQqw0Lb4K3OTZhAnTWa2pmliJn8B8Y+tazIxsTvwmZeiF2Bu45lKLvYS3P5BXd3nHBbKkYsSvmrjtfed2E9OzLOADKJCIJGyv3kYGlQac1wSV4FgFVyCAxC7NNsXccKsA5a6EDigf9NUZFbKQJquYTRCx3rIR+dw60fmnk6wUOLntFSCUuI6ddqV+/yGjLQ8QUlu8ylJ2pGgFcZ/uTjj1xUHtvYuTejRumAHEW3MYvvCf83GQ2+WMo+qE+wz83LJjvxIsVt1FIfevEykPj7z8odsJM557SHPp6EaA1Z736v77FxQEk/kHty0wPXes6Gw4MKHw7UuE/upUfh2aPZ7cJs4qyxPOZ+Cul35ZZLlaNOUAt1XL4NfLOp/L+zXBJmxblq4nBQ8zUl3PommM/4/SIDtulTtaP5jLW1Fa9MdEiCjaDJEQ8G0GRqoTGCNPuFMmJ6NEn3h2+pn5wfUrW5AAfWpV9BWCLG97sQS2sUQ3uGaOPD+qQA0/aHzP3tNqxX+KtyDdaC/89KGdjfVzVHSKxZ/FbGUngo7vZ7ID76xnkn0okdfuTApWk9PdFPXjEggRXDorF7qjJg5T4VQNHM8ahTqQBXzrY4Ka7KRvaWM+vC/iu1x6V5IxRnwCCOEwHVJBFhPy471ccaNcoWDbsLhZ9Vz0963gOjor3OZ3iSfNQ1wAFLK0v0dFKH73hb7S11m4NBYRHduU3AA05j62UoOV15Mfn0jzqiXC8idbkkK4WrB8zLX1MhDOsTQ53h+uEHT2XyIYLH9KLORHjAw3pmmSkYh9HDF3dn5ujUeQzTDaB+RFMl9Bmvp/YXxiD9hv16k2yOMlZbBvKai0SYbQlMSJe4OVJrnrEsWMIgBykUj62banq1IS75X7hzPh2O6IiHru+CxRSZp7GmXg1ImNrjQnOttoDZ2pWMoB3TKtlHOi+ieiUgbIUh2doXsXjtM2Yj0uxrmGamCHLAnK6x+
X-OriginatorOrg: edgeuno.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1d6fa653-891b-47ba-41ca-08d983ece53a
X-MS-Exchange-CrossTenant-AuthSource: BY3PR05MB8578.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 Sep 2021 08:32:53.2310 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 20879dba-fabf-45da-8300-60b8ce560217
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: SyS1gyJ0eZMQX1r33rExZf+c9gobmceQlQ8Ae3M7lIAKG1LTjmeRWKp0x1bCo8EzIYcgxxatjsNfByZ6B71O1v3vWpoV7QXRqUxlbUr4LTU=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR05MB8645
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/vfxJJrDGnCD7JCNejrgdp6Iql3s>
Subject: Re: [v6ops] Implementation Status of PREF64
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Sep 2021 08:33:01 -0000

On 30/9/21 02:53, Lorenzo Colitti wrote:
> On Wed, Sep 29, 2021 at 3:40 AM Gert Doering <gert@space.net
> <mailto:gert@space.net>> wrote:
>
>     As a matter of fact, I know of at least one deployment in a "fortune
>     500"
>     company that was seriously impaired due to lack of DHCPv6 support in
>     Android.  They want control over address assignment, tracking of address
>     assignments, and DHCP is the machinery they use for it (plus NAC, making
>     sure that only assigned IPv6 addresses can be used).
>
>     But they want to support Android devices.
>
>     So, still no IPv6 today...
>
>
> Is there any other way to break this logjam than to implement DHCPv6
> IA_NA and accept one IPv6 address per device? What about DHCPv6 PD or
> /64-per-host? What about resurrecting draft-ietf-dhc-addr-registration
> <https://datatracker.ietf.org/doc/draft-ietf-dhc-addr-registration/>, so
> the device can inform the network of addresses it has created?

Part of the problem here is the assumption that in all scenarios hosts
are and/or should be free to choose.

The reality is that, in a corporate network, "my network, my rules". --
that also applies to SLAAC -- just not gracefully -- since network
devices can limit the number of addresses per device.

SLAAC can be nice ("good" or "doable") for many scenarios. But there are
certainly others where the admin or security team wants to apply policy.
And SLAAC doesn't play nice there....

--
Fernando Gont
Director of Information Security
EdgeUno
PGP Fingerprint: DFBD 63E3 B248 AE79 C598 AF23 EBAE DA03 0644 1531




“This communication is the property of EdgeUno or one of its group companies and/or affiliates. This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and if you are not the intended recipient be aware that any non-explicitly authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, and will be considered a criminal offense. Please notify legal@edgeuno.com about the unintended receipt of this electronic message and delete it.”