Re: [v6ops] I-D Action: draft-ietf-v6ops-balanced-ipv6-security-01.txt

Marc Lampo <marc.lampo.ietf@gmail.com> Mon, 09 December 2013 07:48 UTC

Return-Path: <marc.lampo.ietf@gmail.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 335011ADEBF for <v6ops@ietfa.amsl.com>; Sun, 8 Dec 2013 23:48:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PFI_hHAt-8bZ for <v6ops@ietfa.amsl.com>; Sun, 8 Dec 2013 23:48:35 -0800 (PST)
Received: from mail-ve0-x231.google.com (mail-ve0-x231.google.com [IPv6:2607:f8b0:400c:c01::231]) by ietfa.amsl.com (Postfix) with ESMTP id A50A41AE1DA for <v6ops@ietf.org>; Sun, 8 Dec 2013 23:48:35 -0800 (PST)
Received: by mail-ve0-f177.google.com with SMTP id db12so3204065veb.22 for <v6ops@ietf.org>; Sun, 08 Dec 2013 23:48:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=AcOjfVSS4p3qWLmXkTAycaN7tZQwB0TcP59gGbk3sYs=; b=OyFAuAH9Qye2i9ZQUCvhVZNpnU/qc3OLrYQTuEarYXnjuOh/kqvgxHC8qJS0MAjJ5N RIPZW0+5Jsuy09oI7Vc1Cz/HeIEH3Zx2crr4/1PyO5iGcJJwoffjnehiYIzRohWHCpv8 nS3pNb3pWSK8vhmGl8A9J1KVNIHsb5lcf+0Fgr2PcuMfQw2kcOiYIDLc5Az/sPZzyllh nUIrGmWEXwThXZifFYHjgkSIjn58BfOExvtMqSwiyN7NcoTIZwvufZehgKuKKRXaLK+d p3tSZ9BMVnrJpTNE2cqBIl9Woidcah0O0OwX4h686axB2+Ppo55c57UVw7lWLQravCmw udSQ==
MIME-Version: 1.0
X-Received: by 10.58.6.239 with SMTP id e15mr1119607vea.29.1386575310721; Sun, 08 Dec 2013 23:48:30 -0800 (PST)
Received: by 10.58.227.66 with HTTP; Sun, 8 Dec 2013 23:48:30 -0800 (PST)
In-Reply-To: <CADDV1edv5cjW-Uspm4bfrwkjfs3wX-8VR0x3fHLR8pUvCLLeYw@mail.gmail.com>
References: <20131206153834.19120.52021.idtracker@ietfa.amsl.com> <CADDV1edv5cjW-Uspm4bfrwkjfs3wX-8VR0x3fHLR8pUvCLLeYw@mail.gmail.com>
Date: Mon, 09 Dec 2013 08:48:30 +0100
Message-ID: <CAB0C4xNjcEyoMMksUnaFHEAFLZ-3UMgahHo47nL9bpNUL0nyMQ@mail.gmail.com>
From: Marc Lampo <marc.lampo.ietf@gmail.com>
To: Guillaume Leclanche <guillaume@leclanche.net>
Content-Type: multipart/alternative; boundary="047d7b6d7f7ad998f504ed15387e"
Cc: "v6ops@ietf.org WG" <v6ops@ietf.org>
Subject: Re: [v6ops] I-D Action: draft-ietf-v6ops-balanced-ipv6-security-01.txt
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 07:48:38 -0000

Section 2, Threats, still lists 6 threats of which only one (the fourth) is
addressed by the proposed implementation and then, only partially.

In my opinion this is very misleading as Swisscoms customers might get the
impression their ISP's approach helps against the 5 other threats as well,
which it doesnot.
I'd delete the section altogether.

Kind regards,

Marc


On Fri, Dec 6, 2013 at 4:51 PM, Guillaume Leclanche <guillaume@leclanche.net
> wrote:

> Hello,
>
> This is a new version of the draft after having analyzed the WGLC
> comments and the Security Directorate review.
>
> A lot of text was modified to make sure that the document could not be
> mistaken for a recommendation. The filtering concept and examples are
> not changed, as the authors have chosen to stick to describing the
> documented practice.
>
> There are new mentions of PCP and UPnP, and the Security
> Considerations part was also detailed.
>
> Guillaume
>
> 2013/12/6  <internet-drafts@ietf.org>:
> >
> > A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> >  This draft is a work item of the IPv6 Operations Working Group of the
> IETF.
> >
> >         Title           : Balanced Security for IPv6 Residential CPE
> >         Author(s)       : Martin Gysi
> >                           Guillaume Leclanche
> >                           Eric Vyncke
> >                           Ragnar Anfinsen
> >         Filename        : draft-ietf-v6ops-balanced-ipv6-security-01.txt
> >         Pages           : 9
> >         Date            : 2013-12-06
> >
> > Abstract:
> >    This document describes how an IPv6 residential Customer Premise
> >    Equipment (CPE) can have a balanced security policy that allows for a
> >    mostly end-to-end connectivity while keeping the major threats
> >    outside of the home.  It is documenting an existing IPv6 deployment
> >    by Swisscom and allows all packets inbound/outbound EXCEPT for some
> >    layer-4 ports where attacks and vulnerabilities (such as weak
> >    passwords) are well-known.  The policy is a proposed set of rules
> >    that can be used as a default setting.  The set of blocked inbound
> >    and outbound ports is expected to be updated as threats come and go.
> >
> >
> > The IETF datatracker status page for this draft is:
> > https://datatracker.ietf.org/doc/draft-ietf-v6ops-balanced-ipv6-security
> >
> > There's also a htmlized version available at:
> > http://tools.ietf.org/html/draft-ietf-v6ops-balanced-ipv6-security-01
> >
> > A diff from the previous version is available at:
> >
> http://www.ietf.org/rfcdiff?url2=draft-ietf-v6ops-balanced-ipv6-security-01
> >
> >
> > Please note that it may take a couple of minutes from the time of
> submission
> > until the htmlized version and diff are available at tools.ietf.org.
> >
> > Internet-Drafts are also available by anonymous FTP at:
> > ftp://ftp.ietf.org/internet-drafts/
> >
> > _______________________________________________
> > v6ops mailing list
> > v6ops@ietf.org
> > https://www.ietf.org/mailman/listinfo/v6ops
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops
>