Re: I-D Action: draft-ietf-dhc-addr-notification-08.txt

Jen Linkova <[email protected]>
Newsgroups gmane.ietf.dhc
Message-ID <CAFU7BASfLJEXaNFMktzc4MGwfOG_Df6vnFAXHikUhnX7ASrSGw@mail.gmail.com>
On Fri, Jan 19, 2024 at 4:43 AM Lorenzo Colitti <[email protected]> wrote:
> On Thu, Jan 18, 2024 at 2:13 AM Michael Richardson <[email protected]> wrote:
>>
>>
>> }           If revealing other hosts addresses and
>> }          alllowing onlink peer-to-peer communication is undesirable for a
>> }          given network segment, then layer2 (link-layer) isolation shall be
>> }          used.
>>
>> I think you'll get a BCP14 query on "shall" here from the IESG.
>> (And I hate putting BCP14 into Security Considerations, so upcasing that
>> would not be my choice)
>
>
> Any reason not to just say MUST here? I think it's pretty straightforward. This mechanism relies on hosts multicasting their own addresses. If you have a problem with hosts seeing each other's addresses, then you MUST ensure that that happens at layer 2?

I think it can be rephrased w/o using normative language.
How about:
"Layer2 (link-layer) isolation allows to mitigate this threat by
blocking onlink peer-to-peer communication between hosts."

-- 
Cheers, Jen Linkova

_______________________________________________
dhcwg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dhcwg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.