Re: LC: draft-ietf-forces-protocol-10.txt>>ForCES message size?
Jia Fenggen <[email protected]> Mon, 18 Jun 2007 14:59:07 +0800
| Newsgroups | gmane.ietf.forces |
|---|---|
| Message-ID | <[email protected]> |
I agree with you about that and we have to find a way to solve that in protocol and not in implementation,do you have good suggestion? Yours,Fenggen >From: [email protected] >To: [email protected] >Subject: Re: LC: draft-ietf-forces-protocol-10.txt>>ForCES message size? >Date: Sat, 16 Jun 2007 16:12:54 -0400 > > >Hi, > > > >If the implementation is to be security-aware, the message handlers of the API mustknow about > >thelegitimate size of eachmessagebeing processed.Otherwise, you run the risk of buffer overrun > >attacks. I believe someone has already raised this concern. > > > >Regards, > >Alex. > > >-----Original Message----- >From: Jia Fenggen <[email protected]> >To: [email protected] >Sent: Thu, 14 Jun 2007 12:45 am >Subject: Re: [Fwd: RE: LC: draft-ietf-forces-protocol-10.txt>>ForCES message size?] > > > >For association setup message,FE can unsolicited report some of its LFB attributes to the CE,what the CE handles if the FE send it an arbitrary association message,it's may bring problem to the CE? >Yours,Fenggen > >From: "Joel M. Halpern" <[email protected]> > >Reply-To: "Joel M. Halpern" <[email protected]> > >To: [email protected] > >Subject: Re: [Fwd: RE: LC: draft-ietf-forces-protocol-10.txt>>ForCES message size?] > >Date: Tue, 12 Jun 2007 08:14:45 -0400 > > > >I would strongly prefer not to complicate the protocol by defining a >size limit and then trying to figure out what to do if the messages >are too big. > >The Redirect channel is supposed to be congestion controlled. > >Also, since redirect packets ought not be reassembeled (they ought >to be the packet as received on the interface by the fE) it follows >that they are in practice size limittd well below the IP theoretical >limit of 64K. > >Note that for response messages, if the requestor cares to limit >sizes he can get things in pieces that will get that effect. (i.e. >the CE can choose how much information to ask for. If it wants a >whole table, but wants to control possible size issues, it can >request the data in pieces. Or even one entry at a time.) > >For notifications, it seems that good notification design will not >put too much information in any one notification. But I would >strongly prefer not to have a defined maximum that everyone must >stay under. > > > >Yours, > >Joel > > > >At 04:30 AM 6/12/2007, Patrick Droz wrote: > >>I read the protocol draft again and still want to raise my early > >>question:the size of different ForCES message,i think not restrain >>it and > >>let implementation to freely choose will result in disasters,the >>reason is > >>that the protocol implementator not sure what message is legal and >>must > >>handle all sizes,a attacker may send very large size message to >>cause the > >>receiver down.I suppose we should limit the size of each ForCES >>message > >>accordingly.(FYI:The BGP set the message size limit of 4096 bytes, >>our > >>ForCES message is different,we have two sort of message,redirect >>message is > >>one sort,and all other messages belongs to the other,we should >>treat them > >>diffierently.) > >>Yours,Fenggen > >_________________________________________________________________ >娑规╃娴濞 MSN Messenger: http://messenger.msn.com/cn > > >________________________________________________________________________ >AOL now offers free email to everyone. Find out more about what's free from AOL at AOL.com. _________________________________________________________________ 璐逛杞 MSN Explorer: http://explorer.msn.com/lccn