Re: I-D Action: draft-ietf-dhc-addr-notification-08.txt
Jen Linkova <[email protected]>
| Newsgroups | gmane.ietf.dhc |
|---|---|
| Message-ID | <CAFU7BASfLJEXaNFMktzc4MGwfOG_Df6vnFAXHikUhnX7ASrSGw@mail.gmail.com> |
On Fri, Jan 19, 2024 at 4:43 AM Lorenzo Colitti <[email protected]> wrote: > On Thu, Jan 18, 2024 at 2:13 AM Michael Richardson <[email protected]> wrote: >> >> >> } If revealing other hosts addresses and >> } alllowing onlink peer-to-peer communication is undesirable for a >> } given network segment, then layer2 (link-layer) isolation shall be >> } used. >> >> I think you'll get a BCP14 query on "shall" here from the IESG. >> (And I hate putting BCP14 into Security Considerations, so upcasing that >> would not be my choice) > > > Any reason not to just say MUST here? I think it's pretty straightforward. This mechanism relies on hosts multicasting their own addresses. If you have a problem with hosts seeing each other's addresses, then you MUST ensure that that happens at layer 2? I think it can be rephrased w/o using normative language. How about: "Layer2 (link-layer) isolation allows to mitigate this threat by blocking onlink peer-to-peer communication between hosts." -- Cheers, Jen Linkova _______________________________________________ dhcwg mailing list [email protected] https://www.ietf.org/mailman/listinfo/dhcwg